fix(agent-team): repair Slack listener block_actions matcher; add dedicated Slack app #25
No reviewers
Labels
No labels
app
bug
ci
compliance
content
dependencies
docs
documentation
duplicate
enhancement
github_actions
good first issue
help wanted
infra
invalid
javascript
needs-triage
python
question
tests
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/orchestrator#25
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "fix/agent-team-slack-listener-matcher"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
First live run of the R720 agent-team coordinator exposed a crash in the Socket Mode inbound listener, plus this lands the dedicated Slack app provisioned during bring-up.
The fix (security-surface change)
agent_team/transport/slack_listener.pyserve()registered@app.action({})to catch all block_actions. Underslack_bolt 1.28.0an empty-dict constraint raisesBoltError: action ({}) must be any of str, Pattern, and dictat registration time, killing the listener thread — so the entire inbound answer path (message / app_mention / block_actions) was down, surfacing only as the coordinator's respawn-watchdog ALARM.serve()is# pragma: no cover - live socket, so it was never exercised until provisioning.Replaced with a catch-all
re.compile(r".*")action_id matcher.handle_eventstill performs all filtering + the AUTHZ-01 owner-allowlist gate + thestatus='open'compare-and-set, so over-matching is safe.Verified on
sh-secrevchat.postMessageto#agent-teamworks/sh-security-review: PASS — no confirmed critical/high; the matcher change introduces no new findings (verifier confirmed the allowlist runs before any ledger work and fails closed; answers stored as parameterized data)Also included
agent-team/slack/agent-team-manifest.json+README.md) — "Sea Haven agent-team" (A0BC7AT8NUD). Workspace-scoped install (org_deploy_enabled=false) to avoid the Enterprise-Gridscope_not_allowed_on_enterpriseorg-install trap; scopes minimized (nochat:write.public).langgraph==1.1.10pin to1.2.5(matchesrequirements.txt).Test plan
ruff check .+ruff format --check .cleanpytest(agent-team) — 956 passedNon-blocking follow-up (out of scope)
/sh-security-reviewsurfaced thatcoordinator.pyrespawns the listener withoutclose()-ing the dead one (pre-existing; the fix makes flaps rare). Worth hardening later; not in this PR.