config(mcp): allow the openhuman and opencompany repositories for Teeny - #189
Conversation
Update the pinned commit of the tinyagents submodule to incorporate the latest upstream changes. Auto-committed-on: macbook Co-authored-by: Medulla <medulla@tinyhumans.ai>
The MCP configuration now includes the openhuman and opencompany repositories alongside tinysweeper, enabling the Discord bot to access documentation and file bug reports for all three public product repositories. The comment clarifies that private repositories must remain off this list because the bearer token is shared with a server-wide service. Auto-committed-on: macbook Co-authored-by: Medulla <medulla@tinyhumans.ai>
Tiny Sweeper reviewTiny Sweeper reviewed this change across 6 lanes and found 0 active actionable findings. The configuration change is safe to merge. State: Ready for maintainer review Review snapshot
Completeness: Complete What changedExpanded the MCP repository allowlist to include tinyhumansai/openhuman and tinyhumansai/opencompany, while retaining the existing tinyhumansai/tinysweeper entry. Features
TestsNo supported feature-to-test mapping was produced. Test execution is not inferred. FindingsNo active actionable findings. Before mergeNone. Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
The worktree bootstrap moved the submodule pointer; this puts it back at what main records so the PR is the config change alone. Co-authored-by: Medulla <medulla@tinyhumans.ai>
Update the pinned commit for the tinyagents vendored dependency to incorporate upstream fixes and improvements. Auto-committed-on: macbook Co-authored-by: Medulla <medulla@tinyhumans.ai>
|
Understand this PR’s impact Explore downstream dependencies and potential security impact with Blast Radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe ChangesRepository access configuration
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Feature 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
A rabbit checked the repo gate Comment |
Co-authored-by: Medulla <medulla@tinyhumans.ai>
There was a problem hiding this comment.
tinysweeper found nothing blocking. Approving.
$0.0025 · 44,476 in / 1,484 out · 8,915 cached (20%) · ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash · 91 embedded
critique: $0.0007 · 12,211 in / 351 out · 2,025 cached (17%) · gpt-5.6-luna
security: $0.0017 · 26,995 in / 788 out · 3,562 cached (13%) · gpt-5.6-luna
description: $0.0001 · 3,555 in / 40 out · 3,328 cached (94%) · deepseek/deepseek-v4-flash
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c02421d5ad
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| @@ -1 +1 @@ | |||
| Subproject commit 44afb2e6884690a59eb43e268a09868a9852c410 | |||
| Subproject commit 27a3f39dc6d7db676efe58d0f7b89752a8ab4746 | |||
There was a problem hiding this comment.
Align the tinyagents submodule with Cargo's revision
This changes the submodule from 44afb2e6 back to the older 27a3f39d, even though both tinyagents dependencies and their lockfile entries remain pinned to 44afb2e6. Consequently, checkouts and repository indexing expose an outdated harness source tree while builds use a different revision, and this older pin predates the later v2.1.1/v2.1.2 updates visible in this repository's history. Keep the gitlink at 44afb2e6 or update Cargo.toml and Cargo.lock in the same coherent dependency change.
AGENTS.md reference: AGENTS.md:L28-L29
Useful? React with 👍 / 👎.
What changed
mcp.allowed_reposin the deployed.tinysweeper.tomlgainstinyhumansai/openhumanandtinyhumansai/opencompany, alongsidetinyhumansai/tinysweeper.Why
Teeny (the Discord bot, tinyhumansai/teeny-discord-bot) answers members' product questions through this MCP endpoint —
search_codeover the GitBooks/docs,search_issuesto spot known bugs,create_issuefor tickets — and #188's fail-closed allowlist (rightly) shut it out. Both product repositories are public. Teeny keeps its own client-side allowlist of exactly these two repositories, so the org-wide bearer never reaches a private repository from either side.The same edit has already been applied on the box (
/opt/tinysweeper/.tinysweeper.toml, server restarted, verified: openhuman/opencompany answer,tinyhumansai/backendis refused); this PR makesmainmatch it.Verification
cargo test --locked --features serve config::(config validation still accepts the file: exactowner/name, insideallowed_org, no duplicates)search_codeon both repositories returns hits; a repository off the list getsrepository is not in this MCP server's allowlistCo-authored-by: Medulla medulla@tinyhumans.ai
Summary by CodeRabbit