Skip to content

feat(bug-report): add scan — proactive two-stage bug-finding skill - #3208

Merged
kyle-sexton merged 17 commits into
mainfrom
claude/bug-finding-skill-f2vst1
Aug 23, 2026
Merged

kyle-sexton merged 17 commits into
mainfrom
claude/bug-finding-skill-f2vst1

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

No linked issue

Summary

Adds /bug-report:scan — the marketplace's first proactive bug-finder. Every existing correctness-finding producer is gated on a diff, an observed failure, a factual claim, a test file, or a comment marker; scan hunts unobserved defects in resting code (targeted "find a bug in <X>", or bare lane rotation for a daily routine), verifies candidates adversarially before reporting, and hands verified findings to the plugin's existing report/filing machinery. Plugin bug-report 0.7.4 → 0.8.0.

Fix

  • New skill plugins/bug-report/skills/scan/ — two-stage pipeline: recall-biased per-lens hunter subagents (5 lenses: same-unit contract-vs-body mismatch, boundary/edge-case, cross-file consistency drift, state/concurrency hazards, git-hotspot-guided) then a separate fresh-context default-refute verification gate; findings labeled reproduced vs verified-by-reading; refuted candidates retained in the report, never silently dropped. Read-only on bare invocation; per-run budget (3 verified findings / 10 candidates per wave / refill cap 2); stateless three-rung lane cursor (tracker provenance search → persisted-report cursor metadata → date-derived index). --track files verified findings as raw work-items intake (dogfood-filing beats, dual-axis needs-triage from the live label set, no label creation) behind an explicit flag only; --dry-run persists nothing.
  • New plugins/bug-report/reference/config.md — single home for the tracked .claude/bug-report.md key contract (concatenating lanes with empty-list opt-out; nearest-wins filing_posture; output_dir stays native userConfig).
  • setup extended check-only → check | apply — narrow-write shape, apply bounded to the tracked .claude/bug-report.md; existing output_dir check preserved byte-identical.
  • Convention registries — new Implementers rows in docs/conventions/config-cascade/README.md and docs/conventions/plugin-data-report-keying/README.md.
  • Metadata — plugin.json 0.8.0 (+scan/bug-hunting keywords), CHANGELOG 0.8.0 entry above ten preserved headings, README (3-skill table, scan section, two-surface Configuration), regenerated docs/SKILL-CHEAT-SHEET.md (catalog needed no delta — plugin description unchanged).

Verification

Every phase was implemented by a scope-fenced worker and independently verified by a fresh-context phase-verifier against binary acceptance criteria (Phase 1: 10/10 PASS, Phase 2: 10/10 PASS, Phase 3: 8/8 PASS). Local gate pass, all exit 0: check-changed-skills.sh origin/main (both skills CHECK-SKILL PASS — 0 errors), check-changelog-parity.sh all four modes, validate-plugins.sh (catalog + cheat-sheet in sync, 72 manifests), check-jsonschema on both evals files, markdownlint (0 issues), typos, editorconfig-checker, actionlint, gitleaks. Design was locked via a 25-question interview ledger, two adversarial audit rounds (4 fresh validators), verifier-PASSed exploration/research artifacts, and a dual fresh-context plan stress-test (21 findings folded in).

Related

  • Precedent skill-addition commits mirrored for shape: 8d1c4d5, 465178c
  • Conventions this PR implements/registers against: docs/PLUGIN-PHILOSOPHY.md (verb table, setup narrow-write), docs/conventions/config-cascade/, docs/conventions/plugin-data-report-keying/, plugins/work-items/reference/dogfood-filing.md
  • The full approved planning contract is below; the branch's docs/topics/bug-finding-skill/ slice is pruned pre-merge per the contract-slice convention, with this PR body as the durable pointer.
Approved PLAN.md (planning contract — Brief + Plan)

The complete contract lives in docs/topics/bug-finding-skill/PLAN.md on this branch's pre-prune history (commit 52f6d3e). Key content:

Brief — TLDR: new /bug-report:scan skill (proactive, general-purpose bug finding — on demand, targeted, or a daily routine's single bounded pass); read-only find → verify → report with two-stage precision; targeted scoping + lane rotation with per-run budget; filing behind an explicit argument only, always raw intake; setup writes a tracked config-cascade project file; evals + skill-quality + CI gates.

Constraints (abridged): verb-table read-only contract on bare invocation; no sibling-plugin imports (presence-gated composition); discovering agent never grades its own findings; dogfood-filing conformance with live-label-set needs-triage resolution; durable cursor never in .work/ (three-rung stateless ladder); findings report never declares type: review-findings; refuted candidates retained; refill rounds capped; cross-plugin composition by skill invocation or artifact contract only; eight skip-when fences (review:*, review:security-review, debugging:debug, codebase-health:audit, code-tidying:tidy, work-items:scan-todos, testing:audit, mutation-testing:audit).

Out of scope (explicit deferrals): in-run fixing; cross-repo scanning; formal loop-lane convention adoption; born-briefed self-filing (pending dogfood-filing owner-contract amendment); detector-findings-format persistence; a standalone bug-finding plugin.

Execution: Phase 0 base refresh (branch was 161 commits stale) → Phase 1 scan skill (commit 2132c63) → Phase 2 setup + registry rows (75015bd) → Phase 3 metadata + regen (a0f6863, d4c261e) → Phase 4 local gate pass → Phase 5 PR/prune/squash-merge. Each phase carried mechanically verifiable sanity checks and an independent fresh-context verifier PASS before its [DONE] mark.

Key tagged decisions: verification gate as inline-prompted fresh-context subagents (codebase-health precedent); filing flag --track (write owns --file); workflow-stage: operator + cadence: daily + summary (cheat-sheet generator contract); scan-filed items carry the body provenance line Filed by /bug-report:scan (lane: <name>); same-day zero-state concurrency accepted for V1 (dedupe absorbs); variant-analysis seeding deferred post-V1.

🤖 Generated with Claude Code

https://claude.ai/code/session_01JMRQbnTGgw3zxsd1fUDstX


Generated by Claude Code

claude added 14 commits August 23, 2026 18:03
Contract for the new /bug-report:scan proactive bug-finding skill:
interview + two adversarial audit rounds resolved 18 decisions
(register clean, brief cross-check ok).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JMRQbnTGgw3zxsd1fUDstX
Cursor ladder for the no-filing mode, label-taxonomy dual-axis wording,
report frontmatter fence, trigger disambiguation, and same-PR setup and
config-cascade obligations. Register: 25/25 answered, gates clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JMRQbnTGgw3zxsd1fUDstX
Five-phase plan (scan skill, setup check|apply + cascade row, metadata,
local gates, PR/prune/merge) with the four deferred execution-shape
decisions resolved and tagged. Fresh-context stress-tests in flight;
fixes will follow as amendments.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JMRQbnTGgw3zxsd1fUDstX
Folds 21 verified findings from the fresh-context plan review and
devils-advocate pass: Phase 0 base refresh (branch was 161 commits
stale; bug-report 0.7.4 on main), corrected gate invocations,
--track flag rename, operator/cadence/summary frontmatter, shared
reference/config.md contract home, cursor provenance marker and
degrade paths, and the squash-only PR gate requirements.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JMRQbnTGgw3zxsd1fUDstX
`/bug-report:scan` hunts unobserved bugs in resting code — targeted at a
path/feature/diff, or rotating a lane on a bare invocation — and verifies
every candidate through a separate fresh-context default-refute gate before
reporting. Read-only toward the target repo; filing sits behind `--track`.

- SKILL.md: verb contract, cursor ladder (tracker provenance -> persisted
  report cursor -> date-derived floor), per-run budget, two-stage pipeline,
  dogfood-filing beats, handoffs.
- context/lenses.md: five hunter lens contracts in the four-part subagent
  shape, evidence-quote and no-candidate rules, bundled generic default lanes.
- context/verification-gate.md: default-refute stance, falsification routes,
  reproduced vs verified-by-reading labels, retained-refuted output contract.
- context/findings-report.md: report shape, refuted tail, cursor metadata
  block; never declares `type: review-findings`.
- reference/config.md: the single home for the `.claude/bug-report.md` key
  contract (lanes, filing_posture, output_dir partition rule).
- evals/evals.json: six cases covering targeted, rotation, --track, read-only,
  routing, and --dry-run.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JMRQbnTGgw3zxsd1fUDstX
…nfig

The plugin now owns a writable artifact — the tracked `.claude/bug-report.md`
lane config `/bug-report:scan` reads — so the check-only carve-out no longer
describes it. Setup takes the narrow-write shape instead: `apply` bounded to
that one file, while `output_dir` stays a native `userConfig` surface handled
the check-only way through Claude Code's own configuration prompt.

- setup/SKILL.md: description and body rewritten off the userConfig-only
  carve-out; `check` keeps the existing output_dir probes intact and gains a
  per-layer report of the cascade file (presence, provenance, version-control
  verdict, inert unknown keys); `apply` drafts lanes, writes only the team
  layer conservatively, verifies by re-reading, and recommends — never writes —
  the overlay gitignore line. Keys, layers, and merge semantics are cited from
  `reference/config.md` rather than restated.
- setup/evals: three apply/check cases added alongside the existing two.
- config-cascade: `bug-report` Implementers row — all three layers, conforms,
  with merge semantics and the output_dir partition declared beside it.
- plugin-data-report-keying: `bug-report:scan` recorded as a slug-keyed writer
  of reports plus the cursor metadata it reads back.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JMRQbnTGgw3zxsd1fUDstX
The plugin gained a skill (`scan`) and a rewritten `setup` in this branch but
still declared 0.7.4 with no release note, no README coverage, and a stale
generated cheat sheet.

- `plugin.json`: 0.7.4 -> 0.8.0; keywords gain `scan` and `bug-hunting`
  (same shape the fleet uses for a skill-adding minor).
- `CHANGELOG.md`: a `## [0.8.0]` entry above the preserved 0.7.4/0.7.3/0.7.2
  headings, covering the scan skill's two-stage pipeline, its read-only verb
  contract and `--track` filing, the stateless cursor ladder and per-run
  budget, `reference/config.md` as the key contract's single home, setup's
  move from check-only to `check | apply`, and the two convention-registry
  rows.
- `README.md`: a three-row skills table, a scan section with its flag table
  and the two properties a reader needs before relying on it, and a
  Configuration section rewritten around two surfaces — the personal
  `output_dir` userConfig and the tracked `.claude/bug-report.md` — replacing
  the now-false userConfig-only and check-only claims.
- `docs/SKILL-CHEAT-SHEET.md`: regenerated (scan's operator-cadence row).
  The catalog regenerated to no change; plugin descriptions are unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JMRQbnTGgw3zxsd1fUDstX
… own

`## Usage` read as the plugin's usage while it documents `/bug-report:write`'s
flags alone; the scan section beside it made that ambiguous.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JMRQbnTGgw3zxsd1fUDstX
Close-out per the contract-slice convention: the approved contract is
published in PR #3208's description, which is the durable pointer.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JMRQbnTGgw3zxsd1fUDstX
@claude

claude Bot commented Aug 23, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 47s —— View job


Security review

  • Gather context (PR diff, repo instructions)
  • Attempt /review:security-review skill invocation
  • Manual security-focused review (skill invocation was unavailable in this environment)
  • Post findings

Note on the requested procedure: the custom instructions asked me to invoke /review:security-review and follow it exactly. Both that plugin skill and the built-in generic security-review skill failed to execute in this sandboxed CI environment (the latter errored resolving origin/HEAD, which isn't set on this shallow checkout). I proceeded with the equivalent manual review — logic/trust-boundary findings over the diff at origin/main...HEAD — rather than substituting a different review type.

Scope of this PR

This PR is documentation/skill-definition only: it adds plugins/bug-report/skills/scan/ (SKILL.md + context/*.md prompt contracts + evals/evals.json), a new reference/config.md, and extends skills/setup/SKILL.md. No application code, no executable scripts, and no .github/workflows/* files are touched — confirmed via git diff origin/main...HEAD --stat -- '*.yml' '*.yaml' '.github/*' (empty). That significantly narrows the attack surface a security review would normally cover.

Findings

No security vulnerabilities identified. Specifically checked:

  • Read-only contract on bare invocation (scan/SKILL.md) — the verb contract is explicit that bare invocation never edits, branches, pushes, or files; only plugin-owned state under ${CLAUDE_PLUGIN_DATA} is written, and --dry-run persists nothing. The eval suite (evals/evals.json, id 4 "bare-invocation-stays-read-only") directly tests resistance to a prompt-injection-style request ("...go ahead and file anything you find, plus fix the easy ones") — good defensive test coverage for exactly the kind of instruction-following risk a repo-reading agent skill faces.
  • Filing gated behind an explicit flag — --track is required for any tracker mutation, model auto-invocation is explicitly forbidden from supplying it (scan/SKILL.md L43–44), filing routes only through /work-items:track add rather than the skill pathing into another plugin's files directly, and no new labels are ever created (resolved from the live label set only). This avoids privilege/scope creep into a plugin this one doesn't own.
  • setup apply narrow-write shape (setup/SKILL.md) — bounded to the single tracked file .claude/bug-report.md; explicitly forbidden from touching settings.json, settings.local.json, managed settings, pluginConfigs, userConfig, or the consumer's .gitignore. Verifies via git check-ignore that the written file is actually tracked (not silently gitignored, which would defeat the "team layer" intent).
  • Pre-computed shell context in scan/SKILL.md's frontmatter (shell: bash, backtick-executed git branch, git log, git rev-parse, ls) — all fixed, non-parameterized commands, not built from $ARGUMENTS or other untrusted input, so no injection vector. This shell: bash pattern is pre-existing convention across 83 other SKILL.md files in the marketplace, not something new to audit here.
  • No secrets, credentials, or hardcoded sensitive values introduced in any of the added/modified markdown or JSON files.

One point worth naming (design note, not a vulnerability in this PR): like any agent skill that reads arbitrary repository content for a fresh-context subagent to reason over, hunter/verification prompts inherently process untrusted repo text (comments, strings, docstrings). The design already mitigates the main risk by keeping hunters strictly read-only and separating the recall stage from a default-refute verification stage — there's no path from "content in a file" to a write/file action without the explicit --track flag a human supplied. No action needed; flagging for awareness only.

@github-actions

github-actions Bot commented Aug 23, 2026 •

Copy link
Copy Markdown
Contributor

Last security-reviewed head: a6732f4fe455d2ca662ae2a62951afcdfc2ffc82. On the next push, the relevance gate compares only the commits since this SHA; delete this comment to force a full re-review.

@claude

claude Bot commented Aug 23, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 45s —— View job


Claude finished the security review

  • Gather context (PR diff, files changed)
  • Invoke /review:security-review per custom instructions
  • Post findings

Skip gate check: PR is open, so I reviewed the diff for security-relevant surface.

Files reviewed (git diff origin/main...HEAD, 14 files, all matching the PR description): the new scan skill (SKILL.md + context/lenses.md, verification-gate.md, findings-report.md, evals/evals.json), the extended setup skill (SKILL.md, evals/evals.json), the new reference/config.md, plus plugin.json, CHANGELOG.md, README.md, and the two convention-registry docs.

Result: no security issues found

This PR adds Markdown skill/prompt definitions and documentation — no application code, no .github/workflows changes, no dependency or permission changes. I specifically checked the areas most likely to carry a real trust-boundary or injection surface:

  • Shell interpolation in skill frontmatter. scan/SKILL.md and write/SKILL.md use ! pre-computed-context shell commands (e.g. git branch --show-current, ls "${CLAUDE_PROJECT_DIR:-.}/.claude/bug-report.md"). None of these interpolate $ARGUMENTS or other user-controlled text — only fixed commands and the harness-provided CLAUDE_PROJECT_DIR env var — so there's no command-injection path here.
  • Config-cascade file handling (reference/config.md, setup/SKILL.md). apply is documented as bounded to the single tracked .claude/bug-report.md file, with explicit "never touch settings.json/pluginConfigs/.gitignore" boundaries, and instructs reading before writing. This is a prompt-level (not code-enforced) contract, consistent with how the rest of the marketplace's setup skills work.
  • Filing path (--track). scan/SKILL.md Step 5 routes filing exclusively through /work-items:track add (never "pathing into another plugin's files"), gated on an explicit flag, with dedupe-before-file and no ability to create new labels — no raw shell/API construction that could be injection-prone.
  • Hunter/verification subagent prompts (lenses.md, verification-gate.md, findings-report.md) are read-only-by-contract natural-language dispatch instructions; no code execution, no secret handling.
  • Metadata-only changes (plugin.json version bump/keywords, CHANGELOG.md, README.md, cheat-sheet, and the two convention-registry rows) carry no security surface.

No CRITICAL/IMPORTANT/SUGGESTION findings to report.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 52f6d3e5a8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/bug-report/skills/scan/SKILL.md Outdated
Comment thread plugins/bug-report/skills/scan/SKILL.md
Comment thread plugins/bug-report/skills/scan/SKILL.md Outdated
Comment thread plugins/bug-report/skills/setup/SKILL.md Outdated
…up tracking probe — review findings

Four verified reviewer findings against the scan and setup skill contracts:

1. (P1) scan Step 5 gated filing only on work-items presence plus a tracker
   binding, so `--track` would file even under the default `manual-only`
   filing_posture the config reference declares. Step 5 now opens with a
   posture gate resolved from the cascade (bundled default `manual-only`),
   printing one "filing skipped" notice and stopping at the report — the same
   degrade shape as an absent work-items. The `--track` mode row notes the
   posture dependency.

2. (P2) scan cursor ladder rung 2 read the newest report blindly, but
   /bug-report:write's reports share that directory and carry no cursor block,
   and a targeted scan must never advance rotation. Rung 2 now searches
   backward for the newest report carrying a valid rotation cursor block and
   falls through to rung 3 when none does.

3. (2b) rung 2 also hardcoded ${CLAUDE_PLUGIN_DATA}/bug-reports/<project-slug>/,
   stranding the cursor whenever output_dir is configured. It now resolves the
   directory by the same precedence persistence uses (write's Step 4).

   context/findings-report.md is made consistent: the cursor block belongs to
   rotation-mode reports (bare or --lane); a targeted run omits it and prints a
   one-line non-advancing marker instead.

4. (P2) setup `check` step 3 used `git check-ignore` alone — an ignore probe
   that returns the same empty output for a present-but-untracked file as for a
   healthy tracked one, so check could bless a config teammates never receive.
   It now pairs check-ignore with `git ls-files --error-unmatch` (non-zero exit
   on a present file = FAIL). `apply`'s post-write verification mirrors the
   pairing but does not FAIL a freshly scaffolded file: it states the
   stage/commit obligation instead.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JMRQbnTGgw3zxsd1fUDstX
@claude

claude Bot commented Aug 23, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 12s —— View job


Claude finished the security review

  • Gather context (PR diff, files changed)
  • Invoke /review:security-review per custom instructions
  • Post findings

Skill invocation note: /review:security-review failed to execute in this sandboxed CI environment (same limitation noted on the two prior review passes for this PR). I proceeded with an equivalent manual security-focused review of git diff origin/main..HEAD scoped to the 14 files this PR actually changes (plugins/bug-report/**, docs/SKILL-CHEAT-SHEET.md, the two convention README.md rows) — the local origin/main ref carries unrelated drift in other plugins that isn't part of this PR.

Result: no security issues found

This PR remains Markdown skill/prompt/doc content only — no application code, no .github/workflows changes. I re-read every file in the diff, including the two files most relevant to trust boundaries:

  • scan/SKILL.md — bare invocation is read-only by contract (L40–53); --dry-run persists nothing; --track is the only path to tracker mutation and model auto-invocation is explicitly forbidden from supplying it (L43–44).
  • context/verification-gate.md — explicit boundary: "never run anything that mutates the repository or any external system" (L72–73) and "Read-only. No edits, no writes, no branches, no filing, no network mutation." (L102).
  • Filing path (Step 5, scan/SKILL.md L169–198) — now gates on filing_posture before dedupe/filing (the fix in e63c9cb for the prior review's P1: manual-only blocks all filing, allowed is required to reach track add), routes exclusively through /work-items:track add (never direct file access into another plugin's data), and creates no new labels.
  • setup/SKILL.md — apply stays bounded to .claude/bug-report.md; explicit "never touch settings.json/pluginConfigs/.gitignore" boundary; the tracking verdict now correctly pairs git check-ignore with git ls-files --error-unmatch (L78–83), closing the prior review's gap where a present-but-untracked file was indistinguishable from a healthy one.
  • Pre-computed shell context in scan/SKILL.md frontmatter — fixed, non-parameterized git/ls commands, no $ARGUMENTS interpolation, no injection vector.
  • reference/config.md — the new cascade file is read-only prose/schema documentation; no secret-bearing keys, no execution semantics.
  • No secrets, credentials, or hardcoded sensitive values in any added/modified file.

On the Codex review comments: all three P1/P2 findings from the earlier automated pass (filing-posture enforcement, cursor rung-2 output_dir precedence, cursor rung-3 "newest report" vs. "newest valid rotation cursor", and the setup tracking probe) are design/correctness issues, not security vulnerabilities — and per the commit e63c9cb message ("enforce filing_posture, harden cursor rung 2 and setup tracking probe — review findings") and my read of the current diff, they all appear already addressed on this branch.

No CRITICAL/IMPORTANT/SUGGESTION security findings to report.
· branch

@kyle-sexton

Copy link
Copy Markdown
Contributor Author

Codex review dispositions — all four findings verified against the shipped text, confirmed real, and fixed in e63c9cb:

  • P1 filing_posture unenforced: Step 5 now opens with a posture gate ahead of the work-items presence gate — manual-only (the bundled default) files nothing and prints why; only allowed reaches the filing beats. The --track flag description notes the posture subjection.
  • P2 rung-2 newest-report blindness: rung 2 now searches backward for the newest report carrying a valid rotation cursor block; write's reports and targeted-scan reports (which now explicitly omit the block per context/findings-report.md) are skipped, falling through to the date floor when none exists.
  • P2 output_dir divergence: cursor lookup now resolves the report directory by the same precedence persistence uses (write's Step 4, output_dir first), so the cursor reads where reports actually land.
  • P2 tracking probe: setup check B3 pairs git check-ignore with git ls-files --error-unmatch — present-but-untracked is now FAIL ("commit it so teammates receive it"); apply's post-write verification acknowledges a fresh scaffold is untracked-until-committed without failing it.

Both skills re-pass check-skill --require-evals (0 errors) and markdownlint after the fix.


Generated by Claude Code

@claude

claude Bot commented Aug 23, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 19s —— View job


Claude finished the security review

  • Gather context (PR diff, files changed)
  • Invoke /review:security-review per custom instructions
  • Post findings

Skip gate check: PR is open. The head SHA (5bbc94e) is one merge-commit ahead of the prior automated reviews on this PR and includes the fix commit e63c9cb (which resolved the four Codex findings below), so I re-reviewed the full diff rather than relying on the earlier passes.

Diff reviewed: git diff from the merge-base with origin/main to HEAD (shallow-clone note: origin/main...HEAD triple-dot failed with "no merge base" because this checkout is shallow and origin/main's tip is itself a shallow boundary; I resolved the true merge-base commit — e43c6e6, already in this branch's history — and diffed against that, confirming an exact match to the PR's stated 14 files / +1081/-25). All 14 files: the new scan skill (SKILL.md + context/lenses.md, verification-gate.md, findings-report.md, evals/evals.json), the extended setup skill (SKILL.md, evals/evals.json), the new reference/config.md, plugin.json, CHANGELOG.md, README.md, and the two convention-registry docs. No .github/workflows/*, .yml, or .yaml files are touched.

Result: no security issues found

This remains a documentation/skill-definition-only change — no application code, no CI/workflow changes, no dependency or permission changes. I specifically re-checked:

  • Read-only contract on bare invocation (scan/SKILL.md#L34-L40) — bare invocation never edits, branches, pushes, or files; only plugin-owned ${CLAUDE_PLUGIN_DATA} state is written, and --dry-run persists nothing.
  • Filing posture is now enforced before any tracker mutation (scan/SKILL.md#L207-L212) — this closes the P1 Codex finding from the earlier review round: Step 5 now gates on the resolved filing_posture before the work-items presence check, and manual-only (the bundled default) files nothing.
  • Cursor-rung fixes verified in the diff: rung 2 now resolves the report directory via the same output_dir precedence write uses, and searches backward for the newest report carrying a valid rotation-cursor block, explicitly skipping write's and targeted-scan reports (which now omit the block per context/findings-report.md#L120-L131) — closes both P2 cursor findings.
  • Tracking probe hardened (setup/SKILL.md#L79-L84) — check now pairs git check-ignore with git ls-files --error-unmatch, so a present-but-untracked team config correctly FAILs instead of being blessed as healthy — closes the last P2 finding.
  • No shell injection surface — the only ! pre-computed-context commands in scan/SKILL.md's frontmatter (git branch --show-current, git log, git rev-parse --is-shallow-repository, ls .../.claude/bug-report.md) are fixed and non-parameterized; none interpolate $ARGUMENTS or other untrusted input.
  • Reproduction checks in the verification gate stay bounded (context/verification-gate.md#L60-L64) — explicitly instructed to "never run anything that mutates the repository or any external system" when attempting a cheap reproduction.
  • Filing still routes only through /work-items:track add, gated on --track, with no label creation and no direct pathing into another plugin's files.
  • No secrets, credentials, or hardcoded sensitive values in any added/modified file.

All four prior Codex findings (P1 filing-posture bypass, P2 output_dir cursor divergence, P2 blind newest-report cursor selection, P2 weak tracking probe) are confirmed fixed in the current diff — none were security-severity to begin with (worst case was a config-cascade policy skip or a stale rotation index, not a trust-boundary breach), but they're resolved regardless.

No CRITICAL/IMPORTANT/SUGGESTION security findings to report.
· Branch: claude/bug-finding-skill-f2vst1

…w fixes

Seven leftover sentences still described the pre-fix behavior:

- findings-report.md: the all-refuted and zero-findings forms now name the
  cursor block as the rotation-run form, with the targeted run's no-cursor
  line called out beside each.
- scan/SKILL.md: Step 4's report shape, the pipeline's filing aside, and the
  frontmatter description now carry the mode and filing_posture qualifiers.
- scan/evals: the --track case declares filing_posture: allowed in its prompt
  so its filing expectations are reachable against the bundled manual-only
  default, and gained a posture-gate expectation; rung 2's wording now matches
  the backward search for a valid rotation cursor block.
- CHANGELOG 0.8.0: rung 2 described as the newest report carrying a valid
  rotation cursor block, resolved through persistence's directory precedence.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JMRQbnTGgw3zxsd1fUDstX
@claude

claude Bot commented Aug 23, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 56s —— View job


Claude finished the security review

  • Gather context (PR diff, files changed)
  • Invoke /review:security-review per custom instructions
  • Post findings

Skill invocation note: /review:security-review failed to execute in this sandboxed CI environment (consistent with the prior review passes on this PR). I proceeded with an equivalent manual security-focused review.

Diff reviewed: Full PR diff (e43c6e6 → a6732f4, 14 files, +1089/-25, matching the PR description) plus the incremental delta since the last-reviewed head (5bbc94e → a6732f4, HEAD SHA a6732f4fe455d2ca662ae2a62951afcdfc2ffc82).

Result: no security issues found

The new commit (a6732f4) is wording-only — it touches CHANGELOG.md, scan/SKILL.md, scan/context/findings-report.md, and scan/evals/evals.json to align documentation/eval prose with the fixes already made in e63c9cb (cursor rung-2 directory precedence, cursor rung-3 valid-cursor-block selection, targeted-run no-cursor line). No shell commands, filing logic, or trust-boundary code changed. Re-confirmed:

  • Frontmatter shell context unchanged — scan/SKILL.md#L6 still only pre-computes fixed, non-parameterized git/ls commands — no $ARGUMENTS interpolation, no injection vector.
  • Filing posture gate — the description and Step language now explicitly note --track is "subject to the team's filing_posture" (scan/SKILL.md#L1), consistent with the P1 fix from the earlier Codex review round (manual-only default blocks all filing; allowed required to reach track add).
  • Filing still routes only through /work-items:track add, gated behind the explicit --track flag, with no label creation and no direct pathing into another plugin's files.
  • No secrets, credentials, or hardcoded sensitive values in any added/modified file.
  • No .github/workflows/*, .yml, or .yaml files touched — confirmed via the file list above.

This PR remains documentation/skill-definition content only (Markdown prompt contracts + JSON eval fixtures) — no application code, no CI/workflow changes, no dependency changes. All four prior Codex findings (P1 filing-posture bypass, two P2 cursor-selection issues, P2 weak tracking probe) were security-adjacent design/correctness issues, not vulnerabilities, and remain fixed as of this head per the diff.

No CRITICAL/IMPORTANT/SUGGESTION security findings to report.
· branch

@kyle-sexton
kyle-sexton merged commit 585f293 into main Aug 23, 2026
42 checks passed
@kyle-sexton
kyle-sexton deleted the claude/bug-finding-skill-f2vst1 branch August 23, 2026 19:43
@claude

claude Bot commented Aug 23, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 41s —— View job


Code review — skipped (PR merged)

  • Gather context (PR diff, repo instructions)
  • Invoke /review:code-review skill
  • Apply skip gate
  • Post summary comment

/review:code-review's skip gate stops early and posts nothing further when "PR is closed or not open" (plugins/review/skills/code-review/SKILL.md#L37). PR #3208 is MERGED (squash-merged to main as 585f293), so per that gate this lane produces no findings and no inline comments — deferring to the review passes already completed while the PR was open (three security-review passes above, plus the Codex P1/P2 findings that were verified and fixed in e63c9cb1).

No further action taken.
· Branch: claude/pr-3208-20260823-1945

@github-actions

Copy link
Copy Markdown
Contributor

Claude has reviewed this PR 1 time. The lane skips further automatic reviews after 5; deleting this comment resets the count.

kyle-sexton added a commit that referenced this pull request Aug 23, 2026
No linked issue

## Summary

Renames the `bug-report` plugin to `bugs` — with `scan` (landed in
#3208) beside `write`, the plugin's identity is the front half of the
bug lifecycle (*find them, report them*), and the old name described
only the second half. Follow-up to #3208 by owner request: hard rename,
no aliasing/retirement machinery, breaking changes accepted. Plugin
0.8.0 → 0.9.0.

## Fix

- **`plugins/bug-report/` → `plugins/bugs/`** (15 tracked renames);
skills are now `/bugs:scan`, `/bugs:write`, `/bugs:setup`; marketplace
entry, `.claude/settings.json` enablement, and the skill-leaf-name
registry updated.
- **Tracked team config surface renames with the plugin**:
`.claude/bug-report.md` → `.claude/bugs.md` (same keys, cascade, and
merge semantics per `reference/config.md`); convention registries
(config-cascade, plugin-data-report-keying) updated.
- **Cross-fleet live references swept**: `claude-ops:known-issues`
(0.37.1) and `work-items:track` (0.39.19) with their own changelog
entries per the published-version-reuse gate.
- **Deliberately unchanged**: the persisted report frontmatter `type:
bug-report` (storage-format identifiers stay stable across renames — ADR
0013), the `bug-reports/` plugin-data subdir literal, the `'bug-report
this'` trigger phrase, and historical changelog/upstream/topic-slice
records, which retain the old name as immutable history. The old-name
marketplace tag is kept as a search alias.

## Verification

Fresh-context verifier audited the rename against 8 criteria:
file-census parity (15/15 carried), manifest/marketplace/settings state,
byte-identical changelog history under the new 0.9.0 entry, a classified
residual-reference sweep (only deliberate keeps remain), cross-fleet
surface updates with the keying-convention citation still resolving, and
gates. Its one FAIL (unversioned cross-plugin edits) and one scope flag
(`type:` identifier drift) are fixed in d67519b. Local gates all exit
0: `validate-plugins.sh`, all four `check-changelog-parity.sh` modes,
`check-changed-skills.sh origin/main` (5 skills PASS), catalog +
cheat-sheet `--check`, markdownlint, typos, editorconfig-checker.

## Related

- Refs #3208 (the scan skill this rename reframes the plugin around)
- ADR 0013 (storage-format identifiers stable across renames) — followed
here
- Conventions: `docs/conventions/config-cascade/`,
`docs/conventions/plugin-data-report-keying/`

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01JMRQbnTGgw3zxsd1fUDstX

---
_Generated by [Claude
Code](https://claude.ai/code/session_01JMRQbnTGgw3zxsd1fUDstX)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants