Expand the documentation with measured figures and operational detail
Most of this replaces "roughly 550 characters per tool" with the actual per-tool measurements, and fills in the parts a reader hits after the happy path: what a specific error means, what a setting costs, what is not covered. Measured rather than estimated: - Per-tool byte cost, all fourteen, and the per-set totals. 7,673 B for the full set, averaging 548. - Builtin skill bodies at 5,284 B against a 681 B catalogue, which is the argument for loading bodies on demand. - Full system prompt 3,571 chars, core-only 2,045. New sections: - tools: which sets to keep and why, the jail function itself, an output-cap table, and the real error strings for edit_file and multi_edit. - configuration: env var per provider preset, cost-estimate limits, what each --no-* flag isolates, and three settings that do more than they look like. - agents: step caps per variant, which variant to reach for, and the fact that reasoning is charged as output and discarded first by compaction. - headless: exit code 0 means "the turn completed", not "the answer was yes" — with the jq pattern for gating on content. Timeouts, concurrent -c runs fighting over one session, CI recipes for --no-skills. - mcp: parallel connect, startup cost, a debugging ladder, and that toolSets does not gate MCP tools. - registry: publishing, local testing over http://localhost, and a troubleshooting section keyed on the actual validator messages. - memory: what compaction discards in what order, /compact versus automatic pruning, and that -c matches on cwd. - skills: the frontmatter reader's limits, and how to verify a skill loaded. Corrections found while cross-checking against the source: - The guard table was missing --force-with-lease and > /dev/sd… - The done event's token fields are optional, so the jq example filters on one rather than assuming it. Two honest limits now written down: the guard matches command strings, so a base64-decoded or script-wrapped command is not caught; and a registry index is trusted for its contents, not its authorship. Verified: all internal links and heading anchors resolve, every docs/ page is reachable from the README, 538 tests pass, typecheck clean.
This commit is contained in:
+9
-2
@@ -70,10 +70,10 @@ holding `a` through a batch of edits will approve one of these without reading i
|
||||
| `rm -rf`, `rm -f` | recursive or forced delete |
|
||||
| `git reset --hard` | discards uncommitted work |
|
||||
| `git clean -f` | deletes untracked files |
|
||||
| `git push --force`, `-f` | rewrites remote history |
|
||||
| `git push --force`, `--force-with-lease`, `-f` | rewrites remote history |
|
||||
| `git branch -D` | deletes a branch without a merge check |
|
||||
| `DROP TABLE`, `TRUNCATE` | destroys database data |
|
||||
| `mkfs`, `dd of=/dev/…` | writes to a raw device |
|
||||
| `mkfs`, `dd of=/dev/…`, `> /dev/sd…` | writes to a raw device |
|
||||
| `chmod 777` | makes files world-writable |
|
||||
| `shutdown`, `reboot`, `halt` | affects the whole machine |
|
||||
| `:(){ :\|:& };:` | fork bomb |
|
||||
@@ -88,6 +88,13 @@ The model is told to relay the command rather than work around it. `rm build/one
|
||||
`git push origin feature`, and `git commit` all pass — the patterns target irreversibility,
|
||||
not the commands themselves.
|
||||
|
||||
Two honest limits. The patterns match the command **string**, so `bash -c "$(echo cm0gLXJm | base64 -d)"`
|
||||
is not caught, and neither is a script the agent wrote and then ran. And it only inspects `bash`:
|
||||
a `write_file` overwriting something important is an approval question, not a guard question.
|
||||
|
||||
The guard is the last line before a command runs; `ctrl-c` is the one after. A pattern the guard
|
||||
does not know about is still interruptible by hand — see [tools](tools.md#bash).
|
||||
|
||||
### `time` (default on)
|
||||
|
||||
Adds `current_time`, returning ISO 8601 plus the local string. Auto-approved; it reads
|
||||
|
||||
Reference in New Issue
Block a user