Skip to content

feat: add Copilot Agent Plugins and MCP inventory - #235

Open
raysubham wants to merge 9 commits into
step-security:mainfrom
raysubham:feat/copilot-plugin-inventory
Open

raysubham wants to merge 9 commits into
step-security:mainfrom
raysubham:feat/copilot-plugin-inventory

Conversation

@raysubham

@raysubham raysubham commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

What does this PR do?

Adds Copilot CLI, standalone Copilot app and VS Code Agent Plugins inventory to the existing plugin scan phase. Collects recorded installations and persistent local-marketplace selections, their supplied skills, custom-agent declarations and sanitized MCP definitions, plus standalone user/project MCP configurations. Preserves source, scope, enablement observations and parent relationships without treating cached directories as installed plugins.

Reuses bounded, file-only readers and TCC protection. Git/GitHub catalogs support complete component coverage when matching evidence is readable; failed reads remain partial. Regression tests preserve shared MCP symlinks and unrelated project MCP configurations. Copilot cases are consolidated into the common Agent Plugins golden fixture with Claude/Codex. Matching API fixture/test updates are in main PR #11029 and integration follow-up #11093. Existing AITool inventory and internal/aiagents are unchanged.

Copilot tests use the existing shared plugin, MCP and model test files. Production adapters retain the existing per-agent file pattern.

Type of change

  • Enhancement
  • Documentation

Testing

  • Full go test -race ./..., plus affected-package regression tests
  • go vet ./..., golangci-lint run ./..., formatting and whitespace checks
  • go mod tidy -diff with no dependency drift
  • make smoke: 45/45 checks passed
  • CGO-disabled builds for Linux amd64, macOS arm64 and Windows amd64
  • Shared fixture: DMG contract test and existing API fixture/lifecycle tests passed
  • Pinned Copilot 1.0.91 native-format probes in an isolated offline environment
  • No secrets or credentials included

Gosec completed with no package-load errors and the same 24 pre-existing findings. The four original local review findings were fixed and revalidated. Expanded native-surface limitations are tracked in the live runbook.

Native CLI core lifecycle was checked on macOS, Linux and Windows. Expanded Mac checks cover five app marketplace plugins, three editor/Agents marketplace selections, project local-source registration, toggles/removal and integration Skills/MCP supplier links. Commands, rules and LSP declarations were added with regression tests and a native packaged-fixture check. Rules carry declaration metadata only; CLI runtime activation is not claimed. Expanded Windows/Linux app/editor checks and app-only local GUI lifecycle remain pending. Deployed rule-kind acceptance passed on Mac. Editor activation stays unknown where its private state is not collected. TCC-protected paths remain guarded.

Follow-up commit: 8b8e85c, signature verified. Shared fixture SHA-256: 4aa872e1df3d2c33326cd43193d17f7c0b1d36ce0a4e4f3734af8e0b3144215b. Backend rule-kind acceptance from #11093 is deployed and verified on integration. Release the matching backend changes before this candidate in production.

Custom-catalog follow-up: signed commit dcdb8fb resolves editor file-URI catalogs to their validated Git payload provenance. Native VS Code installation from the owned private catalog, stable identity across CLI/editor, four linked skill/command rows, unselected-entry exclusion and post-uninstall API restoration passed. Missing/mismatched/protected catalogs have regression coverage. Full local gates passed. Latest DMG CI passed Test; remaining jobs were cancelled before execution because hosted runners were not acquired. DMG/main release PRs remain unmerged; API integration follow-up #11093 is merged and deployed.

Post-deployment Mac retest: exact skill/command/rule/LSP details, all four kind filters and skill/command supplier refs passed. Native CLI uninstall and restored API checks passed: six plugin groups, nine installations, 23 linked skills and exact MCP supplier refs. Claude/Codex control IDs and skill hashes match the earlier baseline. No new product fix was needed. Latest DMG CI passed tests, but other jobs could not acquire hosted runners; full CI is not green.

Standalone Mac app custom local-catalog selection passed: the user enabled incident-review through the app. DMG and deployed APIs agree on its single local installation, complete skill component, identity and content hash. Native uninstall for this live plugin only disables it; the backend correctly retained the same installation/skill with configured_enabled=false. This is not a GUI uninstall pass. The app's private Git clone failed authentication despite working shell Git/GitHub access; that native-app/setup limitation remains logged, not reported as a collector defect. Existing Claude/Codex control records remain unchanged.

@raysubham raysubham changed the title Add Copilot CLI Agent Plugins and MCP inventory feat: add Copilot CLI Agent Plugins and MCP inventory Oct 5, 2026
@raysubham raysubham changed the title feat: add Copilot CLI Agent Plugins and MCP inventory feat: add Copilot Agent Plugins and MCP inventory Oct 5, 2026
@raysubham

Copy link
Copy Markdown
Contributor Author

Live integration validation found an editor marketplace identity mismatch. Signed commit cbe8792 preserves the receipt marketplace reference instead of overwriting it with the catalog display name; a regression assertion covers the ID/name contract. Synced current main in signed ba5df7e so the full existing workflow uses a compatible candidate, including already-merged Go inventory. Full race tests, lint, vet, 45 smoke checks and three-platform builds passed. Full three-platform Developer MDM V1 run: https://github.com/step-security/integration-test/actions/runs/37526699915. Live acceptance remains in progress; this PR is not merged.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant