Commit Graph
100 Commits
Author SHA1 Message Date
bastien 2560905be2 docs(toggle): higgsfield header line names the login too 2026-09-30 18:17:17 +02:00
bastien d9617d8eb8 docs: Higgsfield README + CHANGELOG match the npm-only CLI refresh and the two disables — ship-feature higgsfield-pack 2026-09-30 18:17:16 +02:00
bastien 4c7db8893b fix(higgsfield): report upstream drift on every enable; final review fixes 2026-09-30 16:35:45 +02:00
bastien 142f73b08e docs(plan): mirror the final suite in the plan copies 2026-09-30 16:17:58 +02:00
bastien a1f7893786 test(higgsfield): drop the two shellcheck suppressions in the suite 2026-09-30 16:17:34 +02:00
bastien a53d66af98 docs(global): route media generation to the Higgsfield pack 2026-09-30 16:12:58 +02:00
bastien 0a52ca677d docs: Higgsfield pack in README and CHANGELOG 2026-09-30 16:11:41 +02:00
bastien 852ccdcc0f feat(doctor): report the Higgsfield CLI and its session 2026-09-30 16:11:33 +02:00
bastien 51a3353360 chore(higgsfield): lock entry and gitignore for the skill pack 2026-09-30 16:11:29 +02:00
bastien bbd3d209d3 feat(update): refresh the Higgsfield CLI and skill pack 2026-09-30 16:10:08 +02:00
bastien 83043412d0 feat(install): Higgsfield step 8.6; login offers test stdin alone 2026-09-30 16:08:34 +02:00
bastien acb6cd7cb4 feat(toggle): higgsfield and higgsfield-websites toggles 2026-09-30 16:06:43 +02:00
bastien 21df604eb0 fix(higgsfield): guard the suite's cleanup trap 2026-09-30 16:05:37 +02:00
bastien 67b7c98d70 feat(higgsfield): skill pack sync helper and CLI probes, with suite 2026-09-30 16:03:49 +02:00
bastien 65045f6abd docs(plan): close the confirmation-pass findings on the higgsfield plan 2026-09-30 16:00:32 +02:00
bastien 1f4bd4a75a docs(plan): revise the higgsfield plan and spec after the three-lens challenge 2026-09-30 15:06:43 +02:00
bastien 64d094f93a docs(plan): higgsfield pack implementation plan 2026-09-30 14:45:45 +02:00
bastien 4a96ec20b5 docs(spec): higgsfield pack design 2026-09-30 14:26:57 +02:00
bastien 3dad33e475 fix(settings): deny the npm global-install aliases
The deny list matched `npm install -g` only; `npm i -g` and the
`--global` spellings went through.
2026-09-30 14:26:56 +02:00
bastien cceedab095 chore(memory): journal — effort-pins LOW round merged to develop 2026-09-29 2026-09-29 18:04:30 +02:00
bastien 04df0f8979 Merge bugfix/effort-pins-low into develop 2026-09-29 18:04:22 +02:00
bastien be30869775 chore(memory): journal + TODO — effort-pins LOW round, 3 residual parked 2026-09-29 17:12:49 +02:00
bastien 3ce0ff163e docs(effort): helper header names the signal trap and the quoted rejection 2026-09-29 16:48:14 +02:00
bastien 0c135a0ab7 fix(effort): five residual LOW on lib/effort-pins.sh
INT/TERM trap removes the mktemp sibling and exits 130 (traps restored,
never EXIT); re-read message honest and reached by a stubbed test; rejected
map line printed through printf %q; suite guards mktemp -d and skips the
read-only case under root. Cases T13b, T15, T15b, T16.
2026-09-29 16:45:57 +02:00
bastien 5f39f01159 chore(memory): journal — effort round merged to develop 2026-09-29 2026-09-29 16:41:48 +02:00
bastien 902bc76a2f Merge feature/effort-round into develop 2026-09-29 16:41:35 +02:00
bastien 54a93eabe2 chore(memory): BDR-108 effort round, LRN-181/182, BLK-024 resync pins, EVAL-038 sub-agent thinking unmeasured, journal, TODO parked LOW 2026-09-29 15:41:25 +02:00
bastien bb46ee22eb fix(effort): harden lib/effort-pins.sh (security gate, 4 LOW)
Last map line without newline read; unclosed frontmatter skipped with an
err; level re-read after write, mismatch counted as failed; mktemp + cp -p
+ mv, temp removed on failure; rc 1 on any rejected or failed entry.
Cases T11-T14 in the fixture suite; contract criteria 8-9.
2026-09-29 15:36:18 +02:00
bastien c7e8d8191d chore(todo): effort round S1-S7 ticked, gates recorded 2026-09-29 15:14:03 +02:00
bastien 7d8407ec36 docs(effort): design-stack doctrine names the vendored members only
Plugin (ui-ux-pro-max) and gstack (design-html, design-review) members carry
no pin and run at the level in force (verifier observation).
2026-09-29 15:11:48 +02:00
bastien cd3a745857 fix(effort): resync re-applies the pins after the 21st pack refresh, order locked
The 21st pack refresh (update-all 7.4) rewrites every 21st-* SKILL.md after
the superpowers refresh; the re-apply now sits after it, the census locks
the order in both scripts. Contract: criterion 3 anchor, shellcheck
directive authorized, tracked design-motion-principles copy gated.
2026-09-29 15:09:45 +02:00
bastien afa89f9cd9 feat(effort): tracked design-motion-principles copy carries its high pin
The only vendored external tracked in git; the resync (update-all 7.2)
overwrites it and lib/effort-pins.sh puts the line back.
2026-09-29 13:15:57 +02:00
bastien c859ae256f feat(effort): entry level on every skill next to its model pin (BDR-108)
- lib/effort-pins.txt (map) + lib/effort-pins.sh (idempotent re-apply)
  replace the hardcoded brainstorming/writing-plans loop; called after the
  last vendoring step of install-plugins.sh AND update-all.sh (the resync
  dropped the pins until the next make plugin)
- design stack high uniform (last loaded wins), superpowers, agent-skills,
  21st pack pinned from the map; skills-perso low, pdf-translate medium,
  site-motion high
- doctrine: design stack loads paired with the first Read; one level per
  stack (CLAUDE.global.md, lib/effort-shift.md)
- lib/effort-audit.py prints thinking coverage per scope (sub-agent records
  carry no thinking count on ~94 % of requests)
- census map-driven + fixture suite lib/tests/effort-pins.test.sh; docs
  README/USAGE/CHANGELOG; contract + TODO plan
2026-09-29 13:15:41 +02:00
bastien 3fcc0c8211 Merge chore/hook-msg-name into develop 2026-09-29 13:07:31 +02:00
bastien a5b3374fb2 fix(gitflow): push hook names itself in its failure message (post-merge said post-commit) 2026-09-29 13:05:31 +02:00
bastien c83e407bfa chore(memory): journal — gitleaks protect fallback merged 2026-09-28 21:57:22 +02:00
bastien 55b77e3baf Merge bugfix/gitleaks-protect-fallback into develop 2026-09-28 21:57:06 +02:00
bastien 347073a0cc fix(gitflow): pre-commit gitleaks scan falls back to protect --staged on < 8.19
Ubuntu's gitleaks 8.16 package has no git subcommand, so the hook's
"unknown command" exit 1 blocked every commit as a leak. Probe
gitleaks git --help once, fall back to protect --staged; regenerate the
installed hooks. T16c simulates a missing binary with a /usr/bin symlink
farm minus gitleaks instead of a shorter PATH.
2026-09-28 21:40:58 +02:00
bastien 1b95834865 chore(memory): journal — effort tiering merged to develop 2026-09-28 2026-09-28 21:21:47 +02:00
bastien 94ede35f06 Merge feature/effort-tiering into develop 2026-09-28 21:21:32 +02:00
bastien 5b3ea682b4 chore: purge transient planning artifacts (BDR-065) 2026-09-28 21:21:31 +02:00
bastien e529801411 fix(effort): judgment-dispatch shift under its heading (ship-feature, init-project) 2026-09-28 20:50:26 +02:00
bastien a70430e683 chore(memory): EVAL-037 deduped counts, BDR-107 correction, LRN-180 pairing rule, TODO count 2026-09-28 20:48:35 +02:00
bastien 58c3a3e9b7 fix(effort): re-raise judgment dispatches, planning re-asserts, pairing caveat, dedupe audit script (final review I1-I3) 2026-09-28 20:48:27 +02:00
bastien a3b479e984 fix(effort): reflow effort-audit.py to 80 columns (R12) 2026-09-28 20:27:46 +02:00
bastien 5ed96aa8ed chore(memory): BDR-107 effort tiering, EVAL-036 A/B, journal, TODO W1-W4 ticked 2026-09-28 20:20:10 +02:00
bastien 98ef991958 docs(effort): BDR-107 id, CHANGELOG entry, spec corrected for the rulings (vendored pins, exclusions, pairing rule) 2026-09-28 20:20:05 +02:00
bastien 1e3339358c feat(effort): transcript audit script for the thinking/cost split 2026-09-28 20:14:00 +02:00
bastien dd9488964b feat(effort): re-assert the skill level after prose gates that end the turn 2026-09-28 20:04:11 +02:00
bastien 557e4cc317 feat(effort): max at the verify-secure caps and ship-feature 4b; STOP texts suggest /effort-max 2026-09-28 20:02:56 +02:00
bastien a117e7ed67 fix(effort): shifts are sent with the step's first tool call (harness pairing rule); challenge shifts under their heading; fence indentation 2026-09-28 19:55:47 +02:00
bastien 3c58160d0c feat(effort): wire phase shifts in the 13 orchestrators and the handover writer 2026-09-28 19:44:22 +02:00
bastien 4a450ea6bc feat(effort): five shifter skills, lib/effort-shift.md, model-gate second axis 2026-09-28 19:32:26 +02:00
bastien 3de9d4f85a fix(effort): find-docs is ctx7-generated and gitignored, no entry level (30 skills, not 31) 2026-09-28 19:23:43 +02:00
bastien bac235cb33 feat(effort): xhigh on the vendored brainstorming and writing-plans, re-applied at resync 2026-09-28 19:21:15 +02:00
bastien 94189adbc6 feat(effort): entry effort level on the 31 user-invoked skills (spec D3)
A/B /reconcile headless — BEFORE requests=18 output=12374 thinking=3135 effort={'high'} duration_ms=96518 / AFTER requests=15 output=9038 thinking=2248 effort={'low'} duration_ms=78410
2026-09-28 19:11:21 +02:00
bastien 9223fda99f feat(effort): pin effort on the 20 repo-authored agents (BDR-077 second axis) 2026-09-28 18:59:49 +02:00
bastien 45ae0d1217 feat(effort): session default high, env-var warning, live effort in statusline 2026-09-28 18:52:36 +02:00
bastien 5437638437 test(effort): census suite skeleton with flip-test and settings lock 2026-09-28 18:49:40 +02:00
bastien bb28ecefa2 docs(plan): ins_before_para helper for prose anchors (SDD preflight ruling) 2026-09-28 18:47:03 +02:00
bastien 4b722e05c9 docs(plan): effort tiering implementation plan, 11 tasks in 4 waves; TODO section 2026-09-28 18:35:38 +02:00
bastien 854b74e9a4 chore(memory): LRN-179 + EVAL-035 — effort spike facts, thinking-share measurement 2026-09-28 18:24:34 +02:00
bastien 5367b29188 docs(spec): effort tiering design — session high, agent pins, skill effort, phase shifts, max at loop caps 2026-09-28 18:17:34 +02:00
bastien 90242773c1 chore(memory): journal — floor-guard hotfix merged to develop 2026-09-28 2026-09-28 17:06:34 +02:00
bastien c9f9b40086 Merge bugfix/floor-guard-xit-boundary into develop 2026-09-28 17:06:16 +02:00
bastien 018dfa3556 docs: CHANGELOG floor-guard entry names the SKIP boundary fixtures — hotfix floor-guard-xit-boundary 2026-09-28 17:06:15 +02:00
bastien f3f79bb145 chore(memory): BLK-023 resolved — floor-guard xit boundary hotfix, contract, plan, journal 2026-09-28 16:58:30 +02:00
bastien 0deb5594d5 fix(floor-guard): word-bound the bare Jasmine skip patterns
skip_kind matched SKIP_SUBSTRINGS as plain substrings, so 'xit(' hit
exit(, SystemExit( and process.exit(, and 'fit(' hit model.fit( and
profit(, flagging FLOOR SKIP on ordinary test-file lines (BLK-023). The
four bare identifiers (xit, fit, xdescribe, fdescribe) now match through
SKIP_IDENT_RE with an identifier-boundary lookbehind; the dotted and
decorator forms stay substrings. Flip-test fixtures cover the false
positive (RED before, GREEN after) and the three focus/skip calls.
2026-09-28 16:57:47 +02:00
bastien 0a805c562f chore(memory): journal — superpowers vendoring merged to develop 2026-09-28 2026-09-28 15:09:18 +02:00
bastien 65665a552c Merge feature/superpowers-vendored into develop 2026-09-28 15:08:58 +02:00
bastien 7177258f3d chore(memory): BDR-106 superpowers vendored — contract, plan r3, oracles, TODO, journal 2026-09-28 14:54:53 +02:00
bastien ddea411491 chore(config): superpowers citers by bare name, routing map, docs, settings
Every superpowers-prefixed skill call in ship-feature, init-project, tour,
deploy, audit-delta, plugin-advisor and lib/analyze-before-plan now names
the vendored skill directly. finishing-a-development-branch is described
as the upstream skill this config does not vendor (gitflow finish is the
integration path). CLAUDE.global.md Skill routing maps the four
non-vendored skills the vendored text still references. settings.json
loses the plugin key and its marketplace block; README, USAGE,
plugin-advisor and the profile skill describe superpowers as vendored
skills, always on, zero plugin cost. CHANGELOG entry with a known
residual.
2026-09-28 14:54:53 +02:00
bastien 18f8c898f8 feat(superpowers): vendor the 7 wired skills at v6.4.1, drop the plugin
plugins.lock.json gains a superpowers entry (obra/superpowers @ 5bf4e78,
path skills, per-skill file lists, always_on) that lib/vendor-skills.sh
fetches byte-for-byte: brainstorming, writing-plans,
subagent-driven-development, test-driven-development,
requesting-code-review, using-git-worktrees, writing-skills. install-plugins
STEP 8e vendors it, update-all refreshes it at the pin, link.sh links the
seven, .gitignore ignores them. The plugin is no longer installed or
protected: its 8 other skills duplicated personal flows and its
SessionStart injection cost ~900 tokens per start, clear and compact.
detect_superpowers is one file test on the linked skill; doctor and
session-start stop charging the injection. doctor-vendored gains an
always_on class (third lock column) so always-on externals are
link-checked instead of reported parked.
2026-09-28 14:54:52 +02:00
bastien c39c0e1045 Merge feature/skill-catalog-prune into develop 2026-09-28 13:55:04 +02:00
bastien 1805a3cc97 chore(memory): BDR-105 skill-catalog prune + 21st gate, LRN-175..178, BLK-023, EVAL-034 2026-09-28 13:54:51 +02:00
bastien 132bcdf7c5 chore(memory): 21st sign-in gate — contract, plan r3, TODO, journal 2026-09-28 12:51:56 +02:00
bastien bd3e525bb3 feat(design-gate): ask for 21st login and wait instead of skipping
The design gate checked the 21st CLI with command -v only, so an
installed-but-signed-out CLI read as READY and every 21st step failed
downstream. tool_active now probes 21st whoami through a three-state
function: signed in (TWENTYFIRST_TOKEN or API_KEY_21ST set, or 'Logged in
as'), signed out (exact 'Not logged in'), unknown (rc != 0, timeout,
unexpected output). Signed out is a new verdict, SIGN-IN REQUIRED, exit
12: design-gate.md tells the orchestrator to ask the user to run
! 21st login, end the turn, re-run the gate on their reply, and to skip
21st only on an explicit 'proceed without 21st', never silently. Unknown
surfaces as exit 11 with the whoami diagnostic and a CLI-runtime remedy,
so a node/PATH failure can never loop on a sign-in prompt. INCOMPLETE
still wins. Hermetic suite lib/tests/design-tool-gate.test.sh (stub CLI,
fixture repo through DESIGN_GATE_REPO_OVERRIDE) covers every state.
2026-09-28 12:51:55 +02:00
bastien 729d71546f chore(memory): skill-catalog prune — contract, plan r4, oracles, TODO, journal 2026-09-28 11:49:02 +02:00
bastien 4c86d6dc70 chore(config): security-guidance Stop review off, plugins off, routing and docs
settings.json: ENABLE_STOP_REVIEW=0 (the plugin's own switch: no more
Opus call on every turn that changes code, 0 findings in 6 days, 1
recorded false positive; the regex layer and the commit/push agentic
review stay on), brightdata-plugin@synced false (keyless-useless, its MCP
skill would hijack WebFetch/WebSearch), frontend-design official plugin
entry gone (uninstalled: byte-identical to the managed copy).

CLAUDE.global.md routes Ship/PR to ship-feature (gstack ship takes
origin/HEAD = main as base), drops ship/context-save from the gstack-off
list and 21st-ui-review from the design review line (trio is max-only).
deploy's table no longer points at land-and-deploy/setup-deploy.
plugin-advisor.md describes security-guidance's real mechanics. CHANGELOG
Unreleased entry with a Known residual section.
2026-09-28 11:49:01 +02:00
bastien 02b62f787e fix(gstack): one helper-link tree for every hardcoded path, honest doctor stats
gstack skills hardcode ~/.claude/skills/gstack/<path> for 83 shared assets
(bin, scripts/jargon-list.json, ETHOS.md, */sections, review/specialists,
make-pdf/dist, lib/diagram-render/dist, freeze/bin...) but only bin and
browse/dist were linked: make-pdf and diagram failed on every run, cso and
plan-*-review could not read their sections, the freeze hook exited 127.
lib/gstack-links.sh links every top-level entry except SKILL.md, skips
non-skill dirs holding a nested SKILL.md (browser-skills, openclaw,
node_modules), removes the global symlink gstack ./setup plants and refuses
a destination inside the submodule. link.sh, install-plugins.sh and
update-all.sh all call it (three hand-copied blocks gone).

doctor.sh counted 34 skills (find without -L) and zero chars for block
scalar descriptions; lib/doctor-skills.sh reuses the census parser and
counts through the symlinks. Plugin constants re-based on measured values;
install-plugins.sh notes why frontend-design@claude-plugins-official and
brightdata-plugin@synced stay off and describes security-guidance truthfully.
2026-09-28 11:48:45 +02:00
bastien f83f8f755b feat(profiles): prune the gstack catalog, add max, honor a removed denylist
Nine gstack skills leave every profile (ship is trunk-based on Gitea,
land-and-deploy auto-merges and deploys, setup-deploy, autoplan reads
paths that do not exist here, context-save has no restore, learn is an
unused parallel store, careful and guard hooks never fired, design-shotgun
needs an absent OpenAI key). lib/gstack-removed.sh is the single denylist;
profile.sh gstack on and toggle-external.sh enable gstack skip it.

full now carries everything every other profile carries (user rule), minus
the parked make-pdf, diagram and 21st-ai/ui-explore/ui-review, which live
in the new max profile together with pr-review-toolkit. The 21st trio also
leaves web, web-full and design (redundant with impeccable + ui-ux-pro-max).

lib/tests/profile-census.test.sh asserts the invariants live and on a
baseline fixture plus one mutant per invariant; gstack-removed.test.sh
covers both restore paths.
2026-09-28 11:48:44 +02:00
bastien d91d8d820a chore(memory): journal — doctor vendored check merged to develop 2026-09-28 2026-09-28 04:14:35 +02:00
bastien 2c94a0cc5e Merge feature/doctor-vendored-skills into develop 2026-09-28 04:14:27 +02:00
bastien 47c9650ef8 chore(memory): doctor vendored check — contract, CHANGELOG, BDR-104 amendment, journal 2026-09-28 04:11:17 +02:00
bastien 6394fa79fc feat(doctor): check the vendored external skills
lib/doctor-vendored.sh check_vendored_skills: every curl-pinned lock entry
has its files under skills-external/ (list, dict, single-path shapes),
every link.sh EXTERNAL_SKILLS name is symlinked into ~/.claude/skills when
the active profile lists it, parked names reported not failed, hints make
plugin / make link. Lock shape-validated (warn, never a traceback), profile
and item names allowlisted before becoming paths. Suite: 11 cases.
2026-09-28 04:11:16 +02:00
bastien dbcfbe9221 chore(memory): journal — case 7 merged to develop 2026-09-28 2026-09-28 02:36:08 +02:00
bastien d3633db1db Merge feature/mengto-site-motion into develop 2026-09-28 02:35:54 +02:00
bastien 36f94b23e8 chore(memory): BDR-104 amendment, journal, TODO — LOW hardening closed 2026-09-28 02:35:53 +02:00
bastien 415b44ed25 fix(lib): vendor-skills validates lock fields, fullmatch guard
Two security-gate LOW notes closed on user ask: the SAFE guard uses
re.fullmatch so a trailing newline is rejected; commit (40 hex), source
(github.com owner/repo) and path (SAFE class, no traversal) are validated
before any URL is built, INVALID marker names the field. Suite 12 cases.
2026-09-28 02:35:52 +02:00
bastien 8dcf8d3680 chore(memory): case 7 registries, contracts, CHANGELOG — BDR-104 LRN-174 EVAL-033 2026-09-28 01:40:02 +02:00
bastien ba14b5ea03 feat(skills): site-motion, site-level scroll and transition choreography
Personal skill distilling the MengTo motion pack invariants (LRN-141):
gates first (reduced motion renders final states, content visible without
JS, compositor-only, offscreen pause), one smooth-scroll engine with the
Lenis/ScrollTrigger sync, Astro ClientRouter lifecycle, numbered recipes
(reveal, scrub, sticky stack, video and image scrub, TreeWalker split,
progressive blur, marquee, WebGL budgets), upstream pitfalls, checklist.
Routed into the Build UI chain of CLAUDE.global.md and lib/design-gate.md.
2026-09-28 01:40:01 +02:00
bastien 2a1ad1797b feat(lib): vendor-skills helper, five MengTo scroll skills pinned
lib/vendor-skills.sh: vendor_pinned_skills <lock-key> [refresh], list or
dict lock shapes, lock read via python argv, traversal and charset guard
on lock values, VENDOR_BASE_URL honoured only as file:// (hermetic suite),
per-file tmp+mv, refresh skips a skill never installed. install-plugins.sh
Step 8e and update-all.sh 7.3 call it for agent-skills and mengto-skills.
Vendored at a965851: scroll-world-storytelling, build-threejs-scroll-worlds
(+5 references), scroll-scrubbed-visual-sequence, scroll-scrubbed-word-
reveal, scroll-progress-timeline; text files only. Registered in link.sh,
.gitignore, toggle-external, profile.sh and the design/web/web-full/full
profiles, which also list site-motion (personal). Suite: 8 cases.
2026-09-28 01:40:01 +02:00
bastien 7bec2fc51b chore(memory): journal — motion census correction (ui-ux-pro-max data CSVs) 2026-09-27 23:43:39 +02:00
bastien 2f81b2f3fc chore(memory): journal — 6-repo review merged to develop 2026-09-27, motion census 2026-09-27 23:30:27 +02:00
bastien 39d5b159f4 Merge chore/six-repo-review-notes into develop
# Conflicts:
#	.claude/memory/decisions.md
#	.claude/memory/journal.md
#	.claude/tasks/TODO.md
2026-09-27 23:29:05 +02:00
bastien 68fcdaf4d0 Merge feature/web-building-microrules into develop
# Conflicts:
#	.claude/memory/journal.md
#	.claude/tasks/TODO.md
#	CHANGELOG.md
2026-09-27 23:29:02 +02:00
bastien 04cb0576d6 Merge feature/agent-skills-borrow into develop
# Conflicts:
#	.claude/memory/journal.md
#	.claude/tasks/TODO.md
2026-09-27 23:28:44 +02:00
bastien b3597eb627 Merge feature/yagni-ladder into develop 2026-09-27 23:28:22 +02:00
bastien 7b0d4977ad chore(memory): BDR-103 — 6-repo review verdicts and criteria 2026-09-27 23:27:30 +02:00
bastien 197225ab46 chore(memory): case 5 OmniRoute rejected — TODO + journal, review complete 2026-09-27 21:34:10 +02:00