Skip to content

ci: steer the implement agent to commit via git CLI, not the file-ops MCP - #250

Merged
allxsmith merged 1 commit into
mainfrom
claude/implement-git-commit-recipe
Jul 7, 2026
Merged

allxsmith merged 1 commit into
mainfrom
claude/implement-git-commit-recipe

Conversation

@allxsmith

@allxsmith allxsmith commented Jul 7, 2026 •

Copy link
Copy Markdown
Owner

What

Give the implement agent an explicit git-CLI commit+push recipe and tell it there's no MCP commit tool, plus show_full_output.

Why

Implement run #18 fully built Reveal (gates green, Reveal.tsx 100% coverage) but opened no PR — its own finish comment said it was blocked:

"the mcp__github_file_ops__commit_files tool is being rejected… I have no way to grant this permission myself."

It reached for the file-ops MCP commit tool (not allowlisted) instead of the git CLI (git add/commit/push, which is allowlisted and is exactly what runs #16/#17 used to open #243 and #247). Same non-deterministic tool-grab as the fixer reaching for a nonexistent MCP reply tool — and the same fix: steer it to the proven path explicitly.

Changes

  • Step 4 rewritten with a literal git checkout -b / add / commit / push -u origin HEAD recipe, and a plain statement that mcp__github_file_ops__commit_files is not allowlisted / will be denied. Git is already SSH-signing as bestaxbot, so git-CLI commits come out Verified.
  • show_full_output: true on the implement job — a blocked commit shows in the log (the artifact's blob host is proxy-blocked).

Note

Prompt + one input. No allowlist/permission/model change (git verbs were already allowlisted; this just steers to them). YAML validated.


Generated by Claude Code

Summary by CodeRabbit

  • Chores
    • Improved workflow logging so more execution details appear in job output, making blocked or looping runs easier to diagnose.
    • Updated automated commit-and-push guidance to be more explicit and reliable, helping changes be recorded and published consistently.

… MCP

Implement run #18 fully built the Reveal component (gates green, 100%
coverage) but produced no branch/PR: it reached for
mcp__github_file_ops__commit_files, which is not allowlisted, and gave up
blocked — even though the git-CLI commit/push verbs ARE allowlisted and are
what runs #16/#17 used to open #243 and #247. Non-deterministic tool choice,
same class as the fixer reaching for a nonexistent MCP reply tool.

- Rewrite step 4 with an explicit git-CLI commit+push recipe
  (git checkout -b / add / commit / push) and state plainly that there is NO
  MCP commit tool here — git is already set up to SSH-sign as bestaxbot, so
  git-CLI commits come out Verified.
- Add show_full_output so a blocked commit is visible in the log, not just an
  artifact the proxy won't let us download.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NVR5yWevceZEFbTJmpviiM
@allxsmith
allxsmith merged commit 4f95cca into main Jul 7, 2026
8 of 9 checks passed
@coderabbitai

coderabbitai Bot commented Jul 7, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 6eb4846f-1bbf-400e-ab85-e84a9c2b1788

📥 Commits

Reviewing files that changed from the base of the PR and between 816549b and df35fe6.

📒 Files selected for processing (1)
  • .github/workflows/claude-implement.yml

Walkthrough

This PR modifies the Claude implementation GitHub Actions workflow, enabling show_full_output: true for full tool-call/denial log streaming and rewriting the embedded prompt's COMMIT + PUSH section with expanded git-CLI instructions, branch naming, and SSH-signing verification requirements.

Changes

Claude Implement Workflow Update

Layer / File(s) Summary
Enable full log streaming
.github/workflows/claude-implement.yml
Adds show_full_output: true to the Claude action step to stream tool calls and permission denials into the job log.
Rewrite commit/push prompt instructions
.github/workflows/claude-implement.yml
Expands the "COMMIT + PUSH" prompt section with detailed git-CLI steps, branch naming convention, prohibition on MCP commit tools, and SSH-signed verified commit requirement, replacing the prior shorter Conventional Commits wording.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Possibly related PRs

  • allxsmith/bestax#248: Also updates claude-implement.yml with show_full_output: true and related prompt guidance in the same workflow step.
  • allxsmith/bestax#236: Updates --allowedTools allowlists to support the git write commands required by this PR's SSH-signing commit path.
  • allxsmith/bestax#230: Modifies the same embedded Claude prompt in claude-implement.yml, adding a REGRESSION-TEST GATE alongside this PR's COMMIT+PUSH changes.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/implement-git-commit-recipe

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 7, 2026

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://5ad5a1fc.bestax.pages.dev

@github-actions

github-actions Bot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 5.3.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 3.2.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 1.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@allxsmith
allxsmith deleted the claude/implement-git-commit-recipe branch July 31, 2026 04:46
@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 1.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

allxsmith added a commit that referenced this pull request Oct 10, 2026
The show_full_output comments in bestaxbot-reply, claude-implement and
claude-pr-loop said the artifact's blob host was blocked by a proxy. No
proxy sits in those jobs. The claim came from #250, where the proxy was the
reader's, refusing the artifact download, and it predates the jobs going to
block. claude-implement's upload has since succeeded at block through the
agent's built-in entries, which skills-publish already cites.

Each comment now says what is true of its own job: claude-implement and the
loop's fix job upload the artifact, whose blob host needs no listing, and
the log copy saves a download; bestaxbot-reply and the loop's verify job
upload none, so the log is where the stream survives. The two upload-step
comments no longer say the log carries only the init and final result,
which stopped being true when show_full_output was added.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants