You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
My contribution adds a new instruction, prompt, agent, skill, workflow, or canvas extension file in the correct directory.
The file follows the required naming convention.
The content is clearly structured and follows the example format.
I have tested my instructions, prompt, agent, skill, workflow, or canvas extension with GitHub Copilot.
I have run npm start and verified that README.md is up to date.
I am targeting the main branch for this pull request.
Description
Triaging external plugin submissions means working through a lot of issues by hand: reading the automated intake signals, checking the linked repo, then posting /approve or /reject <reason>. This adds a maintainer-only, project-scoped Copilot canvas extension (.github/extensions/external-plugin-review-board) that turns that process into a kanban board.
Buckets: Unreviewed, Reviewing, Straight reject, Probably reject, Needs review, Accept, Actioned. Cards can be dragged between buckets or moved from the details panel.
Perform review: asks the agent to review every unreviewed submission against review-guidance.md (the maintainer's decision pattern, review procedure and bucket definitions) plus decisions already made from the board. Results come back through the record_review action.
Re-review: takes optional guidance from the maintainer (for example "check whether it makes outbound HTTP calls"). The agent runs the re-review in a separate sub-session, and the result is recorded on the card along with that guidance.
Refresh: re-fetches open external-plugin + ready-for-review issues and drops any that have closed.
Details panel: shows the AI review, the rendered issue body and its comments.
Quick decisions: posts /approve or /reject <reason> with gh after a confirm click. The reject reason is prefilled from the AI suggestion.
Type of Contribution
New instruction file.
New prompt file.
New agent file.
New plugin.
New skill file.
New agentic workflow.
New canvas extension.
Update to existing instruction, prompt, agent, plugin, skill, workflow, or canvas extension.
Other (please specify): repo-internal maintainer tooling (project-scoped extension under .github/extensions/, not a published plugin)
Additional Notes
Board state is kept locally in state/board.json next to the extension and is gitignored.
Requires an authenticated gh with write access, because the /approve and /reject commands are only honoured from maintainers.
The loopback server uses a per-instance token, a Host header check, CSP and a body size cap.
It is not part of extensions/ or plugins/, so no README or marketplace regeneration is needed.
By submitting this pull request, I confirm that my contribution abides by the Code of Conduct and will be licensed under the MIT License.
Project-scoped Copilot canvas for maintainers to triage external plugin
submissions: kanban buckets, AI review, guided re-review via sub-session,
refresh, issue/comments view, and quick /approve or /reject.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
- Remove the agent-facing post_decision action to block prompt-injected approvals/rejections
- Record opposite terminal labels as external GitHub decisions instead of reusing the pending command
- State visibly that a reject reason is required
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
queueId is the correlation token required by recordReviews, but the action schema marks it optional. A schema-valid agent result can therefore omit it and be skipped as stale, leaving the card queued indefinitely. Make the token required so the action invocation fails clearly before reaching state handling.
Require an active queue ID before accepting agent results
This check only rejects mismatches while the card still has a queue ID. Cancelling or manually moving a queued card deletes item.queueId, so the old agent result then bypasses this condition and is recorded, undoing the maintainer's move. Require an active queue ID as well as an exact match.
When issue loading fails, loadDetail stores { error: ... }. This expression then reads .length from an undefined comments property, so renderDrawer throws before renderTab can display the intended error notice. Optional-chain comments too.
This issue also appears on line 509 of the same file.
The card is focusable and handles Enter/Space as an activation control, but it retains the semantic role of an article. Screen-reader users are not told that focusing it exposes an actionable control. Give it button semantics (the Bucket select remains the non-drag move alternative).
Implement keyboard navigation and ARIA relationships for tabs
These controls declare the ARIA tab pattern, but the only interaction wired in app.js is click handling: there is no roving tabindex or Left/Right/Home/End keyboard navigation, and the tabs are not associated with the panel. Implement the standard tab keyboard/ARIA relationships, or keep them as ordinary buttons and remove the tab roles.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request Checklist
npm startand verified thatREADME.mdis up to date.mainbranch for this pull request.Description
Triaging external plugin submissions means working through a lot of issues by hand: reading the automated intake signals, checking the linked repo, then posting
/approveor/reject <reason>. This adds a maintainer-only, project-scoped Copilot canvas extension (.github/extensions/external-plugin-review-board) that turns that process into a kanban board.review-guidance.md(the maintainer's decision pattern, review procedure and bucket definitions) plus decisions already made from the board. Results come back through therecord_reviewaction.external-plugin+ready-for-reviewissues and drops any that have closed./approveor/reject <reason>withghafter a confirm click. The reject reason is prefilled from the AI suggestion.Type of Contribution
.github/extensions/, not a published plugin)Additional Notes
state/board.jsonnext to the extension and is gitignored.ghwith write access, because the/approveand/rejectcommands are only honoured from maintainers.extensions/orplugins/, so no README or marketplace regeneration is needed.By submitting this pull request, I confirm that my contribution abides by the Code of Conduct and will be licensed under the MIT License.