From 76ac9c98990b5406a4d232588ce19122957d3b82 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Thu, 18 Jun 2026 15:53:18 -0400 Subject: [PATCH] feat(agent-team): wire opt-in intake-checker run-team subcommand Expose the P5 cross-plane loop only as a manual run-team subcommand (intake-checker --report PATH [--threshold] [--transport] [--dry-run]), mirroring how intake-github is exposed. NOT wired into the always-on serve path: the loop stays opt-in/inert by default. --- agent-team/run-team.py | 83 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 83 insertions(+) diff --git a/agent-team/run-team.py b/agent-team/run-team.py index 8d40c7e..120bb18 100644 --- a/agent-team/run-team.py +++ b/agent-team/run-team.py @@ -41,6 +41,11 @@ Subcommands (P1 surface): * ``intake-github`` — poll a repo for labeled open issues and start one pipeline task per not-yet-ingested issue (one pass). Reads issues + calls the committed coordinator intake entry only; no CI, OIDC, or git/patch apply. Opt-in/inert. +* ``intake-checker`` — the Plane-1 -> Plane-2 cross-plane loop (P5): read one or + more checker report JSON files / a dir, select CONFIRMED findings at/above a + severity threshold (default ``high``), de-dup, and start one remediation task + per unique finding via the committed coordinator intake entry. Reads local + report JSON only; no CI, OIDC, network, or git/patch apply. Opt-in/inert. Exit codes: ``0`` success, ``1`` operational failure (e.g. row not found, the compare-and-set lost the race), ``2`` usage error (argparse). @@ -712,6 +717,44 @@ def _cmd_intake_github(args: argparse.Namespace, *, out: Any) -> int: return 0 +def _cmd_intake_checker(args: argparse.Namespace, *, out: Any) -> int: + """Read checker reports and start one task per confirmed eligible finding. + + The Plane-1 -> Plane-2 cross-plane front door (P5): builds a + :class:`Coordinator` (transport from the lazy factory; ``--dry-run`` posts + nowhere), runs ``setup``, then constructs a + :class:`agent_team.transport.checker_intake.CheckerFindingIntake` and runs + ONE :meth:`~agent_team.transport.checker_intake.CheckerFindingIntake.ingest_reports` + over the report paths. Each ``--report`` may be a checker report JSON file or + a directory of ``*.json`` reports. + + OPT-IN and INERT: this only reads local report JSON and calls the committed + coordinator intake entry — no CI, OIDC, git/patch apply, or network. The + severity threshold (default ``high``) and transport come from CLI flags. + De-dup is in-memory per process, so each run is a single pass. Prints the + finding identities ingested on this pass (one per line). + """ + from agent_team.transport.checker_intake import CheckerFindingIntake + + coordinator = _build_coordinator(args) + coordinator.setup() + + intake = CheckerFindingIntake( + coordinator=coordinator, + threshold=args.threshold, + transport_name=args.transport, + ) + ingested = intake.ingest_reports([Path(p) for p in args.report]) + for identity in ingested: + print(identity, file=out) + if not ingested: + print( + "checker-intake: no new confirmed at/above-threshold findings to ingest", + file=sys.stderr, + ) + return 0 + + def _cmd_force_resume(args: argparse.Namespace, *, out: Any) -> int: """Force-resume a parked task's question (destructive; audit-logged). @@ -982,6 +1025,46 @@ def build_parser() -> argparse.ArgumentParser: ) p_intake.set_defaults(func=_cmd_intake_github) + p_intake_checker = sub.add_parser( + "intake-checker", + help=( + "read checker reports and start one remediation task per confirmed " + "at/above-threshold finding (P5 cross-plane loop)" + ), + ) + p_intake_checker.add_argument( + "--report", + required=True, + action="append", + metavar="PATH", + help=( + "checker report JSON file or directory of *.json reports; repeatable " + "to ingest several reports in one pass" + ), + ) + p_intake_checker.add_argument( + "--threshold", + default="high", + choices=("low", "medium", "high", "critical"), + help=( + "minimum severity a confirmed finding must reach to spawn a task " + "(default: high)" + ), + ) + p_intake_checker.add_argument( + "--transport", + choices=_TRANSPORT_CHOICES, + default="github", + help="channel for delivering clarifier questions (default: github)", + ) + p_intake_checker.add_argument( + "--dry-run", + action="store_true", + dest="dry_run", + help="use a non-posting transport (no token needed; ingest still runs)", + ) + p_intake_checker.set_defaults(func=_cmd_intake_checker) + return parser