Several current review skills describe reviewer independence as automatic central/runtime enforcement, while the v7.0.5 routing wire carries no active-primary or artifact-author lineage fields.
Verified on published v7.0.5 (e2ff45467c1cf5ade7235f40ff6c822b7d9e5c87, runtime 5.0.7) and unchanged in documentation PR #202:
skill-specs/code-review.md says to resolve family snapshots through the runtime and that central policy chooses an independent reviewer.
skill-specs/qa-verify.md likewise says central policy selects an independent reviewer.
- The shared independence block in
code-review, red-team, and qa-verify attributes snapshot handling to runtime policy.
This can give a primary false assurance that its selected reviewer is independent. Repository/skill policy still requires independence; a successful routing result alone does not prove it. The current release used an explicitly selected distinct-family reviewer and checked its actual lineage, so this issue does not invalidate its retained review evidence.
Follow-up scope: correct editable skill instructions to make the primary verify both author and primary lineages, select an eligible distinct-family reviewer before dispatch, and verify observed reviewer lineage before accepting governance evidence. Regenerate existing skill outputs and test generation/consistency through a separate governed content change and subsequent release. Preserve unknown lineage as unknown and do not replay consumed reviews.
Do not add a new coordinator family-classification gate, strict output parser, persona, tool allowlist, or adapter hardening to satisfy this documentation mismatch. The intended correction is accurate caller instructions using the existing runtime.
Origin: #202 (comment). PR #202 only updates descriptive release/architecture documentation; its diff against the signed release does not change skill specs, generated skills, or build configuration. Treat the skill-content change as separate follow-up, not an introduced regression in that documentation PR.
Several current review skills describe reviewer independence as automatic central/runtime enforcement, while the v7.0.5 routing wire carries no active-primary or artifact-author lineage fields.
Verified on published v7.0.5 (
e2ff45467c1cf5ade7235f40ff6c822b7d9e5c87, runtime 5.0.7) and unchanged in documentation PR #202:skill-specs/code-review.mdsays to resolve family snapshots through the runtime and that central policy chooses an independent reviewer.skill-specs/qa-verify.mdlikewise says central policy selects an independent reviewer.code-review,red-team, andqa-verifyattributes snapshot handling to runtime policy.This can give a primary false assurance that its selected reviewer is independent. Repository/skill policy still requires independence; a successful routing result alone does not prove it. The current release used an explicitly selected distinct-family reviewer and checked its actual lineage, so this issue does not invalidate its retained review evidence.
Follow-up scope: correct editable skill instructions to make the primary verify both author and primary lineages, select an eligible distinct-family reviewer before dispatch, and verify observed reviewer lineage before accepting governance evidence. Regenerate existing skill outputs and test generation/consistency through a separate governed content change and subsequent release. Preserve unknown lineage as unknown and do not replay consumed reviews.
Do not add a new coordinator family-classification gate, strict output parser, persona, tool allowlist, or adapter hardening to satisfy this documentation mismatch. The intended correction is accurate caller instructions using the existing runtime.
Origin: #202 (comment). PR #202 only updates descriptive release/architecture documentation; its diff against the signed release does not change skill specs, generated skills, or build configuration. Treat the skill-content change as separate follow-up, not an introduced regression in that documentation PR.