Skip to content

docs(incidents): publish 7 anonymized incident-replay pages - #2

Open
BellmeJoe wants to merge 11 commits into
mainfrom
docs/incident-001-dirty-tree-staged
Open

docs(incidents): publish 7 anonymized incident-replay pages#2
BellmeJoe wants to merge 11 commits into
mainfrom
docs/incident-001-dirty-tree-staged

Conversation

@BellmeJoe

Copy link
Copy Markdown
Owner

Publishes 7 anonymized incident-replay pages (001-007) covering dirty-tree residue, agent force-push, committed .env leak, agent self-report drift, review-bandwidth collapse, open admin route, and over-broad agent cleanup. Each page follows the Move 5 spec: anonymized by default (no repo/org/handle named without consent), a 'what it would NOT have caught' misses section, and the concierge CTA footer (npx getadvantage check, issue within a day). Reconstructed and run through the live gate; not published as anyone's identified incident. 7 of the 6-8 target window for this 30-day cycle.

BellmeJoe and others added 11 commits July 31, 2026 17:11
…git's own dirty-tree refusal) — staged, not published
…, Intent Contract scope drift) — staged, not published
… architecture scan) — staged, not published
…uth check, map advisory-only) - staged, not published
…pe files; misses section covers everything outside the repo) - staged, not published
Grok's 2026-08-17 technical verification (agent-ops/runs/2026-08-17-grok-build-CYCLE-2045.md
section 6) found the published transcript was captured on a pre-0.13.1 build:
missing file:line, missing per-finding auth hash, and stale warn/skip counts.
Reran the reconstruction against live npx getadvantage@latest (confirmed 0.13.1)
with the password-free Postgres URL variant the page already implies. The AWS-shaped
key is now recognized by the live scanner (it was not at the time the page was
first drafted), which also corrects the misses section: the scanner now misses
only the unadorned database URL, not the AWS key.

Not yet re-verified by Grok; PR #2 stays unmerged pending that pass. Incidents
001, 002, 004-007 were spot-checked for the same defect class (only secret-scan
pages carry an auth hash) but not independently re-run against live output this
cycle.
Live-reran the reconstruction against npx getadvantage@latest (confirmed
0.13.1, generic repo, no package.json): full output totals ✓5 ⚠1 ✗1 –3
skipped (Checks section ✓2 + Overview section ✓3), not the ✓2 the page
previously claimed. The page only summed the Checks-section checks and
left out the three passing Overview-section lines (API surface map,
Agents & integrations map, Schedules & jobs map). Checks-section
transcript block, finding text, and misses section were already
byte-for-byte accurate against live output; only the verdict total was
wrong.

Not yet re-verified by Grok; PR #2 stays unmerged pending that pass.
Spot-checked incident 001 the same way this cycle: its verdict (✓6 ⚠1
✗1 –2 skipped, reproduced with a package.json present) matches live
output exactly, no fix needed. Incidents 004-007 not yet re-run this
cycle.
…ncident 004

Live-reran the Intent Contract reconstruction against npx getadvantage@latest
(confirmed 0.13.1): getadvantage intent init + intent check on a fresh repo
reproducing the same scope-drift shape (allowlist src/auth/**, tests/auth/**;
out-of-scope edit to src/billing/charge.js). The Checks-section structure,
finding text, and "scope verified; semantic correctness not proven" line were
already accurate. Missing: two real output lines under "Smallest safe next
edit" — the wider-envelope reauthorization workflow and the
cannot-self-authorize note on a frozen contract. Added both, verbatim from live
output. Illustrative hashes/commit IDs in the page are unchanged (they were
already a different reconstructed run, not meant to be literal).

Not yet re-verified by Grok; PR #2 stays unmerged pending that pass.
Incidents 005-007 not yet re-run against live output this cycle — flagged
open, not silently skipped.
…006, 007

005: architecture scan was missing the explanatory subhead under the
section header and the signal-band suffix on the Verdict line.
006: map output was missing the confirm-each-warning-route line between
the flagged routes and the full route table.
007: intent check was missing the wider-envelope reauthorization
workflow and the cannot-self-authorize note, same truncation class
already fixed in incident 004 this morning.

All three verified against live getadvantage@0.13.1 output from fresh
local reconstructions, not asserted from memory.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant