Skip to content

chore: state plugin rules without history or tracker references - #372

Merged
brenpike merged 7 commits into
mainfrom
chore/prompt-audit-history-scrub
Sep 24, 2026
Merged

brenpike merged 7 commits into
mainfrom
chore/prompt-audit-history-scrub

Conversation

@brenpike

Copy link
Copy Markdown
Owner

Summary

PR 2 of 3 from the prompt-cruft audit.

Prose scrub (no rule changed). Plugin runtime prose now states each rule in present tense. Issue and PR numbers are gone, as is framing that diffs against earlier versions ("no longer", "today's serial behavior", "as before", "now applies", "SUPERSEDES the prior…", "What changed from manifest_version: 3"). Covered files:

  • agents/overlord.md
  • governance/remediation-doctrine.md
  • references/run-ledger-schema.md: the shared "additive, free-form, no schema change" invariant is now stated once instead of four times.
  • references/brood-ledger-model.md
  • references/github-pr-review-graphql.md
  • skills: github-review-loop, spawn-brood, record-state-result, next-wave
  • workflow descriptions: standard-delivery, pr-feedback-remediation
  • CLAUDE.md

Local Codex review found no meaning-preservation issue in any rewrite.

Regression guard (CHECK 15). tools/policy_check.sh now fails on bare tracker references (#123) in plugin/**/*.md and plugin/workflows/*.json, so issue numbers cannot creep back.

  • Every line is scanned, including frontmatter, fenced blocks, and indented lines.
  • Each finding lists every reference on its line.
  • Headings, shebangs, letter-bearing hex colors, in-page anchors, inline-code placeholders, and owner/repo#N citations are exempt.
  • The check carries two canaries: a predicate canary asserting exact token sets, and a scanner canary that runs the real file scanner over committed fixtures in tests/policy/fixtures/tracker-ref-*.md. One fixture has an unclosed frontmatter opener, to prove no region is ever skipped.
  • tests/policy/safety-tracker-ref-guard.json pins the check and its scanner canary.

Known limitations (accepted, tracked)

Local review found two latent false negatives in CHECK 15. Neither affects current content: the check reports 0 findings on plugin/.

  • Word-glued references such as issue#123 or PR#456 are exempt, because the owner/repo#N exemption is too broad.
  • A discovered file that fails to read is treated as clean.

The fix changes the detection approach from a reject list to a safe-shape allowlist, and adds checked reads. It is tracked in #371 instead of being patched here. Separately, CHECK 15 allowlist entries are line-granular (shared allowlist machinery). This is recorded in the check's comments; there are no CHECK 15 allowlist entries.

Validation

  • bash tools/validate.sh --changed, which escalates to the full suite because tools/** changed: 23 suites pass, 0 new policy findings, and Check 15 passes on 64 files.
  • CHECK 15 was bite-proofed. It goes red for each of: a planted #999 #1000 in plugin prose, re-adding a frontmatter skip, re-adding first-token-only emission, and a wrong hex-colour trailing class.
  • Local Codex review ran 3 iterations. The prose had no findings. The CHECK 15 findings were remediated structurally, and the remaining two are deferred to CHECK 15: replace reject-enumeration scanner with safe-shape allowlist and checked reads #371 by maintainer decision.

Versioning

PATCH 4.0.1 -> 4.0.2. CHANGELOG.md has a [4.0.2] entry with Added (CHECK 15) and Changed (prose scrub) sections.

Unresolved issues

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: aaf56ea64f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/policy_check.sh
@brenpike
brenpike merged commit d7b7dcd into main Sep 24, 2026
1 check passed
@brenpike
brenpike deleted the chore/prompt-audit-history-scrub branch September 24, 2026 19:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant