open-swe/agent
Johannes du Plessis 40162a6d9e
fix: inject existing PR review threads into reviewer context (#1331)
* fix(reviewer): inject existing PR review threads into reviewer context

The reviewer agent was filing the same inline comment on every re-review
because it only saw findings recorded on its own thread metadata — not
the live PR review-thread state on GitHub. When a previous finding was
still open (code unchanged, or a human reply explained it), the agent
rediscovered the same defect on the next push and called `add_finding`
again, producing duplicate comments.

This change fetches the PR's review threads (across all reviewers, with
replies and isResolved status) via GraphQL and renders them into the
first-review and re-review contexts as a "Pre-existing PR review
threads" block. The system prompt now lists overlap with that block as
a hard "Do NOT file" rule, and treats threads addressed by a human
reply as resolved.

This also gives the reviewer comment-awareness on its very first run
on a PR, so it skips findings already raised by another reviewer or
bot.

* fix(reviewer): wrap PR review threads in untrusted-data XML block

Addresses the reviewer comment on this PR
(https://github.com/langchain-ai/open-swe/pull/1331#discussion_r3295497533):
PR review comment bodies are attacker-controlled (anyone who can comment
on the PR can put anything in them), and they were being concatenated
into the reviewer's system prompt with instruction-priority.

Switches the existing-threads section from a Markdown block to an XML
data block:

  <pr_review_threads>
    <thread location="path:line" status="open">
      <comment author="open-swe[bot]">
        <body>...</body>
      </comment>
      <comment author="romain-priour-lc">
        <body>We added defaults in the template</body>
      </comment>
    </thread>
  </pr_review_threads>

The system prompt now explicitly names the wrapper, tells the agent that
everything inside it is untrusted data from the PR (not instructions),
and that prompt-injection payloads inside bodies must be disregarded.
We keep the bodies so the agent can actually read engineer replies —
that's the whole point of comment-awareness — but they're delimited as
data, not concatenated as prose. Modern frontier models are well-trained
to honor this contract.

Additional defenses:
- Author logins are validated against the GitHub username grammar; any
  unexpected value is rendered as "unknown" so the `author` attribute
  can't smuggle freeform text.
- Literal closing tags (`</body>`, `</pr_review_threads>`, etc.) in
  bodies are neutered so a body can't break out of its wrapper.
- Body length is capped at 4000 chars per comment to bound the prompt.

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-05-24 16:36:50 -07:00
..
dashboard fix: stream agent tokens to the Agents UI (#1329) 2026-05-22 16:02:43 -07:00
integrations feat: add idle TTL and delete-after-stop sandbox lifecycle controls (#1265) 2026-05-08 00:30:14 -04:00
middleware feat: add Agents chat UI for cloud threads (#1323) 2026-05-22 18:15:59 +00:00
tools fix: remove line collapsing (#1330) 2026-05-23 00:43:48 +00:00
utils feat: inline AGENTS.md into reviewer system prompt (#1328) 2026-05-22 14:58:27 -07:00
_patch_messages_reducer.py feat: add Agents chat UI for cloud threads (#1323) 2026-05-22 18:15:59 +00:00
encryption.py feat: support TOKEN_ENCRYPTION_KEY rotation via MultiFernet [closes AB-2323] (#1275) 2026-05-08 14:29:23 -07:00
prompt.py feat: restructure Open SWE Review tab + wire create_prs (#1319) 2026-05-21 09:17:07 -07:00
review_style_analyzer.py feat: add Agents chat UI for cloud threads (#1323) 2026-05-22 18:15:59 +00:00
review_style_collector.py feat: tune reviewer for precision — web/wiki tools + recalibrated prompt (#1312) 2026-05-20 18:35:00 +00:00
review_style_guidance.py feat: tune reviewer for precision — web/wiki tools + recalibrated prompt (#1312) 2026-05-20 18:35:00 +00:00
reviewer.py fix: inject existing PR review threads into reviewer context (#1331) 2026-05-24 16:36:50 -07:00
reviewer_diff.py fix(open-swe): surface reviewer diff-prep failures instead of swallowing (#1260) 2026-05-07 18:20:27 -07:00
reviewer_findings.py feat: tune reviewer for precision — web/wiki tools + recalibrated prompt (#1312) 2026-05-20 18:35:00 +00:00
reviewer_publish.py fix: inject existing PR review threads into reviewer context (#1331) 2026-05-24 16:36:50 -07:00
server.py feat: add Agents chat UI for cloud threads (#1323) 2026-05-22 18:15:59 +00:00
webapp.py feat: auto-review PRs on opened / ready-for-review (#1325) 2026-05-22 13:36:14 -07:00