Skip to content

Agent safety: 'pm test <id> --add --help' (and 'pm files --add --help') records '--help' as a linked test/file instead of printing help #1398

Description

@unbraind

Repro (pm 2026.10.4, fresh workspace)

pm init
id=$(PM_AUTHOR=x pm create --type Task --title t --description d --create-mode progressive --json | jq -r .id)
PM_AUTHOR=x pm test  $id --add --help    # ok: true  → tests: [{command: "--help", scope: project}]
PM_AUTHOR=x pm files $id --add --help    # ok: true  → files[1]{path,scope}: "--help",project

Both commands mutate the item (with a history record) instead of printing help, and report ok: true.

Why it matters

Agents routinely append --help to the command they are about to run to discover its grammar. In a real package tracker (unbraind/pm-ops, item ops-zq8c) an agent did exactly this, the bogus {command: "--help"} test was committed, and a reviewer had to flag it on the PR ("Recorded test cannot run"). Because pm test --run executes recorded commands, this also turns help discovery into a persisted executable entry.

Expected

  • --help/-h anywhere in argv prints the command's help and exits 0 without mutating, as for every other command; or
  • a value-taking collection option refuses a value that is itself a known global flag (--help, --json, --dry-run, …) with a recovery hint (use --add=--help if you really mean the literal).

Related: #1337 (unsupported --dry-run recovery suggests the real mutation) — same class: discovery flags must never be swallowed as mutation values.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions