Skip to content

[NO-TICKET] Tell agents not to rebuild setup by hand on a builder that blocks the CLI - #357

Merged
daniloradovic merged 1 commit into
mainfrom
docs/blocked-builder-no-hand-built-steps
Oct 2, 2026
Merged

daniloradovic merged 1 commit into
mainfrom
docs/blocked-builder-no-hand-built-steps

Conversation

@daniloradovic

Copy link
Copy Markdown
Contributor

No ticket.

What changed

AGENT-INSTALL.md, section When the platform blocks the CLI outright:

  • A new paragraph says that rebuilding setup by hand counts as routing around the block. That means writing a build plugin or script that imitates a Patchstack step, setting window.__PATCHSTACK_PROD__ or window.__PATCHSTACK_ENV__ yourself, or calling the Patchstack API in place of the CLI. It explains why in one sentence.
  • The Add only the Patchstack Connector choice now says: the tag only, with no production marker and no build step.
  • The Rules bullet on permission refusals says the same thing in one line.

field-test/personas/base44.md: the meta block now lists "no build plugin or production marker of its own" among the things a base44 round's report is read for.

Why

The section already says "do not route around the block". In a real session on a hosted builder that blocks the CLI, an agent read that as "don't run the CLI another way". It then installed the package, read its source, and wrote its own Vite plugin. The plugin added window.__PATCHSTACK_PROD__=true to every build, because no environment variable said otherwise, and copied data-patchstack-build="true" from mark-build.

That builder serves the same build at its preview address and at the published one. The widget saw the live-site flag on the preview, treated the preview as the live site, and never showed the "Connect this website" panel. The person could only claim the site by asking the agent for the link.

A marker decided at build time cannot be right on a platform like that. With no marker, the widget works out from the page's address whether it is on a preview or the live site. So the right instruction is: add nothing in the build.

Verified

  • npm test: 4292 passed, 7 skipped. This includes permission-handoff and execution-disclosure, which read AGENT-INSTALL.md.
  • npm run capabilities:check: up to date, no vocabulary change.

Outstanding gate

AGENT-INSTALL.md ships in the tarball. After the release that carries it:

node field-test/run.mjs --persona base44 --rounds 3

Read the reports for any build plugin or hand-set marker in the changed files. As with #354, a red scorecard is expected.

Docs: this is the docs change.

🤖 Generated with Claude Code

… CLI

On a hosted builder that refuses the CLI, an agent can install the
package, read its source, and write its own build plugin that sets the
live-site flag on every build. The builder serves that build at its
preview address too, so the widget reads the preview as the live site
and hides the claim panel from the owner.

Say plainly that build plugins, a hand-set marker and direct API calls
are routing around the block, and that the Connector-only choice is the
tag alone.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderbuds

coderbuds Bot commented Oct 2, 2026

Copy link
Copy Markdown

Documentation clarifies not to bypass the CLI with manual build hacks.

🎯 Quality: 97% Elite · 📦 Size: Small

📈 This month: Your 207th PR — above team average · Averaging Excellent

See how your team is trending →

@daniloradovic

Copy link
Copy Markdown
Contributor Author

/review

@daniloradovic
daniloradovic merged commit 9f4ee39 into main Oct 2, 2026
23 checks passed
@daniloradovic
daniloradovic deleted the docs/blocked-builder-no-hand-built-steps branch October 2, 2026 11:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants