Skip to content

Add experimental standalone Copilot SDK onboarding - #85

Draft
Rick Brighenti (rbrighenti) wants to merge 2 commits into
mainfrom
rbrighenti-microsoft-copilot-sdk-onboarding-skill
Draft

Rick Brighenti (rbrighenti) wants to merge 2 commits into
mainfrom
rbrighenti-microsoft-copilot-sdk-onboarding-skill

Conversation

@rbrighenti

Copy link
Copy Markdown

Extends existing Agent 365 skills with guarded standalone TypeScript Copilot SDK onboarding, approval boundaries, report-only validation, telemetry diagnostics, and regression coverage. Companion sample is pending merge in microsoft/Agent365-Samples. This is not turnkey autonomous onboarding.

Extend existing skills with standalone detection, explicit approval gates, local-only report validation, and partial telemetry diagnostics. Add compatible plugin packaging and fixtures while preserving the existing runtime and hosting. Document experimental limits and the pending companion helper without operational trial history.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use approval-gated npm install for a fresh sample checkout, keep generated locks local, and document variable transitive resolutions with unchanged direct pins. Cover the bootstrap and registry-policy contract with a focused regression.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings September 28, 2026 13:25

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical Node 18 test compatibility and setup-flow issues remain, along with validation and routing gaps.

Review effort: Lite
Findings: 3 High severity · 5 Medium severity

Open (8)
What changed in this PR

Adds guarded experimental standalone TypeScript GitHub Copilot SDK onboarding for Agent 365, including routing, approval boundaries, report-only validation, telemetry diagnostics, documentation, and regression coverage.

Changes:

  • Adds standalone SDK detection, routing, validators, and hooks.
  • Adds documentation, manifests, fixtures, evaluations, and ignore rules.
  • Adds regression and parity tests.
File Summary
tests/​validate-a365-code-validator-parity.test.js Adds standalone validator parity coverage.
tests/​plugin-manifest.test.js Validates plugin manifests and guidance.
tests/​fixtures/​copilot-sdk/​src/​index.ts Adds SDK fixture source.
tests/​fixtures/​copilot-sdk/​package.json Adds fixture dependency metadata.
tests/​fixtures/​copilot-sdk/​.gitignore Ignores fixture-local artifacts.
tests/​copilot-sdk.test.js Tests SDK detection and routing.
tests/​copilot-sdk-hooks.test.js Tests hook validation boundaries.
README.md Documents experimental SDK onboarding.
plugins/​agent365/​skills/​test-local/​SKILL.md Adds standalone local-test guards.
plugins/​agent365/​skills/​make-ai-teammate/​SKILL.md Blocks incompatible teammate routing.
plugins/​agent365/​skills/​make-a365-agent/​SKILL.md Adds standalone registration guidance.
plugins/​agent365/​skills/​instrument-observability/​SKILL.md Adds standalone instrumentation guidance.
plugins/​agent365/​skills/​add-workiq-tools/​SKILL.md Blocks unsupported WorkIQ routing.
plugins/​agent365/​skills/​a365-setup/​SKILL.md Adds standalone setup workflow.
plugins/​agent365/​skills/​a365-code-validator/​SKILL.md Adds standalone validation guidance.
plugins/​agent365/​skills/​a365-code-validator/​references/​a365-code-validator.js Adds standalone diagnostics.
plugins/​agent365/​shared/​copilot-sdk-standalone.md Defines the standalone onboarding contract.
plugins/​agent365/​shared/​agent-detection.md Adds SDK detection classification.
plugins/​agent365/​plugin.json Adds Copilot-compatible manifest metadata.
plugins/​agent365/​hooks/​stop/​validate-test-local.js Adds standalone test guards.
plugins/​agent365/​hooks/​stop/​validate-make-ai-teammate.js Blocks teammate validation.
plugins/​agent365/​hooks/​stop/​validate-make-a365-agent.js Validates standalone registration.
plugins/​agent365/​hooks/​stop/​validate-instrument-observability.js Validates standalone telemetry.
plugins/​agent365/​hooks/​stop/​validate-add-workiq-tools.js Blocks WorkIQ validation.
plugins/​agent365/​hooks/​stop/​validate-a365-setup.js Adds report-only setup validation.
plugins/​agent365/​hooks/​stop/​validate-a365-code-validator.js Extends SDK-specific validation.
plugins/​agent365/​hooks/​lib/​copilot-sdk.js Implements shared SDK detection and checks.
plugins/​agent365/​.claude-plugin/​plugin.json Updates plugin metadata.
evals/​agent365/​make-a365-agent/​evals.json Adds registration evaluations.
evals/​agent365/​instrument-observability/​evals.json Adds observability evaluations.
evals/​agent365/​a365-setup/​evals.json Adds setup evaluations.
CLAUDE.md Documents standalone routing.
AGENTS.md Adds contributor guidance.
.gitignore Ignores local SDK artifacts.
.github/​copilot-instructions.md Adds SDK instructions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +125 to +128
The final response MUST use exactly the shared three-paragraph template:
**Detected / preserved**, **Local evidence**, **Blocked / not verified**.
End after the report. Do not append a next-gate/next-steps section, an admin
handoff, command names/examples, or an offer/question requesting credentials.
Comment on lines +27 to +32
function snapshot(root) {
return fs.readdirSync(root, { recursive: true }).sort().map(relative => {
const file = path.join(root, relative);
return [relative, fs.statSync(file).isFile() ? fs.readFileSync(file, 'utf8') : null];
});
}
Comment thread tests/copilot-sdk.test.js
Comment on lines +28 to +31
const files = {
'package.json': fs.readFileSync(path.join(FIXTURE, 'package.json'), 'utf8'),
'src/index.ts': fs.readFileSync(path.join(FIXTURE, 'src', 'index.ts'), 'utf8'),
'.gitignore': fs.readFileSync(path.join(FIXTURE, '.gitignore'), 'utf8'),
Comment on lines +42 to +43
if (versions.some(version => typeof version !== 'string' || !EXACT_RELEASE.test(version))) {
issues.push('Pin @github/copilot-sdk to the verified exact published stable release; do not use ranges, prereleases, or local SDK builds');
})) {
issues.push('A manifest is unreadable or declares M365 customEngineAgents; verify the conflicting artifact before standalone routing');
}
if (sourceFiles.some(file =>
Comment on lines +182 to +184
[/\buseS2SEndpoint\s*:\s*true\b/, 'explicit useS2SEndpoint: true for opt-in S2S export'],
[/\bif\s*\(\s*config\.exportToA365\s*\)/, 'exportToA365 guard around exporter creation'],
[/\bflag\s*\(\s*env\s*,\s*['"]ENABLE_A365_OBSERVABILITY_EXPORTER['"]\s*,\s*false\s*\)/, 'exporter opt-in environment gate defaulting to false'],
Comment on lines +262 to +264
const rootPackage = readJson(path.join(cwd, 'package.json'));
const isCopilotSdk = [rootPackage?.dependencies, rootPackage?.devDependencies]
.some(section => section && Object.hasOwn(section, '@github/copilot-sdk'));
Comment on lines +196 to +198
const rootPackage = readJsonSafe(path.join(cwd, 'package.json'));
const isCopilotSdk = [rootPackage?.dependencies, rootPackage?.devDependencies]
.some(section => section && Object.hasOwn(section, '@github/copilot-sdk'));
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants