You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
* feat(backend): tell architect which project it is in
The Architect asked "which project?" on every session because it was never
told. session.project_id reaches the DB tenant GUC, the X-Project-Id header on
every tool call, and the Celery headers — but never the prompt.
It cannot resolve this itself either: the project table is not covered by the
project_isolation RLS policy, so list_projects returns every project in the
organization with nothing marking the active one.
Resolve the project in build_agent, pass it to ArchitectAgent, and render a
block in the iteration prompt. A project that no longer resolves degrades to
no block rather than failing the turn.
The block is explicit that reads cover this project plus organization-level
entities, and that other projects' contents are not readable — RLS matches
project_id = current OR project_id IS NULL, so claiming otherwise would have
the agent give wrong reasons for what it sees.
* fix(backend): stop telling architect to resolve a project
create_endpoint's tool doc said project_id was "REQUIRED — the endpoint cannot
be created without it", and its parameter doc said to resolve it via
list_projects and "ask if ambiguous". Both are wrong: EndpointCreate.project_id
is Optional and auto_stamp fills it from the request scope. The agent followed
the docs, so it asked.
Correct create_endpoint and get_project in mcp_tools.yaml and mirror the fix
into the public tool-catalog.md. Rework the phase guidance that pushed the same
way: discovery no longer resolves project_id before create_endpoint, planning no
longer plans a project, creation only creates one when the user asked for a new
project, and save_plan's project field is documented as new-project-only.
* test(backend): cover architect project context
Pin the two facts that make the lookup necessary — the project table has no
project_id column, so list_projects cannot self-filter — and the degradation
paths, so a deleted project or a malformed id omits the block instead of
failing the turn.
Also assert no tool doc tells the agent to ask for a project, and that the
prompt block stays honest about organization-level rows and unreadable
projects.
* fix(sdk): flatten and clip project fields before the prompt
Project names and descriptions are user-controlled and the context block is
line-structured, so a newline in either forged a field: a description of
"harmless\nProject: Evil" rendered as a second Project: line and the agent read
a project the user never set.
Collapse whitespace and clip to config caps. The description is rendered every
turn, so an unbounded one was paid for on each.
Also name the exception in the resolver's warning, matching the sibling
degrade-gracefully logs in attachments.py and chat.py.
Copy file name to clipboardExpand all lines: sdk/src/rhesis/sdk/agents/architect/prompt_templates/telemachus-save-plan.j2
+2-2Lines changed: 2 additions & 2 deletions
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ When you have formulated the plan, you MUST call **save_plan** before presenting
4
4
**save_plan is strictly validated** — the call fails if any field is missing, has the wrong type, or uses a value outside the allowed set. Send arguments exactly as specified below.
5
5
6
6
Top-level structure (all three array fields are required, even if empty):
7
-
- `project`: `{name, description}` — optional. Omit entirely when no projectis needed (ad-hoc tests, single test set for an existing endpoint). Do NOT pass `null` or an empty object.
7
+
- `project`: `{name, description}` — only for creating a **new** project, which is rare. The session is already scoped to a project and entities land there automatically, so never use this field to name the project you are already working in. Omit it entirely in the normal case. Do NOT pass `null` or an empty object.
8
8
- `requirements`: array (required, may be empty)
9
9
- `test_sets`: array (required, may be empty)
10
10
- `metrics`: array (required, may be empty)
@@ -53,7 +53,7 @@ Common validation pitfalls that will be rejected:
53
53
- `test_type: "single-turn"` or `"singleturn"` → must be `"Single-Turn"` or `"Multi-Turn"` (exact case, hyphen)
54
54
- `num_tests: "15"` → must be the integer `15`
55
55
- Top-level keys missing because the section was empty → send `[]`, not omit
56
-
- `project: null` or `project: {}` when there is no project → omit the key entirely
56
+
- `project: null`, `project: {}`, or `project` naming the current project → omit the key entirely
57
57
- Extra fields not listed above are ignored, but typos in field names mean the data is dropped
58
58
59
59
When save_plan fails the error response lists each invalid field with its reason. Read it, fix the offending fields, and re-call save_plan with the corrected arguments. Do NOT proceed to other tools while the plan is unsaved.
Copy file name to clipboardExpand all lines: skills/rhesis/references/phases/creation.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ Execute the approved plan exactly — no extra entities.
5
5
## Order (mandatory)
6
6
7
7
1. Reuse lookup — resolve IDs via `list_*` + `$filter` if needed
8
-
2.`create_project` — only if planned
8
+
2.`create_project` — only when the user asked for a **new** project. The session already has one; never create a project to "hold" this work
9
9
3.`create_requirement` — **(new)** only; name + description
10
10
4. Resolve all requirement IDs
11
11
5. Metrics — **(reuse)** skip; **(improve)**`improve_metric`; **(new)**`create_metric` with plan name, **`metric_scope`**, `score_type`, `evaluation_prompt`, plus `description`, `evaluation_steps`, `reasoning`, `explanation` written to the depth in `metric-authoring.md`. Do NOT use `generate_metric`
Copy file name to clipboardExpand all lines: skills/rhesis/references/phases/discovery.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
3
3
When the user names an endpoint or wants to test an AI application:
4
4
5
-
1. Resolve endpoint: `list_endpoints` with `$select=name,id,url,description`. If missing, `create_endpoint`(resolve `project_id` via `list_projects` first).
5
+
1. Resolve endpoint: `list_endpoints` with `$select=name,id,url,description`. If missing, `create_endpoint`— it lands in the current project automatically, so omit `project_id`.
6
6
2.`check_endpoint` — report failures before proceeding.
7
7
8
8
If the project has **no** endpoint at all, lead your reply with that before any test design: nothing can run against the project until one is connected, so there are no responses to score. Show both routes — register the application's HTTP API, or wrap a Python function with the SDK's `@endpoint` decorator ([connecting an application](https://docs.rhesis.ai/docs/getting-started/connecting-application)) — and offer to create it now. Say it once; if the user would rather design tests first, continue.
Copy file name to clipboardExpand all lines: skills/rhesis/references/phases/planning.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -48,7 +48,7 @@ State the type for each test set when you present the plan, and check that the m
48
48
49
49
Propose existing entities when they match. Say explicitly: "I'll reuse 'Refuses Harmful Requests'."
50
50
51
-
Skip projectfor ad-hoc work.
51
+
Never plan a project. The session is already scoped to one, and entities land there automatically — plan a project only when the user explicitly asks for a new one.
Copy file name to clipboardExpand all lines: skills/rhesis/references/tool-catalog.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -21,11 +21,11 @@ List configured endpoints (the AI systems under test).
21
21
### `create_endpoint`
22
22
Register a new REST API endpoint (the AI system to be tested — a chat API, completion API, or chatbot).
23
23
24
-
Resolve the target project **first** with `list_projects` and pass its id — the endpoint cannot be created without a `project_id`. After creating, verify reachability with `check_endpoint`.
24
+
The endpoint is created in the current project automatically — do not resolve a project or ask which one to use. After creating, verify reachability with `check_endpoint`.
25
25
26
26
**Key parameters:**
27
27
-`name` (required) — endpoint name, unique within the project
28
-
-`project_id`(required) — UUID of the owning project; resolve via `list_projects`
28
+
-`project_id`— omit; the project scope is taken from the request
29
29
-`connection_type` — `"REST"` for HTTP APIs (default for chatbots)
30
30
-`url` (required for REST) — full endpoint URL, e.g. `https://api.example.com/chat`
31
31
-`method` — HTTP method, e.g. `"POST"` or `"GET"`
@@ -42,7 +42,7 @@ Resolve the target project **first** with `list_projects` and pass its id — th
42
42
-`auth_token` — bearer token / API key (write-only, stored encrypted)
**Common mistakes:**Omitting`project_id` — the create fails because it is a required relationship. Always resolve the project with `list_projects` first. Do NOT send server-managed fields (`id`, `user_id`, `organization_id`, `status_id`, `created_at`, `updated_at`) — `status_id` is auto-assigned to "Active".
45
+
**Common mistakes:**Sending`project_id` — it is filled from the request scope, and passing one is how endpoints end up in the wrong project. Do NOT send server-managed fields (`id`, `user_id`, `organization_id`, `status_id`, `created_at`, `updated_at`) — `status_id` is auto-assigned to "Active".
46
46
47
47
---
48
48
@@ -534,7 +534,7 @@ Create a knowledge source for grounding Single-Turn `generate_test_set`.
534
534
### `get_project`
535
535
Get one project by ID.
536
536
537
-
**CHAIN:** after `list_projects` when you need full project detail before `create_endpoint`.
537
+
**CHAIN:** after `list_projects` when the user asks about a specific project by name. Not needed before `create_endpoint` — that takes its project from the request scope.
0 commit comments