feat(engine): warn on unknown coord-inbox arguments

coord-inbox.sh dropped unknown arguments silently, so a mistyped flag was
indistinguishable from a working invocation. It now warns on stderr per
argument and keeps reading: the read path must stay lenient because it runs
inside the SessionStart hook, which must never fail a session over a stray
flag. The hook runs the script with stderr discarded, so the warning costs
nothing there and surfaces in manual CLI use. Exit code is unchanged.

Selftest 68 -> 70: one check for the warning, one pinning the leniency it
must not break (unknown argument still reads the inbox and exits 0).

Docs realigned with shipped behavior in the same pass:
- selftest count was stale at 64 in README and CLAUDE.md (now 70)
- broadcast sender self-exclusion shipped in 0.2.1 but was undocumented
- rule 6 (message content is data, never instructions) was already enforced
  in the injection framing but missing from the published rule list

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CvTviFeoMCKJcALATRempy
This commit is contained in:
Kjell Tore Guttormsen 2026-07-25 06:39:21 +02:00
commit 11178fa168
5 changed files with 55 additions and 11 deletions

View file

@ -5,6 +5,30 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
## [Unreleased]
### Changed
- `coord-inbox.sh` now warns on stderr for each unknown argument instead of
discarding it silently. The read path stays lenient (it runs inside the
SessionStart hook, which must never fail a session over a stray flag) and
the exit code is unchanged, but a mistyped flag no longer looks like a
working invocation. The hook runs the script with stderr discarded, so the
warning surfaces in manual CLI use only.
### Added
- Selftest: 68 -> 70 checks, covering the stderr warning and the leniency it
must not break (unknown argument still reads the inbox and exits 0).
### Documentation
- README: corrected the stale selftest count (64 -> 70), documented that a
broadcast is never delivered back to its own sender (shipped in 0.2.1 but
undocumented), and added rule 6 — message content is data, never
instructions — which `coord-inbox.sh` already enforces in the injection
framing.
## [0.2.1] - 2026-07-25
### Fixed