github / github/copilot-cli

Code-review task agents can mutate the shared parent worktree

Offen
#4,195 0 Kommentare 1 Reaktion 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

area:agents area:permissions
Vorherrschende Sprache
Shell
Sterne
11.2k
Forks
1.9k
Ø Merge
14 Std. 16 Min.
Gemergte PRs (30 T.)
6

Beschreibung

Describe the bug

Native task agents launched with agent_type: code-review can mutate the shared parent worktree even though the agent type is described as read-only. In one two-reviewer panel, both prompts explicitly required read-only tools and forbade shell commands, scratch files, and repository writes. After the reviewers completed, the parent worktree contained 13 new untracked files and temporary repositories whose names matched the edge cases discussed in the review output.

Prompt-only read-only instructions are not an adequate boundary for a built-in agent advertised as read-only. A reviewer can silently contaminate or overwrite a parent's in-progress work.

Affected version

1.0.71

Steps to reproduce the behavior
  1. Start a project session with one intentional uncommitted file change.
  2. Record git status --porcelain.
  3. Invoke two background task calls with agent_type: code-review.
  4. In each reviewer prompt, require investigation through view, rg, and glob only, and explicitly forbid shell commands, scratch files, and all writes.
  5. Ask the reviewers to inspect rename, file-mode, conflict, and submodule edge cases.
  6. Wait for both reviewers to complete and compare git status --porcelain with the snapshot.

The parent worktree gained these untracked artifacts:

source.txt
target.txt
test-conflict/
test-ita/
test-mode/
test-rename/
test-repo/
test-sub-target/
test-sub/
test_copy
test_copy.rs
test_mode
test_mode.rs

Removing exactly those post-snapshot artifacts restored the parent worktree. The workaround prevents this occurrence from contaminating the pull request, but it cannot prevent a reviewer from overwriting an existing parent file.

Expected behavior

A built-in code-review agent should have an enforced read-only tool profile, regardless of prompt text, so it cannot create, modify, or delete files in the parent worktree. If reviewer validation requires writes, the task should run in an isolated working copy or sandbox rather than the shared parent worktree.

Additional context

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Beginne damit, native Task-Starts für agent_type: code-review und den tool-profile-Einstiegspunkt des integrierten Agents nachzuverfolgen; verwende git status --porcelain vor und nach der Reproduktion mit zwei Reviewern. Erledigt ist die Aufgabe, wenn der code-review-Agent im übergeordneten Worktree keine Dateien erstellen, ändern oder löschen kann und die Validierung die aufgeführten Fälle für Umbenennungen, Modi, Konflikte und Submodule abdeckt.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
git
Bereich
devtools, security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
48/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.