Documentation Gap
.github/copilot-instructions.md:45 instructs agents: Install: npm install.
Issue #703 ("Documented setup installs with npm install, bypassing the reviewed package-lock.json that CI's npm ci enforces") was closed completed on 2026-09-27, and the human-facing docs were fixed — README.md, CONTRIBUTING.md, and AGENTS.md all now prescribe npm ci as the canonical install and explicitly reserve npm install <package> for intentional dependency changes ("it re-resolves the ranges in package.json and rewrites the lockfile"). The fix missed the agent-facing Copilot instructions, the one file most likely to be followed literally by an automation agent.
Verified at main @900592b: grep -rn "npm install" across README.md, CONTRIBUTING.md, AGENTS.md, docs/skills/*.md, and .github/copilot-instructions.md — the only bare npm install instruction left is .github/copilot-instructions.md:45.
Impact
AI agents working in the repo (a heavily used path here — see GOVERNANCE.md's agent-automation policy) get an install instruction that contradicts the integrity-checked npm ci contract every CI workflow uses, risking unintended lockfile rewrites in agent-authored PRs.
Recommendation
Change line 45 to - Install: \npm ci`(optionally with the same one-line rationale the other docs carry: installs the exact, integrity-checked versions inpackage-lock.json`, matching CI).
Filed by guide agent (ACMM L4 — issues-only mode)
🐝 Hive Agent: guide | Instance: hosted-available-lke648397-260827-5n31 | SHA: unknown
— hive: agent=guide backend=copilot model=kimi-k3 copilot=1.0.88
Documentation Gap
.github/copilot-instructions.md:45instructs agents:Install: npm install.Issue #703 ("Documented setup installs with
npm install, bypassing the reviewed package-lock.json that CI'snpm cienforces") was closed completed on 2026-09-27, and the human-facing docs were fixed — README.md, CONTRIBUTING.md, and AGENTS.md all now prescribenpm cias the canonical install and explicitly reservenpm install <package>for intentional dependency changes ("it re-resolves the ranges inpackage.jsonand rewrites the lockfile"). The fix missed the agent-facing Copilot instructions, the one file most likely to be followed literally by an automation agent.Verified at main @900592b:
grep -rn "npm install"across README.md, CONTRIBUTING.md, AGENTS.md, docs/skills/*.md, and .github/copilot-instructions.md — the only barenpm installinstruction left is.github/copilot-instructions.md:45.Impact
AI agents working in the repo (a heavily used path here — see GOVERNANCE.md's agent-automation policy) get an install instruction that contradicts the integrity-checked
npm cicontract every CI workflow uses, risking unintended lockfile rewrites in agent-authored PRs.Recommendation
Change line 45 to
- Install: \npm ci`(optionally with the same one-line rationale the other docs carry: installs the exact, integrity-checked versions inpackage-lock.json`, matching CI).Filed by guide agent (ACMM L4 — issues-only mode)
🐝 Hive Agent:
guide| Instance:hosted-available-lke648397-260827-5n31| SHA:unknown— hive: agent=guide backend=copilot model=kimi-k3 copilot=1.0.88