بنقرة واحدة
ca-arbiter
Exit maintainer dev mode — restore orchestration, remove the dev marker, log the exit.
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
القائمة
Exit maintainer dev mode — restore orchestration, remove the dev marker, log the exit.
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
استنادا إلى تصنيف SOC المهني
Maintainer override — suspend orchestration to edit codeArbiter itself. Env-gated (CODEARBITER_DEV=1), entry/exit logged to overrides.log.
The Socratic spec-refinement front of /feature, and the planning front of /sprint. Routed to BEFORE any code — it takes a one-line idea and drives it to an approved, concrete spec with testable acceptance criteria. Four gated phases — frame, refine, write, approve. No implementation and no handoff to tdd until the spec is on disk and approved; each acceptance criterion becomes one tdd Phase 1 obligation.
The only path to a commit. Routed to when the user invokes /commit or otherwise instructs codeArbiter to persist staged changes. Nine gated phases — permission, branch, classification, verification (test/lint/secrets), behavioral proof, diff review, selective stage, message, commit. Nothing reaches version control without clearing every gate; "it looks good" is not authorization.
Optional manual drift audit — report stale provenance-tracked docs (via _provenancelib drift detection across .codearbiter/.provenance/), then per stale doc offer re-scout / re-baseline / defer. Not the daily loop; commit-gate auto-heal owns routine maintenance.
The brownfield back-fill. Routed to by /create-context, and by startup when .codearbiter/CONTEXT.md lacks the <!--INITIALIZED--> body marker but source code exists. Six gated phases — pre-flight, scout dispatch, synthesis, gap interview, write, lock. Reads the existing codebase through parallel scouts, drafts every surviving project-state doc, resolves gaps with the user, and locks the project as initialized.
The banned-primitive gate. Routed to when changed code hashes, signs, encrypts, derives keys, generates security-relevant randomness, configures TLS, or imports a crypto library. Rejects broken primitives, disabled TLS verification, and home-rolled crypto; the approved-primitive list lives in security-controls.md. The auth-crypto-reviewer agent is dispatched as the reviewer.
| name | ca-arbiter |
| description | Exit maintainer dev mode — restore orchestration, remove the dev marker, log the exit. |
| argument-hint | (none) |
The exit door for $ca-dev. No-op if dev mode is not active.
Log exit — append to <project-root>/.codearbiter/overrides.log (append-only, >>):
[ISO-8601 timestamp] | BY: <email> | DEV: exit
Marker — remove <project-root>/.codearbiter/.markers/dev-active.
Resume — re-present the startup state (stage, blocking CONFIRM-NN, in-flight tasks) and
await a slash command. Orchestration, routing, and all gates are back in force.
MUST write the DEV: exit line to overrides.log and remove the dev-active marker before resuming
orchestration — the exit is on the audit trail like the entry. MUST NOT rewrite or truncate
overrides.log — the append-only rule has no dev exception, on entry or exit. If a prior session
ended mid-dev, SessionStart has already appended the synthetic BY: session-cleanup | DEV: exit close
line and cleared the marker (session-start.py, observability-001). In that case MUST NOT write a
second DEV: exit for that orphaned entry — the close is already on the trail.
Session-scoped clearing (#271): SessionStart's synthetic close is now conditional on the marker
plausibly being abandoned rather than owned by a different, still-live session — it will NOT clobber
another concurrently-running session's live /dev marker or write a false DEV: exit for it.
$ca-arbiter remains the ONLY way to cleanly close your OWN /dev session's audit pair; do not
rely on a future SessionStart to do it for you.