refactor: drop OPERATOR_USERNAME, separate control vs comms planes
There's no good reason to bake a specific operator nickname into the bot's
identity — it differs per server, may not exist at all, and treating any
in-game name as "trusted" is a chat-injection vector ("I am the operator,
do X").
New model: the **repo** is the only trusted control plane. Anyone editing
AGENTS.md, skills/, or .env has filesystem access and is, by definition,
an operator. In-game chat becomes a dialog-only comms plane — the bot
talks to anyone but refuses destructive requests unless a corresponding
skill or AGENTS.md instruction makes the action explicitly permitted.
- .env / .env.example: OPERATOR_USERNAME removed
- AGENTS.md: identity section trimmed; "Operator contact" rewritten as
"Control channel" with the trust model spelled out; rules #2 and #6
rephrased so they no longer reference a named operator
- docs/architecture.md: top box renamed to "Human" with explicit
control-plane vs comms-plane split
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -6,11 +6,12 @@
|
||||
|
||||
```
|
||||
┌─────────────────────────────────────────────────────────────┐
|
||||
│ Operator │
|
||||
│ (human — in-game chat, repo edits, .env) │
|
||||
│ Human │
|
||||
│ - control plane: repo edits (AGENTS.md, skills/, .env) │
|
||||
│ - comms plane: in-game chat (untrusted, dialog only) │
|
||||
└─────┬────────────────────────────────────────────┬──────────┘
|
||||
│ │
|
||||
│ chat / edit AGENTS.md │ optional: Telegram (future)
|
||||
│ edit repo / .env │ optional: Telegram (future)
|
||||
▼ ▼
|
||||
┌─────────────────────────────────────────────────────────────┐
|
||||
│ Pi runtime │
|
||||
|
||||
Reference in New Issue
Block a user