git:20260804.659f272 to git:20260805.96f9c4a

5 added, 3 removed. Audit A to A.

# autorun safety guidance (OpenCode)
OpenCode's hook surface is JavaScript plugins rather than external hook
events, so autorun cannot intercept tool calls the way it does in Claude
Code or Codex. The guidance below is therefore advisory — you (the AI
agent) are expected to read and follow it before taking destructive or
irreversible actions.
## Use these autorun commands when relevant
- `/ar-go <task>` — start an autonomous run with the three-stage
verification cycle (initial → critical review → final verification).
- `/ar-st` — show the current AutoFile policy (allow / justify / find).
- `/ar-allow` — allow all file creation.
- `/ar-find` — restrict edits to existing files only.
- `/ar-commit` — refresh git commit guidelines before staging.
- `/ar-ph` — refresh the universal system design philosophy.
## Safety guardrails
1. Prefer `trash` over `rm` for any path you did not just create.
2. Never run `git reset --hard`, `git push --force`, or `git clean -f`
without an explicit user instruction in the current turn.
3. Never modify uncommitted work that you did not produce in this run.
4. When in doubt about a destructive command, propose it as a question
instead of executing it.
5. Commits use the structure documented in `/ar-commit` — concrete
summary, no internal jargon, no transient session details.
## Stop semantics
- If the user wants you to stop and you have incomplete tasks, surface
- the override path explicitly: only the user can type `/ar:sos` or
- `/ar:task ignore <id>` to unblock the stop.
+ OpenCode delivers no stop event to autorun, so autorun holds nothing open
+ here and no emergency-stop or task command is installed — the six commands
+ above are the whole surface. Never say autorun blocked or cleared a stop.
+ When you stop with work outstanding, name what is left and let the user
+ decide.