Repository navigation
fix: remove tool-name restrictions on primary helper agents - #6
Merged
Merged
Conversation
MrGTV-love
force-pushed
the
fm/fm-subagent-guard-fix
branch
from
October 6, 2026 16:25
ee4d5fb to
45bd16b
Compare
…less hooks as match-all
…ompatibility documentation
MrGTV-love
force-pushed
the
fm/fm-subagent-guard-fix
branch
from
October 6, 2026 20:09
0ea119a to
80c0131
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
The firstmate primary could not use its own helper agents: bin/fm-subagent-pretool-check.sh denied the Agent tool when firstmate tried to delegate a read-only job (reading five reap-inventory reports and consolidating them into one table). The same stem list also denies Monitor, TaskCreate, ScheduleWakeup, SendMessage and Workflow.
The captain's words, in order:
"if firstmate cannot use its own helper agents, you should assume that is not desired"
"Are you suggested I want firstmate to block its helper agents?? I do not. I do not want any non-valuable friction whatsoever"
"I don't want any non-valuable friction. handicapping processes is almost never a good idea. I prefer fixing processes, not handicapping them"
Standing captain rule on guards (data/captain-shared.md, "Guards: fix, remove or consolidate by judgement"): judge each guard on harm prevented, reversibility, read vs write, who acts, cost, evidence, overlap and design; prefer better engineering over more engineering, and consider the whole system.
What Changed
FM_ALLOW_SUBAGENTwhile retaining both Bash command protections.Risk Assessment
✅ Low: The change is a bounded removal of the explicitly unwanted tool-name restriction, preserves the separate Bash protections and project-work delegation contract, and introduces no substantiated correctness, authorization, or simplification issues.
Testing
Three targeted guard scripts passed, including their bundled lint checks. Real Claude sessions demonstrated five-report helper consolidation, native session-tool execution, Workflow completion, unsafe Bash denial, and correct read-only project routing. Baseline executable checks reproduced the former denials, and the current directory guard retained its deny/allow behavior. Runtime evidence was saved; all disposable environments were removed.
bin/fm-watch-arm.sh &was denied with watcher-background. baseline-denials-and-current-cwd-guard.json records the current executable denyingcd projects/demowith exit 2…Evidence: Real helper delegation and five-report consolidation
Source: Real helper delegation and five-report consolidation
Evidence: Baseline tool denials and current directory-guard responses
Source: Baseline tool denials and current directory-guard responses
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
✅ **Review** - passed
✅ No issues found.
✅ **Test** - passed
✅ No issues found.
bin/fm-watch-arm.sh &was denied with watcher-background. baseline-denials-and-current-cwd-guard.json records the current executable denyingcd projects/demowith exit 2…bash tests/fm-turnend-guard.test.sh— passed, including normalized helper-tool matcher coverage and retained Bash-hook registration.bash tests/fm-arm-pretool-check.test.shandbash tests/fm-cd-pretool-check.test.sh— passed. These existing scripts also invoked their bundledfm-lint.shchecks; no standalone lint or formatter command was run.Launched four real Claude 2.1.292 print-mode sessions from the worktree using private, 120×40 tmux sessions, marked disposable FM_HOME directories, project settings, existing authentication, and stream-json hook events.Delegated five disposable reap-inventory reports to a real helper; exercised Monitor, TaskCreate/TaskUpdate, ScheduleWakeup cancellation, SendMessage's missing-recipient response, and an inline Workflow.Attemptedbin/fm-watch-arm.sh &through the real Claude Bash tool and observed the retained PreToolUse denial.Executed the base commit's removed guard from a disposable source snapshot, then exercised the current directory guard's Claude stdin interface against a plain-checkout fixture.Asked the real primary whether a read-only project audit could use a helper instead of a fleet worker; observed its routing decision.Collected runtime transcripts and executable-interface responses; removed all disposable labs, source fixtures, and private tmux servers.✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.
Guard judgement
Current verification
The final run exercised real Claude 2.1.292 helper consolidation, Monitor completion, TaskCreate/TaskUpdate transitions, ScheduleWakeup registration and cancellation, SendMessage reaching its native missing-recipient response, and Workflow completion. The missing-recipient response proves messaging reached its native consumer, not successful delivery; an earlier run separately recorded a helper-message acknowledgement. Targeted guard regressions passed, and the real primary correctly distinguished private reports from read-only project-specific audit work. No new source fixes were needed in this run. Review, test, and document all completed; the earlier document skip was corrected by full revalidation rather than waiving the required CI check.