| name | repo-auditor-owner-settlement |
| description | Deliver one authorized repo-auditor owner change through cached-index validation, read-only real use, exact-head review, GitHub checks, and live readback. |
Repo-Auditor Owner Settlement
Use this as the single lifecycle route for changes to repo-auditor. Detection,
audit, scoring, and pre-scan skills remain domain behavior; this route settles
the repository change that carries that behavior.
Establish the owner agreement
- Read
CONSTITUTION.md, AGENTS.md, the current owner issue, and the exact
current base.
- Inspect live GitHub overlap, branch protection, required checks, reviews, and
direct callers. Current owner evidence outranks plans, memory, and retained
reports.
- Name the outcome, acceptance evidence, allowed effects, forbidden effects,
and consequential approval boundary. Do not create a plan artifact in place
of delivery.
- Pause only for a material authority conflict, destructive ambiguity,
credential/privacy boundary, target mutation request, or changed owner
outcome.
Implement
- Preserve unrelated changes and target-repository read-only behavior.
- Prefer deletion of obsolete local machinery and the smallest coherent
native implementation.
- Preserve detection signatures, finding/schema semantics, deterministic
fixtures, bounded scans, recovery, privacy, and fail-closed behavior.
- Do not introduce a compatibility scaffold, controller, registry, dashboard,
roadmap, execution ledger, updater, scheduler, queue, daemon, background
process, or auto-merge route.
Validate the exact candidate
- Run focused changed-behavior tests.
- Run
make check, make test, make validate, and git diff --check.
- Exercise the auditor against a deterministic or bounded read-only target.
Hash the target before and after, and validate the generated findings/report.
- Stage the complete diff and run
make review. Repair CRITICAL and HIGH
findings. Record and disposition MEDIUM and LOW advice.
- If a repair changes the head, repeat exact-head validation and review.
Settle on GitHub
- Use one owner issue, branch, preserved worktree, and pull request.
- Require
Pre-commit gate, Schema validation, and Test suite on the exact
head plus any requested review.
- Merge only with explicit owner authority and only when no configured,
requested, or ambient reviewer remains queued or active.
- Read back issue closure, pull-request merge identity, default-branch
identity, checks, reviews/threads, changed-file identity, and remote branch
state. Never prune worktrees.
Claims and recovery
- Recover by ordinary Git revert of the owner commit; do not add an active
rollback control plane.
- One successful settlement proves only that bounded episode, not recurring
reliability, lower lifetime burden, downstream adoption, or autonomy.
- Report the achieved outcome, incomplete work or residual risk, and the next
action with its reason.