Skip to content

[docs] AGENTS.md carries no version-release prohibition either — #6170's ruling lives only in the PM lane's SKILL.md #6830

Description

@os-project-manager

Blocked-by: #6801

Found while implementing #6801 (the ADR-merge prohibition clause in AGENTS.md), filed unassigned per Prime Directive #10. Not fixed there#6801's scope is the ADR clause, and writing a second governance rule into the same file would have been silent scope expansion.

The gap

#6801's card asked me to check whether the sibling release-action prohibition (#6170, maintainer 2026-08-07) already had a home in AGENTS.md, so the two could sit side by side. It does not.

Measured on origin/main @ e120a5a1d:

  • grep -inE "release action|发版|changeset publish|npm publish|version tag|workflow_dispatch" over AGENTS.mdno clause of any kind forbidding an AI seat from executing or triggering a release action.
  • The prohibition exists in exactly one file: .claude/skills/pm-dispatch/SKILL.md:2458-2468 — the PM lane's skill. Its own text names the seats it binds as 「任何 AI 座位(PM / dev / Routine / 队列管家)」, i.e. it claims repo-wide scope from inside a file only one lane loads.

Why this is the same defect #6801 / #6785 were filed for, one rule over

The ADR case is the worked example, already paid for: the ruling was written into an issue and one lane's SKILL.md, and within the hour two different seats — os-zhuang on #6671, os-project-manager on #6732 — took the prohibited action. #6785 exists because that propagation failure is structural, not careless.

The release rule has the identical shape and the identical exposure surface. It also has its own precedent that the mechanical channel fires without anyone deciding to use it: on 2026-08-07 release.yml's on-push lane published rc.4 end to end with no human instruction (#6169 / #6170). A os-dev seat or a Routine that never opens the PM skill has, today, no repo-readable statement that it must not run changeset publish, push a version tag, workflow_dispatch a release workflow, or merge a chore: version packages PR.

Suggested shape (not a decision — the maintainer's ruling text is the input)

A short Prime Directive next to the one #6801 just added, or a paragraph inside it, stating: authoring release-adjacent work stays open (release board, pin bumps, version reconciliation, verifying release state); the release act itself — pushing packages to a registry, tagging a version, cutting a GitHub Release, pushing runtime images, merging the Version Packages PR — belongs to no seat. Quote the maintainer's own wording verbatim rather than paraphrasing the SKILL.md restatement, and cross-reference #6170 / #6169.

⚠️ Worth deciding rather than assuming: whether the two prohibitions read better as one directive ("governance actions no AI seat performs", with ADR-merge and release as its two entries) or as two adjacent ones. The ADR half is written as PD #14 in the PR for #6801; whichever way this goes, the verbatim maintainer quotes must stay separate and untranslated.

Refs: #6170 (the release-lane defect and the ruling's context) · #6169 (the rc.4 unattended publish) · #6801 (the ADR half of the same propagation gap) · #6741 (the ADR ruling) · #6785 (machine enforcement for the ADR half — the same question will arise here).


Generated by Claude Code

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions