akm docs

Audit of v8 §11 findings cross-reference

Spec: /home/user/akm/docs/architecture/specs/task-workflow-format-unification.md (v8) Baseline: claude/akm-markdown-tasks-history-75l6du @ current HEAD (d8095a0) Consolidated findings: scratchpad/review-consolidated.md

Method: for each finding, located v8's claimed resolution via §11's table, read the referenced section in full, and where v8 makes a factual claim about current code (to justify the design), re-verified that claim by reading the cited file/lines directly. Flagged anything that only restates the finding, that is logically incomplete relative to the finding's actual scope, or that conflicts with another part of v8 or with a documented architectural decision elsewhere in the codebase.

Verified genuinely resolved (design-level; spec, not code, so "resolved" = coherent design that actually addresses the mechanism, not just names it)

Problems found

C5 | contradicts | v8 §5.6 proposes a new persisted per-bundle trust grant (bundles.<name>.allowScriptExecution, settable via akm setup/akm config set) to unlock third-party script execution — but src/core/activation-policy.ts explicitly documents a 2026-07-14 decision that the "installation is not activation" work "ships no new trust / approval / security machinery: no labeling, action clamps, confirm prompts, digests, trust records, or persisted workspace_bindings," and the existing analogous tools: provenance ceiling (show.ts:433-445) has no override at all — it unconditionally strips toolPolicy for non-primary-stash assets. v8's claimed "same ceiling philosophy" is therefore inaccurate: the tools: ceiling is a hard, ungrantable ceiling, while the new mechanism is an invertible, persisted, named per-bundle opt-in — a materially bigger and different kind of security surface than the finding's own comparison implies, and one that runs directly against a decision already on record in the codebase.

M13 | partial | v8's §11 row points only to "§3 (improve excluded from task bodies)," which resolves the improve-pipeline half of the finding, but the finding's other half — "the akm adapter special-cases type:'task' as pure YAML so markdown checks never fire" (akm-adapter.ts:404-412, confirmed: parsed = { data, content: raw, frontmatter: null } for type==="task", explicitly to suppress missing-updated) — is never revisited. v8's own §3 examples give tasks substantial free-form prose bodies that are now the literal executable prompt, but no change to the lint/OKF parse path is proposed to give that prose the same base-check coverage other markdown assets get (frontmatter-shaped checks like unquoted-colon/missing-updated still never fire on tasks); only stale-path/missing-ref (body-scoped, frontmatter-independent) survive.

M9 | partial | §5.7's fix ("PATH prepend... replacing the argv-rewrite that shell text would defeat") glosses over why resolveNestedAkmCommand was built as an argv splice in the first place: resolveAkmInvocation() (resolve-akm-bin.ts) can return a multi-element invocation (e.g. a node/bun launcher + script path), not always a single standalone binary. A bare PATH prepend only works when there is one real executable file to point PATH at; the multi-arg-launcher case needs a synthesized shim (a generated akm script that re-invokes node <path>), which is materially more than "PATH prepend" and isn't mentioned.

Minor findings with no resolution anywhere in v8 (contradicts §11's blanket "all resolved or explicitly costed" claim and the Minors row's non-exhaustive listing):

Notes on things that check out but are worth flagging as "costed, not fixed" (v8 is honest about these, no complaint)