Conversation
… turns (NousResearch#107850) When a review prompt ("Review the conversation above...") is injected into the foreground agent's loop without forking (v0.21 same-session injection path), the foreground agent's _memory_write_origin stayed at the default "assistant_tool", causing is_background_review() to return False and bypassing the curator/skill guards. Detect the review prompt prefix at turn start and override the origin ContextVar to "background_review" for the duration of that turn, so skill_manage and memory guards apply correctly on both fork and inline paths.
…earch#107850) Unit test for the review-prompt detection logic added in turn_context.py. Confirms that messages starting with 'Review the conversation above' trigger the background_review origin override when the agent is in foreground assistant_tool mode, while preserving fork origins and leaving normal user messages unchanged.
Related: #107850 (the issue), #52849 (merged: sets Note for reviewers: on current |
Fixes #107850
Root cause
When a review prompt ("Review the conversation above...") is injected into the foreground agent's loop without forking (v0.21 same-session injection path), the foreground
agent._memory_write_originstayed at the default"assistant_tool", causingis_background_review()to return False and bypassing the curator / skill-authoring gates that rely on it (user-owned-skills guard, read-before-write, skill ledger [auto] tag, approval staging).Fix
turn_context.py:891already bindsagent._memory_write_originonto the write-origin ContextVar at turn start. This PR adds detection for review-prompt injection: when the foreground agent receives a user message starting with"Review the conversation above", override the origin to"background_review"for the duration of that turn.Both the fork path (
build_cache_parity_forkalready setsreview_agent._memory_write_origin = "background_review") and the same-session injection path now share the same origin, so all guards fire correctly.Evidence
Before: same-session review writes landed in
~/.hermes/skills/without curator/gate review (issue evidence: 2026-09-10 18:08–18:12, platform=cli, skill_manage create passed the gate).After:
is_background_review()returns True for both paths; skill guards apply.Test coverage
✓ 23 tests in
test_turn_context.py(turn prologue, existing paths)✓ 4 tests in
test_skill_provenance.py(origin ContextVar)✓ 10 tests in
test_background_review_memory_scope.py(fork path, attended/unattended)✓ 2 NEW tests in
test_same_session_review_origin.py(injection detection logic)39 tests passed — fork path, normal path, and injection path all verified.