refactor(permission): consume structured bash payload

- require @gotgenes/pi-permission-system >=25.3.0 and read the complete local bash command from PromptPermissionDetails.payload instead of session-walking recovery
- remove the @sikongjueluo/pi-permission-shared package
- pass the triggering command unit to handlers via HandlerContext.unit in place of details.command
- add shadow-only AI judge modules for evidence projection, structured verdict requests, and prompt building, with vitest coverage
- record ADR 0004 and mark the ADR 0001 recovery mechanism superseded
- exclude pi-permission-system 25.3.0 from the pnpm minimumReleaseAge guard
This commit is contained in:
2026-08-16 23:08:45 +08:00
parent 6008c9e817
commit 1afcbd3118
29 changed files with 1540 additions and 587 deletions
@@ -1,5 +1,11 @@
# Research: minimal evidence for the AI Bash authorization judge v0.1
> **2026-08-16 update:** The missing-local-command finding below described
> permission-system 24.0.0. Version 25.3 added a required structured prompt
> payload: a local Bash ask carries the complete input as `full command`
> evidence when it differs from the triggering unit. Forwarded 25.3/25.4 asks
> still lack a separately structured child full command. See ADR 0004.
## Question
Does the proposed six-cluster `JudgeRequestV1` contract contain fields that do not help the model decide whether to allow a Bash authorization request?