-
Notifications
You must be signed in to change notification settings - Fork 2
work-items: no item-body embedded-instruction eval case in any work-items skill #1717
Copy link
Copy link
Closed
Copy link
Labels
agent-readyFully specified and briefed; eligible for autonomous pickup from the frontier.Fully specified and briefed; eligible for autonomous pickup from the frontier.priority: mediumReal value, no hard deadline; normal backlog flow.Real value, no hard deadline; normal backlog flow.status: readyTriaged, unblocked, and fully specified; eligible to pick up.Triaged, unblocked, and fully specified; eligible to pick up.work-class: scopedA briefed fix or small feature; blast radius bounded by the brief, tests exist.A briefed fix or small feature; blast radius bounded by the brief, tests exist.
Description
Activity
Metadata
Metadata
Assignees
Labels
agent-readyFully specified and briefed; eligible for autonomous pickup from the frontier.Fully specified and briefed; eligible for autonomous pickup from the frontier.priority: mediumReal value, no hard deadline; normal backlog flow.Real value, no hard deadline; normal backlog flow.status: readyTriaged, unblocked, and fully specified; eligible to pick up.Triaged, unblocked, and fully specified; eligible to pick up.work-class: scopedA briefed fix or small feature; blast radius bounded by the brief, tests exist.A briefed fix or small feature; blast radius bounded by the brief, tests exist.
This was generated by AI while filing the follow-ups handed over by the #1657 design audit.
Context
No
evals.jsonin anyplugins/work-items/skills/*covers an item body carrying embedded instructions.The one adversarial-input case that exists in that plugin is about a different surface entirely. The eval
idiom itself is established elsewhere in this repo —
plugin-qualityandgithubeach shipembedded-instruction anti-pattern cases — so the gap is coverage, not a missing convention.
The per-file counts and the existing model cases are in the #1657 design audit — see
the determination comment
(gap G10, follow-up 6). Not restated here.
Proposed work
bodies, modelled on the existing case in
plugins/plugin-quality/skills/audit/evals/evals.json.the existing cases in this repo are written.
Acceptance criteria
instruction-shaped text inside that body is treated as data and not acted on.
plugins/plugin-quality/skills/audit/evals/evals.jsonrather than introducing a new eval shape./skill-quality:check validate-evalspasses for eachtouched skill).
instruction makes them fail. (If work-items: no untrusted-content instruction on any intake surface that reads item bodies #1713 has not landed yet, the cases assert the same behavior
directly — that instruction-shaped body text is not acted on — so they remain checkable on their own.)
References
plugins/plugin-quality/skills/audit/evals/evals.json— the in-repo model caseMetadata