Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
108 changes: 108 additions & 0 deletions pmoves/configs/tac_trees/dox-intelligence.tac.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,108 @@
# TAC Tree: DoX Document Intelligence
# Audits DoX backend, geometry visualization, NATS auth, Supabase integration

name: "DoX Document Intelligence"
version: "1.0.0"
description: "Verify DoX document processing, geometric visualization, NATS authentication, and Supabase connectivity"

root:
id: dox
task: "DoX document intelligence review"
context: "PMOVES-DoX/ submodule + pmoves/docker-compose.yml"
agent_hint: codex
children:

# =========================================================================
# Phase 1: Submodule & Service
# =========================================================================
- id: dox.submodule
task: "DoX submodule health"
context: "PMOVES-DoX/"
agent_hint: codex
children:
- id: dox.submodule.initialized
task: "DoX submodule initialized"
action:
type: file_exists
target: "PMOVES-DoX/package.json"
expect: "DoX submodule present with package.json"
agent_hint: codex

- id: dox.submodule.claude-md
task: "DoX CLAUDE.md exists"
action:
type: file_exists
target: "PMOVES-DoX/CLAUDE.md"
expect: "Developer context document present"
agent_hint: codex

# =========================================================================
# Phase 2: NATS Authentication (P1 Finding)
# =========================================================================
- id: dox.nats
task: "NATS auth configuration"
context: "DoX NATS is completely unauthenticated (P1 finding from deep-dive alignment)"
agent_hint: codex
children:
- id: dox.nats.auth-block
task: "NATS auth block configured"
action:
type: grep
target: "PMOVES-DoX/"
pattern: "nats.*auth|NATS_URL.*pmoves@"
expect: "Authenticated NATS URL used (nats://nats:pmoves@nats:4222)"
context: "Must use authenticated NATS URL, not bare nats://nats:4222"
Comment on lines +53 to +54

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Avoid embedding credential-shaped URLs in expected text.

Line 53 includes nats://nats:pmoves@nats:4222, which is flagged by secret scanners and can normalize hardcoded credential patterns in docs/config.

Suggested doc-safe expectation text
-            expect: "Authenticated NATS URL used (nats://nats:pmoves@nats:4222)"
+            expect: "Authenticated NATS URL used (nats://<user>:<password>@nats:4222)"
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
expect: "Authenticated NATS URL used (nats://nats:pmoves@nats:4222)"
context: "Must use authenticated NATS URL, not bare nats://nats:4222"
expect: "Authenticated NATS URL used (nats://<user>:<password>@nats:4222)"
context: "Must use authenticated NATS URL, not bare nats://nats:4222"
🧰 Tools
🪛 Checkov (3.2.508)

[medium] 53-54: Basic Auth Credentials

(CKV_SECRET_4)

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@pmoves/configs/tac_trees/dox-intelligence.tac.yaml` around lines 53 - 54, The
expected string contains a credential-shaped URL "nats://nats:pmoves@nats:4222"
which triggers secret scanners; update the expectation in the config (the expect
value) to a doc-safe placeholder such as "Authenticated NATS URL used
(nats://<user>:<password>@nats:4222)" or a generic phrase like "Authenticated
NATS URL used (auth-required NATS URL)" and keep the context text "Must use
authenticated NATS URL, not bare nats://nats:4222" unchanged so the intent
remains clear.

agent_hint: codex

- id: dox.nats.subjects
task: "NATS subjects documented"
action:
type: grep
target: "PMOVES-DoX/"
pattern: "dox\\.|document\\."
expect: "DoX-specific NATS subjects defined"
agent_hint: codex

# =========================================================================
# Phase 3: Backend API
# =========================================================================
- id: dox.backend
task: "DoX backend API"
context: "Backend service with geometry visualization"
agent_hint: codex
children:
- id: dox.backend.healthz
task: "Health endpoint available"
action:
type: grep
target: "PMOVES-DoX/"
pattern: "healthz|health_check|/health"
expect: "/healthz endpoint implemented"
agent_hint: codex

- id: dox.backend.geometry
task: "Geometry visualization module"
action:
type: grep
target: "PMOVES-DoX/"
pattern: "geometry|three.?js|visualization"
expect: "Geometry visualization components present"
context: "DoX includes geometry bus visualization for CHIT"
agent_hint: codex

# =========================================================================
# Phase 4: Supabase Integration
# =========================================================================
- id: dox.supabase
task: "Supabase connectivity"
context: "DoX uses Supabase for document storage and metadata"
agent_hint: codex
children:
- id: dox.supabase.env-vars
task: "Supabase env vars configured"
action:
type: grep
target: "PMOVES-DoX/"
pattern: "SUPABASE_URL|SUPABASE_KEY|SUPA_REST"
expect: "Supabase connection variables defined"
agent_hint: codex
25 changes: 12 additions & 13 deletions pmoves/configs/tac_trees/firefly-iii.tac.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,33 +8,32 @@ description: "Review and fix Firefly III wealth integration documentation, crede
root:
id: firefly-iii
task: "Firefly III integration review"
context: "PMOVES-Wealth/ submodule + pmoves/integrations/firefly-iii/"
context: "pmoves/integrations/firefly-iii/ + pmoves/docs/TAC/TAC_WEALTH.md"
agent_hint: codex
children:
- id: firefly-iii.docs
task: "Documentation completeness"
context: "PMOVES-Wealth/PMOVES.AI_INTEGRATION.md"
context: "pmoves/docs/TAC/TAC_WEALTH.md + pmoves/docs/operations/SEEDED_BRANDED_DEFAULTS.md"
agent_hint: codex
children:
- id: firefly-iii.docs.port
task: "Fix incorrect port 8096 → 8075"
task: "Firefly port documented correctly as 8075"
action:
type: grep
target: "PMOVES-Wealth/PMOVES.AI_INTEGRATION.md"
pattern: "8096"
invert: true
expect: "No references to port 8096 — pattern should NOT match"
target: "pmoves/docs/TAC/TAC_WEALTH.md"
pattern: "8075"
expect: "Port 8075 referenced (FIREFLY_PORT)"
Comment on lines +23 to +25

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

firefly-iii.docs.port currently targets a string not present in TAC_WEALTH.md.

Line 24 requires 8075 in pmoves/docs/TAC/TAC_WEALTH.md, but provided context (pmoves/docs/TAC/TAC_WEALTH.md:1-10) still shows “Port | None assigned”. This makes the check fail deterministically.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@pmoves/configs/tac_trees/firefly-iii.tac.yaml` around lines 23 - 25, The
check is failing because the config expects pattern: "8075" (expect: "Port 8075
referenced (FIREFLY_PORT)") but the target document still shows "Port | None
assigned"; update the source of truth so they match by either changing the
config's pattern/expect value to reflect the current document (e.g., adjust
pattern to match "None assigned" or the actual port text) or update the
documentation to include "8075" and the FIREFLY_PORT note; locate the entry
referencing firefly-iii.docs.port and the YAML keys pattern: "8075" and expect:
"Port 8075 referenced (FIREFLY_PORT)" and make them consistent with the TAC
wealth document.

context: "Port 8096 is Cipher Memory, Firefly uses FIREFLY_PORT=8075"
agent_hint: codex

- id: firefly-iii.docs.mobile
task: "Document REST API mobile surface (Waterfly III)"
- id: firefly-iii.docs.branded-defaults
task: "Branded defaults documented"
action:
type: grep
target: "PMOVES-Wealth/PMOVES.AI_INTEGRATION.md"
pattern: "[Ww]aterfly|[Mm]obile|REST API"
expect: "Waterfly III mobile app section exists"
context: "Waterfly III is an unofficial Firefly III mobile app using REST API"
target: "pmoves/docs/operations/SEEDED_BRANDED_DEFAULTS.md"
pattern: "Firefly|FIREFLY_APP_KEY"
expect: "Firefly III section in branded defaults docs"
context: "FIREFLY_APP_KEY auto-generated by brand_defaults.py"
agent_hint: codex

- id: firefly-iii.creds
Expand Down
122 changes: 122 additions & 0 deletions pmoves/configs/tac_trees/tokenism-chit.tac.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,122 @@
# TAC Tree: ToKenism CHIT Attribution Engine
# Audits CGP encoding, simulation, NATS geometry bus, TypeScript modules

name: "ToKenism CHIT Attribution Engine"
version: "1.0.0"
description: "Verify ToKenism CGP encoding, simulation pipeline, NATS geometry bus integration, and TypeScript module health"

root:
id: tokenism
task: "ToKenism CHIT engine review"
context: "PMOVES-ToKenism-Multi/ submodule + pmoves/docker-compose.yml"
agent_hint: codex
children:
Comment on lines +8 to +13

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Verify this TAC's identifiers vs canonical registry entries.
rg -n -C2 '^\s*id:\s*tokenism\b|^\s*agent_hint:\s*' pmoves/configs/tac_trees/tokenism-chit.tac.yaml
if [ -f pmoves/config/agent_registry.yaml ]; then
  rg -n -C2 '\btokenism\b|\bcodex\b' pmoves/config/agent_registry.yaml
else
  echo "pmoves/config/agent_registry.yaml not found"
fi

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 3440


🏁 Script executed:

# Get the structure and size of the registry file
wc -l pmoves/config/agent_registry.yaml

# Find the agents list section in the registry
rg -n "^agents:|^  - " pmoves/config/agent_registry.yaml | head -80

# Search for tokenism definition in the registry (not just mentions)
rg -B5 -A10 "^tokenism:" pmoves/config/agent_registry.yaml

# Search for codex agent definition
rg -B2 -A8 "^codex:" pmoves/config/agent_registry.yaml

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 225


🏁 Script executed:

# Read the agents list section (starting at line 62)
sed -n '62,150p' pmoves/config/agent_registry.yaml

# Check if tokenism appears anywhere in the registry
rg -n "tokenism" pmoves/config/agent_registry.yaml

# Check the full first agents list section
sed -n '15,25p' pmoves/config/agent_registry.yaml

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 2938


🏁 Script executed:

# Check if tokenism is defined as an agent (top-level key in agents section)
rg -n "^  tokenism:" pmoves/config/agent_registry.yaml

# See what section the "- codex" list belongs to (line before it)
sed -n '330,365p' pmoves/config/agent_registry.yaml

# Count how many agents are actually defined
rg "^  [a-z_]+:" pmoves/config/agent_registry.yaml | wc -l

# Get just the agent keys
rg "^  [a-z_]+:" pmoves/config/agent_registry.yaml | head -30

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 1867


🏁 Script executed:

# Check if codex is defined as an agent
rg "^  codex:" pmoves/config/agent_registry.yaml

# Get all 71 agent keys to confirm tokenism is absent
rg "^  [a-z_]+:" pmoves/config/agent_registry.yaml | sed 's/.*:  //' | sort

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 1351


Register tokenism and codex as canonical agents in pmoves/config/agent_registry.yaml.

The TAC file references id: tokenism (line 9) and agent_hint: codex throughout, but neither agent is defined in the canonical registry. Per coding guidelines, agent definitions must be maintained in pmoves/config/agent_registry.yaml as the single source of truth for all agents. Add both agents to the registry with appropriate configuration before using them in this TAC tree.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@pmoves/configs/tac_trees/tokenism-chit.tac.yaml` around lines 8 - 13, The TAC
references an undefined agent id "tokenism" and an agent_hint "codex"; add
canonical entries for both to the canonical agent registry (the project's agent
registry) so they can be referenced by TAC trees. Create registry entries named
"tokenism" and "codex" including required fields (id, display name,
connector/configuration, and any credentials or default params your system
expects) and ensure their ids exactly match the TAC's id: tokenism and
agent_hint: codex so lookups succeed when the TAC loader reads the registry.


# =========================================================================
# Phase 1: Submodule & Modules
# =========================================================================
- id: tokenism.submodule
task: "ToKenism submodule health"
context: "PMOVES-ToKenism-Multi/"
agent_hint: codex
children:
- id: tokenism.submodule.initialized
task: "Submodule initialized (not shallow)"
action:
type: file_exists
target: "PMOVES-ToKenism-Multi/package.json"
expect: "ToKenism submodule present with package.json"
agent_hint: codex

- id: tokenism.submodule.chit-contracts
task: "CHIT contract modules present"
action:
type: file_exists
target: "PMOVES-ToKenism-Multi/integrations/contracts/chit/"
expect: "CHIT TypeScript contract modules directory exists"
context: "9 TypeScript modules for CGP encoding/decoding/attribution"
agent_hint: codex

# =========================================================================
# Phase 2: NATS Geometry Bus
# =========================================================================
- id: tokenism.nats
task: "NATS geometry bus integration"
context: "Tokenism is a primary CHIT-aware service on the geometry bus"
agent_hint: codex
children:
- id: tokenism.nats.cgp-subject
task: "CGP subject publishing"
action:
type: grep
target: "PMOVES-ToKenism-Multi/"
pattern: "geometry\\.cgp|tokenism\\.cgp"
expect: "Geometry CGP subjects referenced"
context: "geometry.cgp.v1 (transport), tokenism.cgp.ready.v1 (readiness)"
agent_hint: codex

- id: tokenism.nats.simulation
task: "Simulation result subjects"
action:
type: grep
target: "PMOVES-ToKenism-Multi/"
pattern: "tokenism\\.simulation"
expect: "tokenism.simulation.result.v1 subject present"
agent_hint: codex

# =========================================================================
# Phase 3: Environment & Docker
# =========================================================================
- id: tokenism.env
task: "Environment configuration"
context: "P1 finding: env.shared uses export syntax (Docker incompatible)"
agent_hint: codex
children:
- id: tokenism.env.no-export
task: "No export syntax in env files"
action:
type: grep
target: "PMOVES-ToKenism-Multi/"
pattern: "^export "
invert: true
expect: "No export statements in env files — pattern should NOT match"
context: "Docker env_file cannot parse export VAR=val, only VAR=val"
Comment on lines +75 to +83

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Verify runner regex behavior and this rule's pattern.
rg -n -C2 'def _check_grep|re\.search\(' pmoves/tools/tac_runner.py
rg -n -C2 'id: tokenism\.env\.no-export|pattern:|invert:' pmoves/configs/tac_trees/tokenism-chit.tac.yaml

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 2579


🏁 Script executed:

#!/bin/bash
# Verify Python re.search behavior with ^ anchor and multiline mode
python3 <<'EOF'
import re

# Test 1: ^ anchor without MULTILINE flag
text_multiline = "line1\nexport VAR=val\nline3"
pattern_no_flag = "^export "
pattern_with_inline = "(?m)^export "

result1 = re.search(pattern_no_flag, text_multiline)
result2 = re.search(pattern_with_inline, text_multiline)

print(f"Test 1 - Pattern without flag on multiline text: {bool(result1)}")
print(f"Test 2 - Pattern with (?m) inline flag on multiline text: {bool(result2)}")

# Test 2: ^ at file start
text_start = "export VAR=val\nline2"
result3 = re.search(pattern_no_flag, text_start)
print(f"Test 3 - Pattern at file start: {bool(result3)}")

# Test 3: with MULTILINE flag
result4 = re.search(pattern_no_flag, text_multiline, re.MULTILINE)
print(f"Test 4 - Pattern with re.MULTILINE flag on multiline text: {bool(result4)}")
EOF

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 285


🏁 Script executed:

#!/bin/bash
# Check the invert logic in tac_runner.py
rg -n -A10 "invert.*True\|invert.*true\|invert:" pmoves/tools/tac_runner.py | head -40

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 49


🏁 Script executed:

#!/bin/bash
# List files in the target directory to understand scope
ls -la PMOVES-ToKenism-Multi/ 2>/dev/null | head -20
find PMOVES-ToKenism-Multi/ -type f -name "*.env*" 2>/dev/null | head -20

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 179


🏁 Script executed:

#!/bin/bash
# Check for agent_registry.yaml and verify canonical agent definitions reference
fd agent_registry.yaml pmoves/
cat pmoves/config/agent_registry.yaml 2>/dev/null | head -30

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 926


🏁 Script executed:

#!/bin/bash
# Get full _check_grep function to see invert handling
sed -n '52,100p' pmoves/tools/tac_runner.py

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 1800


🏁 Script executed:

#!/bin/bash
# Search for how invert is processed in the action evaluation
rg -n "invert|result\[.invert" pmoves/tools/tac_runner.py | head -20

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 296


🏁 Script executed:

#!/bin/bash
# Check if tokenism agent is referenced in agent_registry.yaml
rg -n "tokenism" pmoves/config/agent_registry.yaml | head -10

Repository: POWERFULMOVES/PMOVES.AI

Length of output: 208


no-export grep pattern fails to catch export statements on non-first lines.

The pattern ^export uses the ^ anchor without the multiline flag. In Python's re.search() (which the runner uses without flags), ^ only matches the start of the entire string, not the start of each line. Files with export VAR=val on line 2 or later will incorrectly pass the check.

Use the inline (?m) flag to enable multiline mode:

Proposed fix
         - id: tokenism.env.no-export
           task: "No export syntax in env files"
           action:
             type: grep
             target: "PMOVES-ToKenism-Multi/"
-            pattern: "^export "
+            pattern: "(?m)^export "
             invert: true
             expect: "No export statements in env files — pattern should NOT match"
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
- id: tokenism.env.no-export
task: "No export syntax in env files"
action:
type: grep
target: "PMOVES-ToKenism-Multi/"
pattern: "^export "
invert: true
expect: "No export statements in env files — pattern should NOT match"
context: "Docker env_file cannot parse export VAR=val, only VAR=val"
- id: tokenism.env.no-export
task: "No export syntax in env files"
action:
type: grep
target: "PMOVES-ToKenism-Multi/"
pattern: "(?m)^export "
invert: true
expect: "No export statements in env files — pattern should NOT match"
context: "Docker env_file cannot parse export VAR=val, only VAR=val"
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@pmoves/configs/tac_trees/tokenism-chit.tac.yaml` around lines 75 - 83, The
grep rule with id tokenism.env.no-export currently uses pattern "^export " which
only matches at the start of the entire file and misses export statements on
subsequent lines; update the rule's pattern (in the tokenism.env.no-export
action.pattern) to enable multiline matching (for example by prefixing the regex
with the inline (?m) flag) so ^ will match the start of every line and detect
any "export " occurrences anywhere in the file.

agent_hint: codex

- id: tokenism.env.compose
task: "Docker Compose service defined"
action:
type: grep
target: "pmoves/docker-compose.yml"
pattern: "tokenism-simulator|tokenism-ui"
expect: "Tokenism services defined in compose"
context: "Port 8103 (simulator), Next.js UI"
Comment on lines +86 to +93

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Compose check does not guarantee both services are present.

tokenism-simulator|tokenism-ui passes if either exists, but the task expects both services.

Proposed fix
         - id: tokenism.env.compose
           task: "Docker Compose service defined"
           action:
             type: grep
             target: "pmoves/docker-compose.yml"
-            pattern: "tokenism-simulator|tokenism-ui"
+            pattern: "(?s)(?=.*tokenism-simulator)(?=.*tokenism-ui)"
             expect: "Tokenism services defined in compose"
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
- id: tokenism.env.compose
task: "Docker Compose service defined"
action:
type: grep
target: "pmoves/docker-compose.yml"
pattern: "tokenism-simulator|tokenism-ui"
expect: "Tokenism services defined in compose"
context: "Port 8103 (simulator), Next.js UI"
- id: tokenism.env.compose
task: "Docker Compose service defined"
action:
type: grep
target: "pmoves/docker-compose.yml"
pattern: "(?s)(?=.*tokenism-simulator)(?=.*tokenism-ui)"
expect: "Tokenism services defined in compose"
context: "Port 8103 (simulator), Next.js UI"
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@pmoves/configs/tac_trees/tokenism-chit.tac.yaml` around lines 86 - 93, The
compose check (id: tokenism.env.compose, task: "Docker Compose service defined")
currently uses a single regex "tokenism-simulator|tokenism-ui" which matches if
either service exists; update the check to require both services by replacing
the pattern with a combined assertion (e.g. a regex with positive lookaheads
that checks for both "tokenism-simulator" and "tokenism-ui") or run two separate
grep checks for each service, and update the expect message to say "Both
Tokenism services defined in compose" to reflect the stricter requirement.

agent_hint: codex

# =========================================================================
# Phase 4: Skill Pairing Integration
# =========================================================================
- id: tokenism.skills
task: "Skill pairing wiring"
context: "ToKenism is referenced in 5 skill pairings"
agent_hint: codex
children:
- id: tokenism.skills.pairings
task: "Skill pairing references"
action:
type: grep
target: "pmoves/configs/skill-pairings.yaml"
pattern: "tokenism"
expect: "At least 3 skill pairing references"
Comment on lines +104 to +110

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor

This node claims a minimum count that the action type cannot enforce.

grep in the TAC runner is boolean (found/not found). “At least 3 skill pairing references” is not actually validated.

Proposed fix (align assertion with executable behavior)
         - id: tokenism.skills.pairings
           task: "Skill pairing references"
           action:
             type: grep
             target: "pmoves/configs/skill-pairings.yaml"
             pattern: "tokenism"
-            expect: "At least 3 skill pairing references"
+            expect: "One or more skill pairing references"
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@pmoves/configs/tac_trees/tokenism-chit.tac.yaml` around lines 104 - 110, The
node with id tokenism.skills.pairings uses action.type grep which only returns
found/not found, but its expect text claims "At least 3 skill pairing
references"; update the TAC node so the assertion matches grep's boolean
behavior: either change the expect string to something like "Contains tokenism
skill pairing reference" (or "At least one skill pairing reference") to reflect
a boolean check, or if you actually need to enforce a count, replace action.type
grep with a counting-capable action and implement the count check against
pmoves/configs/skill-pairings.yaml; modify the node labeled
tokenism.skills.pairings accordingly.

context: "ingest-chit-index, chit-3d-viz, pr-monitor-graphiti-chit, etc."
agent_hint: codex

- id: tokenism.skills.cgp-schema
task: "CGP schema version alignment"
action:
type: grep
target: "PMOVES-ToKenism-Multi/"
pattern: "chit\\.cgp\\.v|cgp.*version"
expect: "CGP schema version referenced (chit.cgp.v1.0 canonical)"
context: "Transport: geometry.cgp.v1, Payload: chit.cgp.v0.2, Canonical: chit.cgp.v1.0"
agent_hint: codex
11 changes: 11 additions & 0 deletions pmoves/docs/PRODUCTION_AUDIT_DASHBOARD.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,17 @@

## Latest Changes (Mar 15, 2026)

### TAC YAML Audit Trees + Umbrella Coverage (Mar 15, 2026)

- **2 new YAML audit trees** — `dox-intelligence.tac.yaml`, `tokenism-chit.tac.yaml`
- **1 YAML TAC updated** — `firefly-iii.tac.yaml` (fixed broken submodule reference)
- **3 umbrella markdown TACs** for service groups:
- `TAC_EMBEDDING_PIPELINE.md` — Extract Worker (8083) + LangExtract (8084) + PDF Ingest (8092)
- `TAC_MEDIA_ANALYSIS.md` — Media-Video (8079) + Media-Audio (8082)
- `TAC_E2B_SANDBOX.md` — 5 E2B submodules (cloud execution)
- **Coverage:** 26 markdown + 14 YAML = 40 TAC files (~55% of 62 agents)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Coverage percentage is mathematically inconsistent.

Line 24 says 40 TAC files (~55% of 62 agents), but 40/62 is ~64.5%. Please correct percentage or clarify a different denominator.

As per coding guidelines, "pmoves/docs/**: Check docs for operational accuracy: Keep status claims aligned with evidence in runbooks and smokes."

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@pmoves/docs/PRODUCTION_AUDIT_DASHBOARD.md` at line 24, The coverage
percentage in PRODUCTION_AUDIT_DASHBOARD.md is inconsistent: the line currently
reads "40 TAC files (~55% of 62 agents)" but 40/62 ≈ 64.5%; update that line to
either compute and display the correct percentage ("40 TAC files (~64.5% of 62
agents)" or rounded to desired precision) or change the denominator/explanation
if you meant a different total (e.g., agents vs. files); ensure the text "40 TAC
files (~55% of 62 agents)" is replaced with the corrected wording so the
documented claim matches the actual calculation.

- Integration Topology updated to v2.2

### TAC P1 Coverage Expansion (Mar 15, 2026)

- **7 new P1 TAC trees** created for previously undocumented integration services:
Expand Down
Loading
Loading