fix: land the pstack port's post-merge verification findings across eight plugins - #3069
Conversation
|
Claude finished @kyle-sexton's task in 51s —— View job Security review
Skip gate: triggered (condition 2 — no security-relevant surface). All 31 changed files are documentation-only: Per the skip gate in |
|
Claude finished @kyle-sexton's task in 4m 38s —— View job CI Code Review
Scope note: per FindingsNo blocking findings. I checked the eight behavioral/content fixes against their stated defects and the files they touch, and spot-verified several of the more checkable provenance claims in
One low-signal observation, not filed as a blocking finding: I did not attempt to re-verify the upstream |
|
Last security-reviewed head: |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b1bf09c652
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Claude has reviewed this PR 5 times. The lane skips further automatic reviews after 5; deleting this comment resets the count. |
Codex review on #3069 caught that the encapsulation fix traded one defect for another. Citing `/playbooks:fable-5` bare is a supported handle, but that skill's own argument contract makes a bare invocation arm its entire operating doctrine as standing session instructions for the remainder of the session; only a chapter-name argument reads one chapter. `downstream` mode reaches for a single formula — "assessed, not verified because Y" — and must not re-posture the session that follows it. Now cites `/playbooks:fable-5 verification`, and says why the argument is load-bearing so a later editor does not trim it back to bare. Verified against plugins/playbooks/skills/fable-5/SKILL.md's own Arguments paragraph and its `argument-hint: "[full | <chapter>]"` frontmatter, and against context/verification.md existing as a real chapter. The review 0.25.1 entry carries the same reasoning; no version bump, since 0.25.1 has not shipped. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EtvBfWQRz7w6kgRnJm4qgj
|
Claude finished @kyle-sexton's task in 43s —— View job Security review
Skip gate: triggered (condition 2 — no security-relevant surface). This run's incremental scope is the diff since the last-reviewed head (
Both are documentation/skill-instruction prose. No executable code, no GitHub Actions workflow, no script, no auth/access-control logic, and no input-handling surface. If anything, the change tightens a citation to avoid an unintended broad side effect (arming another plugin's full session doctrine) — a correctness improvement, not a new risk. Per the skip gate in |
….16.1 The CI code review on #3069 caught an undescribed change riding along in the diff: `trace-intent`'s Scope-section link to `reference/parent-contract.md` was switched from a relative href to the `${CLAUDE_PLUGIN_ROOT}` token, and the 0.16.1 entry listed only the three code-shape-exclusion routes. The change itself is right and stays. `explore`, `research` and `research-deep` all cite that same file with the token on both sides of the link, and the fleet runs 179 token-href sites to 29 relative ones; `trace-intent` was the outlier. Two spellings of one reference across sibling skills is the divergence `discipline:reuse-or-replace` exists to catch, and the relative form is the one that breaks first — it resolves from the file's own location rather than from the installed plugin root. An undescribed edit in a changelog-bearing diff is a defect whether or not the edit is correct, so the entry now names it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EtvBfWQRz7w6kgRnJm4qgj
|
Claude finished @kyle-sexton's task in 1m 58s —— View job CI Code Review
FindingsNo blocking findings. This lane already reviewed the PR once at Both post-review fixes are correct:
Consistency sweep across the rest of the diff (all confirmed against the actual files, not just the PR body's claims):
I did not attempt to re-verify the |
|
Claude finished @kyle-sexton's task in 2m 0s —— View job CI Code Review
Scope of this passThis lane has already reviewed the PR twice (at FindingsNo blocking findings. I traced each of the eight described fixes back to the actual files rather than trusting the commit message:
No plugin manifests, evals, or other shipped-behavior files changed in this commit — it's changelog/skill-body prose only, and every claim I checked matches the file it describes. |
|
Claude finished @kyle-sexton's task in 51s —— View job Security review
Skip gate: triggered (condition 2 — no security-relevant surface). This run's incremental scope is the diff since the last-reviewed head (
I read every diff hunk directly (not just the stat). All changes are prose corrections: fixing a self-contradicting gate description in Per the skip gate in |
|
Claude finished @kyle-sexton's task in 1m 19s —— View job Security review
Skip gate: triggered (condition 3 — this head already has a successful security review that still applies). The event that triggered this run is the merge commit
The only textual change anywhere since that last review is mechanical: This is documentation/skill-instruction content only, as in every prior pass on this PR. No executable code, no GitHub Actions workflow, no script, no auth/access-control logic, and no input-handling surface. Per the skip gate in |
|
Claude finished @kyle-sexton's task in 1m 37s —— View job CI Code Review
Skip gate: triggered (condition 4 — this head already has a successful review from this lane that still applies)This lane has now reviewed the PR's own content three times, most recently at I confirmed the merge introduced no new content to this PR's own diff:
Since nothing in the PR's actual diff changed, the prior review at |
…ight plugins A fresh-context verification pass over #3065 after it merged found twenty-four defects in what that PR shipped — twelve across the eight plugins it touched, twelve in the provenance record. Two are behavioural — a completion gate that reverses its own skill's first instruction, and a cite into another plugin's private files — and the rest are unresolvable pointers, a schema field with no writer, an eval that cannot fail for the reason it claims to test, and factual errors in the provenance record. Every plugin whose shipped text changed takes a patch bump with its own `### Fixed` entry, because #3065's release entries describe what #3065 shipped and cannot be retrofitted to describe corrections made after it merged. Behavioural fixes: - docs-hygiene 0.18.1 — `write-for-humans`' seven-question self-check ran unconditionally, so a run that reached the end graded a project's README against the bundled Diátaxis/STE/Global-English set *after* resolving that project's own declared guide, and rewrote it to conform. That reverses the skill's first instruction and falsifies two of its six evals. The gate now checks against whichever standard was resolved. "Three rules above the layers" becomes "Three rules that survive a declared guide" and says why. - review 0.25.1 — `downstream` mode pointed at `playbooks/fable-5/context/verification.md`, a path the encapsulation contract makes private. Now cited as `/playbooks:fable-5`'s verification chapter, the only supported handle. - session-flow 0.32.1 — both retro skills "handed" a skill candidate to `/playbooks:skill-authoring`, which takes no arguments and performs no actions. They now read it for the doctrine and draft against it. - architecture 0.6.1 — `graft-record:` was added to the candidate schema but no step wrote it. The Handoff step now fills it, and the research file points at that step instead of naming `agreed-shape` as the destination. - discovery 0.16.1 — three routes back to the code-shape exclusion the skill is built around: "test names" as source-control evidence, a gotcha that read as licensing `Speculative` for code shape, and a behavioural ceiling the body stated more narrowly than the eval graded. Plus an eval whose target behaviour was indistinguishable from correct behaviour in a bare checkout. - prototype 0.9.1 — `explore-directions` step 6 restated the shared capture discipline in its pre-0.9.0 form, immediately above the irreversible deletions. - implementation 0.15.1 — "the loop lanes" now names `work-items:work-loop` and `source-control:babysit-loop`. - testing 0.7.1 — "Prefer no new test to a bad one" now carries its attribution: (Khorikov, via `/tdd:principles`). Declared in-place correction inside a released body, per the changelog contract's sanctioned form (heading untouched, edit named here and in the changelog): architecture 0.6.0's "the five-part schema was pinned in three places" said three; the eval pins it in two. Provenance record — `docs/upstream/cursor-pstack.md` carried twelve claims that did not survive checking against the pinned upstream, including a `must` the upstream states as `Prefer`, an `isolation: worktree` the upstream never mentions, a miscited `arena` precedent, three non-verbatim quotes, two wrong file paths, and four wrong counts. All corrected against `main@60c641e4`. `docs/conventions/upstream-drift` 1.6.0 adds the adopter row for `write-for-humans`' source records — four four-part records over Diátaxis, Google developer documentation style, ASD-STE100 and Global English, each triggered by a publication event rather than a fetch divergence. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EtvBfWQRz7w6kgRnJm4qgj Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Codex review on #3069 caught that the encapsulation fix traded one defect for another. Citing `/playbooks:fable-5` bare is a supported handle, but that skill's own argument contract makes a bare invocation arm its entire operating doctrine as standing session instructions for the remainder of the session; only a chapter-name argument reads one chapter. `downstream` mode reaches for a single formula — "assessed, not verified because Y" — and must not re-posture the session that follows it. Now cites `/playbooks:fable-5 verification`, and says why the argument is load-bearing so a later editor does not trim it back to bare. Verified against plugins/playbooks/skills/fable-5/SKILL.md's own Arguments paragraph and its `argument-hint: "[full | <chapter>]"` frontmatter, and against context/verification.md existing as a real chapter. The review 0.25.1 entry carries the same reasoning; no version bump, since 0.25.1 has not shipped. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EtvBfWQRz7w6kgRnJm4qgj Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
….16.1 The CI code review on #3069 caught an undescribed change riding along in the diff: `trace-intent`'s Scope-section link to `reference/parent-contract.md` was switched from a relative href to the `${CLAUDE_PLUGIN_ROOT}` token, and the 0.16.1 entry listed only the three code-shape-exclusion routes. The change itself is right and stays. `explore`, `research` and `research-deep` all cite that same file with the token on both sides of the link, and the fleet runs 179 token-href sites to 29 relative ones; `trace-intent` was the outlier. Two spellings of one reference across sibling skills is the divergence `discipline:reuse-or-replace` exists to catch, and the relative form is the one that breaks first — it resolves from the file's own location rather than from the installed plugin root. An undescribed edit in a changelog-bearing diff is a defect whether or not the edit is correct, so the entry now names it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EtvBfWQRz7w6kgRnJm4qgj Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
… own diff
Two adversarial verifiers ran over `b1bf09c6` with the rationale withheld — one
on the changelog restructure, one on every factual claim in the PR body, the
second reaching the live upstream at `cursor/plugins@60c641e4`. Between them
they found eight defects in work this PR introduced. All eight are closed here.
Shipped text:
- **`write-for-humans`' new gate contradicted itself.** It said "the seven below
do not apply" under a declared project guide and, one line later, "the three
rules above apply either way" — but questions 4, 6 and 7 ARE those three
rules. A run under a project guide was told to skip and to apply them at once.
The gate now says which four questions come from the bundled layers and stand
down, and which three apply whichever standard was resolved. The 0.18.1 entry
carried the same false premise ("every one of its questions restates a bundled
layer") and is corrected with the per-question breakdown.
- **An undescribed compression pass rode along in that same file** — nine hunks
the changelog never mentioned, three of them lossy: the "does NOT do" bullet
lost "of a published standard" and "the source records"; two gotchas lost
their actionable half; one lost the "only" whose placement the skill's own
ambiguity rule governs. The worked example lost "(and ambiguity)" from a fix
that IS an ambiguity fix, and misquoted its own Before block as "if exceeded"
where the block reads "If exceeded". Reverted to `origin/main` and the two
described fixes re-applied on top, so the diff now matches its changelog.
- **`interface-design.md` named two destinations for one record.** The appended
correction said `graft-record` is a sibling of `agreed-shape` while the
sentence above it still said the record "travels into `agreed-shape`". That
sentence is replaced rather than annotated.
- **`explore-directions` step 6 was still short a clause.** It carried the
losers and the graft but dropped "what the discarded parts held that the graft
deliberately left behind" — which the shared discipline argues is the
highest-value half — while the changelog claimed the widened form.
Provenance and convention records:
- `docs/upstream/cursor-pstack.md` cited `context/spec.md` bare; the real file is
`review/skills/quality-gate/context/spec.md`, and `review/context/` holds no
`spec.md` at all, so the short form pointed nowhere.
- The `upstream-drift` adopter row flattened all four `write-for-humans` source
records to "a publication-event trigger rather than a fetch divergence". Three
are publication events; Google's is a page-content divergence, because that
guide is a continuously-edited site with no edition to pin. The contract admits
either shape — the row now says which record uses which instead of
generalizing from three to four.
Changelog accuracy:
- The `discovery` 0.16.1 umbrella said "three routes back to the code-shape
exclusion". Two are; the third is the version-control-behaviour ceiling, which
the same skill says explicitly is NOT code shape. Split into its own bullet as
what it is — a body-vs-eval derivability gap on the neighbouring rule.
- The `review` 0.25.1 entry spelled the private path the fix removed, leaving the
cite standing in `plugins/review/` after the skill body dropped it. Described
rather than spelled.
Gates at this tip against `origin/main`: markdownlint over all 1253 tracked
markdown files (0 issues), check-changed-skills 9/9, validate-plugins,
validate-plugin-contracts (48 setup skills, 2816 files), all four
changelog-parity modes, and the twelve standalone gates. No executable file is
touched anywhere in this PR, so the plugin test suite cannot be affected by it.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EtvBfWQRz7w6kgRnJm4qgj
Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…d:principles Codex review on #3069 said the new (Khorikov, via /tdd:principles) parenthetical points at a skill that does not contain the rule. Checked against primary sources rather than taking either side on report: - cursor/plugins@60c641e4 pstack/skills/tdd/SKILL.md states "Prefer no new test over a bad test" and lists the six impracticality triggers. That is the file docs/upstream/cursor-pstack.md records as the cost-branch source. - plugins/tdd/skills/principles/ and its routed Khorikov files contain neither the phrase nor the triggers. The nearest sentence is Khorikov's "It's better to not write a test at all than to write a bad test" in testable-architecture-khorikov.md (the 2x2 / Humble Object chapter), which this port used as grounds to reject upstream's five-item bad-test definition as already owned — a different rule. The inline cite is now (upstream cursor/plugins tdd). 0.7.1 has not shipped, so the entry is rewritten in place rather than patched with a further bump. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
8f4eda6 to
34f483a
Compare
|
Claude finished @cursor[bot]'s task in 2m 4s —— View job CI Code Review
Note on scopeThis lane previously reviewed this PR three times against an earlier, messier commit history ( FindingsNo blocking findings. I re-traced every claim in the PR body and prior review rounds against the actual files at this head, and specifically scrutinized the one commit that's substantively new relative to what was reviewed before:
I did not re-run |
…sdlc-jkujin # Conflicts: # plugins/architecture/CHANGELOG.md # plugins/discovery/CHANGELOG.md # plugins/docs-hygiene/CHANGELOG.md # plugins/implementation/CHANGELOG.md # plugins/prototype/CHANGELOG.md # plugins/review/CHANGELOG.md # plugins/session-flow/CHANGELOG.md # plugins/session-flow/skills/retro/context/session.md # plugins/testing/CHANGELOG.md
|
Claude finished @kyle-sexton's task in 1m 34s —— View job Security review
Skip gate: triggered (condition 3 — this head already has a successful security review that still applies).
This lane already reviewed the PR's own content three times ( I confirmed the merge introduced no new content to this PR's own diff:
Since nothing in the PR's actual authored content changed, the prior review findings still apply. This remains documentation/skill-instruction content only, as in every prior pass on this PR: no executable code, no GitHub Actions workflow, no script, no auth/access-control logic, and no input-handling surface. Per the skip gate in |
PR #3069 claimed 0.39.8 for an unrelated change ("Cross-skill chains name the Skill tool") while this branch was open, so the adapter-fix entry moves up to 0.39.9 and sits above it. Manifest and CHANGELOG both. Verified after resolving: no conflict markers anywhere, changelog parity and --check-bump origin/main both pass, markdownlint clean, version sections in descending order, and every change on this branch survived the merge — type=issues and the stdin accumulation in gitea/list-items.sh, the root issueLabels walk in linear/create-item.sh, and the /orgs labels merge in gitea/create-item.sh. Full suite sweep clean across every adapter, conformance binding, lib and the generator. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CnzwTKoTa6xNY7iyEzMYpm
…ion table (#3094) The attribution table claimed to be the single source of truth for everything this marketplace derived from cursor/plugins' pstack/skills collection, and its recheck trigger only reaches rows the table names — but unslop, from which plugins/ai-slop is derived, had no row. Drift in that upstream skill would have gone undetected. One row added, recording what was taken, what was deduplicated against the Wikipedia inventory, and what was rejected with its reason. It also states what it is not: the verdict was formed at integration time against an unpinned upstream main, so the file's pin is this row's baseline for the next diff rather than the state it was audited at, and the derivation is dated 2026-08-19 rather than left to this file's git history. The head resolved a conflict with #3069, which had rewritten three rows on main including a correction retracting two earlier overstatements. Main's rows were taken verbatim; the diff against main is one insertion and zero deletions. show-me-your-work remains a second, pre-existing instance of the same gap and is tracked separately.
No linked issue
Summary
A fresh-context verification pass ran over #3065 after it merged and found defects in what that PR shipped: 12 in the eight plugins it touched, 12 in the provenance record, and 1 wrong count inside a released changelog entry. Two of the twelve are behavioural — a completion gate that reverses its own skill's first instruction, and a cite into another plugin's private files. The rest are unresolvable pointers, a schema field with no writer, an eval that cannot fail for the reason it claims to test, and claims in
docs/upstream/cursor-pstack.mdthat do not survive checking against the pinned upstream.Two more adversarial verifiers then ran over this PR's own first commit, one of them reaching the live upstream. They found eight further defects in work this PR introduced, plus one from a Codex review. All nine are fixed and described below.
Every plugin whose shipped text changed takes a patch bump with its own
### Fixedentry. #3065's release entries describe what #3065 shipped and cannot be retrofitted to describe corrections made after it merged.Fix
The two behavioural defects in #3065
docs-hygiene:write-for-humansgraded against the wrong standard (0.18.2). The skill's first instruction is to resolve the consuming project's own style guide before applying anything bundled — that re-posture is the port, and it is whatPLUGIN-PHILOSOPHY.md:198-202's two-lane rule demands. But 0.18.0 shipped the seven-question self-check unconditionally, and four of those seven restate a bundled layer (1 is Diátaxis, 2 and 3 are ASD-STE100, 5 is Global English's ambiguity set). A run that followed the skill to its end would resolve a project's declared Microsoft guide, write against it, then grade the result against the bundled standards and rewrite it to conform. That is a lane-1 hardcode wearing lane-2 clothing, and it falsifies two of the skill's six evals. The gate is split, not switched off wholesale — see below for why the first attempt was wrong.review:quality-gate downstreamcited into another plugin's private files (0.26.2). Its "say plainly what is unverified" step path-cited theplaybooksplugin'sfable-5skill inside that skill's owncontext/directory, which the encapsulation contract makes private. Now/playbooks:fable-5 verification— the chapter argument is load-bearing, see below.The rest of #3065's defects
architecturegraft-record:was added to the candidate schema and no step wrote it — the Handoff step namedstatusandagreed-shapeand stopped. A field nothing fills is always empty, so the left-behind half of a graft survived nowhere. Handoff now fills it; the research file's "travels intoagreed-shape" named the wrong field and is replaced.discoverySpeculative's own Competing hypotheses output section. Separately a body-vs-eval gap on the neighbouring rule — the version-control-behaviour ceiling said "neverDirect" while the eval graded "neverDirectorSupported". Plus an eval whose target behaviour was indistinguishable from correct behaviour: it told the model not to check the tracker but never stipulated one existed, and the category is presence-gated, so a bare checkout's correct output was graded a failure. Plus a link-target normalization to the fleet's${CLAUDE_PLUGIN_ROOT}convention.implementationimplementationalone. Now nameswork-items:work-loopandsource-control:babysit-loop.prototypeexplore-directionsstep 6 restated the shared capture discipline in its pre-0.9.0 form — "record which variant won and why" — directly above the bullets that delete the losing variants irreversibly.session-flow/playbooks:skill-authoring, which takes no arguments and performs no actions. Handing it a candidate resolves to nothing, so the destination 0.32.0 set out to give did not exist. Both now read it for the doctrine and draft against it.testingtddcost branch (cursor/plugins@60c641e4pstack/skills/tdd/SKILL.md). Cited inline as(upstream cursor/plugins tdd)./tdd:principlescontains neither the phrase nor the six triggers.One declared in-place correction to a released body
scripts/check-changelog-parity.shsanctions corrections inside an already-released version section when the correcting PR names each edit in its body and in the new release entry. Exactly one qualifies, and it is the only removed changelog line in the whole diff: architecture 0.6.0 said "the five-part schema was pinned in three places"; commit228a2b19changed the count in exactly two spots. Corrected in place; heading untouched.Nothing else was edited in place. Three blocks initially drafted as appends into released
### Addedsections were lifted back out and re-homed under the new patch entries, because attributing post-release work to a released version misleads anyone reading the changelog to learn what that version contains.Concurrent-bump resolutions — #3067, #3068, #3070
Main bumped these plugins three separate times while this branch was open, and each time it claimed a number this branch had already taken.
review0.25.1 → this branch moved to 0.25.2.review0.26.0 → this branch moved to 0.26.1.### Changedsweep that claimed the same patch number on all eight plugins this PR bumps → every entry here moved to.2.The third one is worth recording, because it was invisible to the usual check.
git merge-treereported zero conflict markers: each side had edited a different region of each file, so a clean-looking merge would have produced eight changelogs in which two different releases share one heading. That is precisely the corruption--check-preservedexists to catch. The real merge surfaced nine conflicts once the bodies collided. In every case main's heading and body are untouched and this branch's entry moves up; no release is folded, relabelled, or dropped.One of those nine was semantic rather than numeric. #3070 respelled
retro/context/session.md's route as "Hand it off by invoking/playbooks:skill-authoringvia the Skill tool" — which reintroduces the exact claim this PR fixes, since that skill takes no arguments and performs no actions. Both changes are kept: the invocation still names the Skill tool (it is invoked in order to be read), but it reads the doctrine and drafts against it rather than handing anything over. The siblingrunning-retrois deliberately not aligned to match — #3070's own entry says it left that list alone because it sits under "Offer routing — never auto-apply", so the asymmetry is intentional and is now recorded in the 0.32.2 entry.The provenance record — 12 corrections
docs/upstream/cursor-pstack.mdcarried twelve claims that did not survive checking againstcursor/plugins@60c641e4:must; upstream says "Prefer a different model family from the parent's" andmustappears zero times in that file.isolation: worktree" — the word never appears upstream. Its mechanism is a per-candidate output path, which is why this fleet's three recordedisolation:rejections were not in conflict with it.arenaomission's grounds now rest on the Rule of Three alone.technical-writingrow credited our third always-rule to upstream's above-the-layers trio; it comes from upstream's separate word-list and anti-jargon paragraphs.5–7. Three non-verbatim quotes:
debugging:debugphase 5, upstream'stdddescription, and the above-the-layers rule text.ai-slop's catalog path —reference/catalog.md→skills/audit/reference/catalog.md.context/spec.md— the real file isreview/skills/quality-gate/context/spec.md, andreview/context/holds nospec.md, so the short form pointed nowhere.brois seven lines, two of them body" → one.An independent verifier re-checked 1, 2, 11 and 12 against the live upstream files and confirmed each verbatim.
Convention record
docs/conventions/upstream-drift1.6.0 adds the adopter row forwrite-for-humans' source records. Three carry a publication-event trigger; Google's is a page-content divergence, because that guide is a continuously-edited site with no edition to pin. The contract admits either shape, and the row says which record uses which.Defects in this PR's own diff, found and fixed
Two fresh-context verifiers ran over commit
b1bf09c6with the rationale withheld; a Codex review ran alongside.write-for-humansgate contradicted itself — "the seven below do not apply" under a declared guide, then "the three rules above apply either way", when questions 4, 6 and 7 are those three rules. Now split per question: four stand down, three always apply.interface-design.mdnamed two destinations for one record. Replaced rather than annotated.explore-directionsstep 6 was still short a clause — it dropped "what the discarded parts held that the graft deliberately left behind" while the changelog claimed the widened form./playbooks:fable-5cite (Codex). That skill'sargument-hintand Arguments paragraph make a bare invocation arm its entire operating doctrine as standing session instructions for the rest of the run. Now/playbooks:fable-5 verification.discoveryumbrella overcounted — "three routes back to the code-shape exclusion" when the third is the version-control-behaviour ceiling, which the same skill says explicitly is not code shape.reviewentry spelled the private path the fix removed. Described rather than spelled.upstream-driftadopter row generalized from three records to four. Corrected.One Codex finding was accepted after a primary-source check reversed an earlier decline. Its claim that
/tdd:principlescontains neither the phrase nor the six triggers is correct. That skill's nearest sentence is Khorikov's "It's better to not write a test at all than to write a bad test" intestable-architecture-khorikov.md— the 2×2 / Humble Object chapter, which this port used as grounds to reject upstream's five-item bad-test definition as already owned. The phrase and the six triggers come from upstreamtdd("Prefer no new test over a bad test", plus the identical trigger list), whichcursor-pstack.md:34already recorded as Taken. The original cite therefore contradicted this PR's own provenance document. Now(upstream cursor/plugins tdd).Verification
Every gate re-run locally at the branch tip against the current base (
69b3584), all green:check-changelog-parity— all four modes.--check-bump: each of the eight version changes has its own new entry and is strictly greater than the base's.--check-preserved: 9 changed changelogs, 322 headings compared, none dropped — including every heading fix(work-items): harden the tracker seam's lease and generator paths, and reconcile the upstream SSOTs #3067, feat(review): route producer-owned findings to the producer's own fix skill (0.26.0) #3068 and docs(plugins): normalize operative cross-skill chains to explicit Skill-tool phrasing #3070 added.--check-order: newest-first, no duplicates.check-changed-skills— 9 skills checked, 0 failed.validate-plugins(manifests + catalog,--strict),validate-plugin-contracts(48 setup skills, 2823 files).check-skill-portability,check-skill-count-claims,check-skill-leaf-names,check-cross-plugin-source-drift,check-plugin-manifest-presence,check-orphaned-fixtures,check-silent-skips,check-fleet-audit-doc-grammar,check-lane-coverage,check-contract-clause-coverage,check-contract-slice-prune,check-stale-base-overlap.markdownlint-cli2over every tracked markdown file — 0 issues.evals.jsonvalidate against the bundled schema, 0 failures.check-evals-qualityreturns PASS with advisory warnings fleet-wide (the WARN tier never fails the step); the two suites this PR touches carry 0 warnings. An earlier revision said "PASS, 0 warnings" without that distinction — a verifier caught the overstatement.plugin.jsonversion bumps, and oneevals.json— so the plugin test suite cannot be affected by it.Related
docs/upstream/cursor-pstack.md— the single source of truth for everything derived fromcursor/plugins@60c641e4.docs/conventions/upstream-drift— the four-part stamp contract the new adopter row conforms to.docs/PLUGIN-PHILOSOPHY.md:198-202— the two-lane convention posture thewrite-for-humansself-check violated.scripts/check-changelog-parity.sh— the released-entry body-edit clause the one in-place correction is declared under, and the concurrent-bump guidance every resolution here follows.