-
Notifications
You must be signed in to change notification settings - Fork 0
docs(agents): replace Platform Context with public build-agent rules #45
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
@@ -17,18 +17,55 @@ See `README.md` for setup. Run the repo's lint / typecheck / test before opening | |||||||||||||
|
|
||||||||||||||
| Report vulnerabilities via the [Security Policy](https://github.com/wave-av/.github/blob/main/SECURITY.md) (security@wave.online) — never in a public issue. | ||||||||||||||
|
|
||||||||||||||
| # Platform Context | ||||||||||||||
| ## Public Repository Rules for Build Agents | ||||||||||||||
|
|
||||||||||||||
| You are working inside the WAVE platform (wave-av org, 157 repos). Before acting: | ||||||||||||||
| This repository is public. Anything written here — PR titles, PR bodies, commit messages, | ||||||||||||||
| comments, issues, and file content — is permanent and world-readable, including after edits | ||||||||||||||
| or deletes. Treat every write as if a competitor, reporter, or attacker is reading it, because | ||||||||||||||
| they can. | ||||||||||||||
|
|
||||||||||||||
| 1. **The registry is the SSOT.** Query it via `@wave-av/registry-sdk` or the REST API at `https://goqtrxgdmaqojmixradj.supabase.co/rest/v1/<table>`. Tables: models, tools, vendors, products (25+ with data planes), deliverables, tests, prose, usage_logs. | ||||||||||||||
| 2. **Five physics laws gate everything** in CI: gauge-invariance (no raw slug), frame-independence (scores inherited), conservation-of-declaration (four renderings), entropy-monotonicity (nothing unregistered), token-budget-conservation. | ||||||||||||||
| 3. **The full fleet map** lives at `governance/plans/session-deliverable-registry/PLATFORM-MAP.md` in claude-workstation (157 repos by kind: core/spoke/ssot/tool/sdk). | ||||||||||||||
| 4. **The 24-axis model taxonomy** lives at `wave-foundation/frameworks/model-routing/champions.json` (calibrated_at 2026-08-24). | ||||||||||||||
| 5. **The inference pool** runs on our rigs at `http://<fleet-internal-address>:8800/v1` (internal, $0). Frontier fallback via openrouter/anthropic. The rail field on models tracks internal vs customer. | ||||||||||||||
| 6. **The voice laws**: no em-dashes, every word earns its place, short words over long, active voice, receipt over adjective. Enforced by voice-gate.mjs. | ||||||||||||||
| 7. **The test-matrix**: every shipped artifact carries unit/integration/smoke/e2e/probe receipts in the tests table. No test, no ship. | ||||||||||||||
| Before writing anything, apply these rules: | ||||||||||||||
|
|
||||||||||||||
| 1. **Write for strangers.** Every title, message, and doc must make sense to an outside | ||||||||||||||
| developer and contain only what an outside developer should know. Ask: would this sentence | ||||||||||||||
| mean anything to someone who has never seen the private side of this project? | ||||||||||||||
|
|
||||||||||||||
| 2. **No internal identifiers.** Never paste an internal ticket or tracking code, a decision | ||||||||||||||
| record id, a gate or scorecard name, an internal workstream or plan id, or a reference to an | ||||||||||||||
| internal build or process-automation tool. Describe the user-facing change (for example, | ||||||||||||||
| "fix canary marker matching"), never the internal ticket that asked for it. | ||||||||||||||
|
|
||||||||||||||
| 3. **No internal topology.** Never name a private repository, an internal hostname or | ||||||||||||||
| subdomain, a staging/dev/preview environment, an internal tool, or an internal document | ||||||||||||||
| path. Even a bare cross-reference to a private repo is still naming it on a public surface — | ||||||||||||||
| describe the dependency in product terms or leave it out. | ||||||||||||||
|
Comment on lines
+38
to
+41
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Suggestion: These blanket prohibitions conflict with the repository's existing operational guidance, which names tools and automation already required for agents to follow. [api mismatch] Assessment: 🟠 Prompt for AI Agent 🤖This is a comment left during a code review.
**Path:** AGENTS.md
**Line:** 38:41
**Comment:**
*Api Mismatch: These blanket prohibitions conflict with the repository's existing operational guidance, which names tools and automation already required for agents to follow.
Validate the correctness of the flagged issue. If correct, How can I resolve this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask user if the user wants to fix the rest of the comments as well. if said yes, then fetch all the comments validate the correctness and implement a minimal fix |
||||||||||||||
|
|
||||||||||||||
| 4. **No approval status.** Never describe who approves what, what is decided versus pending, a | ||||||||||||||
| confidence score, or that a change is waiting on someone's sign-off. Public PRs and issues | ||||||||||||||
| should stand on their own technical merits. | ||||||||||||||
|
Comment on lines
+43
to
+45
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win Limit Rule 4 to internal approval status. The phrase “what is decided versus pending” is not scoped to internal decisions. It can cause agents to suppress relevant public CI or review status. Use the following wording: Proposed wording-4. **No approval status.** Never describe who approves what, what is decided versus pending, a
- confidence score, or that a change is waiting on someone's sign-off. Public PRs and issues
- should stand on their own technical merits.
+4. **No internal approval status.** Never describe internal approvers, internal decision status,
+ confidence scores, or internal sign-off. Public CI and public review status may be reported
+ when relevant to the change. Public PRs and issues should stand on their own technical merits.📝 Committable suggestion
Suggested change
🤖 Prompt for AI Agents |
||||||||||||||
|
|
||||||||||||||
| 5. **No internal operations detail.** Never describe an internal automation contract, a | ||||||||||||||
| permission rule, a secrets inventory, review-bot internals, an internal briefing document, a | ||||||||||||||
| local checkout or working-directory path, a session or lane identifier, or CI internals | ||||||||||||||
| beyond what any ordinary open-source project would publish. | ||||||||||||||
|
|
||||||||||||||
| 6. **No people.** No personal names tied to a process decision ("X approved this", "per X's | ||||||||||||||
| directive"), and no personal email addresses anywhere. Use this project's bot or no-reply | ||||||||||||||
| identity for commit authorship. | ||||||||||||||
|
Comment on lines
+52
to
+54
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win Add explicit personal-information coverage to Rule 6. Rule 6 covers only process-related names and personal email addresses. Add phone numbers, usernames, addresses, customer identifiers, and other personal information. 📝 Committable suggestion
Suggested change
🤖 Prompt for AI Agents |
||||||||||||||
|
|
||||||||||||||
| 7. **No security internals.** Report vulnerabilities privately per this repo's SECURITY.md — | ||||||||||||||
| never describe incident details, after-action reviews, or how a fix was rolled out in | ||||||||||||||
| public text. Naming a public CVE in a routine dependency bump is fine. | ||||||||||||||
|
|
||||||||||||||
| 8. **No secrets.** Never write a key, token, or credential into any public surface — not even | ||||||||||||||
| an "example" one that looks plausible. Secret scanning may catch it, but you are the first | ||||||||||||||
| line of defense. | ||||||||||||||
|
|
||||||||||||||
| 9. **If it can't be described without an internal fact, it isn't a public change.** Say so and | ||||||||||||||
| stop, and route the work through the appropriate internal channel instead. Don't launder the | ||||||||||||||
| fact into a vague euphemism — just don't publish it. | ||||||||||||||
|
|
||||||||||||||
| **When in doubt, treat it as internal.** Ask before publishing anything borderline. | ||||||||||||||
| ## CONTENTS | ||||||||||||||
|
Comment on lines
+68
to
69
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 💡 Quality: Missing blank line before ## CONTENTS headingThe new closing line "When in doubt, treat it as internal...." is immediately followed by Was this helpful? React with 👍 / 👎 |
||||||||||||||
|
|
||||||||||||||
| WAVE examples | ||||||||||||||
|
|
||||||||||||||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
P3: The opening overstates GitHub's retention guarantees by saying all writes remain permanent and world-readable after edits or deletes. GitHub allows comments and sensitive edit-history revisions to be deleted, so say to treat content as potentially public and persistent instead of asserting this as universal fact.
Prompt for AI agents