Vendored-skill content refreshed by update-all.sh step 8 during the soak
update runs: demo-shell + output-format reworked upstream, new
report-template.html reference. Content-only, no wiring change.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
RC fix (soak day 1, #4). Two stacked defects: (1) update-all.sh never
sourced ~/.cargo/env (unlike install-plugins.sh), so on a profile that
lost the cargo PATH line the rtk step printed "Cargo not available" forever
— rtk never updated via make update (BLK-016 class). (2) once cargo was
found, the "latest" branch ran a bare `cargo install --git` (default-branch
HEAD) and would have recompiled Rust on EVERY update: upstream's HEAD
Cargo.toml (0.42.4) trails its newest stable tag (v0.43.0), so any
tag-vs-installed comparison never converges against a HEAD build.
Fix: source cargo env before concluding cargo is absent; resolve the newest
STABLE tag by name (sed anchored on refs/tags/v?N.N.N$ — dev-N.N.N-rc.*
pre-releases excluded; a naive version grep had picked dev-0.44.0-rc.308),
install BY TAG, and skip when installed == target. Proven live both ways:
run 1 compiled v0.43.0 (?tag=v0.43.0#5a7880d4), run 2 skipped
("already at latest tag (0.43.0)"). Pinned-version branch gets the same
skip-on-match guard.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
RC fix (soak day 1, #3). `read -r` on the "Proceed with GStack update?"
prompt hits EOF in any non-TTY run (cron, CI, background shell) and kills
the whole update under set -e — every later step (rtk, gsd, ctx7, semgrep,
npx skills) silently never ran. Guard on [ -t 0 ]: interactive behavior
unchanged, non-TTY defaults to the safe N and continues. Proven end-to-end:
before = Error 1 at the prompt; after = full run exit 0 through step 7.5.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
RC fix (soak day 1): `make update` step 7.5 failed on a 300s clone timeout
of alchaincyf/find-skills. The skill (search the skills.sh registry from
Claude) was never used; the discovery case stays reachable manually via
`npx -y skills find <query>`. Removed from install-plugins.sh (install list
+ summary + comment), update-all.sh (refresh list), link.sh
(NPX_EXTERNAL_SKILLS), lib/toggle-external.sh (MANAGED_TOOLS + case arms),
plugin-advisor.md, .gitignore; local skills/find-skills symlink deleted.
Memory-registry and test-fixture mentions kept — append-only history.
toggle-external `list` verified post-removal; suites 8/8.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
11 atomic commits on chore/review-remediation, make test GREEN throughout, both
smokes verified (A2 secret blocked, A8 AUTO fix lands). Branch unmerged (human gate).
The session-start line-count guard warned 'density pass requis' every session since
job1 without the 275 target (BDR-031) or even the 280 threshold ever being met —
CLAUDE.md sits at 305 (319→305 at job1, never re-inflated). A gate that never goes
green is noise. BDR-062 supersedes BDR-031's 275 TARGET only (principle kept, append-
only): 305 assumed final, guard warns past a 320 margin so real regressions still
surface. Review A6 (verifier-amended MINEUR).
BLK-016 (rtk PATH-dead) shipped resolved in 1.0.0 (2b4e7401) but neither the entry
NOR the fix reached develop — rtk was live-broken on develop. Fix ported in the
preceding commit (install-plugins.sh bridge), so this backfill marks it resolved
truthfully. Table row + section. Review A3.
Ports e58037c from release/1.0.0 (never back-merged). develop installed rtk via
cargo (~/.cargo/bin) and checked 'command -v rtk' in the installer shell that
sourced cargo env — so the check passed while Claude's tool shell never got the
PATH, dropping every compound rewrite (measured on release audit: 6/5070 commands
compressed over 30 days, ~460K tokens missed). Idempotent bridge symlink, self-
repairs a stale link, skips when no cargo binary. Resolves BLK-016 on develop. Review A3.
EVAL-015 (/tour first real run, report-only bchanot-cv) shipped in 1.0.0 (74d3804),
never back-merged to develop (registry gap between EVAL-014 and EVAL-016). Section
backfill; links to now-present [[LRN-101]]. Review A3.
lib/tests/run-review-guards.sh — 5 whole-surface guards that RED if a banned
pattern subsists anywhere, auto-run by make test (run-*.sh glob):
G1 trailer (A1), G2 false CLAUDE.md attribution (A5), G3 strict-YAML frontmatter
(A4), G4 reconcile hermeticity (job3 B1), G5 hook-drift installed==emit (A2).
This is the check that would have caught A1/A4/A5/A2 at make-test time instead of
an adversarial review — the series' recurring failure was fixing one instance and
leaving twins. G3/G5 degrade to SKIP if pyyaml/emit-hook absent (portability).
Teeth verified: a planted trailer in a real agent REDs G1. Review fil rouge.
geo-analyzer asserted 'PERMISSIVE default per user CLAUDE.md' in 2 sites (L224,
L867-869) but CLAUDE.md carries no PERMISSIVE/RESTRICTIVE crawler policy. Reframed
as the agent's own policy grounded in GEO's purpose (an AI-visibility audit defaults
to allowing AI crawlers); default unchanged. Completes job3 C6/C7/C8 scrub (which
missed geo) — job9's later rewrite also left it. User-approved wording. Review A5.
Both line-3 descriptions contained an unquoted ': ' (and '|') that fails
python3 yaml.safe_load ('mapping values are not allowed here'). seo-analyzer's
line was last rewritten by job9/a5a7b54 AFTER job2's F7 strict-YAML rule
(git blame); security-auditor's dates to job6. Single-quote wrap, no internal
apostrophes. Gate: yaml.safe_load over ALL agents/*.md now clean. Review A4.
Root cause: job7/17bdd08 added the gitleaks scan to the hook GENERATOR
(_gitflow_emit_pre_commit) but the installed .githooks/pre-commit is only
(re)written by 'gitflow init'/'install-hook' — never invoked on this repo after
job7. No mechanism propagates a generator change to already-installed hooks, and
T10 diffs only the allow/block verdict (not content), so the drift was silent.
The installed hook (620071b, 2026-06-29) predated the gitleaks addition by 8 days.
Regenerated via 'gitflow.sh install-hook'; installed hook now == fresh emit.
Gates: grep -c gitleaks=7; negative test (staged AKIA... on a working branch)
BLOCKED with exit 1; make test GREEN. Review finding A2 (P0). A content-drift
assertion is added to make test in the fil-rouge commit.
Completes job9/5a3de92 (which only cleaned commit-changer). These 3 execution
agents still emitted the banned trailer into their commit-message templates;
the settings.attribution backstop does not filter agent-authored message bodies.
Extended sweep of agents/ lib/ hooks/ templates/ for Co-Authored-By|Claude-Session|
--trailer now returns zero. Review finding A1 (BLOQUANT), J4-16 follow-up.
Session log for job8 (A/B/C/D execution, 3 Bash permission denials
worked around mid-C, smoke gate confirmed by user). TODO tracks the
2 open residuals: C/D single-pass re-audit next cycle, MAGIC_API_KEY
rotation still pending (job7 residual, unrelated to job8's own scope).
BDR-059 + LRN-110 + LRN-111. Confirmed A's ask-gate covers component_builder
(mcp__ scope) — no code fix possible or attempted, it's third-party package
code (dist/utils/callback-server.js:36). README MCP section now documents
the risk and why the mitigation is ask-gating, not patching.
BDR-058 + LRN-109. Root cause of the "referenced files absent" finding:
the skills CLI's skillPath only fetches SKILL.md, never sibling
references/scripts/templates dirs. Upstream HEAD matched the already-
recorded lockfile hash exactly (no drift, no tamper) — reinstalled the
full tree at that pinned SHA, detached HEAD so nothing can silently
advance. Reinstall happened outside this repo (~/.agents); this commit
is the only repo-side record. Backup of the old single-file dir kept.
Empty allowlist stays empty for mcp__magic__* (deny-by-default,
no auto-exec ever). All 4 tools now explicit in permissions.ask
so confirmation is guaranteed regardless of default-mode fallthrough,
instead of relying on undocumented absence. No wildcard.
BDR-057: secrets by reference not by value; redact at capture, not just at
rest. Documents the two-part job7 posture (MCP ${VAR} expansion + rtk-rewrite
env-dump redaction) and flags the unreconciled contradiction with job6's
same-day (wrong) finding that ${VAR} expansion was unsupported at user scope.
BDR-026 updated: the backup-vector incident (2026-07-02) is closed at the
source rather than by repeated scrubbing — every native auto-backup taken
while the live file held the plaintext value was a fresh leak, so scrubbing
existing backups alone would have recurred forever.
LRN-108: `claude mcp add --env KEY=value` writes the value literally —
double- vs single-quoting around `${VAR}` is the entire difference between
a reference and a plaintext-forever config. The natural way to type the
flag (bash-expand it first) is exactly the trap.
Also refreshed .audit/scan-secrets-claude-home.json to the post-purge state
(15 residual hits, down from 18 pre-D).
- rm ~/.claude/projects/.../960bd2cf-...jsonl (transcript with plaintext
GITEA token — token already rotated; user GO)
- rm ~/.claude/paste-cache/7d48f52c7499c1a7.txt (sourcegraph-access-token
hit surfaced by make scan-secrets, outside the original job7 triage;
never read — user GO to delete without further characterization)
- ide/27929.lock: already gone (natural rotation, session ended). Its
replacement ide/20429.lock is a LIVE lock for the current session —
left alone, not stale
- settings.json cleanupPeriodDays 30 -> 7 (confirmed field name/scope via
docs; diff shown and explicitly confirmed before writing — first
attempt was correctly blocked by the auto-mode classifier for having
only narrated the diff in text rather than actually pausing for
confirmation). Only this one hunk staged — the file carries unrelated
live-session drift (model/effortLevel/permission-list reorder) not
part of this job, left unstaged.
Residual, deliberately not decided here: transcript f1c9c474-...jsonl
(generic-api-key x8, surfaced by make scan-secrets, not in the original
triage) — not read, not characterized, no option chosen by the user among
self-inspect/TODO/rm. Left intact in TODO as an open item.
Pre-commit (lib/gitflow.sh emit-hook) now runs `gitleaks git --staged` right
after the root-commit/merge-in-progress guard, on ANY branch — not gated by
branch protection, since secrets shouldn't land anywhere. Non-blocking if
gitleaks isn't installed (warn + pass). gitleaks 8.30.1: `protect` isn't
listed in --help anymore (still runs, but undocumented) — used the
documented `git --staged` equivalent instead.
.gitleaks.toml allowlists the 3 false-positive classes from the job7 triage
(marketplace.json 40-hex "sha" fields, superpowers ws-protocol.test.js nonce,
git-game test-secret-* fixtures) plus a 4th entry for ~/.claude/.env itself —
not a false positive, but scanning our own canonical vault (BDR-026) is pure
noise for a tool meant to catch stray copies. All 4 verified empirically
against the real flagged files/values before being added, not assumed from
gitleaks' docs.
`make scan-secrets` scans this repo's git history + ~/.claude (dir scan),
redacted JSON to .audit/ (verified: --redact scrubs Match/Secret in the
report itself, not just console logs — safe to commit). Repo: 0 findings.
~/.claude: 18 remaining across 8 files — 5 match the known job7 triage
(pending the GO-gated purge in step D), 3 are new discoveries outside the
original triage scope (flagged for the user, not characterized further —
never read a flagged file's content past what gitleaks' redacted report
gives you).
lib/gitflow-test.sh T16: fake secret on a feature branch (not main/develop)
→ blocked, proving the check isn't gated by branch protection; clean commit
passes; PATH without gitleaks → warns and still commits. 96/96 green.
toggle-external.sh's `claude mcp add magic --env API_KEY="$MAGIC_API_KEY"`
materialized the key as plaintext into ~/.claude.json — a copy outside the
~/.claude/.env canonical, invisible to the repo's gitignore/allowlist reach.
Claude Code supports ${VAR} expansion in mcpServers config (docs confirmed),
so the fix is a reference, not a scrub.
- lib/toggle-external.sh: --env 'API_KEY=${MAGIC_API_KEY}' (single-quoted
literal reference, not bash-expanded) so future `enable magic` runs write
the safe form too.
- README: new "Adding an MCP server that needs a secret" section documenting
the --env pitfall and the wrapper pattern.
Out-of-repo companion changes (not in this commit): ~/.bashrc gained a
scoped claude() wrapper that sources ~/.claude/.env into a subshell before
exec'ing the real binary (verified: the var never reaches the ambient
interactive shell, only claude + children) — chosen over a global export to
keep the secret's surface minimal. ~/.claude.json's mcpServers.magic.env.API_KEY
was rewritten to the same "${MAGIC_API_KEY}" reference via a surgical jq
edit (never read directly, so the value never entered this session's
context). The 2 of 5 rotating ~/.claude/backups/.claude.json.backup.* files
still holding the old plaintext were scrubbed the same way.
Residual: this session predates the bashrc wrapper, so `claude mcp list`
currently warns "Missing environment variables: MAGIC_API_KEY" — expected,
resolves on next terminal + Claude Code restart. MAGIC_API_KEY rotation
still pending (user action, after this commit).
Any single-pipeline printenv/env dump now gets a redaction pipe appended
before it can reach stdout/transcript; `env VAR=x cmd` (legitimate
subprocess launch) is left intact. Compound commands (;, &, ||) bail
untouched — appending the pipe at the end would attach to the wrong
segment.
Discovered mid-implementation: rtk rewrite classifies any command
containing "env" as exit-code 2 ("deny"), with no settings.json rule
backing it — the command still reaches native evaluation and can run.
Adjusted case 2/1 handling so the redaction check runs regardless.
BDR-056: deps policy reversal — latest gated by integration, not
KEEP-PINNED by default (job6-batch-3 override, gstack #1911 case).
LRN-107: read-only subagent mandates must ban copying secret VALUES,
not just mutations (job6's own MAGIC_API_KEY scratch-copy incident).
EVAL-020: job6 execution quality — 2 real STOP gates hit and resolved
live (graphifyy hook rewrite declined, gsd-pi format break patched).
- README + plugins.lock.json graphifyy note: pipx/PyPI install only, never
npm/npx — a different publisher (rhanka/graphify) squats the same
'graphifyy' name on npm as a version-shadowing shim with its own
conflicting 'graphify' bin (F-X1).
- agents/security-auditor.md: one-line caveat that p/* semgrep packs are
fetched from the registry at runtime — the CLI version pin does not
freeze ruleset content, so a new BLOCK can appear on unchanged code.
MCP magic (F-X3): version pin declined by user call (stays @latest in
lib/toggle-external.sh). ${VAR} env expansion confirmed unsupported at
~/.claude.json user scope (Claude Code docs — expansion is .mcp.json
project-scope only), so the BDR-026 reference-not-plaintext pattern
doesn't transfer here; existing mitigations (canonical ~/.claude/.env,
gitignore, audit env-field filtering) remain the practical ceiling.
~/.claude.json regenerated out-of-repo via toggle-external.sh disable+
enable magic to pick up the already-rotated MAGIC_API_KEY (no repo diff,
no commit for that file — traced in the job6 final report).
Full pull per user verdict (human review of #2047 gbrowser stealth done,
accepted) — motivated by the #1911 fail-open fix for 4 security guards
(careful, guard, freeze, data-loss) plus PII/secrets redaction (#1797),
telemetry-consent + cache sanitization (#1848).
Gate: make test 90/0 green after bump; re-ran link.sh (symlinks already
current) + gstack ./setup (browse binary rebuilt); smoked /careful and
/freeze (guard's constituents) via direct JSON-payload invocation
(job4 §2.3 idiom) — both confirmed blocking a trivial case (rm -rf,
edit outside freeze boundary) that must be blocked.
Local playwright pin (BDR-029/BLK-008, ubuntu26.04 Chromium support) was
reset by the submodule checkout as designed, then re-applied via
gstack_bump_playwright_if_unsupported's own steps (bun install,
detect unsupported, bun add playwright@latest — 1.58.2→1.61.1, one
minor ahead of the pre-bump local patch). Original local diff backed
up before discarding: scratchpad/gstack-local-playwright-fix-070722a.patch.
plugins.lock.json note updated with the pinned SHA and rationale.
Rollback if needed: git -C skills-external/gstack checkout 070722a &&
git add skills-external/gstack && link.sh re-run.
Upgrade confirmed format-incompatible before use (job6 gate, BATCH-2):
gsd-pi 3.0.0 no longer writes .gsd/ROADMAP.md (verified by generating a
real test milestone in a scratch project) — state moved to .gsd/STATE.md,
.gsd/gsd.db (authoritative DB), and one .gsd/milestones/<ID>/<ID>-ROADMAP.md
per milestone, all in a different markdown shape. Every grep/awk in
status-reporter.md PHASE 3 would silently print 0/blank against the old
path instead of erroring.
Rewired PHASE 3 to read `gsd headless query` (stable JSON snapshot, no LLM
call) instead of scraping markdown — smoke-tested against both the absent
case (this repo, no .gsd/) and a real gsd-managed scratch project.
plugins.lock.json pin bumped deliberately to 3.0.0 (update-all.sh honors
the pin; this is the required manual bump).