Codex gpt-5.6-terra on “A digest of several sources”: better with Minto on both measures

Structure 6 → 8 of 8 +2 Quality 8 → 9 of 10 +1

The judge on the output with Minto

The ownership split, synthesis, and citations are excellent, apart from the unsupported conversion of Lisbon to Portugal.

Mode digest · case 09-sources-digest · run v1.7.0-final

Structure of 8, 2 points per axis
StructureWithout Minto 6With Minto 8Change
Top22
Key-line composition12+1
Levels12+1
Order and kind22
Quality of 10, 2 points per axis
QualityWithout Minto 8With Minto 9Change
Top11
Same-kind grouping22
Explainable order22
MECE12+1
Visible, proportionate structure22

Outputs and the judge’s words are quoted as written, in English.

Without Minto

control prompt · blind label out-12
  • invented_facts
  • quality after the rubric’s penalty 7/10

The digest is concise but uncited, and it expands the evidence into an unsupported review-engagement checklist.

Compliance is mandatory before production, and build pricing remains blocked until Aldergate confirms the architecture-dependent requirements and provides its approved-package list.

Already answered:

  • A security review is required; the assigned reviewer will decide whether penetration testing is needed.
  • Aldergate has an internal hardening framework, but meeting it does not replace the review.
  • Dependency use will be assessed in the review; there is no standard approval turnaround.
  • Fernway staff may work from Ireland. No approval has been given for Portugal/Lisbon or other countries.
  • Data-storage, encryption, and logging requirements exist but require an architecture diagram and design walkthrough before Aldergate will answer.

Still needed from Aldergate:

  • The approved-package list — promised on 12 May and again “shortly” on 9 July; still outstanding after 98 days. Confirm owner and delivery date, escalating beyond R. Whitcombe if necessary to S. Okafor.
  • A security-review engagement path: assigned reviewer, review inputs, timing, and the decision process for any required penetration test.
  • Architecture-specific requirements for customer-data location, encryption, and logging, following Fernway’s diagram and walkthrough.
  • Explicit confirmation whether the two Lisbon-based engineers may work on the engagement.

Immediate Fernway action: send the draft architecture diagram (ready since 11 August) and request a walkthrough with S. Okafor, bundling the four outstanding items above.

With Minto

prompt with the skill · blind label out-05
  • invented_facts
  • quality after the rubric’s penalty 7/10

The ownership split, synthesis, and citations are excellent, apart from the unsupported conversion of Lisbon to Portugal.

Compliance is partly defined, but Fernway cannot fix build pricing until Aldergate confirms architecture-specific controls and releases its approved-package list.

Already answered

  • A security review is mandatory before production; the assigned reviewer will decide during that review whether a penetration test is required. (gate-review.xlsx, Q1)
  • Aldergate has an internal hardening framework, but meeting it does not replace the required review. (gate-review.xlsx, Q2)
  • Ireland-based work is acceptable. (gate-review.xlsx, Q6)
  • Dependency use, including critical dependencies, will be assessed in the security review; there is no standard turnaround time for approval. (gate-review.xlsx, Q4–Q5)

Still needed from Aldergate

  • The approved-package list. It was first due from D. Mercer on 12 May and was again described as forthcoming by R. Whitcombe on 9 July, but remains outstanding after 98 days. (gate-review.xlsx, Q3; sync-0709.md; risk register R-11)
  • Architecture-specific requirements for customer-data storage, encryption, and logging. Aldergate will not answer without an architecture diagram and design walkthrough. (gate-review.xlsx, Q7)
  • Confirmation whether Lisbon-based Fernway engineers may work on the engagement; Aldergate only explicitly approved Ireland, and did not respond when Lisbon was raised. (gate-review.xlsx, Q6; sync-0709.md)
  • Direct engagement with S. Okafor, the information-security owner, rather than relying on questions passed through Whitcombe. (sync-0709.md)

Action today

  • Send the existing draft architecture diagram to Aldergate and request a design walkthrough with Okafor. The diagram has been ready since 11 August and currently blocks the storage-control answer. (risk register R-14)
  • Ask Whitcombe/Okafor for a dated commitment on the approved-package list and written confirmation on Portugal-based staff.

How the test was built

Codex gpt-5.6-terra received the same task twice. The control prompt is one framing line and the task. The prompt with Minto is the same task preceded by the full text of the skill. The judge read both outputs among 16 under blind labels and did not know which one had the skill.

Prompt without Minto 3 667 B
You are working on a business document using the Minto Pyramid Principle.

<!-- Original fixture. The scenario, company, people, systems and numbers are
     invented for this benchmark. The defect pattern it tests — a digest of several
     read sources delivered answer-first into chat — is modeled on real usage. -->

# Fixture 09: sources digest

**Mode:** `digest`
**Language:** `en`

## Context

You are assisting the tech lead of Fernway Systems, a vendor building a customer
support assistant for Aldergate Bank. Before Fernway can price the build phase, the
bank's compliance office must confirm its security requirements. You have just read
the three sources below in full. The tech lead has not read them and will not; they
are deciding what to do about the compliance track today.

## Before

Source 1 — `gate-review.xlsx`, sheet "Security questions", filled in by Aldergate's
compliance office on 12 May:

```text
Q1 Is a security review required before production?
   A: Yes. A review is mandatory; whether a penetration test is also needed is
   decided during the review itself, by the assigned reviewer.
Q2 Is there a security standard or checklist we can build against?
   A: An internal hardening framework exists; a review is still required
   regardless of conformance.
Q3 What is the policy on open-source dependencies?
   A: A policy exists. The approved-package list will be sent to Fernway.
   Owner: D. Mercer. Date: 12 May.
Q4 Must critical dependencies be approved individually?
   A: Dependency usage is assessed during the security review.
Q5 What is the turnaround time for dependency approval?
   A: There is no standard turnaround; it is case by case.
Q6 Can Fernway staff work from outside the UK?
   A: Work from Ireland is acceptable. (No other country is mentioned.)
Q7 Where may customer data be stored, and with what encryption and logging?
   A: Declined — "cannot be answered without an architecture diagram and a
   design walkthrough". Encryption and logging requirements exist but are
   not applicable outside an architectural context.
```

Source 2 — follow-up note from the 9 July delivery sync, `sync-0709.md`:

```text
Attendees: R. Whitcombe (Aldergate, delivery), tech lead (Fernway), PM (Fernway).
- Whitcombe repeated that the approved-package list "is being prepared" and will
  reach Fernway "shortly". Action on Whitcombe, no date attached.
- Compliance contact named for the first time: S. Okafor, information security
  owner. Okafor has not attended any joint meeting so far; Whitcombe passes
  questions along.
- Agreed: Fernway sends the draft architecture diagram before the next sync so
  the storage and encryption questions can get a real answer.
- Fernway's PM noted two Fernway engineers are based in Lisbon. Nobody from
  Aldergate responded to the remark in the meeting.
```

Source 3 — Fernway's internal risk register, rows touching compliance, as of
18 August:

```text
R-07  Security requirements unconfirmed; build-phase price cannot be fixed.
      Owner: tech lead. Status: open since 3 May.
R-11  Approved-package list not received. First promised 12 May (Mercer, per
      gate review), promised again 9 July (Whitcombe). Status: open, 98 days.
R-14  Architecture diagram not yet sent to Aldergate; blocks the data-storage
      answer (gate review Q7). Draft exists since 11 August. Status: open.
```

## Task

Give the tech lead a digest of these three sources in chat: what is already
answered on the compliance track, and what still has to be obtained from
Aldergate. The tech lead will act on it today.

Return only the result, with no explanation of how you produced it.
Prompt with Minto five parts, in order · 31 240 B
  1. Below is a skill written as an instruction. Read it in full and apply it to the task at the end.
  2. ===== SKILL.md ===== SKILL.md at f4813ce 17 235 B
  3. ===== references/rules.md ===== references/rules.md at f4813ce 6 464 B
  4. ===== references/templates.md ===== references/templates.md at f4813ce 3 742 B
  5. ===== TASK ===== the whole case input
  6. Return only the result, with no explanation of how you produced it.
Case input before.md

<!-- Original fixture. The scenario, company, people, systems and numbers are
invented for this benchmark. The defect pattern it tests — a digest of several
read sources delivered answer-first into chat — is modeled on real usage. -->

Fixture 09: sources digest

Mode: digest
Language: en

Context

You are assisting the tech lead of Fernway Systems, a vendor building a customer
support assistant for Aldergate Bank. Before Fernway can price the build phase, the
bank's compliance office must confirm its security requirements. You have just read
the three sources below in full. The tech lead has not read them and will not; they
are deciding what to do about the compliance track today.

Before

Source 1 — gate-review.xlsx, sheet "Security questions", filled in by Aldergate's
compliance office on 12 May:

Q1 Is a security review required before production?
                   A: Yes. A review is mandatory; whether a penetration test is also needed is
                   decided during the review itself, by the assigned reviewer.
                Q2 Is there a security standard or checklist we can build against?
                   A: An internal hardening framework exists; a review is still required
                   regardless of conformance.
                Q3 What is the policy on open-source dependencies?
                   A: A policy exists. The approved-package list will be sent to Fernway.
                   Owner: D. Mercer. Date: 12 May.
                Q4 Must critical dependencies be approved individually?
                   A: Dependency usage is assessed during the security review.
                Q5 What is the turnaround time for dependency approval?
                   A: There is no standard turnaround; it is case by case.
                Q6 Can Fernway staff work from outside the UK?
                   A: Work from Ireland is acceptable. (No other country is mentioned.)
                Q7 Where may customer data be stored, and with what encryption and logging?
                   A: Declined — "cannot be answered without an architecture diagram and a
                   design walkthrough". Encryption and logging requirements exist but are
                   not applicable outside an architectural context.

Source 2 — follow-up note from the 9 July delivery sync, sync-0709.md:

Attendees: R. Whitcombe (Aldergate, delivery), tech lead (Fernway), PM (Fernway).
                - Whitcombe repeated that the approved-package list "is being prepared" and will
                  reach Fernway "shortly". Action on Whitcombe, no date attached.
                - Compliance contact named for the first time: S. Okafor, information security
                  owner. Okafor has not attended any joint meeting so far; Whitcombe passes
                  questions along.
                - Agreed: Fernway sends the draft architecture diagram before the next sync so
                  the storage and encryption questions can get a real answer.
                - Fernway's PM noted two Fernway engineers are based in Lisbon. Nobody from
                  Aldergate responded to the remark in the meeting.

Source 3 — Fernway's internal risk register, rows touching compliance, as of
18 August:

R-07  Security requirements unconfirmed; build-phase price cannot be fixed.
                      Owner: tech lead. Status: open since 3 May.
                R-11  Approved-package list not received. First promised 12 May (Mercer, per
                      gate review), promised again 9 July (Whitcombe). Status: open, 98 days.
                R-14  Architecture diagram not yet sent to Aldergate; blocks the data-storage
                      answer (gate review Q7). Draft exists since 11 August. Status: open.
Task

Give the tech lead a digest of these three sources in chat: what is already
answered on the compliance track, and what still has to be obtained from
Aldergate. The tech lead will act on it today.

The judge’s gold gold.md

Gold 09: sources digest

Original gold for an invented scenario.

Expected structure

Top: an answer to the tech lead's question, not a description of the sources.
The strongest available top is an action with its ground: the blocking questions
cannot be answered by more reading — send the architecture diagram (drafted and
sitting unsent since 11 August) and escalate the approved-package list as an
obligation now 98 days old. A top that merely states "five of seven questions are
answered" is weaker but acceptable if the two actions lead the groups.

Three same-kind groups the material supports, in any defensible order:

  1. Settled — do not re-ask. Review is mandatory (pen test decided during it);
    a hardening framework exists but exempts nothing; dependencies are assessed in
    the review with no standard turnaround; Ireland is cleared for remote work.
  2. Blocked on Fernway's own move. The storage/encryption/logging answer (Q7)
    was declined pending an architecture diagram; the draft has existed since
    11 August and has not been sent (R-14). This is Fernway's blocker, not
    Aldergate's.
  3. Owed by Aldergate and overdue. The approved-package list, first promised
    12 May by Mercer per the gate review — not 9 July by Whitcombe, so 98 days
    overdue, which makes the ask an escalation of an old commitment rather than a
    reminder. Direct access to Okafor, who has never attended and is reachable
    only through Whitcombe.
Cross-source synthesis the digest must make
  • The package-list promise appears in two sources with two dates; the digest
    must date it from 12 May (the older commitment), not 9 July.
  • Q7's "declined" plus R-14's "draft exists since 11 August" must combine into
    "the ball is in Fernway's court"; either fact alone misses the point.
  • The Lisbon remark: Q6 clears Ireland only. Two engineers in Lisbon are an
    unanswered exposure, not a settled fact. Presenting Lisbon as approved is an
    invention; omitting it entirely loses the one new risk the sources surface.
Presentation

Chat prose for one reader: answer first, grouped support, a reference to which
source each load-bearing claim comes from (sheet, note, or register row —
exact citation format is free). No marker legend, no mermaid diagram, no
findings table, no meta-commentary about how the groups are ordered. Headings or
bold group labels are acceptable; a full document apparatus (SCQ labels as
headings, scoring, appendix) is excessive. Length: roughly one chat screen —
condensing the six settled answers into one or two lines each is proportional
omission, not source loss.

Judge gpt-5.6-sol, effort high · Codex gpt-5.6-terra, effort low · skill from commit f4813ce · run v1.7.0-final