fix(session-flow): audit remediation (observer flag gate, export records, unattended parsing) - #5239
Conversation
…erver The observer appended --permission-prompts none unconditionally, while hop_chain.py gated it on Claude Code 2.1.259 because older CLIs reject it as an unknown option. Move the version probe and gate into scripts/claude_cli.py and use it from both, so an older CLI runs the analysis with dontAsk alone instead of failing. Refs #4027 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
… adds a no-live-reading fallback Exit 1 is provisional until a live re-check of the current account confirms it. When no live reading is obtainable, ask the operator instead of concluding still-blocked. The verification record quotes the fetched docs, drops /rate-limit-options from the live sources, and the rule is stated once. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
… guard creation The /export suggest sentence in clean-stop, handoff, and retro pointed at a verification record "in this section" that did not exist. Each skill now carries a same-file four-part record (claim, basis, as-of date, recheck trigger) and the sentence names its heading. The record states that /export has no documented disable switch. The sentence also dropped the create-and-announce behaviour for the memory root's self-ignore guard; it is restored at all three sites. In retro the sentence ended a paragraph with a stray "When the" and now stands alone. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…retro and clean-stop The three skills declared `unattended` in argument-hint but their parse sections never consumed it, so handoff read it as the topic or a method and retro read it as a mode. Each Arguments/mode section now strips it first and scopes it to the /export step; evals cover both parse paths. Refs #4056 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…n substitution
Add a four-part verification record for CLAUDE_PLUGIN_DATA in structure.md and
point find-handoff, topic-docs and save_point._plugin_data_root at it. The
plugins-reference page does not say Read-tool files or the ${VAR:-default} form
are substituted, so the running-retro arm block uses a plain substituted token
and the retro context files point at the score-history path SKILL.md states.
Refs #4295
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…s it left stale Refs #4295 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…doff with dispatch, link the pending-CI record Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
|
PR body contract — issue linkage This PR body conforms to the issue-linkage contract. Nothing to do. |
…at /export is reserved for the person Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Claude finished @kyle-sexton's task in 3m 35s —— View job Code review (
|
|
Claude finished @kyle-sexton's task in 1m 29s —— View job Security review completeRan
No security issues found. Scope covered:
No GitHub Actions workflow files are touched by this PR. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 75a8dc582e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
… restore the em dash in setup evals Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
|
Claude finished @kyle-sexton's task in 3m 2s —— View job Code review (
|
|
Claude finished @kyle-sexton's task in 2m 56s —— View job Security review (
|
…ument-hint rewrite #5042 shortened the argument-hint key in skills/interview/SKILL.md and moved the examples to the body. Neither defense pinned by interview-defenses.test.sh is touched by that change, so the whole-frontmatter digest is updated. The suite was failing on main for every pull request. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…rview frontmatter digest - setup check: Node.js stays FAIL when the toggle is off (the runner starts node before the gate runs) and a Bash PASS is scoped to Bash's PATH; the probe's walk limit and file tests are read from probe-prerequisite.sh instead of restated. - planning: re-pin the interview SKILL.md frontmatter digest. #5042 shortened the argument-hint key only (the two defenses are body prose, digested separately), and the stale digest fails test-linux on main. Same one-line change as #5239. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
|
Claude finished @kyle-sexton's task in 2m 5s —— View job Code review (
|
|
Claude finished @kyle-sexton's task in 44s —— View job Security review (
|
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
|
Claude finished @kyle-sexton's task in 34s —— View job Code review (
|
|
Claude finished @kyle-sexton's task in 37s —— View job Security review (
|
…ind notice to manifest (#5284) Refs: #4240 ## Summary Audit findings against `plugins/biome-format` for #4240 (missing-tool prerequisites). The SessionStart probe ignored the `biome_format_enabled` kill switch, the hook's notice text was not bound to `prerequisites.json`, and the README, setup skill and check skill disagreed on notice wording and left out Node and the probe. Coverage of the other five binary-probing plugins and the two owner questions on #4240 stay open, so this PR only refs the issue. ## Fix - `hooks/hooks.json`: the SessionStart row launches with `--run-if-unset-or-true BIOME_FORMAT_ENABLED` (the form typos-format uses). `probe-prerequisite.sh` and `exec-bash.mjs` are untouched; the probe stays byte-identical across biome-format, go-format and markdown-format. - `hooks/biome-format.test.sh`: runs the row as the harness spawns it, from an empty cwd on a PATH without biome. Disabled prints nothing; unset and true print the notice. A missing node fails the suite. A new case binds the hook's missing-binary notice (tool name, check, install line) and the tool's local bin path to `prerequisites.json`. - README, `setup` and `check` skills, and their evals: the two latch classes are stated once, Node.js and the probe are documented, the setup check names the probe as a separate resolver, adds a Node row and reports `biome_format_lint_gitignored`, and the check skill runs every probe through Bash because setup's pre-computed rows are not rendered when it reads the file. - Release 0.7.6 with a CHANGELOG entry. - `plugins/planning/tests/interview-defenses.test.sh`: re-pins the interview `SKILL.md` frontmatter digest that #5042 (argument-hint only) left stale and that failed `test-linux` on main; planning 0.45.13. Same one-line change as #5239. - `CHANGELOG.md`, in-place corrections to released entries (each also named in the 0.7.6 entry): 0.7.2 said this plugin's hook rows were unchanged although 0.7.1, the same commit, changed them; 0.6.59 and 0.6.58 described `hook::shell_c_operand` and `hook::bash_parse_segments`, which no hook here calls. All three now read "shared launcher/library sync; no change to this plugin's behavior" with their issue links kept. 0.7.3 stays: `hook::begin` calls `hook::repo_relative_path_to`. No entry is renumbered or folded. - `docs/formatter-path-probes.md`: the dispatch-completeness block is a pointer at #3549, and the "do not raise `PostToolUse` timeouts" guidance is bound to the recheck (the Windows `claude --debug` result on #3549) instead of standing as fleet guidance. The four-part record stays in this file. Not done, owner-reserved: whether the probe may notify in repos with no Biome config (Q1) and whether to keep the per-plugin check skills (Q2). No option is implemented. ## Verification - `bash plugins/biome-format/hooks/biome-format.test.sh`: PASS=62 FAIL=0 - `bash scripts/check-prerequisite-probes.test.sh`: 18 cases, 0 failed - `bash scripts/check-changelog-parity.sh --check --check-order`: pass - `bash scripts/validate-plugins.sh`: all manifests and the catalog validated - `check-cross-plugin-source-drift.sh`, `check-hook-exec-form.sh`, `check-killswitch-hoist.sh`, `check-skill-leaf-names.sh`, `check-purged-em-dashes.sh`, `check-silent-skips.sh`: no findings for this plugin - Mutation checks (task runs): reverting the hooks.json flag fails the disabled case; changing the install string in the hook only fails the binding case. ## Related - Audit report `.work/audit/REPORT.md`: row 3b #4240 (partial delivery); plugin-biome-format findings carried by hook-launcher (probe ignores toggle, setup check lacks node and gitignore option). - Cross-group requests: markdown-format and go-format gate their SessionStart rows the same way; bash-format, ruff-format, typos-format, actionlint and powershell-format correct their 0.x.5 CHANGELOG claims; core-docs and conventions hold the check-skill split doc edits until Q2 is answered; scripts fixes hook-utils sync bumps; hook-launcher owns `exec-bash.mjs`. - Cross-group requests received and handled: hook-launcher F13, F37 and F38 (kill switch, Node and gitignore option in setup check, and the CHANGELOG rewording above; the `biome.json` opt-in gate on the probe is owner question Q1 on #4240 and is not implemented); markdown-format (its probe is in the Q1 packet on #4240, option C, and stays unchanged); context7 (noted on #4240 with draft PR #5252, plus the playwright gap); conventions (the two `docs/formatter-path-probes.md` edits above, with #3549 as the recheck carrier). The conventions request for the check-skill invocation-mode doc is held with Q2. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…ng label and harness exemption - clean-stop, handoff and retro: the /export checklist line now asks the person to run it instead of contradicting itself. - save_point.py: replace the stray `ponytail:` label with `Caveat:`. - hop_chain.py: judge the read-only save_point.py exemption per command segment, so a chained second interpreter call still counts as a write; two contract tests added. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
Take origin/main's planning release 0.45.13, which already carries the interview digest re-pin. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
|
Claude finished @kyle-sexton's task in 1m 13s —— View job Security review (
|
|
Claude finished @kyle-sexton's task in 1m 23s —— View job Code review (
|
No related issue: audit remediation, the linked issues are Refs only
Summary
Remediates the session-flow findings of the audit of the unattended Cursor run (
.work/audit/REPORT.md). Every linked issue is aRefs: none has all its criteria met on this branch. #3915 is ratified and stays closed. #4056 waits on the claude-ops close ritual. #4295 and #4284 are only partly addressed here. #4661 waits on the architecture and improvement description trims. #3952 and #3953 are owner decisions, so no option is implemented and the Park text stays. Releases session-flow 0.38.28.Fix
--permission-prompts noneis gated on Claude Code 2.1.259+ by the version helper inscripts/claude_cli.py, shared withhop_chain.py(Apply the Claude Code 2.1.257 to 2.1.263 changelog decisions: 20 corrections, 1 native nomination, 7 adoptions, 3 declines #4027).keep-going: exit1ofcheck-usage-limit-reset.pyis provisional until a live re-check of the current account; with no live reading it asks the operator.clean-stop,handoffandretro: the/exportsuggest sentence points at a real same-file record, and the self-ignore guard is created and announced when absent.handoff,retroandclean-stopparse the leadingunattendedargument, with evals.save_point.py memory-rootis documented on the stale surfaces and allowed in the hop harness.orchestraterecords the hung-background-shell claim,handoffmatchesimplement-dispatch, and the pending-CI record is linked.nodeprobe insetup'scheck(every hook row launches throughnode hooks/exec-bash.mjs).setup's eval prompts carry the literal em dash instead of—escapes.Verification
scripts/validate-plugins.sh: all manifests and the catalog validated.scripts/check-changelog-parity.sh --check --check-order: pass.pytest plugins/session-flowviauv run --with pytest: 243 passed, 6 subtests passed.plugins/session-flow/scripts/save_point.test.shandscripts/harness/hop_chain.test.sh: pass.check-skill.shoverplugins/session-flow/skills: 14 passed, 0 failed.check-listing-budget.sh: 6123/8000, no skill description changed.check-changed-skills.sh origin/main: 7 checked, 0 failed.Related
Refs: #3915
Refs: #3952
Refs: #3953
Refs: #4056
Refs: #4284
Refs: #4295
Refs: #4661
Findings in
.work/audit/REPORT.md: #4027 (observer flag, owned by claude-config), #3915, #4056, #4295, #4661, #3952 and #3953 (owner decisions, reopened with decision packets).Cross-group requests applied here: work-items (setup eval escapes) and hook-launcher (Node.js declaration, 0.38.22 wording). The tracker, improvement and decisions-docs requests on #4661 became one addendum comment; no owner decision was implemented.
Cross-group requests sent elsewhere:
docs/conventions/topic-docs/README.md:552; delete or reducedocs/out-of-scope/skill-listing-500-char-exceptions.mdand the matching lines ofdocs/conventions/invocation-mode/README.md.Refs #4661)./exportrecords indocs/native-surfaces/records.json.docs/upstream/claude-code.md:62at this PR and comment on Apply the Claude Code 2.1.257 to 2.1.263 changelog decisions: 20 corrections, 1 native nomination, 7 adoptions, 3 declines #4027 with its link.🤖 Generated with Claude Code
https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB