Skip to content

feat(prompts): progress updates, outcome-scoped research, single-source destructive-fix gate - #374

Merged
brenpike merged 7 commits into
mainfrom
feature/prompt-audit-behaviour
Sep 24, 2026
Merged

brenpike merged 7 commits into
mainfrom
feature/prompt-audit-behaviour

Conversation

@brenpike

Copy link
Copy Markdown
Owner

Summary

This is PR 3 of 3 from the prompt-cruft audit. It makes the behavioural prompt changes for the current Opus and Sonnet generation, and it single-sources the destructive-fix gate.

Behaviour changes (intended)

  • Overlord progress updates. The ## Continuous Execution section in agents/overlord.md no longer suppresses all user-facing text. The overlord still proceeds without pausing. It now surfaces stop conditions, every Tier-A surface, the final report, and a brief progress line on long stretches: multi-wave implement loops, PR watches, and brood dispatch. Per-state announcements, transition logs, and tool-by-tool narration stay out.
  • Reviewer agents. agents/github-reviewer.md and agents/local-reviewer.md no longer say "produce zero text output". The Output Contract YAML remains the report returned to the caller.
  • Cerebrate research scope. agents/cerebrate.md now reads until every step's file list is complete and it is confident in it. Unresolved paths go to Open questions. This replaces the fixed budget of 3N files.
  • enable-brood-remote trigger. The skill description gives one trigger example instead of four near-synonyms. The explicit-request-only gating is unchanged.

Repetition removed (meaning-preserving)
Each of these sites now keeps one authoritative statement:

  • The Routing-vs-Execution Invariant sites in agents/overlord.md
  • The claude-mem note in agents/cerebrate.md
  • plan-interrogation
  • improving-architecture and its INTERFACE-DESIGN reference
  • creep-spread, whose term rules now point at CONTEXT-FORMAT.md
  • decision-report, whose constraints now live in ## Do Not

governance/workflow.md now sizes the PR summary to the change instead of capping it at five sentences. Local review confirmed that no rule was dropped and that no reference dangles.

Destructive Fix Gate is single-sourced (safety)
The ten-category gate used to be hand-mirrored in governance/safety-rails.md and governance/security-policy.md, and the two copies had drifted apart. An earlier commit on this branch aligned one copy to the other and narrowed category 2 as a result: "Delete files marked as security-relevant". That is now fixed.

  • One canonical list. security-policy.md (Destructive Fix Confirmation Gate) holds the only list. Each category is a DESTRUCTIVE-CAT <n>: marker line, and each row is the union of both former wordings, so no row is narrower than either copy on main.

  • Broadest reading. An explicit rule says every category is read at its broadest, and that no marking or label is ever a precondition for a category to fire.

  • Pointer, not copy. safety-rails.md keeps its ## Destructive Fix Gate header and trigger framing, and points to the canonical list. All existing references resolve, and agents/drone.md now cites the canonical section.

  • Regression guards. Two fixtures guard the change:

    • tests/policy/safety-destructive-fix-gate-single-source.json asserts exactly ten markers at the canonical file.
    • tests/policy/safety-destructive-fix-gate-no-second-copy.json asserts zero markers in the five citing documents.

    Both were bite-proofed. Each of these mutations turns the suite red: re-narrowing a row, deleting or adding a category, re-copying the rows, and deleting the never-restates sentence.

Checker fix found along the way
tools/policy_check.sh set_check used to abort the whole run on a fixture file with zero extract_regex matches: the grep fallback appended a second {}, which jq --argjson rejected. The fallback now runs only when perl is absent, and a failed pipeline yields an empty capture. A SAFETY-CANARY witnesses the fix, and it was bite-proofed against the reverted code.

Validation

  • bash tools/validate.sh --changed, which runs the full suite because tools/** changed: 23 suites pass and there are 0 new policy findings.
  • Local Codex review ran 3 iterations:
    • The prose de-duplication had no findings.
    • The gate duplication root cluster was closed by construction. The reviewer confirmed that no canonical row is narrower than either copy on main.
    • One inherited, latent checker issue was deferred (see below).

Versioning

MINOR 4.0.2 -> 4.1.0. The overlord's user-visible output changes, and the destructive-fix gate is broadened. There is no API or format break. CHANGELOG.md has a [4.1.0] entry with Added, Changed, and Fixed sections.

Known limitations and follow-ups

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4ffae52111

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/policy_check.sh
@brenpike

Copy link
Copy Markdown
Owner Author

@codex review

@brenpike
brenpike merged commit 982ecc7 into main Sep 24, 2026
1 check passed
@brenpike
brenpike deleted the feature/prompt-audit-behaviour branch September 24, 2026 23:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant