Browse Source
Changed agent tool declaration from `Bash(gh pr review:*)` to `Bash(gh pr review:--comment*)` to explicitly prevent the agent from executing PR approval or rejection operations. This closes a permission gap where the wildcard pattern technically allowed `--approve` and `--request-changes` flags, though the agent was never instructed to use them. The agent retains full ability to post inline review comments and summary comments. Security hardening following principle of least privilege.pull/521/head
1 changed files with 1 additions and 1 deletions
Loading…
Reference in new issue