From 81c4f5072f8aad266124e804d252de9449b66e64 Mon Sep 17 00:00:00 2001 From: Erny Sans Date: Thu, 17 Sep 2026 19:56:48 -0500 Subject: [PATCH] Add multi-repo workflow guardrail --- .github/copilot-instructions.md | 11 +++++++++++ .github/instructions/cross-repo.instructions.md | 9 +++++++++ 2 files changed, 20 insertions(+) diff --git a/.github/copilot-instructions.md b/.github/copilot-instructions.md index d89a6a9..b6b6edf 100644 --- a/.github/copilot-instructions.md +++ b/.github/copilot-instructions.md @@ -112,6 +112,17 @@ Never run `npm publish`, never add a publish or release workflow, and never intr script that would build or publish on install. If a release is genuinely needed, that is a maintainer decision to raise — not an agent action. +## 0.3 Multi-Repo / Multi-Session Guardrail (Critical) + +- **Verify the target before repository actions.** Before any commit, push, or pull-request action, + check `git remote -v` (or an equivalent authoritative source) and confirm that the remote matches + the exact repository named by the task. Never assume. +- **Scope child sessions explicitly.** An orchestrator that creates child sessions across repositories + must state each child's exact repository scope in its task. +- **Keep authorization repository-specific.** Permission to make a change in one repository does not + authorize a matching change in another repository, including for consistency. +- **Stop on ambiguity.** If a task does not clearly identify its repository, ask before acting. + --- diff --git a/.github/instructions/cross-repo.instructions.md b/.github/instructions/cross-repo.instructions.md index 3977fd3..2d5440c 100644 --- a/.github/instructions/cross-repo.instructions.md +++ b/.github/instructions/cross-repo.instructions.md @@ -238,6 +238,15 @@ relied upon. - **One session ≈ one branch ≈ one PR.** Scope to a single unit of work. - **Assign file ownership explicitly** when several sessions edit this repo in parallel, and state which paths are off-limits. +- **Verify repository scope before repository actions.** Before any commit, push, or pull-request + action, check `git remote -v` (or an equivalent authoritative source) and confirm that the remote + matches the exact repository named by the task. Never infer this from the working directory alone. +- **State child repository scope.** When orchestrating child sessions across repositories, include the + exact repository each child may modify in that child's task. +- **Keep authorization repository-specific.** Permission to change one repository does not authorize + making the same change in another repository for consistency or any similar reason. +- **Stop on repository ambiguity.** If the task does not clearly identify its repository, ask before + taking action. - **Push back on instructions that are wrong.** Treat a coordinator's suggestion that touches a security invariant as a *question about the invariant* rather than an instruction — the question form is self-cancelling when it turns out to be wrong. Some of the most valuable outcomes come