chore(changelog): close #4027 for Claude Code 2.1.257–2.1.263 - #5162
Merged
Merged
Conversation
From Claude Code 2.1.257, project and local settings ignore bypassPermissions the same way they ignore auto. acceptEdits, plan, and dontAsk still apply. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…-apply-one-37e9 Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
On Opus 5.5 and Fable 5.1 an API-key or subscription session keeps the prompt cache when effort changes. The fable alias resolves to Fable 5.1 except on a Claude apps gateway. The boris effort-hold sentence is no longer on model-config. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…and connectors Name the append-system-prompt file and subagent CLI flags on the agent-doc surface tables, and record that deniedMcpServers is what keeps a managed MCP server off after 2.1.259. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Avoid re-serializing levers.json so the #4027 managed-allowlist note is the only content change in that file. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The connectors lever no longer treats allowedMcpServers as the key that removes a managed connector, and the instruction-surface tables name the -p-only append flags. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
markdownlint MD012 rejects the two blank lines that separated the new context-budget and docs-hygiene headings from the published entries. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The cli-reference now has --append-system-prompt-file and both --append-subagent-system-prompt forms. The subagent flags are -p only. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
allowedMcpServers no longer removes managed connectors. /context uses the token-counting API or a local estimate when that API is unavailable. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The model-config page still publishes about 967K tokens for a native 1M window. The reader contract already carried that figure. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Redirect targets are covered, the 2.1.259 Bash-argument widening stays reverted, shell-mode commands escape a strict sandbox, and the working directory fence covers Read, Grep, Glob, and LSP. bashOutputMaxChars is documented and not raised by default. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Lane launch adds --permission-prompts none on Claude Code 2.1.259 and later, beside auto mode. FORCE, /advisor, and resume --bg stay out of the launcher. /reload-plugins is recorded for headless sessions, cache misses route to last_miss_cause, and stale sandbox mask files are nominated to /doctor without a store row. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The isolation check that cannot verify a command is scoped to git. Unattended runs can keep their permission mode with --permission-prompts none. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
A dollar expansion in a block that never runs git is outside the worktree command-shape check. The compose gate was already git-only. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
From Claude Code 2.1.259 the flag keeps the chosen mode and denies only a call that would have prompted. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…tions Refs #4027. Redirect targets, the managed permission lock, ask-rule attribution, per-surface plugin customization, interactive shell mode, unparsable managed settings, the server-managed cache, the working-directory read fence, and permission-rule parentheses now follow the current docs. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The unattended claude -p analysis keeps dontAsk and adds --permission-prompts none, so a request that would still ask a person is denied and the model is told not to retry it. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Lane launches pass --permission-prompts none with auto mode. Restart stays a fresh seed rather than --resume --bg. /reload-plugins is recorded as available in headless sessions, and the doctor sandbox-mask warning is nominated on the existing audit-install-state pair. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Check 1 allows inherit, a model id, and an optional [1m] suffix. skill-authoring and plugin philosophy record the turn scope and the auto-mode exception, the worktree-isolation command-shape basis, and the decline of CLAUDE_CODE_SUBAGENT_MODEL_FORCE. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The local reader still cannot see server-managed settings. Its note now sends the operator to /status and claude doctor for the Organization policy line. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The posture inventory gains a provided_by column so an organization server is distinct from managed-mcp.json and from a user-configured row. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
bashOutputMaxChars is a disclose-only lever because startup snapshots do not include command output. taskOutputMaxChars is recorded as removed. The engine notes that /context falls back to a local estimate when the token-counting API is unavailable. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
prompt-cache-cause.py prints last_miss_cause from a statusline payload. The 1M auto-compact exception list is re-stamped against the current model-config thresholds. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
claude plugin validate --json is rendered per file, with a text fallback when the CLI does not emit the report. The auditor asks for the same flag. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The permission-grant suite names P5 for a Tool(content) rule with trailing text. claude-config moves to 0.51.9 and claude-ops to 0.63.9 so they do not share versions already held by open pull requests. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
… /status The 2.1.282 bundled skill still has the Fable migration sections and the prompt-audit step list, and the model-migration guide adds an eval section from the 2.1.260 refresh. audit-pass sends policy load, helper refresh, and which credential is in use to /status and claude doctor. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Keep bypassPermissions and the pinned tool list. On Claude Code 2.1.259 or later, deny only calls that would still have prompted. Older CLIs omit the flag. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Seed docs/upstream/claude-code.md at changelog through 2.1.263 and point each decision at the pull request or branch that applied it. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The permission and adoption applies are in this history, so the seed no longer names the sibling branches those commits came from. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
# Conflicts: # docs/specs/agent-doc-surfaces.md # plugins/claude-config/.claude-plugin/plugin.json # plugins/claude-config/CHANGELOG.md # plugins/context-budget/.claude-plugin/plugin.json # plugins/context-budget/CHANGELOG.md # plugins/context-budget/skills/audit/reference/engine.md # plugins/context-budget/skills/audit/reference/levers.json # plugins/docs-hygiene/.claude-plugin/plugin.json # plugins/docs-hygiene/CHANGELOG.md # plugins/playbooks/.claude-plugin/plugin.json # plugins/playbooks/CHANGELOG.md Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The default lane-launcher stub is Claude Code 2.1.220, and the launcher omits --permission-prompts none below 2.1.259. The dedicated version cases still pin both sides of that floor. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…-close-37e9 Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
… slug The merge of main left an autonomy changelog link that names the org, which the contract check rejects, and a criteria TOC fragment for the previous heading. Use a bare (#4027) cite and the current ask-rules heading slug. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
claude-config 0.51.17-0.51.19, claude-ops 0.63.16-0.63.17, context-budget 0.6.42, context-guard 0.7.82, playbooks 0.13.22, and session-flow 0.38.20 sit above the numbers already claimed by other open pull requests. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
MD032 and MD022 want a blank line between a list and the next release heading in claude-config, claude-ops, context-budget, and playbooks. MD012 wants the extra blank line removed in the claude-ops changelog and the lanes skill. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
# Conflicts: # plugins/autonomy/.claude-plugin/plugin.json # plugins/autonomy/CHANGELOG.md # plugins/claude-config/.claude-plugin/plugin.json # plugins/claude-config/CHANGELOG.md # plugins/claude-config/skills/audit/reference/required-permissions.md # plugins/claude-ops/.claude-plugin/plugin.json # plugins/claude-ops/CHANGELOG.md # plugins/claude-ops/skills/audit-install-state/reference/surfaces.md # plugins/claude-ops/skills/audit-native-overlap/reference/canonical-pairs.json # plugins/claude-ops/skills/lanes/SKILL.md # plugins/claude-ops/skills/lanes/scripts/lane-launcher.sh # plugins/context-budget/.claude-plugin/plugin.json # plugins/context-budget/CHANGELOG.md # plugins/context-guard/.claude-plugin/plugin.json # plugins/context-guard/CHANGELOG.md # plugins/docs-hygiene/.claude-plugin/plugin.json # plugins/docs-hygiene/CHANGELOG.md # plugins/playbooks/.claude-plugin/plugin.json # plugins/playbooks/CHANGELOG.md # plugins/source-control/.claude-plugin/plugin.json # plugins/source-control/CHANGELOG.md Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
The catalog block still said the retention sweep pauses silently. plugin.json now says that pause warns in /status, and validate-plugins.sh failed on the drift. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
# Conflicts: # plugins/claude-config/.claude-plugin/plugin.json # plugins/claude-config/CHANGELOG.md # plugins/claude-config/skills/audit-permission-state/SKILL.md # plugins/claude-config/skills/audit-permission-state/scripts/managed-conformance.sh # plugins/claude-config/skills/audit-permission-state/scripts/managed-conformance.test.sh # plugins/claude-config/skills/audit-permission-state/scripts/permission-state.sh # plugins/claude-memory/.claude-plugin/plugin.json # plugins/claude-memory/CHANGELOG.md # plugins/claude-ops/.claude-plugin/plugin.json # plugins/claude-ops/CHANGELOG.md Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
kyle-sexton
added a commit
that referenced
this pull request
Sep 29, 2026
The entry repeated the 0.24.8 #4027 text word for word, but 0.24.9 (#5162) touched only plugin.json and CHANGELOG.md; the change shipped in 0.24.8. This corrects the released 0.24.9 entry body in place. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
This was referenced Sep 29, 2026
Merged
kyle-sexton
added a commit
that referenced
this pull request
Sep 29, 2026
…al moment (#5272) Refs: #3357 Refs: #3867 Refs: #3866 ## Summary Fixes from the 2026-09-29 audit of the unattended Cursor run, scoped to `plugins/plugin-quality/` (`exec-bash.mjs` untouched). This PR closes no issue; #3357 is a container that stays open pending two owner questions, #3867 was closed earlier, and #3866 is unchanged (owner decision ratified, no change). - `packet-seal.sh verify` never read the generation manifest `record --acknowledge-divergence` writes, so it reported `packet.sha256.N` and every later note as UNSEALED forever, and a restore-then-add-notes sequence had no way to seal the new notes (#3357). - The #3867 decision says the packet records its seal moment; the manifest held digests only (#3867). - The write-once and seal-time doctrine was restated in five places, and `evidence-packet.md` still said `item.md` where the script and skill say `item*.md`. - `auditor.md` stated a `claude plugin validate --json` version floor with no basis, and the 0.7.28 and 0.7.29 CHANGELOG entries were byte-identical. ## Fix - `verify` still grades `packet.sha256` exactly as before, then grades every entry of the highest-numbered generation as `GEN-MATCH`, `GEN-CHANGED` or `GEN-MISSING`, prints `ACKNOWLEDGED generation=<n>`, and never reports a manifest file as UNSEALED. Exit codes stay 0/1/2/3. - `record --acknowledge-divergence` with a generation in place writes the next generation over the current bytes instead of exiting 2. An ordinary `record` is still refused once a generation exists. - `record` and each generation write `# sealed-at <UTC ISO-8601>`; `verify` prints `sealed-at=` and `gen-sealed-at=`. Older manifests report `sealed-at=unknown`. - `evidence-packet.md` "What a sealed packet asserts" is the single owner of the doctrine; `auditor.md`, `SKILL.md` and `recurring-concerns.md` point at it. No owner decision is reversed: the #3866 Option A text is kept. - `auditor.md` records the basis for the `validate --json` floor: the CLI reference options table ("Requires Claude Code v2.1.259 or later"), corroborated by the 2.1.259 changelog entry. - Version 0.8.0 with one CHANGELOG entry. Declared in-place corrections to released entries, per `check-changelog-parity.sh`: 0.7.28 drops the repo-script sentence that does not belong in a plugin changelog; 0.7.29 now states it carried no plugin change instead of repeating the 0.7.28 body. ## Verification - `bash plugins/plugin-quality/scripts/*.test.sh`: citation-contract-drift PASS=12, context-zone PASS=81, packet-prune passed, packet-seal passed (new cases for generation reads, numeric ordering, restore-then-add-notes, look-alike names, GEN-MISSING, sealed-at), zones-inline-drift PASS=11. - `scripts/check-changelog-parity.sh --check --check-order`, `--check-bump origin/main`, `--check-preserved origin/main`: all pass. - `scripts/validate-plugins.sh`: all manifests and the catalog validated. - `scripts/check-changed-skills.sh origin/main`: audit skill PASS, 0 errors, 3 warnings (none from these edits). - markdownlint on the CHANGELOG: 0 issues. origin/main merged into the branch before the bump. ## Related - Audit report: `.work/audit/REPORT.md`, findings for #3357 (generation manifest never consumed by verify), #3867 (seal moment not recorded), #3866 (3d ratify, no change), #3999 (no action: PR closed unmerged, nothing stranded). - Cross-group request to `scripts` (optional, low priority): make `check-changelog-parity.sh --check-bump` fail when a new entry body is byte-identical to the previous version's, since 0.7.29 shipped that way (#5162). - Owner questions for #3357 (accept the generation-manifest design from #5145; whether the packet-level seal moment plus the timeline-question rule closes P2) go on the issue, not in this PR. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
kyle-sexton
added a commit
that referenced
this pull request
Sep 29, 2026
…og, gate spoke paths (#5270) Refs: #4613 Refs: #4119 ## Summary Three fixes to the `claude-memory` plugin from the Cursor-agent PR audit, released as 0.13.10: - The `audit` scope-boundary eval expected a removed `automation-gaps` route. - The 0.13.7 and 0.13.6 CHANGELOG entries were a verbatim duplicate and a mislabelled sync. - The `<skill-dir>` spoke-script convention from #4613 (0.13.5) had no mechanical gate. ## Fix - `skills/audit/evals/evals.json` case 2 (`scope-boundary-routes-out`) now expects routing to `audit` and `audit-automation-gaps` in the claude-config plugin, matching `SKILL.md`. Refs #4119. - CHANGELOG, two in-place corrections of released entries (named here and in the 0.13.10 entry, per the check-changelog-parity #2388 rule): 1. 0.13.7 was a verbatim copy of 0.13.6 with no plugin change (#5162 touched only `plugin.json` and `CHANGELOG.md`). It is now a Changed entry stating it is a re-release with no `claude-memory` change. The heading stays, since the version shipped. 2. 0.13.6 moved from Fixed to Changed and is reworded as a `lib/managed-scope.sh` sync (byte-identical to the claude-config copy; adds the unused `mscope::remote_cache_file` helper; no behavior change). - New `scripts/spoke-script-paths.test.sh` (about 65 lines, grep and sed): over every file in `skills/*/context/` and `skills/*/reference/`, (a) no literal `${CLAUDE_PLUGIN_ROOT}`, (b) every `<skill-dir>/scripts/<name>.sh` resolves to a real script in the owning skill, (c) each `SKILL.md` whose spokes use `<skill-dir>` states `${CLAUDE_SKILL_DIR}`. A fixture case injects the token and a missing script name and asserts the check rejects both. Refs #4613 (closed; its 0.13.5 fix stands). - `skills/audit/reference/official-guidance.md`: the `AGENTS.md` record said a directly read `AGENTS.md` is absent from `/memory`. Re-fetched the memory page 2026-09-29: `/memory` lists it from v2.1.280 (before that, `/memory` and `/context` did not); the `InstructionsLoaded` gap is unchanged. Record re-dated; it stays self-contained, with no pointer into another plugin. - Version 0.13.9 to 0.13.10 with one CHANGELOG entry. `origin/main` merged in (only a claude-ops change). Not done, deliberately: `mscope::remote_cache_file` stays (the file must stay byte-identical to the claude-config copy, gated by `sync-managed-scope.sh --check`); spoke commands are not routed through `audit-spine.sh` (the 0.13.5 fix meets the issue's first suggestion; the sturdier option is an unrequested design change). ## Verification - `scripts/check-changelog-parity.sh --check --check-order`: pass. - `scripts/check-changelog-parity.sh --check-preserved origin/main`: pass (71 headings). - `scripts/validate-plugins.sh`: all manifests and the catalog validated. - `scripts/sync-managed-scope.sh --check`: both plugin copies match. - `scripts/check-lane-coverage.sh --check`: pass. - `bash plugins/claude-memory/scripts/spoke-script-paths.test.sh`: 8 checks pass; the 10 claude-memory `*.test.sh` suites under `skills/*/scripts/` all pass. - `shellcheck plugins/claude-memory/scripts/spoke-script-paths.test.sh`: clean. - `scripts/check-shell-portability.sh origin/main`: pass (the test writes to a temp file and `mv`s instead of GNU-only `sed -i`). - `evals.json` parses as JSON. `/skill-quality:check validate-evals audit` was not run. ## Related - Audit report: `.work/audit/REPORT.md` (local, not committed); findings #4613 (decision, process), #4119 (stale eval, owned by the planning group), plugin-claude-memory changelog-integrity, scope-drift and churn. - Cross-group request to `scripts`: add a `--check-bump-substance <ref>` mode to `scripts/check-changelog-parity.sh` that fails when a plugin's version changed but nothing outside `plugin.json` and `CHANGELOG.md` did (with a per-plugin opt-out list), so a no-op re-release like 0.13.7 is caught. - Fleet-wide follow-up filed: #5273 (345 hits of `${CLAUDE_PLUGIN_ROOT}` in spoke files across 32 plugins; this PR's test is the template for a repo-wide check). Cross-group request from tracker; the needs-triage label removed from closed #4613. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
kyle-sexton
added a commit
that referenced
this pull request
Sep 29, 2026
) No related issue: audit fix group "autonomy"; #4703 stays closed (ratified, no reopen). ## Summary Audit findings for the autonomy plugin, resolved in place: the #4703 out-of-scope decision was restated in `reference/return-accounting.md` with unverified "As of" claims, and the 0.24.9 changelog entry repeated 0.24.8 word for word. Cross-group requests from hook-launcher add: five changelog entries describing shared code this plugin never calls, a stale Hook cost section, and an undeclared Node.js requirement. Refs #4703. ## Fix - `plugins/autonomy/reference/return-accounting.md`: the section "Agent-run artifact attestation is out of scope (#4703)" keeps its heading and is reduced to one sentence pointing at `docs/out-of-scope/agent-run-artifact-attestation.md`. The options list and the Claim/Basis/As of/Recheck lines are gone from this plugin. The decision is unchanged. - `plugins/autonomy/CHANGELOG.md`: the 0.24.9 entry body is corrected in place (it changed no plugin file; the #4027 change shipped in 0.24.8). This in-place edit of a released entry body is deliberate and is repeated in the 0.24.16 entry. - `plugins/autonomy/CHANGELOG.md`: 0.24.3, 0.24.4, 0.24.11, 0.24.13 and 0.24.15 described shared-library code this plugin never calls (hook-utils.sh parse and path helpers, the format-hook probes, a claude-ops skill), and 0.24.11 closed with a rows-unchanged line after 0.24.10 changed the rows. Each is reduced to "Shared launcher/library sync; no change to this plugin's behavior." Headings and order are unchanged. This also drops the 0.24.3 citation of #4528 with the rest of its text. - `plugins/autonomy/README.md`: new Requirements section declares Node.js on PATH (every hook row runs through `node hooks/exec-bash.mjs`; Claude Code's native binary does not ship Node). Hook cost states that the table counts the script alone and the launcher adds one node process to every row. The default-path row now reads 0 creations and 0 launches: `uname` was removed from that path by #4191 and `lane-stop-gate.test.sh` pins 0. The row was not re-measured here because `strace` is unavailable on this host. - `plugins/autonomy/skills/setup/SKILL.md`: `check` also reports whether `node` resolves (`command -v node` through the Bash tool, so it works without the launcher). - `plugins/autonomy/hooks/lane-stop-gate.test.sh`: one comment says the trace runs the script directly, not through the launcher. - Version 0.24.15 to 0.24.16 (patch, docs only); the entry covers all of the above. ## Verification - `scripts/check-changelog-parity.sh --check --check-order`: pass - `scripts/check-changelog-parity.sh --check-preserved origin/main`: pass (120 headings preserved) - `scripts/check-changelog-parity.test.sh`: PASS=86 FAIL=0 - `scripts/validate-plugins.sh`: all manifests and the catalog validated - `scripts/check-contract-slice-prune.sh --check`, `scripts/check-contract-clause-coverage.test.sh` (24 tests OK), `scripts/check-docs-naming.sh`, `scripts/check-skill-count-claims.sh`, `scripts/check-changed-skills.sh origin/main`: pass - `markdownlint-cli2` on the edited README, CHANGELOG and setup SKILL.md: 0 issues - All `plugins/autonomy/**/*.test.sh` (lane-stop-gate 116, lane-notify 10, security-binding 684 checks, prerequisite slice 4, identity prerequisites 6, resolve-prerequisites 22): pass. The strace budget assertions skip on this host. ## Related - Audit report: `.work/audit/REPORT.md`, findings for #4703 (medium: unverified claims stamped "As of"; low: decision restated in a normative contract doc; low: option 1 chosen against the item's lean, ratify) and the plugin-autonomy changelog findings (0.24.9 duplicate). Report row 3d #4703 = ratify: no decision change. - Accepted history, no change: skipped 0.24.6/0.24.7 and heading-only 0.24.10. - Cross-group request to core-docs: `docs/out-of-scope/agent-run-artifact-attestation.md` Basis/As of lines state `actions/attest-build-provenance` and in-toto predicate claims that #4703 marked "carried, not re-checked". Add fetched URLs and a date, or reword as unverified. If the ledger is reworded or removed, update the pointers in `plugins/autonomy/README.md` and `reference/return-accounting.md`. - Cross-group requests applied here: hook-launcher F11 (changelog rewording), F35 (hook-cost note), F3 (Node.js declaration); the node launcher stays per the owner's fix-forward on #3708. docs-hygiene (0.24.9 body edit) was already applied by an earlier commit on this branch. - Related: #4917, #4908, #5162, #5156, #4027, #3708. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
kyle-sexton
added a commit
that referenced
this pull request
Sep 29, 2026
--check-bump now fails a bump whose only changes under plugins/<name>/ are plugin.json and CHANGELOG.md. A deliberate re-release is named as <plugin>@<version> in scripts/changelog-no-op-bumps.txt, seeded empty. Replayed over #5162 it flags the ten bump-only plugins; the last 25 merges on main pass. Tests cover the failure, a sanctioned and a mismatched opt-out, a synced-file bump, one identical sync entry across carriers, and the 'No change: repeats' pointer form. Refs: #4608 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
kyle-sexton
added a commit
that referenced
this pull request
Sep 30, 2026
#5339) Refs: #4582 Refs: #4222 Refs: #4109 Refs: #3413 Refs: #3708 Refs: #4144 Refs: #4586 Refs: #4608 Refs: #3605 Refs: #4683 Refs: #4112 ## Summary Fixes from the audit of the unattended Cursor agent's PRs, mostly in `scripts/`, plus changes other audit groups asked for in these paths. The only plugin change is the shared `html-escape.mjs` sync into `review`, which bumps review to 0.33.8. - Publisher/portability token alignment gate (#4582) passed with zero active tokens, its test could not fail, and a padded line read as drift. - Exec-form gate remedy text still taught shell form; the owner decided fix-forward on #3708 (2026-09-29). - `GE_DISCOVERY` in `scripts/lib/gate-entry.sh` was dead API, gate-entry adoption scope was unstated, and the ADR baseline header said "never add a pair" while it holds four (#3413, #4109). - The "no hand-rolled base-ref predicate" guard matched one spelling only; two scripts still hand-rolled it. - The detector eval-coverage scanner (#4222) lost wrapper-prefixed emit calls silently, and its header named RE2 while jq uses Oniguruma. The mutation audit of its jq walk left 15 surviving mutants with no recorded disposition, and the shfmt version floor had no test. - The all-skills verb-contract gate (#4586) never checked a skill: since #4219 the checker refuses a skill directory, and the gate swallowed the exit 2 and printed PASS. - A plugin could be bumped with nothing but `plugin.json` and `CHANGELOG.md` changed (#5162 did it to ten plugins). - The pr-explainer page validator let resource-loading CSS through inside `<style>` (#3605). - Smaller gaps: the code-metrics prose gate failed on a rewrapped paragraph, the Dependabot bundle note missed a bundle rebuilt in the working tree (#4144), the guardrails PowerShell differential corpus lacked the #4683 shapes, and no check enforced #4112's third-person descriptions. ## Fix - `check-publisher-token-alignment.sh`: env overrides `PUBLISHER_TOKEN_ORG_FILE` / `PUBLISHER_TOKEN_PORT_FILE`; exits 2 when the ACTIVE marker is missing or either token set is empty. A missing token file now exits 2 instead of 1, matching the check-script contract that reserves 1 for findings (`scripts/check-publisher-token-alignment.sh:11-14`). Both files are now read through `scripts/lib/read-list.sh`, so surrounding whitespace is trimmed on both sides. The test runs fixtures for pass, padded lines, drift, renamed marker, comment-only section, empty org file, missing file and the real files. - `check-hook-exec-form.sh`: header and REMEDY text only, leading with the node launcher route. No gate logic, allowlist or exit code changed. - `lib/gate-entry.sh`: dead `GE_DISCOVERY` removed, adoption scope stated. `adr-numbers-baseline.txt` header reworded. - `lib/gate-entry.test.sh`: guard widened to the class of base-ref predicates; `ai-slop-report.sh` and `dependabot-plugin-bump.sh` migrated to the shared predicate. The allowlist entry for `gitleaks-scoped-scan.sh` is deleted, since #5316 removed that script. - `check-detector-eval-coverage.sh`: wrapper-prefixed and forwarder-with-word emit calls are reported UNRESOLVED instead of dropped; regex-engine note corrected from RE2 to Oniguruma: locally, jq 1.8.2 evaluates the lookbehind `test("(?<=a)b")` as true on `"xab"` and false on `"xcb"`, and RE2 has no lookbehind. The test diff only adds assertions (`git diff --numstat origin/main`: 278 added, 0 deleted). The test pins the walk over case patterns, offsets and replacements, five cases pin the survivors that reach behavior, and a stub `shfmt` reporting v3.12.0 must exit 2. - `check-all-skills-verb-contract.sh`: runs the checker in its root form, once per `plugins/*/skills` root in parallel. It exits 2 when the checker exits anything but 0 or 1, or when the pass/fail rollup does not add up to the skills on disk, and it attributes check-25 lines to their skill. The one live mismatch it finds, `docs-hygiene:audit-encapsulation`, sits in the new `scripts/verb-contract-baseline.txt`, which fails on a stale row. New `check-all-skills-verb-contract.test.sh` runs the real checker on fixtures and stubs a crashing and an undercounting checker. - `check-changelog-parity.sh --check-bump`: a new BUMP WITHOUT CHANGE failure for a bumped plugin whose only changes are `plugin.json` and `CHANGELOG.md`. A deliberate re-release goes in the new, empty `scripts/changelog-no-op-bumps.txt` as `<plugin>@<version>`. Tests cover the failure, a sanctioned and a mismatched opt-out, a synced-file bump, one identical sync entry across two carriers (the hook-launcher shape), and the `No change: repeats` pointer form. Existing bump fixtures now ship a file change. - `lib/html-escape.mjs` (synced to `plugins/review/lib/`): inside `<style>`, `url(`, `@import`, `expression(` and any backslash escape fail the page. Style text ends where a browser ends it: `</style` followed by whitespace, `/` or `>`, or end of input for an unclosed element. The header and `validateRenderedPage` comments no longer claim the marker proves provenance. `lib/html-escape.test.sh` adds hostile CSS cases (including closes with `</style x>`, `</style/>` and no close tag), a restamped safe page (passes) and a restamped hostile page (fails on structure alone), and renames the stale-digest case. review 0.33.8 with a CHANGELOG entry. - `check-code-metrics-skill-prose.py`: whitespace runs collapse on both sides before the substring test; the two wrapped phrases use one space. Tests: a rewrapped paragraph passes, a rewrapped wrong value fails. - `dependabot-plugin-bump.sh`: the bundle note also counts uncommitted and untracked files under the plugin. It compares against `HEAD`, not the merge base, so a pull-request merge commit does not pull in base changes. Fixtures cover a modified and an untracked dist file, and a clean tree. - `guardrails-ps-differential-corpus.jsonl`: re-harvested. It adds 53 payloads and drops none: the #4683 table shapes with their push, `commit --no-verify` and `Set-Content` forms, and the CRLF commit here-strings that must stay allowed. The hand-written section is unchanged. - New `check-skill-description-voice.sh` (+ test, registered in `check-script-contract.test.sh`): fails a description carrying `you`/`your`/`yours`/`yourself`/`yourselves` outside a quoted trigger phrase. A folded or literal block-scalar description (`>-`, `|`) is read from its continuation lines. It has `--all`, `<base-ref>` and `--paths` modes, dispatched in the script itself and listed as such in `scripts/lib/gate-entry.sh`. Not wired into CI. ## Verification Run in the worktree after merging `origin/main`: - `scripts/check-all-skills-verb-contract.sh`: PASS, 307 skills, 1 baselined, in 3 min 11 s on 24 cores. It also passes in a `--depth 1` clone of this branch (307 skills, about 13 CPU-minutes, so roughly 3 to 4 minutes on lint-2's 4 vCPUs). Before this PR every checker call exited 2. The new suite: 11 pass; 8 of the 11 fail against the old gate. The CI step has not yet run on this PR, because the draft run skipped it. It runs once the PR is flipped to ready. - `scripts/check-changelog-parity.test.sh`: 98 pass, 0 fail. The new `--check-bump`, replayed on #5162's merge, flags the ten bump-only plugins. The last 25 first-parent merges on main pass, and so do all 54 open PRs that touch a plugin manifest, each checked against its merge base with main. `--check-bump origin/main`, `--check --check-order`: pass. - `lib/html-escape.test.sh`: pass. `sync-html-escape.sh --check` and `--check-bump origin/main`: pass. - `scripts/check-publisher-token-alignment.test.sh`: 14 pass (the padded-line case fails against the old script). - `scripts/check-detector-eval-coverage.test.sh`: 172 pass. `scripts/dependabot-plugin-bump.test.sh`: 10 pass (the two dist cases fail against the old script). `scripts/check-code-metrics-skill-prose.test.sh`: 5 pass. - `scripts/check-guardrails-ps-differential.test.sh`: 21 pass. `check-guardrails-ps-differential.sh origin/main`: 666 commands, no refusal lost. - `scripts/check-skill-description-voice.test.sh`: 13 pass. `--all` reports three descriptions: provenance audit and setup ("Tells you"), testing setup ("from your answers"). - `scripts/lib/gate-entry.test.sh`: 23 pass. `scripts/check-script-contract.test.sh`: 45 pass. `scripts/check-lane-coverage.sh --check`, `scripts/check-shell-portability.sh --all`: pass. shellcheck, shfmt and ruff check are clean on changed files. - `scripts/affected-tests.sh --run`: 284 shell suites selected, 283 pass. The one failure is `scripts/hook-census.test.sh` ("strace is missing or cannot trace here"), which is this machine's environment and not this change. The non-shell suites it lists as NOT RUN include `scripts/test_check_code_metrics_skill_prose.py`, which ran above. ## Related Audit findings in `.work/audit/REPORT.md`: #4582, #4222, #4109, #3413, #3708. Issue-only items in this group, with no code here: #4288 (reopened with a decision packet), #4008 (stranded work at `refs/pull/5127/head`), #4608 (changelog parity fork-count measurement), #3694 (no action). #4222 was reopened because its 15 surviving mutants had no disposition. This PR records each one and pins the ones that reach behavior, and the issue stays open until the PR merges. Applied requests from other audit groups: core-docs (#4582 whitespace trim and decision record), code-metrics (prose-gate wrapping), miro (#4144 bundle note), ci (verb-contract gate and test; shfmt floor test), claude-memory and docs-hygiene (bump without change), hook-launcher (one-line carrier entry confirmed and pinned), claude-config (pointer-form test), review (#3605 CSS validation), guardrails (#4683 corpus), prototype (#4112 description scan), decisions-docs (#4222 and #4109 owner packets). Owner decisions opened, not implemented: - #4222: confirm the shfmt rewrite at priority low. - #4109: accept or renumber the 0039 ADR pair. - #5427: how a shared-library sync bumps its carriers (desktop-notification, biome-format, hook-launcher requests). Not taken here: - The hook-utils notice wording and the jq notice class (markdown-format, actionlint): both need a `lib/hook-utils.sh` sync that bumps 18 carriers, so they should ride the next sync of that file. - The options-docs generator wording: superseded by conventions. - The improvement cap-baseline row: it must land in the same change as the trim. - typos-format and planning: optional requests. - The claude-ops bare-placeholder warning: the argument-hint convention has no such rule yet. Still needed from others: - ci group: add `ci.yml` steps for `check-all-skills-verb-contract.test.sh`, `check-skill-description-voice.test.sh`, and the five `scripts/*.test.sh` suites with no `.github` reference (`check-publisher-token-alignment`, `check-queue-front-matter`, `check-script-contract`, `gen-hook-event-registry`, `plugin-validate-report`). Today these run only when `affected-tests` selects them on a pull request. - docs-hygiene: fix the `audit-encapsulation` description and delete its baseline row in the same change. - Plugin owners: fix the three provenance and testing descriptions. Earlier cross-group notes: tracker (README pre-flight table rows); ci (wire `check-prerequisite-probes.test.sh`, the #3413 follow-up, `silent-revert-canary.yml:97`); decisions-docs (#4658 reopen); hook-launcher (do not edit `check-hook-exec-form.sh`). 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #4027.
Folded apply tips plus leftover rows for Claude Code
2.1.257..2.1.263. Ledgerdocs/upstream/claude-code.mdnow stamps Last audited upstream state: changelog through2.1.263.changelog-status.sh --no-fetchreportslast-applied: 2.1.263.Built by Close #4027 leftovers on top of the earlier tip fold.
Added on this tip (leftovers)
claude-apicurrency, re-read in Claude Code 2.1.282 (claude-config0.51.10)--permission-prompts noneonhop_chain.py, keepingbypassPermissions(session-flow0.38.14)audit-passdoctor-handoff.mdAlready on the folded history
Surfaces, connectors, permission plane, managed-settings parse, remote-settings cache honesty,
/statusrouting, prompt-cache miss cause, plugin validate--json, skill frontmattermodel, unattended--permission-prompts none(lanes / babysit / autonomy / observer), output-cap levers, worktree / precompute git scope, and the three recorded declines (CLAUDE_CODE_SUBAGENT_MODEL_FORCE,/advisoras lane default,claude --resume <id> --bg).257-006 stale sandbox-mask nomination stays pending a human store verdict; no
docs/native-surfaces/records.jsonrow was written.Folded tips
cursor/4027-changelog-apply-one-37e9/ apply-more / remaining-decisions / permissions / adoptionsTest plan
changelog-status.sh --no-fetch→last-applied: 2.1.263plugins/session-flow/scripts/harness/hop_chain.test.sh(incl. version gate for--permission-prompts none)