--- name: auto-self-improve description: Issue-only Auto-Office bug observer. Use when explicitly invoked, when Auto-Office encounters its own runtime/skill/adapter/hook bug, and on EVERY office land or office close attempt (successful, failed, or refused). Activate with `office self-improve`; capture the entire run, including subagents and prior evidence. Delegate bounded, read-only investigation to a cheaper model, deduplicate, and file sanitized GitHub issues in Hikari9/auto-office. Never fix bugs, edit source, commit, open a PR, or close issues. --- # Auto Self Improve — issues only **Hard boundary:** Self-improvement means evidence-backed **GitHub bug filing**, NOT self-repair. Never modify any repository content, amend model catalogs, create worktrees or branches, commit, open or merge PRs, resolve route defects, or close issues. Historical v3 proposal scripts are NOT part of this skill. 1. **Arm the complete run.** From its repository, `office self-improve` enables durable run-wide observation. All orchestrator and subagent errors, retries, warnings, and anomalies are in scope. During `office land` and `office close` (including refused/failed attempts), the runtime also backfills all earlier evidence even if not explicitly armed. All further eligible bugs in that run follow the same policy. 2. **Do not block delivery.** Landing/closeout continue regardless of investigation, model unavailability, GitHub failure, or retry state. The independent reporter persists reports in `runs.db` outside prunable run details; it retries with backoff, resumes on later Office commands, and reports filed/pending/retry/suspected statuses. Reporter processes are bounded: one per state home behind the home's lock (held through each spawn and inherited by the child, so wake-ups never race a gap), wake-ups skip the spawn when that lock is held or nothing is queued, and each reporter exits on its lifetime bound (`OFFICE_SELF_IMPROVE_MAX_SECONDS`, default 900s) — a queue that outlives the bound hands ownership to a fresh successor so retry delivery stays eventual. A disposable state home (a test home declaring `OFFICE_STATE_HOME_OWNER`) is reclaimed when its owner ends or its directory is released, even after an interrupted teardown. Receipts stay durable in `runs.db` in every case. Never claim success without a GitHub issue URL. 3. **Delegate cheaply, safely.** The runtime currently uses an installed budget-qualified Claude route in bare mode, with all tools, MCP servers, hooks, skills, memory and automatic project context disabled. Investigation receives only the sanitized incident capsule. Bare mode requires API authentication; subscription-only authentication or missing safe routes leave incidents queued for retry. The runtime owns the restricted GitHub issue-creation call. 4. **File only relevant defects.** Include Auto-Office runtime, CLI, skills, routing, adapters, hooks, and integrations whose handling Auto-Office owns. Exclude target-application bugs, normal user/gate refusals, and third-party outages without Auto-Office defects. Confirmed or strongly evidenced defects can be filed without reliable reproduction; weak suspicions remain private until more evidence arrives. 5. **Preserve evidence and privacy.** Store raw evidence only in private state. Public issues include expected/actual behavior, sanitized evidence, impact and safe reproduction steps where available, and a stable deduplication marker. Search open and closed issues first; reuse matches rather than creating duplicates. Do not expose person, repository, path, account, credential, or customer identifiers. 6. **Prevent recursive reporting.** Never treat reporter failures as new incidents to self-investigate. Keep reporting failures in the durable retry queue with visible status. `office self-improve` is the explicit entrypoint; automatic land/close auditing is runtime-owned. Read `protocol/privacy-self-improvement.md` for current issue-only rules. The legacy `scripts/office_propose.py` and related proposal material are historical only.