Skip to content

[NO-TICKET] Say what the package is at the top of AGENT-INSTALL.md, and fix four inaccuracies - #353

Merged
mariojgt merged 2 commits into
mainfrom
feather/d4a2ca16
Oct 2, 2026
Merged

mariojgt merged 2 commits into
mainfrom
feather/d4a2ca16

Conversation

@mariojgt

@mariojgt mariojgt commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

No ticket.

What changed

AGENT-INSTALL.md now opens with a short What this package is section: an npm package for JS/Node projects (not a WordPress plugin), MIT-licensed with its source on GitHub, published from GitHub Actions with npm provenance, how to check that with npm view and npm audit signatures, and a short summary of what it does, with a link to the command reference. The summary names the runtime guard (protect) and says that setup and the prebuild hook upload a structural map of the server, never source text or environment values, while map run on its own sends nothing without --upload.

Four smaller corrections in the same file, and one in the CLI:

  • The login troubleshooting table said CI takes its credential from PATCHSTACK_PULSE_AUTH. The Rules section and the CLI help both say PATCHSTACK_API_KEY, and PATCHSTACK_PULSE_AUTH is only for a separate ingest credential. The table now says PATCHSTACK_API_KEY. The CLI's "cannot run in CI" message in src/cli.ts said the same wrong thing and is aligned too.
  • The mark-build output folders in "Package and command behavior" were missing _site/, which BUILD_DIR_CANDIDATES includes.
  • "Verifying the install" said "the button appears" on the deployed site. An unclaimed site shows the "Connect this website" panel, so it now says "the widget appears".
  • The prebuild line in the manual package.json example was indented wrong.

Why

AI coding tools have described this package as a WordPress plugin, or said it does not exist on npm. The facts that answer both were already in the doc, but at lines 89 and 107, after the setup steps. An agent auditing the tarball now reads who publishes it, where the source is, how to verify it, and what it does before any instruction to run something. The two old lines are removed so the facts are not stated twice. No reassurance wording is added.

The other fixes matter for the same reason: agents compare this doc with dist/, and every mismatch costs trust.

Verified

  • npm run typecheck: passes, including the template typecheck.
  • npm test, after merging current main: 4275 passed, 7 skipped, 1 failed. The failure is multipart-field-names.test.ts › grows linearly with the size of a part, a timing test that fails under full-suite load. It passes 22/22 in three isolated runs, and this PR does not touch the parser.
  • npm run build and npm run capabilities:check: capabilities.json is up to date, with no vocabulary change.

Outstanding gate

This file ships in the tarball, and the field-test fixture installs the published package, so a run before release would check the previous text. Run this immediately after the release that carries this change:

node field-test/run.mjs --persona hostile --rounds 3
node field-test/run.mjs --persona standard --rounds 3

standard is the better check of doc accuracy. Until those runs, the disclosure tests and capabilities:check are what stand behind the change.

Out of scope, worth a follow-up

This does not help with a refusal that happens before install. An agent that refuses at that point never reads this file, and the full install prompt is what addresses it. A field-test persona for that kind of refusal on a hosted AI builder belongs in its own PR.

Docs: this is the docs change. README.md, GETTING-STARTED.md and the install prompt are untouched.

🤖 Generated with Claude Code

…nd fix four inaccuracies

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@mariojgt

mariojgt commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

/review

@coderbuds

coderbuds Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Clarifies package description and fixes credential environment variable names.

🎯 Quality: 98% Elite · 📦 Size: Small

🤖 Authorship: Agent-written — Claude Code, going by its own attribution. Whether a person read it is unknown; coding agents can call the report-ai-usage tool to say.

📈 This month: Your 172nd PR — above team average · Averaging Excellent

See how your team is trending →

Resolve AGENT-INSTALL.md against setup's map upload: keep main's scan and
setup wording, drop the package line now stated in the intro, keep the
_site/ and indentation fixes, and say in the intro that setup and the
prebuild hook upload the structural map.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@mariojgt
mariojgt merged commit b07eaff into main Oct 2, 2026
23 checks passed
@mariojgt
mariojgt deleted the feather/d4a2ca16 branch October 2, 2026 09:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants