Skip to content

ci: enforce protected-path exclusions with --disallowedTools - #260

Merged
allxsmith merged 1 commit into
mainfrom
ci/allowlist-file-tools
Jul 9, 2026
Merged

allxsmith merged 1 commit into
mainfrom
ci/allowlist-file-tools

Conversation

@allxsmith

@allxsmith allxsmith commented Jul 9, 2026 •

Copy link
Copy Markdown
Owner

Summary

Follow-up hardening to #258 (which allowlisted Edit/MultiEdit/Write for the three write-capable agents — superseding this PR's original first commit, since both made the same change).

The agent prompts forbid touching .github/**, pnpm-workspace.yaml, .npmrc, .coderabbit.yaml, turbo.json, and the jest/commitlint/release configs — but prompt text is advisory, and with the bare file-tool grant now on main the whole workspace is writable. CodeRabbit flagged this on the original revision of this PR (3× Major: "the prompt-only exclusions don't enforce anything").

This PR mirrors the exclusion list as --disallowedTools deny rules in the same three workflows (bestaxbot-reply.yml, claude-pr-loop.yml fix step, claude-implement.yml). Deny rules take precedence over allow rules, so the protected paths are enforced by the permission layer rather than prose:

Edit|MultiEdit|Write × (.github/**, pnpm-workspace.yaml, .npmrc, .coderabbit.yaml,
                        turbo.json, **/jest.config.*, commitlint.config.js, **/release.config.*)

Known residual gap (accepted): Bash(sed:*)/Bash(node:*) remain allowlisted and could still write protected files; removing them would break how the agents work today. The loop's changed-files gate (halting on .github/** etc.) stays as the backstop.

Closes #259 (core defect fixed by #258; this carries the enforcement remainder).

Test plan

  • All three workflows parse as valid YAML (js-yaml)
  • Diff is only the --disallowedTools line + explanatory comment in each of the three files
  • Post-merge: trigger bestaxbot-reply on a bestaxbot PR (e.g. feat(bulma-ui): add Avatar, Avatars, and Badge components #257) — file edits inside package dirs succeed; an attempted edit of a protected path is denied in the log

Summary by CodeRabbit

  • Bug Fixes
    • Improved automated workflow reliability by updating headless Claude tool permissions and tool-access rules to correctly scope automated edits.
    • Added explicit deny rules to prevent Edit/MultiEdit/Write changes under protected paths (including .github/** and key repo config/test/release files), with deny precedence over existing allowlists.
  • Documentation
    • Added inline workflow notes clarifying how protected-path exclusions are enforced.

@coderabbitai

coderabbitai Bot commented Jul 9, 2026 •

Copy link
Copy Markdown

Review Change Stack

Walkthrough

Three GitHub Actions workflows update Claude tool permissions, adding protected-path deny rules and adjusting comments around claude_args.

Changes

Claude workflow tool policy updates

Layer / File(s) Summary
Update Claude tool allow and deny rules
.github/workflows/bestaxbot-reply.yml, .github/workflows/claude-implement.yml, .github/workflows/claude-pr-loop.yml
claude_args comments are updated, --disallowedTools is added for protected paths and config globs, and .github/workflows/claude-implement.yml also expands --allowedTools to include Edit, MultiEdit, and Write.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related issues

Possibly related PRs

  • allxsmith/bestax#216: Updates the same Claude workflow tool-access controls and protected-path edit blocking.
  • allxsmith/bestax#218: Modifies .github/workflows/claude-implement.yml and related claude_args tool settings.
  • allxsmith/bestax#227: Modifies .github/workflows/claude-pr-loop.yml and the same Claude tool-configuration block.

Suggested labels: released

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description covers the change and test plan, but it omits most required template sections like affected packages, type of change, checklist, and context. Add the missing template sections: affected package(s), type of change, checklist items, screenshots/demos if needed, and any additional context.
✅ Passed checks (4 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title accurately summarizes the main change: enforcing protected-path exclusions with --disallowedTools in CI workflows.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci/allowlist-file-tools

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://aed3e7c5.bestax.pages.dev

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/bestaxbot-reply.yml:
- Around line 158-164: The Claude tool allowlist in bestaxbot-reply workflow is
too broad because Edit and Write are granted across the whole workspace, so the
prompt-only path exclusions are not enforced. Update the `claude_args` block to
scope `Edit`/`Write` to the intended paths or add explicit `--disallowedTools`
restrictions for the excluded files, keeping the change centered on the
`claude_args` configuration.

In @.github/workflows/claude-implement.yml:
- Around line 110-116: The current claude_args allowlist grants repo-wide Edit
and Write access, so the prompt-only “never touch” restriction is not enforced.
Update the workflow’s claude_args in claude-implement.yml to scope Edit/Write
through tool-policy or path-specific rules, and explicitly constrain them to the
intended config areas such as .github/**, Jest/commitlint/release configs,
pnpm-workspace.yaml, .npmrc, .coderabbit.yaml, and turbo.json.

In @.github/workflows/claude-pr-loop.yml:
- Around line 367-373: The fix-agent allowlist in the claude_args block still
grants Edit and Write access, which leaves the workflow vulnerable to
prompt-injected repo edits. Remove Edit and Write from the allowedTools list in
the claude_args configuration, keeping the step read-only unless a later stage
explicitly requires write access; use the claude_args block as the place to
update the tool permissions.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: e7ef8525-b044-4f76-b69b-8f7493cd06ed

📥 Commits

Reviewing files that changed from the base of the PR and between 689300d and 845bf24.

📒 Files selected for processing (3)
  • .github/workflows/bestaxbot-reply.yml
  • .github/workflows/claude-implement.yml
  • .github/workflows/claude-pr-loop.yml

Comment thread .github/workflows/bestaxbot-reply.yml Outdated
Comment thread .github/workflows/claude-implement.yml Outdated
Comment thread .github/workflows/claude-pr-loop.yml Outdated
allxsmith added a commit that referenced this pull request Jul 9, 2026
The agent prompts forbid touching .github/**, pnpm-workspace.yaml,
.npmrc, .coderabbit.yaml, turbo.json, and the jest/commitlint/release
configs, but prompt text is advisory - with a bare Edit,Write allow the
whole workspace was writable. Mirror the exclusion list as
--disallowedTools deny rules, which take precedence over allow rules,
so the limits are enforced by the permission layer rather than prose.

Addresses the CodeRabbit review on #260.
The agent prompts forbid touching .github/**, pnpm-workspace.yaml,
.npmrc, .coderabbit.yaml, turbo.json, and the jest/commitlint/release
configs, but prompt text is advisory - the bare Edit/MultiEdit/Write
grant from #258 makes the whole workspace writable. Mirror the exclusion
list as --disallowedTools deny rules, which take precedence over allow
rules, so the limits are enforced by the permission layer rather than
prose.

Raised by the CodeRabbit review on #260.
@allxsmith
allxsmith force-pushed the ci/allowlist-file-tools branch from 6114295 to 4669969 Compare July 9, 2026 01:16
@allxsmith allxsmith changed the title ci: allowlist Edit/Write file tools for AI agent workflows ci: enforce protected-path exclusions with --disallowedTools Jul 9, 2026
@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://4234b20e.bestax.pages.dev

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/bestaxbot-reply.yml:
- Around line 164-165: The tool allowlist in the workflow still leaves a write
path open through Bash(sed:*), which can bypass the protected-path restrictions
enforced by the disallowed Edit/MultiEdit/Write entries. Update the allowedTools
configuration to remove or tightly scope the sed Bash allowance so protected
files cannot be modified via sed -i. Keep the restriction aligned with the
existing tool policy in bestaxbot-reply.yml.

In @.github/workflows/claude-pr-loop.yml:
- Around line 373-374: The Bash allowlist in the workflow still permits
write-capable sed usage through the generic Bash(sed:*) entry, which can bypass
the protected-path restrictions. Update the allowedTools list to restrict sed to
read-only usage (for example, a narrowed matcher like Bash(sed -n:*) or remove
sed entirely) so only non-mutating commands are permitted alongside the existing
Edit/MultiEdit/Write blocks.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: c2b16cca-a04a-47e8-be48-bd80c6a4297f

📥 Commits

Reviewing files that changed from the base of the PR and between 6114295 and 4669969.

📒 Files selected for processing (3)
  • .github/workflows/bestaxbot-reply.yml
  • .github/workflows/claude-implement.yml
  • .github/workflows/claude-pr-loop.yml
🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/workflows/claude-implement.yml

Comment thread .github/workflows/bestaxbot-reply.yml
Comment thread .github/workflows/claude-pr-loop.yml
@allxsmith
allxsmith merged commit 75f4566 into main Jul 9, 2026
42 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 3.2.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 1.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@allxsmith
allxsmith deleted the ci/allowlist-file-tools branch July 31, 2026 04:46
@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 1.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci: AI agent workflows deny Edit/Write file tools (agents can only edit files via an incidental sed -i)

1 participant