Add Copilot skill for adding user requested domain to egress allowlist - #274
Merged
v-abhishekbhaskar merged 3 commits intoSep 29, 2026
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The host verification permits shell injection and internal redirects, while the PR command bypasses the required template.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Adds a Copilot skill for safely triaging and implementing egress allowlist requests.
Changes:
- Documents domain safety classification and matching rules.
- Defines regression testing, validation, and PR workflow.
| File | Description |
|---|---|
.github/skills/add-egress-allowlist-domain/SKILL.md |
Adds the allowlist workflow and guardrails. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
v-robaiken
reviewed
Sep 29, 2026
v-robaiken
approved these changes
Sep 29, 2026
v-abhishekbhaskar
force-pushed
the
abhishekbhaskar/add-egress-allowllist-skill
branch
from
September 29, 2026 19:46
1f675c9 to
ee66b86
Compare
v-abhishekbhaskar
deleted the
abhishekbhaskar/add-egress-allowllist-skill
branch
September 29, 2026 19:50
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


What are you trying to accomplish?
Adds a Copilot CLI skill at
.github/skills/add-egress-allowlist-domain/SKILL.mdthat walks a contributor through handling a host blocked by the egress allowlist.The allowlist is enforced progressively, so reports of blocked domains arrive steadily. Most of them should not result in a YAML change: private and org-specific registries belong in
registries:independabot.yml, and shared multi-tenant hosts must be refused outright because the handler authorizes the hostname only and never constrains path or method. The skill encodes triage related to static and private registries and handles correct placement of user's domain in the allowlist.Anything you want to highlight for special attention from reviewers?
How its used-
In a Copilot CLI session with this repo as the working directory, the user just states the problem:
rsc.iois blocked in mygo_modulesjob, can you add it?or simply pastes the log line:
* egress not allowlisted rubygemsregistryv2prod.blob.core.windows.netCopilot matches that against the description and loads the skill before acting. Because it's also
user-invocable: true, they can ask for it by name./skillslists it,/envconfirms it loaded.What it then does: triages whether the host belongs in the static defaults at all (routing private/org registries to registries: in dependabot.yml and refusing multi-tenant hosts) → curl -verifies the host → picks exact vs leading-dot vs glob → places it respecting the YAML anchors → adds a positive probe and an evil. child probe → runs build/test/gofmt → opens the PR with the template.
How will you know you've accomplished your goal?
The skill runs correctly and opens a PR when called with the user's domain. It is discoverable via
/skillsand/envonce merged.Checklist