job6: capitalize — BDR-056, LRN-107, EVAL-020, journal
BDR-056: deps policy reversal — latest gated by integration, not KEEP-PINNED by default (job6-batch-3 override, gstack #1911 case). LRN-107: read-only subagent mandates must ban copying secret VALUES, not just mutations (job6's own MAGIC_API_KEY scratch-copy incident). EVAL-020: job6 execution quality — 2 real STOP gates hit and resolved live (graphifyy hook rewrite declined, gsd-pi format break patched).
This commit is contained in:
@@ -1084,3 +1084,11 @@ rules:
|
||||
- **context**: 2026-07-06, job3 chore/job3-fixes (B1 unblock) then job4 SPEC-10 (`.audit/job4-report.md` J4-10), same run-reconcile.sh, same session-day — closed for real this time (T3/T5 repointed at a new `decisions-snapshot.md` fixture, `$MEM` variable deleted, `grep -c '$MEM' == 0` gate).
|
||||
- **future application**: after fixing one instance of a "reads live state it shouldn't" (or any similarly generic) finding, grep the WHOLE FILE (and ideally the whole surface class) for the same pattern before declaring the class closed — not just the line/test the finding cited.
|
||||
- **cousin**: [[LRN-077]] (pin grep, don't trust one instance), [[BDR-041]] (reconcile design: verify don't believe).
|
||||
|
||||
## LRN-107 — read-only subagent mandates must ban copying secret VALUES, not just mutations
|
||||
|
||||
- **pattern**: job6 (2026-07-07), an explorer subagent under explicit no-execute/read-only mandate (LRN-105 class) copied the plaintext `MAGIC_API_KEY` value into its own scratch file while investigating the magic MCP config. Harness flagged it; main session redacted (1 occurrence, clean post-scan). The mandate said "don't mutate anything" — it never said "don't copy a secret's value into a NEW file you create", so a read-only agent still leaked a secret copy.
|
||||
- **why**: "read-only" naturally reads as "doesn't change existing state" — copying a value into a fresh scratch file isn't a mutation of anything that existed, so it doesn't trip that mental model, but it creates a brand new place the secret now lives (BDR-026's exact class: secrets have copies beyond the canonical store — tool configs, transcripts, caches, and now subagent scratch files too).
|
||||
- **context**: `.audit/job6-report.md` "Incident (contained)" section; explorer-C.md redacted post-incident; caught before job6's execution phase, contained to scratchpad only.
|
||||
- **future application**: any read-only/no-execute subagent mandate that touches config or env files must explicitly ban copying a secret's VALUE into agent output/scratch, not just ban editing/deleting. Phrase the mandate as "reference by name/location, never paste the value" — when auditing MCP/env config, prefer `jq 'del(.. | .env?)'`-style filtering (already BDR-026 practice) over raw `cat`.
|
||||
- **cousin**: [[BDR-026]] (secrets have copies, protect/audit them all), [[LRN-105]] (explorer no-execute mandate, the sibling rule this extends).
|
||||
|
||||
Reference in New Issue
Block a user