The audit walks every settings scope and plugin hook manifest the harness merges, including user and machine scopes (skills/audit/SKILL.md:39-42; skills/audit/context/surface-walk.md:119-132). It writes one finding row per plugin manifest (surface-walk.md:96).
On melodic-software/.github, a 37-file repository, a run on 2026-09-27 produced 61 findings:
- 24 were near-identical UNPROVEN rows for user-scope plugin hook manifests owned upstream (claude-code-plugins or third parties).
- Further rows covered
~/.claude/settings.json and ~/.claude/CLAUDE.md.
- Only 4 were actionable in the repository.
Walking out-of-repo scopes is intended ("Out-of-repo is never a reason to skip"). The gap is that no argument limits the walk to in-repo custody: the arguments are layer scope, unattended and a focus hint (SKILL.md:97-117), and the focus hint does not change the layer scope. The report template (context/report-template.md) also has no grouping by owner.
Merging rows in the artifact would change finding ids and orphan recorded judgments, because the item unit is part of finding identity (surface-walk.md:90). The fix belongs in the report.
Proposed fix, in order of preference:
- In the report only, collapse findings whose custody is out-of-repo into one summary row per owner (count, verdict mix, pointer to the artifact rows). Leave artifact rows and ids unchanged.
- Add a custody-scope argument (for example
custody=repo) that records the out-of-repo layers as not walked in scope, so the merge rules carry their prior findings forward instead of closing them.
Acceptance: an audit of a small repository shows its in-repo findings first, with user-scope plugin manifests taking at most one row per owner in the report.
Related: a separate issue proposes a repo-only default scope for the overengineering entry in the playbooks repo-sweep hygiene catalog.
Found in: overengineering 0.4.13.
🤖 Generated with Claude Code
https://claude.ai/code/session_01S5b57FoPJkJMe1BDwhExiG
The audit walks every settings scope and plugin hook manifest the harness merges, including user and machine scopes (
skills/audit/SKILL.md:39-42;skills/audit/context/surface-walk.md:119-132). It writes one finding row per plugin manifest (surface-walk.md:96).On melodic-software/.github, a 37-file repository, a run on 2026-09-27 produced 61 findings:
~/.claude/settings.jsonand~/.claude/CLAUDE.md.Walking out-of-repo scopes is intended ("Out-of-repo is never a reason to skip"). The gap is that no argument limits the walk to in-repo custody: the arguments are layer scope,
unattendedand a focus hint (SKILL.md:97-117), and the focus hint does not change the layer scope. The report template (context/report-template.md) also has no grouping by owner.Merging rows in the artifact would change finding ids and orphan recorded judgments, because the item unit is part of finding identity (
surface-walk.md:90). The fix belongs in the report.Proposed fix, in order of preference:
custody=repo) that records the out-of-repo layers as not walked inscope, so the merge rules carry their prior findings forward instead of closing them.Acceptance: an audit of a small repository shows its in-repo findings first, with user-scope plugin manifests taking at most one row per owner in the report.
Related: a separate issue proposes a repo-only default scope for the
overengineeringentry in the playbooks repo-sweep hygiene catalog.Found in: overengineering 0.4.13.
🤖 Generated with Claude Code
https://claude.ai/code/session_01S5b57FoPJkJMe1BDwhExiG