Files
stack/agents/rocko
jason.woltjeandClaude Opus 5.5 d1629d610d fix(board): refuse foreign Host and Origin on every control-board route (#1507)
After a DNS rebind, a web page could read /api/board and POST /api/reply,
which pastes into a live seat pane. foreignRequest() now runs first and
returns 403 for a non-loopback Host, a wrong port, userinfo or a path in
Host, or any Origin other than http://<Host>. A missing Origin still passes,
which covers the WebUI proxy. Dewey authored it; Rocko approved de9ff942
(review 5a12f08e) with one low wording finding, now fixed in the notes.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 15:40:34 -05:00
..

Rocko development TUI

Run from any terminal:

/mnt/storage/src/mosaic-stack/agents/rocko/launch.sh

Rocko handles general Mosaic Stack development assignments under project lead Sage. The launcher opens Claude Code in the repository with --model sonnet and the display name Rocko. Sonnet is the selected CLI model alias; Rocko's project persona is supplied by SOUL.md, not a separate custom Claude agent.

Use --check to validate the executable and context inputs without a model call. This does not verify authentication or account access to Sonnet. Claude Code uses its normal authentication, settings, permissions, and discovered resources; this script does not copy credentials or bypass permissions.

Normal launches resume the exact Claude UUID recorded locally in .pi/state/rocko/session-id. First launch creates a UUID; --fresh creates another while retaining previous conversations in Claude's native storage. Each private launch receipt under .pi/state/rocko/launches/ retains its UUID and context snapshot. The launcher lock refuses concurrent Rocko launches through this script; it does not lock sessions opened by other means.

If Claude exits before saving its first conversation, or its history is removed, the saved UUID may not be resumable. Inspect the failure and use --fresh explicitly to start again. The launcher does not fall back to the latest unrelated project conversation. Old UUIDs in launch receipts can be opened manually with claude --resume UUID from the project directory.

The prompt snapshot includes CONSTITUTION, STANDARDS, Rocko's SOUL, the live Mosaic user profile, root AGENTS.md, and Rocko's CONTEXT.md. --soul FILE, --constitution FILE, and --user FILE override individual inputs; relative paths resolve from the repository root. Missing or empty inputs refuse launch. The snapshot is appended to Claude's system prompt on each launch.

This is a host development session, not a managed fleet registration. It loads no Pi goal extension. The user or team lead supplies the assignment.