Skip to content

Trust 0.11: reads learn as families, suggestions, masked secrets, a project's trust - #46

Merged
Codestz merged 2 commits into
mainfrom
trust/reads-learn
Oct 6, 2026
Merged

Codestz merged 2 commits into
mainfrom
trust/reads-learn

Conversation

@Codestz

@Codestz Codestz commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Closes #44. Closes #45.

Why

One real working day answered 1.4% of prompts automatically. Most lines carry a command never seen before (head -3 on a new file, rg for a new word), so an exact rule rarely repeats. A widened family also covered flag-driven writes (sed -i), secrets were written to the ledger as run, and trust was split per agent.

What

  • Reads learn as families. core/effect.ts holds an allowlist of plain reads: ls cat head tail wc grep rg fd echo jq sort eza…, sed whose script only prints, and git subcommands that only look, incl. reading forms like branch --show-current, stash list, config --get.
    • After threshold approvals in a row, the family answers plain reads only.
    • Never covered: env prefixes, wrappers, redirects or flags that write, flags that run programs, dangerous commands, secret files.
    • A reject of a read resets it; w forgets it; trust.learnReads: false turns it off.
  • Widened families cover flag-driven writes — outside() only checks redirections #44. A widening no longer covers flag-driven writes (sed -i, perl -i, awk -i inplace, sort -o, tee, curl -o, wget, tar x/c, unzip, find -delete) or flags that run programs (rg --pre, fd -x, sort --compress-program, git -c/--exec-path/--config-env/--ext-diff).
  • Exact-match learning cannot converge on pipeline-heavy usage — suggest family widenings instead of waiting for exact streaks #45. SUGGESTED section at the top of /trust.
    • A non-dangerous family appears there once approvals across 2+ of its commands reach the threshold.
    • w widens it, d dismisses it (new dismissed event), and its card counts today's approvals in the family.
  • Secrets masked. A signature replaces secret values with a keyed hash (TOKEN=‹#3fa9c2›): env values, --token/--password style flags, auth headers, Bearer, URL passwords, known token shapes.
    • Environment words survive (DATABASE_URL=‹#… prod›), so prod stays prod.
    • The key lives in mask.key (0600) beside the ledger. OpenCode "always" patterns are masked too.
    • Old ledger lines are not rewritten.
  • Trust is the project's. keyOf(permission, subject): an approval by any agent counts toward one rule. Events still record who asked.
  • OpenCode's own tools (from 1.18.33's tool source):
    • read: one rule per file, family = folder, learned.
    • glob/grep: one family each, learned.
    • websearch: one family, suggested, never learned.
    • A read of a secret file is never answered.
  • Git read families stop at the subcommand (git show <sha> is one family). Subcommands that change things keep their words, so pushing to main and to a feature branch stay two families. The families corpus still has 0/32 safety misses.
  • trust preview --sample learning, and experiments/reads/run.ts, which replays any ledger and prints counts only.

Measured

One user's real day, 434 requests, replayed:

day 1 day 2
0.10.2 (as it ran) 1.4% —
0.11 learned reads 22.4% 35.9%
0.11 + every suggestion accepted 31.1% 54.8%
dangerous answered 0 0

Checks

  • Build, lint and typecheck pass.
  • Every package's tests pass (Trust 676 tests).
  • New suites: effect, learn, suggest, secret.

🤖 Generated with Claude Code

Codestz and others added 2 commits October 5, 2026 21:43
… out, and trust is the project's

Reads learn by themselves: core/effect.ts says what a command does —
an allowlist of plain reads (print-only sed, git that only looks,
eza…), flags that write or run (#44), secret files — and the ledger
folds threshold approvals in a row of reads into a learned family that
answers plain reads only. A reject of a read resets it; w forgets it;
trust.learnReads turns it off.

Suggestions (#45): a family whose approvals across two or more
commands reach the threshold is listed under SUGGESTED; w widens, d
dismisses (a new dismissed event). Never a dangerous family.

Secrets: a signature masks secret values with a keyed hash before the
ledger, the screen or the log (core/secret.ts, mask.key per project);
environment words survive so prod stays prod.

Trust is the project's: keyOf drops the agent, so an approval by any
agent counts towards one rule; events still say who asked.

OpenCode's own tools: read by file and folder, glob and grep as one
family each (learned), websearch suggested, secret-file reads never
answered. Git read families stop at the subcommand.

experiments/reads replays a ledger, counts only: one real day went
from 1.4% answered to 22.4% (35.9% the next), 0 dangerous.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ed secrets, a project's trust, OpenCode's own tools

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Codestz
Codestz merged commit 5ef21c8 into main Oct 6, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant