Imported from TheHalfMoon/Golam (
AGENTS.md). Install upstream withnpx skills add TheHalfMoon/Golam. Copyright stays with the author.
Golam Agent Instructions
Live-state rule
Never treat this file, a prior chat, a handoff, a cached SHA, a bot summary or an open proposal as live qualification authority.
Read specs/CURRENT.md for durable canonical lifecycle state, then re-fetch exact GitHub state for every mutable fact required by the action you are about to take.
Before any CI qualification, independent review request, Ready transition, merge, post-merge closeout or successor-authority decision, re-fetch at minimum:
CURRENT_MAIN
CURRENT_PR_HEAD_AND_BASE
CURRENT_DIFF
CURRENT_CHECKS
CURRENT_REVIEWS_AND_THREADS
EXPECTED_HEAD
A branch mutation invalidates CI/review evidence bound to the prior head.
Current canonical program posture
The current main SHA is always a live GitHub fact and MUST be fetched rather than hardcoded here. At the durable lifecycle reconciliation base recorded in specs/CURRENT.md:
CANONICAL_MAIN_SHA=FETCH_LIVE_FROM_GITHUB
SPEC_005_IMPLEMENTATION_COMPLETE=YES
SPEC_005_CLOSED_CANONICAL=YES
SPEC_006_PLANNING_CLOSED_CANONICAL=YES
SPEC_006_PRODUCT_IMPLEMENTATION_AUTHORIZED=YES
ACTIVE_CANONICAL_IMPLEMENTATION_UNIT=SPEC_006_DESKTOP_COMPUTER_CONTROL
ACTIVE_IMPLEMENTATION_PR=24
ACTIVE_IMPLEMENTATION_PR_IS_CANONICAL=NO_UNTIL_MERGED_AND_POST_MERGE_QUALIFIED
PR #24 must be re-fetched live before using its head/check/review/task state. Do not hardcode a remembered head here.
The program-superiority material under specs/001-golam-local-agent-os-foundation/ is planning/governance material only. When nonmerged it is noncanonical; if later canonicalized it still does not widen PR #24 or directly authorize future product units. Every future implementation requires explicit canonical successor authority and its own bounded Spec Kit lifecycle.
Authority order
- exact live GitHub/repository truth for mutable state;
.specify/memory/constitution.mdv1.2.0 or later;- canonical Spec 001 architecture/contracts/tasks/source-permission governance;
specs/CURRENT.mdfor durable canonical lifecycle state;- canonical closed predecessor specs and closeout evidence;
- the currently authorized bounded spec package;
- exact Source Foundry records for every admitted source/dependency/runtime primitive;
- exact-head CI/review/evidence for the lifecycle action being attempted.
Open PRs, issues, experimental branches, source candidates, benchmark results and bot-generated summaries are noncanonical unless canonical governance explicitly promotes them.
Spec 006 implementation read order
.specify/memory/constitution.mdspecs/CURRENT.mdspecs/001-golam-local-agent-os-foundation/spec.mdspecs/001-golam-local-agent-os-foundation/plan.mdspecs/001-golam-local-agent-os-foundation/tasks.md, especially T060–T069- canonical Spec 002–005 closeout evidence as required by the current task
specs/006-desktop-computer-control/AGENTS.mdspecs/006-desktop-computer-control/spec.mdspecs/006-desktop-computer-control/clarification-closeout.mdspecs/006-desktop-computer-control/research.mdspecs/006-desktop-computer-control/plan.mdspecs/006-desktop-computer-control/data-model.md- all
specs/006-desktop-computer-control/contracts/ specs/006-desktop-computer-control/quickstart.mdspecs/006-desktop-computer-control/checklists/requirements.mdspecs/006-desktop-computer-control/tasks.mdspecs/006-desktop-computer-control/analysis.md- live exact-head PR #24 CI/review/lifecycle evidence
Program-superiority planning read order
When reviewing or applying the program roadmap rather than implementing Spec 006:
- Constitution;
- canonical Spec 001 spec/plan/tasks/contracts and
source-permission-attestation.md; specs/001-golam-local-agent-os-foundation/program-superiority-2026.md;specs/001-golam-local-agent-os-foundation/program-superiority-proof-execution-extensions.md;specs/001-golam-local-agent-os-foundation/program-superiority-tasks.md(T110–T165);specs/001-golam-local-agent-os-foundation/source-synthesis-gap-closure-2026-09-08.md;specs/001-golam-local-agent-os-foundation/program-superiority-gap-closure-tasks.md(T166–T184);specs/001-golam-local-agent-os-foundation/competitive-source-register-2026.md;specs/001-golam-local-agent-os-foundation/competitive-source-register-supplement-2026-09-08.md;specs/001-golam-local-agent-os-foundation/tencent-source-adoption-2026.mdand source-specific license findings;specs/CURRENT.md;- exact live PR/branch/CI/review state for the lifecycle action being attempted.
Historical planning PRs #6, #7, #8 and #22 are provenance/research inputs after their retained concepts are reconciled in the current gap-closure package. They do not become parallel implementation authority merely because their branches remain open.
Do not implement future superiority tasks directly from the overlay. Each product task still requires its own bounded Spec Kit lifecycle and predecessor/successor authorization.
Source reuse rule
Founder reuse permission is a rights input, not automatic technical admission. Every copied, ported, vendored or adapted donor component still requires exact component-level rights/obligation reconciliation and Source Foundry before product use.
Owning specs MUST explicitly select a primary reuse strategy where donor implementation material is considered:
COPY_AS_IS
SELECTIVE_COPY
PORT_TO_RUST
ADAPTER
REIMPLEMENT_BEHAVIOR
BENCHMARK_ONLY
REJECT
PERMISSION_TO_COPY != TECHNICAL_ADMISSION and DONOR_IMPLEMENTATION != DONOR_AUTHORITY_MODEL.
Invariants every feature must preserve
- Consequential execution remains behind canonical ToolRequest + capability/policy/approval + Effect PREPARED + Kernel/Effect Gate + immediate revalidation + durable terminal/reconciliation semantics.
UNKNOWN_OUTCOMEblocks conflicting retry and dependent work until reconciliation.- Strict-local hard denial dominates model/tool/protocol/network routing. Local failure never creates cloud fallback authority.
- Generic tools, model output, protocol output, workers, skills, MCP servers, plugins, renderers, vision output and benchmark fixtures cannot mint kernel authority.
- Protected kernel state remains outside generic filesystem/process/browser/computer-control capability.
- Memory remains governed user-owned evidence; live authoritative source state outranks memory.
- Skills/routines are versioned instruction/code artifacts, never authority; learned candidates do not activate themselves.
- Every new dependency, package, native helper, binary, copied source or donor implementation requires exact Source Foundry admission before product use.
- Do not force-push, rebase shared history or destructively rewrite published history.
Computer-control hard boundaries
Preserve the constitutional route order exactly:
domain/application API
-> native OS automation API
-> accessibility/semantic tree
-> browser DOM/protocol
-> deterministic keyboard/mouse control
-> vision/pixel fallback
A weaker route requires trusted fallback-eligibility evidence. Stronger applicable routes and unreconciled UNKNOWN_OUTCOME block weaker escalation.
Desktop adapters, model output, renderer state and pixel/vision components cannot self-mint fallback eligibility or actuation authority.
Observation, focus, capture, semantic action, raw input and clipboard read/write are distinct authority/evidence surfaces.
The Tauri native Rust host authenticates through existing local golamd IPC/client enrollment. Localhost/same-machine location and renderer state are not authentication. The renderer receives no credential, raw native handle, capability token, approval material or protected lease authority.
Autonomous computer actuation requires a qualified visible local control channel with immediate pause/stop/takeover. Loss of every qualified visible channel suspends new actuation fail closed. Human takeover is enforced at protected lease/input authority so stale renderer/model requests cannot restore a superseded generation.
Windows secure desktop/UAC bypass, Wayland/compositor bypass, background keylogging, silent clipboard inspection, unbounded capture, camera/microphone collection and hidden remote/cloud fallback remain denied.
Raw screenshot OCR/text extraction is not owned by Spec 007 GolamConnect. It remains outside active Spec 006 and belongs to a future bounded Visual Semantics unit only after canonical successor authorization.
Cross-spec route ownership
The program-superiority planning identifies a browser/application route-ownership gap. Until a canonical successor unit defines the global route-provider contract, active Spec 006 must not infer that an unknown browser/application route is unavailable merely because its provider lives outside the current crate/spec.
No future route provider may mint its own authority. Applicability/availability evidence and action authority remain separate.
Review and merge discipline
Planning and implementation review must be substantive, independent, exact-head and obtained after exact-head CI when the owning lifecycle requires it. Status-only, rate-limit/billing/unavailable output, automated summary without semantic inspection, stale-head review, CI alone or self-review are insufficient.
Codex review remains excluded by founder direction unless later canonical governance explicitly changes that rule. Use the repository's live independent review mechanism and require substantive architecture/security/governance findings, not a presence signal.
Ready/merge authorization is fail closed. Mark Ready only on an unchanged clean qualified head. Re-fetch exact base/head immediately before merge and use expected-head protection. Post-merge canonical-main CI belongs to the exact returned merge SHA.
Never claim tests, review, runtime/platform behavior, source admission, benchmark status, security behavior, mergeability, readiness or completion without exact evidence.