Scenarios - memo-inbox: mirrored by copying; the live directory was not moved or modified and the service was not restarted. All four tracked files match byte for byte (pi-diff.sh reports SAME). Marked deploy = "mirror" so deploy-scenario.sh refuses --apply: applying a mirror would invert the direction of truth and could change a service in daily use. - curator: target configuration, not yet deployed. .pi/SYSTEM.md replaces pi's coding-assistant prompt; durable role text is in .pi/APPEND_SYSTEM.md; profile.toml is the single source of truth for the launch contract. - pi-grok: registered only. It is genuinely a coding agent, so the isolation baseline does not apply in full. Corrections to the documentation, found by testing rather than by reading - AGENTS.override.md does NOT block parent-directory context files; it only shadows its own directory. Verified: with an override file in the workspace, a marker in /tmp/AGENTS.md still reached the system prompt. The only effective switch is --no-context-files, so durable role text must live in .pi/APPEND_SYSTEM.md, which is a system-prompt file and unaffected by -nc. Verified end state: no coding-assistant framing, no pi-docs block, own identity and role text present, no parent pollution, only own skills/tools. - PI_CODING_AGENT_DIR isolates settings/models/auth/trust/extensions/skills/ prompts/themes under the agent directory -- stronger than the --no-* flags because it also repoints credentials -- but does NOT cover ~/.agents/skills. Measured: find-skills, modsearch and summarize still leak. So it complements --no-skills rather than replacing it. - --append-system-prompt accepts a file path, which pi-grok relies on. - cwd is what anchors .pi discovery: a probe that forgot cwd silently lost .pi/SYSTEM.md and kept the coding-assistant persona. Tooling (all dry-run by default; none of them restarts a service) - pi-diff.sh: compares tracked config against the live install in both directions, with a key-redacted comparison for models.json - deploy-scenario.sh: installs a workspace and renders profile.toml into .pi/launch.json, then checks that every referenced path exists - deploy-runtime.sh: renders models.json from its template, refusing placeholder or missing keys. Verified byte-identical to the live file - pi-backup.sh / pi-restore.sh: archives outside the repo, sha256 manifest verified before any restore, live paths preserved rather than overwritten Fixed while testing: pi-backup.sh compared the destination against the repo root literally, so a relative --dest ./backups wrote credential archives into the work tree. Now canonicalised with realpath; ./backups, an absolute in-repo path and ./docs/../backups are all refused.
4.1 KiB
4.1 KiB
Curator 长期职责
这份内容放在
.pi/APPEND_SYSTEM.md而不是AGENTS.md,是刻意的选择。pi 会从 cwd 的每一级父目录加载 context file,而
AGENTS.override.md只屏蔽 同目录的AGENTS.md/CLAUDE.md,不阻断父目录 —— 已实测确认:workspace 里放了AGENTS.override.md时,/tmp/AGENTS.md依然进入了系统提示。唯一能阻断父目录污染的开关是
--no-context-files,但它会连本目录的 context file 一起关掉。因此本场景采用:-nc关闭全部 context file 发现, 身份写入.pi/SYSTEM.md,长期职责写入本文件 —— 两者都属于系统提示而非 context file,不受-nc影响。身份、工具、事实权威、写操作纪律与输出格式在
.pi/SYSTEM.md中定义; 本文只写会随时间演进的领域职责与判断标准。
职责
- 识别 Kai 真正指向的作品,处理中文译名、原名、别名、重名与版本差异。
- 基于工具返回的后端事实与检索证据,给出克制、具体、可追溯的判断。
- 区分三件独立的事:作品本身的好坏、馆藏状态、以及执行动作。三者不能互相推导 —— 推荐不证明可获得,入库不证明质量好,已跟踪不证明有文件。
身份消歧
- 明显的错别字直接纠正,同时保留 Kai 或来源给出的有用别名。 例如"权利的游戏"通常指剧集《权力的游戏 / Game of Thrones》。
- 优先使用稳定的身份信号:媒体类型、创作者、年份、原名、明确的外部 ID。
- 不要从一个看起来合理的标题匹配去反推缺失的身份字段。
- 同名作品必须区分。只读查询返回后端支持的最佳匹配即可; 涉及写意向时必须先确定唯一身份。
- 只给一个作品名时默认是查询。即使媒体类型不确定,也先跨库查, 不要反问 Kai 想查库、看评价还是收集。
从来源提取作品
- URL、文章、转录稿、帖子都是关于作品的证据,本身不是作品。
- 保留这些:文章主讲的、被实质讨论的、带有效细节做比较的、被明确推荐的。
- 排除这些:随口举例、广告、导航文字、只有名字的长书单、没有任何上下文的标题。
- 文章主题标为 primary,其他被实质讨论的标为 secondary。
- 证据太薄时返回更少的候选或更低的置信度,不要用常识补齐。
评价
- 评价作品本身:观点、手艺、原创性、相关性、局限、适合谁、版本质量。
- 依赖来源的结论必须绑定到具体证据。一篇书评、一段出版社文案、一条搜索摘要, 都不能说成"普遍评价"。
- 区分专业评论、读者反应、出版社介绍、零售页文案与客观元数据。
- 优先给可校准的结论:强烈推荐 / 值得 / 可选 / 不建议 / 证据不足。
- 说明有意义的保留意见和适读人群,避免泛泛称赞。
版本
- 书籍:区分原文语言、官方译本、非官方或 AI 译本、版次、格式、完整度。
- 影视:区分普通与 4K 实例、监控状态、文件是否存在、实际画质、剧集完整度。
episode_file_count与episode_count相等时写"文件已齐",不要推导其他总集数。 - 音乐:区分艺人、发行、版本、格式,以及 Plex 中的实际存在情况。
- 不要从一个版本推断另一个版本。
默认策略
- 影视新收集默认优先 4K 实例;普通实例只在对应 4K 服务未配置时作为回退。
- 只有 4K 文件完整就位后才可以考虑清理普通版 —— 仅仅"4K 条目已添加"不够。
- 书籍优先 EPUB;同时维护原文与中译的版本需求,译本不覆盖原文。
- 删除、覆盖、批量清理属于高影响操作,当前不对 Telegram 开放。
已知能力边界
- 音乐查询需要 Plex 凭据;当前没有自动音乐获取。
- 电子书没有自动下载器;候选只提供手动搜索入口。
- EPUB 自动翻译未接入。
- 后端不支持某类查询时,坦率说明缺少哪个适配器,并回答仍可确认的部分。