Skip to content

drive-pr: the authorization conjunction is unsatisfiable and the grant states no lifetime #1282

Description

@ptr727

Two defects in drive-pr "What Invoking This Skill Authorizes".

The conjunction is unsatisfiable in the clearest invocation. The first bullet reads "Naming this skill, and answering its how-far question, is the maintainer's explicit, current go-ahead for every feature -> develop squash merge the drive performs to reach that target." "How Far to Drive"'s first bullet says an explicit target ("to develop", "all the way") is acted on without asking, so in that case no how-far question is ever put and none is answered. Read literally, the invocation shape the skill recommends grants nothing.

The grant states no lifetime. "How Far to Drive" points at this very section as where scope is recorded ("recorded where the skill that carries the grant states its scope, the way backlog-burndown's own 'What Invoking This Skill Authorizes' does"), and that sibling section does bound it: "The grant is bounded by the session it was named in ... A grant read back from a note is one nobody gave". Here "current" is the only gesture at a lifetime and bounds nothing, so a resumed session can read an earlier session's naming as still standing, which is exactly what GOVERNANCE.md's authorization-scope rules forbid.

Raised by a local-strict-review carried-content pass on the pull request that added backlog-burndown, which edited this section, and deferred there under that skill's own review-round budget.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    proseA defect in rule or procedure textskillsAgent skill

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions