Repository navigation
feat(core): allow explicitly authored empty risk lists - #190
Conversation
pillowtalk-Qy
left a comment
There was a problem hiding this comment.
Hi Box and @rainypilgrimage,
I independently reviewed a2d25655a0ee99a32d6f28780291257390f302df against main@19e602e and the scope accepted in #164. No blocking finding in this change.
The implementation distinguishes an explicit empty array from missing/non-array metadata; the per-member validation also rejects sparse entries and unknown labels. The public field remains required, the type fixtures retain the closed vocabulary, and Registry load() preserves []. The glossary, MCP documentation, onboarding guide/template and Core changeset consistently describe an authored classification, not a guarantee of safety.
The Receipt regression retains the original inbound/outbound Changes and demonstrates that contrary evidence refutes the declaration. It does not introduce a new runtime risk detector or change downstream adapters, which matches the agreed scope.
Independent verification on this exact head:
- frozen install; lint; full workspace build and typecheck;
git diff --check: pass; pnpm test:offline: 685 passed / 42 skipped;- Core: 73/73; MCP: 22/22;
pnpm -r --no-bail test: completed, with 18 workspace commands passing and 2 failing. Aave is 35/36 due to the expired quarantine in #185; Kuru is 85/86 due to the native-swapROUTE_QUOTE_UNAVAILABLEreported in #194. Both also reproduced on unchanged main. Pendle is 155/155.
This approval is for the reviewed Core change; it is not a claim that the full live gate is green or a replacement for maintainer merge/CI decisions. The existing Aave/Kuru failures remain separate follow-ups. No branch changes were made.
- ADR 0003 gains a dated section for the `risk: []` decision (nishuzumi#164): semantics, rejected alternatives (`fundIn`, sentinel, optional field), the authoring rule, and the Receipt-refutation requirement. - AGENTS.md review rule: reject placeholder labels and `risk: []` without no-outbound Receipt coverage. - Onboarding issue template: the rule becomes an HTML comment under the Risk labels column, matching every other guidance line. - Changeset bumps `@themoss/core` as minor, consistent with prior `feat(core)` vocabulary changes; this is an Agent-facing contract change.
|
@rainypilgrimage @pillowtalk-Qy — I audited exact head Rather than another review round, I pushed one follow-up commit
Independent verification on For the downstream owners: Merging once the offline checks report on |
What and why
Closes #164.
Core required every Capability to author
risk, but Registry also rejected an explicit empty list. That forced adapters to publish a known-inaccurate label when the author had reviewed an operation and none of the current closed-set RiskLabels applied.This change allows an explicitly authored
risk: []while keeping the field required. Missing or malformed metadata remains invalid, every non-empty member remains closed-set validated, andload()preserves the authored empty list unchanged.The authoring guidance ships with the contract: contributors should raise a focused Core vocabulary issue when evidence identifies a missing reusable danger semantic, use
[]only after review finds no applicable current category, and request maintainer review when uncertain. Receipt evidence remains authoritative and can refute the declaration.Type of change
Framework and package impact
Registry now accepts an explicitly authored empty risk array while preserving required-field, array-shape, sparse-array, and unknown-label validation. The public
RiskLabel[]shape does not change, andload()returns[]exactly as authored.No new RiskLabel value is added, and no adapter, Simulator, MCP transport, or Monad Runtime behavior is changed. Downstream adoption remains with #158, #187, and the separately coordinated aPriori follow-up.
Verification
pnpm buildpnpm typecheckpnpm lintpnpm testpnpm testcurrently reaches one unrelated Aave mainnet failure:PT_AUSD_8OCT2026 cleared the address-book age guard; vendor it and remove this quarantine. This branch does not modify Aave. The full offline-equivalent workspace run (MOSS_SKIP_E2E=1 pnpm test --reporter=dot) passes.Protocol changes
N/A — this is a focused Core contract change and does not modify a Protocol adapter.
@ts-expect-errorfixtures cover exported type behaviorEvidence
risk: [], reject a missingriskfield, and preserve the closed RiskLabel set.[]and rejects missing, non-array, sparse-array, and unknown-label metadata.load()projects the authored empty list unchanged.nativeTransferChanges, verifies that the inbound case has no account outflow, and demonstrates that outbound evidence refutes the no-outbound claim.CONTEXT.md, MCP documentation, the protocol-onboarding guide and issue template, and an Agent-facing Core patch changeset carry the approved semantics and authoring rule.