fix(impeccable): global-scope install with agents, pin fallback, output-read failure check

make plugin never installed impeccable. The 3.2.0 pin had rotted upstream
(the CLI fetches its skill dist at install time; that release's zip is
gone), the --scope=project staging moved the skill dir alone and dropped
the 4 impeccable-* subagents, and /impeccable init was never announced.

Step 8d now installs at --scope=global straight through the
~/.claude/{skills,agents} symlinks into the repo (both paths gitignored),
guards on those symlinks existing, keeps a profile-parked copy parked,
falls back to @latest on a pin failure with a bump-the-lock warning, and
prints the per-project init hint. update-all.sh mirrors the shape.

Found while probing: with a copy already installed a rotted pin exits 0
("Could not check for skill updates ... left unchanged"), byte-identical
on disk to an up-to-date rerun, so imp_install reads the installer output
instead of trusting the exit code. Harness 4/4 in a sandbox HOME with the
real installer.

plugins.lock.json: impeccable 3.2.0 -> 4.1.0 (CLI only). link.sh drops
impeccable from EXTERNAL_SKILLS. lib/design-gate.md section 5: suggest-only
/impeccable init check when a frontend project has no PRODUCT.md.
This commit is contained in:
bastien
2026-09-22 03:20:25 +00:00
parent 7c05f75eab
commit cc2f246e65
7 changed files with 221 additions and 61 deletions
+37
View File
@@ -44,6 +44,12 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
`profile set|upload`) — publishing puts a component on a public listing.
That tier rather than `ask`, per LRN-153.
- `lib/design-gate.md` §5: a suggest-only check, same shape as the §4
animation-library one. When impeccable is active and the frontend project
has no `PRODUCT.md` at its root, the gate proposes `/impeccable init` once
and never runs it itself (it interviews the user). Skipped for single
component reviews and non-UI work.
### Changed
- **Design gate: `magic` → the `21st` CLI in the required-manual slot.**
`design.profile`'s `GATE-BLOCK` now lists `21st` (CLI channel) and
@@ -119,6 +125,23 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
`bypassPermissions`). Adding a restriction stays allowed; removing one
does not. No instruction clears these.
- **impeccable installs at `--scope=global`, subagents included, and the
pin fails safe.** `install-plugins.sh` Step 8d no longer stages a
`--scope=project` install in a tmpdir and moves the skill directory alone.
The installer writes through the `~/.claude/skills` and `~/.claude/agents`
symlinks straight into the repo: `skills/impeccable` plus the four
`agents/impeccable-*.md`, both gitignored and machine-owned, which is what
the manual `--scope=global` command already did. The step refuses to run
before `make link` has created those symlinks (an install before them
materializes real directories that `link.sh` then refuses to replace),
keeps a profile-parked copy parked, reports the skill version and agent
count, and prints the per-project `/impeccable init` hint. A pinned
install that fails falls back to `impeccable@latest` with a warning to
bump `plugins.lock.json`. `update-all.sh` follows the same shape.
`plugins.lock.json` pin 3.2.0 → 4.1.0 (the CLI only: the skill dist and
the engine binary have their own release tracks). `link.sh` drops
impeccable from `EXTERNAL_SKILLS`; `skills-external/impeccable/` is gone.
### Security
- **Ten secret-reader deny rules added**: `sed`, `awk`, `cut`, `tr`,
`sort`, `uniq`, `diff`, `od`, `xxd`, `strings` against `.env*`. Six of
@@ -160,6 +183,20 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
holds under `defaultMode: default`, not under this config's `auto`. The
paragraph now separates what is verified from what is not, and names
`deny` as the only tier the classifier cannot lift.
- **`make plugin` never installed impeccable.** Three defects. The 3.2.0
pin had rotted upstream: the CLI fetches its skill dist at install time and
that release's artifact is gone (`Download failed: invalid zip data`),
which the step reported as "run it yourself" on every run. The
project-scope staging dropped the four subagents the same install writes.
And `/impeccable init` was never announced. A fourth, found while probing
the fix: once a copy is already installed, a rotted pin exits 0
(`Could not check for skill updates … Existing skills were left
unchanged`), byte-identical on disk to a genuine "Skills are up to date"
rerun, so `imp_install` now reads the installer output instead of trusting
the exit code or a version compare. Verified with the real installer in a
sandbox HOME: fresh install, rotted pin over a copy (fallback fires), same
pin rerun (no false warning), parked copy plus rotted pin (fallback, then
returned to `skills-disabled/`).
## [1.5.0] — 2026-09-13