Skip to content

Commit fe367ce

Browse files
docs(proof): gate journaling on a 4/4 retention score
Keep Proof writes for durable turning points only. Score the information before any mutation or body edit. Existing records do not bypass the gate. Bundle the four eval cases with the skill. Drop PR-lifecycle Proof records from #254 and keep the accepted pagination Decision as the durable rationale. Co-authored-by: Cursor <cursoragent@cursor.com> Change-Id: I9c2eab5cc1df96e6ca2287d21c9f69872d99a072 Co-authored-by: Cursor <cursoragent@cursor.com>
1 parent 55673a2 commit fe367ce

12 files changed

Lines changed: 196 additions & 145 deletions

‎.agents/skills/proof/SKILL.md‎

Lines changed: 38 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
name: proof
3-
description: Journal reasoning (decisions, findings, issues, constraints, risks, citations, blobs) into a Flatbread Proof and recall it with bounded reads. Use when starting or resuming a thread of work, recording a decision or finding, resolving an issue, checking what is blocking or still open on an effort, or when the user mentions effort graph, journaling, blocking decisions, agent memory, citation, blob, cites, longform, WriteCitation, or WriteBlob.
3+
description: Read and update Flatbread Proof, the repository's durable project memory, through bounded queries and typed mutations. Use for recall when resuming a known effort, checking blockers, or when the user mentions Proof or journaling. Use the write path only for a decision-relevant turning point that outlives the current PR or session and adds unique causal rationale. Never journal routine progress, handoffs, review notes, temporary gaps, implementation steps, or journal corrections.
44
---
55

66
# Proof — agent journaling and recall
@@ -51,6 +51,36 @@ The write journal is `<root>/.journal/`; read digests cache under
5151

5252
## Writing (journaling)
5353

54+
### Mandatory write gate
55+
56+
Proof is a map of durable reasons, not a work log. How to use Proof lives in
57+
this skill; do not journal the process itself as a Decision.
58+
59+
Score only new retained information: create mutations and body text that add
60+
claims. Lifecycle transitions (`AcceptDecision`, `ResolveIssue`,
61+
`SetEffortStatus`, `MitigateRisk`, `SetRiskState`) and `proof cache prune` do
62+
not add retained claims and do not need a 4/4 score.
63+
64+
Before a create or a body edit that adds claims, score the information being
65+
added — not the record that would receive it. Answer each test in private
66+
reasoning:
67+
68+
1. **Future need:** Would losing it make a future agent materially
69+
misunderstand why the project is shaped this way?
70+
2. **Durable effect:** Will it outlive the current PR or session and change a
71+
product principle, public contract, architecture, constraint, risk, or docs
72+
direction?
73+
3. **Causal value:** Does it explain why that change happened or what evidence
74+
could reverse it?
75+
4. **Unique signal:** Does it add a reason or link that code, docs, Git, the PR
76+
or tracker issue, and retained records do not already make clear?
77+
78+
Do not create a record or add body claims unless the information scores
79+
**4/4**. An existing or open record does not bypass this gate; appending
80+
low-value text still consumes bounded reads. Keep failed candidates in the
81+
PR, tracker issue, commit, or run artifact. Citations and Blobs persist only
82+
when they support a 4/4 record.
83+
5484
One command for all 15 mutations — pass the payload as a single JSON argument:
5585

5686
```bash
@@ -156,14 +186,16 @@ server-side.
156186
for the full body. Reserve opening `.flatbread-proof/**/*.md` for rare
157187
cases (e.g. digest byte-cap miss on an oversized record), not normal
158188
zoom-in.
159-
3. **During work:** when outside material supports a record, save large
160-
content with `WriteBlob` if needed, then create a `WriteCitation`, then
161-
create the Issue, Finding, Decision, Constraint, or Risk with
189+
3. **During work:** apply the write gate above before any create or body
190+
edit that adds claims. When outside material supports a 4/4 record, save
191+
large content with `WriteBlob` if needed, then create a `WriteCitation`,
192+
then create the Issue, Finding, Decision, Constraint, or Risk with
162193
`cites: ["<cit-id>"]`. You cannot add a citation later, so create the
163194
Citation first. Open Issues for real gaps or blockers, and use
164195
`derives_from` on Decisions to link the Findings, Constraints, and Issues
165196
they respond to.
166197
4. **On commitment:** `AcceptDecision` (mind `rejectSiblings`), `ResolveIssue`
167-
with `resolvedBy` citing the closing Decision/Findings.
198+
with `resolvedBy` citing the closing Decision/Findings. These lifecycle
199+
transitions do not need a 4/4 score.
168200
5. Maintenance: `flatbread proof cache prune` deletes digests older than
169-
24h / over the 100 MiB ceiling.
201+
24h / over the 100 MiB ceiling. Prune does not need a 4/4 score.
Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
{
2+
"skill_name": "proof",
3+
"evals": [
4+
{
5+
"id": 1,
6+
"prompt": "An implementation branch passes lint and 41 of 42 tests. The last failure is a flaky timer assertion owned by this branch. The next session should rerun it and adjust the timeout if it repeats. Preserve this handoff where it belongs.",
7+
"expected_output": "Keep the handoff in a branch, run, PR, or tracker artifact. Do not create or update a Proof record.",
8+
"assertions": [
9+
"No .flatbread-proof record is created or updated",
10+
"The response identifies the handoff as temporary implementation state",
11+
"The response names a native work artifact instead of Proof"
12+
]
13+
},
14+
{
15+
"id": 2,
16+
"prompt": "Put this in project agent memory: for the current PR, the follow-up is split among five temporary file owners covering the changelog, mirrored references, CLI tests, digest tests, and render logic. The map is useful until the PR merges but changes no product rule.",
17+
"expected_output": "Keep the ownership map in the PR or run artifact despite the request to put it in agent memory. Do not create or update a Proof record.",
18+
"assertions": [
19+
"No .flatbread-proof record is created or updated",
20+
"The direct request to use project memory does not bypass the retention gate",
21+
"The response places the ownership map in the PR or run artifact"
22+
]
23+
},
24+
{
25+
"id": 3,
26+
"prompt": "A prior agent created a Finding only to note that a PR checklist used the wrong record kind. Product behavior did not change, and the correction matters only until review ends. Decide what durable project-memory action is warranted.",
27+
"expected_output": "Create no new Proof record. The writer has no delete mutation. Leave the temporary Finding for maintainers, or if a PR must drop the file, strip inbound and outbound ids on retained records in the same change so reads do not fail closed on dangling edges. Keep any separate durable product decision.",
28+
"assertions": [
29+
"No new Proof record is created",
30+
"The response treats the journal correction as temporary bookkeeping",
31+
"The response does not teach a bare record delete",
32+
"Any cleanup preserves separate durable rationale and clears edges on retained records"
33+
]
34+
},
35+
{
36+
"id": 4,
37+
"prompt": "Maintainers made a project-wide, hard-to-reverse choice: Proof will not add numeric confidence fields to any record type. Uncertainty stays in cited evidence and record prose because scores from different models are not comparable. This will govern schema work, writer behavior, and docs. Preserve the conclusion through the repository's normal process.",
38+
"expected_output": "Create and accept one Proof Decision through the typed writer. Pass rejectSiblings false so unrelated proposed Decisions on the same Effort stay proposed. Preserve the rationale, alternatives, consequences, and reversal criteria.",
39+
"assertions": [
40+
"One durable Proof Decision is created",
41+
"AcceptDecision passes rejectSiblings false",
42+
"The rationale explains why model confidence scores are not comparable",
43+
"The Decision covers schema, writer, and documentation consequences",
44+
"No unrelated Proof record is created or rejected"
45+
]
46+
}
47+
]
48+
}

‎.flatbread-proof/citations/cit-pr-254-grouped-review-22-aug--cpbe5anhpby3h625.md‎

Lines changed: 0 additions & 9 deletions
This file was deleted.

‎.flatbread-proof/citations/cit-pr-254-journal-quality-review-22-aug--bf2s44nw13221za3.md‎

Lines changed: 0 additions & 9 deletions
This file was deleted.

‎.flatbread-proof/decisions/dec-address-pr-254-review-as-five-disjoint-file-grou--bx44enbv52ztnrnn.md‎

Lines changed: 0 additions & 25 deletions
This file was deleted.

‎.flatbread-proof/decisions/dec-treat-page-has-more-as-pagination-only--dv24ta688adf262v.md‎

Lines changed: 5 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -4,21 +4,14 @@ effort: eff-proof-and-contributor-operating-system--ahhgtafvdhg4dfve
44
title: Treat page.has_more as pagination-only
55
state: accepted
66
created_at: '2026-08-22T17:41:04.977Z'
7-
derives_from:
8-
- fnd-pr-254-completeness-review-asked-for-a-paging-on--r631nr0gnqp9sypt
9-
- iss-pr-254-journal-used-issue-kind-on-a-finding-and--9p7t7amz79y5rn3b
10-
supersedes:
11-
- dec-address-pr-254-review-as-five-disjoint-file-grou--bx44enbv52ztnrnn
127
---
138

14-
Supersedes the prior Decision that named five file owners as the Choice. The file split is how the follow-up was split for review, not the rule that shipped.
9+
Context: A Proof read can be incomplete because another page exists or because the digest hit a hard cap. Treating both cases as page.has_more tells callers to page when no cursor can recover the omitted data.
1510

16-
Context: PR 254 already exposes complete and cap_reasons. The 22 Aug review asked to document that page.has_more is pagination-only, lock two missing tests, and optionally refuse hasMore without a cursor.
11+
Choice: page.has_more means that another cursor-backed page exists. An input with hasMore: true and no non-empty nextCursor is refused. Hard caps appear through complete and cap_reasons; callers narrow the query or fail closed.
1712

18-
Choice: page.has_more means pagination only. Unpaired hasMore without a nextCursor is refused. Hard caps stay on complete and cap_reasons. Callers page only when page.has_more is true. They use cap_reasons and complete for walls.
13+
Alternatives: Mark every incomplete read as page.has_more, or allow has_more without a cursor. Both options blur recoverable pagination with terminal truncation and can make callers retry a page that cannot help.
1914

20-
Note: the follow-up locked that rule in five file groups: CHANGELOG, both reference.md copies, the CLI spawn, the digest unit, and renderDigest. That split is a working note, not the Choice.
15+
Consequences: The JSON envelope, digest header, and summary share one distinction. Callers page only with a cursor and treat hard caps as walls.
2116

22-
Alternatives: keep the file-split Decision as the accepted record; skip the unpaired-cursor refuse. We kept the refuse because docs already call a null cursor an error.
23-
24-
Reversal: revert the follow-up. Digest cache rebuilds on the next read.
17+
Reversal: Revisit this split only if every incomplete read gains one safe recovery action.

‎.flatbread-proof/findings/fnd-pr-254-completeness-review-asked-for-a-paging-on--r631nr0gnqp9sypt.md‎

Lines changed: 0 additions & 24 deletions
This file was deleted.

‎.flatbread-proof/findings/fnd-pr-254-still-omitted-paging-only-has-more-map-an--hk8r9xfee39s64vc.md‎

Lines changed: 0 additions & 23 deletions
This file was deleted.

‎.flatbread-proof/issues/iss-pr-254-journal-used-issue-kind-on-a-finding-and--9p7t7amz79y5rn3b.md‎

Lines changed: 0 additions & 19 deletions
This file was deleted.

‎CHANGELOG.md‎

Lines changed: 19 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -2,13 +2,31 @@
22

33
## Unreleased
44

5-
- The DAG runner is now `@flatbread/oven` (`pnpm exec oven`); the memory package is now `@flatbread/proof` with the `flatbread proof` CLI.
5+
- The Proof skill now applies a 4/4 write gate. Agents score the information
6+
before a create or a body edit that adds claims; existing records do not
7+
bypass the gate. Four bundled eval cases ship with the skill for a manual
8+
eval run.
69
- Proof read envelopes now expose `complete` and `cap_reasons`. `page.has_more`
710
is pagination-only and no longer signals the 25-record wall; use
811
`cap_reasons` / `complete` for hard caps on `displayed_edges` and `bytes`.
912
The `primary_records` limit remains an in-process defensive signal because
1013
the CLI read bridge slices to 25 records before rendering. Callers can tell
1114
paging from hard caps without parsing the digest Markdown or `summary` text.
15+
- **Breaking for writes:** Proof now rejects create-time `derives_from`,
16+
`supersedes`, and `invalidates` targets from another Effort. The later
17+
`Supersede` and `Invalidate` forms already rejected these edges. Rejected
18+
creates write no record or reverse projection and leave the generation
19+
unchanged.
20+
`flatbread proof relations` now reports stored legacy or hand-edited foreign
21+
edges as `PROOF_CROSS_EFFORT_RELATION` instead of dropping them into a
22+
successful empty page.
23+
24+
Notes for the Flatbread release train. Some packages also keep their own
25+
changelog; this file covers the repository as a whole.
26+
27+
## 1.0.1
28+
29+
- The DAG runner is now `@flatbread/oven` (`pnpm exec oven`); the memory package is now `@flatbread/proof` with the `flatbread proof` CLI.
1230
- `@flatbread/source-filesystem` reads a content directory that does not exist
1331
as an empty collection instead of throwing `ENOENT`. Git cannot store an
1432
empty directory, and a Proof write creates only the directory it writes, so
@@ -29,17 +47,6 @@
2947
incomplete provenance as complete. The error names the record, the relation,
3048
and the missing id. Records written before this release keep any dangling
3149
edge until you repair the file.
32-
- **Breaking for writes:** Proof now rejects create-time `derives_from`,
33-
`supersedes`, and `invalidates` targets from another Effort. The later
34-
`Supersede` and `Invalidate` forms already rejected these edges. Rejected
35-
creates write no record or reverse projection and leave the generation
36-
unchanged.
37-
`flatbread proof relations` now reports stored legacy or hand-edited foreign
38-
edges as `PROOF_CROSS_EFFORT_RELATION` instead of dropping them into a
39-
successful empty page.
40-
41-
Notes for the Flatbread release train. Some packages also keep their own
42-
changelog; this file covers the repository as a whole.
4350

4451
## 1.0.0
4552

0 commit comments

Comments
 (0)