feat(install): wire impeccable into the toolchain — deterministic design floor + /impeccable verbs
Complementary to frontend-design (kept: build-time aesthetic direction). impeccable adds what the chain lacked: 45 deterministic anti-slop rules (npx impeccable detect, exit 0/2, --json) — the design counterpart of the semgrep gate — plus 23 design verbs under one /impeccable skill and persistent per-project design context. - plugins.lock.json: CLI pinned 3.2.0 (rules update = audit output change on unchanged code, LRN-077 class); skill dist = its own release track - install-plugins.sh Step 8d: staged npx install (tmpdir) -> moved to skills-external/impeccable (machine-owned, gitignored, ctx7 pattern); never writes through the ~/.claude/skills symlink into the tracked tree - update-all.sh: pin-honored refresh, Node<24 or failure -> dist kept - Node >= 24 required (host at 22): steps skip gracefully, activation deferred to a deliberate Node bump - link.sh EXTERNAL_SKILLS, profiles (design/web/web-full/full), plugin-advisor, CLAUDE.md design routing, design-gate, README, CHANGELOG - NOT in design GATE-BLOCK yet: promotion after first dogfood
This commit is contained in:
@@ -7,6 +7,7 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
||||
## [Unreleased]
|
||||
|
||||
### Added
|
||||
- **impeccable** (pbakaus, Apache-2.0) wired into the toolchain as the design counterpart of semgrep: the `/impeccable` skill (23 verbs under one command: audit, polish, bolder, quieter…) plus the 45-rule deterministic anti-pattern detector (`npx impeccable detect`, exit 0/2, `--json`). Complementary to `frontend-design` (kept — aesthetic direction at build time); impeccable adds the deterministic audit floor and per-project design context (`/impeccable init`). CLI pinned in `plugins.lock.json` (3.2.0 — a silent rules update would change audit output on unchanged code); dist is machine-owned under `skills-external/impeccable/` (gitignored, ctx7 pattern), staged-installed by `install-plugins.sh` Step 8d, refreshed pin-honored by `update-all.sh`, symlinked by `link.sh`, listed in the design/web/web-full/full profiles and the design-work routing. Requires Node ≥ 24 — the install/update steps skip gracefully below that (this host runs 22: bump Node to activate). Not in the design gate's GATE-BLOCK list yet — promotion deliberate, after first dogfood.
|
||||
- `/tour` skill — grouped all-axes sweep over one or several projects: security (pinned-semgrep `security-auditor` agent + `/cso` posture when gstack is ON) → cleanup → re-verify → reconcile (report-only, never edits the target TODO/registries) → doc sync, looping until a full pass applies zero fixes (bounded at 3 iterations). Fixes land on a `chore/tour-<date>` branch the skill never merges; each project gets an append-only `.claude/audits/TOUR.md` report with BREAKING tags on contract-changing security fixes. Built TDD (superpowers:writing-skills): baseline run showed silent TODO rewrites, autonomous registry writes, grep-as-security-pass, no persistent report, scope creep and an unbounded loop — each countered and verified on a seeded fixture.
|
||||
|
||||
### Fixed
|
||||
|
||||
Reference in New Issue
Block a user