Skip to content

fix(planning,session-flow): drop arguments: frontmatter from prd and workflow - #5212

Merged
kyle-sexton merged 1 commit into
mainfrom
fix/4001-arguments-pilots
Sep 29, 2026
Merged

kyle-sexton merged 1 commit into
mainfrom
fix/4001-arguments-pilots

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Refs: #4001

Summary

The operator declined the arguments: frontmatter field on #4001 and directed the two remaining pilots, planning:prd and session-flow:workflow, off it. This migrates both to the convention in docs/conventions/skill-argument-shape/README.md: the body reads $ARGUMENTS whole.

Fix

  • plugins/planning/skills/prd/SKILL.md: remove arguments: [tier]; the action parse reads the first word of $ARGUMENTS as the tier word, and an empty $ARGUMENTS still means ask for the tier.
  • plugins/session-flow/skills/workflow/SKILL.md: remove arguments: [mode, modifier]; the first word of $ARGUMENTS is the mode, and after continue the second word is the modifier. Missing or non-auto modifier stays suggest-only.
  • argument-hint unchanged in both. No evals, references or tests used $tier, $mode or $modifier.
  • planning 0.45.9 -> 0.45.10, session-flow 0.38.25 -> 0.38.26, with CHANGELOG entries.

Verification

  • scripts/validate-plugins.sh: all manifests and the catalog validated.
  • scripts/check-changelog-parity.sh --check --check-order: pass.
  • scripts/check-changed-skills.sh origin/main: 2 skills checked, 0 failed.
  • Every *.test.sh under plugins/planning and plugins/session-flow: pass, except plugins/planning/surface/surface.test.sh ui_c.3, which fails identically on origin/main (browser timing, unrelated).
  • grep for $tier|$mode|$modifier|arguments: under both plugins: only historical CHANGELOG entries remain.

Related

🤖 Generated with Claude Code

…workflow

Both pilots now read $ARGUMENTS whole, per the skill-argument-shape
convention and the #4001 decline of the arguments: field.

Refs #4001

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Hx63mvV8t39y644DQ3uLnn
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T01:42:17.846153Z 32b811a PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 14s —— View job


Code review — /review:code-review

  • Gather context (PR diff via gh pr diff 5212, convention doc, repo-wide grep)
  • Understand the request (CI code-review lane per custom instructions)
  • Review changed files
  • Report findings

Scope: 6 files, 2 skills (planning:prd, session-flow:workflow) dropping the arguments: frontmatter field per the skill-argument-shape convention, plus the two plugin version bumps and CHANGELOG entries.

Findings: none. This is a clean, tightly-scoped migration:

  • Both SKILL.md bodies now parse $ARGUMENTS whole exactly as the convention prescribes (first word as action/mode, remainder as subject/modifier), and argument-hint is correctly left untouched since it's independent of the arguments: field.
  • Confirmed no other SKILL.md in the repo still declares arguments: frontmatter, so this completes the migration rather than leaving a mixed state.
  • Grepped both skills' bodies, and session-flow:workflow's evals/evals.json, for stray $tier / $mode / $modifier references — none found, matching the PR's own claim.
  • scripts/validate-plugin-contracts.mjs's admitsArguments() check (the thing that gates unescaped $N in argument-taking skills) keys off argument-hint and $ARGUMENTS in the body, not the arguments: field, so removing it doesn't change that gate's behavior for either skill.
  • CHANGELOG entries and version bumps follow the existing format in both files; the marketplace catalog doesn't track per-plugin versions, so no update was needed there.
  • The PR's described verification commands (validate-plugins.sh, check-changelog-parity.sh, check-changed-skills.sh, the *.test.sh suites) are author-claimed; I did not independently re-run them.

No inline comments filed — nothing meets the bar for a blocking or flagged finding.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 28s —— View job


Security review: no findings

  • Gather context (PR diff, changed files)
  • Check skip-gate conditions (open PR, security-relevant surface, instruction-surface deletion lens)
  • Review changed files for security issues
  • Post findings or a clean-review statement

Scope reviewed (full diff via git show HEAD, PR's single commit 32b811a):

  • plugins/planning/skills/prd/SKILL.md — drops arguments: [tier] frontmatter, rewrites the Action Router paragraph to parse $ARGUMENTS in prose instead.
  • plugins/session-flow/skills/workflow/SKILL.md — drops arguments: [mode, modifier] frontmatter, same prose rewrite for mode/modifier parsing.
  • plugins/planning/.claude-plugin/plugin.json, plugins/session-flow/.claude-plugin/plugin.json — version bumps only.
  • plugins/planning/CHANGELOG.md, plugins/session-flow/CHANGELOG.md — changelog entries only.

Analysis:

  • No code execution surface: both SKILL.md bodies use $ARGUMENTS/$tier/$mode/$modifier only as prose the model reads to route its own behavior — confirmed via plugins/planning/skills/prd/SKILL.md#L73 and plugins/session-flow/skills/workflow/SKILL.md#L57. Neither file interpolates these into a shell/run: block, so there's no new injection surface from the reformatting.
  • The arguments: frontmatter field being dropped carries no security function to begin with: per docs/conventions/skill-argument-shape/README.md, named arguments are "only positional aliases" and, per the harness docs it cites, the field performs no validation, escaping, or parsing — $ARGUMENTS was already the same raw, unvalidated string either way. Behavior for malicious/adversarial argument content is unchanged before and after this diff.
  • Instruction-surface deletion lens: checked the removed arguments: lines against the instruction exception register's Gate 0 classes (irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority). No match — the field was declarative, non-enforcing documentation sugar, not a guardrail, and docs(conventions): define the skill argument shape — positional action and subject, earned --flag modifiers #4001's own addendum declined it specifically because "the field adds no validation." Nothing is left unchecked by its removal.
  • Remaining changes (version bumps, changelog prose) have no security surface.

No security issues found in this PR.

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

PR body contract — issue linkage

This PR body conforms to the issue-linkage contract. Nothing to do.

@kyle-sexton
kyle-sexton merged commit c85f058 into main Sep 29, 2026
27 checks passed
@kyle-sexton
kyle-sexton deleted the fix/4001-arguments-pilots branch September 29, 2026 01:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant