Skip to content

Correct review skills that imply automatic runtime family independence #203

Description

@sumitake

Several current review skills describe reviewer independence as automatic central/runtime enforcement, while the v7.0.5 routing wire carries no active-primary or artifact-author lineage fields.

Verified on published v7.0.5 (e2ff45467c1cf5ade7235f40ff6c822b7d9e5c87, runtime 5.0.7) and unchanged in documentation PR #202:

  • skill-specs/code-review.md says to resolve family snapshots through the runtime and that central policy chooses an independent reviewer.
  • skill-specs/qa-verify.md likewise says central policy selects an independent reviewer.
  • The shared independence block in code-review, red-team, and qa-verify attributes snapshot handling to runtime policy.

This can give a primary false assurance that its selected reviewer is independent. Repository/skill policy still requires independence; a successful routing result alone does not prove it. The current release used an explicitly selected distinct-family reviewer and checked its actual lineage, so this issue does not invalidate its retained review evidence.

Follow-up scope: correct editable skill instructions to make the primary verify both author and primary lineages, select an eligible distinct-family reviewer before dispatch, and verify observed reviewer lineage before accepting governance evidence. Regenerate existing skill outputs and test generation/consistency through a separate governed content change and subsequent release. Preserve unknown lineage as unknown and do not replay consumed reviews.

Do not add a new coordinator family-classification gate, strict output parser, persona, tool allowlist, or adapter hardening to satisfy this documentation mismatch. The intended correction is accurate caller instructions using the existing runtime.

Origin: #202 (comment). PR #202 only updates descriptive release/architecture documentation; its diff against the signed release does not change skill specs, generated skills, or build configuration. Treat the skill-content change as separate follow-up, not an introduced regression in that documentation PR.

Activity

  1. sumitake commented on Sep 8, 2026

    @sumitake
    OwnerAuthor

    Published in agent-collab 7.0.6 through #204; release documentation is reconciled in #207.

    The generated review instructions now require caller verification and binding of reviewer lineage when independent approval is required. Ordinary code review may use available Gemini as explicitly advisory when no eligible distinct-family reviewer is available; callers must not repeatedly select an absent Grok installation. Gemini repository review was already admitted in 7.0.5, so this is a caller-guidance correction. Routing, roles and subscription names do not prove independence.

    The signed release workflow and all three assets were verified. Installed released files and provider-free planning were checked separately from fresh-session loading and inference. The signed runtime remains 5.0.7. Fixed and released; unrelated Claude qualification #162 remains open.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions