Standard collaboration patterns for all squad agents — worktree awareness, decisions, cross-agent communication
日本語の概要は準備中です。原文の説明を表示しています。
Implement secret-safe HTTP headers for MCP transport in gh-aw.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Use this reference for HTTP MCP header secret support in the copilot engine.
When HTTP MCP headers include GitHub Actions secrets, mcp-config.json must:
${{ secrets.DD_API_KEY }})on:
workflow_dispatch:
permissions:
contents: read
engine: copilot
mcp-servers:
datadog:
type: http
url: "https://mcp.datadoghq.com/api/unstable/mcp-server/mcp"
headers:
DD_API_KEY: "${{ secrets.DD_API_KEY }}"
DD_APPLICATION_KEY: "${{ secrets.DD_APPLICATION_KEY }}"
DD_SITE: "${{ secrets.DD_SITE || 'datadoghq.com' }}"
allowed:
- search_datadog_dashboards
- search_datadog_slos
- search_datadog_metrics
- get_datadog_metric
# Datadog Dashboard Search
Search for Datadog dashboards and provide a summary.
{
"mcpServers": {
"datadog": {
"type": "http",
"url": "https://mcp.datadoghq.com/api/unstable/mcp-server/mcp",
"headers": {
"DD_API_KEY": "${DD_API_KEY}",
"DD_APPLICATION_KEY": "${DD_APPLICATION_KEY}",
"DD_SITE": "${DD_SITE}"
},
"tools": [
"search_datadog_dashboards",
"search_datadog_slos",
"search_datadog_metrics",
"get_datadog_metric"
],
"env": {
"DD_API_KEY": "\\${DD_API_KEY}",
"DD_APPLICATION_KEY": "\\${DD_APPLICATION_KEY}",
"DD_SITE": "\\${DD_SITE}"
}
}
}
}
env:
DD_API_KEY: ${{ secrets.DD_API_KEY }}
DD_APPLICATION_KEY: ${{ secrets.DD_APPLICATION_KEY }}
DD_SITE: ${{ secrets.DD_SITE || 'datadoghq.com' }}
COPILOT_GITHUB_TOKEN: ${{ secrets.COPILOT_GITHUB_TOKEN }}
# ... other env vars
GH_AW_MCP_CONFIG is intentionally NOT in the YAML env: block — it is exported from the run script (export GH_AW_MCP_CONFIG="$HOME/.copilot/mcp-config.json") so $HOME is resolved at runtime. GitHub Actions does not shell-expand env: values, so the path must be set via export to work on self-hosted/containerized runners where HOME is not /home/runner.
extractSecretsFromValue(value string) - Extracts secret expressions from a string
${{ secrets.VAR_NAME }} patterns${{ secrets.VAR || 'default' }}extractSecretsFromHeaders(headers map[string]string) - Extracts all secrets from HTTP headers
replaceSecretsWithEnvVars(value string, secrets map[string]string) - Replaces secret expressions with env var references
${{ secrets.DD_API_KEY }} to ${DD_API_KEY}collectHTTPMCPHeaderSecrets(tools map[string]any) - Collects secrets from all HTTP MCP tools
\${VAR_NAME})${{ secrets.* }} syntaxAll tests pass ✓
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Standard collaboration patterns for all squad agents — worktree awareness, decisions, cross-agent communication
日本語の概要は準備中です。原文の説明を表示しています。
Shared hard rules enforced across all squad agents
日本語の概要は準備中です。原文の説明を表示しています。
Route gh-aw design, creation, diagnosis, patching, active debugging, and upgrade requests to the right strategies.
日本語の概要は準備中です。原文の説明を表示しています。
How to write comprehensive architectural proposals that drive alignment before code is written
日本語の概要は準備中です。原文の説明を表示しています。
Upgrade gh-aw to latest gh-aw-firewall release and identify follow-up spec tasks.
日本語の概要は準備中です。原文の説明を表示しています。
Review code that performs git or gh operations against repository checkouts in gh-aw, checking that the right credentials are available at the right time and that sparseness, shallowness and credential-free factors are properly considered.
日本語の概要は準備中です。原文の説明を表示しています。