Skip to content

fix: correct stale facts in agent, skill, and governance prose - #370

Merged
brenpike merged 6 commits into
mainfrom
bugfix/prompt-audit-factual-fixes
Sep 24, 2026
Merged

brenpike merged 6 commits into
mainfrom
bugfix/prompt-audit-factual-fixes

Conversation

@brenpike

Copy link
Copy Markdown
Owner

Summary

This is PR 1 of 3 from a prompt-cruft audit of the plugin's runtime prose. It corrects statements that are false against the current code. The only runtime change is removing a tool grant that cerebrate's instructions already forbid it to use.

Factual corrections

  • cerebrate: drop the unused Skill tool grant. Its body already forbids invoking skills, and no workflow routes it through a skill.
  • brood-status: drop the Do-Not bullet naming the retired .hivemind/brood/manifest.json singleton path. Fix the same stale path in the brood-status-project.sh header comment; that edit is line-count-neutral against the CHECK13 allowlist pin.
  • detect-remediation-signals: the Do-Not item "never presence-test a verdict block", listed under ## Do Not, read as a double negative. It now reads "presence-test a verdict block … read the inner fired field instead".
  • adaptation-cycle output schema: drop a stale Codex v1.0.4 version pin.
  • CLAUDE.md: correct the agent list (6 agents, not 4), point at the roster directories instead of stale counts, describe _shared/ accurately, and give the per-brood manifest path .hivemind/broods/<brood-id>/manifest.json.
  • init-run-ledger (skill body and engine comments): the parent brood id is documented as spawn-brood's generated GUID brood-<uuidv4> (ADR-0021), not the retired colon-bearing timestamp. The ':'-tolerant charset gate and the colon-to-dash pass are kept and documented as defensive no-ops. Comments only; no executable line changes.

Inert Inputs-File Navigator Pattern (governance/security-policy.md and five navigator skill bodies)

The pattern stated universal claims about inputs-file field content: fields are "inert", "never a path", "never an instruction". The five covered navigators consume fields differently, so each claim was false for at least one of them:

  • seed-hive resolves project_root and writes under it.
  • spawn-brood carries strains[].description into a bypass-mode child's prompt. The same policy's Brood Spawn Bypass-Mode Mitigation section already treats that text as a prompt-injection surface.

Local review falsified each narrower rewrite in turn. The final form states only transport properties, which hold by construction for every navigator:

  • The Write file_path is a skill-body literal.
  • Each field reaches its engine through jq into a shell variable and is never interpolated into shell or jq program source.

What an engine does with a field after reading it is that engine's own contract. The same claim shape is removed from init-run-ledger, record-state-result, mark-intent-fallback, spawn-brood, and seed-hive. Nothing in the covered sites now asserts a property over all navigators beyond the two transport properties. As a check, grep -rnE "(is|are) inert|inert (DATA|data)" plugin/ --include=*.md returns only unrelated hits.

Validation

  • bash tools/validate.sh --changed: pass. json-manifests, policy_check.sh --strict (0 new findings), validate_workflows.sh --strict and --self-test, test_engine.sh, and test_brood_compat.sh all pass.
  • Local Codex review: four iterations. Iteration 1's fixes are included. Iterations 2 to 4 kept falsifying the security-policy soundness paragraph, and each round was remediated by a structural plan the maintainer approved. The final commit is deletion-only, and per the maintainer's decision it was not put through another local round. The GitHub review on this PR covers it.

Versioning

PATCH 4.0.0 -> 4.0.1. The changes are fix-class corrections to packaged runtime prose. CHANGELOG.md has a [4.0.1] Fixed section.

Unresolved issues

@brenpike
brenpike merged commit aaec6ee into main Sep 24, 2026
1 check passed
@brenpike
brenpike deleted the bugfix/prompt-audit-factual-fixes branch September 24, 2026 14:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant