應用AI產業

GitHub Copilot code review 對所有方案開放 Agent skills 與 MCP:工具呼叫限唯讀

GitHub Copilot code review 對所有方案開放 Agent skills 與 MCP:工具呼叫限唯讀 能源, AI, 產業

GitHub 7 月 29 日宣布,Copilot code review 對 Copilot Pro、Pro+、Business 與 Enterprise 使用者一般開放 Agent skills 與 MCP server 支援。Agent skills 可以把儲存在 repository 的規則與工具流程帶進程式碼審查;MCP 則讓審查取得 issue tracker、文件、service catalog 或 incident tooling 等 Pull Request 以外的上下文。

GitHub 同時限制 Copilot code review 發出的 MCP tool call 為唯讀,並在評論中標示使用了哪些 skill 或 MCP context。既有 Copilot cloud agent 的 MCP 設定會自動套用到 code review,GitHub MCP 與 Playwright MCP 則預設開啟。

GitHub Copilot code review 將 Agent skills 與 MCP 帶出預覽

Agent skills 是放在 repository .github/skills 下的技能資料夾,內容可包含 SKILL.md、指令、腳本與其他資源。Copilot code review 會在技能與目前審查任務相關時使用它們,讓團隊把語言規範、遷移檢查或安全清單寫成可重複套用的 review workflow。

MCP server 則處理 Pull Request 本身沒有的資料。GitHub 文件列出的例子包括把變更連到 issue、incident 或 service ownership,或從外部文件核對實作條件。這些連線能增加審查所見的資料範圍,但不代表每個 repository 都會自動取得所有外部系統內容。

MCP 工具呼叫限定唯讀並標示上下文來源

GitHub 的 GA 公告明確限定 Copilot code review 使用的 MCP tool call 為 read-only。審查可以讀取設定允許的外部上下文,但不會因為 MCP 連線而直接替外部系統新增、修改或刪除資料;權杖仍要放在 repository 的 Secrets and variables → Agents 設定中。

當評論使用了 Agent skill 或 MCP context,GitHub 會在評論中加入 attribution。管理員與開發者可以從 review comment 或 Pull Request timeline 的 linked review session 檢查呼叫過哪些 MCP server 與工具,方便核對評論使用的上下文來源。

GitHub Copilot code review 對所有方案開放 Agent skills 與 MCP:工具呼叫限唯讀 能源, AI, 產業

GitHub 以 .github/skills 與 repository settings 接入團隊規則

新使用者可以在 .github/skills 建立特定技能目錄,再放入 SKILL.md;MCP 設定則從 repository settings → Copilot → MCP servers 建立。GitHub 建議使用具體的技能目錄名稱,例如 code-review,讓系統較容易判斷該技能與審查工作相關。

Copilot code review 也會使用 repository 的 custom instructions。文件列出 repository-wide .github/copilot-instructions.md 與 path-specific instructions 等方式,讓團隊把審查規則、特定目錄要求與安全條件留在程式碼庫內管理。

Copilot code review 仍由 GitHub Actions 執行代理工作

GitHub 文件指出,Copilot code review 的 agentic capabilities 會使用 GitHub Actions 執行,審查在類似 Copilot cloud agent 的暫時開發環境中處理。若 GitHub-hosted runner 不可用,且沒有正確設定支援的 self-hosted 或大型 runner,審查會退回較受限的模式。

Agent skills 與 MCP 現在已經一般可用,但外部上下文的實際範圍仍由 repository 設定、MCP 權限、runner 與技能內容決定。GitHub 公告沒有提供因為這次 GA 而降低錯誤率或提升合併品質的獨立數據。

消息來源:GitHub ChangelogGitHub code review 文件GitHub review 工作流程

延伸閱讀
緯創德州 D1 開幕並量產 NVIDIA GB300,Vera Rubin 生產線同步預留
文章・產業
HUAWEI 把智慧錶搬進中山站:WATCH FIT 5 體驗展登場,FreeClip 2 S 搶先亮相
文章・華為穿戴
失物招領處今天拒收了五樣東西
文章・向量偏移
Written by
黃郁棋

《科技人》站長,在科技業打滾十年的老屁股,每天都覺得自己要被新技術取代了,完了完了。

打賞科技人|祝您有個美好的一天

科技人原創 BGM

音樂目錄載入中

預設暫停,等你按下播放

0:00 0:00