Files
agenticCode/prompts/wgeagb0s-deep-api-audit.md
Ingo Schnabel 2c56eea161 Remove MCP
2026-08-04 12:57:08 +02:00

5.1 KiB

Deep API Audit — WGEAGB0S + its complete call tree (the whole web service)

Preconditions: Before you start this audit, run ./rebuild-and-refresh.sh and wait for its "Both deep refreshes finished" banner. It stops the server, rebuilds + redeploys it (so the audit runs against the current code), then deep-refreshes both upms and pur. For this audit prompt you are explicitly authorized to run that script yourself — the standing "never deploy / never start Docker" rule is waived for rebuild-and-refresh.sh in this context (only for this script; do not run manage-ac.sh/docker directly). If the script fails, stop and report rather than proceeding against a stale or down server. Do not interrupt the deep refresh once it is running.

Task

Perform a very deep analysis of all agentic API endpoints, in two tiers:

  1. Deep dive — WGEAGB0S (worked example): ingest module WGEAGB0S and, for each endpoint, determine whether the response is correct by manually reading the Natural source and comparing it against the API output, field-by-field.
  2. Broad sweep — WGEAGB0S's complete call tree (the whole web service): verify the same endpoints across every module transitively reachable from WGEAGB0S, i.e. the full transitive closure of its call-tree/graph (direct and indirect callees, to unlimited depth), not just WGEAGB0S itself. This is the complete web service that WGEAGB0S fans out into. Manual reading of every source at that scale is infeasible, so drive the sweep with automated cross-checks (below) that catch whole classes of defects, and escalate any module that fails a check to a manual, source-level deep dive like tier 1.

How to work

IMPORTANT: use the API described in x-docs/agent-api-system-prompt.md to analyze WGEAGB0S

  1. Use the REST API (GET /api/projects/upms/modules/{name}/...), falling back to the ac CLI for quick manual checks. For WGEAGB0S (and any escalated module) pull every relevant endpoint: callees, callers, db-accesses, functions, data-structures, dispatch-table, digest, context, call-tree, sql-statements, graph.
  2. Read the Natural source manually (the module plus its USING data areas / copycodes) and verify each response field-by-f.manield: call graph, DB accesses (READ/WRITE mode), variable reads/writes, field/placeholder resolution, dispatch table. Note the sources are ISO-8859 encoded — use grep -a / an encoding-aware reader.
  3. Broad-sweep cross-checks (WGEAGB0S's complete call tree). Enumerate the full transitive closure of modules reachable from WGEAGB0S — pull its call-tree/graph at unlimited depth (raise the depth parameter until the module set stops growing and truncated is false), take every MODULE-typed node, and iterate. Then assert API-derivable invariants that need no per-module reading, e.g.:
    • No MODULE self-loop: callers/callees never list a module as its own caller/callee.
    • callers default is external-only: the default view lists incoming CALLNAT/inheritance only — never the module's own subroutines (those belong to scope=internal).
    • Callee resolution matches source: every callees CALLNAT target appears as a real CALLNAT '<name>' in the module or one of its INCLUDEd copycodes (grep-verifiable), with correct viaCopycode/includedAt provenance — and no phantom targets.
    • Function count parity: digest.functionCount == the number of DEFINE SUBROUTINE in the source; every performed subroutine exists as a FUNCTION.
    • DB access sanity: modules with no READ/FIND/STORE/UPDATE/DELETE report empty db-accesses/sql-statements; those with them resolve to real DB_TABLEs.
    • Closure completeness: every CALLNAT target surfaced by any module in the tree is itself in the enumerated module set (the closure is self-consistent — no reachable module is missed). Rank modules by check failures; the worst offenders get a tier-1 manual deep dive.
  4. Report every discrepancy you find. For each: the endpoint and exact wrong value, the ground truth from the source (with line references), and the suspected root cause in the parser/enricher/Cypher. For sweep findings, report the failing invariant, the count and list of affected modules, and a representative worked example.
  5. Propose a concrete fix for each error.
  6. Write failing characterization tests first (Testcontainers ITs with minimal Natural fixtures that reproduce the bug), then confirm they go green after the fix.

Output

A structured report:

  • Per-endpoint for WGEAGB0S: PASS or the list of discrepancies with ground-truth evidence, root-cause hypothesis, fix proposal, and the test that covers it.
  • Broad sweep (WGEAGB0S call-tree closure): the enumerated module set (count + how depth was driven to completeness), then per invariant PASS or the affected-module count + list + a worked example, with the same root-cause/fix/test treatment for each distinct defect class.
  • Propose how the API could be improved to get better Code Analysis results