8e1238c316f3eced7b1d301d6d242efacfb73b70
TagExtractor collects every [MOVE:] tag occurrence with no dedupe, and
MoveValidator is a pure membership test against available_moves, so N
copies of one legal move all pass validation. MoveApplier then looped
and applied every copy. A model could therefore pick an arbitrary
amount of money in unary by repeating one tag: [MOVE: accept_item(copper)]
x47 against a 47c purse drains it to 0; [MOVE: give_item(gold)] x10
mints +100,000c. The eight-move vocabulary (§6) takes no quantity
argument precisely so the AI cannot choose a number — this closed that
gap by another door and was a §2 breach (AI owns text, never state).
MoveApplier.apply() now tracks currency moves (give_item/accept_item on
a denomination) already applied within one call, keyed on name+denom,
and skips repeats. Non-currency moves are untouched — repeated
give_item(amulet) still yields multiple copies, which stays bounded by
the pre-existing cross-reply gifts_given gate and is a separate,
already-reported issue. move_validator.gd and tag_extractor.gd are
untouched.
Also adds the Finding-2 test the currency spec (§7) named but never
delivered: after GameState.grant("gold", 1), inventory stays empty, so
accept_item(gold) in available_moves comes only from the affordability
loop, never double-offered via the inventory.keys() loop.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QYa9u7Kdxv5gX4AnwWexy8
coc-rpg
AI-driven single-player, party-based fantasy RPG. Godot 4 client, FastAPI proxy, AI as Dungeon Master.
Read CLAUDE.md first — project charter and working agreement. It is the source of truth. If code disagrees with it, the charter wins until the charter is changed.
The one rule
Code owns state. AI owns text. (charter §2)
Repo layout
/client Godot 4.7 game client (GDScript) — ALL game state, ALL game rules
/docs Client-specific docs (scenes, input, combat wiring)
/api FastAPI proxy — auth, metering, prompt routing, logging (charter §4)
/docs API-specific docs (endpoints, model routing, deploy)
/prompts Role prompts — source code, versioned, reviewed (charter §5, §16)
/content Authored game data — quests, NPC knowledge lists, fallback text
/quests Story skeletons and quest definitions
/npcs Per-NPC knowledge lists (charter §6 — "the whole design")
/fallback Authored degraded-DM text for every AI surface (charter §13)
/docs Cross-cutting docs — roadmap, ADRs, planning affecting both sides
/adr Architecture Decision Records
The three processes (charter §4)
client (GDScript) ──HTTP──▶ api (FastAPI) ──▶ Replicate / Ollama
The client holds no API key, ever. It knows one base URL and a set of role endpoints. It sends game state, receives text.
Description
Languages
Text
100%