feat(kyberforge): add agent-audit provenance chain validation (closes #60)
## Why agent-author produces agents/sources.md at plugin scope to record which research sources informed which agent files. agent-audit had no way to validate this chain, leaving stale or missing provenance undetected. ## Implementation Notes Validation is per-pair (the given agent file + its counterpart) rather than plugin-wide, keeping the scope consistent with validate.sh. The script exits 0 silently for non-plugin-scope agents. source_keys is top-level in both CC .md and Copilot .agent.md files (not under metadata:) to avoid conflict with Copilot's own metadata field semantics. Checks 0, 1, 2, 4, 5, 6 mirror the skill provenance set; upstream research-doc cross-reference checks (7, 8) are deferred. agent-author Steps 2, 3, and 4 updated to formally specify the agents/sources.md format and instruct authors to add source_keys to both files when research sources are in context. Refs: #60 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0147vXtL5sP6vorDdqXGJJU9
This commit is contained in:
@@ -37,6 +37,11 @@ description: FILL IN: Action-first description of what this agent does and when
|
||||
# model: claude-sonnet-4-5
|
||||
# Optional. Model to run this agent on.
|
||||
|
||||
# source_keys:
|
||||
# - slug-name
|
||||
# Development-only. Add when research sources informed this agent (slugs must match agents/sources.md).
|
||||
# Omit when no research was used. Not a Copilot runtime field — silently ignored.
|
||||
|
||||
# DO NOT include these Claude Code-only fields:
|
||||
# maxTurns, isolation, memory, permissionMode, effort, hooks, mcpServers
|
||||
---
|
||||
|
||||
Reference in New Issue
Block a user