fix(agent-team): repair Slack listener block_actions matcher; add dedicated Slack app #25

Merged
amoussa1229 merged 1 commit from fix/agent-team-slack-listener-matcher into main 2026-06-22 17:16:35 +00:00
amoussa1229 commented 2026-06-22 17:12:45 +00:00 (Migrated from github.com)

Summary

First live run of the R720 agent-team coordinator exposed a crash in the Socket Mode inbound listener, plus this lands the dedicated Slack app provisioned during bring-up.

The fix (security-surface change)

agent_team/transport/slack_listener.py serve() registered @app.action({}) to catch all block_actions. Under slack_bolt 1.28.0 an empty-dict constraint raises BoltError: action ({}) must be any of str, Pattern, and dict at registration time, killing the listener thread — so the entire inbound answer path (message / app_mention / block_actions) was down, surfacing only as the coordinator's respawn-watchdog ALARM. serve() is # pragma: no cover - live socket, so it was never exercised until provisioning.

Replaced with a catch-all re.compile(r".*") action_id matcher. handle_event still performs all filtering + the AUTHZ-01 owner-allowlist gate + the status='open' compare-and-set, so over-matching is safe.

Verified on sh-secrev

  • Listener connects (live Socket Mode WebSocket to Slack), 6 threads, 0 errors
  • Outbound chat.postMessage to #agent-team works
  • /sh-security-review: PASS — no confirmed critical/high; the matcher change introduces no new findings (verifier confirmed the allowlist runs before any ledger work and fails closed; answers stored as parameterized data)

Also included

  • Dedicated Slack app (agent-team/slack/agent-team-manifest.json + README.md) — "Sea Haven agent-team" (A0BC7AT8NUD). Workspace-scoped install (org_deploy_enabled=false) to avoid the Enterprise-Grid scope_not_allowed_on_enterprise org-install trap; scopes minimized (no chat:write.public).
  • Runbook patch — corrected the stale langgraph==1.1.10 pin to 1.2.5 (matches requirements.txt).

Test plan

  • ruff check . + ruff format --check . clean
  • pytest (agent-team) — 956 passed
  • Pre-push security scanners — PASS

Non-blocking follow-up (out of scope)

/sh-security-review surfaced that coordinator.py respawns the listener without close()-ing the dead one (pre-existing; the fix makes flaps rare). Worth hardening later; not in this PR.

## Summary First live run of the R720 agent-team coordinator exposed a crash in the Socket Mode inbound listener, plus this lands the dedicated Slack app provisioned during bring-up. ### The fix (security-surface change) `agent_team/transport/slack_listener.py` `serve()` registered `@app.action({})` to catch all block_actions. Under `slack_bolt 1.28.0` an empty-dict constraint raises `BoltError: action ({}) must be any of str, Pattern, and dict` **at registration time**, killing the listener thread — so the entire inbound answer path (message / app_mention / block_actions) was down, surfacing only as the coordinator's respawn-watchdog ALARM. `serve()` is `# pragma: no cover - live socket`, so it was never exercised until provisioning. Replaced with a catch-all `re.compile(r".*")` action_id matcher. `handle_event` still performs all filtering + the AUTHZ-01 owner-allowlist gate + the `status='open'` compare-and-set, so over-matching is safe. ### Verified on `sh-secrev` - Listener connects (live Socket Mode WebSocket to Slack), 6 threads, 0 errors - Outbound `chat.postMessage` to `#agent-team` works - `/sh-security-review`: **PASS** — no confirmed critical/high; the matcher change introduces no new findings (verifier confirmed the allowlist runs before any ledger work and fails closed; answers stored as parameterized data) ### Also included - **Dedicated Slack app** (`agent-team/slack/agent-team-manifest.json` + `README.md`) — "Sea Haven agent-team" (`A0BC7AT8NUD`). Workspace-scoped install (org_deploy_enabled=false) to avoid the Enterprise-Grid `scope_not_allowed_on_enterprise` org-install trap; scopes minimized (no `chat:write.public`). - **Runbook patch** — corrected the stale `langgraph==1.1.10` pin to `1.2.5` (matches `requirements.txt`). ## Test plan - `ruff check .` + `ruff format --check .` clean - `pytest` (agent-team) — **956 passed** - Pre-push security scanners — PASS ## Non-blocking follow-up (out of scope) `/sh-security-review` surfaced that `coordinator.py` respawns the listener without `close()`-ing the dead one (pre-existing; the fix makes flaps rare). Worth hardening later; not in this PR.
This repo is archived. You cannot comment on pull requests.
No description provided.