Skip to content

docs(claude-config): record the user-request-conflict axis as an I15 non-member - #5360

Merged
kyle-sexton merged 4 commits into
mainfrom
docs/3565-i15-request-axis-non-member
Sep 29, 2026
Merged

kyle-sexton merged 4 commits into
mainfrom
docs/3565-i15-request-axis-non-member

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

Closes #3565

Summary

Records in conflict-criteria.md that I15 does not detect conflict between a standing instruction and a hypothetical or plausible user request. The paragraph sits in the Boundary section with a Claim/Basis/As of/Recheck record. Plugin bumped to 0.52.1 with a CHANGELOG entry.

Fix

The owner's 2026-09-29 decision comment on #3565 was followed: the axis is rejected, and the rationale is the co-residency prerequisite (a hypothetical request has no residency, enumerability or liveness the tree can determine) plus an unbounded population. The Q2 hold clauses on I1, I4 and I5 in criteria.md were not touched.

Verification

  • markdownlint-cli2 on the two changed markdown files: 0 issues.
  • check-skill.sh audit-instructions: PASS, 0 errors; the one warning is at criteria.md:1238, outside this diff.
  • scripts/check-changelog-parity.sh --check and --check-bump origin/main: pass.
  • No em dashes in the added prose; the diff touches only conflict-criteria.md, plugin.json and CHANGELOG.md.

Related

🤖 Generated with Claude Code

kyle-sexton and others added 3 commits September 29, 2026 13:57
…ainst plausible user requests

Refs #3565

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kyle-sexton
kyle-sexton marked this pull request as ready for review September 29, 2026 18:01
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 42s —— View job


Code review complete

  • Gather context (PR diff, files changed)
  • Run /review:code-review per custom instructions
  • Post findings as inline comments / summary

Summary

Reviewed the diff (origin/main...HEAD, head e649871) across all three changed files:
plugins/claude-config/.claude-plugin/plugin.json, plugins/claude-config/CHANGELOG.md,
plugins/claude-config/skills/audit-instructions/reference/conflict-criteria.md.

This is a small, self-contained documentation change. Checked for:

  • Version/changelog parity: plugin.json 0.52.0 → 0.52.1 matches the new CHANGELOG.md
    [0.52.1] entry, which matches the conflict-criteria.md header bump (1.6.1 → 1.6.2). No stale
    1.6.1/0.52.0 references left elsewhere in the plugin.
  • Verification record format: the new paragraph
    (conflict-criteria.md#L116-L129)
    carries the Claim/Basis/As of/Recheck record .claude/rules/skill-bodies-state-current-rules.md
    requires for a restated volatile specific, matching the existing record style at L35-37.
  • Cross-reference integrity: the [co-residency prerequisite](#prerequisite-co-residency) link
    resolves correctly, and the claim is consistent with I15's comparison set as described in
    criteria.md ("every pair drawn from the surfaces Phase A inventoried") — a hypothetical request
    was never in that population, so this reads as a clarification rather than a behavior change.
    No contradiction with the existing "Must-not-flag set" table, which covers a different concept
    (dropping candidate pairs already in-population, not population membership).
    marketplace.json doesn't pin a per-plugin version, so no parity issue there either.

No correctness bugs found in the high-signal bar (no linter-catchable issues, no pre-existing
issues on untouched lines). One minor, non-blocking observation, not filed as a finding since it's
a structural/subjective call already disclosed in the PR description: the new paragraph sits under
## Boundary: what C6's population actually is, a heading whose surrounding content is entirely
about the claude-memory C6 ↔ I15 routing table, while the new paragraph is about a different
boundary (I15 vs. hypothetical user requests). A reader scanning that heading for C6-routing
content could miss it. This is a documentation-organization judgment call, not a defect — no
inline comment filed.

The author's claimed verification (markdownlint-cli2, check-skill.sh audit-instructions,
check-changelog-parity.sh) is author-claimed and not independently re-run in this review.

No inline comments filed — no findings met the high-signal bar.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 40s —— View job


Security review: no findings

  • Gather context (PR diff, changed files)
  • Apply instruction-surface lens (this diff narrows I15's scope) against the exception register
  • Review conflict-criteria.md addition for security-relevant issues
  • Review plugin.json / CHANGELOG.md changes
  • Post findings or clean bill

Scope reviewed: plugins/claude-config/.claude-plugin/plugin.json (version bump), plugins/claude-config/CHANGELOG.md (entry), plugins/claude-config/skills/audit-instructions/reference/conflict-criteria.md (new paragraph + Claim/Basis/As of/Recheck record declaring the user-request-conflict axis a non-member of I15).

Instruction-surface lens. This diff narrows the stated scope of I15 (a static cross-surface conflict-detection check), so per the skip gate it doesn't get waved through as prose-only without being checked against the instruction exception register's six Gate 0 classes (irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority).

No match. The paragraph doesn't delete or weaken any standing instruction that itself gates a protected-class action (e.g. "never force-push", "never delete without confirmation"). It documents a boundary of an audit mechanism — I15 detects conflicts between co-resident standing instructions across surfaces, not between a standing instruction and a hypothetical/live user request. The pre-existing "Prerequisite: co-residency" section already required both directives to be in the same context window, which a hypothetical request never satisfies, so this change formalizes existing behavior rather than removing enforcement. Any protected-class instruction elsewhere in the tree remains intact and is still read/enforced by the model at runtime regardless of what I15 (a docs-audit check) flags. No hook, permission rule, or validator loses coverage as a result of this change.

Rest of the diff: version bump and changelog entry carry no security surface; the new reference-doc prose contains no code, no injection surface, no secrets/token handling, and no Actions/workflow changes.

No security issues found in this pull request.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T18:07:05.047390Z e649871 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 57s —— View job


Security review: no findings

  • Gather context (PR diff via gh pr diff 5360, changed files)
  • Apply the instruction-surface lens (this diff narrows I15's documented scope) against the instruction exception register
  • Review conflict-criteria.md addition, plugin.json, CHANGELOG.md for security-relevant issues
  • Post findings

Scope reviewed: plugins/claude-config/.claude-plugin/plugin.json (version bump), plugins/claude-config/CHANGELOG.md (entry), plugins/claude-config/skills/audit-instructions/reference/conflict-criteria.md (new "A standing instruction against plausible user requests is not a member" paragraph + Claim/Basis/As of/Recheck record, dae829d#L116-L129).

Instruction-surface lens. This diff narrows the stated scope of I15 (a static, cross-surface conflict-detection audit check), so it is not waved through as prose-only. Checked it against the register's Gate 0 classes — irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority:

  • No match. The added paragraph doesn't delete or weaken a standing instruction that itself gates a protected-class action. It declares that I15's audit population excludes hypothetical/plausible user requests — i.e., I15 checks conflicts between co-resident standing instructions, not between a standing instruction and an imagined request.
  • This is a formalization of pre-existing behavior, not a new gap: the co-residency prerequisite already required both directives to be resident in the same context window before this PR, and a hypothetical request never satisfied that gate. Confirmed by reading that section directly (plugins/claude-config/skills/audit-instructions/reference/conflict-criteria.md:135-140 in the working tree) — the gate's text is unchanged by this diff.
  • I15 is a documentation-audit finding lane, not a runtime enforcement mechanism. Any protected-class instruction elsewhere in the tree (.claude/rules/*, hooks, permissions.deny) is still read and enforced by the model / harness at runtime regardless of what this audit check flags or doesn't flag. No hook, permission rule, or validator loses coverage as a result of this change.
  • The PR description's own claim that the Q2 hold clauses on I1, I4, I5 in criteria.md were untouched checks out — this paragraph sits in the I15 Boundary section, a detection-scope note, not a deletion-hold criterion.

Rest of the diff: the plugin.json version bump and CHANGELOG.md entry carry no security surface — no code, no secrets/token handling, no Actions/workflow changes, no injection surface.

No security issues found in this pull request.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 44s —— View job


Tasks

  • Gather context (PR diff, files changed)
  • Invoke /review:code-review and follow its instructions
  • Post findings as inline comments / summary

Code review complete

Reviewed the diff (gh pr diff 5360, head dae829d) across all three changed files:
plugins/claude-config/.claude-plugin/plugin.json, plugins/claude-config/CHANGELOG.md,
plugins/claude-config/skills/audit-instructions/reference/conflict-criteria.md.

Skip gate: PR is open, not a draft, and this head (dae829d, a merge-main-in commit) postdates the
last review at e649871 — proceeded with a fresh pass rather than reusing it.

Version/changelog parity — independently verified: plugin.json is 0.52.1, matching the new
CHANGELOG.md [0.52.1] entry and the conflict-criteria.md header bump (1.6.1 → 1.6.2).
grep -rn "0.52.0|1.6.1" plugins/claude-config/ (excluding CHANGELOG.md, which legitimately keeps
the old entries) found no stale leftovers.

Verification-record format — the new paragraph
(conflict-criteria.md#L116-L129)
carries the Claim/Basis/As of/Recheck record .claude/rules/skill-bodies-state-current-rules.md
requires, matching the existing record's style and structure at L35-38.

Content consistency — cross-checked against criteria.md's I15 entry
(criteria.md#L941):
the comparison set is already scoped to "every pair drawn from the surfaces Phase A inventoried," a
static inventory that never included live/hypothetical user requests. The new paragraph is
consistent with that existing definition — a clarification, not a scope change — and no other spot
in either reference file restates or contradicts this claim (grep for "hypothetical|plausible|user
request" turns up only the new paragraph and an unrelated I15 sourcing quote).

Cross-reference integrity — the [co-residency prerequisite](#prerequisite-co-residency) anchor
resolves correctly to ## Prerequisite: co-residency. No new heading was added, so the ## Contents
TOC correctly needs no update.

No correctness bugs found at the high-signal bar (no linter-catchable issues, no pre-existing issues
on touched lines). One placement observation, not filed as a finding since it's a documentation
structure judgment call already disclosed in the PR description and in this PR's own prior review
comment: the new paragraph sits under ## Boundary: what C6's population actually is, a heading
whose surrounding content is entirely about claude-memory's C6 ↔ I15 routing, while the new
paragraph addresses an unrelated boundary (I15 vs. hypothetical requests). A reader scanning that
heading for C6-routing content could miss it — worth a future pass to give it its own subheading,
but not a defect in this diff.

The author's claimed verification (markdownlint-cli2, check-skill.sh audit-instructions,
check-changelog-parity.sh) is author-claimed and not independently re-run in this review; the
issue-#3565 owner decision cited as the rationale's basis was not independently re-fetched (gh issue view required approval unavailable in this session).

No inline comments filed — no findings met the high-signal bar.

@kyle-sexton
kyle-sexton merged commit ee132c1 into main Sep 29, 2026
19 checks passed
@kyle-sexton
kyle-sexton deleted the docs/3565-i15-request-axis-non-member branch September 29, 2026 18:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

claude-config: adjudicate the user-request-conflict axis as an I15 boundary reopen

1 participant