github / github/copilot-cli

Code-review task agents can mutate the shared parent worktree

オープン
#4,195 コメント 0 件 リアクション 1 件 担当者 0 名 GitHub で見る
area:agents area:permissions
主要言語
Shell
スター
11.2k
フォーク
1.9k
平均マージ
14時間 16分
マージ済み PR(30日)
6

説明

### Describe the bug

Native `task` agents launched with `agent_type: code-review` can mutate the shared parent worktree even though the agent type is described as read-only. In one two-reviewer panel, both prompts explicitly required read-only tools and forbade shell commands, scratch files, and repository writes. After the reviewers completed, the parent worktree contained 13 new untracked files and temporary repositories whose names matched the edge cases discussed in the review output.

Prompt-only read-only instructions are not an adequate boundary for a built-in agent advertised as read-only. A reviewer can silently contaminate or overwrite a parent's in-progress work.

### Affected version

1.0.71

### Steps to reproduce the behavior

1. Start a project session with one intentional uncommitted file change.
2. Record `git status --porcelain`.
3. Invoke two background `task` calls with `agent_type: code-review`.
4. In each reviewer prompt, require investigation through `view`, `rg`, and `glob` only, and explicitly forbid shell commands, scratch files, and all writes.
5. Ask the reviewers to inspect rename, file-mode, conflict, and submodule edge cases.
6. Wait for both reviewers to complete and compare `git status --porcelain` with the snapshot.

The parent worktree gained these untracked artifacts:

```text
source.txt
target.txt
test-conflict/
test-ita/
test-mode/
test-rename/
test-repo/
test-sub-target/
test-sub/
test_copy
test_copy.rs
test_mode
test_mode.rs
```

Removing exactly those post-snapshot artifacts restored the parent worktree. The workaround prevents this occurrence from contaminating the pull request, but it cannot prevent a reviewer from overwriting an existing parent file.

### Expected behavior

A built-in `code-review` agent should have an enforced read-only tool profile, regardless of prompt text, so it cannot create, modify, or delete files in the parent worktree. If reviewer validation requires writes, the task should run in an isolated working copy or sandbox rather than the shared parent worktree.

### Additional context

- Environment: macOS arm64.
- The reviewers were launched in background mode through the native `task` tool.
- The parent snapshot contained one modified tracked file and no untracked files before launch.
- The most targeted fix would bind a read-only tool allowlist to the built-in `code-review` agent. A broader fallback would isolate background task filesystems by default.
- Related sandbox and background-agent requests:

- https://github.com/github/copilot-cli/issues/892
- https://github.com/github/copilot-cli/issues/2846
- https://github.com/github/copilot-cli/issues/4193

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

まず、agent_type: code-review のネイティブなタスク起動と、組み込みエージェントの tool-profile エントリーポイントを追跡します。2 人のレビュアーで再現する前後に git status --porcelain を使用します。完了条件は、code-review エージェントが親 worktree 内でファイルを作成、変更、削除できず、検証で一覧にある rename、mode、conflict、submodule のケースをカバーしていることです。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
git
領域
devtools, security
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
静か
明瞭さ
おおむね明確
初心者へのやさしさ
48/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。