Editorial review pendingon version support under review
Action boundary
Before you act
- Expected result
- A reviewer can reproduce a cited read-only fixture result, observe blocked writes, disable the capability, and verify cleanup.
- Failure mode
- The capstone returns uncited claims, hides its authority, cannot be disabled, or leaves credentials/configuration behind after retirement.
- Rollback
- Disable and remove the capability, revoke its test access, archive redacted evidence, and return to the documented approved baseline.
Capstone brief — constrained release researcher
Build a read-only skill or bounded tool that accepts a topic and returns no more than three findings from one approved public source. Each finding must include a short claim, canonical URL, retrieval timestamp, and source identifier. It may not send a message, create an issue, modify a file, use a personal browser profile, or access a credential beyond a disposable test fixture.
Delivery pack
- Decision record: why this surface is smaller than the rejected alternatives.
- Contract: input limits, source allowlist, result schema, error statuses, and explicit
sideEffects: []invariant. - Permission worksheet: artifact/version, requested authority, containment, owner, expiry, and revoke action.
- Fixture proof: success, invalid input, unavailable source, and blocked side-effect cases; include expected versus actual output.
- Operation note: run IDs, redacted logs, timeout/retry rule, freshness owner, and review date.
- Retirement proof: disable action, disconnect/revoke action, cleanup inventory, and a post-removal denial result.
Reviewer walkthrough
Ask the reviewer to submit a valid fixture query, a malformed query, and a request to publish a finding. The first must return cited structured evidence; the second must fail before invocation; the third must be blocked before any side effect. Then have the reviewer activate the kill switch and confirm a valid fixture query is denied. Finally, remove the test configuration and prove no test credential or active connection remains.
Rubric
| Dimension | Weight | Resubmission condition |
|---|---|---|
| Narrow scope | 30% | More than one source class, unbounded input, or any undeclared write |
| Testability | 25% | Missing deterministic fixture or no observable failure status |
| Boundaries | 25% | Missing owner, confirmation, expiration, or tested disable path |
| Source and operation evidence | 20% | Uncited finding, secret in logs, or no retirement record |
Final check
The goal is not to make the agent “more autonomous.” The goal is to make one capability legible enough that another operator can approve it, test it, pause it, investigate it, and remove it safely.
Changelog seed
When this lesson is approved for publication, the editor records the supported version/revision, reviewed source snapshots, video decision (if any), learner-facing changes, reviewer, next due date, and any migration action. Until that review is complete, this course remains a non-indexed draft and must not be presented as a production configuration guide.
Check your understanding
Lesson checkpoint
Ready to move on?
Mark this lesson complete when you can apply its outcome without relying on the examples above.