Skip to content

feat(feature-discovery): add multi-agent roadmap discovery plugin - #236

Merged
rube-de merged 26 commits into
mainfrom
feature/feature-discovery-skill
Aug 5, 2026
Merged

rube-de merged 26 commits into
mainfrom
feature/feature-discovery-skill

Conversation

@rube-de

@rube-de rube-de commented Jul 23, 2026 •

Copy link
Copy Markdown
Owner

What

Adds a new standalone plugin, feature-discovery, that turns "what should we build next?" into a researched, ranked roadmap. It runs a deterministic multi-agent Workflow pipeline over five phases:

Ground (map the repo + research competitors) → Ideate (7 value lenses in parallel) → Shortlist (dedup + rank) → Spec & Validate (spec writer + adversarial skeptic per feature) → Synthesize (ranked-roadmap Markdown report).

Ported from the open-source feature-discovery-skill by Fabian Hug (MIT).

Why standalone (not a pm sub-skill)

It's a distinct capability from pm:brainstorm: brainstorm goes deep on one feature (interactive Q&A, one spec); this goes wide across the whole product (competitor research + ranked roadmap of many candidates). It's also the first plugin here to depend on the Workflow tool, so it declares that as a compatibility: prerequisite (mirroring how cdt declares its Agent-Teams flag).

Key decisions

  • Engine started as a verbatim port, adapted through review — prompts, 7 JSON schemas, and the 7 lenses began byte-for-byte from source, but diverged substantially across this PR's review cycles: argument validation/normalization, schema bounds (min/max item counts, required + nonblank content), hard-fail guards for empty ground/ideation/shortlist/validation/synthesis results, character-budgeted and per-record-compacted competitor research, and partial-fan-out coverage reporting (competitor tracks, ideation lenses, spec/validate pairs) were all added in response to review feedback. See the Credit section in SKILL.md/README.md for the current framing.
  • ${CLAUDE_SKILL_DIR} script path — the source's hardcoded .claude/skills/... path (and my first draft's ${CLAUDE_PLUGIN_ROOT}) don't resolve from a skill body; ${CLAUDE_SKILL_DIR} is the documented skill-body variable. Documented as a learning in docs/learnings.md.
  • Model-invocable kept enabled (faithful to source), with a description guardrail against casual triggering given the ~35-40 agent fan-out at full depth.

Verification

  • bun scripts/validate-plugins.mjs — all 4 checks pass (11 plugins, no orphans, valid frontmatter)
  • node --check on the engine; unit-tested the args normalization across string/object/undefined inputs
  • Live end-to-end run (scope: internal, depth: quick): 19/19 agents, 0 errors, produced a full report (51→12→7 funnel earlier; 6 specced this run). The run also confirmed the args fix works in the real harness (meta.scope=internal, meta.depth=quick).

Note (out of scope, pre-existing)

The live run surfaced pre-existing README drift unrelated to this change: cdt is described as "four modes" but ships five (adds bugfix); the tree's ci-review # 10 review agents annotation is stale. Left for a separate docs cleanup to keep this PR focused.

Summary by CodeRabbit

  • New Features

    • Added the feature-discovery plugin and /feature-discovery command.
    • Introduced a guided workflow for researching products and competitors, generating ideas, ranking opportunities, validating proposals, and producing roadmap reports.
    • Added configurable product, scope, and analysis-depth options.
    • Results can be viewed as an artifact and optionally saved for later reference.
    • Added safeguards for incomplete research, invalid inputs, and unavailable competitor data.
  • Documentation

    • Added installation, usage, workflow, licensing, and troubleshooting guidance.
    • Updated plugin listings, installation instructions, repository documentation, and guidance for referencing bundled tools.

Port the open-source feature-discovery skill as a standalone plugin. It runs a
deterministic Workflow pipeline that maps the current product from its repo,
researches competitors, ideates across seven value lenses, dedups and
shortlists, then specs and adversarially validates a ranked roadmap.

The Workflow engine is kept verbatim except for a defensive args normalization:
it accepts the args payload whether it arrives already-parsed or as a JSON
string, so scope/depth are honored instead of silently falling back to the
expensive exhaustive default. Packaging, frontmatter, and the
${CLAUDE_SKILL_DIR} script path are adapted to this marketplace.

Register the plugin in marketplace.json and every README install path (four
install/update loops, the individual-install list, and the structure tree),
add plugin tables to README and CLAUDE, and document the CLAUDE_SKILL_DIR vs
CLAUDE_PLUGIN_ROOT skill-body substitution pitfall in docs/learnings.md.

Credit: ported from github.com/fabianhug/feature-discovery-skill (MIT).
Copilot AI lite review requested due to automatic review settings July 23, 2026 20:06
@gemini-code-assist

Copy link
Copy Markdown

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@coderabbitai

coderabbitai Bot commented Jul 23, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Adds the feature-discovery plugin with a five-phase multi-agent workflow, skill instructions, marketplace registration, installation documentation, repository references, plugin documentation, license text, and bundled-script path guidance.

Changes

Feature discovery plugin

Layer / File(s) Summary
Workflow implementation
plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js
Validates arguments, defines seven ideation lenses, orchestrates five agent phases (Ground, Ideate, Shortlist, Spec & Validate, Synthesize), handles competitor research fallback, and returns a Markdown roadmap with metadata and feature counts.
Skill contract and execution flow
plugins/feature-discovery/skills/feature-discovery/SKILL.md
Defines invocation metadata, workflow phases, argument defaults, result handling, persistence behavior, extension guidance, and attribution for the upstream open-source skill.
Operational and integration guidance
docs/learnings.md
Documents required skill-body path substitution, fan-out pipeline validation rules with explicit error codes, and harness execution model distinctions for testing.
Plugin documentation and packaging
plugins/feature-discovery/README.md, plugins/feature-discovery/LICENSE
Adds plugin overview, prerequisites, installation, usage examples, pipeline phases, parameter documentation, usage caveats, attribution, and MIT license text.
Marketplace registration and repository integration
.claude-plugin/marketplace.json, CLAUDE.md, README.md
Registers the plugin in marketplace and project indexes. Updates plugin listings, install and update commands, repository structure diagram, and plugin count badge.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant User
  participant FeatureDiscoverySkill
  participant FeatureDiscoveryWorkflow
  participant GroundAgents
  participant IdeationAgents
  participant ShortlistCurator
  participant SpecValidateAgents
  participant Synthesizer
  User->>FeatureDiscoverySkill: Invoke /feature-discovery
  FeatureDiscoverySkill->>FeatureDiscoveryWorkflow: Pass product, scope, and depth
  FeatureDiscoveryWorkflow->>GroundAgents: Map product repository and plan competitors
  GroundAgents-->>FeatureDiscoveryWorkflow: Return inventory and segment plan
  FeatureDiscoveryWorkflow->>IdeationAgents: Generate ideas across selected lenses
  IdeationAgents-->>FeatureDiscoveryWorkflow: Return aggregated candidate ideas
  FeatureDiscoveryWorkflow->>ShortlistCurator: Deduplicate and rank by value-to-effort
  ShortlistCurator-->>FeatureDiscoveryWorkflow: Return shortlisted features
  FeatureDiscoveryWorkflow->>SpecValidateAgents: Specify and adversarially validate each feature
  SpecValidateAgents-->>FeatureDiscoveryWorkflow: Return validated features with refinements
  FeatureDiscoveryWorkflow->>Synthesizer: Synthesize polished roadmap with gaps and splits
  Synthesizer-->>FeatureDiscoveryWorkflow: Return Markdown roadmap with analysis
  FeatureDiscoveryWorkflow-->>FeatureDiscoverySkill: Return roadmap, metadata, and feature counts
  FeatureDiscoverySkill-->>User: Present roadmap summary and full report
Loading

Possibly related PRs

  • rube-de/cc-skills#70: Adds related repository discovery and targeted exploration guidance in docs/learnings.md.

Suggested reviewers: copilot

Poem

A rabbit mapped the meadow wide,
Then ranked bright carrots side by side.
Agents refined each growing scheme,
And shaped a clear roadmap dream.
New plugin paths now bloom and gleam—
Hop, /feature-discovery, dream! 🐰

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the addition of the multi-agent feature-discovery roadmap plugin.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feature/feature-discovery-skill
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch feature/feature-discovery-skill

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Add feature-discovery Workflow plugin for multi-agent roadmap discovery

✨ Enhancement 📝 Documentation ⚙️ Configuration changes 🕐 40+ Minutes

Grey Divider

AI Description

• Add a standalone feature-discovery plugin that generates a researched, ranked roadmap via
 Workflow.
• Implement deterministic 5-phase multi-agent pipeline with defensive args parsing for scope/depth.
• Register plugin in marketplace and document installation, usage, and ${CLAUDE_SKILL_DIR} pathing.
Diagram

graph TD
  U([User]) --> S["/feature-discovery skill (SKILL.md)"] --> W["Workflow tool"] --> J["feature-discovery.workflow.js"] --> A["Parallel agents + pipelines"] --> R["Ranked roadmap report (Markdown)"] --> O["Present/Save (Artifact/Write)"]
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Fold into pm plugin as a sub-skill (e.g., pm:roadmap)
  • ➕ Centralizes product-planning capabilities under one namespace
  • ➕ Potentially reuses pm onboarding/UX conventions
  • ➖ Conflates “deep single-feature spec” (brainstorm) with “wide roadmap discovery”
  • ➖ Makes Workflow dependency less explicit and harder to reason about for users
2. Make it skill-only (no plugin packaging)
  • ➕ Simpler distribution surface (SKILL.md only)
  • ➕ Less marketplace/README wiring
  • ➖ Harder to bundle/locate the Workflow script reliably across installs
  • ➖ Less consistent with repo’s plugin structure and validation tooling
3. Stricter args validation with explicit schema + error messaging
  • ➕ Clearer user feedback on invalid scope/depth values
  • ➕ Reduces accidental expensive runs
  • ➖ More divergence from upstream “kept verbatim” engine
  • ➖ Adds maintenance burden for a small practical gain

Recommendation: Keep the standalone plugin approach as implemented: it clearly signals the distinct capability and the Workflow prerequisite, while bundling the deterministic engine script in a reliable, installable structure. The chosen minimal engine modification (args normalization) is the right tradeoff: it prevents an expensive silent fallback without meaningfully diverging from upstream.

Files changed (8) +500 / -8

Enhancement (2) +350 / -0
SKILL.mdAdd feature-discovery skill definition and runbook +121/-0

Add feature-discovery skill definition and runbook

• Adds skill frontmatter (user-invocable, Workflow prerequisite, allowed tools) and step-by-step instructions for invoking the bundled Workflow script and presenting/saving results.

plugins/feature-discovery/skills/feature-discovery/SKILL.md

feature-discovery.workflow.jsAdd deterministic multi-agent Workflow engine with args normalization +229/-0

Add deterministic multi-agent Workflow engine with args normalization

• Introduces the 5-phase Workflow script (Ground, Ideate, Shortlist, Spec & Validate, Synthesize) including JSON schemas, parallel fan-out, pipeline validation, and structured report/meta/count outputs. Adds defensive normalization to accept args as either an object or JSON string so scope/depth are honored.

plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js

Documentation (5) +130 / -8
CLAUDE.mdExpose feature-discovery in top-level command table +1/-0

Expose feature-discovery in top-level command table

• Adds feature-discovery to the documented list of available plugins/commands for quick navigation.

CLAUDE.md

README.mdDocument feature-discovery plugin and update install loops +12/-8

Document feature-discovery plugin and update install loops

• Updates plugin count, adds feature-discovery to the plugins table, and includes it in all install/reinstall command loops and repository structure tree.

README.md

learnings.mdDocument ${CLAUDE_SKILL_DIR} vs ${CLAUDE_PLUGIN_ROOT} substitution pitfall +22/-0

Document ${CLAUDE_SKILL_DIR} vs ${CLAUDE_PLUGIN_ROOT} substitution pitfall

• Adds a new learning explaining why skill bodies must reference bundled scripts via ${CLAUDE_SKILL_DIR} and how using ${CLAUDE_PLUGIN_ROOT} can produce a dead skill due to lack of substitution.

docs/learnings.md

LICENSEAdd MIT license for ported feature-discovery plugin +21/-0

Add MIT license for ported feature-discovery plugin

• Introduces the upstream MIT license text for the feature-discovery plugin with attribution.

plugins/feature-discovery/LICENSE

README.mdAdd plugin README with usage, pipeline, and args +74/-0

Add plugin README with usage, pipeline, and args

• Documents what the plugin does, the Workflow prerequisite/caveats, installation, example triggers, pipeline phases, supported args, and upstream credit.

plugins/feature-discovery/README.md

Other (1) +20 / -0
marketplace.jsonRegister feature-discovery plugin in marketplace +20/-0

Register feature-discovery plugin in marketplace

• Adds a new marketplace entry for the feature-discovery plugin, including description, version, source path, category, author, and keywords.

.claude-plugin/marketplace.json

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a new standalone feature-discovery plugin to the cc-skills marketplace, enabling a multi-agent Workflow-driven pipeline that generates a researched, ranked roadmap (repo grounding → competitor research → ideation lenses → curation → spec + adversarial validation → report synthesis).

Changes:

  • Added the feature-discovery plugin with SKILL instructions and a bundled Workflow engine script.
  • Registered the new plugin across marketplace/docs surfaces (marketplace.json, root README, CLAUDE.md) and documented a packaging learning in docs/learnings.md.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 4 comments.

Show a summary per file
File Description
README.md Bumps plugin count and documents installing/seeing the new plugin.
plugins/feature-discovery/skills/feature-discovery/SKILL.md Defines the new skill’s invocation guidance and how to run the Workflow script.
plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js Implements the deterministic multi-phase Workflow pipeline and args normalization.
plugins/feature-discovery/README.md Adds end-user documentation for installing and using the new plugin.
plugins/feature-discovery/LICENSE Adds MIT license for the ported upstream work.
docs/learnings.md Captures a key packaging lesson about ${CLAUDE_SKILL_DIR} usage in SKILL bodies.
CLAUDE.md Registers the new plugin trigger in the repo’s Claude Code context index.
.claude-plugin/marketplace.json Adds the new plugin entry to the marketplace registry.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread plugins/feature-discovery/README.md Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 06be2aba4b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@plugins/feature-discovery/README.md`:
- Line 4: Update the Claude Code badge markdown in the README to remove the
empty link target: either link the badge to the appropriate Claude Code
documentation or remove the surrounding link wrapper while preserving the badge.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4bd51f9a-794a-44d0-839a-2db617318edc

📥 Commits

Reviewing files that changed from the base of the PR and between f5359d9 and 06be2ab.

📒 Files selected for processing (8)
  • .claude-plugin/marketplace.json
  • CLAUDE.md
  • README.md
  • docs/learnings.md
  • plugins/feature-discovery/LICENSE
  • plugins/feature-discovery/README.md
  • plugins/feature-discovery/skills/feature-discovery/SKILL.md
  • plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js

Comment thread plugins/feature-discovery/README.md Outdated
@qodo-code-review

qodo-code-review Bot commented Jul 23, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (1) 📜 Skill insights (0)

Grey Divider


Action required

1. Illegal top-level return ✓ Resolved 🐞 Bug ≡ Correctness
Description
feature-discovery.workflow.js uses return {…} at file scope (outside any function), which is
invalid JavaScript and will fail before the Workflow can run any phases. This makes the new skill
effectively non-functional on first use if the Workflow runner parses the script as JavaScript.
Code

plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js[R158-163]

+const ground = await parallel(groundThunks)
+const inventory = ground[0]
+if (!inventory) {
+  log('Product mapping failed - cannot ground ideation. Aborting.')
+  return { error: 'product-mapping-failed' }
+}
Relevance

●●● Strong

Top-level return is a deterministic JS syntax/runtime breaker; such correctness fixes get
accepted.

PR-#175

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The file executes workflow steps at top level and then hits return statements without any
surrounding function, including both early aborts and the final result return; this is invalid JS
syntax at file scope.

plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js[141-163]
plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js[218-229]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The workflow script contains `return` statements at top level (outside any function). This is an illegal JavaScript construct and will prevent the script from being parsed/executed by a standard JS engine.

## Issue Context
The script currently mixes top-level orchestration statements (`phase(...)`, `await parallel(...)`) with early-exit returns and a final `return { report, meta, counts }`.

## Fix Focus Areas
- plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js[141-163]
- plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js[218-229]

## Suggested fix approach
- Refactor the workflow body into an exported async entrypoint (whatever the Workflow tool expects), and move all `return` statements inside that function.
- Keep `meta` as a named export if required, but ensure the runner has a valid way to obtain the result object without using top-level `return`.
- Ensure early aborts (`product-mapping-failed`, `empty-shortlist`) use the same in-function return path.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools



Remediation recommended

2. Unvalidated scope/depth args ✓ Resolved 🐞 Bug ☼ Reliability
Description
scope/depth are consumed without normalization/validation, so any typo/case mismatch (e.g.,
Quick, INTERNAL) silently changes behavior (e.g., defaults into competitor-inclusive and/or
exhaustive settings). This can unexpectedly trigger a much more expensive fan-out than the caller
intended.
Code

plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js[R27-59]

+const ARGS = typeof args === 'string'
+  ? (() => { try { return JSON.parse(args) || {} } catch { return {} } })()
+  : (args || {})
+const product = ARGS.product || ''
+const scope = ARGS.scope || 'mixed'
+const depth = ARGS.depth || 'exhaustive'
+const includeCompetitors = scope !== 'internal'
+const emphasis =
+  scope === 'internal'
+    ? 'Focus ideas on gaps in the existing product.'
+    : scope === 'competitor'
+      ? 'Focus ideas on capabilities competitors have that this product lacks.'
+      : 'Draw ideas from a balanced mix of internal gaps and competitor precedent.'
+
+const PRODUCT = product
+  ? `The product is: ${product}.`
+  : 'The product is the one built in the current repository; infer what it is from the code, README, and docs.'
+
+const CONTEXT = `${PRODUCT} Its source code is the current working directory. Map what it does from the repo: entry points and routes, data models, content, services, config, and docs. If a connected MCP server or CLI exposes live product data, you may call it to inspect real usage.`
+
+const ALL_LENSES = [
+  { key: 'discoverability', name: 'Discoverability & acquisition', brief: 'how people and AI agents find the product and its content: search, SEO, structured data, machine-readable surfaces, integrations, shareable and programmatic access.' },
+  { key: 'core-value', name: 'Core value & depth', brief: 'the richness, completeness, and freshness of the product\'s core objects and the primary workflows built on them.' },
+  { key: 'user-ux', name: 'User & contributor UX', brief: 'onboarding, the core task flows, editing and correction, and how data or content stays up to date.' },
+  { key: 'monetization', name: 'Monetization & sustainability', brief: 'ethical, non-annoying ways the product can fund itself: subscriptions, usage tiers, sponsorship, paid placement, pro access.' },
+  { key: 'engagement', name: 'Engagement & retention', brief: 'reasons for users to return: accounts, notifications, digests, collections, collaboration, following.' },
+  { key: 'trust', name: 'Trust, quality & credibility', brief: 'how the product earns trust: verification, moderation, provenance, ratings, transparency about data and sources.' },
+  { key: 'ia-nav', name: 'Information architecture & navigation', brief: 'how content and features are organized and traversed: filtering, faceting, related-entity links, comparison, cross-surface flows.' },
+]
+
+const LENSES = depth === 'quick' ? ALL_LENSES.slice(0, 4) : ALL_LENSES
+const SEGMENT_COUNT = depth === 'quick' ? 2 : 4
+const SHORTLIST_TARGET = depth === 'quick' ? '5-6' : '8-12'
Relevance

●●● Strong

Team often accepts argument normalization/validation to prevent silent fallbacks and expensive
behavior.

PR-#133
PR-#230

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The code uses raw ARGS.scope and ARGS.depth strings and only changes behavior when they exactly
match specific literals; everything else falls into the more expensive defaults (e.g.,
includeCompetitors = scope !== 'internal').

plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js[27-39]
plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js[57-59]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The workflow treats `scope`/`depth` as free strings and only branches on exact matches (`scope === 'internal'`, `depth === 'quick'`). Invalid values are silently accepted and lead to heavier execution paths.

## Issue Context
This workflow is explicitly heavyweight at exhaustive depth; avoiding accidental exhaustive runs is important.

## Fix Focus Areas
- plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js[27-59]

## Suggested fix approach
- Normalize inputs (trim + lowercase) before branching.
- Validate against explicit allowlists: `scope ∈ {mixed, internal, competitor}`, `depth ∈ {exhaustive, quick}`.
- On invalid values, return a structured error (e.g., `{ error: 'invalid-args', allowed: {...}, received: {...} }`) so the skill can ask the user to correct inputs rather than defaulting silently.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


3. Missing scripts/ in plugin 📘 Rule violation ✧ Quality
Description
feature-discovery is registered as a plugin, but its plugin root lacks the required top-level
scripts/, hooks/, agents/, and commands/ subdirectories. This violates the repository plugin
layout convention and can break tooling, installation/runtime expectations, and consistent discovery
of plugin assets.
Code

.claude-plugin/marketplace.json[R213-216]

+      "name": "feature-discovery",
+      "description": "Discover what to build next: map the current product from its repo, research competitors, ideate across value lenses, dedup and shortlist, then spec and adversarially validate a ranked roadmap via a deterministic multi-agent Workflow pipeline",
+      "version": "2.6.2",
+      "source": "./plugins/feature-discovery",
Relevance

●● Moderate

Repo has plugin layout conventions, but no close precedent enforcing empty
scripts/hooks/agents/commands for plugin-only add.

PR-#175

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
PR Compliance IDs 49683, 49684, 49686, and 49687 each require that every plugin root include
scripts/, hooks/, agents/, and commands/ respectively. The PR registers feature-discovery
with source ./plugins/feature-discovery in the marketplace configuration, but the repo tree
snippet for that plugin root shows only a skills/ directory under it, demonstrating that none of
the required top-level directories (scripts/, hooks/, agents/, commands/) are present.

Rule 49683: Ensure each plugin directory contains a scripts subdirectory
Rule 49684: Ensure each plugin directory contains a hooks subdirectory
Rule 49686: Enforce agents subdirectory in each plugin directory
Rule 49687: Require commands subdirectory in each plugin directory
.claude-plugin/marketplace.json[213-216]
README.md[198-202]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The plugin registered at `./plugins/feature-discovery` does not conform to the standard plugin layout because it is missing the required top-level `scripts/`, `hooks/`, `agents/`, and `commands/` directories.

## Issue Context
The marketplace registers `feature-discovery` at `./plugins/feature-discovery`, so the plugin root must include all required top-level subdirectories to satisfy repository conventions and avoid breaking loaders/tooling and runtime expectations.

## Fix Focus Areas
- plugins/feature-discovery/scripts/.gitkeep[1-1]
- plugins/feature-discovery/hooks/.gitkeep[1-1]
- plugins/feature-discovery/agents/.gitkeep[1-1]
- plugins/feature-discovery/commands/.gitkeep[1-1]
- .claude-plugin/marketplace.json[213-216]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


4. Unbounded prompt/context growth ✓ Resolved 🐞 Bug ➹ Performance
Description
The workflow repeatedly embeds full JSON-stringified intermediate artifacts (inventory, competitor
results, all ideas, specced results) into later agent prompts, multiplying token usage across the
fan-out. This creates a real risk of truncated context, higher cost/latency, and occasional agent
failures on larger repos or verbose intermediate outputs.
Code

plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js[R175-191]

+// ---- Phase 2: Ideate ------------------------------------------------------
+phase('Ideate')
+const groundContext = JSON.stringify({ inventory, competitors: competitorResults })
+
+const ideaResults = await parallel(LENSES.map((lens) => () => agent(
+  `${CONTEXT}\n\nGround truth (current-product inventory + competitor research):\n${groundContext}\n\nYou are a PRODUCT IDEATOR working the "${lens.name}" lens: ${lens.brief}\n\n${emphasis}\n\nPropose new, value-adding features or improvements through this lens. Rules: never propose anything the inventory shows already exists; ground every idea in either a concrete product gap or a named competitor precedent; prefer depth and specificity over a long list of shallow ideas. For each idea give: title, description, the lens, the user-value hypothesis, the evidence (the gap or competitor it comes from), and a rough effort estimate (S, M, or L).`,
+  { label: `ideate:${lens.key}`, phase: 'Ideate', schema: IDEAS_SCHEMA },
+)))
+
+const allIdeas = ideaResults.filter(Boolean).flatMap((r) => (r && r.ideas) || [])
+log(`${allIdeas.length} raw ideas from ${LENSES.length} lenses`)
+
+// ---- Phase 3: Shortlist (barrier: needs every idea at once to dedup) ------
+phase('Shortlist')
+const shortlist = await agent(
+  `${CONTEXT}\n\nHere are ${allIdeas.length} candidate ideas from parallel ideators across different lenses:\n${JSON.stringify(allIdeas)}\n\nCurrent-product inventory:\n${JSON.stringify(inventory)}\n\nYou are the CURATOR. Merge duplicate and near-duplicate ideas into single consolidated items. Remove anything that already exists or is trivial. Rank the survivors by value-to-effort and select the TOP ${SHORTLIST_TARGET} for full speccing. For each selected item return: a clear title, a merged description, why it matters (value), rough effort, and the supporting evidence (gaps and/or competitors).`,
+  { label: 'curate:shortlist', phase: 'Shortlist', schema: SHORTLIST_SCHEMA },
Relevance

●● Moderate

Prompt-size bounding is subjective and may conflict with “engine kept verbatim”; only indirect
truncation precedent.

PR-#230

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The script constructs prompts by injecting full serialized intermediate results (including into each
parallel ideator), and the skill itself documents a large sub-agent fan-out, so prompt size/cost
scales multiplicatively.

plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js[175-191]
plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js[218-223]
plugins/feature-discovery/skills/feature-discovery/SKILL.md[3-13]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Large intermediate objects are passed verbatim via `JSON.stringify(...)` into multiple downstream prompts (including parallel ideators), which can blow up token usage.

## Issue Context
The skill advertises ~35-40 sub-agents at exhaustive depth; unbounded per-agent prompt size compounds quickly.

## Fix Focus Areas
- plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js[175-191]
- plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js[189-191]
- plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js[218-223]
- plugins/feature-discovery/skills/feature-discovery/SKILL.md[3-13]

## Suggested fix approach
- Introduce a size budget for `inventory`/`competitorResults`/`allIdeas` before embedding into prompts.
- Pass compact summaries (e.g., top N features + top N gaps + key competitor deltas) rather than full raw blobs.
- For curator/synthesizer, consider including only fields actually needed (titles + 1-2 sentence summaries) and keep full details in a separate artifact store if the Workflow runtime supports it.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context used
✅ Compliance rules (platform): 12 rules

To customize comments, go to the Qodo configuration screen, or learn more in the docs.

Qodo Logo

Comment thread .claude-plugin/marketplace.json
@rube-de

rube-de commented Aug 3, 2026

Copy link
Copy Markdown
Owner Author

PR Comment Status

Status Threads Review Bodies Issue Comments Total
Resolved 0 3 3 6
Fixed by DLC 7 0 0 7
Answered by DLC 2 0 0 2
Skipped (user decision) 0 0 0 0
Discussion-Deferred 0 0 0 0
Discussion-Tracked 0 0 0 0
Pending-Human 2 0 1 3
Blocked 0 0 0 0
Dismissed 0 0 0 0
Total 11 3 4 18

Fixed

  • feature-discovery.workflow.js:33 — added scope/depth normalization + allowlist validation, returning a structured invalid-args error on bad input (also fixes the duplicate finding at :59).
  • feature-discovery.workflow.js:134 — bounded VERDICT_SCHEMA.confidence to 1-10, matching the validator prompt.
  • feature-discovery.workflow.js:226 — added a synthesis-failed guard when the synthesizer returns no report.
  • feature-discovery.workflow.js:216 — added an empty-validated-results guard before synthesis when no features survive validation.
  • plugins/feature-discovery/README.md:4 — linked the Claude Code badge (also fixes the duplicate finding on the same line).

Answered (verified false positives)

  • "Illegal top-level return" — node --check passes; this repo has no "type": "module" override, so .js files run under Node's CommonJS wrapper, which permits top-level return. This exact script has also already completed full live Workflow runs successfully in this repo.
  • "Missing scripts/hooks/agents/commands directories" — scripts/validate-plugins.mjs:86,130 requires at least one of the four directories (OR, not AND), and three existing plugins (doppler, oasis-dev, temporal) ship with only skills/ and pass CI today.

Needs your input (Pending-Human)

These require a human call and were intentionally left unresolved and unreplied — an attended /dlc:pr-check 236 run will surface them for triage:

  1. Prompt gates external MCP/CLI calls with no read-only restriction (feature-discovery.workflow.js:45, @copilot-pull-request-reviewer) — the ideation prompt lets an agent invoke any connected MCP server/CLI to "inspect live usage." Tightening this diverges from the locked "verbatim upstream engine" decision for this PR — your call on whether to harden it here or track separately.
  2. Unbounded prompt/context growth from JSON-stringified intermediates (feature-discovery.workflow.js:191, @qodo-code-review; also raised as part of the bundled Qodo issue-comment review) — full inventory/competitor/idea payloads are embedded verbatim into every downstream agent prompt. A real cost/reliability concern at scale, but bounding it is an architecture change to the "kept verbatim" engine — needs your judgment on scope.

Follow-up

Author will address the Pending-Human items above manually, or re-run /dlc:pr-check 236 in attended mode to triage them interactively.

Separately (not blocking, not part of this PR's diff): the empty Claude Code badge link fixed here is a repo-wide copy-paste pattern — 7 of 8 plugin READMEs share the same dead ]() link. Worth a follow-up cleanup PR if useful.

Copilot AI commented Aug 3, 2026

Copy link
Copy Markdown

@rube-de I've opened a new pull request, #239, to work on those changes. Once the pull request is ready, I'll request review from you.

Address reviewer feedback on the feature-discovery workflow engine and
plugin README: validate/normalize scope and depth args against an
allowlist, bound the validator confidence schema to 1-10, guard against
an empty synthesis report and against zero validated features surviving
spec review, and fix the dead Claude Code badge link.
Copilot AI review requested due to automatic review settings August 3, 2026 13:44
@qodo-code-review

Copy link
Copy Markdown

PR Comment Status

Status Threads Review Bodies Issue Comments Total
Resolved 0 3 3 6
Fixed by DLC 7 0 0 7
Answered by DLC 2 0 0 2
Skipped (user decision) 0 0 0 0
Discussion-Deferred 0 0 0 0
Discussion-Tracked 0 0 0 0
Pending-Human 2 0 1 3
Blocked 0 0 0 0
Dismissed 0 0 0 0
Total 11 3 4 18

Fixed

  • feature-discovery.workflow.js:33 — added scope/depth normalization + allowlist validation, returning a structured invalid-args error on bad input (also fixes the duplicate finding at :59).
  • feature-discovery.workflow.js:134 — bounded VERDICT_SCHEMA.confidence to 1-10, matching the validator prompt.
  • feature-discovery.workflow.js:226 — added a synthesis-failed guard when the synthesizer returns no report.
  • feature-discovery.workflow.js:216 — added an empty-validated-results guard before synthesis when no features survive validation.
  • plugins/feature-discovery/README.md:4 — linked the Claude Code badge (also fixes the duplicate finding on the same line).

Answered (verified false positives)

  • "Illegal top-level return" — node --check passes; this repo has no "type": "module" override, so .js files run under Node's CommonJS wrapper, which permits top-level return. This exact script has also already completed full live Workflow runs successfully in this repo.
  • "Missing scripts/hooks/agents/commands directories" — scripts/validate-plugins.mjs:86,130 requires at least one of the four directories (OR, not AND), and three existing plugins (doppler, oasis-dev, temporal) ship with only skills/ and pass CI today.

Needs your input (Pending-Human)

These require a human call and were intentionally left unresolved and unreplied — an attended /dlc:pr-check 236 run will surface them for triage:

  1. Prompt gates external MCP/CLI calls with no read-only restriction (feature-discovery.workflow.js:45, @copilot-pull-request-reviewer) — the ideation prompt lets an agent invoke any connected MCP server/CLI to "inspect live usage." Tightening this diverges from the locked "verbatim upstream engine" decision for this PR — your call on whether to harden it here or track separately.
  2. Unbounded prompt/context growth from JSON-stringified intermediates (feature-discovery.workflow.js:191, @qodo-code-review; also raised as part of the bundled Qodo issue-comment review) — full inventory/competitor/idea payloads are embedded verbatim into every downstream agent prompt. A real cost/reliability concern at scale, but bounding it is an architecture change to the "kept verbatim" engine — needs your judgment on scope.

Follow-up

Author will address the Pending-Human items above manually, or re-run /dlc:pr-check 236 in attended mode to triage them interactively.

Separately (not blocking, not part of this PR's diff): the empty Claude Code badge link fixed here is a repo-wide copy-paste pattern — 7 of 8 plugin READMEs share the same dead ]() link. Worth a follow-up cleanup PR if useful.

The status update is consistent with the review disposition described:

  • finding 1 — answered as a false positive; no code change needed.
  • finding 2 — fixed through scope/depth normalization and allowlist validation.
  • finding 3 — answered as a false positive; the validator requires at least one supported plugin directory, not all four.
  • finding 4 — remains the substantive pending-human decision regarding unbounded prompt/context growth.

The external MCP/CLI read-only concern is separate from the indexed Qodo findings. Since no dismissal was requested, the findings may still appear active in the review index despite being answered or fixed in the PR discussion.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f0a6085b33

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/feature-discovery/skills/feature-discovery/SKILL.md Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In
`@plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js`:
- Around line 31-45: Update the rawScope and rawDepth argument handling to
default only when the arguments are genuinely missing, not for explicit falsey
values; require supplied values to be strings before trimming and lowercasing,
then validate them against VALID_SCOPES and VALID_DEPTHS so invalid types and
values return the existing invalid-args result.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 42c270ed-748b-4906-9ad8-1c0cc6a8d3ff

📥 Commits

Reviewing files that changed from the base of the PR and between 06be2ab and f0a6085.

📒 Files selected for processing (2)
  • plugins/feature-discovery/README.md
  • plugins/feature-discovery/skills/feature-discovery/scripts/feature-discovery.workflow.js
🚧 Files skipped from review as they are similar to previous changes (1)
  • plugins/feature-discovery/README.md

Guard the args normalization against an undeclared args binding, stop
silently defaulting explicit falsy scope/depth values instead of
rejecting them, add an empty-ideation guard before curating a
shortlist, fix the validator pipeline to actually drop failed
validations instead of wrapping them as truthy, and generalize the
SKILL.md error contract so it covers every current and future error
code instead of an enumerated list.
Copilot AI review requested due to automatic review settings August 3, 2026 13:56
@rube-de

rube-de commented Aug 3, 2026

Copy link
Copy Markdown
Owner Author

PR Comment Status (this cycle's delta)

Bots posted 5 new substantive comments on the previous fix commit (f0a6085) — all confirmed as real, valid findings and fixed. The 2 Pending-Human items from last cycle are unchanged (still awaiting your triage).

Status This cycle Running total
Fixed by DLC 5 12
Pending-Human 0 (unchanged) 2

Fixed this cycle

  • feature-discovery.workflow.js:29 (@copilot-pull-request-reviewer) — args normalization could throw a ReferenceError if the harness left args fully undeclared rather than undefined. Guarded with a typeof check before any direct reference.
  • feature-discovery.workflow.js:45 (@coderabbitai) — scope/depth defaulting used x || default, which silently replaced explicit falsy values ('', 0, false) instead of rejecting them. Now defaults only on undefined and requires a string type, matching the reviewer's proposed diff.
  • feature-discovery.workflow.js:203 (@chatgpt-codex-connector) — if every ideator failed, the curator was still invoked on an empty idea list and could invent an ungrounded shortlist. Added an empty-ideation guard before curation.
  • feature-discovery.workflow.js:226 (@chatgpt-codex-connector) — the validator pipeline wrapped every result (even failed ones) in a truthy object, so specced.filter(Boolean) never dropped failures and the empty-validated-results guard from last cycle couldn't fire. Now returns null on a falsy verdict.
  • SKILL.md:91 (@chatgpt-codex-connector) — the error-handling instruction only enumerated 2 of what are now 6 possible error codes. Rewrote it as a general rule (any error key short-circuits processing) so it can't drift out of sync again.

Still pending your input

Unchanged from the last cycle — feature-discovery.workflow.js:45 (MCP/CLI prompt gating) and feature-discovery.workflow.js:203 (unbounded prompt/context growth, line shifted from :191). See the previous summary comment for details.

@coderabbitai

coderabbitai Bot commented Aug 3, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

@rube-de Acknowledged. The scope and depth defaulting fix addresses the finding at feature-discovery.workflow.js:45.

The two Pending-Human items remain separate design decisions. They need maintainer triage before this PR changes the upstream workflow behavior.


If you found this review helpful, would you consider giving us a shout-out on X?

Thank you for using CodeRabbit!

You are interacting with an AI system.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated no new comments.

Suppressed comments (1)

plugins/feature-discovery/skills/feature-discovery/SKILL.md:25

  • metadata.version is formatted as "1.0", but other SKILL.md files in this repo consistently use SemVer with a patch component (e.g. "1.0.0" in plugins/temporal/skills/temporal/SKILL.md and plugins/doppler/skills/doppler/SKILL.md). Aligning the format avoids inconsistent version parsing/expectations across skills.
  version: "1.0"

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9d28d9813d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 117e59bb31

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated no new comments.

Suppressed comments (1)

plugins/feature-discovery/skills/feature-discovery/SKILL.md:21

  • scope: competitor / mixed runs require WebSearch/WebFetch (as stated in compatibility: and used by the Workflow script), but those tools are not listed under allowed-tools. If the skill invocation is what pre-approves tools for the session, Workflow sub-agents may fail because they cannot prompt for tool approval.
allowed-tools:
  - Workflow
  - Artifact
  - Write
  - Read

@rube-de

rube-de commented Aug 4, 2026

Copy link
Copy Markdown
Owner Author

Duplicate of the same finding raised repeatedly across this PR, already answered: allowed-tools only governs what the orchestrating SKILL.md agent itself can call directly; the competitor-research agents are spawned inside the Workflow script and reach tools through the session's already-connected tools via ToolSearch, independent of this list.

Copilot AI review requested due to automatic review settings August 4, 2026 17:47

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated no new comments.

Suppressed comments (1)

plugins/feature-discovery/skills/feature-discovery/SKILL.md:20

  • allowed-tools does not include WebSearch/WebFetch, but the skill’s own compatibility note and the bundled workflow script rely on WebSearch/WebFetch for scope: competitor and scope: mixed runs. Since Workflow sub-agents can’t prompt for tool approval, leaving these tools out makes competitor research likely to fail even when the environment supports them.

Add WebSearch and WebFetch to allowed-tools so they can be pre-approved for the skill invocation.

compatibility: "Requires the Workflow tool (multi-agent orchestration). Invoking this skill opts into a heavyweight fan-out of up to ~40 sub-agents at exhaustive depth. For scope: competitor or mixed runs, the session also needs WebSearch and WebFetch pre-approved - Workflow sub-agents run in the background and can't prompt for tool approval."
allowed-tools:
  - Workflow
  - Artifact
  - Write

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b7375e598f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@rube-de

rube-de commented Aug 4, 2026

Copy link
Copy Markdown
Owner Author

Duplicate of the same finding raised repeatedly across this PR, already answered: allowed-tools only governs what the orchestrating SKILL.md agent itself can call directly; the competitor-research agents are spawned inside the Workflow script and reach tools through the session's already-connected tools via ToolSearch, independent of this list.

Copilot AI review requested due to automatic review settings August 4, 2026 17:57

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: aa8fec1977

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated no new comments.

Suppressed comments (1)

plugins/feature-discovery/skills/feature-discovery/SKILL.md:21

  • feature-discovery.workflow.js instructs competitor agents to use WebSearch/WebFetch, and the frontmatter compatibility notes those tools must be pre-approved because Workflow sub-agents can’t prompt. However, WebSearch/WebFetch aren’t included in allowed-tools, so a competitor/mixed run can still fail due to missing tool approval.

Add WebSearch and WebFetch to allowed-tools so sessions that invoke the skill pre-approve the tools the Workflow run depends on.

allowed-tools:
  - Workflow
  - Artifact
  - Write
  - Read

@rube-de

rube-de commented Aug 4, 2026

Copy link
Copy Markdown
Owner Author

Duplicate of the same finding raised repeatedly across this PR, already answered: allowed-tools only governs what the orchestrating SKILL.md agent itself can call directly; the competitor-research agents are spawned inside the Workflow script and reach tools through the session's already-connected tools via ToolSearch, independent of this list.

Copilot AI review requested due to automatic review settings August 4, 2026 18:06

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated no new comments.

Suppressed comments (1)

plugins/feature-discovery/skills/feature-discovery/SKILL.md:22

  • compatibility warns that competitor/mixed runs need WebSearch/WebFetch pre-approved because Workflow sub-agents can’t prompt for tool approval, but allowed-tools doesn’t include WebSearch/WebFetch (or basic repo-mapping tools like Grep/Glob/Bash). This makes it much more likely that a real invocation will fail or degrade depending on the environment’s default approvals, even though the skill description expects those tools to be available to sub-agents.
compatibility: "Requires the Workflow tool (multi-agent orchestration). Invoking this skill opts into a heavyweight fan-out of up to ~40 sub-agents at exhaustive depth. For scope: competitor or mixed runs, the session also needs WebSearch and WebFetch pre-approved - Workflow sub-agents run in the background and can't prompt for tool approval."
allowed-tools:
  - Workflow
  - Artifact
  - Write
  - Read
  - AskUserQuestion

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1cfbb109d5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@rube-de

rube-de commented Aug 4, 2026

Copy link
Copy Markdown
Owner Author

Duplicate of the same finding raised repeatedly across this PR, already answered: allowed-tools only governs what the orchestrating SKILL.md agent itself can call directly; the competitor-research and product-mapper agents are spawned inside the Workflow script and reach tools (WebSearch/WebFetch, and basic tools like Grep/Glob/Bash) through the session's already-connected tools via ToolSearch, independent of this list. Grep/Glob/Bash specifically aren't gated behind allowed-tools pre-approval the way WebSearch/WebFetch can be in restricted sessions - they're basic tools available to any spawned agent without an approval prompt.

Copilot AI review requested due to automatic review settings August 4, 2026 18:19

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated no new comments.

Suppressed comments (1)

plugins/feature-discovery/skills/feature-discovery/SKILL.md:22

  • compatibility says competitor/mixed runs need WebSearch/WebFetch pre-approved, but the skill’s allowed-tools list doesn’t include them. Since Workflow sub-agents can’t prompt for tool approval, this makes competitor research likely to fail in environments where tools must be pre-approved via allowed-tools. Add WebSearch and WebFetch here so they’re requested up-front.
  - Workflow
  - Artifact
  - Write
  - Read
  - AskUserQuestion

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9684fd344e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +232 to +235
ideas: { type: 'array', maxItems: MAX_IDEAS_PER_LENS, items: { type: 'object', properties: {
title: { type: 'string', maxLength: 100 }, description: { type: 'string', maxLength: 400 }, lens: { type: 'string', maxLength: 50 },
valueHypothesis: { type: 'string', maxLength: 400 }, evidence: { type: 'string', maxLength: 400 }, effort: { type: 'string', enum: ['S', 'M', 'L'] },
}, required: ['title', 'description', 'lens', 'valueHypothesis', 'evidence', 'effort'] } },

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reject unbounded extra fields from ideator output

The declared idea fields are length-bounded, but the item schema still permits additional properties. If an ideator emits a schema-valid extra field such as a large rationale or notes blob, it survives flatMap and is serialized into the curator prompt at line 393; across seven independent lenses this bypasses the intended context bound and can overflow or substantially inflate the curator call. Set additionalProperties: false on each idea item or normalize outputs to the known fields.

Useful? React with 👍 / 👎.

Comment on lines +243 to +246
features: { type: 'array', maxItems: SHORTLIST_MAX, items: { type: 'object', properties: {
title: { type: 'string', pattern: '\\S' }, description: { type: 'string', pattern: '\\S' }, value: { type: 'string', pattern: '\\S' },
effort: { type: 'string', pattern: '\\S' }, evidence: { type: 'string', pattern: '\\S' },
}, required: ['title', 'description', 'value', 'effort', 'evidence'] } },

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Bound shortlisted feature text before fan-out

When the curator returns unusually verbose but schema-valid feature descriptions, values, or evidence, none of these five strings has a maxLength. Each feature is then copied into its spec prompt, validator prompt, and the final clean payload, so up to twelve verbose entries can multiply prompt cost or exhaust downstream context despite the bounds added to ideas and specs. Add per-field limits and reject or strip additional properties here as well.

Useful? React with 👍 / 👎.

Comment on lines +273 to +274
objections: { type: 'array', minItems: 1, items: { type: 'string', pattern: '\\S' } },
refinements: { type: 'array', items: { type: 'string' } },

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Bound validator output before synthesis

At exhaustive depth, twelve independent validators can each return schema-valid objections and refinements with arbitrarily many arbitrarily long strings. Line 452 concatenates all verdicts via JSON.stringify(clean), so verbose validator responses can overflow the synthesizer context after every prior phase has completed and turn the run into synthesis-failed; add suitable maxItems and item maxLength constraints.

Useful? React with 👍 / 👎.

@rube-de

rube-de commented Aug 4, 2026

Copy link
Copy Markdown
Owner Author

Duplicate of the same finding raised repeatedly across this PR, already answered: allowed-tools only governs what the orchestrating SKILL.md agent itself can call directly; the competitor-research agents are spawned inside the Workflow script and reach tools through the session's already-connected tools via ToolSearch, independent of this list.

@rube-de
rube-de merged commit 758d330 into main Aug 5, 2026
3 checks passed
@rube-de
rube-de deleted the feature/feature-discovery-skill branch August 5, 2026 15:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants