## 1. Gatekeeper Core - [x] 1.1 Add a Gatekeeper validation service with a small result shape: `status`, `failed_rules`, `warnings`, `errors`. - [x] 1.2 Implement `schema.executor_v2` rule. - [x] 1.3 Implement `evidence.invocation_ref` rule using current-session `tool_invocation` rows. - [x] 1.4 Keep recommended action evidence bindings out of hard-fail validation for this phase. ## 2. Hook Integration - [x] 2.1 Inject Gatekeeper into `VerifierInputHook`. - [x] 2.2 Add `gatekeeper_result` to Verifier payload. - [x] 2.3 Store `gatekeeper_result` in `VerifierContextHolder`. - [x] 2.4 Preserve parse-only boundary in `VerifierInputHook`. ## 3. Persistence - [x] 3.1 Persist `gatekeeper_result` under `diagnosis_session.self_evaluation.verifier_evaluation`. - [x] 3.2 Preserve existing verifier evaluation fields. ## 4. Prompt Compatibility - [x] 4.1 Update `chat-verifier-prompt.md` minimally so Verifier sees `gatekeeper_result` and must not output PASS when it fails. ## 5. Tests And Verification - [x] 5.1 Add Gatekeeper unit tests for schema failures and pass cases. - [x] 5.2 Add hook tests proving payload contains `gatekeeper_result`. - [x] 5.3 Add tests for fabricated invocation id and tool name mismatch. - [x] 5.4 Add ChatService persistence test for `gatekeeper_result`. - [x] 5.5 Run targeted tests. - [x] 5.6 Validate this OpenSpec change.