Skip to content

코딩 요청을 작업 브랜치 PR까지 완료하도록 지침 정리 - #11

Merged
nalbam merged 1 commit into
mainfrom
fix/code-agent-git-workflow
Sep 29, 2026
Merged

nalbam merged 1 commit into
mainfrom
fix/code-agent-git-workflow

Conversation

@nalbam

@nalbam nalbam commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

코딩 요청이 구현·검증 후 게시 승인을 기다리며 멈추지 않도록 기본 완료 범위를 작업 브랜치의 커밋·푸시·PR까지 명시했습니다. 사용자가 로컬 작업만 요청하거나 게시를 금지한 경우에는 그 범위를 따릅니다.

  • Workspace 시스템 프롬프트와 구현·수정·리팩토링·업그레이드·프로젝트 생성 스킬의 게시 지침을 통일했습니다.
  • main 병합·직접 푸시·태그·릴리즈·배포는 별도 요청과 확인을 거치도록 구분하고 실제 도구 예제를 추가했습니다.
  • 기본 PR 완료, 게시 금지, 태그 충돌, CI 후속 실행 평가 시나리오를 추가했습니다.

검증: Python 46개 테스트, 저장소 검사(8 plugins / 39 skills), Node 9개 테스트 통과. 로컬 Agent Studio Chat에서 신규 저장소 생성·코딩·추가 승인 없는 PR 생성과 승인 후 main 병합·태그·사전 릴리즈 게시를 확인했습니다.

연결된 구현: Agent Studio PR #134.

Summary by CodeRabbit

  • Workflow Updates
    • Coding requests now generally include implementation, verification, a work-branch commit and push, and pull-request creation without additional approval.
    • Local-only requests, reviews, and other requests with limited scope remain within the boundaries specified by the user.
    • Merging to the main branch, publishing tags or releases, and deployment require a separate request and confirmation. Releases are tied to an existing tag and its exact commit.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 05a5b0be-c5e4-4f54-ae1c-968f0e532b36

📥 Commits

Reviewing files that changed from the base of the PR and between 3d2be53 and 65fda15.

📒 Files selected for processing (16)
  • docs/agent-studio.md
  • docs/code-agent.md
  • docs/prompts/workspace-agent.md
  • evals/engineering-workflows.json
  • plugins/engineering/plugin.json
  • plugins/engineering/skills/ci-failure-investigator/SKILL.md
  • plugins/engineering/skills/dependency-upgrade/SKILL.md
  • plugins/engineering/skills/fix-issue/SKILL.md
  • plugins/engineering/skills/implement-feature/SKILL.md
  • plugins/engineering/skills/project-generator/SKILL.md
  • plugins/engineering/skills/refactor-code/SKILL.md
  • plugins/engineering/skills/security-remediation/SKILL.md
  • plugins/execution/plugin.json
  • plugins/execution/skills/sandbox-task/SKILL.md
  • plugins/execution/skills/workspace-task/SKILL.md
  • plugins/execution/skills/workspace-task/references/git-actions.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Coding-request instructions now include commit, work-branch push, and PR creation unless the user limits the scope. Main-branch changes, tags, releases, and deployments remain subject to separate requests and confirmation. Workflow evaluations cover these boundaries and tag and CI sequencing.

Changes

Work-branch publication guidance

Layer / File(s) Summary
Set the default coding-request scope
docs/agent-studio.md, docs/code-agent.md, docs/prompts/workspace-agent.md, plugins/execution/skills/workspace-task/SKILL.md, plugins/execution/skills/workspace-task/references/git-actions.md, plugins/execution/plugin.json
The guidance includes implementation, verification, commit, work-branch push, and PR creation in coding requests unless the user limits the scope. It excludes lookup, review, and local-only requests from publication.
Specify action handling and confirmation boundaries
plugins/engineering/skills/*, plugins/engineering/plugin.json, plugins/execution/skills/sandbox-task/SKILL.md, plugins/execution/skills/workspace-task/references/git-actions.md
Skill instructions use prepare_git for work-branch publication without additional approval. Main changes, tags, releases, and deployments require separate requests and confirmation. The Git action guidance describes pending actions, tag targets, release targets, and action results.
Cover publication scenarios in workflow evaluations
evals/engineering-workflows.json
The evaluations add local-only, tag-after-merge, tag-target-conflict, and CI-wait cases. Existing cases now expect PR creation without additional approval and retain separate merge confirmation.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Suggested reviewers: nalbam-me

Merge Risk: ⚪ Minimal · up to 65fda

This change makes work-branch PRs part of the default coding workflow while keeping main changes and releases separately confirmed. No merge-blocking issue is established by the repository evidence.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 65fda

A coding request can now lead to remote publication without a separate approval pause. The change limits that default to a work branch and keeps merges and releases separately confirmed, but publishing the wrong files or repository changes remains a meaningful risk.

Retained concerns

  • Medium · security · inferred: A coding request now authorizes remote work-branch publication without the former separate approval pause. If request scope or file selection is mistaken, repository content may be pushed and a PR opened before the user reviews that publication.
Security review details

Security Blast Radius

  • inferred — The expanded default can affect content pushed to the selected repository's work branch, its PR, and ensuing CI. The evidence does not establish token scope, repository visibility, or any cross-repository or cross-tenant authority.

Security Findings and Attack Paths

  • inferred — No verified exploit is established. The material exposure change is that a mistaken interpretation of a coding request or its intended files can reach remote publication without an intervening publication-specific approval; explicit scope limits and the ban on treating issue text as permission constrain that path in guidance.

Trust Boundaries and Controls

  • observed — The documented boundary routes Workspace publication through prepare_git, forbids direct GitHub-write substitutes, and preserves separate confirmation for main and release actions. Its runtime authorization and authenticated identity are unverified.

Resilience and Maintainability Implications

  • inferred — Status checks and no-replay instructions address interruption and repetition at the guidance level, but evidence does not establish atomicity, idempotency, or durable recovery across commit, push, and PR creation.

Hardening Proposals

  • proposed — Before relying on the expanded default, verify that the actual publication action enforces workspace and repository authority, protected-action confirmation, and safe handling of partial success and repeated requests.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 코딩 요청의 기본 완료 범위를 작업 브랜치 PR 생성까지 확장하고 관련 지침을 정리하는 주요 변경사항을 정확하고 간결하게 설명합니다.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@nalbam
nalbam merged commit 87fa309 into main Sep 29, 2026
2 checks passed
@nalbam
nalbam deleted the fix/code-agent-git-workflow branch September 29, 2026 22:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant