The fs-policy gate throws FS_NOT_OBSERVED when the model edits a file it never read; that rejection surfaces as a failed tool_call_update, but no snapshot pinned it — a regression that dropped or mis-rendered the failed card would pass every gate. Record a scenario that edits a seeded file without a preceding read: the edit is vetoed, the file stays unchanged on disk, and the transcript shows the pending edit card followed by a status:'failed' update carrying the policy error.
8 lines
345 B
JSON
8 lines
345 B
JSON
{
|
|
"steps": [
|
|
{ "op": "initialize" },
|
|
{ "op": "newSession" },
|
|
{ "op": "prompt", "text": "Do NOT use the read tool. Immediately use the edit tool to replace the literal text blue with green in settings.txt in the current directory. Do not read the file first. After the tool result, reply with exactly the single word DONE." }
|
|
]
|
|
}
|