Skip to content
Merged
2 changes: 1 addition & 1 deletion plugins/disk-hygiene/.claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json",
"name": "disk-hygiene",
"version": "0.32.0",
"version": "0.32.1",
"description": "Context-aware disk hygiene for arbitrary directory trees: inventories orphaned and temporary artifacts, classifies evidence into review tiers, and offers exact-path cleanup only after a fresh safety preview and explicit per-tier approval. The target is read-only by default; OS-managed paths, links and mount points, VCS-tracked content without the complete checkout evidence bundle, changed entries, and live-handle uncertainty fail closed.",
"author": {
"name": "Melodic Software",
Expand Down
6 changes: 6 additions & 0 deletions plugins/disk-hygiene/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,12 @@
All notable changes to the `disk-hygiene` plugin are documented here. Format follows
[Keep a Changelog](https://keepachangelog.com/en/1.1.0/); this plugin uses semantic versioning.

## [0.32.1] - 2026-09-30

### Changed

- **`clean` names the hook note as the one primary source for `hook_python` and `data_root`.** The fallback is the probe: when the note is absent, one bare-python probe is denied, names the interpreter, and the rerun probe supplies `data_root`. `safety-model.md` records that the hook is the chosen delivery path and that the denied probe in the no-hook path is an accepted residual.

## [0.32.0] - 2026-09-30

### Added
Expand Down
14 changes: 6 additions & 8 deletions plugins/disk-hygiene/skills/clean/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -115,14 +115,12 @@ blocked target, 3 when elevation is needed or filesystem state could not be veri
guard would deny. The guard is the backstop, not the sole enforcer. Every engine call and the
probe need the guard's absolute Python interpreter as `<hook-python>`, and every engine call
needs its authorized `--data-root`; bare `python`/`python3` is rejected because Bash aliases and
functions can replace them. The expansion of this command normally carries a `disk-hygiene guard
values` note naming both as `hook_python` and `data_root`, resolved by the guard's own code
before the skill loads; use them from the first call. The probe's `hook_python` and `data_root`
fields are the same two values, computed by the same guard code; when the note is absent, take
both from the probe. The probe itself needs `<hook-python>`: if neither source has supplied it,
submit the probe once with bare `python`, and the guard denies that read-only call and names its
interpreter; rerun the probe with it. Never submit a scan to learn either value. A `data_root` of
`none` in the note or `null` from the probe means the install layout proved no data root, so the
functions can replace them. The expansion of this command normally carries a `disk-hygiene guard values`
note naming `hook_python` and `data_root`, resolved by the guard's own code; use both from the
first call. Only when the note is absent, submit the probe once with bare `python`: the guard
denies that read-only call and names its interpreter. Rerun the probe with that interpreter and
take `data_root` from the probe's `data_root` field. Never submit a scan to learn either value.
A `data_root` of `none` in the note or `null` from the probe means the install layout proved no data root, so the
guard denies every engine call: report the audit as not run, relay the recovery the guard's
denial names, and submit no engine call. If `hook_python` is older than the engine's declared floor (the `MIN_PYTHON` constant
in `hygiene.py`, the floor's single origin), stop with the declared prerequisite instead of
Expand Down
3 changes: 3 additions & 0 deletions plugins/disk-hygiene/skills/clean/reference/safety-model.md
Original file line number Diff line number Diff line change
Expand Up @@ -310,6 +310,9 @@ typing `/skillname` fires it, it matches on `command_name`, and `additionalConte
alongside the expanded prompt); recheck when that section changes, or if a release note names the
event. Whether `command_name` carries the leading `/` was not observed, so the matcher admits both.

The hook is the chosen primary delivery path for both values. The one denied bare-python probe in
the no-hook path is an accepted residual: the probe cannot supply `hook_python` to itself.

`--max-depth` accepts only a bare positive-integer literal. `--confirmed-large-scan`, `--quiet`
and `--root-children` are the valueless scan flags; the guard permits at most one of each and
rejects any trailing value, so the scan grammar stays exact.
Expand Down
Loading