Upstream Bug Report
Files a bug/improvement against the ai-engineering framework with strict redaction and explicit consent: runs the shared redactor in strict mode, renders the body for review, requires a typed confirm token, then shells gh issue create --repo arcasilesgroup/ai-engineering. A sanitized copy is archived under .ai-engineering/support/upstream-reports/.
/ai-engineering-issue "<short-title>"
/ai-engineering-issue "<short-title>" --include path/to/file.py:42
Workflow
Principles: §10.4 DRY (single redactor service _shared/redactor.py:redact, D-134-09 — no per-skill regex sprawl); §13.4 anonymous content (no PII / machine paths / operator names reach the upstream repo, enforced before render).
- Preflight auth.
gh auth status. On failure, refuse with the fix hint and exit non-zero. - Capture context. Read active spec frontmatter, latest
framework-events.ndjsontail (≤10 entries), any--includetargets, plus the title from$ARGUMENTS. Coerce to text. - Strict redaction. Call
python -c "from ai_engineering._shared.redactor import redact; print(redact(text, strictness='strict'))". Strict mode applies all seven vectors (see table). - Compose body. Upstream-report template: summary (≤3 sentences), reproduction steps, expected vs actual, environment metadata (redacted values only), references (commit SHA + spec ID + framework version from
manifest.yml). - Render preview. Print the full composed body. The render uses the SAME string that will be posted — no second pass between confirmation and
gh issue create. - Confirmation gate. Prompt: "type
confirmto file, or anything else to abort." Any input other than the literalconfirm→ exit non-zero "report not filed". Mandatory — automated callers must also passconfirm. Rejects empty input,y,yes, quoted/capitalized variants. No--forceflag. If the preview shows a missed leak: abort, edit the source context, re-invoke. - Submit.
gh issue create --repo arcasilesgroup/ai-engineering --title <t> --body <redacted> --label "ai-engineering,bug". Capture URL. - Archive. Write the redacted body to
.ai-engineering/support/upstream-reports/{date}-{slug}.md(slug = kebab-case title, ≤50 chars). Append aSubmitted-Issue:trailer with the step-7 URL. Audit viaframework_event kind=upstream_bug_filed.
Sanitization Vectors
Strict mode (_shared.redactor.redact(text, strictness="strict")) enforces seven patterns. Verify each against the rendered preview before confirming.
| Vector | Pattern | Replacement |
|---|---|---|
| 1. secret | `api_key | token |
| 2. user-home path | /Users/<user>/... |
$HOME/... |
| 3. private path | /private/<segment>/... |
[REDACTED-PATH] |
| 4. email | local@host.tld |
[REDACTED-EMAIL] |
| 5. GitHub token | gh[psouar]_<36+chars> |
[REDACTED-GH-TOKEN] |
| 6. username / hostname CLI | `whoami= | hostname= |
| 7. state.db SQL | line containing both state.db AND a SQL keyword |
[REDACTED-DB] |
Redaction is best-effort regex. Reviewers MUST still scan the preview for context-specific leaks (project names, customer references, business logic) before typing confirm.
Examples
User: "report upstream — the /ai-build skill hangs when the patch block is empty"
/ai-engineering-issue "/ai-build hangs on empty patch block"
Runs gh auth status (green), captures the last 10 framework events + active spec frontmatter, redacts everything strict (a /Users/... path becomes $HOME/...), renders the preview, waits for confirm. On confirm, files the issue and archives the sanitized copy. Any other input aborts with "report not filed".
Integration
Called by: user directly (after they encounter a framework bug). Reads: .ai-engineering/manifest.yml, .ai-engineering/state/framework-events.ndjson (tail), active spec frontmatter, optional --include targets. Writes: .ai-engineering/support/upstream-reports/{date}-{slug}.md. Audited: framework_event kind=upstream_bug_filed. Pairs with: _shared/redactor.py (single redaction service per D-134-09). See also: /ai-issue (project-board issues, no redaction).
$ARGUMENTS