Skip to content

feat(skills): argument-hint house style, gate, and fleet rewrite (#3542) - #5042

Merged
kyle-sexton merged 18 commits into
mainfrom
cursor/3542-argument-hint-hygiene-37e9
Sep 29, 2026
Merged

kyle-sexton merged 18 commits into
mainfrom
cursor/3542-argument-hint-hygiene-37e9

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Closes #3542

Summary

Adds a house style for the argument-hint frontmatter key, enforces it in the fleet contract validator, and brings every over-budget or malformed hint in the fleet into line. The six concrete fixes from the original issue body had already landed on main; this PR does the rescoped work from the triage brief.

Fix

  • Owner doc: docs/conventions/argument-hint/README.md (with CHANGELOG.md, 1.0.0) states the style: a 100-character budget counted in code points, [optional] and <required> slots, a spaced | between top-level alternatives, and no em dash, parenthetical example, or Default: prose. A skill with no arguments omits the key. The convention registry in docs/plugin-philosophy.md and the skill-authoring playbook point at it without restating it.
  • Gate: scripts/validate-plugin-contracts.mjs fails an empty hint. It warns, without failing, on a hint that is over budget, a block scalar, or malformed. Each message names the owner doc.
  • Tests: scripts/validate-plugin-contracts.test.sh covers conforming, empty, over budget (101 characters, with 100 as the boundary), and each malformed shape. It also asserts that the shipping tree draws zero warnings, so hint drift fails CI even though the validator only warns.
  • Fleet rewrite: 108 hints across 38 plugins are shortened to grammar. The examples, defaults, and flag catalogs they carried move into each skill body as an **Arguments.** line (for audit-instructions, into its existing Arguments section); none is deleted. All 39 touched plugins, playbooks included, are bumped above main with a CHANGELOG entry.
  • Branch repair: the two earlier commits had overwritten validate-plugin-contracts.mjs, its test, and the prd, workflow, and clean SKILL.md files with other files' contents. A later merge had also reverted main's context-budget audit body. Those files are restored from main, and only the intended hint edits are re-applied.
  • Second main merge: every touched SKILL.md was rebuilt from main so it differs only in its hint and the **Arguments.** line; audit-instructions also keeps its full-form sentence and skill-authoring keeps its pointer paragraph. Four hints that main had changed since the branch point (discovery:research, repo-fleet-hygiene audit and setup, skill-quality:check) are rewritten to the style, with main's full forms in the Arguments line. All 39 plugins are re-bumped one patch above main.
  • Third main merge (after docs(conventions): define the skill argument shape (#4001) #4768 and feat(repo-fleet-hygiene): sync canonical checkouts to default branch (#3992) #5129): docs(conventions): define the skill argument shape (#4001) #4768 landed docs/conventions/skill-argument-shape/, which owns argument order and notation. The two docs now split scope: the shape doc keeps order, flags, and notation and points here for the hint string's budget and punctuation; this doc's "What this convention is not" points back at it; both registry rows stay with non-overlapping scopes. The shape doc's worked-fit rows now quote the live disk-hygiene:clean and repo-hygiene:clean hints. Main's new watch phase (unhobble) and in-place token (batch-simplify, tidy) stay in the rewritten hints.
  • Codex finding: the gate strips a trailing YAML comment before the empty check, so argument-hint: "" # none and argument-hint: # none now fail as empty (two new test cases).

Verification

  • After the second merge: validate-plugin-contracts.test.sh 92 pass, 0 fail, including zero argument-hint warnings on the shipping tree. validate-plugins.sh and check-changelog-parity.sh --check --check-order pass.

Run locally against origin/main (88dd7e1):

  • These checks pass: validate-plugin-contracts.test.sh (90 pass, 0 fail), validate-plugin-contracts.mjs (zero warnings), validate-plugins.sh, check-skill-count-claims.sh --check, skill and shell portability, check-fixture-git-isolation.sh --check, changelog parity in all four modes, check-stale-base-overlap.sh --check, check-purged-em-dashes.sh, the catalog and cheat-sheet --check, typos, markdownlint, editorconfig, shellcheck, and the context-budget suites.
  • check-changed-skills.sh origin/main: 108 of 109 pass. disk-hygiene:clean fails only its 11 test_guard_allows_literal_readonly_supporting_bash_commands subtests, which fail the same way on clean main on this machine.
  • affected-tests.sh --run: 11 suites fail (for example github, guardrails, code-metrics, and hook-census). The same 11 fail on a clean origin/main checkout here, and none of them is touched by this diff.

Related

🤖 Generated with Claude Code

https://claude.ai/code/session_01PT4esxbdC7eQiwQxy35Mie

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

PR body contract — issue linkage

This PR body conforms to the issue-linkage contract. Nothing to do.

@cursor cursor Bot changed the title docs+gate: argument-hint house style and contract warnings (#3542) feat(skills): argument-hint house style, gate, and fleet rewrite (#3542) Sep 28, 2026
@cursor
cursor Bot force-pushed the cursor/3542-argument-hint-hygiene-37e9 branch 2 times, most recently from a8fb285 to 05faaeb Compare September 28, 2026 12:28
cursoragent and others added 2 commits September 28, 2026 12:38
Add the owner doc for argument-hint grammar and a fleet-contract check
that fails an empty hint and warns when a hint is over 100 characters
or malformed. The six named frontmatter fixes from the audit are
already on main.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Move examples, defaults, and flag catalogs out of autocomplete hints that
exceeded 100 characters or broke the grammar, and keep that detail in the
skill body. Each touched plugin is bumped. The contract test now requires
the shipping tree to report zero argument-hint warnings.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@cursor
cursor Bot force-pushed the cursor/3542-argument-hint-hygiene-37e9 branch from 05faaeb to a253626 Compare September 28, 2026 12:38
kyle-sexton and others added 7 commits September 28, 2026 12:01
# Conflicts:
#	plugins/claude-config/CHANGELOG.md
#	plugins/claude-ops/.claude-plugin/plugin.json
#	plugins/claude-ops/CHANGELOG.md
#	plugins/claude-ops/skills/audit-performance/SKILL.md
#	plugins/claude-ops/skills/audit-skill-visibility/SKILL.md
#	plugins/discipline/.claude-plugin/plugin.json
#	plugins/discipline/CHANGELOG.md
#	plugins/disk-hygiene/CHANGELOG.md
# Conflicts:
#	plugins/architecture/CHANGELOG.md
#	plugins/claude-ops/CHANGELOG.md
#	plugins/code-tidying/CHANGELOG.md
#	plugins/debugging/CHANGELOG.md
#	plugins/discipline/CHANGELOG.md
#	plugins/planning/CHANGELOG.md
#	plugins/planning/skills/prd/SKILL.md
#	plugins/session-flow/CHANGELOG.md
#	plugins/source-control/CHANGELOG.md
#	plugins/work-items/CHANGELOG.md
…t gate

The previous commits overwrote the validator, its test, and three
SKILL.md files with unrelated bytes. Those files are restored from main.
The validator now fails an empty argument-hint and warns on an
over-budget or malformed one, naming the owner doc; the test covers each
outcome and asserts the shipping tree draws zero warnings. The prd,
workflow, and clean hints are shortened with the detail moved into the
body.

Refs #3542

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PT4esxbdC7eQiwQxy35Mie
…oken ref

The relocated argument detail for audit-instructions joins its existing
Arguments section instead of a new block, keeping the body at 500 lines.
The skill-authoring pointer names the validator without a repo path the
skill checker reads as a broken skill-internal reference.

Refs #3542

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PT4esxbdC7eQiwQxy35Mie
The earlier merge replaced the audit skill body with a stale copy,
reverting main's Windows install line, the --operator-deny flag, and the
token-count wording. The body is main's again, with only the shortened
argument-hint and its relocated full form.

Refs #3542

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PT4esxbdC7eQiwQxy35Mie
# Conflicts:
#	plugins/disk-hygiene/CHANGELOG.md
#	plugins/docs-hygiene/CHANGELOG.md
#	plugins/docs-hygiene/skills/extract-ssot/SKILL.md
#	plugins/planning/CHANGELOG.md
#	plugins/planning/skills/interview/SKILL.md
#	plugins/session-flow/CHANGELOG.md
@kyle-sexton
kyle-sexton marked this pull request as ready for review September 28, 2026 19:43
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T19:46:43.332305Z 52aef19 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 52aef19bfe

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/validate-plugin-contracts.mjs Outdated
kyle-sexton and others added 2 commits September 28, 2026 20:54
…hint-hygiene-37e9

# Conflicts:
#	plugins/ai-briefing/CHANGELOG.md
#	plugins/architecture/.claude-plugin/plugin.json
#	plugins/architecture/CHANGELOG.md
#	plugins/claude-config/.claude-plugin/plugin.json
#	plugins/claude-config/CHANGELOG.md
#	plugins/claude-ops/.claude-plugin/plugin.json
#	plugins/claude-ops/CHANGELOG.md
#	plugins/claude-ops/skills/audit-skill-visibility/SKILL.md
#	plugins/code-tidying/.claude-plugin/plugin.json
#	plugins/code-tidying/CHANGELOG.md
#	plugins/context-budget/CHANGELOG.md
#	plugins/debugging/CHANGELOG.md
#	plugins/discipline/CHANGELOG.md
#	plugins/discovery/.claude-plugin/plugin.json
#	plugins/discovery/CHANGELOG.md
#	plugins/discovery/skills/research/SKILL.md
#	plugins/disk-hygiene/.claude-plugin/plugin.json
#	plugins/disk-hygiene/CHANGELOG.md
#	plugins/education/CHANGELOG.md
#	plugins/evals/.claude-plugin/plugin.json
#	plugins/evals/CHANGELOG.md
#	plugins/implementation/.claude-plugin/plugin.json
#	plugins/implementation/CHANGELOG.md
#	plugins/instruction-placement/CHANGELOG.md
#	plugins/machine-health/.claude-plugin/plugin.json
#	plugins/machine-health/CHANGELOG.md
#	plugins/planning/.claude-plugin/plugin.json
#	plugins/planning/CHANGELOG.md
#	plugins/playbooks/.claude-plugin/plugin.json
#	plugins/playbooks/CHANGELOG.md
#	plugins/plugin-quality/.claude-plugin/plugin.json
#	plugins/plugin-quality/CHANGELOG.md
#	plugins/prototype/CHANGELOG.md
#	plugins/prototype/skills/explore-directions/SKILL.md
#	plugins/repo-fleet-hygiene/CHANGELOG.md
#	plugins/repo-fleet-hygiene/skills/audit/SKILL.md
#	plugins/repo-fleet-hygiene/skills/setup/SKILL.md
#	plugins/repo-hygiene/CHANGELOG.md
#	plugins/review/.claude-plugin/plugin.json
#	plugins/review/CHANGELOG.md
#	plugins/session-flow/CHANGELOG.md
#	plugins/skill-quality/CHANGELOG.md
#	plugins/skill-quality/skills/check/SKILL.md
#	plugins/source-control/.claude-plugin/plugin.json
#	plugins/source-control/CHANGELOG.md
#	plugins/testing/CHANGELOG.md
#	plugins/testing/skills/run-e2e/SKILL.md
#	plugins/work-items/CHANGELOG.md
The hint gate strips a trailing YAML comment before its empty check, so
`argument-hint: "" # none` fails like `""`. Hints that main changed since
the branch point are brought under the 100-character style.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WejvGhkHUSWPRim2caW2Wh
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 4m 55s —— View job


Code review (/review:code-review)

  • Gather context (PR body, diff, existing Codex review comment)
  • Invoke /review:code-review criteria
  • Review the gate logic, tests, docs, and a representative sample of the fleet rewrite
  • Post summary

Scope

192 files changed vs origin/main (c50da0a). Reviewed in full: the gate
(scripts/validate-plugin-contracts.mjs), its tests
(scripts/validate-plugin-contracts.test.sh), the owner doc
(docs/conventions/argument-hint/README.md + CHANGELOG.md), and the
plugin-philosophy.md registry pointer. Spot-checked ~15 of the 108 rewritten
hints across a diverse set of plugins (claude-config, claude-ops, disk-hygiene,
planning, session-flow, testing, playbooks) plus their CHANGELOG.md/
plugin.json bumps.

Findings

None that clear the high-signal bar. Specifically:

  • The gate's comment-stripping logic
    (validate-plugin-contracts.mjs#L1211-L1213)
    correctly handles the case the earlier Codex review flagged
    (argument-hint: "" # none and argument-hint: # none both now resolve to
    empty and fail, per the last commit c50da0a). Traced the regex against
    quoted/unquoted values, # inside quotes, and # not preceded by whitespace
    (real YAML only starts a comment after whitespace) — all resolve correctly.
    This is confirmed by the new hint_case commented test pairs in
    validate-plugin-contracts.test.sh.
  • The malformed-shape detector's bracket-depth pipe check
    (validate-plugin-contracts.mjs#L1170-L1183)
    correctly allows unspaced | inside []/<> while flagging it at depth 0,
    verified against several real fleet hints (check | apply [disable|deprecate|...],
    <fetch|diff|status|apply> [vA..vB|vX|text]).
  • The "Full form: ..." lines the rewrite inserts into skill bodies sometimes
    repeat the shortened hint's own bracket structure verbatim before appending
    the displaced detail (e.g. plugins/claude-ops/skills/lanes/SKILL.md). This
    is the expected, consistent outcome of truncating trailing prose while
    keeping the leading structure intact — not a defect, just how a truncate-only
    rewrite reads.
  • Budget accounting via [...value].length correctly counts Unicode code
    points rather than UTF-16 units, matching the doc's stated budget.
  • CHANGELOG entries and plugin.json patch bumps sampled across ai-briefing,
    architecture, playbooks, disk-hygiene, planning, and session-flow are
    consistent with each other and with the stated convention.

Not independently verified

I could not execute node/shell commands in this sandbox (denied), so I did
not independently run validate-plugin-contracts.test.sh or the validator
against the shipping tree myself. The PR body's "90 pass, 0 fail" / "zero
warnings" claims are author-reported, not confirmed by me — I verified the
logic by manual tracing and by reading the test file's assertions instead.

No inline comments posted — nothing survived to that bar.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 5s —— View job


Security review complete

No security issues found.

This PR is a documentation and frontmatter hygiene change (argument-hint house style) plus a new validation gate. Scope reviewed, all files changed in git diff origin/main...HEAD:

  • scripts/validate-plugin-contracts.mjs — new argument-hint house-style check. It reads each SKILL.md, strips a trailing YAML comment before checking emptiness (already fixed by the latest commit, c50da0a, in response to the earlier Codex finding), and does a linear bracket-depth scan for malformed shapes. No exec/eval/shell-out, no untrusted network input, no ReDoS-prone backtracking pattern.
  • scripts/validate-plugin-contracts.test.sh — new test cases (8d. argument-hint) run only against fixtures in a throwaway $TMP dir with hardcoded literal inputs; no injection surface.
  • 108 SKILL.md frontmatter edits + docs/conventions/argument-hint/{README,CHANGELOG}.md — every shortened argument-hint has its full form (flags, examples, defaults) preserved verbatim in a new **Arguments.** line in the skill body, confirmed by spot-checking disk-hygiene:clean, claude-config:audit-instructions, testing:run-e2e, and playbooks:skill-authoring. Nothing is deleted, so this doesn't trip the instruction-surface-deletion check (no guardrail, allowlist, or protected-class rule is removed or weakened).
  • 39 plugin.json diffs — version-bump only ("version" field), verified no other keys changed.
  • Grepped all added lines across the full diff for injection/secret/credential/shell-out patterns (curl, eval(, exec(, child_process, process.env, token, secret, password, API keys, sudo, chmod, bare http://) — no hits beyond expected prose (e.g., --include-bare-token as a flag name).

GitHub Actions hardening is out of scope for this lane (zizmor's advisory lane); no workflow files are touched by this PR regardless.

kyle-sexton added a commit that referenced this pull request Sep 29, 2026
…3992) (#5129)

Closes #3992

## Summary

New `/repo-fleet-hygiene:sync` skill. It moves each canonical checkout
onto the remote default branch (`git ls-remote --symref origin HEAD`)
and fast-forwards it. Dirty work is parked in a linked worktree through
source-control's `worktree-create.sh --existing-branch`. Bare invocation
is a dry-run plan; mutation needs `--apply` plus one confirmation.

## Fix

- `plugins/repo-fleet-hygiene`: `sync` skill and `sync-fleet.sh`, plus a
shared scope resolver (explicit args, fleet config, named paths, `ghq`
roots, cwd, else exit 3) that `audit` also uses as its no-scope
fallback. Non-fast-forward, dubious ownership, and a partial stash apply
are skipped and reported; nothing is reset. 0.23.43.
- The skill passes `--yes` only after showing the user the dry-run plan
(its `repos:` count and each repo's action row) and getting the user's
explicit go-ahead, in non-terminal runs too.
- The sync argument hint is 92 characters in the `[optional]` /
`<required>` house style, so it passes the argument-hint gate proposed
in #5042.
- `plugins/source-control`: `worktree-create.sh --existing-branch`
checks out an existing local branch; it cannot be combined with
`--base-ref`. 0.62.16.

## Verification

- `sync-fleet.test.sh`, `scope-resolve.test.sh`, `audit-fleet.test.sh`,
`worktree-create.test.sh`: pass.
- `scripts/validate-plugins.sh`, `scripts/check-changelog-parity.sh
--check --check-order`, `node scripts/validate-plugin-contracts.mjs`:
pass.
- `scripts/check-changed-skills.sh origin/main`: the repo-fleet-hygiene
and source-control skills pass. It also ran disk-hygiene's `clean`
skill, which this PR does not touch; its `hygiene.test.sh` fails 11
cases in `test_guard_allows_literal_readonly_supporting_bash_commands`,
which look machine-local (`/usr/bin/*` guard paths).
- Merged `origin/main`. The `audit-fleet.sh` conflict keeps both main's
`SKIP_APPEND_NAMES` guard and this PR's `NAMED_ARGS` guard.

## Related

- Supersedes draft #5106.
- Argument-hint style: #5042.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01WejvGhkHUSWPRim2caW2Wh

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…hint-hygiene-37e9

# Conflicts:
#	docs/plugin-philosophy.md
#	plugins/claude-config/.claude-plugin/plugin.json
#	plugins/claude-config/CHANGELOG.md
#	plugins/claude-config/skills/unhobble/SKILL.md
#	plugins/code-tidying/.claude-plugin/plugin.json
#	plugins/code-tidying/CHANGELOG.md
#	plugins/code-tidying/skills/batch-simplify/SKILL.md
#	plugins/playbooks/.claude-plugin/plugin.json
#	plugins/playbooks/CHANGELOG.md
#	plugins/repo-fleet-hygiene/.claude-plugin/plugin.json
#	plugins/repo-fleet-hygiene/CHANGELOG.md
#	plugins/source-control/CHANGELOG.md
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 11s —— View job


Code review (/review:code-review)

  • Gather context (PR body, diff, prior Codex/Claude reviews, custom instructions)
  • Invoke /review:code-review skill
  • Diff origin/main...HEAD (matches PR's stated 194 files / +896/-151); confirmed the gate (validate-plugin-contracts.mjs) and its tests are unchanged since the last review at c50da0a — only doc cross-references shifted from the origin/main merge
  • Found and traced a concrete defect in the fleet rewrite (repo-hygiene:clean)
  • Broader spot-check of remaining rewritten hints for the same defect class
  • Post inline findings and finalize summary

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 59s —— View job


Security review (/review:security-review)

Skip gate

This head (031bc212f2566aea54160eb12c2a8338cf092168) already has a successful security review that still applies. Confirmed by diffing the PR's net changes (git diff origin/main...HEAD) at the previously-reviewed commit (c50da0a, reviewed 2026-09-29T00:55:46Z, "No security issues found") against the current HEAD:

No security issues found. This carries forward the prior review's conclusion: the argument-hint gate (scripts/validate-plugin-contracts.mjs) has no exec/eval/shell-out and no untrusted network input; its comment-stripping fix (c50da0a) already closed the Codex-flagged empty-hint bypass; the 108 SKILL.md edits preserve every displaced detail verbatim in an **Arguments.** line (nothing deleted); and the plugin.json diffs are version-bump only. No workflow files are touched by this PR.

kyle-sexton and others added 2 commits September 28, 2026 21:51
…hint-hygiene-37e9

# Conflicts:
#	plugins/claude-config/CHANGELOG.md
#	plugins/claude-ops/CHANGELOG.md
#	plugins/instruction-placement/CHANGELOG.md
#	plugins/planning/CHANGELOG.md
#	plugins/planning/skills/prd/SKILL.md
#	plugins/session-flow/CHANGELOG.md
#	plugins/session-flow/skills/workflow/SKILL.md
#	plugins/source-control/CHANGELOG.md
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 5s —— View job


Code review (/review:code-review)

  • Gather context (PR body, diff, prior Codex/Claude reviews)
  • Invoke /review:code-review and follow it exactly for this PR
  • Review gate logic, tests, docs, and fleet rewrite for new findings since last review
  • Post inline findings and finalize summary

Scope

gh pr diff 5042 at HEAD 7396212 (194 files, matching the prior reviews' +896/-151 shape). The gate (scripts/validate-plugin-contracts.mjs), its tests, and the owner doc are unchanged since the last-reviewed commit c50da0a other than a doc cross-reference tweak already covered. This pass finished the prior (interrupted) review's unchecked item — a broader spot-check of the fleet rewrite for the same defect class — by diffing every +argument-hint: line in the PR against the skill it belongs to.

Findings

One inline comment posted:

  • plugins/repo-hygiene/skills/clean/SKILL.md:5 — the rewritten hint replaces the five real fleet-batch tokens (tree-batch, caches-batch, build-batch, git-batch, all-batch) with an invented word, batch-modes, that sits in the same pipe-list as literal, accepted action words but isn't one itself — resolve-clean-action.sh's resolve_token() never matches it. Every other hint this PR touches truncates real tokens/flags; this one is the only spot that fabricates a non-argument. It also makes the worked-fit table in docs/conventions/skill-argument-shape/README.md (which quotes this exact hint) inaccurate. Details and a suggested fix are in the inline comment.

Everything else sampled — additional argument-hint diffs across the fleet (extract-ssot, rename-references, repo-fleet-hygiene:audit/setup, disk-hygiene:clean, and ~15 more spot-checked across earlier review passes) — truncates trailing flags/prose only, with every remaining alternative staying a real literal the underlying script accepts; nothing else in this sample invents a token.

Not independently verified

Did not re-run validate-plugin-contracts.test.sh or the validator myself (no shell execution available for this pass); relied on the gate logic already traced and confirmed correct in the two prior review rounds at c50da0a, which this diff doesn't touch.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 12s —— View job


Security review (/review:security-review)

Skip gate

This head (73962122fc60bfa735c399bc1ffd03cd0497f528) already has a successful security review that still applies. The prior review at 031bc212f2566aea54160eb12c2a8338cf092168 ("No security issues found," 2026-09-29T01:40:05Z) covers everything except one commit added since:

  • git log 031bc212f2566aea54160eb12c2a8338cf092168..HEAD shows four commits: a1733b0, c85f058, a0e232a (all origin/main commits, pulled in by the merge commit 7396212 — matching PR numbers #4850, #5212, #5124 for prior, unrelated main-branch work, not new content authored on this PR), and one PR-owned commit, 0efdaac.
  • 0efdaac touches only scripts/validate-plugin-contracts.test.sh: it replaces sed -i with a portable sed ... >tmp && mv tmp orig pattern to fix Windows Git Bash compatibility. The edited path ($skill_md) is a fixture file under the test's own throwaway $TMP directory, and the substitution text ($commented) is one of two hardcoded literals ('"" # none' / '# none') from the enclosing for loop — no untrusted input, no injection surface, no privilege or trust-boundary change.

No security issues found. Nothing in the net-new content since the last successful review changes that conclusion. No gate logic, workflow file, or instruction surface is touched by this commit.
· branch cursor/3542-argument-hint-hygiene-37e9

🤖 Generated with Claude Code

Comment thread plugins/repo-hygiene/skills/clean/SKILL.md Outdated
kyle-sexton and others added 2 commits September 28, 2026 22:08
`batch-modes` is not a token the router accepts. The hint now shows the
`<tier>-batch` placeholder and the Arguments line lists the five forms.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WejvGhkHUSWPRim2caW2Wh
…hint-hygiene-37e9

# Conflicts:
#	plugins/ai-briefing/CHANGELOG.md
#	plugins/discipline/CHANGELOG.md
#	plugins/disk-hygiene/CHANGELOG.md
#	plugins/knowledge/CHANGELOG.md
#	plugins/songwriting/CHANGELOG.md
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 32s —— View job


Security review (/review:security-review)

Skip gate

This head already has a successful security review that still applies. The prior review at 73962122fc60bfa735c399bc1ffd03cd0497f528 ("No security issues found," 2026-09-29T01:53:49Z) covers everything except what's been added since.

Using first-parent history to isolate this PR's own commits (the rest are origin/main merges pulled in by the merge commits, matching the pattern the last two reviews established):

$ git log --first-parent --oneline 7396212..e23ad36
e23ad36 fix(repo-hygiene): name the fleet batch forms in the clean hint

Only one PR-owned commit landed since the last review:
e23ad36 — this is the fix for the exact finding the previous code-review pass flagged (the invented batch-modes token in repo-hygiene:clean's argument-hint). It touches two files, both docs/frontmatter only:

No code, no gate logic, no workflow file, no instruction-surface deletion. The merge commits between the two reviewed heads (a776ac0, 6aece33, 863243e, 8fe62d1, 26feaa8, 7239aec) are all reachable only via the merge's second parent (confirmed by the first-parent log above), i.e. pre-existing origin/main history pulled in by the merge, not new content authored on this branch.

No security issues found. Nothing in the net-new content since the last successful review changes that conclusion.
· branch cursor/3542-argument-hint-hygiene-37e9

🤖 Generated with Claude Code

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 13s —— View job


Code review (/review:code-review)

  • Gather context (PR body, diff, prior Codex/Claude review history)
  • Invoke /review:code-review and follow it exactly for this PR
  • Review gate logic, tests, docs, and fleet rewrite for new findings since last review
  • Post summary

Scope

gh pr diff 5042 at HEAD bb9a738 (194 files, matching prior reviews' shape). Commits added since the last review round (7396212) are five origin/main merge pulls plus one PR-owned commit, e23ad36, which fixes the one open finding from the prior round.

Findings

None. The prior inline finding — plugins/repo-hygiene/skills/clean/SKILL.md's hint using an invented batch-modes token that resolve-clean-action.sh doesn't accept — is fixed in e23ad36:

  • The hint now reads [scan|caches|build|git|stash|tree|all|<tier>-batch|aliases…]. <tier>-batch is a <required>-slot-plus-literal-suffix pattern, not a synthesized enum member; it has fleet precedent (machine-health:setup's approve=<id> inside its own bracket list), and it's inside [] so the unspaced | around it stays within the argument-hint house style's "closed enum inside brackets" allowance.
  • The body's **Arguments.** line spells out the five real forms verbatim: tree-batch, caches-batch, build-batch, git-batch, all-batch — nothing is lost, just displaced from the hint as the rest of this PR's rewrite already does everywhere else.
  • The matching worked-fit row in docs/conventions/skill-argument-shape/README.md is updated to quote the new hint and explain what <tier>-batch stands for, so the doc and the skill stay in sync.

Traced the malformed-shape bracket-depth check against the new value by hand: < and > balance depth correctly around tier, and the unspaced | on either side of <tier>-batch sits at depth 1 (inside []), so it doesn't trip the depth-0 pipe-spacing rule. No new gate, test, or fleet-wide changes since the last review — the gate (scripts/validate-plugin-contracts.mjs) and its tests are byte-identical to the previously-reviewed state.

Not independently verified

No shell execution available in this pass (node/gh pr diff write access aside, direct command execution required approval I didn't have), so I did not re-run validate-plugin-contracts.test.sh myself. Verified the fix by manually tracing the gate's regex/bracket-depth logic against the new hint string and by diffing origin/main against HEAD for the full file set.
· branch cursor/3542-argument-hint-hygiene-37e9

…hint-hygiene-37e9

# Conflicts:
#	plugins/claude-config/CHANGELOG.md
#	plugins/claude-memory/CHANGELOG.md
#	plugins/claude-ops/CHANGELOG.md
#	plugins/discovery/CHANGELOG.md
#	plugins/mcp-tools/CHANGELOG.md
#	plugins/overengineering/CHANGELOG.md
#	plugins/playbooks/CHANGELOG.md
#	plugins/playbooks/skills/skill-authoring/SKILL.md
#	plugins/source-control/CHANGELOG.md
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 41s —— View job


Security review (/review:security-review)

Skip gate

This head already has a successful security review that still applies. The prior review at bb9a7385b2ae463d3ab47fd4bd58701d3f308b1d ("No security issues found," 2026-09-29T02:10:08Z) covers everything except what changed since.

git log --first-parent --oneline bb9a738..9ba7c57 shows the only new commit is the merge itself:

9ba7c57 Merge remote-tracking branch 'origin/main' into cursor/3542-argument-hint-hygiene-37e9

No PR-owned commit landed since the last review — this is a merge of origin/main (bringing in e5515e3, an unrelated main-branch docs commit) into the branch, with manual conflict resolution in 9 files (git log -1 --format=%B lists the conflicted paths: 8 CHANGELOG.md files and plugins/playbooks/skills/skill-authoring/SKILL.md). Verified the resolution itself introduces nothing security-relevant:

  • git diff origin/main...HEAD shape: 194 files, +897/-151 — matches the PR's stated totals and the shape confirmed identical across every prior review round, confirming the merge didn't add new PR-owned content beyond a one-line net change already tracked.
  • The 8 CHANGELOG conflicts all resolve the same way: the PR's own version-bump entry stays on top, main's own entry (renumbered one patch down, e.g. 0.51.29 → 0.51.30/0.51.29) is reinserted intact below it. No entry lost or altered, nothing beyond changelog prose.
  • plugins/playbooks/skills/skill-authoring/SKILL.md: the conflict resolution keeps the PR's own argument-hint pointer paragraph (reworded from "the budget, the bracket grammar" to "the length budget, punctuation" — cosmetic, same pointer target) and adds main's independent context: fork / invocation-context rubric paragraph. Neither removes a guardrail; both are pointers to existing convention docs, not restated rules — so this isn't an instruction-surface deletion.
  • plugins/mcp-tools/skills/audit/SKILL.md: main's independent addition of context: fork / background: false frontmatter plus an explanatory paragraph. No change to the argument-hint line this PR owns ([path], untouched). No code, no injection surface, no secrets.
  • The remaining touched files in this merge (docs/conventions/invocation-context/README.md, plugins/dometrain-mcp/*, various reference spokes gaining Contents blocks) are pre-existing origin/main content pulled in by the merge's second parent, not authored on this branch.

No security issues found. Nothing in the net-new content since the last successful review changes that conclusion. No code, gate logic, workflow file, or instruction surface is touched by this merge in a way that weakens a guardrail.
· branch cursor/3542-argument-hint-hygiene-37e9

🤖 Generated with Claude Code

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 36s —— View job


Code review (/review:code-review)

  • Gather context (PR body, diff, prior Codex/Claude review history)
  • Invoke /review:code-review and follow it exactly for this PR
  • Check for new findings since last review (bb9a738)
  • Post summary

Skip gate

This head (9ba7c575bb41fa6b6253eb8536dd04810661f191) already has a successful code review that still applies. The prior review at bb9a738 ("None" found, 2026-09-29T02:10:08Z) confirmed the e23ad36 fix for the batch-modes finding and covers everything except what's landed since.

$ git log --first-parent --oneline bb9a738..HEAD
9ba7c57 Merge remote-tracking branch 'origin/main' into cursor/3542-argument-hint-hygiene-37e9

Only one commit landed since the last review, and it's a merge from origin/main, not a PR-owned commit. Confirmed by diffing the PR's net changes at both points:

  • git diff origin/main...HEAD --shortstat → 194 files changed, 897 insertions(+), 151 deletions(-) — identical to the shape the prior two review rounds already confirmed (c50da0a, 7396212, bb9a738).
  • git diff bb9a738..HEAD --stat shows 52 files touched by the merge, none of which overlap this PR's own files (argument-hint docs, the gate, the fleet SKILL.md/plugin.json/CHANGELOG.md set) — all belong to unrelated origin/main work pulled in by the merge (e.g. the dometrain→dometrain-mcp rename, invocation-context docs).

No findings. Nothing in the net-new content since the last successful review changes that conclusion; the gate (scripts/validate-plugin-contracts.mjs), its tests, and the fleet rewrite remain byte-identical to the previously-reviewed state.
· branch cursor/3542-argument-hint-hygiene-37e9

…hint-hygiene-37e9

# Conflicts:
#	plugins/claude-ops/.claude-plugin/plugin.json
#	plugins/claude-ops/CHANGELOG.md
#	plugins/context7/CHANGELOG.md
#	plugins/instruction-placement/CHANGELOG.md
#	plugins/source-control/CHANGELOG.md
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 52s —— View job


Security review (/review:security-review)

Skip gate

This head already has a successful security review that still applies. The prior review at 9ba7c575bb41fa6b6253eb8536dd04810661f191 ("No security issues found," 2026-09-29T02:31:12Z) covers everything except what changed since.

$ git log --first-parent --oneline 9ba7c57..4e0c962
4e0c962 Merge remote-tracking branch 'origin/main' into cursor/3542-argument-hint-hygiene-37e9

No PR-owned commit landed since the last review — this is a merge of origin/main into the branch (pulling in 030bb3d, feat(claude-ops): surface missing fleet prerequisites without installing), with manual conflict resolution in 5 files. Verified the resolution introduces nothing security-relevant:

  • git diff origin/main...HEAD shape: 194 files, +897/-151 — identical to the shape confirmed across every prior review round (c50da0a through 9ba7c57), confirming the merge added no new PR-owned content.
  • The merge's own diffstat (git diff 9ba7c57..4e0c962, 94 files) is entirely pre-existing origin/main content pulled in via the merge's second parent — the new check-prerequisites.sh/probe-prerequisite.sh scripts, hook-utils.sh changes across the format/guard plugin family, and the new prerequisites skill are all 030bb3d's content, not authored on this branch, and none of it overlaps this PR's own files (the argument-hint docs, the gate, or the fleet SKILL.md set).
  • The 5 conflicts (plugins/claude-ops/.claude-plugin/plugin.json, and CHANGELOG.md in claude-ops, context7, instruction-placement, source-control) all resolve the same way this PR's merges have resolved every prior changelog conflict: the PR's own entry stays on top, main's own entry is reinserted intact below it (e.g. claude-ops gains 0.63.32 on top of main's unrelated 0.63.31/0.63.30 bumps). Diffed each resolved file against origin/main directly to confirm — no entry lost, no version regressed, nothing beyond changelog/version-bump prose.

No code, no gate logic (scripts/validate-plugin-contracts.mjs/.test.sh untouched by this merge), no workflow file, and no instruction-surface deletion (no CLAUDE.md/AGENTS.md/rules file/hook allowlist is touched at all in this merge's diffstat).

No security issues found. Nothing in the net-new content since the last successful review changes that conclusion.
· branch cursor/3542-argument-hint-hygiene-37e9

🤖 Generated with Claude Code

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 55s —— View job


Code review (/review:code-review)

  • Gather context (PR body, diff, prior Codex/Claude review history)
  • Invoke /review:code-review and follow it exactly for this PR
  • Check for new findings since last review (9ba7c57)
  • Post summary

Skip gate

This head (4e0c9622261e67eb8c7ee06810dd7b5d061d5066) already has a successful code review that still applies. The prior review at 9ba7c575bb41fa6b6253eb8536dd04810661f191 ("No findings," 2026-09-29T02:31:13Z) confirmed no new issues through that point, and covers everything except what's landed since.

$ git log --first-parent --oneline 9ba7c57..4e0c962
4e0c962 Merge remote-tracking branch 'origin/main' into cursor/3542-argument-hint-hygiene-37e9

Only one commit landed since the last review, and it's a merge from origin/main, not a PR-owned commit:

  • The merge's second parent is 030bb3d239efb54167b35ade06dc13eb3650a086, which is exactly origin/main's current tip (git merge-base origin/main 4e0c962 resolves to it) — i.e. this merge pulls in the latest main-branch history (e.g. the unrelated claude-ops fleet-prerequisites feature, hook-utils.sh changes in several *-format plugins, check-prerequisite-probes.test.sh) rather than adding new PR-owned content.
  • git diff origin/main...HEAD --shortstat → 194 files changed, 897 insertions(+), 151 deletions(-) — byte-identical to the shape every prior review round already confirmed (c50da0a, 7396212, bb9a738, 9ba7c57) and matching this PR's own stated totals.
  • git diff 9ba7c57..4e0c962 --stat shows 94 files touched by the merge, none of which overlap this PR's own files (the argument-hint docs, the gate script, or the fleet SKILL.md/plugin.json/CHANGELOG.md set this PR touches) — all belong to unrelated origin/main work pulled in by the merge's second parent.

No findings. Nothing in the net-new content since the last successful review changes that conclusion; the gate (scripts/validate-plugin-contracts.mjs), its tests, and the fleet rewrite remain byte-identical to the previously-reviewed state.
· branch cursor/3542-argument-hint-hygiene-37e9

🤖 Generated with Claude Code

@kyle-sexton
kyle-sexton merged commit e544012 into main Sep 29, 2026
19 checks passed
@kyle-sexton
kyle-sexton deleted the cursor/3542-argument-hint-hygiene-37e9 branch September 29, 2026 02:59
kyle-sexton added a commit that referenced this pull request Sep 29, 2026
…ne caveat scoped to branch tier

`scope` returned one line per resolved row and skipped the Brief, so a `deferred` or `blocked`
row, which a normal run writes to the Brief's `### Deferred questions` with an arbiter, vanished
for the caller. `Scope decisions:` now also returns each such row as a `Deferred:` or `Blocked:`
line that leads with its `Q<N>` id and carries the arbiter (`/planning:plan` by default, or
`USER-RESERVED`). A `Blocked:` line, or a `Deferred:` line tagged `USER-RESERVED`, tells the caller
to stop and ask the user. The ledger and the register gate are unchanged.

The Step 4 "Neither slice is a durable home" prune caveat now applies under `contract_tier: branch`
only. Under `contract_tier: local` the contract sits in the memory slice, which never reaches git,
so nothing is pruned. The Action Router `scope` row drops its tracker link, and the three Stance
recommendation-basis links point at the plugin-shipped context/recommendation-basis.md instead of
an org URL.

Adds eval case 26, which grades `scope` returning resolved and unresolved rows and writing no
PLAN.md.

Closes #4286 (all three acceptance criteria re-checked on this branch: the caveat states the slice
is pruned before merge and is not a durable home, names an ADR, a spec or a tracker item as the
graduated destination, and is scoped to the branch tier)
Refs #4502

Digest re-pins for human confirmation

Each region below was read from `git diff` before its digest was recomputed with the commands in
the test header. In none of them is STOP-on-gap or the auto-guard weakened, qualified or
contradicted. No phrase pin, pin_once, within or pin_exact fired, and the `lock` router row, the
Step 1.5 `lock` routing line and the auto-guard paragraph are byte-identical.

- SKILL.md Stance section, be11096...->c2dd078...: three recommendation-basis links repointed at
  the plugin-shipped file or dropped. The partial-round no-silent-resolve rule is untouched.
- SKILL.md Step 4 section, 3824691...->402e1ba...: the prune caveat is qualified to the branch
  tier and the `scope` persist path returns `deferred` and `blocked` rows with their arbiter. That
  extends the rule that a choice never silently disappears to a path with no Brief. It resolves no
  row and relaxes neither the register gate nor the ledger.
- SKILL.md Action Router section, ff84d3f...->0fbfcb7...: the `scope` row lost its tracker link.
  The `lock` row is byte-identical.
- Eval-case roster, a3038d1...->2d0f369...: case 26 added. It grades a `blocked` `USER-RESERVED` row
  that is returned and never assumed, so it agrees with cases 15 and 16.
- SKILL.md frontmatter, bd304c4...->881ecec...: not caused by this change. The pin was already
  stale on origin/main since e544012 (#5042) shortened `argument-hint` to `[action] [topic]`.
  The description and metadata keys are unchanged, and no key states or qualifies either defense.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

argument-hint hygiene: six concrete fixes, a house style rule, and a lint criterion

2 participants