Commit Graph
992 Commits
Author SHA1 Message Date
bastien 45ae0d1217 feat(effort): session default high, env-var warning, live effort in statusline 2026-09-28 18:52:36 +02:00
bastien 5437638437 test(effort): census suite skeleton with flip-test and settings lock 2026-09-28 18:49:40 +02:00
bastien bb28ecefa2 docs(plan): ins_before_para helper for prose anchors (SDD preflight ruling) 2026-09-28 18:47:03 +02:00
bastien 4b722e05c9 docs(plan): effort tiering implementation plan, 11 tasks in 4 waves; TODO section 2026-09-28 18:35:38 +02:00
bastien 854b74e9a4 chore(memory): LRN-179 + EVAL-035 — effort spike facts, thinking-share measurement 2026-09-28 18:24:34 +02:00
bastien 5367b29188 docs(spec): effort tiering design — session high, agent pins, skill effort, phase shifts, max at loop caps 2026-09-28 18:17:34 +02:00
bastien 90242773c1 chore(memory): journal — floor-guard hotfix merged to develop 2026-09-28 2026-09-28 17:06:34 +02:00
bastien c9f9b40086 Merge bugfix/floor-guard-xit-boundary into develop 2026-09-28 17:06:16 +02:00
bastien 018dfa3556 docs: CHANGELOG floor-guard entry names the SKIP boundary fixtures — hotfix floor-guard-xit-boundary 2026-09-28 17:06:15 +02:00
bastien f3f79bb145 chore(memory): BLK-023 resolved — floor-guard xit boundary hotfix, contract, plan, journal 2026-09-28 16:58:30 +02:00
bastien 0deb5594d5 fix(floor-guard): word-bound the bare Jasmine skip patterns
skip_kind matched SKIP_SUBSTRINGS as plain substrings, so 'xit(' hit
exit(, SystemExit( and process.exit(, and 'fit(' hit model.fit( and
profit(, flagging FLOOR SKIP on ordinary test-file lines (BLK-023). The
four bare identifiers (xit, fit, xdescribe, fdescribe) now match through
SKIP_IDENT_RE with an identifier-boundary lookbehind; the dotted and
decorator forms stay substrings. Flip-test fixtures cover the false
positive (RED before, GREEN after) and the three focus/skip calls.
2026-09-28 16:57:47 +02:00
bastien 0a805c562f chore(memory): journal — superpowers vendoring merged to develop 2026-09-28 2026-09-28 15:09:18 +02:00
bastien 65665a552c Merge feature/superpowers-vendored into develop 2026-09-28 15:08:58 +02:00
bastien 7177258f3d chore(memory): BDR-106 superpowers vendored — contract, plan r3, oracles, TODO, journal 2026-09-28 14:54:53 +02:00
bastien ddea411491 chore(config): superpowers citers by bare name, routing map, docs, settings
Every superpowers-prefixed skill call in ship-feature, init-project, tour,
deploy, audit-delta, plugin-advisor and lib/analyze-before-plan now names
the vendored skill directly. finishing-a-development-branch is described
as the upstream skill this config does not vendor (gitflow finish is the
integration path). CLAUDE.global.md Skill routing maps the four
non-vendored skills the vendored text still references. settings.json
loses the plugin key and its marketplace block; README, USAGE,
plugin-advisor and the profile skill describe superpowers as vendored
skills, always on, zero plugin cost. CHANGELOG entry with a known
residual.
2026-09-28 14:54:53 +02:00
bastien 18f8c898f8 feat(superpowers): vendor the 7 wired skills at v6.4.1, drop the plugin
plugins.lock.json gains a superpowers entry (obra/superpowers @ 5bf4e78,
path skills, per-skill file lists, always_on) that lib/vendor-skills.sh
fetches byte-for-byte: brainstorming, writing-plans,
subagent-driven-development, test-driven-development,
requesting-code-review, using-git-worktrees, writing-skills. install-plugins
STEP 8e vendors it, update-all refreshes it at the pin, link.sh links the
seven, .gitignore ignores them. The plugin is no longer installed or
protected: its 8 other skills duplicated personal flows and its
SessionStart injection cost ~900 tokens per start, clear and compact.
detect_superpowers is one file test on the linked skill; doctor and
session-start stop charging the injection. doctor-vendored gains an
always_on class (third lock column) so always-on externals are
link-checked instead of reported parked.
2026-09-28 14:54:52 +02:00
bastien c39c0e1045 Merge feature/skill-catalog-prune into develop 2026-09-28 13:55:04 +02:00
bastien 1805a3cc97 chore(memory): BDR-105 skill-catalog prune + 21st gate, LRN-175..178, BLK-023, EVAL-034 2026-09-28 13:54:51 +02:00
bastien 132bcdf7c5 chore(memory): 21st sign-in gate — contract, plan r3, TODO, journal 2026-09-28 12:51:56 +02:00
bastien bd3e525bb3 feat(design-gate): ask for 21st login and wait instead of skipping
The design gate checked the 21st CLI with command -v only, so an
installed-but-signed-out CLI read as READY and every 21st step failed
downstream. tool_active now probes 21st whoami through a three-state
function: signed in (TWENTYFIRST_TOKEN or API_KEY_21ST set, or 'Logged in
as'), signed out (exact 'Not logged in'), unknown (rc != 0, timeout,
unexpected output). Signed out is a new verdict, SIGN-IN REQUIRED, exit
12: design-gate.md tells the orchestrator to ask the user to run
! 21st login, end the turn, re-run the gate on their reply, and to skip
21st only on an explicit 'proceed without 21st', never silently. Unknown
surfaces as exit 11 with the whoami diagnostic and a CLI-runtime remedy,
so a node/PATH failure can never loop on a sign-in prompt. INCOMPLETE
still wins. Hermetic suite lib/tests/design-tool-gate.test.sh (stub CLI,
fixture repo through DESIGN_GATE_REPO_OVERRIDE) covers every state.
2026-09-28 12:51:55 +02:00
bastien 729d71546f chore(memory): skill-catalog prune — contract, plan r4, oracles, TODO, journal 2026-09-28 11:49:02 +02:00
bastien 4c86d6dc70 chore(config): security-guidance Stop review off, plugins off, routing and docs
settings.json: ENABLE_STOP_REVIEW=0 (the plugin's own switch: no more
Opus call on every turn that changes code, 0 findings in 6 days, 1
recorded false positive; the regex layer and the commit/push agentic
review stay on), brightdata-plugin@synced false (keyless-useless, its MCP
skill would hijack WebFetch/WebSearch), frontend-design official plugin
entry gone (uninstalled: byte-identical to the managed copy).

CLAUDE.global.md routes Ship/PR to ship-feature (gstack ship takes
origin/HEAD = main as base), drops ship/context-save from the gstack-off
list and 21st-ui-review from the design review line (trio is max-only).
deploy's table no longer points at land-and-deploy/setup-deploy.
plugin-advisor.md describes security-guidance's real mechanics. CHANGELOG
Unreleased entry with a Known residual section.
2026-09-28 11:49:01 +02:00
bastien 02b62f787e fix(gstack): one helper-link tree for every hardcoded path, honest doctor stats
gstack skills hardcode ~/.claude/skills/gstack/<path> for 83 shared assets
(bin, scripts/jargon-list.json, ETHOS.md, */sections, review/specialists,
make-pdf/dist, lib/diagram-render/dist, freeze/bin...) but only bin and
browse/dist were linked: make-pdf and diagram failed on every run, cso and
plan-*-review could not read their sections, the freeze hook exited 127.
lib/gstack-links.sh links every top-level entry except SKILL.md, skips
non-skill dirs holding a nested SKILL.md (browser-skills, openclaw,
node_modules), removes the global symlink gstack ./setup plants and refuses
a destination inside the submodule. link.sh, install-plugins.sh and
update-all.sh all call it (three hand-copied blocks gone).

doctor.sh counted 34 skills (find without -L) and zero chars for block
scalar descriptions; lib/doctor-skills.sh reuses the census parser and
counts through the symlinks. Plugin constants re-based on measured values;
install-plugins.sh notes why frontend-design@claude-plugins-official and
brightdata-plugin@synced stay off and describes security-guidance truthfully.
2026-09-28 11:48:45 +02:00
bastien f83f8f755b feat(profiles): prune the gstack catalog, add max, honor a removed denylist
Nine gstack skills leave every profile (ship is trunk-based on Gitea,
land-and-deploy auto-merges and deploys, setup-deploy, autoplan reads
paths that do not exist here, context-save has no restore, learn is an
unused parallel store, careful and guard hooks never fired, design-shotgun
needs an absent OpenAI key). lib/gstack-removed.sh is the single denylist;
profile.sh gstack on and toggle-external.sh enable gstack skip it.

full now carries everything every other profile carries (user rule), minus
the parked make-pdf, diagram and 21st-ai/ui-explore/ui-review, which live
in the new max profile together with pr-review-toolkit. The 21st trio also
leaves web, web-full and design (redundant with impeccable + ui-ux-pro-max).

lib/tests/profile-census.test.sh asserts the invariants live and on a
baseline fixture plus one mutant per invariant; gstack-removed.test.sh
covers both restore paths.
2026-09-28 11:48:44 +02:00
bastien d91d8d820a chore(memory): journal — doctor vendored check merged to develop 2026-09-28 2026-09-28 04:14:35 +02:00
bastien 2c94a0cc5e Merge feature/doctor-vendored-skills into develop 2026-09-28 04:14:27 +02:00
bastien 47c9650ef8 chore(memory): doctor vendored check — contract, CHANGELOG, BDR-104 amendment, journal 2026-09-28 04:11:17 +02:00
bastien 6394fa79fc feat(doctor): check the vendored external skills
lib/doctor-vendored.sh check_vendored_skills: every curl-pinned lock entry
has its files under skills-external/ (list, dict, single-path shapes),
every link.sh EXTERNAL_SKILLS name is symlinked into ~/.claude/skills when
the active profile lists it, parked names reported not failed, hints make
plugin / make link. Lock shape-validated (warn, never a traceback), profile
and item names allowlisted before becoming paths. Suite: 11 cases.
2026-09-28 04:11:16 +02:00
bastien dbcfbe9221 chore(memory): journal — case 7 merged to develop 2026-09-28 2026-09-28 02:36:08 +02:00
bastien d3633db1db Merge feature/mengto-site-motion into develop 2026-09-28 02:35:54 +02:00
bastien 36f94b23e8 chore(memory): BDR-104 amendment, journal, TODO — LOW hardening closed 2026-09-28 02:35:53 +02:00
bastien 415b44ed25 fix(lib): vendor-skills validates lock fields, fullmatch guard
Two security-gate LOW notes closed on user ask: the SAFE guard uses
re.fullmatch so a trailing newline is rejected; commit (40 hex), source
(github.com owner/repo) and path (SAFE class, no traversal) are validated
before any URL is built, INVALID marker names the field. Suite 12 cases.
2026-09-28 02:35:52 +02:00
bastien 8dcf8d3680 chore(memory): case 7 registries, contracts, CHANGELOG — BDR-104 LRN-174 EVAL-033 2026-09-28 01:40:02 +02:00
bastien ba14b5ea03 feat(skills): site-motion, site-level scroll and transition choreography
Personal skill distilling the MengTo motion pack invariants (LRN-141):
gates first (reduced motion renders final states, content visible without
JS, compositor-only, offscreen pause), one smooth-scroll engine with the
Lenis/ScrollTrigger sync, Astro ClientRouter lifecycle, numbered recipes
(reveal, scrub, sticky stack, video and image scrub, TreeWalker split,
progressive blur, marquee, WebGL budgets), upstream pitfalls, checklist.
Routed into the Build UI chain of CLAUDE.global.md and lib/design-gate.md.
2026-09-28 01:40:01 +02:00
bastien 2a1ad1797b feat(lib): vendor-skills helper, five MengTo scroll skills pinned
lib/vendor-skills.sh: vendor_pinned_skills <lock-key> [refresh], list or
dict lock shapes, lock read via python argv, traversal and charset guard
on lock values, VENDOR_BASE_URL honoured only as file:// (hermetic suite),
per-file tmp+mv, refresh skips a skill never installed. install-plugins.sh
Step 8e and update-all.sh 7.3 call it for agent-skills and mengto-skills.
Vendored at a965851: scroll-world-storytelling, build-threejs-scroll-worlds
(+5 references), scroll-scrubbed-visual-sequence, scroll-scrubbed-word-
reveal, scroll-progress-timeline; text files only. Registered in link.sh,
.gitignore, toggle-external, profile.sh and the design/web/web-full/full
profiles, which also list site-motion (personal). Suite: 8 cases.
2026-09-28 01:40:01 +02:00
bastien 7bec2fc51b chore(memory): journal — motion census correction (ui-ux-pro-max data CSVs) 2026-09-27 23:43:39 +02:00
bastien 2f81b2f3fc chore(memory): journal — 6-repo review merged to develop 2026-09-27, motion census 2026-09-27 23:30:27 +02:00
bastien 39d5b159f4 Merge chore/six-repo-review-notes into develop
# Conflicts:
#	.claude/memory/decisions.md
#	.claude/memory/journal.md
#	.claude/tasks/TODO.md
2026-09-27 23:29:05 +02:00
bastien 68fcdaf4d0 Merge feature/web-building-microrules into develop
# Conflicts:
#	.claude/memory/journal.md
#	.claude/tasks/TODO.md
#	CHANGELOG.md
2026-09-27 23:29:02 +02:00
bastien 04cb0576d6 Merge feature/agent-skills-borrow into develop
# Conflicts:
#	.claude/memory/journal.md
#	.claude/tasks/TODO.md
2026-09-27 23:28:44 +02:00
bastien b3597eb627 Merge feature/yagni-ladder into develop 2026-09-27 23:28:22 +02:00
bastien 7b0d4977ad chore(memory): BDR-103 — 6-repo review verdicts and criteria 2026-09-27 23:27:30 +02:00
bastien 197225ab46 chore(memory): case 5 OmniRoute rejected — TODO + journal, review complete 2026-09-27 21:34:10 +02:00
bastien da35cdee2d chore(memory): case 4 reticle parked with a pilot recipe — TODO + journal 2026-09-27 21:26:55 +02:00
bastien d71f3a7d56 chore(memory): BDR-102 amendment + journal — strict waiver policy 2026-09-27 21:20:36 +02:00
bastien 6617889b77 feat(verifier): floor-guard waivers outside test files need a CLARIFICATIONS ack
Security-gate MEDIUM: a self-service floor-guard: allow <reason> neutralised
the detector in the same commit. User chose strict: the tool prints WAIVED,
the contract authorizes, the verifier counts the rest as gaps. BDR-102
amendment.
2026-09-27 21:20:36 +02:00
bastien 5a27372179 chore(memory): journal + TODO — case 3 web-building micro-rules 2026-09-27 20:23:52 +02:00
bastien a2e654d89f feat(rules): write-time UI reflexes in web-building.md, from ui-skills
Fourteen lines of stack-agnostic micro-rules (dvh, safe-area, paste,
tabular-nums, text-wrap, z-index scale, compositor-only motion, 44 px
targets, focus-visible, status not by color alone, errors by the field,
one accent per view). Case 3 of the 6-repo review: nothing installed.
2026-09-27 20:23:52 +02:00
bastien de7371de36 docs(changelog): YAGNI ladder + shortcut marker, case 1 of the 6-repo review 2026-09-27 20:19:08 +02:00
bastien 740138337c chore(memory): case 2 registries, contracts, CHANGELOG — BDR-102 LRN-172 LRN-173 EVAL-032 2026-09-27 20:18:41 +02:00