diff --git a/plugins/ai-briefing/.claude-plugin/plugin.json b/plugins/ai-briefing/.claude-plugin/plugin.json index 53f1f0a732..838d1f1183 100644 --- a/plugins/ai-briefing/.claude-plugin/plugin.json +++ b/plugins/ai-briefing/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "ai-briefing", - "version": "0.7.42", + "version": "0.7.43", "description": "Build source-backed AI-industry briefings from official vendor publications, configured RSS/Atom feeds, GitHub releases, reputable secondary reporting, and user-supplied URLs. Deduplicate, rank, and present results as markdown or optional HTML/PPTX decks, with repository-owned profile, audience, and brand configuration. Automated X/Twitter collection is disabled; Playwright is used only for deterministic local rendering.", "author": { "name": "Melodic Software", diff --git a/plugins/ai-briefing/CHANGELOG.md b/plugins/ai-briefing/CHANGELOG.md index a97699abc2..30f6a5e667 100644 --- a/plugins/ai-briefing/CHANGELOG.md +++ b/plugins/ai-briefing/CHANGELOG.md @@ -3,6 +3,12 @@ All notable changes to the `ai-briefing` plugin are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); this plugin uses semantic versioning. +## [0.7.43] - 2026-09-27 + +### Changed + +- `generate` states three rules in normal register instead of all caps: every bullet renders all its source URLs (`slide-generation.md`), and `meta`/`theme` and the default brand tokens are not redefined per run (`build-pipeline.md`, two sites). The rules are unchanged, and `validate.js` still enforces the URL rule at gate time (#4120). + ## [0.7.42] - 2026-09-27 ### Changed diff --git a/plugins/claude-config/.claude-plugin/plugin.json b/plugins/claude-config/.claude-plugin/plugin.json index ad6cdb39d4..ebe1c702f0 100644 --- a/plugins/claude-config/.claude-plugin/plugin.json +++ b/plugins/claude-config/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "claude-config", - "version": "0.51.20", + "version": "0.51.21", "description": "Nine configuration-health skills (plus setup) for a repo's Claude Code configuration: audit (settings.json / .mcp.json / hooks / plugins / permissions drift), audit-automation-gaps (evidence-gated verdicts on automation gaps), audit-permission-grants (allow-rule / allowed-tools grants for auto-mode durability and portability), audit-permission-state (the permission rules actually in effect: every settings scope merged with per-rule provenance, what auto mode drops on entry, config written where nothing reads it, and which managed intents are enforced versus loosenable), draft-auto-mode-rules (interview and draft a paste-ready autoMode classifier block; prints only, never writes), audit-instructions (locally-owned instruction surfaces vs current model capability, proposing removals/rewrites of instructions the model no longer needs, and detecting cross-surface instruction conflicts), audit-prompting-postures (the additive lane: posture guidance the prompting guide says a component's purpose needs but the component does not carry), audit-pass (one coordinated, ordered, resumable pass over a named target: three-scope inventory, run-time-derived exclusion set, stable finding identity, suppression memory, resume, one human gate, delegating every check to the plugin that owns it), and unhobble (the empirical bare-baseline experiment: reversibly strip a repo's standing instructions, log real stumbles against the current model, re-add only what evidence earns).", "author": { "name": "Melodic Software", diff --git a/plugins/claude-config/CHANGELOG.md b/plugins/claude-config/CHANGELOG.md index 28d16726fb..a444365fcc 100644 --- a/plugins/claude-config/CHANGELOG.md +++ b/plugins/claude-config/CHANGELOG.md @@ -3,6 +3,12 @@ All notable changes to the `claude-config` plugin are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); this plugin uses semantic versioning. +## [0.51.21] - 2026-09-27 + +### Changed + +- `audit`'s env-var checklist row drops its `**MANDATORY**:` prefix. The row still requires reading `code.claude.com/docs/en/env-vars` verbatim and searching it for each env var name, and still says WebSearch alone is insufficient (#4120). + ## [0.51.20] - 2026-09-28 ### Changed diff --git a/plugins/codebase-health/.claude-plugin/plugin.json b/plugins/codebase-health/.claude-plugin/plugin.json index f89162bd03..6f96481202 100644 --- a/plugins/codebase-health/.claude-plugin/plugin.json +++ b/plugins/codebase-health/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "codebase-health", - "version": "0.10.2", + "version": "0.10.3", "description": "Repo-wide drift audit between docs, config, code, and architecture: verifies every factual claim against reality via parallel subagent fan-out, severity-rates findings, and reports read-only, delegating remediation to the implementation/verification lanes. Audit dimensions are configurable through a tracked .claude/codebase-health.md config file written by the setup skill.", "author": { "name": "Melodic Software", diff --git a/plugins/codebase-health/CHANGELOG.md b/plugins/codebase-health/CHANGELOG.md index 9ca44f9dcc..6b7818ef01 100644 --- a/plugins/codebase-health/CHANGELOG.md +++ b/plugins/codebase-health/CHANGELOG.md @@ -3,6 +3,12 @@ All notable changes to the `codebase-health` plugin are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); this plugin uses semantic versioning. +## [0.10.3] - 2026-09-27 + +### Changed + +- `audit`'s discovery method reads "Verify all claims, not just some" instead of "Critical: verify ALL claims". Each claim on a line is still verified independently (#4120). + ## [0.10.2] - 2026-09-27 ### Changed diff --git a/plugins/context7/.claude-plugin/plugin.json b/plugins/context7/.claude-plugin/plugin.json index c277da39f9..b30f76ba54 100644 --- a/plugins/context7/.claude-plugin/plugin.json +++ b/plugins/context7/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "context7", - "version": "0.5.9", + "version": "0.5.10", "description": "Looks up current library documentation, API references, and code examples via Context7 (ctx7 CLI or the Context7 MCP server) with a two-step resolve-then-query workflow: a lookup skill (default lookup plus an upstream drift-check action) and a setup skill for CLI install, auth, and MCP configuration.", "author": { "name": "Melodic Software", diff --git a/plugins/context7/CHANGELOG.md b/plugins/context7/CHANGELOG.md index 506d8e6fe5..18ecb26b0e 100644 --- a/plugins/context7/CHANGELOG.md +++ b/plugins/context7/CHANGELOG.md @@ -3,6 +3,12 @@ All notable changes to the `context7` plugin are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); this plugin uses semantic versioning. +## [0.5.10] - 2026-09-27 + +### Changed + +- `lookup`'s philosophy line drops the anti-laziness clause "even for libraries you 'know.'" It still says to verify against Context7 before claiming how a library works (#4120). + ## [0.5.9] - 2026-09-27 ### Changed diff --git a/plugins/discovery/.claude-plugin/plugin.json b/plugins/discovery/.claude-plugin/plugin.json index e3fcfef471..31ec66bddf 100644 --- a/plugins/discovery/.claude-plugin/plugin.json +++ b/plugins/discovery/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "discovery", - "version": "0.25.2", + "version": "0.25.3", "description": "Structured discovery before changes: explore the local codebase, run disciplined multi-source external research, and reconstruct why a past decision was made from evidence outside the code. Each dispatches a purpose-built subagent by default so the reading stays out of the main conversation, with source tiers, falsification, recency gates, an intent-evidence tier, and a corpus-coverage ledger, and each persists EXPLORE.md / RESEARCH.md / INTENT.md index-plus-sidecar handoff artifacts.", "author": { "name": "Melodic Software", diff --git a/plugins/discovery/CHANGELOG.md b/plugins/discovery/CHANGELOG.md index 698d03c3ff..8bd3c30031 100644 --- a/plugins/discovery/CHANGELOG.md +++ b/plugins/discovery/CHANGELOG.md @@ -1,5 +1,11 @@ # Changelog: discovery plugin +## [0.25.3] - 2026-09-27 + +### Changed + +- `research-deep` states two routing rules without bold caps: N ≥ 2 separable topics are not dispatched to an engine as one blob, and an engine's return is neither re-run inline nor surfaced as-is. Both rules and their reasons are unchanged (#4120). + ## [0.25.2] - 2026-09-28 ### Changed diff --git a/plugins/discovery/skills/research-deep/SKILL.md b/plugins/discovery/skills/research-deep/SKILL.md index e792b8088a..0b29326cd1 100644 --- a/plugins/discovery/skills/research-deep/SKILL.md +++ b/plugins/discovery/skills/research-deep/SKILL.md @@ -1,131 +1,251 @@ ---- -description: "Dispatch deep external research to the heaviest isolated execution tier available. Use when: 'deep research', 'research these N topics', 'broad multi-source research', 'compare these tools thoroughly', 'migration research', 'exhaustive research on X'. For a single small lookup use the research skill directly, which already dispatches its own subagent." -argument-hint: "[topic] (e.g., /discovery:research-deep best practices, /discovery:research-deep migration guide)" -user-invocable: true -disable-model-invocation: false -metadata: - workflow-stage: research - summary: Dispatch deep multi-topic research to the heaviest isolated tier ---- - -## Repository context. Gather first - -Collect these with **individual** Bash calls, one command per call, never combined into a single -invocation: - -- Current branch, `git branch --show-current` - -Treat a failure (not a repository, git unavailable) as an unknown value and carry on. Keep these as -separate body Bash calls rather than pre-compute lines: the harness runs a skill's whole pre-compute -block as one shell invocation, and a worktree-isolated session refuses a compound command that -contains git. The dated record for that composition claim is the worktree skill's -[reference/gather-block.md](https://raw.githubusercontent.com/melodic-software/claude-code-plugins/main/plugins/source-control/skills/worktree/reference/gather-block.md), -"The pre-compute block runs as one shell invocation". - -## Purpose - -`/discovery:research-deep` is the **dispatcher** for deep external research, a depth/execution variant of the sibling `/discovery:research` skill. Same research contract (3-phase discipline, source-tier ratio, recency gate, mandatory falsification, cited `RESEARCH.md` artifact); heavier execution that keeps the main session's context clean. It selects ONE execution tier from tool availability + task heaviness, then surfaces the same summary contract regardless of tier. - -This skill runs **inline (main context)**. It dispatches; the chosen tier provides the context isolation. It must run in main context because that is the only place both of its requirements hold, the `Workflow` tool, absent from every non-fork subagent, and a dependable `Agent` spawn, which no subagent is guaranteed to hold: see the *Dispatching this skill itself* gotcha. The dated record for the tool-filter behavior is [`${CLAUDE_PLUGIN_ROOT}/reference/parent-contract.md`](${CLAUDE_PLUGIN_ROOT}/reference/parent-contract.md), "Harness facts the dispatch design rests on". - -## Topic - -$ARGUMENTS - -If no topic was provided, infer it from the current conversation. Identify the technical claim, decision, or implementation being worked on and research that. - -**Caveat, a `${CLAUDE_…}`-shaped token in a topic may not arrive as you typed it**, and this skill carries the highest exposure of the three because a corrupted topic here is copied into every envelope of an N-way fan-out. What was observed, what is documented, what is not, and the per-topic echo-back check: [`${CLAUDE_PLUGIN_ROOT}/reference/parent-contract.md`](${CLAUDE_PLUGIN_ROOT}/reference/parent-contract.md) ("A different question"). - -## Dispatch decision (multi-topic check, then three tiers) - -**Multi-topic check. Run FIRST, before any tier.** Count the independent sub-topics in the ask (numbered list, enumerated questions, separable subjects that share no claims). N ≥ 2 separable topics → do not dispatch an engine on the combined blob. An engine decomposes ONE question into generic research *angles*; fed a multi-topic blob, every broad agent researches all N topics shallowly. N× the wall-clock and tokens for worse depth. Instead: spawn **N parallel `discovery:researcher` agents** (Agent tool, one per topic), each dispatched with the full envelope below. **Cap N at roughly a dozen**. Past that, narrow the ask with the user before dispatching. **Give each agent its own sub-slice**. `///`, assigned by this session in the dispatch envelope, never chosen by the worker (two workers choosing independently can choose the same one); the memory root travels as its own envelope field, since a worker handed a nested sub-slice path cannot tell from that path alone which ancestor is the configured root. Each writes the normal `RESEARCH.md` index, its sidecars, and its own `research-checklist.md` inside that sub-slice; those filenames are fixed, so N agents pointed at one slice root would overwrite one another's index and ledger rather than producing separable artifacts. **This session owns each topic's post-dispatch boundary. Synthesis is the last step, not the only one.** Close "The post-dispatch boundary" below for **each** topic, then synthesize the slice-root `RESEARCH.md` from the per-topic indexes. Skipping it produces the worst available artifact: a root `RESEARCH.md` presenting claims as gate-passed when the rows that matter were never graded by anyone. An engine is for a SINGLE contested or deep question that needs falsification rounds and adversarial claim-checking. Gaps that share claims stay in one topic here; the researcher fans them out inside its own Phase 2 (research discipline, "Per-gap fan-out (Phase 2)"). - -For a single-topic ask, pick the tier by the task's breadth as the table defines it: a heavy or broad task goes to the workflow engine or, without one, to the isolated subagent; a clearly small task runs inline. Treat an unknown scope as heavy. - -| Tier | Condition | Execution | -|---|---|---| -| 1. Workflow engine (preferred) | The Workflow tool is available AND a deep-research workflow exists (a built-in deep-research workflow, or one the consuming project ships) AND the task is heavy/broad (or unknown scope) | Dispatch that workflow with the topic | -| 2. Isolated subagent | No workflow path AND the task is heavy | Dispatch the purpose-built `discovery:researcher` agent with a resolved envelope | -| 3. Inline | Task clearly small/targeted (single fact, one obvious source, narrow lookup) | Invoke `/discovery:research` via the Skill tool, inline in this session | - -- **Heavy/broad** = multi-source, multi-vendor, comparison/migration, unfamiliar domain, or research that would flood main context with 9+ external queries. -- **Clearly small** = a single verifiable fact from one obvious source. Even here the full `/discovery:research` discipline applies. Task size never reduces depth. -- **Multi-topic parallel agents** = each topic agent still runs the FULL `/discovery:research` discipline (3 phases, source tiers, falsification), the split changes orchestration, never depth. - -### The dispatch envelope. Every `discovery:researcher` spawn carries it - -Both paths that spawn a worker, the N-topic fan-out and Tier 2, spawn the same agent with the same envelope, resolved in this session because the agent cannot resolve any of it once started. It refuses to guess, and halts on an absent or ambiguous topic, reason, or slice path. +# Native references: presence-gated phrasing for Claude Code's own surfaces + +Owner doc for **how a component in this marketplace refers to a native Claude Code surface**, +whether a built-in CLI command, a bundled skill, a plugin-backed built-in, or a session-provided +skill, when that surface materially overlaps what the component does. One shape: a read-time +presence gate that routes, never an assertion that the native thing is there. + +The problem this closes is specific. A marketplace skill and a native surface can do overlapping +work, and the model picks between them from descriptions alone. Silence produces duplication; a +static claim ("Claude Code ships `/doctor`, so use that") produces a false statement in every +session where the surface is gated off. Both failures are avoided by the same sentence shape. + +## Boundary + +This doc owns the phrasing of references **to native surfaces**. It does not own: + +- **Cross-plugin references.** [`seam-phrasing`](../seam-phrasing/README.md) owns the + gate + fallback + ownership-framing shape for optional references to *another plugin's* skill. + Its three elements are the template this doc specializes; a native surface is not a plugin, which + is why the specialization needs its own owner rather than a clause in that doc. +- **Whether a reference should exist at all.** That is a verdict, and verdicts live in the + committed overlap store rendered into [`docs/native-surfaces.md`](../../native-surfaces.md). + This doc governs the words once a verdict says a reference is warranted. +- **The stamp discipline on any upstream fact a reference restates.** + [`upstream-drift`](../upstream-drift/README.md) owns the four-part record (claim, basis, as-of + date, recheck trigger) and the observability bar its triggers must clear. +- **Instruction economy.** [`plugin-philosophy`](../../plugin-philosophy.md) owns the rule that + every always-loaded description is a per-session tax. This doc keeps the phrase to one clause + because of that rule; it does not restate it. + +## Why a gate, and never an assertion + +Native availability varies along at least four independent axes, so any static availability +sentence is wrong somewhere by construction: + +| Axis | Mechanism | +|---|---| +| Settings / environment | `disableBundledSkills` and `CLAUDE_CODE_DISABLE_BUNDLED_SKILLS` remove bundled skills and workflows; `skillOverrides` maps a name to `on` / `name-only` / `user-invocable-only` / `off`; `DISABLE_DOCTOR_COMMAND` hides `/doctor` specifically | +| Plan | Some surfaces require a paid or specific plan tier | +| Platform / provider | Some surfaces are absent on some OSes, and several are unavailable on non-first-party model providers | +| Host surface | CLI, web/cloud, VS Code, and mobile expose different rosters; terminal-interface commands do not exist in a web session, and a cloud session carries session-provided skills a local CLI does not | + +Claim, basis, and trigger for that table, per [`upstream-drift`](../upstream-drift/README.md): +the four axes are documented on `https://code.claude.com/docs/en/settings-reference.md` +(`disableBundledSkills`, `skillOverrides`), `https://code.claude.com/docs/en/env-vars.md`, +`https://code.claude.com/docs/en/commands.md` ("Not every command appears for every user. +Availability depends on your platform, plan, and environment."), and +`https://code.claude.com/docs/en/cloud-environments.md`; verified 2026-08-23; **recheck trigger**: +a Claude Code release note or docs change adds, removes, or renames a gating axis, or a +`skillOverrides` state leaves the four-value set. + +The consequence is the rule: **a component never states that a native surface is present, absent, +enabled, or unavailable.** It states what to do *if the surface resolves in the session*, and the +model reads its own listing to decide. + +## The description phrase + +The routing-effective surface is the frontmatter `description`, because descriptions load into +model context by default while bodies load only on invocation. One clause, front-loaded, matching +this grammar: ```text -Agent({ - subagent_type: "discovery:researcher", - description: "Deep research: ", - prompt: "Topic: - Reason: - Memory slice: // — on the N-topic path, the / sub-slice assigned to THIS topic - Memory root: - Budget: - Turn budget: - Capability flags: nested spawning - Source breadth: - Evidence use: " -}) +When the resolves in this session, prefer it for ; +this skill for . ``` -**Envelope fields only.** The agent arrives with `/discovery:research` preloaded and with its effort and turn budget already calibrated to that discipline, so the mandatory disciplines, the citation rule, the outcome gate, including the split that hands its verifier-owned rows to a fresh-context verifier rather than letting the producer grade them, and the shape of its return payload are all its own standing contract. Restating them in the prompt copies a contract that lives in the parent skill and drifts from it the moment that skill changes. One bound to know when filling `Budget`: the researcher's `maxTurns: 40` is fixed in its definition, so the budget field can narrow depth within that ceiling but never widen past it; a task that needs more belongs to Tier 1's workflow engine. `Turn budget:` is the same bound as a number: the turn by which the agent stops gathering and writes, at or below its default stop turn of 30. The agent ignores a higher value and notes it in `open_questions`, and when the line is absent it uses that default. The labels above are the plugin's one envelope template ([`${CLAUDE_PLUGIN_ROOT}/reference/parent-contract.md`](${CLAUDE_PLUGIN_ROOT}/reference/parent-contract.md)); field-by-field rationale for the six shared fields plus `Source breadth` and `Evidence use`, `Memory root` included, is [`${CLAUDE_PLUGIN_ROOT}/skills/research/context/dispatch.md`](${CLAUDE_PLUGIN_ROOT}/skills/research/context/dispatch.md). - -### Tier 1. Workflow engine (preferred) +Four required parts: + +1. **The gate**: `resolves in this session`. This is the canonical, greppable token. It is a + read-time condition on the model's own listing, not a claim about the machine. It names the + session rather than the reader: a description is injected into the system prompt, and + Anthropic's + [skill-authoring best practices](https://platform.claude.com/docs/en/agents-and-tools/agent-skills/best-practices#writing-effective-descriptions) + say to always write it in the third person (verified 2026-09-28). `if installed`, `always available`, `Claude Code ships`, and `is built in` + are all wrong here: the first is the cross-plugin gate, the rest are assertions. +2. **The provenance class**: `bundled`, `built-in`, `plugin-backed built-in`, or + `session-provided`, named in the sentence. The classes behave differently (different disable + switches, different rosters per host), and a reader who cannot tell which one they are looking + at cannot check the gate. +3. **The routing split**: what the native surface is preferred *for*, and what this component is + preferred *for*. A gate with no split tells the model a thing exists without telling it when to + pick which, which is the duplication the reference exists to stop. +4. **Self-containment**: the phrase carries its own meaning with no external lookup. + +Worked example, in the shipped shape: -If your tool list includes the Workflow tool and a deep-research workflow is available (check the consuming project's workflow registry first, a project-provided engine may superset the built-in one), dispatch it with the topic and, if it accepts one, the artifact destination: `//RESEARCH.md`, resolved per the plugin's topic-docs binding ([`${CLAUDE_PLUGIN_ROOT}/reference/topic-docs.md`](${CLAUDE_PLUGIN_ROOT}/reference/topic-docs.md)). The engine runs in the background; its completion notification carries the summary + artifact path. Do not re-run the research inline, and do not surface the return as-is, an engine is a producing context like any other, so close the post-dispatch boundary below first. +```text +When the bundled doctor skill resolves in this session, prefer it for the quick native +health-and-fix pass; this skill for the deep read-only install-tree inventory. +``` -If no workflow engine resolves, fall through to Tier 2. +**Absent is not a fallback state.** Unlike a cross-plugin seam, there is nothing to degrade to: the +component's own job is the fallback, and the split sentence already says what that job is. Do not +write "otherwise this skill", which is noise the shared budget pays for. -### Tier 2. Isolated subagent fallback +### Budget caveat -Dispatch ONE `discovery:researcher` with the envelope above. With a single worker the slice field is the topic's own `//`, a sub-slice is needed here only when that root already holds an unrelated `RESEARCH.md`, per the parent skill's one-writer-per-slice rule. +Descriptions are subject to two limits, and a baked phrase is the best available routing surface, +not a guaranteed one: -`discovery:researcher` rather than a `general-purpose` spawn carrying a hand-written description of the discipline: it is the plugin's purpose-built worker for exactly this run, arriving with `/discovery:research` already loaded and with its effort and turn budget calibrated to that discipline, so the run is disciplined and correctly provisioned at turn zero rather than to whatever depth a prompt managed to reproduce. Its tool list also covers what the work needs, which a read-only Explore agent's does not: Phase 3 reaches direct-fetch and MCP tools, and the artifact gets written. +- the combined `description` + `when_to_use` text is truncated at **1,536 characters** in the + listing by default (`skillListingMaxDescChars`); and +- the listing as a whole is capped at a **share of the context window** + (`skillListingBudgetFraction`, default 1%). On overflow the listing keeps every skill *name* and + drops whole descriptions, starting with the least-invoked skills. -### Tier 3. Inline (clearly small task) +Basis: `https://code.claude.com/docs/en/skills.md` (Frontmatter reference; Troubleshooting → +"Skill descriptions are cut short") and `https://code.claude.com/docs/en/settings-reference.md`; +verified 2026-08-23. **Recheck trigger**: a release or docs change moves the 1,536 default, the +1% default, or the drop-order rule. -Invoke `/discovery:research` via the Skill tool, inline in this session. No dispatched *research* tier, no workflow. The full `/discovery:research` discipline still applies, including its own rule that an inline run hands the verifier-owned rows to a fresh context rather than self-grading them. That fresh context is a subagent; what Tier 3 declines to dispatch is the research, not the verification, and the boundary below arrives here through the parent skill rather than being restated. +Two obligations follow. Keep the phrase to one clause, since it spends shared budget every session +for every consumer. And where a fleet's listing plausibly overflows, the overlap store records a +per-row *phrase may be budget-dropped* caveat, so nobody later reads a baked phrase as a guarantee +that the model saw it. -### The post-dispatch boundary. Every dispatching tier owns it +### Open consideration: the bundled keep-set -**A dispatched run is not finished when it returns.** No producing context, whether engine, isolated subagent, or topic worker, can complete the `/discovery:research` outcome gate's verifier-owned rows (independent corroboration, HIGH confidence, joint inference) or its parent-owned row (project fit). The verifier rows are assigned to a fresh context precisely because a producer may not grade its own choices; project fit needs the consuming project's conventions, which only this session holds. Nor can the producer be relied on to dispatch that verifier itself. Whether a non-fork subagent holds `Agent` depends on the harness's nesting allowance (`CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH`), a session property this skill does not design against. +A single-source, unconfirmed read of a shipped build suggests bundled entries may be exempt from +budget dropping, which would make native/marketplace routing asymmetric under pressure. It is +recorded here as an open consideration and **nothing in this convention builds on it**: no phrase, +no verdict, and no registry row may cite it until a live probe confirms it. **Recheck trigger**: +a live in-session probe confirms or refutes the exemption, or upstream documents the drop order at +the source level. -So for **every** dispatched run, one per topic on the N-topic path, once on Tier 1 and Tier 2, this session dispatches the sibling verifier against the artifact on disk, applies project fit, and writes both results back into that artifact's index **before** surfacing anything. Surfacing a producer's summary and artifact path directly presents claims as gate-passed when the rows that matter were never graded by anyone. A single-topic ask earns no weaker boundary than a multi-topic one, and an engine earns no weaker boundary than a subagent. On the N-topic path the synthesized root index also goes to a fresh verifier for criterion 12 before it is surfaced, per the research dispatch contract's fan-out section. +## The Boundary section -**Grade the run off disk before any of that.** Every obligation above acts on an artifact, so all of them are worthless against a dispatch that produced none, and `status: complete` is the producer's claim about its own run. The parent skill's **post-dispatch acceptance gate** is what turns that claim into evidence: create the slice and touch a `.research-dispatch` baseline BEFORE the dispatch. Both shell forms of that one command are in [`${CLAUDE_PLUGIN_ROOT}/reference/parent-contract.md`](${CLAUDE_PLUGIN_ROOT}/reference/parent-contract.md), and the POSIX one does not run in PowerShell, then `scripts/check-dispatch-artifact.sh --index-name RESEARCH.md` against the slice path this session resolved (never one read out of the payload), then a parent-side regrade of the coverage ledger and of source applicability (`${CLAUDE_PLUGIN_ROOT}/scripts/check-source-applicability.py` with `--expect-evidence-use` set to the envelope's value; a Tier 1 engine artifact without the header fields fails it by design, so route that topic to Tier 2). Cite exit statuses; any non-zero halts. **On the N-topic path run it against the sub-slice assigned to each topic, before synthesizing the slice-root index**, the gate grades exactly the path it is handed and never scans, so a sub-slice invocation grades that topic's run while a slice-root invocation would grade only the synthesized index, never any dispatched run. **That one baseline at the slice root serves every sub-slice**, the gate compares each sub-slice index's mtime against the file it is handed, and a baseline touched now is newer than anything an earlier run left anywhere under the slice, so a per-sub-slice baseline is optional, not owed. +The Boundary section is the surface a verdict lands on. **A store row whose verdict is not `defer` +and whose observation is extraction-evidence lands together with its `## Boundary` section in the +component's body, in the same change.** A verdict that lives only in the store changes nothing the +model reads: the registry is a maintainer surface and shipped plugins never carry it, so until the +body says how the two surfaces relate, the overlap the row records is still silent at runtime. +The section costs nothing the description phrase costs. Bodies load only on invocation, so a +Boundary section spends no shared listing budget and changes no routing; the gate the phrase +earns (below) has no reason to hold the section back. -Parent-side handling of a `discovery:researcher` return specifically, the gate's steps, the payload checks, and the four obligations stated in full, is the parent skill's contract rather than a second copy here: [`${CLAUDE_PLUGIN_ROOT}/skills/research/SKILL.md`](${CLAUDE_PLUGIN_ROOT}/skills/research/SKILL.md) for the gate's steps, and [`${CLAUDE_PLUGIN_ROOT}/skills/research/context/dispatch.md`](${CLAUDE_PLUGIN_ROOT}/skills/research/context/dispatch.md) for the rationale and the recovery ladder. +The section carries the conclusion: the surfaces by provenance class, the routing split, and the +mutation gate. The four-part records behind it (the basis each upstream specific rests on, its +as-of date, its recheck trigger, the extraction or docs evidence) live in a **reference file inside +the same skill**, linked from the section with a same-plugin relative path, so the body stays short +and the detail stays reachable. Modeled on the `review` plugin's organic pattern (`/review:quality-gate` +and `/review:fanout` each carry one): -## Relationship to `/discovery:research` (parent skill) +```markdown +## Boundary, the bundled `` skill -This variant tracks `/discovery:research`'s conventions. Same discipline file, same artifact contract, same outcome gate. There is no separate copy here; update the parent and this dispatcher follows. + -## Gotchas +- **`` ()**: what it does, what it mutates, how it is invoked. +- **`` ()**: same. -- **Feeding a multi-topic ask to an engine.** An engine decomposes ONE question into research - angles; given N separable topics, every broad agent researches all N shallowly. N× the cost for - worse depth. Run the multi-topic check FIRST, before any tier selection. -- **Dispatching this skill itself.** It must run in main context: `Workflow` is unavailable in every - non-fork subagent, and **every** tier needs the `Agent` tool, the N-topic fan-out to spawn topic - workers, and all four paths to close the post-dispatch boundary, whose availability inside a - subagent depends on the session's nesting allowance, and which, inside a fork, cannot - spawn a further fork at all. A dispatched `/discovery:research-deep` therefore risks silently losing Tier 1, - the N-topic fan-out, and the verification boundary that makes any tier's artifact trustworthy. The - sibling `/discovery:research` is the one that dispatches. -- **Treating a worker's return as the finished thing.** A `discovery:researcher` return is a pointer - plus a payload, and grading that payload is parent-side work this session owes before anything is - surfaced, the checks and the obligations are specified in the parent skill's dispatch contract. - Accepting a payload without running them surfaces an ungraded run as a gate-passed one. -- **Assuming the heaviest tier is available.** Tier selection is engine-biased, but it reads what is - actually connected this session and degrades to the next tier rather than failing. +**Routing:** . -## What this skill does NOT do +**Mutation gate:** . +``` -- Does NOT make decisions or write code. Research only; the planning step (or user) decides. +Six properties the section keeps: + +1. **Every overlapped surface named in the section, as a code span.** `## Boundary` on its own is + a heading any prose satisfies, and several components carry one for a surface this convention + has no verdict on. The heading naming the surface is the preferred shape and is what the + template above shows; a generic `## Boundary` heading is still accepted when the section text + names the surface, which is how one section covers a component that overlaps several. Either + way the name is a code span, so a surface whose name is also an ordinary English word (`run`, + `design`) is never satisfied by a sentence that happens to use the word. +2. **Surfaces named by provenance class**, exactly as in the description phrase. +3. **A mutation gate per surface that mutates.** Naming an overlap without naming what it writes + invites an unrequested mutation. +4. **One owning description, pointers elsewhere.** Where two components in the *same plugin* both + overlap the surface, one carries the description and the other points at it with a same-plugin + relative link and adds only what is specific to itself. Cross-plugin pointers are forbidden. +5. **Presence-gated language throughout**: the body inherits the description's gate; it never + promotes a surface to available because the body is longer. +6. **Upstream specifics carry their basis and date**, per + [`upstream-drift`](../upstream-drift/README.md). + +## Self-containment: shipped plugins never cite the registry + +The overlap store and [`docs/native-surfaces.md`](../../native-surfaces.md) live in this +repository. A plugin installed from the marketplace does **not** have them: a citation would be a +broken reference at install time, and the reader would be routed to a file that does not exist. + +So: baked text repeats what it needs and cites nothing outside its own plugin. The registry is a +maintainer surface: it records the verdict, the evidence, and the trigger that would change them; +the component carries the conclusion. The parity check enforces the forward direction +mechanically: every baked line traces back to a store row, and a claimed Boundary section must name +that row's surface rather than merely carry the heading. In the other direction the two baked +surfaces differ. A row without its Boundary section is a defect the self-check fails on, because +the section costs nothing and can always land in the change that adds the row; a row without a +description phrase is legal pending state, because the phrase is the budget-priced, +routing-affecting half and earns its separate gate. + +## Enforceability + +Classified per `melodic-software/standards` `conventions/engineering/enforceability-tiers.md`: + +| Judgment | Tier | +|---|---| +| A baked native reference traces to a store row | **Deterministic**: built, as the overlap self-check's store↔baked-line parity pass | +| Every non-`defer` extraction-evidence row has its Boundary section (`baked.boundary_section` true, and a `## Boundary` section in the component naming that row's surface as a code span) | **Deterministic**: built, in the same self-check, as a blocking problem (exit 1). The tier carries no advisory grade: advisory belongs to detect-then-judge, where a tool narrows a set a human then rules on, and nothing here needs a ruling. A consumer gate passes a degraded run because degraded reports what this repository cannot fix by editing its own files; a missing section is fixable in the change that adds the row | +| Every store row carries a recheck trigger and a class-tagged observation record | **Deterministic**: built, in the same self-check | +| The phrase uses the presence gate rather than an availability assertion | **Detect-then-judge**: the `resolves in this session` token is greppable, but deciding whether a *different* sentence asserts availability is a judgment about meaning. Candidate check named, not built: flag a component description naming a bundled or built-in surface with no gate token. Build trigger: a second assertion-shaped native reference reaches `main` after this doc | +| The routing split is the right one | **Reasoning-only**: it is the verdict, and verdicts are human-gated by design | + +## Adopters + +| Surface | What it carries | +|---|---| +| `/claude-ops:audit-install-state` | Description phrase + `## Boundary` section for the bundled `doctor` skill (verdict `complementary`) | +| `/review:quality-gate`, `/review:fanout` | The organic Boundary pattern this doc generalizes; adopts the phrasing rules on next touch | + +| `/claude-config:audit-instructions` | `## Boundary` section for the bundled `claude-api` skill's `prompt-audit` subcommand (verdict `complementary`, composite posture), four-part detail in the skill's own reference file; no description phrase | +| `/evals:methodology` | `## Boundary` section for the bundled `claude-api` skill's `hillclimb` and `build-eval` subcommands (verdict `complementary`); detail in the skill's eval-design reference | +| `/playbooks:fable-5` | `## Boundary` section for the bundled `claude-api` skill as the live-facts and cost-audit surface its chapters defer to (verdict `complementary`); detail in the pack's prompt-caching reference chapter | +| `/review:code-review`, `/review:security-review` | `## Boundary` sections for the bundled `code-review` skill and the native `security-review` command (verdict `complementary`, CI lane versus session pass); four-part detail in each skill's `reference/` file; no description phrase | +| `/code-tidying:tidy`, `/code-tidying:batch-simplify` | `## Boundary` sections for the bundled `simplify` skill (verdict `complementary`, diff-anchored versus lane- and sweep-anchored); detail in each skill's reference or context file; no description phrase | +| `/testing:run-e2e` | `## Boundary` section for the bundled `run` skill (verdict `complementary`, a look versus evidenced verification); detail in the skill's context file; no description phrase | +| `/claude-ops:audit-performance`, `/claude-ops:audit-skill-visibility` | `## Boundary` sections for the bundled `doctor` skill (and `/skill-doctor` for the second), verdict `complementary`; the second also carries the description phrase; detail in each skill's `reference/` file | +| `/visualization:visualize`, `/prototype:explore-directions` | `## Boundary` sections for the bundled `design` skill (verdict `complementary`, user-run canvas versus throwaway page or mockup); detail in the catalog spoke and the skill's `reference/` file; no description phrase | + +Applying **description phrases** fleet-wide is a reserved, separately gated sweep: one plugin per +unit, each running apply, verify, PR, close, never a single fleet-wide edit, because each phrase +and spends shared budget. **Boundary sections** are not routing-affecting and spend no budget, so +Boundary-only baking may land across several plugins in one change; the unit rule does not apply +to it. + +## Versioning + +Changing a required part of the description phrase, the canonical gate token, or an enforceability +verdict is a major change to this contract; additive guidance is minor; clarification is a patch. +Version history lives in [`CHANGELOG.md`](CHANGELOG.md), which landed with the first recorded +change; the doc's README-only original state reads as 1.0. + +## External authority + +- `https://code.claude.com/docs/en/skills.md`: description loading, the per-entry cap, and the + listing budget's drop behavior. +- `https://code.claude.com/docs/en/settings-reference.md`, + `https://code.claude.com/docs/en/env-vars.md`: `disableBundledSkills`, `skillOverrides`, + `skillListingMaxDescChars`, `skillListingBudgetFraction`, and the env twins. +- `https://code.claude.com/docs/en/commands.md`, + `https://code.claude.com/docs/en/cloud-environments.md`: plan/platform gating and per-host + roster differences. + +Upstream publishes no convention for deferring to its own surfaces (absence checked 2026-08-23 +against the pages listed above and `https://code.claude.com/docs/llms.txt`), which is why this +repository owns one. + write code. Research only; the planning step (or user) decides. - Does NOT skip phases for "simple" topics. Task size does not reduce depth. - Does NOT run the deep pass itself in main context. It dispatches; Tier 1 (engine) or Tier 2 (subagent) provides the context isolation. diff --git a/plugins/docs-hygiene/.claude-plugin/plugin.json b/plugins/docs-hygiene/.claude-plugin/plugin.json index b724180a35..98da0f57e5 100644 --- a/plugins/docs-hygiene/.claude-plugin/plugin.json +++ b/plugins/docs-hygiene/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "docs-hygiene", - "version": "0.23.11", + "version": "0.23.12", "description": "Documentation-hygiene toolkit: compress (flavor-trim markdown with a semantic-diff safety net), audit-noise (classify markdown noise), extract-ssot (deduplicate repeated content into a single source of truth), audit-encapsulation (detect citations into skill-private surfaces), rename-references (sweep stale references after renames), audit-derivability (classify whether a whole document earns its existence: could a fresh agent re-derive it from the code?), audit-progressive-disclosure (grade instruction files against a load-tier model for split opportunities and hub/spoke disclosure defects), write-for-agents (authoring-time doctrine that fires while agent-consumed markdown is being written), write-for-humans (the same moment for the other reader, covering end-user READMEs, RFCs, release notes and guides, and resolving the consuming project's own style guide first), and a file-name set that plans, applies, and enforces a casing rule across a doc tree: setup (the one configuration surface), audit-file-names (read-only inventory plus the reference sweep), realign-file-names (the executor, one human acceptance per file), and generate-file-name-gate (emits the standalone check that keeps the tree from drifting back).", "author": { "name": "Melodic Software", diff --git a/plugins/docs-hygiene/CHANGELOG.md b/plugins/docs-hygiene/CHANGELOG.md index a8bc3bf000..48c4f1d622 100644 --- a/plugins/docs-hygiene/CHANGELOG.md +++ b/plugins/docs-hygiene/CHANGELOG.md @@ -1,5 +1,11 @@ # Changelog: docs-hygiene plugin +## [0.23.12] - 2026-09-27 + +### Changed + +- `compress`'s Phase A worker prompt writes its nine hard rules as "Never ..." instead of all-caps "NEVER ...". Every rule is unchanged, and the write-scope fence (`Touch ONLY . FORBIDDEN: ...`) keeps its emphasis (#4120). + ## [0.23.11] - 2026-09-28 ### Changed diff --git a/plugins/event-storming/.claude-plugin/plugin.json b/plugins/event-storming/.claude-plugin/plugin.json index 72f042fd49..50508141e6 100644 --- a/plugins/event-storming/.claude-plugin/plugin.json +++ b/plugins/event-storming/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "event-storming", - "version": "0.6.17", + "version": "0.6.18", "description": "EventStorming for domain discovery: a methodology skill (Big Picture / Process Modeling / Design-Level facilitation reference, notation, patterns) and a simulation skill (agentic multi-persona workshops that produce a structured-markdown model by default; a live Miro-board rendering path is available when the first-party miro plugin is enabled).", "author": { "name": "Melodic Software", diff --git a/plugins/event-storming/CHANGELOG.md b/plugins/event-storming/CHANGELOG.md index 1d011c6491..96f10c1bdd 100644 --- a/plugins/event-storming/CHANGELOG.md +++ b/plugins/event-storming/CHANGELOG.md @@ -3,6 +3,12 @@ All notable changes to the `event-storming` plugin are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); this plugin uses semantic versioning. +## [0.6.18] - 2026-09-27 + +### Changed + +- `simulation`'s agentic-simulation reference states five rules in normal register: corrective instructions in every agent prompt, the Behavioral Rules heading, the beneficiary persona coming first, the sticky-note content rules heading, and the no-emoji rule. Every rule is unchanged (#4120). + ## [0.6.17] - 2026-09-27 ### Changed diff --git a/plugins/knowledge/.claude-plugin/plugin.json b/plugins/knowledge/.claude-plugin/plugin.json index 6455d2f099..ce71832e11 100644 --- a/plugins/knowledge/.claude-plugin/plugin.json +++ b/plugins/knowledge/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "knowledge", - "version": "0.14.7", + "version": "0.14.8", "description": "Ingest external knowledge into durable, synthesized artifacts. Ships a book-distillation pipeline (PDF/EPUB into concept-organized, author-attributed skill reference files), a video-digest pipeline (watch a single public video from YouTube or X, formerly Twitter: transcript, link harvest, and repo-applicability synthesis), a course-digest pipeline (extract and synthesize online video courses from Dometrain and Teachable into repo-applicable recommendations), a docpage-digest pipeline (single online documentation page into a verified knowledge slice with dual verification including one cross-vendor verifier, and an interview handoff), and a map-corpus pipeline (multi-resource corpus into a classified link map, deterministic node manifests, gate-verified relevance inventory, and an approved queue of docpage-digest runs), plus a re-runnable setup action; a configurable library directory governs where synthesized artifacts land in the consuming repo.", "author": { "name": "Melodic Software", diff --git a/plugins/knowledge/CHANGELOG.md b/plugins/knowledge/CHANGELOG.md index 0be2f2b5e6..39ac2ebfbc 100644 --- a/plugins/knowledge/CHANGELOG.md +++ b/plugins/knowledge/CHANGELOG.md @@ -4,6 +4,12 @@ All notable changes to the `knowledge` plugin are recorded here. The `version` i `.claude-plugin/plugin.json` is the delivery vehicle. A consumer receives a change only after that version increases. +## [0.14.8] - 2026-09-27 + +### Changed + +- `book-distill`'s one-chapter-at-a-time rule, `course-digest`'s gather-before-Phase-3 rule and storage rules, and the Dometrain adapter's instructor rule drop their all-caps and "Critical rule" markers. The rules themselves are unchanged (#4120). + ## [0.14.7] - 2026-09-28 ### Changed diff --git a/plugins/planning/.claude-plugin/plugin.json b/plugins/planning/.claude-plugin/plugin.json index 08f3e96da1..e892ce0852 100644 --- a/plugins/planning/.claude-plugin/plugin.json +++ b/plugins/planning/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "planning", - "version": "0.45.3", + "version": "0.45.4", "userConfig": { "surface": { "type": "string", diff --git a/plugins/planning/CHANGELOG.md b/plugins/planning/CHANGELOG.md index 0314d2ae36..66fb8b8053 100644 --- a/plugins/planning/CHANGELOG.md +++ b/plugins/planning/CHANGELOG.md @@ -3,6 +3,12 @@ All notable changes to the `planning` plugin are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); this plugin uses semantic versioning. +## [0.45.4] - 2026-09-27 + +### Changed + +- `plan`'s checklist template states that Step 3 is never skipped without the "MANDATORY" and "NEVER" caps. The stress-test is still required before presenting (#4120). + ## [0.45.3] - 2026-09-28 ### Changed diff --git a/plugins/planning/skills/plan/templates/checklist.md b/plugins/planning/skills/plan/templates/checklist.md index f95161a78e..c857b376d3 100644 --- a/plugins/planning/skills/plan/templates/checklist.md +++ b/plugins/planning/skills/plan/templates/checklist.md @@ -6,7 +6,7 @@ Copy into `//plan-checklist.md` (default `.work/`; the t - [ ] Step 1: Prerequisite check. Brief locked (PLAN.md Brief section exists OR equivalent crisp framing); exploration + research done or explicitly waived; design gate evaluated - [ ] Step 2: Formulate the plan. Phases with verifiable Sanity Checks per phase; estimate scope; identify parallelism -- [ ] Step 3: Plan stress-test (never skip). Surface cost, then dispatch the plan-reviewer agent per context/plan-reviewer.md +- [ ] Step 3: Plan stress-test (never skip). Dispatch a fresh-context plan-reviewer sub-agent per context/plan-reviewer.md - [ ] Step 3b: Assess blast radius (LOW / MEDIUM / HIGH / CRITICAL). This gates whether Step 4 runs - [ ] Step 4: Formal stress-test + research-iterate (CONDITIONAL on Step 3b ≥ MEDIUM). Invoke `/planning:devils-advocate` and targeted research on contested claims - [ ] Step 4.5: Execution-shape analysis (default ON for multi-phase plans). Emit scope-fencing tables + per-phase routing table @@ -24,3 +24,314 @@ Copy into `//plan-checklist.md` (default `.work/`; the t ## How to use Copy at session start; tick boxes as steps complete; a resuming session reads the unticked boxes to know where to continue. +markers: none) +- **Our component:** `session-flow:clean-stop` (skill) +- **Evidence:** + - probed on the live v2.1.241 binary 2026-08-24: `claude --bare -p "/export "` returned `/export isn't available in this environment.` and wrote no file, so the command is an interactive-terminal surface + - documented at code.claude.com/docs/en/commands.md: /export renders the current conversation as plain text to clipboard or a file (optional filename argument), no format or redaction flags + - output written to user paths sits outside the cleanupPeriodDays retention sweep (path-scoped to ~/.claude), which is the durability property the suggestions exist for + - suggestion sites: plugins/session-flow/skills/clean-stop/SKILL.md (durability sweep), handoff/SKILL.md (prompt-only close), retro/SKILL.md (post-chain-coverage offer); all body text, presence-gated with the canonical token, none baked into a description or Boundary section +- **Observation:** live-roster: probed on the live v2.1.241 binary in a Linux container (headless form unavailable; interactive form documented but not observed here); one environment, one day (2026-08-24) +- **Recheck trigger:** a Claude Code release note or docs change adds an /export format/redaction flag, a headless or programmatic form, or an official conversation-sharing surface; any of these reopens whether suggestion-only is still the right integration shape (verified 2026-08-24) +- **Baked:** description phrase no · Boundary section no + +### `plugin eval` → `evals:plugin-eval` + +- **Verdict:** `complementary`: The CLI runs and scores: `claude plugin eval ` loads the plugin, runs every case in a with-plugin arm and a no-plugin baseline arm, grades each run, and reports WITH, W/OUT, and the delta. evals:plugin-eval is the guided practice around that command, which the CLI does not ship: a preflight that reports the CLI version against the floor, whether a sandbox backend exists on this machine, and the target type (plugin, wrapped skill, wrapped agent, hooks as advisory; CLAUDE.md and rules refused because the run strips them by design); static validation of the case files with no model call; a cost estimate from cases x runs x arms and a ceiling from plugin user config passed as --max-cost-usd; and a delta-first reading with the iteration loop. Neither replaces the other: the skill never grades, and the command never preflights, prices, or reads. The skill's Boundary section names the command; no listing phrase is baked, because the native-references gate token is a condition on the model's skill listing, and a CLI subcommand never enters that listing, so the skill gates on the CLI itself (preflight's version floor) instead. The gated marker rests on two switches: below the floor the binary prints an early-access refusal, and a server-side switch prints an unavailable refusal that nothing local restores. +- **Native surface:** `plugin eval` (built-in command; markers: gated) +- **Our component:** `evals:plugin-eval` (skill) +- **Evidence:** + - `claude plugin eval --help` at 2.1.269 (read 2026-09-11): 'Run eval cases (/**/case.yaml or prompt.md + graders/*.md; the eval dir is evals/ unless --eval-dir or the manifest says otherwise) against a plugin and report scored results. Target is a path, a plugin name, or a plugin@marketplace id: installed and skills-dir plugins both resolve (and add a no-plugin baseline arm)'; `--ablation` defaults to with-without whenever a plugin resolves and reports the score delta, and under it graders marked with-only, including `tool_used: Skill`, are a plugin-fired indicator rather than part of the score + - the same help text: `--max-cost-usd` is an optional hard ceiling checked before each run launches (exit 2 with partial results when hit; paid graders skipped on the breaching run while free graders still score it); `--trust-plugin` answers the first-run trust prompt for CI; `--threshold` defaults to 1.0; `--allow-tools` is the operator grant for Bash, Write, Edit, WebFetch, and mcp__*; `init` takes only --bare, --eval-dir, and -i + - https://code.claude.com/docs/en/plugin-evals.md (the raw variant; read 2026-09-11) documents the same flag set, the case layout, the exit codes 0/1/2/130/143, and the aggregate-result.json fields; the raw page matched `--help` exactly where a summarizer over the rendered page had fabricated a flag table + - gate basis: the command shipped in Claude Code 2.1.269 (anthropics/claude-code, 2026-09-11); below that floor the binary prints `plugin eval is currently in early access`, and a server-side switch prints `plugin eval is currently unavailable`, which no local setting restores + - the docs page: the run strips user settings, hooks, CLAUDE.md, MCP servers, other plugins, memory, and skills, so a rules or CLAUDE.md target has nothing to measure; native Windows has no sandbox backend, so a case granting Bash, Write, or Edit is refused rather than run unconfined, with WSL2 named for Windows and bubblewrap plus socat for Linux + - the docs page: the case format (`prompt.md` plus `graders/*.md`, or `case.yaml` with `schema_version: "1.1"`) is not the skill-creator `evals/evals.json` format this marketplace's skills carry, so the two coexist and `skill-quality:check validate-evals` keeps the other one + - our planned description: preflight, validate without spending, price, and read the delta for a `claude plugin eval` run; the CLI runs and scores, this skill guides the practice around it (shipped as `plugins/evals/skills/plugin-eval` in melodic-software/claude-code-plugins#4154) + - `plugin eval` is absent from the 2.1.232 and 2.1.251 extractions the sibling rows rest on; absence from an extraction is a statement about the extraction, and the command postdates both +- **Observation:** extraction: `claude plugin eval --help` from the installed CLI at 2.1.269 (`claude --version` prints `2.1.269 (Claude Code)`), read live in the session on 2026-09-11; a targeted observation of one subcommand's help text, not a re-extraction of the binary's roster (2026-09-11) +- **Recheck trigger:** a Claude Code release after 2.1.269 changes the plugin eval flag set, the case schema version, the exit codes, the ablation exclusion rule for with-only and `tool_used: Skill` graders, the early-access or unavailable gate strings, or the sandbox backend list; or the command or its docs page gains a preflight, validate-only, dry-run, or cost-estimate mode that makes any part of evals:plugin-eval redundant (verified 2026-09-11) +- **Baked:** description phrase no · Boundary section yes +- **Budget caveat:** the baked phrase may be dropped from the skill listing under budget pressure. It is the best available routing surface, not a guaranteed one + +### `skill-doctor` → `claude-ops:audit-skill-visibility` + +- **Verdict:** `complementary`: The sibling doctor row's split, narrowed to the surface that now owns the question. Built-in /skill-doctor is a one-shot report of what each loaded skill costs in context and how often it is used, so unused ones can be turned off. audit-skill-visibility answers why a skill is unseen: it reconciles three usage sources (native ~/.claude.json counters, its own JSONL store, OTEL) under a max-across-sources rule, computes an observed horizon and withholds every verdict the span cannot support, diagnoses reachability causes, and analyses listing-budget starvation. It disables nothing by contract. This row is separate from the doctor row rather than folded into it because the two surfaces carry different gates: /doctor answers to DISABLE_DOCTOR_COMMAND, /skill-doctor to a minimum version and to feature-flag fetching, so a session can resolve either, both, or neither, and each routing line needs its own presence gate. +- **Native surface:** `skill-doctor` (built-in command; markers: gated) +- **Our component:** `claude-ops:audit-skill-visibility` (skill) +- **Evidence:** + - upstream commit d7dbd9a09f59775726ed14bbea8fc9dfdff62f7b in anthropics/claude-code (2026-09-04) added the `## 2.1.261` CHANGELOG heading and, under it, `Added /skill-doctor to show which loaded skills go unused and what they cost in context, so you can prune them`; read from the commit diff, not from the rendered changelog page + - https://code.claude.com/docs/en/commands.md carries a /skill-doctor row in the all-commands table, and that row does NOT carry the bold `[Skill](/docs/en/skills#bundled-skills).` prefix the same table puts on /doctor, /run, /run-skill-generator and /simplify; that prefix is how the table marks a bundled skill, so this row is classed builtin-command rather than bundled-skill (read 2026-09-07) + - the same table row and https://code.claude.com/docs/en/skills.md ('Find unused skills') both state that /skill-doctor requires Claude Code v2.1.252 or later and is unavailable in sessions that skip feature-flag fetching, and the skills page adds that it answers `Skill usage reports are not available on this connection.` over Remote Control; that is the gate this row records, and it is not doctor's + - the version the surface was announced in and the version it is documented to require disagree upstream: the CHANGELOG lands it at 2.1.261 while commands.md and skills.md say v2.1.252 or later, so no shipped routing line in this repository states a version for it (read 2026-09-07) + - our description: audit whether each installed skill is actually VISIBLE to the model; reconciles native counters, a JSONL store, and OTEL; withholds every verdict the data cannot support; read-only, never disables, deletes, or edits a skill + - our description's Not-for clause, the Purpose section, and the SKILL.md Scope boundary table each name /skill-doctor behind its own `resolves in this session` gate, separate from the /doctor gate beside it +- **Observation:** upstream-source: d7dbd9a09f59775726ed14bbea8fc9dfdff62f7b, the anthropics/claude-code commit that added the 2.1.261 CHANGELOG entry naming /skill-doctor, plus the commands.md and skills.md pages read the same day. Not an extraction and not a live roster: this container runs 2.1.258, below the release that announced the surface, so nothing here observed the command itself. (2026-09-07) +- **Recheck trigger:** a Claude Code release note or docs change removes /skill-doctor, folds its report back into /doctor, gives its all-commands row the bundled-skill marker (which moves this row to the bundled-skill lane and changes which switch disables it), changes its version or feature-flag gate, or gives it a multi-source reconciliation or observation-horizon discipline of its own (verified 2026-09-07) +- **Baked:** description phrase yes · Boundary section no +- **Budget caveat:** the baked phrase may be dropped from the skill listing under budget pressure. It is the best available routing surface, not a guaranteed one + +## Bundled skills + +### `claude-api` → `claude-config:audit-instructions` + +- **Verdict:** `complementary`: Composite posture, decided at the ClaudeDevs cost-performance adoption interview: wrap or point to the bundled subcommand where it fits the use case, and run our own processes where they fit, rather than routing one way on paper. The bundled skill's prompt-audit subcommand is the vendor's apply-sweep over the working directory's whole prompt surface, application code included; audit-instructions is a standing report-only audit of locally-owned Claude Code instruction surfaces with the versioned I-catalog, target-model scoping, and deterministic pre-scans. ADR-0028 already composes both: run the vendor procedure per model change, feed recurring gap shapes back into the catalog. The app-code surface stays with the bundled skill (scope widening rejected at the same interview). +- **Native surface:** `claude-api` (bundled skill; markers: none) +- **Our component:** `claude-config:audit-instructions` (skill) +- **Evidence:** + - binary extraction 2026-09-09 (claude.exe 2.1.263): registerClaudeApiSkill present; subcommand array cost-optimize, migrate, managed-agents-onboard, prompt-audit, upgrade, build-eval, hillclimb + - platform docs claude-api-skill page (fetched 2026-09-09): 'The skill comes bundled with Claude Code and is also available in the open-source Anthropic skills repository' + - hillclimb and build-eval are bundled-only: absent from anthropics/skills HEAD 41bbe19 (2026-09-03) and from the skill's docs page + - executed composition precedent: docs/specs/prompt-audit-skills-2026-09.md (fleet-wide prompt-audit run, 805 findings applied) + ADR-0028 (repeats per model change; findings are edits, not criteria) + - verdict recorded from the owner's interview answers in docs/upstream/claudedevs-cost-performance.md Lane M and Lane T2, 2026-09-10 +- **Observation:** extraction: extracted from binary 2.1.263 at node_modules/@anthropic-ai/claude-code/bin/claude.exe (registerClaudeApiSkill string plus subcommand array; bundled shared/evals/eval-hillclimb.md extracted and read); bulk registrar enumeration was broken at this build, so this row's evidence is the targeted extraction, not the inventory JSON (2026-09-09) +- **Recheck trigger:** a Claude Code release changes the bundled claude-api skill's subcommand set, or the anthropics/skills repo or the platform claude-api-skill docs page gains hillclimb/build-eval (which also fires the docs/upstream/claudedevs-cost-performance.md hillclimb row) (verified 2026-09-10) +- **Baked:** description phrase no · Boundary section yes +- **Budget caveat:** the baked phrase may be dropped from the skill listing under budget pressure. It is the best available routing surface, not a guaranteed one + +### `claude-api` → `evals:methodology` + +- **Verdict:** `complementary`: Different jobs on the same object. The bundled skill's hillclimb subcommand consumes an eval suite and searches model and effort for the cheapest configuration that holds the target (train/test split, one change per round, held-out scoring), and build-eval scaffolds the suite it needs; both run evals and change configuration. evals:methodology is knowledge about designing the suite (criteria, anatomy, grading, effort as an axis) and runs nothing. The two chain: design the suite here, hand it to the search. Recorded when the effort-axis note citing hillclimb landed in the methodology reference. +- **Native surface:** `claude-api` (bundled skill; markers: none) +- **Our component:** `evals:methodology` (skill) +- **Evidence:** + - binary extraction 2026-09-09 (claude.exe 2.1.263): subcommand array includes build-eval and hillclimb; bundled shared/evals/eval-hillclimb.md read end to end (train/test split, one proposal per round, held-out scoring) + - hillclimb and build-eval absent from anthropics/skills HEAD 41bbe19 (2026-09-03) and from the platform claude-api-skill docs page + - our description: 'Knowledge (WHY/WHAT of eval design), not a runner; ... for running and scoring a plugin's suite against a no-plugin baseline use /evals:plugin-eval' + - reference/eval-design.md 'Effort as an eval axis' cites the subcommand behind the presence gate +- **Observation:** extraction: extracted from binary 2.1.263 at node_modules/@anthropic-ai/claude-code/bin/claude.exe (subcommand array; bundled shared/evals/eval-hillclimb.md extracted and read); bulk registrar enumeration was broken at this build, so this row's evidence is the targeted extraction, not the inventory JSON (2026-09-09) +- **Recheck trigger:** a Claude Code release changes the bundled claude-api skill's subcommand set, or the public anthropics/skills repo or the docs page gains hillclimb/build-eval (verified 2026-09-11) +- **Baked:** description phrase no · Boundary section yes +- **Budget caveat:** the baked phrase may be dropped from the skill listing under budget pressure. It is the best available routing surface, not a guaranteed one + +### `claude-api` → `playbooks:fable-5` + +- **Verdict:** `complementary`: The playbook's chapters defer every current fact (model ID, price, beta boundary, parameter shape) to the bundled claude-api skill by standing rule, and its API prompt-caching chapter names cost-optimize as the automation for the cost levers it describes. The bundled skill resolves live facts and acts (prompt-audit, cost-optimize, hillclimb edit prompts and configuration when asked); the playbook is operating doctrine and mechanisms that outlive any one price, and performs no work. Neither replaces the other. +- **Native surface:** `claude-api` (bundled skill; markers: none) +- **Our component:** `playbooks:fable-5` (skill) +- **Evidence:** + - binary extraction 2026-09-09 (claude.exe 2.1.263): registerClaudeApiSkill present; subcommand array cost-optimize, migrate, managed-agents-onboard, prompt-audit, upgrade, build-eval, hillclimb + - platform docs claude-api-skill page (fetched 2026-09-09): bundled with Claude Code and published in the open-source skills repository + - reference/model-adaptation/fable-5-1.md standing rule: 'this chapter carries no model ID, price, or limit. Resolve the current details through the claude-api skill at the moment of use' + - reference/prompt-caching.md 'Automation' bullet cites cost-optimize behind the presence gate +- **Observation:** extraction: extracted from binary 2.1.263 at node_modules/@anthropic-ai/claude-code/bin/claude.exe (registerClaudeApiSkill string plus subcommand array); bulk registrar enumeration was broken at this build, so this row's evidence is the targeted extraction, not the inventory JSON (2026-09-09) +- **Recheck trigger:** a Claude Code release changes the bundled claude-api skill's subcommand set or moves it between bundled and marketplace distribution (verified 2026-09-11) +- **Baked:** description phrase no · Boundary section yes +- **Budget caveat:** the baked phrase may be dropped from the skill listing under budget pressure. It is the best available routing surface, not a guaranteed one + +### `code-review` → `review:code-review` + +- **Verdict:** `complementary`: Same object, different invocation surface. The bundled skill is a session-driven review of the current diff or a named PR, with mutating flags (--fix writes the working tree, --comment posts to the PR). review:code-review is a non-interactive CI lane a reusable workflow invokes for one pull request, deliberately scoped out of security when a security lane exists. Neither replaces the other: a CI lane cannot be typed into a session, and the session surface has no workflow contract. +- **Native surface:** `code-review` (bundled skill; markers: none) +- **Our component:** `review:code-review` (skill) +- **Evidence:** + - `code-review` present in the extraction as bundled-skill + - aliases: review + - native description: Review the current diff or a PR for bugs and cleanups + - our description: CI code-review lane for a GitHub pull request. High-signal correctness and maintainability findings only, scoped out of security when a security lane exists + - the review plugin already documents this overlap organically in plugins/review/skills/quality-gate/context/pr.md's Boundary section, naming the bundled command, the marketplace plugin, and the managed service as three distinct surfaces +- **Observation:** extraction: extracted from binary v2.1.232 at node_modules/@anthropic-ai/claude-code/bin/claude.exe (integrity: degraded, counts are floors) (2026-08-23) +- **Recheck trigger:** a Claude Code release changes the bundled `code-review` skill's roster entry, its `review` alias, or its invocation mode. The alias was re-pointed at 2.1.220 and the alias-under-shadowing fix landed at 2.1.233, so this pair has moved twice in one quarter (verified 2026-09-11) +- **Baked:** description phrase no · Boundary section yes +- **Budget caveat:** the baked phrase may be dropped from the skill listing under budget pressure. It is the best available routing surface, not a guaranteed one + +### `design` → `prototype:explore-directions` + +- **Verdict:** `complementary`: explore-directions offers the editable design-canvas Artifact as an explicit alternative to its HTML mockup substrate when the bundled skill is listed with the canvas description, invoking it only on the user's choice and keeping the mockup as the default. The canvas persists under the user's account; the mockup is thrown away once the winning-variant key is captured. Same surface as the visualize row, sibling component; the Boundary section states the split and the presence check, and the description's presence phrasing predates the registry and carries no gate token. +- **Native surface:** `design` (bundled skill; markers: gated) +- **Our component:** `prototype:explore-directions` (skill) +- **Evidence:** + - our description: 'or, where the bundled design skill is available, an editable design-canvas Artifact'; the body's design-canvas subsection offers the canvas before building and the Boundary section states the split, the mutation gate, and the presence check + - string search of the installed binary v2.1.263 (2026-09-11): the canvas skill registers model-invocable and user-invocable with no disableModelInvocation, enabled by a first-party-context check, a rollout flag that defaults on, and an Artifact tool whose schema carries capabilities; a second same-named Claude Design hub registration carries disableModelInvocation true behind an allow_design_sync setting (detail in the sibling visualize row and plugins/prototype/skills/explore-directions/reference/bundled-design.md) + - commands page (2026-09-11) carries a /design row labeled Skill describing the canvas and its gates (artifacts availability, v2.1.234+); the changelog names no design-family surface through v2.1.268 + - prior: binary extraction v2.1.251 (2026-08-31) registered the canvas skill research-preview gated with no model-invocation gate; the 2.1.263 registration matches except that the rollout flag now defaults on +- **Observation:** extraction: targeted string search of the installed binary v2.1.263 at node_modules/@anthropic-ai/claude-code/bin/claude.exe (both design registrations read from the bundle strings), refreshing the v2.1.251 extraction (2026-09-11) +- **Recheck trigger:** a Claude Code release adds a model-invocation gate to the canvas skill, changes either design registration's enablement or subcommand set, merges the two registrations, a release note first names a design-family surface, or the commands-page row stops describing the canvas (verified 2026-09-11) +- **Baked:** description phrase no · Boundary section yes + +### `design` → `visualization:visualize` + +- **Verdict:** `complementary`: visualize's form matrix routes hand-tweakable visual layouts (UI mockups, posters, one-pagers) to the bundled design canvas when it is listed with the canvas description, offered as an explicit alternative and invoked only on the user's choice, with the shadowing check and never-mention-when-absent rule its catalog spoke documents. The canvas is a persistent, versioned, shareable Artifact; this skill's page paths are throwaway or plain-static. The Boundary section states the split, the mutation gate, and the presence check; the catalog spoke carries the surface facts. +- **Native surface:** `design` (bundled skill; markers: gated) +- **Our component:** `visualization:visualize` (skill) +- **Evidence:** + - our SKILL.md step 2: 'a design canvas. Route to a design-canvas capability (the bundled design skill), when available'; the Boundary section states the split and the presence check + - catalog spoke plugins/visualization/skills/visualize/context/decision-matrix.md carries the canvas surface facts with their own verified-on line + - string search of the installed binary v2.1.263 (2026-09-11): the canvas skill registers model-invocable and user-invocable (menu line 'Draft a design on a canvas Artifact, editable where saving is enabled (Claude Design preview)'; description 'Create a design canvas...'; argument hint '[what to design]'; no disableModelInvocation; enabled by a first-party-context check, a rollout flag that defaults on, and an Artifact tool whose schema carries capabilities); it is listed to the model with the canvas description in a first-party session on that build + - string search of the same binary: a second bundled registration named design is a Claude Design hub (menu line 'Work with Claude Design (claude.ai/design): create, import, export, sync, login') with disableModelInvocation true, enabled only behind an allow_design_sync setting, a policy gate, and a feature flag; a local design consent|revoke command beside it; so the listed description is the presence check + - commands page (2026-09-11) carries a /design row labeled Skill describing the canvas (artboards on one canvas published as an artifact running a research preview of Claude Design's editor; requires artifacts availability and v2.1.234+); the artifacts page's 'Draft a design canvas' shows /design ; the changelog names no design-family surface through v2.1.268 + - prior: binary extraction v2.1.251 (2026-08-31) registered the canvas skill with a /design dispatch table and no model-invocation gate, and the rollout flag defaulted off at v2.1.234; the 2.1.263 registration matches except that the flag now defaults on +- **Observation:** extraction: targeted string search of the installed binary v2.1.263 at node_modules/@anthropic-ai/claude-code/bin/claude.exe (both design registrations read from the bundle strings), refreshing the v2.1.251 extraction (2026-09-11) +- **Recheck trigger:** a Claude Code release adds a model-invocation gate to the canvas skill, changes either design registration's enablement or subcommand set, merges the two registrations, a release note first names a design-family surface, or the commands-page row stops describing the canvas (verified 2026-09-11) +- **Baked:** description phrase no · Boundary section yes + +### `design-sync` → `visualization:visualize` + +- **Verdict:** `defer`: Deliberately undetermined. The design-sync family (design-sync skill with disableModelInvocation, hidden design-consent/design-revoke commands managing a durable agent-access grant, design-login credential flow, DesignSync tool) is registered in the binary but documented nowhere through v2.1.251, and no operator of this marketplace uses claude.ai/design design-system projects. Real enough to record next to the canvas integration it ships beside; too thin to rule on, and design-system sync is publishing, not visualization, so no integration text ships anywhere. +- **Native surface:** `design-sync` (bundled skill; markers: hidden, gated) +- **Our component:** `visualization:visualize` (skill) +- **Evidence:** + - binary extraction v2.1.251 (2026-08-31): design-sync registered with disableModelInvocation true; design-consent/design-revoke registered as hidden commands ('Grant/Revoke Claude agent access to your Design projects'); design-login flow strings present + - docs and changelog through v2.1.251 carry none of the four names (checked 2026-08-31) + - no claude.ai/design usage among this marketplace's operators (user-confirmed 2026-09-01) +- **Observation:** extraction: extracted from binary v2.1.251 at node_modules/@anthropic-ai/claude-code/bin/claude.exe (design-family registrations read from the bundle strings) (2026-08-31) +- **Recheck trigger:** a Claude Code release documents any of design-sync/design-consent/design-revoke/design-login, or an operator of this marketplace adopts claude.ai/design design-system projects (verified 2026-09-01) +- **Baked:** description phrase no · Boundary section no + +### `doctor` → `claude-ops:audit-install-state` + +- **Verdict:** `complementary`: Bundled `doctor` is the quick native health-and-fix pass over an installation, and it offers to fix, which puts it outside the read-only contract audit-install-state holds. audit-install-state is the deep read-only inventory of the install tree: every file classified, product-managed retention separated from genuinely unmanaged state, filename schemes resolved before any liveness check, and a deliberate-or-experimental state detected before anything is called stale. Prefer the native pass for a fast check; ours when the question is what is actually in the tree and what nothing manages. +- **Native surface:** `doctor` (bundled skill; markers: gated) +- **Our component:** `claude-ops:audit-install-state` (skill) +- **Evidence:** + - `doctor` present in the extraction as bundled-skill + - markers: gated + - aliases: checkup + - native description: Health-check your setup and fix issues: installation, unused extensions, duplicated or bloated memory files, slow hooks, updates, permissions + - the native surface offers to fix; audit-install-state is report-only by contract and never writes to the target tree + - shared listing budget measured at ~13.0x over the documented 8,000-char default across 153 listing-eligible skills (check-listing-budget.sh, 2026-08-23), so the baked phrase is the best available routing surface, not a guaranteed one +- **Observation:** extraction: extracted from binary v2.1.232 at node_modules/@anthropic-ai/claude-code/bin/claude.exe (integrity: degraded, counts are floors) (2026-08-23) +- **Recheck trigger:** a Claude Code release changes `/doctor`'s status as a bundled skill or its gating switch. It became a bundled skill at 2.1.205, which retargeted DISABLE_DOCTOR_COMMAND, and it is the one bundled skill `disableBundledSkills` does not remove (verified 2026-08-23) +- **Baked:** description phrase yes · Boundary section yes +- **Budget caveat:** the baked phrase may be dropped from the skill listing under budget pressure. It is the best available routing surface, not a guaranteed one + +### `doctor` → `claude-ops:audit-performance` + +- **Verdict:** `complementary`: Same native surface, a different one of our lanes. audit-performance is a timed diagnostic capture taken at the moment something feels slow: CLI version, retention-sweep health, a timed stat-walk standing in for the product's own sweep cost, session and plugin-fleet counts, and a process census, all interpreted against a bundled known-issues reference. Bundled `doctor` reports health and offers fixes; it does not capture a timed slowness profile. Registry-row only: the routing line for this pair lives on audit-install-state, which owns the shared surface description for the plugin. +- **Native surface:** `doctor` (bundled skill; markers: gated) +- **Our component:** `claude-ops:audit-performance` (skill) +- **Evidence:** + - `doctor` present in the extraction as bundled-skill + - markers: gated + - native description: Health-check your setup and fix issues: installation, unused extensions, duplicated or bloated memory files, slow hooks, updates, permissions + - our description: read-only slowness-diagnostic capture run AT THE MOMENT the machine or a session feels slow, before restarting or deleting anything +- **Observation:** extraction: extracted from binary v2.1.232 at node_modules/@anthropic-ai/claude-code/bin/claude.exe (integrity: degraded, counts are floors) (2026-08-23) +- **Recheck trigger:** a Claude Code release gives `/doctor` a timed or profiling mode, or changes its status as a bundled skill (verified 2026-09-11) +- **Baked:** description phrase no · Boundary section yes +- **Budget caveat:** the baked phrase may be dropped from the skill listing under budget pressure. It is the best available routing surface, not a guaranteed one + +### `doctor` → `claude-ops:audit-skill-visibility` + +- **Verdict:** `complementary`: Same native surface as the two sibling rows, a third of our lanes. Bundled `doctor` ships a one-shot check (its Check 1) that groups unused skills, MCP servers, and plugins against their context cost, labels each group with a token-savings estimate, and offers to disable the selected groups. audit-skill-visibility answers a different question, why a skill is unseen: it reconciles three usage sources (native ~/.claude.json counters, its own JSONL store, OTEL) under a max-across-sources rule, computes an observed horizon and withholds every verdict the span cannot support, diagnoses reachability causes, and analyses listing-budget starvation. It disables nothing by contract. The skill's own description and Scope boundary already route the one-shot unused-versus-context-cost question to the native surface; this row records that routing in the store rather than replacing it. +- **Native surface:** `doctor` (bundled skill; markers: gated) +- **Our component:** `claude-ops:audit-skill-visibility` (skill) +- **Evidence:** + - `doctor` present in the 2026-08-23 extraction as bundled-skill (markers: gated; aliases: checkup), per the two sibling rows + - the shipped doctor skill carries a check titled 'Check 1: unused skills, MCP servers, and plugins' whose prompt groups unused components, labels each group with a benefit estimate ('37 unused skills, saves ~2.2k est. tokens/session'), and applies only the groups the user selects; confirmed by string search of the installed v2.1.252 binary on 2026-08-31 + - our description: audit whether each installed skill is actually VISIBLE to the model; reconciles native counters, a JSONL store, and OTEL; withholds every verdict the data cannot support; read-only, never disables, deletes, or edits a skill + - our description's Not-for clause and the SKILL.md Scope boundary table both already name the native surface ('Claude Code ships that in /doctor and the Stats tab') with no store row behind them until this one; a prose disclaimer without a store row is the drift this registry exists to catch + - recheck trigger fired 2026-09-04 and is discharged as of 2026-09-07: /skill-doctor now has its own row in this store, pinned to the upstream commit that added it, so this row is scoped back to /doctor alone and no longer stands in for two surfaces + - this row's routing survives the split: the /doctor row of https://code.claude.com/docs/en/commands.md still credits the bundled doctor skill with finding 'unused skills, MCP servers, and plugins versus their context cost' inside its setup checkup, so the deferral recorded here is to a surface that still does the job (read 2026-09-07) +- **Observation:** extraction: targeted string search of the installed binary v2.1.252 (doctor Check 1 strings confirmed; a spot observation over the sibling rows' full v2.1.232 extraction, not a re-extraction) (2026-08-31) +- **Recheck trigger:** a Claude Code release changes doctor's unused-components check (Check 1's grouping, its disable offer, or its benefit estimate), gives it a multi-source reconciliation or observation-horizon discipline, or changes /doctor's status as a bundled skill or its gating switch (verified 2026-09-11) +- **Baked:** description phrase yes · Boundary section yes +- **Budget caveat:** the baked phrase may be dropped from the skill listing under budget pressure. It is the best available routing surface, not a guaranteed one + +### `run` → `testing:run-e2e` + +- **Verdict:** `complementary`: The bundled skill answers 'did this change work when I ran the app'; run-e2e drives named UI and API flows, captures evidence (screenshots, responses, logs), and carries a non-UI smoke playbook for libraries, MCP servers, hooks, and scripts, none of which have an app to launch. Prefer the native surface for the quick look; ours where the verification has to be reproducible or the target is not an app. +- **Native surface:** `run` (bundled skill; markers: none) +- **Our component:** `testing:run-e2e` (skill) +- **Evidence:** + - `run` present in the extraction as bundled-skill + - native description: Launch this project's app to see your change working + - our description: End-to-end live app verification. Check prerequisites, start the app, drive UI/API flows, and capture evidence; includes a non-UI smoke-test playbook + - the non-UI smoke lane has no native counterpart in this extraction +- **Observation:** extraction: extracted from binary v2.1.232 at node_modules/@anthropic-ai/claude-code/bin/claude.exe (integrity: degraded, counts are floors) (2026-08-23) +- **Recheck trigger:** a Claude Code release changes the bundled `run` skill's roster entry or invocation mode, or gives it an evidence-capture or non-app target mode (verified 2026-09-11) +- **Baked:** description phrase no · Boundary section yes +- **Budget caveat:** the baked phrase may be dropped from the skill listing under budget pressure. It is the best available routing surface, not a guaranteed one + +### `simplify` → `code-tidying:batch-simplify` + +- **Verdict:** `complementary`: Scale is the whole difference. The bundled skill handles the change in front of it; batch-simplify fans the same job across a time- or branch-scoped window of changed files, grouped by ecosystem and dependency order, for the catch-up case after a multi-session sprint. Its description already sends single-file cleanup to the native surface. +- **Native surface:** `simplify` (bundled skill; markers: none) +- **Our component:** `code-tidying:batch-simplify` (skill) +- **Evidence:** + - `simplify` present in the extraction as bundled-skill + - native description: Clean up the changed code without changing behavior + - our description already carries `Skip for single-file cleanup. Use /simplify instead` + - seeded rationale: same cleanup job at batch scale across many files +- **Observation:** extraction: extracted from binary v2.1.232 at node_modules/@anthropic-ai/claude-code/bin/claude.exe (integrity: degraded, counts are floors) (2026-08-23) +- **Recheck trigger:** a Claude Code release gives the bundled `simplify` skill a time-window argument form, a repository mode, or ecosystem grouping (the multi-file half of this trigger fired by 2026-09-11: the skill accepts a path or PR reference target, so the remaining distinction is the sweep discipline, recorded in the skill's context/bundled-simplify.md) (verified 2026-09-11) +- **Baked:** description phrase no · Boundary section yes +- **Budget caveat:** the baked phrase may be dropped from the skill listing under budget pressure. It is the best available routing surface, not a guaranteed one + +### `simplify` → `code-tidying:tidy` + +- **Verdict:** `complementary`: Different trigger, not a different job. The bundled skill refines the code a change already touched; tidy proactively hunts unfiled structural drift across a rotated, glob-scoped lane and ships one structure-only PR per invocation. tidy's own description already routes current-diff work away to the native surface, which is the routing this row records rather than replaces. +- **Native surface:** `simplify` (bundled skill; markers: none) +- **Our component:** `code-tidying:tidy` (skill) +- **Evidence:** + - `simplify` present in the extraction as bundled-skill + - native description: Clean up the changed code without changing behavior + - our description already carries `Skip when: /simplify refines the current diff` + - seeded rationale: both clean up code without changing behavior +- **Observation:** extraction: extracted from binary v2.1.232 at node_modules/@anthropic-ai/claude-code/bin/claude.exe (integrity: degraded, counts are floors) (2026-08-23) +- **Recheck trigger:** a Claude Code release adds, removes, or changes the invocation mode of the bundled `simplify` skill, or the skill gains a lane-scoped mode that overlaps tidy's proactive hunt (verified 2026-09-11) +- **Baked:** description phrase no · Boundary section yes +- **Budget caveat:** the baked phrase may be dropped from the skill listing under budget pressure. It is the best available routing surface, not a guaranteed one + +## Plugin-backed built-ins + +### `security-review` → `review:security-review` + +- **Verdict:** `complementary`: The native side is not a bundled skill at all. The extraction reports it under `plugin_backed`, backed by the `security-review` plugin, and it runs in-session over the change at hand. review:security-review is the CI lane a reusable workflow invokes for a pull request, targeting logic, trust-boundary, and Actions findings static analysis misses. Reading the wrong extraction key is the failure this row exists to prevent: under `builtin_commands` the surface looks absent. +- **Native surface:** `security-review` (plugin-backed built-in; markers: none) +- **Our component:** `review:security-review` (skill) +- **Evidence:** + - `security-review` present in the extraction as plugin-backed-builtin + - the extraction's `plugin_backed` map reports {"security-review": "security-review"}; the name appears in neither `builtin_commands` nor `bundled_skills` + - our description: CI security-review lane for a GitHub pull request. Logic, trust-boundary, and Actions security findings static analysis misses +- **Observation:** extraction: extracted from binary v2.1.232 at node_modules/@anthropic-ai/claude-code/bin/claude.exe (integrity: degraded, counts are floors) (2026-08-23) +- **Recheck trigger:** an extraction stops reporting `security-review` under `plugin_backed`: it moves into the bundled-skill or built-in-command lane, or its backing plugin name changes (re-verified 2026-09-11: the installed 2.1.263 binary registers it plugin-backed and the commands page gives the row no Skill label; the skill's reference/bundled-security-review.md carries the record) (verified 2026-09-11) +- **Baked:** description phrase no · Boundary section yes +- **Budget caveat:** the baked phrase may be dropped from the skill listing under budget pressure. It is the best available routing surface, not a guaranteed one + +## Session-provided skills (observation-only) + +### `morning` → `claude-ops:morning-brief` + +- **Verdict:** `defer`: Undetermined, and deliberately so. `morning` was observed in a session roster, not in any binary extraction, so the only evidence available is one environment's roster on one day, not a basis for a routing line shipped to every consumer. The overlap is real enough to record and too thin to rule on: nothing is known about what the session-provided skill reads, whether it is gh-based, or whether it exists outside the surface it was seen on. Observation-only, never baked, until an in-session capture protocol exists. +- **Native surface:** `morning` (session-provided skill; markers: none) +- **Our component:** `claude-ops:morning-brief` (skill) +- **Evidence:** + - `morning` is absent from this extraction. Absence from the extraction is a statement about the extraction, not the product + - observed in this repository's cloud session roster on 2026-08-23, alongside other session-provided skills (docx, pdf, pptx, xlsx, design, artifact-*) that the local-CLI bundled roster does not carry + - our description: prints the operator's read-only morning view for the current GitHub repo in one pass: queue-label counts, merge-ready PRs, parked decisions, loop-lane telemetry freshness +- **Observation:** live-roster: observed in a Claude Code cloud session's own skill roster; one environment, one day, no second observation (2026-08-23) +- **Recheck trigger:** an in-session roster capture protocol lands and can observe this surface repeatably, or `morning` appears in a binary extraction's bundled-skill set (verified 2026-08-23) +- **Baked:** description phrase no · Boundary section no + +## First-party marketplace plugins + +### `playground` → `prototype:explore-directions` + +- **Verdict:** `complementary`: Both produce a browser page with switchable controls, which is why the pair needs a recorded boundary: explore-directions varies YOUR PROJECT'S own UI (real header, real data, real routes) so you can pick a direction and throw the rest away, while a playground explores an arbitrary parameter space and hands back a prompt. Its description now routes the explorer shape to the playground skill via the playgrounds wrapper. +- **Native surface:** `playground` (first-party marketplace plugin; markers: none) +- **Our component:** `prototype:explore-directions` (skill) +- **Evidence:** + - upstream SKILL.md read at commit ed404106fcd80ba98ecb7c851e531dcb626d13b7: 'especially when the input space is large, visual, or structural and hard to express as plain text' + - our description: builds throwaway UI variations, several radically different visual layouts on one route, switchable from a floating control bar + - the baked routing clause carries the marketplace parity token so fleet parity traces it to this row + - corpus slice: 27-resource verified map (2026-08-31) +- **Observation:** upstream-source: anthropics/claude-plugins-official at commit ed404106fcd80ba98ecb7c851e531dcb626d13b7 (HEAD of main, re-verified by fetch 2026-09-01) (2026-09-01) +- **Recheck trigger:** the upstream repository's default branch moves past the pinned commit with changes under plugins/playground, or the playground plugin is renamed, removed, or absorbed into the CLI as a bundled skill (verified 2026-09-01) +- **Baked:** description phrase yes · Boundary section no +- **Budget caveat:** the baked phrase may be dropped from the skill listing under budget pressure. It is the best available routing surface, not a guaranteed one + +### `playground` → `visualization:visualize` + +- **Verdict:** `complementary`: visualize decides the best visual FORM for conversation content and renders it; the first-party playground skill builds an interactive parameter explorer whose output returns as a prompt. The shapes meet only at 'show me this visually', so visualize's Boundary section routes explorer-shaped requests out (to the playground skill, or the playgrounds wrapper which owns install uplift and cloud delivery) and keeps every static form for itself. +- **Native surface:** `playground` (first-party marketplace plugin; markers: none) +- **Our component:** `visualization:visualize` (skill) +- **Evidence:** + - upstream SKILL.md (plugins/playground/skills/playground/SKILL.md) read at commit ed404106fcd80ba98ecb7c851e531dcb626d13b7: 'interactive controls on one side, a live preview on the other, and a prompt output at the bottom with a copy button' + - our description: decide the best visual FORM and MEDIUM for what is in the conversation right now, then render it + - the wrapper plugin `playgrounds` declares the cross-marketplace dependency and carries the install uplift, so the Boundary route has a landing surface in this marketplace + - corpus slice: 27-resource verified map of the announcement article, plugin source, and implicated docs (2026-08-31) +- **Observation:** upstream-source: anthropics/claude-plugins-official at commit ed404106fcd80ba98ecb7c851e531dcb626d13b7 (HEAD of main, re-verified by fetch 2026-09-01) (2026-09-01) +- **Recheck trigger:** the upstream repository's default branch moves past the pinned commit with changes under plugins/playground, or the playground plugin is renamed, removed, or absorbed into the CLI as a bundled skill (verified 2026-09-01) +- **Baked:** description phrase no · Boundary section yes + + diff --git a/plugins/review/.claude-plugin/plugin.json b/plugins/review/.claude-plugin/plugin.json index dc271f1c69..fc5022ea2b 100644 --- a/plugins/review/.claude-plugin/plugin.json +++ b/plugins/review/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "review", - "version": "0.33.0", + "version": "0.33.1", "description": "Code-review toolkit: six reviewer agents, read-only over the reviewed code (code, security, architecture, doc drift, build/test/lint, CI-log audit), plus orchestration skills for the quality gate, fan-out, and enforceability audit (/review:audit-enforceability), an offered HTML pull-request explainer (/review:pr-explainer), and CI lane commands (/review:code-review, /review:security-review) for org reusable workflows.", "author": { "name": "Melodic Software", diff --git a/plugins/review/CHANGELOG.md b/plugins/review/CHANGELOG.md index 7ad680d7a6..2a188fc1a0 100644 --- a/plugins/review/CHANGELOG.md +++ b/plugins/review/CHANGELOG.md @@ -3,6 +3,12 @@ All notable changes to the `review` plugin are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); this plugin uses semantic versioning. +## [0.33.1] - 2026-09-27 + +### Changed + +- `quality-gate`'s `self` and `downstream` dispatch policies say "must not" instead of "MUST NOT". The producing main thread still never runs the checklist or the downstream steps inline, for the reason each line already gives (#4120). + ## [0.33.0] - 2026-09-28 ### Security diff --git a/plugins/songwriting/.claude-plugin/plugin.json b/plugins/songwriting/.claude-plugin/plugin.json index 55ba74165f..ce9c78e3af 100644 --- a/plugins/songwriting/.claude-plugin/plugin.json +++ b/plugins/songwriting/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "songwriting", - "version": "1.4.35", + "version": "1.4.36", "description": "Songwriting craft companion: nine concern-scoped lyric-craft skills (workflow router, rhyme, object-writing, metaphor, meter-prosody, song-form, co-write, diagnose, practice) applying Pat Pattison's methods, with an object-writing agent that performs the sensory exercise itself and per-skill emission boundaries that route generation to the skill that owns it, plus Suno v5.5 prompt engineering (style prompts, tagged lyrics, genre templates, troubleshooting).", "author": { "name": "Melodic Software", diff --git a/plugins/songwriting/CHANGELOG.md b/plugins/songwriting/CHANGELOG.md index 5a626c51f9..3084dcf116 100644 --- a/plugins/songwriting/CHANGELOG.md +++ b/plugins/songwriting/CHANGELOG.md @@ -3,6 +3,12 @@ All notable changes to the `songwriting` plugin are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); this plugin uses semantic versioning. +## [1.4.36] - 2026-09-27 + +### Changed + +- Seven skills (`co-write`, `diagnose`, `metaphor`, `meter-prosody`, `object-writing`, `rhyme`, `song-form`) label their response-filter step "Pre-flight:" instead of "Pre-flight ALWAYS:". The step still runs before output (#4120). + ## [1.4.35] - 2026-09-28 ### Added diff --git a/plugins/source-control/.claude-plugin/plugin.json b/plugins/source-control/.claude-plugin/plugin.json index 4b74cfd700..964198620d 100644 --- a/plugins/source-control/.claude-plugin/plugin.json +++ b/plugins/source-control/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "source-control", - "version": "0.62.8", + "version": "0.62.9", "description": "Git and GitHub delivery workflow: /commit (Conventional Commits + Co-authored-by trailer via safe heredoc mechanics), /pull-request (prep, create, CI monitoring, review-comment triage, merge, CI-log fetch), /babysit-prs (self-pacing fleet loop, safe by default; opt-in worker/autopilot tiers add gate-checked merge and thread resolution behind a deterministic Python engine), /babysit-loop (the loop-lane merge lane: a standing or drain loop that invokes babysit-prs per cycle, configured through repo-scoped babysit_loop_* keys on the layered source-control.md seam, with merge authority human-only until the target repo's tracked config adopts the lane, a gate-proven C2-mechanical baseline once adopted, and standing merge-rung raises binding from the team-tracked layer only, with one named exception, where an invocation line explicitly typing both the autopilot tier keyword and the dedicated raise argument --merge c3-this-run widens that single invocation's merge authority up to C3 behind a fresh independent frontier-tier resolver, while C4-structural and C5-untrusted-provenance stay unconditionally human-merge), /worktree (create, status, cleanup, audit for parallel-session isolation), /setup (check the effective commit-subject / PR-title convention merged across its config layers and the babysit-prs config, or apply, which interviews the repo and writes the convention config to a chosen layer), and /resolve-conflicts (intent-first merge/rebase conflict resolution with a semantic-conflict sweep, never --abort). The commit-subject / PR-title convention is configurable via a source-control.md config written by a re-runnable setup skill, layered across a ~/.claude user-global file, the tracked team file, and a gitignored .claude/source-control.local.md personal overlay merged per key; Conventional Commits is the default when no convention is declared.", "author": { "name": "Melodic Software", diff --git a/plugins/source-control/CHANGELOG.md b/plugins/source-control/CHANGELOG.md index 6d9f39dc3c..6f144df634 100644 --- a/plugins/source-control/CHANGELOG.md +++ b/plugins/source-control/CHANGELOG.md @@ -3,6 +3,13 @@ All notable changes to the `source-control` plugin are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); this plugin uses semantic versioning. +## [0.62.9] - 2026-09-27 + +### Changed + +- `pull-request` says the Monitor checks the push channel first, then falls back, and `monitor.md` says every monitor invocation ensures a session-persistent event watch, both without "MUST"/"FIRST" caps. The order and the idempotent watch step are unchanged (#4120). +- `babysit-prs`'s loop reference points at the subagent dispatch for ≥3-finding comments without the "MANDATORY" marker; the rule in `review-discipline.md` §2 is unchanged (#4120). + ## [0.62.8] - 2026-09-28 ### Changed