Skip to content

feat: enforce cloud banking agent skills - #19

Open
EstandarMustaq wants to merge 3 commits into
mainfrom
feat/cloud-banking-agent-skills
Open

EstandarMustaq wants to merge 3 commits into
mainfrom
feat/cloud-banking-agent-skills

Conversation

@EstandarMustaq

@EstandarMustaq EstandarMustaq commented Jul 16, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Adds the canonical MAVULA cloud-banking engineering skill and strengthens the review skill
  • Routes Codex, Cursor, and GitHub Copilot through the same repository-local policy
  • Enforces canonical agent files in the workbench guardian

Scope

The policy covers module ownership, real banking operations, security and regulation, governed no-code configuration, cloud-native scale, and TypeScript, Go, Java, COBOL, Python, PostgreSQL, and Redis engineering rules.

Validation

  • Module guardian passes
  • Canonical skill synchronization passes
  • Root master guardian and contract checks pass

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 413d2d2c06

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/check-agent-policy.mjs Outdated
import { spawnSync } from "node:child_process";

export const canonicalAgentFiles = Object.freeze([
".agents/AGENTS.md",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Enforce the agent entry point at repo root

When Codex is working on src/, scripts/, or other repo files, an AGENTS.md under .agents/ is out of scope because AGENTS instructions apply only to the directory subtree containing the file. This makes the new guardian bless an entry point that only affects edits inside .agents, so the intended repo-wide cloud-banking/review routing is not applied to normal changes; require a root AGENTS.md instead, or add one in addition to this canonical copy.

Useful? React with 👍 / 👎.

Comment on lines +34 to +36
for (const file of required) {
if (!trackedFiles.has(file)) failures.push(`${file} must be tracked`);
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Validate canonical policy contents, not just paths

When a later change rewrites one of the required skill files while keeping the same tracked path, this loop still passes because it only verifies that the path is present in git ls-files; I confirmed node scripts/guardian.mjs succeeds after replacing .agents/skills/mavula-review/SKILL.md with a stub containing only the skill name. That leaves the new guardian unable to enforce the canonical review/security gates it is meant to protect, so it should compare expected content/digests or at least assert the required sections and hard-rule text for each canonical file.

Useful? React with 👍 / 👎.

Comment on lines +18 to +20
export const canonicalAgentAdapters = Object.freeze([
".cursor/rules/mavula-engineering.mdc",
".github/copilot-instructions.md",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Block path-specific Copilot instructions

For GitHub Copilot contexts that load path-specific repository instructions, GitHub documents .github/instructions/**/*.instructions.md as an additional instruction source (https://docs.github.com/en/copilot/reference/custom-instructions-support), but this adapter list only canonicalizes .github/copilot-instructions.md. I confirmed a tracked .github/instructions/unsafe.instructions.md with applyTo: "src/**" passes node scripts/guardian.mjs, so a later change can add conflicting Copilot guidance for production files while the guardian still reports the repository-local policy is enforced.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6d9d77e2fc

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

if (file.startsWith(".agents/") && !allowedAgents.has(file)) {
failures.push(`${file} is not part of the canonical agent policy`);
}
if (file.startsWith(".cursor/rules/") && file !== canonicalAgentAdapters[0]) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Block legacy Cursor root rules

Because this check only rejects extra files under .cursor/rules/, a tracked root .cursorrules file can add conflicting Cursor instructions while node scripts/guardian.mjs still passes; I verified this in a detached worktree with a staged .cursorrules. Cursor still treats that file as an instruction source for now—the upstream Cursor forum quotes the docs saying the root .cursorrules file is legacy and adds that it “should still work for now” (https://forum.cursor.com/t/project-rule-in-cursorrules-not-applied-in-agent-chat-works-in-cursor-rules/154309)—so the claimed canonical Cursor policy is not actually enforced unless .cursorrules is also blocked or canonicalized.

Useful? React with 👍 / 👎.

if (file.startsWith(".cursor/rules/") && file !== canonicalAgentAdapters[0]) {
failures.push(`${file} is not part of the canonical Cursor policy`);
}
if (file.startsWith(".github/instructions/")) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Block VS Code Copilot instruction sources

This only rejects .github/instructions/ as an alternate Copilot instruction location, but VS Code's official custom-instructions docs also load workspace CLAUDE.md/.claude/rules and allow workspace settings such as github.copilot.chat.reviewSelection.instructions and chat.instructionsFilesLocations (https://code.visualstudio.com/docs/agent-customization/custom-instructions). I confirmed a staged CLAUDE.md plus .vscode/settings.json with conflicting review instructions still passes node scripts/guardian.mjs, so a later PR can override the canonical Copilot review policy while CI remains green.

Useful? React with 👍 / 👎.

@EstandarMustaq

Copy link
Copy Markdown
Contributor Author

As observações de revisão foram incorporadas. A política agora exige AGENTS.md na raiz, valida digests dos ficheiros canónicos, inclui CLAUDE.md canónico e rejeita .cursorrules, regras .claude, instruções Copilot por path, entrypoints aninhados e overrides de instruções no VS Code. O guardian executa quatro testes de mutação e passou localmente.\n\n@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0f8f48be1a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

}
if (file === ".vscode/settings.json") {
const settings = readFileSync(join(root, file), "utf8");
if (/"(?:chat\.instructionsFilesLocations|github\.copilot\.chat\.[^"]*\.instructions)"\s*:/.test(settings)) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reject VS Code instruction-disable settings

Fresh evidence beyond the earlier VS Code override comment: the current VS Code AI settings reference lists chat.useAgentsMdFile, chat.useClaudeMdFile, and github.copilot.chat.codeGeneration.useInstructionFiles (https://code.visualstudio.com/docs/agents/reference/ai-settings), but this regex only matches keys containing instructionsFilesLocations or ending in .instructions. I verified a tracked .vscode/settings.json setting those three keys to false still passes node scripts/guardian.mjs, so VS Code/Copilot workspaces can turn off the required AGENTS.md, CLAUDE.md, and Copilot instruction context while the guardian stays green; reject these disabling keys as overrides too.

Useful? React with 👍 / 👎.

@EstandarMustaq
EstandarMustaq requested review from a team and itsgaspr and removed request for a team July 18, 2026 12:08

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0f8f48be1a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +89 to +91
(["AGENTS.md", "AGENTS.override.md"].includes(basename) && file !== "AGENTS.md")
|| (basename === "CLAUDE.md" && file !== "CLAUDE.md")
) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Rejeite entrypoints GEMINI também

Este bloco só rejeita AGENTS.md/AGENTS.override.md e CLAUDE.md; se alguém versionar GEMINI.md na raiz ou num subdiretório, enforceLocalAgentPolicy({ root }) retorna sem falhas, deixando entrar uma fonte alternativa de instruções de agente fora do conteúdo canónico. Como a política agora pretende centralizar os entrypoints de agentes, inclua GEMINI.md nesta validação para evitar overrides que o guardian não detecta.

Useful? React with 👍 / 👎.

Comment on lines +81 to +83
if (file.startsWith(".github/instructions/")) {
failures.push(`${file} is not part of the canonical Copilot policy`);
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Bloqueie skills de Copilot fora do conjunto canónico

Esta validação bloqueia apenas .github/instructions/, mas o Copilot code review também carrega skills de repositório em .github/skills (documentação). Um PR que adicione, por exemplo, .github/skills/code-review/SKILL.md passa por enforceLocalAgentPolicy({ root }) sem falhas e pode introduzir instruções de revisão fora dos skills canónicos de .agents, anulando a política que este guardian tenta impor.

Useful? React with 👍 / 👎.


For architecture, implementation, operations, security, scalability,
composability, and no-code configuration, follow
`.agents/skills/mavula-cloud-banking/SKILL.md`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Inclua os skills canónicos nas instruções Copilot

Este caminho (e o caminho de review abaixo) só é mencionado como texto; nos fluxos Copilot que usam repository instructions, arquivos externos precisam ser incluídos com @ para serem lidos como contexto referenciado, então o agente pode receber apenas este resumo e não as regras canónicas/digestadas que a política tenta impor. Use referências @.agents/... ou mova os gates essenciais para este adaptador.

Useful? React with 👍 / 👎.

) {
failures.push(`${file} conflicts with the root agent entry point`);
}
if (file === ".vscode/settings.json") {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Verifique settings de workspace do VS Code

Ao limitar a inspeção a .vscode/settings.json, o guardian deixa passar um *.code-workspace versionado com settings.chat.instructionsFilesLocations ou github.copilot.chat.*.instructions; ao abrir esse workspace, o VS Code aplica essas instruções alternativas mesmo sem tocar no arquivo aqui verificado. Para manter a promessa de rejeitar overrides de instruções no VS Code, faça o mesmo scan nos arquivos de workspace rastreados.

Useful? React with 👍 / 👎.

@EstandarMustaq
EstandarMustaq requested review from a team, MrDimande, YasserBoaventura and rodri-oliveira-dev and removed request for a team, itsgaspr and rodri-oliveira-dev September 30, 2026 07:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant