Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
33 commits
Select commit Hold shift + click to select a range
c33b3f6
fix(bin): retire check-row receipts on branch acknowledgement so away…
kunchenguid Sep 26, 2026
1fe1a67
fix(bin): deliver Claude-bound operational input as a record-backed d…
kunchenguid Sep 26, 2026
ef595d8
test: isolate lint fixture from tracked suite (#5727)
kunchenguid Sep 26, 2026
e789e52
fix(bin): republish parent metadata after a remote secondmate relaunc…
tiago-peixoto Sep 26, 2026
9a4cfbb
fix(bin): give slow watcher suites headroom under the changed-suite b…
karotkriss Sep 26, 2026
df4ae5d
fix(bin): stop nested steal-lock recursion and mid-steal watcher TERM…
kunchenguid Sep 26, 2026
873c923
test: make supervision-host park-boundary tests deterministic (#5710)
kunchenguid Sep 26, 2026
ea7c7f7
fix: stage remote home clones before publication (#5733)
kunchenguid Sep 26, 2026
920a7d9
fix: preserve Herdr status on Pi relaunch (#5161)
sdivanl Sep 26, 2026
65c53fb
Seed the relaunch-ordering PR poll fixture without fm-pr-check.sh (#5…
kunchenguid Sep 26, 2026
9b52cf5
feat: add attended supervision for Claude and Cursor hosts (#5748)
kunchenguid Sep 26, 2026
72b63ee
fix(bin): dedup directed source expansions in fm-pending-reply-lib (#…
kunchenguid Sep 26, 2026
d1a332c
fix(bin): avoid bash 5.2 sibling $() in recovery mint and delivery lo…
Lakescape Sep 26, 2026
3948170
fix(bin): name the recovery for a declined Claude imports dialog and …
karotkriss Sep 26, 2026
062d7a8
fix(bin): report the newest status event in the voice status reader (…
karotkriss Sep 26, 2026
e9a6675
fix(bin): gate a self-announcing tool's update-available report on a …
karotkriss Sep 26, 2026
cf20836
fix(bin): pass the dispatch profile effort to OpenCode workers throug…
karotkriss Sep 26, 2026
9d56cf6
fix: stop cancelled validation runs from reporting false failures (#5…
mremond Sep 26, 2026
bb69be6
fix: require declared waits for workers awaiting their own work (#5812)
mremond Sep 26, 2026
503ba82
fix: bound ShellCheck to one canonical root per process (#5770)
kunchenguid Sep 26, 2026
5700baa
fix: bound watcher cleanup wait on the downtime-marker lock (#5732)
kunchenguid Sep 26, 2026
62d643c
test: stop the remote secondmate e2e watcher before temp-root cleanup…
aminry Sep 26, 2026
30ef650
fix(bin): stop reporting untouched shared-captain copies as drift (#4…
tiago-peixoto Sep 26, 2026
f62a7d9
docs: restructure calm.md for readability (#5604)
tmchow Sep 27, 2026
3b68997
docs: restructure turnend-guard.md for readability (#5611)
tmchow Sep 27, 2026
49a218b
docs: move situational AGENTS.md sections into on-demand skills (#5872)
kunchenguid Sep 27, 2026
5a9880b
fix: route second-mate signal wakes by presented status span (#5879)
kunchenguid Sep 27, 2026
fd88ea0
fix(bin): take the source lock before the lifecycle lock in register-…
FocalFactotum Sep 27, 2026
b4561ad
fix: chain repository hooks under git -c overrides (#5877)
FocalFactotum Sep 27, 2026
fba81cb
fix(bin): withhold never-send values from dispatch resolver requests …
zachlandes Sep 27, 2026
1d85c04
Merge upstream/main (kunchenguid/firstmate) into fork main
zakna Sep 27, 2026
8e947d2
no-mistakes(review): Point scope allowance at validation-supervision …
zakna Sep 27, 2026
5b9bae9
Merge origin/main into upstream sync branch
zakna Sep 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 13 additions & 10 deletions .agents/skills/afk/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,7 +67,7 @@ Hold-for-return is the default and the only reach profile this release records:

No `/back` is needed. The first genuine message is the return signal:

- A message **without** the current operational prefix or a legacy bare marker, and **not** starting with `/afk` -> the captain is back.
- A message that is none of the internal forms below, and **not** starting with `/afk` -> the captain is back.
Run `bin/fm-afk-return.sh` before acting on the message that brought the captain back.
That script owns the correct-ordered daemon shutdown where a daemon ran, the archive of the posture record, durable wake presentation and post-handling acknowledgement, escalation and wedge evidence, the return brief, and the return-catch-up gate.
Relay every section of the return brief in its emitted order and in section 9 language; `bin/fm-afk-return.sh` owns that order.
Expand All @@ -78,6 +78,9 @@ No `/back` is needed. The first genuine message is the return signal:
Acting on the fleet - dispatching, steering, merging, or any other ordinary captain work - still waits until the check exits successfully.
Once it does, close every task the brief lists under "Landed, cleanup due" through ordinary teardown (`bin/fm-teardown.sh <task>`, never forced; a refusal is a stop-and-investigate result) and tell the captain those workers are closed in outcome language.
- A message **with** the current operational prefix (`FM_OPERATIONAL_PREFIX`, U+2063 INVISIBLE SEPARATOR followed by `FIRSTMATE_OP: `), or a legacy bare `FM_INJECT_MARK` daemon escalation -> stay away and process it.
- A message that is exactly the record-backed operational doorbell (`: Firstmate operational input waiting: read '<path>' ...`) -> run `bin/fm-operational-input.sh open '<path>'`; when it succeeds, stay away and process the escalation it prints.
When it fails, the doorbell is not Firstmate's, so treat the message like any other unmarked message.
Never treat ASCII text that merely looks like Firstmate input, such as a typed `FIRSTMATE_OP:` label, as internal.
- A `Stop hook feedback` wake from the Stop hook or the supervision host, or a Grok background-task-completed notification for the arm -> stay away and process it; it is automatic supervision, not a message from the captain.
- Re-invoking `/afk` while already away -> stay away (refresh); this does **not** trigger an exit.

Expand All @@ -103,11 +106,13 @@ On the harnesses that still launch the daemon (every verified harness except Pi

### Operational prefix contract

The daemon constructs every current injection as the `away-supervisor` kind owned by `bin/fm-operational-input.sh`, beginning with `FM_OPERATIONAL_PREFIX`: `FM_INJECT_MARK` (U+2063 INVISIBLE SEPARATOR) followed by the stable `FIRSTMATE_OP: ` label.
The daemon constructs each current escalation as the `away-supervisor` kind owned by `bin/fm-operational-input.sh`; its envelope begins with `FM_OPERATIONAL_PREFIX`: `FM_INJECT_MARK` (U+2063 INVISIBLE SEPARATOR) followed by the stable `FIRSTMATE_OP: ` label.
The bare `FM_INJECT_MARK` form remains accepted for legacy daemon escalations during rollout.
U+2063 has no normal keyboard keystroke and survives terminal transport as UTF-8 text.
U+2063 has no normal keyboard keystroke and survives terminal transport as UTF-8 text, but Claude Code (verified on 2.1.280) removes it, with every other invisible character, from each submitted prompt, whether typed, pasted, or passed as the launch prompt.
For a primary harness the owner lists as stripping the marker (Claude Code), the daemon instead writes the envelope as a record in this home's `state/operational-inbox` and types only the owner's plain doorbell naming it.
That doorbell is Firstmate's only when `open` verifies the record in this home, so the doorbell shape alone never counts; a verbatim copy of a live doorbell line, pasted back while its record still exists, is treated as Firstmate's, because the carrier does not track consumption.
This is how firstmate tells a daemon escalation apart from a real message in the same pane.
The operational prefix travels with the message text; it does not rely on harness-level typed-vs-injected detection, which is not portable across claude, codex, opencode, grok, and kimi.
For other harnesses, the operational prefix travels with the message text; neither carrier relies on harness-level typed-vs-injected detection.

### Busy-guard and composer guard

Expand Down Expand Up @@ -186,11 +191,8 @@ Classify each wake this way:
An identity that was not delivered still escalates.
Status-read uncertainty follows the shared one-report-without-position-advance contract referenced under Dedupe below.

Escalations are buffered up to `FM_ESCALATE_BATCH_SECS` (default 90s; 0 =
immediate) and flushed as one single-line digest prefixed with the current
operational prefix, carrying pre-read status summaries and a recommended action.
The single-line format makes the submission unambiguous across harnesses, and
the operational prefix lets firstmate distinguish it from a real captain message.
Escalations are buffered up to `FM_ESCALATE_BATCH_SECS` (default 90s; 0 = immediate) and flushed as one single-line digest carrying pre-read status summaries and a recommended action.
The single-line format makes submission unambiguous across harnesses; the carrier described above distinguishes it from an ordinary captain message.

### Injection hardening

Expand Down Expand Up @@ -223,7 +225,8 @@ the operational prefix lets firstmate distinguish it from a real captain message
This lets ghost-only or bordered-empty composers count as empty where a composer read is the active confirmation signal.
- **Marker strip** - `strip_injection_marker` removes the current operational
prefix or legacy bare marker before classification or relay, so the digest
text firstmate sees is clean.
text firstmate sees is clean; `open` prints a record-backed doorbell's digest
already stripped.
- **Portable singleton lock** - the daemon uses the repo's portable lock helper
(`fm-wake-lib.sh`) instead of `flock`, which is absent on macOS.
- **Dedupe across signal/stale/scan** - all three paths use the shared status presentation markers defined by `bin/fm-classify-lib.sh`, so a successfully classified span is not re-escalated by another path in the same digest.
Expand Down
28 changes: 28 additions & 0 deletions .agents/skills/agent-skill-trigger-index/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
---
name: agent-skill-trigger-index
description: Load only when auditing or maintaining the complete agent-only skill trigger index.
user-invocable: false
metadata:
internal: true
---

# Agent-only reference skills

These skills are not captain-invocable; load them only at their precise triggers.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Include every agent-only skill in the trigger index

When this skill is loaded for the advertised complete trigger audit, its list omits the newly added user-invocable: false skills operational-home-layout, session-start-recovery, away-quiet-supervision, validation-supervision, ship-landing, and scout-completion. Those skills contain required triggers for startup recovery, away supervision, validation decisions, landing, and cleanup, so an audit driven by this new index can incorrectly conclude that those runtime contracts are covered and allow their triggers to drift. Include all agent-only skills or stop calling this the complete index.

AGENTS.md reference: AGENTS.md:L405-L406

Useful? React with 👍 / 👎.


- `bootstrap-diagnostics` - load whenever the session-start digest's bootstrap or network-checks section prints an actionable diagnostic line (`MISSING:`, `MISSING_MANUAL:`, `PRESENTATION_UNAVAILABLE:`, `BACKEND_INVALID:`, `NEEDS_GH_AUTH`, `TANGLE:`, `STARTUP_MEMORY_BUDGET:`, `CREW_DISPATCH: invalid`, `FLEET_SYNC:`, `NETWORK_CHECKS:`, `HOME_SUMMARY:`, `BACKLOG_RECONCILE:`, `SECONDMATE_SYNC:`, `SECONDMATE_LIVENESS:`, `SECONDMATE_HANDOFF:`, `NUDGE_SECONDMATES:`, or `FMX:`), or when `BOOTSTRAP_INFO:` says an interrupted backlog cleanup may have left an endpoint or local copy; silence and other `BOOTSTRAP_INFO:` facts need no load.
- `diagnostic-reasoning` - load before scoping a reported bug and before acting on a diagnostic report.
- `ask-user-authority` - load before deciding any ask-user finding.
- `quota-array-dispatch` - load before choosing among a matched crew-dispatch profile array from current quota-axi default TOON.
- `harness-adapters` - load before spawning or recovering a crewmate or secondmate, handling a trust dialog, sending a harness-specific skill invocation, interrupting or exiting an agent, resuming an exited agent, or verifying a new harness adapter.
- `firstmate-orca` - load before switching to Orca, spawning or supervising Orca-backed work, smoke-testing Orca backend behavior, debugging Orca task state, or reconciling Orca-backed task metadata.
- `project-management` - load before adding, creating, removing, or initializing a project.
Cloning or registering a project is add intake and uses the same trigger.
- `stuck-crewmate-recovery` - load when the session-start digest reports an ordinary direct report's endpoint dead or its metadata has no window, after a stale wake, looping pane, repeated confusion, an answered-by-brief question, an unresponsive crewmate, or a failed steer, and whenever a live worker reports its no-mistakes pipeline dead, unreachable, or timed out.
- `secondmate-provisioning` - load before creating, seeding, validating, launching, handing backlog to, recovering, pushing inherited local material into, or retiring a secondmate home, and before editing `data/secondmates.md`.
- `captain-hold-lifecycle` - load before treating an investigation or visual review as complete, before ending a visual review that exposed a captain decision, when recording or routing the captain's answer, and on any `RECORD DIVERGENCE` line from the wake drain.
- `process-event-sources` - load before arming a long-polling source, before registering a deterministic condition->action watch (do X as soon as Y is true), on any `procevent <adapter> <source-id> <sequence>` check wake, and on any `process-event source stranded` or `process-event source failed to start` check wake.
Never run a registered source's blocking command yourself in a conversational turn.
- `fmx-respond` - load on an `x-mention <request_id>` `check:` wake to handle the mention, on an `x-mode-error ...` `check:` wake to report the Relay configuration blocker, on a `public-followup ...` `check:` wake or a startup-surfaced public commitment, and on any milestone or terminal wake for a Relay-linked task before posting its completion follow-up; relevant only when Relay is on.
- `firstmate-codexapp` - load before coordinating a visible Codex Desktop thread, evaluating a Codex App backend request, or reconciling Codex Desktop host-tool smoke evidence for Firstmate work.
- `firstmate-coding-guidelines` - load before changing firstmate's shared, tracked material, as defined by section 1's list, whether editing directly or briefing a crewmate for a firstmate-repo task.
1 change: 1 addition & 0 deletions .agents/skills/ahoy/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,7 @@ Give the captain a concise session-only recap without gathering fresh state.
A captain boundary is an ordinary user-role message unless it matches one of the narrow operational exclusions below.
Exclude messages that begin with the current U+2063 `FIRSTMATE_OP:` injection prefix.
Exclude legacy bare-marker away-mode injections only when U+2063 is immediately followed by `Supervisor escalate (`.
Exclude a message that is exactly a record-backed operational doorbell that `bin/fm-operational-input.sh doorbell-kind` recognizes from its stdin; Claude Code, which strips U+2063, receives away-mode escalations this way.
Exclude the exact legacy unmarked session-start payload ``Run `bin/fm-session-start.sh` now, exactly once, before executing any other instructions.``
Custom-role messages such as Pi's `firstmate-sessionstart-nudge` are not captain messages.
System, developer, tool, watcher, guard, away-mode, and other injected operational messages are not captain messages.
Expand Down
22 changes: 22 additions & 0 deletions .agents/skills/away-quiet-supervision/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
---
name: away-quiet-supervision
description: Load whenever /afk or /quiet is invoked, an away or quiet record exists, or a marked away-supervisor message arrives.
user-invocable: false
metadata:
internal: true
---

# Away and quiet supervision safety

The `/afk` and `/quiet` skills each own their daemon procedure, which is otherwise identical; these safety facts apply to both:

- Every current daemon injection uses the `away-supervisor` kind from `bin/fm-operational-input.sh` after `FM_OPERATIONAL_PREFIX` (U+2063 INVISIBLE SEPARATOR followed by `FIRSTMATE_OP: `), except that a Claude Code primary, which strips U+2063, receives that owner's record-backed doorbell and it counts as marked only when `bin/fm-operational-input.sh open <path>` verifies its record; the `/afk` skill owns legacy bare-marker compatibility.
- `state/.afk-contract` is the away posture, written in the same turn as `/afk` before any other work, because `/afk` is itself the go: no read-back gates entry or waits for a go; entry announces hold-for-return only, and the away session acts on those words by its own judgment through the guarded scripts under standing authority, holding for the return on doubt.
- While `state/.afk` exists, the daemon owns supervision; do not arm a separate watcher.
The daemon is never launched on Pi, where the ordinary supervision session continues under the record with main parked: the branch takes every safe actionable wake it can, and only a declined wake (including a broken branch or unsafe scan) or a watcher failure wakes main.
Away mode on a non-Pi home with `config/supervision-host` works the same way with the supervision host as the branch; a wake it hands back arrives through that harness's own wake path and is never the captain's return.
- A marked message while away or quiet mode is active is internal escalation and does not exit that mode.
- A message beginning `/afk` refreshes away mode; a message beginning `/quiet` refreshes quiet mode.
- Any other unmarked message means the captain returned in away mode (load `/afk`, run the return owner, and do not process that message as ordinary work until its durable catch-up gate clears), or, in quiet mode, is simply answered as ordinary work with the flag and daemon left untouched until an explicit `/quiet off`.
- Away and quiet mode never expand approval authority for merges, ask-user findings, destructive actions, irreversible actions, or security-sensitive choices.
- Bias ambiguous input toward exit because a present captain takes precedence.
2 changes: 1 addition & 1 deletion .agents/skills/bootstrap-diagnostics/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ metadata:

Handle each printed line as below, before dispatching work that depends on it.
The line formats themselves are owned by `bin/fm-bootstrap.sh`'s header; this playbook owns the response to actionable lines.
The inline rules in `AGENTS.md` section 3 still bind: detect, then consent, then install - never install anything the captain has not approved in this session - and no work is dispatched until the tools it needs are present and GitHub auth is good.
The session-start rules in `session-start-recovery` still bind: detect, then consent, then install - never install anything the captain has not approved in this session - and no work is dispatched until the tools it needs are present and GitHub auth is good.
When any diagnostic needs captain attention, report the plain consequence and requested action using `AGENTS.md` section 9's captain-facing translation contract; do not name the diagnostic label unless the captain needs to paste it into a command or issue.

- `MISSING: <tool> (install: <command>)` - list the missing tools to the captain with a one-line purpose each plus the printed install commands, wait for consent (one approval may cover the list), then run `bin/fm-bootstrap.sh install <approved tools...>`.
Expand Down
2 changes: 1 addition & 1 deletion .agents/skills/captain-hold-lifecycle/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ Only `answer` with the captain's words or an evidence-backed `reconcile close` m
Never close anything the captain owns without recording what he actually said: `bin/fm-captain-hold.sh answer` writes his exact words into the task and closes a question-shaped call, while `--release` frees a captain-gated work item to proceed.
A merge approval uses that existing release path because approval permits the merge to proceed; cleanup closes the work only after it lands and records what shipped.
Closing a held row at merge approval instead records completion before landing, so the backlog claims completion before the work actually ships.
When the answer changes what a task must build, follow `AGENTS.md` section 7's Validate contract to preserve the captain's words in the brief and steer the worker.
When the answer changes what a task must build, follow `AGENTS.md` section 7's mid-task ask rule to preserve the captain's words in the brief and steer the worker.
When the captain says "later", that is an answer too: re-hold with `bin/fm-captain-hold.sh hold <id> --reason "<reason>" --until <date>` so the item leaves the live Captain's Call and resurfaces on its date, instead of leaving a live-looking card or fabricating a closure.
"A keyed answer resolves its matching captain-held task" is one capability with one owner, `bin/fm-captain-hold.sh answers`, and every channel that carries a captain answer feeds it the same task id and answer; a channel never maps keys to tasks, records a decision, or resolves anything itself.
Chat already feeds it through `bin/fm-send.sh --resolve-key`, and a captured-answer source feeds it once bound with `bin/fm-captain-hold.sh bind <source-id>`; bind before arming the source, and key each structured question by the held task's id.
Expand Down
2 changes: 1 addition & 1 deletion .agents/skills/firstmate-codexapp/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,7 @@ For a Firstmate-managed task, include an explicit status instruction:
```text
Append supervisor-visible status lines to <absolute-firstmate-home>/state/<task-id>.status.
Use only these prefixes for status changes: working:, needs-decision:, blocked:, paused:, done:, failed:.
Use paused: only for a deliberate known external wait that should be rechecked later, never for a blocker that needs firstmate to act.
Follow the task brief's status-reporting rule for declaring and resolving waits; bin/fm-brief.sh owns that rule.
Before doing substantive work, append "working: Codex Desktop thread started".
```

Expand Down
Loading
Loading