Skip to content

Disclose Copilot authorship on expert reviewer comments - #8819

Merged
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution
Jun 5, 2026
Merged

Disclose Copilot authorship on expert reviewer comments#8819
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution

Conversation

@Evangelink

Copy link
Copy Markdown
Member

What & why

The expert-reviewer agentic workflow posts reviews via gh-aw safe-output tools that use a maintainer's PAT (COPILOT_GITHUB_TOKEN). As a result, every add_comment, create_pull_request_review_comment, and submit_pull_request_review call shows the maintainer's avatar and username — with no way for readers to tell the content was authored by Copilot rather than by the human whose account they see.

This PR adds an explicit disclosure so the authorship is clear.

Change

  1. .github/agents/expert-reviewer.agent.md

    • New Absolute Rule Bug Fix #258333 : Tests running multiple times in case we have multiple test projects #4 mandating the attribution banner.
    • New ## Copilot Attribution Banner section defining the verbatim banner with a <workflow-run-url> placeholder.
    • Wave 3 step 5 (add_comment) and Wave 4 step 6 (submit_pull_request_review) updated to require the banner at the top of each body. Both example bodies in step 6 now show the banner.
    • Wave 3 step 4 (inline comments) explicitly says no per-comment footer — inline comments are bundled into the Wave 4 review whose body already carries the banner, and gh-aw's shared/formatting.md already appends an automatic footer that we should not duplicate.
  2. .github/workflows/shared/review-shared.md

    • Step 2 of ## Instructions: the orchestrator now forwards the workflow run URL (${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}) to the subagent prompt and references the new banner section. Without this forwarding, the subagent (a background task) has no access to the parent <github-context> block and could not populate the link.

Resulting banner

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Validation

  • gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 3 workflow(s), 0 errors, 0 warnings.
  • No lockfile regenerations were needed for this change: the agent file is loaded at runtime by the subagent (not embedded into the lock), and shared/review-shared.md is pulled in via {{#runtime-import}} rather than inlined. Local strict-compile did surface unrelated SHA-pin regressions in the lock files (likely a local compiler-version artifact) — those were reverted to keep this PR scoped to the disclosure change.

The expert-reviewer agent posts reviews via gh-aw safe-output tools that
use a maintainer's PAT (COPILOT_GITHUB_TOKEN), so every comment appears
under that maintainer's avatar and username. Readers currently have no
way to tell the content was authored by Copilot rather than the human
whose account they see.
Add a mandatory attribution banner at the top of every add_comment body
and every submit_pull_request_review body, with a link back to the
generating workflow run so anyone can audit it. The orchestrator now
forwards the workflow run URL to the subagent so the banner link
resolves.
Inline review comments still get no per-comment footer: they are
bundled into the Wave 4 review whose body already carries the banner,
and gh-aw's formatting shared fragment already appends an automatic
attribution footer that we should not duplicate.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 4, 2026 11:23

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR improves transparency for the repository’s “expert-reviewer” agentic workflow by requiring an explicit “authored by GitHub Copilot” disclosure in posted PR comments and review bodies, clarifying that content is published via a maintainer PAT and may otherwise be mistaken for human-written feedback.

Changes:

  • Added a mandatory Copilot attribution banner (with a workflow-run URL placeholder) to the expert reviewer agent definition and required it at the start of add_comment and submit_pull_request_review bodies.
  • Clarified that inline comments (create_pull_request_review_comment) should not add per-comment attribution, since they’re bundled into the final review and gh-aw already appends its own footer attribution.
  • Updated the shared review workflow instructions to forward the workflow run URL into the subagent prompt so it can populate the banner link.
Show a summary per file
FileDescription
.github/workflows/shared/review-shared.mdInstructs the orchestrator to pass the workflow run URL to the expert-reviewer subagent so it can link the disclosure banner to the originating run.
.github/agents/expert-reviewer.agent.mdDefines the required Copilot attribution banner and enforces its inclusion at the start of posted top-level comments and the submitted review body.

Copilot's findings

  • Files reviewed: 2/2 changed files
  • Comments generated: 2

Comment thread.github/workflows/shared/review-shared.md Outdated
Comment thread.github/agents/expert-reviewer.agent.md Outdated
Two clarifications:
- expert-reviewer.agent.md: spell out a full fallback banner variant for
the case where the orchestrator does not supply a workflow run URL,
instead of telling the agent to `omit the parenthesized link'' (which
would have left dangling markdown like `[Expert Code Review
workflow]()`). The fallback drops the entire `Generated by ...''
sentence so the rendered markdown stays valid.
- shared/review-shared.md: tighten the rationale for forwarding the
workflow run URL. The URL is needed for the banner that goes on
add_comment and submit_pull_request_review bodies only; inline
create_pull_request_review_comment bodies inherit the banner from the
bundled review and do not carry it themselves.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@Evangelink

Copy link
Copy Markdown
MemberAuthor

Addressed both review comments in 3ed7f9f:

  1. .github/agents/expert-reviewer.agent.md (line 36 comment) — replaced the ambiguous "omit the parenthesized link and keep the rest of the banner" guidance with an explicit, verbatim fallback banner that drops the whole "Generated by …" sentence, so the rendered markdown stays valid when no run URL is available.
  2. .github/workflows/shared/review-shared.md (line 42 comment) — tightened the rationale to clarify the URL is needed for the banner on add_comment and submit_pull_request_review bodies only; inline create_pull_request_review_comment bodies inherit the banner from the bundled review and do not carry it themselves.

Strict compile still clean: gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 0 errors, 0 warnings.

@Evangelink
Amaury Levé (Evangelink) merged commit 494227e into microsoft:mainJun 5, 2026
32 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/expert-reviewer-copilot-attribution branch June 5, 2026 07:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@JanKrivanek
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Disclose Copilot authorship on expert reviewer comments by Evangelink · Pull Request #8819 · microsoft/testfx · GitHub
Skip to content

Disclose Copilot authorship on expert reviewer comments - #8819

Merged
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution
Jun 5, 2026
Merged

Disclose Copilot authorship on expert reviewer comments#8819
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution

Conversation

@Evangelink

Copy link
Copy Markdown
Member

What & why

The expert-reviewer agentic workflow posts reviews via gh-aw safe-output tools that use a maintainer's PAT (COPILOT_GITHUB_TOKEN). As a result, every add_comment, create_pull_request_review_comment, and submit_pull_request_review call shows the maintainer's avatar and username — with no way for readers to tell the content was authored by Copilot rather than by the human whose account they see.

This PR adds an explicit disclosure so the authorship is clear.

Change

  1. .github/agents/expert-reviewer.agent.md

    • New Absolute Rule Bug Fix #258333 : Tests running multiple times in case we have multiple test projects #4 mandating the attribution banner.
    • New ## Copilot Attribution Banner section defining the verbatim banner with a <workflow-run-url> placeholder.
    • Wave 3 step 5 (add_comment) and Wave 4 step 6 (submit_pull_request_review) updated to require the banner at the top of each body. Both example bodies in step 6 now show the banner.
    • Wave 3 step 4 (inline comments) explicitly says no per-comment footer — inline comments are bundled into the Wave 4 review whose body already carries the banner, and gh-aw's shared/formatting.md already appends an automatic footer that we should not duplicate.
  2. .github/workflows/shared/review-shared.md

    • Step 2 of ## Instructions: the orchestrator now forwards the workflow run URL (${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}) to the subagent prompt and references the new banner section. Without this forwarding, the subagent (a background task) has no access to the parent <github-context> block and could not populate the link.

Resulting banner

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Validation

  • gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 3 workflow(s), 0 errors, 0 warnings.
  • No lockfile regenerations were needed for this change: the agent file is loaded at runtime by the subagent (not embedded into the lock), and shared/review-shared.md is pulled in via {{#runtime-import}} rather than inlined. Local strict-compile did surface unrelated SHA-pin regressions in the lock files (likely a local compiler-version artifact) — those were reverted to keep this PR scoped to the disclosure change.

The expert-reviewer agent posts reviews via gh-aw safe-output tools that
use a maintainer's PAT (COPILOT_GITHUB_TOKEN), so every comment appears
under that maintainer's avatar and username. Readers currently have no
way to tell the content was authored by Copilot rather than the human
whose account they see.
Add a mandatory attribution banner at the top of every add_comment body
and every submit_pull_request_review body, with a link back to the
generating workflow run so anyone can audit it. The orchestrator now
forwards the workflow run URL to the subagent so the banner link
resolves.
Inline review comments still get no per-comment footer: they are
bundled into the Wave 4 review whose body already carries the banner,
and gh-aw's formatting shared fragment already appends an automatic
attribution footer that we should not duplicate.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 4, 2026 11:23

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR improves transparency for the repository’s “expert-reviewer” agentic workflow by requiring an explicit “authored by GitHub Copilot” disclosure in posted PR comments and review bodies, clarifying that content is published via a maintainer PAT and may otherwise be mistaken for human-written feedback.

Changes:

  • Added a mandatory Copilot attribution banner (with a workflow-run URL placeholder) to the expert reviewer agent definition and required it at the start of add_comment and submit_pull_request_review bodies.
  • Clarified that inline comments (create_pull_request_review_comment) should not add per-comment attribution, since they’re bundled into the final review and gh-aw already appends its own footer attribution.
  • Updated the shared review workflow instructions to forward the workflow run URL into the subagent prompt so it can populate the banner link.
Show a summary per file
FileDescription
.github/workflows/shared/review-shared.mdInstructs the orchestrator to pass the workflow run URL to the expert-reviewer subagent so it can link the disclosure banner to the originating run.
.github/agents/expert-reviewer.agent.mdDefines the required Copilot attribution banner and enforces its inclusion at the start of posted top-level comments and the submitted review body.

Copilot's findings

  • Files reviewed: 2/2 changed files
  • Comments generated: 2

Comment thread.github/workflows/shared/review-shared.md Outdated
Comment thread.github/agents/expert-reviewer.agent.md Outdated
Two clarifications:
- expert-reviewer.agent.md: spell out a full fallback banner variant for
the case where the orchestrator does not supply a workflow run URL,
instead of telling the agent to `omit the parenthesized link'' (which
would have left dangling markdown like `[Expert Code Review
workflow]()`). The fallback drops the entire `Generated by ...''
sentence so the rendered markdown stays valid.
- shared/review-shared.md: tighten the rationale for forwarding the
workflow run URL. The URL is needed for the banner that goes on
add_comment and submit_pull_request_review bodies only; inline
create_pull_request_review_comment bodies inherit the banner from the
bundled review and do not carry it themselves.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@Evangelink

Copy link
Copy Markdown
MemberAuthor

Addressed both review comments in 3ed7f9f:

  1. .github/agents/expert-reviewer.agent.md (line 36 comment) — replaced the ambiguous "omit the parenthesized link and keep the rest of the banner" guidance with an explicit, verbatim fallback banner that drops the whole "Generated by …" sentence, so the rendered markdown stays valid when no run URL is available.
  2. .github/workflows/shared/review-shared.md (line 42 comment) — tightened the rationale to clarify the URL is needed for the banner on add_comment and submit_pull_request_review bodies only; inline create_pull_request_review_comment bodies inherit the banner from the bundled review and do not carry it themselves.

Strict compile still clean: gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 0 errors, 0 warnings.

@Evangelink
Amaury Levé (Evangelink) merged commit 494227e into microsoft:mainJun 5, 2026
32 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/expert-reviewer-copilot-attribution branch June 5, 2026 07:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@JanKrivanek
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Disclose Copilot authorship on expert reviewer comments by Evangelink · Pull Request #8819 · microsoft/testfx · GitHub
Skip to content

Disclose Copilot authorship on expert reviewer comments - #8819

Merged
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution
Jun 5, 2026
Merged

Disclose Copilot authorship on expert reviewer comments#8819
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution

Conversation

@Evangelink

Copy link
Copy Markdown
Member

What & why

The expert-reviewer agentic workflow posts reviews via gh-aw safe-output tools that use a maintainer's PAT (COPILOT_GITHUB_TOKEN). As a result, every add_comment, create_pull_request_review_comment, and submit_pull_request_review call shows the maintainer's avatar and username — with no way for readers to tell the content was authored by Copilot rather than by the human whose account they see.

This PR adds an explicit disclosure so the authorship is clear.

Change

  1. .github/agents/expert-reviewer.agent.md

    • New Absolute Rule Bug Fix #258333 : Tests running multiple times in case we have multiple test projects #4 mandating the attribution banner.
    • New ## Copilot Attribution Banner section defining the verbatim banner with a <workflow-run-url> placeholder.
    • Wave 3 step 5 (add_comment) and Wave 4 step 6 (submit_pull_request_review) updated to require the banner at the top of each body. Both example bodies in step 6 now show the banner.
    • Wave 3 step 4 (inline comments) explicitly says no per-comment footer — inline comments are bundled into the Wave 4 review whose body already carries the banner, and gh-aw's shared/formatting.md already appends an automatic footer that we should not duplicate.
  2. .github/workflows/shared/review-shared.md

    • Step 2 of ## Instructions: the orchestrator now forwards the workflow run URL (${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}) to the subagent prompt and references the new banner section. Without this forwarding, the subagent (a background task) has no access to the parent <github-context> block and could not populate the link.

Resulting banner

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Validation

  • gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 3 workflow(s), 0 errors, 0 warnings.
  • No lockfile regenerations were needed for this change: the agent file is loaded at runtime by the subagent (not embedded into the lock), and shared/review-shared.md is pulled in via {{#runtime-import}} rather than inlined. Local strict-compile did surface unrelated SHA-pin regressions in the lock files (likely a local compiler-version artifact) — those were reverted to keep this PR scoped to the disclosure change.

The expert-reviewer agent posts reviews via gh-aw safe-output tools that
use a maintainer's PAT (COPILOT_GITHUB_TOKEN), so every comment appears
under that maintainer's avatar and username. Readers currently have no
way to tell the content was authored by Copilot rather than the human
whose account they see.
Add a mandatory attribution banner at the top of every add_comment body
and every submit_pull_request_review body, with a link back to the
generating workflow run so anyone can audit it. The orchestrator now
forwards the workflow run URL to the subagent so the banner link
resolves.
Inline review comments still get no per-comment footer: they are
bundled into the Wave 4 review whose body already carries the banner,
and gh-aw's formatting shared fragment already appends an automatic
attribution footer that we should not duplicate.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 4, 2026 11:23

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR improves transparency for the repository’s “expert-reviewer” agentic workflow by requiring an explicit “authored by GitHub Copilot” disclosure in posted PR comments and review bodies, clarifying that content is published via a maintainer PAT and may otherwise be mistaken for human-written feedback.

Changes:

  • Added a mandatory Copilot attribution banner (with a workflow-run URL placeholder) to the expert reviewer agent definition and required it at the start of add_comment and submit_pull_request_review bodies.
  • Clarified that inline comments (create_pull_request_review_comment) should not add per-comment attribution, since they’re bundled into the final review and gh-aw already appends its own footer attribution.
  • Updated the shared review workflow instructions to forward the workflow run URL into the subagent prompt so it can populate the banner link.
Show a summary per file
FileDescription
.github/workflows/shared/review-shared.mdInstructs the orchestrator to pass the workflow run URL to the expert-reviewer subagent so it can link the disclosure banner to the originating run.
.github/agents/expert-reviewer.agent.mdDefines the required Copilot attribution banner and enforces its inclusion at the start of posted top-level comments and the submitted review body.

Copilot's findings

  • Files reviewed: 2/2 changed files
  • Comments generated: 2

Comment thread.github/workflows/shared/review-shared.md Outdated
Comment thread.github/agents/expert-reviewer.agent.md Outdated
Two clarifications:
- expert-reviewer.agent.md: spell out a full fallback banner variant for
the case where the orchestrator does not supply a workflow run URL,
instead of telling the agent to `omit the parenthesized link'' (which
would have left dangling markdown like `[Expert Code Review
workflow]()`). The fallback drops the entire `Generated by ...''
sentence so the rendered markdown stays valid.
- shared/review-shared.md: tighten the rationale for forwarding the
workflow run URL. The URL is needed for the banner that goes on
add_comment and submit_pull_request_review bodies only; inline
create_pull_request_review_comment bodies inherit the banner from the
bundled review and do not carry it themselves.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@Evangelink

Copy link
Copy Markdown
MemberAuthor

Addressed both review comments in 3ed7f9f:

  1. .github/agents/expert-reviewer.agent.md (line 36 comment) — replaced the ambiguous "omit the parenthesized link and keep the rest of the banner" guidance with an explicit, verbatim fallback banner that drops the whole "Generated by …" sentence, so the rendered markdown stays valid when no run URL is available.
  2. .github/workflows/shared/review-shared.md (line 42 comment) — tightened the rationale to clarify the URL is needed for the banner on add_comment and submit_pull_request_review bodies only; inline create_pull_request_review_comment bodies inherit the banner from the bundled review and do not carry it themselves.

Strict compile still clean: gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 0 errors, 0 warnings.

@Evangelink
Amaury Levé (Evangelink) merged commit 494227e into microsoft:mainJun 5, 2026
32 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/expert-reviewer-copilot-attribution branch June 5, 2026 07:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@JanKrivanek
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Disclose Copilot authorship on expert reviewer comments by Evangelink · Pull Request #8819 · microsoft/testfx · GitHub
Skip to content

Disclose Copilot authorship on expert reviewer comments - #8819

Merged
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution
Jun 5, 2026
Merged

Disclose Copilot authorship on expert reviewer comments#8819
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution

Conversation

@Evangelink

Copy link
Copy Markdown
Member

What & why

The expert-reviewer agentic workflow posts reviews via gh-aw safe-output tools that use a maintainer's PAT (COPILOT_GITHUB_TOKEN). As a result, every add_comment, create_pull_request_review_comment, and submit_pull_request_review call shows the maintainer's avatar and username — with no way for readers to tell the content was authored by Copilot rather than by the human whose account they see.

This PR adds an explicit disclosure so the authorship is clear.

Change

  1. .github/agents/expert-reviewer.agent.md

    • New Absolute Rule Bug Fix #258333 : Tests running multiple times in case we have multiple test projects #4 mandating the attribution banner.
    • New ## Copilot Attribution Banner section defining the verbatim banner with a <workflow-run-url> placeholder.
    • Wave 3 step 5 (add_comment) and Wave 4 step 6 (submit_pull_request_review) updated to require the banner at the top of each body. Both example bodies in step 6 now show the banner.
    • Wave 3 step 4 (inline comments) explicitly says no per-comment footer — inline comments are bundled into the Wave 4 review whose body already carries the banner, and gh-aw's shared/formatting.md already appends an automatic footer that we should not duplicate.
  2. .github/workflows/shared/review-shared.md

    • Step 2 of ## Instructions: the orchestrator now forwards the workflow run URL (${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}) to the subagent prompt and references the new banner section. Without this forwarding, the subagent (a background task) has no access to the parent <github-context> block and could not populate the link.

Resulting banner

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Validation

  • gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 3 workflow(s), 0 errors, 0 warnings.
  • No lockfile regenerations were needed for this change: the agent file is loaded at runtime by the subagent (not embedded into the lock), and shared/review-shared.md is pulled in via {{#runtime-import}} rather than inlined. Local strict-compile did surface unrelated SHA-pin regressions in the lock files (likely a local compiler-version artifact) — those were reverted to keep this PR scoped to the disclosure change.

The expert-reviewer agent posts reviews via gh-aw safe-output tools that
use a maintainer's PAT (COPILOT_GITHUB_TOKEN), so every comment appears
under that maintainer's avatar and username. Readers currently have no
way to tell the content was authored by Copilot rather than the human
whose account they see.
Add a mandatory attribution banner at the top of every add_comment body
and every submit_pull_request_review body, with a link back to the
generating workflow run so anyone can audit it. The orchestrator now
forwards the workflow run URL to the subagent so the banner link
resolves.
Inline review comments still get no per-comment footer: they are
bundled into the Wave 4 review whose body already carries the banner,
and gh-aw's formatting shared fragment already appends an automatic
attribution footer that we should not duplicate.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 4, 2026 11:23

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR improves transparency for the repository’s “expert-reviewer” agentic workflow by requiring an explicit “authored by GitHub Copilot” disclosure in posted PR comments and review bodies, clarifying that content is published via a maintainer PAT and may otherwise be mistaken for human-written feedback.

Changes:

  • Added a mandatory Copilot attribution banner (with a workflow-run URL placeholder) to the expert reviewer agent definition and required it at the start of add_comment and submit_pull_request_review bodies.
  • Clarified that inline comments (create_pull_request_review_comment) should not add per-comment attribution, since they’re bundled into the final review and gh-aw already appends its own footer attribution.
  • Updated the shared review workflow instructions to forward the workflow run URL into the subagent prompt so it can populate the banner link.
Show a summary per file
FileDescription
.github/workflows/shared/review-shared.mdInstructs the orchestrator to pass the workflow run URL to the expert-reviewer subagent so it can link the disclosure banner to the originating run.
.github/agents/expert-reviewer.agent.mdDefines the required Copilot attribution banner and enforces its inclusion at the start of posted top-level comments and the submitted review body.

Copilot's findings

  • Files reviewed: 2/2 changed files
  • Comments generated: 2

Comment thread.github/workflows/shared/review-shared.md Outdated
Comment thread.github/agents/expert-reviewer.agent.md Outdated
Two clarifications:
- expert-reviewer.agent.md: spell out a full fallback banner variant for
the case where the orchestrator does not supply a workflow run URL,
instead of telling the agent to `omit the parenthesized link'' (which
would have left dangling markdown like `[Expert Code Review
workflow]()`). The fallback drops the entire `Generated by ...''
sentence so the rendered markdown stays valid.
- shared/review-shared.md: tighten the rationale for forwarding the
workflow run URL. The URL is needed for the banner that goes on
add_comment and submit_pull_request_review bodies only; inline
create_pull_request_review_comment bodies inherit the banner from the
bundled review and do not carry it themselves.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@Evangelink

Copy link
Copy Markdown
MemberAuthor

Addressed both review comments in 3ed7f9f:

  1. .github/agents/expert-reviewer.agent.md (line 36 comment) — replaced the ambiguous "omit the parenthesized link and keep the rest of the banner" guidance with an explicit, verbatim fallback banner that drops the whole "Generated by …" sentence, so the rendered markdown stays valid when no run URL is available.
  2. .github/workflows/shared/review-shared.md (line 42 comment) — tightened the rationale to clarify the URL is needed for the banner on add_comment and submit_pull_request_review bodies only; inline create_pull_request_review_comment bodies inherit the banner from the bundled review and do not carry it themselves.

Strict compile still clean: gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 0 errors, 0 warnings.

@Evangelink
Amaury Levé (Evangelink) merged commit 494227e into microsoft:mainJun 5, 2026
32 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/expert-reviewer-copilot-attribution branch June 5, 2026 07:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@JanKrivanek
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Disclose Copilot authorship on expert reviewer comments by Evangelink · Pull Request #8819 · microsoft/testfx · GitHub
Skip to content

Disclose Copilot authorship on expert reviewer comments - #8819

Merged
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution
Jun 5, 2026
Merged

Disclose Copilot authorship on expert reviewer comments#8819
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution

Conversation

@Evangelink

Copy link
Copy Markdown
Member

What & why

The expert-reviewer agentic workflow posts reviews via gh-aw safe-output tools that use a maintainer's PAT (COPILOT_GITHUB_TOKEN). As a result, every add_comment, create_pull_request_review_comment, and submit_pull_request_review call shows the maintainer's avatar and username — with no way for readers to tell the content was authored by Copilot rather than by the human whose account they see.

This PR adds an explicit disclosure so the authorship is clear.

Change

  1. .github/agents/expert-reviewer.agent.md

    • New Absolute Rule Bug Fix #258333 : Tests running multiple times in case we have multiple test projects #4 mandating the attribution banner.
    • New ## Copilot Attribution Banner section defining the verbatim banner with a <workflow-run-url> placeholder.
    • Wave 3 step 5 (add_comment) and Wave 4 step 6 (submit_pull_request_review) updated to require the banner at the top of each body. Both example bodies in step 6 now show the banner.
    • Wave 3 step 4 (inline comments) explicitly says no per-comment footer — inline comments are bundled into the Wave 4 review whose body already carries the banner, and gh-aw's shared/formatting.md already appends an automatic footer that we should not duplicate.
  2. .github/workflows/shared/review-shared.md

    • Step 2 of ## Instructions: the orchestrator now forwards the workflow run URL (${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}) to the subagent prompt and references the new banner section. Without this forwarding, the subagent (a background task) has no access to the parent <github-context> block and could not populate the link.

Resulting banner

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Validation

  • gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 3 workflow(s), 0 errors, 0 warnings.
  • No lockfile regenerations were needed for this change: the agent file is loaded at runtime by the subagent (not embedded into the lock), and shared/review-shared.md is pulled in via {{#runtime-import}} rather than inlined. Local strict-compile did surface unrelated SHA-pin regressions in the lock files (likely a local compiler-version artifact) — those were reverted to keep this PR scoped to the disclosure change.

The expert-reviewer agent posts reviews via gh-aw safe-output tools that
use a maintainer's PAT (COPILOT_GITHUB_TOKEN), so every comment appears
under that maintainer's avatar and username. Readers currently have no
way to tell the content was authored by Copilot rather than the human
whose account they see.
Add a mandatory attribution banner at the top of every add_comment body
and every submit_pull_request_review body, with a link back to the
generating workflow run so anyone can audit it. The orchestrator now
forwards the workflow run URL to the subagent so the banner link
resolves.
Inline review comments still get no per-comment footer: they are
bundled into the Wave 4 review whose body already carries the banner,
and gh-aw's formatting shared fragment already appends an automatic
attribution footer that we should not duplicate.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 4, 2026 11:23

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR improves transparency for the repository’s “expert-reviewer” agentic workflow by requiring an explicit “authored by GitHub Copilot” disclosure in posted PR comments and review bodies, clarifying that content is published via a maintainer PAT and may otherwise be mistaken for human-written feedback.

Changes:

  • Added a mandatory Copilot attribution banner (with a workflow-run URL placeholder) to the expert reviewer agent definition and required it at the start of add_comment and submit_pull_request_review bodies.
  • Clarified that inline comments (create_pull_request_review_comment) should not add per-comment attribution, since they’re bundled into the final review and gh-aw already appends its own footer attribution.
  • Updated the shared review workflow instructions to forward the workflow run URL into the subagent prompt so it can populate the banner link.
Show a summary per file
FileDescription
.github/workflows/shared/review-shared.mdInstructs the orchestrator to pass the workflow run URL to the expert-reviewer subagent so it can link the disclosure banner to the originating run.
.github/agents/expert-reviewer.agent.mdDefines the required Copilot attribution banner and enforces its inclusion at the start of posted top-level comments and the submitted review body.

Copilot's findings

  • Files reviewed: 2/2 changed files
  • Comments generated: 2

Comment thread.github/workflows/shared/review-shared.md Outdated
Comment thread.github/agents/expert-reviewer.agent.md Outdated
Two clarifications:
- expert-reviewer.agent.md: spell out a full fallback banner variant for
the case where the orchestrator does not supply a workflow run URL,
instead of telling the agent to `omit the parenthesized link'' (which
would have left dangling markdown like `[Expert Code Review
workflow]()`). The fallback drops the entire `Generated by ...''
sentence so the rendered markdown stays valid.
- shared/review-shared.md: tighten the rationale for forwarding the
workflow run URL. The URL is needed for the banner that goes on
add_comment and submit_pull_request_review bodies only; inline
create_pull_request_review_comment bodies inherit the banner from the
bundled review and do not carry it themselves.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@Evangelink

Copy link
Copy Markdown
MemberAuthor

Addressed both review comments in 3ed7f9f:

  1. .github/agents/expert-reviewer.agent.md (line 36 comment) — replaced the ambiguous "omit the parenthesized link and keep the rest of the banner" guidance with an explicit, verbatim fallback banner that drops the whole "Generated by …" sentence, so the rendered markdown stays valid when no run URL is available.
  2. .github/workflows/shared/review-shared.md (line 42 comment) — tightened the rationale to clarify the URL is needed for the banner on add_comment and submit_pull_request_review bodies only; inline create_pull_request_review_comment bodies inherit the banner from the bundled review and do not carry it themselves.

Strict compile still clean: gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 0 errors, 0 warnings.

@Evangelink
Amaury Levé (Evangelink) merged commit 494227e into microsoft:mainJun 5, 2026
32 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/expert-reviewer-copilot-attribution branch June 5, 2026 07:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@JanKrivanek
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Disclose Copilot authorship on expert reviewer comments by Evangelink · Pull Request #8819 · microsoft/testfx · GitHub
Skip to content

Disclose Copilot authorship on expert reviewer comments - #8819

Merged
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution
Jun 5, 2026
Merged

Disclose Copilot authorship on expert reviewer comments#8819
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution

Conversation

@Evangelink

Copy link
Copy Markdown
Member

What & why

The expert-reviewer agentic workflow posts reviews via gh-aw safe-output tools that use a maintainer's PAT (COPILOT_GITHUB_TOKEN). As a result, every add_comment, create_pull_request_review_comment, and submit_pull_request_review call shows the maintainer's avatar and username — with no way for readers to tell the content was authored by Copilot rather than by the human whose account they see.

This PR adds an explicit disclosure so the authorship is clear.

Change

  1. .github/agents/expert-reviewer.agent.md

    • New Absolute Rule Bug Fix #258333 : Tests running multiple times in case we have multiple test projects #4 mandating the attribution banner.
    • New ## Copilot Attribution Banner section defining the verbatim banner with a <workflow-run-url> placeholder.
    • Wave 3 step 5 (add_comment) and Wave 4 step 6 (submit_pull_request_review) updated to require the banner at the top of each body. Both example bodies in step 6 now show the banner.
    • Wave 3 step 4 (inline comments) explicitly says no per-comment footer — inline comments are bundled into the Wave 4 review whose body already carries the banner, and gh-aw's shared/formatting.md already appends an automatic footer that we should not duplicate.
  2. .github/workflows/shared/review-shared.md

    • Step 2 of ## Instructions: the orchestrator now forwards the workflow run URL (${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}) to the subagent prompt and references the new banner section. Without this forwarding, the subagent (a background task) has no access to the parent <github-context> block and could not populate the link.

Resulting banner

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Validation

  • gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 3 workflow(s), 0 errors, 0 warnings.
  • No lockfile regenerations were needed for this change: the agent file is loaded at runtime by the subagent (not embedded into the lock), and shared/review-shared.md is pulled in via {{#runtime-import}} rather than inlined. Local strict-compile did surface unrelated SHA-pin regressions in the lock files (likely a local compiler-version artifact) — those were reverted to keep this PR scoped to the disclosure change.

The expert-reviewer agent posts reviews via gh-aw safe-output tools that
use a maintainer's PAT (COPILOT_GITHUB_TOKEN), so every comment appears
under that maintainer's avatar and username. Readers currently have no
way to tell the content was authored by Copilot rather than the human
whose account they see.
Add a mandatory attribution banner at the top of every add_comment body
and every submit_pull_request_review body, with a link back to the
generating workflow run so anyone can audit it. The orchestrator now
forwards the workflow run URL to the subagent so the banner link
resolves.
Inline review comments still get no per-comment footer: they are
bundled into the Wave 4 review whose body already carries the banner,
and gh-aw's formatting shared fragment already appends an automatic
attribution footer that we should not duplicate.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 4, 2026 11:23

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR improves transparency for the repository’s “expert-reviewer” agentic workflow by requiring an explicit “authored by GitHub Copilot” disclosure in posted PR comments and review bodies, clarifying that content is published via a maintainer PAT and may otherwise be mistaken for human-written feedback.

Changes:

  • Added a mandatory Copilot attribution banner (with a workflow-run URL placeholder) to the expert reviewer agent definition and required it at the start of add_comment and submit_pull_request_review bodies.
  • Clarified that inline comments (create_pull_request_review_comment) should not add per-comment attribution, since they’re bundled into the final review and gh-aw already appends its own footer attribution.
  • Updated the shared review workflow instructions to forward the workflow run URL into the subagent prompt so it can populate the banner link.
Show a summary per file
FileDescription
.github/workflows/shared/review-shared.mdInstructs the orchestrator to pass the workflow run URL to the expert-reviewer subagent so it can link the disclosure banner to the originating run.
.github/agents/expert-reviewer.agent.mdDefines the required Copilot attribution banner and enforces its inclusion at the start of posted top-level comments and the submitted review body.

Copilot's findings

  • Files reviewed: 2/2 changed files
  • Comments generated: 2

Comment thread.github/workflows/shared/review-shared.md Outdated
Comment thread.github/agents/expert-reviewer.agent.md Outdated
Two clarifications:
- expert-reviewer.agent.md: spell out a full fallback banner variant for
the case where the orchestrator does not supply a workflow run URL,
instead of telling the agent to `omit the parenthesized link'' (which
would have left dangling markdown like `[Expert Code Review
workflow]()`). The fallback drops the entire `Generated by ...''
sentence so the rendered markdown stays valid.
- shared/review-shared.md: tighten the rationale for forwarding the
workflow run URL. The URL is needed for the banner that goes on
add_comment and submit_pull_request_review bodies only; inline
create_pull_request_review_comment bodies inherit the banner from the
bundled review and do not carry it themselves.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@Evangelink

Copy link
Copy Markdown
MemberAuthor

Addressed both review comments in 3ed7f9f:

  1. .github/agents/expert-reviewer.agent.md (line 36 comment) — replaced the ambiguous "omit the parenthesized link and keep the rest of the banner" guidance with an explicit, verbatim fallback banner that drops the whole "Generated by …" sentence, so the rendered markdown stays valid when no run URL is available.
  2. .github/workflows/shared/review-shared.md (line 42 comment) — tightened the rationale to clarify the URL is needed for the banner on add_comment and submit_pull_request_review bodies only; inline create_pull_request_review_comment bodies inherit the banner from the bundled review and do not carry it themselves.

Strict compile still clean: gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 0 errors, 0 warnings.

@Evangelink
Amaury Levé (Evangelink) merged commit 494227e into microsoft:mainJun 5, 2026
32 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/expert-reviewer-copilot-attribution branch June 5, 2026 07:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@JanKrivanek
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Disclose Copilot authorship on expert reviewer comments by Evangelink · Pull Request #8819 · microsoft/testfx · GitHub
Skip to content

Disclose Copilot authorship on expert reviewer comments - #8819

Merged
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution
Jun 5, 2026
Merged

Disclose Copilot authorship on expert reviewer comments#8819
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution

Conversation

@Evangelink

Copy link
Copy Markdown
Member

What & why

The expert-reviewer agentic workflow posts reviews via gh-aw safe-output tools that use a maintainer's PAT (COPILOT_GITHUB_TOKEN). As a result, every add_comment, create_pull_request_review_comment, and submit_pull_request_review call shows the maintainer's avatar and username — with no way for readers to tell the content was authored by Copilot rather than by the human whose account they see.

This PR adds an explicit disclosure so the authorship is clear.

Change

  1. .github/agents/expert-reviewer.agent.md

    • New Absolute Rule Bug Fix #258333 : Tests running multiple times in case we have multiple test projects #4 mandating the attribution banner.
    • New ## Copilot Attribution Banner section defining the verbatim banner with a <workflow-run-url> placeholder.
    • Wave 3 step 5 (add_comment) and Wave 4 step 6 (submit_pull_request_review) updated to require the banner at the top of each body. Both example bodies in step 6 now show the banner.
    • Wave 3 step 4 (inline comments) explicitly says no per-comment footer — inline comments are bundled into the Wave 4 review whose body already carries the banner, and gh-aw's shared/formatting.md already appends an automatic footer that we should not duplicate.
  2. .github/workflows/shared/review-shared.md

    • Step 2 of ## Instructions: the orchestrator now forwards the workflow run URL (${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}) to the subagent prompt and references the new banner section. Without this forwarding, the subagent (a background task) has no access to the parent <github-context> block and could not populate the link.

Resulting banner

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Validation

  • gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 3 workflow(s), 0 errors, 0 warnings.
  • No lockfile regenerations were needed for this change: the agent file is loaded at runtime by the subagent (not embedded into the lock), and shared/review-shared.md is pulled in via {{#runtime-import}} rather than inlined. Local strict-compile did surface unrelated SHA-pin regressions in the lock files (likely a local compiler-version artifact) — those were reverted to keep this PR scoped to the disclosure change.

The expert-reviewer agent posts reviews via gh-aw safe-output tools that
use a maintainer's PAT (COPILOT_GITHUB_TOKEN), so every comment appears
under that maintainer's avatar and username. Readers currently have no
way to tell the content was authored by Copilot rather than the human
whose account they see.
Add a mandatory attribution banner at the top of every add_comment body
and every submit_pull_request_review body, with a link back to the
generating workflow run so anyone can audit it. The orchestrator now
forwards the workflow run URL to the subagent so the banner link
resolves.
Inline review comments still get no per-comment footer: they are
bundled into the Wave 4 review whose body already carries the banner,
and gh-aw's formatting shared fragment already appends an automatic
attribution footer that we should not duplicate.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 4, 2026 11:23

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR improves transparency for the repository’s “expert-reviewer” agentic workflow by requiring an explicit “authored by GitHub Copilot” disclosure in posted PR comments and review bodies, clarifying that content is published via a maintainer PAT and may otherwise be mistaken for human-written feedback.

Changes:

  • Added a mandatory Copilot attribution banner (with a workflow-run URL placeholder) to the expert reviewer agent definition and required it at the start of add_comment and submit_pull_request_review bodies.
  • Clarified that inline comments (create_pull_request_review_comment) should not add per-comment attribution, since they’re bundled into the final review and gh-aw already appends its own footer attribution.
  • Updated the shared review workflow instructions to forward the workflow run URL into the subagent prompt so it can populate the banner link.
Show a summary per file
FileDescription
.github/workflows/shared/review-shared.mdInstructs the orchestrator to pass the workflow run URL to the expert-reviewer subagent so it can link the disclosure banner to the originating run.
.github/agents/expert-reviewer.agent.mdDefines the required Copilot attribution banner and enforces its inclusion at the start of posted top-level comments and the submitted review body.

Copilot's findings

  • Files reviewed: 2/2 changed files
  • Comments generated: 2

Comment thread.github/workflows/shared/review-shared.md Outdated
Comment thread.github/agents/expert-reviewer.agent.md Outdated
Two clarifications:
- expert-reviewer.agent.md: spell out a full fallback banner variant for
the case where the orchestrator does not supply a workflow run URL,
instead of telling the agent to `omit the parenthesized link'' (which
would have left dangling markdown like `[Expert Code Review
workflow]()`). The fallback drops the entire `Generated by ...''
sentence so the rendered markdown stays valid.
- shared/review-shared.md: tighten the rationale for forwarding the
workflow run URL. The URL is needed for the banner that goes on
add_comment and submit_pull_request_review bodies only; inline
create_pull_request_review_comment bodies inherit the banner from the
bundled review and do not carry it themselves.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@Evangelink

Copy link
Copy Markdown
MemberAuthor

Addressed both review comments in 3ed7f9f:

  1. .github/agents/expert-reviewer.agent.md (line 36 comment) — replaced the ambiguous "omit the parenthesized link and keep the rest of the banner" guidance with an explicit, verbatim fallback banner that drops the whole "Generated by …" sentence, so the rendered markdown stays valid when no run URL is available.
  2. .github/workflows/shared/review-shared.md (line 42 comment) — tightened the rationale to clarify the URL is needed for the banner on add_comment and submit_pull_request_review bodies only; inline create_pull_request_review_comment bodies inherit the banner from the bundled review and do not carry it themselves.

Strict compile still clean: gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 0 errors, 0 warnings.

@Evangelink
Amaury Levé (Evangelink) merged commit 494227e into microsoft:mainJun 5, 2026
32 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/expert-reviewer-copilot-attribution branch June 5, 2026 07:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@JanKrivanek
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Disclose Copilot authorship on expert reviewer comments by Evangelink · Pull Request #8819 · microsoft/testfx · GitHub
Skip to content

Disclose Copilot authorship on expert reviewer comments - #8819

Merged
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution
Jun 5, 2026
Merged

Disclose Copilot authorship on expert reviewer comments#8819
Amaury Levé (Evangelink) merged 2 commits into
microsoft:mainfrom
Evangelink:dev/amauryleve/expert-reviewer-copilot-attribution

Conversation

@Evangelink

Copy link
Copy Markdown
Member

What & why

The expert-reviewer agentic workflow posts reviews via gh-aw safe-output tools that use a maintainer's PAT (COPILOT_GITHUB_TOKEN). As a result, every add_comment, create_pull_request_review_comment, and submit_pull_request_review call shows the maintainer's avatar and username — with no way for readers to tell the content was authored by Copilot rather than by the human whose account they see.

This PR adds an explicit disclosure so the authorship is clear.

Change

  1. .github/agents/expert-reviewer.agent.md

    • New Absolute Rule Bug Fix #258333 : Tests running multiple times in case we have multiple test projects #4 mandating the attribution banner.
    • New ## Copilot Attribution Banner section defining the verbatim banner with a <workflow-run-url> placeholder.
    • Wave 3 step 5 (add_comment) and Wave 4 step 6 (submit_pull_request_review) updated to require the banner at the top of each body. Both example bodies in step 6 now show the banner.
    • Wave 3 step 4 (inline comments) explicitly says no per-comment footer — inline comments are bundled into the Wave 4 review whose body already carries the banner, and gh-aw's shared/formatting.md already appends an automatic footer that we should not duplicate.
  2. .github/workflows/shared/review-shared.md

    • Step 2 of ## Instructions: the orchestrator now forwards the workflow run URL (${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}) to the subagent prompt and references the new banner section. Without this forwarding, the subagent (a background task) has no access to the parent <github-context> block and could not populate the link.

Resulting banner

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Validation

  • gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 3 workflow(s), 0 errors, 0 warnings.
  • No lockfile regenerations were needed for this change: the agent file is loaded at runtime by the subagent (not embedded into the lock), and shared/review-shared.md is pulled in via {{#runtime-import}} rather than inlined. Local strict-compile did surface unrelated SHA-pin regressions in the lock files (likely a local compiler-version artifact) — those were reverted to keep this PR scoped to the disclosure change.

The expert-reviewer agent posts reviews via gh-aw safe-output tools that
use a maintainer's PAT (COPILOT_GITHUB_TOKEN), so every comment appears
under that maintainer's avatar and username. Readers currently have no
way to tell the content was authored by Copilot rather than the human
whose account they see.
Add a mandatory attribution banner at the top of every add_comment body
and every submit_pull_request_review body, with a link back to the
generating workflow run so anyone can audit it. The orchestrator now
forwards the workflow run URL to the subagent so the banner link
resolves.
Inline review comments still get no per-comment footer: they are
bundled into the Wave 4 review whose body already carries the banner,
and gh-aw's formatting shared fragment already appends an automatic
attribution footer that we should not duplicate.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 4, 2026 11:23

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR improves transparency for the repository’s “expert-reviewer” agentic workflow by requiring an explicit “authored by GitHub Copilot” disclosure in posted PR comments and review bodies, clarifying that content is published via a maintainer PAT and may otherwise be mistaken for human-written feedback.

Changes:

  • Added a mandatory Copilot attribution banner (with a workflow-run URL placeholder) to the expert reviewer agent definition and required it at the start of add_comment and submit_pull_request_review bodies.
  • Clarified that inline comments (create_pull_request_review_comment) should not add per-comment attribution, since they’re bundled into the final review and gh-aw already appends its own footer attribution.
  • Updated the shared review workflow instructions to forward the workflow run URL into the subagent prompt so it can populate the banner link.
Show a summary per file
FileDescription
.github/workflows/shared/review-shared.mdInstructs the orchestrator to pass the workflow run URL to the expert-reviewer subagent so it can link the disclosure banner to the originating run.
.github/agents/expert-reviewer.agent.mdDefines the required Copilot attribution banner and enforces its inclusion at the start of posted top-level comments and the submitted review body.

Copilot's findings

  • Files reviewed: 2/2 changed files
  • Comments generated: 2

Comment thread.github/workflows/shared/review-shared.md Outdated
Comment thread.github/agents/expert-reviewer.agent.md Outdated
Two clarifications:
- expert-reviewer.agent.md: spell out a full fallback banner variant for
the case where the orchestrator does not supply a workflow run URL,
instead of telling the agent to `omit the parenthesized link'' (which
would have left dangling markdown like `[Expert Code Review
workflow]()`). The fallback drops the entire `Generated by ...''
sentence so the rendered markdown stays valid.
- shared/review-shared.md: tighten the rationale for forwarding the
workflow run URL. The URL is needed for the banner that goes on
add_comment and submit_pull_request_review bodies only; inline
create_pull_request_review_comment bodies inherit the banner from the
bundled review and do not carry it themselves.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@Evangelink

Copy link
Copy Markdown
MemberAuthor

Addressed both review comments in 3ed7f9f:

  1. .github/agents/expert-reviewer.agent.md (line 36 comment) — replaced the ambiguous "omit the parenthesized link and keep the rest of the banner" guidance with an explicit, verbatim fallback banner that drops the whole "Generated by …" sentence, so the rendered markdown stays valid when no run URL is available.
  2. .github/workflows/shared/review-shared.md (line 42 comment) — tightened the rationale to clarify the URL is needed for the banner on add_comment and submit_pull_request_review bodies only; inline create_pull_request_review_comment bodies inherit the banner from the bundled review and do not carry it themselves.

Strict compile still clean: gh aw compile --strict review.agent review-on-open.agent review-after-autofix.agent → 0 errors, 0 warnings.

@Evangelink
Amaury Levé (Evangelink) merged commit 494227e into microsoft:mainJun 5, 2026
32 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/expert-reviewer-copilot-attribution branch June 5, 2026 07:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@JanKrivanek