fix(docs-hygiene): close audit findings in audit-derivability, extract-ssot, write-for-agents and the changelog - #5296
Conversation
The routing-index row said targets are readable on demand, which contradicted the rule that derivable means re-derivable from primary sources and the row that grades other markdown as duplication. Name it as an exception graded on its own row, and state that a launch-loaded routing doc is what tells the agent where to look and is never a delete. Refs #4573 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…recondition in audit-derivability Add a keep-sample protocol (size, selection, diverged/converged outcomes, recording) and sampled/overturned counts in the sweep aggregate. Make the git-log deliberate-state check a precondition for every delete and convert-to-pointer verdict, shipping provisional as "reverses a recorded decision", and resolve the Factor 1 history-versus-decision contradiction. Refs #4573 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…sts and add three audit-derivability evals The spot-test protocol said "e.g. an Explore agent", but every subagent type except Explore and Plan starts with CLAUDE.md, AGENTS.md, and project rules already loaded, so a spot-test of those files on any other type is graded by an agent that has read them. Require Explore or Plan when the audited file loads at launch, with a dated four-part record against the sub-agents doc. A custom subagent with omitClaudeMd also skips the user, project, and local files but still loads managed policy, so it is not a substitute. Add evals for a routing-only root CLAUDE.md, a converged keep-sample, and a deliberately created doc whose commit records a decision. Refs #4573 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…for the all-refused record Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
… tracker tag Collapse the three added append-flag table rows into one pointer to the CLI prompt appends section, which keeps the version floors and -p limits, and cite docs/specs/agent-doc-surfaces.md rows 26-28 as its feeder. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…odies Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…er's #4142 decision Refs #4142 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
Bump to 0.23.15 and add the changelog entry. The entry names the four released entries corrected in place (0.23.8, 0.23.9, 0.23.10, 0.23.11). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Claude finished @kyle-sexton's task in 45s —— View job Security review complete
Scope reviewed: all 11 changed files ( No security issues found. This PR is entirely prose/documentation and skill-body edits within a docs-hygiene plugin — no executable code, no input handling, no auth/access-control logic, no secrets, and no workflow-permission changes. I applied the instruction-surface lens to the two edited skill bodies (
The The new eval fixture ( Per this lane's scope: GitHub Actions/workflow hardening is deferred to zizmor and out of scope here (no workflow files changed in this PR anyway). |
|
Claude finished @kyle-sexton's task in 3m 41s —— View job Claude finished the code review
SummaryReviewed all 11 changed files under No blocking or high-signal findings. No inline comments posted. Notable checks performed:
I did not independently re-run the verification commands listed in the PR description ( |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e19eceea49
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…istory are stated The routing fixture named config/settings.json and src/, which do not exist in the reviewed tree, and its git history was the commit that created it. Eval 14 now quotes the CLAUDE.md text, states the pointer targets exist and the git log shows only ordinary edits, and the fixture file is removed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
|
Claude finished @kyle-sexton's task in 1m 27s —— View job Security review complete
Scope reviewed: all 10 changed files ( No security issues found. This is a prose/documentation-only change set in a docs-hygiene plugin — no executable code, no input handling, no auth/access-control logic, no secrets, no CI workflow files touched. Applied the instruction-surface lens (per
Per this lane's scope: GitHub Actions/workflow hardening is deferred to zizmor and out of scope here (no workflow files changed in this PR). |
|
Claude finished @kyle-sexton's task in 2m 51s —— View job Code review complete
SummaryReviewed all 10 files changed vs 1 finding posted inline — a genuine self-contradiction the PR's new text introduces in
Also verified (no issues):
Did not independently re-run the PR description's listed verification commands ( |
… the git-log precondition The routing-index exception said a launch-loaded routing doc is never delete and stays convert-to-pointer (already satisfied), while the deliberate-state precondition and worked-example Case 2 shipped the same doc provisional as reverses a recorded decision. The already-satisfied verdict recommends no change, so it reverses no decision: the precondition applies only to verdicts that recommend a change. Case 2 now uses a derivable deploy-notes doc, and eval 14 no longer expects a git-log check. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
|
Claude finished @kyle-sexton's task in 1m 30s —— View job Code review complete
SummaryReviewed the full PR diff ( No blocking findings. No inline comments posted. This head's only change since the prior review round is commit
No new issues introduced by this fix. Also re-checked the previously-flagged Codex finding on the Spot-checked the remaining unchanged files from earlier rounds ( Did not independently re-run the PR description's listed verification commands |
|
Claude finished @kyle-sexton's task in 1m 7s —— View job Security review complete
Scope reviewed: all 10 files changed vs No security issues found. This is a prose/documentation-only change set inside a docs-hygiene plugin — no executable code, no input handling, no auth/access-control logic, no secrets, no CI workflow files touched. Applied the instruction-surface lens (per
Note: this latest commit ( Per this lane's scope: GitHub Actions/workflow hardening is deferred to zizmor and out of scope here (no workflow files changed in this PR). |
Closes #4573
Refs #4142, #4713, #4700, #4701, #4027, #4657, #4661
Summary
Fixes the docs-hygiene findings from the audit of the unattended Cursor agent's 499 PRs. All changes are under
plugins/docs-hygiene/;hooks/exec-bash.mjsis untouched. Version 0.23.14 becomes 0.23.15.audit-derivability(docs-hygiene: audit-derivability has no verdict for a routing-only agent doc, and keep-sample spot-tests have no defined outcome #4573): the rubric's routing-index row contradicted its own definition of "derivable"; the keep-sample and the git-log precondition were never delivered; the fresh-context spot-test could run on an agent that had already loaded the audited file. All five items in the issue are met on this branch, so it closes.extract-ssot(docs-hygiene:extract-ssot: exhaustive identify always dispatches the survey subagent, and step 8 always persists the roster #4713):identify.mdFlags table and theFull form:line lacked--inline, and an all-refused survey had two names.write-for-agents(Apply the Claude Code 2.1.257 to 2.1.263 changelog decisions: 20 corrections, 1 native nomination, 7 adoptions, 3 declines #4027): the CLI append-flag facts were stated twice (table rows and a section) and carried a tracker tag.Fix
skills/audit-derivability/context/rubric.md: the routing-index row is a named exception to the derivable-from-primary-sources rule and never yieldsdeletefor a launch-loaded routing doc. New "Keep-sample protocol" section (size rule, diverged and converged outcomes, recording rule).git logruns before everydeleteandconvert-to-pointerthat recommends a change (convert-to-pointer (already satisfied)is exempt); a commit-recorded decision ships the verdict provisional asreverses a recorded decision. A launch-loaded audited file must be spot-tested byExploreorPlan, with a four-part verification record against the sub-agents doc.skills/audit-derivability/SKILL.md: matching sweep and spot-test text,sampled/overturnedcounts in the aggregate line and output schema.skills/audit-derivability/evals/: evals 14, 15, 16, all narration cases (routing-only root CLAUDE.md, converged keep-sample, deliberately created doc).skills/extract-ssot/:--inlinerow inidentify.md,[--inline]in theFull form:line, "closed record" used in both files.skills/write-for-agents/reference/agent-doc-surfaces.md: three flag rows collapsed to one pointer row to "CLI prompt appends"; the section citesdocs/specs/agent-doc-surfaces.mdrows 26-28; the#4027 / 261-003tag is removed.reference/plugin-contract.md,README.md: "Status: proposed" and pending the owner's decision; the Decision, Claim, Basis, As of and Recheck text is unchanged.CHANGELOG.md: bodies corrected in place, every heading kept. Edited entries: 0.23.8 (was a copy of 0.23.5), 0.23.9 (tracker item id dropped), 0.23.10 (now describes the section it shipped), 0.23.11 (was a copy of 0.23.10; no plugin file changed). New 0.23.15 entry names each.Verification
scripts/check-changelog-parity.sh --check --check-order: pass.scripts/validate-plugins.sh: all manifests and the catalog validated.plugins/skill-quality/scripts/check-evals-quality.shon the audit-derivabilityevals.json: pass.**/*.test.shunderplugins/docs-hygiene: all pass.plugins/skill-quality/scripts/check-skill.sh plugins/docs-hygiene/skills:audit-derivabilitypasses.ci-statusand both AI review lanes green on the merged head.Related
Findings from
.work/audit/REPORT.md: #4573 (3b partial delivery, 3c rubric.md:49), #4713 (findings 14-16), #4027 (findings 0 and 10), #4657 and #4661 (changelog findings 5, 8, 9), #4142 (3b and 3d decide fresh). #4700 and #4701 were already delivered in 0.23.4.Owner decision pending on #4142: split, hold, or name-only listing for the file-name set; which budget rule governs; boundary 5 versus
extract-ssot --yesandcompressbatch; ratify the charter; a shared audit entry point and a macOS runner. This PR does not choose.🤖 Generated with Claude Code
https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB