Skip to content

fix(context7): restore the lookup clause reserved by #4120 and add a model-invocable /context7:check - #5252

Merged
kyle-sexton merged 9 commits into
mainfrom
fix/audit-context7
Sep 29, 2026
Merged

kyle-sexton merged 9 commits into
mainfrom
fix/audit-context7

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Refs: #4120
Refs: #4240

Summary

Two changes to the context7 plugin from the audit of the unattended Cursor agent's PRs.

Fix

  • plugins/context7/skills/lookup/SKILL.md: the Philosophy line has the pre-Cursor text back. Nothing else in the file changed, including the description's blanket trigger.
  • plugins/context7/skills/check/SKILL.md and evals/evals.json: new skill with the shape of go-format:check, plus three evals (hook notice runs the read-only check, install request is routed not performed, passing check has no successor).
  • plugins/context7/prerequisites.json: check is now /context7:check.
  • plugins/context7/README.md, docs/skill-cheat-sheet.md (generated): list the new skill.
  • plugins/context7/.claude-plugin/plugin.json 0.5.11 to 0.6.0 (new skill), with a 0.6.0 CHANGELOG entry.
  • Cross-group request from core-docs (F18): the 0.5.10 CHANGELOG entry described the claude-ops prerequisites mechanism, not what context7 shipped. It now reads "Declares the ctx7 CLI in prerequisites.json so /claude-ops:prerequisites can report it when missing."
  • Cross-group request from core-docs (F19): the lookup **Arguments.** line ends "Default action is lookup, e.g. /context7:lookup react "useEffect cleanup"." No behavior change; recorded in the 0.6.0 entry, no second version bump.

Both use Refs, not Closes: #4120 needs an owner decision, and #4240 covers other plugins that are still open. plugins/playwright/prerequisites.json still names a human-only check; no fix group owns that plugin.

Verification

  • scripts/check-changelog-parity.sh --check --check-order: pass. --check-bump origin/main: pass.
  • scripts/validate-plugins.sh: pass (58 setup skills, catalog validated).
  • scripts/check-prerequisite-probes.test.sh: 18 cases, 0 failed.
  • scripts/check-changed-skills.sh origin/main: 2 skills checked, 0 failed (one pre-existing ## Next warning on lookup).
  • scripts/check-skill-leaf-names.sh, scripts/check-skill-count-claims.sh (24 claims, 0 mismatched), scripts/check-skill-portability.sh origin/main: pass.
  • node scripts/generate-catalog.mjs --check and node scripts/generate-cheatsheet.mjs --check: in sync.
  • markdownlint-cli2 on the changed markdown: 0 issues.
  • context7 has no test scripts of its own.

Related

🤖 Generated with Claude Code

https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB

kyle-sexton and others added 3 commits September 29, 2026 01:04
…use in lookup

The 0.5.9 removal contradicted #4120's acceptance criterion, which left the
clause unedited pending a human decision. This returns the philosophy line to
the state the issue reserved. The owner decision (keep the removal or keep the
clause) is still open on #4120.

Refs #4120

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…quisites.json at it

prerequisites.json named `/context7:setup check`, which
`disable-model-invocation: true` hides from Claude. `/context7:check`
follows only the `check` section of setup and never installs.

Refs #4240

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
Refs #4120
Refs #4240

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

PR body contract — issue linkage

This PR body conforms to the issue-linkage contract. Nothing to do.

…kup default as a sentence

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
kyle-sexton and others added 2 commits September 29, 2026 09:23
…gistry

The new /context7:check skill makes context7 a seventh owner of the accepted
`check` collision, which check-skill-leaf-names.sh --check fails until the
owner set is updated.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
@kyle-sexton
kyle-sexton marked this pull request as ready for review September 29, 2026 13:42
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T13:46:01.097052Z 37823e6 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 56s —— View job


Claude finished the /review:code-review lane

  • Gather context (PR body, diff, comments)
  • Invoke /review:code-review skill and follow its instructions
  • Post inline findings
  • Finalize summary comment

Summary

Reviewed the diff against origin/main (9 files, +108/-8), scoped to this PR's changes per the code-review lane's criteria. Cross-checked each file against the repo's own conventions (.claude/rules/skill-bodies-state-current-rules.md, scripts/check-changelog-parity.sh) and against the go-format:check / biome-format:check skills this PR says it copies the shape of.

Verified as correct:

  • plugins/context7/skills/lookup/SKILL.md: the restored philosophy clause matches the pre-0.5.9 text exactly (confirmed via git log on the file — commit fe9f6b8 did the restore, this PR's only change beyond that is the unrelated F19 sentence-phrasing edit). Only the philosophy line and the Arguments line changed; nothing else in the file was touched, as claimed.
  • plugins/context7/skills/check/SKILL.md + evals/evals.json: matches go-format:check's structure line-for-line in intent (Purpose/Check/Next/Gotchas, the same four-part upstream-drift verification record, the same ## Next shape, the same three eval cases). disable-model-invocation: false here vs. true on setup correctly makes this the model-invocable one.
  • prerequisites.json, README.md, docs/skill-cheat-sheet.md, scripts/skill-leaf-name-registry.txt: all consistent with each other and correctly alphabetized/ordered.
  • plugin.json version bump (0.5.11 → 0.6.0) is a correct minor bump for a new skill addition, monotonic vs. origin/main.

Finding posted inline (plugins/context7/CHANGELOG.md:37): the PR rewrites the body of the already-released ## [0.5.10] entry. scripts/check-changelog-parity.sh's own header comment sanctions this only "when the correcting PR names each edit in its body AND in the new release entry (#2388)" — --check-preserved only watches headings, so nothing mechanical catches the second half. The PR body names the edit (the "core-docs (F18)" note), but the new ## [0.6.0] entry doesn't mention that 0.5.10 was corrected. plugins/repo-fleet-hygiene/CHANGELOG.md:476 shows the expected declared-correction bullet shape this entry is missing.

I did not independently re-run the verification commands listed in the PR body (check-changelog-parity.sh, validate-plugins.sh, etc. — this sandbox's bash approval didn't allow script execution); those are author-claimed and unverified by me.

No other correctness or maintainability issues found in scope.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 59s —— View job


Security review — /review:security-review

  • Gather context (PR body, changed files, custom instructions)
  • Invoke /review:security-review
  • Post findings / summary

Scope reviewed (git diff origin/main...HEAD, 9 files, +108/-8): all changes are plugin/skill markdown, JSON metadata, docs, and a new eval file for the context7 plugin — no application/service code.

  • plugins/context7/skills/check/SKILL.md (new) — the only file with an allowed-tools grant. Its two entries, Bash(ctx7 --version*) and Bash(npm view ctx7 version*), are copied verbatim from the existing setup skill's own allowed-tools (plugins/context7/skills/setup/SKILL.md#L6-L8). This PR only widens invocability (disable-model-invocation: false so Claude can trigger the check on its own, vs. setup's true) — it does not introduce a new command surface, since check reads setup's own ## check section rather than accepting external input, and both allow-listed commands are read-only version lookups. Pre-existing pattern, not a new finding.
  • plugins/context7/prerequisites.json — now points the ctx7 probe at /context7:check instead of the unreachable /context7:setup check (blocked by setup's disable-model-invocation: true). This restores a working automated check rather than removing a control, so it doesn't trip the instruction-surface-deletion lens.
  • plugins/context7/skills/lookup/SKILL.md — restores a single philosophy-line clause (prose only, no behavior/tooling change).
  • Remaining files (README.md, CHANGELOG.md, plugin.json version bump, docs/skill-cheat-sheet.md, scripts/skill-leaf-name-registry.txt, evals/evals.json) are documentation/metadata/test fixtures with no security-relevant surface.

No secrets, credentials, injection, or authorization/trust-boundary issues found. No CRITICAL/IMPORTANT/SUGGESTION findings to report.
· branch fix/audit-context7

Comment thread plugins/context7/CHANGELOG.md
kyle-sexton added a commit that referenced this pull request Sep 29, 2026
…ind notice to manifest (#5284)

Refs: #4240

## Summary

Audit findings against `plugins/biome-format` for #4240 (missing-tool
prerequisites). The SessionStart probe ignored the
`biome_format_enabled` kill switch, the hook's notice text was not bound
to `prerequisites.json`, and the README, setup skill and check skill
disagreed on notice wording and left out Node and the probe. Coverage of
the other five binary-probing plugins and the two owner questions on
#4240 stay open, so this PR only refs the issue.

## Fix

- `hooks/hooks.json`: the SessionStart row launches with
`--run-if-unset-or-true BIOME_FORMAT_ENABLED` (the form typos-format
uses). `probe-prerequisite.sh` and `exec-bash.mjs` are untouched; the
probe stays byte-identical across biome-format, go-format and
markdown-format.
- `hooks/biome-format.test.sh`: runs the row as the harness spawns it,
from an empty cwd on a PATH without biome. Disabled prints nothing;
unset and true print the notice. A missing node fails the suite. A new
case binds the hook's missing-binary notice (tool name, check, install
line) and the tool's local bin path to `prerequisites.json`.
- README, `setup` and `check` skills, and their evals: the two latch
classes are stated once, Node.js and the probe are documented, the setup
check names the probe as a separate resolver, adds a Node row and
reports `biome_format_lint_gitignored`, and the check skill runs every
probe through Bash because setup's pre-computed rows are not rendered
when it reads the file.
- Release 0.7.6 with a CHANGELOG entry.
- `plugins/planning/tests/interview-defenses.test.sh`: re-pins the
interview `SKILL.md` frontmatter digest that #5042 (argument-hint only)
left stale and that failed `test-linux` on main; planning 0.45.13. Same
one-line change as #5239.
- `CHANGELOG.md`, in-place corrections to released entries (each also
named in the 0.7.6 entry): 0.7.2 said this plugin's hook rows were
unchanged although 0.7.1, the same commit, changed them; 0.6.59 and
0.6.58 described `hook::shell_c_operand` and
`hook::bash_parse_segments`, which no hook here calls. All three now
read "shared launcher/library sync; no change to this plugin's behavior"
with their issue links kept. 0.7.3 stays: `hook::begin` calls
`hook::repo_relative_path_to`. No entry is renumbered or folded.
- `docs/formatter-path-probes.md`: the dispatch-completeness block is a
pointer at #3549, and the "do not raise `PostToolUse` timeouts" guidance
is bound to the recheck (the Windows `claude --debug` result on #3549)
instead of standing as fleet guidance. The four-part record stays in
this file.

Not done, owner-reserved: whether the probe may notify in repos with no
Biome config (Q1) and whether to keep the per-plugin check skills (Q2).
No option is implemented.

## Verification

- `bash plugins/biome-format/hooks/biome-format.test.sh`: PASS=62 FAIL=0
- `bash scripts/check-prerequisite-probes.test.sh`: 18 cases, 0 failed
- `bash scripts/check-changelog-parity.sh --check --check-order`: pass
- `bash scripts/validate-plugins.sh`: all manifests and the catalog
validated
- `check-cross-plugin-source-drift.sh`, `check-hook-exec-form.sh`,
`check-killswitch-hoist.sh`, `check-skill-leaf-names.sh`,
`check-purged-em-dashes.sh`, `check-silent-skips.sh`: no findings for
this plugin
- Mutation checks (task runs): reverting the hooks.json flag fails the
disabled case; changing the install string in the hook only fails the
binding case.

## Related

- Audit report `.work/audit/REPORT.md`: row 3b #4240 (partial delivery);
plugin-biome-format findings carried by hook-launcher (probe ignores
toggle, setup check lacks node and gitignore option).
- Cross-group requests: markdown-format and go-format gate their
SessionStart rows the same way; bash-format, ruff-format, typos-format,
actionlint and powershell-format correct their 0.x.5 CHANGELOG claims;
core-docs and conventions hold the check-skill split doc edits until Q2
is answered; scripts fixes hook-utils sync bumps; hook-launcher owns
`exec-bash.mjs`.
- Cross-group requests received and handled: hook-launcher F13, F37 and
F38 (kill switch, Node and gitignore option in setup check, and the
CHANGELOG rewording above; the `biome.json` opt-in gate on the probe is
owner question Q1 on #4240 and is not implemented); markdown-format (its
probe is in the Q1 packet on #4240, option C, and stays unchanged);
context7 (noted on #4240 with draft PR #5252, plus the playwright gap);
conventions (the two `docs/formatter-path-probes.md` edits above, with
#3549 as the recheck carrier). The conventions request for the
check-skill invocation-mode doc is held with Q2.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Clears the planning interview-defenses digest failure the last CI run hit on the pre-merge base.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 46s —— View job


Claude finished the /review:code-review lane

  • Gather context (PR body, diff, comments)
  • Invoke /review:code-review skill and follow its instructions
  • Post inline findings
  • Finalize summary comment

Summary

This lane already reviewed this pull request's changes: the prior /review:code-review run ran against commit 37823e6 and covered all 9 files in this PR's diff against origin/main. I diffed the current head (4cbad88) against 37823e6 and confirmed the intervening commit (03a7bde → 4cbad88, "Merge origin/main into fix/audit-context7") is a no-op merge for every file this PR touches — git diff 37823e6..4cbad88 -- <the 9 PR files> is empty. Per this lane's skip gate ("This head already has a successful review from this lane that still applies"), I'm not re-running or re-posting duplicate findings.

Status of the prior finding: the inline comment on plugins/context7/CHANGELOG.md:37 is still open — the ## [0.6.0] entry (lines 6-23) does not yet name the in-place correction made to the already-released ## [0.5.10] entry, which scripts/check-changelog-parity.sh's own sanction condition requires. Nothing in scope of this run changed that.

No new findings to report on this head.
· branch fix/audit-context7

…ntry

The #2388 sanction needs the correcting release entry to name the edit as well as the PR body.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 35s —— View job


Security review — /review:security-review

  • Gather context (PR body, diff, comments)
  • Invoke /review:security-review
  • Post findings / summary

Scope reviewed: full PR diff (gh pr diff 5252, 9 files, +112/-8) at current branch HEAD e224112. The HEAD SHA supplied in this lane's instructions (4cbad883…) is one commit behind the branch's actual current head; I reviewed the real current state so findings reflect what's actually on the branch, and permalinks below use the real HEAD.

What's new since the last completed security review on this PR (commit 37823e6, see the earlier automated comment on this PR): exactly one commit, e224112 — a 4-line addition to plugins/context7/CHANGELOG.md declaring the 0.5.10 in-place correction (this closes out the code-review lane's earlier inline finding on this same PR). Prose-only, no security-relevant surface.

Re-verified from the full diff:

  • plugins/context7/skills/check/SKILL.md — its allowed-tools (Bash(ctx7 --version*), Bash(npm view ctx7 version*)) is copied verbatim from the existing setup skill (plugins/context7/skills/setup/SKILL.md#L5-L7), confirmed byte-for-byte identical. This PR only widens invocability (disable-model-invocation: false vs. setup's true); it doesn't add a new command surface or accept external input — both allow-listed commands are fixed, read-only version lookups the skill body issues verbatim. Pre-existing pattern, not a new finding.
  • plugins/context7/prerequisites.json — restores a working automated check (/context7:check, replacing the unreachable /context7:setup check) rather than removing a control. No instruction-surface deletion.
  • plugins/context7/skills/lookup/SKILL.md — restores a single philosophy-line clause; prose only, no behavior/tooling change.
  • Remaining files (CHANGELOG.md, plugin.json version bump, README.md, docs/skill-cheat-sheet.md, scripts/skill-leaf-name-registry.txt, evals/evals.json) are documentation/metadata/test fixtures with no security-relevant surface.

No secrets, credentials, injection, or authorization/trust-boundary issues found. No CRITICAL/IMPORTANT/SUGGESTION findings to report.
· branch fix/audit-context7

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 55s —— View job


Security review — /review:security-review

  • Gather context (PR body, diff, comments)
  • Invoke /review:security-review
  • Post findings / summary

Re-run trigger: new commit e224112 since the prior security review at 37823e6.

Scope of the delta: diffing 37823e6...e224112 restricted to this PR's 9 changed files shows exactly one change — a four-line addition to plugins/context7/CHANGELOG.md declaring the in-place correction to the released ## [0.5.10] entry (the fix for the code-review lane's earlier finding on this same PR). All other 8 files (plugins/context7/skills/check/SKILL.md, prerequisites.json, skills/lookup/SKILL.md, README.md, plugin.json, docs/skill-cheat-sheet.md, scripts/skill-leaf-name-registry.txt, skills/check/evals/evals.json) are byte-identical to what the prior security review already covered.

The new hunk is pure CHANGELOG prose: no code, no allowed-tools grant, no command surface, and no instruction-surface deletion (it adds a declaration, it doesn't remove a guardrail). No security-relevant surface in this delta.

Conclusion: the prior finding — "No secrets, credentials, injection, or authorization/trust-boundary issues found. No CRITICAL/IMPORTANT/SUGGESTION findings to report." — still applies to the full PR. Nothing new to report.
· branch fix/audit-context7

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 57s —— View job


/review:code-review lane

  • Gather context (PR body, diff, comments)
  • Invoke /review:code-review skill and follow its instructions
  • Post inline findings
  • Finalize summary comment

Summary

Re-reviewed at head e224112 (this lane's prior review at 37823e6 is superseded by the new commit). Diff is unchanged except for one addition: docs(context7): declare the 0.5.10 in-place correction in the 0.6.0 entry.

Prior finding resolved. The earlier review flagged that rewriting the released ## [0.5.10] section's body (plugins/context7/CHANGELOG.md#L41) needed a declaring bullet in the ## [0.6.0] entry to satisfy scripts/check-changelog-parity.sh's #2388 sanction (the script's own header requires the edit named "in the correcting PR's body and in the new release entry"). Commit e224112 adds exactly that: plugins/context7/CHANGELOG.md#L24-L27, **Declared in-place correction to the released ## [0.5.10] section (#2388 sanction).**.... This matches the established shape both in plugins/repo-fleet-hygiene/CHANGELOG.md:476 and in this same file's own 0.5.5 precedent (which lists four corrected sections). Touches only the CHANGELOG; nothing else in the commit.

Rest of the diff verified against precedent:

  • plugins/context7/skills/check/SKILL.md mirrors plugins/go-format/skills/check/SKILL.md structurally (Purpose/Check/Next/Gotchas, the same four-part upstream-drift verification block for disable-model-invocation) and correctly diverges where it must: it adds the allowed-tools grant for ctx7 --version / npm view ctx7 version and an explicit note that setup/SKILL.md's pre-computed-context lines don't execute on a plain file Read, so it re-runs those two probes directly. That's a real (and correctly handled) mechanical difference from go-format:check, not an inconsistency.
  • plugins/context7/skills/check/evals/evals.json matches plugins/go-format/skills/check/evals/evals.json eval-for-eval (hook/session notice → read-only check; install request → routed, not performed; passing check → no successor).
  • prerequisites.json, README.md, docs/skill-cheat-sheet.md, scripts/skill-leaf-name-registry.txt are internally consistent and correctly alphabetized.
  • lookup/SKILL.md: restored philosophy clause matches the pre-0.5.9 text; only that line and the **Arguments.** line changed.
  • plugin.json 0.5.11 → 0.6.0 is a correct, monotonic minor bump for the new skill.

No new findings. Nothing in scope for this lane to flag; the one substantive issue from the previous pass is closed out.
· branch fix/audit-context7

Keeps both the actionlint and context7 owners on the check leaf name.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 57s —— View job


Security review — /review:security-review

  • Gather context (PR body, diff, comments)
  • Invoke /review:security-review
  • Post findings / summary

Skip gate hit: #3 — this head already has a successful security review that still applies.

Current head is 666efe0 ("Merge origin/main into fix/audit-context7"). The prior completed security review on this PR (posted against e224112) found no CRITICAL/IMPORTANT/SUGGESTION issues.

I diffed e224112 666efe0 restricted to this PR's 9 changed files
(docs/skill-cheat-sheet.md, plugins/context7/**, scripts/skill-leaf-name-registry.txt).
The only deltas are merge-driven reordering in docs/skill-cheat-sheet.md and
scripts/skill-leaf-name-registry.txt — both add an unrelated actionlint:check
entry pulled in from origin/main, interleaved alphabetically around this PR's own
context7 additions. plugins/context7/ itself (the security-relevant surface —
skills/check/SKILL.md's allowed-tools grant, prerequisites.json, skills/lookup/SKILL.md)
is byte-identical to what e224112's review already covered. No new security-relevant surface
since the last completed review.

Per the skip gate, nothing further to post.
· branch fix/audit-context7

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 36s —— View job


Claude finished the /review:code-review lane

  • Gather context (PR body, diff, comments)
  • Invoke /review:code-review skill and follow its instructions
  • Post inline findings
  • Finalize summary comment

Summary

Applied the skill's skip gate: "This head already has a successful review from this lane that still applies." The last completed review on this PR ran at commit e224112 and found no outstanding issues after the earlier CHANGELOG finding was resolved.

I diffed the current head (666efe0) against e224112 restricted to this PR's 9 changed files. The only differences are two hunks in docs/skill-cheat-sheet.md and scripts/skill-leaf-name-registry.txt that add actionlint entries — content merged in from origin/main (via fix(actionlint): ... (#5264), brought in by 666efe0's "Merge origin/main into fix/audit-context7"), not authored by this PR. None of this PR's own content changed:

$ git diff e224112..666efe0 -- plugins/context7 docs/skill-cheat-sheet.md scripts/skill-leaf-name-registry.txt

shows only pre-existing actionlint lines being added around this PR's own unchanged lines — no context7 line was touched.

No new findings. The prior review's conclusions stand:

  • The ## [0.6.0] entry now declares the in-place correction to the released ## [0.5.10] section (resolves the earlier inline finding).
  • plugins/context7/skills/check/SKILL.md and its evals mirror go-format:check's structure correctly, with the documented divergence (re-running the two probes directly since setup/SKILL.md's pre-computed context doesn't execute on a plain Read).
  • prerequisites.json, README.md, docs/skill-cheat-sheet.md, scripts/skill-leaf-name-registry.txt stay internally consistent and correctly ordered.
  • lookup/SKILL.md's restored philosophy clause matches the pre-0.5.9 text; only that line and the **Arguments.** line changed.
  • plugin.json 0.5.11 → 0.6.0 is a correct, monotonic minor bump.
    · branch fix/audit-context7

@kyle-sexton
kyle-sexton merged commit 2146b48 into main Sep 29, 2026
19 checks passed
@kyle-sexton
kyle-sexton deleted the fix/audit-context7 branch September 29, 2026 15:15
kyle-sexton added a commit that referenced this pull request Sep 30, 2026
…requisite-probe wording (#5377)

Refs: #4240

## Summary

Follow-ups to the prerequisite-probe work in #4240. The owner decision
(2026-09-29) Q1 A and Q2 A were followed as written: the SessionStart
missing-tool notice fires wherever the plugin is enabled and its kill
switch is not false, and the per-plugin `/<plugin>:check` skills stay,
with the split recorded in the philosophy doc and the invocation-mode
rubric. The issue stays open: #5286 still tracks the remaining
binary-probing format plugins, so the original acceptance list is not
fully met.

## Fix

- markdown-format: hook and test comments no longer claim a config-less
repo sees no install notice; only the per-edit rewrite, findings and jq
notice are opt-in gated.
- biome-format: README and setup skill say the probe fires without a
`biome.json`.
- go-format: the owner decision asks for aligned wording in all three
format plugins, and go-format's README never mentioned its SessionStart
probe. The README Requirements and setup check step 4 now say it reports
a missing `goimports` wherever the plugin is enabled and
`go_format_enabled` is not false, including a repository with no `.go`
files.
- playwright: new model-invocable `/playwright:check` skill (with
evals), `prerequisites.json` points at it instead of the human-only
`/playwright:setup check`, README updated. Playwright has no
SessionStart probe, so the skill's trigger names a browser flow that
reports the CLI missing or a prerequisites report, not a session notice.
Its `allowed-tools` pre-approves the read-only probes that setup's
browser and `.gitignore` steps need (`command -v`, `git check-ignore`).
- `docs/plugin-philosophy.md` and
`docs/conventions/invocation-mode/README.md` record the check/setup
split and scope invocation class (ii) to setup.
- `scripts/skill-leaf-name-registry.txt`: the `check` line lists
`playwright` again, with the separator restored.

Versions, each bumped once with a CHANGELOG entry: markdown-format
0.11.84, biome-format 0.7.10, go-format 0.4.12, playwright 0.8.0.
origin/main released markdown-format 0.11.83, biome-format 0.7.9 and
go-format 0.4.11 while this was in review (it is at playwright 0.7.3),
so this branch was merged with origin/main and its entries moved above
those.

## Verification

Run on the head of this branch after merging origin/main:

- `bash scripts/check-skill-leaf-names.sh --check` exits 0 ("All 17
cross-plugin skill leaf-name collisions are registered"); `bash
scripts/check-skill-leaf-names.test.sh` PASS=16 FAIL=0.
- `bash scripts/check-prerequisite-probes.test.sh`: 51 cases, 0 failed.
- Hook suites of the three format plugins: `markdown-format.test.sh`
PASS=182 FAIL=0, `biome-format.test.sh` PASS=62 FAIL=0,
`go-format.test.sh` PASS=66 FAIL=0.
- `bash scripts/check-changelog-parity.sh --check --check-order`,
`--check-bump origin/main`, `bash scripts/validate-plugins.sh`, `bash
scripts/check-purged-em-dashes.sh --check`, `bash
scripts/check-docs-naming.sh --check` and `bash
scripts/check-skill-count-claims.sh --check` pass; `jq empty` passes on
the playwright evals.
- `bash scripts/check-changed-skills.sh origin/main`: 3 skills checked,
0 failed.
- `bash scripts/check-stale-base-overlap.sh --check origin/main`: HEAD
is up to date with origin/main.
- `markdownlint-cli2` on the edited changelogs, the go-format README and
setup skill, `docs/plugin-philosophy.md` and the playwright README and
check skill: 0 issues.
- `bash scripts/affected-tests.sh --run --jobs 4` ran the 290 selected
shell suites (17 more are Python, Node or PowerShell and are not run by
that runner). 287 pass and 3 fail for host reasons unrelated to this
diff: `scripts/check-html-assets.test.sh` and
`scripts/check-script-contract.test.sh` need `htmlhint` (`run npm ci`,
not installed in this worktree), and `scripts/hook-census.test.sh` needs
`strace`. None of the three covers a file this PR touches.

## Related

- #4240 (stays open), #5286 (remaining format plugins)
- Earlier work: #5284, #5266, #5275, #5252, #5264
- Not covered here: disk-hygiene's Python-missing notice
(`plugins/disk-hygiene/hooks/run-python-hook.sh`) still names
`/disk-hygiene:setup check`, which the new philosophy rule says a hook
should not do. It is the only such hook notice in the tree and is
tracked in #5436.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant