feat(claude-config): fence I6 gate set and per-spoke I33 (#4115) - #4850
Conversation
7995535 to
3970ad0
Compare
…4115) Adopt the measured I6 pre-scan gates (sentence-open prohibition, paired positive, rationale, structural exclusions) and report I33 one finding per spoke with excerpt anchors and a per-plugin roll-up. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
3970ad0 to
1f7584e
Compare
# Conflicts: # plugins/claude-config/.claude-plugin/plugin.json # plugins/claude-config/CHANGELOG.md
…ne cap (#4115) Moves the I33 roll-up layout to context/execution-and-report.md and the lane-brief fence note to the I33 catalog row; SKILL.md points at both. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PT4esxbdC7eQiwQxy35Mie
…o 1.24.0 A fence line carrying an info string no longer closes an open fence, and blockquoted fences are recognized, so code after a pseudo-close is not seeded and prose after the real closer is. The scanner header and the CHANGELOG state why audit-noise's hard-guardrail carve-out is not adopted and name the file set behind the 6,608 -> 913 count. criteria.md moves to 1.24.0 for the I6 Detect and I33 Reporting edits (#4115). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Hx63mvV8t39y644DQ3uLnn
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Claude finished @kyle-sexton's task in 1m 6s —— View job Security review
Reviewed all 13 changed files ( No security issues found. This PR is confined to the
The doc/fixture/changelog changes carry no logic that touches secrets, auth, or external I/O. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ed89be7ecb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Claude finished @kyle-sexton's task in 5m 14s —— View job Review complete
Ran the code-review lane against this PR's diff ( 1 finding, posted inline on I6's new emphasis-marker stripping only works for I did not find other functional bugs in the fence-closing, sentence-splitting, soft-wrap-join, or paired-positive/ Out of scope for this lane: security findings (none observed) and the open AC2 item the PR body already flags (five previously-retained findings not recorded anywhere) — that's a process/tracking gap on issue #4115, not a code defect in this diff. |
…ad underscore emphasis A line opening two bare prohibitions now yields one I6 row, so --count and --i6-counts no longer double it. A setext underline drops the pending paragraph as a heading, except after a list item or blockquote, where --- is a thematic break. An underscore after the cue now counts as a boundary, so _Never_ and __Do not__ reach the sentence gate (#4115). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… (#4851) Closes #4116 ## Summary Give every `audit-instructions` finding a stable `audit-pass` identity, and persist I30–I33 from the lane. Deviation from #4116: the issue says a lane-sourced finding's confidence is fixed to `high` because "a deterministic detector still fired". No scanner produces I30–I33, so that premise does not hold; lane rows leave `Confidence` blank instead of claiming a detector confidence. ## Fix - Identity is `(check, claim, sites)`: `check` is `claude-config/audit-instructions/<id>`, claims live in `reference/finding-identity.md`, anchors are `anchor/v1` excerpts with the heading-path discriminator, and an I15 conflict is one finding with two sites. - `scripts/finding-ids.sh` derives `finding_id/v1` and `group/v1` through `audit-pass`'s `finding-identity.sh`. - `emit-findings.sh --from-lane` emits I30–I33 (detector-findings 3.2.0 crosswalk). I32 in frontmatter and I31/I33 outside a spoke are declined with a named reason. Phase D table gains a Finding ID column. - Rows that share a `finding_id` are emitted once, with an `Identity collisions: finding_id=<id> count=<n>` line under `## Surfaces`, per the audit-pass identity contract. - The I32 fallback target matches only `/plugin:skill` or a backticked `plugin:skill`; anything else reports `shape=`. - detector-findings README adopter row states the I30–I33 tier spread. - Version 0.51.27 with CHANGELOG. ## Verification - `finding-ids.test.sh`: 28 passed (a new case proves a fenced `## not a heading` is not in the heading path). - `emit-findings.test.sh`: 170 passed (new Case 16: identical lines collide to one row with `count=2`; `10:30` yields `shape=`). - `scripts/check-detector-findings-crosswalk.sh`, `scripts/validate-plugins.sh`, `scripts/check-changelog-parity.sh --check --check-order`, `scripts/check-changed-skills.sh origin/main`: pass. ## Related - `docs/conventions/detector-findings` 3.2.0. - I6/I33 fences are #4115 (PR #4850). - Follow-up outside this plugin: `plugins/review/skills/audit-enforceability/context/crosswalk.md` has no exact rows for the four new lane rules, so they fall to the `claude-config/audit-instructions/` family row ("already deterministic"). 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01Hx63mvV8t39y644DQ3uLnn --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 1m 24s —— View job Security review
Reviewed the full diff ( No security issues found. Checked specifically:
The 🤖 Generated with Claude Code |
|
Claude finished @kyle-sexton's task in 5m 23s —— View job Review complete
Ran the CI code-review lane ( Since the last review of this PR (commit
I traced that fix commit by hand against the current Fixing the underscore-emphasis case widened the I did not find other functional issues after tracing the fence-closing, Setext-heading, and per-line-dedup logic by hand — those three fixes look correct for the cases they target. I33's changes in this PR are documentation/process only (no scanner code), so out of scope for a code-correctness pass. |
…ke_case `_` after a cue counts as a boundary only when a non-word character or the end follows it, so `_Never_` still reads and `never_delete_flag` does not. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 48s —— View job Security review
No security issues found. This PR remains confined to the Since the last successful security review of this PR (
Re-confirmed the invariants from the prior passes on this PR:
|
|
Claude finished @kyle-sexton's task in 3m 52s —— View job Code review complete
Reviewed the current head ( No new findings. This is the fourth review pass on this PR; the prior three rounds (Codex + this lane) found four real issues, and all four are now fixed on this head:
I traced fix #4 by hand against the new
I could not execute One thing I noticed but am not flagging as a defect: the The I33 changes in this PR are documentation/process only ( |
No related issue: partial delivery of #4115; its AC2 (five previously-retained findings still seed) cannot be verified because those five findings are not recorded anywhere, so #4115 stays open for that check.
Summary
Refs #4115. Fence the I6 pre-scan to the docs-hygiene
rule-negation-without-positivegate set (minus its hard-guardrail carve-out), and report I33 as one finding per spoke with an opener-sentence excerpt anchor.Fix
--i6-countsprints raw and surviving counts.criteria.mdcatalog 1.24.0. Four fixtures plus evals 27 and 28.Verification
instruction-scan.test.sh139/139 (Case 3f: fence closing; Case 3g: one row per line, Setext headings skipped, underscore-emphasized cues read),emit-findings.test.sh172/172,finding-ids.test.sh29/29,lane-runs.test.sh52/52.2dfaaa40(990 files) printsI6 raw=6608 surviving=913:find . -name '*.md' -not -path './.git/*' \( -path './plugins/*/skills/*' -o -path './plugins/*/agents/*' -o -path './.claude/*' -o -name CLAUDE.md -o -name AGENTS.md \) -print0 | sort -z | xargs -0 bash plugins/claude-config/skills/audit-instructions/scripts/instruction-scan.sh --i6-countsscripts/validate-plugins.sh,scripts/check-changelog-parity.sh --check --check-order,scripts/check-changed-skills.sh origin/main: pass.Never commit files, logs, or caches.) reads as a named alternative, as in audit-noise.Related
🤖 Generated with Claude Code