Skip to content

docs(setup): pass the scope claude plugin list reports in the setup skills - #5419

Merged
kyle-sexton merged 4 commits into
mainfrom
docs/5342-setup-scope-rule
Sep 29, 2026
Merged

kyle-sexton merged 4 commits into
mainfrom
docs/5342-setup-scope-rule

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

Closes #5342

Summary

The eol-normalizer, go-format and markdown-format setup skills still told the user to pass -s user and not to copy a scope from claude plugin list, the rule #5267 and #5313 reverted. The discipline setup skill pinned -s user on a reason the convention's record contradicts.

Fix

  • The four setup skills now say to pass the scope claude plugin list reports, and user from the home directory, as caveat 2 of docs/conventions/plugin-reconfiguration/README.md does.
  • The go-format and markdown-format evals/evals.json no longer assert -s user.
  • The eol-normalizer skill no longer restates the verified-version record.
  • Patch bumps with one CHANGELOG entry each: eol-normalizer 0.7.8, go-format 0.4.9, markdown-format 0.11.82, discipline 0.15.5.

Verification

  • git grep -n -E 'copy a scope|-s user' over the four plugins' setup skills and evals: no hits outside CHANGELOG history.
  • scripts/check-changelog-parity.sh --check --check-order: passed.
  • scripts/validate-plugins.sh: all plugin manifests and the catalog validated.
  • The four plugins have no test suites to run.

Related

🤖 Generated with Claude Code

kyle-sexton and others added 4 commits September 29, 2026 15:40
…malizer, go-format and markdown-format setup skills

Restore the plugin-reconfiguration convention's scope caveat: the rerun uses the scope the
plugin list reports (user from the home directory), and the eol-normalizer skill no longer
restates the convention's verified-version record.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tup skill

The reconfiguration convention records that --config writes pluginConfigs to user settings
whatever -s says, and that -s governs only the install record and enabledPlugins. Drop the
claim that -s user follows from where the options load.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kyle-sexton
kyle-sexton marked this pull request as ready for review September 29, 2026 19:58
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T19:59:36.247084Z 362e027 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 42s —— View job


Code review — no blocking findings

  • Gather context (PR diff, CLAUDE.md/AGENTS.md, /review:code-review skill)
  • Review the four setup skills + evals + changelog/version bumps
  • Post findings

Scope checked: all 14 changed files (plugin.json, CHANGELOG.md, and skills/setup/SKILL.md for discipline, eol-normalizer, go-format, markdown-format, plus the go-format/markdown-format evals/evals.json).

What I verified directly:

  • Each rewritten caveat ("Pass the scope claude plugin list reports…") matches caveat 2 of docs/conventions/plugin-reconfiguration/README.md verbatim in intent.
  • git grep -n -E 'copy a scope|-s user' under plugins/ for the four plugins' setup skills/evals: no hits outside their CHANGELOG.md history — confirms the PR's own claim independently.
  • eol-normalizer's setup skill (plugins/eol-normalizer/skills/setup/SKILL.md#L90-L107) no longer restates the dated verified-version record and now only cites the convention doc — consistent with .claude/rules/skill-bodies-state-current-rules.md (no volatile specific left un-anchored).
  • The four plugin.json patch bumps line up 1:1 with each CHANGELOG.md's new ### Fixed entry and date (2026-09-29); the marketplace catalog (.claude-plugin/marketplace.json) doesn't pin plugin versions, so no catalog edit was needed there.
  • scripts/changelog-parity-baseline.txt has no entries for these four plugins, so nothing there needed updating either.

Not independently verified (sandbox denied script execution for this run): scripts/check-changelog-parity.sh --check --check-order and scripts/validate-plugins.sh, and JSON-parsing the two edited evals.json files — every Bash invocation beyond simple reads/greps in this session was denied approval. I did visually confirm both evals.json diffs are structurally sound (matched quotes/braces, single string field changed per entry), but the PR body's script-run results are author-claimed and unverified by me.

Minor, non-blocking observation: markdown-format's caveat (skills/setup/SKILL.md:130-133) omits the "-s places the install record… a rerun at another scope adds an install record there" clause that the eol-normalizer and go-format versions kept — pre-existing asymmetry, not introduced by this PR, and not something a linter/the cited convention doc requires verbatim.

No correctness bugs, architecture issues, or convention violations found in the diff.
· branch docs/5342-setup-scope-rule

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 59s —— View job


Security review: no issues found

  • Gather context (PR diff, changed files)
  • Apply skip-gate check
  • Review changed files for security-relevant surface
  • Check instruction-surface deletions against protected classes
  • Post findings / conclusion

Scope reviewed: all 14 changed files (gh pr diff 5419) — SKILL.md bodies for the discipline, eol-normalizer, go-format, and markdown-format setup skills, their plugin.json version bumps, CHANGELOG.md entries, and the go-format/markdown-format evals/evals.json expectation strings.

Findings: None. This is a documentation-only change — it edits prose instructions about which -s <scope> value to pass to claude plugin install when reconfiguring a plugin, aligning the four setup skills with the single-owner convention at docs/conventions/plugin-reconfiguration/README.md. No executable code, hooks, or CI workflow logic changed; no injection surfaces, secrets/credential handling, or authorization logic touched.

Instruction-surface lens applied. These edits modify skill bodies (a covered surface per the instruction exception register), so I checked each change against the register's six Gate 0 classes (irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority):

  • The old text hardcoded -s user with a caveat not to copy a scope from claude plugin list; the new text instead says to pass the scope claude plugin list reports (falling back to user from the home directory). I cross-checked this against the convention doc's Verified-version record (docs/conventions/plugin-reconfiguration/README.md, caveat 2), and the new wording matches it — this is a factual correction, not a guardrail removal. The scope-mismatch warning itself ("a rerun at another scope adds an install record at that scope and enables the plugin there") is preserved verbatim in every file.
  • The eol-normalizer skill drops its restated "Verified 2026-09-27 on Claude Code 2.1.283" sentence, per the PR description, because the convention doc is now the single owner of that record — deduplication, not deletion of a check.
  • None of the changed instructions fall into a Gate 0 class: nothing here governs an irreversible action, secret/credential handling, data integrity of a store this repo controls, external publication, legal/compliance, or agent authority expansion. It's guidance for a human/agent to pass a CLI flag correctly.

Version bumps, CHANGELOG entries, and eval-expectation text updates are consistent with the code changes and introduce no new risk.

@kyle-sexton
kyle-sexton merged commit 2914dae into main Sep 29, 2026
21 of 29 checks passed
@kyle-sexton
kyle-sexton deleted the docs/5342-setup-scope-rule branch September 29, 2026 20:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Restore the convention's scope rule in the setup skills that still say -s user

1 participant