feat(factory): source-standards model refuses AI attribution in commits and PR text #15
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "attribution-check"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Outcome
Nothing published as the author carries AI attribution: no
Co-Authored-Bynaming an agent or a model, no "generated with" footer, in commit messages or in pull request titles and bodies, whatever the agent's harness asks.The rule is in the source-standards skill. The program enforces it, with capability and policy on different models:
@swamp/gitgainscommit_messages(extensions/models/git_commit_messages.ts): the commits inbase..headwith their full messages. A fact about the repository, no rule; upstreamloghas subjects only and no range.@dataverket/source-standards(extensions/models/source_standards.ts, one instancesource-standards, no credentials) is the program's counterpart of the skill:commitsover that data,textover a PR title and body, each recorded before failing.fabrikk-attestrunscommit_messagesthencommitsbefore signing, so a tainted branch is never attested. Thepull-requeststage runstextbeforepr_ensuresends the PR; this PR's text went through it.validate-attestationadds checks 5 and 6: the same grep over the branch's commits, and over the PR title and body from the event, read through the environment and never interpolated into the script.One pattern, in
source_standards.ts, copied literally into CI. A test pins the copy and proves the model over git's data and the shell recipe agree on a real repository.The other extensions were reviewed for the same smell, policy inside a wrapper of an external system, and are clean:
paths_digest, the Fluxreset, and every forgejo method are capability with the rule as an argument; the fabrikk-owned types carry policy by design.Protected paths
.agents/skills/adversary-source-standards/SKILL.md,.forgejo/workflows/validate-attestation.yaml,extensions/,models/,workflows/. No ADR: factory machinery, no new dependency.Verified
fabrikk-attestvalidates (24 checks); the definition validates (13 stages); docs-check passes.source-standards textrefuses a body with the footer and passes a clean one;commit_messagesthencommitsran over seven real commits ofmain.