Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
213 commits
Select commit Hold shift + click to select a range
0866a77
fix(bin): safely unregister custom checks (#3369)
kunchenguid Aug 31, 2026
4ad8cba
refactor(quota): extract mid-task polling and candidate selection int…
0x7067 Aug 31, 2026
6c1d2db
fix: surface comments on Lavish annotations (#3371)
kunchenguid Aug 31, 2026
a5f3cbe
fix: support first public-followup registration on Bash 3.2 (#3420)
kunchenguid Sep 1, 2026
355f46f
fix(bin): isolate new Herdr server environments (#2792)
RooseveltAdvisors Sep 1, 2026
41d0ab3
fix: surface inbound Relay media to responding agents (#3442)
kunchenguid Sep 1, 2026
f2ee922
fix(bin): defer inactive reconciliation during startup (#3480)
kunchenguid Sep 2, 2026
f42a629
fix(bin): bound wake drain presentation lock waits (#3475)
kunchenguid Sep 2, 2026
ee58e39
fix(bin): retire public follow-ups in remote homes (#3479)
kunchenguid Sep 2, 2026
7d4b517
fix(bin): support process events under symlinked homes (#3484)
kunchenguid Sep 2, 2026
5466394
fix(pi): deliver captain outcomes as deterministic transcript entries…
FocalFactotum Sep 2, 2026
3b891c8
feat: add bounded concurrent Bearings ledger collection (#3481)
kunchenguid Sep 2, 2026
1459c4d
ci: rebalance portable serial test shards (#3489)
kunchenguid Sep 2, 2026
714da64
fix(pi): fall back on incomplete supervision branch prompts (#3491)
kunchenguid Sep 2, 2026
1c41029
fix(pi): re-probe supervision branch after cooldown (#3497)
kunchenguid Sep 2, 2026
521de54
fix(bin): remove legacy remote snapshot reads (#3501)
kunchenguid Sep 2, 2026
84c01b4
fix(pi): preserve watcher continuity across session replacement (#3498)
kunchenguid Sep 2, 2026
d977128
fix(bin): resurface task statuses missed by wake handling (#3495)
kunchenguid Sep 2, 2026
56b4c15
fix(bin): collect follow-up results from remote work homes (#3503)
kunchenguid Sep 2, 2026
763f597
fix(bin): exclude secondmates from home-summary validity (#3504)
kunchenguid Sep 2, 2026
88fb3c0
fix(bin): self-heal outcome indexes on first drain (#3509)
kunchenguid Sep 2, 2026
8988af2
fix(bearings): keep active children underway during captain holds (#3…
kunchenguid Sep 2, 2026
77ee3c8
fix(pi): settle watcher delivery on Pi accepting the follow-up (#3513)
kunchenguid Sep 2, 2026
d22318e
fix(bin): bound repeat stale wakes for parked workers (#3532)
mremond Sep 2, 2026
5fb0ce7
fix(bin): accept the away-mode daemon as the turn-end supervision own…
krakns Sep 2, 2026
353a8f0
fix(backlog): omit --file from row probes for non-markdown backends (…
RooseveltAdvisors Sep 3, 2026
1c00e86
fix(bin): classify progress updates on requested work as routine (#3589)
kunchenguid Sep 3, 2026
b2e3e9e
fix(bin): preserve captain calls during teardown (#3595)
kunchenguid Sep 3, 2026
d3fcdfa
fix(bin): deliver secondmate outcomes to the parent channel (#3592)
kunchenguid Sep 3, 2026
e1d1d69
fix(bin): sync remote second mates to primary commit (#3599)
kunchenguid Sep 3, 2026
28fb5ac
fix(bin): separate captain intent from firstmate specs (#3597)
kunchenguid Sep 3, 2026
3d2a08b
fix: start a fresh supervision branch for every main session (#3600)
kunchenguid Sep 3, 2026
1c5c9c1
feat: restart second mates after instruction updates (#3614)
kunchenguid Sep 3, 2026
7dcf072
perf: accelerate local validation with bounded concurrency (#3644)
kunchenguid Sep 3, 2026
75b2de2
fix: copy PR URLs from durable records (#3648)
kunchenguid Sep 3, 2026
3034912
fix(bin): disable Claude feedback drafts for fleet launches (#3661)
kunchenguid Sep 3, 2026
7adb358
feat(tests): run three more validation families concurrently (#3662)
kunchenguid Sep 3, 2026
ed44d15
feat: structure no-mistakes ask-user escalations (#3670)
kunchenguid Sep 3, 2026
3b82ebd
fix(bin): require self-sufficient no-mistakes intent (#3671)
kunchenguid Sep 3, 2026
5a7ba57
fix: accelerate local Bearings snapshot composition (#3499)
kunchenguid Sep 4, 2026
f4d7875
fix: prevent stale supervision wake loops (#3672)
kunchenguid Sep 4, 2026
31cba0d
fix(bin): avoid fleet snapshot argument limits (#3677)
haroarthur Sep 4, 2026
b82d09f
fix(bin): attribute active runs with unfetched pipeline heads (#3681)
npayette84 Sep 4, 2026
1b0fbb9
fix(bin): pre-register claude workspace trust at spawn time (#3663)
RooseveltAdvisors Sep 4, 2026
efbeb4f
fix: restart every live second mate after updates (#3690)
kunchenguid Sep 4, 2026
3c1e86d
fix(bin): close pending-reply decisions via resolve-key (#3696)
kunchenguid Sep 4, 2026
d43e610
fix(bin): prevent false missed-reply escalations (#3697)
kunchenguid Sep 4, 2026
a5c64a0
feat: add verified Gemini crewmate runtime (#3695)
att430 Sep 4, 2026
8f7b79c
fix(teardown): conclude parked runs advanced past task copy (#3704)
npayette84 Sep 4, 2026
86ff1bf
fix: classify captain holds from structured state (#3508)
kunchenguid Sep 5, 2026
f09de8a
fix(pi): keep supervision outcome delivery responsive (#3767)
kunchenguid Sep 5, 2026
1820316
fix: avoid duplicate AGENTS.md governance for marked projects (#3763)
tiago-peixoto Sep 5, 2026
64304b6
fix: protect primary checkout when spawning from linked homes (#3783)
tiago-peixoto Sep 5, 2026
e075c96
fix(bin): stop reading an unanswered backend probe as a dead endpoint…
RooseveltAdvisors Sep 5, 2026
8fd5575
fix(bin): preserve subshell lock ownership on Bash 3.2 (#3789)
tiago-peixoto Sep 5, 2026
af8c4b6
fix(bin): resolve captain holds and legacy teardowns on non-markdown …
RooseveltAdvisors Sep 5, 2026
a29cdce
fix: reduce local ShellCheck source-analysis cost (#3778)
kunchenguid Sep 5, 2026
d6660d7
fix(pi): route decision-owned wake batches to main (#3776)
kunchenguid Sep 5, 2026
f19efa6
feat(bin): add opt-in worker launch environment allowlist (#3802)
tiago-peixoto Sep 5, 2026
f9aca25
feat(bin): add rovo crewmate/scout adapter with home-path file access…
Puneet-Patwari Sep 5, 2026
12fc10e
fix(bin): prevent false pipeline blocks after drive timeouts (#3813)
kunchenguid Sep 6, 2026
702004e
fix(bin): scope the worker role contract for ship and scout launches …
tiago-peixoto Sep 6, 2026
c499f84
fix(bin): stop ringing steering doorbells into dead panes (#3823)
kunchenguid Sep 6, 2026
51d2e8c
fix(bin): wait out transient primary-checkout reads in the spawn work…
tiago-peixoto Sep 6, 2026
c562be1
fix: support stock macOS Bash 3.2 paths (#3732)
3264studios Sep 6, 2026
a913539
fix(bin): read orphaned green ci monitor and daemon-down failed recor…
RooseveltAdvisors Sep 6, 2026
85ad5e7
fix(spawn): verify preserved backlog state after interrupted spawn de…
RooseveltAdvisors Sep 6, 2026
f3b7e74
docs: correct runtime-backend maturity labels for Herdr (#3821)
kmorebetter Sep 6, 2026
f91a950
fix: restore intent-targeted no-mistakes validation (#3865)
kunchenguid Sep 6, 2026
b028e8b
fix: verify Treehouse slot ownership before teardown (#3837)
kunchenguid Sep 6, 2026
2e65d2e
feat(bin): add verified omp (Oh My Pi) harness adapter for crew, seco…
danielkuykendall23-boop Sep 6, 2026
d8e2bb3
fix(pi): invoke Bash helpers correctly on native Windows (#3843)
cr101 Sep 6, 2026
71ec401
test(bin): pin teardown outcomes for squash-merged rebased branches (…
MortenGad Sep 6, 2026
29015a2
fix(bin): keep supervision armed for registered custom checks (#3860)
gyute Sep 6, 2026
64d3905
fix(bin): resolve Treehouse locks for remote secondmate homes (#3883)
kunchenguid Sep 7, 2026
cf7e2fa
fix(bearings): repair board listening and decision reconciliation (#3…
kunchenguid Sep 7, 2026
1533f47
fix(bin): allow pooled spawns without a git origin (#3885)
kunchenguid Sep 7, 2026
5592cb6
feat(tests): run live harness guards by default when available (#3889)
kunchenguid Sep 7, 2026
6d396da
fix(bin): refuse test runs in the primary checkout when a task marker…
3264studios Sep 7, 2026
d4eb228
fix(bin): bound stale alarms for backlog captain holds (#3842)
mremond Sep 7, 2026
0b9f518
feat(pi): resolve extension-registered providers in the supervision b…
0x7067 Sep 7, 2026
ffd2c89
fix(bin): gate secondmate wake-loop stall alerts on real queue no-pro…
cisrd Sep 7, 2026
36fd955
test(calm): harden the export-DOM render step and record Pi 0.85.1 ev…
cisrd Sep 7, 2026
3af74fe
fix(bin): make every counted wake queue row presentable or retired (#…
cisrd Sep 7, 2026
98b37d4
fix(bin): use system stat for Darwin BSD formats (#3305)
0x7067 Sep 7, 2026
72bfdd0
fix(spawn): carry attribution-off policy in every claude launch (#3945)
NewAiCoder-bot Sep 7, 2026
891dc51
fix(bin): derive watcher beacon staleness grace from poll cadence (#3…
NewAiCoder-bot Sep 8, 2026
b84e0e3
fix(procevent): reap orphaned runners and prevent launch storms (#3904)
kunchenguid Sep 8, 2026
c034b26
test: make timestamp fixtures portable across macOS and Linux (#4037)
mremond Sep 9, 2026
746fc0a
feat(pi): accept native Codex ultra effort with progress-aware superv…
3264studios Sep 9, 2026
0fe226c
fix(herdr): bypass stale clients rejected by running servers (#4041)
kunchenguid Sep 9, 2026
40c50ea
feat: add durable AFK posture lifecycle (#4048)
kunchenguid Sep 9, 2026
9ba29db
feat(bin): add IMAP/SMTP mail plane with standing poll (#3765)
feilipu Sep 9, 2026
55d4069
fix: launch remote Herdr through the user login shell (#4061)
kunchenguid Sep 9, 2026
1c7a713
fix: distinguish landed deliveries from resolved captain calls (#3710)
mremond Sep 9, 2026
78318e2
fix(remote): keep fm-remote Herdr servers in the Aqua session (#4090)
kunchenguid Sep 9, 2026
28153d1
fix(bin): prefer a live no-mistakes run over a terminal one (#2881)
jayjongcheolpark Sep 9, 2026
00334ef
fix(bin): repair process-event shutdown and tighten guard timing (#4009)
mremond Sep 9, 2026
269f8fe
fix(backlog): route lifecycle transitions through configured adapters…
RooseveltAdvisors Sep 9, 2026
b6b51b9
fix(bin): suppress false Claude long-turn supervision alarms (#4119)
kunchenguid Sep 10, 2026
3e817d3
fix(herdr): recover gone and drifted worker endpoints (#4120)
kunchenguid Sep 10, 2026
b1ad702
fix(bin): prevent receiver wake failures from blocking remote handoff…
kunchenguid Sep 10, 2026
34bd418
fix: restrict captain address rule to user chat (#4075)
mremond Sep 10, 2026
527aa7c
fix(herdr): allow detached teardown of persisted-focused tabs (#4131)
kunchenguid Sep 10, 2026
5300a4f
fix(bin): escalate decision-owned wakes once as the decision (#4169)
tiago-peixoto Sep 10, 2026
4768e98
test(herdr): cover agent exit-to-shell liveness (#4172)
kunchenguid Sep 10, 2026
869ae90
fix(bin): rebalance portable parallel test lanes using CI timings (#4…
mremond Sep 11, 2026
0a4e4a2
fix(bin): stop claiming prose-mentioned PR URLs as a task's delivered…
karotkriss Sep 11, 2026
8a61b50
fix(procevent): confirm reconcile launches and reclaim provably dead …
christophmeise Sep 11, 2026
e0d269e
fix(herdr): verify agent liveness at process level before trusting re…
pablontiv Sep 11, 2026
31f062d
feat: add live-head merge gates and away task grants (#4199)
kunchenguid Sep 11, 2026
9074f9d
fix(bin): bound the Claude turn-end re-block against a frozen auto-ar…
christophmeise Sep 11, 2026
ff5c7af
feat(herdr): add guarded foreground viewer for live validation (#4242)
kunchenguid Sep 11, 2026
dee156f
fix(bin): let nonvisual work proceed when lavish-axi is unavailable (…
tiago-peixoto Sep 11, 2026
eb0ea3a
test: isolate fixture Git config from host global and system settings…
tiago-peixoto Sep 11, 2026
2c1017e
feat(bin): add config/claude-permission-mode to launch Claude workers…
sreekarans Sep 11, 2026
7d14fc1
fix(teardown): leave a Treehouse pool slot reassigned to another task…
christophmeise Sep 11, 2026
9e1e85e
docs(AGENTS): keep brief-fill from widening the captain's ask (#4247)
kunchenguid Sep 11, 2026
46ff99c
fix: identify underway tasks and sort charted work (#4245)
kunchenguid Sep 11, 2026
ad14a8d
fix(bearings): surface return catch-up without blocking snapshots (#4…
kunchenguid Sep 12, 2026
a27646c
fix(bin): address the home's backlog from any directory and detect a …
Shazellb Sep 12, 2026
92856fd
fix: pre-register Claude trust for secondmate homes (#4262)
kunchenguid Sep 12, 2026
c191eac
fix: ignore superseded failed GitHub check runs (#4258)
kunchenguid Sep 12, 2026
de00521
fix(bin): persist merge authority for poll-detected outcomes (#4266)
kunchenguid Sep 12, 2026
83c63cc
ci: supersede superseded PR CI and bound unbounded jobs (#4281)
kunchenguid Sep 12, 2026
fa65b5d
test(watch): gate backlog-hold away-record fixture on tasks-axi (#4288)
cipherholdingsllc Sep 12, 2026
fb19dd9
fix(backlog): bound per-item backlog row reads so a wedged backend ca…
RooseveltAdvisors Sep 12, 2026
76d4405
fix(merge): serialize away authority with synchronous merges (#4285)
kunchenguid Sep 12, 2026
3576148
feat(bin): add Antigravity CLI (agy) as third worker/scout adapter (#…
AnPod Sep 12, 2026
b518a25
feat(afk): add quiet supervision mode for a present captain (#4337)
NewAiCoder-bot Sep 13, 2026
0962d4a
fix(bin): let verified harness ancestry outrank retained markers (#3)…
NewAiCoder Sep 13, 2026
305dfff
fix(bin): pre-approve external CLAUDE.md import dialog for spawned wo…
NewAiCoder-bot Sep 13, 2026
ecfe071
fix(afk-return): treat an acked watcher-down marker as no gap (#4355)
NewAiCoder-bot Sep 13, 2026
b182d0f
fix(bin): rebind fm-procevent-when trust bindings after a self-update…
NewAiCoder-bot Sep 13, 2026
e3bd750
fix(pr-merge): treat plan-gated 403 on branch rules as no merge queue…
NewAiCoder Sep 14, 2026
036fec0
fix(bin): select suites that read a changed top-level test fixture (#…
tiago-peixoto Sep 14, 2026
267441d
fix(bin): treat Claude Code's default external-imports flags as never…
Rangezi Sep 14, 2026
287f41e
fix(bin): keep operator-address labels out of no-mistakes intent (#4445)
tiago-peixoto Sep 14, 2026
18fe6e9
fix: classify OpenCode ellipsis hint as idle (#4451)
pablontiv Sep 14, 2026
80556bc
fix(composer): recognize Grok 1.0.5's oversized titled bottom border …
pablontiv Sep 14, 2026
c1103a1
fix(bin): translate Stop hook timeout signals into durable auto-arm f…
pablontiv Sep 14, 2026
0b9de13
fix(spawn): establish Claude task channel authority (#4464)
pablontiv Sep 14, 2026
a6618dd
fix(bin): refuse fm-control.sh exit when the composer holds unproven …
pablontiv Sep 14, 2026
c806c6a
fix(spawn): establish crewmate identity first (#4481)
pablontiv Sep 15, 2026
d499323
fix(bin): reconcile redundant secondmate divergence during updates (#…
pablontiv Sep 15, 2026
da5e658
feat: enable gpt-5.6-luna max reasoning for crew dispatch (#4497)
umeranjum17 Sep 15, 2026
616049a
feat(calm): render smooth Unicode swell with asymmetric two-color sai…
yasuhito Sep 15, 2026
aa92177
fix(bin): supersede stale scout delivery text in brief.md on promotio…
pablontiv Sep 15, 2026
b85e28b
fix(bin): make captain holds work on hosts with an older JSON::PP, an…
Marsjohn-11 Sep 15, 2026
8b10b61
fix(bin): read codex 0.154's idle braille starfield rows as composer …
tbillings28 Sep 15, 2026
2da3c5e
fix(bin): refuse empty text steers in fm-send (#4259)
pablontiv Sep 15, 2026
0f242b9
fix(calm): paint the working ship one yellow over all-blue water (#4554)
kunchenguid Sep 15, 2026
a8dd08d
fix(bin): stop aging a second mate's active turn from its launch (#4270)
tiago-peixoto Sep 15, 2026
8b944a1
feat(bin): add read-only PR blocker and reviewer discovery commands (…
tiago-peixoto Sep 15, 2026
db645b8
fix(bin): teach validation-round pauses in generated briefs (#2752)
tiago-peixoto Sep 15, 2026
9ad5fc4
docs(readme): add star history chart (#4558)
kunchenguid Sep 15, 2026
1bdfd8c
fix(bin): refuse teardown when a task's endpoint close fails (#4510)
aminry Sep 15, 2026
bdcacb9
feat(calm): add flag-gated Claude Code Calm mode (#4565)
kunchenguid Sep 15, 2026
b430bf5
fix(bin): honour a declared wait before wedge-escalating a quiet pane…
aminry Sep 16, 2026
7111081
fix(bin): report verified PR state for passed runs (#4624)
jokim1 Sep 16, 2026
af1f2ea
fix: restore published contribution follow-up (Fixes #4469) (#4627)
mremond Sep 16, 2026
36c9814
fix(bin): make remote report transfers explicit and fail-open (#4658)
kunchenguid Sep 16, 2026
6483df6
fix(calm): preserve substantive mid-turn responses (#4655)
kunchenguid Sep 16, 2026
baede47
fix(bin): preserve PR merge polls across volume remounts (#4656)
mremond Sep 16, 2026
9f8ad95
fix(bin): keep contribution records when the poll budget runs out (fo…
mremond Sep 16, 2026
b0877b4
fix(bin): clear parent pending-replies on local secondmate retirement…
thelad-dev Sep 16, 2026
795e5e4
fix(bin): accept Orca's composite worktree id when tearing down a tas…
JuanJoseGonGi Sep 16, 2026
69d660a
feat(bin): add opt-in typed dispatch resolution (#4692)
kunchenguid Sep 17, 2026
334fa12
fix(bin): read the latest status event so buried declarations and ope…
tiago-peixoto Sep 17, 2026
fa93097
fix(bin): launch codex crewmates with codex's hook layer disabled (#4…
codyjohnsontx Sep 17, 2026
3eb5b63
fix(bin): settle terminal contribution observations (Fixes #4669, Fix…
mremond Sep 17, 2026
f5d7f5f
fix: select authoritative no-mistakes runs (#4476)
mremond Sep 17, 2026
a221640
fix: distinguish captain outcomes from no-op updates (#4738)
kunchenguid Sep 17, 2026
5e879ba
fix(bin): let non-owner Claude Stops exit safely (#4777)
kunchenguid Sep 17, 2026
e213343
fix(bin): survive bash 3.2 empty-array expansion in watcher churn abs…
0x7067 Sep 17, 2026
b752ced
Make the foreign-owner turn-end repro create a Linux-readable session…
kunchenguid Sep 17, 2026
8d9d5da
fix: require complete captain-facing final responses (#4779)
kunchenguid Sep 17, 2026
888871d
fix: preserve substantive mid-turn text in Pi Calm (#4788)
kunchenguid Sep 17, 2026
4055cbd
fix: harden mail checks and rebalance full-coverage CI (#4800)
kunchenguid Sep 18, 2026
5d3acc8
fix(bin): answer Kimi 2.0.0 folder-trust dialog during spawn (#4799)
Shazellb Sep 18, 2026
9bc051f
fix(bin): report a dead-agent record once instead of escalating forev…
umeranjum17 Sep 18, 2026
daaffdb
fix(bin): create captain-hold rows when Beads requires due (#4854)
RooseveltAdvisors Sep 18, 2026
1bb72cc
fix: disable compact adviser for spawned agents (#4877)
kunchenguid Sep 18, 2026
4812db8
fix(bin): preserve Claude lock ownership after helper recycling (#4894)
kunchenguid Sep 19, 2026
65a3bac
feat: park main under the away posture on Pi (#4889)
kunchenguid Sep 19, 2026
2bcb88c
ci: standardize workflow timeouts into three tiers (#4910)
kunchenguid Sep 19, 2026
b6930db
fix(bin): keep supervisor status closes from waking the same home (#4…
tiago-peixoto Sep 19, 2026
1b1b6e0
fix(bin): stop labeling Herdr as experimental (#4972)
kunchenguid Sep 19, 2026
dd9b2ef
fix(bin): treat a live no-mistakes run as current after rebase (#4973)
rovermike Sep 20, 2026
a452a79
fix(bin): prevent long worker launch command truncation (#4994)
kunchenguid Sep 20, 2026
a0b2f34
test: authorize isolated Herdr lab validation (#4998)
kunchenguid Sep 20, 2026
90cd351
docs(vision): accept vendor-semantics and 9k AGENTS ceiling (#4873) (…
kunchenguid Sep 20, 2026
9aabe3b
feat(bin): defer the wedge escalation for a lane parked at a supervis…
aminry Sep 20, 2026
1b1b3cd
fix(bin): reclaim a task whose herdr endpoint was destroyed (#5007)
RooseveltAdvisors Sep 20, 2026
a09090d
feat(bin): stamp status events with their emission time (#3764)
tiago-peixoto Sep 20, 2026
0ac1f60
feat(bin): add opt-in intake classifier
sctru Sep 20, 2026
375410f
fix(test): remove duplicate test family cases
sctru Sep 20, 2026
c443d8c
fix(bin): unify Lavish host and disconnect handling (#5060)
kunchenguid Sep 20, 2026
dee119b
feat: act on captain's away words during AFK supervision (#5076)
kunchenguid Sep 20, 2026
63e8d46
feat(bin): add opt-in intake classifier
sctru Sep 20, 2026
ecb95b7
fix(test): remove duplicate test family cases
sctru Sep 20, 2026
2b75415
no-mistakes(review): Harden classifier curl and Score parsing
sctru Sep 20, 2026
3ba3f6f
no-mistakes(review): Gate implementation authorization only for ship
sctru Sep 20, 2026
1154fea
no-mistakes(review): Protect traced keys and unblock temporary failures
sctru Sep 20, 2026
030c39c
no-mistakes(review): Keep request I/O failures nonblocking
sctru Sep 20, 2026
724ebf9
no-mistakes(document): Document nonblocking classifier runtime failures
sctru Sep 20, 2026
5eefbbb
no-mistakes(document): Document shared typed-classifier key ownership
sctru Sep 20, 2026
25e633c
merge: preserve intake classifier pipeline fixes
sctru Sep 20, 2026
5877b71
fix: reconcile intake classifier pipeline fixes
sctru Sep 20, 2026
00eba29
no-mistakes(lint): Remove duplicate dispatch-resolve family pattern, …
sctru Sep 21, 2026
0f26f20
Fix CI regressions in intake classifier branch
sctru Sep 21, 2026
845ef47
Fix turnend guard lint fixture
sctru Sep 21, 2026
7352075
Harden foreign owner guard fixture
sctru Sep 21, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions .agents/skills/backlog-operations/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
---
name: backlog-operations
description: >-
Agent-only intake reference for deciding what to do with a captain request.
Load before using the opt-in System One intake classifier.
user-invocable: false
metadata:
internal: true
---

# backlog-operations

Before classifying a captain request, run the opt-in `bin/fm-intake-classify.sh` directly on the request file in the same turn.
Its result recommends only `ship`, `scout`, or `answer_now` with urgency and never authorizes a spawn or replaces your intake judgment.
`docs/configuration.md` "Typed intake classification" owns the complete contract and every status meaning.
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ Use the router's detection and safety sections for static crew and secondmate ha
`config/crew-dispatch.json` can override that static default for one crewmate or scout with concrete harness, model, and effort axes.
For a profile array, load `quota-array-dispatch` after establishing harness and provider facts here.
When the opt-in `bin/fm-dispatch-resolve.sh` is on, its `clear` answer already names the concrete axes; `docs/configuration.md` "Typed dispatch resolution" owns that contract.
At request intake, `bin/fm-intake-classify.sh` is an advisory disposition recommendation only; `docs/configuration.md` "Typed intake classification" owns its contract.

`../secondmate-provisioning/SKILL.md` owns inherited local material.
Its harness consequence is that a secondmate's workers receive literal `config/crew-harness` and `config/crew-dispatch.json`, while the primary-only `config/secondmate-harness` is never inherited because secondmates do not spawn secondmates.
Expand Down
4 changes: 3 additions & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,7 @@ README.md public overview and development notes
.claude/mods/ Claude Code mods (function-hooks plugins), committed; Calm's module may load through CLAUDE_CODE_ENABLE_FUNCTION_HOOKS or tengu_plugin_hooks_modules, but activates only when CLAUDE_CODE_ENABLE_FUNCTION_HOOKS is exactly "1" and is otherwise a complete no-op (docs/calm.md)
skills/ standalone public installer-facing skills, committed; not loaded by firstmate
bin/ helper scripts, committed; read each script's header before first use
.env optional Relay pairing token (presence-gates section 14), mail-plane credentials (schema: docs/configuration.md "Mail plane"), and typed dispatch resolution key TYPESAFE_API_KEY (presence-gates bin/fm-dispatch-resolve.sh; docs/configuration.md "Typed dispatch resolution"); LOCAL, gitignored
.env optional Relay pairing token (presence-gates section 14), mail-plane credentials (schema: docs/configuration.md "Mail plane"), and typed-classifier key TYPESAFE_API_KEY (presence-gates bin/fm-dispatch-resolve.sh and bin/fm-intake-classify.sh; docs/configuration.md owns both typed classifier contracts); LOCAL, gitignored
config/crew-harness crewmate harness override; LOCAL, gitignored; absent or "default" = same as firstmate. Inherited as the literal file: a concrete primary adapter value also controls a secondmate home's own crewmates (section 4)
config/claude-permission-mode optional one-token permission posture for every Claude worker launch: absent or "bypass" keeps --dangerously-skip-permissions, "auto" launches with --permission-mode auto; LOCAL, gitignored; inherited by secondmate homes; see docs/configuration.md "Claude permission mode"
config/crew-dispatch.json optional crewmate dispatch profiles; LOCAL, gitignored; firstmate-maintained but human-editable natural-language rules that choose a per-task harness/model/effort profile (section 4). Inherited by secondmate homes
Expand Down Expand Up @@ -232,6 +232,7 @@ Break genuine evidence ties without array-order or harness bias.
`quota-axi` owns how model or product windows relate to bounding account windows and remains data-only.
Load `quota-array-dispatch` before choosing among a matched profile array; that skill is the single owner of the TOON-first spendPriority selection procedure.
Run `bin/fm-dispatch-resolve.sh` directly on the written brief in the same turn, with no preflight, and on `clear` pass its `profile:` line to `fm-spawn` unless you state a reason to override; `ambiguous`, `escalate`, `error`, and off all mean the intake above, unchanged (contract: `docs/configuration.md` "Typed dispatch resolution").
Load `backlog-operations` before using the opt-in request-intake classifier; its disposition remains advisory until firstmate decides the next action.
The generic effort fallback and its precedence are owned by `harness-adapters`: explicit captain and standing configured effort win; otherwise use low for well-understood explicit work, xhigh for ambiguous investigation or design, intermediate levels proportionally, and never max without explicit captain preference.
Do not add model-specific versions of that policy.
For a crewmate's native child delegation, [`docs/configuration.md`](docs/configuration.md) "Nested delegation" owns the same-profile requirement, legacy-tier retirement, and the boundary of Firstmate's runtime enforcement; generated ship and scout briefs carry its operational reinforcement.
Expand Down Expand Up @@ -579,6 +580,7 @@ These skills are not captain-invocable; load them only at their precise triggers
- `bootstrap-diagnostics` - load whenever the session-start digest's bootstrap or network-checks section prints an actionable diagnostic line (`MISSING:`, `MISSING_MANUAL:`, `PRESENTATION_UNAVAILABLE:`, `BACKEND_INVALID:`, `NEEDS_GH_AUTH`, `TANGLE:`, `STARTUP_MEMORY_BUDGET:`, `CREW_DISPATCH: invalid`, `FLEET_SYNC:`, `NETWORK_CHECKS:`, `HOME_SUMMARY:`, `BACKLOG_RECONCILE:`, `SECONDMATE_SYNC:`, `SECONDMATE_LIVENESS:`, `SECONDMATE_HANDOFF:`, `NUDGE_SECONDMATES:`, or `FMX:`), or when `BOOTSTRAP_INFO:` says an interrupted backlog cleanup may have left an endpoint or local copy; silence and other `BOOTSTRAP_INFO:` facts need no load.
- `diagnostic-reasoning` - load before scoping a reported bug and before acting on a diagnostic report.
- `ask-user-authority` - load before deciding any ask-user finding.
- `backlog-operations` - load before classifying a captain request with the opt-in intake classifier.
- `quota-array-dispatch` - load before choosing among a matched crew-dispatch profile array from current quota-axi default TOON.
- `harness-adapters` - load before spawning or recovering a crewmate or secondmate, handling a trust dialog, sending a harness-specific skill invocation, interrupting or exiting an agent, resuming an exited agent, or verifying a new harness adapter.
- `firstmate-orca` - load before switching to Orca, spawning or supervising Orca-backed work, smoke-testing Orca backend behavior, debugging Orca task state, or reconciling Orca-backed task metadata.
Expand Down
5 changes: 5 additions & 0 deletions bin/fm-bootstrap.sh
Original file line number Diff line number Diff line change
Expand Up @@ -156,6 +156,11 @@
# nothing; bin/fm-brief.sh uses it to gate scout Lavish hosting.
set -u

# A caller may invoke bootstrap under `bash -x` while testing the opt-in typed
# dispatch gate.
# Disable tracing before copying its key so neither the environment value nor
# the private handoff variable reaches the shell trace.
set +x
TYPESAFE_API_KEY_PRIVATE=${TYPESAFE_API_KEY:-}
export -n TYPESAFE_API_KEY_PRIVATE 2>/dev/null || true
unset TYPESAFE_API_KEY
Expand Down
7 changes: 5 additions & 2 deletions bin/fm-classify-lib.sh
Original file line number Diff line number Diff line change
Expand Up @@ -1775,9 +1775,12 @@ _fm_status_open_decision_origins() { # <status-file> [<kind>]
while IFS= read -r line || [ -n "$line" ]; do
number=$((number + 1))
after=$(_fm_decision_fold_line "$open" "$line" "$resolve" "$held" "$kind")
[ -n "$after" ] || origins=''
key=$(_fm_decision_key "$line") || { open=$after; continue; }
verb=$(status_line_verb "$line")
# A failure clears the current open-decision set but still needs its unseen decision origin in the same escalation span.
# A completed task drops the historical origin from this escalation-specific view.
# An explicit resolution or verified captain-held transfer drops its own origin below.
[ -n "$after" ] || [ "$verb" != "done" ] || origins=''
key=$(_fm_decision_key "$line") || { open=$after; continue; }
note=$(status_line_note "$line")
case "$verb" in
needs-decision|blocked)
Expand Down
233 changes: 233 additions & 0 deletions bin/fm-intake-classify.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,233 @@
#!/usr/bin/env bash
# fm-intake-classify.sh - recommend a firstmate intake disposition with
# typesafe.ai's System One model (Jev), opt-in.
#
# Usage:
# fm-intake-classify.sh <request-file> [--project <name>]
#
# Opt-in gate: TYPESAFE_API_KEY non-empty in this process environment, else a
# TYPESAFE_API_KEY= line in $FM_HOME/.env read with fmx_env_get. The
# environment wins. Absent in both: one "intake-classify: off" line on
# stderr, nothing on stdout, exit 0, and no network call.
#
# What it does when on: one POST to https://api.typesafe.ai/v1/systemone with
# the project name and a bounded request-text snapshot as state. It asks three
# parallel questions: a Choice recommendation of ship, scout, answer_now, or
# unclear; a NOUL answer about implementation authorization; and a three-level
# urgency Score. Jq composes clear, ambiguous, escalate, or error afterwards.
# The result is recommendation-only: it never spawns a worker, chooses a
# harness or model, or changes firstmate's intake judgment.
#
# Output (stdout, TOON-style block):
# intake-classify:
# status: clear | ambiguous | escalate | error
# model/latency_ms/tokens, deliverable and confidence, intent_clear and
# NOUL score, urgency and score, request truncation, and any reason
# clear -> a high-confidence recommendation; ship is also authorized
# ambiguous -> a low-confidence or unclear recommendation
# escalate -> a ship recommendation without implementation authorization
# error -> local runtime, API, network, response, or rendering failure
# Every runtime outcome exits 0 so intake is never blocked by this tool.
# Exit 2 only for invalid argv, an initially unreadable request, or missing
# jq, which are actionable usage or configuration errors.
#
# Environment:
# TYPESAFE_API_KEY is the only classifier-specific environment setting.
#
# Authority: docs/configuration.md "Typed intake classification" owns the
# operator contract. This script owns flags and exact output. The classifier
# never replaces firstmate judgment or auto-spawns work.
set +x
set -u

TYPESAFE_API_KEY_PRIVATE=${TYPESAFE_API_KEY:-}
export -n TYPESAFE_API_KEY_PRIVATE 2>/dev/null || true
unset TYPESAFE_API_KEY

SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
FM_ROOT="${FM_ROOT_OVERRIDE:-$(cd "$SCRIPT_DIR/.." && pwd)}"
FM_HOME="${FM_HOME:-$FM_ROOT}"

# shellcheck source=bin/fm-env-lib.sh
. "$SCRIPT_DIR/fm-env-lib.sh"
# shellcheck source=bin/fm-timing-lib.sh
. "$SCRIPT_DIR/fm-timing-lib.sh"

CONFIDENCE_FLOOR=0.6
TS_MODEL=jev-latest
TS_BASE=https://api.typesafe.ai
TS_TIMEOUT=5
REQUEST_MAX_BYTES=32768

die() { printf 'error: %s\n' "$1" >&2; exit 2; }
usage() {
awk '
NR == 1 { next }
/^#/ { sub(/^# ?/, ""); print; next }
{ exit }
' "$0"
}
emit_error() {
local reason=$1
printf 'intake-classify: error (%s)\n' "$reason" >&2
printf 'intake-classify:\n status: error\n reason: %s\n' "$reason"
exit 0
}

REQUEST_FILE='' PROJECT=''
while [ $# -gt 0 ]; do
case "$1" in
--project) [ $# -ge 2 ] || die "--project needs a value"; PROJECT=$2; shift 2 ;;
-h|--help) usage; exit 0 ;;
-*) die "unknown flag $1" ;;
*) [ -z "$REQUEST_FILE" ] || die "one request file only"; REQUEST_FILE=$1; shift ;;
esac
done

# ---- opt-in gate ---------------------------------------------------------------
if [ -z "$TYPESAFE_API_KEY_PRIVATE" ]; then
TYPESAFE_API_KEY_PRIVATE=$(fmx_env_get TYPESAFE_API_KEY "$FM_HOME/.env")
fi
if [ -z "$TYPESAFE_API_KEY_PRIVATE" ]; then
printf '%s\n' 'intake-classify: off' >&2
exit 0
fi

# ---- inputs --------------------------------------------------------------------
[ -n "$REQUEST_FILE" ] || die "request file required (see --help)"
[ -r "$REQUEST_FILE" ] || die "request file not readable: $REQUEST_FILE"
command -v jq >/dev/null 2>&1 || die "jq required"

REQUEST_SNAPSHOT=$(mktemp 2>/dev/null) || emit_error "temporary file setup failed"
RESP_FILE=$(mktemp 2>/dev/null) || { rm -f "$REQUEST_SNAPSHOT"; emit_error "temporary file setup failed"; }
trap 'rm -f "$REQUEST_SNAPSHOT" "$RESP_FILE"' EXIT
head -c "$REQUEST_MAX_BYTES" "$REQUEST_FILE" > "$REQUEST_SNAPSHOT" || emit_error "request read failed"
REQUEST_BYTES=$(wc -c < "$REQUEST_FILE") || emit_error "request measurement failed"
REQUEST_BYTES=${REQUEST_BYTES//[[:space:]]/}
case "$REQUEST_BYTES" in ''|*[!0-9]*) emit_error "request measurement failed" ;; esac
if [ "$REQUEST_BYTES" -gt "$REQUEST_MAX_BYTES" ]; then REQUEST_TRUNCATED=true; else REQUEST_TRUNCATED=false; fi

# ---- one System One request ----------------------------------------------------
command -v curl >/dev/null 2>&1 || emit_error "curl not installed"
REQUEST=$(jq -n --rawfile request "$REQUEST_SNAPSHOT" --arg project "$PROJECT" --arg model "$TS_MODEL" '
{
model: $model,
state: {intake: {project: $project, request: $request}},
questions: {
deliverable: {
type: "choice",
instructions: "Which disposition should firstmate consider for this request? This is advice only and must not create, dispatch, or select any worker.",
criteria: {
ship: "A concrete, authorized implementation change should be handled as a ship task.",
scout: "The request needs bounded investigation, reproduction, audit, or planning before an implementation decision.",
answer_now: "The request can be answered directly now without creating a worker task.",
unclear: "The request is too incomplete or conflicting to recommend a disposition."
}
},
intent_clear: {
type: "noul",
instructions: "Is the captain already authorizing a concrete implementation change in this request? Answer true only when the requested change and scope are sufficiently concrete."
},
urgency: {
type: "score",
instructions: "Score urgency on this ordered scale: 0 routine means ordinary work with no material time pressure; 1 soon means a stated near-term deadline or materially useful prompt follow-up; 2 blocking means current work, a release, safety, or a stated deadline is blocked until this is addressed.",
criteria: [
"0 routine: ordinary work with no material time pressure.",
"1 soon: a stated near-term deadline or materially useful prompt follow-up.",
"2 blocking: current work, a release, safety, or a stated deadline is blocked until this is addressed."
]
}
}
}') || emit_error "request rendering failed"

T0=$(fm_timing_now_ms)
HTTP=$(printf '%s' "$REQUEST" | curl -q -sS --max-time "$TS_TIMEOUT" -o "$RESP_FILE" -w '%{http_code}' \
-X POST "$TS_BASE/v1/systemone" -H 'Content-Type: application/json' \
-H @/dev/fd/3 3< <(printf 'Authorization: Bearer %s\n' "$TYPESAFE_API_KEY_PRIVATE") \
--data-binary @- 2>/dev/null) || HTTP=000
T1=$(fm_timing_now_ms)
LAT_MS=$(( T1 - T0 ))
[ "$HTTP" = 200 ] || emit_error "http $HTTP after ${LAT_MS} ms: $(head -c 200 "$RESP_FILE" 2>/dev/null | tr '\n' ' ')"

# ---- response validation and status composition --------------------------------
jq -e '
def confidence($a): $a.confidence;
def intent_noul($a): $a.noul;
def urgency_score($a): $a.score;
def confidence_ok($a): (confidence($a) | type) == "number" and confidence($a) >= 0 and confidence($a) <= 1;
(.answers | type) == "object" and
(.answers.deliverable | type) == "object" and
(.answers.deliverable.choice | type) == "string" and
(.answers.deliverable.choice as $choice | ["ship", "scout", "answer_now", "unclear"] | index($choice)) != null and
confidence_ok(.answers.deliverable) and
(.answers.deliverable.probabilities | type) == "object" and
((.answers.deliverable.probabilities | keys | sort) == ["answer_now", "scout", "ship", "unclear"]) and
all(.answers.deliverable.probabilities[]; type == "number" and . >= 0 and . <= 1) and
((.answers.deliverable.probabilities | [.[]] | add) as $total | $total >= 0.99 and $total <= 1.01) and
(.answers.intent_clear | type) == "object" and
(intent_noul(.answers.intent_clear) | type) == "number" and
intent_noul(.answers.intent_clear) >= 0 and intent_noul(.answers.intent_clear) <= 1 and
(.answers.urgency | type) == "object" and
(urgency_score(.answers.urgency) | type) == "number" and
urgency_score(.answers.urgency) >= 0 and urgency_score(.answers.urgency) <= 2 and
confidence_ok(.answers.urgency) and
((has("usage") | not) or
((.usage | type) == "object" and
(.usage.input_tokens | type) == "number" and
(.usage.output_tokens | type) == "number"))
' "$RESP_FILE" >/dev/null 2>&1 || emit_error "response is not a typed intake answer"

RESULT=$(jq -n --argjson floor "$CONFIDENCE_FLOOR" --argjson latency "$LAT_MS" --argjson truncated "$REQUEST_TRUNCATED" --slurpfile response "$RESP_FILE" '
($response[0]) as $r |
($r.answers.deliverable) as $deliverable |
($r.answers.intent_clear) as $intent |
($r.answers.urgency) as $urgency |
def intent_noul: .noul;
def urgency_score: .score;
def urgency_level($score):
if $score < 0.5 then "routine"
elif $score < 1.5 then "soon"
else "blocking"
end;
($deliverable.confidence) as $deliverable_confidence |
($intent | intent_noul) as $intent_noul |
($urgency.confidence) as $urgency_confidence |
([ $deliverable_confidence, $urgency_confidence ] | min) as $confidence |
{
model: $r.model,
latency_ms: $latency,
tokens: ($r.usage // null),
deliverable: $deliverable.choice,
deliverable_confidence: $deliverable_confidence,
deliverable_probabilities: $deliverable.probabilities,
intent_clear: ($intent_noul >= $floor),
intent_clear_noul: $intent_noul,
urgency: urgency_level($urgency | urgency_score),
urgency_score: ($urgency | urgency_score),
urgency_confidence: $urgency_confidence,
confidence: $confidence,
request_truncated: $truncated
} |
if $confidence < $floor then
. + {status: "ambiguous", reason: "lowest answer confidence \($confidence) below floor \($floor)"}
elif .deliverable == "ship" and .intent_clear != true then
. + {status: "escalate", reason: "concrete implementation authorization is not clear"}
elif .deliverable == "unclear" then
. + {status: "ambiguous", reason: "deliverable recommendation is unclear"}
else . + {status: "clear"}
end') || emit_error "status composition failed"

TEXT=$(jq -r '
def flat: tostring | gsub("[\t\r\n]"; " ");
def show($value): ($value // "-") | flat;
"intake-classify:",
" status: \(.status | flat)",
" model: \(show(.model)) latency_ms: \(show(.latency_ms)) tokens: \(show(.tokens.input_tokens))/\(show(.tokens.output_tokens))",
" deliverable: \(.deliverable | flat) confidence: \(.deliverable_confidence | flat)",
" probabilities: \([.deliverable_probabilities | to_entries[] | "\(.key | flat)=\(.value | flat)"] | join(" "))",
" intent_clear: \(.intent_clear | flat) noul: \(.intent_clear_noul | flat)",
" urgency: \(.urgency | flat) score: \(.urgency_score | flat) confidence: \(.urgency_confidence | flat)",
" request_truncated: \(.request_truncated | flat)",
(if .reason then " reason: \(.reason | flat)" else empty end)' <<<"$RESULT") || emit_error "output rendering failed"
printf '%s\n' "$TEXT"
exit 0
Loading
Loading