Merge feature/audit-hardening into develop

This commit is contained in:
Bastien Chanot
2026-07-02 14:35:56 +02:00
9 changed files with 128 additions and 900 deletions
+7 -4
View File
@@ -24,10 +24,13 @@ prompt="$(printf '%s' "$input" \
lc="$(printf '%s' "$prompt" | tr '[:upper:]' '[:lower:]')"
# UI/design build and review signals (FR + EN). Word boundaries (\b) avoid
# substring false matches like perform/platform/information. Some broad tokens
# (page, color, screen, card, menu) are kept deliberately for coverage — they
# over-fire on non-UI prompts, which is harmless: the reminder self-cancels.
pattern='design|redesign|refonte|refont|ui/ux|ux/ui|\bui\b|\bux\b|ui kit|design system|design-system|interface|frontend|front-end|front end|composant|component|\bnavbar\b|\bsidebar\b|\bmodal\b|\bbouton\b|\bbutton\b|\bcard\b|\bcarte\b|\bform\b|formulaire|\bhero\b|\bheader\b|\bfooter\b|\bmenu\b|dropdown|tooltip|\bbadge\b|\bchart\b|graphique|accordion|carousel|\bslider\b|landing|dashboard|homepage|home page|\baccueil\b|\bpage\b|\bpages\b|\bécran\b|\becran\b|\bscreen\b|portfolio|maquette|mockup|wireframe|prototype|\blook\b|\bjoli\b|\bjolie\b|\bbeau\b|\bbelle\b|esth[eé]tique|aesthetic|\bvisuel\b|\bvisual\b|embellir|fignol|peaufin|polish|styliser|\bstyle\b|styling|stylesheet|\bskin\b|charte graphique|\bbrand\b|branding|\blogo\b|favicon|ic[oô]ne|\bicon\b|\bcss\b|tailwind|shadcn|couleur|\bcolor\b|palette|gradient|d[eé]grad[eé]|\bshadow\b|\bombre\b|spacing|espacement|\bmarge\b|\bpadding\b|\bmargin\b|\bradius\b|arrondi|\bhover\b|dark mode|light mode|\btheme\b|th[eè]me|typograph|\bfont\b|\bfonts\b|font pairing|\bpolice\b|animation|\bmotion\b|transition|micro-interaction|keyframe|glassmorph|neumorph|claymorph|skeuomorph|brutalis|bento|minimalis|responsive|figma'
# substring false matches like perform/platform/information. Tightened
# 2026-07-02: ultra-generic English tokens (page, form, menu, card, style,
# look, screen, interface, color) fired on a large share of NON-UI prompts —
# ~200 tokens of reminder each time (measured: 6 fires during a pure config
# audit). Kept: unambiguous design vocabulary + FR aesthetic words; specific
# compounds (stylesheet, styling, formulaire, écran) still match.
pattern='design|redesign|refonte|refont|ui/ux|ux/ui|\bui\b|\bux\b|ui kit|design system|design-system|frontend|front-end|front end|composant|component|\bnavbar\b|\bsidebar\b|\bmodal\b|\bbouton\b|\bbutton\b|formulaire|\bhero\b|\bheader\b|\bfooter\b|dropdown|tooltip|\bbadge\b|\bchart\b|graphique|accordion|carousel|\bslider\b|landing|dashboard|homepage|home page|\baccueil\b|\bécran\b|\becran\b|portfolio|maquette|mockup|wireframe|prototype|\bjoli\b|\bjolie\b|\bbeau\b|\bbelle\b|esth[eé]tique|aesthetic|\bvisuel\b|\bvisual\b|embellir|fignol|peaufin|polish|styliser|styling|stylesheet|\bskin\b|charte graphique|\bbrand\b|branding|\blogo\b|favicon|ic[oô]ne|\bicon\b|\bcss\b|tailwind|shadcn|couleur|palette|gradient|d[eé]grad[eé]|\bombre\b|spacing|espacement|\bmarge\b|\bpadding\b|\bmargin\b|\bradius\b|arrondi|\bhover\b|dark mode|light mode|\btheme\b|th[eè]me|typograph|\bfont\b|\bfonts\b|font pairing|\bpolice\b|animation|\bmotion\b|transition|micro-interaction|keyframe|glassmorph|neumorph|claymorph|skeuomorph|brutalis|bento|minimalis|responsive|figma'
if printf '%s' "$lc" | grep -Eq "$pattern"; then
cat <<'EOF'
+30 -11
View File
@@ -49,10 +49,12 @@ TOGGLE_ACTIVE=()
TOGGLE_INACTIVE=()
for plugin in gstack uiux_pro_max plugin_dev context7 graphifyy; do
# Map function name to display name
# Map function name to display name. graphifyy = the pipx PACKAGE name
# (pypi:graphifyy); the CLI and skill are 'graphify' — display that.
case "$plugin" in
uiux_pro_max) display="ui-ux-pro-max" ;;
plugin_dev) display="plugin-dev" ;;
graphifyy) display="graphify" ;;
*) display="$plugin" ;;
esac
@@ -105,7 +107,7 @@ declare -A _plugin_costs=(
[ui-ux-pro-max]=400
[plugin-dev]=100
[context7]=200
[graphifyy]=300
[graphify]=300
)
for _p in "${TOGGLE_ACTIVE[@]}"; do
_cost="${_plugin_costs[$_p]:-0}"
@@ -129,20 +131,37 @@ echo "┌─ Claude Code config ────────────────
# the user sees the real picture instead of a misleading literal.
ALWAYS_ON=()
detect_rtk &>/dev/null && ALWAYS_ON+=("rtk")
plugin_enabled "security-guidance@claude-code-plugins" && ALWAYS_ON+=("security-guidance")
plugin_enabled "superpowers@superpowers-marketplace" && ALWAYS_ON+=("superpowers")
# Derive the plugin list from settings.json:enabledPlugins (true entries)
# instead of a hardcoded name pair — a hardcoded SET under-reports newly
# enabled plugins (pr-review-toolkit was enabled yet invisible). LRN-005
# class. Plugins owned by the toggle row below are excluded (dual display).
_toggle_owned=" gstack ui-ux-pro-max plugin-dev context7 graphify "
while IFS= read -r _pl; do
case "$_toggle_owned" in
*" $_pl "*) : ;;
*) ALWAYS_ON+=("$_pl") ;;
esac
done < <(grep -oE '"[A-Za-z0-9_-]+@[A-Za-z0-9_-]+"[[:space:]]*:[[:space:]]*true' "$HOME/.claude/settings.json" 2>/dev/null \
| sed -E 's/^"([^@]+)@.*$/\1/')
unset _toggle_owned _pl
ALWAYS_ON_STR="${ALWAYS_ON[*]:-none}"
# Same 40-char-width split policy as the toggle row below — keeps the
# right border aligned when 4 always-on plugins overflow the field.
# right border aligned on overflow. Greedy width-fill (not a fixed 3-name
# cut: 3 long names overflowed line 1 and left line 2 empty).
if [ "${#ALWAYS_ON_STR}" -le 40 ]; then
printf "│ ✅ ON : %-40s│\n" "$ALWAYS_ON_STR"
else
_ao_line1="${ALWAYS_ON[0]} ${ALWAYS_ON[1]} ${ALWAYS_ON[2]:-}"
_ao_rest=("${ALWAYS_ON[@]:3}")
_ao_line2="${_ao_rest[*]}"
printf "│ ✅ ON : %-40s│\n" "$_ao_line1"
printf "│ %-40s│\n" "$_ao_line2"
unset _ao_line1 _ao_line2 _ao_rest
_ao_l1=""; _ao_l2=""
for _ao_e in "${ALWAYS_ON[@]}"; do
if [ -z "$_ao_l2" ] && [ $(( ${#_ao_l1} + ${#_ao_e} + 1 )) -le 40 ]; then
_ao_l1="${_ao_l1:+$_ao_l1 }$_ao_e"
else
_ao_l2="${_ao_l2:+$_ao_l2 }$_ao_e"
fi
done
printf "│ ✅ ON : %-40s│\n" "$_ao_l1"
printf "│ %-40s│\n" "$_ao_l2"
unset _ao_l1 _ao_l2 _ao_e
fi
unset ALWAYS_ON ALWAYS_ON_STR
# Plugin display — all plugins shown, split across 2 lines if >4