ci(wifi-veil): add honesty / anti-slop guard

Add scripts/ci-guard.sh and a `guard` CI job that statically enforce the
project's honesty invariants so they cannot silently regress:

- no telemetry (.claude-flow/), build artifacts, lockfile, or scratch/probe
  files committed;
- no debug / mock-probe / slop markers in source
  (panic!("probe...), dbg!, println!("DEBUG, TODO(ai), LOREM IPSUM, ...);
- the SYNTHETIC evidence label present on every firmware provider README, and
  the "never jamming" compliance disclaimer present in the root + firmware READMEs;
- no dishonest hardware-validation claims — honest negated / TODO(hw) /
  build-only mentions are explicitly allowed (negation-aware);
- no stale monorepo crate/harness identifiers in the code/manifest surface.

Scans only git-tracked files under the tree, so it works both in-monorepo and
in the extracted standalone repo, and never trips on untracked local scratch or
target/. Documented in CONTRIBUTING.md; passes clean on the current tree.

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01WEXNqzs7UsfNFBcP5yW21p
This commit is contained in:
Claude
2026-08-09 17:20:03 +00:00
parent 17ba9df19a
commit e2ffecde9a
3 changed files with 134 additions and 0 deletions

View File

@@ -10,6 +10,14 @@ concurrency:
cancel-in-progress: true
jobs:
guard:
name: Honesty / anti-slop guard
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Enforce honesty / anti-slop invariants
run: bash scripts/ci-guard.sh
rust:
name: Rust (test + lint + wasm)
runs-on: ubuntu-latest