Add experimental standalone Copilot SDK onboarding - #85
Draft
Rick Brighenti (rbrighenti) wants to merge 2 commits into
Draft
Rick Brighenti (rbrighenti) wants to merge 2 commits into
Rick Brighenti (rbrighenti) wants to merge 2 commits into
Conversation
Extend existing skills with standalone detection, explicit approval gates, local-only report validation, and partial telemetry diagnostics. Add compatible plugin packaging and fixtures while preserving the existing runtime and hosting. Document experimental limits and the pending companion helper without operational trial history. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use approval-gated npm install for a fresh sample checkout, keep generated locks local, and document variable transitive resolutions with unchanged direct pins. Cover the bootstrap and registry-policy contract with a focused regression. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Rick Brighenti (rbrighenti)
September 28, 2026 13:25
View session
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Critical Node 18 test compatibility and setup-flow issues remain, along with validation and routing gaps.
Review effort: Lite
Findings: 3
Open (8)
Unconditionally blocks approved standalone workflow · New Uses unsupported recursive directory reads · New Tests use unsupported recursive directory reads · New Accepts unverified SDK versions · New Ignores JavaScript hosting conflicts · New Fails to require exporter auth scopes · New Standalone detection ignores cache state · New Standalone runner ignores cache state · New
What changed in this PR
Adds guarded experimental standalone TypeScript GitHub Copilot SDK onboarding for Agent 365, including routing, approval boundaries, report-only validation, telemetry diagnostics, documentation, and regression coverage.
Changes:
- Adds standalone SDK detection, routing, validators, and hooks.
- Adds documentation, manifests, fixtures, evaluations, and ignore rules.
- Adds regression and parity tests.
| File | Summary |
|---|---|
tests/validate-a365-code-validator-parity.test.js |
Adds standalone validator parity coverage. |
tests/plugin-manifest.test.js |
Validates plugin manifests and guidance. |
tests/fixtures/copilot-sdk/src/index.ts |
Adds SDK fixture source. |
tests/fixtures/copilot-sdk/package.json |
Adds fixture dependency metadata. |
tests/fixtures/copilot-sdk/.gitignore |
Ignores fixture-local artifacts. |
tests/copilot-sdk.test.js |
Tests SDK detection and routing. |
tests/copilot-sdk-hooks.test.js |
Tests hook validation boundaries. |
README.md |
Documents experimental SDK onboarding. |
plugins/agent365/skills/test-local/SKILL.md |
Adds standalone local-test guards. |
plugins/agent365/skills/make-ai-teammate/SKILL.md |
Blocks incompatible teammate routing. |
plugins/agent365/skills/make-a365-agent/SKILL.md |
Adds standalone registration guidance. |
plugins/agent365/skills/instrument-observability/SKILL.md |
Adds standalone instrumentation guidance. |
plugins/agent365/skills/add-workiq-tools/SKILL.md |
Blocks unsupported WorkIQ routing. |
plugins/agent365/skills/a365-setup/SKILL.md |
Adds standalone setup workflow. |
plugins/agent365/skills/a365-code-validator/SKILL.md |
Adds standalone validation guidance. |
plugins/agent365/skills/a365-code-validator/references/a365-code-validator.js |
Adds standalone diagnostics. |
plugins/agent365/shared/copilot-sdk-standalone.md |
Defines the standalone onboarding contract. |
plugins/agent365/shared/agent-detection.md |
Adds SDK detection classification. |
plugins/agent365/plugin.json |
Adds Copilot-compatible manifest metadata. |
plugins/agent365/hooks/stop/validate-test-local.js |
Adds standalone test guards. |
plugins/agent365/hooks/stop/validate-make-ai-teammate.js |
Blocks teammate validation. |
plugins/agent365/hooks/stop/validate-make-a365-agent.js |
Validates standalone registration. |
plugins/agent365/hooks/stop/validate-instrument-observability.js |
Validates standalone telemetry. |
plugins/agent365/hooks/stop/validate-add-workiq-tools.js |
Blocks WorkIQ validation. |
plugins/agent365/hooks/stop/validate-a365-setup.js |
Adds report-only setup validation. |
plugins/agent365/hooks/stop/validate-a365-code-validator.js |
Extends SDK-specific validation. |
plugins/agent365/hooks/lib/copilot-sdk.js |
Implements shared SDK detection and checks. |
plugins/agent365/.claude-plugin/plugin.json |
Updates plugin metadata. |
evals/agent365/make-a365-agent/evals.json |
Adds registration evaluations. |
evals/agent365/instrument-observability/evals.json |
Adds observability evaluations. |
evals/agent365/a365-setup/evals.json |
Adds setup evaluations. |
CLAUDE.md |
Documents standalone routing. |
AGENTS.md |
Adds contributor guidance. |
.gitignore |
Ignores local SDK artifacts. |
.github/copilot-instructions.md |
Adds SDK instructions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+125
to
+128
| The final response MUST use exactly the shared three-paragraph template: | ||
| **Detected / preserved**, **Local evidence**, **Blocked / not verified**. | ||
| End after the report. Do not append a next-gate/next-steps section, an admin | ||
| handoff, command names/examples, or an offer/question requesting credentials. |
Comment on lines
+27
to
+32
| function snapshot(root) { | ||
| return fs.readdirSync(root, { recursive: true }).sort().map(relative => { | ||
| const file = path.join(root, relative); | ||
| return [relative, fs.statSync(file).isFile() ? fs.readFileSync(file, 'utf8') : null]; | ||
| }); | ||
| } |
Comment on lines
+28
to
+31
| const files = { | ||
| 'package.json': fs.readFileSync(path.join(FIXTURE, 'package.json'), 'utf8'), | ||
| 'src/index.ts': fs.readFileSync(path.join(FIXTURE, 'src', 'index.ts'), 'utf8'), | ||
| '.gitignore': fs.readFileSync(path.join(FIXTURE, '.gitignore'), 'utf8'), |
Comment on lines
+42
to
+43
| if (versions.some(version => typeof version !== 'string' || !EXACT_RELEASE.test(version))) { | ||
| issues.push('Pin @github/copilot-sdk to the verified exact published stable release; do not use ranges, prereleases, or local SDK builds'); |
| })) { | ||
| issues.push('A manifest is unreadable or declares M365 customEngineAgents; verify the conflicting artifact before standalone routing'); | ||
| } | ||
| if (sourceFiles.some(file => |
Comment on lines
+182
to
+184
| [/\buseS2SEndpoint\s*:\s*true\b/, 'explicit useS2SEndpoint: true for opt-in S2S export'], | ||
| [/\bif\s*\(\s*config\.exportToA365\s*\)/, 'exportToA365 guard around exporter creation'], | ||
| [/\bflag\s*\(\s*env\s*,\s*['"]ENABLE_A365_OBSERVABILITY_EXPORTER['"]\s*,\s*false\s*\)/, 'exporter opt-in environment gate defaulting to false'], |
Comment on lines
+262
to
+264
| const rootPackage = readJson(path.join(cwd, 'package.json')); | ||
| const isCopilotSdk = [rootPackage?.dependencies, rootPackage?.devDependencies] | ||
| .some(section => section && Object.hasOwn(section, '@github/copilot-sdk')); |
Comment on lines
+196
to
+198
| const rootPackage = readJsonSafe(path.join(cwd, 'package.json')); | ||
| const isCopilotSdk = [rootPackage?.dependencies, rootPackage?.devDependencies] | ||
| .some(section => section && Object.hasOwn(section, '@github/copilot-sdk')); |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Extends existing Agent 365 skills with guarded standalone TypeScript Copilot SDK onboarding, approval boundaries, report-only validation, telemetry diagnostics, and regression coverage. Companion sample is pending merge in microsoft/Agent365-Samples. This is not turnkey autonomous onboarding.