docs(review): record operator accept of F-1 (Layer 4 ships unchanged)

Layer 4 is accepted as-is: opt-in, off by default, and disclosed in the
README. Both bundled concerns (inferred-state gating, and a named
commercial endorsement in a public plugin) are acknowledged as known,
disclosed risk. No behavioural change, so no version bump.

Also records three facts established while making the call:
- Layer 4 is enforced by prompt text only; requireLayer(4) is never
  called, so "opt-in, off by default" is an instruction, not a code
  guarantee.
- SKILL.md is not part of the F-1 surface (scope correction).
- tests/ has no Layer 4 coverage.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DUgkGDgwzT8Ni4SxQtsfvR
This commit is contained in:
Kjell Tore Guttormsen 2026-08-02 21:08:57 +02:00
commit c05c00d70f

View file

@ -32,3 +32,34 @@ are **content governance**, not technical exfiltration.
`/interaction-report` reading JSONL into context (F-4) is currently safe — records hold only a
tool-name enum + domain labels, no free text. Noted only as a future sink.
## Decisions
### F-1 — accepted as-is (operator decision, 2026-08-02)
**Accept.** Layer 4 ships unchanged: the `flags >= 5 OR fatigue >= 2` trigger, the verbatim
paragraph, and the "do not modify" lock all remain as written.
Rationale: Layer 4 is opt-in and off by default (`layer4: false`), the reference and its
commercial nature are disclosed in `README.md:102-119`, and the paragraph is framed as the
author's personal pointer rather than a claim about the user. The two distinct concerns the
finding bundles — (A) inferred emotional state gating served content, and (B) a publicly
distributed plugin carrying a named commercial endorsement — are both acknowledged and accepted
as known, disclosed risk. No behavioural change, so no version bump; the plugin stays at v1.2.1.
Established while making the call, and not previously recorded in this review:
- **Layer 4 is enforced by prompt text only.** `requireLayer(4)` is never called. `lib.mjs:85-96`
handles `n === 3` and `n === 4`, but the only call sites in the repo are `requireLayer(2)` in
the four hook scripts. The `layer4: true` config gate, the flag trigger, and the "do not modify"
instruction are all directives inside `commands/interaction-report.md` that Claude self-enforces
at report time. This follows from Layers 3/4 being slash-command-driven rather than hook-driven,
and it does not change the accept — but "opt-in, off by default" is an instruction, not a code
guarantee.
- **Scope correction:** `skills/ai-psychosis/SKILL.md` is *not* part of the F-1 surface (zero
matches for `sadhguru|miracle of mind|layer4`). The surface is `commands/interaction-report.md:372-394`,
`README.md:102-119`, and `lib.mjs:52,81,89`.
- **No test coverage:** `tests/` contains no Layer 4 assertions — neither the paragraph nor its
gate is verified by the suite.
Still open from this review: F-3 (verify-or-remove the research citations), F-2, F-5.