3e31ebcc1e
Explicit per-stage grants (least-privilege, invariant #5) for the mounted codebase-memory MCP side-car: - role_pipeline: discovery bootstraps the graph (index_repository) + grounds; analyst/architect/decomposer/implementer/reviewer get read-only query tools (search_code/search_graph/get_architecture/trace_path/get_code_snippet) scoped to each role. NOTE: architect flips from pure-reasoning to tool-calling. - review_loop implement+review and task_planning planner get read-only queries. Tools are approval-gated at T2 (server default in config.toml [[mcp]]). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
73 lines
2.2 KiB
TOML
73 lines
2.2 KiB
TOML
# Implementer ↔ reviewer refinement loop.
|
|
#
|
|
# The reviewer emits a validated `review_report` artifact carrying a `verdict` field.
|
|
# The loop exits to `done` when verdict == "approved" and loops back to `implement`
|
|
# otherwise (verdict != "approved"). The runtime refinement guard caps the
|
|
# review→implement cycle at `implement.max_retries` iterations and then escalates.
|
|
#
|
|
# Requires a `review_report` artifact kind declared in config:
|
|
# [[artifacts]]
|
|
# id = "review_report"
|
|
# schema_path = "schemas/review_report.json"
|
|
# llm_emitted = true
|
|
|
|
id = "review_loop"
|
|
start = "implement"
|
|
|
|
# implement owns the work item across the loop: claim before starting, submit_for_review once
|
|
# the patch is ready, add notes (task_create one first if the work warrants tracking).
|
|
[[stages]]
|
|
id = "implement"
|
|
prompt = "prompts/implement.md"
|
|
produces = [{ name = "patch", kind = "file_written" }]
|
|
allowed_tools = [
|
|
"file_write", "task_create", "task_update", "task_context", "task_search",
|
|
"mcp__codebase-memory__search_code",
|
|
"mcp__codebase-memory__get_code_snippet",
|
|
"mcp__codebase-memory__trace_path",
|
|
]
|
|
token_budget = 8192
|
|
max_retries = 3
|
|
|
|
# review reads the task's own acceptance criteria (task_context) and completes it on an approved
|
|
# verdict (task_update action=complete); on changes_requested it leaves the task claimed.
|
|
[[stages]]
|
|
id = "review"
|
|
prompt = "prompts/review.md"
|
|
needs = ["patch"]
|
|
produces = [{ name = "review_report", kind = "review_report" }]
|
|
allowed_tools = [
|
|
"task_context", "task_update",
|
|
"mcp__codebase-memory__search_code",
|
|
"mcp__codebase-memory__trace_path",
|
|
]
|
|
token_budget = 8192
|
|
max_retries = 3
|
|
|
|
[[transitions]]
|
|
id = "implement-to-review"
|
|
from = "implement"
|
|
to = "review"
|
|
condition_type = "artifact_validated"
|
|
condition_artifact_id = "patch"
|
|
|
|
[[transitions]]
|
|
id = "review-approved"
|
|
from = "review"
|
|
to = "done"
|
|
condition_type = "artifact_field_equals"
|
|
condition_artifact_id = "review_report"
|
|
condition_field = "verdict"
|
|
condition_value = "approved"
|
|
condition_operator = "eq"
|
|
|
|
[[transitions]]
|
|
id = "review-changes-requested"
|
|
from = "review"
|
|
to = "implement"
|
|
condition_type = "artifact_field_equals"
|
|
condition_artifact_id = "review_report"
|
|
condition_field = "verdict"
|
|
condition_value = "approved"
|
|
condition_operator = "neq"
|