Skip to content

Add external plugin review board canvas for maintainers - #4174

Merged
aaronpowell merged 3 commits into
mainfrom
aaronpowell-external-plugin-review
Sep 30, 2026
Merged

aaronpowell merged 3 commits into
mainfrom
aaronpowell-external-plugin-review

Conversation

@aaronpowell

Copy link
Copy Markdown
Contributor

Pull Request Checklist

  • I have read and followed the CONTRIBUTING.md guidelines.
  • I have read and followed the Guidance for submissions involving paid services.
  • My contribution adds a new instruction, prompt, agent, skill, workflow, or canvas extension file in the correct directory.
  • The file follows the required naming convention.
  • The content is clearly structured and follows the example format.
  • I have tested my instructions, prompt, agent, skill, workflow, or canvas extension with GitHub Copilot.
  • I have run npm start and verified that README.md is up to date.
  • I am targeting the main branch for this pull request.

Description

Triaging external plugin submissions means working through a lot of issues by hand: reading the automated intake signals, checking the linked repo, then posting /approve or /reject <reason>. This adds a maintainer-only, project-scoped Copilot canvas extension (.github/extensions/external-plugin-review-board) that turns that process into a kanban board.

  • Buckets: Unreviewed, Reviewing, Straight reject, Probably reject, Needs review, Accept, Actioned. Cards can be dragged between buckets or moved from the details panel.
  • Perform review: asks the agent to review every unreviewed submission against review-guidance.md (the maintainer's decision pattern, review procedure and bucket definitions) plus decisions already made from the board. Results come back through the record_review action.
  • Re-review: takes optional guidance from the maintainer (for example "check whether it makes outbound HTTP calls"). The agent runs the re-review in a separate sub-session, and the result is recorded on the card along with that guidance.
  • Refresh: re-fetches open external-plugin + ready-for-review issues and drops any that have closed.
  • Details panel: shows the AI review, the rendered issue body and its comments.
  • Quick decisions: posts /approve or /reject <reason> with gh after a confirm click. The reject reason is prefilled from the AI suggestion.

Type of Contribution

  • New instruction file.
  • New prompt file.
  • New agent file.
  • New plugin.
  • New skill file.
  • New agentic workflow.
  • New canvas extension.
  • Update to existing instruction, prompt, agent, plugin, skill, workflow, or canvas extension.
  • Other (please specify): repo-internal maintainer tooling (project-scoped extension under .github/extensions/, not a published plugin)

Additional Notes

  • Board state is kept locally in state/board.json next to the extension and is gitignored.
  • Requires an authenticated gh with write access, because the /approve and /reject commands are only honoured from maintainers.
  • The loopback server uses a per-instance token, a Host header check, CSP and a body size cap.
  • It is not part of extensions/ or plugins/, so no README or marketplace regeneration is needed.

By submitting this pull request, I confirm that my contribution abides by the Code of Conduct and will be licensed under the MIT License.

Project-scoped Copilot canvas for maintainers to triage external plugin
submissions: kanban buckets, AI review, guided re-review via sub-session,
refresh, issue/comments view, and quick /approve or /reject.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 29, 2026 05:16
@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

🟡 Contributor Reputation Check: MEDIUM risk

Check Risk
Profile MEDIUM
Credential audit NONE

Maintainers: please review this contributor before merging.
See the workflow run for full details.
Automated check powered by AGT.

@github-actions github-actions Bot added the needs-review:MEDIUM Contributor reputation check flagged MEDIUM risk label Sep 29, 2026
Comment thread .github/extensions/external-plugin-review-board/lib/server.mjs Fixed

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Decision outcomes can be misreported, review jobs can duplicate or race, and the privileged UI has unresolved security and policy issues.

Review effort: Balanced
Findings: 2 High severity · 7 Medium severity

Open (9)
What changed in this PR

Adds a project-scoped maintainer canvas for reviewing and actioning external plugin submissions.

Changes:

  • Adds a kanban UI with issue details and decision controls.
  • Implements persistent state, GitHub CLI integration, and a loopback server.
  • Adds AI review/re-review prompts and maintainer guidance.
File Description
.gitignore Excludes local board state.
review-guidance.md Defines review criteria and buckets.
README.md Documents usage and requirements.
public/​styles.css Styles the board and drawer.
public/​index.html Defines the board UI.
public/​app.js Implements client interactions and updates.
lib/​state.mjs Persists board and review state.
lib/​server.mjs Serves the authenticated local UI/API.
lib/​review-prompt.mjs Builds AI review prompts.
lib/​github.mjs Wraps GitHub CLI operations.
extension.mjs Registers the canvas and coordinates workflows.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/extensions/external-plugin-review-board/lib/server.mjs Outdated
Comment thread .github/extensions/external-plugin-review-board/lib/state.mjs
Comment thread .github/extensions/external-plugin-review-board/extension.mjs Outdated
Comment thread .github/extensions/external-plugin-review-board/extension.mjs
Comment thread .github/extensions/external-plugin-review-board/extension.mjs Outdated
Comment thread .github/extensions/external-plugin-review-board/lib/state.mjs Outdated
Comment thread .github/extensions/external-plugin-review-board/public/app.js
Comment thread .github/extensions/external-plugin-review-board/public/app.js
Comment thread .github/extensions/external-plugin-review-board/review-guidance.md Outdated
- Deny framing and hide stack traces from API error responses
- Track review queue ids, restore queue state on send failure, skip queued items
- Require reject reasons; treat posted decisions as pending until the workflow closes the issue
- Invalidate browser issue cache on refresh
- Clarify paid-services guidance

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 29, 2026 06:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread .github/extensions/external-plugin-review-board/extension.mjs Outdated
Comment thread .github/extensions/external-plugin-review-board/lib/state.mjs Outdated
Comment thread .github/extensions/external-plugin-review-board/public/index.html Outdated
- Remove the agent-facing post_decision action to block prompt-injected approvals/rejections
- Record opposite terminal labels as external GitHub decisions instead of reusing the pending command
- State visibly that a reject reason is required

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 29, 2026 09:09

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Stale reviews can overwrite cancelled work, decision commands can be duplicated, and several UI error and accessibility paths need correction.

Review effort: Balanced
Findings: None

Resolved since last review (3)
Previously missed (5)

In code that hasn't changed since last review

Medium severity Require queueId in the agent action schema

.github/​extensions/​external-plugin-review-board/​lib/​review-prompt.mjs:4

queueId is the correlation token required by recordReviews, but the action schema marks it optional. A schema-valid agent result can therefore omit it and be skipped as stale, leaving the card queued indefinitely. Make the token required so the action invocation fails clearly before reaching state handling.

Medium severity Require an active queue ID before accepting agent results

.github/​extensions/​external-plugin-review-board/​lib/​state.mjs:200

This check only rejects mismatches while the card still has a queue ID. Cancelling or manually moving a queued card deletes item.queueId, so the old agent result then bypasses this condition and is recorded, undoing the maintainer's move. Require an active queue ID as well as an exact match.

Medium severity Guard missing comments when rendering load errors

.github/​extensions/​external-plugin-review-board/​public/​app.js:316

When issue loading fails, loadDetail stores { error: ... }. This expression then reads .length from an undefined comments property, so renderDrawer throws before renderTab can display the intended error notice. Optional-chain comments too.

This issue also appears on line 509 of the same file.

Low severity Use button semantics for the actionable card

.github/​extensions/​external-plugin-review-board/​public/​app.js:194

The card is focusable and handles Enter/Space as an activation control, but it retains the semantic role of an article. Screen-reader users are not told that focusing it exposes an actionable control. Give it button semantics (the Bucket select remains the non-drag move alternative).

Low severity Implement keyboard navigation and ARIA relationships for tabs

.github/​extensions/​external-plugin-review-board/​public/​index.html:63

These controls declare the ARIA tab pattern, but the only interaction wired in app.js is click handling: there is no roving tabindex or Left/Right/Home/End keyboard navigation, and the tabs are not associated with the panel. Implement the standard tab keyboard/ARIA relationships, or keep them as ordinary buttons and remove the tab roles.

@aaronpowell
aaronpowell merged commit e62be96 into main Sep 30, 2026
25 of 26 checks passed
@aaronpowell
aaronpowell deleted the aaronpowell-external-plugin-review branch September 30, 2026 06:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-review:MEDIUM Contributor reputation check flagged MEDIUM risk

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants