Repository navigation
feat: add CP-06 workflow review policy - #8
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Implement Factory CP-06 only, following landed CP-04 and CP-05. Deliver Pi workflow review/risk policy and a real fresh-context exercise without duplicating Firstmate or no-mistakes validation. BUILD_PLAN.md CP-06, COMPLETION.md P-06/P-07, and docs/WORKFLOW.md risk/review and task-local brief are authoritative. For P-06, take a representative sample of exactly ten bounded task context packs and record authoritative provenance, token counts, observed irrelevant-bulk rate, and missing-source rate; when a required source is missing, demonstrate targeted exact-original reads and corrections without hiding critical constraints. For P-07, prove deterministic low-risk checks happen before expensive semantic review, then repair or block a simulated reviewer finding and retest changed behavior with runnable evidence. Include separate normal API and critical auth-isolation fixtures with negative tests; critical fixtures must use no real accounts or secrets. Execute a genuinely fresh-context worker exercise receiving only task contract, bounded pack, and evidence rather than a prior transcript; observe missing documentation and route the worker to exact originals. Do not embed or call a second no-mistakes pipeline from Factory, hijack Firstmate dispatch, change Firstmate routing/shipping config, invent Factory commands, or add a scheduler/review control plane. Keep the CP-04 skill's implemented command list accurate: doctor, init, validate, context, sync, evidence, status, with Firstmate owning dispatch and shipping. Do not implement CP-07 convenience extensions or CP-08 application work. Prefer minimal changes to skills/factory/SKILL.md, docs/WORKFLOW.md, focused fixtures/tests, and docs/probes/CP-06.md; alter project contracts only when necessary and evidenced. Validate npm ci, format:check, lint, typecheck, npm test, git diff --check, exact tested SHA, changed files, residual risk, and proof at the final candidate. Open a PR against latest main for captain review, but never merge or deploy.
What Changed
Risk Assessment
✅ Low: The change is limited to CP-06 workflow documentation/probe evidence and focused executable fixtures, with no production Factory control-plane or dispatch logic changed.
Testing
I verified the target SHA, built only what was needed for the CP-06 workflow fixtures, ran the focused workflow tests, and captured product-level API/auth behavior evidence showing repaired invalid JSON handling and critical disposable auth-isolation negative cases; all targeted checks passed. No screenshot was captured because this change has no rendered UI surface.
Evidence: Focused CP-06 workflow test transcript
Evidence: Observed normal API and critical auth-isolation behavior JSON
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
✅ **Review** - passed
✅ No issues found.
✅ **Test** - passed
✅ No issues found.
git rev-parse HEADnpm run buildnode --test dist/test/workflow.test.jsManual evidence script importing the built normal API and critical auth-isolation fixtures and writing observed API responses toworkflow-api-behavior.json✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.