Skip to content

fix(visualization): gate the design canvas clause in plugin.json - #5253

Merged
kyle-sexton merged 4 commits into
mainfrom
fix/audit-visualization
Sep 29, 2026
Merged

kyle-sexton merged 4 commits into
mainfrom
fix/audit-visualization

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Refs: #4054
Refs: #4055

Summary

The visualization plugin manifest description still carried an ungated presence claim, "where the bundled design skill is available", inside its form list. The visualize skill description dropped that phrasing in #4810, but plugin.json and the generated docs/catalog.md line kept it. The native-overlap self-check scans SKILL.md descriptions only, so CI never flagged it.

Fix

  • plugins/visualization/.claude-plugin/plugin.json: removed the clause from the form list and added one sentence using the canonical gate token: "When the bundled design skill resolves in this session, it is preferred for a hand-editable design canvas; this skill chooses the form and medium."
  • docs/catalog.md: regenerated with node scripts/generate-catalog.mjs (one line).
  • Version 0.8.1 to 0.8.2 with a CHANGELOG entry.
  • docs/native-surfaces/records.json and the regenerated docs/native-surfaces.md: the design to visualization:visualize row gains an evidence bullet quoting the gated description sentence, as the explore-directions row does (cross-group request from prototype, Refs prototype: sweep unit, gate the design canvas mention and bake the design row's integration into explore-directions #4055); the 0.8.2 CHANGELOG entry is extended, not bumped again.
  • Finding 4054 (empty PR feat(visualization): gate design canvas mention in visualize (#4054) #4928) is a historical process fact with nothing to revert; no change made for it.

Verification

  • node scripts/generate-catalog.mjs --check: catalog in sync with the manifests.
  • scripts/check-changelog-parity.sh --check --check-order: pass.
  • scripts/validate-plugins.sh: all plugin manifests and the catalog validated.
  • scripts/check-purged-em-dashes.sh --check: no em dashes.
  • The plugin has no test scripts.

Related

🤖 Generated with Claude Code

https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB

kyle-sexton and others added 2 commits September 29, 2026 01:13
Move the design-canvas mention out of the FORM list and state it behind the
"resolves in this session" gate, matching the SKILL.md description.

Refs #4054

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
kyle-sexton and others added 2 commits September 29, 2026 02:57
…ry row

The design -> visualization:visualize row claims a baked description phrase
but its evidence quoted only SKILL.md step 2. Add the gated description
sentence as an evidence bullet, matching the explore-directions row, and
regenerate the registry view.

Refs #4055

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
@kyle-sexton
kyle-sexton marked this pull request as ready for review September 29, 2026 13:30
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T13:32:36.305906Z 28650f5 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 24s —— View job


Claude finished the code review

Summary

Reviewed the diff (git diff origin/main...HEAD, 5 files, +15/-3) against this repo's CLAUDE.md/AGENTS.md conventions and the CI code-review lane's correctness/maintainability bar.

No findings clear the high-signal bar. This is a tightly-scoped fix:

  • plugins/visualization/.claude-plugin/plugin.json: removed the ungated "where the bundled design skill is available" clause from the FORM list and replaced it with a standalone gated sentence. Verified the JSON is well-formed and the new sentence conveys the same gate as the visualize skill's own frontmatter description (SKILL.md line 2), even though the two use slightly different phrasing ("prefer it for... this skill for choosing" vs. "it is preferred for... this skill chooses") — semantically equivalent, not a defect.
  • docs/native-surfaces/records.json / docs/native-surfaces.md: the new evidence bullet quoting the gated SKILL.md description was checked character-for-character against plugins/visualization/skills/visualize/SKILL.md line 2 — it matches exactly. The bullet's shape also matches the sibling explore-directions row's evidence format (docs/native-surfaces.md#L192) as the PR body claims.
  • docs/catalog.md: the updated blurb reads correctly and is internally consistent with the new plugin.json description.
  • plugins/visualization/CHANGELOG.md: entry is well-formed, correctly versioned 0.8.2, links both issues, and the "Changed" sub-entry is folded into the same release rather than bumping again, as the PR body states.
  • Searched the repo for the old ungated phrase ("where the bundled design skill is available"); the remaining hits are in CHANGELOG.md files (historical, describing the old wording) and files untouched by this PR (docs/specs/native-overlap-route-to-compose.md, plugins/claude-ops/skills/audit-native-overlap/scripts/test_overlap.py) — pre-existing and out of this PR's scope.
  • plugins/visualization/README.md:25 still says "...via the bundled design skill when that presence-gated preview is available" — this already carries explicit gating language ("presence-gated", "when... available"), so it isn't the same defect class as the one this PR fixes, and it's untouched by the diff.

Verification note: I could not execute the author's cited verification commands (node scripts/generate-catalog.mjs --check, check-changelog-parity.sh, validate-plugins.sh, check-purged-em-dashes.sh) in this sandbox — all Bash invocations were denied by the environment's permission gate. I did not re-run them, so per this lane's rule I'm not claiming to have independently verified those results; treat the PR body's verification section as author-claimed only. Manual inspection (JSON well-formedness, exact-string comparison of the quoted evidence against the actual SKILL.md/plugin.json text, and format parity with the sibling registry row) covered what a lint/script run would otherwise catch here.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 31s —— View job


Security review complete

  • Gather context (PR diff, changed files)
  • Apply skip gate
  • Review changed files for security-relevant surface
  • Check for instruction-surface deletions
  • Post final findings

No security issues found.

This PR only edits descriptive text and metadata:

  • plugins/visualization/.claude-plugin/plugin.json: description string edit (gates the "design canvas" clause behind "When the bundled design skill resolves in this session").
  • docs/catalog.md: regenerated catalog line matching the manifest description.
  • docs/native-surfaces.md / docs/native-surfaces/records.json: an added evidence bullet quoting the new gated description sentence.
  • plugins/visualization/CHANGELOG.md: changelog entry for 0.8.2.

None of this touches code execution, permissions, authentication, data handling, or trust boundaries — it's plugin-manifest/doc text only. The change tightens a presence claim (adds a conditional gate) rather than removing or weakening any guardrail, so the instruction-surface-deletion lens doesn't apply here either: no standing instruction (CLAUDE.md, AGENTS.md, a rules file, a skill/agent body, or a hook allow/deny list) is deleted, narrowed, or softened by this diff.

Skip gate applied: no security-relevant surface in this diff.

@kyle-sexton
kyle-sexton merged commit 67ad681 into main Sep 29, 2026
40 checks passed
@kyle-sexton
kyle-sexton deleted the fix/audit-visualization branch September 29, 2026 14:09
kyle-sexton added a commit that referenced this pull request Sep 29, 2026
…e-surface store (#5268)

No related issue: audit remediation of top-level docs that an unattended agent shipped without review. This PR closes nothing, and #3574, #4253 and #3616 stay owner or maintainer decisions. This run's issue operations reopened #3574 and #4253 (both now open with `status: needs-decision`).

Refs #3574 #4253 #3616 #3169 #3172 #3932 #4670 #3535 #3522 #3716 #4703 #4287 #3138 #4583 #4027 #4256 #4050 #4668

## Summary

Fixes factual and wording defects in top-level docs (`docs/*.md`, `README.md`, `AGENTS.md`) plus the native-surface store, and applies the cross-group requests other audit groups sent to this group. No doctrine decision is made or reverted. The decision packets are on the issues, not here.

## Fix

Group plan (unchanged from the first push):

- `docs/plugin-philosophy.md`, #3574 section: the refusal-reason sentence says to name every reason that applies and that at least one always does. Shape table, reasons and subaction classification are untouched.
- `docs/plugin-philosophy.md`, Skills row re-verified and re-stamped. #4253 record names `CLAUDE_CODE_EFFORT_LEVEL` as the coarse all-lanes override, fixes the count (14 `high`, 1 `medium`), and drops "Option A" and the forward-binding "Do not unpark" text. No agent file changes.
- `docs/migration-playbook.md`, #3616: only `strict` and `claude-community` are marked `proposed:`; the `bin/` row states the documented constraint and that `plugins/source-control/bin` ships a top-level `bin/`, and is marked open without choosing; the split H2 sits just before "Local development loop".

Cross-group requests applied in this push:

- `docs/cloud-sessions.md` (work-items, tracker, decisions-docs): `create-item` no longer listed as working on gh 2.45 (GraphQL 403, undefined `type:` label); lease verbs named; `list-frontier`/`list-items` routed through GitHub MCP; Cursor aside dropped; H3 promoted; both links to the deleted `cloud-session-permission-floor.md` point at #3172.
- `docs/plugin-philosophy.md` Hooks row (hook-launcher): shell form stays legal, every plugin hook row uses exec form with `node`, `node` must be on `PATH` and Claude Code does not guarantee it, and a hook that cannot start is a non-blocking error. The Windows exec-form probe record is unchanged.
- `docs/plugin-philosophy.md` (planning): `planning:plan-reviewer` recorded as the exception to the named-agent bar (one site, carried by the pin clause, no generic fallback) and to the effort lane (`medium`); its `model: opus` meets the model-tier rule because, under the fleet's pinned default session, `opus` is the session tier.
- `docs/plugin-philosophy.md` (claude-config, #4583): horizontal-decoupling block moved above the "Hardcoded consumer specifics" H3; the H3 cites the Design boundary rule and the exact standards heading. The "CI enforces that alignment" sentence stays: `scripts/validate-plugins.sh` runs the script.
- `docs/plugin-philosophy.md` (claude-ops F17): two convention-registry rows cut to scope phrases. Effort-cache paragraph re-read 2026-09-29 (page now names Sonnet 5.5); the #5154 and #5161 text was reviewed against the fetched pages and holds.
- `docs/upstream/claude-code.md` (claude-config, #4027): rows citing the closed #5059 now cite #5154, #5159 or #5161 (each checked against the merge diff); the FORCE row states the reopen condition is met and leaves reopening to the owner. The 257-083 row (claude-config, forwarded from playbooks) now states what the model-config page says (fetched 2026-09-29): Opus 5.5 starts at `medium` unless an explicit choice or a saved level sets one, a top-level `effortLevel` in the user settings file does not count for Opus 5.5 and still applies on Opus 5, Fable 5.1 and earlier, and `effortLevel` in project, local or managed settings or via `--settings` applies to every model; the item, owner surface and record #5154 are kept.
- `AGENTS.md` and the ledger row for `--permission-prompts none` (claude-ops F14): documented for print mode and unattended runs, denial under `--bg` not probed.
- `docs/native-surfaces.md` and `records.json` (claude-ops): doctor rows re-derived on v2.1.284, including the audit-skill-visibility row (the v2.1.284 binary carries Check 1's heading, "Let me pick" labels and disable mechanics, spelled with an em dash, so its observation and verified date are refreshed to 2026-09-29), second morning observation added, audit-performance recheck reworded. `overlap.py self-check --upstream-sha ed404106...` prints two advisories (older extraction versions on other rows; a recorded upstream commit that differs) and exits 3 (degraded); no CI step runs it.
- `docs/ci-runner-routing.md` (ci, tracker): "Time-to-green target" section deleted; the contract-only remedy states only what is verified and points at #4670.
- `docs/windows-lsp-epic.md` (tracker): deleted.
- `README.md` (tracker, scripts): pre-flight table gives the CI invocations (each run); #3716 status paragraph dropped.
- `docs/migration-playbook.md` (tracker, conventions F35): per-row source links, observable recheck trigger, #4668 paragraph cut to a sentence.
- `docs/out-of-scope/agent-run-artifact-attestation.md` (autonomy): Basis now cites the fetched in-toto and `actions/attest` pages; decision unchanged.
- `docs/catalog-taxonomy.md` (retro-audio): category-rename narration dropped.
- `docs/conformance-dimensions.md` dim-9 and `.worktreeinclude` (conventions): cadence left to the owner section; #4909's four lines reverted to the baseline (#4287 options not implemented).
- `docs/setup-contract-campaign-follow-ups.md` (decisions-docs): decision-neutral source fixes; the four adopt/defer rows are unchanged.

Issue operations: #3574, #4253 and #4606 reopened with a decision packet each (#4525 commented and left closed); addenda on #3574 (go-format and typos-format evidence; the context7, playwright and markdown-format evidence is already in the packet, and the "Setup is explicit and repeatable" heading is unchanged) and #3616 (fetched `bin/` rule, the `strict` and community evidence); #4051 body clause corrected with a comment. #3742 and #3739 were already reopened by the tracker group.

Repair pass: the plan-reviewer Basis states the #4849 closing comment neutrally instead of attributing it to the maintainer, and the Hooks row says every plugin hook row uses exec form (`.claude/settings.json` carries one shell-form `SessionStart` row). The #4606 acceptance-evidence comment promised a link for the criterion-3 wording fix; #5269 (42de717) landed it and the link is posted on the issue.

## Verification

- `markdownlint-cli2 --config .markdownlint-cli2.jsonc` on the 12 changed markdown files: 0 issues. `typos --config _typos.toml`: clean. `lychee --offline --config lychee.toml` on them and on the 26 files that link into them: 0 errors.
- `scripts/check-purged-em-dashes.sh`: none. `GITHUB_EVENT_NAME=pull_request scripts/ai-slop-report.sh origin/main`: no findings in 12 files.
- `scripts/validate-plugins.sh`: all manifests and the catalog validated. `scripts/check-changelog-parity.sh --check --check-order` and `--check-bump origin/main`: pass. No plugin file changes, so no version bump or CHANGELOG entry.
- README pre-flight rows run as written: `check-changelog-parity.sh --check`, `--check-bump origin/main`, `check-shell-portability.sh origin/main` all exit 0; the bare forms exit 2.
- `overlap.py generate --check` reports `docs/native-surfaces.md` in sync with `records.json`; `overlap.test.sh` and `test_overlap.py` pass. `check-conformance-registry`, `check-docs-naming`, `check-docs-only`, `check-exec-form-windows-probe`, `check-hook-exec-form`, `worktree-create` and `changelog-status` suites pass. `check-script-contract.test.sh` shows 43 pass and 2 fail, both in `check-html-assets.sh` because `htmlhint` is not installed in this worktree; neither file is touched.
- Effort-pin record: `git grep -h '^effort: high' -- 'plugins/*/agents/*.md' | wc -l` prints 14 and the `medium` grep prints 1 (`plan-reviewer`), matching the Claim and Basis in `docs/plugin-philosophy.md` after 54abc31; `research-verifier` is `high` since #5301. The #4253 packet and review addendum said 13; a correction is posted on #4253. markdownlint-cli2 on the file: 0 issues.
- Base: origin/main 2146b48 merged in, clean (later merges through 82c3172 bring in #5301). #5253 and #5300, the two branches this PR overlapped with on `docs/native-surfaces.md`, `records.json` and `docs/upstream/claude-code.md`, are both merged. `check-stale-base-overlap.sh --check origin/main` reports up to date, and `ci-status` is green on the merged head. On the merged tree `overlap.py generate --check` reports `docs/native-surfaces.md` in sync with `records.json` (22 rows); `check-conformance-registry`, `check-hook-exec-form`, `check-exec-form-windows-probe`, `check-docs-naming`, `check-docs-only` and `overlap.test.sh` pass; `test_overlap.py` runs 117 tests, OK. markdownlint, typos, `lychee --offline`, `check-purged-em-dashes.sh` and `ai-slop-report.sh` are clean on the 12 changed markdown files.

- Verifier-fix commit 0ca3350 (257-083 row, refusal-template sentence, plan-reviewer Model wording): markdownlint-cli2, typos and `lychee --offline` clean on `docs/plugin-philosophy.md` and `docs/upstream/claude-code.md`; `check-purged-em-dashes.sh`, `ai-slop-report.sh`, `validate-plugins.sh`, `check-changelog-parity.sh` (`--check --check-order`, `--check-bump origin/main`) and the `check-conformance-registry`, `check-docs-naming`, `check-docs-only`, `check-exec-form-windows-probe` and `check-hook-exec-form` suites pass. origin/main has four newer commits than the last merge; the flip to ready merges the base again.

## Related

Audit report: `.work/audit/REPORT.md` (F2, F14, F23, R3c-4253, R3e-4253, R3e-3574, R3e-3616, tracker's two 3c rows on the playbook, and the cross-group requests above).

Cross-group requests not applied here:

- `docs/conventions/invocation-mode/README.md` row for `repo-fleet-hygiene:sync` (repo-fleet-hygiene): the path belongs to the conventions group, and the table is a dated 2026-08-17 grade, so adding a verdict is a grading call. Left for conventions.
- Hold on #4240 (biome-format): the owner's Q2 is unanswered.
- Conventions' request to skip the rendered-views park section: conventions T7 removes it, as the request says.
- `.github/recurring-schedule.json` cutover-check notes (instruction-placement) and `plugins/provenance` description wording (prototype): outside the paths this group edits.
- `docs/setup-contract-campaign-follow-ups.md` orphan link (decisions-docs): waits on the owner's ruling on #3138.
- Manifest-mirror repoint (decisions-docs f38): the file is not touched here.
- Optional items: go-format `plugin.json` description reword; refreshing the line-range cites in `docs/specs/plugin-conformance-capability-matrix.md`.
- code-tidying FYI: no change needed.

Merge notes: 13 of the 19 original branch commits (8662b2a through e3e27e0) carry `Co-Authored-By: Claude Sonnet 5.5` where the repository mandates the Opus 5.5 trailer, and fixing that needs a history rewrite, so set `Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>` in the squash-merge message. #5288 deletes `cloud-session-permission-floor.md`, and this PR removes the two links to it in `docs/cloud-sessions.md`, so merge this first or in the same pass. `docs/ci-runner-routing.md` says the two-same-name-`ci-status` question is "unverified and tracked in #4670". #4670 was closed; the ci group reopened it (comment 5891976752), which is what makes that sentence true, so keep #4670 open until this merges. The deleted "Time-to-green target" section may be linked from `GOAL.md` in github-iac, which is not checked from here. The #3573 joint packet (conventions) did not exist yet; the #3574 addendum says to link it once posted.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant