Remove broken post_duo_code_review tool from AI Catalog, add MR review tools

What does this MR do and why?

Issue: https://gitlab.com/gitlab-org/gitlab/-/work_items/604613

The post_duo_code_review tool (id 87) is listed in the AI Catalog for custom agents, but it can never work there. The endpoint it calls is locked to the foundational Code Review flow by a security fix (#578840 (closed)), so custom agents always get a 403. It got added by accident in an old bulk tool-addition commit. This MR removes it from the catalog.

To give custom agents a real way to do code-review-style work on merge requests, this MR also adds 9 tools that already exist in the Duo Workflow Service but were missing from the catalog: add_merge_request_reviewers, create_branch, get_downstream_pipelines, get_failing_bridge_jobs, get_repository_files, list_mr_discussions, reply_to_discussion, set_discussion_resolved, submit_mr_review. All of them were checked to call endpoints that accept ai_workflows-scoped tokens, so they actually work for custom agents.

  • Id 87 is retired for good with a new RETIRED_TOOLS constant, backed by specs that fail if the id or name is ever reused.
  • No migration needed: agents that already have 87 stored keep working as before, the id just gets dropped silently everywhere (display, save, flow run, audit) and cleans itself up on the next save.
  • Also added: tool privilege mappings in the governance registry, "MR" added to the display-name acronyms so the new tools render as "Submit MR Review" etc., and the docs tool table updated.

References

https://gitlab.com/gitlab-org/gitlab/-/work_items/604613

How to set up and validate locally

Validation steps
  1. Go to AI Catalog and create or edit a custom agent.
  2. Open the tools picker. post_duo_code_review is gone.
  3. Search for the new tools. All 9 appear, with submit_mr_review and list_mr_discussions titled "Submit MR Review" and "List MR Discussions".
  4. Select a few new tools and save. The agent saves without errors.

Backwards compatibility with a stale tool id (rails console)

# Unknown ids are dropped silently, no errors:
Ai::Catalog::BuiltInTool.where(id: [87, 9]).map(&:name)
# => ["create_merge_request_note"]
Ai::Catalog::BuiltInTool.find_by(id: 87)
# => nil
Ai::Catalog::BuiltInTool.count
# => 101

Then open that agent's edit page: it loads cleanly, the removed tool is not shown, and re-saving drops 87 from the stored tools without any error.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Related to #604613

Edited by Jaydip Pansuriya

Merge request reports

Loading
Loading