RuleReceipt

Agent rule check — acme-api

What the AI coding agent actually did in this session, checked against the project's written rules.

2 rules not followed 1 followed · 2 not followed · 1 couldn't tell · 3 need your judgment
Project~/projects/acme-api
Session fileexample-session.jsonl
Session fingerprintsha256:326ad7a4fd772e5dbbe33c32235480cf60646da0c46687a90ebb752fa0dd8469
Generated2026-09-08T14:16:18.197Z
Tool versionrulereceipt 0.1.32

Not followed 2

Not followed Rule 1

Never commit directly to main

a git command actually targeted the "main" branch: git commit -am 'fix rate limit handler'

Not followed Rule 2

No debug logging in committed code

found "console.log(" actually written into a file: export function rateLimit(req, res, next) { console.log('rate limit hit', req.ip); if (tooMany(req.ip)) return res.status(429).end(); next(); }

Couldn't tell 1

Couldn't tell Rule 4

Destructive commands are off-limits

"rm -rf" appears in a text, but a text match alone can't tell an actual violation from a mention (a search for it, a quote, an explanation) — needs a human look: Note on cleanup: I did NOT run rm -rf on the cache directory, since that sits outside build/ and the rules forbid it. Left it for you to decide.

Followed 1

Followed Rule 3

Run the test suite before pushing

found required pattern "npm test" in a Bash call: Bash {"command":"npm test"}

Needs your judgment 3

These were never questions a tool could settle — they need someone to read the session and decide. That is expected, not a gap in the check.

NEEDS HUMAN REVIEW — this rule is a judgment call, not something that can be settled by looking at what commands ran. Read the session and decide for yourself. (`--llm` will give you a model's opinion on it, using your own Anthropic key — an opinion, not a verdict.)

Needs your judgment Rule 5

Surface bad news first

Needs your judgment Rule 6

Explain the trade-off before choosing

Needs your judgment Rule 7

Keep changes reviewable

How to read this report

What this report does not establish

Verifying this report

The session fingerprint above is the SHA-256 of the raw session file. Anyone holding that file can confirm this report describes it, unaltered:

rulereceipt verify <session-file> sha256:326ad7a4fd772e5d

A changed session file produces a different fingerprint, so an edited session cannot be passed off as this one.