CI / build (push) Has been cancelled
Batch 1 (High severity): - Bug 1: --audit cat3 now checks .automaton/tasks/ paths - Bug 4: Verdict PASS/FAIL uses structured ## Status: line parsing - Bug 5: register-guards.sh checks .json/.jsonc, writes plugin key, strips comments - Bug 7: --can-edit/--scope-check path prefix uses os.sep boundary Batch 2 (Medium/Low severity): - Bug 2: migrate-project.sh find command parentheses for -prune binding - Bug 3: vram_detect model prefix matching with known-suffix whitelist - Bug 6: dashboard reads .state file before artifact heuristic fallback - Bug 8: removed wildcard CORS, added security headers (nosniff, DENY) - Bug 9: stale-task detection uses .state.lastedit instead of .state mtime - Bug 10: TEST_PLAN.md maps to test_design (was implement) 249 tests pass (up from 235). All 10 tasks driven through full workflow to completion.
1.2 KiB
1.2 KiB
Automaton Guard Plugin
Harness: OpenCode (@opencode-ai/plugin)
Status: Active
Enforcement: Pre-edit (tool.execute.before)
Blocks file modifications (edit, write tools) when no automaton task is in
implement or doc_review phase. Calls status.py --can-edit --file <path> --json
before every edit.
Installation
The framework install/update scripts auto-register this plugin in
~/.config/opencode/opencode.json (or opencode.jsonc):
{
"plugin": ["~/.automaton/plugins/automaton-guard"]
}
Other Harnesses
| Harness | Plugin | Status |
|---|---|---|
| OpenCode | plugins/automaton-guard/plugin.ts |
✅ Active |
| Pi Dev | plugins/automaton-guard-pi/guard.ts |
✅ Active |
| Other | N/A | N/A |
To add support for a new harness, create a plugin in plugins/ that calls
status.py --can-edit --file <path> before tool execution, matching the
contracts/harness-integration.md specification.
Enforcement Layers
| Layer | Mechanism | Harness scope |
|---|---|---|
| Pre-edit | This plugin | OpenCode only |
| Pre-commit | scripts/git-hooks/pre-commit |
All git projects |
| Pre-push | scripts/git-hooks/pre-push |
All git projects |