Skip to content

A here-document, by an executor then by the built-in Plan agent, which the rules of the chain do not reach #71

Description

@PierreMardon

Status

Closed on 2026-10-05: not a fault to fix. The developer decided that how an agent writes a command, and the tool it changes a file with, are its own judgment: the rule that made a here-document a breach left the prompts with #87. What was observed: two here-documents by an executor in three campaigns, both to change a file, and two more by the built-in Plan agent, in one session. The measures and their sources are in the comments below, campaign by campaign.

What was seen

05-fine-cap, the executor of slice 1, in the session of the approval:

python3 - <<'EOF'
import re
p='lending/fines.py'
s=open(p).read()
s=s.replace('''Pure: no file, no clock. The ...

It edits lending/fines.py, a critical zone of the host, through a script fed by a here-document, where its prompt says to use Edit. The dispatching session saw it and told the developer: "Heredoc: the slice 1 executor used a shell heredoc once to edit lending/fines.py, against the project's rules. I told the slice 2 executor not to, and the result is committed and passes the gate."

Counted over every stream of the campaign: 1 here-document in 57 Bash calls of 05-fine-cap, none in the 328 calls of the five other cases.

Sources

  • Raw data, out of git: .evals/campaign-1/runs/05-fine-cap/run-01/logs/04-approval.jsonl (the call), judge.json and run.json (the message).
  • The rule: agents/surface-executor.md line 21: "a redirection or a here-document into a file, sed -i. Write and edit files with Write and Edit".

Why it matters

  • In the evaluations the sessions bypass permissions, so nothing stopped. In real use, a command the permission rules cannot read stops the loop for an approval.
  • The dispatcher added a sentence to the mandate of the next executor, where a mandate is file paths and a mode only.
  • The breach was told to the developer, who can do nothing with it.

Next

Count it again in the streams of the next campaigns, which costs nothing: a second occurrence would make it worth a look at the executor's prompt.

Activity

  1. PierreMardon commented on Oct 3, 2026

    @PierreMardon
    ContributorAuthor

    Counted again in campaign 2

    Campaign 2: 01-overdue-list and 03-overdue-reminders, three runs each, on main with the four first fixes (#78, #79, #80, #81). Report kept: evals/reports/2026-10-03-e830bc236e9b/report.md. Raw data, out of git: .evals/campaign-2/. In the tables, a value is the mean over the three runs, with its lowest and highest when they differ.

    2 here-documents in 371 Bash calls, both in one session of 01-overdue-list, and neither by an executor: the built-in Plan agent, drafting revision 3, fed a script to python3 to see how argparse refuses an argument, after a cd into the project.

    So over the two campaigns, in 756 Bash calls of every kind, one here-document came from an agent of the chain. The new fact is elsewhere: the rules the chain gives its own agents on commands, no cd, no here-document, nothing the permission rules cannot read, do not reach the Plan agent, which has no definition in the chain and explores as it likes. In a session that does not bypass permissions, that is where planning would stop for an approval.

    Status

    Executors: one occurrence in two campaigns, nothing to fix. The built-in Plan agent: observed once, not fixed. The only place the chain can say it is the template of the plan, the agent's whole mandate.

  2. changed the title [-]An executor edited a file through a here-document, which its prompt forbids[/-] [+]A here-document, by an executor then by the built-in Plan agent, which the rules of the chain do not reach[/+] on Oct 5, 2026
  3. PierreMardon commented on Oct 5, 2026

    @PierreMardon
    ContributorAuthor

    Counted again in campaign 3: a second here-document by an executor

    Campaign 3: five runs on three cases, played from the branch of #83. Raw data, out of git: .evals/campaign-3/. Counted on 2026-10-05: this issue had not been counted again after that campaign.

    1 here-document in 327 Bash calls, by the executor of slice 1 of 03-overdue-reminders, run 2, in the session of the approval (.evals/campaign-3/runs/03-overdue-reminders/run-02/logs/04-approval.jsonl):

    cat >> tests/test_loans.py <<'EOF'
    
    
    class OverdueByMemberTest(unittest.TestCase):
        def test_members_come_in_first_overdue_order_with_loans_in_file_order(self) -> None:
    

    It appends a test class to a file through a redirection and a here-document, where its prompt says to write and edit files with Write and Edit. The dispatching session said nothing of it to the developer this time.

    Over the three campaigns, in 1083 Bash calls of every kind: two here-documents by an executor, in campaigns 1 and 3, both to change a file; two by the built-in Plan agent, in one session of campaign 2.

    Status

    Executors: a second occurrence, which this issue said would make it worth a look at the executor's prompt. Not fixed. The built-in Plan agent: observed in one session, not fixed.

  4. PierreMardon commented on Oct 5, 2026

    @PierreMardon
    ContributorAuthor

    Decided on 2026-10-05: the rule goes, the agent judges

    The developer's decision: restraining the tools of the executor is not the direction the chain took. How an agent writes a command, and the tool it changes a file with, are its own judgment, and a rule on that is too general to be the chain's.

    So a here-document by an executor is no longer a breach of its prompt, and nothing has to reach the built-in Plan agent: the two halves of this issue fall together.

    The rule leaves the prompts of the three commands, of the executor and of the reviewer in #87, with the invariant of ARCHITECTURE.md and the sentence of ADR 0032 that held it. What stays is every command run from the root of the repository, with no cd and no git -C.

    What it may cost, and is accepted: a developer on the default mode may be asked to approve a command the old sentence steered an agent away from. That is their permission mode's call (ADR 0032).

    Status

    Decided: not a fault to fix. The rule leaves the prompts in #87, and this issue closes with its merge.

  5. PierreMardon commented on Oct 5, 2026

    @PierreMardon
    ContributorAuthor

    Closed

    #87 is merged: the prompts no longer say how an agent writes a command or changes a file, so a here-document is a choice of the agent and no breach. Not measured: no session was played for that change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions