docs(implement): workflowScript embedding gotchas for the review wave #3

Open
rimskij wants to merge 1 commit from reflex/implement-workflowscript-gotchas into main
Owner

Skill-improvement reflex patch (triggered by si after the karl-marx-bot WP #432 /implement run, 2026-08-30).

All three gotchas cost a dead async run or a retry that session:

  1. Diff in a raw template literal dies — a git diff containing bash ${…} or backticks parses as JS interpolation inside the workflowScript sandbox. Fix documented: JSON-encode (jq -Rs .) and pass via workflowScriptPath.
  2. Read-only agents reject implementation-sounding task phrasing — keystone-pi.security-auditor refused a task titled "Security-audit this diff"; phrasing both tasks explicitly READ-ONLY fixes the classification.
  3. runs.host requires an explicit integer timeoutMs — optional per docs, required by the validator.

Single-line insertion in the CODE REVIEW PHASE of skills/implement/SKILL.md, after the existing "Both analyze that supplied diff." sentence. No code changes.

Skill-improvement reflex patch (triggered by `si` after the karl-marx-bot WP #432 /implement run, 2026-08-30). All three gotchas cost a dead async run or a retry that session: 1. **Diff in a raw template literal dies** — a `git diff` containing bash `${…}` or backticks parses as JS interpolation inside the workflowScript sandbox. Fix documented: JSON-encode (`jq -Rs .`) and pass via `workflowScriptPath`. 2. **Read-only agents reject implementation-sounding task phrasing** — `keystone-pi.security-auditor` refused a task titled "Security-audit this diff"; phrasing both tasks explicitly READ-ONLY fixes the classification. 3. **`runs.host` requires an explicit integer `timeoutMs`** — optional per docs, required by the validator. Single-line insertion in the CODE REVIEW PHASE of skills/implement/SKILL.md, after the existing "Both analyze that supplied diff." sentence. No code changes.
All three hit live in the 2026-08-30 karl-marx-bot WP #432 run:
- a diff inlined in a raw template literal dies on bash ${..}/backticks;
  JSON-encode (jq -Rs .) and pass via workflowScriptPath instead
- read-only reviewer agents reject implementation-sounding task phrasing
- runs.host requires an explicit integer timeoutMs
First-time contributor

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

⏱️ Estimated effort to review: 1 🔵⚪⚪⚪⚪
🧪 No relevant tests
🔒 No security concerns identified
⚡ No major issues detected
## PR Reviewer Guide 🔍 Here are some key observations to aid the review process: <table> <tr><td>⏱️&nbsp;<strong>Estimated effort to review</strong>: 1 🔵⚪⚪⚪⚪</td></tr> <tr><td>🧪&nbsp;<strong>No relevant tests</strong></td></tr> <tr><td>🔒&nbsp;<strong>No security concerns identified</strong></td></tr> <tr><td>⚡&nbsp;<strong>No major issues detected</strong></td></tr> </table>
First-time contributor

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

⏱️ Estimated effort to review: 1 🔵⚪⚪⚪⚪
🧪 No relevant tests
🔒 No security concerns identified
⚡ No major issues detected
## PR Reviewer Guide 🔍 Here are some key observations to aid the review process: <table> <tr><td>⏱️&nbsp;<strong>Estimated effort to review</strong>: 1 🔵⚪⚪⚪⚪</td></tr> <tr><td>🧪&nbsp;<strong>No relevant tests</strong></td></tr> <tr><td>🔒&nbsp;<strong>No security concerns identified</strong></td></tr> <tr><td>⚡&nbsp;<strong>No major issues detected</strong></td></tr> </table>
First-time contributor

PR Code Suggestions ✨

No code suggestions found for the PR.

## PR Code Suggestions ✨ No code suggestions found for the PR.
First-time contributor

PR Code Suggestions ✨

No code suggestions found for the PR.

## PR Code Suggestions ✨ No code suggestions found for the PR.
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin reflex/implement-workflowscript-gotchas:reflex/implement-workflowscript-gotchas
git switch reflex/implement-workflowscript-gotchas

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff reflex/implement-workflowscript-gotchas
git switch reflex/implement-workflowscript-gotchas
git rebase main
git switch main
git merge --ff-only reflex/implement-workflowscript-gotchas
git switch reflex/implement-workflowscript-gotchas
git rebase main
git switch main
git merge --no-ff reflex/implement-workflowscript-gotchas
git switch main
git merge --squash reflex/implement-workflowscript-gotchas
git switch main
git merge --ff-only reflex/implement-workflowscript-gotchas
git switch main
git merge reflex/implement-workflowscript-gotchas
git push origin main
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
rimskij/keystone-pi!3
No description provided.