Files
roboco/docs/rag/troubleshooting/blocked-tools.md
T
Renn F f48106cbb6 docs: reflow hard-wrapped prose to one line per paragraph
Markdown and editors soft-wrap on their own, so the manual ~75-char line
breaks across the docs added nothing but noise. Join wrapped prose, list
items, and paragraphs into single lines across 67 docs — README, CLAUDE.md,
deployment, usage, the RAG knowledge base, and the agent role prompts.
Whitespace-only: code fences, tables, and blockquote alerts are byte-identical
and the change is token-verified (no content altered). Applied with a
deterministic reflow tool (committed separately).

Also lands two doc edits that were awaiting commit: the measured under-load
resource numbers in usage.md and the pr_reviewer additions to the
org-structure RAG doc.
2026-06-16 23:18:55 +02:00

2.8 KiB

Blocked Tools

Native Git Commands Blocked

Symptom: Bash(git commit), Bash(git push), Bash(git checkout), etc. denied by the bash-guard hook.

Cause: Shell git for network / auth / branch-mutating ops bypasses the PAT injection done by the MCP layer; raw git fetch etc. would fail with could not read Username for 'https://github.com' anyway.

Solution: Use the role-scoped MCP verb that matches what you're trying to do. There is no roboco_git_commit / _push / _create_pr / _merge_pr / _checkout MCP tool — the surface is smaller than that:

Blocked shell command Use instead
git status / git diff / git log / git branch roboco_git_status / roboco_git_diff / roboco_git_log / roboco_git_branch_list (roboco-git-readonly)
git commit + git push (devs / docs) commit(message, files) (roboco-do) — auto-prefixes [task-id], pushes
git checkout of a task branch None — branch is auto-checked-out by i_will_work_on(task_id) (devs) or i_will_plan(task_id, plan) (PMs)
Open a PR None — PR is opened by the choreographer when the dev calls open_pr(task_id)
Merge a PR complete(task_id, notes) (PMs only) — Cell PM merges leaf PR; Main PM merges parent and escalates to CEO
git fetch / git pull / git rebase None at the agent layer — task branches are short-lived; if yours diverged, unclaim and re-claim

Write/Edit Outside Workspace

Symptom: Write() or Edit() denied for a file path

Cause: Write operations restricted to your workspace

Solution:

  • Developers: Only write in /data/workspaces/{project}/{team}/{agent-id}/
  • Documenters: Only write in /app/docs/
  • QA: No write access (review only)

QA Cannot Commit

Symptom: commit() returns not_authorized for a QA agent

Cause: QA role is read-only — cannot modify code or open PRs.

Solution: QA pass(task_id, notes) or fail(task_id, issues) only. Developers fix issues and re-submit.

NO_PLAN Error on Start

Symptom: Lifecycle transition rejected with NO_PLAN

Cause: Parent tasks require a plan before they can leave pending.

Solution: PMs call i_will_plan(task_id, plan); the verb both records the plan and transitions the task into in_progress.

Parent Branch Required

Symptom: Can't claim subtask, error "Parent task must be claimed first"

Cause: Parent task hasn't been claimed/started yet, so it has no branch for the subtask's branch to fork from.

Solution:

  1. Parent task must transition to in_progress first (PMs: i_will_plan(parent_id, plan); devs: i_will_work_on(parent_id)).
  2. Then the subtask's branch will auto-fork from the parent's on claim.

Branches are auto-created hierarchically. No manual creation needed.