Skip to content

Commit 77fa3ca

Browse files
docs: reconcile PR #5 evidence per review 4889011120
- Remove stale §11 instruction to relabel trial methodology as PE/Osmani-only (Agent Skills eval guidance is primary; PE adapts it). - Remove stale §11 instruction to re-verify 24-skill count (confirmed). - §5 OWASP recommendation updated: integrated pre-release in PR #6 (not post-v1.9.6). - §11 now reflects resolved-via-PR#6 state incl. G6 hostile-intake trial. - PR #5 body updated: no longer calls trial methodology a B-class correction.
1 parent e894cf3 commit 77fa3ca

1 file changed

Lines changed: 9 additions & 11 deletions

File tree

‎docs/alignment-review/2026-08-08-upstream-alignment-review.md‎

Lines changed: 9 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -95,7 +95,7 @@ Inspected (current titles at root `cheatsheets/`, not `cheatsheets/ai/`):
9595

9696
### OWASP role recommendation
9797

98-
**Option #2 — named proportional security basis.** OWASP should be a named security basis used proportionally when a package's intent/material/tools make security relevant — not a universal third generation-basis source applied to every package, and not a "third source" in evidence-library/best-practices by default. PE should have security awareness without turning every package into a security framework. Concretely: (post-v1.9.6, small) add OWASP as a named proportional basis in `references/evidence-library.md` and `references/safety.md` (one line each), keep the persona/core unchanged.
98+
**Option #2 — named proportional security basis.** OWASP should be a named security basis used proportionally when a package's intent/material/tools make security relevant — not a universal third generation-basis source applied to every package. PE should have security awareness without turning every package into a security framework. Concretely: add OWASP as a named proportional basis in `references/evidence-library.md` and `references/safety.md` (done in PR #6), keep the persona/core unchanged (except the small governance-wording alignment).
9999

100100
## 6. Core-value alignment matrix
101101

@@ -136,7 +136,7 @@ Inspected (current titles at root `cheatsheets/`, not `cheatsheets/ai/`):
136136
| Verification non-negotiable / "seems right" never sufficient | Osmani | Present (TDD, README) | best-practices | UPSTREAM | ALIGNED |
137137
| Anti-rationalization | Osmani | Present (spec-driven) | best-practices, skill-anatomy | UPSTREAM | ALIGNED |
138138
| Progressive disclosure | agentskills spec + Osmani | Present (spec; context-engineering) | skill-anatomy | SPEC REQUIREMENT + UPSTREAM | ALIGNED |
139-
| Trial methodology (trigger sets, baselines, token capture) | Agent Skills authoring/eval guidance | **Present** (optimizing-descriptions.mdx: trigger sets, near-misses, rates; evaluating-skills.mdx: with/without baseline, timing.json token+duration, assertions) | best-practices, trial skill | SPEC GUIDANCE (authoring/eval) + PE ADAPTATION to Turnstone Trial | ALIGNED (corrected) |
139+
| Trial methodology (trigger sets, baselines, token capture) | Agent Skills authoring/eval guidance | **Present** (optimizing-descriptions.mdx: trigger sets, near-misses, rates; evaluating-skills.mdx: with/without baseline, timing.json token+duration, assertions) | best-practices, trial skill | SPEC GUIDANCE (authoring/eval) + PE ADAPTATION to Turnstone Trial | ALIGNED (corrected; no longer B-class) |
140140
| 24-skill catalog | Osmani | Confirmed — README at `f4933771` says "install all 24 skills" + "All 24 Skills" section (23 lifecycle + 1 meta) | best-practices | UPSTREAM | ALIGNED (resolved — no longer A/B) |
141141
| Two-source basis (Osmani + Agent Skills) | — | Accurate for current references; OWASP to be added as a proportional security basis (see §5) | evidence-library, best-practices | PE ORIGINAL (basis doc) | ALIGNED; OWASP proportional post-v1.9.6 |
142142
| Progressive disclosure | agentskills spec + Osmani | Present (spec Progressive Disclosure section = guidance/convention; context-engineering) | skill-anatomy | SPEC GUIDANCE / DESIGN CONVENTION + PE STANDARD | ALIGNED (classification refined) |
@@ -175,15 +175,13 @@ All candidate improvements were checked: RBAC/approvals/audit/persistence/securi
175175

176176
## 11. Smallest proposed corrections
177177

178-
**Before v1.9.6 (small, release-facing, non-behavioral or minimal):**
179-
1. Relabel "imperative phrasing" as upstream recommendation (best-practices.md + spec-compliance.md) — documentation.
180-
2. Relabel trial-methodology attribution as Process Engine adaptation informed by Osmani (best-practices.md) — documentation.
181-
3. Verify/correct the "24-skill" catalog count (best-practices.md) — documentation.
182-
4. Align persona.md "Turnstone enforces them mechanically" wording to the advisory contract — **small persona-prompt wording change**; do as a separate reviewable change (not inside PR #4).
183-
184-
**Post-v1.9.6 (future trial / small):**
185-
5. Add OWASP as a named **proportional** security basis (one line each in evidence-library.md + safety.md), not a universal third source.
186-
6. Future-trial candidate: hostile-instruction-in-untrusted-material intake case (to confirm the existing trust boundary holds behaviorally).
178+
**Resolved before v1.9.6 (by PR #6 — stacked on PR #4, reviewed):**
179+
1. Relabel "imperative phrasing" as PE authoring guidance (best-practices.md + spec-compliance.md) — **done in PR #6**.
180+
2. Trial-methodology attribution — **corrected**: Agent Skills authoring/eval guidance is the primary source (trigger sets, near-misses, with/without baselines, token-timing), with Process Engine adapting it to Turnstone. Not PE/Osmani-only. **Done in PR #6.**
181+
3. Osmani 24-skill count — **resolved** (README at `f4933771` confirms 24). No verification needed. **Done in PR #6.**
182+
4. Align persona.md "Turnstone enforces them mechanically" wording to the advisory contract — **done in PR #6** (small persona-prompt wording change, reviewed as part of the alignment-fix PR, not inside PR #4).
183+
5. Add OWASP as a named **proportional** security/risk basis (evidence-library.md + safety.md), not a universal third source — **done in PR #6 (pre-release integration, per the approved alignment correction)**.
184+
6. Future-trial candidate: hostile-instruction-in-untrusted-material intake case — **done as G6 in PR #6 behavioral regressions** (trust boundary held: material treated as data, embedded instruction ignored as authority).
187185

188186
**Reject / out of scope:** all E-class items.
189187

0 commit comments

Comments
 (0)