Summary
Reviewed 5 spec files (rotation indices 5-9 of 20) through the SPDD stages. Findings are mostly maintenance: duplicated version data between spec and changelog, a contradictory fixture note, and a manual-only drift guard not enforced in CI.
Priority Work Queue
- P0: Fix contradictory
total_aic fixture description in specs/forecast-compliance-fixtures/README.md.
- P1: Enforce the MCP access control pinned-spec drift check in CI; add a mechanical spec-version vs changelog sync check.
- P2: Clarify non-sequential CTR to T-CTR mapping and add an ID allocation rule.
SPDD Checklist
Per-Spec Findings
specs/compiler-threat-detection-spec.md
- Goals: compiler-side detection of unsafe generated workflows (CTR-001 to CTR-031) synchronized with implementation, tests, and audits.
- Risks: Section 2 version table duplicates the changelog; runtime trust boundaries (T7, RS-05a) are prose-only and may be misread as missing rules.
- Canvas gaps: Structure (long version table), Norms (no cap on audit-only rows).
specs/compiler-threat-detection-changelog.md
- Issue numbers lack links; collapsed ranges (1.0.27-1.0.30) need verification against the spec table.
- Sync: add a standard audit template.
specs/compiler-threat-detection-compliance/README.md
- Non-sequential crosswalk is intentional but has no allocation rule; CTR-024 is absent without explanation.
specs/forecast-compliance-fixtures/README.md
- Contradictory
total_aic bullets; only one fixture documented; lambda=15 and 1,000,000 boundaries lack explicit test IDs.
specs/github-mcp-access-control-compliance/README.md
- Pin check is manual and not run in CI; deny-code enumeration and fixture naming conventions are missing.
Sync Follow-ups
- Spec edits to compiler-threat-detection-spec.md: bump version, update Section 2, add changelog entry in the same PR.
- Edits to scratchpad/github-mcp-access-control-specification.md: re-pin the compliance README.
- Fixture changes in specs/forecast-compliance-fixtures/: re-verify T-FC-020 to T-FC-040 mappings in pkg/cli/ tests.
- Next run starts at rotation index 10 (specs/intent-attribution-agent-governance.md).
Context
- Files reviewed: specs/compiler-threat-detection-changelog.md, specs/compiler-threat-detection-compliance/README.md, specs/compiler-threat-detection-spec.md, specs/forecast-compliance-fixtures/README.md, specs/github-mcp-access-control-compliance/README.md
- Rotation index: 5-9 of 20 (last_index=9, next=10)
- Run URL: https://github.com/github/gh-aw/actions/runs/37336568239
Generated by 📋 Daily SPDD Spec Planner · copilot · auto · 23 AIC · ⌖ 5.72 AIC · ⊞ 7.1K · ◷
Summary
Reviewed 5 spec files (rotation indices 5-9 of 20) through the SPDD stages. Findings are mostly maintenance: duplicated version data between spec and changelog, a contradictory fixture note, and a manual-only drift guard not enforced in CI.
Priority Work Queue
total_aicfixture description inspecs/forecast-compliance-fixtures/README.md.SPDD Checklist
specs/forecast-compliance-fixtures/README.md: resolve conflicting bullets (total_aic: 0.0054vs5400) against the fixture JSON. Done when one value is documented and matches the fixture.specs/compiler-threat-detection-spec.md(Section 2): compare the version table with the changelog Version History. Done when every changelog version has a row or documented range.specs/github-mcp-access-control-compliance/README.md: move the manual drift check into a script underscripts/and call it from.github/workflows/. Done when a mismatched pin fails CI.specs/compiler-threat-detection-compliance/README.md: add an ID allocation rule for newT-CTR-*IDs and document CTR-024 status. Done when both are stated.specs/forecast-compliance-fixtures/README.md: add a numbered pipeline order (filter, sample cap, Poisson, Bernoulli, bootstrap) tied to T-FC IDs. Done when each step has a test ID.pkg/workflow/tests: add a test asserting spec Section 2 versions equal changelog versions. Done whengo test ./pkg/workflow/...covers it.specs/compiler-threat-detection-compliance/: add a CTR-031 (T-CTR-046) fixture stub for strict vs non-strict behavior. Done when the file exists and is linked from the README.specs/compiler-threat-detection-changelog.md: add an audit entry template (date, files, disposition, CTR impact, linked issues). Done when the template precedes Mapping Audits.specs/github-mcp-access-control-compliance/README.md: re-pin the commit after any change toscratchpad/github-mcp-access-control-specification.md. Done when the pin equals the current tip commit.Per-Spec Findings
specs/compiler-threat-detection-spec.md
specs/compiler-threat-detection-changelog.md
specs/compiler-threat-detection-compliance/README.md
specs/forecast-compliance-fixtures/README.md
total_aicbullets; only one fixture documented; lambda=15 and 1,000,000 boundaries lack explicit test IDs.specs/github-mcp-access-control-compliance/README.md
Sync Follow-ups
Context