From 28646350871f4ff15f07f0d103c547e04d6173d1 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 15 Jul 2026 00:08:12 +0200 Subject: [PATCH 01/28] =?UTF-8?q?docs(spec):=20model=20routing=20=E2=80=94?= =?UTF-8?q?=20reflection=20inline=20/=20execution=20sonnet=20(design)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../specs/2026-07-15-model-routing-design.md | 143 ++++++++++++++++++ 1 file changed, 143 insertions(+) create mode 100644 docs/superpowers/specs/2026-07-15-model-routing-design.md diff --git a/docs/superpowers/specs/2026-07-15-model-routing-design.md b/docs/superpowers/specs/2026-07-15-model-routing-design.md new file mode 100644 index 0000000..e1b1419 --- /dev/null +++ b/docs/superpowers/specs/2026-07-15-model-routing-design.md @@ -0,0 +1,143 @@ +# Model routing — reflection inline (big model) / execution pinned (Sonnet) — design + +**Date**: 2026-07-15 · **Status**: approved (user, 2026-07-15) · **Branch**: `feature/model-routing` +**Lifecycle**: transient planning artifact (BDR-065) — committed during the run, deleted post-merge. + +## Principle + +The session model is assumed to be a big reasoning model (Fable 5, or Opus when +Fable is unavailable). Everything that **thinks** — brainstorming, planning, +technical decisions, audits, loop decisions — runs INLINE in the main +conversation, or in subagents that inherit the session model. Everything that +**executes** a ready-made plan — writing code, applying fix bundles, commits, +deliverable rendering — runs on Sonnet-pinned subagents. A blocking gate +enforces the "session = big model" assumption at the entry of every reflection +orchestrator. + +User verdicts baked in (2026-07-14/15): +- Scope = hybrid: ship-feature/init-project execution → sonnet; `/feat` + re-architected (plan inline → dispatch executor); bugfix/hotfix stay fully + inline (BDR-050 conserved for them). +- Gate = BLOCKING, not advisory. +- Audit agents inherit the session model (no opus pin); the gate extends to + audit orchestrators. +- verifier + security-auditor KEEP `model: sonnet` (job9 decision confirmed). +- client-handover-writer → sonnet (requires converting its inline-load to a + true dispatch; human gates relocate to the main loop). + +## 1. Blocking model gate + +New `lib/model-check.sh`: resolves the current session model from +`settings.json` (physical path resolution — LRN-023 class), normalizes +(`claude-fable-5[1m]` → fable, `claude-opus-*` → opus, sonnet, haiku), prints +`big|small|unknown`. Exit 0 = big, 2 = small, 3 = unknown. + +New `lib/model-gate.md` snippet (same include pattern as `lib/design-gate.md`): +run the check; `small` → STOP the skill: "session model is — reflection +requires Fable/Opus. Switch with /model, then relaunch." `unknown` → +fail-visible: show the raw value, ask the user to confirm or abort (BDR-025 +doctrine — unknown never silently passes). + +Wired as a STEP 0 line in the reflection orchestrators: +`ship-feature, init-project, feat, bugfix, onboard, seo, geo, web-validate, +harden, audit-delta, tour, code-clean`. +NOT wired in: `hotfix` (trivial by definition), `commit-change`, `doc`, +`status`, `release-candidate`. + +Caveats to prove at implementation time: +- `/model` mid-session rewrites settings.json (LRN-098 observed it once — + re-prove with a live flip-test before trusting the source). +- The helper itself must be flip-tested (LRN-096: an unproven guard is a + vacuous guard). + +## 2. Frontmatter pins (`agents/*.md`) + +| Agent | Before | After | Rationale | +|---|---|---|---| +| feater | (inherit) | **sonnet** | executor as subagent: seo/geo L1 applier + new /feat dispatch | +| hotfixer | (inherit) | **sonnet** | L1 applier (seo/geo/web-validate); /hotfix inline unaffected (pin inert on inline load) | +| client-handover-writer | opus | **sonnet** | deliverable executor; pin becomes EFFECTIVE only with §5 dispatch conversion (today's opus pin is inert — the agent is inline-loaded) | +| analyzer | haiku | **(none — inherit)** | analysis feeds the plan = reflection; runs big via the session model | +| verifier | sonnet | keep | F1 confirmed (job9) | +| security-auditor | sonnet | keep | F1 confirmed (job9) | +| seo-analyzer, geo-analyzer, validator-analyzer | (inherit) | keep (inherit) | audit = reflection = session model; covered by the gate | +| code-cleaner | (inherit) | keep (inherit) | audit phase = reflection; fixes hand off to refactorer (sonnet) via CODE-CLEAN-SCOPE.md (job9 H1) | +| doc-syncer, onboarder, scaffolder, refactorer, interviewer, plugin-advisor | sonnet | keep | workers/executors | +| status-reporter | haiku | keep | mechanical collector | +| bugfixer, commit-changer | (inherit) | keep | inline-only playbooks — a pin would be inert | + +## 3. `/feat` re-architecture (partial supersede of BDR-050 — feat only) + +`skills/feat/SKILL.md` absorbs the reflection: analyze-before-plan, design +gate, MINI-PLAN, contract (`lib/contract-interview.md`) — all inline. Then +dispatches `Agent(subagent_type="feater")` (sonnet via pin) with: the +contract, the plan, the branch name, repo conventions. + +`agents/feater.md` is rewritten as a pure executor: implement the plan to the +letter, run project checks, commit (no attribution trailers), return a +structured summary. No user interaction inside feater (subagents cannot ask) — +every decision must be closed pre-dispatch. + +The verify-secure loop moves out of feater.md into the /feat main loop +(LRN-083 invariant: loop decisions live in the main loop): fresh verifier → +ECARTS → re-dispatch feater with the verdict deltas, bounded 3×; then the +security gate. Escalation paths unchanged. + +## 4. SDD execution pinned (ship-feature STEP 4, init-project STEP 8) + +One instruction line in each SKILL.md: every implementation subagent +dispatched under `superpowers:subagent-driven-development` MUST carry +`model: "sonnet"` in the Agent call. No fork of the superpowers skill — the +main loop emits the Agent calls and controls the params. + +## 5. client-handover conversion (inline-load → true dispatch) + +`skills/client-handover/SKILL.md`: collect params inline (URL, logo, options), +then `Agent(subagent_type="client-handover-writer")` — the sonnet pin becomes +effective. Human gates (per-axis threshold escalation, overrides) RELOCATE to +the main loop: the writer returns a structured `GATE NEEDED` status instead of +asking; the dispatcher asks the user and re-dispatches (or continues via +SendMessage) with the decision. `AskUserQuestion` is removed from the writer's +tools. + +OPEN VERIFY POINT: the writer's own nested dispatches (seo/harden re-runs as +general-purpose subagents) — verify at implementation what nested children +inherit (session model vs parent model). If they inherit the sonnet parent, +the re-run audits violate the principle → force the model explicitly in those +nested dispatches or lift them to the main loop. + +## 6. web-validate fixes → L1 applier + +STEP 3 stops applying fixes via inline Edit; dispatches `hotfixer` (sonnet) +with the fix bundle — same pattern as seo/geo (BDR-061 alignment). + +## 7. Memory / doc / tests + +- New BDR: model-routing principle (reflection inline big / executors sonnet / + blocking gate); partial supersede of BDR-050 (feat only); records F1 + (verifier/security stay sonnet) and the analyzer haiku→inherit change. +- README: agent-model table refresh. CHANGELOG Unreleased entry. +- Tests: flip-tests for `model-check.sh` (fable[1m] / opus / sonnet / garbage + fixtures); gate STOP proven on a small-model fixture (LRN-096); /feat smoke + on a throwaway repo (LRN-079): plan inline → dispatch carries sonnet → + verify loop decided in main loop; grep census: no executor dispatch without + an effective pin. + +## Out of scope / accepted deviations + +- `/doc` and `/commit-change` stay inline on the session model (judgment and + execution interleaved; converting them buys little). Revisit under quota + pressure. +- bugfix/hotfix fully inline (BDR-050 conserved). +- No per-agent "fable-else-opus" fallback exists in the harness — the session + model IS the fallback mechanism; the gate is its backstop. + +## Risks + +- Model strings in settings.json may change shape with CC updates → + model-check must return `unknown` (fail-visible), never guess. +- feater as a subagent loses main-conversation context → the plan becomes the + contract; weak plans cost verify-loop iterations. Mitigation: + contract-interview stays mandatory in /feat. +- Nested model inheritance under client-handover-writer unknown → §5 verify + point. From e5dd804e7e2d0ad22895ee9880a47153fc02ad7c Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 15 Jul 2026 10:46:43 +0200 Subject: [PATCH 02/28] =?UTF-8?q?docs(plan):=20model=20routing=20=E2=80=94?= =?UTF-8?q?=2010-task=20implementation=20plan=20(client-handover=20deferre?= =?UTF-8?q?d=20to=20plan=202)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../plans/2026-07-15-model-routing.md | 1060 +++++++++++++++++ 1 file changed, 1060 insertions(+) create mode 100644 docs/superpowers/plans/2026-07-15-model-routing.md diff --git a/docs/superpowers/plans/2026-07-15-model-routing.md b/docs/superpowers/plans/2026-07-15-model-routing.md new file mode 100644 index 0000000..494a9ea --- /dev/null +++ b/docs/superpowers/plans/2026-07-15-model-routing.md @@ -0,0 +1,1060 @@ +# Model Routing Implementation Plan + +> **For agentic workers:** REQUIRED SUB-SKILL: Use superpowers:subagent-driven-development (recommended) or superpowers:executing-plans to implement this plan task-by-task. Steps use checkbox (`- [ ]`) syntax for tracking. + +**Goal:** Reflection (planning, audits, loop decisions) stays on the session big model behind a blocking gate; execution (code from a closed plan, fix-bundle application) runs on sonnet-pinned subagents. + +**Architecture:** A deterministic witness (`lib/model-check.sh`) + a blocking include (`lib/model-gate.md`) wired into 12 reflection orchestrators; frontmatter `model:` pins on executor agents; `/feat` re-architected from inline playbook to "plan inline → dispatch sonnet executor"; SDD implementation subagents and web-validate fix application routed to sonnet. + +**Tech Stack:** bash (shellcheck-clean), Claude Code SKILL.md/agent.md markdown, agent frontmatter `model:` field, Makefile test loop. + +**Spec:** `docs/superpowers/specs/2026-07-15-model-routing-design.md` (approved 2026-07-15). + +## Global Constraints + +- Work on branch `feature/model-routing` (already checked out). Commit per task. NEVER merge/finish — human gate. +- NO commit attribution trailers of any kind (Co-Authored-By, Claude-Session) — user ban, guards will red. +- `make test` must be green at every commit (run from repo root `/home/bchanot/Documents/claude`). +- New/edited `.sh` files: `shellcheck ` clean and `bash -n ` clean. +- The `config-protection` PreToolUse hook BLOCKS Edit/Write on `lib/tests/*`, `hooks/*`, `settings.json`, `lib/gitflow.sh`. Before EACH Edit/Write to `lib/tests/*` in this plan, write the one-shot bypass sentinel (consumed per use): `printf 'model-routing plan: ' > .claude/.config-edit-ok` +- Agent frontmatter must stay `yaml.safe_load`-parseable (job9 gate): if a value contains `: `, quote it. +- Memory registries: append-only, caveman format, English. +- SPEC §5 (client-handover conversion) is DEFERRED to a separate plan — do NOT touch `agents/client-handover-writer.md` or `skills/client-handover/SKILL.md` in this plan. + +--- + +### Task 1: `lib/model-check.sh` witness + flip-tests + +**Files:** +- Create: `lib/model-check.sh` +- Test: `lib/tests/model-check.test.sh` (guarded path — sentinel required) + +**Interfaces:** +- Consumes: `$HOME/.claude/settings.json` `"model"` key; env override `MODEL_CHECK_SETTINGS=` for fixtures. +- Produces: stdout `:` where class ∈ `big|small|unknown`; exit `0`=big, `2`=small, `3`=unknown. Task 2's `lib/model-gate.md` calls `bash "$HOME/.claude/lib/model-check.sh"` and branches on these exact codes. + +- [ ] **Step 1: Write the failing test** + +```bash +printf 'model-routing plan: create model-check flip-tests' > .claude/.config-edit-ok +``` + +Then create `lib/tests/model-check.test.sh` with exactly: + +```bash +#!/usr/bin/env bash +# lib/tests/model-check.test.sh — flip-tests for lib/model-check.sh (LRN-096) +set -u +S="$(cd "$(dirname "$0")/../.." && pwd)/lib/model-check.sh" +pass=0; fail=0 +check() { if [ "$2" = "$3" ]; then pass=$((pass+1)); else fail=$((fail+1)); + printf 'FAIL %s: got[%s] want[%s]\n' "$1" "$2" "$3"; fi; } +T="$(mktemp -d)"; trap 'rm -rf "$T"' EXIT + +fx() { printf '{"model": "%s"}' "$1" > "$T/s.json"; } +run() { MODEL_CHECK_SETTINGS="$T/s.json" bash "$S" >"$T/out" 2>&1; echo "$?"; } + +fx 'claude-fable-5[1m]'; check T1-fable-exit "$(run)" 0 +check T1-fable-class "$(cut -d: -f1 <"$T/out")" big +fx 'claude-opus-4-8'; check T2-opus "$(run)" 0 +fx 'claude-sonnet-5'; check T3-sonnet "$(run)" 2 +fx 'claude-haiku-4-5-20251001'; check T4-haiku "$(run)" 2 +fx 'opusplan'; check T5-opusplan "$(run)" 3 +fx 'gpt-9-mega'; check T6-foreign "$(run)" 3 +printf '{"no_model": true}' > "$T/s.json"; check T7-no-key "$(run)" 3 +printf '{broken' > "$T/s.json"; check T8-malformed "$(run)" 3 +check T9-missing-file "$(MODEL_CHECK_SETTINGS="$T/absent.json" bash "$S" >/dev/null 2>&1; echo $?)" 3 + +printf 'model-check: %d pass, %d fail\n' "$pass" "$fail" +[ "$fail" -eq 0 ] +``` + +- [ ] **Step 2: Run test to verify it fails** + +Run: `bash lib/tests/model-check.test.sh` +Expected: FAIL on every check (script missing → bash exits non-zero, got[127]-style mismatches), final line `model-check: 1 pass, 9 fail` or similar non-zero fail count, exit 1. (T1-fable-class may pass vacuously on empty output only if cut returns empty — any red is enough: the suite CAN fail.) + +- [ ] **Step 3: Write the implementation** + +Create `lib/model-check.sh` with exactly: + +```bash +#!/usr/bin/env bash +# lib/model-check.sh — classify the persisted session model: big | small | unknown +# +# Witness for lib/model-gate.md (reflection requires a big model). Reads the +# "model" key of the user-scope settings (the file /model rewrites — LRN-098). +# Override the source with MODEL_CHECK_SETTINGS (tests use fixtures). +# +# stdout : : (raw = value found, empty if none) +# exit : 0 = big (fable/opus) · 2 = small (sonnet/haiku) · 3 = unknown +set -u + +SETTINGS="${MODEL_CHECK_SETTINGS:-$HOME/.claude/settings.json}" + +raw="" +if [ -f "$SETTINGS" ]; then + raw="$(python3 - "$SETTINGS" 2>/dev/null <<'PY' +import json, sys +try: + v = json.load(open(sys.argv[1])).get("model", "") + print(v if isinstance(v, str) else "") +except Exception: + print("") +PY +)" +fi + +norm="$(printf '%s' "$raw" | tr '[:upper:]' '[:lower:]')" +case "$norm" in + *opusplan*) printf 'unknown:%s\n' "$raw"; exit 3 ;; # opus-for-plan, sonnet otherwise — ambiguous + *fable*|*opus*) printf 'big:%s\n' "$raw"; exit 0 ;; + *sonnet*|*haiku*) printf 'small:%s\n' "$raw"; exit 2 ;; + *) printf 'unknown:%s\n' "$raw"; exit 3 ;; +esac +``` + +(The heredoc passes the settings path as `sys.argv[1]` — never pipe INTO a heredoc'd interpreter, LRN-012.) + +- [ ] **Step 4: Run test to verify it passes** + +Run: `bash lib/tests/model-check.test.sh` +Expected: `model-check: 10 pass, 0 fail`, exit 0. + +- [ ] **Step 5: Lint** + +Run: `shellcheck lib/model-check.sh lib/tests/model-check.test.sh && bash -n lib/model-check.sh` +Expected: no output (clean), exit 0. + +- [ ] **Step 6: Full suite + commit** + +Run: `make test` +Expected: every suite line green, exit 0. + +```bash +git add lib/model-check.sh lib/tests/model-check.test.sh +git commit -m "feat(model-routing): model-check witness (big/small/unknown) + flip-tests" +``` + +--- + +### Task 2: `lib/model-gate.md` blocking include + +**Files:** +- Create: `lib/model-gate.md` + +**Interfaces:** +- Consumes: `lib/model-check.sh` exit codes (Task 1). +- Produces: the include that Tasks 3 and 5 reference verbatim as `` `$HOME/.claude/lib/model-gate.md` ``. + +- [ ] **Step 1: Create the include** + +Create `lib/model-gate.md` with exactly: + +```markdown +# Model gate — reflection requires a big model (BLOCKING) + +Shared include. Runs FIRST in any orchestrator whose reflection — +brainstorming, planning, contract, audit judgment, loop decisions — +executes inline or in inherit-model subagents. Sonnet-pinned executors are +not what this gate protects; it protects the thinking around them (BDR-066). + +## 1. Self-check + +Your system prompt names the model powering this session. Fable or Opus → +big. Sonnet, Haiku, anything else → small. + +## 2. Witness — deterministic check + + bash "$HOME/.claude/lib/model-check.sh" + +Output `:`; exit 0 = big, 2 = small, 3 = unknown. The witness +reads the PERSISTED model (settings.json — the file `/model` rewrites, +LRN-098). It can lag reality (session launched with `--model`, settings not +yet rewritten) — that is why the self-check exists alongside it. + +## 3. Verdict + +| self-check | witness | action | +|---|---|---| +| big | big (0) | proceed, SILENT — the nominal path prints nothing | +| small | any | **STOP** | +| big | small (2) | disagreement — **STOP**, surface BOTH values; the user confirms or relaunches | +| big | unknown (3) | fail-visible: print `model gate: witness unknown () — self-check says ` and ask the user to confirm before continuing (BDR-025: unknown never silently passes) | + +**STOP means**: print exactly + + ⛔ MODEL GATE — session on . Reflection steps of this skill + require Fable or Opus. Switch with /model, then relaunch the skill. + +then end the turn. No later step runs, no agent is dispatched, nothing is +edited. +``` + +- [ ] **Step 2: Commit** + +```bash +git add lib/model-gate.md +git commit -m "feat(model-routing): blocking model-gate include (self-check + witness)" +``` + +--- + +### Task 3: Wire the gate into the 12 reflection orchestrators + +**Files:** +- Modify: `skills/ship-feature/SKILL.md`, `skills/init-project/SKILL.md`, `skills/onboard/SKILL.md`, `skills/seo/SKILL.md`, `skills/geo/SKILL.md`, `skills/web-validate/SKILL.md`, `skills/harden/SKILL.md`, `skills/audit-delta/SKILL.md`, `skills/tour/SKILL.md` (orchestrator idiom), `skills/feat/SKILL.md`, `skills/bugfix/SKILL.md`, `skills/code-clean/SKILL.md` (thin-wrapper idiom) + +**Interfaces:** +- Consumes: `lib/model-gate.md` (Task 2). +- Produces: the string `lib/model-gate.md` present in each of the 12 files — Task 8's census greps exactly this. + +- [ ] **Step 1: Insert the orchestrator gate block (9 files)** + +For each of the 9 orchestrator skills, Edit with `old_string` = the file's unique H1 line (below), `new_string` = the same H1 line followed by a blank line and this exact block: + +```markdown +## MODEL GATE (blocking — run before any other step) + +Run `$HOME/.claude/lib/model-gate.md`. Reflection here (planning, audit +judgment, loop decisions) requires Fable/Opus. Verdict `small` → STOP: the +gate prints the remedy; end the turn — no later step, no dispatch. Nominal +(big) path is silent. +``` + +H1 anchors (verbatim, one per file): +- `skills/ship-feature/SKILL.md` → `# ORCHESTRATOR: SHIP FEATURE` +- `skills/init-project/SKILL.md` → `# ORCHESTRATOR: INIT PROJECT` +- `skills/onboard/SKILL.md` → `# ORCHESTRATOR: ONBOARD` +- `skills/seo/SKILL.md` → `# /seo — parallel SEO + GEO dispatcher` +- `skills/geo/SKILL.md` → `# /geo — GEO (AI-search) audit + fix dispatcher` +- `skills/web-validate/SKILL.md` → `# /web-validate — web standards audit (W3C + WCAG)` +- `skills/harden/SKILL.md` → `# /harden — web hardening audit` +- `skills/audit-delta/SKILL.md` → `# /audit-delta — Incremental multi-axis code audit` +- `skills/tour/SKILL.md` → `# /tour — grouped multi-axis sweep (clean + security + reconcile + doc)` + +- [ ] **Step 2: Insert the thin-wrapper gate paragraph (3 files)** + +For `skills/feat/SKILL.md`, `skills/bugfix/SKILL.md`, `skills/code-clean/SKILL.md`: Edit with `old_string` = `Load and follow strictly:` and `new_string` = + +```markdown +MODEL GATE (blocking): run `$HOME/.claude/lib/model-gate.md` BEFORE loading +the agent below. Verdict `small` → STOP — print the gate's remedy, end the +turn, do not load the agent. + +Load and follow strictly: +``` + +(`Load and follow strictly:` occurs once per file — safe anchor.) + +- [ ] **Step 3: Verify the wiring by census** + +Run: `for s in ship-feature init-project feat bugfix onboard seo geo web-validate harden audit-delta tour code-clean; do grep -L 'lib/model-gate.md' "skills/$s/SKILL.md"; done` +Expected: no output (grep -L lists files MISSING the pattern — empty = all wired). + +Run: `for s in hotfix commit-change doc status release-candidate; do grep -l 'lib/model-gate.md' "skills/$s/SKILL.md"; done` +Expected: no output (excluded skills stay unwired). + +- [ ] **Step 4: Full suite + commit** + +Run: `make test` +Expected: green, exit 0. + +```bash +git add skills/ship-feature/SKILL.md skills/init-project/SKILL.md skills/onboard/SKILL.md skills/seo/SKILL.md skills/geo/SKILL.md skills/web-validate/SKILL.md skills/harden/SKILL.md skills/audit-delta/SKILL.md skills/tour/SKILL.md skills/feat/SKILL.md skills/bugfix/SKILL.md skills/code-clean/SKILL.md +git commit -m "feat(model-routing): wire blocking model gate into 12 reflection orchestrators" +``` + +--- + +### Task 4: Frontmatter pins — hotfixer sonnet, analyzer un-pinned + +**Files:** +- Modify: `agents/hotfixer.md:1-5` (frontmatter) +- Modify: `agents/analyzer.md:1-7` (frontmatter) + +**Interfaces:** +- Produces: `model: sonnet` line in hotfixer frontmatter (Task 7's applier dispatches and seo/geo L1 appliers ride on it); NO `model:` line in analyzer frontmatter (inherits session). Task 8's census greps both. + +- [ ] **Step 1: Pin hotfixer** + +Edit `agents/hotfixer.md`, `old_string`: + +``` +tools: Read, Edit, Write, Bash, Grep, Glob, Agent +--- +``` + +`new_string`: + +``` +tools: Read, Edit, Write, Bash, Grep, Glob, Agent +model: sonnet +--- +``` + +- [ ] **Step 2: Un-pin analyzer** + +Edit `agents/analyzer.md`, `old_string`: + +``` +tools: Read, Grep, Glob, Bash +model: haiku +memory: project +``` + +`new_string`: + +``` +tools: Read, Grep, Glob, Bash +memory: project +``` + +- [ ] **Step 3: Verify YAML stays parseable** + +Run: `python3 -c "import yaml,sys; [yaml.safe_load(open(f).read().split('---')[1]) for f in ['agents/hotfixer.md','agents/analyzer.md']]; print('YAML OK')"` +Expected: `YAML OK`. + +- [ ] **Step 4: Full suite + commit** + +Run: `make test` +Expected: green (includes the job9 review guards). + +```bash +git add agents/hotfixer.md agents/analyzer.md +git commit -m "feat(model-routing): pin hotfixer sonnet (executor), un-pin analyzer (inherits session)" +``` + +--- + +### Task 5: `/feat` re-architecture — reflection inline, execution dispatched + +**Files:** +- Modify (full rewrite): `skills/feat/SKILL.md` +- Modify (full rewrite): `agents/feater.md` +- Modify (3 surgical edits): `lib/verify-secure-loop.md` + +**Interfaces:** +- Consumes: `lib/model-gate.md` (Task 2), `lib/verify-secure-loop.md`, `lib/contract-interview.md`, `lib/gitflow-aiguillage.md`, `lib/analyze-before-plan.md`, `lib/design-gate.md` (all existing). +- Produces: `Agent(subagent_type="feater")` dispatch in feat/SKILL.md; feater `FEAT-EXEC REPORT` grammar `STATUS : DONE | NEED-DECISION | BLOCKED`; `model: sonnet` in feater frontmatter. Task 8's census greps `subagent_type="feater"`, `verify-secure-loop.md`, feater `model: sonnet`, feater has NO `AskUserQuestion`. + +- [ ] **Step 1: Rewrite `skills/feat/SKILL.md`** + +Replace the ENTIRE file content with: + +````markdown +--- +name: feat +description: | + Small feature implementation (1-5 files). Reflection inline (scope, + plan, contract — session model), execution dispatched to the + sonnet-pinned feater executor. For features that don't need the full + /ship-feature pipeline (no design brainstorm, no plugin check gate). + Trigger: "feat", "small feature", "add this", "petite feature", + "quick feature", "ajoute ca", "implement this small thing". + For multi-file features needing design → use /ship-feature. + For bug fixes → use /hotfix or /bugfix. +argument-hint: +allowed-tools: + - Read + - Edit + - Write + - Bash + - Grep + - Glob + - Agent +--- + +# /feat — small-feature orchestrator (reflection inline, execution dispatched) + +MODEL GATE (blocking): run `$HOME/.claude/lib/model-gate.md` BEFORE any +step below. Verdict `small` → STOP — print the gate's remedy, end the +turn, dispatch nothing. + +## REQUEST +$ARGUMENTS + +--- + +## STEP 0 — SCOPE CHECK + +Before starting, verify this is actually a small feature: + +```bash +git status +git log --oneline -3 +``` + +Read the relevant existing code to understand the context. + +### Decision rules (apply in order — first match wins) + +| Rule | Trigger | Action | +|---|---|---| +| 1 | Estimated diff < 2 files AND no logic (config value, copy fix, missing field) | DOWNGRADE → load `$HOME/.claude/agents/hotfixer.md` | +| 2 | New external dependency (`npm install `, `pip install`, `cargo add`) required | ESCALATE → `/ship-feature` (dep choices need design gate) | +| 3 | New route family / new top-level module / new DB migration | ESCALATE → `/ship-feature` | +| 4 | Estimated diff > 5 files | ESCALATE → `/ship-feature` | +| 5 | User wording is uncertain ("not sure how", "what do you think") | ESCALATE → `/ship-feature` (needs brainstorming) | +| 6 | UI feature on a stack with a design system AND the design toolchain incomplete | Proceed in `/feat`, but flag it in STEP 0.5 design gate | +| 7 | Otherwise | PROCEED in `/feat` | + +### Worked examples + +- "Add `/health` endpoint returning `{status:"ok",version}`" → 1-2 files, no new dep, route added to existing router → **PROCEED**. +- "Add a dark-mode toggle bound to `prefers-color-scheme`" → 2-3 files, design system exists → **PROCEED** (design gate triggers in STEP 0.5). +- "Add OAuth login (Google + GitHub providers)" → new deps, new routes, secrets handling → **ESCALATE** to `/ship-feature`. +- "Show a 'New' badge on items created this week" → 1-2 files, pure UI predicate → **PROCEED**. +- "Fix copy: 'Sign In' → 'Sign in'" in 1 file → **DOWNGRADE** to `/hotfix`. + +Print a one-line scope confirmation (use the rule that fired): +``` +FEAT: — rule , ~ files, +``` + +## STEP 0.5 — DESIGN GATE + +Follow `$HOME/.claude/lib/design-gate.md`: +- Scan $ARGUMENTS and target files for design/UI/style signals. +- If signals found → run `design-tool-gate.sh`; if it reports INCOMPLETE, + tell the user to run `/profile design` before proceeding. +- If no signals → skip (zero overhead). + +## STEP 0.6 — MEMORY READ-BEFORE (decisions-first) + +Run the scan per `$HOME/.claude/lib/analyze-before-plan.md`, decisions-weighted: a BDR may +already constrain or forbid the approach; an LRN may name a gotcha to apply. Emit RELATED +MEMORY; feed STEP 1 PLAN. Inline consumption — reader = planner, no injection. +`.claude/memory/` absent → guarded no-op (zero overhead on a memory-less repo). + +## STEP 0.7 — CONTRACT + +Run `$HOME/.claude/lib/contract-interview.md` (main loop — you are it). It +captures the request verbatim, asks 0-3 questions PROPORTIONAL to ambiguity +(a complete request → zero questions, silent), derives testable acceptance +criteria + file scope, and writes the contract to +`.claude/tasks/contracts/--.md`. Keep the path — the +executor reads it first and GATE 1 (STEP 4) hands it to a fresh verifier. + +## STEP 1 — PLAN (dispatch-ready) + +The executor follows this plan to the letter and CANNOT ask questions — +close every decision here: + +1. Files to create or modify (with line references). +2. Approach in 2-5 bullets — name every choice (naming, data shape, API + surface); an open choice left here comes back as a NEED-DECISION + round-trip. +3. Edge cases to handle. +4. Tests to add/update (exact files). +5. Disposition (from STEP 0.6): name each in-force BDR/LRN this plan honors + (`honors BDR-xxx by …`), or state `no in-force decision constrains this feature`. + A plan with neither = read-then-ignore; the disposition must surface as a trace. + +Print the plan as a compact checklist: +``` +PLAN: + [ ] — + [ ] — + [ ] — +``` + +If the approach is ambiguous: ask the user ONE focused question BEFORE +dispatching — never after (the executor cannot relay questions). + +## STEP 2 — BRANCH + +**Gitflow aiguillage (before dispatch):** follow `$HOME/.claude/lib/gitflow-aiguillage.md` +— your type = `feature`. On `main`/`develop` it branches first; on a working +branch it's a no-op (commit in place). Never `finish`. + +## STEP 3 — DISPATCH EXECUTOR + +Dispatch the executor — sonnet by frontmatter pin, do not override: + +``` +Agent(subagent_type="feater") +prompt: "CONTRACT: +PLAN: +BRANCH: +Implement the plan to the letter. Tests alongside code. No commit, no +branch ops, no new dependencies, no files outside the contract FILE SCOPE. +Finish with the FEAT-EXEC REPORT." +``` + +Parse the `FEAT-EXEC REPORT`: +- `STATUS : DONE` → STEP 4. +- `STATUS : NEED-DECISION` → make the decision HERE (that is reflection), + append it to the plan, re-dispatch a FRESH feater with plan + decision. + Max 2 decision round-trips → escalate to the user. +- `STATUS : BLOCKED` → surface the blocker to the user, stop. + +## STEP 4 — VERIFY + SECURE (fresh gates, bounded loops) + +Run the two fresh gates per `$HOME/.claude/lib/verify-secure-loop.md` with +`CONTRACT` = the STEP 0.7 path, `DIFF` = the working-tree diff the executor +produced, `TEST` = the suite named in its report: + +- GATE 1 — a FRESH verifier judges the diff against the contract (blind). + CONFORME on the first pass → straight to GATE 2, no loop. ECARTS → the + "dev" of the loop is the dispatched executor: re-dispatch a FRESH feater + with the CONTRACT path + the exact gap lines, nothing else. Max 3 → + escalate. +- GATE 2 — a FRESH security-auditor (`MODE: gate`) scans the diff. PASS → + STEP 5. BLOCK → re-dispatch a FRESH feater with the BLOCKING list + the + CONTRACT path; re-verify the request THEN re-scan, max 3 → escalate. + +Loop decisions stay HERE, in the main loop (LRN-083). Nominal (clear +request, conform first pass, clean diff) = one executor + one verifier + +one security dispatch. + +## STEP 5 — COMMIT + +Commit using conventional format: +``` +feat(): + + +``` + +If the feature touched multiple concerns (e.g., feature + config + +test), consider splitting into 2-3 atomic commits — load +`$HOME/.claude/agents/commit-changer.md` and follow its grouping logic. + +Print summary: +``` +FEAT COMPLETE +FEATURE : +FILE(S) : +TEST(S) : +VERIFIED : +``` + +## STEP 6 — DOC SYNC (automatic) + +Load `$HOME/.claude/agents/doc-syncer.md`. +Execute in automatic mode: +`auto-mode scope: ` + +**Then commit the docs** — follow `$HOME/.claude/lib/doc-commit.md`: it surgically commits +ONLY the files doc-syncer patched (its `PATCHED_FILES` output), never `git add -A`, never +`.claude/`/`CLAUDE.md` (rc 4 = a loud BDR-022 anomaly, not a silent skip), and no-ops when +nothing was patched — the common case for a trivial change. No FINISH in an inline flow, so +it just commits the docs on the current branch (no ordering concern). + +## STEP 7 — CAPITALIZE (memory registries) + +A small feature may or may not involve a design choice. Scan the work for: + +- **Non-trivial design choice** (even small: a library pick, a naming convention, a data-model tradeoff) → propose `BDR-XXX` in `.claude/memory/decisions.md` with alternatives considered. +- **Reusable pattern or gotcha encountered** → propose `LRN-XXX` in `.claude/memory/learnings.md`. + +Present the candidates grouped: +``` +CAPITALIZE — proposé + [decisions.md] BDR-XXX — (optionnel) + [learnings.md] LRN-XXX — (optionnel) +Valider ? (all / / edit / skip) +``` + +Always append a 1-line entry to today's heading in `.claude/memory/journal.md`. + +**Language rule**: written entries are ALWAYS in English (see CLAUDE.md "Memory registries" § Language). The interactive gate may mirror the user's language; the appended entries must not. + +If no substantive capture candidate → skip with `CAPITALIZE: nothing to log`. + +**Then commit the memory** — follow `$HOME/.claude/lib/capitalize-commit.md`: it +surgically commits what capitalize just wrote (`.claude/memory` + `.claude/tasks` +only, never `git add -A`) as one `chore(memory)` commit, reports the memory-commit +hash, and no-ops if nothing was written. + +--- + +## RULES +- Max 5 files. If more needed → `/ship-feature`. +- Reflection (scope, plan, contract, loop decisions) NEVER leaves this main + loop; execution NEVER stays in it — the executor is the sonnet-pinned + feater subagent (BDR-066). +- The executor is dispatched FRESH on every round-trip — feedback travels + as contract path + named gaps/decisions, never as transcript. +- Design gate only (not full plugin check). See STEP 0.5. +- No brainstorm/design phase (if needed → `/ship-feature`). +- Keep scope tight. If scope creep happens mid-work, stop + and suggest splitting into `/feat` + follow-up task. +- Follow existing code patterns. Don't introduce new patterns + for a small feature. +```` + +(Note: this rewrite REPLACES the Task 3 thin-wrapper gate paragraph for feat — the gate line is now native under the H1. The census greps `lib/model-gate.md`, satisfied either way.) + +- [ ] **Step 2: Rewrite `agents/feater.md`** + +Replace the ENTIRE file content with: + +````markdown +--- +name: feater +description: Small-feature EXECUTOR — dispatched by /feat with a closed plan + contract. Implements to the letter, tests, reports. No planning, no questions, no commit. +tools: Read, Edit, Write, Bash, Grep, Glob +model: sonnet +--- + +# FEATER — plan executor + +You receive a CLOSED plan from the /feat orchestrator. Your job is faithful +execution, not design. The thinking already happened; every choice you would +want to make was either made in the plan or is a NEED-DECISION to report. + +## INPUT (in the dispatch prompt) + +- `CONTRACT`: path to the contract file — read it FIRST; its acceptance + criteria + FILE SCOPE bound everything you do. +- `PLAN`: files + approach + edge cases + tests. +- `BRANCH`: verify with `git branch --show-current`; mismatch → STATUS + BLOCKED — never create or switch branches. +- `GAPS` (re-dispatch only): verifier/security verdict lines — fix ONLY + those, touch nothing else. + +## EXECUTION RULES + +- Follow the plan to the letter. A plan hole or an open choice (naming, + data shape, API surface, dependency) → STOP, report `NEED-DECISION` with + the precise question. Never improvise a design decision. +- Stay inside the contract FILE SCOPE. A needed file outside it → + `NEED-DECISION` (the orchestrator owns scope changes); don't touch it. +- Write tests alongside the code, as the plan names them. Run the relevant + suite incrementally; run it fully before reporting. +- Follow existing code patterns and CLAUDE.md limits (function size, + params, no global state). Match comment density and naming. +- FORBIDDEN: `git commit`, branch ops, push, merge, new dependencies, + editing `.claude/**` or memory registries, user questions (you cannot + ask — report instead), attribution trailers of any kind. + +## OUTPUT — end with exactly this report (your final message) + +``` +FEAT-EXEC REPORT +STATUS : DONE | NEED-DECISION | BLOCKED +FILES : +TESTS : +NOTES : +``` +```` + +- [ ] **Step 3: Update `lib/verify-secure-loop.md` (3 surgical edits)** + +Edit 1 — header, `old_string`: + +``` +finished diff into a verified, security-cleared change through two fresh +gates and bounded loops. The dev stays inline (LRN-083: subagents = +execution + report; loop decisions live here, in the main loop). +``` + +`new_string`: + +``` +finished diff into a verified, security-cleared change through two fresh +gates and bounded loops. Loop decisions live here, in the main loop +(LRN-083: subagents = execution + report). The dev step is either inline +(bugfix) or a dispatched sonnet executor (/feat's feater): "hand the dev" +below means fix inline, or re-dispatch a FRESH executor with exactly those +inputs. +``` + +Edit 2 — GATE 1 ECARTS bullet, `old_string`: + +``` + lines (NOT-MET / out-of-scope), nothing else. Dev fixes inline, then + re-dispatch a FRESH verifier. +``` + +`new_string`: + +``` + lines (NOT-MET / out-of-scope), nothing else. Inline dev fixes in place; + a dispatched dev is re-dispatched FRESH with those inputs only. Then + re-dispatch a FRESH verifier. +``` + +Edit 3 — GATE 2 BLOCK bullet, `old_string`: + +``` +- `BLOCK(n)` → hand the dev the `BLOCKING` list + the CONTRACT path. Dev + fixes inline. Then **re-verify the REQUEST first** (GATE 1, fresh +``` + +`new_string`: + +``` +- `BLOCK(n)` → hand the dev the `BLOCKING` list + the CONTRACT path (inline + fix, or FRESH executor re-dispatch). Then **re-verify the REQUEST first** (GATE 1, fresh +``` + +- [ ] **Step 4: Structural verification** + +Run: `grep -c 'subagent_type="feater"' skills/feat/SKILL.md; grep -c 'verify-secure-loop.md' skills/feat/SKILL.md; grep -c 'model: sonnet' agents/feater.md; grep -c 'tools: Read, Edit, Write, Bash, Grep, Glob$' agents/feater.md; grep -c 'AskUserQuestion' agents/feater.md; true` +Expected: `1` / `1` (or more) / `1` / `1` (exact tools line — no Agent tool) / `0` (no AskUserQuestion anywhere). + +Run: `python3 -c "import yaml; yaml.safe_load(open('agents/feater.md').read().split('---')[1]); print('YAML OK')"` +Expected: `YAML OK`. + +- [ ] **Step 5: Full suite + commit** + +Run: `make test` +Expected: green. + +```bash +git add skills/feat/SKILL.md agents/feater.md lib/verify-secure-loop.md +git commit -m "feat(model-routing): /feat re-architecture — reflection inline, feater = sonnet executor (partial supersede BDR-050)" +``` + +--- + +### Task 6: Pin SDD implementation subagents to sonnet (ship-feature, init-project) + +**Files:** +- Modify: `skills/ship-feature/SKILL.md:144-148` +- Modify: `skills/init-project/SKILL.md:166-170` + +**Interfaces:** +- Produces: the literal `model: "sonnet"` in both files — Task 8's census greps it. + +- [ ] **Step 1: ship-feature STEP 4** + +Edit `skills/ship-feature/SKILL.md`, `old_string`: + +``` +`finishing-a-development-branch` step — this orchestrator owns integration via +`gitflow finish` (STEP 9). When SDD's flow reaches "Use +finishing-a-development-branch", stop and return. +``` + +`new_string`: + +``` +`finishing-a-development-branch` step — this orchestrator owns integration via +`gitflow finish` (STEP 9). When SDD's flow reaches "Use +finishing-a-development-branch", stop and return. + +**Model routing (BDR-066):** every subagent dispatched under SDD — per-task +implementers AND its reviewers — MUST carry `model: "sonnet"` in the Agent +call. The plan is closed; execution and plan-conformity review are sonnet +work. Reflection (task decomposition, review verdict arbitration) stays in +this loop. +``` + +- [ ] **Step 2: init-project STEP 8** + +Edit `skills/init-project/SKILL.md`, `old_string`: + +``` +`finishing-a-development-branch` step — this orchestrator owns integration via +`gitflow finish` (STEP 11). When SDD's flow reaches "Use +finishing-a-development-branch", stop and return. +``` + +`new_string`: + +``` +`finishing-a-development-branch` step — this orchestrator owns integration via +`gitflow finish` (STEP 11). When SDD's flow reaches "Use +finishing-a-development-branch", stop and return. + +**Model routing (BDR-066):** every subagent dispatched under SDD — per-task +implementers AND its reviewers — MUST carry `model: "sonnet"` in the Agent +call. The plan is closed; execution and plan-conformity review are sonnet +work. Reflection (task decomposition, review verdict arbitration) stays in +this loop. +``` + +- [ ] **Step 3: Verify + commit** + +Run: `grep -c 'model: "sonnet"' skills/ship-feature/SKILL.md skills/init-project/SKILL.md` +Expected: `1` for each file. + +Run: `make test` — Expected: green. + +```bash +git add skills/ship-feature/SKILL.md skills/init-project/SKILL.md +git commit -m "feat(model-routing): SDD implementation + review subagents dispatched model sonnet" +``` + +--- + +### Task 7: web-validate fixes via hotfixer L1 applier + +**Files:** +- Modify: `skills/web-validate/SKILL.md:274-277` (STEP 3, options A and B) + +**Interfaces:** +- Consumes: hotfixer sonnet pin (Task 4); mirrors the geo L1 applier idiom (`skills/geo/SKILL.md:72-77`). +- Produces: `subagent_type="hotfixer"` in web-validate — Task 8's census greps it. + +- [ ] **Step 1: Replace inline-Edit application with L1 dispatch** + +Edit `skills/web-validate/SKILL.md`, `old_string`: + +``` +4. On `A` : apply each bundle via `Edit` (targeted `old_string` / + `new_string`). Never use `Write` on shared templates (risk of + overwriting /seo or /geo content — meta tags, JSON-LD). +5. On `B` : for each diff, show and ask yes/no/skip. +``` + +`new_string`: + +```` +4. On `A` : dispatch each file-group's applier at L1 (execution = sonnet; + this loop only orchestrates), serially — one applier at a time, appliers + share files: + + ``` + Agent(subagent_type="hotfixer") + prompt: ". + Context: web-validate fix bundle, user-approved scope — no + confirmation needed. Apply via targeted Edit (old_string/new_string); + NEVER Write whole files (shared templates carry /seo and /geo + content — meta tags, JSON-LD). Do NOT commit — apply and self-verify + only." + ``` + +5. On `B` : for each diff, show and ask yes/no/skip; apply approved diffs + as in `A` (hotfixer dispatch). +```` + +- [ ] **Step 2: Verify + commit** + +Run: `grep -c 'subagent_type="hotfixer"' skills/web-validate/SKILL.md` +Expected: `1`. + +Run: `make test` — Expected: green. + +```bash +git add skills/web-validate/SKILL.md +git commit -m "feat(model-routing): web-validate fix bundle applied via hotfixer at L1 (BDR-061 alignment)" +``` + +--- + +### Task 8: Census guard `lib/tests/model-routing.test.sh` + flip-test + +**Files:** +- Test: `lib/tests/model-routing.test.sh` (guarded path — sentinel required) + +**Interfaces:** +- Consumes: every string produced by Tasks 3-7 (see greps below). Auto-discovered by the Makefile `test` glob `lib/tests/*.test.sh` — no runner edit needed. + +- [ ] **Step 1: Write the census test** + +```bash +printf 'model-routing plan: add census guard test' > .claude/.config-edit-ok +``` + +Then create `lib/tests/model-routing.test.sh` with exactly: + +```bash +#!/usr/bin/env bash +# lib/tests/model-routing.test.sh — census: gate wiring + pins + executor shape (BDR-066) +set -u +R="$(cd "$(dirname "$0")/../.." && pwd)" +pass=0; fail=0 +ok() { pass=$((pass+1)); } +ko() { fail=$((fail+1)); printf 'FAIL %s\n' "$1"; } +has() { if grep -qF "$2" "$R/$1"; then ok; else ko "$1 missing: $2"; fi; } +lacks() { if grep -qF "$2" "$R/$1"; then ko "$1 must NOT contain: $2"; else ok; fi; } +fm_lacks() { if awk 'NR<=10' "$R/$1" | grep -qF "$2"; then ko "$1 frontmatter must NOT contain: $2"; else ok; fi; } + +# 1) gate wired in the 12 reflection orchestrators +for s in ship-feature init-project feat bugfix onboard seo geo web-validate harden audit-delta tour code-clean; do + has "skills/$s/SKILL.md" 'lib/model-gate.md' +done +# 2) gate NOT wired in the excluded skills (encodes the spec exclusion list) +for s in hotfix commit-change doc status release-candidate; do + lacks "skills/$s/SKILL.md" 'lib/model-gate.md' +done +# 3) executor + gate pins +has "agents/feater.md" 'model: sonnet' +has "agents/hotfixer.md" 'model: sonnet' +has "agents/verifier.md" 'model: sonnet' +has "agents/security-auditor.md" 'model: sonnet' +fm_lacks "agents/analyzer.md" 'model:' +# 4) /feat executor shape +has "skills/feat/SKILL.md" 'subagent_type="feater"' +has "skills/feat/SKILL.md" 'verify-secure-loop.md' +lacks "agents/feater.md" 'AskUserQuestion' +# 5) SDD execution pinned +has "skills/ship-feature/SKILL.md" 'model: "sonnet"' +has "skills/init-project/SKILL.md" 'model: "sonnet"' +# 6) web-validate applies via L1 applier +has "skills/web-validate/SKILL.md" 'subagent_type="hotfixer"' + +printf 'model-routing census: %d pass, %d fail\n' "$pass" "$fail" +[ "$fail" -eq 0 ] +``` + +- [ ] **Step 2: Run — expect green (everything already wired by Tasks 3-7)** + +Run: `bash lib/tests/model-routing.test.sh` +Expected: `model-routing census: 28 pass, 0 fail`, exit 0. (Count: 12 wired + 5 excluded + 5 pins + 3 feat-shape + 2 SDD + 1 web-validate.) + +- [ ] **Step 3: Flip-test the guard (LRN-096 — prove it CAN fail)** + +```bash +sed -i 's|lib/model-gate.md|lib/model-gate-REMOVED.md|' skills/tour/SKILL.md +bash lib/tests/model-routing.test.sh; echo "exit=$?" +git checkout -- skills/tour/SKILL.md +bash lib/tests/model-routing.test.sh; echo "exit=$?" +``` + +Expected: first run prints `FAIL skills/tour/SKILL.md missing: lib/model-gate.md` and `exit=1`; second run prints `28 pass, 0 fail` and `exit=0`. + +- [ ] **Step 4: Lint + full suite + commit** + +Run: `shellcheck lib/tests/model-routing.test.sh && make test` +Expected: clean + green. + +```bash +git add lib/tests/model-routing.test.sh +git commit -m "test(model-routing): census guard — gate wiring, pins, executor shape (flip-tested)" +``` + +--- + +### Task 9: README + CHANGELOG + +**Files:** +- Modify: `README.md` (agent/model documentation) +- Modify: `CHANGELOG.md` (Unreleased section) + +- [ ] **Step 1: Locate the README insertion point** + +Run: `grep -niE 'agents?/|sonnet|haiku|model' README.md | head -20` + +If README has a table listing agents (a row per agent), refresh/add its model info from the table below. If not, insert a new subsection `### Agent model routing (BDR-066)` immediately after the section that documents `agents/` (fallback: before the "Skills" section), with exactly: + +```markdown +### Agent model routing (BDR-066) + +Reflection (brainstorm, plan, contract, audit judgment, loop decisions) runs +INLINE on the session model — assumed Fable/Opus, enforced by a blocking +gate (`lib/model-gate.md` + `lib/model-check.sh`) at the entry of the 12 +reflection orchestrators. Execution runs on pinned subagents: + +| Agent | Model | Tier | +|---|---|---| +| feater, hotfixer | sonnet (pinned) | executors — code from a closed plan, fix-bundle appliers | +| verifier, security-auditor | sonnet (pinned) | fresh gates (≤3×/loop) | +| doc-syncer, onboarder, scaffolder, refactorer, interviewer, plugin-advisor | sonnet (pinned) | workers | +| status-reporter | haiku (pinned) | mechanical collector | +| client-handover-writer | opus (pinned, currently inert — inline-loaded; sonnet conversion planned) | deliverable writer | +| analyzer, seo-analyzer, geo-analyzer, validator-analyzer, code-cleaner, bugfixer, commit-changer | inherit session (Fable/Opus) | reflection / audit / inline playbooks | +``` + +- [ ] **Step 2: CHANGELOG** + +Run: `grep -n 'Unreleased' CHANGELOG.md` + +Under the `## [Unreleased]` heading (create `### Added` / `### Changed` subsections if absent), add: + +```markdown +### Added +- Model routing (BDR-066): blocking model gate (`lib/model-gate.md` + + `lib/model-check.sh`, flip-tested) wired into 12 reflection orchestrators; + census guard `lib/tests/model-routing.test.sh`. +- `/feat` re-architected: reflection inline (scope/plan/contract), execution + dispatched to the sonnet-pinned `feater` executor; verify+secure loop + decided in the main loop with fresh executor re-dispatches. + +### Changed +- `hotfixer` pinned `model: sonnet` (seo/geo/web-validate L1 applier); + `analyzer` haiku pin removed (inherits the session model). +- ship-feature / init-project: SDD implementation + review subagents + dispatched with `model: "sonnet"`. +- web-validate `--fix`: bundle applied via `hotfixer` at L1 instead of + inline Edit (BDR-061 alignment). +``` + +- [ ] **Step 3: Commit** + +Run: `make test` — Expected: green. + +```bash +git add README.md CHANGELOG.md +git commit -m "docs(model-routing): README agent-model table + CHANGELOG entry" +``` + +--- + +### Task 10: Capitalize memory + TODO follow-up + +**Files:** +- Modify: `.claude/memory/decisions.md` (append BDR-066 + Index row) +- Modify: `.claude/memory/journal.md` (1 line under a `## 2026-07-15` heading) +- Modify: `.claude/tasks/TODO.md` (chantier section + plan-2 backlog) + +- [ ] **Step 1: Append BDR-066 to `.claude/memory/decisions.md`** + +Add to the Index table (after the BDR-065 row): + +```markdown +| BDR-066 | 2026-07-15 | Model routing: reflection inline (session big model) + sonnet-pinned executors + blocking gate | accepted | +``` + +Append at end of file: + +```markdown +## BDR-066 — Model routing: reflection inline (session big model), executors pinned sonnet, blocking gate + +- **Date**: 2026-07-15 +- **Status**: accepted (partial supersede of BDR-050: /feat dev no longer inline; bugfix/hotfix dev-inline CONSERVED) +- **Decision**: reflection (brainstorm, plan, contract, audit judgment, loop decisions) runs on session model (Fable; Opus fallback) — inline or inherit subagents, never pinned down. Execution (code from closed plan, fix-bundle application) runs sonnet-pinned subagents: feater + hotfixer pinned sonnet; SDD implementation+review subagents dispatched `model: "sonnet"` (ship-feature/init-project); web-validate fixes via hotfixer L1 (was inline Edit). analyzer haiku pin REMOVED (digest feeds plan = reflection tier). verifier + security-auditor STAY sonnet (job9 confirmed — procedural gates, ≤3×/loop). Blocking gate `lib/model-gate.md` (self-check + witness `lib/model-check.sh`) wired in 12 reflection orchestrators; small → STOP, unknown → fail-visible; census guard `lib/tests/model-routing.test.sh` flip-tested. +- **Why**: big-model quota burned on mechanical execution (Fable exhausted mid-job8); plan closed at dispatch → executor needs obedience not judgment; fresh sonnet gates catch executor drift. +- **Alternatives rejected**: opus pins on audit agents (session-independent) — rejected: session assumed big + blocking gate as backstop, one tier fewer; advisory gate — rejected by user, blocking; split bugfix/hotfix too — rejected: bugfix investigation interleaved w/ fix, hotfix gain marginal vs dispatch overhead. +- **Caveats**: client-handover-writer conversion (inline-load → sonnet dispatch, 11 human-gate sites to relocate) DEFERRED to own plan — its opus pin stays inert meanwhile; feater cannot ask → NEED-DECISION report = escalation valve, plan must close decisions; witness reads settings.json — lags `--model`-launched sessions (self-check compensates). +- **Reference**: spec `docs/superpowers/specs/2026-07-15-model-routing-design.md` + plan `docs/superpowers/plans/2026-07-15-model-routing.md` (transient, BDR-065 lifecycle), branch `feature/model-routing`. +``` + +- [ ] **Step 2: Journal line** + +Append under a `## 2026-07-15` heading (create it if absent) in `.claude/memory/journal.md`: + +```markdown +- model routing shipped on feature/model-routing: BDR-066 (reflection inline big / executors sonnet / blocking gate), /feat re-arch, census guard. client-handover conversion deferred to plan 2. +``` + +- [ ] **Step 3: TODO follow-up entry** + +Add at the top of `.claude/tasks/TODO.md` (above the 2026-07-08 section): + +```markdown +## 2026-07-15 — model routing (feature/model-routing) +Spec + plan in docs/superpowers/ (transient, BDR-065). BDR-066. Branch +unmerged — human gate. +- [x] gate lib/model-check.sh + lib/model-gate.md (flip-tested) wired ×12 +- [x] pins: hotfixer/feater sonnet, analyzer un-pinned; SDD model:"sonnet"; + web-validate → hotfixer L1; census guard model-routing.test.sh +- [x] /feat re-arch: reflection inline → feater sonnet executor (partial + supersede BDR-050) +- [ ] DOGFOOD (manual, next sessions): /feat live run — plan closes + decisions, dispatch carries sonnet, verify loop in main loop; gate + STOP on a sonnet session (LRN-079 class, not automatable here) +- [ ] PLAN 2 — client-handover conversion (spec §5): inline-load → sonnet + dispatch, relocate 11 human-gate sites to dispatcher (inventory in + plan-1 session), or lighter variant: dispatch only the redaction + phase. Decide shape at plan time. +``` + +- [ ] **Step 4: Commit memory scoped** + +```bash +git add .claude/memory/decisions.md .claude/memory/journal.md .claude/tasks/TODO.md +git commit -m "chore(memory): BDR-066 model routing + journal + TODO follow-ups" +``` + +- [ ] **Step 5: Final gate** + +Run: `make test` +Expected: green, exit 0. Then report the full commit list (`git log --oneline develop..HEAD`) for the human merge gate. Do NOT run `gitflow finish`. From 9984b75f9023037bb2c62f291bd6417a07adab2f Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 15 Jul 2026 11:00:32 +0200 Subject: [PATCH 03/28] feat(model-routing): model-check witness (big/small/unknown) + flip-tests --- lib/model-check.sh | 33 +++++++++++++++++++++++++++++++++ lib/tests/model-check.test.sh | 25 +++++++++++++++++++++++++ 2 files changed, 58 insertions(+) create mode 100644 lib/model-check.sh create mode 100644 lib/tests/model-check.test.sh diff --git a/lib/model-check.sh b/lib/model-check.sh new file mode 100644 index 0000000..1cd3cf5 --- /dev/null +++ b/lib/model-check.sh @@ -0,0 +1,33 @@ +#!/usr/bin/env bash +# lib/model-check.sh — classify the persisted session model: big | small | unknown +# +# Witness for lib/model-gate.md (reflection requires a big model). Reads the +# "model" key of the user-scope settings (the file /model rewrites — LRN-098). +# Override the source with MODEL_CHECK_SETTINGS (tests use fixtures). +# +# stdout : : (raw = value found, empty if none) +# exit : 0 = big (fable/opus) · 2 = small (sonnet/haiku) · 3 = unknown +set -u + +SETTINGS="${MODEL_CHECK_SETTINGS:-$HOME/.claude/settings.json}" + +raw="" +if [ -f "$SETTINGS" ]; then + raw="$(python3 - "$SETTINGS" 2>/dev/null <<'PY' +import json, sys +try: + v = json.load(open(sys.argv[1])).get("model", "") + print(v if isinstance(v, str) else "") +except Exception: + print("") +PY +)" +fi + +norm="$(printf '%s' "$raw" | tr '[:upper:]' '[:lower:]')" +case "$norm" in + *opusplan*) printf 'unknown:%s\n' "$raw"; exit 3 ;; # opus-for-plan, sonnet otherwise — ambiguous + *fable*|*opus*) printf 'big:%s\n' "$raw"; exit 0 ;; + *sonnet*|*haiku*) printf 'small:%s\n' "$raw"; exit 2 ;; + *) printf 'unknown:%s\n' "$raw"; exit 3 ;; +esac diff --git a/lib/tests/model-check.test.sh b/lib/tests/model-check.test.sh new file mode 100644 index 0000000..040a8f5 --- /dev/null +++ b/lib/tests/model-check.test.sh @@ -0,0 +1,25 @@ +#!/usr/bin/env bash +# lib/tests/model-check.test.sh — flip-tests for lib/model-check.sh (LRN-096) +set -u +S="$(cd "$(dirname "$0")/../.." && pwd)/lib/model-check.sh" +pass=0; fail=0 +check() { if [ "$2" = "$3" ]; then pass=$((pass+1)); else fail=$((fail+1)); + printf 'FAIL %s: got[%s] want[%s]\n' "$1" "$2" "$3"; fi; } +T="$(mktemp -d)"; trap 'rm -rf "$T"' EXIT + +fx() { printf '{"model": "%s"}' "$1" > "$T/s.json"; } +run() { MODEL_CHECK_SETTINGS="$T/s.json" bash "$S" >"$T/out" 2>&1; echo "$?"; } + +fx 'claude-fable-5[1m]'; check T1-fable-exit "$(run)" 0 +check T1-fable-class "$(cut -d: -f1 <"$T/out")" big +fx 'claude-opus-4-8'; check T2-opus "$(run)" 0 +fx 'claude-sonnet-5'; check T3-sonnet "$(run)" 2 +fx 'claude-haiku-4-5-20251001'; check T4-haiku "$(run)" 2 +fx 'opusplan'; check T5-opusplan "$(run)" 3 +fx 'gpt-9-mega'; check T6-foreign "$(run)" 3 +printf '{"no_model": true}' > "$T/s.json"; check T7-no-key "$(run)" 3 +printf '{broken' > "$T/s.json"; check T8-malformed "$(run)" 3 +check T9-missing-file "$(MODEL_CHECK_SETTINGS="$T/absent.json" bash "$S" >/dev/null 2>&1; echo $?)" 3 + +printf 'model-check: %d pass, %d fail\n' "$pass" "$fail" +[ "$fail" -eq 0 ] From f2dd361bd5907df275bf826d93b78dd91ef7cc0f Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 15 Jul 2026 11:06:49 +0200 Subject: [PATCH 04/28] feat(model-routing): blocking model-gate include (self-check + witness) --- lib/model-gate.md | 37 +++++++++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) create mode 100644 lib/model-gate.md diff --git a/lib/model-gate.md b/lib/model-gate.md new file mode 100644 index 0000000..56b4b06 --- /dev/null +++ b/lib/model-gate.md @@ -0,0 +1,37 @@ +# Model gate — reflection requires a big model (BLOCKING) + +Shared include. Runs FIRST in any orchestrator whose reflection — +brainstorming, planning, contract, audit judgment, loop decisions — +executes inline or in inherit-model subagents. Sonnet-pinned executors are +not what this gate protects; it protects the thinking around them (BDR-066). + +## 1. Self-check + +Your system prompt names the model powering this session. Fable or Opus → +big. Sonnet, Haiku, anything else → small. + +## 2. Witness — deterministic check + + bash "$HOME/.claude/lib/model-check.sh" + +Output `:`; exit 0 = big, 2 = small, 3 = unknown. The witness +reads the PERSISTED model (settings.json — the file `/model` rewrites, +LRN-098). It can lag reality (session launched with `--model`, settings not +yet rewritten) — that is why the self-check exists alongside it. + +## 3. Verdict + +| self-check | witness | action | +|---|---|---| +| big | big (0) | proceed, SILENT — the nominal path prints nothing | +| small | any | **STOP** | +| big | small (2) | disagreement — **STOP**, surface BOTH values; the user confirms or relaunches | +| big | unknown (3) | fail-visible: print `model gate: witness unknown () — self-check says ` and ask the user to confirm before continuing (BDR-025: unknown never silently passes) | + +**STOP means**: print exactly + + ⛔ MODEL GATE — session on . Reflection steps of this skill + require Fable or Opus. Switch with /model, then relaunch the skill. + +then end the turn. No later step runs, no agent is dispatched, nothing is +edited. From 06413d9eb5c0ce38865340f11deab4ccbc90d347 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 15 Jul 2026 11:11:29 +0200 Subject: [PATCH 05/28] feat(model-routing): wire blocking model gate into 12 reflection orchestrators --- skills/audit-delta/SKILL.md | 7 +++++++ skills/bugfix/SKILL.md | 4 ++++ skills/code-clean/SKILL.md | 4 ++++ skills/feat/SKILL.md | 4 ++++ skills/geo/SKILL.md | 7 +++++++ skills/harden/SKILL.md | 7 +++++++ skills/init-project/SKILL.md | 7 +++++++ skills/onboard/SKILL.md | 7 +++++++ skills/seo/SKILL.md | 7 +++++++ skills/ship-feature/SKILL.md | 7 +++++++ skills/tour/SKILL.md | 7 +++++++ skills/web-validate/SKILL.md | 7 +++++++ 12 files changed, 75 insertions(+) diff --git a/skills/audit-delta/SKILL.md b/skills/audit-delta/SKILL.md index 0b2b483..87fabe0 100644 --- a/skills/audit-delta/SKILL.md +++ b/skills/audit-delta/SKILL.md @@ -22,6 +22,13 @@ allowed-tools: # /audit-delta — Incremental multi-axis code audit +## MODEL GATE (blocking — run before any other step) + +Run `$HOME/.claude/lib/model-gate.md`. Reflection here (planning, audit +judgment, loop decisions) requires Fable/Opus. Verdict `small` → STOP: the +gate prints the remedy; end the turn — no later step, no dispatch. Nominal +(big) path is silent. + Audit only what changed since the last run, on the axes the user picks. Per axis: **audit → approval gate → fix → re-verify → marker update**, strictly in that order, one axis fully closed before the next starts. diff --git a/skills/bugfix/SKILL.md b/skills/bugfix/SKILL.md index 21744d2..069d264 100644 --- a/skills/bugfix/SKILL.md +++ b/skills/bugfix/SKILL.md @@ -20,6 +20,10 @@ allowed-tools: - Agent --- +MODEL GATE (blocking): run `$HOME/.claude/lib/model-gate.md` BEFORE loading +the agent below. Verdict `small` → STOP — print the gate's remedy, end the +turn, do not load the agent. + Load and follow strictly: - $HOME/.claude/agents/bugfixer.md diff --git a/skills/code-clean/SKILL.md b/skills/code-clean/SKILL.md index 6175c1a..3aa8778 100644 --- a/skills/code-clean/SKILL.md +++ b/skills/code-clean/SKILL.md @@ -20,6 +20,10 @@ allowed-tools: - AskUserQuestion --- +MODEL GATE (blocking): run `$HOME/.claude/lib/model-gate.md` BEFORE loading +the agent below. Verdict `small` → STOP — print the gate's remedy, end the +turn, do not load the agent. + Load and follow strictly: - $HOME/.claude/agents/code-cleaner.md diff --git a/skills/feat/SKILL.md b/skills/feat/SKILL.md index 9e814d8..3839c80 100644 --- a/skills/feat/SKILL.md +++ b/skills/feat/SKILL.md @@ -20,6 +20,10 @@ allowed-tools: - Agent --- +MODEL GATE (blocking): run `$HOME/.claude/lib/model-gate.md` BEFORE loading +the agent below. Verdict `small` → STOP — print the gate's remedy, end the +turn, do not load the agent. + Load and follow strictly: - $HOME/.claude/agents/feater.md diff --git a/skills/geo/SKILL.md b/skills/geo/SKILL.md index 50773f6..1abc7bc 100644 --- a/skills/geo/SKILL.md +++ b/skills/geo/SKILL.md @@ -22,6 +22,13 @@ allowed-tools: # /geo — GEO (AI-search) audit + fix dispatcher +## MODEL GATE (blocking — run before any other step) + +Run `$HOME/.claude/lib/model-gate.md`. Reflection here (planning, audit +judgment, loop decisions) requires Fable/Opus. Verdict `small` → STOP: the +gate prints the remedy; end the turn — no later step, no dispatch. Nominal +(big) path is silent. + Dispatches the `geo-analyzer` subagent (audit + fix bundle), then applies the bundle from THIS main loop at **L1** — same shape as `/web-validate` and `/seo`. The analyzer never edits files: it emits a `## FIX BUNDLE` diff --git a/skills/harden/SKILL.md b/skills/harden/SKILL.md index b94706d..82da28c 100644 --- a/skills/harden/SKILL.md +++ b/skills/harden/SKILL.md @@ -22,6 +22,13 @@ allowed-tools: # /harden — web hardening audit +## MODEL GATE (blocking — run before any other step) + +Run `$HOME/.claude/lib/model-gate.md`. Reflection here (planning, audit +judgment, loop decisions) requires Fable/Opus. Verdict `small` → STOP: the +gate prints the remedy; end the turn — no later step, no dispatch. Nominal +(big) path is silent. + This skill orchestrates a narrow-scope hardening audit: TLS + security headers + redirects + canonical + custom 404 + server configs. It reuses the `seo-analyzer` agent with a **strict scope filter** to avoid diff --git a/skills/init-project/SKILL.md b/skills/init-project/SKILL.md index a9b39d7..617db97 100644 --- a/skills/init-project/SKILL.md +++ b/skills/init-project/SKILL.md @@ -7,6 +7,13 @@ allowed-tools: Read, Write, Edit, Bash, Grep, Glob # ORCHESTRATOR: INIT PROJECT +## MODEL GATE (blocking — run before any other step) + +Run `$HOME/.claude/lib/model-gate.md`. Reflection here (planning, audit +judgment, loop decisions) requires Fable/Opus. Verdict `small` → STOP: the +gate prints the remedy; end the turn — no later step, no dispatch. Nominal +(big) path is silent. + ## REQUEST $ARGUMENTS diff --git a/skills/onboard/SKILL.md b/skills/onboard/SKILL.md index 3be3c93..bf2caa2 100644 --- a/skills/onboard/SKILL.md +++ b/skills/onboard/SKILL.md @@ -7,6 +7,13 @@ allowed-tools: Read, Write, Edit, Bash, Glob, Grep, Agent, Skill # ORCHESTRATOR: ONBOARD +## MODEL GATE (blocking — run before any other step) + +Run `$HOME/.claude/lib/model-gate.md`. Reflection here (planning, audit +judgment, loop decisions) requires Fable/Opus. Verdict `small` → STOP: the +gate prints the remedy; end the turn — no later step, no dispatch. Nominal +(big) path is silent. + ## REQUEST $ARGUMENTS diff --git a/skills/seo/SKILL.md b/skills/seo/SKILL.md index 00a3421..6a5078d 100644 --- a/skills/seo/SKILL.md +++ b/skills/seo/SKILL.md @@ -23,6 +23,13 @@ allowed-tools: # /seo — parallel SEO + GEO dispatcher +## MODEL GATE (blocking — run before any other step) + +Run `$HOME/.claude/lib/model-gate.md`. Reflection here (planning, audit +judgment, loop decisions) requires Fable/Opus. Verdict `small` → STOP: the +gate prints the remedy; end the turn — no later step, no dispatch. Nominal +(big) path is silent. + This skill orchestrates TWO specialist agents running in parallel, then merges their output into a single `.claude/audits/SEO.md` report. It is the main entry point for any SEO/GEO work on a web project. diff --git a/skills/ship-feature/SKILL.md b/skills/ship-feature/SKILL.md index ec3490e..33ecaaa 100644 --- a/skills/ship-feature/SKILL.md +++ b/skills/ship-feature/SKILL.md @@ -7,6 +7,13 @@ allowed-tools: Read, Write, Edit, Bash, Grep, Glob # ORCHESTRATOR: SHIP FEATURE +## MODEL GATE (blocking — run before any other step) + +Run `$HOME/.claude/lib/model-gate.md`. Reflection here (planning, audit +judgment, loop decisions) requires Fable/Opus. Verdict `small` → STOP: the +gate prints the remedy; end the turn — no later step, no dispatch. Nominal +(big) path is silent. + ## REQUEST $ARGUMENTS diff --git a/skills/tour/SKILL.md b/skills/tour/SKILL.md index ad3b357..1b9870f 100644 --- a/skills/tour/SKILL.md +++ b/skills/tour/SKILL.md @@ -23,6 +23,13 @@ allowed-tools: # /tour — grouped multi-axis sweep (clean + security + reconcile + doc) +## MODEL GATE (blocking — run before any other step) + +Run `$HOME/.claude/lib/model-gate.md`. Reflection here (planning, audit +judgment, loop decisions) requires Fable/Opus. Verdict `small` → STOP: the +gate prints the remedy; end the turn — no later step, no dispatch. Nominal +(big) path is silent. + One pipeline per project: **security → clean → re-verify → reconcile → doc → convergence re-audit**, looping until a full pass applies zero new fixes. Auto mode by design: fixes are committed on a dedicated diff --git a/skills/web-validate/SKILL.md b/skills/web-validate/SKILL.md index 193dc7a..03dc31b 100644 --- a/skills/web-validate/SKILL.md +++ b/skills/web-validate/SKILL.md @@ -21,6 +21,13 @@ allowed-tools: # /web-validate — web standards audit (W3C + WCAG) +## MODEL GATE (blocking — run before any other step) + +Run `$HOME/.claude/lib/model-gate.md`. Reflection here (planning, audit +judgment, loop decisions) requires Fable/Opus. Verdict `small` → STOP: the +gate prints the remedy; end the turn — no later step, no dispatch. Nominal +(big) path is silent. + This skill orchestrates a narrow-scope standards audit : - **W3C HTML validity** — validator.nu API (FULL) or `html-validate` / From 1ed77cb3fbca076cb7b27fad74dbb9618d18a4c6 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 15 Jul 2026 11:16:33 +0200 Subject: [PATCH 06/28] feat(model-routing): pin hotfixer sonnet (executor), un-pin analyzer (inherits session) --- agents/analyzer.md | 1 - agents/hotfixer.md | 1 + 2 files changed, 1 insertion(+), 1 deletion(-) diff --git a/agents/analyzer.md b/agents/analyzer.md index b94d16b..0ce6727 100644 --- a/agents/analyzer.md +++ b/agents/analyzer.md @@ -2,7 +2,6 @@ name: analyzer description: Analyze code, codebase, or problem before any modification. Produces a factual report without proposing solutions. Use proactively before any refactoring, design, or implementation. tools: Read, Grep, Glob, Bash -model: haiku memory: project --- diff --git a/agents/hotfixer.md b/agents/hotfixer.md index 0db2d15..b751e19 100644 --- a/agents/hotfixer.md +++ b/agents/hotfixer.md @@ -2,6 +2,7 @@ name: hotfixer description: Quick-fix executor — dispatched by /hotfix, which owns the routing and gitflow gate. Max 2 files, obvious root cause only (typo, CSS value, config, off-by-one, missing import). tools: Read, Edit, Write, Bash, Grep, Glob, Agent +model: sonnet --- # HOTFIX — Quick Superficial Fix From 56c451ea25b06d5587c475e32c0756ff0b7c3b91 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 15 Jul 2026 11:33:18 +0200 Subject: [PATCH 07/28] =?UTF-8?q?feat(model-routing):=20/feat=20re-archite?= =?UTF-8?q?cture=20=E2=80=94=20reflection=20inline,=20feater=20=3D=20sonne?= =?UTF-8?q?t=20executor=20(partial=20supersede=20BDR-050)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- agents/feater.md | 228 ++++++--------------------------- lib/tests/loops-light.test.sh | 15 +-- lib/verify-secure-loop.md | 14 ++- skills/feat/SKILL.md | 230 ++++++++++++++++++++++++++++++++-- 4 files changed, 272 insertions(+), 215 deletions(-) diff --git a/agents/feater.md b/agents/feater.md index 0faea7f..960f16a 100644 --- a/agents/feater.md +++ b/agents/feater.md @@ -1,204 +1,48 @@ --- name: feater -description: Small-feature implementer (1-5 files) — dispatched by /feat, which owns branching and gates. Light planning, direct implementation, no heavy orchestration. -tools: Read, Edit, Write, Bash, Grep, Glob, Agent +description: Small-feature EXECUTOR — dispatched by /feat with a closed plan + contract. Implements to the letter, tests, reports. No planning, no questions, no commit. +tools: Read, Edit, Write, Bash, Grep, Glob +model: sonnet --- -# FEAT — Small Feature, Fast Track +# FEATER — plan executor -Implement a small, well-scoped feature without the overhead of a -full orchestrator. Direct work, light planning, quick delivery. +You receive a CLOSED plan from the /feat orchestrator. Your job is faithful +execution, not design. The thinking already happened; every choice you would +want to make was either made in the plan or is a NEED-DECISION to report. -## REQUEST -$ARGUMENTS +## INPUT (in the dispatch prompt) ---- +- `CONTRACT`: path to the contract file — read it FIRST; its acceptance + criteria + FILE SCOPE bound everything you do. +- `PLAN`: files + approach + edge cases + tests. +- `BRANCH`: verify with `git branch --show-current`; mismatch → STATUS + BLOCKED — never create or switch branches. +- `GAPS` (re-dispatch only): verifier/security verdict lines — fix ONLY + those, touch nothing else. -## STEP 0 — SCOPE CHECK +## EXECUTION RULES -Before starting, verify this is actually a small feature: +- Follow the plan to the letter. A plan hole or an open choice (naming, + data shape, API surface, dependency) → STOP, report `NEED-DECISION` with + the precise question. Never improvise a design decision. +- Stay inside the contract FILE SCOPE. A needed file outside it → + `NEED-DECISION` (the orchestrator owns scope changes); don't touch it. +- Write tests alongside the code, as the plan names them. Run the relevant + suite incrementally; run it fully before reporting. +- Follow existing code patterns and CLAUDE.md limits (function size, + params, no global state). Match comment density and naming. +- FORBIDDEN: `git commit`, branch ops, push, merge, new dependencies, + editing `.claude/**` or memory registries, user questions (you cannot + ask — report instead), attribution trailers of any kind. + +## OUTPUT — end with exactly this report (your final message) -```bash -git status -git log --oneline -3 ``` - -Read the relevant existing code to understand the context. - -### Decision rules (apply in order — first match wins) - -| Rule | Trigger | Action | -|---|---|---| -| 1 | Estimated diff < 2 files AND no logic (config value, copy fix, missing field) | DOWNGRADE → load `$HOME/.claude/agents/hotfixer.md` | -| 2 | New external dependency (`npm install `, `pip install`, `cargo add`) required | ESCALATE → `/ship-feature` (dep choices need design gate) | -| 3 | New route family / new top-level module / new DB migration | ESCALATE → `/ship-feature` | -| 4 | Estimated diff > 5 files | ESCALATE → `/ship-feature` | -| 5 | User wording is uncertain ("not sure how", "what do you think") | ESCALATE → `/ship-feature` (needs brainstorming) | -| 6 | UI feature on a stack with a design system AND the design toolchain incomplete | Proceed in `/feat`, but flag it in STEP 0.5 design gate | -| 7 | Otherwise | PROCEED in `/feat` | - -### Worked examples - -- "Add `/health` endpoint returning `{status:"ok",version}`" → 1-2 files, no new dep, route added to existing router → **PROCEED**. -- "Add a dark-mode toggle bound to `prefers-color-scheme`" → 2-3 files, design system exists → **PROCEED** (design gate triggers in STEP 0.5). -- "Add OAuth login (Google + GitHub providers)" → new deps, new routes, secrets handling → **ESCALATE** to `/ship-feature`. -- "Show a 'New' badge on items created this week" → 1-2 files, pure UI predicate → **PROCEED**. -- "Fix copy: 'Sign In' → 'Sign in'" in 1 file → **DOWNGRADE** to `/hotfix`. - -Print a one-line scope confirmation (use the rule that fired): +FEAT-EXEC REPORT +STATUS : DONE | NEED-DECISION | BLOCKED +FILES : +TESTS : +NOTES : ``` -FEAT: — rule , ~ files, -``` - -## STEP 0.5 — DESIGN GATE - -Follow `$HOME/.claude/lib/design-gate.md`: -- Scan $ARGUMENTS and target files for design/UI/style signals. -- If signals found → run `design-tool-gate.sh`; if it reports INCOMPLETE, - tell the user to run `/profile design` before proceeding. -- If no signals → skip (zero overhead). - -## STEP 0.6 — MEMORY READ-BEFORE (decisions-first) - -Run the scan per `$HOME/.claude/lib/analyze-before-plan.md`, decisions-weighted: a BDR may -already constrain or forbid the approach; an LRN may name a gotcha to apply. Emit RELATED -MEMORY; feed STEP 1 MINI-PLAN. Inline consumption — reader = planner, no injection. -`.claude/memory/` absent → guarded no-op (zero overhead on a memory-less repo). - -## STEP 0.7 — CONTRACT - -Run `$HOME/.claude/lib/contract-interview.md` (main loop — you are it). It -captures the request verbatim, asks 0-3 questions PROPORTIONAL to ambiguity -(a complete request → zero questions, silent), derives testable acceptance -criteria + file scope, and writes the contract to -`.claude/tasks/contracts/--.md`. Keep the path — GATE 1 -(STEP 3) hands it to a fresh verifier. On a small, clear feature this is a -few seconds and no questions; it is the single reference the verifier judges -against, not a restatement. - -## STEP 1 — MINI-PLAN - -Quick mental model, not a formal plan document: - -1. List the files to create or modify (with line references). -2. Describe the approach in 2-5 bullet points. -3. Note any edge cases to handle. -4. If tests exist for the area, note which tests to add/update. -5. Disposition (from STEP 0.6): name each in-force BDR/LRN this plan honors - (`honors BDR-xxx by …`), or state `no in-force decision constrains this feature`. - A plan with neither = read-then-ignore; the disposition must surface as a trace. - -Print the plan as a compact checklist: -``` -PLAN: - [ ] — - [ ] — - [ ] — -``` - -No gate — proceed directly unless the approach is ambiguous. -If ambiguous: ask the user one focused question, then proceed. - -## STEP 2 — IMPLEMENT - -**Gitflow aiguillage (before editing):** follow `$HOME/.claude/lib/gitflow-aiguillage.md` -— your type = `feature`. On `main`/`develop` it branches first; on a working -branch it's a no-op (commit in place). Never `finish`. - -Work through the plan: - -- Implement directly (no subagents). -- Write tests alongside the code (not after). -- Follow existing patterns in the codebase. -- Run tests incrementally as you go. - -## STEP 3 — VERIFY + SECURE (fresh gates, bounded loops) - -First, your own pre-check (dev-side, fast): run the relevant test suite / -lint / type-check, and if a dev server is relevant note what to check -visually. This is your smoke test, NOT the gate. - -Then run the two fresh gates per `$HOME/.claude/lib/verify-secure-loop.md` -with `CONTRACT` = the STEP 0.7 path, `DIFF` = your working-tree diff, `TEST` -= the suite you just ran: - -- GATE 1 — a FRESH verifier judges the diff against the contract (blind, no - self-score of yours counts). CONFORME on the first pass → straight to GATE - 2, no loop. ECARTS → fix the named gaps, re-verify, max 3 → escalate. -- GATE 2 — a FRESH security-auditor (`MODE: gate`) scans the diff. PASS → - commit. BLOCK → fix, re-verify the request THEN re-scan, max 3 → escalate. - -Nominal (clear request, conform first pass, clean diff) = exactly one -verifier + one security dispatch. The loop only costs when it loops. - -## STEP 4 — COMMIT - -Commit using conventional format: -``` -feat(): - - -``` - -If the feature touched multiple concerns (e.g., feature + config + -test), consider splitting into 2-3 atomic commits — load -`$HOME/.claude/agents/commit-changer.md` and follow its grouping logic. - -Print summary: -``` -FEAT COMPLETE -FEATURE : -FILE(S) : -TEST(S) : -VERIFIED : -``` - -## STEP 5 — DOC SYNC (automatic) - -Load `$HOME/.claude/agents/doc-syncer.md`. -Execute in automatic mode: -`auto-mode scope: ` - -**Then commit the docs** — follow `$HOME/.claude/lib/doc-commit.md`: it surgically commits -ONLY the files doc-syncer patched (its `PATCHED_FILES` output), never `git add -A`, never -`.claude/`/`CLAUDE.md` (rc 4 = a loud BDR-022 anomaly, not a silent skip), and no-ops when -nothing was patched — the common case for a trivial change. No FINISH in an inline flow, so -it just commits the docs on the current branch (no ordering concern). - -## STEP 6 — CAPITALIZE (memory registries) - -A small feature may or may not involve a design choice. Scan the work for: - -- **Non-trivial design choice** (even small: a library pick, a naming convention, a data-model tradeoff) → propose `BDR-XXX` in `.claude/memory/decisions.md` with alternatives considered. -- **Reusable pattern or gotcha encountered** → propose `LRN-XXX` in `.claude/memory/learnings.md`. - -Present the candidates grouped: -``` -CAPITALIZE — proposé - [decisions.md] BDR-XXX — (optionnel) - [learnings.md] LRN-XXX — (optionnel) -Valider ? (all / / edit / skip) -``` - -Always append a 1-line entry to today's heading in `.claude/memory/journal.md`. - -**Language rule**: written entries are ALWAYS in English (see CLAUDE.md "Memory registries" § Language). The interactive gate may mirror the user's language; the appended entries must not. - -If no substantive capture candidate → skip with `CAPITALIZE: nothing to log`. - -**Then commit the memory** — follow `$HOME/.claude/lib/capitalize-commit.md`: it -surgically commits what capitalize just wrote (`.claude/memory` + `.claude/tasks` -only, never `git add -A`) as one `chore(memory)` commit, reports the memory-commit -hash, and no-ops if nothing was written. - ---- - -## RULES -- Max 5 files. If more needed → `/ship-feature`. -- Design gate only (not full plugin check). See STEP 0.5. -- No brainstorm/design phase (if needed → `/ship-feature`). -- No subagents — direct implementation. -- Keep scope tight. If scope creep happens mid-work, stop - and suggest splitting into `/feat` + follow-up task. -- Follow existing code patterns. Don't introduce new patterns - for a small feature. diff --git a/lib/tests/loops-light.test.sh b/lib/tests/loops-light.test.sh index 0e95826..077cc98 100644 --- a/lib/tests/loops-light.test.sh +++ b/lib/tests/loops-light.test.sh @@ -9,7 +9,7 @@ set -u REPO="$(cd "$(dirname "$0")/../.." && pwd)" INC="$REPO/lib/verify-secure-loop.md" -FEA="$REPO/agents/feater.md" +FSK="$REPO/skills/feat/SKILL.md" BUG="$REPO/agents/bugfixer.md" HOT="$REPO/agents/hotfixer.md" HSK="$REPO/skills/hotfix/SKILL.md" @@ -43,12 +43,13 @@ tf "order invariant" "$INC" "always re-checked BEFORE security" tf "mute never a pass (verify)" "$INC" "NEVER a PASS" tf "nominal cheap stated" "$INC" "one verifier dispatch + one security dispatch" -echo "── feater.md (feat wiring) ──" -tf "feat contract step" "$FEA" "STEP 0.7 — CONTRACT" -tf "feat contract-interview" "$FEA" "lib/contract-interview.md" -tf "feat verify+secure step" "$FEA" "STEP 3 — VERIFY + SECURE" -tf "feat uses shared include" "$FEA" "lib/verify-secure-loop.md" -tf "feat nominal 1+1 dispatch" "$FEA" "verifier + one security dispatch" +echo "── feat/SKILL.md (feat orchestrator wiring) ──" +tf "feat contract step" "$FSK" "STEP 0.7 — CONTRACT" +tf "feat contract-interview" "$FSK" "lib/contract-interview.md" +tf "feat verify+secure step" "$FSK" "STEP 4 — VERIFY + SECURE" +tf "feat uses shared include" "$FSK" "lib/verify-secure-loop.md" +tf "feat nominal 1+1 dispatch" "$FSK" "verifier + one security dispatch" +tf "feat dispatches feater" "$FSK" 'subagent_type="feater"' echo "── bugfixer.md (bugfix wiring) ──" tf "bug contract step" "$BUG" "STEP 3.5 — CONTRACT" diff --git a/lib/verify-secure-loop.md b/lib/verify-secure-loop.md index 862dfa8..ed3e682 100644 --- a/lib/verify-secure-loop.md +++ b/lib/verify-secure-loop.md @@ -2,8 +2,11 @@ Runs in the ORCHESTRATOR MAIN LOOP after the dev step completes. Turns a finished diff into a verified, security-cleared change through two fresh -gates and bounded loops. The dev stays inline (LRN-083: subagents = -execution + report; loop decisions live here, in the main loop). +gates and bounded loops. Loop decisions live here, in the main loop +(LRN-083: subagents = execution + report). The dev step is either inline +(bugfix) or a dispatched sonnet executor (/feat's feater): "hand the dev" +below means fix inline, or re-dispatch a FRESH executor with exactly those +inputs. Inputs the caller must have ready: - `CONTRACT`: path to the contract file written by `contract-interview.md`. @@ -25,7 +28,8 @@ Parse its single `VERIFY — VERDICT:` line: - `CONFORME` → go to GATE 2. (First-pass conforme = no loop.) - `ECARTS(n)` → hand the dev the CONTRACT path + the exact `CRITERIA` gap - lines (NOT-MET / out-of-scope), nothing else. Dev fixes inline, then + lines (NOT-MET / out-of-scope), nothing else. Inline dev fixes in place; + a dispatched dev is re-dispatched FRESH with those inputs only. Then re-dispatch a FRESH verifier. Repeat. **Max 3 conformity iterations** → STOP + human escalation with the CRITERIA table (the contract-vs-realized diff). @@ -49,8 +53,8 @@ stdout-only, no Write). Parse its single `SECURITY — VERDICT:` line: - `PASS` → done, proceed to commit. -- `BLOCK(n)` → hand the dev the `BLOCKING` list + the CONTRACT path. Dev - fixes inline. Then **re-verify the REQUEST first** (GATE 1, fresh +- `BLOCK(n)` → hand the dev the `BLOCKING` list + the CONTRACT path (inline + fix, or FRESH executor re-dispatch). Then **re-verify the REQUEST first** (GATE 1, fresh verifier) — a security fix can drift the behavior — **then re-run GATE 2** (fresh auditor), in that order. **Max 3 security iterations** → STOP + human escalation with the BLOCKING table. diff --git a/skills/feat/SKILL.md b/skills/feat/SKILL.md index 3839c80..dd8dac0 100644 --- a/skills/feat/SKILL.md +++ b/skills/feat/SKILL.md @@ -1,10 +1,10 @@ --- name: feat description: | - Small feature implementation (1-5 files). Light planning, direct - implementation, no heavy orchestration. For features that don't - need the full /ship-feature pipeline (no design brainstorm, no - subagents, no plugin check gate). + Small feature implementation (1-5 files). Reflection inline (scope, + plan, contract — session model), execution dispatched to the + sonnet-pinned feater executor. For features that don't need the full + /ship-feature pipeline (no design brainstorm, no plugin check gate). Trigger: "feat", "small feature", "add this", "petite feature", "quick feature", "ajoute ca", "implement this small thing". For multi-file features needing design → use /ship-feature. @@ -20,13 +20,221 @@ allowed-tools: - Agent --- -MODEL GATE (blocking): run `$HOME/.claude/lib/model-gate.md` BEFORE loading -the agent below. Verdict `small` → STOP — print the gate's remedy, end the -turn, do not load the agent. +# /feat — small-feature orchestrator (reflection inline, execution dispatched) -Load and follow strictly: -- $HOME/.claude/agents/feater.md - -Execute the FEATER agent on the following target: +MODEL GATE (blocking): run `$HOME/.claude/lib/model-gate.md` BEFORE any +step below. Verdict `small` → STOP — print the gate's remedy, end the +turn, dispatch nothing. +## REQUEST $ARGUMENTS + +--- + +## STEP 0 — SCOPE CHECK + +Before starting, verify this is actually a small feature: + +```bash +git status +git log --oneline -3 +``` + +Read the relevant existing code to understand the context. + +### Decision rules (apply in order — first match wins) + +| Rule | Trigger | Action | +|---|---|---| +| 1 | Estimated diff < 2 files AND no logic (config value, copy fix, missing field) | DOWNGRADE → load `$HOME/.claude/agents/hotfixer.md` | +| 2 | New external dependency (`npm install `, `pip install`, `cargo add`) required | ESCALATE → `/ship-feature` (dep choices need design gate) | +| 3 | New route family / new top-level module / new DB migration | ESCALATE → `/ship-feature` | +| 4 | Estimated diff > 5 files | ESCALATE → `/ship-feature` | +| 5 | User wording is uncertain ("not sure how", "what do you think") | ESCALATE → `/ship-feature` (needs brainstorming) | +| 6 | UI feature on a stack with a design system AND the design toolchain incomplete | Proceed in `/feat`, but flag it in STEP 0.5 design gate | +| 7 | Otherwise | PROCEED in `/feat` | + +### Worked examples + +- "Add `/health` endpoint returning `{status:"ok",version}`" → 1-2 files, no new dep, route added to existing router → **PROCEED**. +- "Add a dark-mode toggle bound to `prefers-color-scheme`" → 2-3 files, design system exists → **PROCEED** (design gate triggers in STEP 0.5). +- "Add OAuth login (Google + GitHub providers)" → new deps, new routes, secrets handling → **ESCALATE** to `/ship-feature`. +- "Show a 'New' badge on items created this week" → 1-2 files, pure UI predicate → **PROCEED**. +- "Fix copy: 'Sign In' → 'Sign in'" in 1 file → **DOWNGRADE** to `/hotfix`. + +Print a one-line scope confirmation (use the rule that fired): +``` +FEAT: — rule , ~ files, +``` + +## STEP 0.5 — DESIGN GATE + +Follow `$HOME/.claude/lib/design-gate.md`: +- Scan $ARGUMENTS and target files for design/UI/style signals. +- If signals found → run `design-tool-gate.sh`; if it reports INCOMPLETE, + tell the user to run `/profile design` before proceeding. +- If no signals → skip (zero overhead). + +## STEP 0.6 — MEMORY READ-BEFORE (decisions-first) + +Run the scan per `$HOME/.claude/lib/analyze-before-plan.md`, decisions-weighted: a BDR may +already constrain or forbid the approach; an LRN may name a gotcha to apply. Emit RELATED +MEMORY; feed STEP 1 PLAN. Inline consumption — reader = planner, no injection. +`.claude/memory/` absent → guarded no-op (zero overhead on a memory-less repo). + +## STEP 0.7 — CONTRACT + +Run `$HOME/.claude/lib/contract-interview.md` (main loop — you are it). It +captures the request verbatim, asks 0-3 questions PROPORTIONAL to ambiguity +(a complete request → zero questions, silent), derives testable acceptance +criteria + file scope, and writes the contract to +`.claude/tasks/contracts/--.md`. Keep the path — the +executor reads it first and GATE 1 (STEP 4) hands it to a fresh verifier. + +## STEP 1 — PLAN (dispatch-ready) + +The executor follows this plan to the letter and CANNOT ask questions — +close every decision here: + +1. Files to create or modify (with line references). +2. Approach in 2-5 bullets — name every choice (naming, data shape, API + surface); an open choice left here comes back as a NEED-DECISION + round-trip. +3. Edge cases to handle. +4. Tests to add/update (exact files). +5. Disposition (from STEP 0.6): name each in-force BDR/LRN this plan honors + (`honors BDR-xxx by …`), or state `no in-force decision constrains this feature`. + A plan with neither = read-then-ignore; the disposition must surface as a trace. + +Print the plan as a compact checklist: +``` +PLAN: + [ ] — + [ ] — + [ ] — +``` + +If the approach is ambiguous: ask the user ONE focused question BEFORE +dispatching — never after (the executor cannot relay questions). + +## STEP 2 — BRANCH + +**Gitflow aiguillage (before dispatch):** follow `$HOME/.claude/lib/gitflow-aiguillage.md` +— your type = `feature`. On `main`/`develop` it branches first; on a working +branch it's a no-op (commit in place). Never `finish`. + +## STEP 3 — DISPATCH EXECUTOR + +Dispatch the executor — sonnet by frontmatter pin, do not override: + +``` +Agent(subagent_type="feater") +prompt: "CONTRACT: +PLAN: +BRANCH: +Implement the plan to the letter. Tests alongside code. No commit, no +branch ops, no new dependencies, no files outside the contract FILE SCOPE. +Finish with the FEAT-EXEC REPORT." +``` + +Parse the `FEAT-EXEC REPORT`: +- `STATUS : DONE` → STEP 4. +- `STATUS : NEED-DECISION` → make the decision HERE (that is reflection), + append it to the plan, re-dispatch a FRESH feater with plan + decision. + Max 2 decision round-trips → escalate to the user. +- `STATUS : BLOCKED` → surface the blocker to the user, stop. + +## STEP 4 — VERIFY + SECURE (fresh gates, bounded loops) + +Run the two fresh gates per `$HOME/.claude/lib/verify-secure-loop.md` with +`CONTRACT` = the STEP 0.7 path, `DIFF` = the working-tree diff the executor +produced, `TEST` = the suite named in its report: + +- GATE 1 — a FRESH verifier judges the diff against the contract (blind). + CONFORME on the first pass → straight to GATE 2, no loop. ECARTS → the + "dev" of the loop is the dispatched executor: re-dispatch a FRESH feater + with the CONTRACT path + the exact gap lines, nothing else. Max 3 → + escalate. +- GATE 2 — a FRESH security-auditor (`MODE: gate`) scans the diff. PASS → + STEP 5. BLOCK → re-dispatch a FRESH feater with the BLOCKING list + the + CONTRACT path; re-verify the request THEN re-scan, max 3 → escalate. + +Loop decisions stay HERE, in the main loop (LRN-083). Nominal (clear +request, conform first pass, clean diff) = one executor + one +verifier + one security dispatch. + +## STEP 5 — COMMIT + +Commit using conventional format: +``` +feat(): + + +``` + +If the feature touched multiple concerns (e.g., feature + config + +test), consider splitting into 2-3 atomic commits — load +`$HOME/.claude/agents/commit-changer.md` and follow its grouping logic. + +Print summary: +``` +FEAT COMPLETE +FEATURE : +FILE(S) : +TEST(S) : +VERIFIED : +``` + +## STEP 6 — DOC SYNC (automatic) + +Load `$HOME/.claude/agents/doc-syncer.md`. +Execute in automatic mode: +`auto-mode scope: ` + +**Then commit the docs** — follow `$HOME/.claude/lib/doc-commit.md`: it surgically commits +ONLY the files doc-syncer patched (its `PATCHED_FILES` output), never `git add -A`, never +`.claude/`/`CLAUDE.md` (rc 4 = a loud BDR-022 anomaly, not a silent skip), and no-ops when +nothing was patched — the common case for a trivial change. No FINISH in an inline flow, so +it just commits the docs on the current branch (no ordering concern). + +## STEP 7 — CAPITALIZE (memory registries) + +A small feature may or may not involve a design choice. Scan the work for: + +- **Non-trivial design choice** (even small: a library pick, a naming convention, a data-model tradeoff) → propose `BDR-XXX` in `.claude/memory/decisions.md` with alternatives considered. +- **Reusable pattern or gotcha encountered** → propose `LRN-XXX` in `.claude/memory/learnings.md`. + +Present the candidates grouped: +``` +CAPITALIZE — proposé + [decisions.md] BDR-XXX — (optionnel) + [learnings.md] LRN-XXX — (optionnel) +Valider ? (all / / edit / skip) +``` + +Always append a 1-line entry to today's heading in `.claude/memory/journal.md`. + +**Language rule**: written entries are ALWAYS in English (see CLAUDE.md "Memory registries" § Language). The interactive gate may mirror the user's language; the appended entries must not. + +If no substantive capture candidate → skip with `CAPITALIZE: nothing to log`. + +**Then commit the memory** — follow `$HOME/.claude/lib/capitalize-commit.md`: it +surgically commits what capitalize just wrote (`.claude/memory` + `.claude/tasks` +only, never `git add -A`) as one `chore(memory)` commit, reports the memory-commit +hash, and no-ops if nothing was written. + +--- + +## RULES +- Max 5 files. If more needed → `/ship-feature`. +- Reflection (scope, plan, contract, loop decisions) NEVER leaves this main + loop; execution NEVER stays in it — the executor is the sonnet-pinned + feater subagent (BDR-066). +- The executor is dispatched FRESH on every round-trip — feedback travels + as contract path + named gaps/decisions, never as transcript. +- Design gate only (not full plugin check). See STEP 0.5. +- No brainstorm/design phase (if needed → `/ship-feature`). +- Keep scope tight. If scope creep happens mid-work, stop + and suggest splitting into `/feat` + follow-up task. +- Follow existing code patterns. Don't introduce new patterns + for a small feature. From 0fbe3103cb96e7fc6a6bd6713a3e3bf30722788f Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 15 Jul 2026 11:40:42 +0200 Subject: [PATCH 08/28] feat(model-routing): SDD implementation + review subagents dispatched model sonnet --- skills/init-project/SKILL.md | 6 ++++++ skills/ship-feature/SKILL.md | 6 ++++++ 2 files changed, 12 insertions(+) diff --git a/skills/init-project/SKILL.md b/skills/init-project/SKILL.md index 617db97..2ad6a2d 100644 --- a/skills/init-project/SKILL.md +++ b/skills/init-project/SKILL.md @@ -176,6 +176,12 @@ Invoke `superpowers:subagent-driven-development` for the per-task implement loop `gitflow finish` (STEP 11). When SDD's flow reaches "Use finishing-a-development-branch", stop and return. +**Model routing (BDR-066):** every subagent dispatched under SDD — per-task +implementers AND its reviewers — MUST carry `model: "sonnet"` in the Agent +call. The plan is closed; execution and plan-conformity review are sonnet +work. Reflection (task decomposition, review verdict arbitration) stays in +this loop. + ## STEP 8b — GRAPHIFY FULL (after implementation) If `graphify` CLI is installed AND complexity >= 30%: 1. Run full graphify on the implemented project: diff --git a/skills/ship-feature/SKILL.md b/skills/ship-feature/SKILL.md index 33ecaaa..e74ba24 100644 --- a/skills/ship-feature/SKILL.md +++ b/skills/ship-feature/SKILL.md @@ -154,6 +154,12 @@ Invoke `superpowers:subagent-driven-development` for the per-task implement loop `gitflow finish` (STEP 9). When SDD's flow reaches "Use finishing-a-development-branch", stop and return. +**Model routing (BDR-066):** every subagent dispatched under SDD — per-task +implementers AND its reviewers — MUST carry `model: "sonnet"` in the Agent +call. The plan is closed; execution and plan-conformity review are sonnet +work. Reflection (task decomposition, review verdict arbitration) stays in +this loop. + ## STEP 4b — ERROR RECOVERY (if STEP 4 fails) If a subagent returns a build error, failing test, or type error: 1. Load `$HOME/.claude/agents/analyzer.md` in DEBUG MODE on the exact error output. From e955c4d0506dc0625ef9cda5e40ae48bba3f932a Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 15 Jul 2026 11:44:53 +0200 Subject: [PATCH 09/28] feat(model-routing): web-validate fix bundle applied via hotfixer at L1 (BDR-061 alignment) --- skills/web-validate/SKILL.md | 21 +++++++++++++++++---- 1 file changed, 17 insertions(+), 4 deletions(-) diff --git a/skills/web-validate/SKILL.md b/skills/web-validate/SKILL.md index 03dc31b..2664aed 100644 --- a/skills/web-validate/SKILL.md +++ b/skills/web-validate/SKILL.md @@ -278,10 +278,23 @@ Options : D) Abort — keep .claude/audits/VALIDATE.md as audit report ``` -4. On `A` : apply each bundle via `Edit` (targeted `old_string` / - `new_string`). Never use `Write` on shared templates (risk of - overwriting /seo or /geo content — meta tags, JSON-LD). -5. On `B` : for each diff, show and ask yes/no/skip. +4. On `A` : dispatch each file-group's applier at L1 (execution = sonnet; + this loop only orchestrates), serially — one applier at a time, appliers + share files: + + ``` + Agent(subagent_type="hotfixer") + prompt: ". + Context: web-validate fix bundle, user-approved scope — no + confirmation needed. Apply via targeted Edit (old_string/new_string); + NEVER Write whole files (shared templates carry /seo and /geo + content — meta tags, JSON-LD). Do NOT commit — apply and self-verify + only." + ``` + +5. On `B` : for each diff, show and ask yes/no/skip; apply approved diffs + as in `A` (hotfixer dispatch). 6. On `C` : filter to Critique + Haute, then behave as `A`. 7. On `D` : stop, leave `.claude/audits/VALIDATE.md` untouched. From bd5a603567c5542f88b6648c2e5e09125099eb7c Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 15 Jul 2026 11:49:59 +0200 Subject: [PATCH 10/28] =?UTF-8?q?test(model-routing):=20census=20guard=20?= =?UTF-8?q?=E2=80=94=20gate=20wiring,=20pins,=20executor=20shape=20(flip-t?= =?UTF-8?q?ested)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- lib/tests/model-routing.test.sh | 37 +++++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) create mode 100755 lib/tests/model-routing.test.sh diff --git a/lib/tests/model-routing.test.sh b/lib/tests/model-routing.test.sh new file mode 100755 index 0000000..9c96b5c --- /dev/null +++ b/lib/tests/model-routing.test.sh @@ -0,0 +1,37 @@ +#!/usr/bin/env bash +# lib/tests/model-routing.test.sh — census: gate wiring + pins + executor shape (BDR-066) +set -u +R="$(cd "$(dirname "$0")/../.." && pwd)" +pass=0; fail=0 +ok() { pass=$((pass+1)); } +ko() { fail=$((fail+1)); printf 'FAIL %s\n' "$1"; } +has() { if grep -qF "$2" "$R/$1"; then ok; else ko "$1 missing: $2"; fi; } +lacks() { if grep -qF "$2" "$R/$1"; then ko "$1 must NOT contain: $2"; else ok; fi; } +fm_lacks() { if awk 'NR<=10' "$R/$1" | grep -qF "$2"; then ko "$1 frontmatter must NOT contain: $2"; else ok; fi; } + +# 1) gate wired in the 12 reflection orchestrators +for s in ship-feature init-project feat bugfix onboard seo geo web-validate harden audit-delta tour code-clean; do + has "skills/$s/SKILL.md" 'lib/model-gate.md' +done +# 2) gate NOT wired in the excluded skills (encodes the spec exclusion list) +for s in hotfix commit-change doc status release-candidate; do + lacks "skills/$s/SKILL.md" 'lib/model-gate.md' +done +# 3) executor + gate pins +has "agents/feater.md" 'model: sonnet' +has "agents/hotfixer.md" 'model: sonnet' +has "agents/verifier.md" 'model: sonnet' +has "agents/security-auditor.md" 'model: sonnet' +fm_lacks "agents/analyzer.md" 'model:' +# 4) /feat executor shape +has "skills/feat/SKILL.md" 'subagent_type="feater"' +has "skills/feat/SKILL.md" 'verify-secure-loop.md' +lacks "agents/feater.md" 'AskUserQuestion' +# 5) SDD execution pinned +has "skills/ship-feature/SKILL.md" 'model: "sonnet"' +has "skills/init-project/SKILL.md" 'model: "sonnet"' +# 6) web-validate applies via L1 applier +has "skills/web-validate/SKILL.md" 'subagent_type="hotfixer"' + +printf 'model-routing census: %d pass, %d fail\n' "$pass" "$fail" +[ "$fail" -eq 0 ] From 97088fe59b23a9f3e449741ac2ea7f6e39873e25 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 15 Jul 2026 11:54:54 +0200 Subject: [PATCH 11/28] docs(model-routing): README agent-model table + CHANGELOG entry --- CHANGELOG.md | 5 +++++ README.md | 16 ++++++++++++++++ 2 files changed, 21 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index b537bd1..5180fb3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -12,6 +12,9 @@ Format follows [Keep a Changelog](https://keepachangelog.com/). - `/deploy` checklist reshaped on first-real-run feedback, in two passes: runbook steps are **one command per line, interactive-session style** (an early step opens the ssh session; later lines run on the box; local steps say "from your machine") instead of folded `ssh host "cd … && …"` one-liners — step = comment header + command lines up to the next blank line, a `@delta:` directive governs the whole block; and the checklist is now **display-only** — `NEXT.sh` is no longer written at all (throwaway artifact; `PENDING.json` + the live runbook regenerate it in any session) and every hand-back **ends the turn with the full checklist as the final text, no tool call after it** (a checklist printed above a blocking question tool was observed never reaching the user). Template `templates/deploy/PROCEDURE.md` restyled to match. - `settings.json`: `inputNeededNotifEnabled: true` adopted (harness notification toggle); committed layout otherwise unchanged. - gsd-pi upgraded 2.64.0 → 3.0.0 — `status-reporter` output parser adapted to the ADR-013 cutover. +- `hotfixer` pinned `model: sonnet` (seo/geo/web-validate L1 applier); `analyzer` haiku pin removed (inherits the session model). +- ship-feature / init-project: SDD implementation + review subagents dispatched with `model: "sonnet"`. +- web-validate `--fix`: bundle applied via `hotfixer` at L1 instead of inline Edit (BDR-061 alignment). ### Security - **Magic MCP fully ask-gated** — all four `mcp__magic__*` tools (builder, refiner, inspiration, logo_search) moved to `permissions.ask` in `settings.json`; no magic call can auto-execute. The builder opens an unauthenticated local callback server (`127.0.0.1:9221+`, `Access-Control-Allow-Origin: *`, no token check) whose POST body is injected verbatim into the tool result the model consumes — the ask-gate is the mitigation on our side (BDR-059). @@ -23,6 +26,8 @@ Format follows [Keep a Changelog](https://keepachangelog.com/). - **GSC + CrUX data layer for `/seo` FULL** — `lib/seo-data/` engine pulls real Google Search Console (Search Analytics + URL Inspection) and Chrome UX Report field data into the `/seo` FULL audit: CrUX p75 field metrics become the primary Core Web Vitals signal (anonymous PageSpeed lab stays the fallback), and a "Performance GSC (90 j)" section flags position 4-10 quick wins. Multi-account via OAuth2 (`make seo-connect`, one-time consent, `webmasters.readonly` scope only) with a per-label token store (0600 file / 0700 dir, atomic write, refresh tokens redacted, gitleaks-allowlisted) so two concurrent site audits never conflict. Absent credentials degrade gracefully to anonymous PageSpeed — the audit never fails. Config: `GOOGLE_OAUTH_CLIENT_ID` / `GOOGLE_OAUTH_CLIENT_SECRET` / `CRUX_API_KEY` in `~/.claude/.env`. Engine contract documented in `lib/seo-data/README.md`. - **impeccable** (pbakaus, Apache-2.0) wired into the toolchain as the design counterpart of semgrep: the `/impeccable` skill (23 verbs under one command: audit, polish, bolder, quieter…) plus the 45-rule deterministic anti-pattern detector (`npx impeccable detect`, exit 0/2, `--json`). Complementary to `frontend-design` (kept — aesthetic direction at build time); impeccable adds the deterministic audit floor and per-project design context (`/impeccable init`). CLI pinned in `plugins.lock.json` (3.2.0 — a silent rules update would change audit output on unchanged code); dist is machine-owned under `skills-external/impeccable/` (gitignored, ctx7 pattern), staged-installed by `install-plugins.sh` Step 8d, refreshed pin-honored by `update-all.sh`, symlinked by `link.sh`, listed in the design/web/web-full/full profiles and the design-work routing. Requires Node ≥ 24: the install baseline is bumped from 22 to 24 LTS (NodeSource `setup_24.x` / brew `node@24`), so `make plugin` upgrades a too-old host in place; the impeccable steps still skip gracefully if Node stays below 24. Not in the design gate's GATE-BLOCK list yet — promotion deliberate, after first dogfood. - `/tour` skill — grouped all-axes sweep over one or several projects: security (pinned-semgrep `security-auditor` agent + `/cso` posture when gstack is ON) → cleanup → re-verify → reconcile (report-only, never edits the target TODO/registries) → doc sync, looping until a full pass applies zero fixes (bounded at 3 iterations). Fixes land on a `chore/tour-` branch the skill never merges; each project gets an append-only `.claude/audits/TOUR.md` report with BREAKING tags on contract-changing security fixes. Built TDD (superpowers:writing-skills): baseline run showed silent TODO rewrites, autonomous registry writes, grep-as-security-pass, no persistent report, scope creep and an unbounded loop — each countered and verified on a seeded fixture. +- Model routing (BDR-066): blocking model gate (`lib/model-gate.md` + `lib/model-check.sh`, flip-tested) wired into 12 reflection orchestrators; census guard `lib/tests/model-routing.test.sh`. +- `/feat` re-architected: reflection inline (scope/plan/contract), execution dispatched to the sonnet-pinned `feater` executor; verify+secure loop decided in the main loop with fresh executor re-dispatches. ### Removed - `lib/detect-plugins.sh`: `detect_security_guidance` — dead since its re-add at `45c3507`; zero callers on any surface, including the dynamic `session-start.sh` detection loop (the banner's row derives from `enabledPlugins` instead). Nothing invokes it — removal, not a breaking change. diff --git a/README.md b/README.md index f07f479..d9dc4f0 100644 --- a/README.md +++ b/README.md @@ -37,6 +37,22 @@ claude-config/ - `templates/` = symlinked to `~/.claude/templates/` — copy into projects via `/onboard` or manually - **Graphify** builds a knowledge graph of any codebase (`/graphify query`), producing a navigable wiki in `graphify-out/wiki/`. This map helps Claude understand project structure, find relevant code faster, and reason across files. Essential for large-scope tasks (multi-file features, complex bugs, architectural changes). Small tasks should skip it and read files directly. +### Agent model routing (BDR-066) + +Reflection (brainstorm, plan, contract, audit judgment, loop decisions) runs +INLINE on the session model — assumed Fable/Opus, enforced by a blocking +gate (`lib/model-gate.md` + `lib/model-check.sh`) at the entry of the 12 +reflection orchestrators. Execution runs on pinned subagents: + +| Agent | Model | Tier | +|---|---|---| +| feater, hotfixer | sonnet (pinned) | executors — code from a closed plan, fix-bundle appliers | +| verifier, security-auditor | sonnet (pinned) | fresh gates (≤3×/loop) | +| doc-syncer, onboarder, scaffolder, refactorer, interviewer, plugin-advisor | sonnet (pinned) | workers | +| status-reporter | haiku (pinned) | mechanical collector | +| client-handover-writer | opus (pinned, currently inert — inline-loaded; sonnet conversion planned) | deliverable writer | +| analyzer, seo-analyzer, geo-analyzer, validator-analyzer, code-cleaner, bugfixer, commit-changer | inherit session (Fable/Opus) | reflection / audit / inline playbooks | + --- ## Fresh install (new machine) From 2ad712cfd4539f870c87b38a8bb1dfc1fbfb16ba Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 15 Jul 2026 12:01:14 +0200 Subject: [PATCH 12/28] chore(memory): BDR-066 model routing + journal + TODO follow-ups --- .claude/memory/decisions.md | 14 ++++++++++++++ .claude/memory/journal.md | 3 +++ .claude/tasks/TODO.md | 16 ++++++++++++++++ 3 files changed, 33 insertions(+) diff --git a/.claude/memory/decisions.md b/.claude/memory/decisions.md index 011f854..07bf919 100644 --- a/.claude/memory/decisions.md +++ b/.claude/memory/decisions.md @@ -86,6 +86,7 @@ rules: | BDR-063 | 2026-07-10 | GSC multi-account: OAuth2 installed-app flow + label-keyed token store, explicit (account,property) args, no global state | accepted | | BDR-064 | 2026-07-14 | global memory split: repo file → CLAUDE.global.md (deployed name unchanged), CLAUDE.md freed for project scope; consumer/maintainer wording rule | accepted | | BDR-065 | 2026-07-14 | transient planning artifacts (superpowers spec/plan): committed during run, deleted post-merge; git history = archive; codified in project CLAUDE.md | accepted | +| BDR-066 | 2026-07-15 | Model routing: reflection inline (session big model) + sonnet-pinned executors + blocking gate | accepted | --- @@ -975,3 +976,16 @@ rules: - **Why**: user call 2026-07-14 — registries already capture decisions; a stale plan describes a superseded intermediate state and misleads future readers; accumulation pollutes the repo. Precedent: gsc-crux cleanup (8a1fac0, 2026-07-10) did the same — this makes it law, not habit. - **Alternatives rejected**: never-commit (gitignore docs/superpowers) — breaks mid-run: briefs, reviewers, other-machine checkouts need the files; superpowers brainstorming commits the spec by convention. Keep-forever — the drift + pollution complained about. - **Reference**: project CLAUDE.md; cleanup commit this chore; precedent 8a1fac0. Linked [[BDR-064]], [[LRN-124]]. + +--- + +## BDR-066 — Model routing: reflection inline (session big model), executors pinned sonnet, blocking gate + +- **Date**: 2026-07-15 +- **Status**: accepted (partial supersede of BDR-050: /feat dev no longer inline; bugfix/hotfix dev-inline CONSERVED) +- **Decision**: reflection (brainstorm, plan, contract, audit judgment, loop decisions) runs on session model (Fable; Opus fallback) — inline or inherit subagents, never pinned down. Execution (code from closed plan, fix-bundle application) runs sonnet-pinned subagents: feater + hotfixer pinned sonnet; SDD implementation+review subagents dispatched `model: "sonnet"` (ship-feature/init-project); web-validate fixes via hotfixer L1 (was inline Edit). analyzer haiku pin REMOVED (digest feeds plan = reflection tier). verifier + security-auditor STAY sonnet (job9 confirmed — procedural gates, ≤3×/loop). Blocking gate `lib/model-gate.md` (self-check + witness `lib/model-check.sh`) wired in 12 reflection orchestrators; small → STOP, unknown → fail-visible; census guard `lib/tests/model-routing.test.sh` flip-tested. +- **Why**: big-model quota burned on mechanical execution (Fable exhausted mid-job8); plan closed at dispatch → executor needs obedience not judgment; fresh sonnet gates catch executor drift. +- **Alternatives rejected**: opus pins on audit agents (session-independent) — rejected: session assumed big + blocking gate as backstop, one tier fewer; advisory gate — rejected by user, blocking; split bugfix/hotfix too — rejected: bugfix investigation interleaved w/ fix, hotfix gain marginal vs dispatch overhead. +- **Caveats**: client-handover-writer conversion (inline-load → sonnet dispatch, 11 human-gate sites to relocate) DEFERRED to own plan — its opus pin stays inert meanwhile; feater cannot ask → NEED-DECISION report = escalation valve, plan must close decisions; witness reads settings.json — lags `--model`-launched sessions (self-check compensates). +- **Caveat (execution)**: /feat re-arch broke 5 stale assertions in lib/tests/loops-light.test.sh (locked OLD feater architecture) — repointed to skills/feat/SKILL.md (FSK, mirrors HOT/HSK split) + new dispatch lock + 1-line reflow in feat SKILL for single-line grep lock (LRN-093 class). +- **Reference**: spec `docs/superpowers/specs/2026-07-15-model-routing-design.md` + plan `docs/superpowers/plans/2026-07-15-model-routing.md` (transient, BDR-065 lifecycle), branch `feature/model-routing`. diff --git a/.claude/memory/journal.md b/.claude/memory/journal.md index b35b827..20a9d57 100644 --- a/.claude/memory/journal.md +++ b/.claude/memory/journal.md @@ -381,3 +381,6 @@ rules: ## 2026-07-14 - `/ship-feature` feature/claude-global-md-rename (unmerged, human GO pending): global memory → CLAUDE.global.md + project-scope CLAUDE.md, 8 commits (a4ee7e1 docs → e9a38a0 guards). Full pipeline: analyzer + contract (17 criteria), brainstorm/spec/plan gates, SDD 5 tasks (all task reviews Approved), verifier CONFORME 17/17 (after user-arbitrated criterion-9 consumer-wording + FILE-SCOPE [gated] enrichment), security PASS (semgrep 43 rules, 0), final review "Yes" after 2 Important fixes (guard-test drift → 7/7; doctor exact-target check). Decided [[BDR-064]]; learned [[LRN-122]] (2-commit rename split), [[LRN-123]] (exact symlink target). `make test` green throughout. settings.json plugin toggles = session-scoped, NOT committed — restore (gstack/ui-ux-pro-max/frontend-design/emil-design-eng/darwin-skill/magic ON) after merge. - Merges to develop: feature/claude-global-md-rename (2d54df5), chore/untrack-audit-reports (d557ee9), chore/post-merge-cleanup. /cso triage: 75 gitleaks findings → 0 real (60 git SHAs vs sourcegraph rule; gitflow-test AWS fixture; expired GitHub image JWT; presigned-URL key ids; doc placeholders; job7-purged artifacts). .gitleaks.toml → [[allowlists]] format + 8 targeted entries; `make scan-secrets` green 0+0. Makefile "safe to commit" hint root-caused → [[LRN-124]]. Transient spec+plan deleted per [[BDR-065]] (user decree, gsc-crux precedent). Mid-merge discovery: user commit 5842119 (gitignore `.audit/` + model pin fable-5) — explains the .audit-in-diff question. cso report: .gstack/security-reports/2026-07-14-secrets-triage.json. + +## 2026-07-15 +- model routing shipped on feature/model-routing: BDR-066 (reflection inline big / executors sonnet / blocking gate), /feat re-arch, census guard. client-handover conversion deferred to plan 2. diff --git a/.claude/tasks/TODO.md b/.claude/tasks/TODO.md index c3550de..e6cda75 100644 --- a/.claude/tasks/TODO.md +++ b/.claude/tasks/TODO.md @@ -1,5 +1,21 @@ # TODO +## 2026-07-15 — model routing (feature/model-routing) +Spec + plan in docs/superpowers/ (transient, BDR-065). BDR-066. Branch +unmerged — human gate. +- [x] gate lib/model-check.sh + lib/model-gate.md (flip-tested) wired ×12 +- [x] pins: hotfixer/feater sonnet, analyzer un-pinned; SDD model:"sonnet"; + web-validate → hotfixer L1; census guard model-routing.test.sh +- [x] /feat re-arch: reflection inline → feater sonnet executor (partial + supersede BDR-050) +- [ ] DOGFOOD (manual, next sessions): /feat live run — plan closes + decisions, dispatch carries sonnet, verify loop in main loop; gate + STOP on a sonnet session (LRN-079 class, not automatable here) +- [ ] PLAN 2 — client-handover conversion (spec §5): inline-load → sonnet + dispatch, relocate 11 human-gate sites to dispatcher (inventory in + plan-1 session), or lighter variant: dispatch only the redaction + phase. Decide shape at plan time. + ## 2026-07-08 — full back-merge release/1.0.0→develop (chore/backmerge-release-full) Genèse : la revue avait porté ~5/19 commits ; back-merge complet demandé. Cherry-pick par catégorie, 1 commit atomique/item, make test après chaque code. Branche non mergée (gate humain). From 89093a7835bc30cf7c4ff043b0f6a1b1d35c755f Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 15 Jul 2026 12:34:20 +0200 Subject: [PATCH 13/28] =?UTF-8?q?docs(plan):=20model=20routing=20wave=202?= =?UTF-8?q?=20=E2=80=94=20pure-execution=20+=20reflection-split=20skills?= =?UTF-8?q?=20(doc/status/hotfix/commit-change/release-candidate)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../plans/2026-07-15-model-routing.md | 302 ++++++++++++++++++ 1 file changed, 302 insertions(+) diff --git a/docs/superpowers/plans/2026-07-15-model-routing.md b/docs/superpowers/plans/2026-07-15-model-routing.md index 494a9ea..58dc42b 100644 --- a/docs/superpowers/plans/2026-07-15-model-routing.md +++ b/docs/superpowers/plans/2026-07-15-model-routing.md @@ -1058,3 +1058,305 @@ git commit -m "chore(memory): BDR-066 model routing + journal + TODO follow-ups" Run: `make test` Expected: green, exit 0. Then report the full commit list (`git log --oneline develop..HEAD`) for the human merge gate. Do NOT run `gitflow finish`. + +--- + +# WAVE 2 — pure-execution + reflection-split skills (user directive 2026-07-15) + +The wave-1 exclusion list left `hotfix, commit-change, doc, status, release-candidate` +inheriting the session model — i.e. running EXECUTION on the big model, the +waste the split exists to kill. User verdicts (2026-07-15): +- **doc / status** = pure non-interactive execution → convert inline-load to a + dispatched subagent so its pin takes effect. doc-syncer stays sonnet; + status-reporter stays **haiku** (right tier for a read-only collector; the + win is getting it off the big model, not the tier). +- **hotfix** = reflection (locate root cause + propose fix) + execution → split + like /feat: reflection inline (+ MODEL GATE), execution dispatched to the + sonnet hotfixer executor. hotfix JOINS the gated group (12→13). +- **commit-change** = grouping (judgment) + committing (execution), interactive + → dispatch EVERYTHING (grouping included) to a sonnet commit-changer, relocate + the two approval gates to the dispatcher (propose→confirm→execute, seo-applier + shape). No MODEL GATE (no inline reflection — grouping runs on sonnet). +- **release-candidate** = create a sonnet `release-executor` agent for the + mechanical spans (version.txt, CHANGELOG rewrite, gitflow start/finish, tag), + relocate the two human gates (when-to-release, push) to the dispatcher. No + MODEL GATE (user's explicit choice — force dispatch, not gate). + +Post-wave-2 gate exclusion list = `commit-change, doc, status, release-candidate` +(hotfix removed — now wired). + +## Global Constraints (wave 2) + +Same as wave 1: branch `feature/model-routing`, no merge, no attribution +trailers, `make test` green per commit, shellcheck clean, config-protection +sentinel before each `lib/tests/*` write, YAML `safe_load`-parseable frontmatter. + +--- + +### Task 11: doc + status → dispatched execution + +**Files:** +- Modify: `skills/doc/SKILL.md` (add `Agent` to allowed-tools; body → dispatch) +- Modify: `skills/status/SKILL.md` (add `Agent` to allowed-tools; body → dispatch) + +**Interfaces:** doc-syncer.md is already `model: sonnet`; status-reporter.md is +already `model: haiku` — no agent edits. Only the skills change from inline-load +to `Agent(subagent_type=…)` so the pins take effect. + +- [ ] **Step 1: doc → dispatch.** In `skills/doc/SKILL.md`, add ` - Agent` to the + `allowed-tools` list, and replace the body block + ``` + Load and follow strictly: + - $HOME/.claude/agents/doc-syncer.md + + Execute the DOC SYNCER on this project. + + Context from the user (if any): + $ARGUMENTS + ``` + with: + ``` + Dispatch the doc-syncer as a subagent so its `model: sonnet` pin takes + effect (doc-sync = execution, not the session's big model): + + Agent(subagent_type="doc-syncer") + prompt: "Audit + sync public docs for this project. Context from the user: + $ARGUMENTS. Report PATCHED_FILES and a summary — do NOT commit." + + Then commit the patched docs from THIS loop per `$HOME/.claude/lib/doc-commit.md` + (surgical: only doc-syncer's PATCHED_FILES, never `.claude/`/`CLAUDE.md`, + no-op if nothing patched). + ``` + +- [ ] **Step 2: status → dispatch.** In `skills/status/SKILL.md`, add `Agent` to + `allowed-tools` (`Read, Bash, Glob, Grep, Agent`), and replace the body + `Load and follow strictly:\n- $HOME/.claude/agents/status-reporter.md\n\nProduce the full PROJECT STATUS report for the current working directory.` + with a dispatch: + ``` + Dispatch the status-reporter as a subagent so its `model: haiku` pin takes + effect (read-only collection = cheapest tier, off the big session model): + + Agent(subagent_type="status-reporter") + prompt: "Produce the full PROJECT STATUS report for the current working + directory. $ARGUMENTS" + ``` + Keep the existing "Fallback when agent file missing" section intact (it still + applies — if the dispatch target is unreachable, emit the missing-agent line + and STOP). + +- [ ] **Step 3: Verify + commit.** `grep -c 'subagent_type="doc-syncer"' skills/doc/SKILL.md` + → 1; `grep -c 'subagent_type="status-reporter"' skills/status/SKILL.md` → 1. + `make test` green. + ```bash + git add skills/doc/SKILL.md skills/status/SKILL.md + git commit -m "feat(model-routing): doc/status dispatch their agent (sonnet/haiku pins take effect)" + ``` + +--- + +### Task 12: hotfix — reflection inline + dispatched sonnet executor (/feat pattern) + +**Files:** +- Modify (rewrite): `skills/hotfix/SKILL.md` — becomes the reflection orchestrator +- Modify (rewrite): `agents/hotfixer.md` — becomes pure executor +- Modify: `lib/tests/loops-light.test.sh` — repoint hotfix structure locks (guarded) + +**Pattern:** mirror the shipped `/feat` split (skills/feat/SKILL.md + agents/feater.md). + +- [ ] **Step 1: Rewrite `skills/hotfix/SKILL.md` as the orchestrator.** Keep `Agent` + in allowed-tools. Structure: + - `# /hotfix — quick-fix orchestrator (reflection inline, execution dispatched)` + - `MODEL GATE (blocking): run $HOME/.claude/lib/model-gate.md BEFORE any step. small → STOP.` + (hotfix now has a reflection phase → it joins the gated group.) + - STEP 1 LOCATE (reflection, inline): find the bug from the description, read + the file(s), CONFIRM the root cause is obvious/superficial, escalate to + `/bugfix` if deeper. Optional blockers-only memory glance (as today). + - STEP 1.5 DESIGN GATE (`lib/design-gate.md`, as today). + - STEP 1.7 CONTRACT (silent autofill, `lib/contract-interview.md`, zero + questions, as today). + - STEP 2 PRE-FLIGHT (inline): gitflow aiguillage (type `hotfix`); snapshot + `git rev-parse HEAD` (the revert SHA) + dirty-tree check (as today's STEP 2 + pre-flight). + - STEP 3 DISPATCH EXECUTOR: `Agent(subagent_type="hotfixer")` with the + contract path, the located file(s), the proposed minimal fix, and the branch. + Parse a `HOTFIX-EXEC REPORT` with `STATUS : DONE | BLOCKED`. + - STEP 4 VERIFY + SECURE + COMMIT (main loop, LRN-083): on executor DONE, the + smoke result is in its report; then the security gate — dispatch a FRESH + security-auditor (`MODE: gate`, SCOPE = diff vs the pre-flight SHA). **hotfix + keeps revert-not-loop**: smoke FAIL or security BLOCK → `git restore .` to the + pre-flight SHA + STOP + "escalate to /bugfix" (verbatim from today's STEP 3). + No verifier at hotfix weight. Commit only after smoke + security pass. + - STEP 5 DOC SYNC + STEP 6 CAPITALIZE: identical to today's STEP 4/5 (doc-sync + auto-mode + `doc-commit.md`; lightweight capitalize + always-on journal + + `capitalize-commit.md`). + - RULES: max 2 files; execution never stays inline, reflection never leaves it + (BDR-066); executor dispatched fresh; revert-not-loop preserved. + +- [ ] **Step 2: Rewrite `agents/hotfixer.md` as the executor.** Frontmatter: + `tools: Read, Edit, Write, Bash, Grep, Glob` (DROP `Agent` — no nested dispatch; + security moved to the orchestrator), `model: sonnet`. Body: receive + CONTRACT + located file(s) + proposed fix + BRANCH (verify with + `git branch --show-current`, never switch). Apply the minimal edit (no + refactoring), run the stack smoke/test cascade (keep today's detection cascade), + report. FORBIDDEN: git commit, branch ops, security dispatch, user questions, + attribution trailers. End with: + ``` + HOTFIX-EXEC REPORT + STATUS : DONE | BLOCKED + FILE(S) : + FIX : + SMOKE : + NOTES : + ``` + +- [ ] **Step 3: Repoint `lib/tests/loops-light.test.sh` hotfix locks** (guarded — + sentinel first). The hotfix block currently checks `agents/hotfixer.md` for + orchestration clauses now moved to the skill. Introduce `HSKL="$REPO/skills/hotfix/SKILL.md"` + and repoint: contract/silent → HSKL `STEP 1.7 — CONTRACT`; security gate + + `failure REVERTS, never loops` + `No verifier is dispatched at hotfix weight` + → HSKL; `hotfix skill has Agent` (HSK ` - Agent`) unchanged. The + `hotfix has Agent tool` lock on hotfixer INVERTS (hotfixer no longer has Agent) + → change to assert hotfixer LACKS Agent and carries `model: sonnet` + the + `HOTFIX-EXEC REPORT` grammar. Add a `hotfix dispatches hotfixer` lock + (`subagent_type="hotfixer"` in HSKL). Keep include/feat/bugfix blocks untouched. + Add a negative-match helper `tn()` (mirror `tf`, invert the grep) if asserting + Agent-absence. + +- [ ] **Step 4: Wire hotfix into the census + gate lists.** In + `lib/tests/model-routing.test.sh` (guarded — sentinel first): MOVE `hotfix` + from the excluded loop to the wired loop (`has "skills/hotfix/SKILL.md" 'lib/model-gate.md'`). + Update the expected count in the run message accordingly. + +- [ ] **Step 5: Verify + commit.** `bash lib/tests/loops-light.test.sh` green; + `bash lib/tests/model-routing.test.sh` green; YAML check both rewritten files; + `make test` green. + ```bash + git add skills/hotfix/SKILL.md agents/hotfixer.md lib/tests/loops-light.test.sh lib/tests/model-routing.test.sh + git commit -m "feat(model-routing): /hotfix split — reflection inline + gate, hotfixer = sonnet executor" + ``` + +--- + +### Task 13: commit-change — dispatch grouping+commit to sonnet, relocate approval gates + +**Files:** +- Modify (rewrite): `skills/commit-change/SKILL.md` — dispatcher owns the two gates +- Modify (rewrite): `agents/commit-changer.md` — sonnet, propose/execute phases, no AskUserQuestion + +**Pattern:** seo-applier shape (subagent proposes → dispatcher confirms → subagent executes). + +- [ ] **Step 1: Rewrite `agents/commit-changer.md`.** Frontmatter: + `tools: Bash, Read, Grep, Glob` (DROP `AskUserQuestion` — gates move to the + dispatcher), `model: sonnet`. Body: two modes driven by the dispatch prompt. + - `MODE: propose` → Phase 0 (gitflow aiguillage, type chore — bash), Phase 1 + (gather), Phase 2 (reconstruct steps), Phase 2.5 → EMIT the `COMMIT PLAN` + block + any edge-case flags (sensitive files, staged-only, conflicts) + + Phase-4 capitalize candidates, then STOP with + `READY TO APPLY — awaiting dispatcher confirmation`. Writes NOTHING. + - `MODE: apply` → receive the APPROVED plan (steps + messages) + approved + capitalize entries; execute Phase 3 (stage-per-step + commit) and write the + approved memory via `capitalize-commit.md`; report the commit hashes. + +- [ ] **Step 2: Rewrite `skills/commit-change/SKILL.md` as dispatcher.** Keep + `Agent` + `AskUserQuestion` in allowed-tools. Flow: pre-flight (detached HEAD / + conflicts / identity — STOP as today) → `Agent(subagent_type="commit-changer")` + with `MODE: propose` → show the returned COMMIT PLAN, `AskUserQuestion` + (all / numbers / edit / skip) → show capitalize candidates, `AskUserQuestion` + (all / IDs / skip) → `Agent(subagent_type="commit-changer")` with `MODE: apply` + + the approved plan + approved entries → report hashes. NO MODEL GATE (grouping + runs on the sonnet subagent — no inline reflection to protect). + +- [ ] **Step 3: Verify + commit.** `grep -c 'subagent_type="commit-changer"' skills/commit-change/SKILL.md` + ≥ 1; `grep -c 'model: sonnet' agents/commit-changer.md` → 1; + `grep -c 'AskUserQuestion' agents/commit-changer.md` → 0; YAML check; `make test` green. + ```bash + git add skills/commit-change/SKILL.md agents/commit-changer.md + git commit -m "feat(model-routing): /commit-change dispatch to sonnet commit-changer, gates relocated to dispatcher" + ``` + +--- + +### Task 14: release-candidate — sonnet release-executor, human gates relocated + +**Files:** +- Create: `agents/release-executor.md` — sonnet, mechanical release spans +- Modify (rewrite): `skills/release-candidate/SKILL.md` — dispatcher owns the two human gates + +- [ ] **Step 1: Create `agents/release-executor.md`.** Frontmatter: + `tools: Read, Edit, Write, Bash, Grep, Glob`, `model: sonnet`. Two-span + executor driven by the dispatch prompt (a human gate sits BETWEEN the spans, so + it cannot be one dispatch): + - `SPAN: prep ` → `gitflow start release `, set `version.txt`, + rewrite CHANGELOG (`## [Unreleased]` → `## [] — `, re-open empty + Unreleased; a MAJOR must spell out breaking), run the test suite (RC gate — + never release red), commit the prep on the release branch. Report the branch + + test result. No merge, no tag, no push. + - `SPAN: finish ` → `gitflow finish` (fan-out), `git tag -a v main + -m "release "` AFTER finish. Report. NEVER push (dispatcher's gate). + - FORBIDDEN: deciding the version number (dispatcher/user owns it), the + when-to-release decision, `git push`, attribution trailers. + +- [ ] **Step 2: Rewrite `skills/release-candidate/SKILL.md` as dispatcher.** Add + `allowed-tools: Read, Write, Edit, Bash, Grep, Glob, Agent, AskUserQuestion` to + the frontmatter (it currently has none). Keep all the Overview/Versioning/Common- + mistakes doctrine. Flow: preconditions (clean tree, identity, develop ahead of + main) → the version-number decision stays HERE (judgment: derives from change + nature; decide before running) → `Agent(subagent_type="release-executor")` + `SPAN: prep ` → **HUMAN GATE — when to release** (`AskUserQuestion`, + explicit go, never on "tests pass") → `Agent(subagent_type="release-executor")` + `SPAN: finish ` → **push GATE (ASK)** (`AskUserQuestion`; on go only, + LRN-069): `git push origin main develop && git push origin v` from THIS + loop. No MODEL GATE. + +- [ ] **Step 3: Verify + commit.** `RC_WORK=$(mktemp -d) RC_TAG=1 bash lib/tests/run-release-candidate.sh` + → 5/5 (the release mechanics test is unchanged — the lib still fans out + the + dispatcher still tags); `grep -c 'subagent_type="release-executor"' skills/release-candidate/SKILL.md` + ≥ 1; YAML check the new agent; `make test` green. + ```bash + git add agents/release-executor.md skills/release-candidate/SKILL.md + git commit -m "feat(model-routing): /release-candidate dispatches sonnet release-executor, human gates in dispatcher" + ``` + +--- + +### Task 15: census + docs + memory for wave 2 + +**Files:** +- Modify: `lib/tests/model-routing.test.sh` (guarded) — wave-2 assertions +- Modify: `README.md`, `CHANGELOG.md`, `.claude/memory/decisions.md`, `.claude/tasks/TODO.md` + +- [ ] **Step 1: Extend the census** (`lib/tests/model-routing.test.sh`, guarded — + sentinel first). The excluded loop drops `hotfix` (moved to wired by Task 12 Step 4) + and now reads `for s in commit-change doc status release-candidate`. Add + execution-dispatch asserts: `has skills/doc/SKILL.md 'subagent_type="doc-syncer"'`; + `has skills/status/SKILL.md 'subagent_type="status-reporter"'`; + `has skills/commit-change/SKILL.md 'subagent_type="commit-changer"'`; + `has skills/release-candidate/SKILL.md 'subagent_type="release-executor"'`; + pins `has agents/commit-changer.md 'model: sonnet'`, + `has agents/release-executor.md 'model: sonnet'`; and executor-shape + `lacks agents/commit-changer.md 'AskUserQuestion'`. Update the printed expected + count. Flip-test one new assertion (LRN-096). + +- [ ] **Step 2: README + CHANGELOG.** Update the BDR-066 agent-model table: + hotfixer stays sonnet (now an effective executor), commit-changer → sonnet, + release-executor (new) → sonnet, status-reporter → haiku (now effective via + dispatch). Move doc/status/commit-change/release-candidate out of the "inherit" + row into a new "execution — dispatched" line. CHANGELOG Unreleased: add the + wave-2 bullets (doc/status/hotfix/commit-change/release-candidate routing). + +- [ ] **Step 3: Capitalize.** Append to the BDR-066 entry a `**Wave 2**` bullet: + doc/status dispatched (sonnet/haiku pins effective); hotfix split like /feat + (joins gated group); commit-change dispatched sonnet with relocated gates; + release-candidate sonnet release-executor with relocated human gates; exclusion + list now commit-change/doc/status/release-candidate. Journal line + + TODO tick under the 2026-07-15 section. + ```bash + git add lib/tests/model-routing.test.sh README.md CHANGELOG.md .claude/memory/decisions.md .claude/memory/journal.md .claude/tasks/TODO.md + git commit -m "chore(model-routing): wave-2 census + docs + BDR-066 update" + ``` + +- [ ] **Step 4: Final wave-2 review** — dispatch a whole-branch reviewer (opus) over + the wave-2 range; confirm both consumers of verify-secure-loop still coherent, + hotfix revert-not-loop preserved, no execution left on the big model in the + five converted skills. Report the full `git log --oneline develop..HEAD`. Do NOT + merge. From f36aec370bb7f7a0f7bbde5c5c28a619aed7b705 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 15 Jul 2026 12:38:12 +0200 Subject: [PATCH 14/28] feat(model-routing): doc/status dispatch their agent (sonnet/haiku pins take effect) --- skills/doc/SKILL.md | 14 +++++++++----- skills/status/SKILL.md | 10 ++++++---- 2 files changed, 15 insertions(+), 9 deletions(-) diff --git a/skills/doc/SKILL.md b/skills/doc/SKILL.md index aa93a51..341381f 100644 --- a/skills/doc/SKILL.md +++ b/skills/doc/SKILL.md @@ -15,12 +15,16 @@ allowed-tools: - Bash - Grep - Glob + - Agent --- -Load and follow strictly: -- $HOME/.claude/agents/doc-syncer.md +Dispatch the doc-syncer as a subagent so its `model: sonnet` pin takes +effect (doc-sync = execution, not the session's big model): -Execute the DOC SYNCER on this project. +Agent(subagent_type="doc-syncer") +prompt: "Audit + sync public docs for this project. Context from the user: + $ARGUMENTS. Report PATCHED_FILES and a summary — do NOT commit." -Context from the user (if any): -$ARGUMENTS +Then commit the patched docs from THIS loop per `$HOME/.claude/lib/doc-commit.md` +(surgical: only doc-syncer's PATCHED_FILES, never `.claude/`/`CLAUDE.md`, +no-op if nothing patched). diff --git a/skills/status/SKILL.md b/skills/status/SKILL.md index 142f60b..b3ec18c 100644 --- a/skills/status/SKILL.md +++ b/skills/status/SKILL.md @@ -2,13 +2,15 @@ name: status description: 'Consolidated project snapshot — plugins, token cost, git state, recent commits, GSD v2 milestone progress. Read-only. Run at session start or after a break. Open-work reconciliation (stale TODO vs real git) → /reconcile. Triggers: "status", "sitrep", "where are we", "project state", "after break".' argument-hint: (no arguments needed) -allowed-tools: Read, Bash, Glob, Grep +allowed-tools: Read, Bash, Glob, Grep, Agent --- -Load and follow strictly: -- `$HOME/.claude/agents/status-reporter.md` +Dispatch the status-reporter as a subagent so its `model: haiku` pin takes +effect (read-only collection = cheapest tier, off the big session model): -Produce the full PROJECT STATUS report for the current working directory. +Agent(subagent_type="status-reporter") +prompt: "Produce the full PROJECT STATUS report for the current working + directory. $ARGUMENTS" ## Fallback when agent file missing From 45cd86810a8c979941db24be032eb6685d07fa09 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 15 Jul 2026 19:28:58 +0200 Subject: [PATCH 15/28] =?UTF-8?q?feat(model-routing):=20/hotfix=20split=20?= =?UTF-8?q?=E2=80=94=20reflection=20inline=20+=20gate,=20hotfixer=20=3D=20?= =?UTF-8?q?sonnet=20executor=20(dual-use=20applier=20preserved)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- agents/hotfixer.md | 208 ++++++++------------------------ lib/tests/loops-light.test.sh | 27 +++-- lib/tests/model-routing.test.sh | 6 +- skills/hotfix/SKILL.md | 183 +++++++++++++++++++++++++++- 4 files changed, 255 insertions(+), 169 deletions(-) diff --git a/agents/hotfixer.md b/agents/hotfixer.md index b751e19..c531917 100644 --- a/agents/hotfixer.md +++ b/agents/hotfixer.md @@ -1,92 +1,48 @@ --- name: hotfixer description: Quick-fix executor — dispatched by /hotfix, which owns the routing and gitflow gate. Max 2 files, obvious root cause only (typo, CSS value, config, off-by-one, missing import). -tools: Read, Edit, Write, Bash, Grep, Glob, Agent +tools: Read, Edit, Write, Bash, Grep, Glob model: sonnet --- -# HOTFIX — Quick Superficial Fix +# HOTFIXER — closed-fix executor / L1 fix-bundle applier -Fast-track fix for obvious bugs. No planning overhead, no plugin check. -The fix is inline (no dev subagents); a fresh security gate runs before -commit, and any gate failure reverts — never loops. Get in, fix, gate, -get out. +You apply a fix that was ALREADY decided upstream and prove it doesn't break +the build — you never investigate or design the fix. Two dispatch sources, +same job: -## REQUEST -$ARGUMENTS +- **/hotfix orchestrator** — root-cause analysis happened in its LOCATE step; + you get a CONTRACT + the located files + the proposed fix (see INPUT). +- **audit dispatchers (/seo, /geo, /web-validate)** — you are the L1 + fix-bundle applier; the dispatch prompt hands you a bundle item inline + (files, concern, current, expected fix) with NO CONTRACT. Apply exactly + that item, self-verify, do not commit. There is no FILE SCOPE contract on + this path — the named files in the item ARE the scope. ---- +## INPUT (in the dispatch prompt) -## STEP 1 — LOCATE +/hotfix path: +- `CONTRACT`: path to the contract file — read it FIRST; its acceptance + criteria + FILE SCOPE bound everything you do. +- `LOCATED`: the file(s) the orchestrator found + the confirmed root cause. +- `FIX`: the proposed minimal fix, already decided. +- `BRANCH`: verify with `git branch --show-current`; mismatch → STATUS + BLOCKED — never create or switch branches. -Find the bug. Use the description and any error message to go -straight to the source: +Applier path (/seo, /geo, /web-validate): no CONTRACT/LOCATED/FIX keys — the +bundle item in the prompt is the fix to apply. Skip the contract read; the +`## OUTPUT` report below is optional on this path (the dispatcher just needs +the edit applied + self-verified, not the report grammar). -```bash -git status -git log --oneline -3 -``` +## EXECUTION RULES -- Read the relevant file(s). Confirm the root cause is obvious - and superficial (typo, wrong value, missing import, etc.). -- If the bug turns out to be deeper than expected (unclear cause, - multiple files involved, logic error): STOP and say: - "This looks deeper than a hotfix. Load `$HOME/.claude/agents/bugfixer.md` - and run the BUGFIXER agent on this target." - -OPTIONAL — memory check (exempt by default; hotfix = obvious fix, mirror of its capitalize -skip). For a RECURRING or urgent bug only, a quick blockers-only glance may save time: - - [ -d .claude/memory ] && grep -nE '^## BLK-' .claude/memory/blockers.md # "déjà vu ?" - -If a prior BLK names this bug, jump to its solution. Not mandatory; no RELATED MEMORY -disposition required at hotfix weight. - -## STEP 1.7 — CONTRACT (silent autofill) - -Run `$HOME/.claude/lib/contract-interview.md` at hotfix weight: **zero -questions ever** (a hotfix is an obvious fix by definition). Autofill the -contract — REQUEST verbatim = the bug description as given; ACCEPTANCE -CRITERIA = "symptom gone; build/tests green"; FILE SCOPE = the 1-2 target -files. It writes `.claude/tasks/contracts/--.md`. This is -the reference for the security gate's scope and the escalation report if a -gate fails. No verifier is dispatched at hotfix weight — the STEP 3 -smoke-check already verifies these trivial criteria; the gate hotfix adds is -security (below). - -## STEP 1.5 — DESIGN GATE - -Follow `$HOME/.claude/lib/design-gate.md`: -- Scan $ARGUMENTS and target files for design/UI/style signals (CSS, component, styling, animation). -- If signals found → run `design-tool-gate.sh`; if it reports INCOMPLETE, - tell the user to run `/profile design` before proceeding. -- If no signals → skip (zero overhead). - -## STEP 2 — PRE-FLIGHT + FIX - -**Gitflow aiguillage (before editing):** follow `$HOME/.claude/lib/gitflow-aiguillage.md` -— your type = `hotfix`. On `main`/`develop` it branches first; on a working -branch it's a no-op (commit in place). Never `finish`. - -### Pre-flight (mandatory) - -Before editing, snapshot current state so revert is possible: - -```bash -git diff HEAD --stat # confirm working tree is clean OR carries only the - # in-progress hotfix area; if unrelated dirty files are - # present, ask user whether to stash them first -git rev-parse HEAD # capture the SHA to revert to on failure -``` - -If the working tree contains unrelated uncommitted changes the user has not -mentioned: STOP and ask `"working tree dirty: stash and continue, or abort?"`. - -### Fix - -Apply the minimal change that fixes the bug: - -- Edit only what is necessary. No refactoring, no cleanup. +- Apply the minimal change that fixes the bug. Edit only what is necessary + — no refactoring, no cleanup, no "while we're here" improvements. +- Stay inside the scope you were given. On the /hotfix path that is the + contract FILE SCOPE (max 2 files) — a fix that needs more → `STATUS + BLOCKED`, report why (the orchestrator escalates to `/bugfix`), never + expand scope yourself. On the applier path it is the files named in the + bundle item — apply only those. - If tests exist for the affected code, run them. Detection cascade: ```bash # JS/TS @@ -102,85 +58,25 @@ Apply the minimal change that fixes the bug: test -f Makefile && grep -qE '^test:' Makefile && echo "make test" ``` Run whichever one resolves; if none → continue to smoke check below. -- Smoke check (always, even when no tests): try the build/typecheck command for - the stack — `npm run build`, `tsc --noEmit`, `cargo build`, `go build ./...`, - `python -c "import "` — to confirm the fix did not break compilation. +- Smoke check (always, even when no tests ran): try the build/typecheck + command for the stack — `npm run build`, `tsc --noEmit`, `cargo build`, + `go build ./...`, `python -c "import "` — to confirm the fix did not + break compilation. +- Report the SMOKE result verbatim, pass or fail. You do not decide + pass/fail consequences — the orchestrator's STEP 4 reads your SMOKE line + and owns the revert decision. +- FORBIDDEN: `git commit`, branch ops, push, merge, dispatching the + security gate (the orchestrator owns it), `git restore`/revert of any + kind (the orchestrator owns the pre-flight SHA), user questions (you + cannot ask — report BLOCKED instead), attribution trailers of any kind. -## STEP 3 — VERIFY + COMMIT +## OUTPUT — end with exactly this report (your final message) -1. Verify the fix: - - Run the test suite or the specific test if available. - - If no tests: smoke check from STEP 2 must have passed. -2. **Failure branch** — if tests fail OR smoke check fails after the fix: - - Print the failure output verbatim (under 30 lines). - - Run `git restore .` to revert the working-tree edits to the pre-flight SHA. - (Files were not yet staged — restore is safe.) - - STOP and tell user: `"Hotfix introduced a regression. Reverted. Escalate to /bugfix or /analyze for deeper investigation."` - - Do NOT commit a broken fix. -3. **Security gate (fresh auditor) — failure REVERTS, never loops.** Dispatch - a FRESH security-auditor (`subagent_type: security-auditor`, or load - `agents/security-auditor.md`) with `MODE: gate`, `SCOPE:` the working-tree - diff vs the pre-flight SHA. Parse its `SECURITY — VERDICT:` line: - - `PASS` (or `DEGRADED` with no BLOCK) → proceed to commit. - - `BLOCK(n)` → this is hotfix: do NOT loop. Run `git restore .` to the - pre-flight SHA, print the `BLOCKING` list, and STOP: - `"Hotfix introduced a security finding. Reverted. Escalate to /bugfix - for a fix under the full verify+security loop."` The hotfix model is - one attempt; any gate failure (smoke OR security) reverts and escalates. - - Structural failure (mute / unparsable / no VERDICT line) → treat as a - failed gate: retry ONCE fresh; a 2nd structural failure → revert + - escalate. A mute auditor is never a PASS. -4. Commit using conventional format (only after verify AND security pass): - ``` - fix(): - ``` -5. Print summary: - ``` - HOTFIX APPLIED - FILE(S) : - FIX : - VERIFIED: - SECURITY: - ``` - -## STEP 4 — DOC SYNC (automatic) - -Load `$HOME/.claude/agents/doc-syncer.md`. -Execute in automatic mode: -`auto-mode scope: ` - -**Then commit the docs** — follow `$HOME/.claude/lib/doc-commit.md`: it surgically commits -ONLY the files doc-syncer patched (its `PATCHED_FILES` output), never `git add -A`, never -`.claude/`/`CLAUDE.md` (rc 4 = a loud BDR-022 anomaly, not a silent skip), and no-ops when -nothing was patched — the common case for a trivial hotfix. No FINISH in an inline flow, so -it just commits the docs on the current branch (no ordering concern). - -## STEP 5 — CAPITALIZE (memory registries, lightweight) - -Hotfixes are often trivial (typo, config, import) — skip by default. But if the fix revealed something non-obvious: - -- Wrong default that should never have been merged → propose `LRN-XXX` in `.claude/memory/learnings.md`. -- Bug that cost real time to locate despite being "superficial" → propose `BLK-XXX` in `.claude/memory/blockers.md` (status: resolved). - -Default behaviour: `CAPITALIZE: hotfix trivial, skip` (no prompt, no output). -Ask the user only when there is an actual candidate to propose. - -Always append a 1-line entry to today's heading in `.claude/memory/journal.md` (even trivial hotfix — journal is timeline, not signal). - -**Language rule**: the journal line and any proposed BLK/LRN entries are ALWAYS written in English (see CLAUDE.md "Memory registries" § Language). - -**Then commit the memory** — follow `$HOME/.claude/lib/capitalize-commit.md`: it -surgically commits what capitalize just wrote (`.claude/memory` + `.claude/tasks` -only, never `git add -A`) as one `chore(memory)` commit, reports the memory-commit -hash, and no-ops if nothing was written. The always-on journal line means a -trivial hotfix still produces a `chore(memory): journal — …` commit (Frame 2 / F3). - ---- - -## RULES -- Max 2 files changed. If more needed → `/bugfix`. -- No refactoring. No "while we're here" improvements. -- Design gate only if CSS/style signals detected. See STEP 1.5. -- If root cause is unclear → escalate to `/bugfix`. -- If fix touches >5 lines of logic → reconsider if this is - truly a hotfix. +``` +HOTFIX-EXEC REPORT +STATUS : DONE | BLOCKED +FILE(S) : +FIX : +SMOKE : +NOTES : +``` diff --git a/lib/tests/loops-light.test.sh b/lib/tests/loops-light.test.sh index 077cc98..4d023db 100644 --- a/lib/tests/loops-light.test.sh +++ b/lib/tests/loops-light.test.sh @@ -13,6 +13,7 @@ FSK="$REPO/skills/feat/SKILL.md" BUG="$REPO/agents/bugfixer.md" HOT="$REPO/agents/hotfixer.md" HSK="$REPO/skills/hotfix/SKILL.md" +HSKL="$REPO/skills/hotfix/SKILL.md" PASS=0; FAIL=0 tf() { # tf