Skip to content

refactor: remove the retired Twilio, Apify and meeting-bot tools - #7344

Merged
senamakel merged 19 commits into
tinyhumansai:mainfrom
senamakel:remove-twilio-apify-meetingbots
Oct 10, 2026
Merged

senamakel merged 19 commits into
tinyhumansai:mainfrom
senamakel:remove-twilio-apify-meetingbots

Conversation

@senamakel

@senamakel senamakel commented Oct 10, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Removes the twilio_call agent tool and the Apify LinkedIn-scrape RPC controller from openhuman-core: the backend retires its Twilio, Apify and Recall meeting-bot integrations (tinyhumansai/backend#1419).
  • Drops their config toggles, pricing fields, fake-backend routes, tool-group mappings, UI tool spec/phrases and the unused meeting-bot / place-call i18n strings.
  • Old config files and pricing responses that still carry twilio / apify keys keep deserializing (no deny_unknown_fields), pinned by tests.

Problem

  • The backend is removing /agent-integrations/twilio/*, /agent-integrations/apify/* and the meeting-bot routes. Without this change the agent would still be offered tools whose backend routes 404.

Solution

  • Delete the tools, schemas and registrations outright rather than feature-flagging them; keep config/pricing parsing tolerant so existing user configs load.
  • No live meeting-bot client code existed; only dead strings and comments were removed.

Submission Checklist

  • Tests added or updated: tools no longer registered (twilio_call, Apify controller), retired config keys and pricing entries still parse; in-process method lists updated.
  • Diff coverage ≥ 80% — N/A: change is almost entirely deletions; the added lines are tests.
  • Coverage matrix updated — N/A: no matrix rows cover these tools.
  • All affected feature IDs listed — N/A: no matrix features affected.
  • No new external network dependencies introduced.
  • Manual smoke checklist — N/A: not a release-cut surface.
  • Linked issue — N/A: follows the backend billing audit.

Impact

  • Desktop/CLI: the agent no longer offers phone calls or LinkedIn scraping via Apify. No migration needed.

Related


AI Authored PR Metadata (required for Codex/Linear PRs)

Linear Issue

  • Key: N/A
  • URL: N/A

Commit & Branch

  • Branch: remove-twilio-apify-meetingbots
  • Commit SHA: a7c47a5

Validation Run

  • pnpm typecheck
  • Focused tests: vitest conversations-tools/i18n/store/MCP (1461 passed); cargo unit tests for tools/integrations/config/egress (1465 passed)
  • Rust fmt/check (if changed): cargo fmt clean, cargo check -p openhuman --tests clean after merging latest main
  • Tauri fmt/check (if changed): N/A

Validation Blocked

  • command: cargo test -p openhuman-cli --test in_process_all (config_auth_app_state_connectivity_e2e)
  • error: 12 failures with "master key unavailable" (keychain)
  • impact: environmental on the dev box; the edited assertions in that file pass. CI will confirm.

Behavior Changes

  • Intended behavior change: Twilio call and Apify LinkedIn scrape tools are gone.
  • User-visible effect: the agent can no longer place phone calls or run Apify scrapes.

Parity Contract

  • Legacy behavior preserved: existing configs with the removed keys still load.
  • Guard/fallback/dispatch parity checks: tool registry and schema catalog tests updated.

Duplicate / Superseded PR Handling

  • Duplicate PR(s): N/A
  • Canonical PR: this one
  • Resolution (closed/superseded/updated): N/A

Summary by CodeRabbit

  • Removed Features
    • Removed Twilio calling and Apify-powered LinkedIn profile scraping from the available tools.
    • Older configuration entries for Twilio and Apify are ignored when loading integrations.
  • Documentation
    • Updated integration and tool references to reflect the tools that remain available.

senamakel and others added 19 commits October 10, 2026 21:09
Add Twilio messaging tools to the integrations toolset, wiring them into
the ops tool groups so they are exposed alongside the existing
integrations. Tests cover the new tool behaviour.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add a schema for the integrations tool so its settings can be validated
and loaded through the standard config pipeline.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Adds test coverage for the integration toggle configuration schema.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
…_family_tests.rs

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Move the execution and serde test cases out of ops_tests.rs into a dedicated
ops_tests_execution_and_serde_tests.rs module so the remaining ops tests stay
focused and easier to navigate.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add a test support backend for the integrations layer so tests can
exercise integration flows without depending on real external services.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add schema definitions for the Apify and LinkedIn tools, including a
dedicated LinkedIn test module, and register them in the schema registry
so the new tools are exposed alongside the existing ones.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add tests covering the tool schema definitions to verify that
serialization and validation behave as expected.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
…types

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
…alls

Egress checks were being skipped for channel startup turns and pricing
lookups, allowing requests to bypass the configured policy. The enforcement
path now covers both call sites so outbound traffic is consistently
validated.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Remove the Twilio call tool and the Apify LinkedIn scrape tool from the
integrations and tools READMEs, along with the corresponding schema
catalog entry in the worker B end-to-end test. These tools no longer
exist, so the documentation and test expectations were stale.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The apify LinkedIn scrape tool is no longer exposed, so the in-process
end-to-end tests that asserted its presence have been updated to match the
current tool set.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Tool call status messages are now generated from per-locale phrase tables instead of hardcoded English strings, so every supported language can describe running, completed, and failed tool calls in its own words.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Remove the recall_calendar domain from the test inventory allowlist and the
meetingBots i18n keys from the intentional-English list, since both are now
covered. Also delete the unused Apify run-polling stubs from the mock API.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Shortened the comment above clearNotificationActions to drop the
redundant example and the duplicated RPC names, keeping the explanation
of why clearing actions removes the handled prompt from the actionable
list.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Trimmed the axum and std imports in the test support module down to the
ones actually used, dropping the extract, routing, and HashMap imports
that no longer have any references.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The pinned legacy size for crates/openhuman-core/src/tools/ops.rs was reduced from 978 to 970 lines to match the file's current length, keeping the layout check in sync after the file shrank.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
…eetingbots

# Conflicts:
#	app/src/lib/i18n/ar.ts
#	app/src/lib/i18n/bn.ts
#	app/src/lib/i18n/de.ts
#	app/src/lib/i18n/en.ts
#	app/src/lib/i18n/es.ts
#	app/src/lib/i18n/fr.ts
#	app/src/lib/i18n/hi.ts
#	app/src/lib/i18n/id.ts
#	app/src/lib/i18n/it.ts
#	app/src/lib/i18n/ja.ts
#	app/src/lib/i18n/ko.ts
#	app/src/lib/i18n/pl.ts
#	app/src/lib/i18n/pt.ts
#	app/src/lib/i18n/ru.ts
#	app/src/lib/i18n/tr.ts
#	app/src/lib/i18n/zh-CN.ts
Adds the jsonschema crate to the app's dependency graph, pulling in its
supporting crates, and bumps several transitive dependencies including
windows-sys to 0.61.2.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-10T18:57:50.476939Z a7c47a5 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 6847900a-a194-4ec5-a7cb-32f1f4716090

📥 Commits

Reviewing files that changed from the base of the PR and between 3d32eec and a7c47a5.


⛔ Files ignored due to path filters (1)
  • crates/openhuman-app/Cargo.lock is excluded by !**/*.lock

📒 Files selected for processing (37)
  • app/src/features/conversations/tools/toolPhrases.ts
  • app/src/features/conversations/tools/toolSpecs.ts
  • app/src/store/notificationSlice.ts
  • crates/openhuman-core/src/channels/runtime/startup/turn_parts.rs
  • crates/openhuman-core/src/config/schema/tools/integrations.rs
  • crates/openhuman-core/src/config/schema/tools/integrations_integration_toggle_tests_tests.rs
  • crates/openhuman-core/src/integrations/README.md
  • crates/openhuman-core/src/integrations/client/pricing.rs
  • crates/openhuman-core/src/integrations/composio/client_tests.rs
  • crates/openhuman-core/src/integrations/mod_tests.rs
  • crates/openhuman-core/src/integrations/test_support.rs
  • crates/openhuman-core/src/integrations/test_support_backend.rs
  • crates/openhuman-core/src/integrations/tools.rs
  • crates/openhuman-core/src/integrations/tools/twilio.rs
  • crates/openhuman-core/src/integrations/tools/twilio_tests.rs
  • crates/openhuman-core/src/integrations/types.rs
  • crates/openhuman-core/src/security/egress/enforce.rs
  • crates/openhuman-core/src/security/egress/enforce_tests.rs
  • crates/openhuman-core/src/tools/README.md
  • crates/openhuman-core/src/tools/ops.rs
  • crates/openhuman-core/src/tools/ops_tests.rs
  • crates/openhuman-core/src/tools/ops_tests_domain_family_tests.rs
  • crates/openhuman-core/src/tools/ops_tests_execution_and_serde_tests.rs
  • crates/openhuman-core/src/tools/ops_tool_groups.rs
  • crates/openhuman-core/src/tools/schemas.rs
  • crates/openhuman-core/src/tools/schemas/apify.rs
  • crates/openhuman-core/src/tools/schemas/linkedin.rs
  • crates/openhuman-core/src/tools/schemas/linkedin_tests.rs
  • crates/openhuman-core/src/tools/schemas/registry.rs
  • crates/openhuman-core/src/tools/schemas_tests.rs
  • scripts/ci/check-openhuman-rust-layout.mjs
  • scripts/generate-test-inventory.mjs
  • scripts/i18n-find-english.ts
  • scripts/mock-api/routes/integrations.mjs
  • tests/in_process/config_auth_app_state_connectivity_e2e.rs
  • tests/in_process/domain_modules_e2e.rs
  • tests/in_process/worker_b_domain_e2e.rs

 ________________________________________________________________________________________________________________________________________
< It is a truth universally acknowledged, that a single developer in possession of a good feature, must be in want of an AI code review. >
 ----------------------------------------------------------------------------------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@senamakel
senamakel merged commit bd5632c into tinyhumansai:main Oct 10, 2026
13 of 23 checks passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a7c47a50b0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +266 to +267
// The backend retired its Twilio route; the agent must not be offered a
// tool that can only fail.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Retire Twilio from resumed session snapshots

This assertion only covers a fresh all_tools registry. A pre-upgrade session that recorded twilio_call keeps that declaration when resumed (retain_recorded_tools(true)), while resume rehydration only rebuilds executors for Composio/search tools; after this patch the model is therefore still offered twilio_call but there is no executor, so requests in such existing conversations end in an unknown-tool failure. Add a recorded-tool migration or a non-networking retirement/tombstone executor, and cover the resume path rather than only the fresh registry.

AGENTS.md reference: AGENTS.md:L490-L496

Useful? React with 👍 / 👎.

@tinysweeper

tinysweeper Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper completed its review; deterministic results follow.

State: Changes requested
Priority: high
Reviewed head: a7c47a50b0a5
Updated: 1791659037 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 18 Active findings 2
Tests 17 Noted findings 0
Documentation 2 Resolved findings 24
Configuration 0 Pending checks/questions 4

Completeness: Complete
Test assessment: Test coverage is assessed from changed tests and lane evidence; execution is not claimed without trusted check data.

What changed

The change removes the retired integrations end to end. In the core, the Twilio managed tool and its config toggle, pricing entry, fake-backend route, and egress test fixture references are deleted, and the tools registry no longer registers 'twilio_call'. The Apify LinkedIn scrape controller and its underlying LinkedIn actor invocation/Markdown rendering modules are removed from the controller registry, and their routes are dropped from the fake integration backend and mock API. Frontend tool phrases and specs for 'twilio_call' are removed. Documentation tables and layout notes in the integrations and tools READMEs are updated to drop Twilio and Apify references. Configuration and pricing deserialization remain tolerant: retired 'twilio'/'apify' keys in older configs and older backend pricing payloads are ignored rather than breaking loads. In-process E2E suites that advertised or exercised the retired controller and tool were updated in the same change. One review lane flagged a possible compile issue: the removal of axum 'Path'/'Query'/'HashMap' imports from the fake-backend test support is only safe if no remaining route uses them, and the critique lane noted a documentation-sync finding in the integrations README.

Features

  • Removed — Twilio phone-call integration (twilio_call tool): The agent no longer registers or exposes the outbound phone-call tool; configs still carrying the retired 'twilio' toggle keep loading because unknown keys are ignored, and older backend pricing payloads with a 'twilio' entry still deserialize. (crates/openhuman-core/src/integrations/tools.rs#use super::IntegrationClient;, crates/openhuman-core/src/tools/ops.rs#pub fn all_tools_with_runtime(, crates/openhuman-core/src/config/schema/tools/integrations.rs#impl Default for IntegrationToggle {, crates/openhuman-core/src/integrations/types.rs#pub struct IntegrationPricing {, app/src/features/conversations/tools/toolSpecs.ts#export const EXACT_TOOL_SPECS: Record<string, ToolSpec> = {, app/src/features/conversations/tools/toolPhrases.ts#export const TOOL_PHRASES = {, crates/openhuman-core/src/tools/ops_tool_groups.rs#pub(crate) fn tool_group(name: &str) -> crate::core::all::DomainGroup {, crates/openhuman-core/src/security/egress/enforce.rs#pub fn local_only_blocks(mode: PrivacyMode, desc: &EgressDescriptor) -> bool {, crates/openhuman-core/src/integrations/README.md#a `DomainSet` without integrations hides them., crates/openhuman-core/src/integrations/client/pricing.rs#pub async fn pricing_for_config()
  • Internal refactor — Notification prompt-handling comment clarified: The comment describing clearNotificationActions was reworded to drop the meeting-bot join/skip example; the behavior of clearing action buttons once a prompt has been handled is unchanged. (app/src/store/notificationSlice.ts#const notificationSlice = createSlice({)

Tests

  • modification — The ops test helper no longer enables the retired 'twilio' config toggle.: Consistent with the toggle removal. (crates/openhuman-core/src/tools/ops_tests.rs#fn integration_test_config(tmp: &TempDir, backend_url: &str) -> Config {)
  • modification — The composio client pricing test no longer asserts on retired 'apify'/'twilio' pricing entries.: Consistent with the pricing struct change. (crates/openhuman-core/src/integrations/composio/client_tests.rs#async fn pricing_for_config_short_circuits_in_direct_mode() {)

Findings

  • high · critique · Restore imports required by the included backend — The README now removes Twilio from the documented managed tools, tool table, prefix mapping, and layout. However, the included backend still requires the Twilio integration imports (crates/openhuman\-core/src/integrations/README\.md:6)
  • high · security · Restore imports required by the included backend — The included `test_support_backend.rs` still uses `Path`, `Query`, `get`, and `HashMap`, but this replacement removes their imports. The crate therefore fails to compile; restore t (crates/openhuman\-core/src/integrations/test\_support\.rs:1)

Resolved this pass

  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend
  • Restore imports required by the included backend

Pending checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)

Before merge

  • Address Restore imports required by the included backend (crates/openhuman\-core/src/integrations/README\.md).
  • Address Restore imports required by the included backend (crates/openhuman\-core/src/integrations/test\_support\.rs).
  • Wait for Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS).

How this fits together

flowchart LR
  n0["all_tools"]:::impacted
  n1["vec"]:::impacted
  n2["integration_tools_for_config"]:::impacted
  n3["expansion_tools_for"]:::impacted
  n2 -->|calls| n0
  n3 -->|calls| n0
  n3 -->|calls| n1
  classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
  classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
  classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
  classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Loading
Agent review details

critique

  • Conclusion: Failure
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 15 files; 2 findings. (1 already reported on an earlier push) _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Evidence: crates/openhuman\-core/src/integrations/README\.md — Restore imports required by the included backend

security

  • Conclusion: Failure
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 13 files; 1 finding. 2 files were not security-reviewed: crates/openhuman-core/src/integrations/README.md (prose or tabular data), crates/openhuman-core/src/tools/README.md (prose or tabular data). _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Evidence: crates/openhuman\-core/src/integrations/test\_support\.rs — Restore imports required by the included backend

tests

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: This change retires the Twilio and Apify integrations across the core, frontend, mock API and docs, and the retirement is consistently pinned: new tests assert old configs with retired toggles still load, old backend pricing payloads still deserialize, `twilio_call` is no longer registered, and the Apify controller resolves to `unknown`. The prior finding about stale imports in the fake-backend test support is resolved — the imports were trimmed to match the removed routes. No new findings; the change looks safe to merge. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: The description lane noted the PR description matches the diff: the retired Twilio tool, Apify LinkedIn controller, and their config/pricing toggles are removed with tests and docs updated.
  • Lane summary: The PR cleanly removes the retired Twilio tool, Apify LinkedIn controller and their config/pricing toggles, with tests pinning the tolerant deserialization and updated docs; the description matches the diff. One prior finding remains: the removal of the axum `Path`/`Query`/`HashMap` imports from the fake backend is only safe if no remaining route uses them, and several surviving `/agent-integrations/*` routes (composio, file-storage) typically take path parameters — if so, the core no longer compiles. (1 earlier finding(s) still open) _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

e2e

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: The pull request retires the Twilio and Apify/LinkedIn integrations end to end: the core tools and controllers are removed, the in-process E2E suites that advertised or exercised `tools_apify_linkedin_scrape` and `twilio_call` were updated in the same change, and the fake backend routes plus mock-API stubs are cleaned up. The earlier finding about the backend test-support imports is resolved by the same cleanup. The change looks sound to merge. Waiting on end-to-end jobs: `Rust E2E (mock backend)`, `Build Playwright E2E Artifact`, `E2E (Playwright / web lane)`, `Desktop E2E (full suite, 3 OS)`. 1 end-to-end job passed on this head.
  • Unresolved questions/checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)
Evidence and run details
  • Models: gpt-5.6-luna, glm-5.3-flash
  • Spend: $0.027623
  • Tokens: 472521 input · 25859 output · 113694 cached · 0 embedding
Head State Pass summary
a7c47a50b0a5 changes requested 1 active finding(s), 0 resolved finding(s) (at 1791658809)
a7c47a50b0a5 changes requested 2 active finding(s), 24 resolved finding(s) (at 1791659037)

tinysweeper 0.1.0

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 1 lane(s) blocking, worst finding is high.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0251 · 435,287 in / 17,113 out · 48,434 cached (11%) · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0158 · 229,489 in / 8,511 out  · 27,291 cached (12%) · gpt-5.6-luna, glm-5.3-flash
security:    $0.0080 · 107,239 in / 3,808 out  · 14,295 cached (13%) · gpt-5.6-luna
tests:       $0.0003 · 38,692 in  / 843 out    · 3,712 cached (10%)  · glm-5.3-flash
description: $0.0001 · 18,528 in  / 793 out    · 1,408 cached (8%)   · glm-5.3-flash
e2e:         $0.0002 · 21,553 in  / 306 out    · 1,728 cached (8%)   · glm-5.3-flash

routing::{get, post},
Json, Router,
};
use axum::{routing::post, Json, Router};

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high critique confident

Restore imports required by the included backend

test_support_backend.rs is textually included into this module, so its uses of Path, Query, get, and HashMap rely on the imports in this file. Removing those imports causes unresolved-name compilation errors even though those names do not appear in this wrapper file. Restore the imports or move equivalent imports into the included implementation.

[RULE] missing-import ·

@tinysweeper tinysweeper Bot added the priority: p1 Next. Wrong behaviour a user will hit, or a security weakness behind a condition. label Oct 10, 2026

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 2 lane(s) blocking, worst finding is high.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0276 · 472,521 in / 25,859 out · 113,694 cached (24%) · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0154 · 213,182 in / 12,839 out · 61,474 cached (29%)  · gpt-5.6-luna, glm-5.3-flash
security:    $0.0114 · 159,607 in / 8,369 out  · 44,412 cached (28%)  · gpt-5.6-luna
tests:       $0.0003 · 39,075 in  / 821 out    · 4,416 cached (11%)   · glm-5.3-flash
description: $0.0002 · 18,809 in  / 788 out    · 1,536 cached (8%)    · glm-5.3-flash
e2e:         $0.0002 · 21,830 in  / 377 out    · 1,728 cached (8%)    · glm-5.3-flash

backend-proxied integration uses for `/agent-integrations/*`, a small family
of managed agent tools built on it (Google Places, stock and market data,
Twilio calls), and three child sub-domains: Composio connectors, task sources,
of managed agent tools built on it (Google Places, stock and market data),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high critique confident

Restore imports required by the included backend

The README now removes Twilio from the documented managed tools, tool table, prefix mapping, and layout. However, the included backend still requires the Twilio integration imports; removing this entry does not fix that backend dependency and leaves the integration documentation inconsistent with the code that is built. Restore the Twilio documentation or update the backend imports and registration together so the documented and compiled integration surfaces match.

[RULE] documentation-sync ·

routing::{get, post},
Json, Router,
};
use axum::{routing::post, Json, Router};

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high security confident

Restore imports required by the included backend

The included test_support_backend.rs still uses Path, Query, get, and HashMap, but this replacement removes their imports. The crate therefore fails to compile; restore the imports needed by the included backend.

[RULE] compile-error ·

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p1 Next. Wrong behaviour a user will hit, or a security weakness behind a condition.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant