chore(config): security-guidance Stop review off, plugins off, routing and docs

settings.json: ENABLE_STOP_REVIEW=0 (the plugin's own switch: no more
Opus call on every turn that changes code, 0 findings in 6 days, 1
recorded false positive; the regex layer and the commit/push agentic
review stay on), brightdata-plugin@synced false (keyless-useless, its MCP
skill would hijack WebFetch/WebSearch), frontend-design official plugin
entry gone (uninstalled: byte-identical to the managed copy).

CLAUDE.global.md routes Ship/PR to ship-feature (gstack ship takes
origin/HEAD = main as base), drops ship/context-save from the gstack-off
list and 21st-ui-review from the design review line (trio is max-only).
deploy's table no longer points at land-and-deploy/setup-deploy.
plugin-advisor.md describes security-guidance's real mechanics. CHANGELOG
Unreleased entry with a Known residual section.
This commit is contained in:
bastien
2026-09-28 11:49:01 +02:00
parent 02b62f787e
commit 4c86d6dc70
5 changed files with 73 additions and 13 deletions
+4 -2
View File
@@ -181,7 +181,7 @@ When the plugin-advisor detects a `simple` or `hotfix` signal, suggest the appro
| ui-ux-pro-max ↔ gstack | ✅ Complementary | GStack = deploy/QA layer; ui-ux-pro-max = UI quality layer. Different concerns. |
| pr-review-toolkit ↔ superpowers | ✅ Complementary | superpowers:requesting-code-review and /pr-review-toolkit:review-pr cover different review styles. |
| rtk ↔ any | ✅ Independent | Hook-only token compression. Zero interaction with any plugin. |
| security-guidance ↔ any | ✅ Independent | Hook-only security rules. Zero interaction. |
| security-guidance ↔ any | ✅ Independent | Hooks + out-of-band LLM reviews (agentic review on commit/push; Stop diff review disabled by ENABLE_STOP_REVIEW=0). No context injection unless a regex hits. |
### Recommended sets by project type
@@ -197,7 +197,9 @@ When the plugin-advisor detects a `simple` or `hotfix` signal, suggest the appro
| Fast-evolving libs (Next.js etc.) | superpowers, context7 | — | ~1000t |
| Enterprise multi-agent orchestration | superpowers + gsd v2 (external) | plugin-dev | ~800t CC |
> security-guidance and rtk are ALWAYS ON (0 tokens) — omitted from cost estimates for clarity.
> rtk is always on at 0 context tokens; security-guidance is always on and
> costs quota out of band (LLM reviews), not context — both omitted from
> the estimates
### Conditional rules