fix(security-auditor,close): hotfix no-verifier carve-out documented; close enumerates STEP 5C + --no-push passthrough

This commit is contained in:
Bastien Chanot
2026-08-26 21:59:08 +02:00
parent c983f1ff94
commit ad4985f410
2 changed files with 8 additions and 4 deletions
+3 -1
View File
@@ -147,7 +147,9 @@ In audit mode, ALSO write this same block (plus per-finding detail) to
## ORCHESTRATOR PROTOCOL (consumer contract — wiring reference) ## ORCHESTRATOR PROTOCOL (consumer contract — wiring reference)
- The security gate runs AFTER the request-conformity verdict is CONFORME - The security gate runs AFTER the request-conformity verdict is CONFORME
(verifier), never before. (verifier), never before — EXCEPT under /hotfix, which by design runs no
verifier: there the gate fires directly on the smoke-passed diff (its
one-attempt model reverts on BLOCK instead of looping).
- Dispatch a FRESH auditor each iteration — no context reuse. Input = mode + - Dispatch a FRESH auditor each iteration — no context reuse. Input = mode +
scope + (report) + (context), nothing else. scope + (report) + (context), nothing else.
- Parse the `SECURITY — VERDICT:` line: - Parse the `SECURITY — VERDICT:` line:
+5 -3
View File
@@ -8,7 +8,7 @@ description: |
(that is /prune-memory). (that is /prune-memory).
Triggers: "close", "end session", "ferme la session", "session close", Triggers: "close", "end session", "ferme la session", "session close",
"checkpoint memory", "what did we learn", "retro rapide", "fin de journée". "checkpoint memory", "what did we learn", "retro rapide", "fin de journée".
argument-hint: (none — runs capitalize in ritual mode on the current conversation) argument-hint: "[--no-push] (runs capitalize in ritual mode; --no-push holds memory on the chore branch instead of the default auto-merge+push)"
allowed-tools: allowed-tools:
- Read - Read
- Edit - Edit
@@ -27,8 +27,10 @@ allowed-tools:
Invoke the `capitalize` skill now and run it in **ritual mode**: the full Invoke the `capitalize` skill now and run it in **ritual mode**: the full
pipeline (STEP 0 precheck → STEP 1 auto-scan → STEP 2 dedup → STEP 2B TODO pipeline (STEP 0 precheck → STEP 1 auto-scan → STEP 2 dedup → STEP 2B TODO
reconcile → STEP 3 approval gate → STEP 4 write → STEP 5 journal → STEP 5B reconcile → STEP 3 approval gate → STEP 4 write → STEP 5 journal → STEP 5B
memory commit → STEP 6 handoff), PLUS STEP 1B's explicit 3-question reflection memory commit → STEP 5C auto-persist: finish + push, BDR-068 — pass
(what did you decide / learn / block). `--no-push` through to hold the chore branch instead → STEP 6 handoff),
PLUS STEP 1B's explicit 3-question reflection (what did you decide / learn
/ block).
Ritual answers are deduped like any other candidate — a dup is dropped and its Ritual answers are deduped like any other candidate — a dup is dropped and its
existing ID shown, not re-logged. This is the upgrade over the legacy `/close`, existing ID shown, not re-logged. This is the upgrade over the legacy `/close`,