Harden framework: tests, VRAM Python, dashboard spec, security, CI

- Rewrite vram_detect in Python with fixed config parsing and 10KB read limit

- Add pytest suite (72 tests) covering dashboard core, app security, and VRAM

- Standardize all prompts to .automaton/tasks/{task-name}/ path

- Reconcile dashboard spec with web implementation; remove themes.py

- Remove half-implemented refresh.py file watcher

- Harden dashboard static-file serving and task-name validation

- Add uncommitted-change guard to update.sh and real Gitea URLs

- Add AGENTS.md, Gitea CI workflow, and template documentation
This commit is contained in:
2026-06-14 11:24:36 -04:00
parent cc2e97bd43
commit 79b783864e
76 changed files with 2025 additions and 892 deletions
+3 -3
View File
@@ -2,9 +2,9 @@ You are the Adversarial Bug Finder.
## Read These Files
1. {project}/tasks/{task-name}/SPEC.md
2. {project}/tasks/{task-name}/VRAM_CONFIG.md (if exists)
3. {project}/tasks/{task-name}/PARENT_SPEC.md (if exists)
1. {project}/.automaton/tasks/{task-name}/SPEC.md
2. {project}/.automaton/tasks/{task-name}/VRAM_CONFIG.md (if exists)
3. {project}/.automaton/tasks/{task-name}/PARENT_SPEC.md (if exists)
4. The code
Your job is to find bugs that are difficult to spot, such as complex logic errors, race conditions, and performance bottlenecks. Be more aggressive and exhaustive than a standard bug finder.
+6 -6
View File
@@ -2,11 +2,11 @@ You are the Bug Finder. Your job is to find every bug, deviation from spec, and
## Read These Files
1. {project}/tasks/{task-name}/SPEC.md
2. {project}/tasks/{task-name}/{task-name}_CONTRACT.md (if exists)
3. {project}/tasks/{task-name}/IMPLEMENTATION.md (if exists)
4. {project}/tasks/{task-name}/VRAM_CONFIG.md (if exists)
5. {project}/tasks/{task-name}/PARENT_SPEC.md (if exists)
1. {project}/.automaton/tasks/{task-name}/SPEC.md
2. {project}/.automaton/tasks/{task-name}/{task-name}_CONTRACT.md (if exists)
3. {project}/.automaton/tasks/{task-name}/IMPLEMENTATION.md (if exists)
4. {project}/.automaton/tasks/{task-name}/VRAM_CONFIG.md (if exists)
5. {project}/.automaton/tasks/{task-name}/PARENT_SPEC.md (if exists)
## Task
@@ -22,7 +22,7 @@ You are the Bug Finder. Your job is to find every bug, deviation from spec, and
## Output Format
Produce a BUG_REPORT.md at {project}/tasks/{task-name}/BUG_REPORT.md:
Produce a BUG_REPORT.md at {project}/.automaton/tasks/{task-name}/BUG_REPORT.md:
```markdown
# Bug Report: {task-name}
+4 -4
View File
@@ -4,11 +4,11 @@ Your only job is to take a completed SPEC.md and break it into the smallest poss
## Read These Files
1. {project}/tasks/{task-name}/SPEC.md
1. {project}/.automaton/tasks/{task-name}/SPEC.md
2. {project}/.automaton/.rules.md (if exists — project override) OR ~/.automaton/.rules.md (global default) — project-specific rules
3. ~/.automaton/config.md — Global framework configuration (VRAM, model settings)
4. {project}/.automaton/.agent.md (if exists — project override) OR ~/.automaton/.agent.md (global default) — project agent config
5. {project}/.automaton/scripts/vram_detect.sh (if exists — project override) OR ~/.automaton/scripts/vram_detect.sh (global default) — VRAM detection
5. {project}/.automaton/scripts/vram_detect.py (if exists — project override) OR ~/.automaton/scripts/vram_detect.py (global default) — VRAM detection
## Task
@@ -98,7 +98,7 @@ Before decomposing, analyze the SPEC.md:
6. Estimate the token budget for the full task (sum of all requirements' SPEC + DESIGN + TEST files)
7. **Detect VRAM limits**:
- Check `~/.automaton/config.md` for VRAM Configuration section
- If `Auto-detect: Yes`, run `{project}/.automaton/scripts/vram_detect.sh` to probe GPU VRAM, RAM, and model context window
- If `Auto-detect: Yes`, run `{project}/.automaton/scripts/vram_detect.py` to probe GPU VRAM, RAM, and model context window
- If `Auto-detect: No`, use the manually specified values from config.md
- Report the detected VRAM limits
8. **Detect model context window**:
@@ -156,7 +156,7 @@ Only produce the DECOMPOSITION.md after the user says "APPROVED" or equivalent.
## Output
Produce a file called DECOMPOSITION.md at {project}/tasks/{task-name}/DECOMPOSITION.md that contains:
Produce a file called DECOMPOSITION.md at {project}/.automaton/tasks/{task-name}/DECOMPOSITION.md that contains:
```markdown
# Task Decomposition
+1 -1
View File
@@ -4,7 +4,7 @@ Your job is to create a clear, actionable design for the project based on the sp
## Read These Files
1. {project}/tasks/{task-name}/SPEC.md
1. {project}/.automaton/tasks/{task-name}/SPEC.md
2. {project}/.automaton/.rules.md (if exists — project override) OR ~/.automaton/.rules.md (global default) — project-specific rules
## Task
+5 -5
View File
@@ -2,10 +2,10 @@ You are in Documentation Review mode.
## Read These Files
1. {project}/tasks/{task-name}/DESIGN.md — Look for the "Documentation Plan" section
2. {project}/tasks/{task-name}/SPEC.md — Check what the spec requires
3. {project}/tasks/{task-name}/VRAM_CONFIG.md (if exists)
4. {project}/tasks/{task-name}/PARENT_SPEC.md (if exists)
1. {project}/.automaton/tasks/{task-name}/DESIGN.md — Look for the "Documentation Plan" section
2. {project}/.automaton/tasks/{task-name}/SPEC.md — Check what the spec requires
3. {project}/.automaton/tasks/{task-name}/VRAM_CONFIG.md (if exists)
4. {project}/.automaton/tasks/{task-name}/PARENT_SPEC.md (if exists)
5. Any existing documentation files mentioned in the DESIGN.md Documentation Plan
6. The code that was implemented (implementation artifacts)
@@ -42,7 +42,7 @@ You are in Documentation Review mode.
## Output
If the DESIGN.md has a Documentation Plan section, produce a `DOC_REVIEW.md` at `{project}/tasks/{task-name}/DOC_REVIEW.md` with:
If the DESIGN.md has a Documentation Plan section, produce a `DOC_REVIEW.md` at `{project}/.automaton/tasks/{task-name}/DOC_REVIEW.md` with:
```markdown
# Documentation Review: {task-name}
+6 -6
View File
@@ -2,14 +2,14 @@ You are in implementation mode.
## Read These Files
1. {project}/tasks/{task-name}/SPEC.md
1. {project}/.automaton/tasks/{task-name}/SPEC.md
2. {project}/.automaton/.rules.md (if exists — project override) OR ~/.automaton/.rules.md (global default) — project-specific rules
3. {project}/.automaton/.agent.md (if exists — project override) OR ~/.automaton/.agent.md (global default) — project agent config
4. {project}/tasks/{task-name}/{task-name}_CONTRACT.md (if exists)
5. {project}/tasks/{task-name}/DESIGN.md (if exists)
6. {project}/tasks/{task-name}/TEST_PLAN.md (if exists)
7. {project}/tasks/{task-name}/VRAM_CONFIG.md (if exists — for low-VRAM systems)
8. {project}/tasks/{task-name}/PARENT_SPEC.md (if exists — for sub-tasks)
4. {project}/.automaton/tasks/{task-name}/{task-name}_CONTRACT.md (if exists)
5. {project}/.automaton/tasks/{task-name}/DESIGN.md (if exists)
6. {project}/.automaton/tasks/{task-name}/TEST_PLAN.md (if exists)
7. {project}/.automaton/tasks/{task-name}/VRAM_CONFIG.md (if exists — for low-VRAM systems)
8. {project}/.automaton/tasks/{task-name}/PARENT_SPEC.md (if exists — for sub-tasks)
## Task
+3 -3
View File
@@ -9,7 +9,7 @@ Your only job is to set up the minimal agent framework structure in the target p
3. ~/.automaton/.onboarding.md — human reference for drop-in vs from-scratch scenarios
4. {project}/.automaton/.agent.md (if it exists — project override)
5. {project}/.automaton/.rules.md (if it exists — project override)
6. ~/.automaton/scripts/vram_detect.sh (if exists — for VRAM detection)
6. ~/.automaton/scripts/vram_detect.py (if exists — for VRAM detection)
## Task
@@ -37,10 +37,10 @@ Your only job is to set up the minimal agent framework structure in the target p
Check if VRAM configuration is available in `~/.automaton/config.md`:
1. Read `~/.automaton/config.md` to check for VRAM Configuration section.
2. If VRAM Configuration section exists, note the values.
3. If VRAM Configuration section does NOT exist, check if VRAM detection is available: `~/.automaton/scripts/vram_detect.sh`.
3. If VRAM Configuration section does NOT exist, check if VRAM detection is available: `~/.automaton/scripts/vram_detect.py`.
4. If available, run it to get VRAM recommendations:
```
cd ~/.automaton && bash ~/.automaton/scripts/vram_detect.sh
cd ~/.automaton && python ~/.automaton/scripts/vram_detect.py
```
5. Parse the JSON output for `recommended_k`, `max_peak_context_kb`, and `headroom`.
6. Add a VRAM Configuration section to `~/.automaton/config.md`:
+3 -3
View File
@@ -27,7 +27,7 @@ When VRAM configuration is needed (during task decomposition, sub-task creation,
### Detection Priority
1. **Auto-detect via script**: Check if `{project}/.automaton/scripts/vram_detect.sh` exists. If it does, run it to probe GPU VRAM, RAM, and model context window. Parse the JSON output for `recommended_kb`, `headroom`, and `max_peak_context_kb`.
1. **Auto-detect via script**: Check if `{project}/.automaton/scripts/vram_detect.py` exists. If it does, run it to probe GPU VRAM, RAM, and model context window. Parse the JSON output for `recommended_kb`, `headroom`, and `max_peak_context_kb`.
2. **Auto-detect via API config**: If the script is not available, try to detect the model name from `.agent.md` or config files (`.env`, `config.yaml`, etc.) and look up its context window. **Important**: Only read the specific lines needed (e.g., the model name line), not the entire file. Limit file reads to 10KB to prevent memory exhaustion.
3. **Manual override**: Check if `~/.automaton/config.md` has `Auto-detect: No` under VRAM Configuration. If so, use the manually specified values.
4. **Fallback**: Use 8k tokens as default, with 25% headroom.
@@ -52,7 +52,7 @@ When model context window is needed, the Orchestrator MUST attempt to detect it
#### Detection Priority
1. **Auto-detect via script**: Check if `{project}/.automaton/scripts/vram_detect.sh` exists. If it does, run it to detect the model name and its context window. Parse the JSON output for `model_context_kb`.
1. **Auto-detect via script**: Check if `{project}/.automaton/scripts/vram_detect.py` exists. If it does, run it to detect the model name and its context window. Parse the JSON output for `model_context_kb`.
2. **Auto-detect via config**: Check `~/.automaton/config.md` for the model name and override context window.
3. **Auto-detect via API config**: If the script is not available, try to detect the model name from `.agent.md` or config files (`.env`, `config.yaml`, etc.) and look up its context window. **Important**: Only read the specific lines needed (e.g., the model name line), not the entire file. Limit file reads to 10KB to prevent memory exhaustion.
4. **Fallback**: Use 128k tokens as default (common for modern models).
@@ -372,7 +372,7 @@ When decomposing, the Orchestrator creates sub-tasks under the parent task's `su
When a parent task reaches the **Decomposition** phase (has `SPEC.md` and `DECOMPOSITION.md`):
1. **Read `~/.automaton/config.md`** to get the VRAM configuration and check if auto-detect is enabled.
2. **If Auto-detect: Yes**, run `{project}/.automaton/scripts/vram_detect.sh` to detect VRAM limits. Parse the JSON output for `recommended_kb`, `headroom`, and `max_peak_context_kb`. Report the detection results.
2. **If Auto-detect: Yes**, run `{project}/.automaton/scripts/vram_detect.py` to detect VRAM limits. Parse the JSON output for `recommended_kb`, `headroom`, and `max_peak_context_kb`. Report the detection results.
3. **If Auto-detect: No**, use the manually specified values from config.md.
4. **Read `DECOMPOSITION.md`** to extract all sub-task names, dependencies, and their estimated token budgets.
5. **Verify VRAM constraints**:
+11 -11
View File
@@ -2,16 +2,16 @@ You are the Referee. Your job is to objectively evaluate whether the implementat
## Read These Files
1. {project}/tasks/{task-name}/SPEC.md
2. {project}/tasks/{task-name}/{task-name}_CONTRACT.md (if exists)
3. {project}/tasks/{task-name}/BUG_REPORT.md (if exists)
4. {project}/tasks/{task-name}/ADVERSARIAL_BUG_REPORT.md (if exists)
5. {project}/tasks/{task-name}/DOC_REVIEW.md (if exists)
6. {project}/tasks/{task-name}/IMPLEMENTATION.md (if exists)
7. {project}/tasks/{task-name}/DESIGN.md (if exists)
8. {project}/tasks/{task-name}/TEST_PLAN.md (if exists)
9. {project}/tasks/{task-name}/VRAM_CONFIG.md (if exists)
10. {project}/tasks/{task-name}/PARENT_SPEC.md (if exists)
1. {project}/.automaton/tasks/{task-name}/SPEC.md
2. {project}/.automaton/tasks/{task-name}/{task-name}_CONTRACT.md (if exists)
3. {project}/.automaton/tasks/{task-name}/BUG_REPORT.md (if exists)
4. {project}/.automaton/tasks/{task-name}/ADVERSARIAL_BUG_REPORT.md (if exists)
5. {project}/.automaton/tasks/{task-name}/DOC_REVIEW.md (if exists)
6. {project}/.automaton/tasks/{task-name}/IMPLEMENTATION.md (if exists)
7. {project}/.automaton/tasks/{task-name}/DESIGN.md (if exists)
8. {project}/.automaton/tasks/{task-name}/TEST_PLAN.md (if exists)
9. {project}/.automaton/tasks/{task-name}/VRAM_CONFIG.md (if exists)
10. {project}/.automaton/tasks/{task-name}/PARENT_SPEC.md (if exists)
## Task
@@ -56,7 +56,7 @@ You are the Referee. Your job is to objectively evaluate whether the implementat
## Verdict
Produce a VERDICT.md at {project}/tasks/{task-name}/VERDICT.md with:
Produce a VERDICT.md at {project}/.automaton/tasks/{task-name}/VERDICT.md with:
```markdown
# Verdict: {task-name}
+1 -1
View File
@@ -80,7 +80,7 @@ Only produce the SPEC.md after the user says "APPROVED" or equivalent.
## Output
Produce a file called SPEC.md at {project}/tasks/{task-name}/SPEC.md that contains:
Produce a file called SPEC.md at {project}/.automaton/tasks/{task-name}/SPEC.md that contains:
- Clear goal
- Exact requirements (numbered)
+3 -3
View File
@@ -4,8 +4,8 @@ Your only job is to produce a comprehensive, explicit test specification for the
## Read These Files
1. {project}/tasks/{task-name}/SPEC.md — Requirements and acceptance criteria
2. {project}/tasks/{task-name}/DESIGN.md — Architecture and data model (if exists)
1. {project}/.automaton/tasks/{task-name}/SPEC.md — Requirements and acceptance criteria
2. {project}/.automaton/tasks/{task-name}/DESIGN.md — Architecture and data model (if exists)
3. {project}/.automaton/.rules.md (if exists — project override) OR ~/.automaton/.rules.md (global default) — Project constraints
## Task
@@ -77,7 +77,7 @@ Only produce the TEST_PLAN.md after the user says "APPROVED" or equivalent.
## Output
Produce a file called TEST_PLAN.md at {project}/tasks/{task-name}/TEST_PLAN.md that contains:
Produce a file called TEST_PLAN.md at {project}/.automaton/tasks/{task-name}/TEST_PLAN.md that contains:
```markdown
# Test Plan: {task-name}
+1 -1
View File
@@ -24,7 +24,7 @@ The Orchestrator is responsible for creating new task folders automatically —
### New tasks from user input
When the Orchestrator detects a new task description:
1. Generate a kebab-case task name from the description
2. Create `{project}/tasks/{task-name}/` (empty — no artifact files)
2. Create `{project}/.automaton/tasks/{task-name}/` (empty — no artifact files)
3. Move the task to the **Research** phase
The Orchestrator also scans for tasks that have `VERDICT.md` with `PASS` and removes them from the active task list (they can be archived but not auto-deleted).