Asking questions
@cujo-guard answers by running the pull request again, not by rewording the review.
Ask it to prove something
Mention @cujo-guard in a comment on the pull request, or in a reply inside one of its review threads, and it answers there.
@cujo-guard that endpoint needs orders to exist.
Seed the database first and try it again.The verb this exists for is re-execution. Any review bot can re-read a diff; Cujo still has the recipe for the sandbox that produced the finding, so the answer to “seed the database first” is a new measurement rather than a rewording of the old one.
Both surfaces work, and the answer goes back to whichever one asked — so a question about an inline finding is answered under that finding.
What it cannot do
- It holds no write tool at all. Its agent is configured with no GitHub access; the service reads the final message and posts it. That is what bounds a prompt injection through a stranger’s comment to “wastes a sandbox”, and it is also why a run that times out still answers you.
- It cannot change a verdict. Asked to, it says so and points at
/cujo dismiss. - It runs in its own session. Never the review’s — a question must not be able to cancel a review in flight, and a review waiting on a person must still be askable about.
Who may ask, and how often
Write access to the repository, checked with GitHub on every mention, and checked before the rate limit. A sandbox is not free speech: answering costs a box. An outside contributor is refused out loud, and told that every finding above is readable by anyone — reading is public, deciding is not.
Three questions per pull request per hour by default, one at a time. A second while one is running is refused rather than queued, and every refusal says which of these it was.