fix(visualization): gate the design canvas clause in plugin.json - #5253
Conversation
Move the design-canvas mention out of the FORM list and state it behind the "resolves in this session" gate, matching the SKILL.md description. Refs #4054 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…ry row The design -> visualization:visualize row claims a baked description phrase but its evidence quoted only SKILL.md step 2. Add the gated description sentence as an evidence bullet, matching the explore-directions row, and regenerate the registry view. Refs #4055 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Claude finished @kyle-sexton's task in 1m 24s —— View job Claude finished the code review
SummaryReviewed the diff ( No findings clear the high-signal bar. This is a tightly-scoped fix:
Verification note: I could not execute the author's cited verification commands ( |
|
Claude finished @kyle-sexton's task in 31s —— View job Security review complete
No security issues found. This PR only edits descriptive text and metadata:
None of this touches code execution, permissions, authentication, data handling, or trust boundaries — it's plugin-manifest/doc text only. The change tightens a presence claim (adds a conditional gate) rather than removing or weakening any guardrail, so the instruction-surface-deletion lens doesn't apply here either: no standing instruction ( Skip gate applied: no security-relevant surface in this diff. |
…e-surface store (#5268) No related issue: audit remediation of top-level docs that an unattended agent shipped without review. This PR closes nothing, and #3574, #4253 and #3616 stay owner or maintainer decisions. This run's issue operations reopened #3574 and #4253 (both now open with `status: needs-decision`). Refs #3574 #4253 #3616 #3169 #3172 #3932 #4670 #3535 #3522 #3716 #4703 #4287 #3138 #4583 #4027 #4256 #4050 #4668 ## Summary Fixes factual and wording defects in top-level docs (`docs/*.md`, `README.md`, `AGENTS.md`) plus the native-surface store, and applies the cross-group requests other audit groups sent to this group. No doctrine decision is made or reverted. The decision packets are on the issues, not here. ## Fix Group plan (unchanged from the first push): - `docs/plugin-philosophy.md`, #3574 section: the refusal-reason sentence says to name every reason that applies and that at least one always does. Shape table, reasons and subaction classification are untouched. - `docs/plugin-philosophy.md`, Skills row re-verified and re-stamped. #4253 record names `CLAUDE_CODE_EFFORT_LEVEL` as the coarse all-lanes override, fixes the count (14 `high`, 1 `medium`), and drops "Option A" and the forward-binding "Do not unpark" text. No agent file changes. - `docs/migration-playbook.md`, #3616: only `strict` and `claude-community` are marked `proposed:`; the `bin/` row states the documented constraint and that `plugins/source-control/bin` ships a top-level `bin/`, and is marked open without choosing; the split H2 sits just before "Local development loop". Cross-group requests applied in this push: - `docs/cloud-sessions.md` (work-items, tracker, decisions-docs): `create-item` no longer listed as working on gh 2.45 (GraphQL 403, undefined `type:` label); lease verbs named; `list-frontier`/`list-items` routed through GitHub MCP; Cursor aside dropped; H3 promoted; both links to the deleted `cloud-session-permission-floor.md` point at #3172. - `docs/plugin-philosophy.md` Hooks row (hook-launcher): shell form stays legal, every plugin hook row uses exec form with `node`, `node` must be on `PATH` and Claude Code does not guarantee it, and a hook that cannot start is a non-blocking error. The Windows exec-form probe record is unchanged. - `docs/plugin-philosophy.md` (planning): `planning:plan-reviewer` recorded as the exception to the named-agent bar (one site, carried by the pin clause, no generic fallback) and to the effort lane (`medium`); its `model: opus` meets the model-tier rule because, under the fleet's pinned default session, `opus` is the session tier. - `docs/plugin-philosophy.md` (claude-config, #4583): horizontal-decoupling block moved above the "Hardcoded consumer specifics" H3; the H3 cites the Design boundary rule and the exact standards heading. The "CI enforces that alignment" sentence stays: `scripts/validate-plugins.sh` runs the script. - `docs/plugin-philosophy.md` (claude-ops F17): two convention-registry rows cut to scope phrases. Effort-cache paragraph re-read 2026-09-29 (page now names Sonnet 5.5); the #5154 and #5161 text was reviewed against the fetched pages and holds. - `docs/upstream/claude-code.md` (claude-config, #4027): rows citing the closed #5059 now cite #5154, #5159 or #5161 (each checked against the merge diff); the FORCE row states the reopen condition is met and leaves reopening to the owner. The 257-083 row (claude-config, forwarded from playbooks) now states what the model-config page says (fetched 2026-09-29): Opus 5.5 starts at `medium` unless an explicit choice or a saved level sets one, a top-level `effortLevel` in the user settings file does not count for Opus 5.5 and still applies on Opus 5, Fable 5.1 and earlier, and `effortLevel` in project, local or managed settings or via `--settings` applies to every model; the item, owner surface and record #5154 are kept. - `AGENTS.md` and the ledger row for `--permission-prompts none` (claude-ops F14): documented for print mode and unattended runs, denial under `--bg` not probed. - `docs/native-surfaces.md` and `records.json` (claude-ops): doctor rows re-derived on v2.1.284, including the audit-skill-visibility row (the v2.1.284 binary carries Check 1's heading, "Let me pick" labels and disable mechanics, spelled with an em dash, so its observation and verified date are refreshed to 2026-09-29), second morning observation added, audit-performance recheck reworded. `overlap.py self-check --upstream-sha ed404106...` prints two advisories (older extraction versions on other rows; a recorded upstream commit that differs) and exits 3 (degraded); no CI step runs it. - `docs/ci-runner-routing.md` (ci, tracker): "Time-to-green target" section deleted; the contract-only remedy states only what is verified and points at #4670. - `docs/windows-lsp-epic.md` (tracker): deleted. - `README.md` (tracker, scripts): pre-flight table gives the CI invocations (each run); #3716 status paragraph dropped. - `docs/migration-playbook.md` (tracker, conventions F35): per-row source links, observable recheck trigger, #4668 paragraph cut to a sentence. - `docs/out-of-scope/agent-run-artifact-attestation.md` (autonomy): Basis now cites the fetched in-toto and `actions/attest` pages; decision unchanged. - `docs/catalog-taxonomy.md` (retro-audio): category-rename narration dropped. - `docs/conformance-dimensions.md` dim-9 and `.worktreeinclude` (conventions): cadence left to the owner section; #4909's four lines reverted to the baseline (#4287 options not implemented). - `docs/setup-contract-campaign-follow-ups.md` (decisions-docs): decision-neutral source fixes; the four adopt/defer rows are unchanged. Issue operations: #3574, #4253 and #4606 reopened with a decision packet each (#4525 commented and left closed); addenda on #3574 (go-format and typos-format evidence; the context7, playwright and markdown-format evidence is already in the packet, and the "Setup is explicit and repeatable" heading is unchanged) and #3616 (fetched `bin/` rule, the `strict` and community evidence); #4051 body clause corrected with a comment. #3742 and #3739 were already reopened by the tracker group. Repair pass: the plan-reviewer Basis states the #4849 closing comment neutrally instead of attributing it to the maintainer, and the Hooks row says every plugin hook row uses exec form (`.claude/settings.json` carries one shell-form `SessionStart` row). The #4606 acceptance-evidence comment promised a link for the criterion-3 wording fix; #5269 (42de717) landed it and the link is posted on the issue. ## Verification - `markdownlint-cli2 --config .markdownlint-cli2.jsonc` on the 12 changed markdown files: 0 issues. `typos --config _typos.toml`: clean. `lychee --offline --config lychee.toml` on them and on the 26 files that link into them: 0 errors. - `scripts/check-purged-em-dashes.sh`: none. `GITHUB_EVENT_NAME=pull_request scripts/ai-slop-report.sh origin/main`: no findings in 12 files. - `scripts/validate-plugins.sh`: all manifests and the catalog validated. `scripts/check-changelog-parity.sh --check --check-order` and `--check-bump origin/main`: pass. No plugin file changes, so no version bump or CHANGELOG entry. - README pre-flight rows run as written: `check-changelog-parity.sh --check`, `--check-bump origin/main`, `check-shell-portability.sh origin/main` all exit 0; the bare forms exit 2. - `overlap.py generate --check` reports `docs/native-surfaces.md` in sync with `records.json`; `overlap.test.sh` and `test_overlap.py` pass. `check-conformance-registry`, `check-docs-naming`, `check-docs-only`, `check-exec-form-windows-probe`, `check-hook-exec-form`, `worktree-create` and `changelog-status` suites pass. `check-script-contract.test.sh` shows 43 pass and 2 fail, both in `check-html-assets.sh` because `htmlhint` is not installed in this worktree; neither file is touched. - Effort-pin record: `git grep -h '^effort: high' -- 'plugins/*/agents/*.md' | wc -l` prints 14 and the `medium` grep prints 1 (`plan-reviewer`), matching the Claim and Basis in `docs/plugin-philosophy.md` after 54abc31; `research-verifier` is `high` since #5301. The #4253 packet and review addendum said 13; a correction is posted on #4253. markdownlint-cli2 on the file: 0 issues. - Base: origin/main 2146b48 merged in, clean (later merges through 82c3172 bring in #5301). #5253 and #5300, the two branches this PR overlapped with on `docs/native-surfaces.md`, `records.json` and `docs/upstream/claude-code.md`, are both merged. `check-stale-base-overlap.sh --check origin/main` reports up to date, and `ci-status` is green on the merged head. On the merged tree `overlap.py generate --check` reports `docs/native-surfaces.md` in sync with `records.json` (22 rows); `check-conformance-registry`, `check-hook-exec-form`, `check-exec-form-windows-probe`, `check-docs-naming`, `check-docs-only` and `overlap.test.sh` pass; `test_overlap.py` runs 117 tests, OK. markdownlint, typos, `lychee --offline`, `check-purged-em-dashes.sh` and `ai-slop-report.sh` are clean on the 12 changed markdown files. - Verifier-fix commit 0ca3350 (257-083 row, refusal-template sentence, plan-reviewer Model wording): markdownlint-cli2, typos and `lychee --offline` clean on `docs/plugin-philosophy.md` and `docs/upstream/claude-code.md`; `check-purged-em-dashes.sh`, `ai-slop-report.sh`, `validate-plugins.sh`, `check-changelog-parity.sh` (`--check --check-order`, `--check-bump origin/main`) and the `check-conformance-registry`, `check-docs-naming`, `check-docs-only`, `check-exec-form-windows-probe` and `check-hook-exec-form` suites pass. origin/main has four newer commits than the last merge; the flip to ready merges the base again. ## Related Audit report: `.work/audit/REPORT.md` (F2, F14, F23, R3c-4253, R3e-4253, R3e-3574, R3e-3616, tracker's two 3c rows on the playbook, and the cross-group requests above). Cross-group requests not applied here: - `docs/conventions/invocation-mode/README.md` row for `repo-fleet-hygiene:sync` (repo-fleet-hygiene): the path belongs to the conventions group, and the table is a dated 2026-08-17 grade, so adding a verdict is a grading call. Left for conventions. - Hold on #4240 (biome-format): the owner's Q2 is unanswered. - Conventions' request to skip the rendered-views park section: conventions T7 removes it, as the request says. - `.github/recurring-schedule.json` cutover-check notes (instruction-placement) and `plugins/provenance` description wording (prototype): outside the paths this group edits. - `docs/setup-contract-campaign-follow-ups.md` orphan link (decisions-docs): waits on the owner's ruling on #3138. - Manifest-mirror repoint (decisions-docs f38): the file is not touched here. - Optional items: go-format `plugin.json` description reword; refreshing the line-range cites in `docs/specs/plugin-conformance-capability-matrix.md`. - code-tidying FYI: no change needed. Merge notes: 13 of the 19 original branch commits (8662b2a through e3e27e0) carry `Co-Authored-By: Claude Sonnet 5.5` where the repository mandates the Opus 5.5 trailer, and fixing that needs a history rewrite, so set `Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>` in the squash-merge message. #5288 deletes `cloud-session-permission-floor.md`, and this PR removes the two links to it in `docs/cloud-sessions.md`, so merge this first or in the same pass. `docs/ci-runner-routing.md` says the two-same-name-`ci-status` question is "unverified and tracked in #4670". #4670 was closed; the ci group reopened it (comment 5891976752), which is what makes that sentence true, so keep #4670 open until this merges. The deleted "Time-to-green target" section may be linked from `GOAL.md` in github-iac, which is not checked from here. The #3573 joint packet (conventions) did not exist yet; the #3574 addendum says to link it once posted. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Refs: #4054
Refs: #4055
Summary
The
visualizationplugin manifest description still carried an ungated presence claim, "where the bundled design skill is available", inside its form list. Thevisualizeskill description dropped that phrasing in #4810, butplugin.jsonand the generateddocs/catalog.mdline kept it. The native-overlap self-check scans SKILL.md descriptions only, so CI never flagged it.Fix
plugins/visualization/.claude-plugin/plugin.json: removed the clause from the form list and added one sentence using the canonical gate token: "When the bundled design skill resolves in this session, it is preferred for a hand-editable design canvas; this skill chooses the form and medium."docs/catalog.md: regenerated withnode scripts/generate-catalog.mjs(one line).docs/native-surfaces/records.jsonand the regenerateddocs/native-surfaces.md: thedesigntovisualization:visualizerow gains an evidence bullet quoting the gated description sentence, as theexplore-directionsrow does (cross-group request from prototype, Refs prototype: sweep unit, gate the design canvas mention and bake the design row's integration into explore-directions #4055); the 0.8.2 CHANGELOG entry is extended, not bumped again.Verification
node scripts/generate-catalog.mjs --check: catalog in sync with the manifests.scripts/check-changelog-parity.sh --check --check-order: pass.scripts/validate-plugins.sh: all plugin manifests and the catalog validated.scripts/check-purged-em-dashes.sh --check: no em dashes.Related
.work/audit/REPORT.md); both issues are already closed and stay closed, henceRefs.check_presence_mentionsinplugins/claude-ops/skills/audit-native-overlap/scripts/overlap.pyshould also scan theplugin.jsondescription so CI catches this class.designregistry row. The two-plugins-in-one-PR bundling note needed no action.🤖 Generated with Claude Code
https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB