forked from bchanot/claude
feat(skills): wire verify+secure into ship-feature/init-project; onboard no-loop + LRN-093 backstop (verify-loops lot 5)
ship-feature: STEP 0e CONTRACT (request verbatim) → ENRICHED at the STEP 3 validation gate (design criteria appended [gated <date>], the human micro-gate) → STEP 5 VERIFY+SECURE judges the branch against the ENRICHED contract via the shared include. Distinct axis from STEP 6 code review, both run (LRN-095). init-project: contract seeded from the PROJECT BRIEF (V1 features → criteria) → ENRICHED at VALIDATION GATE #1 → STEP 9 VERIFY+SECURE. Adds the security gate init-project previously lacked (was deferred to a later /onboard). onboard: explicit NO verify-loop — it produces an audit report, not a change to verify against a request; contract is scope-only, security-auditor runs MODE audit (report-only), never a gate. Documented to prevent a misplaced symmetry loop (BDR-050: dev pipeline != audit). lib/tests/no-vacuous-locks.test.sh: deterministic backstop for LRN-093 (2nd recurrence in this chantier → the advisory alone did not hold). Refuses a literal \n in any grep/tf/tr_/tn pattern across lib/tests/*.test.sh; flip-tested against a synthetic offender so the guard proves it bites. lib/tests/loops-heavy.test.sh: 18 structure locks green. Behavioral dogfood (both vigilance points, real): (1) enrichment — a fresh verifier reads and checks a [gated] design criterion (ECARTS naming it precisely); (2) escalation — 3 consecutive ECARTS on the same criterion → orchestrator STOPs at the max-3 bound + presents the CONTRACT-vs-REALIZED table, no 4th loop, no commit. First real exercise of the infinite-loop guard. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
65edf8c1ba
commit
1c69de2f40
@@ -509,6 +509,15 @@ Agent(
|
||||
Si semgrep absent → l'agent rend DEGRADED (checklist seule) + recommande
|
||||
`make plugin` ; NON bloquant en onboard (audit, pas gate).
|
||||
|
||||
**Onboard n'a PAS de boucle verify→dev (`lib/verify-secure-loop.md`) — par
|
||||
conception.** onboard produit un RAPPORT d'audit, pas une modification à
|
||||
vérifier contre une demande : il n'y a ni contract de conformité, ni diff dev,
|
||||
ni verifier, ni max-3. Le contract d'onboard est un contract de SCOPE (ce que
|
||||
l'interview STEP 3 + `audit_stack` définissent comme périmètre d'audit), et
|
||||
`security-auditor` tourne en `MODE: audit` (report-only), jamais en `MODE:
|
||||
gate`. Ne PAS ajouter la boucle des flux dev ici par symétrie — l'audit et le
|
||||
flux de dev sont deux formes distinctes ([[BDR-050]] pipeline dev ≠ audit).
|
||||
|
||||
#### Dispatch doc-syncer (si `doc` dans audit_stack)
|
||||
```
|
||||
Agent(
|
||||
|
||||
Reference in New Issue
Block a user