Skip to content

Add agentctl for local Copilot custom-agent execution across repositories - #30

Merged
Daigrin merged 4 commits into
mainfrom
copilot/create-cli-tool-for-agents
Oct 5, 2026
Merged

Daigrin merged 4 commits into
mainfrom
copilot/create-cli-tool-for-agents

Conversation

Copilot AI commented Oct 3, 2026 •

Copy link
Copy Markdown

Summary

Add agentctl to invoke installed Copilot custom agents in explicitly selected local GitHub checkouts. Execution uses the real Copilot CLI—not simulated completions or cloud-session APIs.

Why

Provide reusable cross-repository agent invocation with verified checkout identity, explicit permissions, and honest subprocess results.

What changed

  • CLI: list, install, and run; help/version, multiline prompts, and mutually exclusive prompt-file input.
  • Execution: Validate Git root and origin; strip inherited Git overrides; forward terminal IO, cancellation, and native exit codes.
  • Profiles: Bundle nine repo-aware roles outside automatic discovery. Explicit installation supports dry-run, no-clobber, and safe --force replacement.
  • Documentation: Cover authentication, cross-repository usage, ErrorFixer with actual Actions logs, permissions, and quota limitations.
agentctl install reviewer --user
agentctl run reviewer --repo OWNER/REPO --path /absolute/checkout \
  --prompt "Review the selected files; report findings only."

MCP impact

  • No tool or API changes — existing MCP behavior remains unchanged.
  • Tool schema or behavior changed
  • New tool added

Prompts tested (tool changes only)

  • Not applicable; no MCP tool changes.

Security / limits

  • No security or limits impact
  • Auth / permissions considered — Copilot handles authentication and approvals. No blanket grants, automatic Git mutations, or retries; explicit grants are narrowly scoped.
  • Data exposure, filtering, or token/size limits considered — rooted profile writes reject symlink escapes; analysis profiles allow only read/search. Subscription quotas remain enforced; untrusted repository execution risks are documented.

Tool renaming

  • I am renaming tools as part of this PR (e.g. a part of a consolidation effort)
    • I have added the new tool aliases in deprecated_tool_aliases.go
  • I am not renaming tools as part of this PR — this adds a standalone command.

Note: if you're renaming tools, you must add the tool aliases. For more information on how to do so, please refer to the official docs.

Lint & tests

  • Linted locally with ./script/lint — invoked through sh; 0 issues.
  • Tested locally with ./script/test — invoked through sh; full race suite passed.

Uncached focused race tests, all three command builds, and offline CLI checks passed. Tests cover argv/cwd/IO, failures, cancellation, remote validation, injection-like inputs, and installation safety.

Secret scans were clean; CodeQL reported 0 alerts. Independent review found no remaining blockers. Automated review was unavailable; live Copilot authentication/model calls were not tested.

Docs

  • Not needed
  • Updated (README / docs / examples) — installation, profiles, two-repository examples, permissions, and limitations.

Copilot AI and others added 2 commits October 3, 2026 06:04
Co-authored-by: Daigrin <198701947+Daigrin@users.noreply.github.com>
Co-authored-by: Daigrin <198701947+Daigrin@users.noreply.github.com>
Copilot AI changed the title [WIP] Add CLI tool for invoking Copilot custom agents Add agentctl for local Copilot custom-agent execution across repositories Oct 3, 2026
Copilot AI requested a review from Daigrin October 3, 2026 06:10
…ol-for-agents

Co-authored-by: Daigrin <198701947+Daigrin@users.noreply.github.com>
@Daigrin
Daigrin marked this pull request as ready for review October 5, 2026 01:00
Copilot AI balanced review requested due to automatic review settings October 5, 2026 01:00
@Daigrin
Daigrin merged commit 609d0f8 into main Oct 5, 2026
16 of 18 checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Checkout validation has unresolved case-handling defects affecting valid origins and Git override isolation on Windows.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds a standalone agentctl command for safely running installed Copilot custom agents in validated local checkouts without changing MCP behavior.

Changes:

  • Adds checkout validation, subprocess execution, permissions, and exit handling.
  • Bundles nine installable custom-agent profiles.
  • Adds comprehensive tests and usage/security documentation.
File Description
cmd/​agentctl/​main.go Adds the executable entry point.
internal/​agentctl/​command.go Implements CLI commands and execution.
internal/​agentctl/​command_test.go Tests execution, validation, IO, and cancellation.
internal/​agentctl/​checkout.go Validates checkout paths and origins.
internal/​agentctl/​checkout_test.go Tests checkout and remote validation.
internal/​agentctl/​profiles.go Embeds and safely installs profiles.
internal/​agentctl/​profiles_test.go Tests profile installation and restrictions.
internal/​agentctl/​profiles/​coder.agent.md Defines the coding profile.
internal/​agentctl/​profiles/​errorfixer.agent.md Defines the error-fixing profile.
internal/​agentctl/​profiles/​issue-planner.agent.md Defines the issue-planning profile.
internal/​agentctl/​profiles/​researcher.agent.md Defines the research profile.
internal/​agentctl/​profiles/​reviewer.agent.md Defines the review profile.
internal/​agentctl/​profiles/​security-auditor.agent.md Defines the security-audit profile.
internal/​agentctl/​profiles/​summarizer.agent.md Defines the summarization profile.
internal/​agentctl/​profiles/​test-writer.agent.md Defines the test-writing profile.
internal/​agentctl/​profiles/​workflow-debugger.agent.md Defines the workflow-debugging profile.
download.md Documents installation, usage, permissions, and limitations.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +27 to +31
if path, ok := strings.CutPrefix(remote, "git@github.com:"); ok {
repo = path
} else {
u, err := url.Parse(remote)
if err != nil || u.Host != "github.com" || u.RawQuery != "" || u.Fragment != "" || u.RawPath != "" {
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants