Skip to content

docs(ssot): fleet SSOT normalization batch — versioned, evals-complete replay - #3178

Merged
kyle-sexton merged 18 commits into
mainfrom
claude/docs-hygiene-ssot-extract-jpb79j
Aug 23, 2026
Merged

docs(ssot): fleet SSOT normalization batch — versioned, evals-complete replay#3178
kyle-sexton merged 18 commits into
mainfrom
claude/docs-hygiene-ssot-extract-jpb79j

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

No linked issue

Summary

The fleet-wide SSOT normalization batch from closed #2698, replayed onto current main as the versioned, evals-complete batch that close-out called for. Seven verified clusters re-applied with per-cluster Tier 0 re-verification and refutation checks; every touched plugin bumped with a changelog entry; every touched-and-evals-less skill gains a validated eval suite; the contract slice from the old branch is gone (branch restarted from main), so the prune gate passes by construction.

Fix

Replayed in four adversarially-reviewed waves, treating the closed PR's reviewed diff (b89723f0) as the canonical-text source and current main as ground truth:

  • C02 / C04 / C07 — three author-facing conformance blocks added to docs/PLUGIN-PHILOSOPHY.md §"Setup is explicit and repeatable" (contract preamble, check-opening directive, never-writes sentence), with 33 / 24 / 18 setup skills normalized byte-identical around preserved per-plugin slots. Sites main had already brought into conformance were left untouched; new-on-main plugins carrying the old wording were normalized; one reference slot that was self-refuting against disk-hygiene's runtime was rewritten from the runtime and the anti-pattern (audit-only kill switches are not short-circuit gates) recorded in the SSOT block.
  • C06 — new docs/conventions/untrusted-content/ owner doc (framing contract + fixed inline adopter spine) with 17 adopting sites normalized and a Convention-registry row; the fable-5 clause names ADR-0006 and the pack's deliberately independent formulation.
  • C01 — the cross-vendor-advisor-fallback rule normalized across 15 runtime sites (including one that arrived via the feat: port the cursor/plugins pstack collection — 2 new skills, 8 argued absorb/omit verdicts #3065 port with a release note promising this conformance), each with one provenance citation of "Fresh-eyes checkpoints"; four doctrine-drifted variants repaired.
  • C09 — Shape C deletion of 9 README option-scoping preambles the generated block already states, plus 3 in-file pointers.
  • C17 / C23 — songwriting attribution/seam framing normalized across 9 skills against the plugin's own README; the mktemp GNU/BSD dialect semantics hoisted into the topic-docs ephemeral-tier rule with 4 consumer sites normalized.
  • Dropped: C03 (headless-reconfigure recipe) — its central claim was refuted on main by fix(plugins): correct the unstamped --config reconfiguration claim (#3111) #3115 (--config does write to an installed plugin, verified on CC 2.1.240); the philosophy's own --config bullet still carried the refuted wording and is aligned here with the corrected, stamped doctrine the fleet's setup skills already carry.
  • Evals — five new suites (firecrawl, playwright, songwriting setup; songwriting meter-prosody and practice) so every touched skill satisfies the changed-skills gate with real behavioral evals; all schema-validated and eval-quality-lint clean.
  • Lessons 12–15 appended to extract-ssot's context/lessons.md, including the new replay-discipline lesson this PR's own execution produced.
  • Parity — patch bumps + class-tailored changelog entries for every plugin the change set modifies, per the published-version-reuse gate.

Plugin runtime surfaces keep their operable text inline (an installed plugin cannot read this repo's docs/); citations are provenance-only, at most one per file. Every wave carried a fresh-context adversarial diff review before commit; all blocking findings were repaired pre-commit.

Verification

  • Full local gate battery green: changed-skills 76 checked, 0 failed; changelog parity (--check-bump, --check-order) clean; manifest duplicate-keys clean; skill portability clean; cross-plugin source drift clean; plugin contracts 50 setup skills, 2827 files validated; contract-slice prune gate passes (no docs/topics/ paths in the diff).
  • markdownlint-cli2 and typos clean on every touched file, enforced per wave.
  • Post-edit conformance greps per cluster: zero remaining in-scope un-normalized reproductions; exactly one provenance citation per adopting file.

Related

No linked issue (successor to closed #2698, per its close-out plan).


Generated by Claude Code

claude added 10 commits August 23, 2026 05:05
…content convention

Replay of closed PR #2698's waves onto current main (reference
b89723f), with per-cluster Tier 0 re-verification and refutation
checks. C02: philosophy conformance rule + 33 setup skills normalized
(2 post-reference adopters included; guardrails' corrected toggle count
kept as main states it). C06: untrusted-content owner doc + 17 adopting
sites + registry row; review repairs applied (fable-5 clause corrected
to name ADR-0006 and the pack's independent formulation, number-
agreement license added to the spine template).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
…reamble dedup

C01: normalize 15 call sites (one new post-reference site included per
its own release note; four doctrine-drifted variants repaired) to the
canonical sentence with one Fresh-eyes-checkpoints provenance citation
each; refutation check corroborated by verification 0.3.4.
C09: Shape C deletion of 9 README option-scoping preambles + 3 in-file
pointers, identical site set to the reference, generated blocks
re-verified unchanged. Both adversarial reviews approved.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
…attribution

C07: check-opening block added to the philosophy setup section
(anti-pattern for audit-only kill switches included) and the
Read-it-first directive + downgrade pair normalized across 18 setup
skills, gate facts verified against each plugin's runtime. Review
repairs applied: disk-hygiene's downgrade replaced with a truthful
audit-lane-aware paragraph (its toggle is a kill switch, not a
short-circuit; git stays FAIL), session-flow tail flattened,
philosophy vocabulary attribution fixed plus a straggler-tracking
clause, eol-normalizer scope claim de-counted.
C17: Pattison attribution/seam framing normalized across 9 songwriting
skills (review approved).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
C04: third philosophy setup block + 24 setup skills normalized (9
already-conforming main sites untouched; per-file provenance budget
held; two new-on-main plugins' folded variants split). C23: full
mktemp dialect semantics hoisted into the topic-docs ephemeral tier,
4 consumer sites normalized. Both adversarial reviews approved. Also
align the philosophy's --config bullet with the #3115-corrected
doctrine the fleet's setup skills already carry (owner-doc drift the
C04 worker flagged).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
Lessons 12-14 restored from the reviewed reference batch (changelog
refutation evidence, portability output-type inversion, dependent-
cluster re-counts); Lesson 15 added from this replay (re-derive site
rosters on a moved base; hunk-level pre-image checks; reference
omissions are decisions).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
Five behavioral scenarios grounded in the SKILL.md (read-only
inventory, destructive-collision guard, bulk-scaffold refusal,
idempotent apply, guidance-not-edit custom layout); schema-validated
and eval-quality lint clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
Five behavioral scenarios each, grounded in the current SKILL.md text
(lazy-install INFO semantics and no-write-path refusals for firecrawl;
the single permitted install-cli write, probe-verified, for playwright);
schema-validated and eval-quality lint clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
Patch bumps with class-tailored changelog entries for every plugin the
replay waves touch (per the published-version-reuse gate), and compress
the plugin-quality audit skill's untrusted-content paragraph back under
the 500-line hard cap (both grep-protected fragments kept unbroken).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
Five behavioral scenarios each, grounded in the skill bodies (critique-
filter preflight, boundary-table refusals, timed object-writing shape);
schema, checker, and eval-quality lint all clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
Four plugins were released on both sides; ours renumber above main's
published versions (code-tidying 0.14.1, docs-hygiene 0.19.1,
skill-quality 0.19.1, source-control 0.55.3) with main's entries and
history preserved.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
@claude

claude Bot commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 6s —— View job


Security review (/review:security-review)

  • Gather context (PR diff, changed files)
  • Invoke /review:security-review skill and follow its instructions
  • Post findings / summary

Skip gate hit: no security-relevant surface.

Reviewed the full diff (git diff origin/main...HEAD, 214 files, +1827/-551) against commit 6f7fbe6. The change set is entirely:

  • Markdown doc normalization (docs/PLUGIN-PHILOSOPHY.md, new docs/conventions/untrusted-content/README.md, SKILL.md/README.md prose edits across plugins)
  • plugin.json version bumps and non-ASCII-dash → em-dash text fixes (no schema/permission changes)
  • CHANGELOG.md entries
  • New evals/evals.json behavioral eval fixtures (prose prompts/expectations, no executable content)

No .github/workflows/*, no shell/Python/JS scripts, no hook or permissions config, and no application logic are touched anywhere in the diff. This is a pure documentation/SSOT-conformance batch with no injection surface, no auth/access-control code, no secret handling, and no GitHub Actions trigger/permission changes to review.

Per the skip gate in /review:security-review ("change has no security-relevant surface after reading the diff"): stopping here — no findings to report.

@github-actions

github-actions Bot commented Aug 23, 2026

Copy link
Copy Markdown

Last security-reviewed head: 4adc997a72efe7a81e40c348c6d5670ca2477ca1. On the next push, the relevance gate compares only the commits since this SHA; delete this comment to force a full re-review.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 009f9b99fa

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/PLUGIN-PHILOSOPHY.md Outdated
claude added 2 commits August 23, 2026 06:03
The merge-resolution script emitted an extra blank line above the first
retained release heading in the four renumbered changelogs; CI's
repo-wide markdown gate (MD012) caught what the touched-files-only
local lint missed.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
…aries

Codex review (P2, confirmed): the C04 block claimed the prohibition is
stated inline in every setup skill while seven batch-touched skills'
boundaries lists lacked it — add the canonical sentence to each. The
block's claim is scoped truthfully and the remaining out-of-diff
stragglers (plus the documented non-extraction trio) route to the fleet
conformance audit like the sibling blocks' stragglers.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
@claude

claude Bot commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 42s —— View job


Security review (/review:security-review)

  • Gather context (PR diff, changed files)
  • Invoke /review:security-review skill and follow its instructions
  • Post findings / summary

Skip gate hit: no security-relevant surface.

The last successful review covered head 6f7fbe6. This run's job was triggered by two new commits pushed since then (913d7cc, 881d728), so per the skill's relevance gate I reviewed git diff 6f7fbe6..881d728 (12 files, +12/-7):

  • docs/PLUGIN-PHILOSOPHY.md — clarifying prose in the "never-writes sentence" contract paragraph (no operable/behavioral content).
  • plugins/{code-tidying,firecrawl,mutation-testing,review,songwriting,toolchain,work-items}/skills/setup/SKILL.md — each adds the single fixed guard line Write the plugin cache, Claude Code user settings, or pluginConfigs. to an existing "What this skill does NOT do" list.
  • plugins/{code-tidying,docs-hygiene,skill-quality,source-control}/CHANGELOG.md — stray blank-line cleanup only.

No .github/workflows/*, scripts, hooks, permissions, or application logic in this delta (or in the full PR diff, previously reviewed at 6f7fbe6). This remains a pure documentation/SSOT-conformance change with no injection surface, no auth/access-control code, and no secret handling.

Per the skip gate in /review:security-review ("change has no security-relevant surface after reading the diff"): stopping here — no findings to report.

@claude

claude Bot commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 5m 11s —— View job


Code review (/review:code-review)

  • Gather context (PR diff, changed files)
  • Invoke /review:code-review skill and follow its instructions
  • Post findings as inline PR comments / summary

Summary

Reviewed the full PR diff (gh pr diff 3178, 214 files) at HEAD 881d728. This is a large, mostly mechanical SSOT-normalization batch (doc prose, plugin.json version bumps, changelog entries, new eval fixtures). Confirmed a few of the PR body's self-verification claims hold under direct check:

  • The "carry the never-writes sentence in seven more setup boundaries" fix commit (881d728) does add the fixed sentence to the 7 named setup skills, and the PLUGIN-PHILOSOPHY.md wording was correctly softened from an absolute "every setup skill" claim to an honest "stragglers tracked by the fleet conformance audit" — this correctly resolves the prior Codex P2 finding rather than papering over it. The 8 remaining touched setup skills without the sentence (bug-report, context7, discipline, dometrain, education, knowledge, miro, session-flow) don't have a boundaries list at all, so there was nothing in-scope to append it to — consistent with the revised claim.
  • "Exactly one provenance citation per adopting file" for the setup-contract citation: verified true across all 41 touched setup/SKILL.md files (one occurrence each).
  • Spot-checked a C09 README deletion (plugins/actionlint/README.md): the removed hand-written paragraph about user-scoped options and per-repo enabledPlugins disabling is in fact restated by the generated block further down the same file — the deletion is genuinely non-lossy.

One real gap found in the PR's own new conformance mechanism — flagged inline on plugins/github/reference/change-routing.md#L128: that file adopts the new untrusted-content spine phrase without the accompanying provenance citation, which the PR's own new docs/conventions/untrusted-content/README.md "Conformance" section defines as the nonconforming case ("carrying an unattributed copy of the contract"). Running the two greps that doc specifies confirms an 18-vs-18 file-set mismatch, one of which (item-content-trust.md) is a documented, legitimate exception, the other (change-routing.md) is not documented anywhere — so it contradicts both the new conformance check and the PR body's "one provenance citation per adopting file" verification claim.

Did not exhaustively verify the C17/C23 mktemp GNU/BSD dialect semantics claim (docs/conventions/topic-docs/README.md) — that requires access to both a GNU coreutils and a BSD/macOS mktemp binary to confirm the -p/-t/TMPDIR interaction described, which wasn't available in this environment; flagging as author-claimed and unverified rather than confirmed.

No security-relevant surface in this diff (docs/config/changelog/eval-fixture only) — out of scope for this lane regardless, per /review:security-review's prior pass on this PR.

Comment thread plugins/github/reference/change-routing.md Outdated
@github-actions

github-actions Bot commented Aug 23, 2026

Copy link
Copy Markdown

Claude has reviewed this PR 5 times. The lane skips further automatic reviews after 5; deleting this comment resets the count.

claude added 3 commits August 23, 2026 06:28
Code review (P2, confirmed): the reworded sentence adopted the spine
phrase without the provenance citation — the exact unattributed-copy
shape the new convention's conformance grep flags. Carry the standard
parenthetical.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
The previous wrap split the heading from the path, so the convention's
single-line conformance grep still missed the site; wrap after
"(framing per" like the other adopters.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
Main released claude-ops 0.36.0 and its own work-items 0.39.15 under
the branch; ours renumber to 0.36.1 and 0.39.16 with main's entries
preserved. Main's fuller correction of the philosophy --config bullet
supersedes this branch's version of the same fix (theirs taken).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
@claude

claude Bot commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 41s —— View job


Code review (/review:code-review)

  • Gather context (PR diff, changed files)
  • Invoke /review:code-review skill and follow its instructions
  • Post findings as inline PR comments / summary

Skip gate hit: this head already has a successful review from this lane that still applies (skip-gate condition 4).

This run was triggered by a push, but git log 881d728..HEAD shows only:

  • c8114e0 + 3d06b32 — the fix for the one finding this lane flagged in its prior full review at 881d728 (plugins/github/reference/change-routing.md#L128): the untrusted-content spine phrase there was missing its provenance citation.
  • 208e2d4 — a merge of origin/main (#3174, unrelated claude-ops/work-items sync). Since origin/main (208e2d4) is the merge-base with HEAD, git diff origin/main...HEAD correctly excludes all of that content — it isn't part of this PR's reviewable diff.
  • 89a230c — the resulting merge commit itself, no additional diff.

I independently re-ran the two conformance greps this PR's own docs/conventions/untrusted-content/README.md defines:

  • never instructions to you → 18 adopting files (incl. change-routing.md)
  • untrusted-content/README.md` "The framing contract" → matches the same adopting set, plus the documented exception plugins/work-items/reference/item-content-trust.md

change-routing.md now appears in both sets — the fix genuinely resolves the gap flagged in the prior review, matching the author's and this lane's earlier confirmation. No new files, logic, or content beyond that targeted fix are in scope, and the rest of the PR was already fully reviewed at 881d728 (214 files) with the one finding above the only blocking issue raised. No further findings to add.

@claude

claude Bot commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 42s —— View job


Security review (/review:security-review)

  • Gather context (PR diff, changed files)
  • Invoke /review:security-review skill and follow its instructions
  • Post findings / summary

Skip gate hit: no security-relevant surface.

The last successful review covered head 881d728. This run's job was triggered by new commits pushed since then (a merge of origin/main that renumbered claude-ops/work-items releases, plus #3174), landing at head 89a230c.

Per the skill's relevance gate, I compared both scopes:

  • Raw branch delta (git diff 881d728..89a230c, 29 files) pulls in shell scripts (fleet-state.sh, work-item-tracker adapters' claim.sh/common.sh/reclaim.sh/lease.sh) and other content — but these arrived via merging origin/main into the branch, not from this PR's own commits.
  • Actual PR diff (gh pr diff 3178, i.e. origin/main...HEAD, 213 files) confirms none of those scripts, .github/workflows/*, or any .sh/.py/.js/.ts/.yml file appear anywhere in the PR's real diff — they're identical to origin/main and simply passed through the merge unchanged.

The only files touched since 881d728 that remain part of this PR's actual diff are:

  • plugins/claude-ops/.claude-plugin/plugin.json, plugins/work-items/.claude-plugin/plugin.json — version renumbering only.
  • plugins/claude-ops/CHANGELOG.md, plugins/work-items/CHANGELOG.md — changelog prose (including narrative from an already-landed, previously-reviewed fix describing the GitHub adapter's claim/reclaim REST migration — no code here, doc-only).
  • plugins/claude-ops/skills/setup/SKILL.md — reconfiguration guidance prose (headless --config semantics).
  • plugins/github/reference/change-routing.md — the citation-attribution fix already reviewed and confirmed resolved in the prior pass.

No new script, workflow, hook, permissions, or application-logic surface entered the PR since the last review. This remains a pure documentation/SSOT-conformance and version-bump change set with no injection surface, no auth/access-control code, and no secret handling.

Per the skip gate in /review:security-review ("this head already has a successful security review that still applies"): stopping here — no findings to report.

Same MD012 artifact as the earlier renumbered changelogs; the prior
lint pipeline masked its exit code behind tail.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
@claude

claude Bot commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 47s —— View job


Code review (/review:code-review)

  • Gather context (PR diff, changed files)
  • Invoke /review:code-review skill and follow its instructions
  • Post findings as inline PR comments / summary

Summary

This lane already produced two full-diff passes on this PR (head 881d728: comment, and the earlier Codex pass). Per the skill's skip gate ("this head already has a successful review from this lane that still applies"), I scoped this pass to what actually changed since 881d728 rather than re-litigating already-reviewed ground, since re-running the same conclusions on unchanged code produces no new signal.

What changed since the last full review (git diff 881d728..HEAD, filtered to this PR's own diff — the two merge commits in between only pull in unrelated origin/main history and contribute nothing of this PR's own):

  1. plugins/github/reference/change-routing.md — commits c8114e0 + 3d06b32 add the provenance citation to the untrusted-content spine sentence, resolving the P2 finding from my prior pass on this exact line (permalink).
  2. plugins/claude-ops/.claude-plugin/plugin.json / CHANGELOG.md — patch bump 0.36.00.36.1 plus a changelog entry and a stray-blank-line (MD012) cleanup (0b945fb), consistent with this batch's parity/changelog-bump discipline.

Verified independently (not just restating the author's reply): re-ran both conformance greps docs/conventions/untrusted-content/README.md's "Conformance" section specifies —

  • never instructions to you → 18 files
  • untrusted-content/README.md` "The framing contract" → 18 files

The two sets are now identical except for plugins/work-items/reference/item-content-trust.md, which is the documented second-set-only exception. change-routing.md is present in both sets. This confirms the fix is complete and the PR body's "exactly one provenance citation per adopting file" claim now holds for real, not just per the author's self-report.

No new findings. The delta since the last review is a targeted fix for the one issue already raised plus a mechanical version/lint bump — nothing else changed in the diff surface. I did not re-flag anything from the earlier passes (already resolved or already reported) and found no new correctness/maintainability issues in the new commits.

One item remains carried over as noted in my prior pass, not re-verifiable in this environment: the GNU/BSD mktemp -p/-t/TMPDIR interaction described in docs/conventions/topic-docs/README.md (now expanded further in this branch) is author-claimed and technically plausible but unverified here — this sandbox has no BSD/macOS mktemp to cross-check against.

No security-relevant surface in this diff (docs/config/changelog only) — out of scope for this lane per the prior /review:security-review pass on this PR.

@kyle-sexton

Copy link
Copy Markdown
Contributor Author

No description provided.

Main released its own ai-briefing 0.7.6, docs-hygiene 0.19.1,
markdown-format 0.11.27, powershell-format 0.7.20, and claude-config
0.39.0 under the branch; ours renumber above them (0.7.7, 0.19.2,
0.11.28, 0.7.21, 0.39.1) with main's entries preserved. The merge
resolver now collapses its double-blank artifact itself.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REtnZ2hNpvRpfaL7venur5
@claude

claude Bot commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 4s —— View job


Code review (/review:code-review)

  • Gather context (PR diff, changed files)
  • Invoke /review:code-review skill and follow its instructions
  • Post findings as inline PR comments / summary

Summary

This lane has already produced three full-diff passes on this PR (heads 881d728 and 89a230c), with the one real finding raised (missing provenance citation in plugins/github/reference/change-routing.md) confirmed fixed. Per the skill's skip gate ("this head already has a successful review from this lane that still applies"), I scoped this pass to what's actually new since the last full review at 89a230c rather than re-litigating already-reviewed ground.

What changed since 89a230c (git diff 89a230c..HEAD, filtered to this PR's own diff via git diff origin/main...HEAD):

  • c310972 — a merge of origin/main (1aff27e) that renumbers five plugin releases main published under the branch: ai-briefing 0.7.60.7.7, docs-hygiene 0.19.10.19.2, markdown-format 0.11.270.11.28, powershell-format 0.7.200.7.21, claude-config 0.39.00.39.1, with main's own changelog entries (audit-instructions I28 findings relay, trust-gate fixes, audit-noise porcelain-parse fix, etc.) preserved beneath the renumbered SSOT entry.
  • 0b945fb — the merge resolver collapsing its own double-blank-line artifact in plugins/claude-ops/CHANGELOG.md.
  • 1aff27e (#3153, landed on origin/main before this PR merged it) and everything else in the raw 89a230c..HEAD delta (.github/workflows/ci.yml, docs/PLUGIN-PHILOSOPHY.md, various scripts/*.sh, hooks) — confirmed not part of this PR's actual diff (origin/main...HEAD); it's pass-through main history that arrived via the merge and contributes nothing of this PR's own.

Verified independently:

  • For all five renumbered plugins plus the two named in the merge message but already covered (guardrails, work-items, claude-ops), confirmed plugin.json "version" matches the top CHANGELOG.md ## [...] entry exactly (ai-briefing 0.7.7, claude-config 0.39.1, docs-hygiene 0.19.2, markdown-format 0.11.28, powershell-format 0.7.21, guardrails 0.29.9, claude-ops 0.36.1, work-items 0.39.16) — no stale bump or mismatched changelog head from the renumbering.
  • Confirmed guardrails and work-items are byte-identical between 89a230c and HEAD — nothing new there to re-review.
  • Could not run scripts/check-changelog-parity.sh --check-bump --check-order directly in this environment (blocked by this session's command-approval policy); relied on the manual version/changelog-head comparison above, which is consistent with what that gate checks.

No new findings. The delta since the last full review is mechanical merge-conflict resolution (version renumbering + one blank-line collapse) with main's own already-reviewed-elsewhere commits passing through unchanged — nothing introduces new logic, doc content, or conformance drift in this PR's own diff.

No security-relevant surface in this diff (version/changelog renumbering only) — out of scope for this lane per the prior /review:security-review passes on this PR.

@claude

claude Bot commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 38s —— View job


Security review (/review:security-review)

  • Gather context (PR diff, changed files)
  • Invoke /review:security-review skill and follow its instructions
  • Post findings / summary

Skip gate hit: this head already has a successful security review that still applies.

The last successful review covered 89a230c. Head is now c310972 (merge commit "Merge origin/main: renumber five colliding plugin releases"), so I re-derived the actual reviewable scope rather than trusting the raw branch delta:

  • git merge-base origin/main HEAD = 1aff27e = origin/main itself — the branch is fully caught up, so git diff origin/main...HEAD is the true PR diff: 213 files, +1748/-549, matching the PR body's stated totals exactly.
  • That diff contains no .github/workflows/*, no scripts/, no .claude/ config, and no hook/script files — I explicitly checked (git diff origin/main...HEAD -- '.github/workflows/' 'scripts/' '.claude/' 'docs/PLUGIN-PHILOSOPHY.md' returns empty).
  • The merge commit's raw combined diff (git show c310972) does pull in real script/workflow content (ci.yml, emit-findings.sh, check-shell-portability.sh, etc.), but that's all pre-existing origin/main content the merge is reconciling against its first parent — none of it survives into the three-dot PR diff, so it was never this PR's own change.
  • The five renumbered plugin.json files (ai-briefing, claude-config, docs-hygiene, markdown-format, powershell-format) diff to nothing but a version bump plus (for two of them) the same non-ASCII-dash → em-dash text fix already characterized in prior passes.

No new security-relevant surface entered the PR since the last review — this remains a pure documentation/SSOT-conformance and version-bump change set with no injection surface, no auth/access-control code, and no secret handling.

Per the skip gate in /review:security-review ("this head already has a successful security review that still applies"): stopping here — no findings to report.

@claude

claude Bot commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 42s —— View job


Code review (/review:code-review)

  • Gather context (PR diff, changed files)
  • Invoke /review:code-review skill and follow its instructions
  • Post findings as inline PR comments / summary

Skip gate hit: this head already has a successful review from this lane that still applies.

This lane has already produced four full-diff passes on this PR (heads 881d728, 89a230c, and c310972), with the one real finding raised (missing provenance citation in plugins/github/reference/change-routing.md) confirmed fixed. Per the skill's skip gate ("this head already has a successful review from this lane that still applies"), I verified what's actually new since the last full review at c310972 rather than re-litigating already-reviewed ground.

What changed since c310972:

  • 393658c — landed on origin/main as #3183 (unrelated to this PR: three prose-scoping fixes to docs/PLUGIN-PHILOSOPHY.md and docs/MIGRATION-PLAYBOOK.md, plus a workflow comment fix), then pulled in here via merge commit 4adc997 ("Merge remote-tracking branch 'origin/main'").

Verified independently, not just asserted:

  • git diff origin/main...HEAD --name-status (this PR's actual three-dot diff) is byte-identical, file-for-file, to the diff at the time of the last full review (git diff 1aff27e...c310972, the base/head pair reviewed then) — same 213 files, same +1748/-549 totals, same file list, confirmed with a direct diff of both name-status listings (empty output).
  • docs/PLUGIN-PHILOSOPHY.md, docs/MIGRATION-PLAYBOOK.md, and .github/workflows/pr-issue-linkage.yml — the three files 393658c touches — are not in this PR's diff either before or after the merge; origin/main and HEAD are now byte-identical for docs/PLUGIN-PHILOSOPHY.md specifically (confirmed via two-dot git diff origin/main HEAD -- docs/PLUGIN-PHILOSOPHY.md, empty). This file already dropped out of this PR's own diff scope before c310972 (main independently converged to matching content, consistent with the PR body's stated practice of leaving sites main already brought into conformance untouched) — not a new effect of this merge.
  • The merge commit's own combined diff (git show 4adc997) touches exactly those same 3 files and nothing else, confirming no conflict resolution spilled into any file this PR's own diff covers.

No new findings. The only thing that changed since the last full review is a clean pass-through merge of unrelated, already-independent origin/main content that contributes zero net change to this PR's own reviewable diff. Everything previously reviewed (the setup-contract normalization clusters, the untrusted-content citation fix, the version/changelog parity bumps) stands unchanged.

No security-relevant surface in this diff (docs/config/changelog/eval-fixture only) — out of scope for this lane per the prior /review:security-review passes on this PR.
· branch claude/docs-hygiene-ssot-extract-jpb79j

@claude

claude Bot commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 17s —— View job


Security review (/review:security-review)

  • Gather context (PR diff, changed files)
  • Invoke /review:security-review skill and follow its instructions
  • Post findings / summary

Skip gate hit: this head already has a successful security review that still applies.

The last successful review covered c310972. Head is now 4adc997, so I re-derived the actual reviewable scope rather than trusting the raw branch delta:

  • git merge-base origin/main HEAD = 393658c = origin/main itself — the branch is fully caught up, so git diff origin/main...HEAD is the true PR diff: 213 files, +1748/-549, matching the PR body's stated totals exactly.
  • The raw delta since the last review (git diff c310972..HEAD, 3 files: .github/workflows/pr-issue-linkage.yml, docs/MIGRATION-PLAYBOOK.md, docs/PLUGIN-PHILOSOPHY.md) is entirely #3183 content that landed directly on origin/main and arrived here only via the merge commit 4adc997. None of those 3 files appear in origin/main...HEAD — confirmed by grepping the PR's own file list — so nothing new entered this PR's own diff since the last review.
  • Full-diff surface check on origin/main...HEAD (213 files): no .github/workflows/*, no scripts/, no .claude/, and no .sh/.py/.yml/.yaml files anywhere. File extensions are exclusively .md (155) and .json (58) — the .json files are all plugin.json version bumps plus new evals/evals.json behavioral-eval fixtures (prose prompts/expectations, no executable content), both already characterized in prior passes on this PR.

No new security-relevant surface entered the PR since the last review — this remains a pure documentation/SSOT-conformance and version-bump change set with no injection surface, no auth/access-control code, and no secret handling.

Per the skip gate in /review:security-review ("this head already has a successful security review that still applies"): stopping here — no findings to report.

@kyle-sexton
kyle-sexton enabled auto-merge (squash) August 23, 2026 15:03
@kyle-sexton
kyle-sexton merged commit f941113 into main Aug 23, 2026
50 checks passed
@kyle-sexton
kyle-sexton deleted the claude/docs-hygiene-ssot-extract-jpb79j branch August 23, 2026 15:04
kyle-sexton added a commit that referenced this pull request Aug 23, 2026
Fifth #2891 de-slop shard: purge em dashes from the claude-config plugin
instruction surfaces, the next-worst cluster after session-flow (#3106),
planning (#3105), work-items (#3107) and source-control (#3108).

Rewrote README.md and all ten SKILL.md files under /ai-slop:audit fix
semantics: periods, commas, a colon before a list, or a restructured
sentence. Never parentheses, en dashes, or a spaced hyphen, since each of
those is the same interruption wearing a different mark. Two review rounds
on the PR caught seven places where a paired em dash had become
parentheses and two doubled-connective run-ons; all were restructured.

Rebased across two releases that landed on main mid-review, in both cases
re-applying to the newer text rather than reverting it:

- 0.39.0 (#3176) restructured audit-instructions/SKILL.md, moving the
  Phase D state-key block to context/report-keying.md and adding
  --persist-findings. The flag, its Phase D paragraph, and both context/
  spokes are retained.
- 0.39.1 (#3178) normalized setup/SKILL.md and audit-instructions/SKILL.md
  to canonical fleet SSOT wording with PLUGIN-PHILOSOPHY citations. That
  wording and those citations are kept verbatim; only their punctuation is
  de-slopped.

context/ files stay out of scope, matching #2891's target set and every
prior shard.

Frontmatter description and argument-hint values are rewritten too. No
quoted auto-invocation trigger phrase contained an em dash, so no trigger
changed.

Verification (this repo's .claude/ai-slop.json disables rule-em-dash
corpus-wide, so the detector runs against an isolated HOME and
CLAUDE_PROJECT_DIR to force the rule on):

- detect.sh over the 11 shard files: 0 findings, every rule clean
- no en dash or spaced hyphen introduced; the four en dashes in the diff
  are pre-existing numeric ranges (I1-I28, I1-I5, 3-5 lanes)
- check-changelog-parity.sh --check and --check-bump origin/main: pass
- CHECK_SKILL_SKIP_MARKDOWNLINT=1 check-changed-skills.sh origin/main:
  10 skills, 0 errors, every base-ref trigger phrase preserved
- markdownlint-cli2 over the 12 changed files: 0 issues
- audit-instructions/SKILL.md is 484 lines, under the 500-line cap

Pre-existing and not from this diff: three audit-permission-state script
suites fail identically on a clean origin/main worktree in this
environment. This shard touches no script.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Tu5t8rYWv2kDzRcdmLE2ro
claude Bot pushed a commit that referenced this pull request Aug 28, 2026
…its declared recall gap (#3460)

The repo-wide docs-hygiene sweep (#3362) ran eight lanes and graduated its remainder into
docs/specs/docs-hygiene-sweep-unapplied-remediations.md. #3380 closed out L2, L4, L5, L6 and L7 and
left L3, the extract-ssot deduplication lane, untouched. An adversarial verifier re-tested that
premise cluster by cluster before anything was edited: all 13 remediated clusters were still open,
no later commit had applied them, and no open pull request covered them.

That lane also declared its own recall limit and named the fix. This carries it out: a shingled
n-gram pass over whitespace-normalized markdown with line breaks removed, plus the reading-driven
semantic pass it had no subagent tool to attempt. Against a control paragraph re-wrapped at three
widths, the old line-anchored method shares zero lines and the new pass recovers 100%.

Five of the findings are factual defects rather than prose drift:

- A fallback that could never fire, at 25 sites, and a 26th that fired and said nothing. Piping a
  probe into head before || makes the fallback unreachable, so a failed git status rendered an
  empty string under a label that reads as a clean tree. verification:confirm is the fleet's one
  uncapped site, so its fallback did run and emitted an empty string, which under that label is the
  same misreading by a different mechanism. Proven by execution.
- An inline floor whose carriers had drifted into two distinct texts. loop-lane §6 binds three lane
  bodies on the values; under that scope the values never drifted and the surrounding prose did.
  Both de-slop shards made the same substitutions, one of which left a comma splice.
- A dropped-allow-rule roster missing the Monitor class upstream added in v2.1.236, so a dropped
  Monitor grant was reported under none of the classes. Bounded to that version, since on an older
  install the verdict inverts in the less safe direction.
- A line-number citation asserting the opposite of the line it named: four surfaces cited
  check-skill.sh:414 as the hard FAIL for a dropped trigger phrase, where 414 says a trigger move
  WARNs and never blocks and the err is at 462. main fixed one of the four independently while this
  branch was in review; the other three now name the check rather than a line.
- A title taxonomy credited to a living author that the owner file records as unaudited and not his,
  including in a shipped prompt template.

docs/PLUGIN-PHILOSOPHY.md gains the runtime-grounded clause 20 setup skills were asserting with
nothing to point at, and four Convention registry rows: three owner docs that declare themselves
owners and were absent from the registry that indexes them, plus the precompute convention.

Three adversarial review rounds were run against the change set itself, and each found real defects
in its record-keeping rather than its mechanics. Six changelog entries described a change their own
diff did not make. The new detector-findings adopter row claimed a mechanical selection the producer
does not have, and its shape count was wrong at the source: audit-noise's context/persist-findings.md
and emit-findings.sh header both said six shapes and five declined, where lib/noise-shapes.sh appends
eight and detect.sh drives a ninth. Round three re-derived every remaining claim and found eight
more: "three distinct texts" was two, the spec overstated what loop-lane 6 binds, the
check-skill.sh:414 cluster was declared closed while audit-noise's own script still carried it (the
earlier sweep grepped only *.md), "every site carries one wording" was 18 of 20, the four-preambles
claim went stale when provenance landed with the merge, one entry misdescribed a file that was
internally inconsistent rather than wrong, a contradiction count read 15 where the file records 12,
and one roster row attached a quote to the wrong subject. All corrected, each re-verified against
the repository first, and each count now points at the artifact that is its source.

The full roster, the twelve contradictions the semantic pass surfaced, the four filtered-probe sites
deliberately left unnormalized and why, and the measured recall limits of the detector itself are
recorded in docs/specs/extract-ssot-sweep-2026-08-28.md so the remainder is resumable. That file
states plainly that its recall figures are unreproducible from this repository, because the
detector was a session tool and was deliberately not committed.

Refs #3362, refs #3380, refs #3178.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants