You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
PR #2160 ("fix(orchestrator): add existing file context injection, stub discard, and destructive-command gating")
merged at 2026-08-24T19:37:59Z over a standing Needs more work verdict, and has not been reverted.
Timeline
Ten consecutive Claude review rounds between 17:38 and 19:24 UTC, every one of them Needs more work.
The final verdict (comment 5400199490, 19:24, reviewed commit 560e8d2) reads:
"Needs more work. ... Finding 1 above is a new, directly-reproduced instance of the same bypass class this round's own diff introduced, on a common and realistic filename shape."
Two further pushes (bd9c7f6, 74f221a) received only "Claude review skipped --- API credential or quota unavailable" notices (the quota outage that began ~19:30).
The PR merged at head 74f221a with no clean verdict, no self-review fallback, and no disposition of the round-10 finding.
Per fully-clean.md, a skip notice neither clears nor supersedes a prior not-clean verdict,
and a later push does not clear one either --- only a later clean verdict does.
The two commits after 560e8d2 may well have addressed finding 1, but nothing verified that.
Suggested disposition
Either revert (as gha#645 did for gha's #622-#633 batch), or run a retroactive review of the merged
delta (560e8d2..74f221a plus the round-10 finding's filename-shape bypass) and fix or file whatever it finds.
Sweep performed 2026-08-24 ~16:30 PT across all 57 PRs merged into ai-config main on 2026-08-24 (UTC),
classifying each latest-verdict-at-merge with check-pr-fully-clean.py's classify_verdict and
hand-confirming every flagged comment's last ### Verdict heading.
Every other merge either had a clean Claude verdict at merge or a posted self-review fallback verdict.
PR #2160 ("fix(orchestrator): add existing file context injection, stub discard, and destructive-command gating")
merged at 2026-08-24T19:37:59Z over a standing Needs more work verdict, and has not been reverted.
Timeline
560e8d2) reads:"Needs more work. ... Finding 1 above is a new, directly-reproduced instance of the same bypass class this round's own diff introduced, on a common and realistic filename shape."
bd9c7f6,74f221a) received only "Claude review skipped --- API credential or quota unavailable" notices (the quota outage that began ~19:30).74f221awith no clean verdict, no self-review fallback, and no disposition of the round-10 finding.Per
fully-clean.md, a skip notice neither clears nor supersedes a prior not-clean verdict,and a later push does not clear one either --- only a later clean verdict does.
The two commits after
560e8d2may well have addressed finding 1, but nothing verified that.Suggested disposition
Either revert (as gha#645 did for gha's #622-#633 batch), or run a retroactive review of the merged
delta (
560e8d2..74f221aplus the round-10 finding's filename-shape bypass) and fix or file whatever it finds.Related
adversarial self-review APPROVED verdicts under the quota outage, which
self-review-fallback.mdsanctions;they are not listed here as violations, though Five UMS entries merged with a Needs-more-work verdict: 14 findings, several factual errors on main #2174 shows the fallback's error rate that evening was not zero.
Sweep performed 2026-08-24 ~16:30 PT across all 57 PRs merged into ai-config
mainon 2026-08-24 (UTC),classifying each latest-verdict-at-merge with
check-pr-fully-clean.py'sclassify_verdictandhand-confirming every flagged comment's last
### Verdictheading.Every other merge either had a clean Claude verdict at merge or a posted self-review fallback verdict.