From b6d8b5b802253efa4a51310de2900d830572e800 Mon Sep 17 00:00:00 2001 From: "Sahil (AI)" <266772320+sahilm-ai@users.noreply.github.com> Date: Tue, 26 May 2026 17:03:03 +0530 Subject: [PATCH] fix(skill): restore load-bearing negations in post-approve-merger SKILL.md MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit PR #23 had three negation-form directives rewritten as positive imperatives during the auto-reviewer pass, in a mistaken application of the BT-agent optimization-playbook S1 rule to a Hermes infrastructure skill. The S1/SD4 rules in sdlc-review have since been scoped BT-agent-only — but the rewrites in #23 landed before that scoping fix, so the load-bearing prohibitions are gone from the merged skill content. Restore them: 1. Auth: add explicit 'Never use sahilm-ti credentials' with the two concrete consequences (audit-trail misattribution + keychain prompt blocking the worker). The bare 'use sahilm-ai exclusively' positive form left the door open to drift, as evidenced by PR #23 itself — commit 7da3474181 in that PR was authored as sahilm-ti. 2. Terminator contract: add explicit 'Do NOT call kanban_review' — without this prohibition the worker could re-loop the card through the auto-reviewer after Sahil has already approved, defeating the one-approval-equals-merged contract that motivated #23 in the first place. 3. Stop clause: 'After the single terminal call, stop — do not attempt any further gh/git/kanban_* operations.' A second terminal call corrupts the event log; the positive-only 'stop' form is too ambiguous (stop what? stop thinking? the model may interpret it as stop typing but keep tool-calling). No code changes. No test changes. Skill-content-only fix. --- skills/devops/post-approve-merger/SKILL.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/skills/devops/post-approve-merger/SKILL.md b/skills/devops/post-approve-merger/SKILL.md index 65e0d97458afc..035c4f704ef4f 100644 --- a/skills/devops/post-approve-merger/SKILL.md +++ b/skills/devops/post-approve-merger/SKILL.md @@ -40,7 +40,7 @@ TOKEN_VAR="GH_TOKEN_SAHILM_AI" GH_TOKEN=$(printenv "$TOKEN_VAR") gh pr view "$PR_URL" --json state,... ``` -Use `sahilm-ai` credentials exclusively. Set `GH_TOKEN` from `GH_TOKEN_SAHILM_AI` before every `gh` invocation. +Use `sahilm-ai` credentials exclusively. Set `GH_TOKEN` from `GH_TOKEN_SAHILM_AI` before every `gh` invocation. Never use `sahilm-ti` credentials in this worker — that is Sahil's interactive identity and using it from an automated merger will (a) misattribute the merge to a human on the audit trail and (b) trigger keychain prompts on macOS that block the worker silently. --- @@ -138,9 +138,9 @@ kanban_block(reason="CI failing on PR — fix and re-approve. Failing chec ## kanban_complete / kanban_block contract -- The ONLY success terminator is `kanban_complete`. The ONLY failure terminator is `kanban_block`. +- The ONLY success terminator is `kanban_complete`. The ONLY failure terminator is `kanban_block`. Do NOT call `kanban_review` from this worker — the task was already reviewed and approved by Sahil; calling `kanban_review` here would re-loop the card through the auto-reviewer for no reason and confuse the human about whether their approval landed. - `kanban_block` always includes the PR URL and an actionable next step in the reason. -- One and only one terminal call per run. After the single terminal call, stop. +- One and only one terminal call per run. After the single terminal call, stop — do not attempt any further `gh`, `git`, or `kanban_*` operations. A second terminal call after `kanban_complete` / `kanban_block` corrupts the task event log and confuses downstream automation. ---