open-swe/agent/tools
Adam Moussa 8a9974c3c4
Some checks failed
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
Build & publish app artifacts / Publish + deploy (dev) (push) Has been cancelled
Build & publish app artifacts / Publish + deploy (prod) (push) Has been cancelled
Infra CD / Infra CI (pre-deploy) (push) Has been cancelled
Infra CD / Deploy open-swe-dev (push) Has been cancelled
Infra CD / Deploy open-swe-prod (push) Has been cancelled
feat: author Slack/dashboard/schedule commits + PRs as the app by default (#57) (#60)
* feat: default Slack/dashboard/schedule PRs + commits to the app identity (#57)

Slack/dashboard/schedule runs now author PRs and run git/gh operations as the
GitHub App seahaven-openswe[bot] by default (matching GitHub-issue runs), so the
self-review 422 is impossible by construction rather than guarded in the prompt.
A profile flag author_prs_as_user restores per-user attribution.

- open_pull_request._resolve_pr_author_token + auth.resolve_github_token: default
  to the installation token for these sources; per-user only when opted in.
- authorship: commit identity -> seahaven-openswe[bot] (numeric noreply;
  accepted Vercel-resolution risk, documented inline).
- self-trigger safety: INTERNAL_BOT_LOGINS + webapp/reviewer_reconcile/reply
  markers recognize seahaven-openswe[bot] (bot-authored events are now ours).

Supersedes the prompt-only guard in #58.

* fix: author commits as the app bot in the default path (SH-IDSPLIT-01)

Security review found the commit identity was NOT actually unified to the bot:
resolve_triggering_user_identity got a 403 from the installation token and fell
back to configurable['github_login'], so commits were still authored as the
triggering user (commit=user, push+PR=bot — a three-way split that missed the
stated goal). Now gate the triggering-user identity resolution on the same
default-bot decision as the token: slack/dashboard/schedule default to the app
bot identity unless author_prs_as_user is set.

* docs(security): record AUTHZ-SLACK-BOT-DEFAULT-001 as an accepted residual (#59)

Single-user deployment; bounded by App-on-pilot + ALLOWED_GITHUB_REPOS lock.
Revisit (add a per-user gate) before expanding users or the App installation.
2026-06-29 14:22:33 -04:00
..
__init__.py feat: plan mode with model-driven entry and collaborative review (#1580) 2026-06-23 12:06:58 -07:00
add_finding.py feat: disable out-of-diff reviewer findings (#1516) 2026-06-12 10:19:30 -07:00
enter_plan_mode.py feat: plan mode with model-driven entry and collaborative review (#1580) 2026-06-23 12:06:58 -07:00
fetch_url.py feat: add size caps for PR diff, fetch_url, Slack threads, pagination, message queue [closes OPE-51] (#1567) 2026-06-17 15:40:59 -07:00
http_request.py fix: harden http_request SSRF guard against DNS rebinding [closes AB-2321] (#1277) 2026-05-08 22:06:25 +00:00
linear_comment.py feat: move github workflows to gh cli (#1238) 2026-05-04 18:03:53 -07:00
linear_create_issue.py feat: add linear tools for listing teams, get/create/update/delete issues, and get issue comments (#1105) 2026-03-23 14:32:44 -07:00
linear_delete_issue.py feat: add linear tools for listing teams, get/create/update/delete issues, and get issue comments (#1105) 2026-03-23 14:32:44 -07:00
linear_get_issue.py feat: add linear tools for listing teams, get/create/update/delete issues, and get issue comments (#1105) 2026-03-23 14:32:44 -07:00
linear_get_issue_comments.py feat: add linear tools for listing teams, get/create/update/delete issues, and get issue comments (#1105) 2026-03-23 14:32:44 -07:00
linear_list_teams.py feat: add linear tools for listing teams, get/create/update/delete issues, and get issue comments (#1105) 2026-03-23 14:32:44 -07:00
linear_update_issue.py feat: add linear tools for listing teams, get/create/update/delete issues, and get issue comments (#1105) 2026-03-23 14:32:44 -07:00
list_findings.py fix: honest publish_review reporting + structured thread-not-found errors (#1481) 2026-06-10 10:44:13 -07:00
list_review_findings.py feat: chat with your PR on the review page (#1534) 2026-06-15 17:17:30 -07:00
open_pull_request.py feat: author Slack/dashboard/schedule commits + PRs as the app by default (#57) (#60) 2026-06-29 14:22:33 -04:00
publish_review.py feat: surface sub-threshold findings in review summary with web app link (#1571) 2026-06-18 11:15:42 -07:00
read_finding_outcomes.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
read_repo_file.py feat: chat with your PR on the review page (#1534) 2026-06-15 17:17:30 -07:00
reply_to_finding_thread.py feat: author Slack/dashboard/schedule commits + PRs as the app by default (#57) (#60) 2026-06-29 14:22:33 -04:00
request_pr_review.py fix: route PR review requests through agent tool (#1340) 2026-05-27 10:29:43 -07:00
resolve_finding_thread.py fix: honest publish_review reporting + structured thread-not-found errors (#1481) 2026-06-10 10:44:13 -07:00
save_plan.py feat: plan mode with model-driven entry and collaborative review (#1580) 2026-06-23 12:06:58 -07:00
save_review_style.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
schedule_thread_wakeup.py feat: add schedule_thread_wakeup tool for self-polling (#1592) 2026-06-23 11:06:01 -07:00
search_repo_code.py feat: chat with your PR on the review page (#1534) 2026-06-15 17:17:30 -07:00
slack_read_thread_messages.py feat: add size caps for PR diff, fetch_url, Slack threads, pagination, message queue [closes OPE-51] (#1567) 2026-06-17 15:40:59 -07:00
slack_thread_reply.py feat: plan mode with model-driven entry and collaborative review (#1580) 2026-06-23 12:06:58 -07:00
update_finding.py fix: honest publish_review reporting + structured thread-not-found errors (#1481) 2026-06-10 10:44:13 -07:00
web_search.py fix: add Exa web search tool [closes: OPE-29] (#1133) 2026-03-25 16:24:31 -07:00