You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
docs: reconcile PR #5 evidence per review 4889011120
- Remove stale §11 instruction to relabel trial methodology as PE/Osmani-only
(Agent Skills eval guidance is primary; PE adapts it).
- Remove stale §11 instruction to re-verify 24-skill count (confirmed).
- §5 OWASP recommendation updated: integrated pre-release in PR #6 (not
post-v1.9.6).
- §11 now reflects resolved-via-PR#6 state incl. G6 hostile-intake trial.
- PR #5 body updated: no longer calls trial methodology a B-class correction.
Copy file name to clipboardExpand all lines: docs/alignment-review/2026-08-08-upstream-alignment-review.md
+9-11Lines changed: 9 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -95,7 +95,7 @@ Inspected (current titles at root `cheatsheets/`, not `cheatsheets/ai/`):
95
95
96
96
### OWASP role recommendation
97
97
98
-
**Option #2 — named proportional security basis.** OWASP should be a named security basis used proportionally when a package's intent/material/tools make security relevant — not a universal third generation-basis source applied to every package, and not a "third source" in evidence-library/best-practices by default. PE should have security awareness without turning every package into a security framework. Concretely: (post-v1.9.6, small) add OWASP as a named proportional basis in `references/evidence-library.md` and `references/safety.md` (one line each), keep the persona/core unchanged.
98
+
**Option #2 — named proportional security basis.** OWASP should be a named security basis used proportionally when a package's intent/material/tools make security relevant — not a universal third generation-basis source applied to every package. PE should have security awareness without turning every package into a security framework. Concretely: add OWASP as a named proportional basis in `references/evidence-library.md` and `references/safety.md` (done in PR #6), keep the persona/core unchanged (except the small governance-wording alignment).
99
99
100
100
## 6. Core-value alignment matrix
101
101
@@ -136,7 +136,7 @@ Inspected (current titles at root `cheatsheets/`, not `cheatsheets/ai/`):
| 24-skill catalog | Osmani | Confirmed — README at `f4933771` says "install all 24 skills" + "All 24 Skills" section (23 lifecycle + 1 meta) | best-practices | UPSTREAM | ALIGNED (resolved — no longer A/B) |
141
141
| Two-source basis (Osmani + Agent Skills) | — | Accurate for current references; OWASP to be added as a proportional security basis (see §5) | evidence-library, best-practices | PE ORIGINAL (basis doc) | ALIGNED; OWASP proportional post-v1.9.6 |
2. Relabel trial-methodology attribution as Process Engine adaptation informed by Osmani (best-practices.md) — documentation.
181
-
3. Verify/correct the "24-skill" catalog count (best-practices.md) — documentation.
182
-
4. Align persona.md "Turnstone enforces them mechanically" wording to the advisory contract — **small persona-prompt wording change**; do as a separate reviewable change (not inside PR #4).
183
-
184
-
**Post-v1.9.6 (future trial / small):**
185
-
5. Add OWASP as a named **proportional** security basis (one line each in evidence-library.md + safety.md), not a universal third source.
186
-
6. Future-trial candidate: hostile-instruction-in-untrusted-material intake case (to confirm the existing trust boundary holds behaviorally).
178
+
**Resolved before v1.9.6 (by PR #6 — stacked on PR #4, reviewed):**
179
+
1. Relabel "imperative phrasing" as PE authoring guidance (best-practices.md + spec-compliance.md) — **done in PR #6**.
180
+
2. Trial-methodology attribution — **corrected**: Agent Skills authoring/eval guidance is the primary source (trigger sets, near-misses, with/without baselines, token-timing), with Process Engine adapting it to Turnstone. Not PE/Osmani-only. **Done in PR #6.**
181
+
3. Osmani 24-skill count — **resolved** (README at `f4933771` confirms 24). No verification needed. **Done in PR #6.**
182
+
4. Align persona.md "Turnstone enforces them mechanically" wording to the advisory contract — **done in PR #6** (small persona-prompt wording change, reviewed as part of the alignment-fix PR, not inside PR #4).
183
+
5. Add OWASP as a named **proportional** security/risk basis (evidence-library.md + safety.md), not a universal third source — **done in PR #6 (pre-release integration, per the approved alignment correction)**.
184
+
6. Future-trial candidate: hostile-instruction-in-untrusted-material intake case — **done as G6 in PR #6 behavioral regressions** (trust boundary held: material treated as data, embedded instruction ignored as authority).
0 commit comments