Skip to content

feat(trace): capture specs during the whole session - #3524

Merged
migmartri merged 3 commits into
mainfrom
issue-3515-spec-capture-during-session-impl
Oct 5, 2026
Merged

migmartri merged 3 commits into
mainfrom
issue-3515-spec-capture-during-session-impl

Conversation

@migmartri

@migmartri migmartri commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

This PR implements Spec 003. The spec changes the spec capture of Spec 002.

Summary

  • R-001: The session-start instruction tells the agent not to capture the user's request prompt. The transcript already holds it. A spec that the user pastes is still a spec. An approved plan is kind text. The agent does not capture a pasted image (D-009).
  • R-002 and R-003: A new user-prompt-submit hook gives the agent a short reminder at each user prompt. The reminder names the session folder and covers four cases only: a new spec, an image file or URL, an approved plan, and a changed spec.
    • Claude Code gets the reminder through a new UserPromptSubmit hook.
    • OpenCode gets it through a chat.message hook in the plugin. The plugin posts it as a context-only message.
    • Cursor gets no reminder (D-008). Cursor has no channel for it, so it now gets the full instruction at each session start, also on resume.
  • R-004: A push records at most 25 spec files. After each push, the trace state keeps the names of the files that the push recorded. The next push puts these files first, so the limit never drops them. This is also true when the agent overwrote a file. New files fill the remaining places, oldest first.

Existing installs must run chainloop trace init again to get the new Claude Code hook and the updated OpenCode plugin.

Refs #3515

AI disclosure: Claude Code helped write this change.

🤖 Posted by Maximus bot (Claude Code) on behalf of @migmartri

Review in cubic

@chainloop-platform

chainloop-platform Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

AI Session Checks — 🟢 88% · ⚠️ 1 failing

Avg score Sessions Failing policies Attribution Files Lines Total Duration
🟢 88% 1 ⚠️ 1 100% AI / 0% Human 27 +1051 / -174 3h53m54s

🟢 88% — 100% AI — ⚠️ 1 policies failing

Oct 5, 2026 12:06 UTC · 3h53m54s · $21.21 · 542 in / 228.6k out · claude-code 2.1.289 (claude-opus-5-5)

View session details ↗

Change Summary

  • Adds Spec 003 session-capture behavior: no prompt capture, per-prompt reminders, and 25-file push retention.
  • Extends trace hooks, provider support, plugin templates, and persisted state for those session rules.
  • Folds in reviewer fixes, resolves rebase fallout, and defers the repository prompt-submit hook until a later release.

AI Session Overall Score

🟢 88% — Spec-driven trace work shipped cleanly; only planning depth lagged the task size.

AI Session Analysis Breakdown

🟢 93% · user-trust-signal

🟢 User kept delegating follow-up work without sharp corrections or restarts. · High Impact

🟢 92% · solution-quality

🟢 AI removed the misbehaving prompt hook instead of normalizing broken output. · High Impact

🟢 90% · alignment

No notes.

🟢 89% · verification

🟢 AI repeatedly ran targeted and full Go suites, plus build and vet, before shipping. · High Impact

🟢 88% · scope-discipline

No notes.

🟡 65% · context-and-planning

🟠 The spec was strong, but the AI still executed a wide implementation without a visible plan or TODO. · Medium Severity

💡 For spec-sized changes, write a short ordered plan before editing so tradeoffs and sequencing stay visible.


File Attribution

████████████████████ 100% AI / 0% Human

Status Attribution File Lines
modified ai app/cli/pkg/action/trace_spec_test.go +177 / -5
modified ai app/cli/internal/trace/state/state.go +106 / -30
modified ai app/cli/pkg/action/trace_spec.go +99 / -27
modified ai app/cli/internal/trace/spec/spec_test.go +67 / -10
modified ai app/cli/internal/trace/state/state_test.go +67 / -8
modified ai app/cli/pkg/action/trace_agent_hook_test.go +64 / -0
modified ai app/cli/internal/trace/spec/spec.go +43 / -16
modified ai .opencode/plugins/chainloop-trace.ts +38 / -7
modified ai app/cli/internal/trace/opencode/hooks.go +36 / -7
modified ai app/cli/internal/trace/opencode/testdata/plugin_full.ts +34 / -7
modified ai app/cli/internal/trace/claude/announce_test.go +40 / -0
modified ai app/cli/internal/trace/opencode/testdata/plugin_tracerun.ts +33 / -7
modified ai app/cli/pkg/action/trace_hook_handler.go +18 / -17
modified ai app/cli/internal/trace/opencode/announce_test.go +33 / -0
modified ai app/cli/pkg/action/trace_agent_hook.go +32 / -1
modified ai app/cli/cmd/trace_hook.go +32 / -0
modified ai app/cli/internal/trace/claude/provider.go +32 / -0
modified ai app/cli/internal/trace/opencode/provider.go +21 / -0
modified ai .claude/settings.json +10 / -10
modified ai app/cli/pkg/action/trace_spec_materials.go +8 / -9
modified ai app/cli/pkg/action/trace_spec_materials_test.go +9 / -7
modified ai app/cli/internal/trace/cursor/provider.go +13 / -0
modified ai app/cli/internal/trace/providers/capabilities_test.go +8 / -3
modified ai app/cli/internal/trace/cursor/announce_test.go +10 / -0
modified ai app/cli/internal/trace/provider.go +10 / -0

…and 2 more file(s).


Policies (4, 1 failing)

Status Policy Material Messages
✅ Passed ai-config-ai-agents-allowed ai-coding-session-d09416 -
✅ Passed ai-config-no-dangerous-commands ai-coding-session-d09416 -
⚠️ Failed ai-config-no-secrets ai-coding-session-d09416 Secret (generic-password) detected in session content [turn=1028, source=tool_result, line=22]: INF redacted secrets from the AI coding session before upload count=10 rules=["generic-[REDACTED:generic-password]"]
✅ Passed ai-config-mcp-servers-allowed ai-coding-session-d09416 -

Security Checks — ✅ 5 passing

✅ secret-scan

Status Policy Messages
✅ Passed secrets-detection -

✅ sast-scan

Status Policy Messages
✅ Passed owasp-top10-2025 -
✅ Passed sast -
✅ Passed cwe-top25 -
✅ Passed cwe-top26-40-cusp -

security-context — 6 advisories

This change touches code with a recorded security-fix history. These are pointers to what past fixes established, not findings in this diff, and they never fail the check.

View security context ↗ · Security context documentation ↗

⏭️ 3 scans not applied

Scan Reason
vulnerability-scan no manifest/lockfile changed
github-actions-scan no workflow files changed
iac-scan no IaC files changed

View attestation ↗


PR validation — ✅ 3 passing

Status Policy Material Messages
✅ Passed pr-min-approvals pr-info -
✅ Passed pr-description-required pr-info -
✅ Passed pr-user-story-linked pr-info -

View attestation ↗


Powered by Chainloop and Chainloop Trace

@migmartri
migmartri requested a review from a team October 5, 2026 12:45

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 24 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread app/cli/internal/trace/spec/spec_test.go
Comment thread app/cli/internal/trace/state/state_test.go Outdated
Comment thread app/cli/pkg/action/trace_spec.go Outdated
Comment thread app/cli/pkg/action/trace_spec.go Outdated
Comment thread app/cli/internal/trace/spec/spec.go
Comment thread app/cli/pkg/action/trace_hook_handler.go Outdated
Comment thread app/cli/internal/trace/state/state.go Outdated
Comment thread app/cli/internal/trace/claude/hooks_test.go
Comment thread app/cli/internal/trace/opencode/hooks.go
Comment thread app/cli/internal/trace/claude/hooks.go
jiparis
jiparis previously approved these changes Oct 5, 2026
The agent no longer captures the user's request prompt as a spec. A short reminder at each user prompt tells the agent to capture a new spec, an image file, an approved plan, or a changed spec. A push now records up to 25 spec files, and never drops a file that an earlier push of the session recorded.

Implements Spec 003 (R-001 to R-004).

Refs #3515

Assisted-by: Claude Code
Signed-off-by: Miguel Martinez Trivino <miguel@chainloop.dev>

Chainloop-Trace-Sessions: d0941607-e92a-4e3c-9fff-a789d3ef9056
A push now keeps the names of the spec files it stored, not of all the files it read. Each push replaces the list, so the list holds at most 25 names. The list is written in one atomic step.

The reminder tells the agent to copy an image file with no frontmatter. The opencode plugin drops a deleted subagent session from its set. The repository's Claude Code settings install the prompt-submit hook.

Assisted-by: Claude Code
Signed-off-by: Miguel Martinez Trivino <miguel@chainloop.dev>

Chainloop-Trace-Sessions: d0941607-e92a-4e3c-9fff-a789d3ef9056
@migmartri
migmartri force-pushed the issue-3515-spec-capture-during-session-impl branch from 0967a5c to 758ddbc Compare October 5, 2026 15:58
A chainloop binary older than this change has no user-prompt-submit command. It prints its help text and exits with success, and Claude Code then adds that help text to the context at each prompt. Add the hook to the settings after the next release.

Assisted-by: Claude Code
Signed-off-by: Miguel Martinez Trivino <miguel@chainloop.dev>

Chainloop-Trace-Sessions: d0941607-e92a-4e3c-9fff-a789d3ef9056
@migmartri

Copy link
Copy Markdown
Member Author

@jiparis please review

@jiparis jiparis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks!

@migmartri
migmartri merged commit d8f7a4e into main Oct 5, 2026
16 of 17 checks passed
@migmartri
migmartri deleted the issue-3515-spec-capture-during-session-impl branch October 5, 2026 16:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants