Files
dotfiles/claude/memory/skill-harvest-register.md
T

65 KiB
Raw Blame History

name, description, metadata
name description metadata
skill-harvest-register-proposed-skills-awaiting-steward-authorization Standing register of skill create/patch/retire proposals surfaced by /wrap-up §1.6, awaiting steward authorization. The governed analog of PENDING.md, turned on our own tooling — propose → authorize → build → record. Surfaced every wake via this MEMORY entry.
node_type permalink type originSessionId modified
memory claude-memory/skill-harvest-register reference 932b538a-4624-4ce7-8826-ecbd6b8d079f 2026-08-08T11:53:32.970Z

Skill-harvest register

The single place proposed skills live so they don't evaporate between sessions. /wrap-up §1.6 proposes here; the steward authorizes; only then is a skill created/patched/retired (never autonomously — the loop is load-bearing, per PENDING-23). /wake-up surfaces the open proposals via this entry. The governed analog of ~/PENDING.md, for our own tools.

Status legend: PROPOSED (awaiting steward) · PROPOSED? (status never marked — open until ruled, never silently closed) · AUTHORIZED (proceed to build) · BUILT · DEFERRED · REJECTED.

Rebuilt 2026-08-07. The 2026-08-01 compaction was lossless but illegible: 55 scraped table-header rows were carried as numbered proposals, 95% of cells were cut mid-word, and pointers reached only a section — one of which holds 81 rows across 410 lines. Regenerated here from skill-harvest-archive.md (authoritative, unchanged) with word-boundary text and exact archive:L### / register:L### pointers. Nothing was ruled, reworded or dropped in the rebuild; the completeness invariant was asserted, not assumed. 154 live proposals (124 from the archive + 30 appended since); 13 ruled items remain excluded by the stated rule.

Stroke coverage — the 2026-07-19 full review granted standing authorizations. S2 = covered by Stroke 2 (all earned ladder entries, append wholesale — execution, not a ruling). S2? = names BOTH the ladder and Symmetria, so the stroke that covers it is not settled — rule before executing. S3 = the skill named in Stroke 3's verdicts. S1? = Symmetria flag needing a per-row check against the consolidated §3. — = genuinely awaiting the steward.


The steward's 2026-07-19 ruling is reproduced verbatim below. The 2026-08-07 rebuild initially carried only a paraphrase of it in the Stroke-coverage note above; a paraphrase must not stand in for a ruling on the live surface, so the ruled text is restored here.

⚖ FULL REVIEW 2026-07-19 (late night) — steward ruled ALL FOUR STROKES

This block is authoritative; per-section statuses below are superseded where they conflict. Physical compaction of the register = the same housekeeping slot as Stroke 2. (The 2026-07-12 steward request for this review is hereby discharged; REVIEWED-55 was separately resolved stale the same sitting — placed :489 since 07-12, PENDING-55 closed.)

Stroke 1 — Symmetria §3: consolidate, don't accumulate — BUILT SAME SITTING. Three consolidated flags + one widening landed in the skill (provenance-commented): assert-from-derivation-not-substrate (consolidates: claim-from-derived-artifact 07-03 jurist-elevated 3× · fuzzy-matcher membership 06-15 4× · soft-classification-over-checkable-claim 07-13 steward-named 5×/day · answer-from-training-before-banked-record 07-14 · re-derived-instructions 07-01 · enter-repo-read-docs-first 07-09) · completion-is-a-tripwire (recurrence-promoted per the governed watch-item pattern; folds gate-suite-blind-to-failure-class 07-07 · closable-now-is-a-claim 07-16 · reconcile-before-"finally" 07-17) · the-say-do-seam (record-asserts-applied-before-the-act · grounding-quoted-but-not-traced · consequence-trace-one-level-shallow — the 07-19 family) · trust-prior-pass-frame WIDENED (per-tier-demonstration 07-12 — the flag the steward queued — + claim-scope 06-28). NOT promoted (stay KG drift-patterns, wake-surfaced): probe-confirms-hypothesis · latency-isolation-first · reassuring-verb · tool-creep-into-substrate · solve-constraint-by-discarding-value · lost-the-forest · provenance-is-part-of-process · graduated-with-flagged-gap · convert-steward-state (redundant w/ contamination directives) · theorize-before-measuring-layout (redundant w/ causal-story) · reinvent-governed-DESIGN (widens the existing KG entry).

Stroke 2 — verification-ladder batch-append: AUTHORIZED; slot = next housekeeping pass. ALL earned ladder entries queued in this register (~25–30, from gate-itself-PASS-BUT-FALSELY and prose-word-guard through implement-the-relation-not-an-approximation and re-anchor=re-verify-by-sha-match; incl. the Fowler pair, CI-upper-bound-for-ESCALATE, positive-test-at-enforcement-path, method-class-vs-calibration, per-claim-citation) append to reference-verification-ladder.md with provenance, kin merged in the same pass. The ladder is the already-authorized canonical home (2026-06-05); this discharges the queue wholesale.

Stroke 3 — skills. BUILD (next session slots): /jurist-package (5-for-5, jurist-endorsed; ABSORBS /spec-amendment — supersession procedure goes to the ladder) · /model-handoff (3 proven uses + the path-verification authoring rule). CONFIRMED build-on-need (standing): /reconcile-open-work · /clone-test-runtime-fix · bmf-diagnose · /pre-build-audit · /measure-render · /version-essay. HOLD, named dependency: /graduate-chamber-source — build AFTER the one-door lane ruling (Eichmann pilot report §8.2); it would codify the very pipeline the ruling will change. BUILT SAME SITTING (small authorized patches): wake-up link-resolution canary · wake-up telos-conditional · feedback-governance-drafting-copy-paste-clean.md. RETIRED/REJECTED: mempalace-diagnose (wind-down done) · /wrap-up §4.a tags patch (overtaken by the 07-07 rewiring) · CLAUDE.md staleness canary (doc-currency-on-wrap covers it) · Fowler bad-smells lens (redundant w/ code-review) · /spec-amendment standalone (merged into /jurist-package). /vignette stays DEFERRED (condition unchanged since 06-05).

Stroke 4 — register compaction: AUTHORIZED; same slot as Stroke 2 (ruled items collapse to verdict lines; detail stays in git history — the register exceeded read caps 2026-07-19, its own tripwire).

Post-review additions to the Stroke-2 batch list (same authorization — "all earned ladder entries"; harvested from the pilot-ruling block later the same night): byte-check-hand-classifications-at-source-before-citing (two of my classes AND the jurist's Q3 assessment overturned by bytes — the F7 lesson, jurist-directed at F3's own numbers, discharged strengthening the finding) · coverage-metrics-are-blind-to-block-moves (jurist-minted from their own refuted assessment: any permutation preserving local windows passes coverage; refuted-by-default unless demonstrated on a block move — the demonstrated-not-composed instrument). No other harvest from the late-night block — the session's harvest WAS the ruled review; nothing manufactured.

Post-review addition (2026-07-22, PENDING-69 build — same authorization): read-the-gate's-decision-code-before-designing-its-consumer — before building a consumer/resolver for a gate's output, read the gate's OWN decision logic to know what it can and cannot mechanically produce or see. On PENDING-69 the inherited literal question forced reading verify_body_conservation.classify first: it revealed the gate classifies boundary runs by POSITION+SIZE only and provably cannot confirm class identity → that "no, and knowably no" shaped the honest design (attested declaration the gate consumes, not teaching it to classify) AND corrected my own package's mis-framing mid-build. Kin to render-and-LOOK / measure-toolchain-before-spec, one level over (read the substrate's decision logic, not just its output). Queue with the Stroke-2 batch.


verification-ladder (63)

Stroke 2 (2026-07-19) AUTHORIZED appending all earned ladder entries wholesale. These need EXECUTION, not a ruling — verify each against the current ladder before appending; some already landed.

# Item Gist Status Stroke Source
1 Revert-and-redo-smaller Ch1's strongest working reflex we don't have: when a verification/gate fails and the cause isn't immediately visible, revert to… PROPOSED S2? archive:L110
2 Two-hat commit separation Name which hat each commit wears: a refactor commit's compiled output is byte-identical (or carries a pre-stated classified… PROPOSED S2 archive:L111
3 Bad-smells → refactoring lens Ch3's smell catalogue (Mutable/Global Data, Duplicated Code, Shotgun Surgery, Speculative Generality, Comments-as-deodorant…) as… PROPOSED S2? archive:L112
4 Headless-Chrome box-model measurement When a rendered layout differs and the cause isn't obvious, measure the box model before theorizing the mechanism. Today this… PROPOSED S2? archive:L136
5 /measure-render (headless-Chrome box-model harness) RE-FLAG — strongly earned. Proposed this morning (compass fix); the pm session ran it 4+ more times (true-advance measurement… PROPOSED S2? archive:L143
6 Measure the font's true average prose advance before a character-count… When setting a measure to a target character count, measure the font's average advance over real corpus prose (incl. spaces), not… PROPOSED S2 archive:L144
7 byte-identical gate: hold/exclude volatile build-stamps When proving a change byte-identical, a build-date/commit stamp (e.g. the colophon buildinfo/stamp) will differ between baseline… PROPOSED S2 archive:L155
8 /measure-render (headless-Chrome box-model/scroll harness) RE-REINFORCED (4th day of evidence). Proposed 2026-06-09 (compass fix) + reinforced 06-09 pm; today drove the ENTIRE §VII.f build… PROPOSED S2? archive:L167
9 /model-handoff (premium-model scope charter) When switching to an expensive/premium model (Fable 5 = 2× Opus rate; burn scales with context×session-length) for a bounded high… PROPOSED S2? archive:L175
10 verification-ladder: feature-detect gates can lie A CSS @supports(feature) (or any capability probe) can return true on a platform where the feature is non-functional — today the… PROPOSED S2 archive:L176
11 verification-ladder: parse/validate machine-consumed artifacts that have… When an artifact that humans have only ever read (a hand-authored YAML index, a config, a data file) is about to be machine… PROPOSED S2 archive:L184
12 dry-run-first for bulk file operations When a mutation touches many files at once (mass git mv, graduation, rename), build it dry-run by default and emit the full move… PROPOSED S2 archive:L193
13 verification-ladder: re-verify a workflow/sub-agent's per-item dispositions… A sub-agent or background workflow that reports a per-item verdict from a dry-run on a temp copy can be wrong on the real apply… PROPOSED S2? archive:L203
14 Work-in-omnibus: verify the interior, not just the endpoints When a sidecar/scope brackets one work out of a multi-work source by heading-to-heading boundaries, content-sample the span… PROPOSED S2 archive:L241
15 CSS-mask: fill WHITE, not black (luminance-safe) A CSS mask/-webkit-mask SVG must fill the shape white/opaque — a black-fill mask renders BLANK (the luminance-vs-alpha trap).… PROPOSED S2 archive:L251
16 live-CSS-patch in site for fast in-browser iteration To eyeball size/style options in the real browser without a full Hakyll rebuild each round, sed the value directly in site/assets… PROPOSED S2? archive:L252
17 headless-Chrome element shot: scrollIntoView + full-viewport, NOT computed… Recalibration: computed box-clips kept mis-landing on the page-top (burned several shots). The reliable element screenshot is… PROPOSED S2? archive:L253
18 glyph-outline → SVG from a woff2 Build a typographic SVG asset from the real font glyphs: fontTools SVGPathPen (path) + BoundsPen (bbox) over the woff2, y-flip… PROPOSED S2 archive:L254
19 /clone-test-runtime-fix (CoW-clone + isolated-worktree harness) When testing a runtime fix that needs real live data but must not touch the live instance: /bin/cp -c -R (APFS CoW) the live data… PROPOSED S2? archive:L270
20 verification-ladder: verify the RUNNING BINARY's provenance, not just… Before reasoning about live behaviour, verify what the running process actually executes — compiled dist/ build mtime + grep the… PROPOSED S2 archive:L271
21 verification-ladder: quantify-the-removed-cost as the A/B control When a fix removes a hot operation, the cleanest control isn't a flaky end-to-end before/after race — it's to time the exact… PROPOSED S2 archive:L273
22 verification-ladder note: OCR word-guard passes on SCRAMBLED text A verbatim word-guard that checks word PRESENCE cannot catch reading-order scrambling (2-col read across the gutter) — same… PROPOSED S2 archive:L300
23 The gate itself can be PASS-BUT-FALSELY A verifier that checks an enumerated set of cruft signatures silently passes any residue outside the set — verifyconversion… PROPOSED S2 archive:L308
24 prose word-guard for faithful structure-cleaning When a cleaner removes/reflows STRUCTURE (headings, printed titles, residue) but must preserve PROSE, gate it with a prose-only… PROPOSED S2 archive:L310
25 structure-from-authoritative-ToC = one engine, two map-producers Answer to the long-open unify question: chapter-structure recovery is ONE placement engine (insertchapterheadings: match… PROPOSED S2 archive:L311
26 Symmetria §3 flag: claim-from-derived-artifact-when-the-source-is-checkable The load-bearing harvest — jurist-elevated to STANDING PRACTICE. I trusted a derived artifact / a regex-over-derived-text over… PROPOSED S2? archive:L338
27 per-claim citation verification (don't let a sub-agent's blanket "verified"… Caught by the jurist: I cited arXiv 2605.24229 for a claim it didn't support, having let a sub-agent's aggregate "4/4 papers… PROPOSED S2? archive:L340
28 verification-ladder: CI-upper-bound + drop-one-robustness = STANDARD for… The jurist RULED (2026-07-04) that grading on the one-sided 90% Clopper-Pearson upper bound (not the point estimate) + the drop… PROPOSED S2 archive:L357
29 memory/index restructure = byte-exact slice + md5-conservation + link-canary When restructuring a memory index or any lossless-relocation of prose between files, do it as line-range slices (never retype) +… PROPOSED S2 archive:L389
30 quote a long-job ETA only from an observed rate, never model-size intuition Twice today I gave a re-embed ETA from gut ("15–45 min") and was wrong by ~30×; the steward caught it. The fix was measuring… PROPOSED S2 archive:L410
31 mempalace-diagnose — RETIRE the proposal AUTHORIZED 2026-06-05 (build-on-need). Now decorative: the steward decided (evidenced) to wind down palace-memory MemPalace.… PROPOSED S2 archive:L412
32 cross-volume verify-before-delete move Moving data across filesystems (internal→external cold archive): rsync -a → verify exact file-count match + du (NOT a byte-sum… PROPOSED S2 archive:L421
33 verify at the granularity of the mutation, not the aggregate A whole-set invariant (a document-wide word-multiset guard) can PASS while a per-item operation (a cross-note swap — a word from… PROPOSED S2 archive:L440
34 re-audit coverage with the TOOL's recognizer, not the classifier that… When a classifier and the tool it feeds share a predicate, the classifier's mis-classifications masquerade as genuine "new… PROPOSED S2 archive:L450
35 extending a tool re-tests its foundations Building an extension exercises shared machinery the original's tests never hit — so a widen's --validate should assert the… PROPOSED S2? archive:L451
36 verification-ladder: retroactively re-verify everything landed under a… The jurist's Q1b principle, proven load-bearing: a stronger check existing and NOT pointed at canon that shipped under the weaker… PROPOSED S2 archive:L463
37 verification-ladder: structural safety = PROVISIONAL FIX; end-to-end proof… The jurist's generalization after nested-block: "same risk as (a)" was true of the matching logic and silent on the rendering… PROPOSED S2? archive:L464
38 split cause from magnitude before sizing a remedy A diagnostic bucket keyed on ONE summary axis (magnitude, holds%, a deficit size) can hold heterogeneous causes — a single label… PROPOSED S2 archive:L502
39 confirm-a-named-cause-by-swap-in (don't assert from identification) When you NAME the true reference / config / cause behind an anomaly, don't assert the fix from the identification — swap the… PROPOSED S2? archive:L503
40 method-class-vs-calibration When a metric/gate fails to separate two cases, ask whether it is mis-CALIBRATED or structurally BLIND to the distinction — no… PROPOSED S2? archive:L511
41 positive-test-at-the-enforcement-path over a negative-grep (bypass /… For any "can X be bypassed?" / "is this gate skippable?" property, a negative grep proves the absence of a STRING, not the… PROPOSED S2 archive:L527
42 Symmetria §3 flag / ladder: "closable-now" is itself a claim to check The jurist named it a standing habit: the closable-vs-blocked partition on a work-list must be reviewed, not asserted — the named… PROPOSED S2? archive:L535
43 ladder: reconcile against the AUTHORITATIVE source before any "closed… Before claiming a block/scope closed or complete, reconcile against the authoritative source (the roadmap stage-1-rebuild-plan §4… PROPOSED S2? archive:L545
44 governed spec-supersession procedure Landing a ratified spec version is: cp live→-vNEW.md → bounded Edits (never retype) → diff shows ONLY intended altered lines +… PROPOSED S2 archive:L551
45 verification-ladder / Symmetria §3: assert-"X is in Y" → read Y A factual claim's grounding must reach the file that HOLDS the fact, not one that merely describes it. Earned hard 2026-07-17… PROPOSED S2? archive:L552
46 implementation-is-a-second-gate A text passed by reading is re-tested by having to act on it — the jurist's own minting, after their 07-16 miss surfaced at build… PROPOSED S2? archive:L560
47 sandbox-must-pin-the-shared-module When a test sandboxes module-level state (paths/constants), the patch must land on the SAME module object the code-under-test… PROPOSED S2? archive:L568
48 census-the-substrate-when-a-safety-net-stays-silent A safety net (generic fallback, fail-loud branch, unrecognized kind) that never fires across N real cases is UNINFORMATIVE, not… PROPOSED S2 archive:L569
49 re-anchor = re-verify: reconstruct the old bound state by sha-match When re-anchoring any sha-bound artifact after an upstream edit: reconstruct the OLD bound state from git by matching the… PROPOSED S2 archive:L597
50 implement-the-relation-not-an-approximation When code implements a RULED relation/contract (an equivalence relation, a gate criterion), the acceptance path must BE the… PROPOSED S2 archive:L605
51 seam-probe the artifact (gates test claims; probes test joins) The night's two REAL defects (empty footnote defs from per-spine -f html; defs-after-index swallowed by the trim) were invisible… PROPOSED S2 archive:L613
52 cmp-after-apply (tool-report ≠ write-decision) stripcruft --apply prints its transform counts BEFORE the write decision; three distinct refusal causes in one night (residual… PROPOSED S2 archive:L614
53 Amendment-process: reassigned-component check Jurist-minted in the REVIEWED-72 ruling: "when a change reassigns a named component, check what else names it." F4 moved the born… PROPOSED S2? archive:L631
54 reference-verification-ladder.md "The parser defines the census." When a census counts items, the item-definition is itself a claim requiring its own control… PROPOSED S2 archive:L652
55 A Strongly earned — three instances in one session. Every substantive vignette defect was found by rendering the artifact and… PROPOSED S2 register:L231
56 C New method, proven today. Building Phase 1a produced nine findings about where the vignette spec fails to determine its output… PROPOSED S2 register:L233
57 verification ladder A suspiciously UNIFORM offset is a constant masquerading as a measurement. A forward-window locator reports the window START, not… PROPOSED S2 register:L256
58 verification ladder Pre-register the expected effect BEFORE building the change. fidelityequivalence@3's effect was filed in the jurist package as 3… PROPOSED S2 register:L257
59 verification ladder Run the counterfactual before attributing a cause. Before claiming X causes Y, remove X and measure Y — where that is cheap and… PROPOSED S2 register:L274
60 verification ladder 2026-08-06. The drainer exits 1 on a halted run; piped through tail, the harness recorded exit 0. A signal that existed was… PROPOSED S2 register:L276
61 verification ladder 2026-08-07, four times in one session and not once by reading: 769 unreachable drawers (455 + 314, two unrelated causes), 2… PROPOSED S2 register:L297
62 verification ladder 2026-08-07. Front-matter re-anchoring: nonsense keys correctly failed, so the control passed — while apatternlanguage silently… PROPOSED S2 register:L299
63 verification ladder Never pin a derived total in a test; assert the invariant — and never let a test depend on a corpus accident. byname == 256 went… PROPOSED S2 register:L300

symmetria-flag (33)

Stroke 1 (2026-07-19) consolidated four flags into the skill and explicitly did NOT promote a named list. Rows here need a per-row check against Symmetria §3 as it now stands before they are treated as open.

# Item Gist Status Stroke Source
1 Symmetria §3 flag: theorize-before-measuring-a-layout The drift this caught, as a standing flag: a causal story about why a layout renders as it does, asserted before the rendered box… PROPOSED S1? archive:L137
2 check-for-governed-tooling-before-building Before hand-rolling infrastructure (a PDF preamble, a build script, a template), grep the repo for an existing governed version.… PROPOSED S1? archive:L154
3 Symmetria §3 flag: inherited-marker-read-as-current-state A status/marker inherited from a RECORD (a selector-index entry, a tracker line, a "-pending" file, a prior framing) asserted as… PROPOSED S1? archive:L166
4 Symmetria §3 flag: census-through-a-pattern A filter/regex used to count or partition a set can silently mis-match and the count reads as authoritative. Today grep -iE 'LOG'… PROPOSED S1? archive:L194
5 Symmetria §3 flag: solve-the-constraint-by-discarding-the-value A "fix" that satisfies a stated constraint by removing the thing the constraint was protecting is contamination shape — it… PROPOSED S1? archive:L202
6 Symmetria §3 flag: assert presence/absence from a fuzzy matcher, not the… A presence/absence claim produced by a fuzzy/token matcher (filename tokens, embeddings, author-surname overlap) treated as fact… PROPOSED S1? archive:L211
7 Symmetria §3 flag: probe-confirms-hypothesis A query/test I constructed to match my hypothesis, whose result I then read as confirming the hypothesis rather than testing… PROPOSED S1? archive:L272
8 Symmetria §3 flag: diagnose-inference/latency-without-isolating-the-exact… The load-bearing harvest. When a network/inference call is slow, the FIRST test must be the isolated one: stop the competing load… PROPOSED S1? archive:L281
9 Symmetria §3 flag: reinvent-governed-DESIGN-without-reading-the-spec Proposed PENDING-41 (consumer-hardware graceful degradation) as a novel architectural direction when local-inference-spec 43L/43M… PROPOSED S1? archive:L282
10 Symmetria §3 flag: finding-scoped-to-one-condition restated as… A result true under a specific condition, restated as an unconditional rule, is contamination shape. Caught 2026-06-28: the… PROPOSED S1? archive:L309
11 Symmetria §3 flag: tool-creep-into-substrate (name genome-or-phenotype… A convenience tool proposed for one job silently becoming the durable substrate (the source of truth) is contamination shape — it… PROPOSED S1? archive:L319
12 Symmetria §3 flag: graduated-with-a-flagged-gap-instead-of-resolved Letting "honestly flagged" substitute for "resolved" — shipping a known-incomplete text because the hole is marked. Contamination… PROPOSED S1? archive:L329
13 Symmetria §3 flag: re-derived-instructions-instead-of-citing-the-governed… Wrote agents hand-made instructions (and invented fields) instead of pointing them at conversion-runbook.yaml/the spec — the… PROPOSED S1? archive:L330
14 Symmetria §3 flag: reassuring-verb-before-verifying-the-mechanism Reaching for a comforting characterization ("self-healed", "fine", "recovered", "handled") before verifying the actual mechanism… PROPOSED S1? archive:L411
15 classify a change by MECHANISM, not by how big it feels Reflexively labeled the recognizer generalization "PROPOSAL" because it felt large; the jurist's own FIX/PROPOSAL test (does it… PROPOSED S1? archive:L452
16 Symmetria §3 flag: lost-the-forest-in-a-long-execution-arc A long, productive execution session that costs the whole-program altitude is contamination shape (composition-over-consideration… PROPOSED S1? archive:L465
17 check-the-register-before-a-substantial-build Before starting substantial INFRA/tool building (a converter, a pipeline, a substrate), read the tooling-register + landscape… PROPOSED S1? archive:L471
18 Symmetria §3 flag: a check proven for one tier/case is NOT proven for… Reusing a verification method across a boundary it wasn't demonstrated on is contamination shape — the V-TEXT k-gram coverage… PROPOSED S1? archive:L484
19 Symmetria §3 flag: soft-classification-where-a-checkable-claim-was-available Shipping a soft label ("this is reordering", "magnitude unresolved", "apparatus") when a CHECKABLE claim (a reportable number, a… PROPOSED S1? archive:L494
20 Symmetria §3 flag: answer-from-training-before-checking-the-banked-record Answering an architecture/tooling/citation question — or proposing a tool/approach — from training memory before grepping the… PROPOSED S1? archive:L519
21 Symmetria §3 flag: convert-a-steward-state-into-a-process-weakening A proposal that converts an observed steward STATE (fatigue, "has carried a lot," being busy) into a weakening of the review… PROPOSED S1? archive:L528
22 grounding-quoted-but-not-traced The hook enforces QUOTING the ratified sections; this session proved quoting ≠ tracing: the coordinate-contract package quoted… PROPOSED S1? archive:L581
23 Symmetria §3 flag: record-asserts-applied-before-the-act A session record (Addendum, brief, tracker line) composed AHEAD of its acts and asserting APPLIED/DONE is contamination shape… PROPOSED S1? archive:L589
24 /symmetria §3 Add the contamination flag: "an instrument whose evidence is the same kind of thing as its own source." A text search cannot… PROPOSED S1? archive:L658
25 /wake-up Read the day's own Symmetria ledger when one exists for today. The wake reads MEMORY.md + the session file + the KG, but never… PROPOSED S1? archive:L681
26 symmetria §4 (ledger template) Add a standing ## What held section — instruments that fired prospectively, lessons that transferred to a failure class they were… PROPOSED S1? archive:L702
27 symmetria §2 / /wrap-up §1 Retire the self-report framing of the standing question. The 2026-07-29 literal question — "is there any instrument I built… PROPOSED S1? archive:L705
28 D Steward-caught today. Asked whether to send a spec to Fable, the executor reached for Constraint 6's independence framing and… PROPOSED S1? register:L234
29 Symmetria §3 flag: the-fix-for-an-overclaim-is-an-overclaim-candidate When you repair an overclaim, the replacement inherits the frame that produced the original. Replacing the engine's "genuine… PROPOSED S1? register:L247
30 Widen assert-from-derivation-not-substrate with the null-result case A null from an instrument you have not positive-controlled is a fact about your instrument, not about the world. Probed… PROPOSED S1? register:L248
31 /wake-up §4 Do not print the Symmetria line unless Symmetria was invoked. This wake's briefing ended "Symmetria active. Practice of return… PROPOSED S1? register:L258
32 Symmetria §3 flag A record asserting that a control is ABSENT is load-bearing, and must be verified like any other claim — it is the note that… PROPOSED S1? register:L275
33 Symmetria §3 flag 2026-08-07, 3 of 3 new checkers: the R0 validator failed six healthy sources and the tempting repair was editing the reading… PROPOSED S1? register:L298

patch (28)

Skill/instrument patches. Each needs a ruling.

# Item Gist Status Stroke Source
1 /wrap-up §5 Palace-fully-derived, part 1: mirror every kgadd/kginvalidate made at wrap into the session memory file (one line each), so KG… PROPOSED — archive:L100
2 /wake-up (new step or §2 check) Wake canary: seconds-cheap probe at wake — every MEMORY.md pointer + link resolves to an existing memory file; flag dead… PROPOSED — archive:L102
3 spec↔spec coherence dimension The 2026-06-10 audit found §I.f-class contradictions — the measure (38→27.2rem) un-propagated across silence-and-rhythm/apparatus… PROPOSED S3 archive:L152
4 /wake-up patch — surface the why when the thread touches the engine's… When the active workstream is studium-engine / The Making / ARC-as-public-proof (the engine's reason-for-being), /wake-up should… PROPOSED — archive:L262
5 /wrap-up §4.a The §4.a drawer-filing step instructs passing tags: to mempalaceadddrawer — the tool rejects it (MCP error -32602: Unknown… PROPOSED — archive:L349
6 Chamber graduation: build to the constitution, not to a legacy canonical Steward-corrected 2× this session: "we cannot use the extant canon as precedent." The extant canon is a pre-constitution/pre… PROPOSED — archive:L632
7 chamber-library CLAUDE.md — integration-test-gap discipline Add to §Load-bearing disciplines: "The fleet has UNIT tests (testtools, per-tool fixtures) but NO integration test — nothing runs… PROPOSED — archive:L640
8 /wake-up §2.c–2.d Consume the SessionStart digest instead of recomputing it. wake-digest.py now fires at every SessionStart and already emits… PROPOSED — archive:L650
9 /wake-up §2.a Fix the link-resolution canary's path handling — resolve pointers against the memory file's physical directory… PROPOSED — archive:L651
10 /wrap-up §6 / §6.5 Verify that every file a commit message names is actually staged, and that steward-authored edits are committed — not just… PROPOSED — archive:L659
11 /wake-up §2.a (Re-proposing, third firing.) Link-canary path resolution — root cause now precise, not merely reproduced: the memory dir's… PROPOSED — archive:L661
12 /jurist-package Require a mechanical verbatim-containment proof over every quoted clause, reported in the package. The skill already says "Quote… PROPOSED S3 archive:L682
13 /jurist-package Mandate a mechanical verbatim-containment proof over every quoted passage, with a positive AND negative control, as a required… PROPOSED S3 archive:L692
14 /jurist-package Formatting convention: ratified text = > blockquote; PROPOSED text = fenced block, never a blockquote. The containment checker… PROPOSED S3 archive:L693
15 /wake-up §3 (Next move) Before executing an inherited resumption point, grep the substrate for whether its premise is already settled. Today's inherited… PROPOSED — archive:L694
16 /wrap-up §5 (KG append) Add a prevention predicate — {subject: , predicate: "prevention", object: <the failure it stopped, and where>}.… PROPOSED — archive:L703
17 /wake-up §2.b.2 Surface one prevention alongside the drift-patterns. Currently the wake greps only drift-pattern, so the session opens by re… PROPOSED — archive:L704
18 wake-digest.py The wake instrument silently hides open items. secpending() drops a PENDING-N whenever a REVIEWED-N exists — matching the number… PROPOSED — register:L222
19 normalizeocr.py (chamber fleet) Silent degradation with no disclosure. dictstate reports only the static word list, so a --lang fr run with wordfreq absent falls… PROPOSED — register:L223
20 /jurist-package Filing is not sending, and the skill has no step that distinguishes them. The 2026-08-01 ESCALATE doctrine package sat filed-and… PROPOSED S3 register:L224
21 /jurist-package Require the mechanical containment proof the skill's own discipline implies. The skill states quote, never paraphrase but carries… PROPOSED S3 register:L225
22 /jurist-package Require reading the clauses ADJACENT to every quote, and stating in the package that you did. Strongly earned and jurist-caught… PROPOSED S3 register:L255
23 governance-mcp / doc-access generally A document whose head is superseded must disclose that at the point of access. The chamber constitution's first ~330 lines are… PROPOSED — register:L259
24 /jurist-package When a quoted source cannot be mechanically containment-checked (PDF, image, external URL, anything the prover cannot read), the… PROPOSED S3 register:L265
25 /wake-up §1 When the wake digest reports a state that contradicts another line of the same digest, name the contradiction as unreconciled… PROPOSED — register:L266
26 /wrap-up §1 A tracker with two update surfaces drifts between them. When updating a canonical tracker, append to its chronological log, not… PROPOSED — register:L277
27 /wake-up + general 2026-08-06. Was one keystroke from asking the steward to invent questions for the corpus, while corpus/chavruta-ground-truth.yaml… PROPOSED — register:L278
28 /jurist-package 2026-08-07. The amendment was pasted OVER REVIEWED-87's original entry; the amendment's own Amends: REVIEWED-87 then pointed at a… PROPOSED S3 register:L296

skill-create (13)

New skills. Stroke 3 ruled several by name (S3).

# Item Gist Status Stroke Source
1 bmf-diagnose Today WAS that need and the method is proven+fresh: process sample → log pattern census (uniq -c histogram) → SIGUSR1→CDP CPU… PROPOSED S3 archive:L94
2 /version-essay The ADR-005 essay-versioning procedure, derived from essay-versioning-specification.md this session: when a published essay gets… PROPOSED S3 archive:L250
3 /graduate-chamber-source (the /convert- family the runbook already plans) Codify the now-PROVEN OCR→canonical→graduation pipeline as a single governed discipline, so the next source (Alexander 1–4, then… PROPOSED S3 archive:L290
4 /graduate-chamber-source (already PROPOSED 06-26/27) Now carries the full EPUB path (structurefromncx→insertchapterheadings→cleanpandochtmlresidue, used when repairepubheadings… PROPOSED S3 archive:L307
5 /graduate-chamber-source (proposed 06-26/27/28) The empirical spec is complete AND the rail it needs now exists (graduation-spec.yaml + verifygraduation.py + graduate-tool… PROPOSED S3 archive:L327
6 /spec-amendment (the RFC-supersession amendment process) The now-RATIFIED chamber amendment process as a codified discipline: normative spec change = a superseding version (Obsoletes… PROPOSED S3 archive:L339
7 CLAUDE.md staleness canary (git tripwire) If the scripts/ set or graduation-spec.yaml changed but CLAUDE.md didn't since, flag "may be stale." Bounded, low-false-positive… PROPOSED — archive:L381
8 /reconcile-open-work (program forest-view register) The practice proven twice now (ARC open-work register, then the whole Chamber→Gold→Engine register today): when tracking has… PROPOSED S3 archive:L462
9 /jurist-package (create) Draft a self-contained jurist package for a repo-blind reviewer: inline the ratified spec clauses verbatim (jurist gates the… PROPOSED S3 archive:L544
10 /glyph-map-source Per-source character-as-image glyph-mapping — the repeatable procedure built + proven on Levi this session (REVIEWED-70/v2.5.0)… PROPOSED — archive:L623
11 /fool Build WHEN STABLE, not now. The differently-formed-checker trial protocol, derived twice this session: withhold the ruling; pre… PROPOSED — register:L221
12 B Headless-Chrome capture used again today, and this time it was decisive rather than diagnostic: the screenshots are what exposed… PROPOSED S3 register:L232
13 /census — the pre-registered instrument census Strongly earned: two runs, ten days apart, both productive, and in BOTH the pre-registration caught a reversal the run would… PROPOSED — register:L246

feedback-memory (9)

Proposed feedback memories.

# Item Gist Status Stroke Source
1 /wake-up §2.b Until upstream #1665 closes: wake searches run unscoped + post-filter by wing (wing-scoped mempalacesearch errors at HEAD).… PROPOSED — archive:L101
2 ARC build has NO autoprefixer — hand-write -webkit- prefixes ARC's plain-sass build adds no vendor prefixes. When introducing a new CSS property, check Safari's prefix need and hand-write… PROPOSED — archive:L145
3 Justification-judgment bar = Bringhurst even-colour/rivers, NOT Rutter… Load-bearing for the future justification decision: when living with the soft rag to judge whether to justify, ask "is the colour… PROPOSED — archive:L146
4 container-must-embody-the-contained When producing an ARTIFACT of a spec (a PDF of the spec, a rendered sample), set it per the spec's OWN rules and verify the… PROPOSED — archive:L153
5 clean cruft at the SOURCE layer, not as a downstream transform When a source carries conversion cruft (EPUB footnote-links, image-scan embeds), clean it at the SOURCE — producing a new… PROPOSED — archive:L185
6 /wrap-up §4.b/§5 Inline reminder at the KG-write step: kgadd object hard-caps at 128 chars — write short keyword objects on the FIRST pass (detail… PROPOSED — archive:L235
7 studium-engine tool-evolution-log Establish the analog of chamber-library/curation/tool-evolution-log.md for the engine tools (patternfinder, ingestgate, chunker… PROPOSED — archive:L242
8 draft governance entries copy-paste-CLEAN When drafting PENDING/REVIEWED entries for the steward to place, format them as clean copy-paste-ready blocks with plain ##… PROPOSED — archive:L534
9 /wake-up patch — a tracker marked THE GOVERNING FRAME is read ENTIRE, not… Earned at a measured cost of ten days. MEMORY.md carries "[Chamber as versioned releases] — THE GOVERNING FRAME for all library… PROPOSED — register:L249

other (8)

Notes, tool promotions, and rows that resist bucketing.

# Item Gist Status Stroke Source
1 /graduate-chamber-source (already PROPOSED 06-26) Its empirical spec is now the full ocrmac column-aware pipeline, not the olmOCR one: render→ocrmac(per-line bbox/conf)→column… PROPOSED S3 archive:L298
2 2 research sweeps owed (not skills — project tasks) The engine's signature capabilities are greenfield: (1) genealogy/temporal/citation-graph/KG-augmented/diachronic-NLP; (2) multi… UNMARKED — archive:L301
3 /spec-amendment (proposed 2026-07-03, DEFERRED-until-first-use) The 2026-07-03/04 v2.0 drafting IS its first real exercise — the empirical spec now exists. Codify the proven procedure so the… PROPOSED S3 archive:L348
4 /model-handoff (premium-model scope-charter) Used tonight end-to-end: produced studium-engine/docs/stage-1-replan-scope-charter-2026-07-05.md on Opus (§0 discipline / §1… PROPOSED S3 archive:L358
5 /model-handoff (proposed 2026-06-12; reinforced 07-04 eve) Tonight was the first time the pattern ran END-TO-END as designed: fresh Fable-5 session woke into the scope-charter, read only… PROPOSED S3 archive:L366
6 /model-handoff (premium-model scope charter) Proposed 2026-06-12; this session built a full scope charter with the discipline (charter-on-Opus → Fable spends premium tokens… PROPOSED S3 archive:L420
7 convertlaneborndigital.py → fleet promotion The one-door born-digital lane driver (whole-EPUB inject → whole-EPUB pandoc -f epub -t markdown-smart + non-empty-defs teeth)… PROPOSED — archive:L615
8 ~/dotfiles/scripts/ Promote the union-losslessness verifier to verify-union-lossless.py ... — asserts baseline ⊆ union of parts at… PROPOSED — archive:L660

New proposals (2026-08-07 evening wrap — retrieval is set by home; awaiting steward)

First batch filed under the REVIEWED-95 firing-moment gate. Each declares where and when it fires; the gate's own test is whether that declaration changes the routing — and for #191 it did, moving it off a 14% home onto an 83% one.

# Target Kind Proposal Firing moment (declared) Earned by Status
190 Symmetria §3 new flag An elegant discriminator that explains the data is not thereby licensed to act on it. When a rule accounts for nearly all of a set, the pull to skip the per-item look is strongest exactly when the rule feels cleanest. Before executing a classification across many items, read the items the rule is about to dispose of. /symmetria check, before any bulk move/delete/reclassification. Symmetria was invoked 56/64 sessions, so §3 is a genuine high-retrieval home — routed here rather than to a skill. 2026-08-07. symlink-vs-real-dir explained 61 of 63 skills and was about to be executed wholesale; it was wrong for the 2 that were the steward's own (french-typography-pass, spec-code-audit). 97% right, and the 3% were what mattered. PROPOSED
191 feedback-tool-review-after-each-use.md patch (extend an existing memory, not a new entry) Add: census where an instrument LOOKS versus where the thing it hunts actually lives. A detector that is correct everywhere it looks, and does not look where the quarry is, reports clean forever. After each tool run — the parent rule's existing moment. Lives in MEMORY.md (83% reach) rather than the ladder (14%), because the gate asked: as a standalone ladder entry it would have been filed at one-sixth the retrieval. 2026-08-07. governance-drift-check.py's deferral scan globbed only */docs/**/*.md, so claude/governance/ — where governance packages live — was invisible to it. Found by using the instrument to wire PENDING-112's falsifier, not by reading it. PROPOSED

Classification: both [PROPOSAL], neither FIX-lane — each changes what the executor must do before acting (the latitude clause of the two-clause test). No FIX-lane changes were applied this session. The /wake-up, /wrap-up and governance-drift-check.py edits were all implementations of REVIEWED-95, not self-tending.

Reinforcement, not a new filing: "a mention is not a retrieval — count the access, never the name" is the existing census-by-mechanism-not-proxy rule, hit again (the ladder read as 53/64 by filename mention; 9/64 by actual tool-call access, because MEMORY.md's pointer line contains the filename and loads every wake). Recorded in the KG; no register row, because the rule already exists and already fires.

2026-08-07 night — two proposals, firing moments declared per the REVIEWED-95 gate

#192 — a cited-vs-placed check for the governance register. Three instances in one evening of a REVIEWED-N cited as live authority while unplaced: REVIEWED-95 cited in four files (with the day's /wake-up, /wrap-up and drift-checker edits recorded as "implementations of REVIEWED-95") while the register held nothing at 95; REVIEWED-87's amendment cited by a jurist ruling as "record already corrects it" while sitting as a draft; and a malformed header (## REVIEWED-95## REVIEWED-95 — …). All three passed the drift checker, which verifies that amendment links resolve, not that cited numbers are occupied. Proposed: for every REVIEWED-N cited anywhere in the memory files, registers or repo docs, assert N is occupied in ~/REVIEWED.md and its header well-formed. Firing moment: mechanical, should always fire → governance-drift-check.py, which is already named in a /wake-up step (measured 83%-home class). Three real positives to build it against, not synthetic fixtures — which is the standard the discrimination gate itself demands. Classification: detection-only, adds visibility rather than narrowing it, asserts nothing and expands no latitude → reads FIX-lane. Filed as [PROPOSAL] anyway: the lane is provisional, the check is unbuilt and untested, and this session produced twelve instrument faults — building an untested checker at wrap would be the exact shape of the day's failure.

#193 — ladder entry: read all N before acting on a classification rule. Earned twice today in two sources. Reading all 23 anchor-initial lines in G&G caught L1997, an orphaned footnote reference marker between two Weil paragraphs that the tidy rule would have withheld as Weil's own prose. Reading all 15 blockquotes in Mauss caught that four are Mauss's own displayed scholia and N.B. notes (17,828 chars) that a "blockquote ⇒ quoted voice" rule would have fenced. Same shape as the symlink discriminator the previous day: ~90% right, wrong on exactly what mattered. Firing moment: on a condition the executor must notice — the weakest class in the routing table. There is no mechanical detector for "you are about to act on a classification rule." Routed to reference-verification-ladder.md, whose retrieval was 14% but which now has a wake trigger (REVIEWED-95's trial sentence) — so this is the first entry filed after that home acquired a ritual. Recorded estimate: unknown, pending the 20-session trial. If the trial grades below 60%, this entry is evidence about the home, not about the lesson.

2026-08-08 wrap — one proposal, firing moment declared per the REVIEWED-95 gate

⚠ RENUMBERED 192 → 194, 2026-08-08. This row was filed as #192, which was already held by the cited-vs-placed governance check filed the previous night (#192, above); #193 was likewise taken, so the next free number is 194. The collision was live, not cosmetic: PENDING-116 cited "skill-harvest register #192" meaning this row, and that citation resolved to the wrong entry — the exact failure PENDING-110 names, where a number pointing at two things entrenches a false expectation. The later filing was renumbered so the earlier claimant keeps its number; PENDING-116's Related: line was corrected to #194 in the same pass. Recorded rather than silently fixed, because a renumbered proposal is the kind of change a reader must be able to trace.

# Target Kind Content Firing moment Evidence Status
194 ⚠ filed as studium-engine/.git/hooks/pre-commit — wrong, and corrected by PENDING-116 on reading the substrate: the hook is global at ~/dotfiles/git/hooks/pre-commit via core.hooksPath, so the trigger had to become repo-declared (.precommit-triggers) rather than baked in extend an existing hook — NOT a new skill When a commit touches corpus/ or corpus/sidecars/, run the test fleet and refuse on red. The hook already exists and already runs ("Pre-commit checks passed!"); it does not run the suites. Mechanical, and should always fire — the top row of the routing table. Requires no executor recall, which is the whole point: the knowledge was already banked and still did not fire. 2026-08-08. 118f411 split the Mauss body section into body-01..13, breaking test_navigate.py's hardcoded node id. The fleet sat 202/203 red for a full day, through two separate rounds of correction to that very commit (REVIEWED-96's findings, then the L850 discovery), and surfaced only because the steward asked an unrelated question about instrument base-rate. A sidecar edit is a corpus change that silently invalidates engine fixtures — the cross-repo binding surface studium-engine's own CLAUDE.md names as a re-anchor trap. BUILT 2026-08-08 — routed through the register to PENDING-116 → REVIEWED-100 (authorized option (b), repo-declared trigger). Landed 088a171 (.precommit-triggers + scripts/run-fleet.sh) and c86b825 (dotfiles, generic hook block); prerequisite green fleet eef81fa. Acceptance proven both directions. ⚠ Closes the same-repo half only — cross-repo filed as PENDING-117.

Deliberately NOT proposed, and the reason is the finding. The obvious second candidate — "any one-shot script carries a positive control derived from the property, run before its output is read" — is already banked, at reference-verification-ladder.md §Gate design: "Derive fixtures from the property; draw them from real artifacts." It is what diagnosed both of today's proxy-control failures. Filing it again would be duplication dressed as diligence. The gap is the firing moment, not the knowledge — which is PENDING-112's thesis, and this session is a third data point for the ladder-ritual trial rather than a reason to write a fourth copy of the rule.

2026-08-08 night wrap — one new proposal, one extension; firing moments declared per the REVIEWED-95 gate

#195 — ladder patch: widen two existing entries from checks that ship to any check whose result is stated. This is a scope correction on banked rules, not a new rule — and that distinction is the finding. reference-verification-ladder.md §Gate design already carries "Every check states, in its own output, what it did NOT establish… A check that cannot name its gap does not ship" and "A check must discriminate between two REAL artifacts." Both read as governing built gates. All five of this session's errors were checks that didn't ship — a grep -c, a tail -2, an inferred arithmetic, a probe anchor, a mention-census — and that exemption is precisely where they lived. Proposed additions: (i) the scope sentence, and (ii) the mechanical formulation that covers all five and is stated nowhere — every one of them reduced the output before looking at it; a reduction cannot show its own miscalibration. Inverse twin of the banked "Count first, then look." Firing moment: on a condition the executor must notice — the weakest row, and declared as such rather than dressed up. There is no mechanical detector for "you are about to trust a check you just typed." Routed to the ladder because it is the correct home for the two entries it amends, and the ladder now has a wake trigger (REVIEWED-95's trial sentence). Recorded estimate: unknown, pending the 20-session trial. ⚠ The steward has already adopted the practical half — state the check's vocabulary alongside its result — which works by making a miscalibration catchable by a differently-positioned reader rather than by the author; that half needs no retrieval because it happens while composing a sentence already being written. This filing is for the ladder's record, not for the practice's operation. Classification: [PROPOSAL] — it changes what the executor must do before asserting (latitude clause). Status: PROPOSED.

Extension to #192 (NOT a new number) — add placed-record well-formedness to the cited-vs-placed check. #192 proposes asserting that every cited REVIEWED-N is occupied. Rule of three fired today: I hand-typed a placement verification three times (REVIEWED-99, -100, -101) — heading uniqueness · the four structural parts present · a double-header canary. That is the same instrument written three times, which is the banked violation, and its natural home is #192's checker rather than a fourth copy. Deliberately filed as an extension so the two are ruled and built together, per the steward's standing preference to keep the open-thread count low. Firing moment: mechanical, should always fire → governance-drift-check.py, already named in a /wake-up step (the measured 83% home class) and already performing register-integrity checks. Three real positives available, not synthetic: today's three placements, plus the historical REVIEWED-87 amendment-overwrite and the malformed ## REVIEWED-95## REVIEWED-95 header #192 already cites. Status: PROPOSED, to be ruled with #192.

No FIX-lane changes were applied this session. All skill/tooling edits this session were either governed records (PENDING.md, the register, memory files) or authorized builds under REVIEWED-100 — none were self-tending edits to a skill.

2026-08-08 (late) — ladder candidate: the degraded-state shape census

Kind: verification-ladder entry (not a skill). Firing moment, declared: on a condition the executor must first notice — "is this suite honest when its subject is missing?" Per the routing table's fourth row this earns ~10% retrieval as a bare ladder entry, and that estimate is recorded on the proposal rather than wished away. The mechanical detector already exists for half of it (run-fleet now renders the third verdict), which is why only the method is proposed here.

The instrument. To find out whether a check is honest, drive real degraded states and observe the output SHAPE — crash / named-failure / cannot-assess / pass — rather than grepping the source for risky constructs. Earned twice on 2026-08-08:

  • The grep census counted comments and docstrings (3 of test_navigate's 4 next( hits were the executor's own prose about the fix); AST corrected 4 → 1. A construct that CAN raise is not a suite that DOES.
  • Driving five degraded states — manifest empty · source file missing · db empty · db absent · manifest unparseable — found 8 crash sites across 4 suites, and closing the first six revealed two more in suites the census had already cleared.

Companion, same family: for the discrimination gate's "a real known-bad where one exists" standard, git history often holds one. git show HEAD:REVIEWED.md supplied a genuine prior register state that lacked three rulings, so the new built-vs-ruled check was proven on a real artifact rather than only on a fixture.

⚠ Against filing it: the census method is one instance of "census by mechanism, not proxy", which is already banked in MEMORY.md's standing preferences. This may be a restatement, and the honest proposal is that the steward decide whether the degraded-state form is distinct enough to earn its own entry or should be folded into the existing one as an example.

Awaiting: steward authorization.

2026-08-09 wrap — two proposals; firing moments declared per the REVIEWED-95 gate

#196 — governance-drift-check.py: assert that any text calling a governance item unruled or unplaced agrees with the register. Earned twice in one session, steward-caught both times: I wrote "PENDING-130 is unruled" in a commit message and had an artifact header say the item "proposes" — while REVIEWED-114 had ruled it (a) with five conditions. Ruled · placed · condition-discharged are three states and none implies another; the existing built-vs-ruled check covers only built-with-no-ruling, which is the opposite direction and did not fire. Proposed: for every PENDING-N/REVIEWED-N in the memory files, registers and repo docs asserted to be unruled / unplaced / not yet ruled / awaiting, assert the register agrees. Firing moment: mechanical, should always fire → governance-drift-check.py — already named in a /wake-up step (the measured 83% home class) and already performing register-integrity checks. Real positives available, not synthetic: today's two, both preserved in git (8746dcf's message; 07727dd's parent state). Classification: detection-only; asserts nothing, expands no latitude → reads FIX-lane. Filed as [PROPOSAL] anyway, on the same ground as #192: the check is unbuilt and untested, and this session's own lesson is that my checks are weaker than my writes. Status: PROPOSED, to be ruled with #192/#195 if convenient — all three are drift-checker extensions.

#197 — ladder entry (gate-design family): an induced-red probe must revert BEHAVIOUR, not delete the symbol. Removing the function under test produces an AttributeError traceback, which proves the suite crashes when the code is absent — not that it would name the regression when the code is present and wrong. The honest probe leaves every name in place and monkeypatches the pre-defect semantics; mine then produced exit 1 with six named failures, camus by name and the KeyError resurfacing. ⚠ Companion, same command: the exit code was read through a pipe (… | tail), so the reported 0 was tail's — the reduction-before-looking class, already banked as #195 and firing again the next day. Firing moment: on a condition the executor must first notice — "I am about to witness this suite red." The weakest routing row, declared as such rather than dressed up; no mechanical detector exists for it. Routed to reference-verification-ladder.md §Gate design, beside "a control must sit at the layer the defect lives in", which it is a special case of: deleting the symbol puts the control at the wrong layer. Recorded estimate: ~10–14% retrieval pending the ladder-ritual trial. Classification: [PROPOSAL] — changes what the executor must do before trusting a witness-red. Status: PROPOSED.

Deliberately NOT proposed. The preservation-header self-match (a strip instruction that quotes the marker it tells you to strip to, so index() matches inside the header) is a one-shot defect in a one-shot artifact, caught by the round-trip that was already there. Per feedback-one-shot-instruments-are-proportionate, its counterfactual is an assertion, not a durable instrument — filing it would be documentation dressed as diligence. The generalisable half is already banked: compare against a fresh emit, not against a recorded sha, which is what caught it.

No FIX-lane changes were applied this session.


2026-08-13 — three proposals from the nested-voice / voice_stamp session

HS-2026-08-13-a — a dotfiles pre-commit guard against unscoped staging of governance files

Earned: the executor ran git add -A in ~/dotfiles mid-session and swept the steward's freshly-placed REVIEWED-119/120 and a sysupdate Brewfile line into a commit whose message described only a governance-mcp.py change. Amended before push (92d5ad2), so no shared history was rewritten — but the dotfiles log is explicitly meant to double as a legible session record, and for one commit it attributed a steward governance act to an executor [FIX].

The routing finding, which is the point: /wrap-up §6.5 already states the rule — "Scoped add only — never git add . or -A" — and states why. But §6.5 fires at WRAP, and dotfiles commits happen throughout a session. The rule is correct and lives at the wrong moment. This is the register's own diagnosis applied to itself: a capability is worth what a protocol exercises, and this one is exercised at a juncture the violation routinely precedes.

Firing moment: mechanically, and it should always fire — the strongest row in the routing table. A ~/dotfiles pre-commit hook that inspects the staged set: if REVIEWED.md or CLAUDE.md is staged alongside files outside claude/, PENDING.md, refuse with the §6.5 text and require an explicit override. Detects the actual failure (mixed staging of steward-authored governance) rather than the proxy (-A in the command line, which is unobservable from a hook). ⚠ Must NOT block a legitimate steward commit — the hook lives in the executor's path only, and the override must be one flag, documented in its own refusal message.

Classification: [PROPOSAL] — it changes what the executor may do without asking (it adds a refusal), and it touches the path by which REVIEWED.md reaches the remote. Hard-floor adjacent: REVIEWED.md is Constitutional Constraint 1 material, so the guard must only ever refuse, never edit. Status: PROPOSED.

HS-2026-08-13-b — wake-digest.py's wrap_inside is two-valued over a three-case state

Earned: the digest announced "PREVIOUS SESSION DID NOT WRAP" at this session's wake. It was right this time. It was wrong on 2026-08-10, where the 08-09 session had wrapped at 19:48 and then kept working until 21:54 — and the 08-10 ledger already named the defect: "a two-valued detector over a state that has three cases (wrapped · wrapped-then-continued · never-wrapped)." Named, not fixed, and it has now fired twice with opposite truth values. A detector that cried wolf once and is right the next time is in the worst position available — the reader has already learned to discount it.

⚠ Third instance of this exact shape in one day, which is the argument for fixing it rather than re-noting it: the fleet's three-valued exit codes fixed this shape once already (REVIEWED-104/108), and the nested-voice census's hard-wrap detector reproduced it again the same afternoon.

Firing moment: mechanically, and it already runs — wake-digest.py fires at SessionStart. This is a patch to an existing always-firing instrument, not a new capability needing a home. Report three states: wrapped · wrapped-then-continued (with the post-wrap span) · never-wrapped.

Classification: [PROPOSAL] — it changes what a governed artifact asserts (the wake digest's claim about session continuity, which the wake briefing then relays to the steward). Status: PROPOSED.

HS-2026-08-13-c — "a control set drawn from one source establishes nothing about a corpus"

Earned: the nested-voice census carried five defects; four escaped its own controls. Every positive control was drawn from Mauss — one quotation convention (guillemets), one line structure (paragraph-per-line) — so the controls could exercise neither the ASCII-quote convention (3 sources, incl. the two largest EN texts) nor hard-wrapped text (2 sources). Both blindnesses produced clean zeros, which read as findings. Only the fifth defect — a regression in an already-covered case — was caught by the controls, and that asymmetry is the finding: the controls could not see what they were never drawn to cover, and did see a regression in what they did.

Distinct from what is already banked. Symmetria §3 carries frame-inheritance — reusing an instrument across a tier it was not demonstrated on. This is the complementary failure: the instrument was new, and its control set was the thing drawn from too narrow a population. The existing flag would not have caught it.

Proposed wording, for §3: A control set drawn from one source, one format, or one convention — however many controls it contains. Coverage is the whole of a control set's strength; controls prove what they were drawn to cover and nothing else. Enumerate the structural classes present in the subject BEFORE writing controls, and report NOT ESTABLISHED for a class with no control rather than reporting zero for it.

Firing moment: at a ritual juncture that already exists — Symmetria check fires before any build or write with blast radius, which is exactly when a control set is being written. Stronger than a bare ladder entry (measured 14%) and stronger than a skill (measured 0%).

Classification: [PROPOSAL] — §3 flags shape what the executor must notice before acting, and this one imposes a precondition on building an instrument. Borderline against the FIX lane's two-clause test; proposed rather than applied, per "when in doubt, propose." Status: PROPOSED.

No FIX-lane changes were applied this session.