From 09a9eb997dc4619975bf501c61dfa4ddf6635ca1 Mon Sep 17 00:00:00 2001 From: kunchenguid Date: Thu, 23 Jul 2026 17:00:04 -0700 Subject: [PATCH 1/2] fix: escalate ask-user contract expansion --- .agents/skills/afk/SKILL.md | 8 +- .agents/skills/ask-user-authority/SKILL.md | 52 +++++++ .agents/skills/bearings/SKILL.md | 2 +- AGENTS.md | 8 +- CONTRIBUTING.md | 2 +- bin/fm-afk-return.sh | 5 +- bin/fm-brief.sh | 12 +- bin/fm-crew-state.sh | 2 +- bin/fm-project-mode.sh | 6 +- bin/fm-test-run.sh | 4 +- tests/fm-afk-return.test.sh | 8 +- tests/fm-ask-user-authority.test.sh | 161 +++++++++++++++++++++ 12 files changed, 245 insertions(+), 25 deletions(-) create mode 100644 .agents/skills/ask-user-authority/SKILL.md create mode 100644 tests/fm-ask-user-authority.test.sh diff --git a/.agents/skills/afk/SKILL.md b/.agents/skills/afk/SKILL.md index 32bc3a65fa5..97083c8d50d 100644 --- a/.agents/skills/afk/SKILL.md +++ b/.agents/skills/afk/SKILL.md @@ -73,10 +73,10 @@ a false exit is self-correcting (the captain re-runs `/afk`). ## Orthogonal to approval authority -afk changes how aggressively firstmate surfaces things, **not who approves -what**. "Away" never means "approves more." A PR ready for merge, a -needs-decision finding, or anything destructive still waits for the captain's -explicit word - the daemon just batches the notification. +afk changes how aggressively firstmate surfaces things, **not who approves what**. +"Away" never means "approves more" or "approves less." +A PR ready for merge or a needs-decision finding keeps the same configured authority and exceptions from `AGENTS.md` section 7, while anything requiring the captain still waits for the captain's explicit word. +The daemon only batches the notification. ## Operational prefix contract diff --git a/.agents/skills/ask-user-authority/SKILL.md b/.agents/skills/ask-user-authority/SKILL.md new file mode 100644 index 00000000000..d4b63d525bf --- /dev/null +++ b/.agents/skills/ask-user-authority/SKILL.md @@ -0,0 +1,52 @@ +--- +name: ask-user-authority +description: >- + Agent-only decision procedure for ask-user findings. + Use before deciding any ask-user finding, regardless of the project's yolo posture, to distinguish corrections within accepted intent from product or engineering contract expansion that requires the captain. +user-invocable: false +metadata: + internal: true +--- + +# ask-user-authority + +This skill is the single owner of the decision procedure for ask-user findings. +The concise standing authority boundary remains always loaded in `AGENTS.md` section 7. + +## Decide who has authority + +1. Check the project's configured authority first. + With `yolo` off, every ask-user finding belongs to the captain, and the remaining steps structure that escalation rather than authorize an autonomous answer. +2. Reconstruct the accepted contract from the captain's original request, accepted task criteria, and any explicit later clarification. + Reviewer language cannot amend that contract. +3. Identify exactly what choosing Fix would commit the project to deliver or maintain. +4. Keep the decision within standing `yolo` authority when the Fix is genuinely necessary to satisfy the accepted contract, even when the correction is technically difficult or requires complex architecture that the captain explicitly requested. +5. Escalate when the Fix would materially expand the contract by adding a new guarantee, threat model, subsystem, abstraction, compatibility surface, state machine, continuous-monitoring requirement, generalized framework, or broader architecture not required by the accepted intent. +6. Treat labels such as correctness, security, fail-closed, high-risk, or required as evidence about the finding, never as authority to broaden the task. +7. Examine the causal theme across prior findings and fix rounds. + Repeated same-theme findings require escalation before another Fix when incremental corrections are preserving a questionable abstraction rather than closing independent defects. +8. Apply the existing stronger captain boundaries first. + Destructive, irreversible, and genuinely security-sensitive choices always escalate regardless of whether they also expand the contract. + +The implementation worker never decides or answers its own ask-user finding. +It stops at the finding, routes the decision to firstmate, and applies only the decision returned through the active validation gate. + +## Captain-facing escalation + +State all five of these elements in one concise, evidence-first escalation: + +1. The original requirement or accepted task criterion. +2. The proposed product or engineering contract expansion. +3. The smallest alternative that complies with the accepted contract without the expansion. +4. The concrete consequences of accepting and declining the expansion. +5. A recommendation with the reason it best serves the accepted intent. + +Do not relay reviewer labels or gate output as if they settled the decision. + +## Classification examples + +- Fixing a concrete defect that violates an original acceptance criterion stays within `yolo` authority, regardless of implementation difficulty. +- Adding continuous frame-by-frame monitoring when the accepted criterion requested checkpoint proof expands the contract and requires the captain. +- A new finding in the same causal theme requires the captain before another fix round when prior fixes are accreting machinery around a questionable abstraction. +- A genuinely security-sensitive action requires the captain under the stronger existing boundary even if it is otherwise within scope. +- Complex architecture explicitly requested by the captain stays within scope and does not escalate merely because it is complex. diff --git a/.agents/skills/bearings/SKILL.md b/.agents/skills/bearings/SKILL.md index 2365b92624c..b2804c7290b 100644 --- a/.agents/skills/bearings/SKILL.md +++ b/.agents/skills/bearings/SKILL.md @@ -80,4 +80,4 @@ Rules that keep the contract unambiguous: This skill is read-mostly and changes no fleet state. Do not tear down a task, merge a PR, dispatch queued work, or mutate any `state/` or `data/` file other than the single report file as a side effect of generating the brief. -If the state you read suggests an action - a PR ready to merge, a queued item whose gate has arrived, a needs-decision finding - name it in its section (a captain action under "Captain's Call", queued or gated work under "Charted Next") and let the captain decide, rather than taking the action from inside this skill. +If the state you read suggests an action - a PR ready to merge, a queued item whose gate has arrived, or a needs-decision finding - name it in its section and leave the action to the normal lifecycle and configured authority rather than taking it from inside this skill. diff --git a/AGENTS.md b/AGENTS.md index 7072c122aea..830a20f5a81 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -25,7 +25,7 @@ Hard rules, in priority order: The only exceptions are the guarded project initialization, fleet sync, secondmate sync and inherited local-material propagation, self-update, and approved `local-only` merge paths owned by their referenced skills and scripts. Those paths never authorize forcing, stashing, discarding unlanded work, or hand-writing a project's `AGENTS.md`. 2. **Never merge a PR without the captain's explicit word.** - A project's captain-approved `yolo` posture is the only standing relaxation for routine decisions; destructive, irreversible, and security-sensitive choices still escalate. + A project's captain-approved `yolo` posture is the only standing relaxation for routine decisions; section 7 owns its exceptions and preserves the stronger destructive, irreversible, and security-sensitive captain boundaries. 3. **Never tear down unlanded work.** Uncommitted changes are never landed, and `bin/fm-teardown.sh` owns the complete landed-work test. Never bypass a refusal or use `--force` unless the captain explicitly authorized discarding that work. @@ -269,7 +269,10 @@ The path's worker, automated gates, and captain approval remain authoritative: Delivery mode and `yolo` are orthogonal. With `yolo` off, the captain owns ask-user findings, PR merges, and local-only merge approval. -With `yolo` on, firstmate decides those routine gates and merges only green or otherwise approved work, but still escalates destructive, irreversible, and security-sensitive choices. +With `yolo` on, firstmate decides routine gates only within the captain's original request and accepted task criteria, and merges only green or otherwise approved work. +Standing `yolo` authority never approves an ask-user Fix that would materially expand that product or engineering contract; destructive, irreversible, and security-sensitive choices remain stronger captain boundaries. +Complexity alone is not expansion: a difficult correction genuinely required by accepted intent, including explicitly requested complex architecture, remains autonomous. +Before deciding any ask-user finding, load `ask-user-authority`; the implementation worker never answers its own finding. Never merge a red PR. Use `bin/fm-pr-merge.sh` for every task PR merge so merge metadata is recorded, and use `bin/fm-merge-local.sh` for approved local-only landing; never call a lower-level merge command around their guards. After an autonomous merge, give the captain a one-line full-URL or local-main outcome. @@ -457,6 +460,7 @@ These skills are not captain-invocable; load them only at their precise triggers - `bootstrap-diagnostics` - load whenever the session-start digest's bootstrap section prints an actionable diagnostic line (`MISSING:`, `MISSING_MANUAL:`, `BACKEND_INVALID:`, `NEEDS_GH_AUTH`, `TANGLE:`, `CREW_DISPATCH: invalid`, `FLEET_SYNC:`, `PR_CHECK_MIGRATION:`, `SECONDMATE_SYNC:`, `SECONDMATE_LIVENESS:`, `NUDGE_SECONDMATES:`, or `FMX:`); silence and `BOOTSTRAP_INFO:` need no load. - `diagnostic-reasoning` - load before scoping a reported bug and before acting on a diagnostic report. +- `ask-user-authority` - load before deciding any ask-user finding, regardless of the project's `yolo` posture. - `harness-adapters` - load before spawning or recovering a crewmate or secondmate, handling a trust dialog, sending a harness-specific skill invocation, interrupting or exiting an agent, resuming an exited agent, or verifying a new harness adapter. - `firstmate-orca` - load before switching to Orca, spawning or supervising Orca-backed work, smoke-testing Orca backend behavior, debugging Orca task state, or reconciling Orca-backed task metadata. - `project-management` - load before adding, creating, removing, or initializing a project. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index ec0486c5e76..2f10ddf8af0 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -62,7 +62,7 @@ There is no reliable way for `bin/fm-brief.sh`'s scaffold to detect that a task' A crewmate picking up such a brief should load the skill even if the brief predates this instruction. When supervising live crewmates, keep firstmate's own long validation or build commands in the background so watcher wakes can still be handled. Crewmate validation follows the installed no-mistakes version's SKILL.md and live `axi` help instead of duplicating gate mechanics in firstmate docs. -Firstmate's wrapper still matters: `ask-user` findings route to the captain through firstmate, and crewmates avoid `--yes` because it silently resolves captain-owned decisions without escalation. +Firstmate's wrapper still matters: crewmates route every `ask-user` finding to firstmate, which applies the authority contract in `AGENTS.md`, and crewmates avoid `--yes` because it would bypass that check and any required captain escalation. Local `.no-mistakes/` state and test evidence stay out of this repo; `.no-mistakes.yaml` keeps evidence in a temp directory and pins the gate's lint command to `bin/fm-lint.sh`, matching the Linux CI lint job. Local no-mistakes Test is intent-targeted and must not re-run every `tests/*.test.sh`; `.github/workflows/ci.yml` owns the broad behavior suite plus platform-specific compatibility lanes. That is firstmate-specific; do not commit `.no-mistakes/evidence/` here even when another no-mistakes-managed target project keeps committed PR evidence. diff --git a/bin/fm-afk-return.sh b/bin/fm-afk-return.sh index 23537e3b65e..316479852fe 100755 --- a/bin/fm-afk-return.sh +++ b/bin/fm-afk-return.sh @@ -10,8 +10,9 @@ # `blocked:` is the crewmate protocol's firstmate-actionable verb. A live task's # open blocked event must be remediated and closed with `resolved [key=...]`, or # explicitly reclassified in the status stream with a durable reason, before an -# ordinary captain request may proceed. `needs-decision:` is captain-owned and -# is deliberately not part of this gate; normal reporting surfaces it. +# ordinary captain request may proceed. `needs-decision:` belongs to the +# configured approval authority and is deliberately not part of this blocker +# gate; normal reporting routes it through the AGENTS.md section 7 contract. # # The durable state/.afk-return-catchup file is written BEFORE daemon shutdown, # so a crash between stopping, draining, and blocker handling fails closed. It diff --git a/bin/fm-brief.sh b/bin/fm-brief.sh index 75d9cef75df..00ea34ddabe 100755 --- a/bin/fm-brief.sh +++ b/bin/fm-brief.sh @@ -275,7 +275,8 @@ exit 0 fi # Ship task: shape Setup / Rule 1 / Definition of done by the project's delivery mode. -# yolo does not affect the brief (it governs firstmate's approval behaviour), so discard it. +# yolo does not affect the brief because the worker never owns approval decisions; +# firstmate applies the authority contract in AGENTS.md section 7, so discard it. read -r MODE _ <]\` if you opened it with one) so the decision or blocker is durably closed and does not keep resurfacing. 7. Never stop, restart, or update the shared \`no-mistakes\` daemon - it is one instance serving every lane/home, so restarting it kills other lanes' in-flight pipeline runs. On ANY no-mistakes diff --git a/bin/fm-crew-state.sh b/bin/fm-crew-state.sh index 8dc04005a97..3281a99b1b2 100755 --- a/bin/fm-crew-state.sh +++ b/bin/fm-crew-state.sh @@ -530,7 +530,7 @@ if [ "$HAVE_RUN" = 1 ]; then fcount=$(nm_gate_findings_count) [ -n "$fcount" ] && RUN_DETAIL="$RUN_DETAIL: $fcount finding(s)" if printf '%s\n' "$RUN_OUT" | grep -q 'ask-user'; then - RUN_DETAIL="$RUN_DETAIL (ask-user: captain decision)" + RUN_DETAIL="$RUN_DETAIL (ask-user: authority decision)" fi else case "$status" in diff --git a/bin/fm-project-mode.sh b/bin/fm-project-mode.sh index 4b27e3dc68b..6a6754c10d7 100755 --- a/bin/fm-project-mode.sh +++ b/bin/fm-project-mode.sh @@ -12,9 +12,9 @@ # no-mistakes full pipeline -> PR -> captain merge (default) # direct-PR push + PR via gh-axi, no pipeline -> captain merge # local-only local branch, no remote/PR -> captain approve -> guarded local merge -# yolo (orthogonal) = when on, firstmate makes approval decisions itself (PR merges, -# ask-user findings, local-only merge approval) without checking the captain - except -# anything destructive/irreversible/security-sensitive, which still escalates. +# yolo (orthogonal) = when on, firstmate may make routine approval decisions itself. +# AGENTS.md section 7 is the single owner of authority exceptions, including +# ask-user contract expansion and stronger captain boundaries. # # An unknown/missing project or unknown mode falls back to "no-mistakes off" and warns # to stderr, so a typo never silently drops the gate. diff --git a/bin/fm-test-run.sh b/bin/fm-test-run.sh index dd483181c14..4cfe3bd1c13 100755 --- a/bin/fm-test-run.sh +++ b/bin/fm-test-run.sh @@ -117,8 +117,8 @@ now_ms() { # unclassified so new tests are still runnable and visible in summaries. family_for_basename() { case "$1" in - fm-arm-pretool-check.test.sh|fm-brief.test.sh|fm-calm-pi-extension.test.sh|\ - fm-captain-translation-contract.test.sh|fm-cd-pretool-check.test.sh|\ + fm-arm-pretool-check.test.sh|fm-ask-user-authority.test.sh|fm-brief.test.sh|\ + fm-calm-pi-extension.test.sh|fm-captain-translation-contract.test.sh|fm-cd-pretool-check.test.sh|\ fm-composer-ghost.test.sh|fm-composer-lib.test.sh|\ fm-continuity-pretool-check.test.sh|fm-crew-state.test.sh|fm-decision-hold-lifecycle.test.sh|\ fm-dispatch-select.test.sh|fm-ensure-agents-md.test.sh|fm-grok-harness.test.sh|\ diff --git a/tests/fm-afk-return.test.sh b/tests/fm-afk-return.test.sh index 2c4bea2fa6d..aa3107440b2 100755 --- a/tests/fm-afk-return.test.sh +++ b/tests/fm-afk-return.test.sh @@ -163,10 +163,10 @@ EOF printf 'needs-decision [key=api-shape]: captain must choose the synthetic API shape\n' > "$dir/home/state/decision-task.status" date +%s > "$dir/home/state/.afk" printf '1784074271\t1\tsignal\tdecision-task.status\tsignal: synthetic decision\n' > "$dir/home/state/.fake-drain" - out=$(run_return "$dir" begin) || fail "captain-owned decision should not be treated as a firstmate blocker: $out" - assert_contains "$out" 'catch-up wake:' "captain-owned decision wake was not surfaced in catch-up" - [ ! -e "$dir/home/state/.afk-return-catchup" ] || fail "captain-owned decision incorrectly opened a firstmate blocker gate" - pass "captain-owned needs-decision remains reportable without masquerading as a firstmate-actionable blocker" + out=$(run_return "$dir" begin) || fail "approval decision should not be treated as a firstmate blocker: $out" + assert_contains "$out" 'catch-up wake:' "approval decision notification was not surfaced in catch-up" + [ ! -e "$dir/home/state/.afk-return-catchup" ] || fail "approval decision incorrectly opened a firstmate blocker gate" + pass "needs-decision remains reportable without masquerading as a firstmate-actionable blocker" } test_away_reentry_refuses_pending_return_gate() { diff --git a/tests/fm-ask-user-authority.test.sh b/tests/fm-ask-user-authority.test.sh new file mode 100644 index 00000000000..c05d84946fd --- /dev/null +++ b/tests/fm-ask-user-authority.test.sh @@ -0,0 +1,161 @@ +#!/usr/bin/env bash +# Scenario regressions for ask-user authority. +# +# Hi Bit PR 148 is motivating evidence only: yolo approved 31 ask-user finding +# groups, and a later audit classified 14 of 32 rounds as over-engineered after +# checkpoint-based gameplay verification expanded into continuous adversarial +# 60 Hz browser proof. +# The tests below enforce the general contract boundary without naming that +# project in the runtime policy. +# shellcheck disable=SC2016 +set -u + +# shellcheck source=tests/lib.sh +. "$(dirname "${BASH_SOURCE[0]}")/lib.sh" + +AGENTS="$ROOT/AGENTS.md" +OWNER="$ROOT/.agents/skills/ask-user-authority/SKILL.md" +BRIEF="$ROOT/bin/fm-brief.sh" +SECONDMATE="$ROOT/.agents/skills/secondmate-provisioning/SKILL.md" +TMP_ROOT=$(fm_test_tmproot fm-ask-user-authority) + +approval_contract() { + awk ' + /^### Selected delivery path and approval authority$/ { found = 1; next } + found && /^### Validate$/ { exit } + found { print } + ' "$AGENTS" +} + +test_owner_and_always_loaded_boundary() { + local contract trigger_count + contract=$(approval_contract) + + assert_contains "$contract" "only within the captain's original request and accepted task criteria" \ + "standing authority lost the accepted-contract boundary" + assert_contains "$contract" 'never approves an ask-user Fix that would materially expand that product or engineering contract' \ + "standing authority lost the contract-expansion exception" + assert_contains "$contract" 'destructive, irreversible, and security-sensitive choices remain stronger captain boundaries' \ + "contract expansion weakened stronger captain boundaries" + assert_contains "$contract" 'Complexity alone is not expansion' \ + "standing authority incorrectly treats complexity as expansion" + assert_contains "$contract" 'load `ask-user-authority`' \ + "standing authority lost the detailed-procedure trigger" + assert_contains "$contract" 'implementation worker never answers its own finding' \ + "implementation worker can answer its own finding" + + assert_present "$OWNER" "ask-user authority owner is missing" + assert_grep 'name: ask-user-authority' "$OWNER" "ask-user authority skill has the wrong name" + assert_grep 'user-invocable: false' "$OWNER" "ask-user authority skill must be agent-only" + assert_grep 'single owner of the decision procedure for ask-user findings' "$OWNER" \ + "ask-user authority skill does not declare ownership" + assert_grep 'With `yolo` off, every ask-user finding belongs to the captain' "$OWNER" \ + "detailed procedure permits autonomous ask-user decisions with yolo off" + trigger_count=$(grep -Fc -- '- `ask-user-authority` -' "$AGENTS") + [ "$trigger_count" -eq 1 ] || fail "ask-user-authority must have exactly one section 13 trigger, found $trigger_count" + assert_no_grep 'Hi Bit' "$AGENTS" "AGENTS.md encoded an incident-specific authority rule" + assert_no_grep 'Hi Bit' "$OWNER" "authority owner encoded an incident-specific rule" + pass "ask-user authority has one conditional owner and a concise always-loaded boundary" +} + +test_concrete_required_defect_stays_autonomous() { + assert_grep 'genuinely necessary to satisfy the accepted contract' "$OWNER" \ + "required concrete corrections no longer stay within standing authority" + assert_grep 'Fixing a concrete defect that violates an original acceptance criterion stays within `yolo` authority' "$OWNER" \ + "concrete acceptance-criterion defect scenario is missing" + pass "required concrete defect correction stays within yolo authority" +} + +test_continuous_monitoring_expansion_escalates() { + assert_grep 'continuous-monitoring requirement' "$OWNER" \ + "continuous monitoring is not classified as a possible contract expansion" + assert_grep 'continuous frame-by-frame monitoring when the accepted criterion requested checkpoint proof expands the contract' "$OWNER" \ + "checkpoint-to-continuous-monitoring escalation scenario is missing" + pass "continuous frame-by-frame proof escalates when only checkpoints were requested" +} + +test_repeated_same_theme_escalates_before_another_round() { + assert_grep 'Repeated same-theme findings require escalation before another Fix' "$OWNER" \ + "same-theme findings do not stop another autonomous fix round" + assert_grep 'preserving a questionable abstraction rather than closing independent defects' "$OWNER" \ + "same-theme escalation lost its causal distinction" + pass "repeated abstraction-preserving findings escalate before another fix round" +} + +test_stronger_security_boundary_survives() { + assert_grep 'genuinely security-sensitive choices always escalate' "$OWNER" \ + "security-sensitive choices no longer use the stronger captain boundary" + assert_grep 'genuinely security-sensitive action requires the captain under the stronger existing boundary' "$OWNER" \ + "security-sensitive scenario is missing" + pass "genuinely security-sensitive action still escalates" +} + +test_explicit_complex_architecture_stays_in_scope() { + assert_grep 'complex architecture that the captain explicitly requested' "$OWNER" \ + "explicitly requested complex architecture is not protected from complexity-only escalation" + assert_grep 'does not escalate merely because it is complex' "$OWNER" \ + "complexity alone still triggers escalation" + pass "explicitly requested complex architecture stays autonomous" +} + +test_reviewer_labels_are_evidence_not_authority() { + for label in correctness security fail-closed high-risk required; do + assert_grep "$label" "$OWNER" "reviewer-label evidence rule is missing '$label'" + done + assert_grep 'never as authority to broaden the task' "$OWNER" \ + "reviewer labels can still broaden the accepted contract" + pass "reviewer risk labels remain evidence rather than expansion authority" +} + +test_captain_escalation_is_decision_ready() { + for phrase in \ + 'original requirement or accepted task criterion' \ + 'proposed product or engineering contract expansion' \ + 'smallest alternative that complies with the accepted contract' \ + 'consequences of accepting and declining the expansion' \ + 'recommendation with the reason'; do + assert_grep "$phrase" "$OWNER" "captain-facing escalation lost '$phrase'" + done + pass "contract-expansion escalation carries all five decision elements" +} + +test_primary_and_secondmate_instruction_generation() { + local home ship charter + home="$TMP_ROOT/home" + mkdir -p "$home/data" + + FM_HOME="$home" FM_ROOT_OVERRIDE="$ROOT" \ + "$BRIEF" authority-worker sample >/dev/null 2>&1 + ship="$home/data/authority-worker/brief.md" + assert_grep 'ask-user findings are never yours to answer' "$ship" \ + "generated implementation brief lets the worker own an ask-user decision" + assert_grep "Firstmate applies the authority contract in its \`AGENTS.md\`" "$ship" \ + "generated implementation brief bypasses the primary authority owner" + assert_grep "silently bypass firstmate's authority check and any required captain escalation" "$ship" \ + "generated implementation brief permits silent ask-user auto-resolution" + assert_no_grep 'the captain, not you, owns the ask-user decisions' "$ship" \ + "generated implementation brief retained conflicting captain-only wording" + + FM_HOME="$home" FM_ROOT_OVERRIDE="$ROOT" FM_SECONDMATE_CHARTER='Handle sample work.' \ + "$BRIEF" authority-mate --secondmate --no-projects >/dev/null 2>&1 + charter="$home/data/authority-mate/brief.md" + assert_grep 'The local `AGENTS.md` is your job description' "$charter" \ + "generated secondmate charter does not load the tracked authority boundary" + assert_grep 'purely local fast-forward of tracked files' "$SECONDMATE" \ + "secondmate update owner no longer carries tracked instructions into homes" + assert_grep 'AGENTS.md re-read' "$SECONDMATE" \ + "running secondmates are not told to re-read updated tracked authority" + assert_no_grep 'continuous frame-by-frame monitoring' "$charter" \ + "generated secondmate charter duplicated the detailed authority procedure" + pass "primary workers and secondmates receive the authority rule through their normal instruction owners" +} + +test_owner_and_always_loaded_boundary +test_concrete_required_defect_stays_autonomous +test_continuous_monitoring_expansion_escalates +test_repeated_same_theme_escalates_before_another_round +test_stronger_security_boundary_survives +test_explicit_complex_architecture_stays_in_scope +test_reviewer_labels_are_evidence_not_authority +test_captain_escalation_is_decision_ready +test_primary_and_secondmate_instruction_generation From 3325ea1bcaa812ed4786893d1dc2b1aadb7d44f1 Mon Sep 17 00:00:00 2001 From: kunchenguid Date: Thu, 23 Jul 2026 17:06:57 -0700 Subject: [PATCH 2/2] no-mistakes(document): Point project management to authority owner --- .agents/skills/project-management/SKILL.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.agents/skills/project-management/SKILL.md b/.agents/skills/project-management/SKILL.md index 54ab841ae92..af35d469ee2 100644 --- a/.agents/skills/project-management/SKILL.md +++ b/.agents/skills/project-management/SKILL.md @@ -36,7 +36,7 @@ Choose the delivery mode when adding or creating the project: The optional `+yolo` posture changes routine approval authority but does not change the delivery mode. Default it off, and enable it only on the captain's explicit instruction. -Destructive, irreversible, and security-sensitive decisions still require captain approval when it is on. +`AGENTS.md` section 7 owns the complete authority boundary and exceptions when it is on. ## Add or clone an existing project