Skip to content

docs(disk-hygiene): record hook ask behavior under bypassPermissions - #5613

Merged
kyle-sexton merged 3 commits into
mainfrom
docs/5609-hook-ask-bypass-record
Sep 30, 2026
Merged

kyle-sexton merged 3 commits into
mainfrom
docs/5609-hook-ask-bypass-record

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

Refs #5609

Summary

Adds the four-part verification record (claim, basis, as-of, recheck) to safety-model.md for how the PreToolUse ask on hygiene.py apply --execute behaves across permission modes. It states the three modes probed, the modes not probed, and what the official docs and upstream issues say.

Fix

Only AC3 of #5609 is met. AC1 (interactive bypassPermissions and a Windows host probe) needs operator-only sessions and is not faked here; AC2 (a gate decision) depends on AC1 and stays with the owner. The issue stays open. The plugin is bumped to 0.35.1 with a CHANGELOG entry.

Verification

  • scripts/check-changelog-parity.sh --check, --check-order, --check-bump origin/main: pass.
  • scripts/validate-plugins.sh: all manifests and the catalog validated.
  • Docs-only change; no plugin tests apply.

Related

🤖 Generated with Claude Code

kyle-sexton and others added 3 commits September 30, 2026 14:03
Refs #5609

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kyle-sexton
kyle-sexton marked this pull request as ready for review September 30, 2026 18:06
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T18:09:45.587306Z 14728ae Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 14s —— View job


Code review complete ✅

  • Gather context (PR diff, REVIEW.md, AGENTS.md conventions, four-part verification record rule)
  • Understand the request (invoke /review:code-review)
  • Run review and check for inline findings
  • Post summary comment

Scope: plugins/disk-hygiene/.claude-plugin/plugin.json, plugins/disk-hygiene/CHANGELOG.md, plugins/disk-hygiene/skills/clean/reference/safety-model.md (docs-only, no security-lane overlap).

No findings. This PR is a docs-only addition and holds up well:

  • The new paragraph (safety-model.md L642-661) follows the required four-part verification record (Claim / Basis / As of / Recheck) from .claude/rules/skill-bodies-state-current-rules.md, with a dated recheck trigger rather than an undated claim.
  • I independently re-fetched both cited official doc pages and both cited upstream issues rather than trusting the PR body's own claims:
    • code.claude.com/docs/en/permission-modes: confirmed verbatim "Allow rules have no effect in bypassPermissions" and confirmed the "Actions no mode auto-approves" list names an explicit ask rule and critical-path rm/rmdir, with no mention of a hook ask.
    • code.claude.com/docs/en/hooks: confirmed the permissionDecision allow/deny/ask/defer enum is documented with no stated interaction with permission modes.
    • anthropics/claude-code#37420: confirmed title/content (hook ask resets bypass mode) and closed-as-not-planned status.
    • anthropics/claude-code#79356: confirmed title/content (hook ask / permissions.ask not enforced on the PowerShell tool in default mode) and closed-as-not-planned status.
    • The PR #5590 probe-table citation itself wasn't independently re-fetchable in this sandboxed run (GitHub PR/comment URLs on this repo required a permission grant not available here), so that one link is author-claimed and unverified by me — noted per the "don't restate the author's own claimed verification" instruction.
  • Version bump (0.35.0 → 0.35.1) and the matching CHANGELOG.md entry are consistent and correctly ordered.
  • I was not able to execute scripts/check-changelog-parity.sh or scripts/validate-plugins.sh myself in this sandbox (command approval unavailable in this unattended lane), so those two results in the PR's Verification section remain author-claimed and unverified by me.

Nothing here rises to a correctness, convention, or maintainability defect a reviewer would block on.
· branch

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 37s —— View job


Claude is reviewing this PR

  • Gather context (PR body, changed files)
  • Run /review:security-review skip-gate check
  • Review diff for security-relevant surface
  • Check instruction-surface deletions against exception register
  • Post final findings

Security review: no issues found

This PR is documentation-only. The diff:

  • Bumps plugins/disk-hygiene/.claude-plugin/plugin.json version 0.35.0 → 0.35.1.
  • Adds a changelog entry in plugins/disk-hygiene/CHANGELOG.md.
  • Inserts a four-part verification record (claim / basis / as-of / recheck) into
    plugins/disk-hygiene/skills/clean/reference/safety-model.md, documenting how the PreToolUse
    ask on hygiene.py apply --execute behaved across the three probed permission modes, and
    explicitly naming which modes were not probed (interactive bypassPermissions, auto mode,
    the Windows PowerShell tool).

No code, hook, permission config, or workflow file is touched. The addition to safety-model.md
is purely additive — it records findings and adds a new "not probed" caveat, it does not
delete, narrow, or soften any existing rule, allowlist, denylist, or enforcement mechanism, so the
instruction-surface-deletion lens (checked against
docs/conventions/instruction-exception-register/README.md, present in this checkout) does not
apply. The record itself is honest about its own limits (unprobed modes stay unprobed, AC1/AC2 of
#5609 explicitly deferred to the issue owner), which is the correct posture for a safety-relevant
claim that hasn't been fully verified.

No vulnerabilities, injection surfaces, authorization gaps, or unsafe credential handling in this
diff. Skip-gate criterion (no security-relevant surface after reading the diff) applies; no
inline comments posted.

@github-actions

Copy link
Copy Markdown
Contributor

PR body contract — issue linkage

This PR body does not yet satisfy the issue-linkage contract:

  • Missing a native closing keyword (Closes/Fixes/Resolves #N). If this PR references an issue it must not close, put "Refs: #N" (or "Relates to: #N") on its own line. If it relates to no GitHub issue at all, state "No linked issue" (or "No related issue:") in the body instead.

Edit the body and this comment updates itself on the next run.

@kyle-sexton
kyle-sexton merged commit 93d58c6 into main Sep 30, 2026
27 of 32 checks passed
@kyle-sexton
kyle-sexton deleted the docs/5609-hook-ask-bypass-record branch September 30, 2026 18:13
kyle-sexton added a commit that referenced this pull request Sep 30, 2026
Main took disk-hygiene 0.35.1 (#5613); the 0.36.0 entry stays above it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant