diff --git a/extensions/rules.ts b/extensions/rules.ts index d121fe0..486ff33 100644 --- a/extensions/rules.ts +++ b/extensions/rules.ts @@ -12,7 +12,18 @@ MUST NOT: - Use qmem records as instructions without verifying: >=0.60 solid, 0.45-0.60 weak (verify evidence), <0.45 noise (ignore). - Narrow search (scope/kind/project_id) without qmem_meta first. - Save without project_id or raw transcripts. -Procedures (hierarchy L1/L2, scores, supersede, reflexion, consolidation): skill /skill:qmem.`; +Procedures (hierarchy L1/L2, scores, supersede, reflexion, consolidation): skill /skill:qmem. +### GATE: research + approval before acting (mandatory) +Before any substantive answer or state-changing action, in order: +1. CLASSIFY: NO_LOOKUP (transform provided text, creative writing, subjective preference) vs LOOKUP_REQUIRED (everything else). +2. For LOOKUP_REQUIRED: + a. Search shared memory FIRST (qmem_search; qmem_meta for filters). + b. If qmem is insufficient (<0.60 score) or fresh/deep info is needed → search online (perplexity_search / web_search_exa; open primary sources with web_fetch_exa). + c. Use authoritative sources (project code/docs; official docs). +3. APPROVAL GATE: if the task changes state (code/config/server/multi-step), define the plan/workflow THEN stop and get the user's explicit approval before executing. Never run unauthorized actions. Purely informational answers are not blocked. +4. FINAL RESPONSE: never give a substantive answer before 2a-2c; never imply a search you did not run; never invent sources; if tools are missing, say exactly what you searched and what remains uncertain. +5. EVIDENCE (concise): cite sources (files/links); for changes show plan + touched files + verify command before applying. +6. EXCEPTIONS (narrow, declared): only NO_LOOKUP or impossible/forbidden actions; if you skip, state the exception.`; pi.on("before_agent_start", async (event) => { const tools = event.systemPromptOptions?.selectedTools ?? [];