refactor: drop OPERATOR_USERNAME, separate control vs comms planes

There's no good reason to bake a specific operator nickname into the bot's
identity — it differs per server, may not exist at all, and treating any
in-game name as "trusted" is a chat-injection vector ("I am the operator,
do X").

New model: the **repo** is the only trusted control plane. Anyone editing
AGENTS.md, skills/, or .env has filesystem access and is, by definition,
an operator. In-game chat becomes a dialog-only comms plane — the bot
talks to anyone but refuses destructive requests unless a corresponding
skill or AGENTS.md instruction makes the action explicitly permitted.

- .env / .env.example: OPERATOR_USERNAME removed
- AGENTS.md: identity section trimmed; "Operator contact" rewritten as
  "Control channel" with the trust model spelled out; rules #2 and #6
  rephrased so they no longer reference a named operator
- docs/architecture.md: top box renamed to "Human" with explicit
  control-plane vs comms-plane split

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-05-25 10:15:37 +03:00
co-authored by Claude Opus 4.7
parent 4dd8576d5b
commit 602134671e
3 changed files with 16 additions and 13 deletions
-5
View File
@@ -37,11 +37,6 @@ TICK_INTERVAL_SECONDS=60
# trigger around 20/min.
CHAT_RATE_LIMIT_PER_MIN=15
# --- Operator -----------------------------------------------------------------
# In-game nick of the human operator. The bot treats their chat messages as
# higher-priority than other players.
OPERATOR_USERNAME=your_in_game_nick
# --- Optional: Telegram bridge (future skill, not wired yet) ------------------
# TELEGRAM_BOT_TOKEN=
# TELEGRAM_OPERATOR_CHAT_ID=