From 0a52ca677d3ce9eb9cf8add113d91865a64a4131 Mon Sep 17 00:00:00 2001 From: bastien Date: Wed, 30 Sep 2026 16:11:41 +0200 Subject: [PATCH] docs: Higgsfield pack in README and CHANGELOG --- CHANGELOG.md | 3 +++ README.md | 49 +++++++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 52 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 333332c..60287f5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,7 @@ Format follows [Keep a Changelog](https://keepachangelog.com/). ## [Unreleased] ### Added +- **Higgsfield pack, off by default**: `make plugin` installs the `@higgsfield/cli` CLI (Step 8.6) and clones the skills of higgsfield-ai/skills into `skills-external/higgsfield-*` through the new `lib/higgsfield-skills.sh`; `make update` refreshes both; `make doctor` reports the CLI and its session at info level. The pack belongs to no profile: `lib/toggle-external.sh enable higgsfield` links the seven allowlisted media skills, `enable higgsfield-websites` the landing-page aid, and no `profile set` or `make link` re-enables either. `CLAUDE.global.md` routes explicit media-generation asks to it. Hermetic suite `lib/tests/higgsfield.test.sh`. - **Effort round (BDR-108)**: every skill carries an entry level next to its model pin. `lib/effort-pins.txt` (map) + `lib/effort-pins.sh` (idempotent re-apply after the last vendoring step of `install-plugins.sh` and `update-all.sh`) replace the hardcoded brainstorming/writing-plans loop and extend the pins to the design stack (high, one level per stack since the last loaded wins), superpowers, agent-skills and the 21st pack; `skills-perso` low, `pdf-translate` medium, `site-motion` high; doctrine: the design stack loads paired with the first Read (a lone Skill call applies nothing). Model pins stay tier aliases: the latest version of a tier is also the cheapest or same-priced, so the quality/price trade-off is tier × effort, never version. `lib/effort-audit.py` prints thinking coverage per scope (sub-agent records carry no thinking count on ~90 % of requests: EVAL-037's "executors stay cheap" was a measurement gap, not a finding). - **Effort tiering (BDR-107)**: reasoning effort routed per role and per phase. Session default `high`; `effort:` pins on the 20 repo-authored agents; entry level on 28 tracked user-invoked skills plus the two vendored superpowers skills (re-applied by `install-plugins.sh` after resync); five shifter skills `effort-low` … `effort-max` loaded at phase boundaries per `lib/effort-shift.md`, always sent with the step's first tool call (a lone Skill call is a no-op on 2.1.283), with `max` at the verify-secure caps and ship-feature 4b; `/effort-max` as the turn-scoped relaunch lever; statusline shows the live level; session banner warns when `CLAUDE_CODE_EFFORT_LEVEL` silences the pins; census `lib/tests/effort-routing.test.sh`; transcript audit `lib/effort-audit.py`. - **Design gate asks the user to sign in to 21st instead of skipping it**: @@ -400,6 +401,7 @@ Format follows [Keep a Changelog](https://keepachangelog.com/). `verification-before-completion` to the verifier gates. ### Security +- `settings.json` `permissions.deny` now refuses `npm i -g`, `npm install --global` and `npm i --global`: the rule matched `npm install -g` only, so the other spellings of the same global install went through. - **Ten secret-reader deny rules added**: `sed`, `awk`, `cut`, `tr`, `sort`, `uniq`, `diff`, `od`, `xxd`, `strings` against `.env*`. Six of those tools sat in `permissions.allow`, so reading a `.env` through @@ -463,6 +465,7 @@ Format follows [Keep a Changelog](https://keepachangelog.com/). plugin cache or `claude plugin list`. ### Fixed +- `install-plugins.sh` never offered the ctx7 and 21st logins: both blocks required stdout to be a terminal, and stdout is the `tee` pipe of the install log. They now test stdin alone, as `update-all.sh` already did. - `lib/effort-pins.sh` residual LOW (security re-gate of BDR-108): INT/TERM trap removes the mktemp sibling and exits 130 (never an EXIT trap, the installer owns one); the post-write re-read message no longer claims CRLF and is reached by a stubbed unit test; the rejected map line is printed through `printf '%q'` so a caller's `echo -e` cannot interpret map content; the fixture suite guards its `mktemp -d` and skips the read-only case visibly under root. - `update-all.sh` re-fetched the vendored skills at every run but never re-applied the effort pins: brainstorming/writing-plans lost their xhigh until the next `make plugin` (BDR-107 gap, closed by `lib/effort-pins.sh`). - **gitflow pre-commit blocked every commit with gitleaks 8.16** (Ubuntu's apt diff --git a/README.md b/README.md index 870d9c3..8ae41bd 100644 --- a/README.md +++ b/README.md @@ -348,6 +348,55 @@ under `defaultMode: auto` (this config's default) `ask` rules were observed auto-approving with no prompt raised (LRN-153), so an `ask` entry would have declared an intent without gating anything. +### Higgsfield CLI + +`@higgsfield/cli` (bins `higgsfield` and `higgs`) generates images, video, +audio and brand media from the terminal. One browser login, no API key. +Generation spends account credits. + +```bash +npm i -g @higgsfield/cli +higgsfield auth login # browser flow +``` + +`make plugin` does both (Step 8.6 installs the CLI, then offers the login in +an interactive terminal) and clones the skills of +[higgsfield-ai/skills](https://github.com/higgsfield-ai/skills) into +`skills-external/higgsfield-*`. `make update` refreshes the CLI and the +skills, and `make doctor` reports the CLI and its session. The copies are +machine-owned and gitignored. They follow upstream `main`, so a prompt +change arrives with no diff to review, and a skill that upstream removes +keeps its last local copy. + +The pack is off by default and belongs to no profile. It costs nothing until +you ask for it, and no `profile set` touches it: + +```bash +bash lib/toggle-external.sh enable higgsfield # media skills +bash lib/toggle-external.sh enable higgsfield-websites # landing-page aid +bash lib/toggle-external.sh disable higgsfield +``` + +`higgsfield` links a fixed list of seven media skills: generate, soul-id, +product-photoshoot, brandkit, marketplace-cards, video-explainer and +youtube-thumbnail. The list is `HIGGSFIELD_MEDIA_SKILLS` in +`lib/toggle-external.sh`. A skill that upstream adds later is synced and +reported, and stays unlinked until it is added there. + +`higgsfield-websites` is kept apart. Here it helps with landing pages inside +the design stack (assets, references), and `higgsfield website +create|deploy|publish` stays unused. Claude enables either toggle itself on +an explicit ask (Skill routing in `CLAUDE.global.md`) and checks the price +with `higgsfield generate cost` before a paid run. + +The skills are cloned, not installed with `npx skills add`: that installer +links every skill into `~/.claude/skills` on each refresh, which would undo +the off-by-default state. + +The package ships its binary through a postinstall script. If npm holds that +script back, `higgsfield` exists on PATH and fails at once; reinstall with +`npm install -g --allow-scripts=@higgsfield/cli @higgsfield/cli`. + --- ## Diagnostic and maintenance