fix(explore): make the capture request the write confirmation (#1832)
* fix(explore): make the capture request the write confirmation Explore's write-confirmation rule named `openspec new change` as an action requiring a separate yes/no, while the capture branch told the agent to transition "seamlessly" into running it. Both readings were defensible, so the same request either wrote files immediately or stopped and asked. State the resolution in all three places: an explicit capture request is the confirmation, for the change and artifacts that request names. The guardrail keeps its teeth where #1715 reported the problem — an agent-proposed capture, or work beyond the requested scope, still asks. Closes #1828 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * test(explore): guard the capture branch against a re-added confirmation gate Also disambiguate the scope fence in the IMPORTANT block: "the artifacts that request names" parses as a relative clause, and it is the sentence an agent weighs first. Match the article used by both restatements. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(explore): put the capture discriminators where the decision is made Four hardening findings from review of the first pass: - A yes to an offer the agent made looks identical to a user-initiated capture request at the point the branch decides. The discriminator sat 190 lines away in Guardrails. Move it into the branch, and require the offer to name what it would create. - "Do not ask for a second confirmation" contradicted step 2 nine lines below it, which requires asking before expanding the capture. Narrow it to re-asking for what was already asked for. - Scope the carve-out to change artifacts, so it cannot be read to reach the workflow configuration #1715 reported an agent editing. - The Guardrails bullet restated the whole contract a third time, in a quick-reference list whose next-longest entry is 43 words. Replace with a pointer to the branch that owns it. Tests: the three not.toContain guards could not see a gate phrased in words they did not anticipate. Replace with a structural check that collects every consent-bearing sentence and requires each to be sanctioned — inside the capture branch with no topic filter, since a gate written there is about the capture whether or not it says so. Mutation testing: kills 6 of 8 contradiction mutations that survived before, and all three sites stay independently pinned. The two survivors reverse the resolution without any consent word and are noted as review-only. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(explore): keep the contact clause in the scope fence The previous commit reintroduced "the change artifacts that request names", the garden-path parse that 55eeac6 removed: read as a relative clause it says the artifacts name a request. Restore "the request names", matching both restatements. Caught by CodeRabbit. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(changeset): drop em dashes from the release note Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
C
Clay Good committed
4c369e022b1d397842d2b85675e34da6287f5801
Parent: 8146be5
Committed by GitHub <noreply@github.com>
on 9/16/2026, 3:47:47 PM