70aad32e86
Tightens `skills/planner/agents/ailang-plan-recon.md` against two recon-contract failure modes documented in Gitea #9: (a) For signature-change / enum-variant-add-remove / public-symbol- removal scopes, hand-listing of call sites or match arms has under-counted the blast radius four times across two milestones, each through a different site type (loop-recur.1 walker arms, loop-recur.2 cross-module synth callers, loop-recur.tidy implicit, remove-mut-var-assign.1 in-source `mod tests` fns + drift pin + `.ail.json` carve-outs + a non-enumerated E0599). The recon now MUST report a compile-driven enumeration (cargo check after a stub / exhaustive `git grep -nE` / `cargo expand`) as the authoritative code-site set; hand-listing is explicitly labelled "advisory". The compile-driven channel only covers compile-checked sites, so a separate sweep for drift pins, `.ail`/`.ail.json` fixtures, and design-doc references is required and reported under a "Non-compile-checked sites" section. (b) Every path the spec names is now `ls`-verified before propagation into the brief. An existence claim feeding a recon is itself load-bearing — one prior recon brief inherited an unverified "X does not exist" claim (form_a.md, remove-mut-var-assign.1) and was caught only at milestone-close audit. The new "Spec-named path existence table" is mandatory for every dispatch (regardless of scope class); entries marked "not exists" must carry the exact `ls` / `git ls-files` command run, and only verified-not-exists entries may feed "Anchors not yet present". Three new Common Rationalisations and three new Red Flags calibrate against the named failure modes. The "Compile-driven site set" / "Non-compile-checked sites" output sections may be omitted for iterations that do not involve a signature / variant / removal scope; the existence table is always required. No language change; no code change. Agent-definition discipline fix only. closes #9