Adversarial red-team review of the v1.23 Nova Deck Cleanup & Python PPTX plan (7 phases, 5 waves). Overall verdict: PROCEED-WITH-REVISIONS (conf 0.78). Empirically verified (P0 risks cleared): - Image format: rendered HTML uses plain <img src="assets/png/...">, no xlink:href → inline_images.py regex will match (Axis 4 PASS, conf 0.95) - Marp <div> passthrough: minimal test deck through marp-cli@4.5.0 confirms <div class="benefit"> passes through verbatim (Axis 6 PASS, conf 0.95) - Versioning: no v1.22.* tags exist (Axis 10 PASS, conf 0.95) - Test inversion list complete (Axis 3 PASS, conf 0.92) 4 binding revisions: - G-001: Purge "penetrate" from entire repo (docs/ + .ciagent/), not just docs/presentations/ — term appears in docs/scope.md:16, docs/vision.md:18, and all .ciagent/*.md - G-002: Serialize P3→P4 — "zero file overlap" is false for verification (P3 parser depends on deck P4 trims; P4 verify render depends on P3's render_slides.sh being stable) - G-003: Split P3 into P3a (inline_images + render_slides.sh + pyproject — low-risk) and P3b (render_pptx.py + parser — high-risk, 10+ markdown constructs + python-pptx XML constraints) - G-004: Merge P5+P6 — P6 is ceremonial overhead for an NFR docs milestone; P5 absorbs review/audit/ship. Net phases: 7 (P1, P2, P3a, P3b, P4, P5+P6) No escalations (all axes resolved at conf >= 0.78). ---ci--- status: grill decisions: - G-001: Purge "penetrate" from docs/ + .ciagent/ (conf 0.85) - G-002: Serialize P3->P4 (conf 0.85) - G-003: Split P3 into P3a + P3b (conf 0.80) - G-004: Merge P5+P6 (conf 0.80) escalations: []
12 KiB
CIAgent Grill Report
Run: 2026-08-12 (mode: interactive, focus: all axes) — v1.23 Nova Deck Cleanup & Python PPTX
Overall Verdict: PROCEED-WITH-REVISIONS (confidence: 0.78)
The plan is fundamentally sound — the empirical checks (image format, Marp
<div> passthrough, versioning, test-inversion completeness) all pass. But
four binding revisions restructure the wave/phase plan and expand the
"penetrate" purge scope. Two axes were escalated-but-resolved (the empirical
verifications de-risked P2 and P3). The plan proceeds with the revisions
below.
Per-Axis Findings
Axis 1 — Scope / over-reach: PASS (conf 0.80)
Building a whole new render_pptx.py + markdown parser is significant for a
"deck cleanup" milestone, but REQ-269 explicitly mandates it, the milestone
is NFR docs/render/test-only (no runtime impact), and the dual-PPTX value
(MARP image-of-slide + python structured/editable) is a real deliverable, not
gold-plating. The G-003 split (P3a/P3b) mitigates the parser-complexity risk.
The plan stays in scope; it does not reach into the deck's 4-beat narrative
arc (out-of-scope section confirms).
Axis 2 — Hidden dependencies (P3/P4 "zero file overlap"): REVISE → G-002 (conf 0.85)
The "zero file overlap" claim is true for EDITS but false for VERIFICATION.
P3's render_pptx.py parsing logic depends on the deck markdown structure
that P4 is simultaneously trimming; P4's verify step runs render_slides.sh
that P3 is mid-editing. Binding revision G-002: serialize P3→P4.
Axis 3 — Test inversion risk: PASS (conf 0.92)
The plan's test-update list (Finding 5 / P5 tasks) is complete and accurate. Empirically confirmed all affected tests:
test_marp_deck_not_using_default_theme(line 66-74: invert — we now USEtheme: default) ✓ plan mentionstest_marp_deck_uses_sp_theme(line 55-64: rewrite to assert inlinestyle:block) ✓ plan mentionstest_theme_css_*trio (lines 275, 284, 295: retarget to inlinestyle:) ✓test_html_embeds_theme(line 353:--sp-red→#D6002A) ✓ plan mentionstest_source_md_*pair (lines 240, 266: delete — plain.mdgone) ✓test_render_slides_script_renders_marp(line 92: still produces.pptxvia marp-cli for the fallback PPTX) — ✓ plan handles- No latent assertions missed. The plan's enumeration is thorough.
Axis 4 — Image-inlining correctness: PASS (conf 0.95)
Empirically verified the rendered HTML at
docs/presentations/nova-autonomous-cloud-delivery.html uses plain
<img src="assets/png/platform-pipeline.png" ...> and
<img src="assets/png/telemetry-live-ops.png" ...> — standard <img> tags
inside Marp's SVG <foreignObject> wrapper. Zero xlink:href occurrences.
The inline_images.py regex (<img\s+src="([^"]+)") will match. The 2
data:image matches already in the HTML are Marp OSC onscreen-control SVG
icons (CSS backgrounds, not slide images) — not a conflict. P0 risk
cleared.
Axis 5 — python-pptx parser complexity: REVISE → G-003 (conf 0.80)
The parser must handle 10+ distinct markdown constructs (frontmatter, ---
separators, H1/H2, bullets, bold leads, blockquotes, fenced code, images,
markdown tables, <div class="benefit"> HTML blocks) plus edge cases
(tables with **bold** R/A cells, nested bullets, class:tall image alt
text) plus two python-pptx constraints (no CSS font fallback — single
font.name; blank layout has no bullets — must inject <a:buChar> XML).
Finding 3 confirmed the APIs exist but the parser is non-trivial. With P3
on the serial critical path (G-002), an overflow blocks everything.
Binding revision G-003: split P3 into P3a (inline_images + render_slides.sh
- pyproject — low-risk mechanical) and P3b (render_pptx.py + parser + the attach_release_asset.py extension — high-risk).
Axis 6 — Benefit callout <div> in Marp: PASS (conf 0.95)
Empirically verified by rendering a minimal test deck through
@marp-team/marp-cli@4.5.0 (the pinned version): <div class="benefit">text</div>
passes through verbatim into the rendered <section>. Marpit's html: true
option is on by default; no sanitization of styling divs. The .benefit class
in the inline style: block will apply. P2's restyle approach is valid.
P0 risk cleared.
Axis 7 — "penetrate" removal completeness: REVISE → G-001 (conf 0.85)
CRITICAL gap. The plan's verify step grep -ri penetrat docs/presentations/
misses docs/scope.md (line 16: "Nova never penetrates the PDLC") and
docs/vision.md (line 18: "It does not penetrate upstream product or
software development lifecycles") — the repo's two core strategic docs. The
term also appears in every .ciagent/ file (PLAN, REQUIREMENTS, RESEARCH,
CLARIFY, ROADMAP, PROJECT, PERSONAS, NORTH_STAR). The deck does not link out
to these docs, but they are audience-reachable via the repo.
Binding revision G-001: purge "penetrate" (and derivatives) from the
entire repo — docs/ AND .ciagent/. P4's verify step becomes
grep -ri penetrat docs/ .ciagent/ returns nothing. test_no_penetrate_term
asserts the same. The deleted plain .md (P1) already removes its
occurrence; docs/scope.md + docs/vision.md reworded in P4; all
.ciagent/ files reworded across the relevant phases (the phase that owns
each file's edit window).
Axis 8 — Wave 3 parallelization feasibility: REVISE → G-002 (conf 0.85)
Resolved by G-002 (serialize P3→P4). Wave 3 is no longer parallel. P3's
render_slides.sh is stable before P4 runs its verify render; P3's parser
is tested against the current (untrimmed) deck before P4 trims it.
Axis 9 — Phase count vs. value: REVISE → G-004 (conf 0.80)
G-003 split P3 (→8 phases); G-004 merges P5+P6 to compensate. P6 (final-review-ship) for an NFR docs-only milestone is largely ceremonial — the review/audit/ship work folds into P5's final commits. Binding revision G-004: merge P5+P6. Net phase count returns to 7.
Axis 10 — Versioning: PASS (conf 0.95)
git tag --list 'v1.22.*' returns nothing — no conflicts. The v1.21.x line
(v1.21.0..v1.21.6) is the precedent; v1.23 tags v1.22.0..v1.22.6 per the
revised phase plan (G-003 split shifts tag numbers; G-004 merge keeps the
final at v1.22.6).
Binding Decisions
| ID | Decision | Confidence | Rationale |
|---|---|---|---|
| G-001 | Purge "penetrate" (and derivatives) from the entire repo — docs/ AND .ciagent/, not just docs/presentations/. P4 verify: grep -ri penetrat docs/ .ciagent/ returns nothing. test_no_penetrate_term asserts the same. docs/scope.md:16 + docs/vision.md:18 reworded in P4; all .ciagent/ files reworded in the phase that owns each file's edit window. |
0.85 | The term appears in the repo's two core strategic docs (audience-reachable) and all internal metadata. REQ-272 says "removed from all presentation files"; the user confirmed a full-repo purge (politically loaded term). The plan's docs/presentations/-only grep is a gap. |
| G-002 | Serialize P3→P4. Wave 3 is no longer parallel. P3 completes (stable render_slides.sh + tested parser against the current deck) before P4 trims the deck + purges "penetrate" (per G-001). C8's parallelization rationale is overruled. |
0.85 | "Zero file overlap" is true for edits but false for verification: P3's parser depends on the deck structure P4 is trimming; P4's verify render depends on P3's render_slides.sh being stable. The interaction risk is the failure mode. |
| G-003 | Split P3 into P3a (inline_images.py + render_slides.sh inline-images step + pyproject.toml — low-risk mechanical) and P3b (render_pptx.py + the full markdown parser + render_slides.sh python-pptx step + attach_release_asset.py extension — high-risk). Both serial in Wave 3. | 0.80 | The parser handles 10+ markdown constructs + python-pptx XML constraints (font fallback, bullet injection); on the serial critical path (G-002) an overflow blocks everything. Splitting isolates the high-risk work. |
| G-004 | Merge P5+P6. P5 absorbs the final-review/audit/ship work (multi-persona review, reconstruction audit, milestone merge, tag, release, branch cleanup, REQUIREMENTS/ROADMAP update) as its final commits. Tag v1.22.6 = milestone release. | 0.80 | For an NFR docs-only milestone, a dedicated review/ship phase is ceremonial overhead. P5 already asserts the final state via tests. The merge compensates for the G-003 split, returning to 7 phases. |
Escalations
None. All axes resolved at confidence ≥ 0.78. Two axes (4 and 6) were
escalation candidates (P0 risks if the empirical checks failed) but both
were cleared by direct verification — the rendered HTML uses plain <img src="assets/..."> (not SVG xlink:href), and Marp 4.5.0 passes through
<div class="benefit"> verbatim (empirically confirmed with a minimal test
deck).
Revised Wave/Phase Plan (post-revisions)
Wave 1 (P1): consolidate-docs (edits -marp.md, deletes plain .md)
↓
Wave 2 (P2): restore-clean-style (edits -marp.md frontmatter +
↓ benefit callouts; edits render_slides.sh; retires
nova-sp-theme.css from render)
↓
Wave 3 (P3a → P3b, serial):
P3a: inline-images (inline_images.py + render_slides.sh step + pyproject)
↓
P3b: python-pptx-generator (render_pptx.py + parser + render_slides.sh
step + attach_release_asset.py extension)
↓
Wave 4 (P4): trim-wordcount + purge "penetrate" (edits -marp.md +
↓ talking-points.md + docs/scope.md + docs/vision.md +
all .ciagent/ files per G-001)
↓
Wave 5 (P5+P6 merged): ci-tests-readme + final-review-ship (tests, CI,
README, multi-persona review, audit, ship —
tag v1.22.6 = milestone release)
Revised Tag Plan
- v1.22.0 (P0 — already tagged)
- v1.22.1 (P1)
- v1.22.2 (P2)
- v1.22.3 (P3a)
- v1.22.4 (P3b)
- v1.22.5 (P4)
- v1.22.6 (P5+P6 merged — final patch = milestone release)
P4 expanded scope (per G-001)
P4 now owns, in addition to the deck word-count trim:
docs/scope.md:16— reword "Nova never penetrates the PDLC"docs/vision.md:18— reword "It does not penetrate upstream product or software development lifecycles".ciagent/PLAN.md,REQUIREMENTS.md,RESEARCH.md,CLARIFY.md,ROADMAP.md,PROJECT.md,PERSONAS.md,NORTH_STAR.md— reword every "penetrate" occurrence (or the phase that owns each file's edit window does so; P4 is the natural owner since it owns the "penetrate" removal requirement REQ-272).
P5 expanded scope (per G-004)
P5 now owns, in addition to the test/CI/README work:
- Multi-persona code review (
ciagent-review) of the milestone branch - Audit (
ciagent-audit) — reconstruction test + .ciagent discipline - Milestone ship (
ciagent-ship) — merge to milestone branch → main, tag v1.22.6, release with both PPTX attached, delete milestone branches - Update REQUIREMENTS.md (mark v1.23 complete) + ROADMAP.md (mark v1.23 complete)
- Commit:
docs(milestone): complete v1.23 — Nova Deck Cleanup & Python PPTX
Evidence Index
- Image format:
docs/presentations/nova-autonomous-cloud-delivery.htmlgrep — 2×<img src="assets/png/...">, 0×xlink:href - Marp
<div>passthrough: minimal test deck rendered through@marp-team/marp-cli@4.5.0→<div class="benefit">survives verbatim - Versioning:
git tag --list 'v1.22.*'→ empty (no conflicts) - "penetrate" occurrences:
grep -riI penetrat→ docs/scope.md:16, docs/vision.md:18, docs/presentations/{-marp.md, .html, .md, -talking-points.md}, all .ciagent/*.md - Test inversion targets: tests/test_slides_pipeline.py lines 55-64 (rewrite), 66-74 (invert), 240-270 (delete), 275-302 (retarget), 353-359 (assert #D6002A not --sp-red)
- Benefit callout count: 21
**Benefit:**in current deck → 21<div class="benefit">in P2