Skip to content

ci: rebuild the review tier like diagnose, posting as the Louise agent app - #21

Merged
bowenforsoup merged 1 commit into
mainfrom
ci/review-as-app
Sep 29, 2026
Merged

bowenforsoup merged 1 commit into
mainfrom
ci/review-as-app

Conversation

@bowenforsoup

Copy link
Copy Markdown
Member

Rebuilds louise-review.yml the way louise-diagnose.yml now works, so review comments come from bowenlabs-louise-agent[bot] instead of github-actions[bot].

  • No shell for the agent.
    • A workflow step collects the PR's title, body, author, branches, files, commit headlines, and diff into .louise/.
    • The louise:reviewer agent reads those and the checkout, and asks Louise. It writes .louise/review.md and nothing else.
    • This closes the review tier's copies of two holes the adversarial review found in diagnose: Bash(git log:*) accepting --output, and gh pr comment … --body-file accepting a second --body-file.
  • Posting from a fresh runner.
    • The post job refuses a review that contains a credential.
    • It edits this poster's earlier <!-- louise-review --> comment, or posts a new one.
    • It posts as the app, with a token narrowed to pull-request write on the one repository, and falls back to github-actions[bot] without the app.
  • Reviews the app's own PRs. Other bots are still skipped. bowenlabs/ghostfire.coffee#52 had no review because it came from the app.
  • Waits for the subagent. Background tasks are off, the same fix as fix(ci): wait for the subagent in the agent tiers #20.
  • One fix-tier change: the agent no longer writes its own closing keyword, which duplicated the workflow's.

Backward compatible: the new agent_app_id input and agent_app_private_key secret are optional. Callers that don't pass them keep posting as github-actions[bot] until their caller PRs add both.

On first run in each repository: the old github-actions[bot] review comment stays in place, since the app can't edit it, and the app posts its own comment beside it. From then on, the app edits its own comment.

Checks: Vale reports 0 errors, claude plugin validate passes, and the workflow parses.

🤖 Generated with Claude Code

…t app

- The reviewer agent gets no shell. A workflow step collects the pull
  request and its diff into files; the agent writes its review to one file.
  This closes the review tier's copies of the holes the adversarial review
  found in diagnose: `git log --output` and a second `--body-file`.
- A second job, on a fresh runner, refuses a review with a credential in
  it, then edits this poster's earlier Louise review or posts one, as
  bowenlabs-louise-agent with a token narrowed to pull-request write on the
  one repository. Without the app it falls back to github-actions[bot].
- The Louise agent app's own pull requests are reviewed; other bots are
  still skipped.
- Background tasks off, and the agent told to wait for its subagent.
- The fix tier's agent no longer writes its own closing keyword, which
  duplicated the one the workflow adds (bowenlabs/ghostfire.coffee#52).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@bowenforsoup
bowenforsoup merged commit dc08f0b into main Sep 29, 2026
2 checks passed
@bowenforsoup
bowenforsoup deleted the ci/review-as-app branch September 29, 2026 01:03
bowenforsoup added a commit to bowenlabs/louise-toolkit that referenced this pull request Sep 29, 2026
Passes `LOUISE_AGENT_APP_ID` and `LOUISE_AGENT_APP_PRIVATE_KEY` to the
review workflow, which bowenlabs/claude-plugins#21 rebuilt. Part of
bowenlabs/louise-ops#8.

- **Who posts:** the Louise review now comes from
`bowenlabs-louise-agent[bot]` rather than `github-actions[bot]`.
- **How:** the reviewer agent works without a shell, and a separate job
posts its review with a token narrowed to pull-request write on this
repository.

This PR tests itself: its own review runs with this version of the
caller, so it should get a review comment from the app.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
bowenforsoup added a commit to bowenlabs/astroidjs that referenced this pull request Sep 29, 2026
Passes `LOUISE_AGENT_APP_ID` and `LOUISE_AGENT_APP_PRIVATE_KEY` to the
review workflow, which bowenlabs/claude-plugins#21 rebuilt. Part of
bowenlabs/louise-ops#8.

- **Who posts:** the Louise review now comes from
`bowenlabs-louise-agent[bot]` rather than `github-actions[bot]`.
- **How:** the reviewer agent works without a shell, and a separate job
posts its review with a token narrowed to pull-request write on this
repository.

This PR tests itself: its own review runs with this version of the
caller, so it should get a review comment from the app.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant