From faaf81257c55e5f2d5a54b3cd98c59c04fd89cb5 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Wed, 12 Aug 2026 13:24:44 +0000 Subject: [PATCH 1/3] fix(source-control): anchor finding-extractor reads to the PR worktree Mirror the Worker Contract worktree-cwd discipline in the finding-extractor subagent dispatch prompt so validation reads cannot drift to the session checkout. Fixes #1300. Co-authored-by: Kyle Sexton --- plugins/source-control/reference/review-discipline.md | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/plugins/source-control/reference/review-discipline.md b/plugins/source-control/reference/review-discipline.md index d3bb96d968..c298cee3b5 100644 --- a/plugins/source-control/reference/review-discipline.md +++ b/plugins/source-control/reference/review-discipline.md @@ -107,8 +107,13 @@ Extract individual findings from the multi-finding bot/human review at: ALLOWED scope (read-only on PR branch ): - `gh api repos///issues//comments` and per-id endpoints - `gh api repos///pulls//{comments,reviews}` and per-id endpoints -- `Read` / `Grep` / `Glob` against the repo working tree -- `Bash` for git inspection (`git show`, `git log`, `git diff`) — NEVER state-mutating +- `Read` / `Grep` / `Glob` against the repo working tree at the PR's assigned + worktree — every path is absolute under `` (or an + explicit absolute `${CLAUDE_PLUGIN_ROOT}/…` path for bundled plugin references); + never a bare relative path that resolves against the session's default checkout +- `Bash` for git inspection (`git -C show`, `git -C + log`, `git -C diff`) — NEVER + state-mutating and NEVER bare `git` without `-C ` FORBIDDEN: - Any Edit / Write of repo files From 22f27d5f5766785090828281c1ae8f2c9a9918d9 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Wed, 12 Aug 2026 16:57:18 +0000 Subject: [PATCH 2/3] fix(source-control): quote worktree path in review-discipline dispatch Document substitution and quote git -C paths. Bump to 0.53.11. Co-authored-by: Kyle Sexton --- plugins/source-control/.claude-plugin/plugin.json | 2 +- plugins/source-control/reference/review-discipline.md | 10 +++++----- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/plugins/source-control/.claude-plugin/plugin.json b/plugins/source-control/.claude-plugin/plugin.json index dacb7368e6..7f85f8d333 100644 --- a/plugins/source-control/.claude-plugin/plugin.json +++ b/plugins/source-control/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "source-control", - "version": "0.53.9", + "version": "0.53.11", "description": "Git and GitHub delivery workflow: /commit (Conventional Commits + Co-authored-by trailer via safe heredoc mechanics), /pull-request (prep, create, CI monitoring, review-comment triage, merge, CI-log fetch), /babysit-prs (self-pacing fleet loop \u2014 safe by default; opt-in worker/autopilot tiers add gate-checked merge and thread resolution behind a deterministic Python engine), /babysit-loop (the loop-lane merge lane: a standing or drain loop that invokes babysit-prs per cycle, configured through repo-scoped babysit_loop_* keys on the layered source-control.md seam, with merge authority human-only until the target repo's tracked config adopts the lane, a gate-proven C2-mechanical baseline once adopted, and standing merge-rung raises binding from the team-tracked layer only \u2014 with one named exception, where an invocation line explicitly typing both the autopilot tier keyword and the dedicated raise argument --merge c3-this-run widens that single invocation's merge authority up to C3 behind a fresh independent frontier-tier resolver, while C4-structural and C5-untrusted-provenance stay unconditionally human-merge), /worktree (create, status, cleanup, audit for parallel-session isolation), /setup (check the effective commit-subject / PR-title convention merged across its config layers and the babysit-prs config, or apply \u2014 interview the repo and write the convention config to a chosen layer), and /resolve-conflicts (intent-first merge/rebase conflict resolution with a semantic-conflict sweep \u2014 never --abort). The commit-subject / PR-title convention is configurable via a source-control.md config written by a re-runnable setup skill, layered across a ~/.claude user-global file, the tracked team file, and a gitignored .claude/source-control.local.md personal overlay merged per key; Conventional Commits is the default when no convention is declared.", "author": { "name": "Melodic Software", diff --git a/plugins/source-control/reference/review-discipline.md b/plugins/source-control/reference/review-discipline.md index c298cee3b5..e6ed01b089 100644 --- a/plugins/source-control/reference/review-discipline.md +++ b/plugins/source-control/reference/review-discipline.md @@ -96,8 +96,8 @@ attempting inline extraction. The subagent: FORBIDDEN: edits, commits, pushes, reactions, replies on GitHub (those stay in the main session) -**Subagent dispatch prompt (compose verbatim, substitute `` and `` / -``):** +**Subagent dispatch prompt (compose verbatim, substitute ``, `` / +``, and ``):** ```text Extract individual findings from the multi-finding bot/human review at: @@ -111,9 +111,9 @@ ALLOWED scope (read-only on PR branch ): worktree — every path is absolute under `` (or an explicit absolute `${CLAUDE_PLUGIN_ROOT}/…` path for bundled plugin references); never a bare relative path that resolves against the session's default checkout -- `Bash` for git inspection (`git -C show`, `git -C - log`, `git -C diff`) — NEVER - state-mutating and NEVER bare `git` without `-C ` +- `Bash` for git inspection (`git -C "" show`, `git -C + "" log`, `git -C "" diff`) — NEVER + state-mutating and NEVER bare `git` without `-C ""` FORBIDDEN: - Any Edit / Write of repo files From 6054d672a9eef2b01bff17a7585ef653d5385b2d Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Wed, 12 Aug 2026 16:57:32 +0000 Subject: [PATCH 3/3] chore(source-control): add 0.53.11 changelog entry Co-authored-by: Kyle Sexton --- plugins/source-control/CHANGELOG.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/plugins/source-control/CHANGELOG.md b/plugins/source-control/CHANGELOG.md index 0497701e47..187baabaf6 100644 --- a/plugins/source-control/CHANGELOG.md +++ b/plugins/source-control/CHANGELOG.md @@ -3,6 +3,14 @@ All notable changes to the `source-control` plugin are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); this plugin uses semantic versioning. +## [0.53.11] + +### Fixed + +- **Finding-extractor reads anchor to the PR worktree cwd (#2454).** Review-discipline + dispatch text now substitutes `` and quotes it in `git -C` + examples so paths with spaces stay valid. + ## [0.53.9] ### Added