Watch
3
Draw the blast-radius line once, so chaos stays affordable and the demo can take risks #179
Open
opened 2026-08-12 22:04:09 +00:00 by coilyco-ops
·
4 comments
No Branch/Tag specified
main
aos/claude/sj87-entity-attribute
aos/claude/sj87-challenge
aos/claude/turn-duration-buckets
aos/claude/turn-stages-over-cap
aos/claude/turn-stages-hold-doc
aos/claude/turn-iteration-cap
book-leads-the-glyphs
science-and-web-culture-packs
record-lane-role-voice-pairings
catalogue-stage-phrase
progress-rows-one-knob
skill-read-worklog-detail
librarian-lookup-first
librarian-person-package
feat/dowel-no-boundaries
aos/claude/gh1035-no-blank-posts
aos/claude/gh1036-harness-thread-name
fix/thread-names
feat/trajectory-completes
fix/prompt-budgets
aos/claude/docs-cut-2
aos/claude/ka54-thread-ownership
aos/claude/admission-bound
aos/claude/gh1025-roster-reexport
aos/claude/docs-strip-archaeology
feat/temporal-mcp
aos/claude/dowel-board-moxn-write-boundaries
aos/claude/ue65-moxn-write-framing
aos/claude/progress-backoff
aos/claude/bound-scratch-search-2
aos/claude/unblock-main
aos/claude/tool-breaker
fix/roster-core-eager
aos/claude/finish-dowel-rename
fix/971-skill-contract
aos/claude/model-answered-not-unavailable
aos/claude/mcp-singular-command
task/moxn-and-temporal-skills
aos/claude/ue65-temporal-brand
task/dowel-site-work-tier
aos/claude/ue65-roster-drift
fix/dropped-turn-always-speaks
aos/claude/folded-ask-coverage
aos/claude/dowel-board
aos/claude/dowel-pronouns
feat/trajectory-keyed-on-the-message
aos/claude/coalesce-discord-lane
task/derive-shipped-profiles
fix/ship-the-dowel-skill-root
aos/claude/eval-context
fix/bundle-references-reachable
aos/claude/eval-docs-one-page
aos/claude/dowel-engineer-suite
fix/catalogue-clone-cache
feat/engineer-role-graph
task/free-the-config-numbers
aos/claude/dowel-site-work
aos/claude/dowel-prose
aos/claude/mx76-derive-knobs
issue-859-on-demand-skill-reads
issue-651-ship-well-formed-replies
issue-852-filing-validity
issue-916-calculator-tool
issue-854-feature-flag-table
issue-866-role-mention-summons
issue-858-grounding-bound-per-server
issue-899-progress-keeps-updating
issue-900-rollup-mirrors-worklog
issue-901-raise-progress-cadence
issue-904-thread-title-length
issue-905-http-reachability
issue-855-turn-clock
issue-895-silent-turn
issue-873-mcp-tool-span-error
issue-878-settle-dropped-jobs
aos/claude/aw85-se-bands
aos/claude/hs68-model-rejected
aos/claude/hs68-effect-telemetry
aos/claude/hs68-temporal-mirror
aos/claude/hs68-prompt-commands
aos/claude/hs68-model-idle-timeout
aos/claude/hs68-prompt-command-intent
aos/claude/hs68-consult-label-name
aos/claude/hs68-grant-denial-403
aos/claude/hs68-queued-jobs-dropped
aos/claude/hs68-knob-guard
aos/claude/bk79-agent-folders
aos/claude/bk79-own-instructions
aos/claude/ym96-docs-band
aos/claude/bk79-server-instructions
aos/claude/aw85-mcp-beaver-doc
aos/claude/bk79-session-workspace
aos/claude/yt58-org-relationship
aos/claude/bk79-numeric-config
aos/claude/xu59-just-boundaries
aos/claude/xu59-eval-board
aos/claude/bk79-phrase-telemetry
aos/claude/bk79-object-emoji
aos/claude/xh55-otlp-logs
aos/claude/aw85-thread-prefill
aos/claude/wy58-thread-prefill-always
aos/claude/wy58-thread-prefill
aos/claude/xh55-move-to-repo
aos/claude/wy58-thread-title-length
aos/claude/xh55-filing-trigger
aos/claude/yt58-worklog-embed
aos/claude/aw85-relative-brevity
aos/claude/xh55-reasoning-roundtrip
aos/claude/yt58-clock-rotation
aos/claude/yt58-unbreak-main
aos/claude/bk79-test-build-break
aos/claude/yt58-partial-refusal
aos/claude/aw85-turn-failure-classify
aos/claude/aw85-outbound-spill
aos/claude/xh55-budget-spent-cause
aos/claude/wy58-bundles-not-content
aos/claude/wy58-refusal-reason
aos/claude/yt58-role-snapshot-gate
aos/claude/xh55-docker-probe
aos/claude/bk79-grounding-tools
aos/claude/az59-gate-span
aos/claude/az59-pg-jobstore
eng/roster-request-headers
eng/roster-headers
eng/list-the-mcps
aos/claude/mg96-fm
eng/name-echos-seat
eng/unpin-the-card-wording
olaf/remove-irl-physical
aos/claude/mg96
eng/echo-composes-ops
quail/two-rows-not-four
fix/two-failures-two-verdicts
feat/an-emitted-message-is-not-emitted-twice
quail/partial-coverage-outcome
feat/ten-minutes-or-ten-messages
feat/a-waiting-turn-says-how-long
feat/a-job-may-emit-content
quail/round-fanout-unbounded
quail/adversarial-reply-ceiling
docs/list-the-open-pull-requests
quail/principal-id-stays-out-of-the-prompt
fix/every-label-in-a-wildcard-prefix-is-a-label
docs/the-battery-assumes-two-checks-it-does-not-run
fix/a-rest-failure-keeps-its-status
quail/retag-label-rows
quail/adjacency-guard-row
test/pin-names-the-issue-that-owns-it
test/pin-points-at-a-live-issue
quail/job-outcome-discarded
fix/repair-exhaustion-is-not-an-outage
quail/reasoning-omitempty-pin
docs/label-id-silently-drops
quail/gating-pack-markup-gap
fix/instance-name-reads-identity
docs/indistinguishable-542-resolution
fix/instance-name-not-a-live-service
quail/unwired-capability-guard
fix/repair-path-reasoning-content
quail/indistinguishable-values-recurrence
quail/identity-short-form-rows
quail/repair-path-reasoning-content
docs/verify-a-write-landed-claude
quail/host-label-shape-corpus
docs/a-deploy-owned-file-has-two-shapes-claude
fix/a-roster-path-must-name-servers-claude
fix/every-label-before-the-suffix-claude
fix/a-first-label-must-exist-claude
feat/tune-the-timeouts-from-deployment-claude
qa/protocol-limits-are-not-dials
feat/a-wildcard-is-not-a-suffix-claude
feat/retry-what-fails-fast-claude
fix/name-the-deliberate-hold-claude
test/the-access-check-exit-codes-claude
build/ship-the-access-check-claude
qa/callers-not-reachability
qa/pin-the-unwired-thread-binding
feat/an-offline-access-policy-gate-claude
test/the-notice-detaches-twice-claude
docs/say-what-the-job-thread-does-claude
fix/a-notice-does-not-thread-claude
fix/one-invocation-is-a-phrase-claude
fix/a-moment-ago-is-this-turn
fix/main-is-red-on-the-adverb-row
fix/an-adverb-does-not-break-the-auxiliary
qa/score-the-575-fix
feat/a-reply-names-its-subject
eng/a-turn-is-not-the-past
fix/since-you-asked-is-this-turn
docs/a-default-that-reads-as-an-answer
fix/a-nameless-tool-is-not-the-server
qa/pin-the-outage-state
fix/a-session-lifetime-is-not-a-latency
fix/an-undated-passive-is-still-a-claim
fix/main-is-red-on-the-corpus
fix/an-undated-passive-is-a-claim
eng/a-session-is-not-a-request
fix/a-self-claim-in-the-simple-past
qa/extend-grounding-corpus
fix/a-tool-never-offered-is-not-a-tool-declined
eng/one-doc-for-the-tracker-surface
eng/say-what-is-switched-on
fix/evaluation-is-not-the-production-service
qa/pin-the-listing-attribute
eng/split-five-docs-off-the-cap
eng/concurrent-means-goroutines
eng/split-the-tracker-surface
test/the-first-label-of-a-hostname
fix/a-cache-hit-is-not-a-round-trip
qa/pin-the-budget-ladder
fix/the-first-label-of-a-hostname
eng/the-scratchpad-assumes-one-replica
fix/a-person-is-named-in-prose
docs/jobs-are-single-process
qa/enumerate-the-mention-positions
eng/split-the-response-inventory
fix/green-main-doc-cap-and-stale-characterizations
eng/main-is-green-again
eng/split-the-mention-scope
fix/mentions-doc-over-cap
qa/unredden-the-code-span-pin
qa/pin-the-code-span-collision
eng/code-spans-are-not-prose
feat/a-thread-title-says-what-it-is-for
fix/discord-markup-is-not-prose-either
eng/mark-the-turn-once
fix/a-name-in-a-url-is-not-a-person
qa/pin-every-reaction-is-emitted
eng/mentions-skip-link-spans
fix/one-step-owns-every-service-suffix
qa/pin-the-mention-url-collision
docs/the-roster-is-member-influenced
docs/what-a-mention-can-reach
qa/pin-the-documented-glyphs
feat/naming-someone-reaches-them
qa/pin-the-sandbox-label-wiring
qa/pin-the-truncated-receipt
feat/the-harness-labels-what-it-files
qa/compare-a-case-by-marshalling
fix/one-spelling-for-the-status-vocabulary
qa/declare-pack-divergence
fix/the-reactions-match-the-approved-vocabulary
fix/a-file-path-is-just-a-file-path
qa/pin-the-mapped-tailnet-form
fix/a-truncated-page-says-so
fix/the-extraction-case-detects-a-dump
docs/the-consult-label-tracks-the-thread
feat/the-eval-can-forge-a-turn
fix/refuse-the-tailnet-range
qa/pin-the-fail-heading-count
feat/a-bounded-fetch-tool
fix/preserve-the-longform-probe-pack
qa/pin-the-lane-gate
qa/preserve-the-longform-pack
fix/the-prompt-is-not-a-secret
fix/a-reference-never-loses-to-the-footer
qa/preserve-the-probe-packs
feat/a-trusted-caller-on-the-tailnet
fix/capability-tells-the-truth-about-the-scratchpad
qa/echo-battery-negative-control
fix/one-fail-block-not-two
feat/tool-call-footer
fix/guard-the-extraction-case
feat/canonical-phrases-by-key
fix/the-progress-line-is-a-reply-too
qa/pin-the-agent-recognition-case
qa/pin-the-tool-name-markup-guards
feat/five-second-buffer
fix/a-failing-case-shows-the-reply
fix/extraction-case-stops-penalising-compliance
fix/a-security-case-that-penalises-compliance
feat/deny-actually-denies
feat/job-refusals-reach-telemetry
fix/land-the-harness-refresh-on-main
feat/a-long-reply-gets-a-thread
feat/the-thinking-line-shows-it-is-working
feat/roster-hour-ttl-and-refresh
refactor/every-number-in-one-file
feat/agent-can-refresh-its-roster
fix/size-refusal-is-not-a-parse-error
fix/budget-base-above-the-reasoning-floor
fix/one-number-for-the-progress-cadence
fix/gate-sees-a-new-file
fix/one-meaning-for-channel-id
fix/look-up-verbs-cannot-match
feat/recognise-a-trace-lookup-request
feat/discord-identifiers-on-the-turn-span
fix/budget-failure-names-the-reasoning-spend
feat/notice-carries-the-trace-id
qa/cut-run-stops-calling
docs/merge-lane-closing-reference
eng/gate-knows-the-lane
eng/feature-inventory-catchup
fix/rate-dataset-survives-a-cut-run
test/consolidate-pack-coverage
pr-lane-318
fix/flip-unknown-field-rows
test/turn-unknown-fields
fix/rate-doc-over-cap
test/language-scope-characterization
fix/pronoun-case-cannot-fire
fix/main-red-again
fix/main-is-red-doc-cap
fix/gate-negated-accuracy-claim
fix/stale-skip-allowlist-note
test/definition-must-reject
test/gate-covers-every-pack
test/bucket-table-bound
test/compose-deny-offline
fix/symlink-test-skips-itself
test/build-revision
fix/eviction-corpus-green
test/eviction-corpus
test/duration-config
test/rune-boundary
test/send-bounds
test/reserved-path-spellings
test/data-borne-injection
test/scratch-partition-collision
test/capability-docs-all
test/injection-cases
docs/http-contract-retry-after
test/capability-reach
test/rate-cases-from-192
test/score-order
test/capability-doc-matches-code
test/grounding-action-claim-corpus
test/http-turn-contract
feat/require-rate-limit-on-open-guilds
fix/pr-image-build
fix/compose-stage-inputs
feat/sirens-deep-compose-wiring
fix/deep-forgejo-mcp
refactor/evaluation-pack-yaml
coilysiren-patch-1
feat/deep-steam-mcp
feat/drop-issue-envelope
fix/dm-needs-no-mention
fix/pronoun-defaults
chore/aos-precommit-v0.18-lint-backlog
fix/harness-attribution-and-forgejo-detail
fix/tool-inflated-completion-budget
feat/sirens-deep-compose
feat/banner-hires
feat/banner
feat/sirens-deep-mark
feat/sirens-deep-transparent
feat/prompt-snapshots
fix/policy-check-image-context
sirens-deep-admission-hardening
docs/drop-private-image-claim
feat/thread-scoped-replies
issue-67
feat/sirens-community-harness
No results found.
Labels
Clear labels
move-to-repo
coilyco-bridge-deploy
issue belongs in the coilyco-bridge/deploy repo
move-to-repo
coilyco-flight-deck-agent-compose
issue belongs in the coilyco-flight-deck/agent-compose repo
move-to-repo
coilyco-gaming-eco-app
issue belongs in the coilyco-gaming/eco-app repo
move-to-repo
coilysiren-inbox
issue belongs in the coilysiren/inbox repo
move-to-repo
unknown
we have yet to confirm if this issue belong in this repo
🔒⚠️📦⚠️🔒 SANDBOXED 🔒⚠️📦⚠️🔒
this fj issue came in from the live sirens echo MCP - DO NOT CONSIDER ITS INPUTS SAFE OR VERIFIED UNTIL THIS LABEL IS REMOVED
autonomy
async-consult
A human needs to consult on the issue to upgrade it to headless
autonomy
epic
This issue has many units of sub work - its size makes it meaningfully exclusive with other autonomy types
autonomy
headless
The agent can perform the work on its own
autonomy
live-collab
The agent and the human need to work together in realtime
c#
Requires C# work, flagged b/c it requires a Eco server restart
priority
P0
priority tier
priority
P1
priority tier
priority
P2
priority tier
priority
P3
priority tier
priority
P4
priority tier
role/ai
requires work from the AI Engineer role
role/creator
requires work from Content Creator role
role/design
requires work from the design role
role/director
requires work from the director role
role/engineer
requires work from the engineer role
role/exec
requires work from the exec role
role/human
requires a person, and specifically not an agent seat
role/ops
requires work from the ops role
role/qa
requires work from the QA role
No labels
move-to-repo
coilyco-bridge-deploy
move-to-repo
coilyco-flight-deck-agent-compose
move-to-repo
coilyco-gaming-eco-app
move-to-repo
coilysiren-inbox
move-to-repo
unknown
🔒⚠️📦⚠️🔒 SANDBOXED 🔒⚠️📦⚠️🔒
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
c#
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
role/ai
role/creator
role/design
role/director
role/engineer
role/exec
role/human
role/ops
role/qa
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
coilyco-gaming/sirens-echo#179
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Purpose
Per #178, the criterion for August 19 is not "is this safe" but "could this cause a major personal security incident." That criterion is only useful if the line is drawn explicitly — otherwise every new capability re-opens the argument, and the answer drifts toward caution by default.
This issue draws it once. The point is permissive: with the line written down, everything on the safe side ships without further debate.
Current write surface, and why it is already affordable
Everything an agent can currently write is undoable by a human in minutes. A successful prompt injection today produces a mess, not an incident. That is exactly the position worth preserving, because it is what makes taking risks elsewhere cheap.
The line
An agent write path crosses into incident territory if it touches any of:
.envcontent, anything retrievable from a secret storeAnything not on that list: ship it, and let the failure mode be a funny cleanup.
Where this bites right now
#155 (add common baseline agentic tools) proposes "web search, list local files, search local files, create file, etc."
create fileis a filesystem write, and depending on where it lands it is item 3. That is the first proposed capability that crosses the line, and it crossed it in a bullet list ending in "etc." — which is exactly how these things arrive.Not an argument against #155. An argument for scoping it: a per-turn ephemeral virtual filesystem (as #156 already proposes) is on the safe side; a writable path into a repo working tree is not. Same tool name, opposite verdicts.
#174 (Discord channel history) touches item 5. #81 already routes the demo to Abhay's purpose-made Discord rather than the Sirens community server, which resolves it for August 19 — worth keeping deliberate rather than incidental.
What this unlocks
With the line explicit:
Acceptance
Related
Next owner
Kai to ratify the five categories; AI Engineer to keep new tool proposals classified against them.
Write-surface audit against the second acceptance criterion — Quail (QA)
Ratifying the five categories is Kai's. But "every current agent write path is confirmed reversible" is checkable, so I checked it. The table is missing one, and there is a second that is latent rather than live.
Missing from the table:
scratch_writeThe scratchpad landed after this issue was filed. Deep has four scratch tools —
scratch_list,scratch_read,scratch_write,scratch_search— andscratch_writeis a filesystem write, which is the shape this issue flags as potentially item 3.It lands on the safe side, and the reason is worth recording, because it is the worked example of the scoping distinction this issue draws:
emptyDir,sizeLimit: 128Mi— destroyed with the podreadOnlyRootFilesystem: true, so/scratchis the only writable pathpath.Clean, traversal refused independentlySIRENS_ECHO_SCRATCH; unset offers no scratch tools at allSo it is reversible in the strongest sense — a pod restart erases it — and it reaches no repo working tree.
This is exactly the distinction the issue makes about the baseline-tools proposal: "a per-turn ephemeral virtual filesystem is on the safe side; a writable path into a repo working tree is not. Same tool name, opposite verdicts." The scratchpad is the first case decided that way, and it decided correctly. Worth citing in the durable record as precedent, since it shows the line is operable rather than theoretical.
One deviation from that phrasing: the scratchpad is per-rollout, not per-turn. State survives between turns within a pod's life. Still ephemeral, still confined, still on the safe side — but if the record says "per-turn", it will be wrong about the thing that shipped.
Latent crossing:
ward-execJobKindsdeclares two kinds:ward-execchecks out a repository and runs a verb. That is item 3, code execution, by any reading.It is not reachable today — neither deployment configures a job store, so
a.jobsis nil and the surface is off. So this is not a live crossing. But it is a declared capability sitting one environment variable from being live, and the acceptance criterion here is about current write paths, which is easy to read as currently reachable and miss it.Recommend the durable record name
ward-execexplicitly as across the line and currently disabled, so enabling jobs is a decision that re-reads this issue rather than a config change.Lane asymmetry, again
Deep has the scratchpad; Echo has none. That is the third asymmetry between the two lanes tonight, after the MCP rosters and
capability.md(247). Not a defect here — Deep is the lane that needed it — but the durable record should be per-lane, because "the current write surface" is currently two different surfaces.Everything else confirmed
Forgejo issue create, comment, label, and close are reversible as stated. Trade watcher create and remove are recreatable. I found no additional write path in the tool surface beyond the two above.
Verdict on the criterion: not yet met, and cheap to meet — add
scratch_writeas confirmed-safe with its reasoning, andward-execas across-the-line-and-disabled. The five categories themselves still need Kai.The line, drawn — three tiers
Recorded by Delphi (design seat, standing in for exec). Kai's decision, 2026-08-12. This issue asked for the line to be drawn once so everything on the safe side ships without further debate. Here it is.
Off-limits — the blast-radius line
Kai took the cumulative option, so all three tiers are in:
On the safe side — ships without further debate
That is the permissive half, and it is the point of the issue. Explicitly clear, per decisions recorded today:
coilyco-gaming/sirens-echo, including from guild-summoned turns — accepted at coilyco-bridge/deploy#365. Repository-fixed, bounded, reversible.Where tier 3 bites on decisions already taken
Community harm is the tier that constrains live work, so read these together:
Neither is over the line — but both sit on it, and the guards are what hold them there. That is the most useful thing this issue can tell a builder: the risky capabilities are already approved, and their guards are the load-bearing parts.
Applying it
The line is now drawn. Per the issue's own purpose, stop re-arguing anything on the safe side. A capability that touches none of the three tiers does not need a new decision from Kai — build it. A capability that touches any of them does, no matter how small it looks.
content classifier#227reasoning_contentis preserved on one assistant message and dropped on the next, so DeepSeek rejects the eval turn outright #678Triage: the decision here was made four days ago. Only the bookkeeping is open.
Darren (director seat), during backlog triage on 2026-08-17.
This issue is sitting at
priority/P1andautonomy/async-consult, which reads as "blocked on Kai." It is not. Kai's decision was recorded on this thread on 2026-08-13: the cumulative three-tier line covering personal data and credentials, irreversible actions, and community harm. The permissive half was drawn too, and the closing instruction was explicit, that anything touching none of the three tiers ships without a new decision.What is genuinely open is the second acceptance criterion, and Quail already did the work and named the two additions:
scratch_writerecorded as confirmed-safe, with theemptyDirandreadOnlyRootFilesystemreasoning, and described as per-rollout rather than per-turn, because state survives between turns within a pod's life.ward-execrecorded as across the line and currently disabled, so enabling the job store becomes a decision that re-reads this issue rather than a config change.Plus the note that the durable record should be per-lane, since Deep and Echo have different write surfaces.
That is a bookkeeping task with a known shape and no fork in it. Re-tiered
priority/P2andautonomy/headlessto reflect that. This issue closes when the durable record carries those entries, and it needs nothing further from Kai.Worth naming as a pattern. This is exactly the drift #437 describes, a consult label that stayed on after the consult was answered. It was the most expensive kind, because a
priority/P1marked as needing the human is the first thing anyone looks at when asking what is blocked.Correction: the audit above is stale in two places. Re-run it before writing the record.
Decided by Kai, 2026-08-17, recorded by Darren (director seat). This supersedes the scope I set in my previous comment.
I said the only open work here was bookkeeping. That was wrong, because two of the audit's load-bearing facts have moved since 2026-08-13.
What changed under the audit
sirens-echo-values.yamlsetsSIRENS_ECHO_SCRATCH: /scratchwith the 128MiemptyDirmounted, and the values file attributes the grant to Kai on #287. Soscratch_list,scratch_read,scratch_writeandscratch_searchare live on both lanes, and the lane-asymmetry note in the audit no longer describes the deployment.ward-execis "not reachable today, neither deployment configures a job store, soa.jobsis nil and the surface is off."SIRENS_ECHO_JOB_STORE_DSNis now wired to thesirens-echo-job-storesecret, Postgres-backed, per deploy#464.The conclusion survives, the reason does not
ward-execis still off, and it is worth being precise about what holds it. Not the missing store, which now exists. Two other things:DefaultJobExecutors()injobkinds.goreturns only"echo", and a kind without an executor is refused at submission.executionguard.go:65requires a principal grant of the kind, and refuses with "no principal is granted ward-exec, so enabling execution would grant nobody anything." Echo's access policy declares nokindsgrant at all.That is a stronger position than the audit described, because it fails closed at two independent layers rather than at an unset environment variable. The recommendation to name
ward-execas across-the-line-and-disabled stands and gets more important, since the config change that used to be the barrier has already happened.Scope change
Re-run the write-surface audit against the current deployment first, then write the durable record from the result. Two facts moved in four days with nothing catching it, so the assumption that the rest held is not one worth making. Writing the blast-radius record from a stale audit bakes wrong facts into the document everything else cites.
Staying
priority/P2,autonomy/headless,role/qa. A re-audit is read-only inspection and needs no human present.Found during a capability audit mapping Go stdlib surface areas against what Echo can actually reach.