Skip to content

index: say where a gate runs — commit/push and in the agent - #171

Merged
jothimani-rajendran merged 1 commit into
mainfrom
claude/index-gates-in-agent
Sep 27, 2026
Merged

jothimani-rajendran merged 1 commit into
mainfrom
claude/index-gates-in-agent

Conversation

@jothimani-rajendran

Copy link
Copy Markdown
Collaborator

What

The generated .agents/policies/INDEX.md headed its gates "enforced automatically at commit/push". An agent reading that could expect nothing until a commit, yet a gate compiled for tool use refuses the write during the turn. The java-security agent-kit runs on Windows showed this: Claude's Edit was denied at PreToolUse.

What changes:

  • The heading now reads ## Gates — enforced automatically at commit/push, and in the agent where noted.
  • Every gate whose manifest declares hook.gate.on: [..., tool_use] ends with: "Also checked in the agent: before a write, or at the end of the turn, depending on the agent."
  • The note names both places because INDEX.md is shared by every agent. Some agents' hooks can refuse a write before it happens; others only judge the result at Stop.

Implementation:

  • IndexEntry.in_agent is read straight from the manifest's gate on list.
  • render.py has the GATES_HEADING and IN_AGENT_NOTE constants.
  • chock's own INDEX.md is regenerated, and the note appears on pin-github-actions.
  • Changelog entry under Unreleased.
  • Adopters get the new wording on their next chock sync after release.

Definition of done

  • chock check passes. The only output is the existing INDEX budget warning (1617/2000 tokens).
  • chock check --only matrix passes
  • chock sync --repo . --check clean
  • chock check --only verify clean
  • pytest -q green (1516 passed, 6 skipped). New test: tests/test_index_in_agent_gates.py. A tool-use gate gets the note; a commit-only gate does not.
  • ruff check . and ruff format --check . clean

Claims

  • No surface is described as enforcing more than it installs. The note is added only for gates compiled for tool use, and it does not promise the check runs before the write.

🤖 Generated with Claude Code

https://claude.ai/code/session_01CzNYfzP8ymU3r4JB9Sz8Ha


Generated by Claude Code

The gates heading said enforced at commit/push only, but a gate compiled
for tool use also refuses the write in the agent. Mark those gates and
reword the heading.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
@jothimani-rajendran
jothimani-rajendran marked this pull request as ready for review September 27, 2026 16:27
@jothimani-rajendran
jothimani-rajendran merged commit 9d0b00a into main Sep 27, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants