Repository navigation
Conversation
Add a simulation-only CAO supervisor, zone workers, and independent checker over a persistent scoped MuJoCo controller. Keep robotics dependencies isolated and cover measured custody, refusal, interruption, replay, and alternative setups. Refs #845 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Restricted Copilot profiles can still access workflow-based CAO delegation through the automatically injected MCP server.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Adds an isolated, simulation-only cross-zone robotics example using CAO agents, authenticated MCP tools, and a persistent MuJoCo world.
Changes:
- Implements bounded transport, custody handoffs, stopping, and scoped access.
- Adds scenarios, prompts, tests, dependencies, and dedicated CI.
- Documents operation, limitations, cleanup, and contributor checks.
| File | Description |
|---|---|
.github/workflows/ci.yml |
Formats the robotics example. |
.github/workflows/robotics-transport.yml |
Tests Python 3.10 and 3.12. |
CHANGELOG.md |
Records the new example. |
README.md |
Links the robotics example. |
skills/cao-contributing/SKILL.md |
Documents the new CI check. |
src/cli_agent_orchestrator/skills/cao-contributing/SKILL.md |
Updates packaged contributor guidance. |
examples/robotics/cross-zone-transport/README.md |
Documents setup, operation, and limitations. |
examples/robotics/cross-zone-transport/demo.py |
Generates profiles and manages controller access. |
examples/robotics/cross-zone-transport/pyproject.toml |
Defines isolated dependencies. |
examples/robotics/cross-zone-transport/uv.lock |
Locks the example dependency graph. |
examples/robotics/cross-zone-transport/simulation.py |
Implements the shared MuJoCo world. |
examples/robotics/cross-zone-transport/transport_mcp.py |
Exposes authenticated MCP tools. |
examples/robotics/cross-zone-transport/site.json |
Defines the default scene. |
examples/robotics/cross-zone-transport/return-site.json |
Defines the alternative scene. |
examples/robotics/cross-zone-transport/prompts/supervisor.md |
Guides transport coordination. |
examples/robotics/cross-zone-transport/prompts/zone.md |
Guides zone operations. |
examples/robotics/cross-zone-transport/prompts/checker.md |
Guides independent verification. |
examples/robotics/cross-zone-transport/tests/test_simulation.py |
Tests transport and custody behavior. |
examples/robotics/cross-zone-transport/tests/test_mcp.py |
Tests authentication and controller boundaries. |
examples/robotics/cross-zone-transport/tests/test_setup.py |
Tests generated profiles and run setup. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Apply the existing caller allowlist guard to workflow dispatch and resumption. Preserve unbound operators and require both ephemeral opt-in and the delegation grant. Cover every dispatch route and document the transport example's checkout requirement. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Include the dependency remediation from #884 and preserve both the robotics workflow entry and the expanded documentation workflow triggers in the canonical and packaged contributing guides. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Require a nonblank operator request during prepare and forward it unchanged as a quoted positional MESSAGE. Cover missing/blank requests and round-trip quoting for distinct goals, option-like text, and multiline input; document the complete setup and launch commands. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Keep the transport PR current with the main-branch documentation removal without changing its feature scope. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
Refs #845. Implements Transport across ownership zones as the first simulation-only robotics example, rather than adding a robotics framework to CAO or claiming the entire example catalogue is complete.
handoff; zone workers and the checker use a shared, authenticated MCP simulator.prepare --requestrequires an explicit nonblank goal and emits a complete, safely quoted nonblocking launch command. No new provider, driver, workflow engine, or normal-install dependency.@cao-mcp-serveror*grant. Unbound operators remain unrestricted; ephemeral callers still need their separate opt-in. This is the only core behavior change, and no robotics logic enters CAO core.Real CAO acceptance
These were actual authenticated Copilot CLI agents using the real headless MuJoCo controller and HTTP/stdio MCP connections, not a scripted replacement planner. Each case used a fresh world, credentials, profiles, and CAO session. They ran on the initial example before the shared authorization correction; the simulator implementation is unchanged, and the follow-up permission regressions cover the corrected delegation boundary.
9477448dfd574391b0ec4d6cab60e129: tote at[2.0, 0.0]m, locationetch, ownereast, no pending offer. Both moves, the custody offer, and the exact receiving acceptance finished. Checker observation:2026-10-06T08:18:41.304413Z.eb8cfec34492446b908472f6f8b76046:cleanroomexplicitly unavailable; no substitution, motion, or custody command. Tote remained atstock,[-2.0, 0.0]m, owned bywest. Checker observation:2026-10-06T08:57:30.095348Z.ed905b8be44a45cd9adaeca7d684ee13: independently stopped an actual running command. Tote stayed at[-1.976, 0.0]m, between locations, still west-owned; command recordedinterrupted/operator_stop. No east leg, custody offer, or replay. Checker observation:2026-10-06T09:00:24.087757Z.14eb37ae876c42758420786d7e9cae3f: returnedsample-trayfromrackthroughtransfertoinspection, using different coordinates, fixtures, capacities, speeds, and names. Final pose[1.0, -0.996]m is 0.004 m from the target, within the 0.010 m tolerance; ownerassembly, no pending offer, all four commands finished. Checker observation:2026-10-06T09:01:11.848888Z.The alternative run exceeded the synchronous launch client's 300-second wait, but its existing agents and controller continued and completed; the result was reconciled without replay. Generated and documented launch commands therefore use CAO's existing
--asyncmode and explicitly distinguish message delivery from task completion.All four owned CAO sessions, five listeners, sixteen generated global provider profiles, and five private run/state directories were removed after confirmed stopping. No credentials, raw account banners, or robot assets are included in the PR.
Validation
main: 15 pre-existing errors on both base and head, zero new errors. The unchanged repository-wide mypy policy remains non-blocking.72ccbd5af9881b1c77a6c19a9fdd80e1eadfa65c, including permission fixaad3b827afe76544b9bebf13bbf33c15b2904151, launch-message fixdbc9d60bf1ba72fafb3d65e418640611c5b48eaa, and currentmainat14a6d8fb9e4c0fe95ddc8051daf2f8ad571c254f. The final CI run completed successfully at2026-10-06T12:34:30Z: 21/21 jobs passed. All 28 reported PR checks passed, including both security gates, both transport simulator jobs, Secret Scan, and cargo-deny. All five associated workflow runs, including Copilot review, completed successfully on this exact head.Dependency blocker remediation: the initial Security Scan reported eight findings in the unchanged Docusaurus lockfile. After the maintainer merged #884, this branch incorporated that
maincommit rather than duplicating its dependency fixes. The latest hosted dependency gate scanned 13 locked graphs / 2,221 package entries, including the new transport lockfile and development/unfixed dependencies, with zero findings at2026-10-06T12:18:42Z. All three clean-install mitigation suites also pass. No scan exemptions or weakened gates were added.The PR's delta against current
mainremains the transport example, its supporting CI/documentation, and the narrowly coupled delegation-permission correction.Final review
The final Copilot review reports nil findings on
72ccbd5af9881b1c77a6c19a9fdd80e1eadfa65c. All three review threads have published fixes and replies and are resolved.Final verification at
2026-10-06T12:37:40Zrechecked every paginated conversation, review, inline-comment, and thread surface: zero unresolved actionable threads, no late findings, unchanged head/base SHAs, and all checks successful. Copilot's recommendation is not a maintainer approval: GitHub still reportsREVIEW_REQUIRED. The PR remains open and unmerged.Deliberate limits
This is an assisted kinematic simulation: cart proxies follow straight segments and directly carry the payload. It does not model wheel dynamics, grasping, collisions, obstacle avoidance, physical docking, or real-world safety. There is no hardware driver, hardware endpoint, extra Strands/LangGraph agent, or hidden reasoning loop.
The local account and private run directory are trusted; scoped MCP credentials and provider-native tool restrictions are not an OS sandbox or production multi-tenant authorization system. Initial robots must already be positioned for pickup and receiving. Restarting a consumed run is refused; recovery requires inspection and a fresh prepared run rather than silently resetting command history.