Hook Enforcement — 20260722T120000000Z-cursor-composer-rerun
144-trial babel relay replicating the 2026-07-20 composer-2.5-fast run through the same Cursor wrapper gate: warn detects 31/31 drifted relays but 18 ship anyway (58%, vs 78% original); enforce halts 31/31. Composer remains the leakiest model in the isolation set.
Provenance
- Harness: Cursor CLI
- Version: cursor-agent 2026.07.17-3e2a980
- Model: composer-2.5-fast
- Gate integration: wrapper
- Gate source: sema check CLI (RobinOppenstam/sema@feat/sema-check)
- Records path: experiments/cursor-hook/records/2026-07-22-composer-rerun/
Deviations
- Enforcement is wrapper-level (sema check runs before cursor-agent is invoked); cursor hook dispatch is server-gated off on this account, so the in-harness hook tier could not be tested
- The warn channel is prompt-prepension of the repair text, not hook-stdout context injection
- Frozen boundary prompts delivered via per-trial AGENTS.md plus the same inline-artifacts harness note as codex-hook
- Registry rebuilt from scenarios.yaml with sema's mint pipeline; all six stubs verified byte-identical to the frozen babel-hook stubs.json before the run
- Replication of the 2026-07-20 composer run under the model-parameterized runner, contemporaneous with the three cheap-model isolation runs
| Condition | Trials | Drift detection | Silent divergence | Drift halted | Task success | False halts | Malformed | Hop failed |
|---|---|---|---|---|---|---|---|---|
off |
48 | 14/32 | 18/32 | 14/32 | 29/48 | 0 | 0 | 1 |
warn |
48 | 31/31 | 0/31 | 13/31 | 29/48 | 0 | 0 | 1 |
enforce |
48 | 31/31 | 0/31 | 31/31 | 46/48 | 1 | 0 | 1 |
Drift-conditioned columns use drift-injected trials as the denominator; task success uses all trials in the condition.