Skip to content

Add Copilot skill for adding user requested domain to egress allowlist - #274

Merged
v-abhishekbhaskar merged 3 commits into
mainfrom
abhishekbhaskar/add-egress-allowllist-skill
Sep 29, 2026
Merged

v-abhishekbhaskar merged 3 commits into
mainfrom
abhishekbhaskar/add-egress-allowllist-skill

Conversation

@v-abhishekbhaskar

Copy link
Copy Markdown
Contributor

What are you trying to accomplish?

Adds a Copilot CLI skill at .github/skills/add-egress-allowlist-domain/SKILL.md that walks a contributor through handling a host blocked by the egress allowlist.

The allowlist is enforced progressively, so reports of blocked domains arrive steadily. Most of them should not result in a YAML change: private and org-specific registries belong in registries: in dependabot.yml, and shared multi-tenant hosts must be refused outright because the handler authorizes the hostname only and never constrains path or method. The skill encodes triage related to static and private registries and handles correct placement of user's domain in the allowlist.

Anything you want to highlight for special attention from reviewers?

How its used-
In a Copilot CLI session with this repo as the working directory, the user just states the problem:
rsc.io is blocked in my go_modules job, can you add it?
or simply pastes the log line:
* egress not allowlisted rubygemsregistryv2prod.blob.core.windows.net

Copilot matches that against the description and loads the skill before acting. Because it's also user-invocable: true , they can ask for it by name. /skills lists it, /env confirms it loaded.

What it then does: triages whether the host belongs in the static defaults at all (routing private/org registries to  registries:  in  dependabot.yml  and refusing multi-tenant hosts) →  curl -verifies the host → picks exact vs leading-dot vs glob → places it respecting the YAML anchors → adds a positive probe and an  evil.  child probe → runs build/test/gofmt → opens the PR with the template.

How will you know you've accomplished your goal?

The skill runs correctly and opens a PR when called with the user's domain. It is discoverable via /skills and /env once merged.

Checklist

  • I have run the complete test suite to ensure all tests and linters pass.
  • I have thoroughly tested my code changes to ensure they work as expected, including adding additional tests for new functionality.
  • I have written clear and descriptive commit messages.
  • I have provided a detailed description of the changes in the pull request, including the problem it addresses, how it fixes the problem, and any relevant details about the implementation.
  • I have ensured that the code is well-documented and easy to understand.

@v-abhishekbhaskar v-abhishekbhaskar self-assigned this Sep 28, 2026
@v-abhishekbhaskar
v-abhishekbhaskar requested a review from a team as a code owner September 28, 2026 06:56
Copilot AI balanced review requested due to automatic review settings September 28, 2026 06:56

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The host verification permits shell injection and internal redirects, while the PR command bypasses the required template.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Adds a Copilot skill for safely triaging and implementing egress allowlist requests.

Changes:

  • Documents domain safety classification and matching rules.
  • Defines regression testing, validation, and PR workflow.
File Description
.github/​skills/​add-egress-allowlist-domain/​SKILL.md Adds the allowlist workflow and guardrails.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/skills/add-egress-allowlist-domain/SKILL.md Outdated
Comment thread .github/skills/add-egress-allowlist-domain/SKILL.md Outdated
Comment thread .github/skills/add-egress-allowlist-domain/SKILL.md
@v-abhishekbhaskar
v-abhishekbhaskar force-pushed the abhishekbhaskar/add-egress-allowllist-skill branch from 1f675c9 to ee66b86 Compare September 29, 2026 19:46
@v-abhishekbhaskar
v-abhishekbhaskar merged commit 5a46b44 into main Sep 29, 2026
112 checks passed
@v-abhishekbhaskar
v-abhishekbhaskar deleted the abhishekbhaskar/add-egress-allowllist-skill branch September 29, 2026 19:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants