Skip to content

docs(conventions): revert agent rulings on owner-reserved issues and correct convention text - #5313

Merged
kyle-sexton merged 24 commits into
mainfrom
fix/audit-conventions
Sep 29, 2026
Merged

kyle-sexton merged 24 commits into
mainfrom
fix/audit-conventions

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

No related issue: audit remediation; no issue is closed by this PR

Summary

An unattended Cursor run edited docs/conventions/ and took decisions that belong to the owner, stated false facts in the config-cascade tables, left conversational residue and parked records in several conventions, and left one fleet-wide rule contradicting its own measured record. This branch removes the agent rulings, corrects the text, and changes nothing outside docs/conventions/. No decision is implemented in place of the removed ones; each goes to the owner in a decision packet posted on its issue. No plugin version bump and no plugin CHANGELOG entry.

Fix

Look at these first:

Other edits: config-cascade glance-table facts, consumer-gotchas rationale and single local form, shell-test-helpers wording, hook-budget (host-defect section reduced to a pointer, tautological token-leak probe deleted, exec-form cost, prerequisite, failure behavior and measurement slot stated), rendered-views parked record dropped, hook-precision and hook-observability records reduced to pointers, permission-rule-hygiene house position, native-references Adopters row, topic-docs "no config persisted" wording.

Cross-group requests applied (all in docs/conventions/):

Verification

Run at the branch tip in the worktree after merging origin/main, all exit 0:

  • bash scripts/check-purged-em-dashes.sh --check: 1289 files scanned, no em dashes.
  • bash scripts/check-docs-naming.sh --check: every tracked file under docs/ is lower-kebab-case.
  • python3 scripts/check-contract-clause-coverage.py: passed.
  • bash scripts/check-loop-lane-floor-drift.sh --check: 6 consumers match, no unregistered copy.
  • bash scripts/check-detector-findings-crosswalk.sh --check: 38 rows OK.
  • bash scripts/check-changelog-parity.sh --check --check-order: passed.
  • git diff --name-only origin/main...HEAD lists only docs/conventions/ paths.
  • git diff 7acaf085 -- docs/conventions/hook-telemetry is empty; no "Option A" or "parked" text remains in hook-telemetry or config-cascade.

Related

Refs #3410 #3412 #3549 #3573 #3575 #3577 #3603 #3604 #4287 #4372 #3547 #3615 #3680 #4598 #4661 #4657 #4001 #3542 #3356 #4116 #4656 #4267 #3686 #3708 #4828 #5324

#3356 and #4001 are already closed and stay closed; #4828 is a merged PR. #5324 is a new decision packet for the owner (hook-observability carve-out condition 3), filed for the guardrails group's request on #4679, which the guardrails group owns.

Audit findings by issue number are in .work/audit/REPORT.md (action tables 3a to 3e).

Cross-group requests received: 26, from core-docs, work-items, markdown-format, playbooks, hook-launcher, bugs, go-format, ci, event-storming, repo-fleet-hygiene, actionlint, decisions-docs, testing, planning, source-control, guardrails, claude-ops, session-flow, context-budget, attribution, claude-config, review and biome-format.

Requests not edited here:

Every owner-reserved question above stays with the owner; decision packets and operator steps are posted on the issues.

🤖 Generated with Claude Code

https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB

kyle-sexton and others added 16 commits September 29, 2026 01:35
The envelope-schema check was parked as "Option A" without an owner
decision. Restore the pre-park README and CHANGELOG text; whether to
build the check is left to the owner.

Refs #3410

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
The owner's 2026-09-27 comment on #3577 asked for an empirical write-guard
measurement and a one-pointer-file comparison before any ruling on where
standards locates its layers. PR #4874 ratified the standards location, the
songwriting override path and the work-items recurring schedule on the
unmeasured premise that writes under .claude/ are permission-guarded.

Remove those rulings and the glance-table rows that mirrored them. The
standards location returns to observed, not ratified.

Refs #3577

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
The bugs row omits that a `## Gotchas` section concatenates across layers, which the Implementers row states. The Claim bullet cites an Implementers pointer that does not exist. Compared surface labels of both tables: the only remaining difference is `standards` versus `standards` (`planning`, `review`), a label difference with no fact behind it.

Refs #3575

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
… unchosen dedicated-file form

The rejected-alternatives line said editing files under CLAUDE_PLUGIN_DATA is lost on
plugin update; CLAUDE_PLUGIN_DATA is the directory that survives updates, and the hazard
is editing shipped skill files in the plugin cache.

Local tier resolution offered two equal forms. The #3547 operator decision ratified the
two-tier design on the existing `.claude/<plugin>.md` `## Gotchas` surface, and no plugin
uses `.claude/<plugin>/gotchas.md`, so that form is deleted.

Refs #3547

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…e grouping that contradicted the premise

The make_sink section opened with "Option A", a label from a list that
exists nowhere in the file or the issue. State the sentence plainly.

The intro says the three shapes are assertion-primitive shapes, yet the
hook-contract bullet listed make_sink/wait_for_sink inside one of them.
Say the two helper files also carry a make_sink/wait_for_sink copy that
is outside those shapes, and state the drifted-family exception once in
the paragraph before the bullets. The sanction and the section heading
are unchanged.

Refs #3412

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…e the host-defect section to a pointer

The probe's self-test compared constants pasted from the issue table against constants pasted
from the issue table, and no CI lane discovers docs/conventions, so the recorded pass count was
never produced by a run. The Windows Token-leak measurements, sources, and recheck triggers live
in the claude-ops runbook; the README keeps a four-sentence pointer and no longer carries a
Claim, Basis, As of, or recheck record.

Refs #4372

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…red-views

The tracker holds the gate: #3603 is blocked by #3604 natively, and the
baseline sentence already states the dependency.

Refs #3604
Refs #3603

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
hook-precision keeps the Windows `if` file-rule rule and a four-part record that points at the
dated probe in the context-budget README; the restated probe narrative is removed.
hook-observability keeps the no-substitute-channel rule and points at formatter-path-probes.md
and #3549 instead of restating the incident status.

Refs #3680
Refs #3549

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…ill paragraph

The README paragraph stated as fact that background jobs block Write/Edit to
the shared checkout until EnterWorktree and told operators to launch in a
foreground interactive session. The issue's own evidence is narrower and the
refusal was never reproduced. The convention now says launch mode decides
whether the escalation record can be written, keeps the tracker marker as the
escalation of record and the no-EnterWorktree rule, and cites the skill
paragraph that holds the observed conditions and their verification record.
The CHANGELOG records the correction as 9.3.1.

Refs #4598

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…ig persisted

Refs #4661
Refs #4657

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…rgument-hint and restores the adopted 'destructive' ground

Remove the Provenance paragraph; the Record table already carries the
sources. Stop claiming how the argument-hint string is written: the intro
and the "bound to the shape" section keep the action-set, modifiers,
subject order and point to the argument-hint house style for notation,
alternatives, budget and punctuation, so an unspaced top-level a|b is no
longer taught here while the validator warns on it.

Earned-flag ground 2 returns to the wording the owner adopted on #4001:
"it opts into a destructive effect, such as --execute or --force". The
disk-hygiene:clean worked-fit row already says destructive.

The repo-hygiene:clean worked-fit hint keeps its unspaced alternatives:
they sit inside [ ] and are a closed set of action words, which the
argument-hint style allows. The POSIX 12.1 Record row stays as evidence
although no prose cites the 12.1 notation any more.

Refs #4001, #3542

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…pendency runners

Bundled scripts are not launched through PEP 723 inline-dependency runners
(uvx, pipx run and the like), because an allow rule written for a package
runner is dropped in auto mode and grants nothing. Adds a short subsection
under anti-pattern 1 and a 1.5.0 changelog entry.

Refs #3615

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…asured record

Caveat 2 said to pass `-s user` and not to copy a scope from `claude plugin list`, but the
verified-version record in the same file measured that a `-s user` rerun of a plugin installed
at project and local scope enabled it machine-wide. Pass the scope the list reports, from the
project directory for project and local scope, and pass `user` only when the home directory
makes one file carry both labels.

The home-directory bullet now states its status (seen once, outside the sandbox probe) instead
of naming an audit as its origin.

Refs #3356

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…criteria.md

The I31 and I33 rows listed a context/, reference/, or references/ spoke as
their surfaces; each now points at criteria.md for the surfaces and its
outside-rule-surfaces decline refers to the same ones. The I32 row states
CRITICAL on the marketplace arm and IMPORTANT on the user and project arm,
arguing the second from the reason criteria.md gives for that arm's warning
severity. The adopter row's tier-spread sentence follows.

A new 3.3.0 entry lists these edits and corrects the 3.1.3 sentence that no
producer's output changes: review:fanout now ranks an omitted Confidence
after a reviewer's low. The released 3.1.3 entry is untouched.

Refs #4116
Refs #4656
Refs #4267

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…of the exec-form launcher

The Exec-form fleet sweep paragraph named no k and no measured cost although
Rule 1 asks for both. It now states the shipped shape, k = 2 for a bash-scripted
row behind the node launcher, the node-on-PATH prerequisite and the exit 1
behavior of an unresolvable bash, the scope of "no shell-form row remains", and
that no paired before-and-after run with the launcher is recorded.

Refs #3686
Refs #3708

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
The skill now carries the description phrase, the Boundary section and
the Native step (verdict complementary, integration wrap).

Refs #4828

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
kyle-sexton and others added 4 commits September 29, 2026 10:38
…inter

The pointer stated roughly one token per child-creating process and said the
runbook section holds the measurements. That section records per-binary rates
that differ by host (bash 0.46 to 1.5, node 0.3, cmd and python about 0), so
the pointer named one owner and stated a figure the owner does not carry. It now
states no rate, says the rate differs by binary and host, and points at #4372
for the melo-lap-001 rows.

Refs #4372

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…ugin-shipped scripts

The position said bundled scripts in this repository, which the repo's own
development wrappers (scripts/run-ruff.sh runs the ruff pin through uvx) contradict, and
named pipx run beyond the PEP 723 and uvx wording of the decision. It now covers
scripts shipped in plugins, names PEP 723 runners and uvx, states that the
development scripts under scripts/ are outside it, and drops the decision
citation.

Refs #3615

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…cord

The paragraph still said launch mode decides whether the record file can be
written, a harness claim the issue's evidence does not support (a background lane
from an isolated worktree wrote records). It now keeps the tracker marker as the
escalation of record and the no-EnterWorktree rule, and leaves every launch
condition to the work-loop skill paragraph.

Refs #4598

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…nding wrap

Refs #3547

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
kyle-sexton added a commit that referenced this pull request Sep 29, 2026
… docs (#5266)

Refs: #3574
Refs: #4784
Refs: #4671
Refs: #5096
Refs: #3686
Refs: #4240
Refs: #3356
Refs: #5057
Refs: #4581

## Summary

Audit fixes for `plugins/go-format` (REPORT.md finding
`plugin-go-format` and the 3c row for
`hooks/probe-prerequisite.sh:43-52`). Closes no issue: #3574 is owned by
core-docs and waits on an owner decision.

- The SessionStart prerequisite probe ran even with
`go_format_enabled=false`, so the disabled plugin still printed a
`goimports was not found` notice.
- README, setup skill, hook header comments and evals still described
the hook as unconditional, which predates the gitignore exemption
(#4784).
- The setup skill's toggle-off step carried stale scope advice that
contradicts the reconfiguration convention.

## Fix

- `hooks/hooks.json`: the SessionStart row passes
`--run-if-unset-or-true GO_FORMAT_ENABLED` to the launcher, the same
shape as `typos-format`. `probe-prerequisite.sh`, `hook-utils.sh` and
`exec-bash.mjs` are untouched (the first two are byte-pinned to the
shared copy).
- `hooks/go-format.test.sh`: hook-wiring selectors match the new args;
new behavioral cases assert no notice with the switch off and the notice
with it unset or `true`.
- `README.md`, `skills/setup/SKILL.md`, `hooks/go-format.sh` and
`go-format.test.sh` header comments: "no consumer-config opt-in gate"
replaces "unconditional"; the gitignored-file skip and
`go_format_lint_gitignored` are documented; the setup `check` action
reports the option's effective value.
- `skills/setup/SKILL.md` toggle-off: prints the convention's short form
(`-s user`, never uninstall to reconfigure, next-session observation,
read output not exit code) and cites the convention.
- `skills/setup/evals/evals.json`: new eval for the gitignore option;
eval 5 aligned with the short form.
- `plugin.json` 0.4.5 to 0.4.6 with a CHANGELOG entry. The `plugin.json`
description ("Runs unconditionally (no consumer-config gate)") stays
accurate; changing it would force a `docs/catalog.md` regeneration
outside this change's scope.

- Cross-group requests applied: the setup toggle-off step keeps `-s
user` per the convention on main, and the setup `check` action keeps
`node` a FAIL behind the kill switch. README Requirements and the setup
`check` action declare Node.js (hook-launcher request). CHANGELOG
entries 0.3.62, 0.3.63, 0.4.2 and 0.4.3 read "Shared launcher/library
sync; no change to this plugin's behavior" and 0.4.1 drops the
shell-form sentence; these released-entry edits are declared in the
0.4.6 entry and are not folded or renumbered.

## Verification

- `bash plugins/go-format/hooks/go-format.test.sh`: PASS=66 FAIL=0
- `bash scripts/validate-plugins.sh`: all manifests and catalog
validated
- `bash scripts/check-changelog-parity.sh --check --check-order`: pass
- `bash scripts/check-prerequisite-probes.test.sh`,
`check-hook-exec-form.sh`, `check-hook-userconfig-argv.sh`,
`check-hook-wiring-liveness.sh`, `check-killswitch-hoist.sh`,
`check-cross-plugin-source-drift.sh`, `check-hooks-description.sh`,
`check-purged-em-dashes.sh`: exit 0
- `bash scripts/check-changed-skills.sh origin/main`: setup skill PASS,
0 errors
- `python3 scripts/sync-plugin-options-docs.py --check`, `node
scripts/generate-catalog.mjs --check`: exit 0

## Related

Audit findings: `plugin-go-format` (correctness, docs-coherence,
convention); 3c row `probe-prerequisite.sh:43-52`; 3d finding #3574
(owned by core-docs, not changed here). Related issues: #4784, #4671,
#5096, #3686, #4240, #3356, #5057, #4581.

Applied from other groups: hook-launcher F43, F44 and the node
declaration; the scope wording request was not applied (see below).
Skipped: biome-format request to gate the SessionStart row, already done
in this PR (`hooks.json` passes `--run-if-unset-or-true
GO_FORMAT_ENABLED`, with disabled, unset and `true` probe tests). The
setup toggle-off step follows caveat 2 as it reads on main (`-s user`);
the conventions group (#5313) owns changing it, after which the setup
skills can follow.

Cross-group requests:
- core-docs: include go-format's setup rationale (`SKILL.md:69`) as
evidence in the #3574 decision packet; optionally reword the
`plugin.json` description together with `docs/catalog.md` if the owner
wants the gitignore exemption named.
- conventions: `scripts/sync-plugin-options-docs.py:126` emits "pass the
scope `claude plugin list` reports", contradicting the reconfiguration
convention's caveat 2; fix the template and regenerate every README's
generated options block (go-format's generated block changes in that
run).
- biome-format and markdown-format carry the same probe-gate defect;
their own groups own the fix.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
kyle-sexton added a commit that referenced this pull request Sep 29, 2026
…t-ssot, write-for-agents and the changelog (#5296)

Refs: #3574
Refs: #4784
Refs: #4671
Refs: #5096
Refs: #3686
Refs: #4240
Refs: #3356
Refs: #5057
Refs: #4581

## Summary

Audit fixes for `plugins/go-format` (REPORT.md finding
`plugin-go-format` and the 3c row for
`hooks/probe-prerequisite.sh:43-52`). Closes no issue: #3574 is owned by
core-docs and waits on an owner decision.

- The SessionStart prerequisite probe ran even with
`go_format_enabled=false`, so the disabled plugin still printed a
`goimports was not found` notice.
- README, setup skill, hook header comments and evals still described
the hook as unconditional, which predates the gitignore exemption
(#4784).
- The setup skill's toggle-off step carried stale scope advice that
contradicts the reconfiguration convention.

## Fix

- `hooks/hooks.json`: the SessionStart row passes
`--run-if-unset-or-true GO_FORMAT_ENABLED` to the launcher, the same
shape as `typos-format`. `probe-prerequisite.sh`, `hook-utils.sh` and
`exec-bash.mjs` are untouched (the first two are byte-pinned to the
shared copy).
- `hooks/go-format.test.sh`: hook-wiring selectors match the new args;
new behavioral cases assert no notice with the switch off and the notice
with it unset or `true`.
- `README.md`, `skills/setup/SKILL.md`, `hooks/go-format.sh` and
`go-format.test.sh` header comments: "no consumer-config opt-in gate"
replaces "unconditional"; the gitignored-file skip and
`go_format_lint_gitignored` are documented; the setup `check` action
reports the option's effective value.
- `skills/setup/SKILL.md` toggle-off: prints the convention's short form
(`-s user`, never uninstall to reconfigure, next-session observation,
read output not exit code) and cites the convention.
- `skills/setup/evals/evals.json`: new eval for the gitignore option;
eval 5 aligned with the short form.
- `plugin.json` 0.4.5 to 0.4.6 with a CHANGELOG entry. The `plugin.json`
description ("Runs unconditionally (no consumer-config gate)") stays
accurate; changing it would force a `docs/catalog.md` regeneration
outside this change's scope.

- Cross-group requests applied: the setup toggle-off step keeps `-s
user` per the convention on main, and the setup `check` action keeps
`node` a FAIL behind the kill switch. README Requirements and the setup
`check` action declare Node.js (hook-launcher request). CHANGELOG
entries 0.3.62, 0.3.63, 0.4.2 and 0.4.3 read "Shared launcher/library
sync; no change to this plugin's behavior" and 0.4.1 drops the
shell-form sentence; these released-entry edits are declared in the
0.4.6 entry and are not folded or renumbered.

## Verification

- `bash plugins/go-format/hooks/go-format.test.sh`: PASS=66 FAIL=0
- `bash scripts/validate-plugins.sh`: all manifests and catalog
validated
- `bash scripts/check-changelog-parity.sh --check --check-order`: pass
- `bash scripts/check-prerequisite-probes.test.sh`,
`check-hook-exec-form.sh`, `check-hook-userconfig-argv.sh`,
`check-hook-wiring-liveness.sh`, `check-killswitch-hoist.sh`,
`check-cross-plugin-source-drift.sh`, `check-hooks-description.sh`,
`check-purged-em-dashes.sh`: exit 0
- `bash scripts/check-changed-skills.sh origin/main`: setup skill PASS,
0 errors
- `python3 scripts/sync-plugin-options-docs.py --check`, `node
scripts/generate-catalog.mjs --check`: exit 0

## Related

Audit findings: `plugin-go-format` (correctness, docs-coherence,
convention); 3c row `probe-prerequisite.sh:43-52`; 3d finding #3574
(owned by core-docs, not changed here). Related issues: #4784, #4671,
#5096, #3686, #4240, #3356, #5057, #4581.

Applied from other groups: hook-launcher F43, F44 and the node
declaration; the scope wording request was not applied (see below).
Skipped: biome-format request to gate the SessionStart row, already done
in this PR (`hooks.json` passes `--run-if-unset-or-true
GO_FORMAT_ENABLED`, with disabled, unset and `true` probe tests). The
setup toggle-off step follows caveat 2 as it reads on main (`-s user`);
the conventions group (#5313) owns changing it, after which the setup
skills can follow.

Cross-group requests:
- core-docs: include go-format's setup rationale (`SKILL.md:69`) as
evidence in the #3574 decision packet; optionally reword the
`plugin.json` description together with `docs/catalog.md` if the owner
wants the gitignore exemption named.
- conventions: `scripts/sync-plugin-options-docs.py:126` emits "pass the
scope `claude plugin list` reports", contradicting the reconfiguration
convention's caveat 2; fix the template and regenerate every README's
generated options block (go-format's generated block changes in that
run).
- biome-format and markdown-format carry the same probe-gate defect;
their own groups own the fix.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
kyle-sexton and others added 3 commits September 29, 2026 11:17
Takes main's plugin-reconfiguration caveat 2 (scope matching, landed with the
context-budget setup change) and keeps this branch's drop of the origin aside.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…and mark the launcher measurement slot

The home-directory record no longer cites where it was seen. The hook-budget exec-form section
names #3686 as the carrier of the operator's paired run instead of leaving the gap unmarked.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
@kyle-sexton
kyle-sexton marked this pull request as ready for review September 29, 2026 15:46
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 4m 27s —— View job


CI Code Review

  • Gather context (PR body, changed files list)
  • Fetch diff (git diff origin/main...HEAD)
  • Review each changed file for correctness/maintainability per CLAUDE.md and REVIEW.md criteria
  • Post inline findings
  • Post final summary

This is a docs-only revert/correction PR (docs/conventions/ only, 24 files, no plugin code). I read the full diff against origin/main and independently spot-checked a sample of the PR's factual claims against the actual repo state (hooks.json command values, lib/exec-bash.mjs, plugins/claude-config/skills/audit-instructions/reference/criteria.md, plugins/context-budget/README.md, .claude/rules/ruff-pin.md, and heading anchors) rather than trusting the author-claimed verification script output in the PR body, which I could not re-run myself here (no permission to execute scripts/*.sh) — that verification remains author-claimed and unconfirmed by me.

Most of the diff checks out: the dropped songwriting/work-items recurring-schedule rows leave no orphaned references in config-cascade, the deleted token-leak-amplification.sh/.test.sh leave no dangling references, all new/changed links and anchors I checked resolve, and the exec-form/hook-budget factual claims (every hooks.json row and both hygiene skill-frontmatter hooks use "command": "node") hold up.

Two findings from this pass, both real inconsistencies introduced by this diff itself (posted inline):

  1. docs/conventions/skill-argument-shape/README.md (L92-96) — deletes the definition of the ... repeatable-argument notation and delegates "notation" to argument-hint's house style, but that doc never defines .... Leaves an undefined ... still used two lines later in the same file, and orphans the Record table's POSIX-12.1-notation citation.
  2. docs/conventions/loop-lane/README.md (L239-245) and the matching [9.3.1] CHANGELOG entry — removes the loop-lane convention's own unverified harness claim (good) but replaces it with a pointer claiming the work-items work-loop SKILL.md paragraph "holds the observed conditions and their verification record." As of this PR's head, that SKILL.md paragraph restates the identical unverified claim with no verification record at all. The PR body's own merge-order note acknowledges work-items hasn't made its complementary edit yet, so this pointer is currently making a false claim about its target.

No other correctness issues found in the remaining files (config-cascade, detector-findings, hook-observability, hook-precision, hook-telemetry, invocation-mode, native-references, permission-rule-hygiene, plugin-reconfiguration, rendered-views, shell-test-helpers, topic-docs).
· Branch

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 50s —— View job


Security review complete

  • Gather context (PR diff, changed files)
  • Check instruction-exception-register for instruction-surface deletions
  • Review diff for security-relevant issues (injection, secrets, authz, trust boundaries)
  • Post findings

No security issues found.

This PR is scoped entirely to docs/conventions/ (verified via git diff origin/main...HEAD --stat): prose corrections, removal of "parked"/decision-record text, and deletion of two standalone shell scripts (hook-budget/token-leak-amplification.sh and its test), none of which are wired into CI or an enforcement path. No application code, hook logic, permission config, CI workflow, or executable script with runtime effect is touched.

I applied the instruction-surface-deletion lens from docs/conventions/instruction-exception-register/README.md to every removal/narrowing in the diff (hook-telemetry, hook-observability, hook-precision, invocation-mode, rendered-views, loop-lane, plugin-reconfiguration, config-cascade, skill-argument-shape, permission-rule-hygiene). None match a Gate 0 protected class (irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority): each removed block is a probe record, a parked-decision note, or duplicated rationale text, not a standing rule that prevents a dangerous action. Two edits (permission-rule-hygiene, config-cascade's consumer-gotchas.md plugin-cache rationale) actually add or correct guidance rather than weaken it.

The deleted token-leak-amplification.sh/.test.sh pair is a documentation-illustrative arithmetic self-test for a Windows kernel token-leak measurement (per the PR body, "#4372, no CI step wired"); it was never wired into CI, so its removal does not drop a running security check.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 98893e711a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/conventions/loop-lane/README.md Outdated
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T15:51:11.690641Z 98893e7 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Comment thread docs/conventions/skill-argument-shape/README.md
Comment thread docs/conventions/loop-lane/README.md Outdated
…d stop promising a verification record in loop-lane

Review findings on #5313.

- argument-hint owns the hint notation after the skill-argument-shape
  delegation, but defined only [ ], < > and the spaced pipe. Add the
  `...` repeatable bullet with its POSIX 12.1 basis (re-read 2026-09-29),
  a 1.0.1 docs-only CHANGELOG entry, and narrow the skill-argument-shape
  Record row to the guidelines that doc still states.
- loop-lane pointed at the work-loop paragraph as holding "the observed
  conditions and their verification record", which that paragraph does
  not carry yet. State that the convention neither states nor verifies
  the launch-mode behavior and that the paragraph owns the text, so the
  pointer holds whatever order the work-items PR lands in.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 6s —— View job


Security review complete

  • Gather context (PR diff origin/main...HEAD, changed files)
  • Read docs/conventions/instruction-exception-register/README.md and apply the instruction-surface-deletion lens to every removal/narrowing in the diff
  • Review diff for injection, secrets, authz, and trust-boundary issues
  • Post findings

No security issues found.

Scope confirmed: this diff touches only docs/conventions/ (26 files), all prose corrections, reverts of unauthorized "agent ruling" text, and two deletions (hook-budget/token-leak-amplification.sh and its .test.sh). Neither deleted script was wired into CI or any enforcement path (per the PR body, #4372, no CI step), so removing them drops no running check.

I applied the instruction-surface-deletion lens (Gate 0 classes: irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority) to every removal/narrowing in the diff: config-cascade (location-outlier rulings, songwriting/work-items schedule rows), hook-telemetry (parked-schema-validation note), hook-observability/hook-precision (probe records reduced to pointers), invocation-mode (ledger pointer), rendered-views (parked smoke-test record), loop-lane (background-job launch-mode paragraph), skill-argument-shape (notation delegation, earned-flag ground 2 reverted to #4001 wording). None match a protected class: each removed block is a probe record, a parked-decision note, duplicated rationale, or an out-of-scope agent ruling being reverted to the owner-authorized baseline, not a standing rule that gates a dangerous action. This PR is itself restoring agent-authority boundaries (undoing owner-reserved decisions an unattended run made) rather than weakening any.

Two edits actually add/tighten guidance rather than narrow it: permission-rule-hygiene's new "no inline-dependency runners" house position, and config-cascade/consumer-gotchas.md's corrected plugin-cache rationale.

The detector-findings severity split (I32's user/project arm downgraded CRITICAL → IMPORTANT) is an audit-tooling triage classification aligned to claude-config's criteria.md, not a security control — it doesn't gate an irreversible action, secret handling, data integrity, publication, or agent authority.

No injection surfaces, credential handling, or authorization logic are touched anywhere in this diff (docs-only, no application code, hooks, CI workflows, or permission config changed).

Branch ·

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 9s —— View job


CI Code Review

  • Gather context (PR body, changed files, prior review comments)
  • Check skip gate (draft/trivial/already-reviewed-head)
  • Fetch diff since last reviewed head (git diff origin/main...HEAD, and the new commit 98893e7...8e24c25)
  • Review each changed file for correctness/maintainability per CLAUDE.md and REVIEW.md criteria
  • Post inline findings
  • Post final summary

This synchronize event adds one commit, 8e24c25, on top of the previously-reviewed 98893e7. It touches exactly the four files needed to close the two correctness findings raised by this lane and by Codex on the prior head, and no other files changed. I re-read both edits against their targets rather than trusting the commit message.

Both prior findings are resolved, verified against current file contents:

  1. docs/conventions/skill-argument-shape/README.md (L92-96) — the ... repeatable-argument notation is now defined at its new home, docs/conventions/argument-hint/README.md#L31-L35, with a proper four-part basis/verified/recheck record (POSIX.1-2024 XBD 12.1, verified 2026-09-29). The orphaned Record-table citation in skill-argument-shape is fixed by narrowing it from "Guidelines 9, 11, 12 and the 12.1 notation" to "Guidelines 9, 11 and 12" (L130), since the notation citation moved with the definition. The ... usage at L98 is now backed by a real definition instead of a dangling reference. A matching argument-hint CHANGELOG [1.0.1] patch entry was added.

  2. docs/conventions/loop-lane/README.md (L239-245) and the [9.3.1] CHANGELOG entry — no longer claims the work-items work-loop SKILL.md paragraph "holds the observed conditions and their verification record." It now states plainly that the launch-mode harness behavior is "neither state[d] nor verifie[d]" by this convention, and that the SKILL.md paragraph merely "owns that text" (an ownership claim, not a verification claim). I confirmed plugins/work-items/skills/work-loop/SKILL.md:295 still carries that paragraph, so the (now much weaker, purely-ownership) claim holds.

No new correctness issues found in this commit's diff. No other files changed since the last review, so the remainder of the PR (config-cascade, detector-findings, hook-observability, hook-precision, hook-telemetry, invocation-mode, native-references, permission-rule-hygiene, plugin-reconfiguration, rendered-views, shell-test-helpers, topic-docs, argument-hint) stands as previously reviewed.

As with the prior pass, the author-claimed verification-script output in the PR body (check-purged-em-dashes.sh, check-docs-naming.sh, etc.) is author-claimed and not independently re-run by me here.
· Branch

@kyle-sexton
kyle-sexton merged commit 8118525 into main Sep 29, 2026
18 checks passed
@kyle-sexton
kyle-sexton deleted the fix/audit-conventions branch September 29, 2026 16:43
kyle-sexton added a commit that referenced this pull request Sep 29, 2026
…nline suites (#5373)

Closes #3412

## Summary

Fourteen hook test suites in 12 plugins each defined their own
`make_sink`/`wait_for_sink` pair. They now source one helper, canonical
at `lib/hook-test-sink.sh` and carried byte-identical at
`plugins/<p>/hooks/hook-test-sink.sh` (plugins do not import siblings).
A contract suite, `lib/hook-test-sink.test.sh`, pins the helper's
behavior.

## Fix

- Add `lib/hook-test-sink.sh` and `lib/hook-test-sink.test.sh`; wire the
suite in the `hook-utils` CI job.
- Vendor the helper into the 12 carrying plugins and register the
cluster in `scripts/cross-plugin-source-registry.txt`, gated by
`check-cross-plugin-source-drift.sh`.
- Switch the 14 suites to the helper; no assertion added or removed.
- Amend `docs/conventions/shell-test-helpers/README.md` to the decided
rule.
- Patch-bump the 12 plugins with changelog entries (test-only, no
behavior change).

## Verification

- All 14 suites and `lib/hook-test-sink.test.sh` pass with FAIL=0 and
unchanged assertion counts, after merging current `main`.
- `check-cross-plugin-source-drift.sh --check`,
`check-changelog-parity.sh --check` and `--check-bump origin/main` pass.
- No `ok`/`bad`/`fail` line is deleted in the suite diffs.
- Earlier tasks: shellcheck and shfmt clean, lane coverage clean,
mutation of the helper body to a no-op fails the positive-telemetry
assertions.
- Not run: `test-windows.yml` (Git Bash `env -i` cannot be verified
here).

## Related

#3410, #3408, #3411, #5313

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
kyle-sexton added a commit that referenced this pull request Sep 29, 2026
…kills (#5419)

Closes #5342

## Summary

The eol-normalizer, go-format and markdown-format setup skills still
told the user to pass `-s user` and not to copy a scope from `claude
plugin list`, the rule #5267 and #5313 reverted. The discipline setup
skill pinned `-s user` on a reason the convention's record contradicts.

## Fix

- The four setup skills now say to pass the scope `claude plugin list`
reports, and `user` from the home directory, as caveat 2 of
`docs/conventions/plugin-reconfiguration/README.md` does.
- The go-format and markdown-format `evals/evals.json` no longer assert
`-s user`.
- The eol-normalizer skill no longer restates the verified-version
record.
- Patch bumps with one CHANGELOG entry each: eol-normalizer 0.7.8,
go-format 0.4.9, markdown-format 0.11.82, discipline 0.15.5.

## Verification

- `git grep -n -E 'copy a scope|-s user'` over the four plugins' setup
skills and evals: no hits outside CHANGELOG history.
- `scripts/check-changelog-parity.sh --check --check-order`: passed.
- `scripts/validate-plugins.sh`: all plugin manifests and the catalog
validated.
- The four plugins have no test suites to run.

## Related

- #5267, #5313: reverted the blanket `-s user` ruling.
- #5340: guardrails setup skill follows the convention.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
kyle-sexton added a commit that referenced this pull request Sep 29, 2026
…ementers rows (#5368)

Closes #3575

## Summary

The "Semantics at a glance" table in
`docs/conventions/config-cascade/README.md` was hand-written next to the
Implementers table and could drift from it. It is now generated from the
Implementers rows, with a CI drift check.

## Fix

- The Implementers table gains structured `Who wins` and `Merge form`
columns (24 rows, every cell filled).
- `scripts/sync-config-cascade-semantics.py` renders the glance table
between BEGIN/END GENERATED markers; `--check` exits 1 with a diff on
drift, 2 on missing markers or table.
- `ci.yml` runs the generator self-test and the `--check` step; the
README pre-flight table lists it.
- The hand-written table and its "a generated table stays out" paragraph
are removed.

## Verification

- `python3 scripts/sync-config-cascade-semantics.py --check` passes (24
surfaces).
- `scripts/sync-config-cascade-semantics.test.sh`: 11/11.
- `scripts/check-purged-em-dashes.sh`,
`scripts/check-changelog-parity.sh --check`, markdownlint-cli2 on the
touched Markdown, pinned ruff wrapper: pass.
- actionlint and the docs-only gate checks pass.
- shellcheck (repo `.shellcheckrc`) on the self-test,
`scripts/check-shell-portability.sh origin/main` and the git index mode
check (both scripts are 100755) pass; these are the `shellcheck`,
`shell-portability-lint` and `exec-bit` gates.

## Related

Follows PR #5313, which corrected two facts in the hand table and added
no guard.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
kyle-sexton added a commit that referenced this pull request Sep 30, 2026
)

Closes #3614

Refs #3172 #3593 #3756 #3568 #4666 #4661 #4657 #4281 #5163 #3544 #3138
#3465 #4240 #5255

## Summary

Docs-only remediation for the audit group "decisions-docs" (docs/adr/,
docs/out-of-scope/, docs/specs/). It takes agent-encoded decisions off
main where the owner had not ruled, corrects false facts in the records
that stay, records a current-version probe in ADR 0007, and delivers the
two unmet acceptance criteria of #3614 in the eval gap analysis. No
plugin file changes, so no version bump or CHANGELOG entry applies.

## Fix

One commit per change so the owner can drop any of them:

1. Reverse three decisions (#3172, #3593, #3756): delete
`docs/out-of-scope/cloud-session-permission-floor.md` and
`docs/out-of-scope/context-engineering-effort-candidates.md`; restore
ADR 0003 to its pre-run text (removes the `Session-log grading (#3756)`
section and its Sources suffix).
2. Out-of-scope ledger. `docs/out-of-scope/README.md` is one paragraph:
one file per settled rejection, matched and appended to as the
`/work-items:triage` "Rejected-concept ledger" step defines, rejections
only, never deferred work. `machine-profile.md` drops the false claims
about #4240 and the invocation-mode amendment, names #4240 question 2
(keep the per-plugin `check` skills or replace them with one shared
script) as the open owner question, says in a status line that the park
is an unratified agent proposal (the owner rules under #4666), and
counts the five plugins with a model-invocable `check` skill
(`actionlint`, `biome-format`, `context7`, `go-format`,
`markdown-format`) and the seven `prerequisites.json` declarations; no
Decision line changes. `shared-surface-instruction-governance.md` says
the #3568 "No" was an AI triage default with owner confirmation open.
3. Delete `docs/out-of-scope/skill-listing-500-char-exceptions.md`
(stale branch and PR bookkeeping, an unrecorded "operator skip").
Judgment call kept as its own commit (#4661, #4657).
4. ADR 0036: the "Native only" row no longer reads "Accepted" under a
"Rejected" heading; the run-log Update is one dated paragraph that says
the remote flag is no longer the blocker and points at the `sources.md`
section "Current fleet grade" (lands with #5285, see Merge order); one
broken line reflow is rejoined. The tracker pointer is unchanged:
choosing #4281 or #5163 as the canonical tracker is an owner question
(#4281, #5163).
5. Delete `docs/specs/precompute-injection-sweep-status.md`, re-verified
as derivable on the branch tip before the deletion (#3544; result under
Verification). The durable record is the #3544 comment.
6. ADR 0007: add a Claude Code 2.1.284 probe of `${CLAUDE_PLUGIN_ROOT}`
on three surfaces (skill body expanded, single-quoted shell-form hook
command literal with the variable set in the hook environment, Bash-tool
environment unset), plus one sentence: the shell-form hook command does
not show the documented inline substitution, while an exec-form `args`
element expanded. This delivers only the probe half of #3138 AC1. The
`context/` call sites
(`plugins/source-control/skills/worktree/context/status.md:7,24` and
`audit.md:12,15,16`) were not probed; fixing them versus documenting the
resolution order is put to the owner in the #3138 packet.
7. Eval gap analysis
(`docs/specs/evaluation-methodology-gap-analysis.md`, #3614). New
section "Reference implementation: skill-creator coverage": what
`skill-creator` ships (read at `fbe07fb6ce7d`), which pipeline row each
file covers, what it does not ship. New section "Assertion discipline
measurement": 303 files, 2,230 cases, 8,327 expectation strings, 230
under six words, 186 with a quality word, 20 with a strongly evaluative
word; the rule and the script are in the doc, both broad screens are
stated as heuristics that over-match, and no count of vague expectations
is claimed. The last table row cites the comparison, the
assertion-discipline row cites the measurement, the snapshot line is
re-dated (303 files on 2026-09-29), and the proposed adoptions link
#5255. No verdict changes; every adopt stays a proposal for the operator
gate.
8. `docs/specs/plugin-conformance-capability-matrix.md`: the
trigger-register clause says the `music` to `audio` rename has fired,
without naming the plugin or the landing.

The branch also carries merges of origin/main (no conflicts). Not
touched, on purpose: ADR 0025 (true again once #3593 is reopened),
`docs/cloud-sessions.md` and
`docs/setup-contract-campaign-follow-ups.md` (other groups' files).

## Merge order

- `docs/cloud-sessions.md:54,492` and
`docs/conventions/invocation-mode/README.md:92` link files this PR
deletes. #5268 (core-docs) removes the two `cloud-sessions.md` links and
#5313 (conventions) removes the `invocation-mode` link. Land #5268 and
#5313 in the same merge pass as this PR; this PR alone leaves three
dangling links.
- ADR 0036 cites the `sources.md` section "Current fleet grade", which
exists only on #5285 (instruction-placement); main still carries
"Standing refresh (#5163)", which grades condition 3 `[UNREACH]`. Land
#5285 before this PR or in the same pass.

## Verification

Run in the worktree at the merged head:

- `bash scripts/check-changelog-parity.sh --check --check-order`: pass.
- `bash scripts/validate-plugins.sh`: all manifests and the catalog
validated.
- `bash scripts/check-adr-numbers.sh --check`: pass.
- `bash scripts/check-docs-naming.sh --check`: pass.
- `bash scripts/check-purged-em-dashes.sh --check`: 1288 files scanned,
no em dashes.
- `markdownlint-cli2` and `typos` on the edited ADRs,
`docs/out-of-scope/` files and `docs/specs/` files: 0 issues; `lychee
--offline` on the eval gap analysis and the two ledger files: 0 errors.
- `bash scripts/check-docs-only.sh origin/main`: reports docs_only=false
because `docs/adr/0003-*` is outside its allowlist, so CI runs the full
suite; no plugin file is in the diff. `bash scripts/affected-tests.sh`:
no suites selected.
- ADR 0003 vs baseline 7acaf08: identical.
- Gap-analysis counts: the script printed in the doc, run on the branch
tip, prints `303 2230 47 8327 230 186 20`. The 47 cases without
`expectations[]` all carry `expected_output`.
- #3614 acceptance, for the owner to audit the close:
- AC1 (reference implementation examined, coverage recorded): met by
"Reference implementation: skill-creator coverage".
- AC2 (every pipeline element has a verdict): already met on main;
unchanged.
- AC3 (measured counts, not estimates): met by "Assertion discipline
measurement". It reports what the screen matches, not how many
expectations are vague, and the doc says so.
- AC4 (adopted pieces implemented, rejected ones recorded): waived by
the owner's 2026-09-27 narrowing to the read-only analysis
(#3614 (comment)).
The rejected row keeps its reason. If the owner rejects the waiver, drop
the closing line from the squash message.
- AC5 (adopted run mechanisms reuse existing facilities): not
applicable, nothing is adopted.
- AC6 (affected tests pass): `scripts/affected-tests.sh` selects no
suites for this diff.
- T6 probe: real `claude -p` on CLI 2.1.284, run twice with identical
results. An exec-form hook probe on the same CLI: the `args` element
expanded to the plugin root, the single-quoted shell-form token stayed
literal.
- #3544 re-verification of the deleted status spec, on the branch tip:
- Each of the 23 setup skills in the issue's sweep table injects its
probes: counting inline `!` and fenced `!` injection lines in
`plugins/<name>/skills/setup/SKILL.md` gives 1 to 4 for all 23, none 0.
- The five consolidations are present: `claude-memory:audit` (one
`audit-spine.sh` call), `knowledge:video-digest` and
`knowledge:course-digest` (one fenced `!` block each),
`claude-ops:observability` and `claude-ops:lanes` (merged probe lines).
- `bash scripts/check-skill-precompute-compose.sh --all`: 312 skills
scanned, 2 warn-only violations, exit 0. Both are outside #3544's sweep
and are not fixed here: `claude-ops:morning-brief` (3 precompute lines
with a git command) and `code-tidying:dissolve-comments` (2 such lines),
under the #1619 composition rule.
  - The per-plugin counts are in the #3544 comment.

## Related

Findings from `.work/audit/REPORT.md` (local, not committed), by issue:
#3172, #3593, #3756 (3d reverse); #3568, #4666 (out-of-scope ledger,
3e); #4661, #4657 (exceptions ledger, 3b); #4281, #5163 (ADR 0036);
#3544 (status spec); #3138 (3c and 3d decide fresh, item 1 probe only);
#4240 (machine-profile pointer to its open question 2); #3465 (decision
packet only); #3614 (gap analysis, AC1 and AC3).

Requests from other fix groups (twelve), applied here:

- evals: the skill-creator comparison, the measured counts and the #5255
link in the eval gap analysis (item 7).
- retro-audio: the capability-matrix wording (item 8).
- instruction-placement: ADR 0036 history parenthetical dropped, run-log
detail cut to a pointer at "Current fleet grade", and the "flag is the
blocker" implication replaced by a dated Update (item 4).
- work-items: the ledger README points at the triage skill's definition
and drops the unsourced consumer claim; machine-profile is marked an
unratified proposal (item 2).
- claude-ops: the stale #4240 facts in `machine-profile.md` are
corrected and what remains blocked is named; Decision, options and
Recheck outcome are unchanged (item 2).
- core-docs (ledger findings F0, F10, F12) and conventions (a): already
delivered by items 1 to 3, with the reopened issues #3172, #3593, #3756
and #4666.

Not applied:

- core-docs, `docs/plugin-philosophy.md` finding: that file and the fix
are core-docs's.
- source-control, #3138 comment, Windows child and follow-ups edit: the
guard-versus-support question is an owner decision in the #3138 packet,
`docs/setup-contract-campaign-follow-ups.md` is core-docs's, and #5317
changes neither Windows test suite.
- instruction-placement, tracker repoint in ADR 0036: waits on the
owner's canonical-tracker choice.
- conventions (b): the #3615 comment already cites the house position in
`docs/conventions/permission-rule-hygiene/README.md`.
- tracker and scripts, reopening #4658, #3465, #3617, #2954, #3615 and
#3138: done as issue operations, with #4655 linked as the blocker of
#4658.

Cross-group requests (owners of those groups act on them; this PR does
not):

- core-docs: decision-neutral fixes to
`docs/setup-contract-campaign-follow-ups.md` (cite ADR 0007's
version-stamped record) and `docs/plugin-philosophy.md:1286`.
- claude-config: add the ledger-README and #3568 questions to its
packet; claude-ops: #4666 packet, #4049 and #4047 items; scripts:
`scripts/adr-numbers-baseline.txt` header; evals: the comparison narrows
#5255 items 1, 2 and 7 and raises a question on the "rejected"
task-completion-notification row, none of which #5255 carries;
source-control, session-flow, planning, review, skill-quality,
instruction-placement, attribution, context-budget: see the group plan.

Issue operations (reopen, decision packets) for #2954, #3138, #3172,
#3465, #3593, #3615, #3617, #3756, #4658 are performed separately from
this PR.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant