feat(agent-team): wire opt-in intake-checker run-team subcommand

Expose the P5 cross-plane loop only as a manual run-team subcommand
(intake-checker --report PATH [--threshold] [--transport] [--dry-run]),
mirroring how intake-github is exposed. NOT wired into the always-on serve
path: the loop stays opt-in/inert by default.
This commit is contained in:
Adam Moussa 2026-06-18 15:53:18 -04:00
parent 23135c14a6
commit 76ac9c9899

View file

@ -41,6 +41,11 @@ Subcommands (P1 surface):
* ``intake-github`` — poll a repo for labeled open issues and start one pipeline
task per not-yet-ingested issue (one pass). Reads issues + calls the committed
coordinator intake entry only; no CI, OIDC, or git/patch apply. Opt-in/inert.
* ``intake-checker`` — the Plane-1 -> Plane-2 cross-plane loop (P5): read one or
more checker report JSON files / a dir, select CONFIRMED findings at/above a
severity threshold (default ``high``), de-dup, and start one remediation task
per unique finding via the committed coordinator intake entry. Reads local
report JSON only; no CI, OIDC, network, or git/patch apply. Opt-in/inert.
Exit codes: ``0`` success, ``1`` operational failure (e.g. row not found, the
compare-and-set lost the race), ``2`` usage error (argparse).
@ -712,6 +717,44 @@ def _cmd_intake_github(args: argparse.Namespace, *, out: Any) -> int:
return 0
def _cmd_intake_checker(args: argparse.Namespace, *, out: Any) -> int:
"""Read checker reports and start one task per confirmed eligible finding.
The Plane-1 -> Plane-2 cross-plane front door (P5): builds a
:class:`Coordinator` (transport from the lazy factory; ``--dry-run`` posts
nowhere), runs ``setup``, then constructs a
:class:`agent_team.transport.checker_intake.CheckerFindingIntake` and runs
ONE :meth:`~agent_team.transport.checker_intake.CheckerFindingIntake.ingest_reports`
over the report paths. Each ``--report`` may be a checker report JSON file or
a directory of ``*.json`` reports.
OPT-IN and INERT: this only reads local report JSON and calls the committed
coordinator intake entry — no CI, OIDC, git/patch apply, or network. The
severity threshold (default ``high``) and transport come from CLI flags.
De-dup is in-memory per process, so each run is a single pass. Prints the
finding identities ingested on this pass (one per line).
"""
from agent_team.transport.checker_intake import CheckerFindingIntake
coordinator = _build_coordinator(args)
coordinator.setup()
intake = CheckerFindingIntake(
coordinator=coordinator,
threshold=args.threshold,
transport_name=args.transport,
)
ingested = intake.ingest_reports([Path(p) for p in args.report])
for identity in ingested:
print(identity, file=out)
if not ingested:
print(
"checker-intake: no new confirmed at/above-threshold findings to ingest",
file=sys.stderr,
)
return 0
def _cmd_force_resume(args: argparse.Namespace, *, out: Any) -> int:
"""Force-resume a parked task's question (destructive; audit-logged).
@ -982,6 +1025,46 @@ def build_parser() -> argparse.ArgumentParser:
)
p_intake.set_defaults(func=_cmd_intake_github)
p_intake_checker = sub.add_parser(
"intake-checker",
help=(
"read checker reports and start one remediation task per confirmed "
"at/above-threshold finding (P5 cross-plane loop)"
),
)
p_intake_checker.add_argument(
"--report",
required=True,
action="append",
metavar="PATH",
help=(
"checker report JSON file or directory of *.json reports; repeatable "
"to ingest several reports in one pass"
),
)
p_intake_checker.add_argument(
"--threshold",
default="high",
choices=("low", "medium", "high", "critical"),
help=(
"minimum severity a confirmed finding must reach to spawn a task "
"(default: high)"
),
)
p_intake_checker.add_argument(
"--transport",
choices=_TRANSPORT_CHOICES,
default="github",
help="channel for delivering clarifier questions (default: github)",
)
p_intake_checker.add_argument(
"--dry-run",
action="store_true",
dest="dry_run",
help="use a non-posting transport (no token needed; ingest still runs)",
)
p_intake_checker.set_defaults(func=_cmd_intake_checker)
return parser