Skip to content

question: v0.10.2 claude-args asymmetry — review lane lost inline-comment tool, security lane kept it #382

Description

@kyle-sexton

In v0.10.2, the review reusable's claude-args default REPLACED --allowedTools "mcp__github_inline_comment__create_inline_comment" with --allowedTools "Bash(gh pr diff:*)", while the security reusable's default ADDED the Bash grant alongside the inline-comment tool ("mcp__github_inline_comment__create_inline_comment,Bash(gh pr diff:*)").

Consequence: consumers inheriting defaults (all of them — claude-args is not caller-passable; allowedInputs excludes it) now have a review lane that cannot post inline comments while the security lane still can. If the asymmetry is intentional per the #355 decision, close this with a pointer; if not, the review lane default likely wants the inline-comment tool restored alongside the Bash grant.

Observed by the fresh-context merge verifier on melodic-software/claude-code-plugins#1990 during the fleet repin (sandbox, standards, and claude-code-plugins callers all inherit this now).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageNot yet classified. Floor until a type and one priority tier are set.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions