Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
5f3064b
fix(claude-config): drop dead repo-root link from conflict-criteria
kyle-sexton Sep 29, 2026
7ff898e
fix(claude-config): align the findings relay with criteria.md surface…
kyle-sexton Sep 29, 2026
2ad68e7
fix(claude-config): refuse non-instruction files under home in findin…
kyle-sexton Sep 29, 2026
06bc4ea
fix(claude-config): admit a skill's own files under home in finding-ids
kyle-sexton Sep 29, 2026
587918f
docs(claude-config): delete audit-instructions execution-and-report.m…
kyle-sexton Sep 29, 2026
f599a9c
docs(claude-config): audit-instructions records the subagent-window c…
kyle-sexton Sep 29, 2026
5b35c9f
fix(claude-config): state the unattended-lane note on the live-hook a…
kyle-sexton Sep 29, 2026
1754c23
fix(claude-config): unhobble: one deletion warrant, no silence as evi…
kyle-sexton Sep 29, 2026
e4bcd22
fix(claude-config): unhobble: product-surface class, session branch, …
kyle-sexton Sep 29, 2026
78fc858
feat(claude-config): unhobble: status fields, ledger grouping, decide…
kyle-sexton Sep 29, 2026
af55f3a
fix(claude-config): review the #5154 defaultMode lint, scan string-on…
kyle-sexton Sep 29, 2026
db120c6
fix(claude-config): qualify the defaultMode masking claim, state the …
kyle-sexton Sep 29, 2026
fb25a5e
docs(claude-config): update README for audit-instructions flags and u…
kyle-sexton Sep 29, 2026
7d07ab0
docs(claude-config): collapse repeated #4027 changelog entries, recor…
kyle-sexton Sep 29, 2026
ae299bd
Merge origin/main into fix/audit-claude-config
kyle-sexton Sep 29, 2026
9af637f
chore(claude-config): release 0.52.0
kyle-sexton Sep 29, 2026
28a4d13
fix(claude-config): silence SC2016 on the reachx rule fixture line
kyle-sexton Sep 29, 2026
f7b296a
Merge remote-tracking branch 'origin/main' into fix/audit-claude-config
kyle-sexton Sep 29, 2026
3e1d98b
fix(claude-config): restate effort defaults and the state-write gotch…
kyle-sexton Sep 29, 2026
5cb0e0d
Merge branch 'main' into fix/audit-claude-config
kyle-sexton Sep 29, 2026
091b82f
Merge branch 'main' into fix/audit-claude-config
kyle-sexton Sep 29, 2026
5be292f
fix(claude-config): validate defaultMode type and stamp the 200000 fa…
kyle-sexton Sep 29, 2026
ea8e674
fix(claude-config): keep a wrong-typed defaultMode from hiding disabl…
kyle-sexton Sep 29, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion plugins/claude-config/.claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json",
"name": "claude-config",
"version": "0.51.30",
"version": "0.52.0",
"description": "Nine configuration-health skills (plus setup) for a repo's Claude Code configuration: audit (settings.json / .mcp.json / hooks / plugins / permissions drift), audit-automation-gaps (evidence-gated verdicts on automation gaps), audit-permission-grants (allow-rule / allowed-tools grants for auto-mode durability and portability), audit-permission-state (the permission rules actually in effect: every settings scope merged with per-rule provenance, what auto mode drops on entry, config written where nothing reads it, and which managed intents are enforced versus loosenable), draft-auto-mode-rules (interview and draft a paste-ready autoMode classifier block; prints only, never writes), audit-instructions (locally-owned instruction surfaces vs current model capability, proposing removals/rewrites of instructions the model no longer needs, and detecting cross-surface instruction conflicts), audit-prompting-postures (the additive lane: posture guidance the prompting guide says a component's purpose needs but the component does not carry), audit-pass (one coordinated, ordered, resumable pass over a named target: three-scope inventory, run-time-derived exclusion set, stable finding identity, suppression memory, resume, one human gate, delegating every check to the plugin that owns it), and unhobble (the empirical bare-baseline experiment: reversibly strip a repo's standing instructions, log real stumbles against the current model, re-add only what evidence earns).",
"author": {
"name": "Melodic Software",
Expand Down
106 changes: 86 additions & 20 deletions plugins/claude-config/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,88 @@
All notable changes to the `claude-config` plugin are documented here. Format follows
[Keep a Changelog](https://keepachangelog.com/en/1.1.0/); this plugin uses semantic versioning.

Versions 0.51.8 to 0.51.9 and 0.51.11 to 0.51.14 were reserved by parallel branches and never released.

## [0.52.0] - 2026-09-29

### Added

- **`unhobble`: a `decide` argument.** `decide` lists an experiment's open decisions and, when the
`discovery` plugin is installed, researches each one and gives the memo to two blind decision
agents. Agreement is presented for confirmation and disagreement returns to the operator as a
question. It never mutates ([#4094](https://github.com/melodic-software/claude-code-plugins/issues/4094)).
- **`unhobble`: `status` prints phase, elapsed days, ledger row count, register holds, confounds,
and the pull request URL.** The manifest gains `phase`, `branch_deviation`, and an optional
`pr_url`. `readd` refuses to run while the phase is `bare` or `observe` and reports the ledger
grouped by suspected missing instruction against the two-row gate (#4094).

### Changed

- **`unhobble`: a convention unit's default follows an oracle test.** A gating oracle strips the
prose and keeps the gate, an advisory oracle or none keeps the unit, and a register class is kept
whatever the test says. A unit under `plugins/<name>/` is recorded as
`unstripped-product-surface` and never stripped, and a session pinned to a branch uses it as the
experiment branch (#4094).
- **`unhobble`: silence is no longer a deletion warrant.** An empty ledger licenses deleting an
editorial candidate only. A consequential rule the ledger did not defend goes to a Deletion watch
or is restored, and only a closed watch makes its removal permanent. The watch counts qualifying
sessions as fresh sessions on the experiment branch
([#3563](https://github.com/melodic-software/claude-code-plugins/issues/3563)).
- **`audit-instructions`: the findings relay follows `criteria.md` surfaces and tiers.** I31 and I33
admit any file inside a skill directory (I33 excludes `SKILL.md`), I33 names the nearest ancestor
`SKILL.md` as its hub, and I32 is CRITICAL under `plugins/` and IMPORTANT on a user or project
surface ([#4116](https://github.com/melodic-software/claude-code-plugins/issues/4116),
[#4656](https://github.com/melodic-software/claude-code-plugins/issues/4656)).
- **`audit-instructions`: the subagent-window claim carries a verification record, the read-only
contract covers lane reports and run-state writes, and I33 rows count as one dispatch outside the
per-lane verifier batches.** `context/execution-and-report.md` is deleted; `SKILL.md`, the
finding-identity reference, and `context/persist-findings.md` own what it restated
([#4113](https://github.com/melodic-software/claude-code-plugins/issues/4113),
[#4114](https://github.com/melodic-software/claude-code-plugins/issues/4114),
[#4115](https://github.com/melodic-software/claude-code-plugins/issues/4115)).
- **`README.md`** describes the `audit-instructions` flags and the `unhobble` state fields.

### Fixed

- **`audit-instructions`: I21 and the `audit` effort-pin row state the current effort defaults.**
The default carve-out named only Opus 4.7 as a non-`high` default; the model-config page's
resolution order also has Opus 5.5 and Sonnet 5.5 defaulting to `medium`, so the "`high` is the
default" exemption lifts for them too. The stale first-run-hold clause is removed from Source,
and Verified and the recheck trigger follow the 2026-09-28 read of both pages.
- **`unhobble`: the state-write gotcha and its eval no longer restate the `block-hook-bypass`
exit code or call a heredoc alone a blocked form.** The skill says why a shell write is wrong and
leaves what the hook catches to its README.
- **`audit-instructions`: `finding-ids.sh` no longer hashes a non-instruction file under `$HOME`.**
A row naming `~/.ssh/config` or `~/.claude/.credentials.json` is refused as
`surface-not-an-instruction-file`. The user surface stays home-wide for instruction-file shapes
(any markdown file, and `settings.json`, `settings.local.json`, `hooks.json` inside a `.claude`
tree or the resolved `CLAUDE_CONFIG_DIR`, plus any file beneath a `skills/` directory in those
trees) (#4116).
- **`audit-instructions`: the I15 ledger link in `conflict-criteria.md` no longer points outside the
repository.** It names the path in code font
([#3568](https://github.com/melodic-software/claude-code-plugins/issues/3568)).
- **`audit`: the row for a live `PreToolUse` hook that already blocks a pattern carries the
unattended-lane note** like the other ask-rule rows
([#4600](https://github.com/melodic-software/claude-code-plugins/issues/4600)).
- **`audit-permission-state`: a settings file whose last `permissions` key is a string is no longer
rejected as invalid JSON.** `{"permissions":{"defaultMode":"bypassPermissions"}}` is now scanned,
so `C2-defaultMode` and `C5-disableType` fire on real files. Both `C2-defaultMode` findings say to
remove the value from the named file and state the masking claim only where no higher-ranked
settings file or `--permission-mode` sets a mode. The unsourced auto version boundary is removed
([#4027](https://github.com/melodic-software/claude-code-plugins/issues/4027)).
- **`audit-instructions`: the 200000-token lane-window fallback carries a recheck trigger.** The
claim, basis, as-of date and trigger sit beside the fallback in `SKILL.md`.
- **`audit-instructions`: `emit-findings.sh` finds the I33 hub when run from a repository
subdirectory with relative paths.** The hub probe now starts from the repository root instead of
the working directory.

In-place changelog corrections:

- 0.51.18: body replaced by a pointer; it repeated the 0.51.16 Fixed entry (released by #5159) and the 0.51.10 Changed entry (released by #5161).
- 0.51.17: body replaced by a pointer; it repeated the 0.51.15 entry (released by #5156).
- 0.51.7: states it shipped through #5154 (commit 9c2db71f6), not #5059 (closed unmerged).
- File header: notes that 0.51.8 to 0.51.9 and 0.51.11 to 0.51.14 were reserved by parallel branches and never released.

## [0.51.30] - 2026-09-28

### Changed
Expand Down Expand Up @@ -125,29 +207,11 @@ All notable changes to the `claude-config` plugin are documented here. Format fo

## [0.51.18] - 2026-09-28

### Fixed

- **Permission surfaces now match Claude Code 2.1.257–2.1.263** ([#4027](https://github.com/melodic-software/claude-code-plugins/issues/4027)). Read and Edit deny rules cover Bash redirect targets from v2.1.257; the v2.1.259 widening to every Bash argument was reverted in v2.1.260 and is not written in ([permissions](https://code.claude.com/docs/en/permissions)). `allowManagedPermissionRulesOnly` ignores `--allowedTools` and user, project, and local rules; `--disallowedTools` and session deny and ask rules stay across reloads ([settings reference](https://code.claude.com/docs/en/settings-reference#allowmanagedpermissionrulesonly)). The ask-rule contract is quoted from the [auto mode config](https://code.claude.com/docs/en/auto-mode-config) page; #42797 is closed, #83766 is open, and v2.1.257 fixed compound and subshell paths only. `strictPluginOnlyCustomization` is `true` or a per-surface array; `"mcp"` blocks user and project MCP servers and does not switch hooks off ([settings reference](https://code.claude.com/docs/en/settings-reference#strictpluginonlycustomization)). Interactive `!` shell mode runs outside the sandbox even in strict mode from v2.1.260 ([sandboxing](https://code.claude.com/docs/en/sandboxing)). A managed settings file, drop-in, plist, or HKLM value that cannot be parsed refuses startup; a user settings parse failure warns in `/status` ([managed settings](https://code.claude.com/docs/en/managed-settings), [settings](https://code.claude.com/docs/en/settings)). Server-managed settings are cached at `~/.claude/remote-settings.json`; cross-source merge is by key kind, and `sandbox.credentials.awsPairs` and `sandbox.ripgrep` are taken whole since v2.1.257 ([server-managed settings](https://code.claude.com/docs/en/server-managed-settings)). `permissions.blockReadsOutsideWorkingDirectories` fences Read, Grep, Glob, and LSP; Bash subprocess reads stay unbounded ([settings reference](https://code.claude.com/docs/en/settings-reference#permissionsblockreadsoutsideworkingdirectories)). Permission-rule lints keep a `)` inside a specifier, report `Bash(ls) x` as a malformed Tool(content) rule, and treat an uncompilable deny as guarding the literal path.

### Changed

- **Managed-policy diagnosis routes to `/status`** ([#4027](https://github.com/melodic-software/claude-code-plugins/issues/4027)). `audit-permission-state` still cannot see server-managed settings as live policy. The note sends the operator to `/status` (Setting sources and the Organization policy line) and to `claude doctor`, which shows the same line, for a policy that did not load, a policy-helper failure, or a credential that is signed in but not in use.
No change: repeats the 0.51.16 entry (released by #5159) and the 0.51.10 entry (released by #5161).

## [0.51.17] - 2026-09-28

### Changed

- **Permission and effort facts from Claude Code 2.1.257 to 2.1.261**
([#4027](https://github.com/melodic-software/claude-code-plugins/issues/4027)).
`required-permissions.md` now states that redirect targets are covered by Read and Edit deny
rules from 2.1.257, and that the 2.1.259 widening onto Bash arguments was reverted in 2.1.260.
Strict sandbox mode does not sandbox `!` shell-mode commands in an interactive session from
2.1.260. `permissions.blockReadsOutsideWorkingDirectories` fences Read, Grep, Glob, and LSP
from 2.1.257. The audit checklist records `bashOutputMaxChars` (clamped 4000 to 128000, not
raised by default) and that `taskOutputMaxChars` was removed in 2.1.277. `audit-instructions`
I21 drops the "Opus 5 has no hold" sentence for the current model-config page: Opus 5.5 ignores
a top-level user `effortLevel`, and that key still applies on Opus 5, Fable 5.1, and earlier
models. Each claim cites the page read on 2026-09-28.
No change: repeats the 0.51.15 entry (released by #5156).

## [0.51.16] - 2026-09-28

Expand Down Expand Up @@ -179,6 +243,8 @@ All notable changes to the `claude-config` plugin are documented here. Format fo

## [0.51.7] - 2026-09-28

Shipped through [#5154](https://github.com/melodic-software/claude-code-plugins/pull/5154) (commit 9c2db71f6), not #5059, which was closed unmerged.

### Fixed

- **`audit-permission-state` treats project `defaultMode: "bypassPermissions"` as dead**
Expand Down
15 changes: 11 additions & 4 deletions plugins/claude-config/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -111,8 +111,8 @@ Audits instruction *content* against current model capability, a different quest
sibling audits (config-file correctness) and from `skill-quality:check` (structural lint) or
`docs-hygiene:compress` (token brevity). It sweeps the locally-owned surfaces (user + project
`CLAUDE.md`, a natively read `AGENTS.md`, `.claude/rules`, skill bodies, agent definitions, hook
instruction text, output styles) against a sixteen-check catalog cited to current official prompting and harness doctrine, running
a fresh read-only subagent per surface, then a fresh-context verify pass that re-judges every removal
instruction text, output styles) against a check catalog cited to current official prompting and harness doctrine, running
plugin-atomic, token-budgeted read-only lanes (see Lane sizing in `skills/audit-instructions/SKILL.md`), then a fresh-context verify pass that re-judges every removal
proposal before it is surfaced. Findings are tiered mechanical vs behavioral and delivered as a
report plus proposed diffs, report-only and never auto-applied. On memory-layer surfaces it runs only
the model-era checks and routes hygiene findings to the `claude-memory` plugin's `audit` skill (with
Expand All @@ -129,6 +129,9 @@ pass alone, so a scheduled hygiene routine can compose it on its own token budge
/claude-config:audit-instructions skills # one surface (claude-md|rules|skills|agents|hooks|output-styles)
/claude-config:audit-instructions conflicts # the cross-surface conflict pass only
/claude-config:audit-instructions --opinion # also run the default-off OPINION-tier checks
/claude-config:audit-instructions --unattended # nobody to answer: disclose the ~20-dispatch cost instead of asking
/claude-config:audit-instructions --resume # continue the latest run, re-running only incomplete or changed lanes
/claude-config:audit-instructions --persist-findings # also write I28-I33 findings as a review-findings file for review:fanout fix
```

### audit-pass
Expand Down Expand Up @@ -184,7 +187,9 @@ phases:

The canonical trigger
is a frontier model release. Instructions written for the previous generation are the experiment's
subject. Human-gated at every mutation; state persists under `${CLAUDE_PLUGIN_DATA}` for resume.
subject. Human-gated at every mutation; the manifest and stumbles log live in the repo under
`.claude/unhobble/<experiment-id>/`, and `${CLAUDE_PLUGIN_DATA}` holds only `backups/` (see State in
`skills/unhobble/SKILL.md`).

```shell
/claude-config:unhobble # guided full flow
Expand Down Expand Up @@ -246,7 +251,9 @@ automatically. If you used `/claude-config-audit:memory-health`, install it expl
No `userConfig`. One tracked consumer-project file, `audit-pass`'s suppression record, above.
Persistent plugin state: `audit-pass` writes its run reports and manifests under
`${CLAUDE_PLUGIN_DATA}`, which resolves under `~`, outside a target below the home directory and
inside one at or above it. A run never *scans* what it wrote: where the resolved report path is
inside one at or above it. `audit-instructions` keeps its run files under
`${CLAUDE_PLUGIN_DATA}/audit-instructions/runs`, and `unhobble` keeps pre-strip `backups/` under
`${CLAUDE_PLUGIN_DATA}/unhobble/<experiment-id>/`. A run never *scans* what it wrote: where the resolved report path is
contained in the target, the run excludes that path before writing and says so.
Network: `audit` fetches official docs pages and each registered marketplace's `marketplace.json`
from `raw.githubusercontent.com` (read-only; a failed fetch degrades to SKIP).
Expand Down
Loading
Loading