Skip to content

fix: guardrail against inventing an async trigger; route to work-story (#82) - #83

Merged
atamanvega merged 1 commit into
mainfrom
fix/no-fabricated-automation
Sep 22, 2026
Merged

atamanvega merged 1 commit into
mainfrom
fix/no-fabricated-automation

Conversation

@atamanvega

Copy link
Copy Markdown
Collaborator

Fixes #82.

The report

A colleague plugged the kit into their project (on Codex), used plan-backlog to create a GitHub backlog, then asked the agent to build it. Instead of routing to work-story, the agent fabricated an async, Actions-driven mechanism the kit doesn't have: /builder issue comments, self-assignment on #2/#8/#10, and a non-existent codex-builder.yml it then reported as "missing" (recommending an OPENAI_API_KEY secret + a workflow). grep across the repo confirms none of /builder / codex-builder.yml / issue-comment triggers exist in the kit — pure hallucination, pattern-matched from other products.

The fix — guardrail that routes, not just forbids

A "how work is triggered" section added to:

  • agents/coding-agent.md
  • codex/skills/work-story/SKILL.md (portable)
  • skills/plan-backlog/SKILL.md §7 handoff
  • agents/backlog-planner.md handoff

It says: the kit works stories interactively via work-story (one session per story; launch-story to parallelize) — the only trigger it provides; no CI/comment/label/assignment trigger, no workflow runner; never invent or scaffold one (/builder, codex-builder.yml). And crucially it routes: if the repo genuinely has its own async coding agent (a real .github/workflows file, or Copilot's coding agent), point the user to its actual trigger — but only after verifying it exists by reading the repo, never a fabricated one. That async path is the user's own tool, separate from the kit.

Same doctrine the kit already applies elsewhere (don't scaffold silently, verify by reading, no fabricated infrastructure).

Not in this PR

A real opt-in async delegation (hand created issues to a genuine async agent as an alternative to interactive work-story) — bigger, host-specific; separate follow-up.

Verification

  • build → 12 skills @ 0.19.13, validator clean, node --test 35/35, rebuild a no-op, source/bundle byte-identical.
  • Docs: CHANGELOG entry added. Kit → 0.19.13.

Version note: #79 (plan-definition) also carries a 0.19.13 bump on its (unmerged, in-review) branch. These don't touch the same files, so no conflict; whichever lands second re-bumps to 0.19.14 + rebuilds. I'll handle that.

🤖 Generated with Claude Code

#82)

A user with a freshly-created GitHub backlog asked the kit to build it; the
agent invented an async mechanism the kit doesn't have — /builder issue
comments, self-assignment, and a non-existent codex-builder.yml GitHub
Actions workflow it then reported as "missing". None of that exists in the
kit.

Add a "how work is triggered" guardrail to coding-agent, the portable
work-story playbook, and the plan-backlog / backlog-planner handoffs:

- The kit works stories interactively via work-story (one session per
  story; launch-story to parallelize) — the only trigger it provides.
- No CI/comment/label/assignment trigger and no workflow runner; never
  invent or scaffold one (/builder, codex-builder.yml, etc.).
- If the repo genuinely has its own async coding agent (a real
  .github/workflows file, or GitHub Copilot's coding agent), point to its
  real trigger only after verifying it exists — never a fabricated one.

A real opt-in async delegation is tracked as a separate follow-up.

Bundle rebuilt; validator + 35 tests pass. Kit → 0.19.13.

Note: #79 (plan-definition) also carries a 0.19.13 bump on its branch; if
this lands first, #79 re-bumps to 0.19.14 before merging.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@vercel

vercel Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
claude-dev-kit-telemetry-relay Ignored Ignored Preview Sep 22, 2026 7:40am UTC

Request Review

@atamanvega
atamanvega merged commit 80db7cb into main Sep 22, 2026
3 checks passed
@atamanvega
atamanvega deleted the fix/no-fabricated-automation branch September 22, 2026 07:48
atamanvega added a commit that referenced this pull request Sep 28, 2026
…, v1) (#91)

* feat(po): delegate-backlog — async fan-out to Copilot coding agent (#84, v1)

The async, throughput-first alternative to running work-story per story:
hand an approved backlog to a real async agent (GitHub Copilot coding
agent) so several stories build in parallel (one branch/PR per issue),
then re-apply the kit's quality via pr-review/fix-pr on the PRs that
come back.

Honest about the trade-off: the kit's in-session gates don't run on the
delegated path (re-applied on review), it verifies Copilot coding agent
is actually enabled before delegating (never fabricates a trigger —
#82/#83 doctrine), reads back the assignment and captures the real PR
(never invents a number — #85), tracks issue->branch->PR in a run
manifest, and never auto-merges.

Ships the same trio as the other PO features:
- skills/delegate-backlog/SKILL.md (portable)
- commands/delegate-backlog.md (Claude command)
- agents/backlog-delegator.md (orchestrator; skills: delegate-backlog,
  pr-review, fix-pr)

v1 is GitHub + Copilot only; other async targets are a later step. From
@hmamonk17's demand and the RFC in #84.

Bundle rebuilt (14 skills); validator + 35 tests pass. Kit -> 0.19.18.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(po): address self-review findings on delegate-backlog (#91)

From the kit's own pr-reviewer pass (APPROVE, non-blocking):
- Make the "experimental" maturity signal uniform (was README-only) —
  add it to the skill intro and the CHANGELOG entry.
- Add dev-kit-setup to backlog-delegator's skills list, matching its
  sibling backlog-planner, so a repo without .claude/dev-kit.json has a
  bootstrap path.
- Clarify the dependency-hold line: a held dependent waits on the user
  merging the prerequisite PR (the kit never auto-merges), so say it's
  waiting rather than letting it stall silently.

Bundle rebuilt; validator + 35 tests pass. Kit stays 0.19.18.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Atamán Vega <atamanvega@Atamans-MacBook-Pro.local>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix: agent invents a /builder + GitHub Actions async trigger instead of routing to work-story

1 participant