diff --git a/plugins/overengineering/.claude-plugin/plugin.json b/plugins/overengineering/.claude-plugin/plugin.json index f6958413e3..ad3d5289dc 100644 --- a/plugins/overengineering/.claude-plugin/plugin.json +++ b/plugins/overengineering/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "overengineering", - "version": "0.4.14", + "version": "0.4.15", "description": "Evidence-earned-keep audit of an existing enforcement surface, covering agent hooks and standing instructions, repository and version-control hooks, CI lanes and gate scripts, branch protections, forge apps, and declared external integrations. It treats every incumbent mechanism as a retirement candidate until empirical evidence earns its keep, argues every verdict in cost of carry, caps retirement-direction verdicts on security-class artifacts at FLAG-FOR-HUMAN, and realigns to the simplest adequate solution behind an explicit per-item human gate. The audit is read-only and emits a diffable findings artifact; realignment is a separate, explicitly invoked skill; and a third read-only lane re-runs the audit on whatever cadence the consumer wires and reports only what moved since the last run, above a configurable noise budget. A justification lane applies the same method to whatever single artifact you point at, a decision record, a document, a component, a dependency, or a code construct, asking whether a reason existed for it and whether that reason still holds, and reporting how much evidence each verdict actually rests on.", "author": { "name": "Melodic Software", diff --git a/plugins/overengineering/CHANGELOG.md b/plugins/overengineering/CHANGELOG.md index 563f655144..8977a4f82d 100644 --- a/plugins/overengineering/CHANGELOG.md +++ b/plugins/overengineering/CHANGELOG.md @@ -3,6 +3,12 @@ All notable changes to the `overengineering` plugin are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); this plugin uses semantic versioning. +## [0.4.15] - 2026-09-28 + +### Changed + +- **`audit` report groups out-of-repo findings by owner** ([#4596](https://github.com/melodic-software/claude-code-plugins/issues/4596)). The inline report lists in-repo findings first and in full, then one summary row per out-of-repo owner (count, verdict mix, pointer to the artifact). Finding ids and artifact rows are unchanged. #4597 already scoped the playbooks repo-sweep entry off the four org-level layers; a direct audit still walks every settings scope, so this is a report view, not a walk filter. Eval 13 covers the rollup. + ## [0.4.14] - 2026-09-27 ### Fixed diff --git a/plugins/overengineering/skills/audit/SKILL.md b/plugins/overengineering/skills/audit/SKILL.md index 38fab7d870..e519a533fc 100644 --- a/plugins/overengineering/skills/audit/SKILL.md +++ b/plugins/overengineering/skills/audit/SKILL.md @@ -121,6 +121,16 @@ Parse `$ARGUMENTS`: - Anything else, a free-text focus hint (a path, a mechanism name). Narrow attention with it; it does not change the layer scope, and a hint that matches nothing is reported, not silently dropped. +The inline report groups by custody: in-repo findings first and in full; out-of-repo findings +(user- and machine-scope settings, plugin hook manifests owned upstream) as one summary row per +owner. The findings artifact is unchanged. See +[context/report-template.md](context/report-template.md) "Custody grouping". +**Claim:** the walk still covers every settings scope; only the inline report groups out-of-repo +findings per owner. **Basis:** issue #4596 after #4597 scoped the playbooks repo-sweep entry off +the four org-level layers; a direct `/overengineering:audit` still walks every harness-merged +scope. **As of:** 2026-09-28. **Recheck:** when this skill gains a custody-scope argument or stops +walking user or machine settings. + ## Before the walk 1. **Resolve the branch identity, then the artifact home.** The branch call above yields a branch diff --git a/plugins/overengineering/skills/audit/context/report-template.md b/plugins/overengineering/skills/audit/context/report-template.md index 6566bf969b..005b7fff52 100644 --- a/plugins/overengineering/skills/audit/context/report-template.md +++ b/plugins/overengineering/skills/audit/context/report-template.md @@ -70,6 +70,19 @@ it. Cap the inline list **only when the artifact was written**; the artifact carries the rest. When no branch identity resolved and this summary is the only record, emit **every** finding inline. A cap here would discard the tail of a scheduled detached run. + **Custody grouping (report view only).** In-repo findings render first, in full. Findings whose + custody is out-of-repo (a `settings:` identifier outside the tree, a user- or machine-scope + plugin hook manifest the repo does not own) collapse to **one summary row per owner**: the + owning plugin, marketplace, or settings scope, the count of findings, the verdict mix, and a + pointer to the underlying artifact rows. Artifact rows and finding ids are unchanged; only this + view groups them. #4597 scoped the playbooks `repo-sweep` hygiene entry off the four org-level + layers; a direct `/overengineering:audit` still walks every settings scope the harness merges, + so this grouping is what keeps those rows from burying the in-repo list. + **Claim:** a custody *filter* is declined; the walk stays complete and only the inline report + groups by owner. **Basis:** #4597 already took the org-level layers off the repo-sweep entry; + a walk filter would hide user- and machine-scope incumbents this skill still has to name + (§12). **As of:** 2026-09-28. **Recheck:** when a consumer-config key scopes the walk itself, + or when the harness stops merging user and machine settings into a repo session. 5. **The proposed ablation batch**, when one was produced: its items, an owner and a re-check date each, and the observation window's end date. 6. **Open checkpoints**: the intent questions awaiting an answer (attended), or the count of diff --git a/plugins/overengineering/skills/audit/evals/evals.json b/plugins/overengineering/skills/audit/evals/evals.json index 92d7e62d92..e404d415c3 100644 --- a/plugins/overengineering/skills/audit/evals/evals.json +++ b/plugins/overengineering/skills/audit/evals/evals.json @@ -169,6 +169,20 @@ "Writes a checkpoint through that route after each completed layer, re-reading and merging first, with scope naming only the layers completed so far", "Never uses a shell content-write for the artifact" ] + }, + { + "id": 13, + "name": "out-of-repo-findings-rollup-per-owner-in-the-report", + "prompt": "/overengineering:audit — this is a 37-file repo. Walk everything; I need the report, not a filter.", + "expected_output": "Walks every settings scope the harness merges, including user and machine, and writes one artifact row per plugin hook manifest as before. The inline report lists in-repo findings first, in full. Out-of-repo findings (user-scope plugin hook manifests owned upstream, ~/.claude/settings.json, machine-scope settings) collapse to one summary row per owner: count, verdict mix, and a pointer at the artifact rows. Finding ids in the artifact are identical to a run without the rollup. It does not add a custody=repo argument and does not skip out-of-repo layers.", + "files": [], + "narration": true, + "expectations": [ + "Renders in-repo findings before any out-of-repo content in the inline report", + "Gives each out-of-repo owner at most one row in the report (count, verdict mix, pointer to artifact rows)", + "Leaves the findings artifact rows and finding ids unchanged", + "Does not skip out-of-repo layers and does not introduce a custody-scope argument" + ] } ] }