Commit Graph
958 Commits
Author SHA1 Message Date
Bastien Chanot 8e9ff33cd7 chore(memory): backmerge BLK-016 from release/1.0.0 (resolved on develop)
BLK-016 (rtk PATH-dead) shipped resolved in 1.0.0 (2b4e7401) but neither the entry
NOR the fix reached develop — rtk was live-broken on develop. Fix ported in the
preceding commit (install-plugins.sh bridge), so this backfill marks it resolved
truthfully. Table row + section. Review A3.
2026-07-08 15:59:09 +02:00
Bastien Chanot 416b68f7d2 fix(rtk): bridge ~/.cargo/bin/rtk into ~/.local/bin — compression was PATH-dead on develop
Ports e58037c from release/1.0.0 (never back-merged). develop installed rtk via
cargo (~/.cargo/bin) and checked 'command -v rtk' in the installer shell that
sourced cargo env — so the check passed while Claude's tool shell never got the
PATH, dropping every compound rewrite (measured on release audit: 6/5070 commands
compressed over 30 days, ~460K tokens missed). Idempotent bridge symlink, self-
repairs a stale link, skips when no cargo binary. Resolves BLK-016 on develop. Review A3.
2026-07-08 15:58:00 +02:00
Bastien Chanot 38cc821a35 chore(memory): backmerge EVAL-015 from release/1.0.0
EVAL-015 (/tour first real run, report-only bchanot-cv) shipped in 1.0.0 (74d3804),
never back-merged to develop (registry gap between EVAL-014 and EVAL-016). Section
backfill; links to now-present [[LRN-101]]. Review A3.
2026-07-08 15:55:53 +02:00
Bastien Chanot a01250ba59 chore(memory): backmerge LRN-101 from release/1.0.0
LRN-101 (nginx add_header inheritance trap — verify headers live, not in config)
shipped in 1.0.0 (74d3804), never back-merged to develop. Append-only backfill,
table row + section. Review A3.
2026-07-08 15:55:27 +02:00
Bastien Chanot 7cd82cf9c1 chore(memory): backmerge LRN-098 from release/1.0.0
LRN-098 (/model rewrites settings.json — read diff before settings commit) shipped
in 1.0.0 (a623514) but never back-merged to develop (registry gap). Append-only
backfill at numeric position, table row + section. Review A3.
2026-07-08 15:54:48 +02:00
Bastien Chanot 4e83f39a70 test(guards): add anti-partial-fix regression guards (fil rouge)
lib/tests/run-review-guards.sh — 5 whole-surface guards that RED if a banned
pattern subsists anywhere, auto-run by make test (run-*.sh glob):
  G1 trailer (A1), G2 false CLAUDE.md attribution (A5), G3 strict-YAML frontmatter
  (A4), G4 reconcile hermeticity (job3 B1), G5 hook-drift installed==emit (A2).
This is the check that would have caught A1/A4/A5/A2 at make-test time instead of
an adversarial review — the series' recurring failure was fixing one instance and
leaving twins. G3/G5 degrade to SKIP if pyyaml/emit-hook absent (portability).
Teeth verified: a planted trailer in a real agent REDs G1. Review fil rouge.
2026-07-08 15:48:51 +02:00
Bastien Chanot f0111e107d fix(geo-analyzer): drop false CLAUDE.md attribution, own-policy PERMISSIVE default
geo-analyzer asserted 'PERMISSIVE default per user CLAUDE.md' in 2 sites (L224,
L867-869) but CLAUDE.md carries no PERMISSIVE/RESTRICTIVE crawler policy. Reframed
as the agent's own policy grounded in GEO's purpose (an AI-visibility audit defaults
to allowing AI crawlers); default unchanged. Completes job3 C6/C7/C8 scrub (which
missed geo) — job9's later rewrite also left it. User-approved wording. Review A5.
2026-07-08 15:19:52 +02:00
Bastien Chanot 5a0fc1653a fix(agents): quote strict-YAML descriptions (seo-analyzer, security-auditor)
Both line-3 descriptions contained an unquoted ': ' (and '|') that fails
python3 yaml.safe_load ('mapping values are not allowed here'). seo-analyzer's
line was last rewritten by job9/a5a7b54 AFTER job2's F7 strict-YAML rule
(git blame); security-auditor's dates to job6. Single-quote wrap, no internal
apostrophes. Gate: yaml.safe_load over ALL agents/*.md now clean. Review A4.
2026-07-08 15:17:27 +02:00
Bastien Chanot d4526e6fa7 chore(gitflow): regenerate installed pre-commit hook to include job7 gitleaks backstop
Root cause: job7/17bdd08 added the gitleaks scan to the hook GENERATOR
(_gitflow_emit_pre_commit) but the installed .githooks/pre-commit is only
(re)written by 'gitflow init'/'install-hook' — never invoked on this repo after
job7. No mechanism propagates a generator change to already-installed hooks, and
T10 diffs only the allow/block verdict (not content), so the drift was silent.
The installed hook (620071b, 2026-06-29) predated the gitleaks addition by 8 days.

Regenerated via 'gitflow.sh install-hook'; installed hook now == fresh emit.
Gates: grep -c gitleaks=7; negative test (staged AKIA... on a working branch)
BLOCKED with exit 1; make test GREEN. Review finding A2 (P0). A content-drift
assertion is added to make test in the fil-rouge commit.
2026-07-08 15:16:19 +02:00
Bastien Chanot 56018df52b fix(agents): strip banned Co-Authored-By trailer from bugfixer/feater/hotfixer templates
Completes job9/5a3de92 (which only cleaned commit-changer). These 3 execution
agents still emitted the banned trailer into their commit-message templates;
the settings.attribution backstop does not filter agent-authored message bodies.
Extended sweep of agents/ lib/ hooks/ templates/ for Co-Authored-By|Claude-Session|
--trailer now returns zero. Review finding A1 (BLOQUANT), J4-16 follow-up.
2026-07-08 15:14:00 +02:00
Bastien Chanot 02409bbda7 Merge branch 'chore/job9-agents' into develop 2026-07-08 13:23:02 +02:00
Bastien Chanot aa73793b90 chore(memory): job9 — commit-changer trailer fix + J4-16 cross-check follow-up 2026-07-08 13:10:10 +02:00
Bastien Chanot 5a3de923ac job9: strip banned attribution trailer from commit-changer template 2026-07-08 13:09:29 +02:00
Bastien Chanot f667780156 chore(memory): job9 — BDR-060 version floor, BDR-061 path-b, LRN-112 nesting, journal + TODO 2026-07-08 12:43:39 +02:00
Bastien Chanot af9656faee job9: H1+H2 code-cleaner→refactorer — INLINE-LOAD verb + named handoff contract, drop unused Agent 2026-07-08 12:38:42 +02:00
Bastien Chanot 87d63bfa93 job9: H2 mark scaffolder→doc-syncer as INLINE-LOAD (idiom disambiguation) 2026-07-08 12:38:42 +02:00
Bastien Chanot 212f9aa968 job9: dispatchers tolerant of analyzer batch labels (smoke-A hardening) 2026-07-08 12:38:42 +02:00
Bastien Chanot 70fb3b46e7 job9: /geo becomes dispatch+apply orchestrator (L1 bundle apply, mirrors /web-validate) 2026-07-08 12:28:13 +02:00
Bastien Chanot c498b93e9d job9: /seo applies analyzer fix-bundles at L1 (STEP 1.5, serial by ownership) 2026-07-08 12:28:13 +02:00
Bastien Chanot 6df42e4f9a job9: re-architect geo-analyzer to fix-bundle→L1 (path b, no nested dispatch) 2026-07-08 12:24:22 +02:00
Bastien Chanot a5a7b54f28 job9: re-architect seo-analyzer to fix-bundle→L1 (path b, no nested dispatch) 2026-07-08 12:24:22 +02:00
Bastien Chanot 5ab6c21e38 job9: D pin plugin-advisor to sonnet 2026-07-08 02:50:08 +02:00
Bastien Chanot 1c270e6537 job9: C pin security-auditor to sonnet 2026-07-08 02:50:08 +02:00
Bastien Chanot ea6c126f73 job9: B pin verifier to sonnet 2026-07-08 02:50:08 +02:00
Bastien Chanot 0ede52c0ea job9: A commit-changer drop unused Agent tool 2026-07-08 02:50:08 +02:00
Bastien Chanot e4ba8edc16 adde changed settings 2026-07-08 01:29:06 +02:00
Bastien Chanot 5822869056 chore(memory): job8 capitalize — journal + TODO follow-ups
Session log for job8 (A/B/C/D execution, 3 Bash permission denials
worked around mid-C, smoke gate confirmed by user). TODO tracks the
2 open residuals: C/D single-pass re-audit next cycle, MAGIC_API_KEY
rotation still pending (job7 residual, unrelated to job8's own scope).
2026-07-07 23:58:50 +02:00
Bastien Chanot 66e4c4d0f9 docs(mcp): job8 B — document component_builder callback-injection risk
BDR-059 + LRN-110 + LRN-111. Confirmed A's ask-gate covers component_builder
(mcp__ scope) — no code fix possible or attempted, it's third-party package
code (dist/utils/callback-server.js:36). README MCP section now documents
the risk and why the mitigation is ask-gating, not patching.
2026-07-07 23:48:52 +02:00
Bastien Chanot c34ac99882 chore(memory): job8 C — darwin-skill reinstalled full pinned tree, detached HEAD
BDR-058 + LRN-109. Root cause of the "referenced files absent" finding:
the skills CLI's skillPath only fetches SKILL.md, never sibling
references/scripts/templates dirs. Upstream HEAD matched the already-
recorded lockfile hash exactly (no drift, no tamper) — reinstalled the
full tree at that pinned SHA, detached HEAD so nothing can silently
advance. Reinstall happened outside this repo (~/.agents); this commit
is the only repo-side record. Backup of the old single-file dir kept.
2026-07-07 23:47:07 +02:00
Bastien Chanot bb7f25adc1 chore(perms): explicit ask-gate for all magic MCP tools (job8 A)
Empty allowlist stays empty for mcp__magic__* (deny-by-default,
no auto-exec ever). All 4 tools now explicit in permissions.ask
so confirmation is guaranteed regardless of default-mode fallthrough,
instead of relying on undocumented absence. No wildcard.
2026-07-07 19:23:33 +02:00
Bastien Chanot e9241d5d7c added some rules 2026-07-07 13:17:23 +02:00
Bastien Chanot eade4e603e job7 capitalize: BDR-057, BDR-026 update, LRN-108, journal
BDR-057: secrets by reference not by value; redact at capture, not just at
rest. Documents the two-part job7 posture (MCP ${VAR} expansion + rtk-rewrite
env-dump redaction) and flags the unreconciled contradiction with job6's
same-day (wrong) finding that ${VAR} expansion was unsupported at user scope.

BDR-026 updated: the backup-vector incident (2026-07-02) is closed at the
source rather than by repeated scrubbing — every native auto-backup taken
while the live file held the plaintext value was a fresh leak, so scrubbing
existing backups alone would have recurred forever.

LRN-108: `claude mcp add --env KEY=value` writes the value literally —
double- vs single-quoting around `${VAR}` is the entire difference between
a reference and a plaintext-forever config. The natural way to type the
flag (bash-expand it first) is exactly the trap.

Also refreshed .audit/scan-secrets-claude-home.json to the post-purge state
(15 residual hits, down from 18 pre-D).
2026-07-07 12:58:51 +02:00
Bastien Chanot 5d5b386b9c job7 step D: purge stale secret-bearing artifacts (GO-gated)
- rm ~/.claude/projects/.../960bd2cf-...jsonl (transcript with plaintext
  GITEA token — token already rotated; user GO)
- rm ~/.claude/paste-cache/7d48f52c7499c1a7.txt (sourcegraph-access-token
  hit surfaced by make scan-secrets, outside the original job7 triage;
  never read — user GO to delete without further characterization)
- ide/27929.lock: already gone (natural rotation, session ended). Its
  replacement ide/20429.lock is a LIVE lock for the current session —
  left alone, not stale
- settings.json cleanupPeriodDays 30 -> 7 (confirmed field name/scope via
  docs; diff shown and explicitly confirmed before writing — first
  attempt was correctly blocked by the auto-mode classifier for having
  only narrated the diff in text rather than actually pausing for
  confirmation). Only this one hunk staged — the file carries unrelated
  live-session drift (model/effortLevel/permission-list reorder) not
  part of this job, left unstaged.

Residual, deliberately not decided here: transcript f1c9c474-...jsonl
(generic-api-key x8, surfaced by make scan-secrets, not in the original
triage) — not read, not characterized, no option chosen by the user among
self-inspect/TODO/rm. Left intact in TODO as an open item.
2026-07-07 12:53:48 +02:00
Bastien Chanot 17bdd08b43 job7 step C: gitleaks backstop — .gitleaks.toml, pre-commit hook, make scan-secrets
Pre-commit (lib/gitflow.sh emit-hook) now runs `gitleaks git --staged` right
after the root-commit/merge-in-progress guard, on ANY branch — not gated by
branch protection, since secrets shouldn't land anywhere. Non-blocking if
gitleaks isn't installed (warn + pass). gitleaks 8.30.1: `protect` isn't
listed in --help anymore (still runs, but undocumented) — used the
documented `git --staged` equivalent instead.

.gitleaks.toml allowlists the 3 false-positive classes from the job7 triage
(marketplace.json 40-hex "sha" fields, superpowers ws-protocol.test.js nonce,
git-game test-secret-* fixtures) plus a 4th entry for ~/.claude/.env itself —
not a false positive, but scanning our own canonical vault (BDR-026) is pure
noise for a tool meant to catch stray copies. All 4 verified empirically
against the real flagged files/values before being added, not assumed from
gitleaks' docs.

`make scan-secrets` scans this repo's git history + ~/.claude (dir scan),
redacted JSON to .audit/ (verified: --redact scrubs Match/Secret in the
report itself, not just console logs — safe to commit). Repo: 0 findings.
~/.claude: 18 remaining across 8 files — 5 match the known job7 triage
(pending the GO-gated purge in step D), 3 are new discoveries outside the
original triage scope (flagged for the user, not characterized further —
never read a flagged file's content past what gitleaks' redacted report
gives you).

lib/gitflow-test.sh T16: fake secret on a feature branch (not main/develop)
→ blocked, proving the check isn't gated by branch protection; clean commit
passes; PATH without gitleaks → warns and still commits. 96/96 green.
2026-07-07 12:47:06 +02:00
Bastien Chanot b9300c3382 job7 step A: MAGIC_API_KEY by reference, not by value (BDR-026 follow-up)
toggle-external.sh's `claude mcp add magic --env API_KEY="$MAGIC_API_KEY"`
materialized the key as plaintext into ~/.claude.json — a copy outside the
~/.claude/.env canonical, invisible to the repo's gitignore/allowlist reach.
Claude Code supports ${VAR} expansion in mcpServers config (docs confirmed),
so the fix is a reference, not a scrub.

- lib/toggle-external.sh: --env 'API_KEY=${MAGIC_API_KEY}' (single-quoted
  literal reference, not bash-expanded) so future `enable magic` runs write
  the safe form too.
- README: new "Adding an MCP server that needs a secret" section documenting
  the --env pitfall and the wrapper pattern.

Out-of-repo companion changes (not in this commit): ~/.bashrc gained a
scoped claude() wrapper that sources ~/.claude/.env into a subshell before
exec'ing the real binary (verified: the var never reaches the ambient
interactive shell, only claude + children) — chosen over a global export to
keep the secret's surface minimal. ~/.claude.json's mcpServers.magic.env.API_KEY
was rewritten to the same "${MAGIC_API_KEY}" reference via a surgical jq
edit (never read directly, so the value never entered this session's
context). The 2 of 5 rotating ~/.claude/backups/.claude.json.backup.* files
still holding the old plaintext were scrubbed the same way.

Residual: this session predates the bashrc wrapper, so `claude mcp list`
currently warns "Missing environment variables: MAGIC_API_KEY" — expected,
resolves on next terminal + Claude Code restart. MAGIC_API_KEY rotation
still pending (user action, after this commit).
2026-07-07 12:37:29 +02:00
Bastien Chanot 3340c7d1bd job7 step B: redact printenv/env dumps in rtk-rewrite.sh (GITEA leak vector)
Any single-pipeline printenv/env dump now gets a redaction pipe appended
before it can reach stdout/transcript; `env VAR=x cmd` (legitimate
subprocess launch) is left intact. Compound commands (;, &, ||) bail
untouched — appending the pipe at the end would attach to the wrong
segment.

Discovered mid-implementation: rtk rewrite classifies any command
containing "env" as exit-code 2 ("deny"), with no settings.json rule
backing it — the command still reaches native evaluation and can run.
Adjusted case 2/1 handling so the redaction check runs regardless.
2026-07-07 12:30:30 +02:00
Bastien Chanot 563fbd5422 job6: capitalize — BDR-056, LRN-107, EVAL-020, journal
BDR-056: deps policy reversal — latest gated by integration, not
KEEP-PINNED by default (job6-batch-3 override, gstack #1911 case).
LRN-107: read-only subagent mandates must ban copying secret VALUES,
not just mutations (job6's own MAGIC_API_KEY scratch-copy incident).
EVAL-020: job6 execution quality — 2 real STOP gates hit and resolved
live (graphifyy hook rewrite declined, gsd-pi format break patched).
2026-07-07 04:07:07 +02:00
Bastien Chanot 00c97bcacb job6: supply-chain documentation pass (F-X1, semgrep caveat)
- README + plugins.lock.json graphifyy note: pipx/PyPI install only, never
  npm/npx — a different publisher (rhanka/graphify) squats the same
  'graphifyy' name on npm as a version-shadowing shim with its own
  conflicting 'graphify' bin (F-X1).
- agents/security-auditor.md: one-line caveat that p/* semgrep packs are
  fetched from the registry at runtime — the CLI version pin does not
  freeze ruleset content, so a new BLOCK can appear on unchanged code.

MCP magic (F-X3): version pin declined by user call (stays @latest in
lib/toggle-external.sh). ${VAR} env expansion confirmed unsupported at
~/.claude.json user scope (Claude Code docs — expansion is .mcp.json
project-scope only), so the BDR-026 reference-not-plaintext pattern
doesn't transfer here; existing mitigations (canonical ~/.claude/.env,
gitignore, audit env-field filtering) remain the practical ceiling.
~/.claude.json regenerated out-of-repo via toggle-external.sh disable+
enable magic to pick up the already-rotated MAGIC_API_KEY (no repo diff,
no commit for that file — traced in the job6 final report).
2026-07-07 03:42:15 +02:00
Bastien Chanot 2813e55289 job6: gstack submodule 070722a→11de390 (v1.52.1.0→v1.58.5.0)
Full pull per user verdict (human review of #2047 gbrowser stealth done,
accepted) — motivated by the #1911 fail-open fix for 4 security guards
(careful, guard, freeze, data-loss) plus PII/secrets redaction (#1797),
telemetry-consent + cache sanitization (#1848).

Gate: make test 90/0 green after bump; re-ran link.sh (symlinks already
current) + gstack ./setup (browse binary rebuilt); smoked /careful and
/freeze (guard's constituents) via direct JSON-payload invocation
(job4 §2.3 idiom) — both confirmed blocking a trivial case (rm -rf,
edit outside freeze boundary) that must be blocked.

Local playwright pin (BDR-029/BLK-008, ubuntu26.04 Chromium support) was
reset by the submodule checkout as designed, then re-applied via
gstack_bump_playwright_if_unsupported's own steps (bun install,
detect unsupported, bun add playwright@latest — 1.58.2→1.61.1, one
minor ahead of the pre-bump local patch). Original local diff backed
up before discarding: scratchpad/gstack-local-playwright-fix-070722a.patch.

plugins.lock.json note updated with the pinned SHA and rationale.

Rollback if needed: git -C skills-external/gstack checkout 070722a &&
git add skills-external/gstack && link.sh re-run.
2026-07-07 03:30:11 +02:00
Bastien Chanot b4896c9ae1 job6: gsd-pi 2.64.0→3.0.0 — adapt status-reporter parser to ADR-013 cutover
Upgrade confirmed format-incompatible before use (job6 gate, BATCH-2):
gsd-pi 3.0.0 no longer writes .gsd/ROADMAP.md (verified by generating a
real test milestone in a scratch project) — state moved to .gsd/STATE.md,
.gsd/gsd.db (authoritative DB), and one .gsd/milestones/<ID>/<ID>-ROADMAP.md
per milestone, all in a different markdown shape. Every grep/awk in
status-reporter.md PHASE 3 would silently print 0/blank against the old
path instead of erroring.

Rewired PHASE 3 to read `gsd headless query` (stable JSON snapshot, no LLM
call) instead of scraping markdown — smoke-tested against both the absent
case (this repo, no .gsd/) and a real gsd-managed scratch project.

plugins.lock.json pin bumped deliberately to 3.0.0 (update-all.sh honors
the pin; this is the required manual bump).
2026-07-07 03:23:19 +02:00
Bastien Chanot 4c105997ec job5: changelog — removed settings.local.json template + pending verbs 2026-07-07 00:58:26 +02:00
Bastien Chanot aad50e3c0b job5: J5-11 relink SETTINGS.md in README 2026-07-07 00:57:57 +02:00
Bastien Chanot 0e18116ae3 job5: BDR-055 — pending verbs removal, J4-17 closed MOOT 2026-07-07 00:57:07 +02:00
Bastien Chanot da3abf9f1b job5: J5-13 delete pending verbs (v2 hook rejected by BDR-037, J4-17 moot) 2026-07-07 00:53:49 +02:00
Bastien Chanot af4f5cc6a4 job5: J5-15 delete orphan settings.local.json template (content recoverable at a145e3c) 2026-07-07 00:50:29 +02:00
Bastien Chanot 273208878a job5: changelog — removed dead detect-plugins functions 2026-07-07 00:30:47 +02:00
Bastien Chanot 5fc38e74e6 job5: J5-10 delete plugin_enabled (last caller replaced at 6d72d0a) 2026-07-07 00:14:06 +02:00
Bastien Chanot 3c796ade9c job5: J5-04 delete detect_security_guidance (born dead at 45c3507 re-add) 2026-07-07 00:13:07 +02:00
Bastien Chanot a1b65c2540 Merge chore/job4-tests into develop 2026-07-06 22:41:39 +02:00
Bastien Chanot bb5fb0cf5c job4: capitalize execution — EVAL-019 + LRN-106 + journal
EVAL-019: job4 test-gap audit + execution summary (11 specs, 5 fixes/
seams, every mutation red-green verified, zero residual, /tmp-exhaustion
incident + recovery, SPEC-06 checkpoint honesty, J4-22 caller-census
flag).

LRN-106: fixing B1 in one file != closing the B1 pattern. job3-B1
froze a fixture + repointed run-reconcile.sh's T2 off the live
registry, declared unblocked, 20/20 green — job4's very next audit
pass found T3/T5 in the SAME FILE still reading the live registry,
same fragility, untouched siblings. Now actually closed (SPEC-10).

journal: 2026-07-06 (cont. 2) entry.
2026-07-06 21:59:58 +02:00