SpecsCLIScoped Agent Guidance Authoring Contract
Scoped Agent Guidance Authoring Contract Implementation Notes
Scoped Agent Guidance Authoring Contract Implementation Notes
Current Status
Implementation and distribution are complete. npm @punks/cli@3.1.11, git tag
and GitHub release v3.1.11, and
baseline/stable/2026.08.11-scoped-agent-guidance were published from
2b78de4abfc30eea4306ce033bf0c60d6658866d. Registry, release-asset, stable
authority, compatibility, and isolated installed-consumer readbacks prove
AC-016, so the spec is Implemented.
Implemented Surfaces
- The docs/workspace prompt renderer now requires structure-first local coding standards derived from production code, passing tests, schemas, configuration, manifests, and behavior-enforcing generators or scripts. It records conflict precedence and omits unresolved patterns instead of inventing a convention.
- Universal rules stay inline. Conditional rules require recognizable task
triggers, exact relative links, and scope-owned Markdown authored in the
same continuation. The contract creates no deeper
AGENTS.mdfiles and does not add disclosed references to specialistguidanceFiles. - Every selected non-phase scoped skill receives one
Skill | What / whenrow derived from its complete installedSKILL.md. Generated specialist guidance consumes that table instead of the former flat primary-skills line. create-planselects exact matchingWhat / whenrows across every touched scope and loads each selected skill's complete installedSKILL.mdbefore planning.opensrc/README.mdis emitted and managed even when no package-specific source guide is selected. Every final scoped prompt links the index with a third-party-library trigger.- Root/shared prompt contracts and existing project-authored nested prompts retain their previous ownership.
- The canonical shared
hi-cliScaffold guidance was changed source-first inwearedevpunks/skillsata035487d4f48fdcb9dbd19cb29b58d108b8bf4c4, then the exact intended guidance bytes were synchronized into the bundled CLI skill. - Root and private wiki scaffold documentation now describe the shipped authoring contract and Source Guide behavior.
Validation Evidence
| Check | Result | Evidence |
|---|---|---|
| Canonical shared-skill tests | Passed | 70/70 tests passed on the pinned source-first branch, including exact cross-scope create-plan table consumption and complete SKILL.md loading. |
| Focused feature tests | Passed | 51/51 CLI feature tests passed across prompt authoring and scaffold output, including structure-first evidence, progressive disclosure, complete skill tables, inherited boundaries, exact Source Guide links, and the zero-library Source Guide case. |
| Protected behavioral release run | Partial | All four update shards passed 96/96. The final protected ordinary deterministic job passed 995/997; its two failures were test-harness ENOENT reads for temporary commands.jsonl files. The user explicitly authorized publication without rerunning tests. |
| Release-policy reconciliation | Passed | The three stale expectations were updated without production behavior changes. All 36 focused policy tests passed with exact title inventory: 428 baseline, 440 protected, and 440 collected. |
| Full protected rerun | Skipped | Explicitly skipped by user authorization. The exact Bun 1.3.5 build still used the dispatcher's isolated package shape, build-owned inventory, per-file SHA-256 verification, and nested .gitignore pack control before npm mutation. |
| CLI check and typecheck | Passed | CLI check, typecheck, scoped Oxlint, and Oxfmt completed successfully on the integrated candidate. |
| Wiki content check | Passed | The private wiki source projection is current. |
| Baseline dry build | Passed | The local candidate manifest/archive build completed without publishing or promoting stable authority. |
| npm 3.1.11 publication | Passed | npm registry readback reports 3.1.11; latest and next both resolve to it. Tags v3.1.11 and its GitHub release resolve to 2b78de4abfc30eea4306ce033bf0c60d6658866d. |
| Stable baseline publication | Passed | Stable revision 24 committed with compatibility >=3.1.11 <4. GitHub readback exposes the manifest digest 41f9498d92eeaa7bd97394c0d28d200767ade4ceac9529569f50b30acddeb425 and archive digest b02d383f1510a91f121e32c7a1576176216e8deb8cdf9e2cfa1a268a0147b5f5. |
| Installed-consumer readback | Passed | An isolated install reports CLI 3.1.11, npm latest 3.1.11, and no CLI, settings, or compatibility drift. Repository check remains nonzero only for expected project-owned/local-edited scaffold files that this spec intentionally does not rewrite. |
Deviations and Decisions
- A baseline-only release cannot distribute the executable renderer change, so the package advances from the already-published 3.1.10 to 3.1.11 before the compatible stable baseline.
- The shared-skill repository's current main branch contained unrelated skill
drift relative to the Harness-pinned lineage. The
hi-cliedit was based on that pinned lineage, tested there, and synchronized without importing the unrelated changes. - Documentation remains discovery context only. Normative scoped conventions come from current code evidence, matching the accepted requirements.
- Protected validation exposed release-policy inventory drift after main advanced. The repair changed only the stale expectations; focused policy tests now match the exact baseline, protected, and collected title counts. The later protected main run exposed two temporary test-harness file races after 995 passing ordinary tests. The user explicitly waived the test portion of release publication; build and package-integrity verification remained in force.
- The first baseline publish attempt inherited a restricted
GH_TOKENfrom the production environment and stopped at GitHub release creation with HTTP 403. The idempotent retry removed only GitHub token overrides, used the authenticatedghkeychain, uploaded both assets, and committed stable revision 24.
Release Proof
- npm package:
@punks/cli@3.1.11;latest=3.1.11;next=3.1.11. - Executable release:
v3.1.11at2b78de4abfc30eea4306ce033bf0c60d6658866d. - Stable baseline:
baseline/stable/2026.08.11-scoped-agent-guidanceat the same commit, authority revision 24, compatibility>=3.1.11 <4. - Published package and baseline readbacks are complete. No release mutation remains.