Stop workflow executor agents from creating ordinary tasks while preserving explicit self-spawned dependency handling. - Gate task creation by session identity and execution context. - Add self-spawned dependency support, validation, and persistence coverage. - Update agent prompts, tools, documentation, and CLI integration. - Add a published-package changeset. Files changed: .changeset/fn-125-removal.md | 7 +++ docs/agents.md | 2 +- docs/dashboard-guide.md | 2 +- docs/settings-reference.md | 6 +- .../cli/skill/fusion/references/engine-tools.md | 10 ++-- .../extension-task-execution-task-creation.test.ts | 70 ++++++++++++++++++++++ packages/cli/src/extension.ts | 49 +++++++++++++-- .../postgres/store-self-spawned-dep.pg.test.ts | 56 +++++++++++++++++ .../src/__tests__/self-spawned-dependency.test.ts | 18 ++++++ .../__tests__/session-identity-registry.test.ts | 14 ++++- packages/core/src/agents/agent-prompts.ts | 27 ++++----- .../src/agents/task-execution-task-creation.ts | 19 ++++++ packages/core/src/index.ts | 7 +++ packages/core/src/session-identity-registry.ts | 7 +++ packages/core/src/store.ts | 2 + packages/core/src/task-store/errors.ts | 21 +++++++ packages/core/src/task-store/task-update.ts | 10 +++- packages/core/src/task-store/update-task-deps.ts | 12 +++- .../__tests__/ephemeral-task-create-gate.test.ts | 18 +++--- .../src/__tests__/executor-review-verdicts.test.ts | 3 +- packages/engine/src/agent-tools.ts | 4 ++ packages/engine/src/agents/agent-runtime.ts | 2 + .../engine/src/execution/step-session-executor.ts | 15 ++--- .../executor/attempt-executor-verification-fix.ts | 1 + .../engine/src/executor/create-spawn-agent-tool.ts | 1 + .../engine/src/executor/create-task-done-tool.ts | 18 +++++- .../engine/src/executor/create-task-update-tool.ts | 12 +++- .../engine/src/executor/execute-workflow-step.ts | 1 + packages/engine/src/executor/run-implementation.ts | 18 +++--- packages/engine/src/executor/system-prompt.ts | 21 +++---- packages/engine/src/executor/task-add-dep-tool.ts | 14 ++++- packages/engine/src/pi.ts | 15 ++++- 32 files changed, 401 insertions(+), 81 deletions(-) Fusion-Task-Id: FN-125 Fusion-Task-Lineage: da3d69f6-c9cb-45fd-8691-3dfaf7007514 Co-authored-by: Fusion <noreply@runfusion.ai>
20 lines
1.1 KiB
TypeScript
20 lines
1.1 KiB
TypeScript
import type { FusionSessionPrincipal } from "../session-identity-registry.js";
|
|
|
|
/*
|
|
FNXC:TaskExecutionTaskCreation 2026-08-21-23:16:
|
|
FN-125 forbids sessions executing a board task from creating or delegating board
|
|
work. Ephemerality was insufficient because the durable Workflow Executor bypassed
|
|
that policy; this shared contract makes the restriction lane-based and fail-closed.
|
|
*/
|
|
export const TASK_EXECUTION_WITHHELD_TASK_CREATION_TOOLS = ["fn_task_create", "fn_delegate_task"] as const;
|
|
|
|
export function isTaskExecutionSessionPrincipal(principal: FusionSessionPrincipal): boolean {
|
|
if (principal.kind === "operator") return false;
|
|
if (principal.kind === "agent") return principal.identity.taskExecutionSession === true;
|
|
return principal.identities.some((identity) => identity.taskExecutionSession === true);
|
|
}
|
|
|
|
export function taskExecutionTaskCreationRefusalText(toolName: string): string {
|
|
return `${toolName} is unavailable while executing a board task. Record out-of-scope findings as completion recommendations, and implement in-scope work directly in this task.`;
|
|
}
|