Compare commits
12 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| c8ec64bf0a | |||
| df04392ebb | |||
| 8758455aaa | |||
| 581b59f070 | |||
| 3da61ba891 | |||
| b75feaf7a3 | |||
| 7dda57b054 | |||
| fc5a8a9e6d | |||
| f8f74a56d9 | |||
| 02e7cb39f6 | |||
| e1bfc970a7 | |||
| e16181a7ec |
+143
-7
@@ -17,7 +17,7 @@
|
||||
"CleverThis": {
|
||||
"npm": "@ai-sdk/openai-compatible",
|
||||
"options": {
|
||||
"baseURL": "https://d651xgxku0ipo0pb.us-east-2.aws.endpoints.huggingface.cloud/v1",
|
||||
"baseURL": "https://ke5ntcikhnj2clcp.us-east-1.aws.endpoints.huggingface.cloud/v1",
|
||||
"apiKey": "{env:HF_TOKEN}",
|
||||
"headers": {
|
||||
"X-HF-Bill-To": "CleverThis",
|
||||
@@ -89,7 +89,7 @@
|
||||
"CleverThis-5": {
|
||||
"npm": "@ai-sdk/openai-compatible",
|
||||
"options": {
|
||||
"baseURL": "https://f4jvts1w3gue3tqu.us-east-1.aws.endpoints.huggingface.cloud/v1",
|
||||
"baseURL": "https://fhe4kwehnm1rb275.us-east-1.aws.endpoints.huggingface.cloud/v1",
|
||||
"apiKey": "{env:HF_TOKEN}",
|
||||
"headers": {
|
||||
"X-HF-Bill-To": "CleverThis",
|
||||
@@ -97,8 +97,8 @@
|
||||
}
|
||||
},
|
||||
"models": {
|
||||
"Qwen3-Coder-Next-GGUF-Q8-0": {
|
||||
"name": "Qwen3 Coder Next GGUF Q8_0 (Instruct)",
|
||||
"Qwen3-Coder-Next-GGUF-BF16": {
|
||||
"name": "Qwen3 Coder Next GGUF BF16",
|
||||
"tools": true
|
||||
}
|
||||
}
|
||||
@@ -140,7 +140,7 @@
|
||||
"CleverThis-8": {
|
||||
"npm": "@ai-sdk/openai-compatible",
|
||||
"options": {
|
||||
"baseURL": "https://u1txtbgmwbllttq0.us-east-1.aws.endpoints.huggingface.cloud/v1",
|
||||
"baseURL": "https://ki19d58snp1d3qa4.us-east-1.aws.endpoints.huggingface.cloud/v1",
|
||||
"apiKey": "{env:HF_TOKEN}",
|
||||
"headers": {
|
||||
"X-HF-Bill-To": "CleverThis",
|
||||
@@ -148,8 +148,144 @@
|
||||
}
|
||||
},
|
||||
"models": {
|
||||
"Qwen3-Coder-Next-GGUF-Q6-K": {
|
||||
"name": "Qwen3 Coder Next GGUF Q6_K (Instruct)",
|
||||
"Qwen3-Coder-Next-GGUF-Q4-0": {
|
||||
"name": "Qwen3 Coder Next GGUF Q4_0",
|
||||
"tools": true
|
||||
}
|
||||
}
|
||||
},
|
||||
"CleverThis-9": {
|
||||
"npm": "@ai-sdk/openai-compatible",
|
||||
"options": {
|
||||
"baseURL": "https://m56026p5kxvout0d.us-east-1.aws.endpoints.huggingface.cloud/v1",
|
||||
"apiKey": "{env:HF_TOKEN}",
|
||||
"headers": {
|
||||
"X-HF-Bill-To": "CleverThis",
|
||||
"Authorization": "Bearer {env:HF_TOKEN}",
|
||||
}
|
||||
},
|
||||
"models": {
|
||||
"Qwen3-6-35B-A3B-GGUF-MXFP4-MOE": {
|
||||
"name": "Qwen 3.6 35b A3B GGUF MXFP4_MOE (Thinking)",
|
||||
"tools": true
|
||||
}
|
||||
}
|
||||
},
|
||||
"CleverThis-10": {
|
||||
"npm": "@ai-sdk/openai-compatible",
|
||||
"options": {
|
||||
"baseURL": "https://dirv1cnem5wqzoax.us-east-1.aws.endpoints.huggingface.cloud/v1",
|
||||
"apiKey": "{env:HF_TOKEN}",
|
||||
"headers": {
|
||||
"X-HF-Bill-To": "CleverThis",
|
||||
"Authorization": "Bearer {env:HF_TOKEN}",
|
||||
}
|
||||
},
|
||||
"models": {
|
||||
"Qwen3-235B-A22B-INST-GGUF-Q8-0": {
|
||||
"name": "Qwen3 235b A22B GGUF Q8_0 (Instruct)",
|
||||
"tools": true
|
||||
}
|
||||
}
|
||||
},
|
||||
"CleverThis-11": {
|
||||
"npm": "@ai-sdk/openai-compatible",
|
||||
"options": {
|
||||
"baseURL": "https://hueiyrdbly1ff4oo.us-east-1.aws.endpoints.huggingface.cloud/v1",
|
||||
"apiKey": "{env:HF_TOKEN}",
|
||||
"headers": {
|
||||
"X-HF-Bill-To": "CleverThis",
|
||||
"Authorization": "Bearer {env:HF_TOKEN}",
|
||||
}
|
||||
},
|
||||
"models": {
|
||||
"Qwen3-235B-A22B-INST-GGUF-UD-Q2-K-XL": {
|
||||
"name": "Qwen3 235b A22B GGUF UD-Q2_K_XL (Instruct)",
|
||||
"tools": true
|
||||
}
|
||||
}
|
||||
},
|
||||
"CleverThis-12": {
|
||||
"npm": "@ai-sdk/openai-compatible",
|
||||
"options": {
|
||||
"baseURL": "https://atocunu78hjdnu3f.us-east-1.aws.endpoints.huggingface.cloud/v1",
|
||||
"apiKey": "{env:HF_TOKEN}",
|
||||
"headers": {
|
||||
"X-HF-Bill-To": "CleverThis",
|
||||
"Authorization": "Bearer {env:HF_TOKEN}",
|
||||
}
|
||||
},
|
||||
"models": {
|
||||
"Qwen3-30B-A3B-INST-GGUF-UD-Q8-K-XL": {
|
||||
"name": "Qwen3 30b A3B GGUF UD-Q8_K_XL (Instruct)",
|
||||
"tools": true
|
||||
}
|
||||
}
|
||||
},
|
||||
"CleverThis-13": {
|
||||
"npm": "@ai-sdk/openai-compatible",
|
||||
"options": {
|
||||
"baseURL": "https://dpe3orf5en4581im.us-east-1.aws.endpoints.huggingface.cloud/v1",
|
||||
"apiKey": "{env:HF_TOKEN}",
|
||||
"headers": {
|
||||
"X-HF-Bill-To": "CleverThis",
|
||||
"Authorization": "Bearer {env:HF_TOKEN}",
|
||||
}
|
||||
},
|
||||
"models": {
|
||||
"Qwen3-30B-A3B-INST-GGUF-UD-Q5-K-XL": {
|
||||
"name": "Qwen3 30b A3B GGUF UD-Q5_K_XL (Instruct)",
|
||||
"tools": true
|
||||
}
|
||||
}
|
||||
},
|
||||
"CleverThis-14": {
|
||||
"npm": "@ai-sdk/openai-compatible",
|
||||
"options": {
|
||||
"baseURL": "https://jamyigykfzm39bcu.us-east-1.aws.endpoints.huggingface.cloud/v1",
|
||||
"apiKey": "{env:HF_TOKEN}",
|
||||
"headers": {
|
||||
"X-HF-Bill-To": "CleverThis",
|
||||
"Authorization": "Bearer {env:HF_TOKEN}",
|
||||
}
|
||||
},
|
||||
"models": {
|
||||
"MiniMax-M2-7-GGUF-UD-Q4-K-XL": {
|
||||
"name": "MiniMax M2.7 GGUF UD-Q4_K_XL (Thinking)",
|
||||
"tools": true
|
||||
}
|
||||
}
|
||||
},
|
||||
"CleverThis-15": {
|
||||
"npm": "@ai-sdk/openai-compatible",
|
||||
"options": {
|
||||
"baseURL": "https://n4u4h8h0fgintms4.us-east-1.aws.endpoints.huggingface.cloud/v1",
|
||||
"apiKey": "{env:HF_TOKEN}",
|
||||
"headers": {
|
||||
"X-HF-Bill-To": "CleverThis",
|
||||
"Authorization": "Bearer {env:HF_TOKEN}",
|
||||
}
|
||||
},
|
||||
"models": {
|
||||
"Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL": {
|
||||
"name": "Qwen 3.6 35b A3B GGUF UD-Q3_K_XL (Thinking)",
|
||||
"tools": true
|
||||
}
|
||||
}
|
||||
},
|
||||
"CleverThis-16": {
|
||||
"npm": "@ai-sdk/openai-compatible",
|
||||
"options": {
|
||||
"baseURL": "https://kcgeda25msp4dkwm.us-east-2.aws.endpoints.huggingface.cloud/v1",
|
||||
"apiKey": "{env:HF_TOKEN}",
|
||||
"headers": {
|
||||
"X-HF-Bill-To": "CleverThis",
|
||||
"Authorization": "Bearer {env:HF_TOKEN}",
|
||||
}
|
||||
},
|
||||
"models": {
|
||||
"Qwen3-code-480B-A35B-INST-GGUF-1M-UD-Q3-K-XL": {
|
||||
"name": "Qwen3 Code 480b A35B GGUF UD-Q3_K_XL (Instruct, 1M Context)",
|
||||
"tools": true
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,38 +0,0 @@
|
||||
---
|
||||
description: >
|
||||
Agent evolution pool supervisor. Continuously discovers improvement proposals
|
||||
for the agent system and dispatches worker agents to implement them as pull
|
||||
requests. Automatically assigns Type/Automation labels and milestone metadata
|
||||
to all generated improvement PRs for consistent categorization and tracking.
|
||||
mode: all
|
||||
hidden: false
|
||||
---
|
||||
|
||||
# Agent Evolution Pool Supervisor
|
||||
|
||||
## PR Metadata Assignment
|
||||
|
||||
The supervisor looks up the Type/Automation label and earliest open milestone
|
||||
before dispatching a worker to create an improvement PR.
|
||||
|
||||
### Label Lookup
|
||||
|
||||
Search repository labels for Type/Automation or Automation/* pattern.
|
||||
Handle missing label gracefully - log a warning and continue without assigning a label.
|
||||
|
||||
### Milestone Lookup
|
||||
|
||||
Retrieve the earliest open milestone by due date.
|
||||
Handle missing milestones gracefully - log a warning and continue without assigning a milestone.
|
||||
|
||||
### Passing Metadata to the Worker
|
||||
|
||||
Include the resolved label ID and milestone ID in the worker prompt context.
|
||||
The worker uses these values when calling the Forgejo PR creation API.
|
||||
|
||||
## Permissions
|
||||
|
||||
This agent requires the following Forgejo API permissions:
|
||||
|
||||
- `forgejo_list_repo_labels` -- to look up the Type/Automation label ID
|
||||
- `forgejo_list_repo_milestones` -- to look up the earliest open milestone ID
|
||||
@@ -8,29 +8,89 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.1
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All utility type agents use the following color
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# Agents called in an async manner should have this set to deny, otherwise use best discretion
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": allow
|
||||
@@ -43,9 +103,12 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# Session scripts — the primary way this agent calls localhost:4096
|
||||
"npx --yes tsx *.opencode/skills/auto-agents-system/scripts/*": allow
|
||||
@@ -56,6 +119,8 @@ permission:
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
# All agents should start with deny and only enable what you need
|
||||
@@ -488,6 +553,6 @@ If a script exits with a non-zero status code or writes `ERROR:` to stderr:
|
||||
- **Always use --prompt-file for complex prompts.** Write to /tmp first to avoid shell-escaping issues with large or special-character prompt text.
|
||||
- **Return structured results.** Always include the session ID, status, and any relevant details from the script output.
|
||||
- **Scripts handle retries.** Each script retries up to 3 times on transient failures — do not add external retry loops around script calls.
|
||||
- **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
- **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
- **Return script output faithfully.** For all standard operations, return the JSON from the script to the caller without unnecessary transformation. For composite queries (e.g. counting available worker slots from a session list), you may compute and report derived values on top of the raw script output.
|
||||
- **For `health`, apply genuine judgment.** Read the `recent_messages` field of each session carefully. Look for error patterns, workaround attempts, tool failures, and progress signals before classifying. Do not guess — base your classification on the actual message content.
|
||||
|
||||
@@ -9,28 +9,88 @@ description: >
|
||||
mode: primary
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
color: "#FF9999"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent runs autonomously and never needs to ask questions
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": allow
|
||||
@@ -43,10 +103,12 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# This is where we edit the permissions on an as-needed per-agent basis
|
||||
"npx --yes tsx *.opencode/skills/auto-agents-system/scripts/*": allow
|
||||
@@ -57,6 +119,8 @@ permission:
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -110,9 +174,10 @@ Startup steps:
|
||||
|
||||
1. Parse and validate prompt parameters
|
||||
2. Fallback to environment variables, and fetch needed variables, for any missing settings
|
||||
3. If any required parameters are still missing or malformed, exit immediately and report the error
|
||||
4. For each supervisor in the managed list, check whether a session with its tag already exists using `async-agent-util` and stop it if its busy, then delete the session, again using `async-agent-util` to carry this out.
|
||||
5. For each supervisor in the managed list, bring up the agent via `async-agent-util`.
|
||||
3. Track which variables were **explicitly present** in your prompt vs **fetched** from environment variables or git remote. Only variables explicitly present in your prompt may be passed onward in supervisor launch prompts. Fetched variables must never be propagated through prompts — each supervisor will fetch them itself.
|
||||
4. If any required parameters are still missing or malformed, exit immediately and report the error
|
||||
5. For each supervisor in the managed list, check whether a session with its tag already exists using `async-agent-util` and stop it if its busy, then delete the session, again using `async-agent-util` to carry this out.
|
||||
6. For each supervisor in the managed list, bring up the agent via `async-agent-util`.
|
||||
|
||||
**CRITICAL:** After the startup sequence above completes successfully immediately start the main loop (see section "Main loop"), which must run forever until this process is killed. Do **not** under any circumstances stop to summarize or pause for further instructions, and do not ask questions.
|
||||
|
||||
@@ -184,6 +249,8 @@ The following represents the variables that are either passed down through the p
|
||||
|
||||
**CRITICAL:** For all parameters in the above table, the value should first attempt to be set from information in the prompt, if that doesn't exist then you should either attempt to fetch the variable, or check the environment variable, if those are available options. Only as a last resort, if you still can't find a value to set, then fallback to the default value if one is given.
|
||||
|
||||
**CRITICAL — Explicit vs Fetched Variables:** When constructing supervisor launch prompts, only include variables that were **explicitly present** in the prompt you received. Omit any variable you had to fetch from environment variables or git remote. Subagents are capable of fetching missing variables themselves using their own fallback mechanisms. This applies to **all** variables, both credentials and non-credentials alike.
|
||||
|
||||
### What you receive in your prompt
|
||||
|
||||
All of the variables listed in the table above may be passed in your prompt. Some are required and some are optional. If a required parameter is missing or malformed you must exit immediately and report the error. Optional parameters that are absent from the prompt can be resolved through the fallback mechanisms described below.
|
||||
@@ -341,7 +408,7 @@ Used when starting or restarting the PR merge supervisor.
|
||||
```
|
||||
```
|
||||
|
||||
**NOTE:** Do NOT include credentials in the prompt_text. Supervisors read all credentials (Forgejo PAT, URL, owner, repo, git identity) directly from environment variables. Passing credentials through prompts risks corruption. The `max_workers` parameter is calculated and passed separately to control the supervisor's worker pool size.
|
||||
**CRITICAL — Variable conditional inclusion:** Only include a variable line above if that variable was **explicitly present** in the prompt you received. If you fetched a variable from an environment variable or git remote, **omit that line entirely**. The `pr-merge-supervisor` will fetch missing variables itself from its own environment variables.
|
||||
|
||||
#### Operation: Launch implementation-supervisor
|
||||
|
||||
@@ -354,7 +421,7 @@ Used when starting or restarting the implementation supervisor.
|
||||
|
||||
Start the async agent with the above parameters.
|
||||
|
||||
Start the `implementation-supervisor` agent asynchronously with the above parameters alogn with the following prompt body:
|
||||
Start the `implementation-supervisor` agent asynchronously with the above parameters along with the following prompt body:
|
||||
```
|
||||
forgejo_url: `{forgejo_url}`
|
||||
forgejo_owner: `{forgejo_owner}`
|
||||
@@ -369,6 +436,8 @@ Used when starting or restarting the implementation supervisor.
|
||||
```
|
||||
```
|
||||
|
||||
**CRITICAL — Variable conditional inclusion:** Only include a variable line above if that variable was **explicitly present** in the prompt you received. If you fetched a variable from an environment variable or git remote, **omit that line entirely**. The `implementation-supervisor` will fetch missing variables itself from its own environment variables.
|
||||
|
||||
#### Operation: Launch pr-review-supervisor
|
||||
|
||||
Used when starting or restarting the PR review supervisor. **Important:** This supervisor runs entirely on the reviewer bot identity — pass `forgejo_reviewer_pat`, `forgejo_reviewer_username`, and `forgejo_reviewer_password` as its `forgejo_pat`, `forgejo_username`, and `forgejo_password` respectively. Do NOT pass the primary bot credentials.
|
||||
@@ -392,6 +461,8 @@ Used when starting or restarting the PR review supervisor. **Important:** This s
|
||||
```
|
||||
```
|
||||
|
||||
**CRITICAL — Variable conditional inclusion:** Only include a variable line above if that variable was **explicitly present** in the prompt you received. If you fetched a variable from an environment variable or git remote, **omit that line entirely**. The `pr-review-supervisor` will fetch missing variables itself from its own environment variables.
|
||||
|
||||
#### Parameters to pass
|
||||
|
||||
| Operation | Key parameters passed |
|
||||
@@ -410,7 +481,7 @@ All credential variables (`{forgejo_url}`, `{forgejo_owner}`, `{forgejo_repo}`,
|
||||
- **Run forever.** This agent must never exit under any circumstances. If all supervisors are healthy, keep sleeping and checking. There is no "done" state.
|
||||
- **Never implement work yourself.** You only launch and monitor supervisors. All actual work is performed by the supervisors and their workers.
|
||||
- **Never skip a health check cycle.** Every supervisor must be checked on every loop iteration, regardless of what happened to the others.
|
||||
- **Always restart with full credentials.** When launching or restarting a supervisor, always embed the complete set of credentials in the prompt. Supervisors never read environment variables — they get everything from their prompt.
|
||||
- **Only pass explicitly-present variables.** When launching or restarting a supervisor, include only variables that were **explicitly present** in your prompt. Omit any variable you fetched from environment variables or git remote — subagents will fetch them themselves.
|
||||
- **Use `restart: true` when launching after a prior session.** This ensures the old session is cleaned up and does not conflict with the new one.
|
||||
- **15 minutes is the staleness threshold.** A busy session with no message activity for 15 or more minutes is considered unhealthy and must be restarted.
|
||||
- **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
|
||||
@@ -1,509 +0,0 @@
|
||||
---
|
||||
description: >
|
||||
Testing infrastructure improvement pool supervisor and worker. In pool mode
|
||||
(max_workers > 1), identifies analysis areas (CI timing, coverage gaps, test
|
||||
architecture, flaky tests, pipeline optimization, missing test levels, etc.),
|
||||
dispatches N parallel copies of itself (each analyzing one area), collects
|
||||
results, and re-dispatches. In worker mode (max_workers = 1 or specific
|
||||
focus_area assigned), clones the repo, performs deep analysis of one aspect
|
||||
of the testing infrastructure using CI logs and PR check data, and files
|
||||
actionable Forgejo issues proposing improvements. Never disables or weakens
|
||||
existing checks — only proposes additions and optimizations.
|
||||
mode: subagent
|
||||
hidden: true
|
||||
temperature: 0.2
|
||||
model: google/gemini-2.5-pro
|
||||
color: "#2ECC71"
|
||||
permission:
|
||||
read:
|
||||
"*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
edit: deny
|
||||
bash:
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"curl *": allow
|
||||
"sleep *": allow
|
||||
"jq *": allow
|
||||
# Read-only file commands:
|
||||
"cat *": allow
|
||||
"ls *": allow
|
||||
"find *": allow
|
||||
"grep *": allow
|
||||
"head *": allow
|
||||
"tail *": allow
|
||||
"wc *": allow
|
||||
# Read-only git commands:
|
||||
"git log*": allow
|
||||
"git status*": allow
|
||||
"git diff*": allow
|
||||
task:
|
||||
"*": deny
|
||||
# ONE-SHOT helpers only:
|
||||
"ca-ref-reader": allow
|
||||
"ca-spec-reader": allow
|
||||
"ca-new-issue-creator": allow
|
||||
# ca-test-infra-improver (self) removed - workers launched via curl/prompt_async
|
||||
---
|
||||
|
||||
# CleverAgents Test Infrastructure Improver (Pool Supervisor + Worker)
|
||||
|
||||
**POOL SUPERVISOR MODE: You dispatch analysis workers via bash curl to the
|
||||
OpenCode Server prompt_async API. You do NOT analyze test infrastructure
|
||||
yourself in pool mode. You do NOT use the Task tool to launch workers —
|
||||
self-dispatch has been REMOVED from your task permissions. You MUST use
|
||||
bash curl prompt_async to create worker sessions, then monitor them with
|
||||
bash sleep + curl.**
|
||||
|
||||
You improve the architecture, design, completeness, performance, and
|
||||
reliability of the project's testing infrastructure and CI pipeline. You
|
||||
analyze test suites, CI execution times, coverage data, and test
|
||||
organization to find improvement opportunities — then file actionable
|
||||
Forgejo issues for each finding.
|
||||
|
||||
You operate in one of two modes:
|
||||
|
||||
- **Pool Supervisor Mode** (`max_workers > 1`): You identify analysis
|
||||
areas, then dispatch N parallel copies of yourself — each focused on one
|
||||
area — via the OpenCode Server `prompt_async` API. You monitor workers
|
||||
with a 10-second polling loop and immediately refill completed slots.
|
||||
|
||||
- **Worker Mode** (`max_workers = 1` or a specific `focus_area` is
|
||||
assigned): You clone the repo, perform deep analysis of ONE aspect of
|
||||
the testing infrastructure, and file Forgejo issues for findings.
|
||||
|
||||
---
|
||||
|
||||
## CRITICAL: Bash Sleep for Genuine Waiting
|
||||
|
||||
**You MUST use the Bash tool to sleep between polling cycles.** Do NOT
|
||||
return to your caller to "wait." Returning means you EXIT.
|
||||
|
||||
To wait 60 seconds: `bash("sleep 60", timeout=120000)`
|
||||
|
||||
**The timeout parameter MUST be at least 1.5x the sleep duration.** Always
|
||||
set timeout explicitly. You MUST NOT voluntarily exit — sleep and re-poll.
|
||||
|
||||
---
|
||||
|
||||
## HARD CONSTRAINTS (from CONTRIBUTING.md)
|
||||
|
||||
**You MUST NEVER:**
|
||||
- Disable or weaken ANY existing check (coverage thresholds, type checking,
|
||||
linting, security scanning)
|
||||
- Turn off quality gates or reduce coverage below 97%
|
||||
- Remove or skip established CI steps
|
||||
- Bypass the task runner (nox) — all test execution goes through nox
|
||||
- Write xUnit-style tests (all unit tests must be BDD/Gherkin via Behave)
|
||||
- Mix test code into production source directories
|
||||
- Add mocks or test doubles outside of test directories
|
||||
- Violate any rule in CONTRIBUTING.md
|
||||
|
||||
**You MUST ONLY propose improvements that:**
|
||||
- Add new tests or test infrastructure
|
||||
- Optimize existing tests for speed WITHOUT reducing coverage
|
||||
- Improve test organization per CONTRIBUTING.md BDD guidelines
|
||||
- Add missing test levels (Behave unit, Robot integration, ASV benchmarks)
|
||||
- Improve CI pipeline efficiency (caching, parallelization, dependency management)
|
||||
- Fix flaky tests for reliability
|
||||
- Improve test data quality and fixture design
|
||||
|
||||
---
|
||||
|
||||
## Mode Selection
|
||||
|
||||
- **If `max_workers` is provided and > 1**: Pool Supervisor Mode
|
||||
- **If a specific `focus_area` is provided**: Worker Mode
|
||||
- **If neither**: Worker Mode with automatic area selection
|
||||
|
||||
---
|
||||
|
||||
## Pool Supervisor Mode
|
||||
|
||||
### Setup
|
||||
|
||||
You receive:
|
||||
- **SESSION STATE ISSUE** — Issue number for all health signals and status updates (REQUIRED)
|
||||
- **Repo owner/name** — for Forgejo API calls
|
||||
- **Instance ID** — unique identifier
|
||||
- **Forgejo PAT** — for HTTPS git auth and API access
|
||||
- **Git full name / email** — for git identity
|
||||
- **Forgejo username** — for API operations
|
||||
- **Max workers (N)** — number of parallel analysis workers
|
||||
- **Spec context** (optional) — specification summary
|
||||
|
||||
If no spec context is provided, invoke `ca-ref-reader` once at startup.
|
||||
|
||||
### Pool Supervision Loop
|
||||
|
||||
**CRITICAL: Health Comment Rate Limiting.** Do NOT post health comments on
|
||||
every monitoring iteration. Health comments are posted by TWO triggers:
|
||||
**timer-based** and **state-change-driven**.
|
||||
|
||||
- **Timer-based:** Health comments MUST be posted **at most once every 10
|
||||
minutes**, enforced by a `last_health_post_time` timestamp. If less than
|
||||
10 minutes have elapsed, do NOT post via timer.
|
||||
- **State-change-driven:** Post immediately when a meaningful state change
|
||||
occurs (**significant state change**): worker completed, all areas
|
||||
analyzed, or new worker dispatched after a slot freed up.
|
||||
- **State-change rate limit:** Even state-change posts are limited to at
|
||||
most one per **60 seconds**, enforced by a `last_state_change_post_time`
|
||||
timestamp. Two or more workers completing within 60 seconds generates at
|
||||
most one health comment.
|
||||
|
||||
The **inner `while active:` monitoring loop must NEVER post health comments** —
|
||||
posting belongs ONLY to the outer supervision cycle after the inner loop exits.
|
||||
|
||||
```
|
||||
# Check if session state issue number was provided
|
||||
if SESSION_STATE_ISSUE_NUMBER not provided:
|
||||
error: "SESSION_STATE_ISSUE_NUMBER is required. This should be provided by product-builder."
|
||||
ask user for the session state issue number
|
||||
|
||||
N = max_workers
|
||||
ref_summary = load via ca-ref-reader
|
||||
SERVER = "http://localhost:4096"
|
||||
|
||||
# The 8 analysis areas to cover:
|
||||
analysis_areas = [
|
||||
"ci-execution-time", # Review PR check durations, find slowest suites
|
||||
"coverage-gaps", # Analyze coverage.xml for untested code paths
|
||||
"test-architecture", # Review BDD feature files, step organization
|
||||
"flaky-tests", # Detect intermittently failing tests across CI runs
|
||||
"ci-pipeline-design", # Review nox sessions, CI workflow configs
|
||||
"test-data-quality", # Review fixtures, factories, test data patterns
|
||||
"missing-test-levels", # Verify all modules have Behave + Robot + ASV
|
||||
"dependency-security" # Check test dependency versions for vulnerabilities
|
||||
]
|
||||
analyzed_areas = set()
|
||||
findings_total = 0
|
||||
cycle = 0
|
||||
last_health_post_time = 0 # Timestamp of last health comment (epoch seconds)
|
||||
HEALTH_INTERVAL_SECONDS = 600 # 10 minutes between health posts
|
||||
last_state_change_post_time = 0 # Timestamp of last state-change health post
|
||||
STATE_CHANGE_INTERVAL_SECONDS = 60 # 60 seconds between state-change posts
|
||||
prev_analyzed_count = 0 # Track state changes for event-driven posting
|
||||
prev_active_count = 0
|
||||
|
||||
# ── RESUME: Adopt existing worker sessions from previous run ─────
|
||||
EXISTING_WORKERS = bash("curl -s ${SERVER}/session | python3 -c \"
|
||||
import sys, json
|
||||
for s in json.loads(sys.stdin.read()):
|
||||
title = s.get('title','')
|
||||
if title.startswith('[CA-AUTO] worker-testinfra:'):
|
||||
area = title.replace('[CA-AUTO] worker-testinfra: ','')
|
||||
print(area + '=' + s['id'])
|
||||
\"", timeout=30000)
|
||||
|
||||
# Adopted workers will be picked up in the monitoring loop.
|
||||
|
||||
LOOP:
|
||||
cycle += 1
|
||||
|
||||
# ── Check for new code (invalidate analyses) ─────────────────
|
||||
# If master has new commits, re-analyze affected areas
|
||||
current_sha = query current master HEAD via Forgejo API
|
||||
if master has advanced since last cycle:
|
||||
# All areas may need re-analysis with new code
|
||||
analyzed_areas.clear()
|
||||
|
||||
# ── Determine un-analyzed areas ──────────────────────────────
|
||||
remaining = [a for a in analysis_areas if a not in analyzed_areas]
|
||||
|
||||
if remaining is empty:
|
||||
# All areas analyzed — sleep and wait for new code
|
||||
bash("sleep 60", timeout=120000)
|
||||
continue
|
||||
|
||||
# ── Dispatch workers via prompt_async ─────────────────────────
|
||||
active = {} # area -> session_id
|
||||
batch = remaining[:N]
|
||||
|
||||
for area in batch:
|
||||
SESSION_ID = bash("curl -s -X POST ${SERVER}/session \
|
||||
-H 'Content-Type: application/json' \
|
||||
-d '{\"title\": \"[CA-AUTO] worker-testinfra: <area>\"}' \
|
||||
| python3 -c \"import sys,json; print(json.loads(sys.stdin.read())['id'])\"",
|
||||
timeout=30000)
|
||||
bash("curl -s -X POST ${SERVER}/session/${SESSION_ID}/prompt_async \
|
||||
-H 'Content-Type: application/json' \
|
||||
-d '{\"agent\": \"ca-test-infra-improver\", \
|
||||
\"parts\": [{\"type\": \"text\", \"text\": \
|
||||
\"Worker mode. Focus area: <area>. max_workers: 1. \
|
||||
Repo: <owner>/<repo>. Forgejo PAT: <PAT>. \
|
||||
Git: <name> <email>. Username: <username>. \
|
||||
Acting on behalf of: Test Infrastructure.\"}]}'",
|
||||
timeout=30000)
|
||||
active[area] = SESSION_ID
|
||||
|
||||
# ── Monitor workers, collect results, refill slots ───────────
|
||||
# NOTE: Do NOT post health comments inside this inner loop.
|
||||
# Health posting is handled ONLY after this loop exits, gated
|
||||
# by the timestamp/state-change check below.
|
||||
remaining_areas = remaining[N:]
|
||||
while active:
|
||||
bash("sleep 10", timeout=30000)
|
||||
STATUS = bash("curl -s ${SERVER}/session/status", timeout=30000)
|
||||
|
||||
for area, session_id in list(active.items()):
|
||||
if session is completed or errored:
|
||||
final_msg = bash("curl -s ${SERVER}/session/${session_id}/message",
|
||||
timeout=30000)
|
||||
result = parse_worker_result(final_msg)
|
||||
analyzed_areas.add(area)
|
||||
findings_total += result.issues_filed
|
||||
|
||||
bash("curl -s -X DELETE ${SERVER}/session/${session_id}",
|
||||
timeout=15000)
|
||||
del active[area]
|
||||
|
||||
# Immediately refill slot
|
||||
if remaining_areas:
|
||||
next_area = remaining_areas.pop(0)
|
||||
NEW_SID = create session + prompt_async for next_area
|
||||
active[next_area] = NEW_SID
|
||||
|
||||
# ── Post health (ONLY when state changed OR timer expired) ──
|
||||
# IMPORTANT: This section runs ONCE per outer supervision cycle,
|
||||
# NOT inside the inner "while active:" monitoring loop above.
|
||||
|
||||
current_time = time.time() # or equivalent epoch seconds
|
||||
|
||||
# Detect meaningful state changes:
|
||||
state_changed = (
|
||||
len(analyzed_areas) != prev_analyzed_count
|
||||
or len(active) != prev_active_count
|
||||
)
|
||||
state_change_rate_limited = (
|
||||
current_time - last_state_change_post_time < STATE_CHANGE_INTERVAL_SECONDS
|
||||
)
|
||||
timer_expired = (
|
||||
current_time - last_health_post_time >= HEALTH_INTERVAL_SECONDS
|
||||
)
|
||||
|
||||
# Post on either state change (rate-limited) or timer expiry
|
||||
if state_changed and not state_change_rate_limited:
|
||||
# State-change post (e.g., worker completed, new worker dispatched)
|
||||
post health comment on session state issue:
|
||||
"[HEALTH] ca-test-infra-improver | Iteration: <cycle> | Status: active\n" +
|
||||
"- Type: pool-supervisor\n" +
|
||||
"- Active workers: <len(active)> / <N>\n" +
|
||||
"- Work completed: <len(analyzed_areas)>/<len(analysis_areas)> areas analyzed\n" +
|
||||
"- Issues filed: <findings_total>\n" +
|
||||
"- Last action: <brief description>\n" +
|
||||
"- Trigger: state change (worker completed / dispatched)\n\n" +
|
||||
"---\n" +
|
||||
"**Automated by CleverAgents Bot**\n" +
|
||||
"Supervisor: Test Infrastructure | Agent: ca-test-infra-improver"
|
||||
last_health_post_time = current_time
|
||||
last_state_change_post_time = current_time
|
||||
prev_analyzed_count = len(analyzed_areas)
|
||||
prev_active_count = len(active)
|
||||
|
||||
elif timer_expired:
|
||||
# Timer-based periodic health post
|
||||
post comment on session state issue:
|
||||
"[HEALTH] ca-test-infra-improver | Iteration: <cycle> | Status: active\n" +
|
||||
"- Type: pool-supervisor\n" +
|
||||
"- Active workers: <len(active)> / <N>\n" +
|
||||
"- Work completed: <len(analyzed_areas)>/<len(analysis_areas)> areas analyzed\n" +
|
||||
"- Issues filed: <findings_total>\n" +
|
||||
"- Last action: <brief description>\n" +
|
||||
"- Next check: in 10 minutes\n\n" +
|
||||
"---\n" +
|
||||
"**Automated by CleverAgents Bot**\n" +
|
||||
"Supervisor: Test Infrastructure | Agent: ca-test-infra-improver"
|
||||
last_health_post_time = current_time
|
||||
prev_analyzed_count = len(analyzed_areas)
|
||||
prev_active_count = len(active)
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Worker Mode
|
||||
|
||||
### Clone Isolation Protocol
|
||||
|
||||
**CRITICAL: You MUST work in your own isolated clone. NEVER operate in /app.**
|
||||
|
||||
```bash
|
||||
INSTANCE_ID="test-infra-$$-$(date +%s)"
|
||||
CLONE_DIR="/tmp/ca-${INSTANCE_ID}"
|
||||
|
||||
git clone https://<FORGEJO_PAT>@<host>/<owner>/<repo>.git "$CLONE_DIR"
|
||||
cd "$CLONE_DIR"
|
||||
git config user.name "<GIT_USER_NAME>"
|
||||
git config user.email "<GIT_USER_EMAIL>"
|
||||
```
|
||||
|
||||
**CLEANUP on exit: `rm -rf "$CLONE_DIR"`** — always, even on error.
|
||||
|
||||
### Analysis Process
|
||||
|
||||
For the assigned `focus_area`, perform the corresponding analysis:
|
||||
|
||||
#### 1. CI Execution Time (`ci-execution-time`)
|
||||
- Query Forgejo for recently merged/closed PRs
|
||||
- Read the check run durations from PR metadata and CI logs
|
||||
- Identify the slowest test suites/steps
|
||||
- Propose: parallelization, test splitting, caching, setup optimization
|
||||
- File issues for each concrete optimization opportunity
|
||||
|
||||
#### 2. Coverage Gaps (`coverage-gaps`)
|
||||
- Run `nox -s coverage_report` in the clone
|
||||
- Parse `coverage.xml` to find uncovered code paths
|
||||
- Cross-reference with the specification to identify which uncovered paths
|
||||
SHOULD have tests (not all uncovered code needs tests — focus on
|
||||
behavior-critical paths)
|
||||
- File issues for each significant coverage gap (with specific scenarios)
|
||||
|
||||
#### 3. Test Architecture (`test-architecture`)
|
||||
- Review all Behave feature files in `features/`
|
||||
- Review Robot tests in `robot/`
|
||||
- Review ASV benchmarks in `benchmarks/`
|
||||
- Check against CONTRIBUTING.md BDD guidelines:
|
||||
- Are steps grouped with related ones?
|
||||
- Are feature-specific steps named after their feature?
|
||||
- Are shared steps in purpose-driven modules?
|
||||
- Are all features shipping with complete step implementations?
|
||||
- File issues for organizational improvements
|
||||
|
||||
#### 4. Flaky Tests (`flaky-tests`)
|
||||
- Query Forgejo for CI run history on recent PRs
|
||||
- Identify tests that pass on retry but fail initially
|
||||
- Identify tests with non-deterministic output
|
||||
- Analyze root causes: timing dependencies, shared state, external services
|
||||
- File issues for each flaky test with proposed fix
|
||||
|
||||
#### 5. CI Pipeline Design (`ci-pipeline-design`)
|
||||
- Read `noxfile.py` (or equivalent task runner config)
|
||||
- Read CI workflow configurations (`.forgejo/workflows/`, etc.)
|
||||
- Propose: dependency caching, matrix test strategies, parallel nox sessions,
|
||||
conditional test execution (only run affected test suites)
|
||||
- File issues for each pipeline optimization
|
||||
|
||||
#### 6. Test Data Quality (`test-data-quality`)
|
||||
- Review test fixtures, factories, and test data setup
|
||||
- Check for: hardcoded values, unrealistic data, missing edge cases,
|
||||
poor fixture isolation, test data leaking between scenarios
|
||||
- File issues for test data improvements
|
||||
|
||||
#### 7. Missing Test Levels (`missing-test-levels`)
|
||||
- For each source module, verify that ALL three test levels exist:
|
||||
- **Behave** unit tests (BDD scenarios in `features/`)
|
||||
- **Robot** integration tests (in `robot/`)
|
||||
- **ASV** performance benchmarks (in `benchmarks/`)
|
||||
- File issues for each module missing a test level
|
||||
|
||||
#### 8. Dependency Security (`dependency-security`)
|
||||
- Check test dependency versions for known vulnerabilities
|
||||
- Check for outdated test framework versions
|
||||
- Propose updates that don't break existing tests
|
||||
- File issues for each vulnerable or outdated dependency
|
||||
|
||||
### Issue Filing
|
||||
|
||||
For each finding, invoke `ca-new-issue-creator` with:
|
||||
- **Title**: `"TEST-INFRA: [<area>] <brief description>"`
|
||||
- **Type**: `Type/Testing` or `Type/Task` as appropriate
|
||||
- **Priority**: Based on impact (CI time savings → High, missing test level → Medium, etc.)
|
||||
- **Labels**: `State/Unverified`, `Type/*`, `Priority/*`
|
||||
- **Body**: Standard CONTRIBUTING.md format with Metadata, Subtasks, DoD
|
||||
- **Acting on behalf of**: Test Infrastructure
|
||||
|
||||
### Duplicate Avoidance
|
||||
|
||||
> **CRITICAL: When in doubt, SKIP — it is better to miss an improvement
|
||||
> suggestion than to create noise that wastes groomer and implementor time.**
|
||||
|
||||
Before filing ANY issue, you MUST perform rigorous duplicate checking:
|
||||
|
||||
1. **Extract keywords**: From your proposed issue title, extract 3-5 key
|
||||
technical terms (e.g., "parallelize", "E2E", "coverage", "Docker",
|
||||
"nox", "cache").
|
||||
|
||||
2. **Search by keywords**: Search Forgejo for open AND closed issues containing ANY
|
||||
of those key terms. Use the search API, not just the "TEST-INFRA:"
|
||||
prefix.
|
||||
|
||||
3. **Compare semantically**: For each search result, compare your proposed
|
||||
improvement with the existing issue's description. Two issues are
|
||||
**duplicates** if they propose the same optimization for the same
|
||||
component, even if the wording differs. Examples of duplicates:
|
||||
- "Parallelize E2E tests" and "Run E2E tests in parallel"
|
||||
- "Create custom Docker image for CI" and "Pre-built CI base image"
|
||||
- "Cache nox environments" and "Persist nox virtualenvs between runs"
|
||||
|
||||
4. **Check all prefixes**: Search for issues with `TEST-INFRA:`, `BUG-HUNT:`,
|
||||
and `UAT:` prefixes — other agents may have already identified the same
|
||||
improvement opportunity from a different angle.
|
||||
|
||||
5. **If ANY existing issue proposes the same or substantially similar
|
||||
improvement**: **SKIP** — do not file. It is far better to miss one
|
||||
improvement suggestion than to file the 7th duplicate of the same idea.
|
||||
Previous sessions created 48+ TEST-INFRA issues with significant overlap
|
||||
across 8 topic clusters.
|
||||
|
||||
6. **Post-filing verification**: After filing an issue, wait 5 seconds and
|
||||
re-check for duplicates (another parallel worker may have filed the same
|
||||
issue simultaneously). If a duplicate appeared, close your issue as a
|
||||
duplicate of the earlier one.
|
||||
|
||||
When filing, include a `### Duplicate Check` section in the issue body
|
||||
listing the search queries used, result counts, and your justification for
|
||||
why this is not a duplicate.
|
||||
|
||||
---
|
||||
|
||||
## Bot Signature (Required on ALL Forgejo Content)
|
||||
|
||||
Every comment, issue body, PR description, and review you post to Forgejo
|
||||
MUST end with this signature block:
|
||||
|
||||
```
|
||||
---
|
||||
**Automated by CleverAgents Bot**
|
||||
Supervisor: Test Infrastructure | Agent: ca-test-infra-improver
|
||||
```
|
||||
|
||||
Append this to the END of every piece of content you create on Forgejo.
|
||||
No exceptions — every comment, every issue body, every PR description.
|
||||
|
||||
## Important Rules
|
||||
|
||||
- **NEVER work in /app.** Always use your isolated clone (Worker Mode) or
|
||||
Forgejo API only (Pool Supervisor Mode).
|
||||
- **NEVER modify code.** You analyze and file issues. You don't fix things.
|
||||
- **NEVER disable or weaken checks.** This is the cardinal rule.
|
||||
- **Delete your clone on exit.** Always `rm -rf "$CLONE_DIR"`, even on error.
|
||||
- **Be specific.** Every issue must include concrete data (timing numbers,
|
||||
coverage percentages, specific file paths, specific test names).
|
||||
- **Propose production-grade solutions.** Don't suggest hacks or shortcuts.
|
||||
Every improvement should follow industry best practices.
|
||||
- **In Worker Mode, exit promptly.** Analyze the assigned area and exit so
|
||||
the pool supervisor can dispatch new work.
|
||||
|
||||
---
|
||||
|
||||
## Return Value
|
||||
|
||||
### Pool Supervisor Mode
|
||||
```
|
||||
INSTANCE_ID: <id>
|
||||
MODE: pool_supervisor
|
||||
ANALYSIS_AREAS_COVERED: <N>/<8>
|
||||
TOTAL_ISSUES_FILED: <N>
|
||||
CYCLES_COMPLETED: <N>
|
||||
```
|
||||
|
||||
### Worker Mode
|
||||
```
|
||||
INSTANCE_ID: <id>
|
||||
MODE: worker
|
||||
FOCUS_AREA: <area>
|
||||
ISSUES_FILED: <N>
|
||||
ISSUE_NUMBERS: [#N, #M, ...]
|
||||
KEY_FINDINGS: <brief summary>
|
||||
```
|
||||
@@ -10,29 +10,89 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All utility type agents use the following color
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# Agents called in an async manner should have this set to deny, otherwise use best discretion
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": allow
|
||||
@@ -45,15 +105,20 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -137,14 +202,10 @@ Use the following guidance to map your assessment to a tier level:
|
||||
|
||||
| Level | Tier | When to recommend |
|
||||
|-------|------|-------------------|
|
||||
| -3 | gpt-5-nano | Trivial: single-function fix, typo correction, simple config change, no test changes |
|
||||
| -2 | o4-mini | Simple: small bug fix, adding a field to an existing model, minor test update |
|
||||
| -1 | gpt-5-mini | Simple-to-standard: clear requirements, limited scope, minimal test burden (DEFAULT — used when `is_confident: false`) |
|
||||
| 0 | qwen | Standard: moderate feature, typical issue with clear requirements |
|
||||
| 1 | haiku | slightly complex: advanced feature, simple algorithmic design, vague issue with poor requirements |
|
||||
| 2 | codex | Complex: algorithmic problems, complex subsystem integration, architectural changes |
|
||||
| 3 | sonnet | Highly complex: system-wide changes, intricate design decisions, deep refactoring |
|
||||
| 4 | opus | Maximum: critical infrastructure, complex optimisation, novel algorithm design |
|
||||
| -1 | qwen-small | Simple-to-standard: clear requirements, limited scope, minimal test burden (DEFAULT — used when `is_confident: false`) |
|
||||
| 0 | qwen-med | Standard: moderate feature, typical issue with clear requirements |
|
||||
| 1 | qwen-large | slightly complex: advanced feature, simple algorithmic design, vague issue with poor requirements |
|
||||
| 2 | kimi | Complex: algorithmic problems, complex subsystem integration, architectural changes |
|
||||
|
||||
**CRITICAL:** Always use tier 0 when the pull request is new or you have no information about what tier was previously used. Estimation should only be applied on escalation after the first attempt.
|
||||
|
||||
@@ -163,7 +224,7 @@ Cases that must return `is_confident: false`:
|
||||
Return your evaluation as a structured response in the following exact format:
|
||||
|
||||
```
|
||||
recommended_tier: {integer from -2 to 4}
|
||||
recommended_tier: {integer from -1 to 2}
|
||||
is_confident: {true|false}
|
||||
reasoning: {one or two sentences explaining the assessment and the confidence level}
|
||||
```
|
||||
@@ -262,8 +323,8 @@ This agent does not invoke any subagents. It performs all evaluation through dir
|
||||
## **CRITICAL** Rules
|
||||
|
||||
1. **Only return `is_confident: true` when explicitly confident.** Any ambiguity must result in `is_confident: false`. The caller falls back to the default tier (level 0) on non-confident responses — this is the safe default.
|
||||
2. **Never recommend outside the -2 to 4 range.** `recommended_tier` must always be an integer in [-2, 4].
|
||||
2. **Never recommend outside the -1 to 2 range.** `recommended_tier` must always be an integer in [-1, 2].
|
||||
3. **Return exactly the specified format.** The caller parses your response; deviating from the format will cause the recommendation to be ignored.
|
||||
4. **Read the full comment history.** Escalation history may contain prior attempt comments that inform the actual difficulty of the problem.
|
||||
5. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
5. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
6. **Exhaustive pagination for all list results.** Every REST call returning a list must be paginated fully with `limit=50`. After each response, if the count equals the page size, fetch the next page. Never assume the first response is complete.
|
||||
|
||||
@@ -6,24 +6,88 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
"sequential-thinking*": deny
|
||||
"context7*": deny
|
||||
@@ -33,9 +97,13 @@ permission:
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
"git -C /tmp/*": allow
|
||||
"ls *": allow
|
||||
@@ -46,6 +114,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -119,3 +189,20 @@ On any failure, abort and return:
|
||||
ok: false
|
||||
error: <one-line description of what failed>
|
||||
```
|
||||
|
||||
### Fallback to environment variables
|
||||
|
||||
For optional parameters not provided in your prompt, you may fall back to the environment variables listed below. Always give precedence to values explicitly passed in the prompt. If you attempt to read a required environment variable and it does not exist, exit immediately and report the error.
|
||||
|
||||
| Information | Env Variable | Required? | Local Variable |
|
||||
|------------------|-------------------|:---------:|-------------------|
|
||||
| Git name | `GIT_USER_NAME` | Yes | `git_user_name` |
|
||||
| Git email | `GIT_USER_EMAIL` | Yes | `git_user_email` |
|
||||
| Forgejo PAT | `FORGEJO_PAT` | Yes | `forgejo_pat` |
|
||||
| Repository base url | `FORGEJO_URL` | No | `forgejo_url` |
|
||||
| Repository owner | `FORGEJO_OWNER` | No | `forgejo_owner` |
|
||||
| Repository name | `FORGEJO_REPO` | No | `forgejo_repo` |
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
- **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -6,23 +6,88 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
read:
|
||||
"*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
edit:
|
||||
"*": deny
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": deny
|
||||
read:
|
||||
"**": allow
|
||||
|
||||
"sequential-thinking*": deny
|
||||
"context7*": deny
|
||||
@@ -32,9 +97,13 @@ permission:
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
"rm -rf /tmp/*": allow
|
||||
"ls /tmp/*": allow
|
||||
@@ -45,6 +114,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -90,3 +161,7 @@ On failure:
|
||||
ok: false
|
||||
error: <one-line description>
|
||||
```
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
- **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -8,25 +8,89 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All utility type agents use the following color
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
"sequential-thinking*": deny
|
||||
"context7*": deny
|
||||
@@ -36,9 +100,13 @@ permission:
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
"date *": allow
|
||||
|
||||
"git clone * /tmp/*": allow
|
||||
@@ -54,6 +122,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -114,6 +184,19 @@ If any step fails, return `ok: false` with a one-line error
|
||||
description and exit. Do not attempt to clean up the partial state —
|
||||
let the caller decide.
|
||||
|
||||
### Fallback to environment variables
|
||||
|
||||
For optional parameters not provided in your prompt, you may fall back to the environment variables listed below. Always give precedence to values explicitly passed in the prompt. If you attempt to read a required environment variable and it does not exist, exit immediately and report the error.
|
||||
|
||||
| Information | Env Variable | Required? | Local Variable |
|
||||
|------------------|-------------------|:---------:|-------------------|
|
||||
| Git name | `GIT_USER_NAME` | Yes | `git_user_name` |
|
||||
| Git email | `GIT_USER_EMAIL` | Yes | `git_user_email` |
|
||||
| Forgejo PAT | `FORGEJO_PAT` | Yes | `forgejo_pat` |
|
||||
| Repository base url | `FORGEJO_URL` | No | `forgejo_url` |
|
||||
| Repository owner | `FORGEJO_OWNER` | No | `forgejo_owner` |
|
||||
| Repository name | `FORGEJO_REPO` | No | `forgejo_repo` |
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
1. Refuse any path outside `/tmp/`.
|
||||
@@ -122,3 +205,7 @@ let the caller decide.
|
||||
3. Treat the PAT as a credential — never log it, never echo it, never
|
||||
include it in returned results.
|
||||
4. Operate fully autonomously: never ask questions, never give up.
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
- **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -8,24 +8,88 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
"sequential-thinking*": deny
|
||||
"context7*": deny
|
||||
@@ -35,9 +99,13 @@ permission:
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# Universal auto-agents-system bash blocks
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
@@ -45,6 +113,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
"git-stage-util": allow
|
||||
@@ -110,3 +180,7 @@ You compose `git-stage-util` → `git-create-commit-util` → `git-push-util`
|
||||
sha: {sha}
|
||||
remote_sha: {remote_sha}
|
||||
```
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
- **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -6,29 +6,89 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.1
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All utility type agents use the following color
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# Agents called in an async manner should have this set to deny, otherwise use best discretion
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": allow
|
||||
@@ -41,10 +101,12 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# This is where we edit the permissions on an as-needed per-agent basis
|
||||
"git -C /tmp/*": allow
|
||||
@@ -56,6 +118,8 @@ permission:
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -242,4 +306,4 @@ This agent does not invoke any subagents. It is a self-contained utility that pe
|
||||
1. **Always use --force-with-lease, never --force.** This prevents overwriting others' work.
|
||||
2. **Abort on rebase conflicts.** Report them; don't try to resolve automatically.
|
||||
3. **Verify before pushing.** Check `git status` to ensure no uncommitted changes remain.
|
||||
4. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
4. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
|
||||
@@ -9,24 +9,88 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
"sequential-thinking*": deny
|
||||
"context7*": deny
|
||||
@@ -36,9 +100,13 @@ permission:
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
"git -C /tmp/*": allow
|
||||
|
||||
@@ -48,6 +116,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -110,3 +180,7 @@ On any other failure:
|
||||
ok: false
|
||||
error: <one-line description>
|
||||
```
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
- **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -6,24 +6,88 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
"sequential-thinking*": deny
|
||||
"context7*": deny
|
||||
@@ -33,9 +97,13 @@ permission:
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
"git -C /tmp/*": allow
|
||||
|
||||
@@ -45,6 +113,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -89,3 +159,7 @@ On failure:
|
||||
ok: false
|
||||
error: <one-line description>
|
||||
```
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
- **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -8,24 +8,88 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
"sequential-thinking*": deny
|
||||
"context7*": deny
|
||||
@@ -35,10 +99,13 @@ permission:
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C /tmp/*": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# Universal auto-agents-system bash blocks
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
@@ -46,6 +113,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
"git-stage-util": allow
|
||||
@@ -131,3 +200,7 @@ lease. Execute these steps exactly.
|
||||
sha: {sha}
|
||||
remote_sha: {remote_sha from push result}
|
||||
```
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
- **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -7,29 +7,89 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All utility type agents use the following color
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# Agents called in an async manner should have this set to deny, otherwise use best discretion
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
@@ -42,10 +102,12 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# This is where we edit the permissions on an as-needed per-agent basis
|
||||
"git -C /tmp/*": allow
|
||||
@@ -61,6 +123,8 @@ permission:
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -258,4 +322,4 @@ This agent does not invoke any subagents. It is a self-contained utility that pe
|
||||
2. **Unique directory names.** Include agent name and timestamp to avoid collisions.
|
||||
3. **Configure git identity.** Always set user.name and user.email before returning.
|
||||
4. **Credentials in the URL.** Use the PAT in the HTTPS clone URL for authentication.
|
||||
5. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
5. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
|
||||
@@ -7,24 +7,88 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
"sequential-thinking*": deny
|
||||
"context7*": deny
|
||||
@@ -34,9 +98,13 @@ permission:
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
"git -C /tmp/*": allow
|
||||
|
||||
@@ -46,6 +114,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -112,3 +182,20 @@ On any other failure:
|
||||
ok: false
|
||||
error: <one-line description>
|
||||
```
|
||||
|
||||
### Fallback to environment variables
|
||||
|
||||
For optional parameters not provided in your prompt, you may fall back to the environment variables listed below. Always give precedence to values explicitly passed in the prompt. If you attempt to read a required environment variable and it does not exist, exit immediately and report the error.
|
||||
|
||||
| Information | Env Variable | Required? | Local Variable |
|
||||
|------------------|-------------------|:---------:|-------------------|
|
||||
| Git name | `GIT_USER_NAME` | Yes | `git_user_name` |
|
||||
| Git email | `GIT_USER_EMAIL` | Yes | `git_user_email` |
|
||||
| Forgejo PAT | `FORGEJO_PAT` | Yes | `forgejo_pat` |
|
||||
| Repository base url | `FORGEJO_URL` | No | `forgejo_url` |
|
||||
| Repository owner | `FORGEJO_OWNER` | No | `forgejo_owner` |
|
||||
| Repository name | `FORGEJO_REPO` | No | `forgejo_repo` |
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
- **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -8,24 +8,88 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
"sequential-thinking*": deny
|
||||
"context7*": deny
|
||||
@@ -35,9 +99,14 @@ permission:
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
"git -C /tmp/*": allow
|
||||
|
||||
# Universal auto-agents-system bash blocks
|
||||
@@ -46,6 +115,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
"git-fetch-util": allow
|
||||
@@ -113,3 +184,7 @@ You compose `git-fetch-util` → `git-rebase-util` → `git-push-util`
|
||||
sha: {from rebase result}
|
||||
remote_sha: {from push result}
|
||||
```
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
- **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -7,32 +7,89 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All utility type agents use the following color
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# Agents called in an async manner should have this set to deny, otherwise use best discretion
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
read: allow
|
||||
grep: allow
|
||||
glob: allow
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": allow
|
||||
@@ -45,10 +102,12 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# This is where we edit the permissions on an as-needed per-agent basis
|
||||
"git -C /tmp/*": allow
|
||||
@@ -64,6 +123,8 @@ permission:
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -323,4 +384,4 @@ This agent does not invoke any subagents. It is a self-contained utility that pe
|
||||
5. **Preserve the intent of both sides.** When resolving a conflict, do not silently drop either side's changes without justification. If you cannot safely combine them, abort.
|
||||
6. **Never work in `/app`.** The working directory provided by your caller must be inside `/tmp/`. Refuse and report an error if it is not.
|
||||
7. **One task, then exit.** Do not look for more work, do not loop, do not sleep.
|
||||
8. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
8. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
|
||||
@@ -7,24 +7,88 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
"sequential-thinking*": deny
|
||||
"context7*": deny
|
||||
@@ -34,9 +98,13 @@ permission:
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
"git -C /tmp/*": allow
|
||||
"ls *": allow
|
||||
@@ -47,6 +115,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -97,3 +167,7 @@ On failure:
|
||||
ok: false
|
||||
error: <one-line description>
|
||||
```
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
- **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -13,13 +13,13 @@ description: >
|
||||
mode: all
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All supervisor type agents use the following color
|
||||
color: "#FF9999"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
@@ -27,15 +27,75 @@ permission:
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
@@ -48,16 +108,20 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C *remote get-url origin": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -86,7 +150,8 @@ If you are in a new session, and have not yet initiated startup, then do the fol
|
||||
Startup steps:
|
||||
|
||||
1. Parse and validate prompt parameters
|
||||
2. If any required parameters are missing or malformed, exit immediately and report the error
|
||||
2. Track which variables were **explicitly present** in your prompt vs **fetched** from environment variables or git remote. Only variables explicitly present in your prompt may be passed onward in the supervisor prompt. Fetched variables must never be propagated through prompts — the generic `supervisor` subagent will fetch them itself.
|
||||
3. If any required parameters are missing or malformed, exit immediately and report the error
|
||||
|
||||
### Main loop
|
||||
|
||||
@@ -120,6 +185,8 @@ The following represents the variables that are either passed down through the p
|
||||
|
||||
**CRITICAL:** For all parameters in the above table, the value should first attempt to be set from information in the prompt, if that doesn't exist then you should either attempt to fetch the variable, or check the environment variable, if those are available options. Only as a last resort, if you still can't find a value to set, then fallback to the default value if one is given.
|
||||
|
||||
**CRITICAL — Explicit vs Fetched Variables:** When constructing the supervisor prompt, only include variables that were **explicitly present** in the prompt you received. Omit any variable you had to fetch from environment variables or git remote. The generic `supervisor` subagent is capable of fetching missing variables itself using its own fallback mechanisms. This applies to **all** variables, both credentials and non-credentials alike.
|
||||
|
||||
### What you receive in your prompt
|
||||
|
||||
All of the variables listed in the table above may be passed in your prompt. All are optional — if absent they are omitted from the supervisor prompt and resolved by the supervisor itself via environment variables or auto-detection.
|
||||
@@ -205,7 +272,7 @@ Invoke the `supervisor` subagent as a blocking call via the Task tool, passing i
|
||||
|
||||
Construct the prompt with the following content, substituting your **actual** resolved values for each line that has a variable substitution (of the form `{variable}`), using the template below replacing **only** the values marked as `{variable}` leaving all text as literal, non-summarized text.
|
||||
|
||||
Use the following prompt template to construct your your prompt for the `supervisor` subagent, being sure to substitute `{variable}` with the variables value:
|
||||
Use the following prompt template to construct your your prompt for the `supervisor` subagent, being sure to substitute `{variable}` with the variables value. **Only include a variable line if that variable was explicitly present in your prompt.** Omit any variable you fetched from environment variables — the supervisor will fetch it itself.
|
||||
|
||||
```
|
||||
forgejo_url: `{forgejo_url}`
|
||||
@@ -267,6 +334,7 @@ The hardcoded values in the template (worker subagent name, pool size, idle slee
|
||||
## **CRITICAL** Rules
|
||||
|
||||
- **Pass all credentials verbatim.** Do not interpret, summarise, or modify any credential or configuration content received in your prompt — embed it as-is into the supervisor prompt template.
|
||||
- **Only pass explicitly-present variables.** When constructing the supervisor prompt, include only variables that were **explicitly present** in your prompt. Omit any variable you fetched from environment variables or git remote — the supervisor subagent will fetch them itself.
|
||||
- **Never implement anything yourself.** Your only job is to construct the supervisor prompt and invoke the `supervisor` subagent.
|
||||
- **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
- **Exhaustive pagination for all list results.** Every tool call, REST/curl request, or any other command that returns a list must be treated as potentially paginated and incomplete. Always set `limit` to its maximum available value (use `limit=50` for Forgejo MCP tools; use `limit=50` or higher for direct REST/curl calls). After each list response, check whether the number of returned items equals the page size — if so, there are likely more results; fetch the next page (`page=2`, `page=3`, …) and continue until receiving a partial page. Never assume the first response is the complete result.
|
||||
|
||||
@@ -11,30 +11,89 @@ description: >
|
||||
mode: all
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All worker type agents use the following color
|
||||
color: "#00FF00"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This wrapper runs autonomously as a worker session and must not interrupt
|
||||
# the supervisor by prompting the user for input.
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
read:
|
||||
"*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": deny
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
@@ -47,20 +106,24 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"*": allow
|
||||
|
||||
# The wrapper only needs three commands: env-var fallback, identity output,
|
||||
# and reading the git origin URL to derive `forgejo_url` / `forgejo_owner` /
|
||||
# `forgejo_repo` when those are not provided in the prompt or environment.
|
||||
"echo $*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -96,7 +159,8 @@ Startup steps:
|
||||
|
||||
1. Parse and validate prompt parameters
|
||||
2. Resolve missing credential/repository parameters via environment variables and git-remote auto-detection (see "Variables to fetch" and "Fallback to environment variables" below)
|
||||
3. If any required parameters are still missing or malformed, exit immediately and report the error
|
||||
3. Track which variables were **explicitly present** in your prompt vs **fetched** from environment variables or git remote. Only variables explicitly present in your prompt may be passed onward in the `tier-dispatcher` prompt. Fetched variables must never be propagated through prompts — downstream agents will fetch them themselves.
|
||||
4. If any required parameters are still missing or malformed, exit immediately and report the error
|
||||
|
||||
### Main task
|
||||
|
||||
@@ -126,6 +190,8 @@ The following represents all variables this agent works with:
|
||||
|
||||
**CRITICAL:** Parameters given explicitly in the prompt always take precedence. Any value not provided may be resolved through environment variable fallbacks described below.
|
||||
|
||||
**CRITICAL — Explicit vs Fetched Variables:** When constructing the `tier-dispatcher` prompt, only include variables that were **explicitly present** in the prompt you received. Omit any variable you had to fetch from environment variables or git remote. Downstream agents are capable of fetching missing variables themselves using their own fallback mechanisms. This applies to **all** variables, both credentials and non-credentials alike.
|
||||
|
||||
### What you receive in your prompt
|
||||
|
||||
| Parameter | Required? | Local Variable |
|
||||
@@ -210,6 +276,8 @@ Invoke `tier-dispatcher` as a blocking call via the Task tool. The dispatcher wi
|
||||
|
||||
#### Prompt template
|
||||
|
||||
**Only include a variable line if that variable was explicitly present in your prompt.** Omit any variable you fetched from environment variables — downstream agents will fetch it themselves.
|
||||
|
||||
```
|
||||
forgejo_url: `{forgejo_url}`
|
||||
forgejo_owner: `{forgejo_owner}`
|
||||
@@ -259,5 +327,6 @@ Invoke `tier-dispatcher` as a blocking call via the Task tool. The dispatcher wi
|
||||
3. **Always bind `task-implementor` and `estimator-implementation`.** These two agent names are not configurable from this wrapper; this agent exists specifically to bind those two to the implementation work flow. If you ever find yourself sending a different `task_agent` or `estimator_agent`, you have made a mistake.
|
||||
4. **Pass `task_prompt` verbatim once constructed.** Build the prompt body once from the work-item fields, credentials, git identity, and the standing instruction line; then embed that body as-is into the dispatcher call. Do not summarise, paraphrase, or reformat fields once embedded.
|
||||
5. **Pass all credentials verbatim.** Do not interpret, summarise, or modify any credential or configuration content received in your prompt — embed it as-is into the dispatcher call (both at the top level and inside `task_prompt`).
|
||||
6. **Return the dispatcher's output verbatim.** Do not summarise, interpret, or modify what `tier-dispatcher` returns — pass it back to your caller exactly as received.
|
||||
7. **Never ask questions or give up.** Operate fully autonomously using best judgement. If a required parameter is missing or `tier-dispatcher` fails fatally, exit immediately and report the error.
|
||||
6. **Only pass explicitly-present variables.** Include only variables that were **explicitly present** in your prompt in the dispatcher call. Omit any variable you fetched from environment variables or git remote — downstream agents will fetch them themselves.
|
||||
7. **Return the dispatcher's output verbatim.** Do not summarise, interpret, or modify what `tier-dispatcher` returns — pass it back to your caller exactly as received.
|
||||
8. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question. If a required parameter is missing or `tier-dispatcher` fails fatally, exit immediately and report the error.
|
||||
|
||||
@@ -6,13 +6,13 @@ description: >
|
||||
mode: all
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All supervisor type agents use the following color
|
||||
color: "#FF9999"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
@@ -20,15 +20,75 @@ permission:
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
@@ -41,16 +101,20 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -78,7 +142,8 @@ If you are in a new session, and have not yet initiated startup, then do the fol
|
||||
Startup steps:
|
||||
|
||||
1. Parse and validate prompt parameters
|
||||
2. If any required parameters are missing or malformed, exit immediately and report the error
|
||||
2. Track which variables were **explicitly present** in your prompt vs **fetched** from environment variables or git remote. Only variables explicitly present in your prompt may be passed onward in the supervisor prompt. Fetched variables must never be propagated through prompts — the generic `supervisor` subagent will fetch them itself.
|
||||
3. If any required parameters are missing or malformed, exit immediately and report the error
|
||||
|
||||
|
||||
### Main loop
|
||||
@@ -113,6 +178,8 @@ The following represents all variables this agent works with:
|
||||
|
||||
**CRITICAL:** For all parameters in the above table, the value should first attempt to be set from information in the prompt, if that doesn't exist then you should either attempt to fetch the variable, or check the environment variable, if those are available options. Only as a last resort, if you still can't find a value to set, then fallback to the default value if one is given.
|
||||
|
||||
**CRITICAL — Explicit vs Fetched Variables:** When constructing the supervisor prompt, only include variables that were **explicitly present** in the prompt you received. Omit any variable you had to fetch from environment variables or git remote. The generic `supervisor` subagent is capable of fetching missing variables itself using its own fallback mechanisms. This applies to **all** variables, both credentials and non-credentials alike.
|
||||
|
||||
### What you receive in your prompt
|
||||
|
||||
All of the variables listed in the table above may be passed in your prompt. All are optional — if absent they are omitted from the supervisor prompt and resolved by the supervisor itself via environment variables or auto-detection.
|
||||
@@ -203,7 +270,7 @@ Invoke the `supervisor` subagent as a blocking call via the Task tool, passing i
|
||||
|
||||
Construct the prompt with the following content, substituting your ACTUAL resolved values for each line that has a variable substitution (of the form `{variable}`), using the template below replacing **only** the values marked as `{variable}` leaving all text as literal, non-summarized text.
|
||||
|
||||
Use the following prompt template to construct your your prompt for the `supervisor` subagent, being sure to substitute `{variable}` with the variables value:
|
||||
Use the following prompt template to construct your your prompt for the `supervisor` subagent, being sure to substitute `{variable}` with the variables value. **Only include a variable line if that variable was explicitly present in your prompt.** Omit any variable you fetched from environment variables — the supervisor will fetch it itself.
|
||||
|
||||
```
|
||||
forgejo_url: `{forgejo_url}`
|
||||
@@ -266,4 +333,5 @@ The hardcoded values in the template (worker subagent name, pool size, idle slee
|
||||
## **CRITICAL** Rules
|
||||
|
||||
- **Pass all credentials verbatim.** Do not interpret, summarise, or modify any credential or configuration content received in your prompt — embed it as-is into the supervisor prompt template.
|
||||
- **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
- **Only pass explicitly-present variables.** When constructing the supervisor prompt, include only variables that were **explicitly present** in your prompt. Omit any variable you fetched from environment variables or git remote — the supervisor subagent will fetch them itself.
|
||||
- **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -6,13 +6,13 @@ description: >
|
||||
mode: all
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All worker type agents use the following color
|
||||
color: "#00FF00"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
@@ -20,15 +20,75 @@ permission:
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": allow
|
||||
@@ -41,10 +101,12 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# This is where we edit the permissions on an as-needed per-agent basis
|
||||
"git -C * status *": allow
|
||||
@@ -60,6 +122,8 @@ permission:
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -96,8 +160,9 @@ If you are in a new session, and have not yet initiated startup, then do the fol
|
||||
Startup steps:
|
||||
|
||||
1. Parse and validate prompt parameters
|
||||
2. If any required parameters are missing or malformed, exit immediately and report the error
|
||||
3. Load the `auto-agents-system` skill and from it learn how to use the scripts with the following names: `merge_pr`, and `rebase_pr`.
|
||||
2. Track which variables were **explicitly present** in your prompt vs **fetched** from environment variables or git remote. Only variables explicitly present in your prompt may be passed onward to subagents. Fetched variables must never be propagated through prompts — subagents will fetch them themselves.
|
||||
3. If any required parameters are missing or malformed, exit immediately and report the error
|
||||
4. Load the `auto-agents-system` skill and from it learn how to use the scripts with the following names: `merge_pr`, and `rebase_pr`.
|
||||
|
||||
### Main task
|
||||
|
||||
@@ -150,6 +215,8 @@ The following represents what you expect to receive in your prompt:
|
||||
|
||||
**CRITICAL:** It is important to note that parameters given explicitly in the prompt always override those that are fetched or come from environment variables. However when a variable can be determined both through environment variables or fetching (not explicitly provided in the prompt) then consult the details the section titled "Parameters to fetch" to determine if the environment variable takes precedence or not.
|
||||
|
||||
**CRITICAL — Explicit vs Fetched Variables:** When constructing prompts for subagents (`git-isolator-util`, `git-rebase-util`, `git-commit-util`), only include variables that were **explicitly present** in the prompt you received. Omit any variable you had to fetch from environment variables or git remote. Subagents are capable of fetching missing variables themselves using their own fallback mechanisms. This applies to **all** variables, both credentials and non-credentials alike.
|
||||
|
||||
### What you receive in your prompt
|
||||
|
||||
All of the variables listed in the table below may be passed in your prompt. Some are required and some are optional. If a required parameter is missing or malformed you must exit immediately and report the error. Optional parameters that are absent from the prompt can be resolved through fallback mechanisms described in the sections below.
|
||||
@@ -254,6 +321,8 @@ Invoke the `git-isolator-util` subagent via the Task tool, passing it repository
|
||||
|
||||
#### Prompt template
|
||||
|
||||
**Only include a variable line if that variable was explicitly present in your prompt.** Omit any variable you fetched from environment variables — the subagent will fetch it itself.
|
||||
|
||||
```
|
||||
forgejo_url: `{forgejo_url}`
|
||||
forgejo_owner: `{forgejo_owner}`
|
||||
@@ -292,6 +361,8 @@ Invoke the `git-commit-util` subagent via the Task tool, passing it the reposito
|
||||
|
||||
#### Prompt template
|
||||
|
||||
**Only include a variable line if that variable was explicitly present in your prompt.** Omit any variable you fetched from environment variables.
|
||||
|
||||
```
|
||||
repo_dir: `{repo_dir}`
|
||||
branch: `{branch_name}`
|
||||
@@ -330,6 +401,8 @@ Invoke the `git-rebase-util` subagent via the Task tool, passing it the reposito
|
||||
|
||||
#### Prompt template
|
||||
|
||||
**Only include a variable line if that variable was explicitly present in your prompt.** Omit any variable you fetched from environment variables.
|
||||
|
||||
```
|
||||
repo_dir: `{repo_dir}`
|
||||
base_branch: master
|
||||
@@ -355,4 +428,4 @@ The `git-rebase-util` needs the working directory of the isolated clone and the
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
1. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
1. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -9,13 +9,13 @@ description: >
|
||||
mode: all
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All supervisor type agents use the following color
|
||||
color: "#FF9999"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
@@ -23,15 +23,75 @@ permission:
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
@@ -44,16 +104,20 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -81,7 +145,8 @@ If you are in a new session, and have not yet initiated startup, then do the fol
|
||||
Startup steps:
|
||||
|
||||
1. Parse and validate prompt parameters
|
||||
2. If any required parameters are missing or malformed, exit immediately and report the error
|
||||
2. Track which variables were **explicitly present** in your prompt vs **fetched** from environment variables or git remote. Only variables explicitly present in your prompt may be passed onward in the supervisor prompt. Fetched variables must never be propagated through prompts — the generic `supervisor` subagent will fetch them itself.
|
||||
3. If any required parameters are missing or malformed, exit immediately and report the error
|
||||
|
||||
|
||||
### Main loop
|
||||
@@ -120,6 +185,8 @@ The following represents all variables this agent works with:
|
||||
|
||||
**CRITICAL:** For all parameters in the above table, the value should first attempt to be set from information in the prompt, if that doesn't exist then you should either attempt to fetch the variable, or check the environment variable, if those are available options. Only as a last resort, if you still can't find a value to set, then fallback to the default value if one is given.
|
||||
|
||||
**CRITICAL — Explicit vs Fetched Variables:** When constructing the supervisor prompt, only include variables that were **explicitly present** in the prompt you received. Omit any variable you had to fetch from environment variables or git remote. The generic `supervisor` subagent is capable of fetching missing variables itself using its own fallback mechanisms. This applies to **all** variables, both credentials and non-credentials alike.
|
||||
|
||||
### What you receive in your prompt
|
||||
|
||||
All of the variables listed in the table above may be passed in your prompt. All are optional — if absent they are omitted from the supervisor prompt and resolved by the supervisor itself via environment variables or auto-detection.
|
||||
@@ -213,7 +280,7 @@ Invoke the `supervisor` subagent as a blocking call via the Task tool, passing i
|
||||
|
||||
Construct the prompt with the following content, substituting your ACTUAL resolved values for each line that has a variable substitution (of the form `{variable}`), using the template below replacing **only** the values marked as `{variable}` leaving all text as literal, non-summarized text.
|
||||
|
||||
Use the following prompt template to construct your your prompt for the `supervisor` subagent, being sure to substitute `{variable}` with the variables value:
|
||||
Use the following prompt template to construct your your prompt for the `supervisor` subagent, being sure to substitute `{variable}` with the variables value. **Only include a variable line if that variable was explicitly present in your prompt.** Omit any variable you fetched from environment variables — the supervisor will fetch it itself.
|
||||
|
||||
```
|
||||
forgejo_url: `{forgejo_url}`
|
||||
@@ -276,5 +343,6 @@ The hardcoded values in the template (worker subagent name, pool size, idle slee
|
||||
|
||||
- **Never implement anything yourself.** Your only job is to construct the supervisor prompt and invoke the `supervisor` subagent.
|
||||
- **Pass all credentials verbatim.** Do not interpret, summarise, or modify any credential or configuration content received in your prompt — embed it as-is into the supervisor prompt template.
|
||||
- **Only pass explicitly-present variables.** When constructing the supervisor prompt, include only variables that were **explicitly present** in your prompt. Omit any variable you fetched from environment variables or git remote — the supervisor subagent will fetch them itself.
|
||||
- **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
- **Exhaustive pagination for all list results.** Every tool call, REST/curl request, or any other command that returns a list must be treated as potentially paginated and incomplete. Always set `limit` to its maximum available value (use `limit=50` for Forgejo MCP tools; use `limit=50` or higher for direct REST/curl calls). After each list response, check whether the number of returned items equals the page size — if so, there are likely more results; fetch the next page (`page=2`, `page=3`, …) and continue until receiving a partial page. Never assume the first response is the complete result.
|
||||
|
||||
@@ -10,13 +10,13 @@ description: >
|
||||
mode: all
|
||||
hidden: false
|
||||
temperature: 0.1
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All worker type agents use the following color
|
||||
color: "#00FF00"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
@@ -24,15 +24,75 @@ permission:
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": allow
|
||||
@@ -45,10 +105,12 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# This is where we edit the permissions on an as-needed per-agent basis
|
||||
"git -C /tmp/*": allow
|
||||
@@ -69,6 +131,8 @@ permission:
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -108,8 +172,9 @@ If you are in a new session, and have not yet initiated startup, then do the fol
|
||||
Startup steps:
|
||||
|
||||
1. Parse and validate prompt parameters
|
||||
2. If any required parameters are missing or malformed, exit immediately and report the error
|
||||
3. Proceed to the main task
|
||||
2. Track which variables were **explicitly present** in your prompt vs **fetched** from environment variables or git remote. Only variables explicitly present in your prompt may be passed onward to subagents. Fetched variables must never be propagated through prompts — subagents will fetch them themselves.
|
||||
3. If any required parameters are missing or malformed, exit immediately and report the error
|
||||
4. Proceed to the main task
|
||||
|
||||
### Main task
|
||||
|
||||
@@ -284,6 +349,8 @@ The following represents all variables this agent works with:
|
||||
|
||||
**CRITICAL:** It is important to note that parameters given explicitly in the prompt always override those that are fetched or come from environment variables. However when a variable can be determined both through environment variables or fetching (not explicitly provided in the prompt) then consult the details the section titled "Parameters to fetch" to determine if the environment variable takes precedence or not.
|
||||
|
||||
**CRITICAL — Explicit vs Fetched Variables:** When constructing prompts for subagents (`git-isolator-util`), only include variables that were **explicitly present** in the prompt you received. Omit any variable you had to fetch from environment variables or git remote. Subagents are capable of fetching missing variables themselves using their own fallback mechanisms. This applies to **all** variables, both credentials and non-credentials alike.
|
||||
|
||||
### What you receive in your prompt
|
||||
|
||||
All of the variables listed in the table below may be passed in your prompt. Some are required and some are optional. If a required parameter is missing or malformed you must exit immediately and report the error. Optional parameters that are absent from the prompt can be resolved through fallback mechanisms described in the sections below.
|
||||
@@ -386,6 +453,8 @@ Invoke the `git-isolator-util` subagent via the Task tool, passing it repository
|
||||
|
||||
#### Prompt template
|
||||
|
||||
**Only include a variable line if that variable was explicitly present in your prompt.** Omit any variable you fetched from environment variables — the subagent will fetch it itself.
|
||||
|
||||
```
|
||||
forgejo_url: `{forgejo_url}`
|
||||
forgejo_owner: `{forgejo_owner}`
|
||||
@@ -424,17 +493,18 @@ Returns `repo_dir` — the absolute path to the cloned repository inside `/tmp/`
|
||||
|
||||
1. **One task, then exit.** Do not loop, do not sleep, do not look for more work.
|
||||
2. **Use `{forgejo_pat}` for all Forgejo API calls.** This agent runs entirely on the reviewer bot identity — a separate account from the primary bot that creates PRs. This separation is required by branch protection rules that prohibit self-approval. Use `Authorization: token {forgejo_pat}` for both reading (PR details, reviews, comments, CI status) and writing (submitting reviews).
|
||||
3. **Follow CONTRIBUTING.md exactly.** The review checklist, comment format, and approval criteria must be followed. Load the `cleveragents-contributing` skill for the full CONTRIBUTING.md rules.
|
||||
4. **Be constructive in all feedback.** Every `REQUEST_CHANGES` comment must explain WHY something is a problem and suggest HOW to fix it. Never leave vague or unhelpful feedback.
|
||||
5. **CI flag mode is lightweight.** When `review_type` is `ci_flag`, do NOT perform a full code review. Only flag the missing CI checks and exit.
|
||||
6. **Never merge.** Submit reviews; the merge supervisor handles merging. Never call any merge endpoint.
|
||||
7. **Clean up your clone.** Delete the temporary directory before exiting (`rm -rf {repo_dir}`). In CI flag mode, no clone is created so no cleanup is needed.
|
||||
8. **Never work in `/app`.** Always work in `/tmp/`. If `repo_dir` is not inside `/tmp/`, refuse and report an error.
|
||||
9. **Bot signature on all Forgejo content:**
|
||||
3. **Only pass explicitly-present variables to subagents.** When invoking `git-isolator-util`, include only variables that were **explicitly present** in your prompt. Omit any variable you fetched from environment variables or git remote — the subagent will fetch them itself.
|
||||
4. **Follow CONTRIBUTING.md exactly.** The review checklist, comment format, and approval criteria must be followed. Load the `cleveragents-contributing` skill for the full CONTRIBUTING.md rules.
|
||||
5. **Be constructive in all feedback.** Every `REQUEST_CHANGES` comment must explain WHY something is a problem and suggest HOW to fix it. Never leave vague or unhelpful feedback.
|
||||
6. **CI flag mode is lightweight.** When `review_type` is `ci_flag`, do NOT perform a full code review. Only flag the missing CI checks and exit.
|
||||
7. **Never merge.** Submit reviews; the merge supervisor handles merging. Never call any merge endpoint.
|
||||
8. **Clean up your clone.** Delete the temporary directory before exiting (`rm -rf {repo_dir}`). In CI flag mode, no clone is created so no cleanup is needed.
|
||||
9. **Never work in `/app`.** Always work in `/tmp/`. If `repo_dir` is not inside `/tmp/`, refuse and report an error.
|
||||
10. **Bot signature on all Forgejo content:**
|
||||
```
|
||||
---
|
||||
Automated by CleverAgents Bot
|
||||
Supervisor: PR Review | Agent: pr-review-worker
|
||||
```
|
||||
10. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
11. **Exhaustive pagination for all list results.** Every REST call returning a list must be paginated fully with `limit=50`. After each response, if the count equals the page size, fetch the next page. Never assume the first response is complete. *Examples specific to this agent:* PR reviews (paginate to read all rounds of feedback before beginning re-review); review comments (paginate to read all inline comments from each review); PR comments (paginate to capture full discussion history); CI statuses (paginate to find all failing checks).
|
||||
11. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
12. **Exhaustive pagination for all list results.** Every REST call returning a list must be paginated fully with `limit=50`. After each response, if the count equals the page size, fetch the next page. Never assume the first response is complete. *Examples specific to this agent:* PR reviews (paginate to read all rounds of feedback before beginning re-review); review comments (paginate to read all inline comments from each review); PR comments (paginate to capture full discussion history); CI statuses (paginate to find all failing checks).
|
||||
|
||||
@@ -10,24 +10,88 @@ description: >
|
||||
mode: subagent
|
||||
hidden: true
|
||||
temperature: 0.1
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
"sequential-thinking*": allow
|
||||
"context7*": deny
|
||||
@@ -37,13 +101,20 @@ permission:
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
"npx --yes tsx /app/.opencode/skills/auto-agents-system/scripts/session_*": allow
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
@@ -226,4 +297,4 @@ Return ONLY this exact JSON with no other text:
|
||||
2. **step_finish.reason == "tool-calls" is never stuck.** The session is waiting on tool/subagent results.
|
||||
3. **Supervisors do not finish.** A -SUP session that is idle is `idle`, not `finished`.
|
||||
4. **Healthy is the default.** When signals are mixed or absent, prefer `healthy` over a negative state.
|
||||
5. **Never ask questions or give up.** Return the JSON result regardless of data quality.
|
||||
5. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
|
||||
@@ -10,24 +10,88 @@ description: >
|
||||
mode: subagent
|
||||
hidden: true
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
"sequential-thinking*": allow
|
||||
"context7*": deny
|
||||
@@ -37,13 +101,20 @@ permission:
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
"npx --yes tsx /app/.opencode/skills/auto-agents-system/scripts/session_*": allow
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
@@ -151,4 +222,4 @@ Return ONLY this exact JSON with no other text, no markdown, no explanation:
|
||||
2. **Supervisors never finish.** Any `-SUP` tagged session → `escalate`.
|
||||
3. **Busy sessions always escalate.** Timing and tool analysis is required for busy sessions.
|
||||
4. **Do not infer from absence.** If the last messages don't clearly signal completion or failure, escalate — do not guess.
|
||||
5. **Never ask questions or give up.** Return one of the three verdicts.
|
||||
5. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
|
||||
@@ -10,24 +10,88 @@ description: >
|
||||
mode: subagent
|
||||
hidden: true
|
||||
temperature: 0.1
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
"sequential-thinking*": allow
|
||||
"context7*": deny
|
||||
@@ -37,13 +101,20 @@ permission:
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
"npx --yes tsx /app/.opencode/skills/auto-agents-system/scripts/session_messages.ts*": allow
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
@@ -177,4 +248,4 @@ For full-path results, return the JSON from `session-health-full-util` unchanged
|
||||
2. **Always run Tier 1 first.** Never skip to Tier 2 without the quick check.
|
||||
3. **The quick evaluator decides escalation.** Do not override an `escalate` verdict with your own guess.
|
||||
4. **Pass full-evaluator output unchanged.** Do not reinterpret or summarise it.
|
||||
5. **Never ask questions or give up.** Return a health result for every session.
|
||||
5. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
|
||||
@@ -5,29 +5,89 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All pass-through type agents for abstraction and reusability purposes, use the following color
|
||||
color: "#FFFF00"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# Agents called in an async manner should have this set to deny, otherwise use best discretion
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": allow
|
||||
@@ -40,10 +100,12 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# This is where we edit the permissions on an as-needed per-agent basis
|
||||
"sleep *": allow
|
||||
@@ -56,6 +118,8 @@ permission:
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -96,7 +160,8 @@ If you are in a new session, and have not yet initiated startup, then do the fol
|
||||
Startup steps:
|
||||
|
||||
1. Parse and validate prompt parameters (tag prefix, work groups, worker config, etc.)
|
||||
2. If any required parameters are missing or malformed, exit immediately and report the error; Validate that the work group names match the required naming conventions (all lowercase letters and underscores, no other characters).
|
||||
2. Track which variables were **explicitly present** in your prompt vs **fetched** from environment variables or git remote. Only variables explicitly present in your prompt may be passed onward in worker launch prompts. Fetched variables must never be propagated through prompts — workers and their subagents will fetch them themselves.
|
||||
3. If any required parameters are missing or malformed, exit immediately and report the error; Validate that the work group names match the required naming conventions (all lowercase letters and underscores, no other characters).
|
||||
|
||||
**CRITICAL:** After startup is complete you must **immediately** begin the main loop, and loop forever. Do not stop or pause to summarize or narrate, do not pause to give a status update, do not ask question, never ask for next steps. Run the main loop indefinately and if you have any questions use your best judgement.
|
||||
|
||||
@@ -160,6 +225,8 @@ The following represents the variables that are either passed down through the p
|
||||
|
||||
**CRITICAL:** For all parameters in the above table, the value should first attempt to be set from information in the prompt, if that doesn't exist then you should either attempt to fetch the variable, or check the environment variable, if those are available options. Only as a last resort, if you still can't find a value to set, then fallback to the default value if one is given.
|
||||
|
||||
**CRITICAL — Explicit vs Fetched Variables:** When constructing worker launch prompts, only include variables that were **explicitly present** in the prompt you received. Omit any variable you had to fetch from environment variables or git remote. Workers and their subagents are capable of fetching missing variables themselves using their own fallback mechanisms. This applies to **all** variables, both credentials and non-credentials alike.
|
||||
|
||||
### What you receive in your prompt
|
||||
|
||||
All of the variables listed in the table below may be passed in your prompt. Some are required and some are optional. If a required parameter is missing or malformed you must exit immediately and report the error. Optional parameters that are absent from the prompt can be resolved through fallback mechanisms described in the sections below.
|
||||
@@ -362,11 +429,17 @@ Here is an example of a prompt you'd pass to `async-agent-util` in order to laun
|
||||
|
||||
Note: The text "Process the indicated Pull Request or Issue." is the `prompt_body` parameter extracted earlier from the input prompt.
|
||||
|
||||
**CRITICAL — Variable conditional inclusion in worker prompts:** Only include a variable line in the worker prompt if that variable was **explicitly present** in the prompt you received. If you fetched a variable from an environment variable or git remote, **omit that line entirely** from the worker prompt. Workers and their subagents will fetch missing variables themselves from their own environment variables.
|
||||
|
||||
#### Parameters to pass
|
||||
|
||||
The default rule is: **pass everything to the worker.** This includes all resolved variables (from the prompt, environment, or auto-detection) and all unknown pass-through parameters. Workers may depend on parameters the supervisor does not know about, so erring on the side of passing more is always safer.
|
||||
The default rule is: **pass everything to the worker** except fetched variables. Workers may depend on parameters the supervisor does not know about, so erring on the side of passing more is always safer.
|
||||
|
||||
The only exceptions are supervisor-internal parameters that have no meaning to a worker and must be **omitted**. Only omit the variables explicitly listed below:
|
||||
The exceptions that must be **omitted** are:
|
||||
|
||||
1. **Fetched variables:** Any variable (`forgejo_url`, `forgejo_owner`, `forgejo_repo`, `forgejo_pat`, `git_user_name`, `git_user_email`, `forgejo_username`, `forgejo_password`, or any other variable) that you resolved from environment variables or git remote, rather than receiving explicitly in your prompt. Workers will fetch these themselves.
|
||||
|
||||
2. **Supervisor-internal parameters** that have no meaning to a worker:
|
||||
|
||||
| Parameter | Reason for omitting |
|
||||
|--------------------------------|-------------------------------------------------------------------------------------------------|
|
||||
@@ -384,6 +457,7 @@ The only exceptions are supervisor-internal parameters that have no meaning to a
|
||||
## **CRITICAL** Rules
|
||||
|
||||
- **Pass all credentials verbatim.** Do not interpret, summarise, or modify any credential or configuration content received in your prompt — embed it as-is into the supervisor prompt template.
|
||||
- **Only pass explicitly-present variables.** When launching workers, include only variables that were **explicitly present** in your prompt. Omit any variable you fetched from environment variables or git remote — workers and their subagents will fetch them themselves.
|
||||
- **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
- **Never stop or finish.** You run forever. If you reach the end of a main loop iteration, immediately begin the next iteration. Never output a final summary — always continue executing.
|
||||
- **Act, don't narrate.** Every main loop step requires tool calls. If you find yourself writing text like "proceeding to dispatch" or "next I will fetch", STOP the text immediately and make the actual tool call instead. Text-only output without tool calls is a failure mode — avoid it.
|
||||
|
||||
@@ -12,29 +12,87 @@ description: >
|
||||
mode: all
|
||||
hidden: false
|
||||
temperature: 0.1
|
||||
reasoningEffort: "high"
|
||||
# All worker type agents use the following color
|
||||
color: "#00FF00"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This task agent runs autonomously as a synchronous subagent of a `tier-*`
|
||||
# selector and must not interrupt the workflow to prompt the user for input.
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": deny
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": allow
|
||||
@@ -47,10 +105,12 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# This is where we edit the permissions on an as-needed per-agent basis
|
||||
"nox *": allow
|
||||
@@ -71,6 +131,8 @@ permission:
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -111,7 +173,8 @@ If you are in a new session, and have not yet initiated startup, then do the fol
|
||||
Startup steps:
|
||||
|
||||
1. Parse and validate prompt parameters
|
||||
2. If any required parameters are missing or malformed, exit immediately and report the error
|
||||
2. Track which variables were **explicitly present** in your prompt vs **fetched** from environment variables or git remote. Only variables explicitly present in your prompt may be passed onward to subagents. Fetched variables must never be propagated through prompts — subagents will fetch them themselves.
|
||||
3. If any required parameters are missing or malformed, exit immediately and report the error
|
||||
|
||||
### Main task
|
||||
|
||||
@@ -277,6 +340,8 @@ The two tables below list the variables you will find at each level.
|
||||
|
||||
**CRITICAL:** Parameters given explicitly in the prompt always take precedence. Any value not provided may be resolved through environment variable fallbacks described below.
|
||||
|
||||
**CRITICAL — Explicit vs Fetched Variables:** When constructing prompts for subagents (`git-isolator-util`, `git-commit-util`), only include variables that were **explicitly present** in the prompt you received. Omit any variable you had to fetch from environment variables or git remote. Subagents are capable of fetching missing variables themselves using their own fallback mechanisms. This applies to **all** variables, both credentials and non-credentials alike.
|
||||
|
||||
### What you receive in your prompt
|
||||
|
||||
The prompt you receive is the two-level structure described above. Every variable below is required; the "Location" column tells you which level to read it from (`outer`, `inner`, or `both (duplicated)`).
|
||||
@@ -375,6 +440,8 @@ Invoke `git-isolator-util` as a blocking call via the Task tool. Two variants de
|
||||
|
||||
#### Prompt template (issue_impl — new branch)
|
||||
|
||||
**Only include a variable line if that variable was explicitly present in your prompt.** Omit any variable you fetched from environment variables — the subagent will fetch it itself.
|
||||
|
||||
```
|
||||
forgejo_url: `{forgejo_url}`
|
||||
forgejo_owner: `{forgejo_owner}`
|
||||
@@ -393,6 +460,8 @@ Create an isolated git clone with a new branch for implementation work.
|
||||
|
||||
#### Prompt template (pr_fix — existing branch)
|
||||
|
||||
**Only include a variable line if that variable was explicitly present in your prompt.** Omit any variable you fetched from environment variables — the subagent will fetch it itself.
|
||||
|
||||
```
|
||||
forgejo_url: `{forgejo_url}`
|
||||
forgejo_owner: `{forgejo_owner}`
|
||||
@@ -431,6 +500,8 @@ Invoke `git-commit-util` as a blocking call via the Task tool. Two variants depe
|
||||
|
||||
#### Prompt template (issue_impl — commit and push new branch)
|
||||
|
||||
**Only include a variable line if that variable was explicitly present in your prompt.** Omit any variable you fetched from environment variables.
|
||||
|
||||
```
|
||||
forgejo_url: `{forgejo_url}`
|
||||
forgejo_owner: `{forgejo_owner}`
|
||||
@@ -447,6 +518,8 @@ Commit all staged changes and push the branch.
|
||||
|
||||
#### Prompt template (pr_fix — force push with lease)
|
||||
|
||||
**Only include a variable line if that variable was explicitly present in your prompt.** Omit any variable you fetched from environment variables.
|
||||
|
||||
```
|
||||
forgejo_url: `{forgejo_url}`
|
||||
forgejo_owner: `{forgejo_owner}`
|
||||
@@ -491,5 +564,5 @@ Commit all staged changes and force-push with lease.
|
||||
Automated by CleverAgents Bot
|
||||
Supervisor: Implementation | Agent: task-implementor
|
||||
```
|
||||
10. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
10. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
11. **Exhaustive pagination for all list results.** Every REST call returning a list must be paginated fully with `limit=50`. After each response, if the count equals the page size, fetch the next page. Never assume the first response is complete. *Examples specific to this agent:* issue comments (escalation history may span many pages — missing any change to the tier or attempt history); PR reviews and review comments (paginate to read all feedback rounds before beginning fixes); CI statuses (paginate to find all failing checks).
|
||||
|
||||
@@ -14,24 +14,84 @@ reasoningEffort: "high"
|
||||
# All pass-through type agents for abstraction and reusability purposes, use the following color
|
||||
color: "#FFFF00"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# Agents called in an async manner should have this set to deny, otherwise use best discretion
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
@@ -44,15 +104,20 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -155,4 +220,4 @@ All parameters received in this agent's own prompt — **except `tier_agent`** a
|
||||
1. **Never act on the context.** Your only role is model-tier enforcement and pass-through.
|
||||
2. **Strip `tier_agent` and `target_agent` before forwarding.** `tier_agent` would cause a dispatch loop in the inner agent; `target_agent` is a routing instruction for this tier selector only.
|
||||
3. **Return results verbatim.** Do not summarize, interpret, or modify what `{target_agent}` returns.
|
||||
4. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
4. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
|
||||
@@ -13,30 +13,89 @@ description: >
|
||||
mode: all
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All worker type agents use the following color
|
||||
color: "#FFFF00"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This dispatcher runs autonomously as a synchronous subagent of its caller
|
||||
# and must not interrupt the workflow to prompt the user for input.
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
read:
|
||||
"*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": deny
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": allow
|
||||
@@ -49,20 +108,24 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"*": allow
|
||||
|
||||
# The dispatcher only needs three commands: env-var fallback, identity output,
|
||||
# and reading the git origin URL to derive `forgejo_url` / `forgejo_owner` /
|
||||
# `forgejo_repo` when those are not provided in the prompt or environment.
|
||||
"echo $*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -103,7 +166,8 @@ If you are in a new session, and have not yet initiated startup, then do the fol
|
||||
Startup steps:
|
||||
|
||||
1. Parse and validate prompt parameters
|
||||
2. If any required parameters are missing or malformed, exit immediately and report the error
|
||||
2. Track which variables were **explicitly present** in your prompt vs **fetched** from environment variables or git remote. Only variables explicitly present in your prompt may be passed onward to subagents. Fetched variables must never be propagated through prompts — downstream agents will fetch them themselves.
|
||||
3. If any required parameters are missing or malformed, exit immediately and report the error
|
||||
|
||||
### Main task
|
||||
|
||||
@@ -139,17 +203,15 @@ The following represents all variables this agent works with:
|
||||
|
||||
| `escalation_tier` | `tier_agent` value |
|
||||
|:-----------------:|--------------------|
|
||||
| -3 | `tier-gpt5-nano` |
|
||||
| -2 | `tier-o4-mini` |
|
||||
| -1 | `tier-gpt5-mini` |
|
||||
| 0 | `tier-qwen` |
|
||||
| 1 | `tier-haiku` |
|
||||
| 2 | `tier-codex` |
|
||||
| 3 | `tier-sonnet` |
|
||||
| 4 | `tier-opus` |
|
||||
| -1 | `tier-qwen-small` |
|
||||
| 0 | `tier-qwen-med` |
|
||||
| 1 | `tier-qwen-large` |
|
||||
| 2 | `tier-kimi` |
|
||||
|
||||
**CRITICAL:** Parameters given explicitly in the prompt always take precedence. Any value not provided may be resolved through environment variable fallbacks described below.
|
||||
|
||||
**CRITICAL — Explicit vs Fetched Variables:** When constructing prompts for subagents (`estimator_agent` and `tier_agent`), only include variables that were **explicitly present** in the prompt you received. Omit any variable you had to fetch from environment variables or git remote. Downstream agents are capable of fetching missing variables themselves using their own fallback mechanisms. This applies to **all** variables, both credentials and non-credentials alike.
|
||||
|
||||
### What you receive in your prompt
|
||||
|
||||
| Parameter | Required? | Local Variable |
|
||||
@@ -227,14 +289,14 @@ The following are the variables and the steps to fetch them:
|
||||
|
||||
For optional parameters not provided in your prompt, you may fall back to the environment variables listed below. Always give precedence to values explicitly passed in the prompt. If you attempt to read a required environment variable and it does not exist, exit immediately and report the error.
|
||||
|
||||
| Information | Env Variable | Required? | Local Variable |
|
||||
|------------------|-------------------|:---------:|-------------------|
|
||||
| Git name | `GIT_USER_NAME` | Yes | `git_user_name` |
|
||||
| Git email | `GIT_USER_EMAIL` | Yes | `git_user_email` |
|
||||
| Forgejo PAT | `FORGEJO_PAT` | Yes | `forgejo_pat` |
|
||||
| Information | Env Variable | Required? | Local Variable |
|
||||
|---------------------|-------------------|:---------:|-------------------|
|
||||
| Git name | `GIT_USER_NAME` | Yes | `git_user_name` |
|
||||
| Git email | `GIT_USER_EMAIL` | Yes | `git_user_email` |
|
||||
| Forgejo PAT | `FORGEJO_PAT` | Yes | `forgejo_pat` |
|
||||
| Repository base url | `FORGEJO_URL` | No | `forgejo_url` |
|
||||
| Repository owner | `FORGEJO_OWNER` | No | `forgejo_owner` |
|
||||
| Repository name | `FORGEJO_REPO` | No | `forgejo_repo` |
|
||||
| Repository owner | `FORGEJO_OWNER` | No | `forgejo_owner` |
|
||||
| Repository name | `FORGEJO_REPO` | No | `forgejo_repo` |
|
||||
|
||||
**Note:** The `Required?` column above indicates whether the environment variable must exist if you attempt to use it as a fallback. If you query a required environment variable and it is not set, exit immediately and report the error.
|
||||
|
||||
@@ -248,6 +310,8 @@ Invoke and resolve `{estimator_agent}`, call it as a subagent. Its job is to rev
|
||||
|
||||
#### Prompt template
|
||||
|
||||
**Only include a variable line if that variable was explicitly present in your prompt.** Omit any variable you fetched from environment variables — the estimator will fetch it itself.
|
||||
|
||||
```
|
||||
forgejo_url: `https://git.cleverthis.com`
|
||||
forgejo_owner: `cleveragents`
|
||||
@@ -302,14 +366,14 @@ For example here is a possible prompt:
|
||||
| Repository owner | `forgejo_owner` | Owner/org of the repository |
|
||||
| Repository name | `forgejo_repo` | Name of the repository |
|
||||
| Forgejo PAT | `forgejo_pat` | For authenticated API reads |
|
||||
| Task agent | `task_agent` | Name of the agent that will ultimately run the task; informs the scope of complexity estimation |
|
||||
| Task prompt | `task_prompt` | Full prompt body that will be passed to the task agent; embedded verbatim as context for the estimator |
|
||||
| Task agent | `task_agent` | Name of the agent that will ultimately run the task; informs the scope of complexity estimation |
|
||||
| Task prompt | `task_prompt` | Full prompt body that will be passed to the task agent; embedded verbatim as context for the estimator |
|
||||
|
||||
### Tier Selectors
|
||||
|
||||
The following 7 tier selectors may be invoked by this dispatcher. Each is invoked identically — the only difference is which one is called based on the resolved `tier_agent` value.
|
||||
|
||||
**Agents:** `tier-gpt5-nano`, `tier-o4-mini`, `tier-gpt5-mini`, `tier-qwen`, `tier-haiku`, `tier-codex`, `tier-sonnet`, `tier-opus`
|
||||
**Agents:** `tier-gpt5-nano`, `tier-o4-mini`, `tier-gpt5-mini`, `tier-qwen-small`, `tier-qwen-medium`, `tier-qwen-large`, `tier-haiku`, `tier-codex`, `tier-sonnet`, `tier-opus`, `tier-kimi`
|
||||
|
||||
#### How to invoke
|
||||
|
||||
@@ -319,6 +383,8 @@ Invoke the resolved `{tier_agent}` as a blocking call via the Task tool.
|
||||
|
||||
The prompt sent to the tier selector must be shaped so that after the tier selector strips the `target_agent` and `tier_agent` parameter lines, the remaining content is exactly what the inner task agent (`{task_agent}`) expects to receive. For `task-implementor` (and by convention, every `task-*` agent) that means credentials at the outer level, `escalation_tier` at the outer level, and the `{task_prompt}` body embedded inside a nested code block preceded by a short intro line and followed by a short outro instruction. The tier selector forwards everything except `target_agent` and `tier_agent` verbatim.
|
||||
|
||||
**Only include a variable line at the outer level if that variable was explicitly present in your prompt.** Omit any variable you fetched from environment variables — the inner agent will fetch it itself. The `{task_prompt}` block is passed as-is.
|
||||
|
||||
```
|
||||
target_agent: `{task_agent}`
|
||||
escalation_tier: `{escalation_tier}`
|
||||
@@ -343,7 +409,7 @@ For example here is a possible prompt (with `{task_prompt}` already substituted
|
||||
```
|
||||
target_agent: `task-implementor`
|
||||
escalation_tier: `1`
|
||||
tier_agent: `tier-haiku`
|
||||
tier_agent: `tier-qwen-large`
|
||||
forgejo_url: "https://git.cleverthis.com"
|
||||
forgejo_owner: "cleveragents"
|
||||
forgejo_repo: "cleveragents-core"
|
||||
@@ -369,7 +435,7 @@ The following is the task prompt, describing the directives the inner task agent
|
||||
Carry out the instructions from the task prompt above.
|
||||
```
|
||||
|
||||
Note that the credentials (`forgejo_url`, `forgejo_owner`, `forgejo_repo`, `forgejo_pat`, `git_user_name`, `git_user_email`) appear **twice** — once at the outer level (where the tier selector forwards them through to the inner task agent) and once inside the nested `{task_prompt}` code block (because `task_prompt` was constructed to be self-contained by the dispatcher's caller). This duplication is intentional; do not collapse it.
|
||||
Note that the credentials (`forgejo_url`, `forgejo_owner`, `forgejo_repo`, `forgejo_pat`, `git_user_name`, `git_user_email`) appear **twice** — once at the outer level (where the tier selector forwards them through to the inner task agent) and once inside the nested `{task_prompt}` code block (because `task_prompt` was constructed to be self-contained by the dispatcher's caller). This duplication is intentional; do not collapse it. However, only include the outer-level credential lines if those credentials were **explicitly present** in the prompt you received.
|
||||
|
||||
#### Parameters to pass
|
||||
|
||||
@@ -392,6 +458,7 @@ Note that the credentials (`forgejo_url`, `forgejo_owner`, `forgejo_repo`, `forg
|
||||
2. **Never implement work yourself.** Your only responsibilities are (a) calling `{estimator_agent}` to resolve the tier and (b) forwarding `{task_prompt}` to `{task_agent}` through the resolved `{tier_agent}`. Do not attempt to perform the work described in `{task_prompt}` — that is the inner task agent's job.
|
||||
3. **Pass `{task_prompt}` verbatim.** Do not summarise, paraphrase, truncate, or otherwise modify the prompt body — embed it as-is into both the estimator call and the tier-selector call. Modifying it would change what the inner agents are asked to do.
|
||||
4. **Pass all credentials verbatim.** Do not interpret, summarise, or modify any credential or configuration content received in your prompt — embed it as-is into the subagent prompts.
|
||||
5. **Default to tier 0 on low confidence.** If `{estimator_agent}` returns `is_confident: false`, set `escalation_tier` to `0` (and `tier_agent` to `tier-qwen`) and dispatch from there. Do not pick a tier yourself or override a confident estimator response.
|
||||
6. **Return the tier-selector output verbatim.** Do not summarise, interpret, or modify what the tier selector returns — pass it back to your caller exactly as received.
|
||||
7. **Never ask questions or give up.** Operate fully autonomously using best judgement. If a required parameter is missing or a subagent fails fatally, exit immediately and report the error.
|
||||
5. **Only pass explicitly-present variables.** Include only variables that were **explicitly present** in your prompt in subagent calls. Omit any variable you fetched from environment variables or git remote — downstream agents will fetch them themselves.
|
||||
6. **Default to tier 0 on low confidence.** If `{estimator_agent}` returns `is_confident: false`, set `escalation_tier` to `0` (and `tier_agent` to `tier-qwen`) and dispatch from there. Do not pick a tier yourself or override a confident estimator response.
|
||||
7. **Return the tier-selector output verbatim.** Do not summarise, interpret, or modify what the tier selector returns — pass it back to your caller exactly as received.
|
||||
8. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question. If a required parameter is missing or a subagent fails fatally, exit immediately and report the error.
|
||||
|
||||
@@ -13,24 +13,84 @@ reasoningEffort: "high"
|
||||
# All pass-through type agents for abstraction and reusability purposes, use the following color
|
||||
color: "#FFFF00"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# Agents called in an async manner should have this set to deny, otherwise use best discretion
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
@@ -43,15 +103,20 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -154,4 +219,4 @@ All parameters received in this agent's own prompt — **except `tier_agent`** a
|
||||
1. **Never act on the context.** Your only role is model-tier enforcement and pass-through.
|
||||
2. **Strip `tier_agent` and `target_agent` before forwarding.** `tier_agent` would cause a dispatch loop in the inner agent; `target_agent` is a routing instruction for this tier selector only.
|
||||
3. **Return results verbatim.** Do not summarize, interpret, or modify what `{target_agent}` returns.
|
||||
4. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
4. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
|
||||
@@ -13,24 +13,84 @@ reasoningEffort: "high"
|
||||
# All pass-through type agents for abstraction and reusability purposes, use the following color
|
||||
color: "#FFFF00"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# Agents called in an async manner should have this set to deny, otherwise use best discretion
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
@@ -43,15 +103,20 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -154,4 +219,4 @@ All parameters received in this agent's own prompt — **except `tier_agent`** a
|
||||
1. **Never act on the context.** Your only role is model-tier enforcement and pass-through.
|
||||
2. **Strip `tier_agent` and `target_agent` before forwarding.** `tier_agent` would cause a dispatch loop in the inner agent; `target_agent` is a routing instruction for this tier selector only.
|
||||
3. **Return results verbatim.** Do not summarize, interpret, or modify what `{target_agent}` returns.
|
||||
4. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
4. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
|
||||
@@ -13,24 +13,84 @@ reasoningEffort: "max"
|
||||
# All pass-through type agents for abstraction and reusability purposes, use the following color
|
||||
color: "#FFFF00"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# Agents called in an async manner should have this set to deny, otherwise use best discretion
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
@@ -43,15 +103,20 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -154,4 +219,4 @@ All parameters received in this agent's own prompt — **except `tier_agent`** a
|
||||
1. **Never act on the context.** Your only role is model-tier enforcement and pass-through.
|
||||
2. **Strip `tier_agent` and `target_agent` before forwarding.** `tier_agent` would cause a dispatch loop in the inner agent; `target_agent` is a routing instruction for this tier selector only.
|
||||
3. **Return results verbatim.** Do not summarize, interpret, or modify what `{target_agent}` returns.
|
||||
4. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
4. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
---
|
||||
description: >
|
||||
Level 0 tier selector (default starting tier). Enforces the Qwen
|
||||
`kimi` tier selector (default starting tier). Enforces the Kimi
|
||||
model tier for any target agent passed via the `target_agent` parameter.
|
||||
Receives a context prompt and invokes `{target_agent}` as a synchronous
|
||||
subagent that inherits the Haiku model, then returns the result verbatim.
|
||||
@@ -8,29 +8,88 @@ description: >
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
reasoningEffort: "high"
|
||||
model: "CleverThis-4/Kimi-K2-6-GGUF-Q2-K-XL"
|
||||
# All pass-through type agents for abstraction and reusability purposes, use the following color
|
||||
color: "#FFFF00"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# Agents called in an async manner should have this set to deny, otherwise use best discretion
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
@@ -43,15 +102,20 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -69,9 +133,9 @@ permission:
|
||||
"*": deny
|
||||
---
|
||||
|
||||
# Tier Selector: Level 1 (Qwen)
|
||||
# Tier Selector: `kimi`
|
||||
|
||||
You are a pure pass-through agent that enforces the Qwen model tier (level 1, the default starting tier for implementation work). You receive a context prompt and immediately invoke the `{target_agent}` subagent — which inherits your Qwen model tier. You do not interpret, modify, or act on the context yourself. Your sole purpose is model-tier enforcement, enabling callers to route any compatible worker through this tier.
|
||||
You are a pure pass-through agent that enforces the Kimi model tier (level 1, the default starting tier for implementation work). You receive a context prompt and immediately invoke the `{target_agent}` subagent — which inherits your Kimi model tier. You do not interpret, modify, or act on the context yourself. Your sole purpose is model-tier enforcement, enabling callers to route any compatible worker through this tier.
|
||||
|
||||
## Behavior
|
||||
|
||||
@@ -89,7 +153,7 @@ Startup steps:
|
||||
|
||||
### Main task
|
||||
|
||||
This agent has no true loop of its own. It receives the context prompt, dispatches to `{target_agent}` at the Qwen tier, and returns the result.
|
||||
This agent has no true loop of its own. It receives the context prompt, dispatches to `{target_agent}` at the Kimi tier, and returns the result.
|
||||
|
||||
1. Forward the entire received prompt — verbatim and without modification — to `{target_agent}` via the Task tool, **omitting the `tier_agent` parameter line** (if present) and **omitting the `target_agent` parameter line**
|
||||
2. Return the result from `{target_agent}` verbatim to the caller
|
||||
@@ -100,11 +164,11 @@ Throughout this prompt we will use a format where we will use the local variable
|
||||
|
||||
| Parameter | Local Variable | Notes |
|
||||
|--------------|:---------------:|---------------------------------------------------------------------|
|
||||
| Target agent | `target_agent` | Name of the subagent to invoke at the Qwen model tier |
|
||||
| Target agent | `target_agent` | Name of the subagent to invoke at the Kimi model tier |
|
||||
|
||||
All other parameters present in the prompt are opaque pass-through values for `{target_agent}`. This tier selector does not interpret, validate, or act on them.
|
||||
|
||||
**CRITICAL:** Never interpret or act on the context yourself. Your only job is to enforce the Qwen model tier and forward everything to `{target_agent}`.
|
||||
**CRITICAL:** Never interpret or act on the context yourself. Your only job is to enforce the Kimi model tier and forward everything to `{target_agent}`.
|
||||
|
||||
### What you receive in your prompt
|
||||
|
||||
@@ -137,7 +201,7 @@ This agent does not use environment variable fallbacks. All necessary parameters
|
||||
|
||||
#### How to invoke
|
||||
|
||||
Invoke `{target_agent}` as a blocking call via the Task tool, passing the full received prompt verbatim, omitting both `tier_agent` and `target_agent`. Because `{target_agent}` has no model of its own configured, it inherits this agent's Qwen model and runs at that tier.
|
||||
Invoke `{target_agent}` as a blocking call via the Task tool, passing the full received prompt verbatim, omitting both `tier_agent` and `target_agent`. Because `{target_agent}` has no model of its own configured, it inherits this agent's Kimi model and runs at that tier.
|
||||
|
||||
#### Prompt template
|
||||
|
||||
@@ -154,4 +218,4 @@ All parameters received in this agent's own prompt — **except `tier_agent`** a
|
||||
1. **Never act on the context.** Your only role is model-tier enforcement and pass-through.
|
||||
2. **Strip `tier_agent` and `target_agent` before forwarding.** `tier_agent` would cause a dispatch loop in the inner agent; `target_agent` is a routing instruction for this tier selector only.
|
||||
3. **Return results verbatim.** Do not summarize, interpret, or modify what `{target_agent}` returns.
|
||||
4. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
4. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -13,24 +13,84 @@ reasoningEffort: "high"
|
||||
# All pass-through type agents for abstraction and reusability purposes, use the following color
|
||||
color: "#FFFF00"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# Agents called in an async manner should have this set to deny, otherwise use best discretion
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
@@ -43,15 +103,20 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -154,4 +219,4 @@ All parameters received in this agent's own prompt — **except `tier_agent`** a
|
||||
1. **Never act on the context.** Your only role is model-tier enforcement and pass-through.
|
||||
2. **Strip `tier_agent` and `target_agent` before forwarding.** `tier_agent` would cause a dispatch loop in the inner agent; `target_agent` is a routing instruction for this tier selector only.
|
||||
3. **Return results verbatim.** Do not summarize, interpret, or modify what `{target_agent}` returns.
|
||||
4. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
4. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
|
||||
@@ -14,24 +14,84 @@ reasoningEffort: "max"
|
||||
# All pass-through type agents for abstraction and reusability purposes, use the following color
|
||||
color: "#FFFF00"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# Agents called in an async manner should have this set to deny, otherwise use best discretion
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
@@ -44,15 +104,20 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -155,4 +220,4 @@ All parameters received in this agent's own prompt — **except `tier_agent`** a
|
||||
1. **Never act on the context.** Your only role is model-tier enforcement and pass-through.
|
||||
2. **Strip `tier_agent` and `target_agent` before forwarding.** `tier_agent` would cause a dispatch loop in the inner agent; `target_agent` is a routing instruction for this tier selector only.
|
||||
3. **Return results verbatim.** Do not summarize, interpret, or modify what `{target_agent}` returns.
|
||||
4. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
4. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
|
||||
@@ -0,0 +1,221 @@
|
||||
---
|
||||
description: >
|
||||
`qwen-large` tier selector (default starting tier). Enforces the Large Qwen
|
||||
model tier for any target agent passed via the `target_agent` parameter.
|
||||
Receives a context prompt and invokes `{target_agent}` as a synchronous
|
||||
subagent that inherits the Haiku model, then returns the result verbatim.
|
||||
Reusable across any worker that supports tier-based model escalation.
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-16/Qwen3-code-480B-A35B-INST-GGUF-1M-UD-Q3-K-XL"
|
||||
# All pass-through type agents for abstraction and reusability purposes, use the following color
|
||||
color: "#FFFF00"
|
||||
permission:
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
"context7*": deny
|
||||
|
||||
#Only agents that need external information should have these as allow
|
||||
webfetch: deny
|
||||
websearch: deny
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
# target_agent is caller-controlled but is required by convention to be a
|
||||
# `task-*` agent (the final inner work agent in the tiered dispatch flow).
|
||||
# Restricting the wildcard to `task-*` enforces that contract while keeping
|
||||
# the selector reusable across any task agent.
|
||||
task:
|
||||
"task-*": allow
|
||||
|
||||
# All the skills this agent should have access to load
|
||||
skill:
|
||||
# Always start with deny and enable what the agent needs
|
||||
"*": deny
|
||||
---
|
||||
|
||||
# Tier Selector: qwen-large
|
||||
|
||||
You are a pure pass-through agent that enforces the Large Qwen model tier (level 1, the default starting tier for implementation work). You receive a context prompt and immediately invoke the `{target_agent}` subagent — which inherits your Large Qwen model tier. You do not interpret, modify, or act on the context yourself. Your sole purpose is model-tier enforcement, enabling callers to route any compatible worker through this tier.
|
||||
|
||||
## Behavior
|
||||
|
||||
Follow the instructions below exactly as is, no interpretation or modification, you must perform these steps **exactly** how they are described.
|
||||
|
||||
### Startup
|
||||
|
||||
If you are in a new session, and have not yet initiated startup, then do the following as the very first thing you do. **Never** proceed to the operation until these startup steps are completed.
|
||||
|
||||
Startup steps:
|
||||
|
||||
1. Verify the prompt is not empty — if it is, exit immediately and report the error
|
||||
2. Parse `target_agent` from the prompt — if absent or empty, exit immediately and report the error
|
||||
3. Proceed to the main task
|
||||
|
||||
### Main task
|
||||
|
||||
This agent has no true loop of its own. It receives the context prompt, dispatches to `{target_agent}` at the Large Qwen tier, and returns the result.
|
||||
|
||||
1. Forward the entire received prompt — verbatim and without modification — to `{target_agent}` via the Task tool, **omitting the `tier_agent` parameter line** (if present) and **omitting the `target_agent` parameter line**
|
||||
2. Return the result from `{target_agent}` verbatim to the caller
|
||||
|
||||
## Parameters and local variables
|
||||
|
||||
Throughout this prompt we will use a format where we will use the local variable name in curly brackets anywhere we want to substitute the contents of that variable. For example, if `{target_agent}` has the value `task-implementor` then `{target_agent}` should be replaced with `task-implementor` wherever it appears.
|
||||
|
||||
| Parameter | Local Variable | Notes |
|
||||
|--------------|:---------------:|---------------------------------------------------------------------|
|
||||
| Target agent | `target_agent` | Name of the subagent to invoke at the Large Qwen model tier |
|
||||
|
||||
All other parameters present in the prompt are opaque pass-through values for `{target_agent}`. This tier selector does not interpret, validate, or act on them.
|
||||
|
||||
**CRITICAL:** Never interpret or act on the context yourself. Your only job is to enforce the Large Qwen model tier and forward everything to `{target_agent}`.
|
||||
|
||||
### What you receive in your prompt
|
||||
|
||||
| Parameter | Required? | Local Variable |
|
||||
|--------------|:---------:|-----------------|
|
||||
| Target agent | yes | `target_agent` |
|
||||
|
||||
All other content in the prompt is pass-through for `{target_agent}`.
|
||||
|
||||
#### Example prompt
|
||||
|
||||
```
|
||||
target_agent: "task-implementor"
|
||||
work_type: "issue_impl"
|
||||
work_number: 42
|
||||
[... all other parameters for the target agent ...]
|
||||
```
|
||||
|
||||
### Variables to fetch
|
||||
|
||||
This agent does not fetch any variables from the repository context or environment. All parameters must be provided directly by the caller.
|
||||
|
||||
### Fallback to environment variables
|
||||
|
||||
This agent does not use environment variable fallbacks. All necessary parameters must be provided directly in the prompt.
|
||||
|
||||
## Subagents
|
||||
|
||||
### `{target_agent}`
|
||||
|
||||
#### How to invoke
|
||||
|
||||
Invoke `{target_agent}` as a blocking call via the Task tool, passing the full received prompt verbatim, omitting both `tier_agent` and `target_agent`. Because `{target_agent}` has no model of its own configured, it inherits this agent's Qwen model and runs at that tier.
|
||||
|
||||
#### Prompt template
|
||||
|
||||
Forward the entire received prompt as-is, removing:
|
||||
- The `tier_agent` parameter line (if present) — its presence in the inner call would cause a dispatch loop
|
||||
- The `target_agent` parameter line — not needed by the inner agent
|
||||
|
||||
#### Parameters to pass
|
||||
|
||||
All parameters received in this agent's own prompt — **except `tier_agent`** and **`target_agent`**.
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
1. **Never act on the context.** Your only role is model-tier enforcement and pass-through.
|
||||
2. **Strip `tier_agent` and `target_agent` before forwarding.** `tier_agent` would cause a dispatch loop in the inner agent; `target_agent` is a routing instruction for this tier selector only.
|
||||
3. **Return results verbatim.** Do not summarize, interpret, or modify what `{target_agent}` returns.
|
||||
4. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -0,0 +1,222 @@
|
||||
---
|
||||
description: >
|
||||
`qwen-med` tier selector (default starting tier). Enforces the Qwen
|
||||
model tier for any target agent passed via the `target_agent` parameter.
|
||||
Receives a context prompt and invokes `{target_agent}` as a synchronous
|
||||
subagent that inherits the Haiku model, then returns the result verbatim.
|
||||
Reusable across any worker that supports tier-based model escalation.
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-9/Qwen3-6-35B-A3B-GGUF-MXFP4-MOE"
|
||||
reasoningEffort: "high"
|
||||
# All pass-through type agents for abstraction and reusability purposes, use the following color
|
||||
color: "#FFFF00"
|
||||
permission:
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
"context7*": deny
|
||||
|
||||
#Only agents that need external information should have these as allow
|
||||
webfetch: deny
|
||||
websearch: deny
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
# target_agent is caller-controlled but is required by convention to be a
|
||||
# `task-*` agent (the final inner work agent in the tiered dispatch flow).
|
||||
# Restricting the wildcard to `task-*` enforces that contract while keeping
|
||||
# the selector reusable across any task agent.
|
||||
task:
|
||||
"task-*": allow
|
||||
|
||||
# All the skills this agent should have access to load
|
||||
skill:
|
||||
# Always start with deny and enable what the agent needs
|
||||
"*": deny
|
||||
---
|
||||
|
||||
# Tier Selector: `qwen-med`
|
||||
|
||||
You are a pure pass-through agent that enforces the Qwen model tier. You receive a context prompt and immediately invoke the `{target_agent}` subagent — which inherits your Qwen model tier. You do not interpret, modify, or act on the context yourself. Your sole purpose is model-tier enforcement, enabling callers to route any compatible worker through this tier.
|
||||
|
||||
## Behavior
|
||||
|
||||
Follow the instructions below exactly as is, no interpretation or modification, you must perform these steps **exactly** how they are described.
|
||||
|
||||
### Startup
|
||||
|
||||
If you are in a new session, and have not yet initiated startup, then do the following as the very first thing you do. **Never** proceed to the operation until these startup steps are completed.
|
||||
|
||||
Startup steps:
|
||||
|
||||
1. Verify the prompt is not empty — if it is, exit immediately and report the error
|
||||
2. Parse `target_agent` from the prompt — if absent or empty, exit immediately and report the error
|
||||
3. Proceed to the main task
|
||||
|
||||
### Main task
|
||||
|
||||
This agent has no true loop of its own. It receives the context prompt, dispatches to `{target_agent}` effectively setting it to the `qwen-med` tier, and returns the result.
|
||||
|
||||
1. Forward the entire received prompt — verbatim and without modification — to `{target_agent}` via the Task tool, **omitting the `tier_agent` parameter line** (if present) and **omitting the `target_agent` parameter line**
|
||||
2. Return the result from `{target_agent}` verbatim to the caller
|
||||
|
||||
## Parameters and local variables
|
||||
|
||||
Throughout this prompt we will use a format where we will use the local variable name in curly brackets anywhere we want to substitute the contents of that variable. For example, if `{target_agent}` has the value `task-implementor` then `{target_agent}` should be replaced with `task-implementor` wherever it appears.
|
||||
|
||||
| Parameter | Local Variable | Notes |
|
||||
|--------------|:---------------:|---------------------------------------------------------------------|
|
||||
| Target agent | `target_agent` | Name of the subagent to invoke at the Medium Qwen model tier |
|
||||
|
||||
All other parameters present in the prompt are opaque pass-through values for `{target_agent}`. This tier selector does not interpret, validate, or act on them.
|
||||
|
||||
**CRITICAL:** Never interpret or act on the context yourself. Your only job is to enforce the Medium Qwen model tier and forward everything to `{target_agent}`.
|
||||
|
||||
### What you receive in your prompt
|
||||
|
||||
| Parameter | Required? | Local Variable |
|
||||
|--------------|:---------:|-----------------|
|
||||
| Target agent | yes | `target_agent` |
|
||||
|
||||
All other content in the prompt is pass-through for `{target_agent}`.
|
||||
|
||||
#### Example prompt
|
||||
|
||||
```
|
||||
target_agent: "task-implementor"
|
||||
work_type: "issue_impl"
|
||||
work_number: 42
|
||||
[... all other parameters for the target agent ...]
|
||||
```
|
||||
|
||||
### Variables to fetch
|
||||
|
||||
This agent does not fetch any variables from the repository context or environment. All parameters must be provided directly by the caller.
|
||||
|
||||
### Fallback to environment variables
|
||||
|
||||
This agent does not use environment variable fallbacks. All necessary parameters must be provided directly in the prompt.
|
||||
|
||||
## Subagents
|
||||
|
||||
### `{target_agent}`
|
||||
|
||||
#### How to invoke
|
||||
|
||||
Invoke `{target_agent}` as a blocking call via the Task tool, passing the full received prompt verbatim, omitting both `tier_agent` and `target_agent`. Because `{target_agent}` has no model of its own configured, it inherits this agent's Medium Qwen model and runs at that tier.
|
||||
|
||||
#### Prompt template
|
||||
|
||||
Forward the entire received prompt as-is, removing:
|
||||
- The `tier_agent` parameter line (if present) — its presence in the inner call would cause a dispatch loop
|
||||
- The `target_agent` parameter line — not needed by the inner agent
|
||||
|
||||
#### Parameters to pass
|
||||
|
||||
All parameters received in this agent's own prompt — **except `tier_agent`** and **`target_agent`**.
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
1. **Never act on the context.** Your only role is model-tier enforcement and pass-through.
|
||||
2. **Strip `tier_agent` and `target_agent` before forwarding.** `tier_agent` would cause a dispatch loop in the inner agent; `target_agent` is a routing instruction for this tier selector only.
|
||||
3. **Return results verbatim.** Do not summarize, interpret, or modify what `{target_agent}` returns.
|
||||
4. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -0,0 +1,222 @@
|
||||
---
|
||||
description: >
|
||||
`qwen-small` tier selector (default starting tier). Enforces the Small Qwen
|
||||
model tier for any target agent passed via the `target_agent` parameter.
|
||||
Receives a context prompt and invokes `{target_agent}` as a synchronous
|
||||
subagent that inherits the Haiku model, then returns the result verbatim.
|
||||
Reusable across any worker that supports tier-based model escalation.
|
||||
mode: subagent
|
||||
hidden: false
|
||||
temperature: 0.0
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All pass-through type agents for abstraction and reusability purposes, use the following color
|
||||
color: "#FFFF00"
|
||||
permission:
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
"context7*": deny
|
||||
|
||||
#Only agents that need external information should have these as allow
|
||||
webfetch: deny
|
||||
websearch: deny
|
||||
codesearch: deny
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
# target_agent is caller-controlled but is required by convention to be a
|
||||
# `task-*` agent (the final inner work agent in the tiered dispatch flow).
|
||||
# Restricting the wildcard to `task-*` enforces that contract while keeping
|
||||
# the selector reusable across any task agent.
|
||||
task:
|
||||
"task-*": allow
|
||||
|
||||
# All the skills this agent should have access to load
|
||||
skill:
|
||||
# Always start with deny and enable what the agent needs
|
||||
"*": deny
|
||||
---
|
||||
|
||||
# Tier Selector: `qwen-small`
|
||||
|
||||
You are a pure pass-through agent that enforces the Small Small Qwen model tier (level 1, the default starting tier for implementation work). You receive a context prompt and immediately invoke the `{target_agent}` subagent — which inherits your Small Qwen model tier. You do not interpret, modify, or act on the context yourself. Your sole purpose is model-tier enforcement, enabling callers to route any compatible worker through this tier.
|
||||
|
||||
## Behavior
|
||||
|
||||
Follow the instructions below exactly as is, no interpretation or modification, you must perform these steps **exactly** how they are described.
|
||||
|
||||
### Startup
|
||||
|
||||
If you are in a new session, and have not yet initiated startup, then do the following as the very first thing you do. **Never** proceed to the operation until these startup steps are completed.
|
||||
|
||||
Startup steps:
|
||||
|
||||
1. Verify the prompt is not empty — if it is, exit immediately and report the error
|
||||
2. Parse `target_agent` from the prompt — if absent or empty, exit immediately and report the error
|
||||
3. Proceed to the main task
|
||||
|
||||
### Main task
|
||||
|
||||
This agent has no true loop of its own. It receives the context prompt, dispatches to `{target_agent}` at the Small Qwen tier, and returns the result.
|
||||
|
||||
1. Forward the entire received prompt — verbatim and without modification — to `{target_agent}` via the Task tool, **omitting the `tier_agent` parameter line** (if present) and **omitting the `target_agent` parameter line**
|
||||
2. Return the result from `{target_agent}` verbatim to the caller
|
||||
|
||||
## Parameters and local variables
|
||||
|
||||
Throughout this prompt we will use a format where we will use the local variable name in curly brackets anywhere we want to substitute the contents of that variable. For example, if `{target_agent}` has the value `task-implementor` then `{target_agent}` should be replaced with `task-implementor` wherever it appears.
|
||||
|
||||
| Parameter | Local Variable | Notes |
|
||||
|--------------|:---------------:|---------------------------------------------------------------------|
|
||||
| Target agent | `target_agent` | Name of the subagent to invoke at the Small Qwen model tier |
|
||||
|
||||
All other parameters present in the prompt are opaque pass-through values for `{target_agent}`. This tier selector does not interpret, validate, or act on them.
|
||||
|
||||
**CRITICAL:** Never interpret or act on the context yourself. Your only job is to enforce the Small Qwen model tier and forward everything to `{target_agent}`.
|
||||
|
||||
### What you receive in your prompt
|
||||
|
||||
| Parameter | Required? | Local Variable |
|
||||
|--------------|:---------:|-----------------|
|
||||
| Target agent | yes | `target_agent` |
|
||||
|
||||
All other content in the prompt is pass-through for `{target_agent}`.
|
||||
|
||||
#### Example prompt
|
||||
|
||||
```
|
||||
target_agent: "task-implementor"
|
||||
work_type: "issue_impl"
|
||||
work_number: 42
|
||||
[... all other parameters for the target agent ...]
|
||||
```
|
||||
|
||||
### Variables to fetch
|
||||
|
||||
This agent does not fetch any variables from the repository context or environment. All parameters must be provided directly by the caller.
|
||||
|
||||
### Fallback to environment variables
|
||||
|
||||
This agent does not use environment variable fallbacks. All necessary parameters must be provided directly in the prompt.
|
||||
|
||||
## Subagents
|
||||
|
||||
### `{target_agent}`
|
||||
|
||||
#### How to invoke
|
||||
|
||||
Invoke `{target_agent}` as a blocking call via the Task tool, passing the full received prompt verbatim, omitting both `tier_agent` and `target_agent`. Because `{target_agent}` has no model of its own configured, it inherits this agent's Qwen model and runs at that tier.
|
||||
|
||||
#### Prompt template
|
||||
|
||||
Forward the entire received prompt as-is, removing:
|
||||
- The `tier_agent` parameter line (if present) — its presence in the inner call would cause a dispatch loop
|
||||
- The `target_agent` parameter line — not needed by the inner agent
|
||||
|
||||
#### Parameters to pass
|
||||
|
||||
All parameters received in this agent's own prompt — **except `tier_agent`** and **`target_agent`**.
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
1. **Never act on the context.** Your only role is model-tier enforcement and pass-through.
|
||||
2. **Strip `tier_agent` and `target_agent` before forwarding.** `tier_agent` would cause a dispatch loop in the inner agent; `target_agent` is a routing instruction for this tier selector only.
|
||||
3. **Return results verbatim.** Do not summarize, interpret, or modify what `{target_agent}` returns.
|
||||
4. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
@@ -13,24 +13,84 @@ reasoningEffort: "max"
|
||||
# All pass-through type agents for abstraction and reusability purposes, use the following color
|
||||
color: "#FFFF00"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# Agents called in an async manner should have this set to deny, otherwise use best discretion
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
|
||||
"sequential-thinking*": deny
|
||||
@@ -43,15 +103,20 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# The following bash permissions must be applied to all agents in the auto-agents-system
|
||||
# Block ALL commands that could hit the label creation endpoints
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -154,4 +219,4 @@ All parameters received in this agent's own prompt — **except `tier_agent`** a
|
||||
1. **Never act on the context.** Your only role is model-tier enforcement and pass-through.
|
||||
2. **Strip `tier_agent` and `target_agent` before forwarding.** `tier_agent` would cause a dispatch loop in the inner agent; `target_agent` is a routing instruction for this tier selector only.
|
||||
3. **Return results verbatim.** Do not summarize, interpret, or modify what `{target_agent}` returns.
|
||||
4. **Never ask questions or give up.** Operate fully autonomously using best judgement.
|
||||
4. **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
|
||||
@@ -7,29 +7,89 @@ description: >
|
||||
mode: subagent
|
||||
hidden: true
|
||||
temperature: 0.1
|
||||
model: "CleverThis-8/Qwen3-Coder-Next-GGUF-Q6-K"
|
||||
model: "CleverThis-15/Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL"
|
||||
reasoningEffort: "high"
|
||||
# All utility type agents use the following color
|
||||
color: "#5555FF"
|
||||
permission:
|
||||
# Block whatever we don't explicitly allow
|
||||
"*": deny
|
||||
"glob": allow
|
||||
"grep": allow
|
||||
"doom_loop": deny
|
||||
|
||||
# One-shot subagent, no questions
|
||||
# This agent only needs to call one subagent
|
||||
"question": deny
|
||||
|
||||
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
|
||||
external_directory:
|
||||
"/tmp/*": allow
|
||||
"/tmp/**": allow
|
||||
"/app/**": deny
|
||||
edit:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
write:
|
||||
"*": deny
|
||||
"/tmp/*": allow
|
||||
"a**": deny
|
||||
"b**": deny
|
||||
"c**": deny
|
||||
"d**": deny
|
||||
"e**": deny
|
||||
"f**": deny
|
||||
"g**": deny
|
||||
"h**": deny
|
||||
"i**": deny
|
||||
"j**": deny
|
||||
"k**": deny
|
||||
"l**": deny
|
||||
"m**": deny
|
||||
"n**": deny
|
||||
"o**": deny
|
||||
"p**": deny
|
||||
"q**": deny
|
||||
"r**": deny
|
||||
"s**": deny
|
||||
"t**": deny
|
||||
"u**": deny
|
||||
"v**": deny
|
||||
"w**": deny
|
||||
"x**": deny
|
||||
"y**": deny
|
||||
"z**": deny
|
||||
"A**": deny
|
||||
"B**": deny
|
||||
"C**": deny
|
||||
"D**": deny
|
||||
"E**": deny
|
||||
"F**": deny
|
||||
"G**": deny
|
||||
"H**": deny
|
||||
"I**": deny
|
||||
"J**": deny
|
||||
"K**": deny
|
||||
"L**": deny
|
||||
"M**": deny
|
||||
"N**": deny
|
||||
"O**": deny
|
||||
"P**": deny
|
||||
"Q**": deny
|
||||
"R**": deny
|
||||
"S**": deny
|
||||
"T**": deny
|
||||
"U**": deny
|
||||
"V**": deny
|
||||
"W**": deny
|
||||
"X**": deny
|
||||
"Y**": deny
|
||||
"Z**": deny
|
||||
"1**": deny
|
||||
"2**": deny
|
||||
"3**": deny
|
||||
"4**": deny
|
||||
"5**": deny
|
||||
"6**": deny
|
||||
"7**": deny
|
||||
"8**": deny
|
||||
"9**": deny
|
||||
"0**": deny
|
||||
"/app/**": deny
|
||||
"/tmp/**": allow
|
||||
read:
|
||||
"*": allow
|
||||
"**": allow
|
||||
|
||||
# MCP permissions
|
||||
"sequential-thinking*": allow
|
||||
@@ -42,9 +102,12 @@ permission:
|
||||
|
||||
bash:
|
||||
# All agents should start with deny and then add in as needed
|
||||
"*": deny
|
||||
"echo $*": allow
|
||||
"*": allow
|
||||
"echo *": allow
|
||||
"cat *": allow
|
||||
"printenv *": allow
|
||||
"git -C * remote get-url origin": allow
|
||||
"git remote get-url origin": allow
|
||||
|
||||
# Work-group fetch scripts from auto-agents-system
|
||||
"npx --yes tsx *.opencode/skills/auto-agents-system/scripts/*": allow
|
||||
@@ -60,6 +123,8 @@ permission:
|
||||
"*api/v1/orgs/*/labels*": deny
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
@@ -123,8 +188,19 @@ Each item in `items` should include only the fields the supervisor needs to disp
|
||||
| Pool size | yes | Number of items to return |
|
||||
| Credentials | no | May be provided, or read from vault |
|
||||
|
||||
### Fallback to environment variables
|
||||
|
||||
For optional parameters not provided in your prompt, you may fall back to the environment variables listed below. Always give precedence to values explicitly passed in the prompt. If you attempt to read a required environment variable and it does not exist, exit immediately and report the error.
|
||||
|
||||
| Information | Env Variable | Required? | Local Variable |
|
||||
|------------------|-------------------|:---------:|-------------------|
|
||||
| Forgejo PAT | `FORGEJO_PAT` | Yes | `forgejo_pat` |
|
||||
| Repository base url | `FORGEJO_URL` | No | `forgejo_url` |
|
||||
| Repository owner | `FORGEJO_OWNER` | No | `forgejo_owner` |
|
||||
| Repository name | `FORGEJO_REPO` | No | `forgejo_repo` |
|
||||
|
||||
## **CRITICAL** Rules
|
||||
|
||||
- **Return compact results.** The whole point is to keep the supervisor's context clean. Return only what's needed.
|
||||
- **Report errors, don't hide them.** If a fetch fails, include it in the `errors` array.
|
||||
- **Never ask questions or give up.** Return the best results you can even if some groups fail.
|
||||
- **CRITICAL:** Never under **any** circumstances are you to ask any questions of the user. If you have a question, use your best judgement and answer it yourself. Even if you are completely unsure of the answer, make your best guest. It is **COMPLETELY FORBIDDEN** for you to ever ask a question.
|
||||
|
||||
Regular → Executable
+1
-1
@@ -17,7 +17,7 @@ PORT="${OPENCODE_PORT:-4096}"
|
||||
HOST="${OPENCODE_HOST:-127.0.0.1}"
|
||||
BASE="http://${HOST}:${PORT}"
|
||||
AGENT="auto-agents"
|
||||
PROMPT="Complete the current project's milestones up to and including v3.7.0 to a production ready state"
|
||||
PROMPT="Initialize the new environment then enter your main loop forever."
|
||||
HEALTH_TIMEOUT=60 # seconds to wait for the server to become healthy
|
||||
MAX_IDLE_PER_MINUTE=10
|
||||
|
||||
|
||||
@@ -8,6 +8,7 @@ subtypes) and their lifecycle attachments to resources.
|
||||
| Command | Description |
|
||||
|--------------------------------|------------------------------------------|
|
||||
| ``agents validation add`` | Register validation from YAML config |
|
||||
| ``agents validation list`` | List all registered validations |
|
||||
| ``agents validation attach`` | Attach validation to a resource |
|
||||
| ``agents validation detach`` | Detach a validation attachment |
|
||||
|
||||
@@ -49,14 +50,21 @@ Based on implementation_plan.md -- Task C1.tool.cli.
|
||||
from __future__ import annotations
|
||||
|
||||
from pathlib import Path
|
||||
from typing import Annotated, Any
|
||||
from typing import Annotated
|
||||
|
||||
import typer
|
||||
import yaml
|
||||
from rich.console import Console
|
||||
from rich.panel import Panel
|
||||
from rich.table import Table
|
||||
|
||||
from cleveragents.cli.bootstrap import ensure_cli_database_bootstrapped
|
||||
from cleveragents.cli.commands.validation_helpers import (
|
||||
attachment_dict,
|
||||
compile_pattern,
|
||||
get_tool_registry_service,
|
||||
get_validation_name,
|
||||
print_validation,
|
||||
validation_spec_dict,
|
||||
)
|
||||
from cleveragents.cli.formatting import OutputFormat, format_output
|
||||
from cleveragents.core.exceptions import (
|
||||
CleverAgentsError,
|
||||
@@ -74,97 +82,6 @@ console = Console()
|
||||
_FORMAT_HELP = "Output format: json, yaml, plain, table, or rich (default: rich)"
|
||||
|
||||
|
||||
def _get_tool_registry_service() -> Any:
|
||||
"""Get the ToolRegistryService from the DI container.
|
||||
|
||||
Delegates to get_container().tool_registry_service() so that
|
||||
service wiring is managed exclusively by the container (Forgejo #3006).
|
||||
"""
|
||||
from cleveragents.application.container import get_container
|
||||
|
||||
ensure_cli_database_bootstrapped()
|
||||
|
||||
return get_container().tool_registry_service()
|
||||
|
||||
|
||||
def _validation_spec_dict(tool: Any) -> dict[str, Any]:
|
||||
"""Return validation data as a dict for CLI rendering."""
|
||||
if hasattr(tool, "as_cli_dict"):
|
||||
return dict(tool.as_cli_dict())
|
||||
|
||||
if isinstance(tool, dict):
|
||||
result: dict[str, Any] = {
|
||||
"name": tool.get("name", ""),
|
||||
"description": tool.get("description", ""),
|
||||
"source": tool.get("source", ""),
|
||||
"tool_type": tool.get("tool_type", "validation"),
|
||||
"mode": tool.get("mode", "required"),
|
||||
}
|
||||
if tool.get("wraps"):
|
||||
result["wraps"] = tool["wraps"]
|
||||
if tool.get("transform"):
|
||||
result["transform"] = tool["transform"]
|
||||
return result
|
||||
|
||||
return {"name": str(tool)}
|
||||
|
||||
|
||||
def _attachment_dict(attachment: Any) -> dict[str, Any]:
|
||||
"""Convert an attachment to a plain dict for output formatting."""
|
||||
if isinstance(attachment, dict):
|
||||
return {
|
||||
"attachment_id": attachment.get("attachment_id", ""),
|
||||
"validation_name": attachment.get("validation_name", ""),
|
||||
"resource_id": attachment.get("resource_id", ""),
|
||||
"mode": attachment.get("mode", "required"),
|
||||
"project_name": attachment.get("project_name"),
|
||||
"plan_id": attachment.get("plan_id"),
|
||||
"created_at": attachment.get("created_at", ""),
|
||||
}
|
||||
return {
|
||||
"attachment_id": getattr(attachment, "attachment_id", ""),
|
||||
"validation_name": getattr(attachment, "validation_name", ""),
|
||||
"resource_id": getattr(attachment, "resource_id", ""),
|
||||
"mode": getattr(attachment, "mode", "required"),
|
||||
"project_name": getattr(attachment, "project_name", None),
|
||||
"plan_id": getattr(attachment, "plan_id", None),
|
||||
"created_at": str(getattr(attachment, "created_at", "")),
|
||||
}
|
||||
|
||||
|
||||
def _print_validation(
|
||||
tool: Any,
|
||||
title: str = "Validation",
|
||||
fmt: str = OutputFormat.RICH.value,
|
||||
) -> None:
|
||||
"""Print validation details in the requested format."""
|
||||
data = _validation_spec_dict(tool)
|
||||
if fmt != OutputFormat.RICH.value:
|
||||
console.print(format_output(data, fmt))
|
||||
return
|
||||
|
||||
name = data.get("name", "")
|
||||
desc = data.get("description", "")
|
||||
source = data.get("source", "")
|
||||
mode = data.get("mode", "required")
|
||||
|
||||
details = (
|
||||
f"[bold]Name:[/bold] {name}\n"
|
||||
f"[bold]Description:[/bold] {desc}\n"
|
||||
f"[bold]Source:[/bold] {source}\n"
|
||||
f"[bold]Mode:[/bold] {mode}"
|
||||
)
|
||||
|
||||
wraps = data.get("wraps")
|
||||
if wraps:
|
||||
details += f"\n[bold]Wraps:[/bold] {wraps}"
|
||||
transform = data.get("transform")
|
||||
if transform:
|
||||
details += f"\n[bold]Transform:[/bold] {transform}"
|
||||
|
||||
console.print(Panel(details, title=title, expand=False))
|
||||
|
||||
|
||||
@app.command("add")
|
||||
def add(
|
||||
config: Annotated[
|
||||
@@ -233,17 +150,17 @@ def add(
|
||||
config_dict["mode"] = ValidationMode.INFORMATIONAL.value
|
||||
|
||||
validation = Validation.from_config(config_dict)
|
||||
service = _get_tool_registry_service()
|
||||
service = get_tool_registry_service()
|
||||
|
||||
if update:
|
||||
existing = service.get_tool(validation.name)
|
||||
if existing is not None:
|
||||
registered = service.update_tool(validation)
|
||||
_print_validation(registered, title="Validation Updated", fmt=fmt)
|
||||
print_validation(registered, title="Validation Updated", fmt=fmt)
|
||||
return
|
||||
|
||||
registered = service.register_tool(validation)
|
||||
_print_validation(registered, title="Validation Registered", fmt=fmt)
|
||||
print_validation(registered, title="Validation Registered", fmt=fmt)
|
||||
|
||||
except FileNotFoundError as exc:
|
||||
console.print(f"[red]Config file error:[/red] {exc}")
|
||||
@@ -262,6 +179,92 @@ def add(
|
||||
raise typer.Abort() from exc
|
||||
|
||||
|
||||
@app.command("list")
|
||||
def list_validations(
|
||||
namespace: Annotated[
|
||||
str | None,
|
||||
typer.Option("--namespace", "-n", help="Filter by namespace"),
|
||||
] = None,
|
||||
source: Annotated[
|
||||
str | None,
|
||||
typer.Option("--source", "-s", help="Filter by source type"),
|
||||
] = None,
|
||||
pattern: Annotated[
|
||||
str | None,
|
||||
typer.Option(
|
||||
"--pattern",
|
||||
"-p",
|
||||
help="Filter validation names by regex pattern",
|
||||
),
|
||||
] = None,
|
||||
fmt: Annotated[
|
||||
str,
|
||||
typer.Option("--format", "-f", help=_FORMAT_HELP),
|
||||
] = "rich",
|
||||
) -> None:
|
||||
"""List validations with optional filters.
|
||||
|
||||
Examples:
|
||||
agents validation list
|
||||
agents validation list --namespace local
|
||||
agents validation list --source custom
|
||||
agents validation list --pattern "coverage-.*"
|
||||
agents validation list --format json
|
||||
"""
|
||||
try:
|
||||
service = get_tool_registry_service()
|
||||
validations = service.list_tools(
|
||||
namespace=namespace,
|
||||
tool_type="validation",
|
||||
source=source,
|
||||
)
|
||||
|
||||
# Apply regex filter if provided
|
||||
if pattern:
|
||||
compiled_pattern = compile_pattern(pattern)
|
||||
validations = [
|
||||
v
|
||||
for v in validations
|
||||
if compiled_pattern.search(get_validation_name(v))
|
||||
]
|
||||
|
||||
if not validations:
|
||||
console.print("[yellow]No validations found.[/yellow]")
|
||||
console.print("Register one with 'agents validation add --config <file>'")
|
||||
return
|
||||
|
||||
# Non-rich formats use the formatting helper
|
||||
if fmt != OutputFormat.RICH.value:
|
||||
data = [dict(validation_spec_dict(v)) for v in validations]
|
||||
console.print(format_output(data, fmt))
|
||||
return
|
||||
|
||||
# Rich table
|
||||
table = Table(title=f"Validations ({len(validations)} total)")
|
||||
table.add_column("Name", style="cyan")
|
||||
table.add_column("Mode", style="blue")
|
||||
table.add_column("Source", style="magenta")
|
||||
table.add_column("Description", style="dim")
|
||||
|
||||
for validation in validations:
|
||||
spec = validation_spec_dict(validation)
|
||||
desc = str(spec.get("description", ""))
|
||||
if len(desc) > 40:
|
||||
desc = desc[:37] + "..."
|
||||
table.add_row(
|
||||
str(spec.get("name", "")),
|
||||
str(spec.get("mode", "required")),
|
||||
str(spec.get("source", "")),
|
||||
desc,
|
||||
)
|
||||
|
||||
console.print(table)
|
||||
|
||||
except CleverAgentsError as exc:
|
||||
console.print(f"[red]Error:[/red] {exc.message}")
|
||||
raise typer.Abort() from exc
|
||||
|
||||
|
||||
@app.command(
|
||||
"attach",
|
||||
context_settings={"allow_extra_args": True, "ignore_unknown_options": True},
|
||||
@@ -324,7 +327,7 @@ def attach(
|
||||
raise typer.Abort()
|
||||
key = token[2:].replace(
|
||||
"-", "_"
|
||||
) # --coverage-threshold → coverage_threshold
|
||||
) # --coverage-threshold -> coverage_threshold
|
||||
if i + 1 >= len(raw_extra) or raw_extra[i + 1].startswith("--"):
|
||||
console.print(
|
||||
f"[red]Missing value for option:[/red] {token} "
|
||||
@@ -335,7 +338,7 @@ def attach(
|
||||
extra_args[key] = val
|
||||
i += 2
|
||||
|
||||
service = _get_tool_registry_service()
|
||||
service = get_tool_registry_service()
|
||||
attachment = service.attach_validation(
|
||||
validation_name=validation_name,
|
||||
resource_id=resource,
|
||||
@@ -344,7 +347,7 @@ def attach(
|
||||
args=extra_args,
|
||||
)
|
||||
|
||||
att_data = _attachment_dict(attachment)
|
||||
att_data = attachment_dict(attachment)
|
||||
|
||||
if fmt != OutputFormat.RICH.value:
|
||||
console.print(format_output(att_data, fmt))
|
||||
@@ -398,7 +401,7 @@ def detach(
|
||||
console.print("[yellow]Aborted.[/yellow]")
|
||||
raise typer.Abort()
|
||||
|
||||
service = _get_tool_registry_service()
|
||||
service = get_tool_registry_service()
|
||||
removed = service.detach_validation(attachment_id)
|
||||
|
||||
if not removed:
|
||||
|
||||
@@ -0,0 +1,125 @@
|
||||
"""Helper functions for validation CLI commands.
|
||||
|
||||
This module contains utility functions for validation command processing,
|
||||
including formatting, filtering, and data transformation.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import re
|
||||
from typing import Any
|
||||
|
||||
from rich.console import Console
|
||||
from rich.panel import Panel
|
||||
|
||||
from cleveragents.cli.bootstrap import ensure_cli_database_bootstrapped
|
||||
from cleveragents.cli.formatting import OutputFormat, format_output
|
||||
|
||||
console = Console()
|
||||
|
||||
|
||||
def get_tool_registry_service() -> Any:
|
||||
"""Get the ToolRegistryService from the DI container.
|
||||
|
||||
Delegates to get_container().tool_registry_service() so that
|
||||
service wiring is managed exclusively by the container (Forgejo #3006).
|
||||
"""
|
||||
from cleveragents.application.container import get_container
|
||||
|
||||
ensure_cli_database_bootstrapped()
|
||||
|
||||
return get_container().tool_registry_service()
|
||||
|
||||
|
||||
def validation_spec_dict(tool: Any) -> dict[str, Any]:
|
||||
"""Return validation data as a dict for CLI rendering."""
|
||||
if hasattr(tool, "as_cli_dict"):
|
||||
return dict(tool.as_cli_dict())
|
||||
|
||||
if isinstance(tool, dict):
|
||||
result: dict[str, Any] = {
|
||||
"name": tool.get("name", ""),
|
||||
"description": tool.get("description", ""),
|
||||
"source": tool.get("source", ""),
|
||||
"tool_type": tool.get("tool_type", "validation"),
|
||||
"mode": tool.get("mode", "required"),
|
||||
}
|
||||
if tool.get("wraps"):
|
||||
result["wraps"] = tool["wraps"]
|
||||
if tool.get("transform"):
|
||||
result["transform"] = tool["transform"]
|
||||
return result
|
||||
|
||||
return {"name": str(tool)}
|
||||
|
||||
|
||||
def get_validation_name(v: Any) -> str:
|
||||
"""Return the name string for a validation object or dict."""
|
||||
if isinstance(v, dict):
|
||||
return str(v.get("name", ""))
|
||||
return str(getattr(v, "name", ""))
|
||||
|
||||
|
||||
def attachment_dict(attachment: Any) -> dict[str, Any]:
|
||||
"""Convert an attachment to a plain dict for output formatting."""
|
||||
if isinstance(attachment, dict):
|
||||
return {
|
||||
"attachment_id": attachment.get("attachment_id", ""),
|
||||
"validation_name": attachment.get("validation_name", ""),
|
||||
"resource_id": attachment.get("resource_id", ""),
|
||||
"mode": attachment.get("mode", "required"),
|
||||
"project_name": attachment.get("project_name"),
|
||||
"plan_id": attachment.get("plan_id"),
|
||||
"created_at": attachment.get("created_at", ""),
|
||||
}
|
||||
return {
|
||||
"attachment_id": getattr(attachment, "attachment_id", ""),
|
||||
"validation_name": getattr(attachment, "validation_name", ""),
|
||||
"resource_id": getattr(attachment, "resource_id", ""),
|
||||
"mode": getattr(attachment, "mode", "required"),
|
||||
"project_name": getattr(attachment, "project_name", None),
|
||||
"plan_id": getattr(attachment, "plan_id", None),
|
||||
"created_at": str(getattr(attachment, "created_at", "")),
|
||||
}
|
||||
|
||||
|
||||
def print_validation(
|
||||
tool: Any,
|
||||
title: str = "Validation",
|
||||
fmt: str = OutputFormat.RICH.value,
|
||||
) -> None:
|
||||
"""Print validation details in the requested format."""
|
||||
data = validation_spec_dict(tool)
|
||||
if fmt != OutputFormat.RICH.value:
|
||||
console.print(format_output(data, fmt))
|
||||
return
|
||||
|
||||
name = data.get("name", "")
|
||||
desc = data.get("description", "")
|
||||
source = data.get("source", "")
|
||||
mode = data.get("mode", "required")
|
||||
|
||||
details = (
|
||||
f"[bold]Name:[/bold] {name}\n"
|
||||
f"[bold]Description:[/bold] {desc}\n"
|
||||
f"[bold]Source:[/bold] {source}\n"
|
||||
f"[bold]Mode:[/bold] {mode}"
|
||||
)
|
||||
|
||||
wraps = data.get("wraps")
|
||||
if wraps:
|
||||
details += f"\n[bold]Wraps:[/bold] {wraps}"
|
||||
transform = data.get("transform")
|
||||
if transform:
|
||||
details += f"\n[bold]Transform:[/bold] {transform}"
|
||||
|
||||
console.print(Panel(details, title=title, expand=False))
|
||||
|
||||
|
||||
def compile_pattern(pattern: str) -> re.Pattern[str]:
|
||||
"""Compile a regex pattern, raising an error if invalid."""
|
||||
try:
|
||||
return re.compile(pattern)
|
||||
except re.error as exc:
|
||||
console.print(f"[red]Invalid regex pattern:[/red] {pattern}")
|
||||
raise ValueError(f"Invalid regex pattern: {pattern}") from exc
|
||||
Reference in New Issue
Block a user