Skip to content

V4: Output redaction on Claude Code #5

Description

@afogel

Master doc: docs/shaping/acs-reference-impl-slices.md §V4 — authoritative for this slice's scope.

Demo: AGT's own package documents that Claude Code cannot reliably redact tool output. Here it is, redacted, by AGT's stock redact policy — in the tool's own output shape, which is the condition that makes it reliable.

Blocked by: #4
Plan: docs/superpowers/plans/2026-08-11-v4-output-redaction.md

Amendments

  • F1 resolved by hand against Claude Code 2.1.227; risk row 1 retired, R3.8 confirmed, six corrections and two new risk rows recorded in §V4 — c09c0a5
  • Plan revised for what the review redistribution landed underneath it: four of its assumptions invalidated, three of which had it naming symbols and a rule shape that never shipped — 118c335
  • N23 names both assemblers; §V4's "a post_tool_call branch" corrected to the sibling ruling PR V1: One host, one hook, a real AGT decision #10's review had already made — b32474c
  • N3 gains the hook parameter; N24 names both modification shapes; N7 says what it applies modifications to and what else it refuses — 3b7cc45, 3c392af, 4281e38, 810ef3d
  • An audit entry can outlive the decision it claims: measured outcome: "proceeded" for a step the shim then blocked. Recorded in §V4 and R1.7's Fit Check; repair belongs to the audit sink's contract, not V4 — 60db609
  • Two claims the landing check does not support, narrowed and both holes filed — 72b7d29
  • The per-modification landing check parked to V5, recorded on both ends, with the note that only the result-gate half is pinned and the unpinned half is the one V5 inherits — b7e1e19, b50b893
  • R4.4 breach fixed: the demo sentence had dropped "reliably" in four places, the exact overclaim R4.4 exists to prevent. Recorded as C9 — ed7ce3e
  • N28/N5/S13 name the fields the handshake actually carries (profiles_accepted never shipped; methods_evaluated was omitted), and the payload-lacks-the-leaf hazard is filed in §V4 — f485a9c

Landed: 495 pass / 1 skip / 0 fail (496 tests, 32 files), typecheck clean, verify:pin 5/0, and git diff -- 'policy/lib/*.rego' empty across the whole slice — R2.1/R2.3 hold as a measured fact. Verified live end to end: a secret-bearing Bash result comes back redacted in the tool's own output shape with every sibling field intact.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    sliceOne vertical slice of a shaped track

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions