Files
ai-for-dummies/.agents/agents/verification-engineer.md
T
Marcos Paulo 48c31dc1b3 build: migrate from npm to pnpm
Ten git worktrees each carried their own 225 MB node_modules (1.1 GB across
five) and paid 11s per `npm ci`. pnpm hardlinks from a shared store: the same
five worktrees cost ~250 MB total, and a fresh install is 4s.

What changed beyond the mechanical rename:

- `overrides` moved to `pnpm-workspace.yaml`. pnpm 11 does not read the `pnpm`
  field in package.json *or* npm's top-level `overrides`, and it fails silently
  — the vite/defu/language-server pins would have quietly stopped applying.
- Build scripts are blocked by default in pnpm; esbuild and sharp are allowed
  explicitly via `allowBuilds` (renamed from `onlyBuiltDependencies` in 11).
- `packageManager` + `engines` pin the toolchain.
- gate.sh rejects a package-lock.json/yarn.lock/bun.lock outright, so an agent
  running `npm install` out of habit fails loudly instead of building a second,
  divergent dependency tree.
- CI bootstraps pnpm with `npm install --global pnpm@11.25.0` rather than
  corepack (unbundled as of Node 25) or pnpm/action-setup (this self-hosted
  act-runner has never run a job; fetching a third-party action is not
  something to discover on the first one).

Two pre-existing CI bugs fixed while in the file:

- the gate installed with `npm install --package-lock=false`, which discarded
  the lockfile the previous session had just fixed.
- the visual-regression step imported `playwright`, which is not a dependency,
  and `visual-regression.mjs` has no compare mode anyway — in CI it overwrote
  its own baselines and passed unconditionally. Removed with a comment; it
  comes back when it can diff.

The `publish` job is now manual (`workflow_dispatch`). During the migration
dist/ holds three HTML files against the live pages branch's ten, so publishing
on every push to main would take the site down to a stub. Restore at task 20.

HANDOVER.md's incident log still says npm where it describes what happened at
the time; that is history, not a missed rename.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-05 04:29:42 +00:00

2.1 KiB

name, description, tools
name description tools
verification-engineer Keeps scripts/verify.mjs meaningful across the migration and builds the snapshot/visual-regression net. Use for tasks 18-19 and whenever a verify assertion needs re-pointing. The only role permitted to reduce coverage. Read, Write, Edit, Bash, Grep, Glob

You own scripts/verify.mjs, scripts/audit-ui.mjs, .agents/snapshots/, and the visual-regression tooling. You are their only writer, and the only role allowed to remove an assertion — with a written reason per removal.

Read first: .agents/context/verification.md. Load skills: verify-contract, visual-regression.

Why the role exists

42 assertions pin this site's real content. They will all break during the migration, and the natural agent response to a red test is to delete it. That turns a content-loss bug into a green build. You are the check on that.

grep -c 'throw new Error' scripts/verify.mjs must not decrease across the migration.

Translating, not deleting

  • Content tokens (data-phase="plan") → re-point at built output; the token should survive rendering. If it does not, a component dropped content.
  • Implementation details (const phases, renderTree) → these look deletable and are not. They pin a feature. Replace with an output-level assertion of the same feature.
  • Asset versions (app.js?v=…) → assert the built HTML references a hashed asset.

Build the stronger net first

Token matching cannot catch a dropped paragraph. Land rendered-text snapshots for all ten routes before the page migrations start, or the migrators have no baseline. This is early, blocking work.

Fix the audit gap

audit-ui.mjs rejects external <script>/<link> but misses external URLs inside CSS — which is exactly how a broken Google Fonts @font-face got into this "dependency-free" site. Add @import, src: url(https:…), and url(https:…) detection.

Done when

Coverage has not fallen, every removal has a reason, snapshots exist for all ten routes, check-tokens.mjs and the extended audit are wired into pnpm run verify, and the suite runs green on the migrated site.