mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 11:33:14 +00:00
fix: allow agent to pause and ask before adding a dependency (#1578)
* fix(prompt): allow agent to pause and ask before adding a dependency Brace's review on #1577 noted that the agent can in fact pause to ask mid-task: post a Slack message (or PR-description note) and end the turn without a tool call, then resume when the user replies. Reword the DEPENDENCY_SECTION guidance so it tells the agent to use that mechanism instead of claiming it cannot pause. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Update agent/prompt.py Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com> * fix(prompt): restore dependency pause guidance assertion --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
This commit is contained in:
parent
e599166e5a
commit
80e23f56c5
2 changed files with 12 additions and 2 deletions
|
|
@ -247,7 +247,7 @@ If you encounter missing dependencies, install them using the appropriate packag
|
|||
- Before ADDING a new dependency the project does not already declare, first confirm the task cannot be solved with the standard library or a package already in the project's manifest/lockfile. Prefer reusing what is already there.
|
||||
- Vet any genuinely new package before adding it: it should be actively maintained (a recent release, responsive issues, more than a single maintainer, steady downloads), free of known unpatched CVEs (check with `npm audit` / `pip-audit` or the GitHub advisory database), and under a permissive license (MIT, Apache-2.0, BSD). Do not add abandoned, single-source, or unlicensed packages.
|
||||
- Pin or bound every newly added dependency to a specific version in the project's manifest; never add a floating or unpinned dependency.
|
||||
- You cannot pause to ask for approval mid-task, so call out every dependency you add in the PR description — the package name, why it is needed, its maintenance/security status, and the alternatives you considered — so a human reviewer can veto it. This vetting is complementary to the `sfw` runtime firewall below: vetting screens out poorly-maintained or risky packages, `sfw` blocks actively-malicious ones at install time.
|
||||
- For any dependency you add, surface it for human review. You can stop to ask: post a question or note in the source Slack thread (or, when the task came from elsewhere, in the PR description) and end your turn without making a tool call — the user can reply and the run will resume. This is an exception to the general autonomy rule. Do the same for the PR description so a human reviewer can veto it: list the package name, why it is needed, its maintenance/security status, and the alternatives you considered. This vetting is complementary to the `sfw` runtime firewall below: vetting screens out poorly-maintained or risky packages, `sfw` blocks actively-malicious ones at install time.
|
||||
- Before any supported package install, ensure Socket Firewall Free (`sfw`) is available with `command -v sfw`. If missing, install it with `npm i -g sfw`; if that fails, report the failure and skip the protected install.
|
||||
- Prefix supported package-manager commands that fetch packages from a registry with `sfw`: npm/yarn/pnpm, pip/uv, and cargo (for example: `sfw npm ci`, `sfw pnpm install`, `sfw pip install -r requirements.txt`, `sfw uv pip install -e .`, `sfw cargo fetch`). For unsupported package managers such as Poetry, run the normal documented install command without `sfw`.
|
||||
- Always ensure dependencies are installed before running a script that might require them."""
|
||||
|
|
|
|||
|
|
@ -62,7 +62,17 @@ def test_construct_system_prompt_includes_dependency_vetting_guidance() -> None:
|
|||
assert "standard library or a package already in the project's manifest/lockfile" in prompt
|
||||
assert "permissive license" in prompt
|
||||
assert "never add a floating or unpinned dependency" in prompt
|
||||
assert "call out every dependency you add in the PR description" in prompt
|
||||
assert "list the package name, why it is needed" in prompt
|
||||
|
||||
|
||||
def test_construct_system_prompt_explains_pause_to_ask_for_dependency_review() -> None:
|
||||
prompt = construct_system_prompt(working_dir="/workspace")
|
||||
|
||||
assert "You can stop to ask" in prompt
|
||||
assert "post a question or note in the source Slack thread" in prompt
|
||||
assert "end your turn without making a tool call" in prompt
|
||||
assert "the user can reply and the run will resume" in prompt
|
||||
assert "You cannot pause to ask for approval mid-task" not in prompt
|
||||
|
||||
|
||||
def test_construct_system_prompt_identifies_own_repo() -> None:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue