Skip to content

Focus automatic review on security risk - #566

Draft
fazxes wants to merge 4 commits into
mainfrom
fazxes/auto-review-context
Draft

Focus automatic review on security risk#566
fazxes wants to merge 4 commits into
mainfrom
fazxes/auto-review-context

Conversation

@fazxes

@fazxes fazxes commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Review ordinary actions in auto mode for concrete security danger without task text.
  • Include bounded root request context for destructive, dynamic-tool, and subagent reviews.
  • Keep hidden execution, credential access, injected commands, unsafe deletion, and mismatched dynamic calls on the caution path.
  • Preserve exact-action authority, one reviewer call, and agent recovery without opening a permission prompt.

Review ordinary actions without task text while preserving bounded root context for destructive, dynamic, and delegated actions.
@fazxes fazxes added the type: improvement Improves existing user-facing behavior label Sep 1, 2026
@vercel-security-reviewer

Copy link
Copy Markdown

Assert the normal review view omits root task text for external file mutations.
Assert normal reviews omit root task text across file and command permission flows.
@fazxes
fazxes marked this pull request as ready for review September 1, 2026 16:03
@fazxes
fazxes marked this pull request as draft September 1, 2026 16:06
Route destructive markers hidden by shell syntax or wrappers through contextual automatic review.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: improvement Improves existing user-facing behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant