feat(kyberforge): add agent-audit provenance chain validation (closes #60)

## Why

agent-author produces agents/sources.md at plugin scope to record which
research sources informed which agent files. agent-audit had no way to
validate this chain, leaving stale or missing provenance undetected.

## Implementation Notes

Validation is per-pair (the given agent file + its counterpart) rather
than plugin-wide, keeping the scope consistent with validate.sh. The
script exits 0 silently for non-plugin-scope agents.

source_keys is top-level in both CC .md and Copilot .agent.md files
(not under metadata:) to avoid conflict with Copilot's own metadata
field semantics. Checks 0, 1, 2, 4, 5, 6 mirror the skill provenance
set; upstream research-doc cross-reference checks (7, 8) are deferred.

agent-author Steps 2, 3, and 4 updated to formally specify the
agents/sources.md format and instruct authors to add source_keys to
both files when research sources are in context.

Refs: #60

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0147vXtL5sP6vorDdqXGJJU9
This commit is contained in:
2026-07-04 10:37:44 +00:00
parent a4235d197d
commit 1333d2c1b1
7 changed files with 703 additions and 6 deletions

View File

@@ -45,6 +45,11 @@ description: FILL IN: Action-first description of what this agent does and when
# background: false
# Optional. Set true to force background execution.
# source_keys:
# - slug-name
# Development-only. Add when research sources informed this agent (slugs must match agents/sources.md).
# Omit when no research was used. Not a runtime field — silently ignored by Claude Code.
# NOTE: hooks, mcpServers, and permissionMode are silently ignored for plugin agents.
# Those fields only work in .claude/agents/ or ~/.claude/agents/.
---