[repo-assist] Add DeepWiki MCP tool for cross-repo grounding - #50962
blozano-tt wants to merge 1 commit into
Conversation
Add the public read-only DeepWiki MCP server (https://mcp.deepwiki.com/mcp) to the repo-assist gh-aw workflow so the agent can ask grounded questions about the sibling Tenstorrent repos it cannot easily clone/grep from the agent runner: tt-metal, tt-umd, tt-kmd, tt-isa-documentation. Design guidance baked into the workflow body: - DeepWiki is orientation, not ground truth: verify anything load-bearing against current code via bash/gh before putting it in a PR diff or a definitive comment (DeepWiki content can lag real repo state). - repo-memory discipline: cache re-derivable pointers, not frozen facts, and date every DeepWiki-derived note so it is visibly re-verifiable. No write permissions change: this is purely an additional read-only tool. Scoped to the three read tools (read_wiki_structure, read_wiki_contents, ask_question). lock.yml regenerated via `gh aw compile` (v0.82.14, matching the version that compiled the existing lock). Follow-up to #50829. Co-Authored-By: Claude <noreply@anthropic.com> Co-Authored-By: BrAIn <brain@tenstorrent.com>
There was a problem hiding this comment.
Pull request overview
Adds read-only DeepWiki MCP access for cross-repository grounding while requiring verification against current source code.
Changes:
- Registers three restricted DeepWiki read tools.
- Adds verification and memory-staleness guidance.
- Regenerates the workflow lock and firewall allowlist.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
.github/workflows/repo-assist.md |
Configures DeepWiki and usage safeguards. |
.github/workflows/repo-assist.lock.yml |
Adds generated MCP gateway and egress configuration. |
|
|
||
| **Important**: Memory may be stale. Issues and PRs may have changed since the last run. Always verify memory against current repository state before acting. | ||
|
|
||
| **Cache pointers, not frozen facts.** When you learn something useful via DeepWiki (see **Using DeepWiki** below) that looks reusable across runs, store a *pointer to how to re-derive it* — not the answer itself. For example, save "for tt-umd device-init issues, ask DeepWiki about tt-umd's init sequence; last checked 2026-07-23" rather than pasting DeepWiki's description of that sequence as a fixed fact. ISA docs and repo state drift, and a stale cached "fact" is worse than no cache — it invites confidently wrong comments. **Date every DeepWiki-derived note** so it is visibly re-verifiable, and re-verify against current code before relying on it again. |
|
Superseded by #50964, which combines this PR with #50963 into a single coherent Since the compiled lock is a deterministic function of the whole Closing (not merging) in favor of #50964. Leaving the |
…(supersedes tenstorrent#50962, tenstorrent#50963) [skip ci] (tenstorrent#50964) ## Summary This PR **combines and supersedes** two open repo-assist PRs so there is a **single coherent `repo-assist.md` source and one clean `gh aw compile`** to test against: - Supersedes tenstorrent#50962 — *DeepWiki MCP tool + cross-repo grounding guidance* - Supersedes tenstorrent#50963 — *4 triage-logic bug fixes from the first live run* ### Why combine them `.github/workflows/repo-assist.lock.yml` is a deterministic function of the **whole** `.github/workflows/repo-assist.md` source (both its `frontmatter_hash` and `body_hash` are recomputed on every compile). Each of the two PRs changed **both** hashes, so merging them independently would have one PR's lock regeneration clobber the other's. Per @wilder's request, they are merged here into one source file and compiled **once** so the workflow can be manually tested end-to-end against a single lock. ## What's included ### DeepWiki MCP tool + guidance (from tenstorrent#50962) - Adds a read-only **DeepWiki** MCP server (`https://mcp.deepwiki.com/mcp`) scoped to `read_wiki_structure`, `read_wiki_contents`, `ask_question`. No new write permissions — purely an additional read-only tool. - New body section **"Using DeepWiki (cross-repo grounding)"**: use it to orient across the sibling repos the runner can't easily clone (`tt-metal`, `tt-umd`, `tt-kmd`, `tt-isa-documentation`), with a strict **verify-before-asserting** discipline — anything load-bearing must be confirmed against current code via `bash`/`gh`, never asserted from DeepWiki alone. - **Memory** guidance: cache **pointers, not frozen facts** — store dated, re-derivable notes ("ask DeepWiki about X; last checked <date>") rather than pasting DeepWiki answers that drift. ### Triage-logic fixes (from tenstorrent#50963) 1. **New-contributor welcome (Task 7)** now requires **verified** zero merged PRs **and** zero prior issues/comments (via GitHub search) before welcoming — no longer inferring "new" from local context/memory. 2. **Firewall boilerplate** — adds an instruction to strip the benign `⚠️ Firewall blocked … awmgmcpg` block from public comments. `awmgmcpg` is gh-aw's own internal MCP-gateway sidecar; it **cannot** be silenced via `network.allowed` at this compiler version (confirmed dead end, documented in a frontmatter NOTE), so it's handled at the instruction level. 3. **Fresh-issue scoping (Task 1/2)** — first-time comment+label triage is restricted to issues active in ~90 days, and `[HELP]`/question issues no longer default to the `bug` label. 4. **Comment dedup (Task 7 + Anti-spam)** — when both a triage comment (Task 2) and a welcome (Task 7) apply to the same issue in one run, they are **combined into a single comment** instead of two. ## Compile / testing notes - `repo-assist.lock.yml` was regenerated **once** with `gh aw compile` on the combined source using **gh-aw v0.82.14** — the exact `compiler_version` pinned in the base `main` lock's `gh-aw-metadata`. Result: **0 errors, 0 warnings**, and a second compile is byte-identical (deterministic). The lock diff reflects only real content changes (DeepWiki added to the MCP gateway config + `GH_AW_ALLOWED_DOMAINS`, updated `gh-aw-metadata` hashes). The `.lock.yml` is generated — please don't hand-edit; regenerate via `gh aw compile repo-assist`. - **Suggested manual test:** trigger `/repo-assist <a cross-repo question>` (e.g. something about tt-umd device init) on a test issue. One run then exercises **both** change-sets: the DeepWiki tool for cross-repo grounding, and the fixed contributor-detection / labeling / comment-dedup behavior. Once this is verified and merged, tenstorrent#50962 and tenstorrent#50963 are being closed in favor of it. 🤖 Generated with [Claude Code](https://claude.com/claude-code) ### CI Status _Auto-generated on every push. Badges update live. Click a badge to filter runs by this branch._ - [](https://github.com/tenstorrent/tt-metal/actions/workflows/sanity-tests.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) - [](https://github.com/tenstorrent/tt-metal/actions/workflows/runtime-sanity-tests.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) - [](https://github.com/tenstorrent/tt-metal/actions/workflows/blackhole-sanity-tests.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) - [](https://github.com/tenstorrent/tt-metal/actions/workflows/tt-metal-l2-nightly.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) - [](https://github.com/tenstorrent/tt-metal/actions/workflows/all-model-tests.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) - [](https://github.com/tenstorrent/tt-metal/actions/workflows/pipeline-select.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) - [](https://github.com/tenstorrent/tt-metal/actions/workflows/pipeline-select-t3k.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) - [](https://github.com/tenstorrent/tt-metal/actions/workflows/pipeline-select-galaxy.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) --------- Co-authored-by: Repo Assist <repo-assist@tenstorrent.com> Co-authored-by: BrAIn <brain@tenstorrent.com> Co-authored-by: Repo Assist (BrAIn) <repo-assist@users.noreply.github.com>
Summary
Follow-up to #50829 (which added the
repo-assistGitHub Agentic Workflow). This adds a read-only DeepWiki MCP tool torepo-assistso the agent can ask grounded questions about the related Tenstorrent repos while triaging issues, investigating bugs, and proposing fixes:tenstorrent/tt-metal— this repotenstorrent/tt-umd— User Mode Drivertenstorrent/tt-kmd— Kernel Mode Drivertenstorrent/tt-isa-documentation— ISA / hardware semantics docsWhy DeepWiki
repo-assistruns on a generic agent runner: it cannot build tt-metal locally (documented in the workflow already), and it cannot easily clone-and-grep the sibling driver/ISA repos either. DeepWiki (Cognition Labs' public, unauthenticated, remote MCP server) fills that gap for conceptual/cross-repo questions like "how does tt-umd expose interrupts?" or "what does the ISA doc say about register X?" — the kind of thing local tooling can't answer.What changed
.github/workflows/repo-assist.md(source of truth):mcp-servers:block registeringdeepwikiathttps://mcp.deepwiki.com/mcp(the current recommended HTTP endpoint; the legacy/sseendpoint is being deprecated), scoped viaallowed:to just the three read tools:read_wiki_structure,read_wiki_contents,ask_question..github/workflows/repo-assist.lock.yml(compiled — do not hand-edit): regenerated viagh aw compile. The compiler also auto-addedmcp.deepwiki.comto the firewall egress allowlist and wrapped the server in gh-aw's standardguard-policies/write-sink, so no manualnetwork:change was needed.Design principles (from an internal design discussion)
bash/gh(which the workflow already has), never asserted from DeepWiki alone.repo-assistalready hasrepo-memory: true. When it learns something reusable via DeepWiki it should store a re-derivable pointer (e.g. "for tt-umd device-init issues, ask DeepWiki about tt-umd's init sequence; last checked 2026-07-23") rather than caching the answer as a fixed fact — and date it — because ISA docs and repo state drift, and a stale cached "fact" is worse than no cache.This does not change
repo-assist's write surface: still a read-only job plus the existing scopedsafe-outputs. DeepWiki is purely an additional read-only external tool.Provenance
Proposed by a maintainer (Wilder) and drafted based on an internal design discussion.
Testing / validation status
gh aw compile repo-assistsucceeds with 0 errors, 0 warnings. I pinned the CLI to v0.82.14 — the same compiler version that produced the existing committed lock — and confirmed a baseline recompile reproduces the current lock byte-for-byte, so the lock diff here is attributable solely to the DeepWiki addition (no toolchain/version drift)./repo-assist <some cross-repo question>on a test issue after merge to confirm the DeepWiki tool actually resolves and answers.References
🤖 Drafted by an automated assistant. Please review before merging — do not auto-merge.
CI Status
Auto-generated on every push. Badges update live. Click a badge to filter runs by this branch.