Files
worldmonitor/todos/093-complete-p3-tryparsesimulation-jsdoc-and-sanitize-at-boundary.md
Elie Habib 2fddee6b05 feat(simulation): add keyActorRoles to fix actor overlap bonus vocabulary mismatch (#2582)
* feat(simulation): add keyActorRoles field to fix actor overlap bonus vocabulary mismatch

The +0.04 actor overlap bonus never reliably fired in production because
stateSummary.actors uses role-category strings ('Commodity traders',
'Policy officials') while simulation keyActors uses named geo-political
entities ('Iran', 'Houthi'). 53 production runs audited showed the bonus
fired once out of 53.

Fix: add keyActorRoles?: string[] to SimulationTopPath. The Round 2 prompt
now includes a CANDIDATE ACTOR ROLES section with theater-local role vocab
seeded from candidatePacket.stateSummary.actors. The LLM copies matching
roles into keyActorRoles. applySimulationMerge scores overlap against
keyActorRoles when actorSource=stateSummary, preserving the existing
keyActors entity-overlap path for the affectedAssets fallback.

- buildSimulationPackageFromDeepSnapshot: add actorRoles[] to each theater
  from candidate.stateSummary.actors (theater-scoped, no cross-theater noise)
- buildSimulationRound2SystemPrompt: inject CANDIDATE ACTOR ROLES section
  with exact-copy instruction and keyActorRoles in JSON template
- tryParseSimulationRoundPayload: extract keyActorRoles from round 2 output
- mergedPaths.map(): filter keyActorRoles against theater.actorRoles guardrail
- computeSimulationAdjustment: dual-path overlap — roleOverlapCount for
  stateSummary, keyActorsOverlapCount for affectedAssets (backwards compat)
- summarizeImpactPathScore: project roleOverlapCount + keyActorsOverlapCount
  into path-scorecards.json simDetail

New fields: roleOverlapCount, keyActorsOverlapCount in SimulationAdjustmentDetail
and ScorecardSimDetail. actorOverlapCount preserved as backwards-compat alias.

Tests: 308 pass (was 301 before). New tests T-P1/T-P2/T-P3 (prompt/parser),
T-RO1/T-RO2/T-RO3 (role overlap logic), T-PKG1 (pkg builder actorRoles),
plus fixture updates for T2/T-F/T-G/T-J/T-K/T-N2/T-SC-4.

🤖 Generated with Claude Sonnet 4.6 via Claude Code (https://claude.ai/claude-code) + Compound Engineering v2.49.0

Co-Authored-By: Claude Sonnet 4.6 (200K context) <noreply@anthropic.com>

* fix(simulation): address CE review findings from PR #2582

- Add SimulationPackageTheater interface to seed-forecasts.types.d.ts
  (actorRoles was untyped under @ts-check)
- Add keyActorRoles to uiTheaters Redis projection in writeSimulationOutcome
  (field was stripped from Redis snapshot; only visible in R2 artifact)
- Extract keyActorRoles IIFE to named sanitizeKeyActorRoles() function;
  hoist allowedRoles Set computation out of per-path loop
- Harden bonusOverlap ternary: explicit branch for actorSource='none'
  prevents silent fallthrough if new actorSource values are added
- Eliminate roleOverlap intermediate array in computeSimulationAdjustment
- Add U+2028/U+2029 Unicode line-separator stripping to sanitizeForPrompt
- Apply sanitizeForPrompt at tryParseSimulationRoundPayload parse boundary;
  add JSDoc to newly-exported function

All 308 tests pass, typecheck + typecheck:api clean.

* fix(sim): restore const sanitized in sanitizeKeyActorRoles after early-return guard

Prior edit added `if (!allowedRoles.length) return []` but accidentally removed
the `const sanitized = ...` line, leaving the filter on line below referencing an
undefined variable. Restores the full function body:

  if (!allowedRoles.length) return [];
  const sanitized = (Array.isArray(rawRoles) ? rawRoles : [])
    .map((s) => sanitizeForPrompt(String(s)).slice(0, 80));
  const allowedNorm = new Set(allowedRoles.map(normalizeActorName));
  return sanitized.filter((s) => allowedNorm.has(normalizeActorName(s))).slice(0, 8);

308/308 tests pass.

---------

Co-authored-by: Claude Sonnet 4.6 (200K context) <noreply@anthropic.com>
2026-04-01 08:53:13 +04:00

2.2 KiB

status, priority, issue_id, tags, dependencies
status priority issue_id tags dependencies
pending p3 093
code-review
typescript
simulation
security

tryParseSimulationRoundPayload missing JSDoc after export + apply sanitizeForPrompt at parse boundary

Problem Statement

Two related cleanup items on the newly-exported tryParseSimulationRoundPayload:

  1. Missing JSDoc — the function was private before PR #2582. Exporting it without JSDoc annotations means @ts-check callers get no type feedback on parameters. The project pattern for exported functions is to annotate @param and @returns.

  2. sanitizeForPrompt deferred to merge steptryParseSimulationRoundPayload applies only String(s).trim() to keyActorRoles items. Sanitization happens later in mergedPaths.map(). If a future caller uses tryParseSimulationRoundPayload directly (e.g., in a test or a new code path) and skips the merge step, unsanitized LLM strings will escape. The fix is to apply sanitizeForPrompt at the parse boundary.

Proposed Solution

Add JSDoc:

/**
 * @param {string} text - raw LLM response text (may be JSON or JSON-with-prefix)
 * @param {1 | 2} round - simulation round number
 * @returns {{ paths: import('./seed-forecasts.types.d.ts').SimulationTopPath[] | null, stabilizers?: string[], invalidators?: string[], globalObservations?: string, confidenceNotes?: string, dominantReactions?: string[] }}
 */
function tryParseSimulationRoundPayload(text, round) {

Apply sanitizeForPrompt at parse boundary:

// BEFORE:
p.keyActorRoles.map((s) => String(s || '').trim()).filter(Boolean).slice(0, 10)

// AFTER:
p.keyActorRoles.map((s) => sanitizeForPrompt(String(s || '')).trim()).filter(Boolean).slice(0, 10)

Note: .trim() after sanitizeForPrompt is fine since sanitizeForPrompt doesn't strip leading/trailing spaces.

Technical Details

  • Files: scripts/seed-forecasts.mjs (tryParseSimulationRoundPayload)
  • Effort: Trivial | Risk: Very Low

Acceptance Criteria

  • tryParseSimulationRoundPayload has @param + @returns JSDoc
  • sanitizeForPrompt applied to keyActorRoles items at parse time
  • T-P3 test still passes

Work Log

  • 2026-03-31: Identified by kieran-typescript-reviewer and security-sentinel during PR #2582 review