Skip to content

perf(claude-config): precompute setup dependency probes - #4566

Merged
cursor[bot] merged 31 commits into
mainfrom
chore/3544-precompute-sweep-inject-unconditional-de
Sep 27, 2026
Merged

cursor[bot] merged 31 commits into
mainfrom
chore/3544-precompute-sweep-inject-unconditional-de

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

No related issue: first batch of the #3544 precompute sweep; the issue stays open for the remaining plugin batches.

Summary

claude-config:setup ran four unconditional, read-only command -v probes (jq, curl, awk, sort) as separate Bash calls on every invocation. They now run as pre-computed context at skill load, so check reads four rows instead of making four Bash calls.

Fix

  • plugins/claude-config/skills/setup/SKILL.md: add shell: bash; add a ## Pre-computed context section with one { command -v <tool> 2>/dev/null || echo "absent"; } row per tool (no $, no git). Check steps 1-3 read those rows; their FAIL rules are unchanged. A row showing [shell command execution disabled by policy] falls back to the Bash probe. apply's post-install verification still re-probes live, since the rows predate the install.
  • Version 0.48.2 to 0.48.3 with a matching CHANGELOG entry.

Known limit: on a native-Windows host with no bash, the injection cannot run and the skill fails to load, so check item 4 ("FAIL only if no bash is resolvable") cannot report there. context-guard:setup, the in-corpus precedent, has the same exposure.

Verification

  • scripts/check-skill-precompute-compose.sh --strict --paths plugins/claude-config/skills/setup/SKILL.md: 1 scanned, 0 violations (run by the worker and again by the orchestrator).
  • scripts/check-changed-skills.sh origin/main: CHECK-SKILL setup: PASS.
  • scripts/check-skill-portability.sh, markdownlint-cli2, and scripts/check-changelog-parity.sh (all four modes): clean.
  • Fresh-context phase verifier: 7/7 acceptance criteria PASS.

Related

🤖 Generated with Claude Code

https://claude.ai/code/session_01GbjVB83kN5jYHnZpcztrBG

Move the jq, curl, awk, and sort command -v probes into load-time
pre-computed context so check reads them instead of spending four Bash
calls. FAIL semantics are unchanged; a policy-disabled injection falls
back to the Bash probe.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbjVB83kN5jYHnZpcztrBG
cursoragent and others added 28 commits September 27, 2026 20:10
…-sweep-inject-unconditional-de

# Conflicts:
#	plugins/claude-config/.claude-plugin/plugin.json
#	plugins/claude-config/CHANGELOG.md

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The detector's --show-config runs as load-time pre-computed context; apply's
post-write re-run still calls the detector live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…probes

lanes renders claude --version and command -v jq on one line; observability
renders the --hook-events and --pipeline --observed probe-observability-state.sh
calls on one line. Each probe keeps its own fallback; git stays in body calls.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
check's read of .claude/topic-docs.yaml runs as load-time pre-computed context
via a relative path (no $ expansion). A non-root working directory or a
policy-disabled injection falls back to reading the file directly.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
… fence

video-digest and course-digest each run their four dependency probes from one
fenced pre-compute block. Labels are unchanged; each node -e probe gains the
fallback it lacked, so a host without node renders a MISSING row instead of
failing the skill load.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
check's read of .claude/topic-docs.yaml runs as load-time pre-computed context
via a relative path (no $ expansion). A non-root working directory or a
policy-disabled injection falls back to reading the file directly.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move setup's unconditional, read-only dependency probes into load-time
pre-computed context so check reads them instead of spending Bash calls. FAIL
semantics are unchanged; a policy-disabled injection falls back to the Bash
probe, and post-remediation re-checks still probe live.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
check's read of .claude/topic-docs.yaml runs as load-time pre-computed context
via a relative path (no $ expansion). A non-root working directory or a
policy-disabled injection falls back to reading the file directly.

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
… lines

The hook-events and pipeline probes now share one line, so the guard counts
two probe-invoking lines and recognizes each chained fallback that ends in
"unknown", not only a bare "unknown".

Refs #3544

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…-sweep-inject-unconditional-de

# Conflicts:
#	plugins/actionlint/CHANGELOG.md
#	plugins/ai-briefing/CHANGELOG.md
#	plugins/bash-format/CHANGELOG.md
#	plugins/biome-format/CHANGELOG.md
#	plugins/context-budget/CHANGELOG.md
#	plugins/desktop-notification/CHANGELOG.md
#	plugins/eol-normalizer/CHANGELOG.md
#	plugins/go-format/CHANGELOG.md
#	plugins/knowledge/CHANGELOG.md
#	plugins/markdown-format/CHANGELOG.md
#	plugins/planning/.claude-plugin/plugin.json
#	plugins/planning/CHANGELOG.md
#	plugins/powershell-format/CHANGELOG.md
#	plugins/rate-limit-guard/CHANGELOG.md
#	plugins/repo-hygiene/CHANGELOG.md
#	plugins/ruff-format/CHANGELOG.md
#	plugins/typos-format/CHANGELOG.md

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…-sweep-inject-unconditional-de

# Conflicts:
#	plugins/discovery/CHANGELOG.md

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…-sweep-inject-unconditional-de

# Conflicts:
#	plugins/guardrails/CHANGELOG.md
cursoragent and others added 2 commits September 27, 2026 20:42
…-sweep-inject-unconditional-de

# Conflicts:
#	plugins/claude-ops/CHANGELOG.md
#	plugins/markdown-format/CHANGELOG.md
#	plugins/planning/.claude-plugin/plugin.json
#	plugins/planning/CHANGELOG.md
#	plugins/typos-format/CHANGELOG.md
Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@cursor
cursor Bot marked this pull request as ready for review September 27, 2026 20:44
@cursor
cursor Bot enabled auto-merge (squash) September 27, 2026 20:44
@cursor
cursor Bot merged commit 946caf1 into main Sep 27, 2026
18 checks passed
@cursor
cursor Bot deleted the chore/3544-precompute-sweep-inject-unconditional-de branch September 27, 2026 20:49
@cursor
cursor Bot restored the chore/3544-precompute-sweep-inject-unconditional-de branch September 27, 2026 20:53
@cursor
cursor Bot deleted the chore/3544-precompute-sweep-inject-unconditional-de branch September 27, 2026 20:54
cursor Bot pushed a commit that referenced this pull request Sep 27, 2026
…rable (#4286) (#4637)

<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
Fixes #4286

## Summary

`planning:interview` Step 4 named `docs/topics/<slug>/` as the contract
destination but never said the slice is pruned before merge.

- Step 4 gains "Neither slice is a durable home": contract slice pruned
before merge; memory slice never reaches git; lasting content goes to
ADR/spec/tracker.
- `topic-docs.md` contract rows say "pruned before merge".
- New interview eval 24; defenses digests re-pinned (153/153).

`planning` 0.44.1 → 0.44.2 (serialized above #4566).

## Research trail

- `docs/conventions/topic-docs/README.md` Contract-slice lifecycle
(prune with pointer).
- `scripts/check-contract-slice-prune.sh`.

## Test plan

- [x] `interview-defenses.test.sh` PASS=153; `standards-binding.test.sh`
PASS=9
- [x] changelog parity; contract-slice-prune check; markdownlint

## Notes

Open PRs #4628 and #4622 also bump `planning` (version-line only).
<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a
href="https://cursor.com/agents/bc-ab53da24-b89d-4314-a060-0da474e837e9?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-ab53da24-b89d-4314-a060-0da474e837e9&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
kyle-sexton added a commit that referenced this pull request Sep 29, 2026
…t Bash diagnosis reachable

The setup skill restated the policy-disabled placeholder with no basis. It now carries a
four-part record against the skills docs. Step 1 only reports a Bash version because a
`shell: bash` skill fails to load on Windows without Git Bash; the skill and the README
Requirements now say so and point to Git for Windows. Notice wording in check steps 2 and 3
matches the hook's latch scopes, and a new eval covers the Windows case.

Refs #4566

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
kyle-sexton added a commit that referenced this pull request Sep 29, 2026
…t:check

The setup skill's pre-computed jq row only runs when setup itself loads, so
under check it is literal command text. The check skill now runs the probe
itself, setup tells a reader to do the same when the row carries no result,
and a new eval requires a jq FAIL row when jq is absent.

Refs #5096, #4566

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
kyle-sexton added a commit that referenced this pull request Sep 29, 2026
…after binary probe, setup and doc corrections (#5271)

Refs: #4240
Refs: #4264
Refs: #4566
Refs: #4671
Refs: #5286
Refs: #4677

## Summary

Repairs the seven typos-format findings from the Cursor-agent PR audit.
The missing-`typos` notice now uses the session-only `prerequisite`
class, the gitignore check runs after binary resolution, the setup skill
records its basis and keeps the Git Bash diagnosis reachable, and the
README and CHANGELOG drop claims the plugin does not back. The plugin
goes from 0.7.5 to 0.7.6.

## Fix

- `hooks/typos-format.sh`: the missing-`typos` notice passes
`prerequisite` to `hook::notice_once` (one latch per session, shared by
all agents, renewed every eighth skip with the install route kept). The
notice text, the README Requirements and the setup skill state that
scope. The missing-`jq` notice keeps its per-session-and-agent latch.
- `hooks/typos-format.sh`: the `git check-ignore` gate runs after the
binary is resolved (#4671). It is a reorder only; the
`typos_format_lint_gitignored` default is unchanged.
- `skills/setup/SKILL.md`: dated four-part basis for the policy-disabled
row and step 1's limit; the Git Bash diagnosis stays reachable when the
precompute cannot run (#4566). New eval for the Windows case.
- `README.md`: removed the unreproducible 2026-09-27 Linux spawn table
and the stale nine-plugin count (#4264).
- `CHANGELOG.md`: the 0.7.5 entry claimed a session-start probe and
`prerequisites.json` this plugin does not ship. It now states what
shipped and why there is no probe (the hook fires on every Write, Edit
and NotebookEdit, so the missing-binary branch is reached on the first
edit). This is a declared correction of a released entry. Also restored
the `### Changed` headings on 0.6.65 and 0.6.64.
- `README.md` and `skills/setup/SKILL.md` (cross-group request from
hook-launcher, F28): Node.js is declared in README Requirements and as a
setup `check` row (FAIL even with the toggle off, since the launcher is
node). The hook cost section now says a disabled hook costs a `node`
process and an enabled edit costs `node` plus bash. The pre-0.7.1
disabled-row figures are dropped, a 2026-09-29 Linux wall-time table in
its own table (37 to 45 ms disabled, 84 to 120 ms enabled, 58 to 73 ms
script alone; three hyperfine repeats, n=30 each, on a host at load
average near 30) is added, and the 0.6.35 and 0.6.55 figures and the
0.6.48 census are marked as predating the launcher and the current
`hook-utils.sh`.
- `CHANGELOG.md` (cross-group request from biome-format): the 0.7.6
correction of the 0.7.5 entry links #5286 for the remaining
binary-probing plugins. No `probe-prerequisite.sh` or
`prerequisites.json` is added; that waits on the owner's answer to #4240
Q1.
- `hooks/exec-bash.mjs`, `hook-utils.sh` and `rewrite-guard.sh` are
untouched.

## Verification

- `bash plugins/typos-format/hooks/typos-format.test.sh`: PASS=197
FAIL=0 (new cases: second agent in the same session stays silent; the
eighth-skip renewal keeps the install URL; gitignore gate ordering).
- `scripts/check-changelog-parity.sh --check --check-order`: exit 0.
- `scripts/validate-plugins.sh`: all manifests and the catalog
validated.
- origin/main merged into the branch with no conflicts.
- Linux wall-time table: the first 2026-09-29 run (62.7 ms enabled, 23.8
ms disabled, 34.6 ms script alone) had no kept output and did not
reproduce, so the README now carries ranges from three fresh runs of the
recipe (enabled 84, 120, 109 ms; script alone 58, 58, 73 ms; disabled
37, 39, 45 ms; floor 1 to 2 ms). The host was at load average near 30,
so the spread is about 40%. The launcher's added cost is roughly 35 to
45 ms in every run.

## Related

- Audit: `.work/audit/REPORT.md` findings for #4240, #4264, #4566, #4671
and #4677 (the #4677 synchronous-row decision is ratified as recorded in
the README; no change, no issue operation).
- Not renumbered: the historical 0.6.68 gap.
- Cross-group request to scripts (optional, low priority): a warn-only
`check-changelog-parity.sh` rule for skipped patch versions and for
version entries with no `###` heading, with an allowlist for existing
history such as 0.6.68.
- Cross-group requests: the markdown-format request to reword the "only
this notice latches" text in `typos-format.sh` was already met by this
PR's notice rewording. The hook-launcher (F28) and biome-format requests
are applied above; #3708's launcher stays as the owner decided.
Follow-up for the probe and manifest: #5286.
- #4671's gitignore default and #4240's fleet-wide probe design are
owned elsewhere; this PR does not decide them.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants