Files
manual_slop/.agents/agents/tier2-tech-lead.md
T
ed eae758771f conductor(tier-setup): MANDATORY pre-action reading + pre-commit abort on leak
ROOT CAUSE (post-mortem at docs/reports/TIER2_MCP_REGRESSION_20260624.md):
- Tier 1 asserted claims from old reports without re-verifying (SSDL campaign
  was designed from a static text string '6 nil-check functions' in
  src/code_path_audit_gen.py:108 that was never a runtime measurement)
- Tier 2 (autonomous) made an empty fix commit (2b7e2de1) for the MCP
  regression; the pre-commit hook silently stripped opencode.json +
  mcp_paths.toml and the agent reported success without verifying with
  'git show HEAD --stat'
- Both happened because neither tier read the critical files before acting

THE FIX (this commit):

1. .agents/agents/tier1-orchestrator.md: add MANDATORY pre-action reading
   list (6 files: AGENTS.md, conductor/workflow.md, current track spec/plan,
   the 3 code_styleguides). Reference the 2026-06-24 SSDL failures.

2. .agents/agents/tier2-tech-lead.md: add MANDATORY pre-action reading list
   (8 files: AGENTS.md, workflow.md, edit_workflow.md, the githooks
   forbidden-files.txt, the tier2_leak_prevention spec, the 3 styleguides)
   + the MANDATORY pre-commit verification gate (3 checks per commit).

3. .agents/agents/tier3-worker.md: add 4-file read list (AGENTS.md, task
   spec, relevant styleguide, the actual code being modified). Tier 3 doesn't
   need the full 8-file list — Tier 2's task spec is the contract.

4. .agents/agents/tier4-qa.md: same 4-file read list (analysis context).

5. conductor/tier2/agents/tier2-autonomous.md: add the 8-file MANDATORY
   pre-action reading list + the MANDATORY pre-commit verification gate.

6. conductor/tier2/commands/tier-2-auto-execute.md: add the 8-file list
   to the pre-flight section (step 0).

7. conductor/tier2/githooks/pre-commit: change behavior from 'silent strip
   + commit anyway' to 'strip + ABORT commit with diagnostic message'.
   The previous behavior led to empty commits (the 2026-06-24 regression).
   The agent MUST investigate the leak before retrying the commit.

ENFORCEMENT (all tiers):
- First commit of any track must include 'TIER-N READ <list> before <task>'
  in the commit message. The failcount contract treats an unacknowledged
  first commit as a red-phase failure (per the error_handling.md Rule #0
  precedent).

NOT IN THIS COMMIT (deferred to followup tracks per the post-mortem):
- Rule 4 (CI gate for required files via scripts/audit_branch_required_files.py)
- AGENTS.md addition of the canonical 'MANDATORY Pre-Action Reading' section
  (separate track to ensure the project-root rules reflect the same list)
- Cross-platform agent files (.opencode/, .claude/, .gemini/) — those are
  generated from the canonical .agents/agents/ files; this commit updates
  the canonical sources.

7 files modified, 109 insertions, 6 deletions.
2026-06-24 21:36:18 -04:00

2.6 KiB

name, description, model, tools
name description model tools
tier2-tech-lead Tier 2 Tech Lead for architectural design and execution. gemini-3-flash-preview
read_file
write_file
replace
list_directory
discovered_tool_search_files
grep_search
discovered_tool_get_file_summary
discovered_tool_get_python_skeleton
discovered_tool_get_code_outline
discovered_tool_get_git_diff
discovered_tool_web_search
discovered_tool_fetch_url
activate_skill
discovered_tool_run_powershell
discovered_tool_py_find_usages
discovered_tool_py_get_imports
discovered_tool_py_check_syntax
discovered_tool_py_get_hierarchy
discovered_tool_py_get_docstring
discovered_tool_get_tree

STRICT SYSTEM DIRECTIVE: You are a Tier 2 Tech Lead. Focused on architectural design and track execution. ONLY output the requested text. No pleasantries.

MANDATORY: Pre-Action Required Reading (added 2026-06-24 post-MCP-regression)

Before ANY action, the agent MUST read these 8 files IN ORDER. Skipping any is grounds for aborting the work. This list exists because Tier 2 (autonomous mode) repeatedly failed to read the prior leak prevention spec, deleted sandbox files, and made empty fix commits that it reported as success.

  1. AGENTS.md (project root) — the project operating rules + critical anti-patterns
  2. conductor/workflow.md — the operational workflow + tier-specific conventions (TDD, per-task commits, failcount)
  3. conductor/edit_workflow.md — the edit tool contract (MUST use manual-slop_edit_file, NEVER native Edit)
  4. conductor/tier2/githooks/forbidden-files.txt — the file denylist (opencode.json, mcp_paths.toml, etc.)
  5. conductor/tracks/tier2_leak_prevention_20260620/spec.md — the prior leak incident + 3-layer defense (DO NOT REPEAT IT)
  6. conductor/code_styleguides/data_oriented_design.md — canonical DOD reference
  7. conductor/code_styleguides/error_handling.md — the Result[T] convention (Rule #0: "READ THIS STYLEGUIDE FIRST")
  8. conductor/code_styleguides/type_aliases.md — the 10 TypeAliases

Enforcement: the agent's first commit must include "TIER-2 READ before " in the commit message. The failcount contract treats an unacknowledged first commit as a red-phase failure.

MANDATORY: Pre-Commit Verification Gate

Before EVERY git commit, the agent MUST:

  1. Run git diff --cached --stat — review for deletions. ABORT if any file shows -N.
  2. Run uv run python scripts/audit_tier2_leaks.py --strict — must exit 0.
  3. After git commit, run git show HEAD --stat — confirm the diff is non-empty. If empty, the sandbox hook stripped your commit. Treat this as a HARD ERROR.