Skip to content

feat(copilot): add Olive Studio code-review agent skill - #173

Merged
tonythethompson merged 3 commits into
mainfrom
feat/copilot-code-review-skill
Aug 8, 2026
Merged

tonythethompson merged 3 commits into
mainfrom
feat/copilot-code-review-skill

Conversation

@tonythethompson

@tonythethompson tonythethompson commented Aug 8, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Adds .github/skills/code-review/SKILL.md so GitHub Copilot code review (and other agents) can load Olive Studio–specific PR review guidance.
  • Directory name code-review follows Copilot code review agent skills guidance.
  • Encodes local-first security, high-risk paths (Olive spawn, MCP proxy, AI SSRF, recipe validation, Tauri), mcp<2, no live Olive in CI, pnpm-only, and dual AI provider registration checks from AGENTS.md / REVIEW.md.

Test plan

  • Confirm .github/skills/code-review/SKILL.md is present on the PR head branch
  • Request Copilot code review on a PR that includes this skill and verify attributions / session logs show the skill when relevant
  • Spot-check that the skill text matches current gotchas in AGENTS.md (pnpm, mcp<2, no live Olive in CI)

Made with Cursor

Review in cubic

Give Copilot code review a review-focused skill under .github/skills/code-review so PR reviews follow local-first security, recipe/MCP boundaries, and testing tiers from AGENTS.md.

Co-authored-by: Cursor <cursoragent@cursor.com>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @tonythethompson, you have reached your weekly rate limit of 500000 diff characters.

Please try again later or upgrade to continue using Sourcery

@vercel

vercel Bot commented Aug 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
olive-studio Ready Ready Preview Aug 8, 2026 4:06am

@coderabbitai

coderabbitai Bot commented Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@tonythethompson, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 50 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 2b90845f-1867-45a6-8005-9cea339a10d9

📥 Commits

Reviewing files that changed from the base of the PR and between e44f509 and 4ed249e.

📒 Files selected for processing (1)
  • .github/skills/code-review/SKILL.md
📝 Walkthrough

Walkthrough

Added a repository-specific code-review skill. It defines project context, review priorities, security checks, Olive and MCP constraints, architecture guidance, testing conventions, dependency rules, comment standards, and excluded activities.

Changes

Code Review Skill

Layer / File(s) Summary
Repository review guidance
.github/skills/code-review/SKILL.md
Adds project-specific code-review rules for security, path validation, Olive and MCP safeguards, architecture, testing, dependencies, comments, and review scope.

Estimated code review effort: 1 (Trivial) | ~5 minutes

🚥 Pre-merge checks | ✅ 8
✅ Passed checks (8 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the addition of the Olive Studio code-review agent skill.
Description check ✅ Passed The description directly explains the new skill, its purpose, and the review guidance it contains.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Pipeline Stage Enum Ordering ✅ Passed The cumulative PR diff adds only .github/skills/code-review/SKILL.md; it does not modify or reference SessionWorkflowStage or any listed stage member.
Gpu/Cpu Runtime Boundary ✅ Passed The PR changes only .github/skills/code-review/SKILL.md; no inference or managed runtime requirements files changed, so the GPU/CPU boundary check is not triggered.
Managed Host Restart Safety ✅ Passed The PR changes only .github/skills/code-review/SKILL.md; none of the four managed-host entities or lifecycle methods are modified or present in tracked source.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/copilot-code-review-skill
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch feat/copilot-code-review-skill

Warning

Review ran into problems

🔥 Problems

Linked repositories: Public OSS repositories can only analyze public repositories installed in this organization. Analyzed tonythethompson/QuickShell, tonythethompson/numan, tonythethompson/dependency-chain-substrate, skipped Trackdubllc/Trackdub.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@qodo-code-review

Copy link
Copy Markdown
Contributor

PR Summary by Qodo

Add Copilot code-review skill with Olive Studio PR review guidance

📝 Documentation ⚙️ Configuration changes 🕐 Less than 10 minutes

Grey Divider

AI Description

• Add a GitHub Copilot “code-review” skill file to standardize PR review guidance.
• Encode local-first security, high-risk paths, and Olive/MCP/AI validation priorities.
• Document project-specific testing tiers and dependency/tooling constraints for reviewers.
Diagram

graph TD
  C{{"Copilot code review"}} --> S[".github/skills/code-review/SKILL.md"] --> O["Review findings"] --> H["Human reviewers"]
  S --> D["AGENTS.md + REVIEW.md"]
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Use only existing docs (AGENTS.md/REVIEW.md) without a Copilot skill
  • ➕ No new Copilot-specific surface area to maintain
  • ➕ Avoids duplication of review rules
  • ➖ Copilot code review is less likely to apply the guidance consistently
  • ➖ Harder to discover in the review workflow compared to a dedicated skill entrypoint
2. Add/extend PR template + review checklist (e.g., .github/pull_request_template.md)
  • ➕ Forces human authors/reviewers to acknowledge security/testing checklists
  • ➕ Useful even when Copilot is not used
  • ➖ Does not directly steer Copilot agent behavior
  • ➖ Templates can become noisy and get ignored over time
3. Add CODEOWNERS for high-risk paths
  • ➕ Ensures domain owners are requested for Olive spawn/MCP/AI/Tauri areas
  • ➕ Reduces risk of missing specialized review
  • ➖ Doesn’t encode detailed guidance; only routes review responsibility
  • ➖ May increase reviewer load/latency if too broad

Recommendation: Keep the SKILL.md approach (it aligns with GitHub’s agent-skill discovery and directly influences Copilot review behavior). Consider complementing it with (a) a lightweight PR template checklist for human reviewers and (b) CODEOWNERS on the listed high-risk paths to ensure the right reviewers are automatically pulled in.

Files changed (1) +114 / -0

Documentation (1) +114 / -0
SKILL.mdAdd Copilot code-review skill for Olive Studio PR guidance +114/-0

Add Copilot code-review skill for Olive Studio PR guidance

• Introduces a GitHub Copilot skill definition for code reviews, capturing Olive Studio-specific priorities: local-first security boundaries, high-risk paths (Olive spawn, MCP proxy, AI SSRF, recipe validation, Tauri), and testing/tooling conventions (pnpm-only, mcp<2, no live Olive in CI). Also specifies comment style expectations and MCP usage guidance when available.

.github/skills/code-review/SKILL.md

@greptile-apps

greptile-apps Bot commented Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

Adds a repository-specific Copilot code-review skill derived from Olive Studio’s existing development and review guidance.

  • Documents security boundaries and high-risk review paths.
  • Records Olive/MCP/CI constraints and AI provider checks.
  • Maps change areas to the repository’s test commands and review conventions.

Confidence Score: 5/5

The PR appears safe to merge.

No blocking failure remains.

Important Files Changed

Filename Overview
.github/skills/code-review/SKILL.md Adds accurate, repository-specific code-review guidance with no eligible follow-up defect identified.

Reviews (3): Last reviewed commit: "fix(copilot): refresh code-review skill ..." | Re-trigger Greptile

greptile-apps[bot]
greptile-apps Bot previously approved these changes Aug 8, 2026
@qodo-code-review

qodo-code-review Bot commented Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📜 Skill insights (0)

Grey Divider


Remediation recommended

1. Pytest directory is ambiguous ✓ Resolved 🐞 Bug ⚙ Maintainability
Description
The skill lists python -m pytest tests -q for olive-mcp-server/ without specifying that the
command must run from that directory. An agent copying the command from the repository root may test
the wrong tests path or report a spurious failure, unlike the repository's explicit setup command.
Code

.github/skills/code-review/SKILL.md[81]

+| `olive-mcp-server/` | `python -m pytest tests -q` (with `mcp<2`) |
Relevance

●●● Strong

Team has accepted doc fixes to make pytest commands copy-pasteable and correct for MCP server
workflows.

PR-#27
PR-#8

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The changed skill gives a relative pytest path while only naming the directory in the table's area
column. Existing project guidance explicitly changes into the MCP server directory before invoking
pytest, proving that the working directory matters.

AGENTS.md[109-114]
.github/skills/code-review/SKILL.md[75-82]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The MCP testing command uses the relative path `tests`, but the skill does not explicitly tell agents to run it from `olive-mcp-server/`. Running it from the repository root can resolve the path incorrectly and produce a misleading test failure.

## Issue Context
The repository instructions use `cd olive-mcp-server` before running the MCP pytest command. Keep the documented `mcp<2` requirement intact.

## Fix Focus Areas
- .github/skills/code-review/SKILL.md[81-81]

Replace the command with an explicit root-safe form such as `cd olive-mcp-server && python -m pytest tests -q`, or state clearly that the command must be run with `olive-mcp-server/` as the working directory.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context used
✅ Compliance rules (platform): 87 rules
✅ REVIEW.md
Review mode: 🚀 Fast: This is a self-contained, documentation-only skill file with one edit site and no runtime behavior or high-risk code changes.

To customize comments, go to the Qodo configuration screen, or learn more in the docs.

Qodo Logo

Comment thread .github/skills/code-review/SKILL.md Outdated
@qodo-code-review

Copy link
Copy Markdown
Contributor

Qodo Fixer

No findings are within the configured fix scope. To change which findings are fixed, adjust the setting on your Qodo configuration page.

Agents copying the relative tests path from repo root can hit the wrong suite; match AGENTS.md with cd olive-mcp-server before pytest.

Co-authored-by: Cursor <cursoragent@cursor.com>
@greptile-apps
greptile-apps Bot dismissed their stale review August 8, 2026 03:56

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

greptile-apps[bot]
greptile-apps Bot previously approved these changes Aug 8, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/skills/code-review/SKILL.md:
- Around line 98-100: Update the GitHub MCP guidance in the review workflow to
require its use only when a GitHub MCP server is available and configured. When
it is unavailable, direct agents to use the available GitHub integration, PR
description, or proceed without that lookup, while preserving the preference for
MCP-backed facts when accessible.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 5820b455-42eb-46c2-ac19-942ee22c7126

📥 Commits

Reviewing files that changed from the base of the PR and between 14202bb and e44f509.

📒 Files selected for processing (1)
  • .github/skills/code-review/SKILL.md
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • tonythethompson/QuickShell (manual)
  • tonythethompson/numan (manual)
  • tonythethompson/dependency-chain-substrate (manual)
📜 Review details
⏰ Context from checks skipped due to timeout. (3)
  • GitHub Check: olive-pass-availability
  • GitHub Check: python-tests
  • GitHub Check: validate
🔇 Additional comments (1)
.github/skills/code-review/SKILL.md (1)

1-97: LGTM!

Also applies to: 101-115

Comment thread .github/skills/code-review/SKILL.md Outdated
Align high-risk paths with routes/ai/, github.ts, and services/mcp; replace stale call_tool-import warning; name registerProvider/ALLOWED_AI_PROVIDERS plus aiProviderCatalog; only require GitHub MCP when configured.

Co-authored-by: Cursor <cursoragent@cursor.com>
@greptile-apps
greptile-apps Bot dismissed their stale review August 8, 2026 04:06

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

@tonythethompson
tonythethompson merged commit ce8bac0 into main Aug 8, 2026
14 checks passed
@tonythethompson
tonythethompson deleted the feat/copilot-code-review-skill branch August 8, 2026 04:56
@linear-code

linear-code Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

OLI-70

This branch was successfully deployed

1 active deployment
Preview — 4ed249ea Deployed Aug 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant