An operator's Chat agent does not know which sign-ins its sandbox holds, and in a Slack room it can answer without reading the thread.
Example: in a Slack thread, people asked their agents to read a private repository with gh. The operator's sandbox held their GitHub sign-in (#769), so gh worked as them. The operator tagged their agent: "you should have gh cli authenticated with my account". The agent made no tool call. It did not run gh auth status and did not call chat_read_thread. It looked at its working directory, saw no git repository, and answered that there was nothing to authenticate against.
Two gaps:
- The agent does not know what it can reach. Nothing in the Chat prompt says which services the sandbox holds a sign-in for, so the agent infers from its empty working directory that it has no GitHub access.
- Reading the thread is optional. For Slack, the prompt says "In a room, other people also write in the thread: call chat_read_thread to read it." The agent answered a one-line message from a long thread without its context.
Expected
- The Chat prompt names the sign-ins the sandbox holds, for each service with a host: for example, "
gh is signed in as , the person's GitHub account". Without a sign-in, it says how to connect one (Chat → Channels).
- In a room, the agent reads the thread with
chat_read_thread before it answers a message whose subject is not in the message itself.
An operator's Chat agent does not know which sign-ins its sandbox holds, and in a Slack room it can answer without reading the thread.
Example: in a Slack thread, people asked their agents to read a private repository with
gh. The operator's sandbox held their GitHub sign-in (#769), soghworked as them. The operator tagged their agent: "you should have gh cli authenticated with my account". The agent made no tool call. It did not rungh auth statusand did not callchat_read_thread. It looked at its working directory, saw no git repository, and answered that there was nothing to authenticate against.Two gaps:
Expected
ghis signed in as , the person's GitHub account". Without a sign-in, it says how to connect one (Chat → Channels).chat_read_threadbefore it answers a message whose subject is not in the message itself.