docs(skill): wire scope ingestion, audit trail & pattern recall into SKILL.md#22
Merged
Merged
Conversation
…to SKILL.md The new capabilities shipped as importable modules but SKILL.md — the doc that drives a Hermes agent — never referenced them, so the agent wouldn't reach for them. Document them in the existing methodology: - Scope check now shows HackerOneClient.scope_guard() (authoritative scope) and attaches an AuditLog so every request's scope decision is recorded. - Memory discipline gains a "pattern memory" step: recall past wins via suggest_methodology (source="pattern") before crafting an approach, and record_pattern after confirming a finding. Doc-only; no code change. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The new capabilities (HackerOne scope ingestion, scope-compliance audit trail, write-back pattern recall) shipped as importable modules, but SKILL.md — the doc a Hermes agent is driven by — never referenced them, so the agent wouldn't reach for them after
install.sh. This closes that gap.Changes (doc-only)
HackerOneClient().scope_guard("program")for authoritative scope and attaches anAuditLog, withAuditLog().summary()as in-bounds proof.suggest_methodology(...)(entries taggedsource="pattern") before crafting an approach, andrecord_pattern(...)after confirming a finding.No code change, so
install.sh→pip install -e .still exposes the modules exactly as before; now the skill doc tells the agent to use them. (.claude/commands remain the Claude Code-native path; this makes the capabilities reachable under Hermes too.)🤖 Generated with Claude Code