Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

`pull_request_review_write` combines create/submit/delete into one tool, making fine-grained permissions by method impossible

未關閉
#2,525 5 則留言 2 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

評估

難度
4/5
預估耗時
3-5 天
新手友好度
48/100
Issue 類型
功能
描述清晰度
基本清楚
活躍度
活躍
技術堆疊
github, go
領域
api, security, tooling

研究方向

從 tools.go 開始,特別查看對 FeatureFlagPullRequestsGranular 的參照以及 pull_request_review_write 的註冊;將它們與現有的細粒度 pull request 工具進行比較。確認如何讓 MCP 用戶端能夠區分 create、submit_pending 和 delete_pending,同時保留 feature flag 的行為。當權限層能夠分離這些操作,且測試或文件涵蓋由此產生的行為時,即表示完成。

由索引模型根據 Issue 內容生成。

描述

request ai review

Today the pull_request_review_write tool consolidates three distinct review operations behind a single tool name with a method enum:

  • create
  • submit_pending
  • delete_pending

The description is:

Create and/or submit, delete review of a pull request.
Available methods:

  • create: Create a new review of a pull request. If event parameter is provided, the review is submitted. If event is omitted, a pending review is created.
  • submit_pending: Submit an existing pending review of a pull request.
  • delete_pending: Delete an existing pending review of a pull request.

This consolidation plays nicely with context/token budgets, but it makes permissions in MCP clients effectively all-or-nothing for these three operations, because most clients (Claude Code, etc.) attach permissions at the tool name level, not on the method argument.

My use case

  • I want to always allow create for pending reviews, so the agent can open a pending review and add inline comments.
  • But I do not want the agent to be allowed to submit or delete reviews automatically; those should always require explicit human approval (or be disallowed entirely).

With the current API surface, the client can't express this as:

  • allow: create_pending_review
  • ask/deny: submit_pending_review
  • ask/deny: delete_pending_review

because all three are encoded as pull_request_review_write with different method values. There's no way to distinguish them in a tool-level permission model.

Request

Please provide a way to make these operations distinguishable at the tool/permission layer. A few possible approaches:

1. Split into separate tools (preferred for permissioning)

For example:

  • create_pending_pull_request_review
  • submit_pending_pull_request_review
  • delete_pending_pull_request_review

This would let MCP clients and policy engines attach different permissions to creation vs submission/deletion, while still sharing implementation internally.

2. Add a server-side permission hint or annotation per method

If full tool splitting is not desirable, consider some form of metadata/annotation that lets clients understand that:

  • method: "create" (without event) is "low-risk, pending-only"
  • method: "submit_pending" and method: "delete_pending" are "higher-risk, finalizing/destructive"

so they can enforce stricter prompts or denials for the latter two, even under a single tool name.

3. At minimum, document the permissioning implications

A note in the README or docs that "if your client permission model is per-tool-name, you cannot allow create while denying submit_pending/delete_pending" would help users reason about the tradeoff.

Why this matters

There's a meaningful security and UX distinction between:

  • letting an agent open a pending review and propose comments, versus
  • letting an agent actually submit or delete reviews without human oversight.

Right now, clients that operate at the MCP tool level either have to:

  • allow all three (create + submit_pending + delete_pending), or
  • prompt/deny all three,

which removes a useful "middle ground" of: always allow pending review creation, but gate final submission/deletion.

A small API surface adjustment (or richer annotations) would make it much easier for clients to implement that pattern.

Related

  • FeatureFlagPullRequestsGranular already exists in the codebase as a feature flag for splitting granular PR tools — this issue is in the same spirit for the review write path.
  • The tools.go comment mentions: // Granular pull request tools (feature-flagged, replace consolidated update_pull_request/pull_request_review_write), suggesting this split has already been considered.
主要語言
Go
星號
33.1k
分支
5k
平均合併
2 天 3 小時
30 天內合併 PR
18

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

github/github-mcp-server 的其他 Issue

查看 github/github-mcp-server 的全部 Issue

相似的 Issue

更多 Go Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。