diff --git a/.devcontainer/opencode.json b/.devcontainer/opencode.json index 59f8bcf5f..bb96801d9 100644 --- a/.devcontainer/opencode.json +++ b/.devcontainer/opencode.json @@ -17,7 +17,7 @@ "CleverThis": { "npm": "@ai-sdk/openai-compatible", "options": { - "baseURL": "https://d651xgxku0ipo0pb.us-east-2.aws.endpoints.huggingface.cloud/v1", + "baseURL": "https://ke5ntcikhnj2clcp.us-east-1.aws.endpoints.huggingface.cloud/v1", "apiKey": "{env:HF_TOKEN}", "headers": { "X-HF-Bill-To": "CleverThis", @@ -89,7 +89,7 @@ "CleverThis-5": { "npm": "@ai-sdk/openai-compatible", "options": { - "baseURL": "https://f4jvts1w3gue3tqu.us-east-1.aws.endpoints.huggingface.cloud/v1", + "baseURL": "https://fhe4kwehnm1rb275.us-east-1.aws.endpoints.huggingface.cloud/v1", "apiKey": "{env:HF_TOKEN}", "headers": { "X-HF-Bill-To": "CleverThis", @@ -97,8 +97,8 @@ } }, "models": { - "Qwen3-Coder-Next-GGUF-Q8-0": { - "name": "Qwen3 Coder Next GGUF Q8_0 (Instruct)", + "Qwen3-Coder-Next-GGUF-BF16": { + "name": "Qwen3 Coder Next GGUF BF16", "tools": true } } @@ -140,7 +140,7 @@ "CleverThis-8": { "npm": "@ai-sdk/openai-compatible", "options": { - "baseURL": "https://u1txtbgmwbllttq0.us-east-1.aws.endpoints.huggingface.cloud/v1", + "baseURL": "https://ki19d58snp1d3qa4.us-east-1.aws.endpoints.huggingface.cloud/v1", "apiKey": "{env:HF_TOKEN}", "headers": { "X-HF-Bill-To": "CleverThis", @@ -148,8 +148,144 @@ } }, "models": { - "Qwen3-Coder-Next-GGUF-Q6-K": { - "name": "Qwen3 Coder Next GGUF Q6_K (Instruct)", + "Qwen3-Coder-Next-GGUF-Q4-0": { + "name": "Qwen3 Coder Next GGUF Q4_0", + "tools": true + } + } + }, + "CleverThis-9": { + "npm": "@ai-sdk/openai-compatible", + "options": { + "baseURL": "https://m56026p5kxvout0d.us-east-1.aws.endpoints.huggingface.cloud/v1", + "apiKey": "{env:HF_TOKEN}", + "headers": { + "X-HF-Bill-To": "CleverThis", + "Authorization": "Bearer {env:HF_TOKEN}", + } + }, + "models": { + "Qwen3-6-35B-A3B-GGUF-MXFP4-MOE": { + "name": "Qwen 3.6 35b A3B GGUF MXFP4_MOE (Thinking)", + "tools": true + } + } + }, + "CleverThis-10": { + "npm": "@ai-sdk/openai-compatible", + "options": { + "baseURL": "https://dirv1cnem5wqzoax.us-east-1.aws.endpoints.huggingface.cloud/v1", + "apiKey": "{env:HF_TOKEN}", + "headers": { + "X-HF-Bill-To": "CleverThis", + "Authorization": "Bearer {env:HF_TOKEN}", + } + }, + "models": { + "Qwen3-235B-A22B-INST-GGUF-Q8-0": { + "name": "Qwen3 235b A22B GGUF Q8_0 (Instruct)", + "tools": true + } + } + }, + "CleverThis-11": { + "npm": "@ai-sdk/openai-compatible", + "options": { + "baseURL": "https://hueiyrdbly1ff4oo.us-east-1.aws.endpoints.huggingface.cloud/v1", + "apiKey": "{env:HF_TOKEN}", + "headers": { + "X-HF-Bill-To": "CleverThis", + "Authorization": "Bearer {env:HF_TOKEN}", + } + }, + "models": { + "Qwen3-235B-A22B-INST-GGUF-UD-Q2-K-XL": { + "name": "Qwen3 235b A22B GGUF UD-Q2_K_XL (Instruct)", + "tools": true + } + } + }, + "CleverThis-12": { + "npm": "@ai-sdk/openai-compatible", + "options": { + "baseURL": "https://atocunu78hjdnu3f.us-east-1.aws.endpoints.huggingface.cloud/v1", + "apiKey": "{env:HF_TOKEN}", + "headers": { + "X-HF-Bill-To": "CleverThis", + "Authorization": "Bearer {env:HF_TOKEN}", + } + }, + "models": { + "Qwen3-30B-A3B-INST-GGUF-UD-Q8-K-XL": { + "name": "Qwen3 30b A3B GGUF UD-Q8_K_XL (Instruct)", + "tools": true + } + } + }, + "CleverThis-13": { + "npm": "@ai-sdk/openai-compatible", + "options": { + "baseURL": "https://dpe3orf5en4581im.us-east-1.aws.endpoints.huggingface.cloud/v1", + "apiKey": "{env:HF_TOKEN}", + "headers": { + "X-HF-Bill-To": "CleverThis", + "Authorization": "Bearer {env:HF_TOKEN}", + } + }, + "models": { + "Qwen3-30B-A3B-INST-GGUF-UD-Q5-K-XL": { + "name": "Qwen3 30b A3B GGUF UD-Q5_K_XL (Instruct)", + "tools": true + } + } + }, + "CleverThis-14": { + "npm": "@ai-sdk/openai-compatible", + "options": { + "baseURL": "https://jamyigykfzm39bcu.us-east-1.aws.endpoints.huggingface.cloud/v1", + "apiKey": "{env:HF_TOKEN}", + "headers": { + "X-HF-Bill-To": "CleverThis", + "Authorization": "Bearer {env:HF_TOKEN}", + } + }, + "models": { + "MiniMax-M2-7-GGUF-UD-Q4-K-XL": { + "name": "MiniMax M2.7 GGUF UD-Q4_K_XL (Thinking)", + "tools": true + } + } + }, + "CleverThis-15": { + "npm": "@ai-sdk/openai-compatible", + "options": { + "baseURL": "https://n4u4h8h0fgintms4.us-east-1.aws.endpoints.huggingface.cloud/v1", + "apiKey": "{env:HF_TOKEN}", + "headers": { + "X-HF-Bill-To": "CleverThis", + "Authorization": "Bearer {env:HF_TOKEN}", + } + }, + "models": { + "Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL": { + "name": "Qwen 3.6 35b A3B GGUF UD-Q3_K_XL (Thinking)", + "tools": true + } + } + }, + "CleverThis-16": { + "npm": "@ai-sdk/openai-compatible", + "options": { + "baseURL": "https://kcgeda25msp4dkwm.us-east-2.aws.endpoints.huggingface.cloud/v1", + "apiKey": "{env:HF_TOKEN}", + "headers": { + "X-HF-Bill-To": "CleverThis", + "Authorization": "Bearer {env:HF_TOKEN}", + } + }, + "models": { + "Qwen3-code-480B-A35B-INST-GGUF-1M-UD-Q3-K-XL": { + "name": "Qwen3 Code 480b A35B GGUF UD-Q3_K_XL (Instruct, 1M Context)", "tools": true } } diff --git a/.opencode/agents/agent-evolution-pool-supervisor.md b/.opencode/agents/agent-evolution-pool-supervisor.md deleted file mode 100644 index 78ed269cd..000000000 --- a/.opencode/agents/agent-evolution-pool-supervisor.md +++ /dev/null @@ -1,38 +0,0 @@ ---- -description: > - Agent evolution pool supervisor. Continuously discovers improvement proposals - for the agent system and dispatches worker agents to implement them as pull - requests. Automatically assigns Type/Automation labels and milestone metadata - to all generated improvement PRs for consistent categorization and tracking. -mode: all -hidden: false ---- - -# Agent Evolution Pool Supervisor - -## PR Metadata Assignment - -The supervisor looks up the Type/Automation label and earliest open milestone -before dispatching a worker to create an improvement PR. - -### Label Lookup - -Search repository labels for Type/Automation or Automation/* pattern. -Handle missing label gracefully - log a warning and continue without assigning a label. - -### Milestone Lookup - -Retrieve the earliest open milestone by due date. -Handle missing milestones gracefully - log a warning and continue without assigning a milestone. - -### Passing Metadata to the Worker - -Include the resolved label ID and milestone ID in the worker prompt context. -The worker uses these values when calling the Forgejo PR creation API. - -## Permissions - -This agent requires the following Forgejo API permissions: - -- `forgejo_list_repo_labels` -- to look up the Type/Automation label ID -- `forgejo_list_repo_milestones` -- to look up the earliest open milestone ID diff --git a/.opencode/agents/async-agent-util.md b/.opencode/agents/async-agent-util.md index 271ff6621..d9f73483d 100644 --- a/.opencode/agents/async-agent-util.md +++ b/.opencode/agents/async-agent-util.md @@ -13,24 +13,84 @@ reasoningEffort: "high" # All utility type agents use the following color color: "#5555FF" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # Agents called in an async manner should have this set to deny, otherwise use best discretion + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": allow diff --git a/.opencode/agents/auto-agents.md b/.opencode/agents/auto-agents.md index bf9732046..183d6a361 100644 --- a/.opencode/agents/auto-agents.md +++ b/.opencode/agents/auto-agents.md @@ -13,24 +13,84 @@ model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K" reasoningEffort: "high" color: "#FF9999" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # This agent runs autonomously and never needs to ask questions + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": allow diff --git a/.opencode/agents/ca-test-infra-improver.md b/.opencode/agents/ca-test-infra-improver.md deleted file mode 100644 index 471772761..000000000 --- a/.opencode/agents/ca-test-infra-improver.md +++ /dev/null @@ -1,509 +0,0 @@ ---- -description: > - Testing infrastructure improvement pool supervisor and worker. In pool mode - (max_workers > 1), identifies analysis areas (CI timing, coverage gaps, test - architecture, flaky tests, pipeline optimization, missing test levels, etc.), - dispatches N parallel copies of itself (each analyzing one area), collects - results, and re-dispatches. In worker mode (max_workers = 1 or specific - focus_area assigned), clones the repo, performs deep analysis of one aspect - of the testing infrastructure using CI logs and PR check data, and files - actionable Forgejo issues proposing improvements. Never disables or weakens - existing checks — only proposes additions and optimizations. -mode: subagent -hidden: true -temperature: 0.2 -model: google/gemini-2.5-pro -color: "#2ECC71" -permission: - read: - "*": allow - write: - "*": deny - "/tmp/*": allow - edit: deny - bash: - "*": deny - "echo $*": allow - "curl *": allow - "sleep *": allow - "jq *": allow - # Read-only file commands: - "cat *": allow - "ls *": allow - "find *": allow - "grep *": allow - "head *": allow - "tail *": allow - "wc *": allow - # Read-only git commands: - "git log*": allow - "git status*": allow - "git diff*": allow - task: - "*": deny - # ONE-SHOT helpers only: - "ca-ref-reader": allow - "ca-spec-reader": allow - "ca-new-issue-creator": allow - # ca-test-infra-improver (self) removed - workers launched via curl/prompt_async ---- - -# CleverAgents Test Infrastructure Improver (Pool Supervisor + Worker) - -**POOL SUPERVISOR MODE: You dispatch analysis workers via bash curl to the -OpenCode Server prompt_async API. You do NOT analyze test infrastructure -yourself in pool mode. You do NOT use the Task tool to launch workers — -self-dispatch has been REMOVED from your task permissions. You MUST use -bash curl prompt_async to create worker sessions, then monitor them with -bash sleep + curl.** - -You improve the architecture, design, completeness, performance, and -reliability of the project's testing infrastructure and CI pipeline. You -analyze test suites, CI execution times, coverage data, and test -organization to find improvement opportunities — then file actionable -Forgejo issues for each finding. - -You operate in one of two modes: - -- **Pool Supervisor Mode** (`max_workers > 1`): You identify analysis - areas, then dispatch N parallel copies of yourself — each focused on one - area — via the OpenCode Server `prompt_async` API. You monitor workers - with a 10-second polling loop and immediately refill completed slots. - -- **Worker Mode** (`max_workers = 1` or a specific `focus_area` is - assigned): You clone the repo, perform deep analysis of ONE aspect of - the testing infrastructure, and file Forgejo issues for findings. - ---- - -## CRITICAL: Bash Sleep for Genuine Waiting - -**You MUST use the Bash tool to sleep between polling cycles.** Do NOT -return to your caller to "wait." Returning means you EXIT. - -To wait 60 seconds: `bash("sleep 60", timeout=120000)` - -**The timeout parameter MUST be at least 1.5x the sleep duration.** Always -set timeout explicitly. You MUST NOT voluntarily exit — sleep and re-poll. - ---- - -## HARD CONSTRAINTS (from CONTRIBUTING.md) - -**You MUST NEVER:** -- Disable or weaken ANY existing check (coverage thresholds, type checking, - linting, security scanning) -- Turn off quality gates or reduce coverage below 97% -- Remove or skip established CI steps -- Bypass the task runner (nox) — all test execution goes through nox -- Write xUnit-style tests (all unit tests must be BDD/Gherkin via Behave) -- Mix test code into production source directories -- Add mocks or test doubles outside of test directories -- Violate any rule in CONTRIBUTING.md - -**You MUST ONLY propose improvements that:** -- Add new tests or test infrastructure -- Optimize existing tests for speed WITHOUT reducing coverage -- Improve test organization per CONTRIBUTING.md BDD guidelines -- Add missing test levels (Behave unit, Robot integration, ASV benchmarks) -- Improve CI pipeline efficiency (caching, parallelization, dependency management) -- Fix flaky tests for reliability -- Improve test data quality and fixture design - ---- - -## Mode Selection - -- **If `max_workers` is provided and > 1**: Pool Supervisor Mode -- **If a specific `focus_area` is provided**: Worker Mode -- **If neither**: Worker Mode with automatic area selection - ---- - -## Pool Supervisor Mode - -### Setup - -You receive: -- **SESSION STATE ISSUE** — Issue number for all health signals and status updates (REQUIRED) -- **Repo owner/name** — for Forgejo API calls -- **Instance ID** — unique identifier -- **Forgejo PAT** — for HTTPS git auth and API access -- **Git full name / email** — for git identity -- **Forgejo username** — for API operations -- **Max workers (N)** — number of parallel analysis workers -- **Spec context** (optional) — specification summary - -If no spec context is provided, invoke `ca-ref-reader` once at startup. - -### Pool Supervision Loop - -**CRITICAL: Health Comment Rate Limiting.** Do NOT post health comments on -every monitoring iteration. Health comments are posted by TWO triggers: -**timer-based** and **state-change-driven**. - -- **Timer-based:** Health comments MUST be posted **at most once every 10 - minutes**, enforced by a `last_health_post_time` timestamp. If less than - 10 minutes have elapsed, do NOT post via timer. -- **State-change-driven:** Post immediately when a meaningful state change - occurs (**significant state change**): worker completed, all areas - analyzed, or new worker dispatched after a slot freed up. -- **State-change rate limit:** Even state-change posts are limited to at - most one per **60 seconds**, enforced by a `last_state_change_post_time` - timestamp. Two or more workers completing within 60 seconds generates at - most one health comment. - -The **inner `while active:` monitoring loop must NEVER post health comments** — -posting belongs ONLY to the outer supervision cycle after the inner loop exits. - -``` -# Check if session state issue number was provided -if SESSION_STATE_ISSUE_NUMBER not provided: - error: "SESSION_STATE_ISSUE_NUMBER is required. This should be provided by product-builder." - ask user for the session state issue number - -N = max_workers -ref_summary = load via ca-ref-reader -SERVER = "http://localhost:4096" - -# The 8 analysis areas to cover: -analysis_areas = [ - "ci-execution-time", # Review PR check durations, find slowest suites - "coverage-gaps", # Analyze coverage.xml for untested code paths - "test-architecture", # Review BDD feature files, step organization - "flaky-tests", # Detect intermittently failing tests across CI runs - "ci-pipeline-design", # Review nox sessions, CI workflow configs - "test-data-quality", # Review fixtures, factories, test data patterns - "missing-test-levels", # Verify all modules have Behave + Robot + ASV - "dependency-security" # Check test dependency versions for vulnerabilities -] -analyzed_areas = set() -findings_total = 0 -cycle = 0 -last_health_post_time = 0 # Timestamp of last health comment (epoch seconds) -HEALTH_INTERVAL_SECONDS = 600 # 10 minutes between health posts -last_state_change_post_time = 0 # Timestamp of last state-change health post -STATE_CHANGE_INTERVAL_SECONDS = 60 # 60 seconds between state-change posts -prev_analyzed_count = 0 # Track state changes for event-driven posting -prev_active_count = 0 - -# ── RESUME: Adopt existing worker sessions from previous run ───── -EXISTING_WORKERS = bash("curl -s ${SERVER}/session | python3 -c \" -import sys, json -for s in json.loads(sys.stdin.read()): - title = s.get('title','') - if title.startswith('[CA-AUTO] worker-testinfra:'): - area = title.replace('[CA-AUTO] worker-testinfra: ','') - print(area + '=' + s['id']) -\"", timeout=30000) - -# Adopted workers will be picked up in the monitoring loop. - -LOOP: - cycle += 1 - - # ── Check for new code (invalidate analyses) ───────────────── - # If master has new commits, re-analyze affected areas - current_sha = query current master HEAD via Forgejo API - if master has advanced since last cycle: - # All areas may need re-analysis with new code - analyzed_areas.clear() - - # ── Determine un-analyzed areas ────────────────────────────── - remaining = [a for a in analysis_areas if a not in analyzed_areas] - - if remaining is empty: - # All areas analyzed — sleep and wait for new code - bash("sleep 60", timeout=120000) - continue - - # ── Dispatch workers via prompt_async ───────────────────────── - active = {} # area -> session_id - batch = remaining[:N] - - for area in batch: - SESSION_ID = bash("curl -s -X POST ${SERVER}/session \ - -H 'Content-Type: application/json' \ - -d '{\"title\": \"[CA-AUTO] worker-testinfra: \"}' \ - | python3 -c \"import sys,json; print(json.loads(sys.stdin.read())['id'])\"", - timeout=30000) - bash("curl -s -X POST ${SERVER}/session/${SESSION_ID}/prompt_async \ - -H 'Content-Type: application/json' \ - -d '{\"agent\": \"ca-test-infra-improver\", \ - \"parts\": [{\"type\": \"text\", \"text\": \ - \"Worker mode. Focus area: . max_workers: 1. \ - Repo: /. Forgejo PAT: . \ - Git: . Username: . \ - Acting on behalf of: Test Infrastructure.\"}]}'", - timeout=30000) - active[area] = SESSION_ID - - # ── Monitor workers, collect results, refill slots ─────────── - # NOTE: Do NOT post health comments inside this inner loop. - # Health posting is handled ONLY after this loop exits, gated - # by the timestamp/state-change check below. - remaining_areas = remaining[N:] - while active: - bash("sleep 10", timeout=30000) - STATUS = bash("curl -s ${SERVER}/session/status", timeout=30000) - - for area, session_id in list(active.items()): - if session is completed or errored: - final_msg = bash("curl -s ${SERVER}/session/${session_id}/message", - timeout=30000) - result = parse_worker_result(final_msg) - analyzed_areas.add(area) - findings_total += result.issues_filed - - bash("curl -s -X DELETE ${SERVER}/session/${session_id}", - timeout=15000) - del active[area] - - # Immediately refill slot - if remaining_areas: - next_area = remaining_areas.pop(0) - NEW_SID = create session + prompt_async for next_area - active[next_area] = NEW_SID - - # ── Post health (ONLY when state changed OR timer expired) ── - # IMPORTANT: This section runs ONCE per outer supervision cycle, - # NOT inside the inner "while active:" monitoring loop above. - - current_time = time.time() # or equivalent epoch seconds - - # Detect meaningful state changes: - state_changed = ( - len(analyzed_areas) != prev_analyzed_count - or len(active) != prev_active_count - ) - state_change_rate_limited = ( - current_time - last_state_change_post_time < STATE_CHANGE_INTERVAL_SECONDS - ) - timer_expired = ( - current_time - last_health_post_time >= HEALTH_INTERVAL_SECONDS - ) - - # Post on either state change (rate-limited) or timer expiry - if state_changed and not state_change_rate_limited: - # State-change post (e.g., worker completed, new worker dispatched) - post health comment on session state issue: - "[HEALTH] ca-test-infra-improver | Iteration: | Status: active\n" + - "- Type: pool-supervisor\n" + - "- Active workers: / \n" + - "- Work completed: / areas analyzed\n" + - "- Issues filed: \n" + - "- Last action: \n" + - "- Trigger: state change (worker completed / dispatched)\n\n" + - "---\n" + - "**Automated by CleverAgents Bot**\n" + - "Supervisor: Test Infrastructure | Agent: ca-test-infra-improver" - last_health_post_time = current_time - last_state_change_post_time = current_time - prev_analyzed_count = len(analyzed_areas) - prev_active_count = len(active) - - elif timer_expired: - # Timer-based periodic health post - post comment on session state issue: - "[HEALTH] ca-test-infra-improver | Iteration: | Status: active\n" + - "- Type: pool-supervisor\n" + - "- Active workers: / \n" + - "- Work completed: / areas analyzed\n" + - "- Issues filed: \n" + - "- Last action: \n" + - "- Next check: in 10 minutes\n\n" + - "---\n" + - "**Automated by CleverAgents Bot**\n" + - "Supervisor: Test Infrastructure | Agent: ca-test-infra-improver" - last_health_post_time = current_time - prev_analyzed_count = len(analyzed_areas) - prev_active_count = len(active) -``` - ---- - -## Worker Mode - -### Clone Isolation Protocol - -**CRITICAL: You MUST work in your own isolated clone. NEVER operate in /app.** - -```bash -INSTANCE_ID="test-infra-$$-$(date +%s)" -CLONE_DIR="/tmp/ca-${INSTANCE_ID}" - -git clone https://@//.git "$CLONE_DIR" -cd "$CLONE_DIR" -git config user.name "" -git config user.email "" -``` - -**CLEANUP on exit: `rm -rf "$CLONE_DIR"`** — always, even on error. - -### Analysis Process - -For the assigned `focus_area`, perform the corresponding analysis: - -#### 1. CI Execution Time (`ci-execution-time`) -- Query Forgejo for recently merged/closed PRs -- Read the check run durations from PR metadata and CI logs -- Identify the slowest test suites/steps -- Propose: parallelization, test splitting, caching, setup optimization -- File issues for each concrete optimization opportunity - -#### 2. Coverage Gaps (`coverage-gaps`) -- Run `nox -s coverage_report` in the clone -- Parse `coverage.xml` to find uncovered code paths -- Cross-reference with the specification to identify which uncovered paths - SHOULD have tests (not all uncovered code needs tests — focus on - behavior-critical paths) -- File issues for each significant coverage gap (with specific scenarios) - -#### 3. Test Architecture (`test-architecture`) -- Review all Behave feature files in `features/` -- Review Robot tests in `robot/` -- Review ASV benchmarks in `benchmarks/` -- Check against CONTRIBUTING.md BDD guidelines: - - Are steps grouped with related ones? - - Are feature-specific steps named after their feature? - - Are shared steps in purpose-driven modules? - - Are all features shipping with complete step implementations? -- File issues for organizational improvements - -#### 4. Flaky Tests (`flaky-tests`) -- Query Forgejo for CI run history on recent PRs -- Identify tests that pass on retry but fail initially -- Identify tests with non-deterministic output -- Analyze root causes: timing dependencies, shared state, external services -- File issues for each flaky test with proposed fix - -#### 5. CI Pipeline Design (`ci-pipeline-design`) -- Read `noxfile.py` (or equivalent task runner config) -- Read CI workflow configurations (`.forgejo/workflows/`, etc.) -- Propose: dependency caching, matrix test strategies, parallel nox sessions, - conditional test execution (only run affected test suites) -- File issues for each pipeline optimization - -#### 6. Test Data Quality (`test-data-quality`) -- Review test fixtures, factories, and test data setup -- Check for: hardcoded values, unrealistic data, missing edge cases, - poor fixture isolation, test data leaking between scenarios -- File issues for test data improvements - -#### 7. Missing Test Levels (`missing-test-levels`) -- For each source module, verify that ALL three test levels exist: - - **Behave** unit tests (BDD scenarios in `features/`) - - **Robot** integration tests (in `robot/`) - - **ASV** performance benchmarks (in `benchmarks/`) -- File issues for each module missing a test level - -#### 8. Dependency Security (`dependency-security`) -- Check test dependency versions for known vulnerabilities -- Check for outdated test framework versions -- Propose updates that don't break existing tests -- File issues for each vulnerable or outdated dependency - -### Issue Filing - -For each finding, invoke `ca-new-issue-creator` with: -- **Title**: `"TEST-INFRA: [] "` -- **Type**: `Type/Testing` or `Type/Task` as appropriate -- **Priority**: Based on impact (CI time savings → High, missing test level → Medium, etc.) -- **Labels**: `State/Unverified`, `Type/*`, `Priority/*` -- **Body**: Standard CONTRIBUTING.md format with Metadata, Subtasks, DoD -- **Acting on behalf of**: Test Infrastructure - -### Duplicate Avoidance - -> **CRITICAL: When in doubt, SKIP — it is better to miss an improvement -> suggestion than to create noise that wastes groomer and implementor time.** - -Before filing ANY issue, you MUST perform rigorous duplicate checking: - -1. **Extract keywords**: From your proposed issue title, extract 3-5 key - technical terms (e.g., "parallelize", "E2E", "coverage", "Docker", - "nox", "cache"). - -2. **Search by keywords**: Search Forgejo for open AND closed issues containing ANY - of those key terms. Use the search API, not just the "TEST-INFRA:" - prefix. - -3. **Compare semantically**: For each search result, compare your proposed - improvement with the existing issue's description. Two issues are - **duplicates** if they propose the same optimization for the same - component, even if the wording differs. Examples of duplicates: - - "Parallelize E2E tests" and "Run E2E tests in parallel" - - "Create custom Docker image for CI" and "Pre-built CI base image" - - "Cache nox environments" and "Persist nox virtualenvs between runs" - -4. **Check all prefixes**: Search for issues with `TEST-INFRA:`, `BUG-HUNT:`, - and `UAT:` prefixes — other agents may have already identified the same - improvement opportunity from a different angle. - -5. **If ANY existing issue proposes the same or substantially similar - improvement**: **SKIP** — do not file. It is far better to miss one - improvement suggestion than to file the 7th duplicate of the same idea. - Previous sessions created 48+ TEST-INFRA issues with significant overlap - across 8 topic clusters. - -6. **Post-filing verification**: After filing an issue, wait 5 seconds and - re-check for duplicates (another parallel worker may have filed the same - issue simultaneously). If a duplicate appeared, close your issue as a - duplicate of the earlier one. - -When filing, include a `### Duplicate Check` section in the issue body -listing the search queries used, result counts, and your justification for -why this is not a duplicate. - ---- - -## Bot Signature (Required on ALL Forgejo Content) - -Every comment, issue body, PR description, and review you post to Forgejo -MUST end with this signature block: - -``` ---- -**Automated by CleverAgents Bot** -Supervisor: Test Infrastructure | Agent: ca-test-infra-improver -``` - -Append this to the END of every piece of content you create on Forgejo. -No exceptions — every comment, every issue body, every PR description. - -## Important Rules - -- **NEVER work in /app.** Always use your isolated clone (Worker Mode) or - Forgejo API only (Pool Supervisor Mode). -- **NEVER modify code.** You analyze and file issues. You don't fix things. -- **NEVER disable or weaken checks.** This is the cardinal rule. -- **Delete your clone on exit.** Always `rm -rf "$CLONE_DIR"`, even on error. -- **Be specific.** Every issue must include concrete data (timing numbers, - coverage percentages, specific file paths, specific test names). -- **Propose production-grade solutions.** Don't suggest hacks or shortcuts. - Every improvement should follow industry best practices. -- **In Worker Mode, exit promptly.** Analyze the assigned area and exit so - the pool supervisor can dispatch new work. - ---- - -## Return Value - -### Pool Supervisor Mode -``` -INSTANCE_ID: -MODE: pool_supervisor -ANALYSIS_AREAS_COVERED: /<8> -TOTAL_ISSUES_FILED: -CYCLES_COMPLETED: -``` - -### Worker Mode -``` -INSTANCE_ID: -MODE: worker -FOCUS_AREA: -ISSUES_FILED: -ISSUE_NUMBERS: [#N, #M, ...] -KEY_FINDINGS: -``` diff --git a/.opencode/agents/estimator-implementation.md b/.opencode/agents/estimator-implementation.md index 8cc2a2931..bf6a055d6 100644 --- a/.opencode/agents/estimator-implementation.md +++ b/.opencode/agents/estimator-implementation.md @@ -15,24 +15,84 @@ reasoningEffort: "high" # All utility type agents use the following color color: "#5555FF" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # Agents called in an async manner should have this set to deny, otherwise use best discretion + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": allow diff --git a/.opencode/agents/git-checkout-util.md b/.opencode/agents/git-checkout-util.md index ca7d25d3c..01605623c 100644 --- a/.opencode/agents/git-checkout-util.md +++ b/.opencode/agents/git-checkout-util.md @@ -10,20 +10,84 @@ model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K" reasoningEffort: "high" color: "#5555FF" permission: - "*": deny + "glob": allow + "grep": allow "doom_loop": deny + + # This agent only needs to call one subagent "question": deny + # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow "sequential-thinking*": deny "context7*": deny diff --git a/.opencode/agents/git-cleanup-util.md b/.opencode/agents/git-cleanup-util.md index b141a8961..e0375a886 100644 --- a/.opencode/agents/git-cleanup-util.md +++ b/.opencode/agents/git-cleanup-util.md @@ -10,19 +10,84 @@ model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K" reasoningEffort: "high" color: "#5555FF" permission: - "*": deny + "glob": allow + "grep": allow "doom_loop": deny + + # This agent only needs to call one subagent "question": deny - read: - "*": allow - write: - "*": deny - "/tmp/*": allow - edit: - "*": deny + # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny + edit: + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": deny + read: + "**": allow "sequential-thinking*": deny "context7*": deny diff --git a/.opencode/agents/git-clone-util.md b/.opencode/agents/git-clone-util.md index 9498a23f5..84169adc0 100644 --- a/.opencode/agents/git-clone-util.md +++ b/.opencode/agents/git-clone-util.md @@ -13,20 +13,84 @@ reasoningEffort: "high" # All utility type agents use the following color color: "#5555FF" permission: - "*": deny + "glob": allow + "grep": allow "doom_loop": deny + + # This agent only needs to call one subagent "question": deny + # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow "sequential-thinking*": deny "context7*": deny diff --git a/.opencode/agents/git-commit-and-push-util.md b/.opencode/agents/git-commit-and-push-util.md index aea02330d..70dcac991 100644 --- a/.opencode/agents/git-commit-and-push-util.md +++ b/.opencode/agents/git-commit-and-push-util.md @@ -12,20 +12,84 @@ model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K" reasoningEffort: "high" color: "#5555FF" permission: - "*": deny + "glob": allow + "grep": allow "doom_loop": deny + + # This agent only needs to call one subagent "question": deny + # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow "sequential-thinking*": deny "context7*": deny diff --git a/.opencode/agents/git-commit-util.md b/.opencode/agents/git-commit-util.md index ae0865c75..aed24dcf0 100644 --- a/.opencode/agents/git-commit-util.md +++ b/.opencode/agents/git-commit-util.md @@ -11,24 +11,84 @@ reasoningEffort: "high" # All utility type agents use the following color color: "#5555FF" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # Agents called in an async manner should have this set to deny, otherwise use best discretion + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": allow diff --git a/.opencode/agents/git-create-commit-util.md b/.opencode/agents/git-create-commit-util.md index 7eaa2b32a..90b878657 100644 --- a/.opencode/agents/git-create-commit-util.md +++ b/.opencode/agents/git-create-commit-util.md @@ -13,20 +13,84 @@ model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K" reasoningEffort: "high" color: "#5555FF" permission: - "*": deny + "glob": allow + "grep": allow "doom_loop": deny + + # This agent only needs to call one subagent "question": deny + # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow "sequential-thinking*": deny "context7*": deny diff --git a/.opencode/agents/git-fetch-util.md b/.opencode/agents/git-fetch-util.md index 4c1dffcb5..5c4a6cc89 100644 --- a/.opencode/agents/git-fetch-util.md +++ b/.opencode/agents/git-fetch-util.md @@ -10,20 +10,84 @@ model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K" reasoningEffort: "high" color: "#5555FF" permission: - "*": deny + "glob": allow + "grep": allow "doom_loop": deny + + # This agent only needs to call one subagent "question": deny + # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow "sequential-thinking*": deny "context7*": deny diff --git a/.opencode/agents/git-force-push-with-lease-util.md b/.opencode/agents/git-force-push-with-lease-util.md index 71569d75d..d66280dcc 100644 --- a/.opencode/agents/git-force-push-with-lease-util.md +++ b/.opencode/agents/git-force-push-with-lease-util.md @@ -12,20 +12,84 @@ model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K" reasoningEffort: "high" color: "#5555FF" permission: - "*": deny + "glob": allow + "grep": allow "doom_loop": deny + + # This agent only needs to call one subagent "question": deny + # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow "sequential-thinking*": deny "context7*": deny diff --git a/.opencode/agents/git-isolator-util.md b/.opencode/agents/git-isolator-util.md index 62c73255f..7fe26bcc8 100644 --- a/.opencode/agents/git-isolator-util.md +++ b/.opencode/agents/git-isolator-util.md @@ -12,24 +12,84 @@ reasoningEffort: "high" # All utility type agents use the following color color: "#5555FF" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # Agents called in an async manner should have this set to deny, otherwise use best discretion + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": deny diff --git a/.opencode/agents/git-push-util.md b/.opencode/agents/git-push-util.md index 82766cfaa..3ae42a886 100644 --- a/.opencode/agents/git-push-util.md +++ b/.opencode/agents/git-push-util.md @@ -11,20 +11,84 @@ model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K" reasoningEffort: "high" color: "#5555FF" permission: - "*": deny + "glob": allow + "grep": allow "doom_loop": deny + + # This agent only needs to call one subagent "question": deny + # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow "sequential-thinking*": deny "context7*": deny diff --git a/.opencode/agents/git-rebase-and-push-util.md b/.opencode/agents/git-rebase-and-push-util.md index 6835ae064..8ceac461e 100644 --- a/.opencode/agents/git-rebase-and-push-util.md +++ b/.opencode/agents/git-rebase-and-push-util.md @@ -12,20 +12,84 @@ model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K" reasoningEffort: "high" color: "#5555FF" permission: - "*": deny + "glob": allow + "grep": allow "doom_loop": deny + + # This agent only needs to call one subagent "question": deny + # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow "sequential-thinking*": deny "context7*": deny diff --git a/.opencode/agents/git-rebase-util.md b/.opencode/agents/git-rebase-util.md index 3c6c92504..ad739c163 100644 --- a/.opencode/agents/git-rebase-util.md +++ b/.opencode/agents/git-rebase-util.md @@ -12,27 +12,84 @@ reasoningEffort: "high" # All utility type agents use the following color color: "#5555FF" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # Agents called in an async manner should have this set to deny, otherwise use best discretion + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that - read: allow - grep: allow - glob: allow external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": allow diff --git a/.opencode/agents/git-stage-util.md b/.opencode/agents/git-stage-util.md index 3049ae275..6564264b4 100644 --- a/.opencode/agents/git-stage-util.md +++ b/.opencode/agents/git-stage-util.md @@ -11,20 +11,84 @@ model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K" reasoningEffort: "high" color: "#5555FF" permission: - "*": deny + "glob": allow + "grep": allow "doom_loop": deny + + # This agent only needs to call one subagent "question": deny + # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow "sequential-thinking*": deny "context7*": deny diff --git a/.opencode/agents/implementation-supervisor.md b/.opencode/agents/implementation-supervisor.md index 7e80ecf3c..cb9a21a8d 100644 --- a/.opencode/agents/implementation-supervisor.md +++ b/.opencode/agents/implementation-supervisor.md @@ -18,8 +18,8 @@ reasoningEffort: "high" # All supervisor type agents use the following color color: "#FF9999" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny # This agent only needs to call one subagent @@ -27,15 +27,75 @@ permission: # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": deny diff --git a/.opencode/agents/implementation-worker.md b/.opencode/agents/implementation-worker.md index e290b6c2a..c99e52d01 100644 --- a/.opencode/agents/implementation-worker.md +++ b/.opencode/agents/implementation-worker.md @@ -16,25 +16,84 @@ reasoningEffort: "high" # All worker type agents use the following color color: "#00FF00" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # This wrapper runs autonomously as a worker session and must not interrupt - # the supervisor by prompting the user for input. + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that - read: - "*": allow - write: - "*": deny - "/tmp/*": allow - edit: - "*": deny - "/tmp/*": deny external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny + edit: + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow + read: + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": deny diff --git a/.opencode/agents/pr-merge-supervisor.md b/.opencode/agents/pr-merge-supervisor.md index 679a3e170..77b272728 100644 --- a/.opencode/agents/pr-merge-supervisor.md +++ b/.opencode/agents/pr-merge-supervisor.md @@ -11,8 +11,8 @@ reasoningEffort: "high" # All supervisor type agents use the following color color: "#FF9999" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny # This agent only needs to call one subagent @@ -20,15 +20,75 @@ permission: # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": deny diff --git a/.opencode/agents/pr-merge-worker.md b/.opencode/agents/pr-merge-worker.md index f1676aa6a..10270f8da 100644 --- a/.opencode/agents/pr-merge-worker.md +++ b/.opencode/agents/pr-merge-worker.md @@ -11,8 +11,8 @@ reasoningEffort: "high" # All worker type agents use the following color color: "#00FF00" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny # This agent only needs to call one subagent @@ -20,15 +20,75 @@ permission: # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": allow diff --git a/.opencode/agents/pr-review-supervisor.md b/.opencode/agents/pr-review-supervisor.md index eaa34f9d7..b9d49af65 100644 --- a/.opencode/agents/pr-review-supervisor.md +++ b/.opencode/agents/pr-review-supervisor.md @@ -14,8 +14,8 @@ reasoningEffort: "high" # All supervisor type agents use the following color color: "#FF9999" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny # This agent only needs to call one subagent @@ -23,15 +23,75 @@ permission: # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": deny diff --git a/.opencode/agents/pr-review-worker.md b/.opencode/agents/pr-review-worker.md index aeb40552f..1a6068b89 100644 --- a/.opencode/agents/pr-review-worker.md +++ b/.opencode/agents/pr-review-worker.md @@ -15,8 +15,8 @@ reasoningEffort: "high" # All worker type agents use the following color color: "#00FF00" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny # This agent only needs to call one subagent @@ -24,15 +24,75 @@ permission: # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": allow diff --git a/.opencode/agents/session-health-full-util.md b/.opencode/agents/session-health-full-util.md index 7bddb0066..1b931686b 100644 --- a/.opencode/agents/session-health-full-util.md +++ b/.opencode/agents/session-health-full-util.md @@ -14,20 +14,84 @@ model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K" reasoningEffort: "high" color: "#5555FF" permission: - "*": deny + "glob": allow + "grep": allow "doom_loop": deny + + # This agent only needs to call one subagent "question": deny + # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow "sequential-thinking*": allow "context7*": deny diff --git a/.opencode/agents/session-health-quick-util.md b/.opencode/agents/session-health-quick-util.md index 9f00b63b5..a90708ec9 100644 --- a/.opencode/agents/session-health-quick-util.md +++ b/.opencode/agents/session-health-quick-util.md @@ -14,20 +14,84 @@ model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K" reasoningEffort: "high" color: "#5555FF" permission: - "*": deny + "glob": allow + "grep": allow "doom_loop": deny + + # This agent only needs to call one subagent "question": deny + # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow "sequential-thinking*": allow "context7*": deny diff --git a/.opencode/agents/session-health-util.md b/.opencode/agents/session-health-util.md index 257a05a85..3ebaa503e 100644 --- a/.opencode/agents/session-health-util.md +++ b/.opencode/agents/session-health-util.md @@ -14,20 +14,84 @@ model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K" reasoningEffort: "high" color: "#5555FF" permission: - "*": deny + "glob": allow + "grep": allow "doom_loop": deny + + # This agent only needs to call one subagent "question": deny + # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow "sequential-thinking*": allow "context7*": deny diff --git a/.opencode/agents/supervisor.md b/.opencode/agents/supervisor.md index 5c6c5bbbc..efaab7c3e 100644 --- a/.opencode/agents/supervisor.md +++ b/.opencode/agents/supervisor.md @@ -10,24 +10,84 @@ reasoningEffort: "high" # All pass-through type agents for abstraction and reusability purposes, use the following color color: "#FFFF00" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # Agents called in an async manner should have this set to deny, otherwise use best discretion + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": allow diff --git a/.opencode/agents/task-implementor.md b/.opencode/agents/task-implementor.md index 4c6a3e00e..bbbf16be8 100644 --- a/.opencode/agents/task-implementor.md +++ b/.opencode/agents/task-implementor.md @@ -16,25 +16,84 @@ reasoningEffort: "high" # All worker type agents use the following color color: "#00FF00" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # This task agent runs autonomously as a synchronous subagent of a `tier-*` - # selector and must not interrupt the workflow to prompt the user for input. + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": deny read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": allow diff --git a/.opencode/agents/tier-codex.md b/.opencode/agents/tier-codex.md index 27ee0f834..fcef6bf23 100644 --- a/.opencode/agents/tier-codex.md +++ b/.opencode/agents/tier-codex.md @@ -14,24 +14,84 @@ reasoningEffort: "high" # All pass-through type agents for abstraction and reusability purposes, use the following color color: "#FFFF00" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # Agents called in an async manner should have this set to deny, otherwise use best discretion + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": deny diff --git a/.opencode/agents/tier-dispatcher.md b/.opencode/agents/tier-dispatcher.md index 0164d9a98..6c5795f83 100644 --- a/.opencode/agents/tier-dispatcher.md +++ b/.opencode/agents/tier-dispatcher.md @@ -18,25 +18,84 @@ reasoningEffort: "high" # All worker type agents use the following color color: "#FFFF00" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # This dispatcher runs autonomously as a synchronous subagent of its caller - # and must not interrupt the workflow to prompt the user for input. + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that - read: - "*": allow - write: - "*": deny - "/tmp/*": allow - edit: - "*": deny - "/tmp/*": deny external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny + edit: + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow + read: + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": allow diff --git a/.opencode/agents/tier-gpt5-mini.md b/.opencode/agents/tier-gpt5-mini.md index 23013af17..4fa8a7509 100644 --- a/.opencode/agents/tier-gpt5-mini.md +++ b/.opencode/agents/tier-gpt5-mini.md @@ -13,24 +13,84 @@ reasoningEffort: "high" # All pass-through type agents for abstraction and reusability purposes, use the following color color: "#FFFF00" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # Agents called in an async manner should have this set to deny, otherwise use best discretion + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": deny diff --git a/.opencode/agents/tier-gpt5-nano.md b/.opencode/agents/tier-gpt5-nano.md index e6eeb835d..b2d1e8fb3 100644 --- a/.opencode/agents/tier-gpt5-nano.md +++ b/.opencode/agents/tier-gpt5-nano.md @@ -13,24 +13,84 @@ reasoningEffort: "high" # All pass-through type agents for abstraction and reusability purposes, use the following color color: "#FFFF00" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # Agents called in an async manner should have this set to deny, otherwise use best discretion + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": deny diff --git a/.opencode/agents/tier-haiku.md b/.opencode/agents/tier-haiku.md index b985c19b5..7a07c6faa 100644 --- a/.opencode/agents/tier-haiku.md +++ b/.opencode/agents/tier-haiku.md @@ -13,24 +13,84 @@ reasoningEffort: "max" # All pass-through type agents for abstraction and reusability purposes, use the following color color: "#FFFF00" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # Agents called in an async manner should have this set to deny, otherwise use best discretion + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": deny diff --git a/.opencode/agents/tier-o4-mini.md b/.opencode/agents/tier-o4-mini.md index c57de3c7a..87b977ec0 100644 --- a/.opencode/agents/tier-o4-mini.md +++ b/.opencode/agents/tier-o4-mini.md @@ -13,24 +13,84 @@ reasoningEffort: "high" # All pass-through type agents for abstraction and reusability purposes, use the following color color: "#FFFF00" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # Agents called in an async manner should have this set to deny, otherwise use best discretion + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": deny diff --git a/.opencode/agents/tier-opus.md b/.opencode/agents/tier-opus.md index 87afaa11d..ead3b751b 100644 --- a/.opencode/agents/tier-opus.md +++ b/.opencode/agents/tier-opus.md @@ -14,24 +14,84 @@ reasoningEffort: "max" # All pass-through type agents for abstraction and reusability purposes, use the following color color: "#FFFF00" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # Agents called in an async manner should have this set to deny, otherwise use best discretion + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": deny diff --git a/.opencode/agents/tier-qwen.md b/.opencode/agents/tier-qwen.md index 77bff32d6..5ab473710 100644 --- a/.opencode/agents/tier-qwen.md +++ b/.opencode/agents/tier-qwen.md @@ -13,24 +13,84 @@ reasoningEffort: "high" # All pass-through type agents for abstraction and reusability purposes, use the following color color: "#FFFF00" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # Agents called in an async manner should have this set to deny, otherwise use best discretion + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": deny diff --git a/.opencode/agents/tier-sonnet.md b/.opencode/agents/tier-sonnet.md index 0066f6514..0b5f6f6b9 100644 --- a/.opencode/agents/tier-sonnet.md +++ b/.opencode/agents/tier-sonnet.md @@ -13,24 +13,84 @@ reasoningEffort: "max" # All pass-through type agents for abstraction and reusability purposes, use the following color color: "#FFFF00" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # Agents called in an async manner should have this set to deny, otherwise use best discretion + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed "sequential-thinking*": deny diff --git a/.opencode/agents/work-group-util.md b/.opencode/agents/work-group-util.md index 00e3aa143..f6e66ae21 100644 --- a/.opencode/agents/work-group-util.md +++ b/.opencode/agents/work-group-util.md @@ -12,24 +12,84 @@ reasoningEffort: "high" # All utility type agents use the following color color: "#5555FF" permission: - # Block whatever we don't explicitly allow - "*": deny + "glob": allow + "grep": allow "doom_loop": deny - # One-shot subagent, no questions + # This agent only needs to call one subagent "question": deny # All agents are supposed to be working in isolated repos in `/tmp`, so this forces that external_directory: - "/tmp/*": allow + "/tmp/**": allow + "/app/**": deny edit: - "*": deny - "/tmp/*": allow - write: - "*": deny - "/tmp/*": allow + "a**": deny + "b**": deny + "c**": deny + "d**": deny + "e**": deny + "f**": deny + "g**": deny + "h**": deny + "i**": deny + "j**": deny + "k**": deny + "l**": deny + "m**": deny + "n**": deny + "o**": deny + "p**": deny + "q**": deny + "r**": deny + "s**": deny + "t**": deny + "u**": deny + "v**": deny + "w**": deny + "x**": deny + "y**": deny + "z**": deny + "A**": deny + "B**": deny + "C**": deny + "D**": deny + "E**": deny + "F**": deny + "G**": deny + "H**": deny + "I**": deny + "J**": deny + "K**": deny + "L**": deny + "M**": deny + "N**": deny + "O**": deny + "P**": deny + "Q**": deny + "R**": deny + "S**": deny + "T**": deny + "U**": deny + "V**": deny + "W**": deny + "X**": deny + "Y**": deny + "Z**": deny + "1**": deny + "2**": deny + "3**": deny + "4**": deny + "5**": deny + "6**": deny + "7**": deny + "8**": deny + "9**": deny + "0**": deny + "/app/**": deny + "/tmp/**": allow read: - "*": allow + "**": allow # MCP permissions "sequential-thinking*": allow