agent-team Plane-2: bind P1+P2 to real models, live transport, coordinator #12
No reviewers
Labels
No labels
app
bug
ci
compliance
content
dependencies
docs
documentation
duplicate
enhancement
github_actions
good first issue
help wanted
infra
invalid
javascript
needs-triage
python
question
tests
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/orchestrator#12
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feature/agent-team-plane2-p1-p2"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
Takes the Plane-2 scaffold from deterministic stubs to real model bindings + a live runtime, through P1 (human gate) and P2 (planner + adversarial review loop) of the depth-first track. Pre-deployment: nothing is provisioned or wired to live Slack/CI.
Commits (logical)
feat: P1 clarifier -> real Claude (subscription-OAuth invoker + Claude clarifier callables, fail-safe gate)feat: planner/review/builder/verifier node bindings (GPT-4.1 review, DeepSeek builders inert, ci_gate sole PASS authority) + review_loop hardeningfeat: live Slack transport + Socket Mode listener with owner allowlistfeat: P1/P2 graph wiring + coordinator daemon + run-team start/serve (+ guarded re-delivery CAS)docs: R720 deploy runbook + coordinator systemd unitSecurity review (
/sh-security-review)4 fresh-context detectors + proof-or-kill verifier. Gate: PASS after fixes.
AGENT_TEAM_SLACK_OWNER_IDS) + the open-status CAS as anti-replay.status='open' AND channel_ref IS NULLCAS underBEGIN IMMEDIATE+ rowcount-skip.run.pyconfirmed list-argv (no shell).Residual (non-blocking, follow-ups)
question_idis derivable; mitigated by the allowlist. Optional: mint random ids as defense-in-depth.snapshot_interrupt_turnsto distinguish an unparseable turn.Tests
733 passing, ruff clean. New coverage spans the invoker, clarifier/planner/review/builder/verifier bindings, live transport + listener authz, the P1/P2 graph routing (approve-terminate, loop-to-cap-then-escalate), the coordinator, and the two security regressions.
Not in this PR (gated / later)
/sh-security-review+ the mandatory GPT-4.1 cross-review of the CI/OIDC trust boundary.