Skip to content

overengineering:audit: out-of-repo manifests bury repo findings in a single-repo audit; add a custody filter or a per-owner rollup #4596

Description

@kyle-sexton

The audit walks every settings scope and plugin hook manifest the harness merges, including user and machine scopes (skills/audit/SKILL.md:39-42; skills/audit/context/surface-walk.md:119-132). It writes one finding row per plugin manifest (surface-walk.md:96).

On melodic-software/.github, a 37-file repository, a run on 2026-09-27 produced 61 findings:

  • 24 were near-identical UNPROVEN rows for user-scope plugin hook manifests owned upstream (claude-code-plugins or third parties).
  • Further rows covered ~/.claude/settings.json and ~/.claude/CLAUDE.md.
  • Only 4 were actionable in the repository.

Walking out-of-repo scopes is intended ("Out-of-repo is never a reason to skip"). The gap is that no argument limits the walk to in-repo custody: the arguments are layer scope, unattended and a focus hint (SKILL.md:97-117), and the focus hint does not change the layer scope. The report template (context/report-template.md) also has no grouping by owner.

Merging rows in the artifact would change finding ids and orphan recorded judgments, because the item unit is part of finding identity (surface-walk.md:90). The fix belongs in the report.

Proposed fix, in order of preference:

  1. In the report only, collapse findings whose custody is out-of-repo into one summary row per owner (count, verdict mix, pointer to the artifact rows). Leave artifact rows and ids unchanged.
  2. Add a custody-scope argument (for example custody=repo) that records the out-of-repo layers as not walked in scope, so the merge rules carry their prior findings forward instead of closing them.

Acceptance: an audit of a small repository shows its in-repo findings first, with user-scope plugin manifests taking at most one row per owner in the report.

Related: a separate issue proposes a repo-only default scope for the overengineering entry in the playbooks repo-sweep hygiene catalog.

Found in: overengineering 0.4.13.

🤖 Generated with Claude Code

https://claude.ai/code/session_01S5b57FoPJkJMe1BDwhExiG

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-humanHuman-in-the-loop required; autonomous sessions must not resolve items carrying this.priority: mediumReal value, no hard deadline; normal backlog flow.status: readyTriaged, unblocked, and fully specified; eligible to pick up.work-class: scopedA briefed fix or small feature; blast radius bounded by the brief, tests exist.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions