feat(blocking-review): add cost guards and scope constraints - #17
Merged
Conversation
Add max_turns (default 6), timeout_minutes (default 4), and model inputs to prevent runaway API usage. A review on transmission-filebot PR #23 consumed 20 turns, $1.00, and 11 minutes for a 109-line diff. - Add --max-turns and --model to claude_args - Add timeout-minutes to the Claude step - Add input validation with env vars (prevents expression injection) - Validate integer format before range checks - Add scope constraints to prompt (diff-only, no codebase exploration) - Replace plugin-based example template with blocking review caller Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
4 tasks
…ermissions on the example caller workflow. Add explicit permissions block matching what the called reusable workflow needs (contents:read, pull-requests:write, issues:write, id-token:write for claude-code-action OIDC auth). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
max_turns(default 6),timeout_minutes(default 4), andmodelinputs toclaude-blocking-review.ymlMotivation
A Claude review on transmission-filebot PR #23 consumed 20 API turns, $1.00, and 11 minutes for a 109-line diff. The Anthropic
code-reviewplugin has no turn limit or timeout, allowing unconstrained exploration.Test plan
v1tagtimeout_minutesandmax_turnsinputs work when overridden by callers🤖 Generated with Claude Code