Repository navigation
fix: cap Soundwave interview at 8 questions (was ~18) - #825
Merged
Merged
Conversation
roe-template drove 10 separate ask_user_question calls and conops-template another 8 (including one for the DEPRECATED communication_plan field), so a fresh engagement paid for every dimension one field at a time before any planning document existed. - Add a hard 8-question interview budget (CRITICAL_RULES #12 in soundwave.md): only Scope and Success criteria are always asked; everything else defaults from schema/RoE/CONOPS content unless the operator's answers raise a flag a default cannot cover. - roe-template: merge related fields into 6 combined questions (was 10) instead of one ask_user_question per field. - conops-template: ask only threat-actor tier + success criteria (2, was 8); derive motivation/initial access from tier, drop the deprecated communication_plan question, agent-draft the narrative, default deconfliction method. - Fold assumption-challenge follow-ups into the original picker's options instead of spawning a second question round. Fixes #824
musicsms
pushed a commit
to musicsms/decepticon
that referenced
this pull request
Sep 28, 2026
…#825) * fix: cap Soundwave interview at 8 questions (was ~18) roe-template drove 10 separate ask_user_question calls and conops-template another 8 (including one for the DEPRECATED communication_plan field), so a fresh engagement paid for every dimension one field at a time before any planning document existed. - Add a hard 8-question interview budget (CRITICAL_RULES BitterSecurity#12 in soundwave.md): only Scope and Success criteria are always asked; everything else defaults from schema/RoE/CONOPS content unless the operator's answers raise a flag a default cannot cover. - roe-template: merge related fields into 6 combined questions (was 10) instead of one ask_user_question per field. - conops-template: ask only threat-actor tier + success criteria (2, was 8); derive motivation/initial access from tier, drop the deprecated communication_plan question, agent-draft the narrative, default deconfliction method. - Fold assumption-challenge follow-ups into the original picker's options instead of spawning a second question round. Fixes BitterSecurity#824 * chore: regenerate skills.cypher for roe/conops-template edits --------- Co-authored-by: NetVar1337 <netvar1337@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #824.
Root cause
roe-templatealone drove 10 separateask_user_questioncalls andconops-templateanother 8 (including one for theCONOPS.communication_planfield, which is DEPRECATED perSCHEMA_REFERENCEand duplicated byContactPlan). That's 18 questions before a single planning document exists — exactly matching the reporter's count.Fix
soundwave.mdCRITICAL_RULES demo #12 (new): Question Budget. Hard cap of 8ask_user_questioncalls for the whole engagement. Only Scope and Success criteria are always asked; every other dimension gets a schema/tier/RoE-derived default instead of its own question round. Assumed defaults are surfaced in the Phase 3 bundle summary so the operator corrects them after generation instead of before.roe-template/SKILL.md: 10 → 6 questions. Merges engagement name+org, in-scope+out-of-scope, and escalation contacts+auth-ref into single combined free-form answers; additional-prohibited-actions defaults silently to the standard deny-list instead of its own multi-select.conops-template/SKILL.md: 8 → 2 questions (threat-actor tier, success criteria). Motivation/initial-access derive from the tier's archetype table; attack narrative and ultimate objectives are agent-drafted, not operator homework; the deprecated communication-plan question is removed; deconfliction method defaults unless a SOC endpoint was already flagged.SOCRATIC_INTERVIEWCore Rule fix : dockerfile #3: "Challenge assumptions" now folds into the sameask_user_questioncall's options instead of a separate follow-up round — this was silently doubling questions on ambiguous answers.workflows/soundwave.md: synced anti-pattern guidance and budget note so the workflow doc doesn't contradict the system prompt.1.1.45.Verification
Manually traced the old vs. new question counts per template (RoE 10→6, CONOPS/Threat 8→2, others already 0-1 conditional) = 18 → ≤8 worst case. No code paths changed (prompt/skill markdown only), so no test suite is affected.