agents/security-auditor.md: fresh read-only-on-code SAST gate. Pinned
rulesets p/security-audit + p/secrets + p/owasp-top-ten (owasp REQUIRED —
measured: the 2-ruleset baseline misses SQLi + path-traversal entirely on
realistic Flask code), never --config auto, never auto login (BDR-048).
Severity map: secrets ERROR → CRITICAL, other ERROR → HIGH (block),
WARNING/INFO → reported. gate mode (diff, no Write) vs audit mode (Write
only to REPORT, rule-locked). DEGRADED (semgrep absent) still runs the
checklist and still blocks — never a vacuous pass (LRN-048). Anti-gaming:
a new un-gated nosemgrep suppression is BLOCKING. PROOF mandatory, mute
auditor never a PASS, blind (no iteration history), blocks HIGH/CRITICAL
only (LRN-047).
Grafts: onboard STEP 6 L3a dispatches it in audit mode (report
.onboard-audit/semgrep.md) in BOTH gstack branches — complement to cso
(cso is a gstack submodule, unmodifiable); synthesis picks it up via the
existing .onboard-audit/ sweep. audit-delta security axis runs the SAST
pass first, folds findings into the existing gate/fix/re-verify flow.
lib/tests/security-auditor.test.sh: 28 structure locks green, shellcheck
clean. Behavioral dogfood (fresh agents on a planted fixture):
BLOCK(9) on the vuln commit (2 secrets→CRITICAL, semgrep+checklist
complementarity — checklist caught the 6 semgrep missed off-context);
BLOCK(1) on a new nosemgrep suppression (understood semgrep's 0 was the
mask); DEGRADED → BLOCK(7) on grep-detectable secrets with semgrep hidden.
FP measured on real repos (faunosteo, game): owasp adds only hygiene
findings, contained by diff-scoping.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
The 07-02 tightening left bare tokens common in non-UI talk (design, component, theme, transition, frontend, palette) -> ~6 false-fires/session during the ECC config audit. Dropped them; dashboard now word-boundary matched (kills the ecc_dashboard.py filename match, keeps 'admin dashboard'); kept animation; added 'front-end design' bigram. Each fire now logs time+token+excerpt to a light file so 're-firing?' is measured, not argued. Regression test 18/18, shellcheck clean.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
Blocks Edit/Write to guardrails (settings.json + .claude/settings*, lib/gitflow.sh, .githooks/*, doctor.sh, hooks/*.sh self-guard, lib/tests/*, lint) so a gate can't be weakened to pass an error. Bypass = one-shot sentinel .claude/.config-edit-ok (non-empty reason, logged+consumed), not an env-var. Adaptation from the ECC second-look (BDR-047 corrob): own bash idiom, not ECC's Node dispatcher. shellcheck clean, test 20/20.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
A doctor that cries false is a doctor you ignore (LRN-047). Three stale
checks fixed:
- cargo "(RTK unavailable)" -> honest optional info: RTK ships prebuilt
(detect_rtk finds ~/.cargo/bin|~/.local/bin), cargo only builds it from
source.
- check_symlink passes files reached via dir-level symlinks. hooks/,
skills/, agents/, lib/, templates/ are directory symlinks, so a child
like hooks/session-start.sh is a real file under $REPO, not a symlink
itself. Now: PASS iff the canonical path lands in $REPO; a stray real
copy still warns as drift.
- gstack check counts the 34 per-skill symlinks into skills-external/gstack/
instead of a mythical skills/gstack link (link.sh deliberately removes
that one -> "run link.sh" could never satisfy the old check).
- token budget vs the 200k default context window, not a bogus 11k
"session budget" -- the old denominator was a category error producing a
false "92% CRITICAL". Measured footprint ~11.4k post-audit (LRN-088) ->
~5% of context.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
gitflow_finish ignored its <type> <name> args and always merged the
checked-out branch — `finish bugfix audit-bugs` run from
feature/audit-tokens merged the wrong branch (audit UX trap, 2026-07-02).
Args are now an optional safety ASSERTION: if present and != current
branch, refuse loudly (rc 2) instead of merging the wrong thing. No args
= unchanged (the only real caller, SKILL.md:36, passes none). +7 T12
regression assertions.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
The rtk hook no longer auto-allows (audit-bugs branch): rewritten
commands are evaluated natively. Allow rules match the original forms
(grep *, ls *) not the rewritten ones — without explicit rules every
rewrite would fall to the classifier. Added the read-only rtk-wrapped
family, bare + absolute-path forms (the hook emits absolute paths when
PATH lacks the cargo dir): grep, ls, cat, head, tail, wc, diff, git
status/log/diff/show/branch. NOT find (rtk find could carry -exec rm —
native find-deny rules would not match the rtk prefix).
Deny mirrors guard the bypass the allowlist would open on hand-written
'rtk cat .env'-class commands: cat/grep/head/tail × .env, both prefixes.
Residual: exotic quoting may evade the mirrors — second curtain stays
the auto-mode classifier (BDR-004).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
The exit-0 branch emitted permissionDecision:allow, making rtk's internal
Rust registry a PARALLEL permission authority: a rewritten command
bypassed settings.json deny/ask entirely (audit #11). Both rewrite paths
now emit updatedInput only; the rewritten command goes through native
evaluation. Companion allow rules for read-only 'rtk <tool>' forms land
in settings.json (audit-hardening branch) to keep the safe majority
frictionless. Re-pinned.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
Measured: 6 agent descriptions = ~2.2k tokens injected EVERY session
(the single largest plugin contributor) for a toolkit useful only when
reviewing PRs. enabledPlugins → false; removed from full+backend
profiles (BDR-017 caveat already accepts full excluding rarely-used
items); audit.profile KEEPS it = profile reactivation channel.
Per-PR-session: claude plugin enable pr-review-toolkit@claude-code-plugins
(or bash lib/profile.sh apply audit); a later 'profile set full'
re-disables it via the MANAGED_PLUGINS lifecycle.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
Step 6.5: bun upgrade (guarded). Deliberate exclusions documented in
place: magic MCP (npx @latest resolves at invocation), graphify claude
install (rewrites curated configs — BDR-028 territory, manual only),
gsd (lock-pinned: make update reinstalls the pin, note added to
plugins.lock.json so the no-op is explicit).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
page/pages/form/menu/card/carte/style/look/screen/interface/color/shadow
fired on a large share of non-UI prompts (~200 tokens of reminder each;
measured 6 fires during a pure config audit, including on task
notifications). Specific compounds stay: formulaire, styling, stylesheet,
styliser, écran, couleur, palette… FR aesthetic words kept.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
- ALWAYS_ON derived from settings.json:enabledPlugins (true entries)
minus toggle-owned names — the hardcoded pair under-reported newly
enabled plugins (pr-review-toolkit enabled yet invisible). LRN-005.
- Display 'graphify' (the CLI/skill name); graphifyy stays the pipx
package name everywhere it IS the package.
- Overflow split = greedy width-fill: the fixed 3-name cut overflowed
line 1 and printed an empty line 2 with 3 long names.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
- EXPECTED_DENY hardcoded 100 vs 99 real → derive from committed
settings.json (HEAD): auto-tracks legit deny edits, still flags
live-vs-committed divergence.
- EXPECTED_SKILLS required gstack 'health' (OFF by default, profile-
managed): false warn on a default install with a wrong remedy —
link.sh cannot restore gstack skills. Dropped; 'status' kept (repo-
owned personal skill, git ls-files proven).
- disable-model-invocation check required a key BDR-019 stripped
repo-wide (2026-06-09) → warned on every owned skill since.
Inverted into a BDR-019 regression watch.
- pass message derives the skill list from the array (LRN-005 class:
no hardcoded display drift).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
$MEM/../skills resolved to .claude/skills/ (the LRN-042 parasite, removed
2026-06-30 by make plugin Step 8.5), not the real skills/. Green at build
time only because the parasite still existed — green-for-wrong-reason
(LRN-077 class); red ever since. Suite back to 20/20.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
git show origin/master:version.txt fatal-ed since the gitflow migration
(2026-06-29): the 'update available' banner could never fire while a
synchronous git fetch was still paid every session for a discarded result.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
rtk lives at ~/.cargo/bin but the hand-managed .bashrc lost the cargo
line: command -v failed in hook AND tool shell, so the hook no-op'd with
a stderr warn on every Bash call — input compression silently OFF.
- Resolve RTK_BIN by probing known install dirs (LRN-036 class).
- Substitute the ABSOLUTE path at the rewrite head: a bare 'rtk …'
exits 127 in the tool shell, whose PATH the hook cannot fix (proven).
- Compound rewrites carrying further bare rtk segments pass through
unrewritten: quoted text (commit messages) makes a global substitution
unsafe — lose compression, never emit a command that 127s (proven:
a commit chain 127'd mid-flow).
- detect_rtk probes the same dirs so the banner reports capability.
- Re-pinned .rtk-hook.sha256: the rtk BINARY verifies the hook against
it at execution time and refuses a modified hook — the pin is live
machinery, not a vestige; coupling documented in the header.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
STEP 6 ctx7 auth, when anonymous:
- interactive TTY -> prompt [y/N] then run `ctx7 login`; non-interactive
(CI/headless/re-run) keeps text guidance, never opens a browser or blocks.
- run `ctx7 setup --claude --cli` when the find-docs skill is absent, to
(re)install CLI+Skills mode. Guarded on absence so a re-run never clobbers
a customized ~/.claude/rules/context7.md.
gitignore skills/find-docs/: it is a ctx7-managed skill materialized by
`ctx7 setup --claude --cli` into ~/.claude/skills (symlink to repo skills/),
re-created on demand by Step 6 — not vendored here.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C8bmCXTHNccS7KRV4gWXEF
Step 6 printed its ctx7 hints unconditionally — telling already-authed users
to log in, and pointing at `ctx7 setup --claude` (MCP-adjacent). Anonymous mode
is fully functional (docs + library work without auth); auth only buys rate
limits, so setup was never required for ctx7 to work.
- Detect auth via an offline oracle: credentials.json presence (XDG-aware),
no subprocess / network / browser — mirrors the idempotent-claude fix.
- Authenticated -> "ctx7 authenticated"; anonymous -> non-blocking guidance
(works anonymously; `ctx7 login`, `--no-browser` for headless). The installer
guides, never launches login/setup.
- Drop `ctx7 setup --claude`: leftover reopening MCP path, aligns w/ TODO:48
CLI-only decision.
Verified: bash -n, shellcheck (no new findings), + simulated both auth states
(credentials.json present/absent) — correct branch each, credentials restored.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VeBXkDr74N9whdiJyjzyVN
Session capture for the /reconcile pass + the BLK-013 fix-forward build:
- journal 2026-07-01: reconcile real-state (1 actionable / 3 upstream /
3 deferred / release live), (c) TODO drift, (a) npm guard built.
- BLK-013: append Update — fix-forward now BUILT (1f2c1cc); was
"script hardening NOT built". Now fully resolved (env + script).
- BLK-014 + BDR-046: append Update — MERGED 2393ca5, supersedes the
stale "pending merge". Records that BDR-046 already settled the
"canal d'install" question (native installer, no `elif npm` branch).
Append-only (Update blocks, last-block-wins) — no past entry rewritten;
verified reconcile_blk_open now returns only the true upstream trio.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VeBXkDr74N9whdiJyjzyVN
BLK-013 fix-forward. Step 1 checked `node >=22` but never verified npm.
On a host where node was already recent, NODE_OK short-circuited the
installer and npm was never touched — yet GSD (gsd-pi) and ctx7 install
via `npm install -g`, so a missing npm made `make plugin` die Error 127
mid-run (distro `apt install nodejs` can ship npm as a separate package).
Add an unconditional npm guard right after the Node block:
corepack enable npm → distro package-manager install fallback → fatal
exit 1 with an actionable message if still absent. Happy path (npm
present) skips the whole block: zero behavior change on healthy machines.
shellcheck clean (only pre-existing SC1091 infos), bash -n OK. Fresh
npm-less apt host validation still pending. Closes TODO (a) 2026-06-30.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VeBXkDr74N9whdiJyjzyVN
/reconcile show-only surfaced 7 open [ ] boxes under the
`## Helper --help` section headed [WON'T-BUILD 2026-06-30]. The chantier
was killed (BDR-001 won't-build, measured non-rentable) but the build
subtasks stayed unchecked → naive `grep '[ ]'` counted them as open work.
Mark them [-] (cancelled) so declared state matches reality. The ⛔
WON'T-BUILD prose already frames them as "historique, non actionnables".
Naive open-count 10→3; survivors are genuine deferred-open (context-file
2e passage, zenquality cross-repo, install-plugins npm harden).
Registries left untouched (reconcile is read-only there; BLK-014/BDR-046
"pending merge" staleness is a /prune-memory concern, not this).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VeBXkDr74N9whdiJyjzyVN
Uniformizes point 1: install.sh fresh-machine branch used npm, but npm
is no longer a documented Claude Code channel (official quickstart lists
Native/Homebrew/WinGet/apt only) and collides with the native symlink.
Switch the fresh-install path to the recommended native installer,
matching install-plugins.sh which already points to the native channel.
- install.sh: fresh install via `curl -fsSL https://claude.ai/install.sh
| bash`; ensure ~/.local/bin on PATH for the auth/verify steps.
- skip-if-present guard unchanged.
- fix stale node/npm prerequisite comment (npm now serves the plugins
step, not the Claude Code install).
Co-Authored-By: Claude <noreply@anthropic.com>
install.sh aborted with npm EEXIST when claude was already present:
the binary is a native-installer symlink (~/.local/bin/claude ->
~/.local/share/claude/versions/*) that npm does not own, and the
npm prefix (~/.local, set for BLK-013) targets the same path. The
`else err` branch turned EEXIST into a fatal exit. No presence guard
existed, unlike the RTK/GSD steps.
- install.sh: skip-if-present guard (command -v claude), mirroring
the RTK/GSD pattern; npm only runs on a truly fresh machine.
- update-all.sh: pick updater by channel — npm for npm-managed
installs, `claude update` for native installs (npm would EEXIST).
Co-Authored-By: Claude <noreply@anthropic.com>