Use when reviewing UI for accessibility — WCAG 2.2 AA, keyboard nav, focus, ARIA, contrast, screen-reader semantics — even on 'is this a11y-OK?' or 'mach das barrierefrei'.
日本語の概要は準備中です。原文の説明を表示しています。
Use BEFORE planning/coding against a DB schema, API/GraphQL shape, DTO/Model/Entity, or vendor package — read the real source, emit an Evidence Report, stop inventing fields.
インストールする前に、エージェントに与えられる指示の中身を確認できます。
The procedure behind the source-discovery
rule. Hand-off target from think-before-action
when a task touches external or expensive structure. Definitions
(Evidence Report buckets, provenance, trust tiers, the DB-not-in-codebase
boundary, the card-worthiness threshold) live in
evidence-discipline —
read it once; this file is the executable procedure.
Before you plan or code against a structure you have not confirmed this session: a DB schema, an API/GraphQL shape, a DTO/Model/Entity, a vendor package's surface, or any field/endpoint/column/value.
Do NOT use for: trivial edits (rename/typo/format), structure already verified
this session, or when the user supplied the verified structure (gate-skip per
rdp-gate).
discover the real source → Evidence Report (Verified / Assumed / Gaps) → plan → act → verify with the real tool
Scaffold the report cheaply so it never gets skipped:
npx tsx node_modules/@event4u/agent-config/src/scripts/evidence_report.ts git-state # fail-fast: abort if a rebase/merge/cherry-pick is in progress
npx tsx node_modules/@event4u/agent-config/src/scripts/evidence_report.ts init --task "<task>" # writes the gitignored session report
npx tsx node_modules/@event4u/agent-config/src/scripts/evidence_report.ts add --bucket verified --claim "users.email is unique" --source "db/schema/users.sql:23"
Provenance on every item (observed_at / source / version). Within a
session a read is fresh until the file's mtime changes; invalidate all session
reads when git rev-parse HEAD changes; across sessions always re-read.
Resolve name → path fresh each lookup with rg / glob, then read the file
fresh. There is no persistent bootstrap index (a measured rg-latency
problem on a large monorepo is the only thing that would justify one — deferred).
rg -n "class User\b|model User|CREATE TABLE .*users" --type-add 'src:*.{php,ts,js,py,go,rb,sql}' -t src
In-codebase (schema defined by repo migrations / models / ORM / app code,
including schemaless stores the app controls — Mongoose / Prisma / Firestore
rules) → always local & fresh. Dump tables, columns, types, primary/foreign/
unique keys, indexes, relations, and derived filter/sort/group-ability into the
session cache with provenance — framework-neutral (MySQL / Postgres / SQLite;
ORM-agnostic). The migration is intended truth, the live DB is actual;
divergence is a drift signal worth surfacing. Only negative facts graduate to
a committed card (see database for the dump procedure).
Resolve an OpenAPI/Swagger spec or GraphQL introspection from config/task first.
Else run a read-only, idempotent GET probe, reduced with jq — never a full
dump, never a write/stateful call, never prod without permission, secrets-aware
per security-sensitive-stop. A probed
positive shape is trust: low ("Assumed (from card)" if card-sourced) and must
be confirmed against the live surface before use.
Card-worthy = (external package / remote API / DB-not-in-codebase) AND (≥3
distinct methods/fields intended to be used, OR the source exposes >50 methods
and ≥1 is used, OR a prior hallucination on it, OR local types/README are
insufficient) — judged on intended use at discovery (still built before
coding). For a card-worthy dependency named in the task: local-first
(node_modules / vendor/ README + type defs; the installed version is ground
truth), then the net (registry → repo host → homepage). Pin the remote ref to
the installed version — never blind main. Reuse
external-reference-deep-dive +
markitdown; honor source-confidentiality,
untrusted-input-defense, lethal-trifecta-guard. Persist via the
knowledge-card template under agents/knowledge/<source>.md.
Resolve and read the actual class fresh (Step 0). In-codebase → local, no card.
When knowledge.global_sharing.enabled (user-global, default on), a matching
card may exist in the per-user file-first store
(~/.event4u/agent-config/knowledge/), promoted from another project. It is a
lead, never a build input:
trust: durable).evidence_report.ts add --bucket assumed --origin global … and re-confirm it
against the live source this session before use (version skew / schema drift
across projects). Never "Verified" on the global card alone.public/vendor card seen in ≥ 2 distinct repos
triggers a one-tap promotion suggestion (never silent). proprietary cards
are manual-only and never auto-shared. Record sightings via
_lib/knowledge_global_promote.ts record-seen.When the field/endpoint/table you need is not there:
searched and
not_searched (via evidence_report.ts add --bucket gaps --searched … --not-searched …).type: anti-hallucination,
polarity: negative, with actionable + next_step + a revalidate_if
trigger ("an OpenAPI spec / contracts dir is added"). A negative fact is a
current-state fact ("searched X, didn't find X") — not a card-worthiness
decision (that belongs in notes/ADR).scope-control).After acting on discovered structure, verify with the real tool per the
think-before-action matrix — curl /
Playwright / debugger / test runner / DB query. Any Assumed (from card) or
trust: low line used without this-session confirmation is a violation surfaced
post-task. A stale card (installed-version mismatch OR last_verified older than
N days) is lead-only: negative facts + pointers stay usable, positive
structure must be re-confirmed. Green is not a correctness proof — high-risk /
irreversible steps verify regardless.
The Evidence Report (gitignored session cache), three buckets, soft-capped to ~10–20 decision-relevant facts, produced before the plan; plus, where the threshold is met, a thin committed card.
Curated project-intelligence (Class A config digests, Class B observed
conventions, Class C learned lessons) may be loaded to inform where to look and
what convention to expect — but it is read for heuristics only and never
bypasses a fresh structural read. A field/endpoint/column/value is still confirmed
against a live source this session. v2 capture is write-only into gitignored
intake (the agent may suggest a signal, never silently commit); trust and
commit are always human-gated. Full model + the three classes + memory tiers:
project-intelligence.
api_shape_learned / convention_detected events)A confirmed API/GraphQL shape (§B) or an observed coding convention with ≥ 2 supporting locations is worth persisting for the team, distinct from the per-session Evidence Report above. Append to the knowledge intake — never write a tracked page mid-task:
npx tsx node_modules/@event4u/agent-config/src/scripts/emit_knowledge_event.ts --type api_shape_learned \
--endpoint "<path>" --method "<verb>" --request-schema '<json>' --response-schema '<json>'
npx tsx node_modules/@event4u/agent-config/src/scripts/emit_knowledge_event.ts --type convention_detected \
--pattern "<pattern>" --evidence "file:line" --sample-size <N> --scope project
/team-knowledge consolidate turns accumulated events into
agents/knowledge/concepts/ pages as a reviewed batch — see
knowledge-pages.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Use when reviewing UI for accessibility — WCAG 2.2 AA, keyboard nav, focus, ARIA, contrast, screen-reader semantics — even on 'is this a11y-OK?' or 'mach das barrierefrei'.
日本語の概要は準備中です。原文の説明を表示しています。
Use when defining or auditing the activation event — aha-moment selection, retention correlation, falsifiable definition. Triggers on 'what is our aha moment', 'redefine activation'.
日本語の概要は準備中です。原文の説明を表示しています。
Use when capturing an architectural decision — file naming, next ADR number, Status / Context / Decision / Consequences, index regen; fires even without saying 'ADR'.
日本語の概要は準備中です。原文の説明を表示しています。
Adversarial critique — devil's advocate, stress-test, honest teardown ('poke holes', 'be brutal', 'was hältst du davon'); explicit request only. Routine code or design review → code-review.
日本語の概要は準備中です。原文の説明を表示しています。
Use when reading, creating, or updating agent documentation, module docs, roadmaps, or AGENTS.md. Understands the full .augment/, agents/, and copilot-instructions structure.
日本語の概要は準備中です。原文の説明を表示しています。
Use for an adversarial red-team / blue-team / auditor review of an AI agent's CONFIG + behaviour (rules, skills, MCP, hooks, permissions) — attack-chain → defensive-gap list, not a code audit.
日本語の概要は準備中です。原文の説明を表示しています。