docs(disk-hygiene): record hook ask behavior under bypassPermissions - #5613
Conversation
Refs #5609 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Claude finished @kyle-sexton's task in 2m 14s —— View job Code review complete ✅
Scope: No findings. This PR is a docs-only addition and holds up well:
Nothing here rises to a correctness, convention, or maintainability defect a reviewer would block on. |
|
Claude finished @kyle-sexton's task in 37s —— View job Claude is reviewing this PR
Security review: no issues foundThis PR is documentation-only. The diff:
No code, hook, permission config, or workflow file is touched. The addition to No vulnerabilities, injection surfaces, authorization gaps, or unsafe credential handling in this |
|
PR body contract — issue linkage This PR body does not yet satisfy the issue-linkage contract:
Edit the body and this comment updates itself on the next run. |
Main took disk-hygiene 0.35.1 (#5613); the 0.36.0 entry stays above it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Refs #5609
Summary
Adds the four-part verification record (claim, basis, as-of, recheck) to
safety-model.mdfor how the PreToolUseaskonhygiene.py apply --executebehaves across permission modes. It states the three modes probed, the modes not probed, and what the official docs and upstream issues say.Fix
Only AC3 of #5609 is met. AC1 (interactive
bypassPermissionsand a Windows host probe) needs operator-only sessions and is not faked here; AC2 (a gate decision) depends on AC1 and stays with the owner. The issue stays open. The plugin is bumped to 0.35.1 with a CHANGELOG entry.Verification
scripts/check-changelog-parity.sh --check,--check-order,--check-bump origin/main: pass.scripts/validate-plugins.sh: all manifests and the catalog validated.Related
🤖 Generated with Claude Code