Observed from hyperpolymath/oikos-economics-accounting-dsl (its audit docs/tech-debt-2026-10-10.adoc §7 item 1), against this repo at 3108c1b. Local workaround deliberately not taken; filing instead of patching the checker from outside.
Defect A — [baseline] is unenforced. scripts/check-rsr-profile.sh walks [gates] against declared capabilities and nothing else:
$ grep -c baseline scripts/check-rsr-profile.sh
0
So the "Always carried (gate = empty)" rows in .machine_readable/template-capability-gates.toml's [baseline].paths are asserted by no executable. A repo can be missing LICENSE, Justfile, 0-AI-MANIFEST.a2ml — everything on the list — and the checker still reports only capability rows.
Defect B — one of those unenforced rows is also stale. [baseline].paths contains ".well-known/", a root directory the estate migrated away from (rsr-template-repo#53 / scripts/migrate-wellknown-to-www.sh; the live checker for the convention is the template's validate-template.sh, which knows www/.well-known/). The SECURITY.md|.github/SECURITY.md rows already use | alternation for exactly this problem; the row should read .well-known/|www/.well-known/.
Repro shape: oikos carries www/.well-known/security.txt and is conformant to the estate's current convention; the baseline neither passes nor fails it, because nothing reads it. Two defects, one root cause: the baseline is prose with no reader.
Ask: (1) wire [baseline] into check-rsr-profile.sh (MISSING rows, like the gates table); (2) fix the row to .well-known/|www/.well-known/. The tempting local fix — a root .well-known/ or a symlink — would be scaffolding added to satisfy a document rather than a consumer.
Observed from
hyperpolymath/oikos-economics-accounting-dsl(its auditdocs/tech-debt-2026-10-10.adoc§7 item 1), against this repo at3108c1b. Local workaround deliberately not taken; filing instead of patching the checker from outside.Defect A —
[baseline]is unenforced.scripts/check-rsr-profile.shwalks[gates]against declared capabilities and nothing else:So the "Always carried (gate = empty)" rows in
.machine_readable/template-capability-gates.toml's[baseline].pathsare asserted by no executable. A repo can be missingLICENSE,Justfile,0-AI-MANIFEST.a2ml— everything on the list — and the checker still reports only capability rows.Defect B — one of those unenforced rows is also stale.
[baseline].pathscontains".well-known/", a root directory the estate migrated away from (rsr-template-repo#53 /scripts/migrate-wellknown-to-www.sh; the live checker for the convention is the template'svalidate-template.sh, which knowswww/.well-known/). TheSECURITY.md|.github/SECURITY.mdrows already use|alternation for exactly this problem; the row should read.well-known/|www/.well-known/.Repro shape: oikos carries
www/.well-known/security.txtand is conformant to the estate's current convention; the baseline neither passes nor fails it, because nothing reads it. Two defects, one root cause: the baseline is prose with no reader.Ask: (1) wire
[baseline]intocheck-rsr-profile.sh(MISSING rows, like the gates table); (2) fix the row to.well-known/|www/.well-known/. The tempting local fix — a root.well-known/or a symlink — would be scaffolding added to satisfy a document rather than a consumer.