Repository navigation
ci: rebuild the review tier like diagnose, posting as the Louise agent app - #21
Merged
Merged
Conversation
…t app - The reviewer agent gets no shell. A workflow step collects the pull request and its diff into files; the agent writes its review to one file. This closes the review tier's copies of the holes the adversarial review found in diagnose: `git log --output` and a second `--body-file`. - A second job, on a fresh runner, refuses a review with a credential in it, then edits this poster's earlier Louise review or posts one, as bowenlabs-louise-agent with a token narrowed to pull-request write on the one repository. Without the app it falls back to github-actions[bot]. - The Louise agent app's own pull requests are reviewed; other bots are still skipped. - Background tasks off, and the agent told to wait for its subagent. - The fix tier's agent no longer writes its own closing keyword, which duplicated the one the workflow adds (bowenlabs/ghostfire.coffee#52). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
bowenforsoup
added a commit
to bowenlabs/louise-toolkit
that referenced
this pull request
Sep 29, 2026
Passes `LOUISE_AGENT_APP_ID` and `LOUISE_AGENT_APP_PRIVATE_KEY` to the review workflow, which bowenlabs/claude-plugins#21 rebuilt. Part of bowenlabs/louise-ops#8. - **Who posts:** the Louise review now comes from `bowenlabs-louise-agent[bot]` rather than `github-actions[bot]`. - **How:** the reviewer agent works without a shell, and a separate job posts its review with a token narrowed to pull-request write on this repository. This PR tests itself: its own review runs with this version of the caller, so it should get a review comment from the app. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
bowenforsoup
added a commit
to bowenlabs/astroidjs
that referenced
this pull request
Sep 29, 2026
Passes `LOUISE_AGENT_APP_ID` and `LOUISE_AGENT_APP_PRIVATE_KEY` to the review workflow, which bowenlabs/claude-plugins#21 rebuilt. Part of bowenlabs/louise-ops#8. - **Who posts:** the Louise review now comes from `bowenlabs-louise-agent[bot]` rather than `github-actions[bot]`. - **How:** the reviewer agent works without a shell, and a separate job posts its review with a token narrowed to pull-request write on this repository. This PR tests itself: its own review runs with this version of the caller, so it should get a review comment from the app. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rebuilds
louise-review.ymlthe waylouise-diagnose.ymlnow works, so review comments come frombowenlabs-louise-agent[bot]instead ofgithub-actions[bot]..louise/.louise:revieweragent reads those and the checkout, and asks Louise. It writes.louise/review.mdand nothing else.Bash(git log:*)accepting--output, andgh pr comment … --body-fileaccepting a second--body-file.postjob refuses a review that contains a credential.<!-- louise-review -->comment, or posts a new one.github-actions[bot]without the app.Backward compatible: the new
agent_app_idinput andagent_app_private_keysecret are optional. Callers that don't pass them keep posting asgithub-actions[bot]until their caller PRs add both.On first run in each repository: the old
github-actions[bot]review comment stays in place, since the app can't edit it, and the app posts its own comment beside it. From then on, the app edits its own comment.Checks: Vale reports 0 errors,
claude plugin validatepasses, and the workflow parses.🤖 Generated with Claude Code