Skip to content

fix: align agent skills and descriptions with runtime contracts - #9

Merged
nalbam merged 5 commits into
mainfrom
improve/agentops-configuration
Sep 29, 2026
Merged

nalbam merged 5 commits into
mainfrom
improve/agentops-configuration

Conversation

@nalbam

@nalbam nalbam commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

현재 Agent 설정과 실제 File 계약에 맞춰 연결·작업 지침을 정리합니다. Agent Memory 설명은 호출자의 접근 범위를 따르도록 하고, 운영 메모의 이전 project/version 용어를 현재 Agent 설정으로 바꿨습니다. 별도 서버 등록과 도구 검색·실제 실행의 검증 범위도 명확히 합니다. Sample Agent는 Chat·API·Slack의 다목적 역할로 설명합니다.

Workspace의 start schema가 title을 제공할 때 작업 목적을 표시 제목으로 보내도록 안내합니다. personal-records는 지원되지 않는 File read 이어 읽기나 동일 호출 반복을 하지 않으며, 사용자가 요청한 본문을 확인한 범위에서만 기록합니다. 전체 기록과 명시적 발췌 기록을 구분합니다.

검증:

  • 저장소 검사: Plugin 8개·Skill 39개 통과
  • Python 검사 46건, HTML 동작 검사 9건 통과
  • 배포의 Skill 39개 본문·참고 파일과 Plugin 8개 상세 화면 확인
  • 실제 모델로 전체 문서 일부 반환·완전한 발췌 반환·요약만 요청의 3개 시나리오를 분류해 예상 결과 확인; 실제 Memory/Document 쓰기를 수행한 검증은 아닙니다
  • 배포에서 Agent Memory와 Sample Agent의 설명 변경 저장 확인; 인증 정보와 권한 설정은 변경하지 않았습니다
  • Audio Inbox에서 한국어 오디오의 전 구간 전사·요약·비공개 결과 저장을 실제 실행하고, 제안과 미확정 사항을 구분한 요약 확인

Workspace title은 호스트 앱이 제공하는 schema를 확인한 뒤에만 사용합니다. 이 브랜치의 Skill 변경은 머지 후 Plugin sync가 필요합니다.

Summary by CodeRabbit

  • Documentation
    • Clarified Agent Memory connection setup, access, ingestion readiness, and token rotation.
    • Updated workspace guidance to distinguish the task from its optional display title.
    • Expanded sample-agent documentation with supported channels, capabilities, and reporting expectations.
    • Clarified that personal records should not be saved when the requested source text cannot be fully verified.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 39d2434a-441a-4536-aea4-5e5d74dc6e32

📥 Commits

Reviewing files that changed from the base of the PR and between f6d0581 and 704a61a.

📒 Files selected for processing (5)
  • docs/agent-studio.md
  • docs/integrations/agent-memory.md
  • docs/sample-agent.md
  • plugins/execution/skills/workspace-task/SKILL.md
  • plugins/workspace/skills/personal-records/SKILL.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

This pull request updates Agent Memory connection documentation, Workspace title guidance, sample Agent text, and personal-records instructions for incomplete file reads.

Changes

Agent Memory connection guidance

Layer / File(s) Summary
Document Agent Memory setup and scope
docs/agent-studio.md, docs/integrations/agent-memory.md
Adds connection setup and access-scope notes, tool and ingestion guidance, connection-test limits, recall details, and identifier distinctions. Agent Studio guidance links to the connection notes.

Workspace task titles

Layer / File(s) Summary
Describe Workspace titles
docs/agent-studio.md, plugins/execution/skills/workspace-task/SKILL.md
When the offered schema supports title, guidance says to use a short title in the user’s language and keep the task or script in task.

Sample Agent description

Layer / File(s) Summary
Describe sample Agent behavior
docs/sample-agent.md
Adds console description and sample text about supported channels, task types, Skill and tool use, and reporting results and unverified scope.

Personal-records handling

Layer / File(s) Summary
Handle incomplete record reads
plugins/workspace/skills/personal-records/SKILL.md
Guidance now says to stop saving and report the unverified range when a File read response does not provide the requested source range.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: nalbam-me

Merge Risk: ⚪ Minimal · up to 704a6

The guidance is ready to merge after normal checks. Sync the changed Skills after merge so their updated instructions are deployed.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 704a6

The new guidance narrows when personal information is recorded and does not show a change to access permissions. The external service’s enforcement of identity and access rules remains unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — If the external service accepts forged user identity or fails to constrain organization-token access, Memory and document access could cross user or organization scope. The supplied evidence does not establish that this path is reachable or was introduced by this PR.

Security Findings and Attack Paths

  • inferred — No introduced or worsened attack path is established. The identity-control candidate remains deferred because the external server’s authentication, active-membership checks, forged-header handling, and authorization tests are unavailable.

Trust Boundaries and Controls

  • observed — The written boundary keeps credentials installation-side, identity host-provided, and effective access server-controlled. The recording skill rejects caller-selected email, token, arbitrary user ID, or organization scope as substitutes for server-provided user context.

Resilience and Maintainability Implications

  • observed — On an incomplete read, the changed procedure stops before a write and reports the unverified range. For writes that proceed, it retains stable retry parameters and keys and does not treat an accepted ingestion as ready.

Hardening Proposals

  • proposed — Verify in the deployed external service that the host-only identity header cannot be forged, membership and tenant authorization are checked for reads and writes, and repeat writes honor the documented idempotency keys.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: updating agent skills and descriptions to match current runtime contracts. It is concise and specific.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@nalbam
nalbam marked this pull request as ready for review September 29, 2026 02:25
@nalbam
nalbam merged commit f500bc4 into main Sep 29, 2026
2 checks passed
@nalbam
nalbam deleted the improve/agentops-configuration branch September 29, 2026 03:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant