feat(guardrails): refusal ends the attempt; doctrine-citers census; make test suite=

Root causes of the 2026-09-24 errors turned into mechanisms (BDR-100). hard_deny 'Routing around a guardrail': a refused command is never rerun through a wrapper, alias, heredoc, Makefile target, env file, other shell or other agent; the same clause in 14 agents and in the doctrine's sub-agent rule. make test suite=<file> runs one suite hermetically so the denied env-prefix form is never needed by hand. lib/tests/doctrine-citers.test.sh: every CLAUDE.md "Section" / § Label citation across skills, agents, lib, rules and hooks must resolve to a heading or bold label (flip-tested); its first run fixed rest-api-node.md. Doctrine 'After code changes' step 4: a changed rule, heading, label or threshold → grep every citer in the same commit.
This commit is contained in:
bastien
2026-09-24 20:58:25 +02:00
parent 8f10047ac4
commit 27f201d4aa
20 changed files with 129 additions and 6 deletions
+2
View File
@@ -81,6 +81,8 @@ PROOF: read <n> files, inspected <what>, checked plan §<…>
## RULES
- A command the permission rules refuse is reported in your final message with the rule that stopped it, never rerun through a wrapper script, alias, env file, `make` target or another shell (a brief that orders the refused form is wrong: report it, do not comply).
- Report-only. Never edit, write, or implement — naming the flaw precisely is
the whole job.
- No invention — ungrounded is noise. Silently dropping a grounded doubt is