diff --git a/corpus/skills/principle-subagent-inherits-scope/SKILL.md b/corpus/skills/principle-subagent-inherits-scope/SKILL.md index f3ee37c0..fde4521c 100644 --- a/corpus/skills/principle-subagent-inherits-scope/SKILL.md +++ b/corpus/skills/principle-subagent-inherits-scope/SKILL.md @@ -62,8 +62,33 @@ the work in a single round trip. until verified — `engine/hooks/agent-relay-attribution` flags the shape. - **State the scope in the prompt, not in your head.** An unstated boundary is not inherited. Name the files, the write authority, and the question. +- **A brief carries three things, not two: facts, the question, and + decisions.** A decision the user already made is neither a fact to weigh + nor a question to answer. Relay it as a constraint sentence that says it is + settled — "the toggle gates the re-injection, not the emission; that is + decided, do not re-open it." Filed under the question, it reads as + something to work out, and a subagent that re-opens it looks rigorous while + discarding the only part the user owned outright. Repeating the user's + words is not enough on its own: a brief can carry the requirement verbatim + and still lose it by appending one open question beside it. - **Don't prime the answer.** Hand over the facts and the question. A - subagent told what you expect finds roughly that. + subagent told what you expect finds roughly that. This governs findings, + never decisions. Leaving out a decision the user already made is not + neutrality — it is dropping a constraint, and the anti-priming rule then + rewards re-opening it. + +Prior art for the third slot: Orlena Gotel and Anthony Finkelstein, "An +analysis of the requirements traceability problem", Proc. IEEE International +Conference on Requirements Engineering, https://doi.org/10.1109/ICRE.1994.292398 +— pre-requirements-specification traceability exists so a requirement keeps +its link to the stakeholder who set it; without that link it gets +renegotiated by people who do not own it. Read this citation as +single-source: Crossref's `issued` field for the record is null, so the 1994 +date is inferred from the DOI string and the conference rather than confirmed +by metadata, and Crossref renders the second author as "C.W. Finkelstein" +while the paper is normally cited as Anthony Finkelstein. IEEE Xplore +returned an empty body and ACM DL returned 403, so no publisher page was +read. ## Related diff --git a/corpus/skills/principle-subagent-inherits-scope/tests/fires_example.md b/corpus/skills/principle-subagent-inherits-scope/tests/fires_example.md index 0414e076..e1c0c997 100644 --- a/corpus/skills/principle-subagent-inherits-scope/tests/fires_example.md +++ b/corpus/skills/principle-subagent-inherits-scope/tests/fires_example.md @@ -23,3 +23,18 @@ and conventions are not concurrency control, so a read-only brief is not filesystem isolation. A subagent told to write files runs in its own worktree even when the rest of the prompt defaults to read-only, and the parent that omitted one has not stated the boundary at all. + +A third shape, the one the decisions slot exists for. The user has already +decided which stage a new toggle gates. The parent relays that requirement +word for word and then appends "work out what a toggle would actually gate." +A mechanical containment check on the delegation passes — the requirement is +verbatim-contained and every content word is present — and the subagent still +ranks the user's own requirement fourth of six and argues its premise away. +The skill fires here because the decision was relayed as part of the +question instead of as a settled constraint, and because the anti-priming +rule reads re-opening it as rigour. + +No mechanical catch is claimed for that third shape, and the obvious one is +known not to work: the containment check returns PASS on the exact +delegation that drifted, because the words were all there. The gate is the +parent's wording, so this stays an `unchecked` case pinned by prose. diff --git a/corpus/skills/principle-subagent-inherits-scope/tests/stays_silent_example.md b/corpus/skills/principle-subagent-inherits-scope/tests/stays_silent_example.md index 4dcd585d..0dbd6090 100644 --- a/corpus/skills/principle-subagent-inherits-scope/tests/stays_silent_example.md +++ b/corpus/skills/principle-subagent-inherits-scope/tests/stays_silent_example.md @@ -8,3 +8,11 @@ whose authority could exceed the parent's. The principle has no target: its four limits all describe what a delegate may do, and the contradiction contract describes how a delegate reports back. A single agent editing one file on its own behalf is the case this principle is not about. + +A second silent shape, against the decisions slot. A parent hands an explorer +a read-only brief that names the files, the question, and one settled +decision relayed as a constraint the explorer may not re-open. The explorer +reads those files, answers the question, and reports one contradiction with a +`file:line` and the ref it was read at, leaving the decision alone. Nothing +here is a widening: the boundary was stated, the constraint travelled as a +constraint, and the contradiction went back up rather than being acted on.