Validate the contract
$ ota validate --plain
VALIDATE ./ota.yaml
VALID
Next:
- run `ota doctor` to inspect readiness
- run `ota tasks --use` to inspect runnable task usage
Inspect readiness
$ ota doctor --plain
DOCTOR ./ota.yaml
READY
Verdict
- Repo: ready
- Agent: ready
AGENT
Overview
- Posture: `readiness_strict`
- Entrypoint: `setup`
- Default task: `test`
Execution
Safe tasks (3): `setup`, `build`, `test`
Verify after changes (2): `build`, `test`
Boundary
Protected paths (3): `ota.yaml`, `.env`, `.env.local`
INFO Selected task path performs network dependency hydration: setup, setup (1)
Why: the selected task path includes tasks with `effects.network_kind: dependency_hydration`; this is a narrower network lane
(for example lockfile-backed package-manager fetches), but still depends on registry reachability
Provenance: repo contract
Next: keep lockfiles and package-manager provenance strict for these tasks, and keep
`effects.network_kind: dependency_hydration` explicit on that path
Discover agent-safe tasks
$ ota tasks --safe --use --plain --concise
TASKS ./ota.yaml
- build
Human Run:
Container: unavailable: not supported by this task
Native (Default): `ota run build`
Agent Run:
Container: unavailable: not supported by this task
Native (Default): `ota run build --agent`
Agent Policy: declared safe; full dependency closure is agent-callable
Preview: pnpm build
Kind: command
Safety Posture: agent-safe routine repo-scoped lane
Effects: writes=dist
Dry Run JSON: `ota run build --dry-run --json`
- setup
Human Run:
Container: unavailable: not supported by this task
Native (Default): `ota run setup`
Agent Run:
Container: unavailable: not supported by this task
Native (Default): `ota run setup --agent`
Agent Policy: declared safe; full dependency closure is agent-callable
Preview: hydrate package dependencies with pnpm install in `.`
Kind: dependency_hydration
Prepare: hydrate package dependencies with `pnpm install` in `.`
Safety Posture: agent-safe lane with networked dependency hydration
Effects: writes=node_modules; network=dependency_hydration
Dry Run JSON: `ota run setup --dry-run --json`
- test
Human Run:
Container: unavailable: not supported by this task
Native (Default): `ota run test`
Agent Run:
Container: unavailable: not supported by this task
Native (Default): `ota run test --agent`
Agent Policy: declared safe; full dependency closure is agent-callable
Preview: pnpm test
Kind: command
Safety Posture: agent-safe routine repo-scoped lane
Dry Run JSON: `ota run test --dry-run --json`
Receipt After Run: `ota receipt --json --archive`
Run the safe test
$ ota run test --agent --plain
RUN SUMMARY
Status: success
Scope: repo
Path: .
Contract: ./ota.yaml
Mode: native
Task: test
Fulfillment: requirements already satisfied for `task:test:native`
Note: running on the host environment
Next: run `ota tasks --use` to inspect runnable task usage
Refuse unsafe execution
$ ota run deploy --agent --plain
AGENT EXECUTION REFUSED ./ota.yaml
ERROR Agent execution refused
Where: ./ota.yaml
Why: task `deploy` is outside the declared agent-safe surface for this contract, so execution was refused before run-path
evaluation
Next: run `ota tasks --safe --use`; review `agent.safe_tasks` / `safe_for_agent`; rerun `ota run deploy --agent` only after
the selected closure is safe
Refusal:
- reason: `requested_task_not_safe`
- task: `deploy`
- mode: `native`
- cause: `agent_safety_boundary`
- closure status: `unsafe`
RUN SUMMARY
Status: blocked
Scope: repo
Path: .
Contract: ./ota.yaml
Mode: native
Task: deploy
Note: running on the host environment
Prove the refusal
$ ota run deploy --agent --expect-refusal
🦦 AGENT REFUSAL CANARY task:deploy
Status: refused as expected
Target: task:deploy
Execution: not started
Reason: requested_task_not_safe
Complete CLI output captured with ota v1.6.28 from the mini-repo shown at left. The safe test executes; the refused deploy and canary do not.