You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[finding] skills/objectstack-ai tells authors metadata_assistant is "not vocabulary" while the platform's own Studio app pins defaultAgent: 'metadata_assistant' #14461
Out-of-scope by-product of the skills optimization flight on #14305 (audit finding "incidental falsehood 3"). Filed unassigned for triage — no doc edit was made for it, because the contradiction is between the skill's advice and shipped platform code, and which side moves is a ruling, not a rewrite.
The two sides
The published skill (unchanged by the flight, both before and after):
data_chat to ask and metadata_assistant to build resolve through the alias table for old bookmarks and persisted agent_ids; they are not vocabulary — always write ask / build.
The platform's own shipped app — packages/platform-objects/src/apps/studio.app.ts:50:
// Studio is the metadata-authoring host, so its ambient copilot is// pinned to the schema-architect agent. Resolved by the ambient chat// endpoint via `app.defaultAgent` — no UI-side `?agent=` override// needed. Every other app falls back to the data-query agent.defaultAgent: 'metadata_assistant',
Measured at origin/maind16df74: this is the onlyapp.defaultAgent usage in the repo (the audit's real-usage census found 1). So the single live example of the key an author would copy spells the alias the catalog tells them never to write.
Why it needs grading rather than a patch
Three readings, and they lead to different edits:
The code is residue. Studio should be re-pinned to 'build', and the alias table keeps working for persisted agent_ids only. Cheapest, and makes the one live example match the advice.
The alias is load-bearing here. If the cloud AI-Studio plugin registers under the legacy id and the alias resolves at read time, re-pinning is a behaviour change in a repo that cannot see the consumer (service-ai-studio lives in the closed cloud repo). Then the doc advice is right for third parties and the platform pin is a deliberate internal exception that should say so in a comment.
Neither. The retired-spelling ledger should simply carry this as a known residue with an owner.
Reading 2 is not disprovable from this repo — which is exactly why this is a finding and not a fix.
Suggested triage inputs
If reading 1: one-line change in studio.app.ts, plus whatever pin test asserts the current value.
Either way, the retired-spelling ledger should see the residue (that was the audit's own recommendation).
Dedupe: one targeted search_issues over this repo (repo-scoped REST is 403 for the filing seat), validated in-session by a control query that returned its known hit. Nothing open covers this.
Triage addendum — there is a THIRD side, and it is maintainer-ruled
Measured at origin/mained44512. Two corrections to the card above, both material to whichever way this is decided.
(a) #6041's lint landed, and it passes this value by design. The card's closing line — "If reading 1 wins, #6041's lint is what would have caught it" — does not hold. The rule shipped as packages/lint/src/validate-ai-agent-authoring.ts, and its docblock at :30-45 records the outcome verbatim: "the maintainer ruling on #6041 (2026-08-07, reaffirmed 2026-08-09) is option A: add the value check at warning tier, reusing PLATFORM_AGENT_NAMES rather than narrowing the schema to an enum". And :91 is
with :139-140 short-circuiting on membership. So defaultAgent: 'metadata_assistant' is not merely unlinted — it is deliberately accepted, under a ruling, with a docblock at :83-90 explaining that all four names are legitimate references to a platform record "directly or through its alias".
⇒ The platform has treated the alias as a legal authored value twice: once in the Studio pin, once in a maintainer-ruled gate roster. The published skill is the lone dissenter. Reading 1 is therefore not a one-line change plus a pin test; it is a two-site change that reopens #6041's ruling.
(b) Reading 2's unfalsifiability is now documented in-repo, not just suspected.validate-ai-agent-authoring.ts:85 states the aliases are "registered via the cloud alias registry — ADR-0063 §2". So alias resolution is confirmed to be a cloud-side mechanism this repo cannot inspect. That does not prove service-ai-studio registers under the legacy id, but it does establish that the question the card flagged as undecidable really is undecidable from here.
Why this is needs-user-decision and not dispatchable
Every limb is above the seat. Editing published skill text is a change to the authoring contract every agent and third party reads; skills changes are ADR-class and run through the dedicated skills seat with the maintainer. Narrowing the lint roster reopens a standing maintainer ruling. And reading 2 turns on a closed repo. The seat can measure the sides — it cannot pick one.
<!-- os-decision-facets -->
① 项目长远合理性(权重 ≥50%,领起推荐) —— 今天一个助手有两个名字,平台要永远同时认这两个名字。别名表是特例,不是词表:让它只兜住旧数据(用户书签里、库里存着的旧 agent_id),它就是一个有终点的搬迁垫片;让它同时当作者写新代码时的合法拼法,它就是一条永久多出来的契约。缩小特例的方向 = 技能手册那句话是对的,两处代码是残留。
Out-of-scope by-product of the skills optimization flight on #14305 (audit finding "incidental falsehood 3"). Filed unassigned for triage — no doc edit was made for it, because the contradiction is between the skill's advice and shipped platform code, and which side moves is a ruling, not a rewrite.
The two sides
The published skill (unchanged by the flight, both before and after):
The platform's own shipped app —
packages/platform-objects/src/apps/studio.app.ts:50:Measured at
origin/maind16df74: this is the onlyapp.defaultAgentusage in the repo (the audit's real-usage census found 1). So the single live example of the key an author would copy spells the alias the catalog tells them never to write.Why it needs grading rather than a patch
Three readings, and they lead to different edits:
'build', and the alias table keeps working for persistedagent_ids only. Cheapest, and makes the one live example match the advice.service-ai-studiolives in the closedcloudrepo). Then the doc advice is right for third parties and the platform pin is a deliberate internal exception that should say so in a comment.Reading 2 is not disprovable from this repo — which is exactly why this is a finding and not a fix.
Suggested triage inputs
studio.app.ts, plus whatever pin test asserts the current value.skills/objectstack-ui/SKILL.md的 App 例子仍教defaultAgent: 'sales_copilot'—— ADR-0063 之后该绑定解析不到任何 agent #5985 (a skill example teaching adefaultAgentthat resolves to nothing) and [决策] 是否给app.defaultAgent的取值加 lint(平台 agent 名单外即 warning)—— #5985 实测门禁对该类缺陷结构性失明 #6041 (the decision on whether to lintapp.defaultAgentvalues against the platform agent list —skills/objectstack-ui/SKILL.md的 App 例子仍教defaultAgent: 'sales_copilot'—— ADR-0063 之后该绑定解析不到任何 agent #5985 measured that the gates are structurally blind to this defect class). If reading 1 wins, [决策] 是否给app.defaultAgent的取值加 lint(平台 agent 名单外即 warning)—— #5985 实测门禁对该类缺陷结构性失明 #6041's lint is what would have caught it.Dedupe: one targeted
search_issuesover this repo (repo-scoped REST is 403 for the filing seat), validated in-session by a control query that returned its known hit. Nothing open covers this.Triage addendum — there is a THIRD side, and it is maintainer-ruled
Measured at
origin/mained44512. Two corrections to the card above, both material to whichever way this is decided.(a) #6041's lint landed, and it passes this value by design. The card's closing line — "If reading 1 wins, #6041's lint is what would have caught it" — does not hold. The rule shipped as
packages/lint/src/validate-ai-agent-authoring.ts, and its docblock at:30-45records the outcome verbatim: "the maintainer ruling on #6041 (2026-08-07, reaffirmed 2026-08-09) is option A: add the value check at warning tier, reusingPLATFORM_AGENT_NAMESrather than narrowing the schema to an enum". And:91iswith
:139-140short-circuiting on membership. SodefaultAgent: 'metadata_assistant'is not merely unlinted — it is deliberately accepted, under a ruling, with a docblock at:83-90explaining that all four names are legitimate references to a platform record "directly or through its alias".⇒ The platform has treated the alias as a legal authored value twice: once in the Studio pin, once in a maintainer-ruled gate roster. The published skill is the lone dissenter. Reading 1 is therefore not a one-line change plus a pin test; it is a two-site change that reopens #6041's ruling.
(b) Reading 2's unfalsifiability is now documented in-repo, not just suspected.
validate-ai-agent-authoring.ts:85states the aliases are "registered via the cloud alias registry — ADR-0063 §2". So alias resolution is confirmed to be acloud-side mechanism this repo cannot inspect. That does not proveservice-ai-studioregisters under the legacy id, but it does establish that the question the card flagged as undecidable really is undecidable from here.Why this is
needs-user-decisionand not dispatchableEvery limb is above the seat. Editing published skill text is a change to the authoring contract every agent and third party reads; skills changes are ADR-class and run through the dedicated skills seat with the maintainer. Narrowing the lint roster reopens a standing maintainer ruling. And reading 2 turns on a closed repo. The seat can measure the sides — it cannot pick one.
<!-- os-decision-facets -->
agent_id),它就是一个有终点的搬迁垫片;让它同时当作者写新代码时的合法拼法,它就是一条永久多出来的契约。缩小特例的方向 = 技能手册那句话是对的,两处代码是残留。MCPServerPlugin's own docblock still teaches the deprecated stdio trigger —plugin.ts:112-122disagrees withplugin.ts:234-239twelve lines below it #14473),在合同评审第一轮才被抓住(PR skills(ai): optimization flight — the closed agent surface cut to its retirement rows, the flagship defineSkill example made to resolve, open-edition MCP wiring and the tool registry taught (net −1,315 tokens) #14463)。拉动非零,但不是线上事故级。ask/build),同一个错误就变成写代码当场的响亮拒绝。推荐:A —— 手册那句话原地不动;
studio.app.ts:50改回'build';lint 的defaultAgent取值那一限用ask/build(声明-遮蔽那一限继续认全部四个名字,它判的是另一回事)。四棱同向,②有拉动⇒按分歧推荐序荐①的长远终态。回退:B —— 若 cloud 侧确实按旧 id 注册(读数 2),则手册对第三方是对的,平台这一钉是有意的内部例外,就在
studio.app.ts写清楚为什么,并把这条残留登进退役拼法台账。置信缺口(本分析看不见什么): 看不见
cloud仓。validate-ai-agent-authoring.ts:85只说别名注册在 cloud 的别名注册表里,没有说service-ai-studio用哪个 id 注册 —— 这一条正是能把 A 翻成 B 的唯一变量,本仓无法证伪。另外 A 会重开 #6041 的既有裁决(2026-08-07 裁、08-09 重申),这一点不是本席能代裁的。