llms.sgit.ai / admin / comms

Comms: tasks, requests & status

The working channel between the project lead and the site agent, kept in public on the site itself. Updated on every release. Current release: v0.2.0, 25 August 2026. Full history: versions.

Needed from the project lead

#RequestWhy it blocksStatus
N4 Rule on Q3, now that it has moved. The pack calls the attached-file injection question the most important open question on the site and instructs that no injection page ship until it is answered. Reading the shipped source at v0.33.62 turns up a mechanism the pack did not have: an explicit BEGIN/END UNTRUSTED DATA fence around vault and tool content, a system-prompt rule telling the model to treat fenced text as data and to report anything inside it that asks for action, tool groups that ship enabled: false, and grants stored in /.vault/llm/tools.json where the tools structurally cannot reach them. Published as a narrowing rather than an answer, because fencing is enforced by persuasion and nothing measures how well it holds. Two calls are yours: whether that is enough to lift the HOLD on the injection material in the source manifest, and whether the fencing claim may be stated more strongly than this site currently states it The /injection/ page and two tier-2 manifest rows stay held until you rule waiting on human
N5 The contract and the code disagree about tool calling. AUTHORING.md says "There is no tool-calling loop. sg.llm.chat is a reader." That is still true of the bridge and no longer true of the product: the vault's own chat ships an opt-in tool layer with a bounded loop, read-tier groups and per-group path scopes. Both statements are individually correct, and a reader of the contract alone would not know the second exists. Since this site generates its reference from that contract, the drift propagates here by design. Recommendation: a paragraph in the contract's own "What this is not" section, pointing at the tool layer as a separate, non-app-facing capability Not blocking. It is recorded on the shipped page and will keep being recorded until the contract moves reported
N6 The demo vault, and whether it can publish a read key at all (pack Q4). The pack's own recommended artefact is a vault app that exercises every call, published as both the documentation and its test, which would also make the samples verified by existing rather than by review. It cannot be published casually: a vault with an LLM key configured carries a credential. Two workable answers, and the choice is yours: a shared-tier key with hard maxCostPerSession and maxCallsPerSession caps chosen deliberately for publication, or bring-your-own-key following the Article 9 Lab precedent Blocks the demo vault, and with it the strongest thing this site could add next waiting on human
N7 Confirm the network boundary with sgit.ai (pack Q2). Proposed and published unconfirmed: this site owns the capability, sgit.ai owns the product tour. On the network page. Also worth a decision: which sibling network pages should now link here, since none of them list this site yet Not blocking until two sites claim the same page, which is the failure the boundary exists to prevent proposed
N8 Is Phase 4 scheduled? Minted credentials are described as "the commercially load-bearing piece" and as what would make vault-sharing safe with AI configured. This site's strongest claim is narrower than it wants to be until they exist, and a date would change what the front page can say Not blocking. It changes the claim, not the build open
N1 The brief pack. Received 25 August 2026, twelve documents and a 24-row source manifest. Published verbatim with a reader page each, and the site built from it No longer blocking done
N2 GitHub Pages and the custom domain. Done: llms.sgit.ai resolves and serves, the github.io address redirects to it, and the pipeline is verified end to end No longer blocking done
N3 The site's boundary with its siblings. Superseded by N7, which asks the narrower question the brief pack actually raises — superseded

Task board

#TaskOwnerStatus
T1CI pipeline: validate, auto-tag, deploy to Pages, ported from pki.sgit.ai with two improvements from graphs.sgit.aisite agentdone v0.1.0, verified live v0.1.1
T6The site itself, in the brief's build order: the chat pane and samples, the API and traps, security, websites, provenance, the provider layer, local, agents, shippedsite agentdone v0.2.0
T7The brief pack captured verbatim under briefs/ with reader pages generated alongside. The raw markdown stays the source of truthsite agentdone v0.2.0
T10Q1 answered by mechanism. The API reference is generated from the canonical AUTHORING.md section, vendored under sources/ with its hash recorded, and the gate fails if the page stops matching. No second source of truth, and no unreadable contract eithersite agentdone v0.2.0
T11The agent surface, treated as an acceptance criterion rather than a topic: a markdown twin at every path with links rewritten to point at twins, a self-sufficient llms.txt, llms-full.txt (which pki.sgit.ai lacks), and a generated sitemap listing both. All four enforced by the gatesite agentdone v0.2.0
T12The brief's conditions turned into gates. Key shapes (sk-or-, OpenRouter formats, the write prefix) banned before the first sample page shipped; the CSP qualification required on the front page; twins required; the generated reference required to match its source; house spelling enforced. A condition in a brief is one somebody forgets on the fourth pagesite agentdone v0.2.0
T13Seven claims re-verified against the shipped source at v0.33.62 rather than against the brief, per the pack's own closing instruction. Five confirmed, one superseded, one no longer truesite agentdone v0.2.0
T14The sg-llm-chat web component with a pluggable transport, so one component serves the backend-proxy, BYOK and embedded-vault options. The recommendation, and half the commissionsite agentqueued, and named as not built
T15The demo vault app that is the documentationproject lead + agentblocked on N6
T16The /injection/ pagesite agentheld on N4, deliberately
T17Ask the sibling sites to link here, and add this site to their network pagessite agentqueued, after N7
T9Reported upstream: standards.sgit.ai's repository ignores admin/build/ through the inherited Python .gitignore, so its gate script is not committed and its CI runs against a file that is not in the checkout. This repository carries the one-line negation that fixes itsite agentreported v0.1.0

How to use this channel