fix: correct stale facts in agent, skill, and governance prose - #370
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This is PR 1 of 3 from a prompt-cruft audit of the plugin's runtime prose. It corrects statements that are false against the current code. The only runtime change is removing a tool grant that cerebrate's instructions already forbid it to use.
Factual corrections
cerebrate: drop the unusedSkilltool grant. Its body already forbids invoking skills, and no workflow routes it through a skill.brood-status: drop the Do-Not bullet naming the retired.hivemind/brood/manifest.jsonsingleton path. Fix the same stale path in thebrood-status-project.shheader comment; that edit is line-count-neutral against the CHECK13 allowlist pin.detect-remediation-signals: the Do-Not item "never presence-test a verdict block", listed under## Do Not, read as a double negative. It now reads "presence-test a verdict block … read the inner fired field instead".adaptation-cycleoutput schema: drop a stale Codexv1.0.4version pin.CLAUDE.md: correct the agent list (6 agents, not 4), point at the roster directories instead of stale counts, describe_shared/accurately, and give the per-brood manifest path.hivemind/broods/<brood-id>/manifest.json.init-run-ledger(skill body and engine comments): the parent brood id is documented asspawn-brood's generated GUIDbrood-<uuidv4>(ADR-0021), not the retired colon-bearing timestamp. The':'-tolerant charset gate and the colon-to-dash pass are kept and documented as defensive no-ops. Comments only; no executable line changes.Inert Inputs-File Navigator Pattern (
governance/security-policy.mdand five navigator skill bodies)The pattern stated universal claims about inputs-file field content: fields are "inert", "never a path", "never an instruction". The five covered navigators consume fields differently, so each claim was false for at least one of them:
seed-hiveresolvesproject_rootand writes under it.spawn-broodcarriesstrains[].descriptioninto a bypass-mode child's prompt. The same policy's Brood Spawn Bypass-Mode Mitigation section already treats that text as a prompt-injection surface.Local review falsified each narrower rewrite in turn. The final form states only transport properties, which hold by construction for every navigator:
file_pathis a skill-body literal.jqinto a shell variable and is never interpolated into shell or jq program source.What an engine does with a field after reading it is that engine's own contract. The same claim shape is removed from
init-run-ledger,record-state-result,mark-intent-fallback,spawn-brood, andseed-hive. Nothing in the covered sites now asserts a property over all navigators beyond the two transport properties. As a check,grep -rnE "(is|are) inert|inert (DATA|data)" plugin/ --include=*.mdreturns only unrelated hits.Validation
bash tools/validate.sh --changed: pass. json-manifests,policy_check.sh --strict(0 new findings),validate_workflows.sh --strictand--self-test,test_engine.sh, andtest_brood_compat.shall pass.Versioning
PATCH 4.0.0 -> 4.0.1. The changes are fix-class corrections to packaged runtime prose.
CHANGELOG.mdhas a[4.0.1]Fixed section.Unresolved issues