pilot(mcp): enable GitHub MCP secret-scanning for .github-private reviews (#681) - #757
Conversation
…iews (#681) Activates the opt-in MCP review knob (epic #676) on this repo as the #681 pilot: commits .github/review-mcp.json — the conventional path engine.sh auto-discovers — configuring GitHub's hosted MCP server (read-only secret_protection toolset). Auth uses the review job's existing GH_TOKEN via env expansion; no token is committed. Graceful degradation (#678) means a launch/auth failure is a ::warning:: + normal review, never a broken pipeline. Inert until REVIEW_MCP_ALLOWED_TOOLS is set and this lands on the running pr-review channel — see PR body. https://claude.ai/code/session_015VRMMWmqW9nW81jygmea3e
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
📝 WalkthroughWalkthroughA new ChangesMCP Server Configuration
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Possibly related issues
Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dev-Lead — waiting on PR blockers (intent: review-changes)PR: #757 |
|
Note @don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically. |
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
Dev-Lead — waiting on PR blockers (intent: review-changes)PR: #757 |
|
Note @don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically. |
Dev-Lead — review-changes (applied)Changes committed and pushed. |
Dev-Lead — waiting on PR blockers (intent: review-changes)PR: #757 |
|
Note @don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically. |
|
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
|
Manual step performed (variable set). Human approves. |



What
Activates the opt-in MCP review knob (epic #676) on this repo as the #681 pilot, using GitHub MCP secret-scanning (the security-first starter from the #650 weekly update). Adds
.github/review-mcp.json— the conventional pathengine.shauto-discovers (#679) — pointing at GitHub's hosted MCP server, read-onlysecret_protectiontoolset.{ "mcpServers": { "github": { "type": "http", "url": "https://api.githubcopilot.com/mcp/x/secret_protection/readonly", "headers": { "Authorization": "Bearer ${GH_TOKEN}" } } } }${GH_TOKEN}is expanded at review time from the review job's existing token (theDON_PETRY_BOT_GH_PAT_CLASSICPAT set atpr-review.ymljob level — not the ActionsGITHUB_TOKEN).secret_protection/readonly; reads secret-scanning signal, never writes.::warning::[mcp] …and the review continues normally — it cannot break the pipeline.test_engine_mcp.bats"MCP off by default" assertion (which expected this file to be absent) and wires the config path into the dev-lead test triggers.All three must be in place; order doesn't matter.
✅ Set the tools knob (repo variable) so the model may invoke the server's tools:
❌ Promote the review channel — REQUIRED, MANUAL. Reviews run
pr-review.yml@pr-review/stable(pinned viaagent_ref: pr-review/stable), sopr-review/stablemust point at a commit that has the MCP engine ([Phase 1] Thread an optional MCP config into the Claude agentic review tiers (engine.sh) #677–[Phase 2] Document recommended MCP servers per tech stack #680).v1.6.0is already burned on the wrong commit, so use1.6.1(or higher). ImmutablevX.Y.Ztags are never overwritten.pr-review/*namespace; CI/automation cannot push it.git show pr-review/stable:scripts/engine.sh | grep -q REVIEW_MCP_CONFIG && echo OKshould printOK.⏳ Merge this PR (CODEOWNER approval / admin).
Token scope — only if needed. The bot PAT already carries
repo(validated bypr-review.yml), so secret-scanning read should work. If the first MCP review emits::warning::[mcp] …, grantdonpetry-botrepo-Admin / org security-manager access + confirm the PAT'sreposcope, then re-promote.Measurement (the #681 deliverable)
daily-pr-review-health.yml); latency ~20–30s/PR; reviews currently use training-data + repo-local tools only.pr_review_health.sh(widerLOOKBACK_DAYS) for the latency/reliability delta + watch reviews for MCP-sourced secret findings → pilot note + go/no-go.Scope / safety
Pilot only — broader rollout is a separate, explicit human decision (#681). Target is
.github-privateitself (ring-0 self-host); graceful degradation bounds the blast radius.Refs: epic #676, story #681,
docs/initiatives/mcp-powered-review.md.Generated by Claude Code