Source: MIZOKI audit 2026-09-06 (pinned fc8b03f9) → work-order backlog 2026-09-08 (docs/audits/AUDIT_WORK_ORDERS_2026-09-08.md); WO-44..49 added 2026-09-08 from the source-verified review v1.1 (docs/reports/MIZOKI_ACQUISITION_ECONOMICS_REVIEW_v1.1_2026-09-06.md, verified on main 635318712). Findings are hypotheses until reproduced on current main (WO-00).

Finding (OPEN_ITEMS W3-CI-1, measured): no workflow runs tests/mcp, tests/spec, tests/gtm, packages/truthgate/tests, tests/shared/test_origin_{schema,strata,classifier}.py, tests/shared/test_agent_share_threshold.py, tests/test_origin_shadow_ddl.py on PR or merge (ci.yaml:140 names one file, not the directory). Their tenant-isolation, read-only-manifest, consent and flag-pin gates are enforced only when someone runs them locally. Separately, scripts/mizoki_canon.py has no CLI — --check is silently ignored (library only); the canon gate is scripts/skill_sync.py --audit. Files: .github/workflows/ci.yaml (protected path → review PR); tests/governance/ (new pin test). Fix: one step beside the governance-gates job: pytest tests/mcp tests/spec tests/gtm packages/truthgate/tests tests/shared tests/test_origin_shadow_ddl.py -q -p no:cacheprovider -o addopts=""; plus a governance test asserting no workflow/Makefile/doc invokes mizoki_canon.py --check and that skill_sync.py --audit is the named canon gate. Acceptance: the step is green on a PR; a seeded failure in tests/mcp reddens CI; the canon-invocation pin passes. Depends on: WO-00. Same review PR as WO-26/27 where practical. Owning prompt: CX-4 (.github/workflows/**).

← All docsView source on GitHub →