Merge feature/plan-challenge-phase into develop
This commit is contained in:
@@ -0,0 +1,85 @@
|
||||
# Challenge the plan — shared orchestrator include
|
||||
|
||||
Runs in the ORCHESTRATOR MAIN LOOP after a plan / reflection is elaborated and
|
||||
BEFORE it is executed. Turns a fresh plan into a hardened one by attacking it
|
||||
from three independent angles, then RE-THINKING every aspect a challenger lands.
|
||||
Loop + synthesis decisions live here, in the main loop (BDR-066: reflection runs
|
||||
on the big model; `verify-secure-loop.md`: fresh blind gates, decisions in the
|
||||
loop). It never merges, executes, or edits code — it hardens the plan and hands
|
||||
it to the orchestrator's existing human gate.
|
||||
|
||||
The challenge is ADVISORY into that gate — no new hard block — but a BLOCKER is
|
||||
never silently carried past: it is either closed by a NAMED plan change or
|
||||
explicitly deferred for the human.
|
||||
|
||||
## Inputs the caller must have ready
|
||||
|
||||
- `PLAN`: path to the plan ON DISK. If your plan is still inline (a printed
|
||||
checklist / diagnosis / fix plan), FIRST persist it to
|
||||
`.claude/tasks/plans/<date>-<slug>-<HHMM>.md` — the challengers read from disk
|
||||
and judge blind, exactly like the verifier reads the contract.
|
||||
- `KIND`: `build-plan` | `proposals` | `fix-bundle` — tunes the lens framing
|
||||
below; the mechanism is identical.
|
||||
- `SCOPE`: the files/dirs the plan touches (grounds the critique).
|
||||
- `CONSTRAINTS` (optional): the decided trade-offs / rejected alternatives from
|
||||
the design step, so a lens does not re-litigate a settled choice.
|
||||
|
||||
Nominal path is cheap for a small, clean plan: three parallel challengers return
|
||||
SOLID, synthesis is a no-op. It only costs more when a lens lands a real finding
|
||||
— which is the point.
|
||||
|
||||
## DISPATCH — three fresh challengers, in parallel, blind
|
||||
|
||||
Dispatch THREE fresh `plan-challenger` subagents IN PARALLEL, one per LENS, each
|
||||
blind to the others and to this conversation:
|
||||
|
||||
```
|
||||
Agent(subagent_type="plan-challenger", description="challenge:<lens>", prompt="""
|
||||
PLAN: <the PLAN path>
|
||||
LENS: <correctness | robustness | simplicity> # one per agent — all three
|
||||
SCOPE: <SCOPE>
|
||||
CONSTRAINTS: <CONSTRAINTS, if any>
|
||||
""")
|
||||
```
|
||||
|
||||
**MODEL (BDR-066):** plan critique is AUDIT JUDGMENT — do NOT pin
|
||||
`model: "sonnet"`; the challengers inherit the big session model. (The executor
|
||||
gates stay sonnet; the challenger does not.)
|
||||
|
||||
**Lens framing by `KIND`** (the agent's three lenses, read against the artifact):
|
||||
- `build-plan` — will it WORK / will it BREAK / is it needlessly COMPLEX.
|
||||
- `proposals` — are these the RIGHT items & priorities / what did the audit MISS
|
||||
or under-rate as risk / is the backlog over- or under-scoped.
|
||||
- `fix-bundle` — will each fix ACHIEVE its goal / could it BREAK or regress the
|
||||
page / is there a simpler fix, or an unnecessary one.
|
||||
|
||||
## FAIL-SAFE — never fail open
|
||||
|
||||
A challenger that returns a malformed/empty verdict, a missing `PROOF`, or dies →
|
||||
retry ONCE with a fresh challenger; a 2nd failure on that lens → STOP and escalate
|
||||
to the human, NAMING the lens. Never carry "plan challenged" into the gate on a
|
||||
silently dropped lens (`verify-secure-loop.md`: "a mute verifier is NEVER a PASS").
|
||||
|
||||
## SYNTHESIZE + RE-THINK (main loop, big model)
|
||||
|
||||
Parse each `CHALLENGE — LENS: … — VERDICT:` line and merge the FINDINGS:
|
||||
|
||||
- **Severity-driven, not consensus.** Any `[BLOCKER]` from ANY single lens is
|
||||
must-address — the lenses are orthogonal, so a lone security/rollback finding
|
||||
is real, never outvoted by lens-count. Cross-lens agreement only RANKS the MINORs.
|
||||
- **RE-THINK the aspect the challenge pointed at.** For each BLOCKER (and each
|
||||
MAJOR you accept): revise the plan on THAT aspect — a NAMED, diffable change to
|
||||
the plan, never a self-authored "addressed" line. A BLOCKER you consciously keep
|
||||
is tagged `[deferred <date>]` for the human to accept at the gate.
|
||||
- **Re-challenge once if the plan materially changed** — a fix can open a new
|
||||
flaw. Re-persist the revised `PLAN`, dispatch ONE fresh confirmation challenger,
|
||||
max 1 extra pass, then the gate.
|
||||
|
||||
## OUTPUT — into the existing human gate
|
||||
|
||||
Feed the orchestrator's gate:
|
||||
- the REVISED plan, and
|
||||
- a CHALLENGE SUMMARY: each BLOCKER raised → the named change that closed it;
|
||||
anything `[deferred]`; and any lens that failed to return.
|
||||
|
||||
The human remains the decider.
|
||||
@@ -0,0 +1,47 @@
|
||||
#!/usr/bin/env bash
|
||||
# lib/tests/plan-challenger.test.sh — structure lock: the plan-challenger agent,
|
||||
# the reusable lib/challenge-plan.md phase, and every reflection orchestrator that
|
||||
# wires it (3-way adversarial plan challenge, BDR-066). STATIC only — the agent's
|
||||
# adversarial behavior needs a live model (manual smoke), not a CI gate.
|
||||
set -u
|
||||
R="$(cd "$(dirname "$0")/../.." && pwd)"
|
||||
pass=0; fail=0
|
||||
ok() { pass=$((pass+1)); }
|
||||
ko() { fail=$((fail+1)); printf 'FAIL %s\n' "$1"; }
|
||||
has() { if grep -qF "$2" "$R/$1"; then ok; else ko "$1 missing: $2"; fi; }
|
||||
fm_lacks() { if awk 'NR<=10' "$R/$1" | grep -qF "$2"; then ko "$1 frontmatter must NOT contain: $2"; else ok; fi; }
|
||||
|
||||
A="agents/plan-challenger.md"
|
||||
L="lib/challenge-plan.md"
|
||||
|
||||
# 1) agent shape
|
||||
has "$A" "name: plan-challenger"
|
||||
has "$A" "tools: Read, Grep, Glob, Bash"
|
||||
fm_lacks "$A" "model: sonnet" # BDR-066: audit judgment → NOT sonnet-pinned
|
||||
has "$A" "CHALLENGE — LENS:" # load-bearing verdict grammar
|
||||
has "$A" "VERDICT: SOLID | CONCERNS(n) | FATAL(n)"
|
||||
has "$A" "correctness"
|
||||
has "$A" "robustness"
|
||||
has "$A" "simplicity"
|
||||
has "$A" "Report-only"
|
||||
|
||||
# 2) reusable phase — the mechanism lives here (one canonical include)
|
||||
has "$L" 'subagent_type="plan-challenger"'
|
||||
has "$L" "BDR-066" # challengers on the big model
|
||||
has "$L" "a mute verifier is NEVER a PASS" # fail-safe (never fail open)
|
||||
has "$L" "Severity-driven" # any single-lens BLOCKER = must-address
|
||||
has "$L" "RE-THINK" # findings re-plan the aspect, not just noted
|
||||
has "$L" "correctness | robustness | simplicity"
|
||||
has "$L" "CHALLENGE SUMMARY"
|
||||
has "$L" "build-plan" # the three KINDs
|
||||
has "$L" "proposals"
|
||||
has "$L" "fix-bundle"
|
||||
|
||||
# 3) every reflection orchestrator wires the phase + carries a challenge summary
|
||||
for s in ship-feature init-project feat bugfix onboard audit-delta code-clean seo geo harden web-validate; do
|
||||
has "skills/$s/SKILL.md" "lib/challenge-plan.md"
|
||||
has "skills/$s/SKILL.md" "CHALLENGE SUMMARY"
|
||||
done
|
||||
|
||||
printf 'plan-challenge structure lock: %d pass, %d fail\n' "$pass" "$fail"
|
||||
[ "$fail" -eq 0 ]
|
||||
Reference in New Issue
Block a user