Skip to content

fix: point at upstream for doctor prompt-audit write posture and relay turn cost - #5834

Merged
kyle-sexton merged 3 commits into
mainfrom
fix/task-cost-followups
Oct 2, 2026
Merged

kyle-sexton merged 3 commits into
mainfrom
fix/task-cost-followups

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

No related issue: follow-ups found while landing #5827. The two findings that need a design decision are filed as #5832 and #5833.

Summary

  • harness-config:audit-instructions said that /doctor prompt-audit's write posture was undocumented. The upstream memory page now documents it.
  • fleet:reach's relay probe table stated a per-turn dollar figure. It now links the official cost-tracking docs instead.

Fix

Verification

  • scripts/check-changelog-parity.sh --check, --check-bump origin/main, --check-order and --check-preserved origin/main all pass.
  • scripts/check-changed-skills.sh origin/main: 2 skills, 0 errors. The one warning is pre-existing, in the untouched reference/criteria.md.
  • markdownlint-cli2 reports 0 issues on the 5 touched markdown files. typos is clean.
  • run-plugin-tests.sh passes on the 6 audit-instructions suites plus check-doc-citations and check-structure.

Related

🤖 Generated with Claude Code

…y turn cost

harness-config audit-instructions said /doctor prompt-audit's write
posture was undocumented; the memory page now documents it. State our
decision (offer it, never chain into it, edits stay the person's call),
note it needs the bundled claude-api skill, and record the pointer,
as-of date and recheck trigger in reference/native-doctor.md.

fleet reach relay.md stated a per-turn dollar figure; keep what the
cost went to and link the official cost-tracking section instead.

Bump harness-config to 1.3.2 and fleet to 0.2.2.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kyle-sexton
kyle-sexton marked this pull request as ready for review October 2, 2026 16:42
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-02T16:46:10.422475Z 26ae2d4 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 35s —— View job


Code review complete

  • Load /review:code-review instructions
  • Gather PR diff and context
  • Review changed files for correctness/maintainability issues
  • Post findings (inline + summary)

Scope: git diff origin/main...HEAD (7 files, docs/changelog/manifest only — no scripts or
executable code changed).

Findings: None that clear the high-signal bar.

Notes from the review (not blocking):

  • plugins/harness-config/skills/audit-instructions/SKILL.md (doctor Boundary section) drops the
    old "it survives disableBundledSkills" clause while adding the new claude-api dependency
    clause. At first pass this reads like silently-dropped information, but it's actually consistent:
    if prompt-audit now depends on the bundled claude-api skill (itself subject to
    disableBundledSkills), restating an unqualified "survives disableBundledSkills" would be
    misleading for that subcommand. The full detail is still preserved in
    reference/native-doctor.md,
    so this isn't a defect — just worth a sentence in the PR description for the next reader.
  • The new reference/native-doctor.md row (pointer + 2026-10-02 as-of + recheck trigger) conforms
    to the upstream-drift convention's required parts and to
    .claude/rules/skill-bodies-state-current-rules.md.
  • Version sequencing (harness-config 1.3.0 → 1.3.2, intentionally skipping 1.3.1 reserved by
    docs(upstream): answer "What a task costs on Opus 5.5" with routing, observability and pointer updates #5827) is fine under check-changelog-parity.sh: --check-bump only requires strictly-greater
    and newly-added, --check-order only requires no gaps/repeats in heading order, so the skip
    needs no special annotation.
  • plugins/fleet/skills/reach/reference/relay.md and the two CHANGELOG.md/plugin.json pairs
    are straightforward, internally consistent, and match their stated versions.

Author-claimed verification (markdownlint, typos, changelog-parity, check-changed-skills,
run-plugin-tests.sh) was not independently re-run in this review.

@claude

claude Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 39s —— View job


Security review complete

  • Gather context (PR diff, changed files)
  • Apply skip gate
  • Review diff for security-relevant findings (including instruction-surface deletion lens on SKILL.md changes)
  • Post final results

No security issues found.

This PR is documentation/metadata-only: two version bumps (plugin.json), two CHANGELOG.md entries, and three reference/skill doc edits that replace a stated dollar figure and an "undocumented" uncertainty note with links-only pointers to upstream docs (consistent with this repo's upstream-drift convention). No code paths, input handling, auth/access logic, or CI workflow files are touched.

I checked the one text change that could plausibly weaken a guardrail — the doctor Boundary "Mutation gate" line in plugins/harness-config/skills/audit-instructions/SKILL.md:

Old: "Its write posture is undocumented; this skill never chains into /doctor."
New: "Applying its proposed edits is the person's call; never chain into /doctor."

The substantive control — the skill never invokes /doctor itself, only offers it to the person — is unchanged in both versions. The edit only replaces the reasoning (uncertain write posture) with a stated decision now that upstream documents the write posture, per reference/native-doctor.md. No guardrail was removed or narrowed.

No findings to post inline.

Branch ·

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 26ae2d41a1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/fleet/skills/reach/reference/relay.md Outdated
Comment thread plugins/harness-config/skills/audit-instructions/SKILL.md Outdated
…ll body

Review follow-up: the relay Cost row's pointer gains an as-of date and
recheck trigger, and audit-instructions reads /doctor prompt-audit's
gates from the records' pointers instead of listing them.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 3s —— View job


Code review complete

  • Load /review:code-review instructions
  • Gather PR diff and context (git diff origin/main...HEAD, head 8492bdf)
  • Apply skip gate (not a repeat review at this head — a new commit landed since the prior review at 26ae2d4)
  • Review changed files for correctness/maintainability issues
  • Adversarially verify candidate findings
  • Post findings (inline + summary)

Scope: 7 files, docs/changelog/manifest only (no scripts or executable code).

Findings: None that clear the high-signal bar. No inline comments posted.

This commit (8492bdf) is itself a follow-up to the Codex and self-review findings posted
against 26ae2d4 (dropping the hardcoded claude-api gate list from the SKILL.md availability
line, and stamping the relay.md Cost row with an as-of date and recheck trigger). I checked that
the fix is complete and internally consistent rather than re-raising what it already addresses:

  • Verified against the live upstream page
    (code.claude.com/docs/en/memory#audit-your-instruction-files):
    it does state "The audit runs through the bundled /claude-api skill" and that nothing changes
    until the user applies proposed edits, so the claim this PR adds in
    reference/native-doctor.md line 14
    is accurate, not a hallucinated dependency.
  • SKILL.md lines 127-130
    now states the decision and points at the records without re-listing the specific gates, matching
    skill-bodies-state-current-rules.md and the reviewer's "Fix:" comment on 26ae2d4.
  • The harness-config CHANGELOG.md 1.3.2 entry was itself edited in this second commit to drop
    the stale "needs the bundled claude-api skill on" wording, so the changelog and the skill body
    stay in sync.
  • relay.md line 210's
    Cost row now carries its own as-of date and recheck trigger, independent of the section-level
    stamp above the table (which only covers the cli-reference/agent-view pages) — checked against
    the live costs page's "Using the /usage command" section, which is a plausible target for that
    recheck trigger.
  • Version sequencing (harness-config 1.3.0 → 1.3.2, fleet 0.2.1 → 0.2.2) and SKILL.md's line
    count (499, matching the PR description) check out.

Author-claimed verification (markdownlint, typos, changelog-parity, check-changed-skills,
run-plugin-tests.sh) was not independently re-run in this review.
·
Branch

@claude

claude Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 2s —— View job


Security review complete

  • Gather context (PR diff, changed files, HEAD SHA 8492bdf)
  • Invoke /review:security-review and apply its skip gate / instruction-surface lens
  • Post final results

No security issues found.

Scope

git diff origin/main...HEAD (7 files): two plugin.json version bumps, two CHANGELOG.md
entries, and three reference/skill doc edits replacing a stated dollar figure and an
"undocumented" uncertainty note with links-only pointers to upstream docs, per this repo's
upstream-drift convention.
No code paths, input handling, auth/access logic, secrets, or CI workflow files are touched — the
skip gate's "no security-relevant surface" condition applies, except for one instruction-surface
edit checked explicitly below.

Instruction-surface deletion lens

The Boundary section in
plugins/harness-config/skills/audit-instructions/SKILL.md
rewrites the doctor "Mutation gate" and "Availability is never assumed" lines. I checked this
against the instruction exception register's
six protected classes (irreversible-action, secret-handling, data-integrity,
external-publication, legal-compliance, agent-authority):

  • The actual control — this skill is report-only and never invokes /doctor itself, only offers
    it to the person — is preserved word-for-word in substance across old and new text ("this
    skill never chains into /doctor" → "never chain into /doctor").
  • What changed is reasoning, not the rule: the old text hedged on an "undocumented" write posture;
    the new text states a decision now that upstream documents it
    (reference/native-doctor.md#L14),
    and the hard-coded gate list (DISABLE_DOCTOR_COMMAND, skillOverrides, version, bundled
    claude-api dependency) is replaced with "read live from the pointers in the records" — the
    correct shape under .claude/rules/skill-bodies-state-current-rules.md, and the fix the author
    already applied in response to Codex's P2 comment on this same line.
  • No Gate 0 class is weakened; if anything the agent-authority constraint (never chain into
    /doctor) reads more definite than before, not less.

plugins/fleet/skills/reach/reference/relay.md's Cost row (also previously flagged by Codex) now
carries both an as-of date and a recheck trigger, satisfying the pointer convention. The two
CHANGELOG.md/plugin.json pairs are consistent, metadata-only changes.
·
Branch

@claude

claude Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 51s —— View job


Code review complete

  • Load /review:code-review instructions
  • Apply skip gate
  • Gather PR diff and context (git diff origin/main...HEAD, head c42ffad)
  • Review changed files for correctness/maintainability issues
  • Post findings (inline + summary)

Skip gate hit: c42ffad is a merge of main into this branch with no content changes —
git diff 8492bdf..c42ffad -- plugins/fleet plugins/harness-config is empty, confirming the
tree for all 7 changed files is byte-identical to 8492bdf. That commit already received a full
code review from this lane (no findings) plus a security review (no findings), both posted above.
Re-reviewing unchanged content would just restate those results, so per the skip gate ("this head
already has a successful review from this lane that still applies") I'm stopping here rather than
re-litigating.

No new findings. No inline comments posted.

For reference, the substance already covered at 8492bdf:

Author-claimed verification (markdownlint, typos, changelog-parity, check-changed-skills,
run-plugin-tests.sh) was not independently re-run in this review.
·
Branch

@claude

claude Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 58s —— View job


Security review complete

  • Gather context (PR diff, changed files, HEAD SHA c42ffad)
  • Load /review:security-review and apply its skip gate
  • Compare current diff against the last-reviewed commit
  • Post final results

No security issues found — skip gate hit (condition 3: this head already has a successful security review that still applies).

c42ffad is a merge of main into this branch. git diff origin/main...HEAD for this PR is
byte-for-byte identical to git diff origin/main...8492bdf, the commit the security review already
completed and reported clean on (see the two "Security review complete" comments above, at
2026-10-02T16:43:19Z and 2026-10-02T16:48:27Z). The merge brought in unrelated upstream commits
(e.g. a287fa4, fb2a38b, 28c0493, …) but introduced no new changes to this PR's own 7 files:

  • plugins/fleet/.claude-plugin/plugin.json, plugins/fleet/CHANGELOG.md,
    plugins/fleet/skills/reach/reference/relay.md
  • plugins/harness-config/.claude-plugin/plugin.json, plugins/harness-config/CHANGELOG.md,
    plugins/harness-config/skills/audit-instructions/SKILL.md,
    plugins/harness-config/skills/audit-instructions/reference/native-doctor.md

The one instruction-surface edit (the doctor Boundary "Mutation gate" / "Availability is never
assumed" lines in
SKILL.md)
was already checked against the instruction exception register's protected classes in the prior
review and found to preserve the substantive control (never chain into /doctor) while only
replacing hedged reasoning with a stated decision now that upstream documents it — see
reference/native-doctor.md#L14.
No new text to re-check here.

Still a docs/changelog/manifest-only PR: two version bumps, two changelog entries, three
reference/skill doc edits. No code paths, input handling, auth/access logic, secrets, or CI
workflow files touched.
·
Branch

@kyle-sexton
kyle-sexton merged commit 0059cf3 into main Oct 2, 2026
20 checks passed
@kyle-sexton
kyle-sexton deleted the fix/task-cost-followups branch October 2, 2026 16:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant