chore(config): security-guidance Stop review off, plugins off, routing and docs

settings.json: ENABLE_STOP_REVIEW=0 (the plugin's own switch: no more
Opus call on every turn that changes code, 0 findings in 6 days, 1
recorded false positive; the regex layer and the commit/push agentic
review stay on), brightdata-plugin@synced false (keyless-useless, its MCP
skill would hijack WebFetch/WebSearch), frontend-design official plugin
entry gone (uninstalled: byte-identical to the managed copy).

CLAUDE.global.md routes Ship/PR to ship-feature (gstack ship takes
origin/HEAD = main as base), drops ship/context-save from the gstack-off
list and 21st-ui-review from the design review line (trio is max-only).
deploy's table no longer points at land-and-deploy/setup-deploy.
plugin-advisor.md describes security-guidance's real mechanics. CHANGELOG
Unreleased entry with a Known residual section.
This commit is contained in:
bastien
2026-09-28 11:49:01 +02:00
parent 02b62f787e
commit 4c86d6dc70
5 changed files with 73 additions and 13 deletions
+8 -6
View File
@@ -249,8 +249,9 @@ cryptic names.
gates, registries). investigate only on explicit ask for the gstack
ecosystem (cross-project learnings, /freeze, long open-ended investigation)
- feat / hotfix / bugfix distinguished by file count → see descriptions
- Ship / PR → ship (ship-feature if gstack off); deploy → deploy (runbook,
the user runs it)
- Ship / PR → ship-feature (never gstack ship: it takes `origin/HEAD` =
main as base and skips develop); deploy → deploy (runbook, the user
runs it)
- Docs post-ship → document-release (doc if gstack off); stale-doc audit → doc
- Grouped all-axes sweep ("tir groupé", fix + loop until clean) → tour
- Open-work inventory / "queue empty?" / stale TODO vs git → reconcile
@@ -259,8 +260,8 @@ cryptic names.
- Before /clear or /compact → capitalize; end-of-session ritual → close
- SEO+GEO → seo (GEO only → geo); W3C + WCAG a11y → web-validate;
security audit (secrets, CVE, OWASP) → cso
gstack OFF → its skills (investigate, ship, qa, review, health, retro,
office-hours, context-save…) are gone: use the fallback above, else say so.
gstack OFF → its skills (investigate, qa, review, health, retro,
office-hours…) are gone: use the fallback above, else say so.
## Design work — full toolchain (tiered by scope)
Trigger = UI work: editing a component/style file (.tsx/.vue/.svelte/.css…)
@@ -275,11 +276,12 @@ design routing; the design-toolchain hook reinforces it.
<files>` (45 deterministic anti-slop rules, exit 2 = findings).
- Design system / brand → design-consultation first, then the build tools.
- Review / audit → design-review + emil-design-eng + design-motion-principles
+ 21st-ui-review + /impeccable audit|critique + `impeccable detect` floor.
+ /impeccable audit|critique + `impeccable detect` floor.
Scope doubt → ask or default to Build, never silently skip. Gate: light
skills run `~/.claude/lib/design-gate.md`, orchestrators plugin-check. 21st =
CLI (`npm i -g @21st-dev/cli`, `21st login`), no MCP, no key; search free,
`21st get`/`generate` metered → generation, not micro-tweaks.
`21st get`/`generate` metered → generation, not micro-tweaks. 21st-ai /
ui-explore / ui-review are `max`-profile only.
## graphify