feat(trace): capture specs during the whole session - #3524
Conversation
AI Session Checks — 🟢 88% ·
|
| Avg score | Sessions | Failing policies | Attribution | Files | Lines | Total Duration |
|---|---|---|---|---|---|---|
| 🟢 88% | 1 | 100% AI / 0% Human | 27 | +1051 / -174 | 3h53m54s |
🟢 88% — 100% AI — ⚠️ 1 policies failing
-
Oct 5, 2026 12:06 UTC · 3h53m54s · $21.21 · 542 in / 228.6k out · claude-code 2.1.289 (claude-opus-5-5)
Change Summary
-
- Adds Spec 003 session-capture behavior: no prompt capture, per-prompt reminders, and 25-file push retention.
- Extends trace hooks, provider support, plugin templates, and persisted state for those session rules.
- Folds in reviewer fixes, resolves rebase fallout, and defers the repository prompt-submit hook until a later release.
AI Session Overall Score
-
🟢 88% — Spec-driven trace work shipped cleanly; only planning depth lagged the task size.
AI Session Analysis Breakdown
-
🟢 93% · user-trust-signal
-
🟢 User kept delegating follow-up work without sharp corrections or restarts. · High Impact
🟢 92% · solution-quality
-
🟢 AI removed the misbehaving prompt hook instead of normalizing broken output. · High Impact
🟢 90% · alignment
-
No notes.
🟢 89% · verification
-
🟢 AI repeatedly ran targeted and full Go suites, plus build and vet, before shipping. · High Impact
🟢 88% · scope-discipline
-
No notes.
🟡 65% · context-and-planning
-
🟠 The spec was strong, but the AI still executed a wide implementation without a visible plan or TODO. · Medium Severity
💡 For spec-sized changes, write a short ordered plan before editing so tradeoffs and sequencing stay visible.
-
File Attribution
████████████████████100% AI / 0% Human…and 2 more file(s).
Policies (4, 1 failing)
Status Policy Material Messages ✅ Passed ai-config-ai-agents-allowedai-coding-session-d09416- ✅ Passed ai-config-no-dangerous-commandsai-coding-session-d09416- ⚠️ Failedai-config-no-secretsai-coding-session-d09416Secret (generic-password) detected in session content [turn=1028, source=tool_result, line=22]: INF redacted secrets from the AI coding session before upload count=10 rules=["generic-[REDACTED:generic-password]"] ✅ Passed ai-config-mcp-servers-allowedai-coding-session-d09416- -
Security Checks — ✅ 5 passing
✅ secret-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | secrets-detection |
- |
✅ sast-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | owasp-top10-2025 |
- |
| ✅ Passed | sast |
- |
| ✅ Passed | cwe-top25 |
- |
| ✅ Passed | cwe-top26-40-cusp |
- |
security-context — 6 advisories
This change touches code with a recorded security-fix history. These are pointers to what past fixes established, not findings in this diff, and they never fail the check.
View security context ↗ · Security context documentation ↗
⏭️ 3 scans not applied
| Scan | Reason |
|---|---|
vulnerability-scan |
no manifest/lockfile changed |
github-actions-scan |
no workflow files changed |
iac-scan |
no IaC files changed |
PR validation — ✅ 3 passing
| Status | Policy | Material | Messages |
|---|---|---|---|
| ✅ Passed | pr-min-approvals |
pr-info |
- |
| ✅ Passed | pr-description-required |
pr-info |
- |
| ✅ Passed | pr-user-story-linked |
pr-info |
- |
Powered by Chainloop and Chainloop Trace
There was a problem hiding this comment.
All reported issues were addressed across 24 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
The agent no longer captures the user's request prompt as a spec. A short reminder at each user prompt tells the agent to capture a new spec, an image file, an approved plan, or a changed spec. A push now records up to 25 spec files, and never drops a file that an earlier push of the session recorded. Implements Spec 003 (R-001 to R-004). Refs #3515 Assisted-by: Claude Code Signed-off-by: Miguel Martinez Trivino <miguel@chainloop.dev> Chainloop-Trace-Sessions: d0941607-e92a-4e3c-9fff-a789d3ef9056
A push now keeps the names of the spec files it stored, not of all the files it read. Each push replaces the list, so the list holds at most 25 names. The list is written in one atomic step. The reminder tells the agent to copy an image file with no frontmatter. The opencode plugin drops a deleted subagent session from its set. The repository's Claude Code settings install the prompt-submit hook. Assisted-by: Claude Code Signed-off-by: Miguel Martinez Trivino <miguel@chainloop.dev> Chainloop-Trace-Sessions: d0941607-e92a-4e3c-9fff-a789d3ef9056
0967a5c to
758ddbc
Compare
A chainloop binary older than this change has no user-prompt-submit command. It prints its help text and exits with success, and Claude Code then adds that help text to the context at each prompt. Add the hook to the settings after the next release. Assisted-by: Claude Code Signed-off-by: Miguel Martinez Trivino <miguel@chainloop.dev> Chainloop-Trace-Sessions: d0941607-e92a-4e3c-9fff-a789d3ef9056
|
@jiparis please review |
This PR implements Spec 003. The spec changes the spec capture of Spec 002.
Summary
text. The agent does not capture a pasted image (D-009).user-prompt-submithook gives the agent a short reminder at each user prompt. The reminder names the session folder and covers four cases only: a new spec, an image file or URL, an approved plan, and a changed spec.UserPromptSubmithook.chat.messagehook in the plugin. The plugin posts it as a context-only message.Existing installs must run
chainloop trace initagain to get the new Claude Code hook and the updated OpenCode plugin.Refs #3515
AI disclosure: Claude Code helped write this change.
🤖 Posted by Maximus bot (Claude Code) on behalf of @migmartri