feat(factory): source-standards model refuses AI attribution in commits and PR text #15

Merged
beddari merged 5 commits from attribution-check into main 2026-09-18 09:09:33 +00:00
Owner

Outcome

Nothing published as the author carries AI attribution: no Co-Authored-By naming an agent or a model, no "generated with" footer, in commit messages or in pull request titles and bodies, whatever the agent's harness asks.

The rule is in the source-standards skill. The program enforces it, with capability and policy on different models:

  • @swamp/git gains commit_messages (extensions/models/git_commit_messages.ts): the commits in base..head with their full messages. A fact about the repository, no rule; upstream log has subjects only and no range.
  • @dataverket/source-standards (extensions/models/source_standards.ts, one instance source-standards, no credentials) is the program's counterpart of the skill: commits over that data, text over a PR title and body, each recorded before failing. fabrikk-attest runs commit_messages then commits before signing, so a tainted branch is never attested. The pull-request stage runs text before pr_ensure sends the PR; this PR's text went through it.
  • validate-attestation adds checks 5 and 6: the same grep over the branch's commits, and over the PR title and body from the event, read through the environment and never interpolated into the script.

One pattern, in source_standards.ts, copied literally into CI. A test pins the copy and proves the model over git's data and the shell recipe agree on a real repository.

The other extensions were reviewed for the same smell, policy inside a wrapper of an external system, and are clean: paths_digest, the Flux reset, and every forgejo method are capability with the rule as an argument; the fabrikk-owned types carry policy by design.

Protected paths

.agents/skills/adversary-source-standards/SKILL.md, .forgejo/workflows/validate-attestation.yaml, extensions/, models/, workflows/. No ADR: factory machinery, no new dependency.

Verified

  • 29 extension tests pass, including the recipe agreement on a real repository and the CI pattern pin.
  • fabrikk-attest validates (24 checks); the definition validates (13 stages); docs-check passes.
  • source-standards text refuses a body with the footer and passes a clean one; commit_messages then commits ran over seven real commits of main.
## Outcome Nothing published as the author carries AI attribution: no `Co-Authored-By` naming an agent or a model, no "generated with" footer, in commit messages or in pull request titles and bodies, whatever the agent's harness asks. The rule is in the source-standards skill. The program enforces it, with capability and policy on different models: - **`@swamp/git` gains `commit_messages`** (`extensions/models/git_commit_messages.ts`): the commits in `base..head` with their full messages. A fact about the repository, no rule; upstream `log` has subjects only and no range. - **`@dataverket/source-standards`** (`extensions/models/source_standards.ts`, one instance `source-standards`, no credentials) is the program's counterpart of the skill: `commits` over that data, `text` over a PR title and body, each recorded before failing. `fabrikk-attest` runs `commit_messages` then `commits` before signing, so a tainted branch is never attested. The `pull-request` stage runs `text` before `pr_ensure` sends the PR; this PR's text went through it. - **`validate-attestation` adds checks 5 and 6**: the same grep over the branch's commits, and over the PR title and body from the event, read through the environment and never interpolated into the script. One pattern, in `source_standards.ts`, copied literally into CI. A test pins the copy and proves the model over git's data and the shell recipe agree on a real repository. The other extensions were reviewed for the same smell, policy inside a wrapper of an external system, and are clean: `paths_digest`, the Flux `reset`, and every forgejo method are capability with the rule as an argument; the fabrikk-owned types carry policy by design. ## Protected paths `.agents/skills/adversary-source-standards/SKILL.md`, `.forgejo/workflows/validate-attestation.yaml`, `extensions/`, `models/`, `workflows/`. No ADR: factory machinery, no new dependency. ## Verified - 29 extension tests pass, including the recipe agreement on a real repository and the CI pattern pin. - `fabrikk-attest` validates (24 checks); the definition validates (13 stages); docs-check passes. - `source-standards text` refuses a body with the footer and passes a clean one; `commit_messages` then `commits` ran over seven real commits of `main`.
feat(factory): source-standards model refuses AI attribution in commits and PR text
Some checks failed
validate-attestation / validate (pull_request) Failing after 2m52s
86505a4439
Nothing published as the author carries a Co-Authored-By naming an agent
or a "generated with" footer. The rule goes into the source-standards
skill; the program enforces it, with capability and policy on different
models:

- @swamp/git gains commit_messages (extensions/models/git_commit_messages.ts):
  the commits in base..head with full messages, a fact and no rule;
  upstream log has subjects only and no range.
- @dataverket/source-standards (extensions/models/source_standards.ts, one
  instance, no credentials) is the program's counterpart of the skill:
  `commits` over that data, `text` over a PR title and body, each recorded
  before failing. fabrikk-attest runs commit_messages then commits before
  signing; the pull-request stage runs text before pr_ensure sends the PR.
- validate-attestation adds checks 5 and 6: the same grep over the
  branch's commits, and over the PR title and body from the event, passed
  through the environment.

One pattern, in source_standards.ts, copied literally into CI; a test pins
the copy and proves the model over git's data and the shell recipe agree
on a real repository. Docs, code map, and README follow.
A tainted trailer found at attesting sent the work item back through
implementing, both test tiers, and a full review round for a reword.
fabrikk-verify's preflight already refuses a dirty tree and a moved HEAD;
the source-standards `commits` check joins it there, before the stack
comes up. Attest need not repeat it: it refuses unless the verify record
concerns headSha, and base..headSha at verify covers what attest would
see at the same commit. CI check 5 stays as the independent recheck.
Docs, skill, and the factory's stage description follow.
refactor(factory): PR text is an instruction to the agent, not a method
Some checks failed
validate-attestation / validate (pull_request) Failing after 2m50s
bb13f6b725
Only the title reaches main, in Forgejo's merge commit, and CI check 6
already reads title and body from the event. A method run before
pr_ensure bought nothing the pull-request prompt and the skill do not
already say. Drop `text` from the source-standards model and its tests;
the prompt keeps one clause at the point of action. `commits` stays.
chore(claude): turn the harness's AI attribution off at the source
Some checks failed
validate-attestation / validate (pull_request) Failing after 2m58s
5318e301e0
A committed .claude/settings.json sets attribution.commit and .pr to
empty, so Claude Code offers no Co-Authored-By trailer or "generated
with" footer to begin with. Prevention only: the source-standards check
at verify preflight and CI check 5 stay the trust. swamp's own repo
commits a settings.json too, but leaves attribution on.
Merge branch 'main' into attribution-check
Some checks failed
validate-attestation / validate (pull_request) Failing after 2m48s
304491dca1
beddari deleted branch attribution-check 2026-09-18 09:09:33 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dataverket/fabrikk!15
No description provided.