chore(config): security-guidance Stop review off, plugins off, routing and docs
settings.json: ENABLE_STOP_REVIEW=0 (the plugin's own switch: no more Opus call on every turn that changes code, 0 findings in 6 days, 1 recorded false positive; the regex layer and the commit/push agentic review stay on), brightdata-plugin@synced false (keyless-useless, its MCP skill would hijack WebFetch/WebSearch), frontend-design official plugin entry gone (uninstalled: byte-identical to the managed copy). CLAUDE.global.md routes Ship/PR to ship-feature (gstack ship takes origin/HEAD = main as base), drops ship/context-save from the gstack-off list and 21st-ui-review from the design review line (trio is max-only). deploy's table no longer points at land-and-deploy/setup-deploy. plugin-advisor.md describes security-guidance's real mechanics. CHANGELOG Unreleased entry with a Known residual section.
This commit is contained in:
@@ -201,6 +201,21 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
||||
seeded like a real tree (gstack off, nothing linked).
|
||||
|
||||
### Changed
|
||||
- **`full` = everything the other profiles carry** (user rule: full does
|
||||
what every specialized profile does), minus the 9 removed gstack
|
||||
skills, the 21st generation/review trio and one named exception
|
||||
(`pr-review-toolkit`, deliberately out of full since audit 2026-07-02
|
||||
#12). New `max` profile (`# SUPERSET-OF: full` marker) is `full` plus
|
||||
the parked tools (`make-pdf`, `diagram`, `21st-ai`, `21st-ui-explore`,
|
||||
`21st-ui-review`) plus `pr-review-toolkit` — switch here when one of
|
||||
them is needed. The 21st generation/review trio leaves `full`, `web`,
|
||||
`web-full` and `design`; `CLAUDE.global.md`'s Design work line drops
|
||||
`21st-ui-review` and notes the trio is `max`-profile only.
|
||||
`security-guidance`'s Stop-hook LLM review is off
|
||||
(`ENABLE_STOP_REVIEW=0` in `settings.json`'s `env`, the plugin's own
|
||||
switch); its regex layer and the commit/push agentic review stay on.
|
||||
`doctor.sh`'s skill-catalog token constants are recomputed from a real
|
||||
count instead of a stale estimate.
|
||||
- **CLAUDE.global.md § Code style** — the ordered YAGNI decision ladder
|
||||
(not needed → reuse → stdlib → platform → installed dependency → one line
|
||||
→ the minimum that works, after understanding the problem) and a
|
||||
@@ -381,6 +396,19 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
||||
traced by reading, never by running, whatever the brief says.
|
||||
|
||||
### Removed
|
||||
- **Skill-catalog prune**: `brightdata-plugin@synced` disabled
|
||||
(account-synced, keyless-useless, its `bright-data-mcp` skill would
|
||||
hijack WebFetch/WebSearch), `frontend-design@claude-plugins-official`
|
||||
uninstalled (byte-identical duplicate of the managed `skills-external`
|
||||
copy). The 9 broken or doctrine-breaking gstack skills — `ship`,
|
||||
`land-and-deploy`, `setup-deploy`, `autoplan`, `context-save`, `learn`,
|
||||
`careful`, `guard`, `design-shotgun` — are out of every profile that
|
||||
listed them (`dev`, `backend`, `web`, `web-full`, `design`, `full`),
|
||||
each with its reason in the new `lib/gstack-removed.sh` (exit-127 hooks,
|
||||
an absent `OPENAI_API_KEY`, `ship`/`land-and-deploy` skipping develop,
|
||||
`context-save` with no restore). The new `GSTACK_REMOVED` denylist is
|
||||
honored by `profile.sh gstack on` and `toggle-external.sh enable
|
||||
gstack`: both now skip a removed name instead of silently restoring it.
|
||||
- `deploy` `push_deploy_tags` knob (the STATE.json commit's hook pushes the tag
|
||||
with `--follow-tags`); `/onboard add gsd` and `/onboard continue` mentions
|
||||
(never had a handler).
|
||||
@@ -393,6 +421,24 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
||||
and the dead `MAGIC_API_KEY=abc123` gitleaks allowlist regex.
|
||||
|
||||
### Fixed
|
||||
- **gstack's shared helper tree was mostly unreachable.** gstack skills
|
||||
hardcode `~/.claude/skills/gstack/<path>` for shared assets, but
|
||||
`link.sh` and `install-plugins.sh` only ever linked `bin` and
|
||||
`browse/dist`. A shared `lib/gstack-links.sh` (used by `link.sh`,
|
||||
`install-plugins.sh` and `update-all.sh`) now links every non-skill
|
||||
child of the gstack submodule, so `make-pdf`, `diagram`, the `freeze`
|
||||
hook, the `*/sections/*.md` files, `scripts/jargon-list.json` and
|
||||
`ETHOS.md` resolve; `/unfreeze` now actually clears
|
||||
`~/.gstack/freeze-dir.txt`. `doctor.sh` counted skills with `find
|
||||
-maxdepth 2` (no `-L`, missed symlinked skills) and truncated
|
||||
block-scalar (`|`/`>`) descriptions to 0 chars; it now reuses
|
||||
`lib/skill-routing-census.py`'s description parser through
|
||||
`lib/doctor-skills.sh`. Dropped the stale "security-guidance … 0
|
||||
tokens" claim from `install-plugins.sh` and `agents/plugin-advisor.md`:
|
||||
the Stop review costs out-of-band quota, not context.
|
||||
`CLAUDE.global.md`'s Ship/PR routing pointed at gstack's `ship`, which
|
||||
bases off `origin/HEAD` (= main) and skips develop; it now routes
|
||||
straight to `ship-feature`.
|
||||
- **`gitflow init` on an existing repo under the machine-wide hooks** — the
|
||||
socle commit (`.gitignore` + `.githooks/`) landed directly on `main`
|
||||
"while the hook is inactive"; since the global `core.hooksPath` the
|
||||
@@ -438,6 +484,14 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
||||
pin rerun (no false warning), parked copy plus rotted pin (fallback, then
|
||||
returned to `skills-disabled/`).
|
||||
|
||||
### Known residual
|
||||
- The kept gstack skills still carry upstream prose routing to `/ship`,
|
||||
`/land-and-deploy`, `/context-save`, `/autoplan` and `/design-shotgun`
|
||||
(their own text, machine-owned submodule files, not ours to patch);
|
||||
`21st-ui-build` and `21st-cli-use` still point at the now-`max`-only
|
||||
21st trio. A Skill call on a parked name fails, and the doctrine
|
||||
routing in `CLAUDE.global.md` applies instead.
|
||||
|
||||
## [1.5.0] — 2026-09-13
|
||||
|
||||
### Added
|
||||
|
||||
+8
-6
@@ -249,8 +249,9 @@ cryptic names.
|
||||
gates, registries). investigate only on explicit ask for the gstack
|
||||
ecosystem (cross-project learnings, /freeze, long open-ended investigation)
|
||||
- feat / hotfix / bugfix distinguished by file count → see descriptions
|
||||
- Ship / PR → ship (ship-feature if gstack off); deploy → deploy (runbook,
|
||||
the user runs it)
|
||||
- Ship / PR → ship-feature (never gstack ship: it takes `origin/HEAD` =
|
||||
main as base and skips develop); deploy → deploy (runbook, the user
|
||||
runs it)
|
||||
- Docs post-ship → document-release (doc if gstack off); stale-doc audit → doc
|
||||
- Grouped all-axes sweep ("tir groupé", fix + loop until clean) → tour
|
||||
- Open-work inventory / "queue empty?" / stale TODO vs git → reconcile
|
||||
@@ -259,8 +260,8 @@ cryptic names.
|
||||
- Before /clear or /compact → capitalize; end-of-session ritual → close
|
||||
- SEO+GEO → seo (GEO only → geo); W3C + WCAG a11y → web-validate;
|
||||
security audit (secrets, CVE, OWASP) → cso
|
||||
gstack OFF → its skills (investigate, ship, qa, review, health, retro,
|
||||
office-hours, context-save…) are gone: use the fallback above, else say so.
|
||||
gstack OFF → its skills (investigate, qa, review, health, retro,
|
||||
office-hours…) are gone: use the fallback above, else say so.
|
||||
|
||||
## Design work — full toolchain (tiered by scope)
|
||||
Trigger = UI work: editing a component/style file (.tsx/.vue/.svelte/.css…)
|
||||
@@ -275,11 +276,12 @@ design routing; the design-toolchain hook reinforces it.
|
||||
<files>` (45 deterministic anti-slop rules, exit 2 = findings).
|
||||
- Design system / brand → design-consultation first, then the build tools.
|
||||
- Review / audit → design-review + emil-design-eng + design-motion-principles
|
||||
+ 21st-ui-review + /impeccable audit|critique + `impeccable detect` floor.
|
||||
+ /impeccable audit|critique + `impeccable detect` floor.
|
||||
Scope doubt → ask or default to Build, never silently skip. Gate: light
|
||||
skills run `~/.claude/lib/design-gate.md`, orchestrators plugin-check. 21st =
|
||||
CLI (`npm i -g @21st-dev/cli`, `21st login`), no MCP, no key; search free,
|
||||
`21st get`/`generate` metered → generation, not micro-tweaks.
|
||||
`21st get`/`generate` metered → generation, not micro-tweaks. 21st-ai /
|
||||
ui-explore / ui-review are `max`-profile only.
|
||||
|
||||
## graphify
|
||||
|
||||
|
||||
@@ -181,7 +181,7 @@ When the plugin-advisor detects a `simple` or `hotfix` signal, suggest the appro
|
||||
| ui-ux-pro-max ↔ gstack | ✅ Complementary | GStack = deploy/QA layer; ui-ux-pro-max = UI quality layer. Different concerns. |
|
||||
| pr-review-toolkit ↔ superpowers | ✅ Complementary | superpowers:requesting-code-review and /pr-review-toolkit:review-pr cover different review styles. |
|
||||
| rtk ↔ any | ✅ Independent | Hook-only token compression. Zero interaction with any plugin. |
|
||||
| security-guidance ↔ any | ✅ Independent | Hook-only security rules. Zero interaction. |
|
||||
| security-guidance ↔ any | ✅ Independent | Hooks + out-of-band LLM reviews (agentic review on commit/push; Stop diff review disabled by ENABLE_STOP_REVIEW=0). No context injection unless a regex hits. |
|
||||
|
||||
### Recommended sets by project type
|
||||
|
||||
@@ -197,7 +197,9 @@ When the plugin-advisor detects a `simple` or `hotfix` signal, suggest the appro
|
||||
| Fast-evolving libs (Next.js etc.) | superpowers, context7 | — | ~1000t |
|
||||
| Enterprise multi-agent orchestration | superpowers + gsd v2 (external) | plugin-dev | ~800t CC |
|
||||
|
||||
> security-guidance and rtk are ALWAYS ON (0 tokens) — omitted from cost estimates for clarity.
|
||||
> rtk is always on at 0 context tokens; security-guidance is always on and
|
||||
> costs quota out of band (LLM reviews), not context — both omitted from
|
||||
> the estimates
|
||||
|
||||
### Conditional rules
|
||||
|
||||
|
||||
+6
-3
@@ -5,6 +5,9 @@
|
||||
"pr": "",
|
||||
"sessionUrl": false
|
||||
},
|
||||
"env": {
|
||||
"ENABLE_STOP_REVIEW": "0"
|
||||
},
|
||||
"permissions": {
|
||||
"allow": [
|
||||
"Bash(git status)",
|
||||
@@ -419,7 +422,7 @@
|
||||
"security-guidance@claude-code-plugins": true,
|
||||
"superpowers@superpowers-marketplace": true,
|
||||
"pr-review-toolkit@claude-code-plugins": false,
|
||||
"frontend-design@claude-plugins-official": true
|
||||
"brightdata-plugin@synced": false
|
||||
},
|
||||
"extraKnownMarketplaces": {
|
||||
"claude-code-plugins": {
|
||||
@@ -447,6 +450,7 @@
|
||||
}
|
||||
}
|
||||
},
|
||||
"feedbackDrafts": "off",
|
||||
"effortLevel": "xhigh",
|
||||
"remoteControlAtStartup": true,
|
||||
"inputNeededNotifEnabled": true,
|
||||
@@ -499,6 +503,5 @@
|
||||
"**Sensitive remote targets**: any namespace, host, database or container whose name carries `prod` or `production` as a whole word or name segment.",
|
||||
"**Sensitive data locations & audiences**: per-project `.env` files (gitignored) hold database, deploy and API credentials; some web projects store customer-submitted form data under a retention policy. Both are personal or client data — never send either to an external service."
|
||||
]
|
||||
},
|
||||
"feedbackDrafts": "off"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -58,8 +58,7 @@ jq dependency.
|
||||
|-----------|-------|
|
||||
| Run this project's deploy runbook, delta-instantiated, learning | **this skill** |
|
||||
| Project has no `.claude/deploy/PROCEDURE.md` yet | this skill's **bootstrap** branch (see STEP 0) |
|
||||
| Merge a branch + trigger CI deploy (gstack) | `/land-and-deploy` |
|
||||
| Configure deployment settings | `/setup-deploy` |
|
||||
| Merge a finished branch | `gitflow finish` on an explicit human signal (skills/gitflow) |
|
||||
| Document a release after shipping | `/document-release`, `/doc` |
|
||||
|
||||
## Artifacts — `.claude/deploy/` (four files)
|
||||
|
||||
Reference in New Issue
Block a user