ai : do not run bash commands in the prompt (#20810)

This commit is contained in:
Georgi Gerganov 2026-03-20 19:06:33 +02:00 committed by GitHub
parent 58c81f7e81
commit b31b30f31d
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 5 additions and 6 deletions

View File

@ -26,7 +26,8 @@ jobs:
{
"bash": {
"*": "deny",
"gh issue*": "allow"
"gh issue*": "allow",
"gh search*": "allow"
},
"webfetch": "deny"
}
@ -38,11 +39,9 @@ jobs:
Issue number: ${{ github.event.issue.number }}
Lookup the contents of the issue using the following `gh` command:
Lookup the contents of the issue using the following 'gh' command:
```bash
gh issue view ${{ github.event.issue.number }} --json title,body,url,number
```
Next, perform the following task and then post a SINGLE comment (if needed).
@ -50,7 +49,7 @@ jobs:
TASK : FIND RELATED ISSUES
Using the `gh` CLI tool, search through existing issues on Github.
Using the 'gh' CLI tool, search through existing issues on Github.
Find related or similar issues to the newly created one and list them.
Do not list the new issue itself (it is #${{ github.event.issue.number }}).
@ -83,5 +82,5 @@ jobs:
- Do not include the comment tags in your actual comment.
- Post at most ONE comment combining all findings.
- If you didn't find issues that are related enough, post nothing.
- You have access only to the `gh` CLI tool - don't try to use other tools.
- You have access only to the 'gh' CLI tool - don't try to use other tools.
"