Skip to content

fix(plugins): drop availability assertions from native Boundary bullets - #5568

Merged
kyle-sexton merged 12 commits into
mainfrom
feat/native-presence-wording
Sep 30, 2026
Merged

kyle-sexton merged 12 commits into
mainfrom
feat/native-presence-wording

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

No related issue: wording-only follow-up to the native-reference sweep; it fixes the presence-wording defect Codex raised on #5504.

Summary

Boundary bullets in 13 plugins said a native surface "Ships with Claude Code rather than as a marketplace plugin". That is an availability assertion, and the native-references convention says a component never states that a native surface is present. The sweep units fix it plugin by plugin (#5509, #5556). This PR covers every other plugin in one change, since body text spends no listing budget and changes no routing.

Fix

  • Each affected bullet now uses the convention's template form, **\` ()**: what it does`, and keeps every behavioral statement it carried (what the surface mutates, and whether the model or only the person invokes it).
  • review:fanout's Boundary says the bundled command and the managed service are not marketplace plugins, without asserting that either is present.
  • No description, store row, or routing text changes.
  • Patch bumps, each one above origin/main: bugs 0.11.6, claude-memory 0.13.12, code-tidying 0.25.1, debugging 0.7.12, discovery 0.25.16, github 0.3.22, implementation 0.19.16, planning 0.49.2, review 0.34.1, session-flow 0.40.3, source-control 0.65.3, testing 0.11.6, verification 0.6.13.

Verification

  • overlap.py self-check: degraded, on the 2 documented advisories only. generate --check: in sync. test_overlap.py: OK.
  • overlap.py detect against a 2.1.285 inventory: 0 new, 0 resurfaced.
  • check-changed-skills.sh origin/main: 21 checked, 0 failed.
  • validate-plugin-contracts.mjs: 0 warnings. generate-catalog.mjs --check: in sync.
  • check-changelog-parity.sh: --check, --check-order, --check-bump, --check-preserved all pass. check-spoke-plugin-root.sh --check: clean.
  • typos and markdownlint on the changed files: clean.
  • The only "Ships with Claude Code" bullets left are in claude-ops, context-budget, playbooks and prototype. feat(claude-ops): bake the explain-usage route phrase into observability's description #5556 and the combined phrase-sweep PR fix those.

Related

🤖 Generated with Claude Code

kyle-sexton and others added 2 commits September 29, 2026 23:03
Every remaining Boundary bullet that said a native surface "Ships with
Claude Code" now uses the native-references template form: the
provenance class, what the surface does, and how it is invoked, with no
availability claim. Covers bugs, claude-memory, code-tidying, debugging,
discovery, github, implementation, planning, review, session-flow,
source-control, testing and verification, each patch-bumped with a
CHANGELOG entry. Review's fanout Boundary now says the bundled command
and the managed service are not marketplace plugins. No description or
store row changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…wording

# Conflicts:
#	plugins/discovery/CHANGELOG.md
#	plugins/implementation/CHANGELOG.md
#	plugins/planning/.claude-plugin/plugin.json
#	plugins/planning/CHANGELOG.md
#	plugins/review/CHANGELOG.md
#	plugins/source-control/.claude-plugin/plugin.json
#	plugins/source-control/CHANGELOG.md
@kyle-sexton
kyle-sexton marked this pull request as ready for review September 30, 2026 04:23
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T15:15:34.347026Z 455ce41 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

…wording

# Conflicts:
#	plugins/planning/CHANGELOG.md
#	plugins/source-control/CHANGELOG.md
@kyle-sexton

Copy link
Copy Markdown
Contributor Author

@codex review

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 3s —— View job


Security review: no issues found

Skip gate evaluated, review completed with no findings.

This PR is a prose-only edit across 47 files (13 SKILL.md docs, 13 plugin.json version bumps, 13 CHANGELOG.md entries, and plugins/planning/.claude-plugin/plugin.json). Diffed the full non-changelog content at 253eb6c:

  • Every changed SKILL.md only removes the sentence "Ships with Claude Code rather than as a marketplace plugin" (an availability assertion) from a native-surface bullet in each file's ## Boundary section, per the native-references convention this PR implements.
  • Applied the instruction-surface deletion lens from this skill's criteria, since a ## Boundary bullet is an instruction body and this diff narrows text there: in every file where the original bullet carried an enforceable restriction ("It is reserved for the person to run; the model does not invoke it", "registration disables model invocation", "the model does not invoke them", etc.), that restriction is preserved verbatim in the new text — e.g. plugins/bugs/skills/write/SKILL.md, plugins/claude-memory/skills/stateless/SKILL.md, plugins/discovery/skills/research-deep/SKILL.md, plugins/session-flow/skills/continue-in-background/SKILL.md, plugins/source-control/skills/pull-request/SKILL.md, and the rest of the set. Nothing that gated model invocation, mutation scope, or posting authority was removed or softened.
  • plugins/review/skills/fanout/SKILL.md swaps "Both ship with Claude Code itself rather than as marketplace plugins" for "Neither is a marketplace plugin" — same fact, no presence assertion added.
  • plugin.json changes are version-number bumps only; CHANGELOG.md changes are new entries only. No workflow, script, permission, or config file is touched.

No CRITICAL, IMPORTANT, or SUGGESTION findings. GitHub Actions hardening is out of scope for this lane (zizmor's) and no workflow files changed in this PR regardless.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. You're on a roll.

Reviewed commit: f7bea6c3bf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@kyle-sexton
kyle-sexton enabled auto-merge (squash) September 30, 2026 04:39
@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in progress

  • Gather context (PR diff, CLAUDE.md/AGENTS.md conventions)
  • Understand request: run /review:code-review per custom instructions
  • Review changed files for correctness/maintainability findings
  • Post inline comments for anchorable findings
  • Post final summary

View job run

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 7s —— View job


Security review complete

  • Gather context (PR diff, changed files)
  • Check skip-gate conditions
  • Review diff for security-relevant surface (injection, authz, secrets, instruction-surface deletions)
  • Post findings

No security issues found.

This PR is a wording-only sweep across 13 plugins: .claude-plugin/plugin.json version bumps, CHANGELOG.md entries, and one Boundary bullet per affected SKILL.md. No code, scripts, hooks, permissions, or .github/workflows files changed.

Instruction-surface deletion check. Every changed SKILL.md bullet removes the sentence "Ships with Claude Code rather than as a marketplace plugin" (an availability/provenance assertion) and folds the remainder into the native-references template form **\` ()**: .... I checked each hunk against the [instruction exception register](https://github.com/melodic-software/claude-code-plugins/blob/f7bea6c3bf3fb8bbd2a3f10048fed259b927e2a9/docs/conventions/instruction-exception-register/README.md)'s six protected classes (irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority`):

  • The removed sentence itself doesn't match any protected class — it's a factual "where this ships from" statement, not a behavioral rule.
  • Every agent-authority-relevant clause (who may invoke: "reserved for the person to run; the model does not invoke it", "The model and the person can both invoke it", etc.) is preserved verbatim in all 21 affected bullets. Confirmed by diffing each hunk, e.g. plugins/bugs/skills/write/SKILL.md#L44, plugins/source-control/skills/pull-request/SKILL.md#L707.
  • No mutation, invocation, or trust-boundary behavior changes — only the wording that asserted the native surface's presence is dropped, consistent with the convention this PR cites (a component should never assert that a native surface is present, since availability is host/settings-gated).

Nothing in this diff touches injection surfaces, authz, secrets, or GitHub Actions configuration, so zizmor's lane is not implicated either.

…wording

# Conflicts:
#	plugins/planning/CHANGELOG.md
#	plugins/source-control/.claude-plugin/plugin.json
#	plugins/source-control/CHANGELOG.md
@kyle-sexton

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Swish!

Reviewed commit: 1961835623

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

…wording

# Conflicts:
#	plugins/review/.claude-plugin/plugin.json
#	plugins/review/CHANGELOG.md
@kyle-sexton

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Nice work!

Reviewed commit: 708f8a6fd3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

…wording

# Conflicts:
#	plugins/discovery/CHANGELOG.md
@kyle-sexton

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 93e1f86d0e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/discovery/CHANGELOG.md Outdated
Each of the 13 CHANGELOG entries this change adds sat above a
2026-09-30 release on main while dated 2026-09-29, so the chronology
ran backward. All 13 now read 2026-09-30.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 5s —— View job


Security review: no issues found

Skip gate evaluated, review completed with no findings.

Reviewed the content commit ecb2087 (the only non-merge, non-date-fix commit on this branch since the last Codex pass), which matches the PR's 47 changed files: 13 SKILL.md docs, 13 plugin.json version bumps, 13 CHANGELOG.md entries, and one further version-bump chain. The head SHA supplied in this task's header (708f8a6f) is a merge ancestor of the branch's current tip; the one commit made on top of it since (5f611b4) only corrects 13 CHANGELOG date strings and touches nothing security-relevant.

Instruction-surface deletion check. Every changed SKILL.md bullet removes the sentence "Ships with Claude Code rather than as a marketplace plugin" (or the fanout variant "Both ship with Claude Code itself rather than as marketplace plugins" → "Neither is a marketplace plugin"). I read docs/conventions/instruction-exception-register/README.md and checked each removed sentence against its six protected classes (irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority):

  • The removed sentence is a pure provenance/availability statement in every hunk — it doesn't match any protected class.
  • Every agent-authority-bearing clause (who may invoke the surface) is preserved verbatim alongside the removal, in all 21 affected bullets — e.g. plugins/bugs/skills/write/SKILL.md ("reserved for the person to run; the model does not invoke it"), plugins/discovery/skills/research-deep/SKILL.md ("its registration disables model invocation, so the model does not start it and Tier 1 does not dispatch it"), plugins/source-control/skills/pull-request/SKILL.md and plugins/source-control/skills/commit/SKILL.md ("The model and the person can both invoke it"), plugins/review/skills/code-review/SKILL.md ("Claude may start it on its own where the session allows"), and the rest of the set. Nothing that gates model invocation, mutation scope, or posting authority was weakened or dropped.
  • plugin.json diffs are version-number bumps only; CHANGELOG.md diffs are new dated entries only. No workflow, script, permission, hook, or config file changed.

No CRITICAL, IMPORTANT, or SUGGESTION findings. GitHub Actions hardening is out of scope for this lane (zizmor's) and no .github/workflows files are touched regardless.

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 34s —— View job


Code review complete

  • Gather context (PR diff via gh pr diff, CLAUDE.md/AGENTS.md conventions)
  • Understand request: invoke /review:code-review for this PR (code-review CI lane)
  • Review changed files for correctness/maintainability findings
  • Post inline comments for anchorable findings
  • Post final summary

This is a mechanical wording sweep across 13 plugins (20 SKILL.md bullets, 13 plugin.json version bumps, 13 CHANGELOG.md entries), removing the "Ships with Claude Code rather than as a marketplace plugin" availability assertion from each Boundary bullet. I diffed every changed bullet against its pre-PR text line by line.

Content preserved. In every converted bullet, all behavioral clauses (who may invoke it, what it mutates, model-invocation restrictions) carry over verbatim into the new **\name` (class)**: description` form. No information was dropped in the rewrite.

Version/changelog consistency verified. All 13 plugin.json bumps match their CHANGELOG.md entry versions, all new entries are dated 2026-09-30 (today), and each sits above its prior (2026-09-29-dated) entry in correct newest-first order — including discovery's 0.25.14 entry, which Codex flagged for a backward date at commit 93e1f86; that's fixed as of the latest commit (5f611b4), now dated 2026-09-30 same-or-after its 0.25.13 predecessor. Each CHANGELOG.md bullet also accurately names every file/bullet it describes (spot-checked planning, review, session-flow, source-control, code-tidying multi-bullet entries against their diffs).

One minor inline finding: plugins/testing/skills/run-e2e/SKILL.md#L152-L154 — this is the only bullet (of 21) that doesn't follow the **name (class)**: description template the rest of the sweep establishes; the , beside \/verify` and `/run-skill-generator`` aside sits between the bold header and the colon, making the colon's referent ambiguous on first read. Posted as an inline suggestion that moves the aside to the end of the sentence, matching every other converted bullet.

No other correctness, maintainability, or template-consistency issues found. Author-claimed verification (overlap/changelog/contract scripts, typos, markdownlint) was not independently re-run here — those are outside this lane's scope and are reported in the PR body as author-run.

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 12s —— View job


Security review: no issues found

No security issues found.

This PR is a wording-only sweep across 13 plugins: .claude-plugin/plugin.json version bumps, CHANGELOG.md entries, and one Boundary bullet per affected SKILL.md (21 bullets total across the diff). No scripts, hooks, permissions, or .github/workflows files are touched.

Instruction-surface deletion check. Every changed SKILL.md bullet removes only the sentence "Ships with Claude Code rather than as a marketplace plugin" (an availability/provenance assertion, not a behavioral rule) and folds the remainder into the native-references template form **\` ()**: .... I read [docs/conventions/instruction-exception-register/README.md](https://github.com/melodic-software/claude-code-plugins/blob/5f611b49adb3362e90c6a70d5ce7fbdcf7ad237e/docs/conventions/instruction-exception-register/README.md), which points to Gate 0's six protected classes (irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority`), and diffed all 21 hunks against it directly rather than relying on the earlier reviews' summary:

  • The removed sentence itself doesn't match any protected class — it states where a surface ships from, not a behavioral rule.
  • Every agent-authority clause (who may invoke a surface) is preserved verbatim in every hunk that carried one: "reserved for the person to run; the model does not invoke it" (plugins/bugs/skills/write/SKILL.md#L44), "its registration disables model invocation, so the model does not start it" (plugins/discovery/skills/research-deep/SKILL.md#L262), "the model and the person can both invoke it" (plugins/source-control/skills/commit/SKILL.md#L681), and the equivalent clauses in the remaining 18 bullets (claude-memory, code-tidying ×2, debugging, github, implementation, planning ×2, review ×3, session-flow ×3, source-control ×2 more, testing, verification).
  • plugins/review/skills/fanout/SKILL.md#L500 swaps "Both ship with Claude Code itself rather than as marketplace plugins" for "Neither is a marketplace plugin" — same fact, no presence assertion added, no mutation-gate text touched.
  • No mutation, invocation, posting-authority, or trust-boundary text changed anywhere in the diff — only the presence/availability wording the native-references convention forbids.

Nothing here touches injection surfaces, authz, secrets, or GitHub Actions configuration, so zizmor's lane isn't implicated either. (Codex's one open comment, on discovery/CHANGELOG.md date ordering, is a doc-quality nit outside this lane's scope — not a security finding.)

Comment thread plugins/testing/skills/run-e2e/SKILL.md Outdated
@kyle-sexton

Copy link
Copy Markdown
Contributor Author

@codex review

…wording

# Conflicts:
#	plugins/planning/.claude-plugin/plugin.json
#	plugins/planning/CHANGELOG.md
@kyle-sexton

Copy link
Copy Markdown
Contributor Author

@codex review

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 9s —— View job


Code review: skip gate — no new diff to review

Skip gate hit: this lane already reviewed this exact diff.

The head this run was triggered on, 545a6ed, is a merge of origin/main into this branch. I diffed 5f611b4 (the commit the prior code-review pass reviewed, posted 2026-09-30 06:20 UTC in this thread) against 545a6ed: the merge brings in 134 files from origin/main (docs/conventions, claude-ops, disk-hygiene, guardrails, machine-health, instruction-placement, etc.), and none of them overlap the 47 files this PR actually changes. So the reviewable content — the 21 Boundary-bullet rewrites, 13 plugin.json bumps, 13 CHANGELOG.md entries — is byte-identical to what was already reviewed.

That earlier pass found the diff mechanically sound (behavioral clauses preserved verbatim in every converted bullet, plugin.json/CHANGELOG.md bumps consistent and correctly ordered after the 5f611b4 date fix) and left one open minor finding, still unaddressed on this head:

  • plugins/testing/skills/run-e2e/SKILL.md#L152 — this is the only bullet (of 21) that doesn't follow the **name (class)**: description template the rest of the sweep establishes. The appositive , beside \/verify` and `/run-skill-generator`` sits between the bold header and the colon, making the colon's referent ambiguous on first read. Already posted as an inline suggestion on this PR by the earlier review pass; not re-posted here to avoid a duplicate.

No new correctness or maintainability findings on top of that.

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 52s —— View job


Security review: no issues found

Skip gate: the diff narrows Boundary-bullet wording in 21 places, so it isn't eligible for the cheap skip until read under the instruction-surface lens below. Read docs/conventions/instruction-exception-register/README.md directly (present in this checkout) for the six protected classes.

Full diff re-read against origin/main (git diff origin/main...HEAD) confirms it matches the PR's 47 files exactly (13 SKILL.md docs, 13 plugin.json version bumps, 13 CHANGELOG.md entries, 1 further planning-plugin file). No script, hook, permission, or .github/workflows file is touched.

Instruction-surface deletion check. Every changed SKILL.md bullet removes only the sentence "Ships with Claude Code rather than as a marketplace plugin" (or, in fanout, "Both ship with Claude Code itself rather than as marketplace plugins" → "Neither is a marketplace plugin") and folds the remainder into the native-references template **\name` (class)**: description. Checked all 21 hunks against the register's six protected classes (irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority`):

  • The removed sentence is a pure provenance/availability statement in every hunk — it matches none of the six classes.
  • Every agent-authority clause (who may invoke the surface) survives verbatim in every bullet that carried one, e.g. plugins/bugs/skills/write/SKILL.md#L144 ("reserved for the person to run; the model does not invoke it"), plugins/discovery/skills/research-deep/SKILL.md#L114 ("its registration disables model invocation, so the model does not start it"), plugins/source-control/skills/commit/SKILL.md#L364 ("the model and the person can both invoke it"), and the equivalent clause in the remaining 18 bullets. No mutation-gate, invocation-authority, or posting-scope text was weakened or dropped anywhere in the diff.
  • plugin.json diffs are version-number bumps only; CHANGELOG.md diffs are new entries only, each matching its plugin.json version, dated 2026-09-30, and ordered correctly (the discovery backward-date issue Codex flagged on 93e1f86 is fixed as of 5f611b4: 0.25.14 now sits above 0.25.13 with a same-or-later date).

No CRITICAL, IMPORTANT, or SUGGESTION findings. GitHub Actions hardening is zizmor's advisory lane and out of scope regardless — no .github/workflows files changed in this PR.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Breezy!

Reviewed commit: 545a6ed574

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

The aside naming /verify and /run-skill-generator sat between the bold
header and the colon, so the colon no longer introduced what `run`
does. It moves to the end of the description, matching the other
converted bullets.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 37s —— View job


Code review complete

Skip gate: only one file changed since the last full pass, and it's the fix for that pass's sole finding.

HEAD is now 8ae3190. The only content commit on top of 545a6ed (already reviewed by this lane, confirmed no-op via the merge-diff check in an earlier run) is 8ae3190, which touches exactly one file: plugins/testing/skills/run-e2e/SKILL.md.

That's the fix for this lane's earlier minor finding: the run bullet had an appositive (, beside \/verify` and `/run-skill-generator`) sitting between the bold header and the colon, breaking the name (class): description` template every other converted bullet follows. The new text moves the aside to the end of the sentence:

- **`run` (bundled skill)**: infers the launch from the project type (CLI, server, TUI,
  browser-driven), starts the app, and drives it so a change can be looked at, beside `/verify` and
  `/run-skill-generator`. It captures no evidence to a contract and has no non-UI mode.

This matches the suggested fix exactly, restores the template shape, and changes nothing else — the sentence's content (what run does, that it captures no evidence, that it has no non-UI mode) is unchanged. The adjacent bullet (**This skill (marketplace plugin).**, which uses a period rather than a colon) is untouched by this PR and pre-existing, so it's out of scope here.

I diffed origin/main...HEAD in full (git diff origin/main...HEAD --stat) to confirm it still totals 47 files / 198(+)/105(-), matching the PR description, with no other changes introduced alongside this fix.

No new correctness or maintainability findings. No inline comments needed — the sole outstanding item from this lane is resolved.

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 29s —— View job


Security review: no issues found

Skip gate: the only commit added since the last security-review pass (545a6ed, posted 2026-09-30 13:13 UTC in this thread) is 8ae3190, which touches one file: plugins/testing/skills/run-e2e/SKILL.md. I read the full diff of that commit directly rather than relying on the prior pass's summary.

What changed: this commit is the fix for the inline template-shape finding Codex/Claude posted earlier in this thread. It only relocates the existing appositive , beside \/verify` and `/run-skill-generator`` from between the bold header and the colon to the end of the description sentence:

- **`run` (bundled skill)**: infers the launch from the project type (CLI, server, TUI,
  browser-driven), starts the app, and drives it so a change can be looked at, beside `/verify` and
  `/run-skill-generator`. It captures no evidence to a contract and has no non-UI mode.

No text was added or removed — every clause present before (including the agent-authority-relevant scope: no invocation-permission language is present in this bullet at all, and none was introduced) is still present, just reordered for readability. This is a pure word-order edit with no instruction-surface deletion, so the instruction-exception-register lens from the skill's criteria doesn't add anything beyond what the last full pass already established.

The rest of the PR's 47 changed files are unchanged since 545a6ed, which the prior security-review pass (posted 2026-09-30 13:13 UTC) already reviewed in full: 21 Boundary-bullet rewrites across 13 plugins, all agent-authority clauses (who may invoke a surface) preserved verbatim, plugin.json/CHANGELOG.md changes limited to version bumps and dated entries, no .github/workflows files touched.

No CRITICAL, IMPORTANT, or SUGGESTION findings. GitHub Actions hardening remains zizmor's advisory lane and is out of scope regardless — no workflow files changed in this PR.

@kyle-sexton

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Delightful!

Reviewed commit: 8ae31902ea

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

…wording

# Conflicts:
#	plugins/discovery/CHANGELOG.md
#	plugins/planning/.claude-plugin/plugin.json
#	plugins/planning/CHANGELOG.md
#	plugins/source-control/CHANGELOG.md
#	plugins/testing/.claude-plugin/plugin.json
#	plugins/testing/CHANGELOG.md
@kyle-sexton

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. More of your lovely PRs please.

Reviewed commit: 0fc4d5a5ea

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

…wording

# Conflicts:
#	plugins/source-control/CHANGELOG.md
@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 32s —— View job


Security review: no issues found

Skip gate: this head's reviewable content is unchanged from the last full pass.

HEAD is now 0fc4d5a, a merge of origin/main into this branch (no new commit on top of 8ae3190, the last commit this lane reviewed). I re-pulled the PR diff directly via gh pr diff 5568 rather than relying on the prior summary, and confirmed it is byte-identical in content to what the last full security-review pass (posted 2026-09-30 13:21 UTC) covered: 47 files, 21 Boundary-bullet rewrites across 13 plugins, 13 plugin.json version bumps, 13 CHANGELOG.md entries, one further planning file.

Instruction-surface deletion check, done directly against the diff (not the prior summary): every changed SKILL.md bullet removes only the sentence "Ships with Claude Code rather than as a marketplace plugin" (or, in fanout, "Both ship with Claude Code itself rather than as marketplace plugins" → "Neither is a marketplace plugin") and folds the remainder into the native-references template **\name` (class)**: description. Read [docs/conventions/instruction-exception-register/README.md](https://github.com/melodic-software/claude-code-plugins/blob/0fc4d5a5eaa79b42ec6e74c9e10aef5b517d8159/docs/conventions/instruction-exception-register/README.md) (present in this checkout) for the six protected classes (irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority`):

  • The removed sentence itself is a pure provenance/availability statement in every hunk — it matches none of the six classes.
  • Every agent-authority clause (who may invoke a surface) survives verbatim in every bullet that carried one, e.g. plugins/bugs/skills/write/SKILL.md#L144 ("reserved for the person to run; the model does not invoke it"), plugins/discovery/skills/research-deep/SKILL.md#L114 ("its registration disables model invocation, so the model does not start it"), plugins/source-control/skills/commit/SKILL.md#L684 ("the model and the person can both invoke it"), and the equivalent clause in the remaining 18 bullets (claude-memory, code-tidying ×2, debugging, github, implementation, planning ×2, review ×3, session-flow ×3, source-control ×2 more, testing, verification). No mutation-gate, invocation-authority, or posting-scope text was weakened or dropped anywhere in the diff.
  • plugin.json diffs are version-number bumps only; CHANGELOG.md diffs are new dated entries only. No script, hook, permission, or .github/workflows file is touched.

No CRITICAL, IMPORTANT, or SUGGESTION findings. GitHub Actions hardening remains zizmor's advisory lane and is out of scope regardless — no workflow files changed in this PR.

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Code review in progress

  • Gather context (PR diff, CLAUDE.md/AGENTS.md conventions)
  • Invoke /review:code-review per custom instructions
  • Review changed files for correctness/maintainability findings
  • Post inline comments for anchorable findings
  • Post final summary

View job run

@kyle-sexton

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Another round soon, please!

Reviewed commit: 84ae4326cf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

…wording

# Conflicts:
#	plugins/discovery/CHANGELOG.md
@kyle-sexton

Copy link
Copy Markdown
Contributor Author

@codex review

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 55s —— View job


Security review: no issues found

No security issues found.

This PR is a wording-only sweep across 13 plugins: .claude-plugin/plugin.json version bumps (checked all — version-number changes only), CHANGELOG.md new dated entries, and one Boundary bullet per affected SKILL.md (21 bullets total). No scripts, hooks, permissions, or .github/workflows files are touched.

Instruction-surface deletion check. I read docs/conventions/instruction-exception-register/README.md directly (present in this checkout) and diffed every non-changelog, non-manifest hunk (git diff origin/main...HEAD) against its six protected classes (irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority):

  • The sentence every hunk removes, "Ships with Claude Code rather than as a marketplace plugin" (or the fanout variant, "Both ship with Claude Code itself rather than as marketplace plugins" → "Neither is a marketplace plugin"), is a pure provenance/availability statement — it matches none of the six classes.
  • Every agent-authority clause (who may invoke a surface) survives verbatim in every bullet that carried one, confirmed line-by-line, e.g.:
  • No mutation, invocation, or posting-authority text changed anywhere in the diff — only the presence/availability wording the native-references convention forbids.

Nothing here touches injection surfaces, authz, secrets, or GitHub Actions configuration, so zizmor's lane isn't implicated either — no .github/workflows files changed in this PR.

This is a re-confirmation of the same conclusion this lane reached on every prior head in this thread; the reviewable content has not changed since (the merge commits since bring in unrelated origin/main history only).

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🚀

Reviewed commit: 455ce4102c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 3s —— View job


Code review: skip gate — no new diff to review

Skip gate hit: this lane already reviewed this exact diff.

HEAD is now 455ce41. Since the last full code-review pass on this lane (posted 2026-09-30 15:00:27Z / job 36732094078, which found no issues on 8ae3190), only two merge commits landed (84ae432, 455ce41), bringing in 218 files' worth of origin/main history (docs/, plugins/disk-hygiene, plugins/claude-ops, plugins/planning/surface, plugins/repo-hygiene, format-plugin hook-utils.sh consolidation, etc.).

I verified the PR's actual reviewable content is unchanged rather than trusting that on its face:

  • git diff origin/main...HEAD --stat still totals exactly 47 files, 198(+)/105(-) — matching the PR description byte-for-byte.
  • Spot-checked the plugins whose files also appear in the incoming merge diff (discovery, planning, testing, source-control) directly against origin/main: each CHANGELOG.md/plugin.json diff is a clean version bump + one new dated entry, with no merge-conflict artifacts or stray content pulled in from the resolved merge.

So the 21 Boundary-bullet rewrites, 13 plugin.json bumps, and 13 CHANGELOG.md entries are byte-identical to what the prior full pass already reviewed and cleared: behavioral clauses (who may invoke a surface, what it mutates) preserved verbatim in every converted bullet, version/changelog bumps consistent and correctly ordered, the run-e2e template-shape fix (from this lane's earlier inline finding) still in place.

No new correctness or maintainability findings.

@kyle-sexton
kyle-sexton merged commit 1142789 into main Sep 30, 2026
25 checks passed
@kyle-sexton
kyle-sexton deleted the feat/native-presence-wording branch September 30, 2026 15:19
@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 33s —— View job


Security review: skip gate — PR is merged

Skip gate hit: PR is closed (merged). This PR's state is MERGED; the local checkout on claude/pr-5568-20260930-1519 sits on the merge commit 1142789 on main, and the branch tip 455ce4102cd5d76c404f88bae43eaab10f498035 this task's header names is not reachable from this checkout — it was the PR branch's head immediately before merge, with no further commits since.

Per this skill's skip gate ("PR is closed or not open"), no new review runs. For reference, this exact diff (47 files: 21 Boundary-bullet wording rewrites across 13 plugins, 13 plugin.json version bumps, 13 CHANGELOG.md entries) was already reviewed multiple times in this thread by this lane with no CRITICAL/IMPORTANT/SUGGESTION findings, most recently against HEAD 0fc4d5a (2026-09-30 14:59 UTC): the removed "Ships with Claude Code rather than as a marketplace plugin" sentence is a pure availability/provenance statement in every hunk, not a protected-class instruction (checked against docs/conventions/instruction-exception-register/README.md's six classes), and every agent-authority clause (who may invoke a surface) survives verbatim. No script, hook, permission, or .github/workflows file was touched anywhere in the PR's history.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant