Commit Graph
16 Commits
Author SHA1 Message Date
Bastien Chanot ae1339d656 chore(config): untrack emil-design-eng skill (machine-owned curl copy)
skills-external/emil-design-eng/SKILL.md is curl'd from emilkowalski/skill
by install-plugins.sh when absent and re-fetched unconditionally by every
update-all.sh run, so tracking it produced a repo diff on each upstream edit
(latest: Radix vars dropped for Base UI). Same category as frontend-design/
and impeccable/, already ignored on that rationale — a fresh clone re-fetches
it, so no offline copy is needed and nothing was pinned here anyway.

design-motion-principles/ has the same overwrite-on-update behaviour but NOT
the same bootstrap: install-plugins.sh only warns instead of cloning it, so it
stays tracked until that gap is closed.
2026-08-24 12:17:17 +02:00
Bastien Chanot 00c97bcacb job6: supply-chain documentation pass (F-X1, semgrep caveat)
- README + plugins.lock.json graphifyy note: pipx/PyPI install only, never
  npm/npx — a different publisher (rhanka/graphify) squats the same
  'graphifyy' name on npm as a version-shadowing shim with its own
  conflicting 'graphify' bin (F-X1).
- agents/security-auditor.md: one-line caveat that p/* semgrep packs are
  fetched from the registry at runtime — the CLI version pin does not
  freeze ruleset content, so a new BLOCK can appear on unchanged code.

MCP magic (F-X3): version pin declined by user call (stays @latest in
lib/toggle-external.sh). ${VAR} env expansion confirmed unsupported at
~/.claude.json user scope (Claude Code docs — expansion is .mcp.json
project-scope only), so the BDR-026 reference-not-plaintext pattern
doesn't transfer here; existing mitigations (canonical ~/.claude/.env,
gitignore, audit env-field filtering) remain the practical ceiling.
~/.claude.json regenerated out-of-repo via toggle-external.sh disable+
enable magic to pick up the already-rotated MAGIC_API_KEY (no repo diff,
no commit for that file — traced in the job6 final report).
2026-07-07 03:42:15 +02:00
Bastien Chanot 2813e55289 job6: gstack submodule 070722a→11de390 (v1.52.1.0→v1.58.5.0)
Full pull per user verdict (human review of #2047 gbrowser stealth done,
accepted) — motivated by the #1911 fail-open fix for 4 security guards
(careful, guard, freeze, data-loss) plus PII/secrets redaction (#1797),
telemetry-consent + cache sanitization (#1848).

Gate: make test 90/0 green after bump; re-ran link.sh (symlinks already
current) + gstack ./setup (browse binary rebuilt); smoked /careful and
/freeze (guard's constituents) via direct JSON-payload invocation
(job4 §2.3 idiom) — both confirmed blocking a trivial case (rm -rf,
edit outside freeze boundary) that must be blocked.

Local playwright pin (BDR-029/BLK-008, ubuntu26.04 Chromium support) was
reset by the submodule checkout as designed, then re-applied via
gstack_bump_playwright_if_unsupported's own steps (bun install,
detect unsupported, bun add playwright@latest — 1.58.2→1.61.1, one
minor ahead of the pre-bump local patch). Original local diff backed
up before discarding: scratchpad/gstack-local-playwright-fix-070722a.patch.

plugins.lock.json note updated with the pinned SHA and rationale.

Rollback if needed: git -C skills-external/gstack checkout 070722a &&
git add skills-external/gstack && link.sh re-run.
2026-07-07 03:30:11 +02:00
Bastien Chanot b4896c9ae1 job6: gsd-pi 2.64.0→3.0.0 — adapt status-reporter parser to ADR-013 cutover
Upgrade confirmed format-incompatible before use (job6 gate, BATCH-2):
gsd-pi 3.0.0 no longer writes .gsd/ROADMAP.md (verified by generating a
real test milestone in a scratch project) — state moved to .gsd/STATE.md,
.gsd/gsd.db (authoritative DB), and one .gsd/milestones/<ID>/<ID>-ROADMAP.md
per milestone, all in a different markdown shape. Every grep/awk in
status-reporter.md PHASE 3 would silently print 0/blank against the old
path instead of erroring.

Rewired PHASE 3 to read `gsd headless query` (stable JSON snapshot, no LLM
call) instead of scraping markdown — smoke-tested against both the absent
case (this repo, no .gsd/) and a real gsd-managed scratch project.

plugins.lock.json pin bumped deliberately to 3.0.0 (update-all.sh honors
the pin; this is the required manual bump).
2026-07-07 03:23:19 +02:00
Bastien Chanot 73c765aa08 feat(install): wire impeccable into the toolchain — deterministic design floor + /impeccable verbs
Complementary to frontend-design (kept: build-time aesthetic direction).
impeccable adds what the chain lacked: 45 deterministic anti-slop rules
(npx impeccable detect, exit 0/2, --json) — the design counterpart of the
semgrep gate — plus 23 design verbs under one /impeccable skill and
persistent per-project design context.

- plugins.lock.json: CLI pinned 3.2.0 (rules update = audit output change
  on unchanged code, LRN-077 class); skill dist = its own release track
- install-plugins.sh Step 8d: staged npx install (tmpdir) -> moved to
  skills-external/impeccable (machine-owned, gitignored, ctx7 pattern);
  never writes through the ~/.claude/skills symlink into the tracked tree
- update-all.sh: pin-honored refresh, Node<24 or failure -> dist kept
- Node >= 24 required (host at 22): steps skip gracefully, activation
  deferred to a deliberate Node bump
- link.sh EXTERNAL_SKILLS, profiles (design/web/web-full/full),
  plugin-advisor, CLAUDE.md design routing, design-gate, README, CHANGELOG
- NOT in design GATE-BLOCK yet: promotion after first dogfood
2026-07-05 14:42:42 +02:00
Bastien ChanotandClaude Opus 4.8 ccfecc9c21 feat(install): semgrep pinned install + pin-honored update (security-gate lot 1)
Step 7.5 in install-plugins.sh: pipx install semgrep==<pin> behind a
command -v guard (LRN-085 pattern), version echo on skip, login is
Pro-rules-only guidance — never run automatically (ctx7 pattern).
Step 6.2 in update-all.sh: pin-honored update that displays the version
jump (cur → pin) before pipx install --force; latest only when unpinned.
plugins.lock.json: semgrep pinned 1.168.0 — semgrep is a BLOCKING gate,
a silent upgrade means new BLOCKs on unchanged code (gsd-pin pattern).

Dogfooded via extracted real blocks: fresh install, idempotent re-run,
pin-match skip, jump display + clean warn on bogus pin. Rulesets
p/security-audit + p/secrets fetch anonymously (no login) and detect.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
2026-07-03 18:32:59 +02:00
Bastien ChanotandClaude Fable 5 45a387c1dd feat(update-all): bun self-upgrade + documented non-update exclusions
Step 6.5: bun upgrade (guarded). Deliberate exclusions documented in
place: magic MCP (npx @latest resolves at invocation), graphify claude
install (rewrites curated configs — BDR-028 territory, manual only),
gsd (lock-pinned: make update reinstalls the pin, note added to
plugins.lock.json so the no-op is explicit).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:16:36 +02:00
Bastien ChanotandClaude Opus 4.8 d4a5cfec93 chore(caveman): purge plugin + always-on integration
Disable + uninstall caveman@caveman and delete every repo dependency on
it: SessionStart/UserPromptSubmit hook blocks, standalone hook files,
settings.json enabledPlugins + marketplace entries, install-plugins.sh
STEP 5.5, update-all.sh refresh step, plugins.lock.json entry, doctor.sh
checks, lib/detect-plugins.sh helpers, lib/profile.sh + plugin-advisor +
skills/profile protected-list entries, .gitignore runtime-file block,
and README/USAGE docs. Dead /caveman:compress refs replaced with
manual/claude.ai guidance. Memory-registry terse-format convention kept
(separate subsystem). Version 3.4.0 -> 3.5.0.

On a subscription plan caveman's ~75% output-token compression has no
cost benefit, and the always-on hooks added friction on validation
gates and client deliverables.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X3e8LaH2vymmxyh36h3jFU
2026-06-19 19:08:40 +02:00
bastienandClaude Opus 4.7 e4f4edc121 feat(caveman): full install — plugin + standalone hooks + MCP scaffold
Wires JuliusBrussee/caveman into the always-on tier alongside
security-guidance and superpowers. Caveman compresses Claude's output
tokens (~75%) by speaking like a caveman while keeping technical
substance. Three layers:

  1. Plugin (caveman@caveman, marketplace JuliusBrussee/caveman)
     — adds /caveman, /caveman-commit, /caveman-review, /caveman-stats,
       /caveman-help, /cavecrew, /compress + 3 cavecrew agents +
       SessionStart/UserPromptSubmit hooks from the plugin path.
  2. Standalone hooks (statusline + stats badge) deployed by
     caveman's own hooks/install.sh into ~/.claude/hooks/. Paths in
     settings.json normalized to ~/.claude/hooks/... so this user's
     home dir doesn't leak across machines.
  3. caveman-shrink MCP proxy — NOT auto-registered. The bare proxy
     fails health checks because it requires an upstream MCP server
     to wrap. install-plugins.sh STEP 5.5 prints a snippet showing how
     to register a wrapped entry (e.g. caveman-shrink-fs) when the user
     decides which upstream to compress.

New helper enable_plugin() for explicit always-on activation —
'claude plugin install' only copies into cache, doesn't write
enabledPlugins. Idempotent via Python json check.

doctor.sh adds detect_caveman / detect_caveman_hooks / detect_caveman_shrink
checks plus a 300t passive-cost adder. update-all.sh refreshes hook
files via the upstream installer's --force mode.

.gitignore covers caveman runtime files materialized into hooks/
because ~/.claude/hooks is symlinked to this repo.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-03 23:02:47 +02:00
bastienandClaude 9536527a37 chore(plugins): unpin rtk to latest
Move rtk from v0.34.3 to "latest" to pick up upstream fixes as they
ship (notably the pending TTY-passthrough issue documented in
tasks/rtk-upstream-issue.md).

Co-Authored-By: Claude <noreply@anthropic.com>
2026-04-17 05:16:40 +02:00
bastienandClaude Opus 4.6 50db70cbf2 chore: remove ruflo and frontend-design — full cleanup
Both plugins removed from all config, scripts, and documentation:
- ruflo: uninstalled globally (npm), removed from install/update/doctor/session-start/detect/lock/advisor
- frontend-design: removed from install/session-start/detect/advisor (was already commented out)
- plugin-advisor.md: compatibility matrix, decision table, conditional rules, recommended sets all updated
- README.md/USAGE.md: all references cleaned, token cost estimates recalculated
- install-plugins.sh: steps renumbered (10→9 steps)
- CHANGELOG.md: kept as historical record

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-15 23:54:52 +02:00
bastienandClaude Opus 4.6 74a0901cc4 add emil-design-eng skill to install/update pipeline
- Download SKILL.md from emilkowalski/skill to skills-external/
- Symlink to ~/.claude/skills/ via link.sh
- install-plugins.sh step 9: curl download + symlink check
- update-all.sh step 8: re-fetch latest SKILL.md on update
- plugins.lock.json: add emil-design-eng entry
- .gitignore: ignore auto-created symlink in skills/

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-13 14:31:24 +02:00
bastienandClaude Opus 4.6 35ea5c1a49 audit fixes: RTK hook, settings unification, graphifyy, statusline
- Add RTK PreToolUse hook (rtk-rewrite.sh) and fix missing config
- Unify settings.json: merge hooks, marketplaces, model into project file
  so link.sh symlink is the single source of truth
- Add statusline: model, folder, git branch, context % progress bar
- Add graphifyy support: detect, install (pipx), lock, doctor, session-start
- Clarify ctx7/ruflo as standalone CLI (not MCP servers)
- Fix install-plugins.sh step numbering (duplicate step 6)
- Add version check in session-start (local vs origin/master)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-12 13:28:30 +02:00
bchanot 854a0af92a changed context7 to cli 2026-04-09 14:31:24 +02:00
bchanot f55a2b3fdf final version seems 2026-04-08 13:46:45 +02:00
bastien f8811fab37 opus version correction 2026-04-03 18:08:21 +02:00