# 외부 dependency와 실행 예제

<a id="dependencies"></a>

## Go module graph — 외부 entry 9개

module은 `github.com/Autumn-27/norma`, language directive는 `go 1.26.3`이다. 고정 snapshot에서 `go mod graph`가 반환하는 외부 module entry는 direct 4개와 transitive 5개다. 아래의 production/test 열은 각각 `go list -deps ./...`와 `go list -deps -test ./...`가 해당 module의 package를 선택하는지를 뜻한다. `go`/`toolchain` synthetic edge는 외부 module 분모에 넣지 않았다. [module graph 근거와 재현법](evidence:go-module-graph)

| graph entry | graph parent·종류 | production | test | 소비·의미 |
|---|---|:---:|:---:|---|
| `github.com/creack/pty v1.1.24` | Norma direct | Y | Y | `tool/pty_unix.go`: Unix PTY process start/resize |
| `github.com/hinshun/vt10x v0.0.0-20220301184237-5011da428d02` | Norma direct | Y | Y | `tool/shell_session.go`: PTY output을 terminal grid로 emulate |
| `golang.org/x/net v0.55.0` | Norma direct | Y | Y | `tool/webfetch.go`, `tool/websearch.go`: HTML parse/DOM walk |
| `gopkg.in/yaml.v3 v3.0.1` | Norma direct | Y | Y | `skill/skill.go`: SKILL.md frontmatter decode |
| `golang.org/x/crypto v0.51.0` | `x/net` transitive | N | N | module graph에만 포함; 현재 Norma package closure는 선택하지 않음 |
| `golang.org/x/sys v0.45.0` | `x/net` transitive | N | N | module graph에만 포함; 현재 Norma package closure는 선택하지 않음 |
| `golang.org/x/term v0.43.0` | `x/net` transitive | N | N | module graph에만 포함; 현재 Norma package closure는 선택하지 않음 |
| `golang.org/x/text v0.37.0` | `x/net` transitive | N | N | module graph에만 포함; 현재 Norma package closure는 선택하지 않음 |
| `gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405` | `yaml.v3` transitive | N | N | upstream test dependency edge; current Norma test closure는 선택하지 않음 |

`yaml.v3`는 별도 `require` 문장에 있지만 production code가 직접 import하므로 direct runtime dependency다. 네 direct module은 현재 production과 test package closure 모두에 들어가고, 다섯 transitive entry는 module selection graph에만 남는다. `go.sum`은 direct 4개와 `check.v1`의 checksum을 기록하지만 네 `x/*` transitive entry checksum은 기록하지 않는다. graph membership을 runtime linkage로 읽으면 안 된다. [go.mod 근거](evidence:go-module) [go.sum 근거](evidence:go-sum) [PTY 근거](evidence:dep-pty) [terminal 근거](evidence:dep-vt10x) [HTML 근거](evidence:dep-html) [YAML 근거](evidence:dep-yaml)

<a id="examples"></a>

## Examples 5개

| example | 보여주는 wiring | 실행 결과/주의 |
|---|---|---|
| `coding-agent` | OpenAI/Anthropic provider, default tools, TodoWrite, PreToolUse Bash logging hook, built-in compaction, REPL/one-shot | `MaxTurns=80`; transcript 없음; hook는 관찰 로그일 뿐 policy가 아님 |
| `coordinator` | `RunParallel` programmatic fan-out과 coordinator model의 `Agent` delegation, Skill registry | 두 경로 모두 shared WorkingDir/tool registry 가능; programmatic results만 task order로 정렬 |
| `custom-llm` | OpenAI-compatible endpoint 교체, custom system prompt, read-only `add` tool | permission bypass 예시; provider/model 호환성은 runtime에 확인 |
| `planner-memory` | start-in-plan, terminal approver, file memory auto-inject/index | `.agent-memory`에 씀; transcript/session resume은 없음 |
| `security-audit` | Read/Glob/Grep와 specialized tracer Agent, security prompt | parent가 `ModePlan`인데 `Agent` metadata는 mutating이므로 permission pipeline이 **Agent 호출을 거부**한다. 주석이 말하는 delegation은 현재 wiring대로 성립하지 않음 |

[코딩 예제](evidence:example-coding) [coordinator 예제](evidence:example-coordinator) [custom provider 예제](evidence:example-custom) [plan/memory 예제](evidence:example-planner) [security 예제](evidence:example-security)

examples는 API 조합을 보여주는 compileable programs이지 production support matrix나 end-to-end test가 아니다. 모두 live provider 호출에 credential/비용이 필요하며 durable task/finding/evidence control plane을 만들지 않는다.
