# Implementation: Phase-Scoped Prompts with Forbidden Actions ## Changes Made ### 1. ALLOWED/FORBIDDEN sections in all phase prompts Each phase prompt now includes: - **ALLOWED ACTIONS** — explicit list of what the agent can do - **FORBIDDEN ACTIONS** — explicit list of what the agent cannot do, including "Do NOT" instructions and handling user overrides Phase-specific definitions: - research.md: ALLOWED read/ask questions/write SPEC.md; FORBIDDEN edit code, create IMPLEMENTATION.md, skip to implementation - decompose.md: ALLOWED read SPEC/ask questions/write DECOMPOSITION.md; FORBIDDEN edit code, modify SPEC.md, create sub-task folders - design.md: ALLOWED read SPEC/ask questions/write DESIGN.md; FORBIDDEN edit code, create IMPLEMENTATION.md, skip to implementation - test_design.md: ALLOWED read SPEC+DESIGN/ask questions/write TEST_PLAN.md; FORBIDDEN edit code, write test implementations - implement.md: ALLOWED edit code/write tests/create IMPLEMENTATION.md; FORBIDDEN create new tasks, modify SPEC/DESIGN - bug_finder.md: ALLOWED read code/SPEC/IMPLEMENTATION/write BUG_REPORT.md; FORBIDDEN edit code, fix bugs - adversarial_bug_find.md: ALLOWED read code/SPEC/BUG_REPORT/write ADVERSARIAL_BUG_REPORT.md; FORBIDDEN edit code, fix bugs - doc_review.md: ALLOWED read DESIGN/code/docs/write DOC_REVIEW.md/update docs; FORBIDDEN edit non-doc code, modify SPEC/DESIGN - referee.md: ALLOWED read all artifacts/write VERDICT.md; FORBIDDEN edit code, modify any artifact other than VERDICT.md - orchestrate.md: ALLOWED read .state/transition state/create tasks/delegate; FORBIDDEN edit code directly, skip phases ### 2. User override resistance Each prompt includes a "Handling User Overrides" section telling agents to refuse forbidden actions and suggest the correct phase. ### 3. `.state` precondition check Every phase prompt includes `.state` as the first file to read, with instructions to STOP if the phase doesn't match. ### 4. Pre-Work Validation (MANDATORY) Every phase prompt requires running `python ~/.automaton/scripts/status.py --validate-folder --task {task-name}` before starting work. ### 5. Approval gates - research.md, decompose.md, design.md, test_design.md: include Approval Gate section with `--transition {phase}:awaiting_approval`, `--approve`, and `--transition {next-phase}` - implement.md, bug_finder.md, adversarial_bug_find.md, doc_review.md, referee.md: include "No Approval Gate" section with direct `--transition` ### 6. Orchestrate.md restructuring - Reduced from 493 to 143 lines - State determination logic referenced from workflow.md - Sub-task management extracted to subtask_management.md - Gate-check loop with `--validate-folder` and approval pauses ## Files Modified - `prompts/research.md` (updated) - `prompts/design.md` (updated) - `prompts/decompose.md` (updated) - `prompts/test_design.md` (updated) - `prompts/implement.md` (updated) - `prompts/bug_finder.md` (updated) - `prompts/adversarial_bug_find.md` (updated) - `prompts/doc_review.md` (updated) - `prompts/referee.md` (updated) - `prompts/orchestrate.md` (rewritten, 143 lines) - `prompts/subtask_management.md` (new, extracted) ## Test Results - All prompt self-consistency tests passing - onboarding.md excluded from stop-condition test