chore(config): security-guidance Stop review off, plugins off, routing and docs
settings.json: ENABLE_STOP_REVIEW=0 (the plugin's own switch: no more Opus call on every turn that changes code, 0 findings in 6 days, 1 recorded false positive; the regex layer and the commit/push agentic review stay on), brightdata-plugin@synced false (keyless-useless, its MCP skill would hijack WebFetch/WebSearch), frontend-design official plugin entry gone (uninstalled: byte-identical to the managed copy). CLAUDE.global.md routes Ship/PR to ship-feature (gstack ship takes origin/HEAD = main as base), drops ship/context-save from the gstack-off list and 21st-ui-review from the design review line (trio is max-only). deploy's table no longer points at land-and-deploy/setup-deploy. plugin-advisor.md describes security-guidance's real mechanics. CHANGELOG Unreleased entry with a Known residual section.
This commit is contained in:
@@ -201,6 +201,21 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
|||||||
seeded like a real tree (gstack off, nothing linked).
|
seeded like a real tree (gstack off, nothing linked).
|
||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
- **`full` = everything the other profiles carry** (user rule: full does
|
||||||
|
what every specialized profile does), minus the 9 removed gstack
|
||||||
|
skills, the 21st generation/review trio and one named exception
|
||||||
|
(`pr-review-toolkit`, deliberately out of full since audit 2026-07-02
|
||||||
|
#12). New `max` profile (`# SUPERSET-OF: full` marker) is `full` plus
|
||||||
|
the parked tools (`make-pdf`, `diagram`, `21st-ai`, `21st-ui-explore`,
|
||||||
|
`21st-ui-review`) plus `pr-review-toolkit` — switch here when one of
|
||||||
|
them is needed. The 21st generation/review trio leaves `full`, `web`,
|
||||||
|
`web-full` and `design`; `CLAUDE.global.md`'s Design work line drops
|
||||||
|
`21st-ui-review` and notes the trio is `max`-profile only.
|
||||||
|
`security-guidance`'s Stop-hook LLM review is off
|
||||||
|
(`ENABLE_STOP_REVIEW=0` in `settings.json`'s `env`, the plugin's own
|
||||||
|
switch); its regex layer and the commit/push agentic review stay on.
|
||||||
|
`doctor.sh`'s skill-catalog token constants are recomputed from a real
|
||||||
|
count instead of a stale estimate.
|
||||||
- **CLAUDE.global.md § Code style** — the ordered YAGNI decision ladder
|
- **CLAUDE.global.md § Code style** — the ordered YAGNI decision ladder
|
||||||
(not needed → reuse → stdlib → platform → installed dependency → one line
|
(not needed → reuse → stdlib → platform → installed dependency → one line
|
||||||
→ the minimum that works, after understanding the problem) and a
|
→ the minimum that works, after understanding the problem) and a
|
||||||
@@ -381,6 +396,19 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
|||||||
traced by reading, never by running, whatever the brief says.
|
traced by reading, never by running, whatever the brief says.
|
||||||
|
|
||||||
### Removed
|
### Removed
|
||||||
|
- **Skill-catalog prune**: `brightdata-plugin@synced` disabled
|
||||||
|
(account-synced, keyless-useless, its `bright-data-mcp` skill would
|
||||||
|
hijack WebFetch/WebSearch), `frontend-design@claude-plugins-official`
|
||||||
|
uninstalled (byte-identical duplicate of the managed `skills-external`
|
||||||
|
copy). The 9 broken or doctrine-breaking gstack skills — `ship`,
|
||||||
|
`land-and-deploy`, `setup-deploy`, `autoplan`, `context-save`, `learn`,
|
||||||
|
`careful`, `guard`, `design-shotgun` — are out of every profile that
|
||||||
|
listed them (`dev`, `backend`, `web`, `web-full`, `design`, `full`),
|
||||||
|
each with its reason in the new `lib/gstack-removed.sh` (exit-127 hooks,
|
||||||
|
an absent `OPENAI_API_KEY`, `ship`/`land-and-deploy` skipping develop,
|
||||||
|
`context-save` with no restore). The new `GSTACK_REMOVED` denylist is
|
||||||
|
honored by `profile.sh gstack on` and `toggle-external.sh enable
|
||||||
|
gstack`: both now skip a removed name instead of silently restoring it.
|
||||||
- `deploy` `push_deploy_tags` knob (the STATE.json commit's hook pushes the tag
|
- `deploy` `push_deploy_tags` knob (the STATE.json commit's hook pushes the tag
|
||||||
with `--follow-tags`); `/onboard add gsd` and `/onboard continue` mentions
|
with `--follow-tags`); `/onboard add gsd` and `/onboard continue` mentions
|
||||||
(never had a handler).
|
(never had a handler).
|
||||||
@@ -393,6 +421,24 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
|||||||
and the dead `MAGIC_API_KEY=abc123` gitleaks allowlist regex.
|
and the dead `MAGIC_API_KEY=abc123` gitleaks allowlist regex.
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
- **gstack's shared helper tree was mostly unreachable.** gstack skills
|
||||||
|
hardcode `~/.claude/skills/gstack/<path>` for shared assets, but
|
||||||
|
`link.sh` and `install-plugins.sh` only ever linked `bin` and
|
||||||
|
`browse/dist`. A shared `lib/gstack-links.sh` (used by `link.sh`,
|
||||||
|
`install-plugins.sh` and `update-all.sh`) now links every non-skill
|
||||||
|
child of the gstack submodule, so `make-pdf`, `diagram`, the `freeze`
|
||||||
|
hook, the `*/sections/*.md` files, `scripts/jargon-list.json` and
|
||||||
|
`ETHOS.md` resolve; `/unfreeze` now actually clears
|
||||||
|
`~/.gstack/freeze-dir.txt`. `doctor.sh` counted skills with `find
|
||||||
|
-maxdepth 2` (no `-L`, missed symlinked skills) and truncated
|
||||||
|
block-scalar (`|`/`>`) descriptions to 0 chars; it now reuses
|
||||||
|
`lib/skill-routing-census.py`'s description parser through
|
||||||
|
`lib/doctor-skills.sh`. Dropped the stale "security-guidance … 0
|
||||||
|
tokens" claim from `install-plugins.sh` and `agents/plugin-advisor.md`:
|
||||||
|
the Stop review costs out-of-band quota, not context.
|
||||||
|
`CLAUDE.global.md`'s Ship/PR routing pointed at gstack's `ship`, which
|
||||||
|
bases off `origin/HEAD` (= main) and skips develop; it now routes
|
||||||
|
straight to `ship-feature`.
|
||||||
- **`gitflow init` on an existing repo under the machine-wide hooks** — the
|
- **`gitflow init` on an existing repo under the machine-wide hooks** — the
|
||||||
socle commit (`.gitignore` + `.githooks/`) landed directly on `main`
|
socle commit (`.gitignore` + `.githooks/`) landed directly on `main`
|
||||||
"while the hook is inactive"; since the global `core.hooksPath` the
|
"while the hook is inactive"; since the global `core.hooksPath` the
|
||||||
@@ -438,6 +484,14 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
|||||||
pin rerun (no false warning), parked copy plus rotted pin (fallback, then
|
pin rerun (no false warning), parked copy plus rotted pin (fallback, then
|
||||||
returned to `skills-disabled/`).
|
returned to `skills-disabled/`).
|
||||||
|
|
||||||
|
### Known residual
|
||||||
|
- The kept gstack skills still carry upstream prose routing to `/ship`,
|
||||||
|
`/land-and-deploy`, `/context-save`, `/autoplan` and `/design-shotgun`
|
||||||
|
(their own text, machine-owned submodule files, not ours to patch);
|
||||||
|
`21st-ui-build` and `21st-cli-use` still point at the now-`max`-only
|
||||||
|
21st trio. A Skill call on a parked name fails, and the doctrine
|
||||||
|
routing in `CLAUDE.global.md` applies instead.
|
||||||
|
|
||||||
## [1.5.0] — 2026-09-13
|
## [1.5.0] — 2026-09-13
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|||||||
+8
-6
@@ -249,8 +249,9 @@ cryptic names.
|
|||||||
gates, registries). investigate only on explicit ask for the gstack
|
gates, registries). investigate only on explicit ask for the gstack
|
||||||
ecosystem (cross-project learnings, /freeze, long open-ended investigation)
|
ecosystem (cross-project learnings, /freeze, long open-ended investigation)
|
||||||
- feat / hotfix / bugfix distinguished by file count → see descriptions
|
- feat / hotfix / bugfix distinguished by file count → see descriptions
|
||||||
- Ship / PR → ship (ship-feature if gstack off); deploy → deploy (runbook,
|
- Ship / PR → ship-feature (never gstack ship: it takes `origin/HEAD` =
|
||||||
the user runs it)
|
main as base and skips develop); deploy → deploy (runbook, the user
|
||||||
|
runs it)
|
||||||
- Docs post-ship → document-release (doc if gstack off); stale-doc audit → doc
|
- Docs post-ship → document-release (doc if gstack off); stale-doc audit → doc
|
||||||
- Grouped all-axes sweep ("tir groupé", fix + loop until clean) → tour
|
- Grouped all-axes sweep ("tir groupé", fix + loop until clean) → tour
|
||||||
- Open-work inventory / "queue empty?" / stale TODO vs git → reconcile
|
- Open-work inventory / "queue empty?" / stale TODO vs git → reconcile
|
||||||
@@ -259,8 +260,8 @@ cryptic names.
|
|||||||
- Before /clear or /compact → capitalize; end-of-session ritual → close
|
- Before /clear or /compact → capitalize; end-of-session ritual → close
|
||||||
- SEO+GEO → seo (GEO only → geo); W3C + WCAG a11y → web-validate;
|
- SEO+GEO → seo (GEO only → geo); W3C + WCAG a11y → web-validate;
|
||||||
security audit (secrets, CVE, OWASP) → cso
|
security audit (secrets, CVE, OWASP) → cso
|
||||||
gstack OFF → its skills (investigate, ship, qa, review, health, retro,
|
gstack OFF → its skills (investigate, qa, review, health, retro,
|
||||||
office-hours, context-save…) are gone: use the fallback above, else say so.
|
office-hours…) are gone: use the fallback above, else say so.
|
||||||
|
|
||||||
## Design work — full toolchain (tiered by scope)
|
## Design work — full toolchain (tiered by scope)
|
||||||
Trigger = UI work: editing a component/style file (.tsx/.vue/.svelte/.css…)
|
Trigger = UI work: editing a component/style file (.tsx/.vue/.svelte/.css…)
|
||||||
@@ -275,11 +276,12 @@ design routing; the design-toolchain hook reinforces it.
|
|||||||
<files>` (45 deterministic anti-slop rules, exit 2 = findings).
|
<files>` (45 deterministic anti-slop rules, exit 2 = findings).
|
||||||
- Design system / brand → design-consultation first, then the build tools.
|
- Design system / brand → design-consultation first, then the build tools.
|
||||||
- Review / audit → design-review + emil-design-eng + design-motion-principles
|
- Review / audit → design-review + emil-design-eng + design-motion-principles
|
||||||
+ 21st-ui-review + /impeccable audit|critique + `impeccable detect` floor.
|
+ /impeccable audit|critique + `impeccable detect` floor.
|
||||||
Scope doubt → ask or default to Build, never silently skip. Gate: light
|
Scope doubt → ask or default to Build, never silently skip. Gate: light
|
||||||
skills run `~/.claude/lib/design-gate.md`, orchestrators plugin-check. 21st =
|
skills run `~/.claude/lib/design-gate.md`, orchestrators plugin-check. 21st =
|
||||||
CLI (`npm i -g @21st-dev/cli`, `21st login`), no MCP, no key; search free,
|
CLI (`npm i -g @21st-dev/cli`, `21st login`), no MCP, no key; search free,
|
||||||
`21st get`/`generate` metered → generation, not micro-tweaks.
|
`21st get`/`generate` metered → generation, not micro-tweaks. 21st-ai /
|
||||||
|
ui-explore / ui-review are `max`-profile only.
|
||||||
|
|
||||||
## graphify
|
## graphify
|
||||||
|
|
||||||
|
|||||||
@@ -181,7 +181,7 @@ When the plugin-advisor detects a `simple` or `hotfix` signal, suggest the appro
|
|||||||
| ui-ux-pro-max ↔ gstack | ✅ Complementary | GStack = deploy/QA layer; ui-ux-pro-max = UI quality layer. Different concerns. |
|
| ui-ux-pro-max ↔ gstack | ✅ Complementary | GStack = deploy/QA layer; ui-ux-pro-max = UI quality layer. Different concerns. |
|
||||||
| pr-review-toolkit ↔ superpowers | ✅ Complementary | superpowers:requesting-code-review and /pr-review-toolkit:review-pr cover different review styles. |
|
| pr-review-toolkit ↔ superpowers | ✅ Complementary | superpowers:requesting-code-review and /pr-review-toolkit:review-pr cover different review styles. |
|
||||||
| rtk ↔ any | ✅ Independent | Hook-only token compression. Zero interaction with any plugin. |
|
| rtk ↔ any | ✅ Independent | Hook-only token compression. Zero interaction with any plugin. |
|
||||||
| security-guidance ↔ any | ✅ Independent | Hook-only security rules. Zero interaction. |
|
| security-guidance ↔ any | ✅ Independent | Hooks + out-of-band LLM reviews (agentic review on commit/push; Stop diff review disabled by ENABLE_STOP_REVIEW=0). No context injection unless a regex hits. |
|
||||||
|
|
||||||
### Recommended sets by project type
|
### Recommended sets by project type
|
||||||
|
|
||||||
@@ -197,7 +197,9 @@ When the plugin-advisor detects a `simple` or `hotfix` signal, suggest the appro
|
|||||||
| Fast-evolving libs (Next.js etc.) | superpowers, context7 | — | ~1000t |
|
| Fast-evolving libs (Next.js etc.) | superpowers, context7 | — | ~1000t |
|
||||||
| Enterprise multi-agent orchestration | superpowers + gsd v2 (external) | plugin-dev | ~800t CC |
|
| Enterprise multi-agent orchestration | superpowers + gsd v2 (external) | plugin-dev | ~800t CC |
|
||||||
|
|
||||||
> security-guidance and rtk are ALWAYS ON (0 tokens) — omitted from cost estimates for clarity.
|
> rtk is always on at 0 context tokens; security-guidance is always on and
|
||||||
|
> costs quota out of band (LLM reviews), not context — both omitted from
|
||||||
|
> the estimates
|
||||||
|
|
||||||
### Conditional rules
|
### Conditional rules
|
||||||
|
|
||||||
|
|||||||
+6
-3
@@ -5,6 +5,9 @@
|
|||||||
"pr": "",
|
"pr": "",
|
||||||
"sessionUrl": false
|
"sessionUrl": false
|
||||||
},
|
},
|
||||||
|
"env": {
|
||||||
|
"ENABLE_STOP_REVIEW": "0"
|
||||||
|
},
|
||||||
"permissions": {
|
"permissions": {
|
||||||
"allow": [
|
"allow": [
|
||||||
"Bash(git status)",
|
"Bash(git status)",
|
||||||
@@ -419,7 +422,7 @@
|
|||||||
"security-guidance@claude-code-plugins": true,
|
"security-guidance@claude-code-plugins": true,
|
||||||
"superpowers@superpowers-marketplace": true,
|
"superpowers@superpowers-marketplace": true,
|
||||||
"pr-review-toolkit@claude-code-plugins": false,
|
"pr-review-toolkit@claude-code-plugins": false,
|
||||||
"frontend-design@claude-plugins-official": true
|
"brightdata-plugin@synced": false
|
||||||
},
|
},
|
||||||
"extraKnownMarketplaces": {
|
"extraKnownMarketplaces": {
|
||||||
"claude-code-plugins": {
|
"claude-code-plugins": {
|
||||||
@@ -447,6 +450,7 @@
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"feedbackDrafts": "off",
|
||||||
"effortLevel": "xhigh",
|
"effortLevel": "xhigh",
|
||||||
"remoteControlAtStartup": true,
|
"remoteControlAtStartup": true,
|
||||||
"inputNeededNotifEnabled": true,
|
"inputNeededNotifEnabled": true,
|
||||||
@@ -499,6 +503,5 @@
|
|||||||
"**Sensitive remote targets**: any namespace, host, database or container whose name carries `prod` or `production` as a whole word or name segment.",
|
"**Sensitive remote targets**: any namespace, host, database or container whose name carries `prod` or `production` as a whole word or name segment.",
|
||||||
"**Sensitive data locations & audiences**: per-project `.env` files (gitignored) hold database, deploy and API credentials; some web projects store customer-submitted form data under a retention policy. Both are personal or client data — never send either to an external service."
|
"**Sensitive data locations & audiences**: per-project `.env` files (gitignored) hold database, deploy and API credentials; some web projects store customer-submitted form data under a retention policy. Both are personal or client data — never send either to an external service."
|
||||||
]
|
]
|
||||||
},
|
}
|
||||||
"feedbackDrafts": "off"
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -58,8 +58,7 @@ jq dependency.
|
|||||||
|-----------|-------|
|
|-----------|-------|
|
||||||
| Run this project's deploy runbook, delta-instantiated, learning | **this skill** |
|
| Run this project's deploy runbook, delta-instantiated, learning | **this skill** |
|
||||||
| Project has no `.claude/deploy/PROCEDURE.md` yet | this skill's **bootstrap** branch (see STEP 0) |
|
| Project has no `.claude/deploy/PROCEDURE.md` yet | this skill's **bootstrap** branch (see STEP 0) |
|
||||||
| Merge a branch + trigger CI deploy (gstack) | `/land-and-deploy` |
|
| Merge a finished branch | `gitflow finish` on an explicit human signal (skills/gitflow) |
|
||||||
| Configure deployment settings | `/setup-deploy` |
|
|
||||||
| Document a release after shipping | `/document-release`, `/doc` |
|
| Document a release after shipping | `/document-release`, `/doc` |
|
||||||
|
|
||||||
## Artifacts — `.claude/deploy/` (four files)
|
## Artifacts — `.claude/deploy/` (four files)
|
||||||
|
|||||||
Reference in New Issue
Block a user