Repository navigation
Design criticism wanted — argue with the contract #14
DivyamTalwar
started this conversation in
Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Orrery makes unusually strong claims about what it enforces. Those claims are worth more when people try hard to break them, so this category exists for exactly that.
The claims most worth attacking:
"The model can never choose where a file is written." Destinations are derived from
(client, scope, workspace)and a fixed filename table; only aworkspacepath crosses the tool boundary. If you can find a code path where a caller influences a target, that is the highest-value bug in the repository."No unenforceable claims." Orrery refuses to store a reasoning-effort setting for a host that cannot bind one, and reports the advisor's read-only guarantee as a mechanism (
os-sandbox,tool-allowlist,frontmatter-flag,prompt-only) rather than a yes. If you think a mechanism is described more strongly than it deserves, say so."Consent is exact." A preview mints a single-use token bound to a digest of the planned content and the observed on-disk state. The README already concedes the honest limit — the token is handed back to the caller, so an unsupervised agent can chain preview into install, and the
destructiveHinthost prompt is the actual human-in-the-loop control. Is that concession sufficient?The routing thesis. Two implementation lanes exist because a bounded edit and a schema migration are not the same work. Ties break toward the deeper lane on a recoverability argument: over-spending reasoning costs latency, under-spending it costs correctness, and only the first is recoverable. Disagree with that asymmetry if you think it is wrong.
What is useful here: a concrete case that breaks a guarantee, a claim that overstates what the code does, a place where the docs and the shipped files disagree, or an argument that a refusal is user-hostile without buying real safety.
Criticising a design decision is explicitly not a conduct issue — see
CODE_OF_CONDUCT.md. The only line is between the work and the person.All reactions