Visitar URL original
Expose check diagnostics through existing Actions tools by greggroth · Pull Request #3449 · github/github-mcp-server · GitHub
Skip to content

Expose check diagnostics through existing Actions tools - #3449

Draft
greggroth wants to merge 1 commit into
mainfrom
greggroth-check-details-access
Draft

greggroth wants to merge 1 commit into
mainfrom
greggroth-check-details-access

Conversation

@greggroth

Copy link
Copy Markdown

Summary

Expose check-run output and paginated annotations through the existing actions_get and actions_list tools. Keep check lists small.

Why

Follow-up to #1942. This change preserves the smaller Actions list payloads from #3047.

Agents can list failed checks today, but cannot retrieve their diagnostic output or annotations through MCP. This change adds the missing detail operations without adding tool names.

What changed

  • Add actions_get(method="get_check_run") for one check's output, provider identity, and annotation count.
  • Add actions_list methods list_check_runs and list_check_run_annotations. Support reference or suite lookup, API filters, and explicit pagination.
  • Add compact check_suite_id and check_run_id fields to workflow summaries. Extract job-to-check identifiers without fetching the URL or assuming matching IDs.
  • Preserve legacy response envelopes and modern typed output. Keep diagnostic text and annotation bodies out of list summaries.
  • Add protocol, validation, API error, content-sanitization, IFC-label, and payload-size coverage. Update snapshots and documentation.

MCP impact

  • No tool or API changes
  • Tool schema or behavior changed. actions_get gains one method. actions_list gains two methods.
  • New tool added

Tool names and default toolsets stay unchanged. Additional methods still increase the advertised JSON size:

Updated registration Without output schemas With output schemas
actions_list +1,104 bytes +4,285 bytes
actions_get +280 bytes +2,360 bytes
pull_request_read guidance +87 bytes +87 bytes
Total +1,471 bytes +6,732 bytes

These measurements use minified registration snapshots. They are byte counts, not model-token or routing-quality measurements.

Fixture responses add 20 bytes per workflow run and 25 bytes per job. A check summary remains 323 bytes with 50,000 bytes of upstream output text.

Prompts tested (tool changes only)

No live agent prompts were run. Mocked MCP sessions cover the operations for these example prompts:

  • "Why did this check fail?": retrieve one check's output without embedded annotations or logs.
  • "Show the annotations for this check.": retrieve one annotation page and expose the next page number.
  • "List checks for this workflow's suite, including earlier attempts.": preserve distinct check IDs when names repeat.
  • "List checks for this commit without a PR.": use reference lookup with provider and status filters.

Security / limits

  • No security or limits impact
  • Auth / permissions considered. The new methods require Checks read permission where fine-grained permissions apply. Existing OAuth policy stays unchanged.
  • Data exposure, filtering, or token/size limits considered. Lists omit diagnostic text and annotation bodies. Each new call fetches one check or one page, with at most 100 entries.

Provider text uses the content sanitizer and existing repository-visibility IFC labels. Workflow lists make no additional API requests. API errors remain errors rather than empty successful results.

Tool renaming

  • I am renaming tools as part of this PR (e.g. a part of a consolidation effort)
    • I have added the new tool aliases in deprecated_tool_aliases.go
  • I am not renaming tools as part of this PR. All existing tool names remain available.

Note: if you're renaming tools, you must add the tool aliases. For more information on how to do so, please refer to the official docs.

Lint & tests

  • Linted locally with ./script/lint: script/lint passed with 0 issues.
  • Tested locally with ./script/test: script/test passed, including race detection.

UPDATE_TOOLSNAPS=true go test ./...: passed.

go test ./pkg/github -run '^TestActionsCheckPayloadSizes$' -count=1 -v: passed with the measurements above.

Live GitHub E2E tests were not run.

Docs

  • Not needed
  • Updated (README / docs / examples). Added docs/checks.md. script/generate-docs: passed.

Extend existing Actions tools with read-only Checks API methods and compact workflow-to-check identifiers. Keep list responses small and fetch diagnostic output and annotation pages only on request.

Refs #1942

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d8331c1e-a71c-4a15-bc68-7c00064a0ee5
next-ace[bot]
next-ace Bot previously approved these changes Oct 8, 2026

@next-ace next-ace Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

test

next-ace[bot]
next-ace Bot previously requested changes Oct 8, 2026

@next-ace next-ace Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

test

next-ace[bot]
next-ace Bot previously approved these changes Oct 8, 2026

@next-ace next-ace Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security research run 2 - please disregard

@next-ace
next-ace Bot dismissed stale reviews from themself October 8, 2026 14:16

Removing security test review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant