Repository navigation
Separate native foundation and trading catalogs with upstream acceptance - #20
Merged
seathatflowsinourveins merged 15 commits intoSep 20, 2026
Merged
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
seathatflowsinourveins
deleted the
codex/foundation-catalogs-20260920
branch
September 25, 2026 18:47
4 tasks done
seathatflowsinourveins
added a commit
that referenced
this pull request
Sep 28, 2026
…e automation; stale-upstream flags; sandbox-profile open gate (#448) * Skills trial: pin cloudflare/security-audit-skill name-only for LLM-native automation, flag stale upstreams, open the sandbox-profile gate - adoption/skills/manifest.json: trial row security-audit at cloudflare/security-audit-skill@c1c8a8c (tree ccbc33e, SKILL.md sha256 5e3e96a1, 359-character description), claude_listing name-only, codex_enabled false, added 2026-09-27; checked_at 2026-09-27. The settings template mirrors it in skillOverrides. - docs/decisions/2026-09-25-skills-trial-and-usage.md: 2026-09-27 addendum (audits re-observed, MIT, the 2026-09-23 not_adopted refutation with the gap restated from the commands reference, issue #20 as weak third-party evidence, LLM-native wiring, M5b gate, M5c bake-off queued behind Gates A and B, trial exit and overturn; openai/skills and noseyparker flags). - catalogs/foundation/manifest.json: open gate claude-code-sandbox-profile (owner foundation coordinator, re-check 2026-10-11) on a new open top gap in the priority-2 slot of worker-cancellation-crash-resume, whose scope the decision native-child-interruption-recovery carries verbatim. - evidence/artifacts/cloudflare-audit-skill-trial-20260927/: receipt at catalog_revision ba1700a; manifests/evidence.json re-registered. Nothing was installed. The coordinator applies the settings template, the Codex disable table and install_skills.py --only security-audit, in that order. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Skills trial repair: credentials and strictAllowlist arms in the sandbox gate, adoption next_action_refs, recorded skill quotes - catalogs/foundation/manifest.json: gate claude-code-sandbox-profile's next_action adds the deferral's credentials.files deny for the store (a sandbox.credentials.files entry with mode deny), a credentials arm (a sandboxed read of a store file fails through ~/ and through its absolute path, filesystem isolation on) and a separate sandbox.network.strictAllowlist arm; source_paths add docs/secret-storage.md and docs/harness-rules-convergence-20260922.md (PS-1). - adoption/manifest.json: continuation.next_action_refs lists claude-code-sandbox-profile, as d17b3cf and 49c094d kept the foundation open gates and this list together. - docs/decisions/2026-09-25-skills-trial-and-usage.md: the completeness sentence names what delta.json records; M5c adds the native claude plugin eval with-without candidate (non-Haiku --judge-model, resolved model from --json, the baseline arm must be shown to run); new M6 paragraph. - evidence/artifacts/cloudflare-audit-skill-trial-20260927/: delta.json gains quoted_passages (SKILL.md L12, L21, L24, L40, L60, L82, L172, L175; report-schema.json verdict consts; repository quotes), the settings reference and sandboxing lines for sandbox.credentials and strictAllowlist, the plugin eval help lines, the fuller sandbox_gate measurements and checks.repair_round; README turns the install-order sentence into a conditional and records the repair-round checks. - manifests/evidence.json: the five changed files re-registered. Nothing was installed and no host setting changed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Skills trial repair 2: name-only reduces visibility, it does not enforce stage-only invocation Cross-family GPT-6 review of PR #448 (P2, changes-needed): the security-audit addendum said the name-only skill cannot fire on an ordinary security question and gets no user trigger, and the manifest gap said never by user invocation. Reproduced: jq '.native_docs.skills.L811' on the receipt prints the name-only row with Yes in the "In / menu" column, and the in-memory skills_status.check_claude_listing probe returns state ok for name-only. Corrected the claims, not the listing (name-only stays the user's choice): - docs/decisions/2026-09-25-skills-trial-and-usage.md: the decision, the W011 sentence and the name-only item now say name-only removes only the description from Claude's listing; Claude can still invoke the skill by name and a user can still type /security-audit, so stage-only use is a usage policy. New enforcement-residual item and overturn condition; name-only invocation reach joins the live-run-pending row. - adoption/skills/manifest.json and the receipt's manifest_row: gap text to match. - evidence/artifacts/cloudflare-audit-skill-trial-20260927/: the docs lines cited, checks.repair_round_2, the README round and reproduce lines. - manifests/evidence.json: hash re-registration of the four files only. Sources: - https://code.claude.com/docs/en/skills.md fetched 2026-09-28T07:07:11Z, sha256 86137b6232cd54722549525729d1888717d5ee0eed6312a9a089097b2cadc181 (same bytes as the first read): "Override skill visibility from settings" table L808-L813 and L817; "Control who invokes a skill" table L523/L527; frontmatter reference L360; "Restrict Claude's skill access" L766, L768. - https://code.claude.com/docs/en/settings-reference.md, same fetch, sha256 19fc12a219077c947744ba81977f1d3559d8b2ab36ac975de754aaef49e00117: skillOverrides L4163 and L4167-L4170. - tools/adoption/install_skills.py classify_skill and process_skill (pinned SKILL.md sha256 check and rollback) for the residual: the frontmatter field user-invocable: false would need a new upstream pin and a native probe. Checks: scripts/validate.py exit 1 before registration (SHA-256 and byte mismatches on exactly the four files), exit 0 after; validate_foundation exit 0; nine test modules OK, test_install_claude_profile 58/58 with the cached PyYAML; component_matrix and new_host_grand_list --write changed no tracked file. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Security-audit trial: limit the invocation residual to the user trigger The round-2 verifier found a new claim of the same kind: that the frontmatter field user-invocable: false plus a probe would enforce stage-only use. The Claude Code skills docs say otherwise (https://code.claude.com/docs/en/skills.md, sha256 86137b62..., fetched 2026-09-28): L799 "With `user-invocable: false`, you can't invoke the skill, but Claude still can", and L796 disable-model-invocation: true "removes the skill from Claude's context entirely", which would also stop the session that drives the stages. So the residual now covers only the user trigger, and stage-only use stays a usage policy with or without either field. Changed: the decision addendum's Enforcement residual item and its overturn condition, the README residual lines, the manifest gap (mirrored in delta.json manifest_row.gap) and checks.repair_round_2.residual. Added: docs lines L796 and L799 in native_docs.skills, and checks.repair_round_2_verification. Re-registered the four files in manifests/evidence.json. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Scout <scout@local> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
General native-harness adoption was mixed with trading-specific continuation. This change adds a separate 16-layer Foundation catalog, capability-specific acceptance and lifecycle limits, and a distinct NautilusTrader 2.0.0rc5 / IBKR / Alpaca target. Both catalogs have searchable HTML views and portable setup references. Short native-harness instructions are persisted for both Codex homes and Claude, with a quiet daily maintenance task.
Upstream Tavily installation, Search/Extract and skill discovery are recorded with their failure and activation boundaries. The pinned Nautilus example has two isolated native replay receipts; the new GitHub workflow verifies downloaded artifacts and repeats the upstream example offline on a clean runner. Native child interruption/recovery evidence preserves the original failed recorder and process-containment limits.
Validation includes 602 Python tests (40 dependency-scoped skips), publication/catalog consistency checks, independent receipt and browser review, workflow security analysis and retained native command outputs. The accepted GitHub replay independently matched all 46 artifacts: 10,000 synthetic bars, 902 fills, 451 closed positions and matching economic reports in both runs. Original CI failures and the restricted-worker compatibility boundary remain visible. No broker execution, account entitlement, independent-host recovery or causal lifetime token-savings claim is implied.