typescript-untracked-foreign-agentsmd-injection
Done. Deliverable: ~/SOLUTION-typescript-untracked-foreign-agentsmd-injection.md.
Diagnosis: This is a harness-context flaw, not a normal "delete the file" problem. AGENTS.md discovery for specs/ consults a registry/cache, not only the working tree — so a file that is absent from disk and absent from git ls-files still gets stale foreign content injected (here: DexDat specifications-repo instructions), and the phantom entry is invisible to git status. Deletion is therefore not a durable fix.
Fix (verified in a sandbox clone):
1. Write a project-accurate specs/AGENTS.md describing the actual repo (and do not echo the foreign marker string inside it, or the grep check trips).
2. git add specs/AGENTS.md and commit it — a tracked authoritative file supersedes the stale cache entry and makes any future foreign drift show up in git status/git diff.
3. Restart the agent session (or clear the context cache) so re-injection reads the tracked file, not the cache.
Verification (all pass):
- grep -ri dexdat specs/ → 0
- git ls-files specs/AGENTS.md → specs/AGENTS.md
- test -f specs/AGENTS.md → on-disk present
- Injected-then-reverted edit surfaces in git diff --stat (drift is now visible)
- tree-wide marker scan → 0
This matches the documented durable-fix pattern from mafia MAF-GAP-051 (commit cb06b3a): tracked accurate file, not deletion. It also notes the tier-1 lint/secrets flags were deterministic FPs unrelated to this issue.
# Evidence - Problem class: typescript-untracked-foreign-agentsmd-injection - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-17T00:28:34.821Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "AGENTS.md auto-injection showed FOREIGN project content (DexDat specifications-repo instructions: 'NOT: code implementation', crypto/email security framework) while working under a repo's specs/ subdirectory. The file was NOT in git (git ls-files empty) and, on inspection, NOT on disk at all \u2014 the harness injected stale foreign content from its context registry even with the file absent. Same signature documented on off-by-one and mafia-ai-benchmark. Fix applied (mafia MAF-GAP-051, commit cb06b3a): write a project-accurate specs/AGENTS.md describing the actual project and TRACK it in git \u2014 the harness then injects correct content, and the file's tracked state makes foreign-content drift visible in git status. Verify: grep -ri dexdat specs/ \u2192 0 matches; git ls-files specs/AGENTS.md returns the path.", "environment": "hermes-agent-foreman-tick", "language": "typescript", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "typescript-untracked-foreign-agentsmd-injection", "provider": "openrouter", "solved_at": "2026-08-17T00:28:34.821Z", "version": "2026-08-16"}Done. Deliverable: ~/SOLUTION-typescript-untracked-foreign-agentsmd-injection.md.
Diagnosis: This is a harness-context flaw, not a normal "delete the file" problem. AGENTS.md discovery for specs/ consults a registry/cache, not only the working tree — so a file that is absent from disk and absent from git ls-files still gets stale foreign content injected (here: DexDat specifications-repo instructions), and the phantom entry is invisible to git status. Deletion is therefore not a durable fix.
Fix (verified in a sandbox clone):
1. Write a project-accurate specs/AGENTS.md describing the actual repo (and do not echo the foreign marker string inside it, or the grep check trips).
2. git add specs/AGENTS.md and commit it — a tracked authoritative file supersedes the stale cache entry and makes any future foreign drift show up in git status/git diff.
3. Restart the agent session (or clear the context cache) so re-injection reads the tracked file, not the cache.
Verification (all pass):
- grep -ri dexdat specs/ → 0
- git ls-files specs/AGENTS.md → specs/AGENTS.md
- test -f specs/AGENTS.md → on-disk present
- Injected-then-reverted edit surfaces in git diff --stat (drift is now visible)
- tree-wide marker scan → 0
This matches the documented durable-fix pattern from mafia MAF-GAP-051 (commit cb06b3a): tracked accurate file, not deletion. It also notes the tier-1 lint/secrets flags were deterministic FPs unrelated to this issue.
# Evidence - Problem class: typescript-untracked-foreign-agentsmd-injection - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-17T00:28:34.821Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "AGENTS.md auto-injection showed FOREIGN project content (DexDat specifications-repo instructions: 'NOT: code implementation', crypto/email security framework) while working under a repo's specs/ subdirectory. The file was NOT in git (git ls-files empty) and, on inspection, NOT on disk at all \u2014 the harness injected stale foreign content from its context registry even with the file absent. Same signature documented on off-by-one and mafia-ai-benchmark. Fix applied (mafia MAF-GAP-051, commit cb06b3a): write a project-accurate specs/AGENTS.md describing the actual project and TRACK it in git \u2014 the harness then injects correct content, and the file's tracked state makes foreign-content drift visible in git status. Verify: grep -ri dexdat specs/ \u2192 0 matches; git ls-files specs/AGENTS.md returns the path.", "environment": "hermes-agent-foreman-tick", "language": "typescript", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "typescript-untracked-foreign-agentsmd-injection", "provider": "openrouter", "solved_at": "2026-08-17T00:28:34.821Z", "version": "2026-08-16"}