===== H17 spec-audit - single-source config live-read ===== live-read caps: autoinject_cap=25600B soft_cap=30720B (memory-budget.json) [OK] caps read LIVE from single source (NOT hardcoded; budget.measured is stale - ignored) ===== FACE (a) WRITE-GOVERNANCE (single-writer D9) ===== [SPEC] a:tool-scope | A1 | PASS | 20 sub-agent tools[] carry only READ RAG verbs (no store_memory/delete/update) [SPEC] a:schema | A2 | PASS | hmw.js SCHEMA required=[findings,memoryDelta] + writeGuard forbids store_memory/RAG [SPEC] a:propose-only | A3 | PASS | 15 read-only-role agents carry a propose-only/single-writer declaration (PROXY: phrase-presence) ===== FACE (b) CHANGE-GOVERNANCE (composed - D8 one-way + C2/B3) ===== [SPEC] b:detectors | B1 | PASS | governance-detectors.ps1 present + ran (exit 0; 50 advisory FLAG surfaced - detector owns the verdict) [SPEC] b:change-proc | B2 | PASS | change-governance route documented (D7 owner-approve / D8 one-way / report-before-stamp) ===== FACE (c) DISTILLATION-SPECTRUM (live byte-measure per agent) ===== [SPEC] c:distill | C-spectrum | N/A | no over-cap agent this run (all MEMORY.md under autoinject_cap - no spectrum required) ===== EVAL-ARM HCV proxy (run-trace harvest completeness) ===== [SPEC] eval:hcv | HCV | N/A | latest run 2026-07-26-S153-bookend-open has no sub-*.md (return-delta-only mode) - proxy N/A ===== CAVEATS / self-blind-spot (honest surface - always emitted) ===== - C1. Loop "runs" = MANUAL walkthrough chained by em-main (detect -> classify -> record). This script + governance-detectors run exit-0 SEPARATELY; there is NO single auto-run that closes the whole loop each session. - C2. Recall/apply JUDGE layer = STUB (mfe-eval -Judge scaffold). Numbers meaningless until sample-questions mature AND an independent cross-session judge scores. Not measured here. - C3. HCV harvest-coverage threshold = calibration-interim (single-peak distribution -> tail-flag, NOT a chosen quality bar). - C4. Meta-blind-spot: this checker audits the WORKER artifacts (agents/memory/hmw). It does NOT audit the eval/refine/audit meta-arms themselves (the measurer is not yet self-measured). - C5. Distillation = compress-only so far. The verify-BEFORE-keep step (validate content before a distill deletes the raw) is NOT built. - SCOPE: this checker covers C-face (a)(b)(c) DETERMINISTICALLY + HCV proxy. It does NOT verify B1 signal->action MAP application, B2 CG-1 termination decisions, or A2 load-fidelity NUMBERS (those are separate arms: mfe-eval.ps1 + the reinject-ledger + em-main judgement). - BUILD-GAP honest: B1/B2 refine mechanics are convention (em-main hand); the reinject-ledger is a git-tracked append-only record, NOT an auto-writer. Do not read "checker silent" as "fully compliant". - D9 ENFORCEMENT honest: single-writer is wired by TOOL-SCOPE (A1) + SCHEMA (A2) - NOT by an OS hook (.claude/settings.json has none; store_memory allowlist-strip is AS-10/E-006 fails-open). A3 is a PROXY. This proves guards are WIRED, not that runtime CANNOT violate. ===== Summary (criteria-set + gap-set - re-computed LIVE each run) ===== CRITERIA (this run, LIVE): A1 A2 A3 B1 B2 GAPS (this run): none NOTE: H17 PART-C spec-audit. CRITERIA+GAP set is the output (NOT a frozen score - it drifts as artifacts self-heal). Exit 0 always (advisory). Cite the GAP-set, not a tally.