feat(guardrails): refusal ends the attempt; doctrine-citers census; make test suite=
Root causes of the 2026-09-24 errors turned into mechanisms (BDR-100). hard_deny 'Routing around a guardrail': a refused command is never rerun through a wrapper, alias, heredoc, Makefile target, env file, other shell or other agent; the same clause in 14 agents and in the doctrine's sub-agent rule. make test suite=<file> runs one suite hermetically so the denied env-prefix form is never needed by hand. lib/tests/doctrine-citers.test.sh: every CLAUDE.md "Section" / § Label citation across skills, agents, lib, rules and hooks must resolve to a heading or bold label (flip-tested); its first run fixed rest-api-node.md. Doctrine 'After code changes' step 4: a changed rule, heading, label or threshold → grep every citer in the same commit.
This commit is contained in:
+7
-2
@@ -44,8 +44,10 @@ Apply unless repo-specific instructions override.
|
||||
gates (pinned executors, fresh verifier/security/challenge) always dispatch
|
||||
as written, whatever the task size; a failed gate re-dispatches a fresh
|
||||
executor, never redo its work by hand. A brief never
|
||||
authorizes a sub-agent to run a destructive tool, inside or outside the
|
||||
repo (Security → Destructive tools & data loss).
|
||||
authorizes a sub-agent to run a destructive tool (Security → Destructive
|
||||
tools & data loss) or to route around a guardrail: a refused command is
|
||||
reported with its rule, never rerun through a wrapper, alias, env file or
|
||||
other shell. Hermetic tests run through `make test [suite=…]` only.
|
||||
- Ask rather than guess. A choice visible in the result (placement,
|
||||
wording, order, behavior), a name that becomes public (command, flag,
|
||||
endpoint, file), or a scope the request leaves open → ask, even mid-task;
|
||||
@@ -78,6 +80,9 @@ Apply unless repo-specific instructions override.
|
||||
verified and what was not; list remaining risks and surviving deviations.
|
||||
2. Don't mark complete without proof it works.
|
||||
3. Correction or notable event → capitalize to the right registry.
|
||||
4. Rule, heading, label or threshold changed → grep every citer across
|
||||
skills/agents/lib and patch them in the same commit (`make test` runs the
|
||||
doctrine-citers census; a threshold lives in one lib file, skills call it).
|
||||
|
||||
## Memory registries (`.claude/memory/`)
|
||||
Five registries persist across sessions; capitalize during and after work.
|
||||
|
||||
Reference in New Issue
Block a user