Problem
devloop/spec.py:process_spec builds the refine prompt as:
f"## Conversation so far\n" + "\n---\n".join(c.body for c in comments)
Every comment body — any author, including agents and strangers — enters the agent prompt with no access gate and no untrusted-data framing. The build side fixed exactly this in #9 / PR #10 (core.comment_block).
Requirements
- Route spec-loop comment context through the same seam (
comment_block) — gated by cfg.access, untrusted-framed, bounded.
- Keep
spec_phase's existing authorized-approved check untouched (that's the Ledger-adjacent protocol, not prompt context).
- Note: spec conversations are long — decide whether
[pipeline].prompt_comments's cap fits the spec loop or spec needs its own key (cheapest: one shared key, raise it for everyone).
Tests
- spec prompt excludes a non-authorized author's comment
- untrusted framing present in the spec prompt
- existing spec-phase transitions unchanged
Problem
devloop/spec.py:process_specbuilds the refine prompt as:Every comment body — any author, including agents and strangers — enters the agent prompt with no access gate and no untrusted-data framing. The build side fixed exactly this in #9 / PR #10 (
core.comment_block).Requirements
comment_block) — gated bycfg.access, untrusted-framed, bounded.spec_phase's existing authorized-approvedcheck untouched (that's the Ledger-adjacent protocol, not prompt context).[pipeline].prompt_comments's cap fits the spec loop or spec needs its own key (cheapest: one shared key, raise it for everyone).Tests