workbench

module
v0.0.0-...-a7e9a7b Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 22, 2026 License: MIT

README

workbench

The home for the Go agentic-infra family: one repo, one Go module, twenty tools (twenty-one binaries) that let one person run a team of coding agents and trust what comes back. Tools live side by side and share contracts, not call stacks: they compose at runtime through artifacts (exit codes and JSONL on disk), never by importing each other's decision code.

go install github.com/itsHabib/workbench/cmd/<tool>@latest

Start here

The tools

Grouped by what they own. Each has its own README under cmd/<tool>/.

Running agents

tool what it does
fleet the substrate for a team of agents: a hook that derives identity, liveness and leases from harness events; seats, assignment rows, receipts, role-addressed mail, one Go watcher for the board, headless polling, assignment/mail wakeups and recurring lead ticks
org, org-mcp editable Markdown role cards and an optional parent directory; register, read, list. Work, messaging and checkpoints need no Org lifecycle; old lifecycle callers are removed during cutover
standup the record and the compiler behind the standup: an agenda derived from records, one standup.v1 record the lead lane proposes, a confirm that only the operator's phrase can set, and an apply that turns cards into fleet dispatch rows and mail
runway foreground execution-runtime controller: one admitted request at a time
dispatch placement: which engine and where a task runs
driverstate the human and cron CLI over the driver-state event ledger
codexguard the deterministic policy floor for Codex tool calls

Deciding what may merge

tool what it does
gate the merge-authorization boundary: scoped, tiered, time-boxed grants; a verifier ladder; a hash-chained decision log; exit codes 0 pass, 1 blocked, 2 parked, 3 refused, 4 error
triage PR risk classification: a deterministic floor plus an escalate-only advisory (triage-floor, triage-advisory)
review who has to review an exact head, and whether they have
reviewfindings one artifact over the reviewers' findings: a producer that reads GitHub, and an address verb that records each finding's lifecycle in the driver-state ledger; it records, it does not judge
escalate the agent → human → agent back-channel: ingests a human's decision for a parked gate run and closes it

Seeing and being told

tool what it does
console a local, read-only web view of gate's inbox
flare notifications on authoritative receipts; a best-effort sink, never a gate
tracelens agent trace diagnostics: loops, redundant calls, retry storms, and what to change
workbench-mcp the unified MCP surface over the workbench verbs

Local models and secrets

tool what it does
local, eval hand one sub-task to a local model (Ollama) with an escalate-on-uncertainty gate; measure which tasks can be exported to it
custody a localhost credential broker: the agent calls an API it is never handed the secret for; every request is an injected pass or a fail-closed refusal

A taste, the local primitive classifying a CI log line on a local model (needs Ollama):

$ echo "Error: connect ETIMEDOUT registry.npmjs.org:443" | \
    env local -prompt "Classify this CI line: flake, infra, or real-break." \
              -schema '{"type":"object","properties":{"class":{"type":"string"}},"required":["class"]}'
{"source":"local","result":{"class":"infra"}}   # output varies by model; verified on qwen2.5:7b

(env sidesteps the local builtin in bash and zsh.)

Layout

  • contracts/ — the shared vocabulary: the verdict schema and Go types every verifier emits, the artifact envelope every producer writes, the org record types. A leaf package that imports nothing else in the module.
  • local/ — the shared local-model mechanism behind cmd/local and cmd/eval; leaf-checked like contracts.
  • cmd/<tool>/ — one binary per tool, guts private under cmd/<tool>/internal/, docs beside it (README.md, and for most tools a CLAUDE.md and AGENTS.md pair CI keeps identical).
  • docs/ — the charter (DESIGN.md), the teaching docs, the autonomy doctrine, and docs/features/<feature>/ with a spec and evidence per feature. Decisions that cut across tools live there too, for example docs/features/org-fleet-boundary/spec.md, which settles what org owns and what fleet owns.

The one rule

A tool may share types and schemas through contracts. A tool may not import another tool's decision logic. When a tool needs another tool's output, it reads an artifact. CI enforces this (the hygiene job); it is not a convention.

Where to read, by question

Develop

gofmt -l . && go vet ./...
golangci-lint run ./...
go test ./...

Third-party Go dependencies are allowed. Every change lands from a worktree; main in the root checkout stays clean.

Directories

Path Synopsis
cmd
codexguard command
codexguard applies deterministic policy to one Codex tool call.
codexguard applies deterministic policy to one Codex tool call.
codexguard/internal/hook
Package hook adapts native Codex lifecycle envelopes to codexguard policy.
Package hook adapts native Codex lifecycle envelopes to codexguard policy.
codexguard/internal/policy
Package policy owns Codex's deterministic authority-bearing action policy.
Package policy owns Codex's deterministic authority-bearing action policy.
codexguard/internal/projection
Package projection safely projects reviewed codexguard assets into a Codex home.
Package projection safely projects reviewed codexguard assets into a Codex home.
console command
Command console is a local, read-only web view of gate's inbox: the runs parked for judgment and the grant ledger, plus a click-through to any run's decision trace.
Command console is a local, read-only web view of gate's inbox: the runs parked for judgment and the grant ledger, plus a click-through to any run's decision trace.
console/internal/fleetcli
Package fleetcli reads Fleet projections through bounded CLI calls.
Package fleetcli reads Fleet projections through bounded CLI calls.
console/internal/gatecli
Package gatecli is the console's only data source: it shells the gate binary and hands back gate's own JSON projections.
Package gatecli is the console's only data source: it shells the gate binary and hands back gate's own JSON projections.
console/internal/web
Package web is the console's loopback HTTP surface: it serves one embedded, self-contained UI page and a few JSON endpoints that proxy gate's own projections.
Package web is the console's loopback HTTP surface: it serves one embedded, self-contained UI page and a few JSON endpoints that proxy gate's own projections.
custody command
Command custody is the operator's credential broker.
Command custody is the operator's credential broker.
custody/internal/credstore
Package credstore is custody's secret backend: the OS credential store that holds the real vendor credentials the proxy injects.
Package credstore is custody's secret backend: the OS credential store that holds the real vendor credentials the proxy injects.
custody/internal/grant
Package grant is custody's signed-capability mechanism: mint an HMAC-signed, key-scoped, action-scoped, TTL-bounded grant; validate one before any forwarding.
Package grant is custody's signed-capability mechanism: mint an HMAC-signed, key-scoped, action-scoped, TTL-bounded grant; validate one before any forwarding.
custody/internal/manifest
Package manifest loads and validates custody's key manifest (`<state>/manifest.json`, spec §5).
Package manifest loads and validates custody's key manifest (`<state>/manifest.json`, spec §5).
custody/internal/match
Package match is custody's request-identity policy: it turns a raw origin-form request target into one canonical form and matches that form against a key's action rules.
Package match is custody's request-identity policy: it turns a raw origin-form request target into one canonical form and matches that form against a key's action rules.
custody/internal/rollup
Package rollup aggregates custody's request-log artifact (<state>/log/requests.jsonl) into a deterministic per-key summary — the telemetry base an offline reviewer (human or local model) reads instead of the raw log.
Package rollup aggregates custody's request-log artifact (<state>/log/requests.jsonl) into a deterministic per-key summary — the telemetry base an offline reviewer (human or local model) reads instead of the raw log.
custody/internal/serve
Package serve is custody's proxy engine: the localhost reverse proxy that turns an agent request into a pass (credential injected, forwarded, logged) or a fail-closed refusal/denial with a remedy.
Package serve is custody's proxy engine: the localhost reverse proxy that turns an agent request into a pass (credential injected, forwarded, logged) or a fail-closed refusal/denial with a remedy.
dispatch command
dispatch decides placement — which engine, provider, model, and effort a task gets — from a versioned, content-hashed policy file.
dispatch decides placement — which engine, provider, model, and effort a task gets — from a versioned, content-hashed policy file.
dispatch/internal/placement
Package placement turns a validated policy plus a task descriptor into a deterministic placement decision.
Package placement turns a validated policy plus a task descriptor into a deterministic placement decision.
dispatch/internal/policy
Package policy is dispatch's data model and fail-closed loader: it reads a versioned policy file, content-hashes the exact file bytes, and validates the frozen task_class taxonomy before any placement decision is made.
Package policy is dispatch's data model and fail-closed loader: it reads a versioned policy file, content-hashes the exact file bytes, and validates the frozen task_class taxonomy before any placement decision is made.
dispatch/internal/receipt
Package receipt writes the append-only JSONL decision record.
Package receipt writes the append-only JSONL decision record.
dispatch/internal/replay
Package replay is the phase-2 validation gate (spec §11): it reproduces the operator's real historical placements by deriving each stream's descriptor via the phase-1 rules (docs/DESIGN.md) and running it through the exact decide engine (policy.Load + placement.Decide) — never hand-labeling a descriptor to fit a historical choice, and never reimplementing matching.
Package replay is the phase-2 validation gate (spec §11): it reproduces the operator's real historical placements by deriving each stream's descriptor via the phase-1 rules (docs/DESIGN.md) and running it through the exact decide engine (policy.Load + placement.Decide) — never hand-labeling a descriptor to fit a historical choice, and never reimplementing matching.
driverstate command
Command driverstate is the human/cron CLI mirror of the workbench-mcp driver verbs: record | state | runs | verify, each with --json.
Command driverstate is the human/cron CLI mirror of the workbench-mcp driver verbs: record | state | runs | verify, each with --json.
escalate command
Command escalate is the resolution back-channel of the Escalation plane: it ingests the decision a notification carried back for a parked escalation and drives gate's `resolve` verb to record it — closing the agent→human→agent loop WITHOUT flare (the router) ever writing a decision.
Command escalate is the resolution back-channel of the Escalation plane: it ingests the decision a notification carried back for a parked escalation and drives gate's `resolve` verb to record it — closing the agent→human→agent loop WITHOUT flare (the router) ever writing a decision.
escalate/e2e/stubgate command
Command stubgate is a recording test double for the gate binary, used only by the escalate serve e2e (cmd/escalate/e2e).
Command stubgate is a recording test double for the gate binary, used only by the escalate serve e2e (cmd/escalate/e2e).
escalate/internal/ingest
Package ingest is the resolution back-channel's only mechanism: it validates the decision a notification carried back for a parked escalation and drives gate's `resolve` verb to record it.
Package ingest is the resolution back-channel's only mechanism: it validates the decision a notification carried back for a parked escalation and drives gate's `resolve` verb to record it.
escalate/internal/serve
Package serve is the HTTP transport adapter for the resolution back-channel.
Package serve is the HTTP transport adapter for the resolution back-channel.
eval command
Command eval measures how well the local model does a task, by running a labeled dataset through the primitive and scoring each answer against a known correct one.
Command eval measures how well the local model does a task, by running a labeled dataset through the primitive and scoring each answer against a known correct one.
flare command
flare — the escalation/block routing sink (an Observability tool, not a plane).
flare — the escalation/block routing sink (an Observability tool, not a plane).
flare/internal/config
Package config loads and validates the routes file — flare's whole policy surface.
Package config loads and validates the routes file — flare's whole policy surface.
flare/internal/event
Package event defines the one value that flows through flare's pipeline: a push-worthy fact lifted from a producer's artifact log.
Package event defines the one value that flows through flare's pipeline: a push-worthy fact lifted from a producer's artifact log.
flare/internal/journal
Package journal is flare's private state under ~/.flare: an append-only delivery journal (the dedupe substrate and the answer to "was the operator paged at T"), and the per-source cursors with the last-poll liveness fact.
Package journal is flare's private state under ~/.flare: an append-only delivery journal (the dedupe substrate and the answer to "was the operator paged at T"), and the per-source cursors with the last-poll liveness fact.
flare/internal/notify
Package notify delivers one event to one channel.
Package notify delivers one event to one channel.
flare/internal/preflight
Package preflight answers one question about a parked escalation: could a human's Approve possibly land, or is it already guaranteed to fail?
Package preflight answers one question about a parked escalation: could a human's Approve possibly land, or is it already guaranteed to fail?
flare/internal/route
Package route matches events against the declarative routes table and applies the throttle.
Package route matches events against the declarative routes table and applies the throttle.
flare/internal/source
Package source lifts events out of producers' append-only JSONL logs.
Package source lifts events out of producers' append-only JSONL logs.
fleet command
Command fleet is the agent-fleet substrate: the harness hook, the operator's CLI, the MCP face and, later, the watcher — one binary, one store, two machines.
Command fleet is the agent-fleet substrate: the harness hook, the operator's CLI, the MCP face and, later, the watcher — one binary, one store, two machines.
fleet/internal/codex
Package codex translates Codex hook events to the fleet hook contract.
Package codex translates Codex hook events to the fleet hook contract.
fleet/internal/fleet
Package fleet is the substrate: one process per harness event, a directory of JSON files under $FLEET_STATE, and the policy that decides a tool call from them.
Package fleet is the substrate: one process per harness event, a directory of JSON files under $FLEET_STATE, and the policy that decides a tool call from them.
fleet/internal/jobs
Package jobs implements a single-host durable job ledger.
Package jobs implements a single-host durable job ledger.
fleet/internal/mcp
Package mcp is the fleet's verbs as MCP tools, over stdio, thin over the verbs.
Package mcp is the fleet's verbs as MCP tools, over stdio, thin over the verbs.
fleet/internal/provider
Package provider supplies the installed provider transport, never scheduling.
Package provider supplies the installed provider transport, never scheduling.
fleet/internal/report
Package report folds passive local telemetry without mutating the substrate.
Package report folds passive local telemetry without mutating the substrate.
fleet/internal/verbs
Package verbs is the operator's side of the hook: stop, resume, revoke, the board, and every other `fleet <verb>`.
Package verbs is the operator's side of the hook: stop, resume, revoke, the board, and every other `fleet <verb>`.
fleet/internal/watch
Package watch is Fleet's Go scheduler, delivery launcher and observer.
Package watch is Fleet's Go scheduler, delivery launcher and observer.
gate command
Command gate decides whether a pull request may merge.
Command gate decides whether a pull request may merge.
gate/internal/authorization
Package authorization owns Gate's policy for protected approvals, exact action freshness, permanent execution claims, and terminal result records.
Package authorization owns Gate's policy for protected approvals, exact action freshness, permanent execution claims, and terminal result records.
gate/internal/capability
Package capability bounds effectful verbs.
Package capability bounds effectful verbs.
gate/internal/evidence
Package evidence runs real reads against GitHub (via the authenticated gh CLI) and records what it saw as evidence artifacts.
Package evidence runs real reads against GitHub (via the authenticated gh CLI) and records what it saw as evidence artifacts.
gate/internal/executor
Package executor owns GitHub App credential custody and exact-head merge execution.
Package executor owns GitHub App credential custody and exact-head merge execution.
gate/internal/ledger
Package ledger closes the loop between what gate AUTHORIZED and what actually LANDED.
Package ledger closes the loop between what gate AUTHORIZED and what actually LANDED.
gate/internal/observe
Package observe is read-only and storeless.
Package observe is read-only and storeless.
gate/internal/readiness
Package readiness owns Gate's policy for explaining how an operator can leave a non-zero terminal state.
Package readiness owns Gate's policy for explaining how an operator can leave a non-zero terminal state.
gate/internal/stamp
Package stamp posts gate's provenance "stamp" onto a PR: a GitHub commit status (gate/authorized → success) that carries the deciding run id and the action artifact's chain hash, so the PR page shows a verifiable pointer back to gate's audit chain.
Package stamp posts gate's provenance "stamp" onto a PR: a GitHub commit status (gate/authorized → success) that carries the deciding run id and the action artifact's chain hash, so the PR page shows a verifiable pointer back to gate's audit chain.
gate/internal/state
Package state is the substrate every other package writes through: typed, append-only, content-hashed artifacts with explicit provenance refs.
Package state is the substrate every other package writes through: typed, append-only, content-hashed artifacts with explicit provenance refs.
gate/internal/tier
Package tier defines the shared risk-tier ordering used by both verdict composition and grant ceilings, so the two can never drift apart.
Package tier defines the shared risk-tier ordering used by both verdict composition and grant ceilings, so the two can never drift apart.
gate/internal/verify
Package verify turns recorded evidence into verdict artifacts and composes them monotonically.
Package verify turns recorded evidence into verdict artifacts and composes them monotonically.
gate/tools/ci-classify-eval command
ci-classify-eval emits ci-classify eval JSONL via gate's cloud Model backend.
ci-classify-eval emits ci-classify eval JSONL via gate's cloud Model backend.
local command
Command local is the agent-callable face of the shared local primitive.
Command local is the agent-callable face of the shared local primitive.
org command
Command org registers editable role cards.
Command org registers editable role cards.
org-mcp command
Command org-mcp exposes role-card registration and reads over MCP.
Command org-mcp exposes role-card registration and reads over MCP.
org-mcp/internal/server
Package server translates MCP role-card operations to the org CLI.
Package server translates MCP role-card operations to the org CLI.
review command
Command review plans, requests, and decides exact-head tier-aware review.
Command review plans, requests, and decides exact-head tier-aware review.
review/internal/policy
Package policy owns review's deterministic routing and continuation rules.
Package policy owns review's deterministic routing and continuation rules.
reviewfindings command
reviewfindings emits Ship-compatible ReviewFindingsV1 artifacts from exact-head GitHub inline review comments.
reviewfindings emits Ship-compatible ReviewFindingsV1 artifacts from exact-head GitHub inline review comments.
runway command
runway — local execution-runtime controller.
runway — local execution-runtime controller.
runway/internal/backend
Package backend is the Runway placement seam (TDD §6): backends propose observations; only the controller assigns seq and writes events.
Package backend is the Runway placement seam (TDD §6): backends propose observations; only the controller assigns seq and writes events.
runway/internal/backend/install
Package install is the private registry of Runway placement adapters.
Package install is the private registry of Runway placement adapters.
runway/internal/backend/local
Package local is the process-group backend: one non-shell argv, explicit cwd/env, and redacting capture of stdout/stderr into logs/ (D11).
Package local is the process-group backend: one non-shell argv, explicit cwd/env, and redacting capture of stdout/stderr into logs/ (D11).
runway/internal/backend/rooms
Package rooms is Runway's Rooms CLI adapter.
Package rooms is Runway's Rooms CLI adapter.
runway/internal/bundle
Package bundle admits a placed request against a work bundle and materializes verified bytes into a run directory.
Package bundle admits a placed request against a work bundle and materializes verified bytes into a run directory.
runway/internal/claim
Package claim is the atomic per-run writer-claim MECHANISM: exclusivity comes only from O_CREATE|O_EXCL (atomic on Linux and Windows).
Package claim is the atomic per-run writer-claim MECHANISM: exclusivity comes only from O_CREATE|O_EXCL (atomic on Linux and Windows).
runway/internal/controller
Package controller is the Runway lifecycle POLICY layer: phase transitions, absolute deadline, idempotent cancellation, collection/cleanup ordering (D7), and the atomic terminal receipt.
Package controller is the Runway lifecycle POLICY layer: phase transitions, absolute deadline, idempotent cancellation, collection/cleanup ordering (D7), and the atomic terminal receipt.
runway/internal/expand
Package expand maps structured {root, value} path refs onto a run's three native roots and computes the RUNWAY_* env values from the same roots — one function, two consumers, so Gate A parity ("env vars equal the expansion roots") holds by construction (FR3).
Package expand maps structured {root, value} path refs onto a run's three native roots and computes the RUNWAY_* env values from the same roots — one function, two consumers, so Gate A parity ("env vars equal the expansion roots") holds by construction (FR3).
runway/internal/journal
Package journal is the append-only sole-writer events.ndjson for one run.
Package journal is the append-only sole-writer events.ndjson for one run.
runway/internal/state
Package state owns the run-directory layout and creation.
Package state owns the run-directory layout and creation.
standup command
Command standup is the compiler behind the standup: a conversation with the lead lane that ends in one JSON record, which then compiles field by field into Fleet verbs that already exist.
Command standup is the compiler behind the standup: a conversation with the lead lane that ends in one JSON record, which then compiles field by field into Fleet verbs that already exist.
standup/internal/standup
Package standup is the record and the compiler behind the standup: a conversation with the lead lane that ends in one JSON record, which then compiles field by field into Fleet verbs that already exist.
Package standup is the record and the compiler behind the standup: a conversation with the lead lane that ends in one JSON record, which then compiles field by field into Fleet verbs that already exist.
swarm command
Command swarm is the substrate for a fleet with no management sessions.
Command swarm is the substrate for a fleet with no management sessions.
swarm/internal/poc
Package poc is the adversarial proof of concept: the same builder workload run with and without management sessions, with planted faults, scored against kill conditions written before the run (poc/KILL.md).
Package poc is the adversarial proof of concept: the same builder workload run with and without management sessions, with planted faults, scored against kill conditions written before the run (poc/KILL.md).
swarm/internal/swarm
Package swarm is the substrate for a fleet of coding agents that has no management sessions: a board derived from git, a decision ledger, claims with fencing epochs, resource leases, admission, a watcher that renders and nudges, and a hook that delivers nudges into a session.
Package swarm is the substrate for a fleet of coding agents that has no management sessions: a board derived from git, a decision ledger, claims with fencing epochs, resource leases, admission, a watcher that renders and nudges, and a hook that delivers nudges into a session.
tracelens command
Command tracelens ingests an agent trace and prints the diagnostic verdict.
Command tracelens ingests an agent trace and prints the diagnostic verdict.
tracelens/internal/tracelens
Package tracelens analyzes agent run trajectories (JSONL steps) and diagnoses pathologies: loops, redundant tool calls, retry storms, cost hotspots, and stuck (no-progress) states.
Package tracelens analyzes agent run trajectories (JSONL steps) and diagnoses pathologies: loops, redundant tool calls, retry storms, cost hotspots, and stuck (no-progress) states.
triage/internal/advisory
Package advisory verifies the agent advisory pass — the escalate-only cloud tier above the deterministic floor (RUBRIC §6, spec §4).
Package advisory verifies the agent advisory pass — the escalate-only cloud tier above the deterministic floor (RUBRIC §6, spec §4).
triage/internal/floor
Package floor computes the deterministic risk floor for a PR from its diff.
Package floor computes the deterministic risk floor for a PR from its diff.
triage/triage-advisory command
triage-advisory joins the deterministic floor with a verified agent advisory:
triage-advisory joins the deterministic floor with a verified agent advisory:
triage/triage-floor command
Command triage-floor reads a unified diff on stdin and prints the deterministic risk floor as JSON.
Command triage-floor reads a unified diff on stdin and prints the deterministic risk floor as JSON.
workbench-mcp command
Command workbench-mcp is the unified workbench MCP surface (v0): a JSON-RPC 2.0 server over stdio exposing the four driver-state verbs — driver_record, driver_state, driver_runs, driver_verify.
Command workbench-mcp is the unified workbench MCP surface (v0): a JSON-RPC 2.0 server over stdio exposing the four driver-state verbs — driver_record, driver_state, driver_runs, driver_verify.
workbench-mcp/internal/server
Package server is the workbench-mcp stdio MCP server: it exposes the four driver-state verbs (driver_record / driver_state / driver_runs / driver_verify) over JSON-RPC 2.0 on stdin/stdout, and owns the run lease for the life of the client session.
Package server is the workbench-mcp stdio MCP server: it exposes the four driver-state verbs (driver_record / driver_state / driver_runs / driver_verify) over JSON-RPC 2.0 on stdin/stdout, and owns the run lease for the life of the client session.
Package contracts is the shared vocabulary of the workbench: the verdict schema every verifier emits and the artifact envelope every producer writes.
Package contracts is the shared vocabulary of the workbench: the verdict schema every verifier emits and the artifact envelope every producer writes.
authority
Package authority is the cross-repo room-authority receipt contract: the wire shape one placed run's authority evidence takes when it carried at least one custody: secret reference — the grant chain (parent → child, attenuation visible in-receipt), how the child token was delivered, what evidence artifacts and custody log lines cover what the run did with it, and how the room that held it was torn down.
Package authority is the cross-repo room-authority receipt contract: the wire shape one placed run's authority evidence takes when it carried at least one custody: secret reference — the grant chain (parent → child, attenuation visible in-receipt), how the child token was delivered, what evidence artifacts and custody log lines cover what the run did with it, and how the room that held it was torn down.
automode
Package automode defines the provider-neutral artifacts exchanged by deterministic auto-mode policy and harness lifecycle adapters.
Package automode defines the provider-neutral artifacts exchanged by deterministic auto-mode policy and harness lifecycle adapters.
driverstate
Package driverstate is the contract home for driver-state events: the typed event vocabulary a writer records as a driver run moves through its lifecycle, the kind-specific body payloads, the reducer output shapes, and the embedded JSON schema every emitter — Go or ship's TS — writes against.
Package driverstate is the contract home for driver-state events: the typed event vocabulary a writer records as a driver run moves through its lifecycle, the kind-specific body payloads, the reducer output shapes, and the embedded JSON schema every emitter — Go or ship's TS — writes against.
escalation
Package escalation is the cross-tool contract for one agent→human PUSH: the wire shape a gate run takes when it parks a pull request for judgment, the brief it carries for a zero-context approver, and — new — the resolution that closes the loop when a human's decision comes back.
Package escalation is the cross-tool contract for one agent→human PUSH: the wire shape a gate run takes when it parks a pull request for judgment, the brief it carries for a zero-context approver, and — new — the resolution that closes the loop when a human's decision comes back.
execution
Package execution is the Runway execution-contract vocabulary: the four wire shapes — portable work spec, placed run request, run event, terminal result — that let a caller compile domain intent into one explicit work bundle, one placement binding, one ordered lifecycle, and one terminal receipt.
Package execution is the Runway execution-contract vocabulary: the four wire shapes — portable work spec, placed run request, run event, terminal result — that let a caller compile domain intent into one explicit work bundle, one placement binding, one ordered lifecycle, and one terminal receipt.
gateauthorization
Package gateauthorization defines the versioned, provider-neutral artifacts exchanged by Gate's protected approval and custodied execution boundary.
Package gateauthorization defines the versioned, provider-neutral artifacts exchanged by Gate's protected approval and custodied execution boundary.
grantrequest
Package grantrequest defines the versioned, provider-neutral request Gate publishes when an operator may mint one exact T0 capability from Slack.
Package grantrequest defines the versioned, provider-neutral request Gate publishes when an operator may mint one exact T0 capability from Slack.
reviewfindings
Package reviewfindings defines ReviewFindingsV1 and the deterministic AddressWorkV1 handoff consumed by Ship or the session-native address boundary.
Package reviewfindings defines ReviewFindingsV1 and the deterministic AddressWorkV1 handoff consumed by Ship or the session-native address boundary.
reviewpanel
Package reviewpanel defines the exact-head ReviewPanelV1 evidence exchanged by evidence collectors and review-completeness verifiers.
Package reviewpanel defines the exact-head ReviewPanelV1 evidence exchanged by evidence collectors and review-completeness verifiers.
reviewroute
Package reviewroute defines the engine-neutral, exact-head vocabulary for selecting and continuing pull-request review.
Package reviewroute defines the engine-neutral, exact-head vocabulary for selecting and continuing pull-request review.
Package driverstate is the write-side MECHANISM of the driver-state plane: durable single-writer-per-run leases and hash-chained, crash-safe appends.
Package driverstate is the write-side MECHANISM of the driver-state plane: durable single-writer-per-run leases and hash-chained, crash-safe appends.
Package filelock is an exclusive advisory file lock, one implementation per operating system.
Package filelock is an exclusive advisory file lock, one implementation per operating system.
Package local is the one shared primitive for running structured calls against a local model (Ollama), with an escalate-on-uncertainty gate.
Package local is the one shared primitive for running structured calls against a local model (Ollama), with an escalate-on-uncertainty gate.
Package slackauth implements the shared mechanism for authenticating and parsing one Slack interactive-action callback.
Package slackauth implements the shared mechanism for authenticating and parsing one Slack interactive-action callback.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL