Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 8 additions & 9 deletions .agents/skills/project-management/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,15 +38,14 @@ Do not overwrite or repurpose an existing path.
The registry records the project's standing posture, which is the captain's default for the work rather than any task's answer; `AGENTS.md` section 7 owns how each task's concrete mode and yolo are resolved at intake and passed explicitly to the brief, the spawn, and any promotion.
Choose that posture when adding or creating the project:

- `no-mistakes` runs the full validation pipeline before a PR.
- `direct-PR` pushes and opens a PR without the no-mistakes pipeline.
- `local-only` has no required remote or PR and lands only through the approved local fast-forward path.
- `no-mistakes-prod-only` is a conditional policy rather than one flat mode: genuinely internal-only tooling, automation, contributor or operator process, and release or submission work ships `direct-PR`, while product-facing, mixed, and uncertain work ships `no-mistakes`.
- `no-mistakes` runs the full validation pipeline before a PR, and is registered only when the captain asks for it.

`no-mistakes-prod-only` is the default for a newly added or created remote-backed project when the captain specifies nothing, and a project with no remote defaults to `local-only`.
State that resolved default while confirming the source, local name, and posture instead of asking the captain to choose from scratch, and record a flat mode instead whenever they ask for one.
Existing registry entries keep the meaning they already have and are never migrated or reinterpreted, so a legacy entry with no bracket stays `no-mistakes`.
Registering a conditional policy is a one-time choice and never requires classifying any change; the per-task surface classification happens at each task's intake, and internal-only is never inferred from file location or project name.
For now, `direct-PR` is the default for a newly added or created remote-backed project, and a project with no remote defaults to `local-only`.
State that resolved default while confirming the source, local name, and posture instead of asking the captain to choose from scratch.
Never register a project as `no-mistakes` or `no-mistakes-prod-only` unless the captain asks for that posture.
The conditional `no-mistakes-prod-only` posture is retired: existing entries were converted to `direct-PR`, and a legacy entry that still carries it, or has no bracket, now reads as `direct-PR`.

The optional `+yolo` posture changes merge authority only and does not change the delivery mode.
Default it off for every project and every posture, and enable it only on the captain's explicit instruction.
Expand All @@ -56,14 +55,14 @@ Default it off for every project and every posture, and enable it only on the ca

Confirm the source URL, local project name, delivery posture, and autonomy posture, stating the resolved default for each rather than asking the captain to invent one.
Clone into `projects/<name>` and add the registry entry only after the destination is known to be unused.
A `no-mistakes` or `no-mistakes-prod-only` project must have an `origin` remote and must complete the initialization procedure below, because a conditional policy's product-facing work runs the pipeline while its internal-only work still takes the direct PR.
A `direct-PR` project needs an `origin` remote but skips no-mistakes initialization.
A `no-mistakes` project, registered only at the captain's request, must have an `origin` remote and must complete the initialization procedure below.
A `local-only` project may have no remote and skips no-mistakes initialization.

## Create a project

Creating a GitHub repository is outward-facing.
Before making that remote change, propose the repository name, owner or organization, visibility, and delivery posture, defaulting visibility to private and the posture to `no-mistakes-prod-only`, then obtain the captain's explicit consent for those exact values; a stated default never replaces that consent.
Before making that remote change, propose the repository name, owner or organization, visibility, and delivery posture, defaulting visibility to private and the posture to `direct-PR`, then obtain the captain's explicit consent for those exact values; a stated default never replaces that consent.
Use `gh-axi` for the approved GitHub operation and consult its current help rather than relying on remembered flags.
After remote creation succeeds, clone it locally, add the registry entry, and initialize it according to its delivery posture.

Expand All @@ -72,7 +71,7 @@ The captain's request to create that local project authorizes this local initial

## Initialize

Run no-mistakes initialization only for `no-mistakes` and `no-mistakes-prod-only` projects:
Run no-mistakes initialization only when the captain has asked for it, either for a project registered as `no-mistakes` at the captain's request or on a direct request to initialize one:

```sh
cd projects/<name> && no-mistakes init && no-mistakes doctor
Expand Down
8 changes: 4 additions & 4 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ You may maintain this repo's private operational state directly.
Shared tracked material is `AGENTS.md`, `README.md`, `CONTRIBUTING.md`, `.tasks.toml`, `.github/workflows/`, `bin/`, `.agents/skills/`, and public `skills/`.
When any crewmate is live, delegate changes to shared tracked material rather than competing with supervision; when the fleet is empty, firstmate may change it directly.
This repo is a shared template, while `.env`, `data/`, `state/`, `config/`, `projects/`, and `.no-mistakes/` are captain-private and gitignored.
Ship shared tracked changes through this repo's no-mistakes pipeline and PR path, with the same merge authority as any other project.
Ship shared tracked changes through a PR on the delivery path section 7 selects, with the same merge authority as any other project.
Never add an agent name as a commit co-author.

## 2. Layout and state
Expand Down Expand Up @@ -311,8 +311,8 @@ Load `diagnostic-reasoning` before scoping a reported bug and before acting on a
Resolve every ship task's concrete delivery mode and `yolo` merge posture at intake.
Pass the mode explicitly to the brief, and pass both values explicitly to the spawn and any scout promotion; each command refuses to guess the values it consumes.
A current explicit captain instruction wins; otherwise the project's registry entry is the captain's standing posture, and dropping below its rigor needs a reason you can state.
On a `no-mistakes-prod-only` project, classify the task's surface: internal-only tooling, automation, contributor or operator process, and release or submission work ships `direct-PR`, while product-facing, mixed, and uncertain work ships `no-mistakes`; never infer internal-only from file location or project name.
An unregistered project or absent registry resolves to `no-mistakes` with yolo off, and the registration gap goes to the captain.
For now, firstmate never selects `no-mistakes` itself, for any project or kind of change: a task ships `no-mistakes` only when the captain explicitly requests it for that task or asked to register it as the project's posture, and otherwise ships `direct-PR`, or `local-only` for a project with no remote.
An unregistered project or absent registry resolves to that same default with yolo off, and the registration gap goes to the captain.
Record the resulting mode, `yolo` merge posture, and the one-line reason for any deviation in the backlog item note.

Treat file or subsystem overlap as a risk signal rather than an automatic reason to wait, and dispatch isolated work immediately with no concurrency cap when each change can be independently implemented and validated and the selected delivery path can reconcile ordinary rebases or conflicts.
Expand Down Expand Up @@ -343,7 +343,7 @@ The selected delivery path owns its own rigor.
When no-mistakes is selected, no-mistakes alone owns review, fixes, tests, documentation, push, PR, and CI; otherwise follow the faster path without adding an independent reviewer.
Never hold work outside no-mistakes for a manual clean verdict, stack serial manual reviews, or infer authority for one from security, architecture, or risk alone.
A separate review or audit is allowed only when the captain explicitly requests that deliverable or the authorized task is a knowledge-only review; one named question remains scoped to that question.
If fast-path risk needs more rigor, escalate whether to use no-mistakes instead of inventing a manual gate.
If fast-path risk needs more rigor, ask the captain whether to request no-mistakes instead of inventing a manual gate.
The path's worker, automated gates, and captain approval remain authoritative:

- **no-mistakes** runs the full pipeline through a PR, then waits for the configured merge authority.
Expand Down
2 changes: 1 addition & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ Coordinate any workflow rollback with its required-check names so a retired chec

## Development

Tracked changes to firstmate itself - `AGENTS.md`, `README.md`, `CONTRIBUTING.md`, `.tasks.toml`, `.github/workflows/`, `bin/`, `.agents/skills/`, and `skills/` - ship through the `no-mistakes` pipeline on a feature branch and require an explicit merge approval.
Tracked changes to firstmate itself - `AGENTS.md`, `README.md`, `CONTRIBUTING.md`, `.tasks.toml`, `.github/workflows/`, `bin/`, `.agents/skills/`, and `skills/` - ship through a PR from a feature branch on the delivery path `AGENTS.md` section 7 selects - `direct-PR` unless the captain requests the `no-mistakes` pipeline - and require an explicit merge approval.
Before making any such change, load the agent-only `firstmate-coding-guidelines` skill (`.agents/skills/firstmate-coding-guidelines/SKILL.md`).
It has the knowledge-placement rules that keep `AGENTS.md` from regrowing after each diet pass.
There is no reliable way for `bin/fm-brief.sh`'s scaffold to detect that a task's repo is firstmate itself, so firstmate adds this skill's load line to firstmate-repo briefs by hand.
Expand Down
6 changes: 3 additions & 3 deletions bin/fm-brief.sh
Original file line number Diff line number Diff line change
Expand Up @@ -45,8 +45,8 @@
# direct-PR implement -> push + open PR via gh-axi (no pipeline) -> configured merge authority
# local-only implement on branch, stop and report "ready in branch" (no push/PR);
# the configured merge authority approves, firstmate merges to local main
# no-mistakes-prod-only is a registry policy, not a task mode; resolve it to one of
# the three concrete modes at intake before calling this script.
# no-mistakes-prod-only is a retired registry value, not a task mode; pass one of
# the three concrete modes resolved at intake.
# The generated ship brief records the chosen mode as a fixed machine-readable
# "Delivery contract: mode=<mode>" line. bin/fm-spawn.sh reads that line and refuses
# to launch a ship task whose explicit --mode disagrees, so an adjusted brief and the
Expand Down Expand Up @@ -166,7 +166,7 @@ if [ "$KIND" = ship ]; then
case "$MODE" in
no-mistakes|direct-PR|local-only) ;;
no-mistakes-prod-only)
echo "error: no-mistakes-prod-only is a registry policy, not a task mode; classify this task's surface and resolve it to no-mistakes or direct-PR at intake" >&2
echo "error: no-mistakes-prod-only is a retired registry value, not a task mode; ship direct-PR unless the captain requested no-mistakes for this task at intake" >&2
exit 1 ;;
*) echo "error: --mode must be one of no-mistakes, direct-PR, local-only (got '$MODE')" >&2; exit 1 ;;
esac
Expand Down
2 changes: 1 addition & 1 deletion bin/fm-fleet-sync.sh
Original file line number Diff line number Diff line change
Expand Up @@ -324,7 +324,7 @@ sync_project() {
echo "$label: skipped: not a clone root (git would act on $proj_top)"
return 0
fi
mode_line=$("$FM_ROOT/bin/fm-project-mode.sh" "$label" 2>/dev/null || echo "no-mistakes off")
mode_line=$("$FM_ROOT/bin/fm-project-mode.sh" "$label" 2>/dev/null || echo "direct-PR off")
mode=${mode_line%% *}
if [ "$mode" = "local-only" ]; then
echo "$label: skipped: local-only project"
Expand Down
44 changes: 22 additions & 22 deletions bin/fm-project-mode.sh
Original file line number Diff line number Diff line change
Expand Up @@ -12,28 +12,28 @@
# bin/fm-spawn.sh's advisory registry-deviation notice.
#
# Registry line format (data/projects.md):
# - <name> - <desc> (added <date>) -> no-mistakes off (legacy default)
# - <name> - <desc> (added <date>) -> direct-PR off (legacy, no bracket)
# - <name> [<mode>] - <desc> (added <date>) -> <mode> off
# - <name> [<mode> +yolo] - <desc> (added <date>) -> <mode> on
#
# Registered modes:
# no-mistakes full pipeline -> PR -> configured merge authority (default)
# direct-PR push + PR via gh-axi, no pipeline
# direct-PR push + PR via gh-axi, no pipeline (default)
# local-only local branch, no remote/PR, guarded local merge
# no-mistakes-prod-only a conditional policy, not a task mode: firstmate
# classifies each task's surface at intake (the
# project-management skill owns that classification).
# Mechanical output maps it to its most rigorous leg,
# no-mistakes, so sync, seeding, and init treat such a
# project as the remote-backed pipeline project it is.
# no-mistakes full pipeline -> PR -> configured merge authority;
# registered only at the captain's request
# no-mistakes-prod-only retired conditional posture (the project-management
# skill owns its retirement); still parsed so an
# unconverted entry is not a typo, and mapped to
# direct-PR, the posture it was converted to.
# yolo (orthogonal) = merge authority only: when on, firstmate merges green,
# in-scope work itself (AGENTS.md section 7).
#
# --raw prints the registered annotation unmapped, so a caller that must tell a
# conditional policy apart from a flat mode sees "no-mistakes-prod-only" itself.
# --raw prints the registered annotation unmapped, so a caller that must tell the
# retired value apart from a flat mode sees "no-mistakes-prod-only" itself.
#
# An unknown/missing project or unknown mode falls back to "no-mistakes off" and warns
# to stderr, so a typo never silently drops the gate.
# An unknown/missing project or unknown mode falls back to the "direct-PR off"
# default and warns to stderr, so a typo is visible. Firstmate never selects the
# no-mistakes pipeline on its own (AGENTS.md section 7), so no fallback does either.
# Usage: fm-project-mode.sh [--raw] <project-name>
set -eu

Expand All @@ -50,15 +50,15 @@ fi
NAME=${1:?usage: fm-project-mode.sh [--raw] <project-name>}

if [ ! -f "$REG" ]; then
echo "warn: no registry at $REG; defaulting $NAME to no-mistakes off" >&2
echo "no-mistakes off"
echo "warn: no registry at $REG; defaulting $NAME to direct-PR off" >&2
echo "direct-PR off"
exit 0
fi

# awk emits "<mode> <yolo>" (one line) or nothing if the project is absent.
parsed=$(awk -v n="$NAME" '
$1=="-" && $2==n {
mode="no-mistakes"; yolo="off";
mode="direct-PR"; yolo="off";
if ($3 ~ /^\[/) {
s="";
for (i=3; i<=NF; i++) { s = s (s==""?"":" ") $i; if ($i ~ /\]$/) break }
Expand All @@ -72,21 +72,21 @@ parsed=$(awk -v n="$NAME" '
' "$REG")

if [ -z "$parsed" ]; then
echo "warn: project \"$NAME\" not in registry; defaulting to no-mistakes off" >&2
echo "no-mistakes off"
echo "warn: project \"$NAME\" not in registry; defaulting to direct-PR off" >&2
echo "direct-PR off"
exit 0
fi

mode=${parsed%% *}
yolo=${parsed##* }
case "$mode" in
no-mistakes|direct-PR|local-only|no-mistakes-prod-only) ;;
*) echo "warn: unknown mode \"$mode\" for $NAME; defaulting to no-mistakes off" >&2; mode=no-mistakes; yolo=off ;;
*) echo "warn: unknown mode \"$mode\" for $NAME; defaulting to direct-PR off" >&2; mode=direct-PR; yolo=off ;;
esac
case "$yolo" in on|off) ;; *) yolo=off ;; esac
# A conditional policy is not a task mode. Mechanical callers get its most
# rigorous leg; --raw callers get the annotation itself (see the header).
# The retired conditional posture reads as the direct-PR it was converted to;
# --raw callers get the annotation itself (see the header).
if [ "$RAW" -eq 0 ] && [ "$mode" = no-mistakes-prod-only ]; then
mode=no-mistakes
mode=direct-PR
fi
echo "$mode $yolo"
4 changes: 2 additions & 2 deletions bin/fm-promote.sh
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@
# alongside the kind= flip. Firstmate resolves both at promotion time, having just
# read the scout's report (AGENTS.md section 7); data/projects.md holds the
# captain's standing posture as context, and this script never looks it up.
# no-mistakes-prod-only is a registry policy rather than a task mode and is refused.
# no-mistakes-prod-only is a retired registry value rather than a task mode and is refused.
# Usage: fm-promote.sh <task-id> --mode <no-mistakes|direct-PR|local-only> --yolo <on|off>
set -eu

Expand Down Expand Up @@ -89,7 +89,7 @@ done
case "$MODE" in
no-mistakes|direct-PR|local-only) ;;
no-mistakes-prod-only)
echo "error: no-mistakes-prod-only is a registry policy, not a task mode; classify this task's surface and resolve it to no-mistakes or direct-PR" >&2
echo "error: no-mistakes-prod-only is a retired registry value, not a task mode; ship direct-PR unless the captain requested no-mistakes for this task" >&2
exit 1 ;;
*) echo "error: --mode must be one of no-mistakes, direct-PR, local-only (got '$MODE')" >&2; exit 1 ;;
esac
Expand Down
12 changes: 6 additions & 6 deletions bin/fm-spawn.sh
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,8 @@
# than becoming intent. That library owns the parsing and intent rules. When
# the explicit mode carries less rigor than the project's standing posture, a
# loud one-line deviation notice is printed and the spawn continues.
# no-mistakes-prod-only is a registry policy rather than a task mode and is
# refused as a flag value.
# no-mistakes-prod-only is a retired registry value rather than a task mode and
# is refused as a flag value.
# Ship/scout launches always put fm-dod-lib.sh's current worker role scope
# first in the private launch-brief overlay, including the exact task-owned
# steering inbox. This never rewrites a project's instruction files or a
Expand Down Expand Up @@ -718,7 +718,7 @@ else
case "$MODE" in
no-mistakes | direct-PR | local-only) ;;
no-mistakes-prod-only)
echo "error: no-mistakes-prod-only is a registry policy, not a task mode; classify this task's surface and resolve it to no-mistakes or direct-PR at intake" >&2
echo "error: no-mistakes-prod-only is a retired registry value, not a task mode; ship direct-PR unless the captain requested no-mistakes for this task at intake" >&2
exit 1
;;
*)
Expand Down Expand Up @@ -2629,9 +2629,9 @@ if [ "$KIND" = ship ]; then
fi
# The registry holds the captain's standing posture, so dropping below it is
# allowed (a current explicit captain instruction wins) but never silent. An
# unregistered project resolves to the same no-mistakes standing default, which
# is why the notice names the standing posture rather than the registry line. A
# conditional policy is excluded: both of its legs are legitimate classifications.
# unregistered project resolves to the same direct-PR standing default, which
# is why the notice names the standing posture rather than the registry line.
# The retired conditional value is excluded: it now reads as direct-PR.
STANDING_MODE=$("$FM_ROOT/bin/fm-project-mode.sh" --raw "$PROJ_NAME" 2>/dev/null | cut -d' ' -f1) || STANDING_MODE=
if [ -n "$STANDING_MODE" ] && [ "$STANDING_MODE" != no-mistakes-prod-only ] &&
[ "$(delivery_rigor_rank "$MODE")" -lt "$(delivery_rigor_rank "$STANDING_MODE")" ]; then
Expand Down
Loading
Loading