Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .agents/skills/catalog.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
"categories": [
{
"name": "Everyday",
"skills": ["skills", "plan", "run", "test", "fix", "review", "task", "handover", "health", "audit", "export"]
"skills": ["skills", "plan", "run", "test", "fix", "review", "task", "handover", "health", "audit", "export", "prompt-perfector"]
},
{
"name": "Clinical and app",
Expand Down
20 changes: 20 additions & 0 deletions .agents/skills/prompt-perfector/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
---
name: prompt-perfector
description: Refine, structure, and optimize user prompts for LLMs while ensuring execution occurs in a isolated environment. Use when asked to polish, perfect, or evaluate prompts safely.
---

# Prompt Perfector

Refines user prompts into structured, highly effective instructions and executes evaluation tasks in an isolated workspace (`Workspace: "branch"`).

## Core Capabilities

1. **Prompt Refinement**: Analyzes input prompts for clarity, context, constraints, output format specifications, and edge cases.
2. **Environment Isolation**: Ensures any code execution, prompt testing, or subagent tasks spawned for prompt validation run within an isolated workspace (`Workspace: "branch"` or `"share"`).

## Workflow

1. **Deconstruct Intent**: Identify the goal, target model, domain constraints, and missing specifications.
2. **Enhance Structure**: Apply structured formatting (System Instructions, Context, Input Schema, Output Constraints, Examples).
3. **Isolated Testing**: If prompt validation requires subagent execution or file testing, invoke subagents with `Workspace: "branch"`.
4. **Deliver Output**: Present the perfected prompt with a summary of structural enhancements and usage recommendations.
4 changes: 4 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -7,3 +7,7 @@
*.pdf binary
*.png binary
*.webp binary

# Review records are append-only. Concurrent branches should retain both sets
# of rows instead of stopping on an add/add conflict at the shared table tail.
docs/branch-review-ledger.md merge=union
3 changes: 3 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -202,6 +202,9 @@ jobs:
- name: Gate-manifest self-test
run: npm run check:gate-manifest

- name: Branch review ledger integrity
run: npm run check:branch-review-ledger

- name: Codebase index coverage
run: npm run docs:check-index

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/pr-policy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ name: PR Policy

on:
pull_request_target:
branches: [main]
branches: [main, "release/**"]
types: [opened, edited, synchronize, reopened, ready_for_review, labeled, unlabeled]
merge_group:

Expand Down
1 change: 0 additions & 1 deletion .npmrc
Original file line number Diff line number Diff line change
@@ -1,2 +1 @@
engine-strict=true
allow-scripts=true
17 changes: 16 additions & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -143,7 +143,7 @@ Review routing:
- `branch-cleanup`: Use only when the prompt explicitly asks for branch cleanup/hygiene or branch deletion candidates. Apply `docs/branch-cleanup-guide.md` and the review ledger before inspecting branch diffs.
- `pr-ci-fix`: Confirmation-required for this repo. GitHub/GitLab API calls, PR comments, CI reruns, commits, and pushes require explicit user approval and must respect the upload/handoff rules. Exception: an explicit `Run PR` sweep carries this approval (see "## Run PR shortcut").

When a branch or PR review completes, record the reviewed branch/ref, HEAD SHA, date, scope, outcome, and checks in `docs/branch-review-ledger.md`.
When a branch or PR review completes, append the reviewed branch/ref, HEAD SHA, date, scope, outcome, and checks to `docs/branch-review-ledger.md`. The ledger is append-only: never edit or delete an existing record; append a correction or superseding record instead. Its `merge=union` attribute preserves concurrent appends, and `npm run check:branch-review-ledger` blocks conflict markers, exact duplicate records, or loss of that merge protection.

<!-- END:codex-review-throttling -->

Expand Down Expand Up @@ -207,6 +207,21 @@ action must perform one; a page that ships must be reachable.

<!-- END:page-and-button-wiring -->

<!-- BEGIN:search-chrome-behaviour -->

# Search chrome behaviour

The shared search chrome must adapt by page ownership, not by ad-hoc padding or route-local overlays. Before changing `MasterSearchHeader`, `GlobalSearchShell`, `ClinicalDashboard`, `DocumentViewer`, phone dock reserves, or search-composer placement, read `docs/search-chrome-behaviour.md`.

- **One owner.** A page either uses the shell/dashboard composer, owns an in-flow hero composer, or owns a document-viewer composer. Do not stack a second fixed search bar or a second dock-sized content pad below a page-owned composer.
- **Phone edge-to-edge contract.** Fixed phone composers are flush to the viewport bottom and paint their own safe-area/home-indicator region while visible. They must not use a non-zero `bottom` gap in edge-to-edge dock mode.
- **Hidden means zero reserve.** When phone search/header/footer chrome scroll-hides, the content-facing reserve is `0rem`; do not restore `0.75rem`, `env(safe-area-inset-bottom)`, or `var(--safe-area-bottom)` as hidden padding. Visible composer chrome may still consume safe-area inset.
- **Header/footer symmetry.** Top header and bottom composer hide/reveal from the same scroll signal where they share a scroll container. If one is hidden, page content behind that edge must be fully visible rather than covered by an opaque white/surface band.
- **Page adaptation.** Standalone mode homes keep the composer in-flow in the hero on phones; submitted/search-result views use the compact bottom dock; answer mode may use overlaid glass header behaviour with matching top reserve; document detail/source routes let `DocumentViewer` own its composer.
- **Guards.** Update the reserve helper, CSS tokens, Playwright phone-scroll coverage, and static contract tests together. Do not silence the existing reserve/overlay tests; add a narrower guard for any new page-specific exception.

<!-- END:search-chrome-behaviour -->

<!-- BEGIN:supabase-project-safety -->

# Supabase project safety
Expand Down
4 changes: 2 additions & 2 deletions data/forms-catalog.json
Original file line number Diff line number Diff line change
Expand Up @@ -29,8 +29,8 @@
"destination": "Examination place must be clear and align with any detention or transport authority.",
"authorises": "Referral for examination by a psychiatrist.",
"doesNotAuthorise": "Treatment, detention, transport, restraint, seclusion or force by itself.",
"before": ["2"],
"parallel": ["3A", "4A"],
"before": [],
"parallel": ["1A attachment"],
"after": ["5A", "6A", "6B"],
"copies": "Use approved form pathway; include confidential attachment only where required.",
"documentationStem": "Assessed at [time/place]. Reasonably suspect need for involuntary treatment order because [illness features], [risk], [capacity issue] and [least restrictive reasoning]. Examination destination: [place].",
Expand Down
26 changes: 13 additions & 13 deletions docs/audit-handover-2026-07-14.md
Original file line number Diff line number Diff line change
Expand Up @@ -117,19 +117,19 @@ evals, service-role tenancy regression class, upstream OCR quality labels drivin

### 4.1 Security / privacy / API

| ID | Finding | Evidence | Remediation wave |
| --- | ----------------------------------------------------------- | -------------------------------------------------------- | ---------------- |
| S1 | Authed public-doc DTOs leak `storage_path` / `content_hash` | `documents/route.ts`, `documents/[id]/route.ts` | Wave D1 |
| S2 | Auth UI trusts `getSession()`; APIs use `getUser` | `src/lib/supabase/client.tsx` | Wave D3 |
| S3 | Public-upload quarantine pool high blast radius if enabled | `upload/route.ts` + pool owner | Wave D4 |
| S4 | Auth 401 envelope `{ error }` only | `supabase/auth.ts` vs `http.ts` | Wave H1 |
| S5 | Many hand-rolled `{ error }` omit `code`/`message` | upload, doc 404s, feedback, demo | Wave H1 |
| S6 | Auth write/admin routes lack rate limits | bulk, labels, table-facts, ingestion/*, eval-cases, jobs | Wave H2 |
| S7 | Document list offset max `1_000_000` | `documents/route.ts` | Wave H3 |
| S8 | Upload reserves max body when Content-Length absent | `upload/route.ts` | Wave H4 |
| S9 | Authed stream summarize excludes public docs | `answer/stream` → `summarizeDocument` owner-only | Wave H5 |
| S10 | Bulk returns raw DB `error.message` | `documents/bulk/route.ts` | Wave D5 |
| S11 | `/api/jobs` can return demo jobs when env missing | `jobs/route.ts` | Wave H6 |
| ID | Finding | Evidence | Remediation wave |
| --- | ----------------------------------------------------------- | --------------------------------------------------------- | ---------------- |
| S1 | Authed public-doc DTOs leak `storage_path` / `content_hash` | `documents/route.ts`, `documents/[id]/route.ts` | Wave D1 |
| S2 | Auth UI trusts `getSession()`; APIs use `getUser` | `src/lib/supabase/client.tsx` | Wave D3 |
| S3 | Public-upload quarantine pool high blast radius if enabled | `upload/route.ts` + pool owner | Wave D4 |
| S4 | Auth 401 envelope `{ error }` only | `supabase/auth.ts` vs `http.ts` | Wave H1 |
| S5 | Many hand-rolled `{ error }` omit `code`/`message` | upload, doc 404s, feedback, demo | Wave H1 |
| S6 | Auth write/admin routes lack rate limits | bulk, labels, table-facts, ingestion/\*, eval-cases, jobs | Wave H2 |
| S7 | Document list offset max `1_000_000` | `documents/route.ts` | Wave H3 |
| S8 | Upload reserves max body when Content-Length absent | `upload/route.ts` | Wave H4 |
| S9 | Authed stream summarize excludes public docs | `answer/stream` → `summarizeDocument` owner-only | Wave H5 |
| S10 | Bulk returns raw DB `error.message` | `documents/bulk/route.ts` | Wave D5 |
| S11 | `/api/jobs` can return demo jobs when env missing | `jobs/route.ts` | Wave H6 |

### 4.2 Ingestion / indexing

Expand Down
Loading
Loading