From 1fe33c4b91f8c2fe1d0cdaedd5375a0d9cb3b2b1 Mon Sep 17 00:00:00 2001 From: WFL Repo Warden Date: Mon, 31 Aug 2026 04:03:11 -0500 Subject: [PATCH] fix(ci): allow the cursor bot to trigger Claude Code Review Every PR push made by the Cursor cloud agent fails the claude-review job with "Workflow initiated by non-human actor: cursor (type: Bot)". Add cursor to the existing allowed_bots list, alongside github-actions. --- .github/workflows/claude-code-review.yml | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/.github/workflows/claude-code-review.yml b/.github/workflows/claude-code-review.yml index dbb33a47..0aa63670 100644 --- a/.github/workflows/claude-code-review.yml +++ b/.github/workflows/claude-code-review.yml @@ -36,10 +36,14 @@ jobs: uses: anthropics/claude-code-action@v1 with: claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} - # Allow review of PRs opened by github-actions[bot], such as the - # monthly SECURITY.md rotation. Without this the job fails with - # "Workflow initiated by non-human actor". - allowed_bots: 'github-actions' + # Allow review of PRs opened or pushed by trusted bot actors. + # Without this the job fails with "Workflow initiated by non-human + # actor". github-actions covers the monthly SECURITY.md rotation; + # cursor covers the Cursor cloud agent, which pushes to cursor/* + # branches on our own PRs. The review prompt below is fixed by this + # workflow, so an allowed bot cannot influence what Claude is asked + # to do -- it only gets the same code review a human push would. + allowed_bots: 'github-actions,cursor' plugin_marketplaces: 'https://github.com/anthropics/claude-code.git' plugins: 'code-review@claude-code-plugins' prompt: '/code-review:code-review ${{ github.repository }}/pull/${{ github.event.pull_request.number }}'