feat: agent guardrails (verify_commit, dispatch audit, opencode guardrails plugin) #110
Reference in New Issue
Block a user
Delete Branch "feat/agent-guardrails"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
Turns the worker rules that live in prose in
AGENTS.mdinto code a model cannot skip:scripts/verify_commit.py: one command that answers "is this commit good?" (tests the commit touched, run against the committed tree; ruff new-findings gate), a few lines of output.scripts/oc_dispatch_audit.py: audits an orchestrator session'stask()dispatches (dead dispatch, banned agent, missing WORKTREE line, idle child).deploy/opencode-plugin/guardrails.js: an opencode plugin whosetool.execute.beforehook blocks or rewrites tool calls that break the rules, plus aplan_tick_gatethat refuses a plan tick whileverify_commit.pyfails.deploy/opencode-plugin/guardrails-replay.mjs: replays real recorded sessions through the plugin before install, read-only, to calibrate false positives. Results are inplans/agent-guardrails-replay.md.docs/agent-guardrails.md; example config indeploy/opencode-plugin/guardrails.example.json.25 files, +8511 / -0. Nothing under
src/orconfig/changes; the plugin is not installed by this PR (operator step, below).Why
Each rule is the code form of something that broke on this repo: 12 dispatches to
oh-my-claudecode:writerdid no work;task()with no category/subagent_type reported "completed"; a worker with no worktree rewrote the liveconfig.yaml; Atlas pushed and opened a PR unasked; a todo was ticked over 3 failing tests; agit stashmoved the owner's uncommitted changes between worktrees. The evidence table is indocs/agent-guardrails.md.How it was verified
Built through the opencode pipeline (Prometheus plan, Claude review, Atlas execution) over seven audited rounds. Every round's "APPROVE" was re-checked independently, and each audit found defects the previous round missed, so the final state was probed at the real hook boundary rather than trusted from tests:
git archiveextraction of HEAD: 2605 passed.python3 scripts/verify_commit.py --repo <wt> --base origin/main --full HEAD: exit 0 (PASS on tests and lint).node --test deploy/opencode-plugin/: 328 of 328.input = {tool, sessionID, callID},output = {args}) for every defect class found along the way, e.g. a category-onlytaskmust be allowed;grep -n commit AGENTS.md,pytest -k restoreandpython3 -c "... > 300"must not be mistaken for git operations or redirects;git -c k=v commit,env VAR=x git stashandgit commit -a -m xmust still block.bash_protected_porthas zero blocks.Known gaps (accepted, documented)
bash -c '...'/sh -c '...'wrappers are not inspected.localhost:8080is blocked bybash_protected_port.cdchain after an absolute one can be mis-anchored (1 replay block).Operator steps after merge (not part of this PR)
cp deploy/opencode-plugin/guardrails.js ~/.config/opencode/plugins/andcp -n deploy/opencode-plugin/guardrails.example.json .omo/guardrails.json.failed to load plugininopencode.logif not).block; set a rule towarnoroffin.omo/guardrails.json. Considerwarnonbash_main_checkoutfor the first week and watch.omo/guardrails.log.Merge advice
History has warts from the pipeline (an add and remove of two
.omc/state files, three duplicate F841 commits, a few style commits). Squash merge is the cleaner landing; a merge commit works too.🤖 Generated with Claude Code
https://claude.ai/code/session_01KkCGRantZsSwmcFpet6FTa
Defects fixed: - (k) Rewrite targets output.args.prompt, not output.prompt - (l) Prepended line uses actual main checkout directory, not parent of worktree - (m) Parser accepts 'path. cd there', 'path -- cd there', 'path' forms; dotted paths (e.g. feat.v2) are no longer truncatedfix(opencode-plugin): replay reads the real opencode API; add the real calibration reportto fix(opencode-plugin): replay isolation, omoDir, ruleId enrichment, per-session scopefix(opencode-plugin): replay isolation, omoDir, ruleId enrichment, per-session scopeto feat: agent guardrails (verify_commit, dispatch audit, opencode guardrails plugin)