← Files Repo ScoutARCHIVED FILE
skills/repo-scout/references/ai-agents.md
1.63 KB · Oct 5, 2026 · 18:33 UTC
# AI agents, MCP, skills and model-integrated systems Map model/provider configuration, tool registry, prompts, retrieval, persistent memory, sessions, checkpoints, delegation and approval boundaries. Distinguish a model's capability from what the current harness actually exposes or enforces. Inspect tool input validation, least privilege, tenant/session isolation, prompt injection boundaries, secret redaction, replay/duplicate actions, idempotency, termination, bounded retries, cancellation, timeout propagation and budget controls. Check schema/version drift between tool definitions, clients and runtime behavior. Do not treat a tool description saying read-only as enforcement if its code can write. For multi-agent work inspect handoff contracts, provenance, task ownership, shared filesystem collisions and independent verification. Two agents agreeing is not runtime evidence. A prompt saying spawn workers does not implement concurrency. Evaluate fallback behavior when a provider, subagent, connector or tool is absent. For skills inspect trigger precision, prompt length/loading, relative file paths, platform assumptions, allowed operations and expected outputs. Use positive, negative, ambiguous, clean-repo and adversarial fixtures. Measure false findings, missed seeded defects, ungrounded success claims, tool misuse and cost—not output volume. Model-generated test plans are not completed evaluations. For scheduled work require explicit enablement, bounded scope, overlap prevention, a run ledger, stale-result detection, failure reporting and publication gates. Never silently turn a one-time code review into a persistent background worker.
SHA-256: 2715856f5af2978211c2760682554564bcbe6cd991440f653b169003e12363f8