Author: @Tom-Zafred | Maintained by Biomed Systems Ltd (UK)
Specification Standard: British English (en-GB)
Target Platform: Google Antigravity & Model Context Protocol (MCP) Ecosystem
Architecture Blueprint & Open-Source Gist: https://gist.github.com/Tom-Zafred/7be8e3efcf9b76d27945eaa3dc44ae49
1. The 5-Second Emotional Hook: The “Rule Amnesia” Trap
Every developer operating in long-horizon agentic coding sessions knows this exact failure mode:
- Turn 1: The agent digests a monolithic, 4,000-token narrative prompt file (
AGENTS.md,CLAUDE.md,.cursorrules) and adheres to your architectural constraints. - Turn 25: As conversation trajectory expands, the agent succumbs to the “Lost in the Middle” attention dip. It forgets critical database paradigms, resurrects forbidden legacy libraries, writes non-standard queries, and repeats anti-patterns you explicitly forbade at the start of the session.
- The Multi-Repo Nightmare: Across 10+ sibling microservices or client repositories, teams copy-paste instruction files manually. Rules drift silently, contradictory constraints emerge, and maintaining shared architectural standards becomes an unsustainable manual chore.
Traditional natural language prompt files are fundamentally flawed: they suffer from low signal-to-noise ratio (SNR), lack compile-time AST validation, and burn thousands of pre-fill tokens on every single turn.
RFC-004 (governance-guard) solves this permanently with a zero-dependency, native Model Context Protocol (MCP) engine and compiler that treats agent rules as compiled runtime bytecode rather than conversational prose.
2. Platform ROI: Why Every Platform Engineering Team Needs This
For engineering teams and platform architects operating agentic workbenches at scale, conversational prompt bloat represents a compounding infrastructure tax:
========================================================================================
COMPUTATIONAL & LATENCY BENCHMARKS
========================================================================================
Metric Narrative Markdown Prose RFC-004 Compiled ANIR Engine
----------------------------------------------------------------------------------------
Pre-Fill Token Footprint 3,500 – 6,000 tokens/turn 600 – 1,100 tokens/turn (75% ↓)
Time-To-First-Token (TTFT) ~1,450 ms ~410 ms (3.5× Faster)
Cross-Repo Rule Propagation Manual Copy-Paste / Lag 0.00 ms (Physical Hardlink Fabric)
Rule Conflict Detection None (Silent Hallucination) < 0.08 ms (AST Inverted Domain Index)
IPC Query Latency 180 ms (Process Spawning) 0.41 – 1.12 ms (Native OS Named Pipe)
Multi-Repo Onboarding ~1,800 ms (Serial Disk I/O) 9.83 ms (Concurrent Batch Engine)
Lock-in / Rollback Risk Irreversible Manual Edits 1-Click Atomic Restore (/gov 0 / /gov 5)
========================================================================================
- KV-Cache Economics: Slashing prompt pre-fill weight by ~75% saves >25,000 tokens per turn in multi-workspace environments, dramatically lowering token overhead and freeing GPU/TPU Key-Value cache memory.
- Sub-Millisecond AST Conflict Gate (< 0.08ms): Candidate rules are validated against an in-memory inverted domain token index (
Map<domain, Set<tokens>>). Conflicting rules (e.g. “mandate Vanilla DOM” vs “use jQuery plugins”) are intercepted and rejected at pre-commit time before ever reaching the LLM’s context window. - Zero-Latency Physical Hardlink Fabric: Sibling repositories share physical MFT/inode disk blocks. Broadcasting a rule to a governance family synchronises every linked project in the exact same millisecond with zero background polling.
3. High-Contrast System Architecture
+-------------------------------------------------------------------------------------+
| DEVELOPER WORKBENCH (IDE) |
| |
| Turn 1 Context Check ────► [governance-guard MCP Server] (0.41ms IPC Bridge) |
| │ |
| ▼ |
| ~/.gemini/antigravity/governance/ |
| ├── registry.json (Families & Signatures) |
| ├── backups/ (Atomic Pre-Commit Snapshots) |
| ├── snapshots/ (Clean Start Cryptographic Archives) |
| └── families/ |
| ├── enterprise-core/rules.anir |
| ├── commercial-web/rules.md |
| └── agentic-platform/rules.anir |
| │ |
| +──────────────────────────┴──────────────────────────+ |
| ▼ (Native NTFS / POSIX Physical Block Hard Link) ▼ |
| [Repo A: Microservice 1] [Repo B: Microservice 2] |
| AGENTS.md ◄─────────────────────────────────────────────► AGENTS.md |
| (Bit-for-Bit Physical Block Synchronisation Across Sibling Repositories) |
+-------------------------------------------------------------------------------------+
The Agent-Native Intermediate Representation (ANIR)
Why narrative conversational English fails in model attention heads:
-
Conversational Prose (Low SNR — 42 tokens):
“Whenever you write database queries in this project, you must never write N+1 select loops in the application layer, but instead always use set-based batch operations via Table-Valued Parameters.”
-
Compiled ANIR Vector (High SNR — 9 tokens — 78% reduction):
[DB: SET_BASED(TVP|XML_SHRED) !N1_LOOP]
The Dual-Mode Paradigm
- Machine Mode (ANIR): The
.mdfile on disk acts as the compiled runtime intermediate representation (IR) ingested into the model’s KV cache. - Human Decompiler (
/gov 2//gov explain): When a human developer asks “What are the rules for this repository?”, the engine decompiles active ANIR vectors into fluent, structured British English prose on demand.
3-Tier Lifecycle Execution Model
Rules are categorised into three strict temporal phases to eliminate instructional ambiguity:
[PHASE:BEFORE]: Pre-flight intake, attributable operator checks, environment validation.[PHASE:DURING]: In-flight code generation invariants, separation of concerns, set-based database execution.[PHASE:AFTER]: Selective compilation, assertion verification gates, ephemeral test daemon termination.
4. Turnkey 1-Line Remote Installation (Zero Third-Party Dependencies)
governance-guard requires zero external npm packages and runs natively on standard Node.js (v18+) and standard OS APIs.
Remote 1-Line Installation
- Windows (PowerShell):
irm https://gist.githubusercontent.com/Tom-Zafred/7be8e3efcf9b76d27945eaa3dc44ae49/raw/install.ps1 | iex
- Linux / macOS (Bash / zsh):
curl -fsSL https://gist.githubusercontent.com/Tom-Zafred/7be8e3efcf9b76d27945eaa3dc44ae49/raw/install.sh | bash
The installer automatically provisions the central vault, deploys the MCP server, pre-warms the shell JIT background runspace, registers /gov and /gov? shell functions, and launches the guided 3-step setup wizard.
3-Tier Rule Scoping Hierarchy
# Tier 1 (Family - Default): Broadcasts across all sibling repositories in active family
/gov 8 Strictly use Pure Vanilla JavaScript
# Tier 2 (Global): Enforces across all present and future workspaces via ~/.gemini/GEMINI.md
/gov 8 --global Strictly adhere to British English spelling
# Tier 3 (Local): Confined strictly to current repository via .gemini-instructions.md
/gov 8 --local Isolated custom testing invariant
Advanced Directives & Operations
/gov wizard # 3-step guided configuration wizard (/gov setup)
/gov 1 # Real-time status & physical link health
/gov 2 # Decompile active machine tokens into plain British English
/gov 8 --ttl=14d --tag=sprint-42 ... # Ephemeral rule with automatic TTL expiration
/gov 8 --diff ... # Visual colourised diff preview before commit
/gov 10 --preview # Non-destructive Clean Start simulation (calculates token ROI)
/gov 11 --tag=sprint-42 # Batch prune all sprint-specific rules
/gov heal # Autonomous link watchdog: re-links severed hardlinks
/gov 0 # 1-Click complete uninstallation & multi-repo rollback
Complete 1-Line Teardown & Rollback Guarantee
In strict adherence to zero-residue platform standards, uninstallation is 100% atomic and non-destructive:
# Windows
irm https://gist.githubusercontent.com/Tom-Zafred/7be8e3efcf9b76d27945eaa3dc44ae49/raw/uninstall.ps1 | iex
# Linux / macOS
curl -fsSL https://gist.githubusercontent.com/Tom-Zafred/7be8e3efcf9b76d27945eaa3dc44ae49/raw/uninstall.sh | bash
Restores original pre-compilation markdown files bit-for-bit, purges the vault, deregisters MCP configurations, cleans shell profiles, and leaves 0 bytes of orphaned state.
5. Pre-Empted Objections & Community Reply Magnet
Pre-Empted Objections
- “Why use physical hardlinks (
fs.linkSync) instead of symbolic links?”- Architecture Rationale: On Windows, creating symbolic links requires elevated Administrator rights or Developer Mode, which enterprise IT policies prohibit on developer machines. Hardlinks operate under standard unprivileged user permissions across NTFS. Furthermore, many linters and build tools traverse symlinks inconsistently; hardlinks point directly to the underlying file record and are 100% transparent to every compiler. For multi-volume setups (e.g.
C:toD:), the engine automatically falls back to relative symlinks and continuously monitors link health via/gov heal.
- Architecture Rationale: On Windows, creating symbolic links requires elevated Administrator rights or Developer Mode, which enterprise IT policies prohibit on developer machines. Hardlinks operate under standard unprivileged user permissions across NTFS. Furthermore, many linters and build tools traverse symlinks inconsistently; hardlinks point directly to the underlying file record and are 100% transparent to every compiler. For multi-volume setups (e.g.
- “Does the model follow ANIR bytecode as reliably as natural English?”
- Architecture Rationale: Yes—in fact, attention heads adhere to ANIR more consistently. Natural language paragraphs introduce epistemic ambiguity and conversational filler. ANIR’s
[PHASE:DURING] [DOMAIN: MANDATORY !PROHIBITED]grammar concentrates semantic density into high-contrast tokens, dramatically reducing token distance across long multi-turn contexts.
- Architecture Rationale: Yes—in fact, attention heads adhere to ANIR more consistently. Natural language paragraphs introduce epistemic ambiguity and conversational filler. ANIR’s
- “What happens if an external tool or git checkout decouples
AGENTS.md?”- Architecture Rationale: The built-in Turn-1 Watchdog inspects the physical inode link count (
nlink). If an external editor rewrites the file as a disconnected copy (nlink = 1), the watchdog flags the decoupling instantly. Running/gov heal(or/gov 16) captures an atomic backup snapshot and restores hardlink synchronisation in under 2ms.
- Architecture Rationale: The built-in Turn-1 Watchdog inspects the physical inode link count (
Community Discussion Questions (Join the Debate!)
- The System Prompt IR Paradigm: Should agentic IDEs move universally to an Intermediate Representation (IR) model for system prompts—compiling human instructions into dense symbolic bytecode rather than raw narrative text?
- Multi-Repo Governance: How does your engineering organisation currently prevent rule drift and conflicting constraints across 10+ microservice repositories?
- Pre-Commit Conflict Linting: Have you encountered agentic hesitation or hallucinations caused by contradictory prompt directives, and should pre-commit AST conflict detection be a native standard across all agentic frameworks?
Check out the full 23-file production implementation, test suites (107/107 tests passing), and architecture schemas on GitHub Gist:
RFC-004 Gist: Enterprise Rule Governance Engine (governance-guard)
Looking forward to hearing your thoughts and architectural critiques!