Commit Graph
1048 Commits
Author SHA1 Message Date
bastien d71f3a7d56 chore(memory): BDR-102 amendment + journal — strict waiver policy 2026-09-27 21:20:36 +02:00
bastien 6617889b77 feat(verifier): floor-guard waivers outside test files need a CLARIFICATIONS ack
Security-gate MEDIUM: a self-service floor-guard: allow <reason> neutralised
the detector in the same commit. User chose strict: the tool prints WAIVED,
the contract authorizes, the verifier counts the rest as gaps. BDR-102
amendment.
2026-09-27 21:20:36 +02:00
bastien 5a27372179 chore(memory): journal + TODO — case 3 web-building micro-rules 2026-09-27 20:23:52 +02:00
bastien a2e654d89f feat(rules): write-time UI reflexes in web-building.md, from ui-skills
Fourteen lines of stack-agnostic micro-rules (dvh, safe-area, paste,
tabular-nums, text-wrap, z-index scale, compositor-only motion, 44 px
targets, focus-visible, status not by color alone, errors by the field,
one accent per view). Case 3 of the 6-repo review: nothing installed.
2026-09-27 20:23:52 +02:00
bastien de7371de36 docs(changelog): YAGNI ladder + shortcut marker, case 1 of the 6-repo review 2026-09-27 20:19:08 +02:00
bastien 740138337c chore(memory): case 2 registries, contracts, CHANGELOG — BDR-102 LRN-172 LRN-173 EVAL-032 2026-09-27 20:18:41 +02:00
bastien 1a8e6decdb feat(rules): rest-api path-scoped rule distilled from agent-skills
Contract-first order, one error envelope + HTTP map, paginated lists,
idempotency (key from intent, atomic claim, payload guard, duplicate
policy, retention), naming, Hyrum's law. Versioning points to CLAUDE.md
§ Web APIs — always versioned; the upstream one-version rule is dropped.
2026-09-27 20:17:38 +02:00
bastien 409db51af9 test(lib): skill-routing census, TF-IDF collisions across the live catalog
Top 10 description pairs, WARN >= 0.50, FAIL >= 0.75, fixture flip-test
with a positive control and a sensitivity re-run (2-doc corpora are
degenerate, LRN-172). Baseline 2026-09-27: 120 skills, max 0.52
(careful ~ guard). Adapted from agent-skills evals Tier 2.
2026-09-27 20:17:37 +02:00
bastien 2b25cb4704 feat(lib): floor-guard, diff-scoped detector of a weakened quality bar
SUPPRESS / SKIP / DELETED_TEST / ASSERT_DROP / STUB / THRESHOLD_DOWN over
git diff <base> (untracked files included), floor-guard: allow <reason>
waiver printed as WAIVED, rc 0/2/3. Mandatory verifier STEP 3, documented
under GATE 1 of verify-secure-loop.md. Suite: 6 kinds + WAIVED + CLEAN,
flip-tested. Adapted from agent-skills constraint-driven-development.
2026-09-27 20:17:36 +02:00
bastien d28c45ed19 feat(skills): vendor agent-skills trio at a pinned commit, emil precedent
observability-and-instrumentation, deprecation-and-migration,
ci-cd-and-automation from addyosmani/agent-skills 2686b620, curl'd into
skills-external/<name>/ by install-plugins.sh Step 8e (tmp+mv), refreshed
by update-all.sh 7.3, symlinked by link.sh, registered in toggle-external,
profile.sh and the full/backend/dev profiles. Pin read from the lock via
argv, never hardcoded. Case 2 of the 6-repo review, BDR-102.
2026-09-27 20:17:36 +02:00
bastien ffb5b73373 chore(memory): journal + TODO — case 1 yagni-ladder 2026-09-27 15:06:20 +02:00
bastien 9315c6cb39 feat(doctrine): YAGNI decision ladder + shortcut marker in § Code style
Case 1 of the 6-repo review (ponytail, chisle): both rejected as plugins,
the ordered ladder borrowed as 6 doctrine lines. 287 -> 293, budget 320.
2026-09-27 15:06:20 +02:00
bastien 642fea826e chore(memory): journal, gitignore allowlist merged to develop 2026-09-27 2026-09-27 14:19:09 +02:00
bastien facd26db75 Merge bugfix/gitignore-diagram-allowlist into develop 2026-09-27 14:18:59 +02:00
bastien 6bebc6f70c chore(memory): journal + TODO — hotfix gitignore-diagram-allowlist 2026-09-25 19:32:55 +02:00
bastien f363f114ee fix(gitignore): gstack symlink allowlist lacked skills/diagram
`profile.sh apply full` linked skills/diagram (added to full today) and it
showed as untracked: the per-skill allowlist never listed it (LRN-025
class). One literal line, alphabetical slot; the full.profile census now
finds every bare gstack entry ignored.
2026-09-25 19:32:31 +02:00
bastien fbb67b43d1 chore(memory): journal, full profile +4 merged to develop 2026-09-25 2026-09-25 19:29:30 +02:00
bastien db8c179725 Merge bugfix/full-profile-web-doc-skills into develop 2026-09-25 19:28:56 +02:00
bastien 6104ee5c6b chore(memory): journal + TODO — hotfix full-profile-web-doc-skills 2026-09-25 18:44:27 +02:00
bastien d7ac457376 docs: CHANGELOG full profile +4 gstack skills — hotfix full-profile-web-doc-skills 2026-09-25 18:44:27 +02:00
bastien bbe1087bd8 fix(profiles): full lacked the web/doc gstack tools superpowers does not cover
`scrape`, `skillify` (Browser + dogfooding) and `diagram`, `make-pdf`
(Docs + translation) join the default profile, user go. The rest of the
BDR-017 exclusion list (ios-*, connect-chrome duplicate of
open-gstack-browser, gstack-internal tooling) stays out; enable it per
session with `profile apply` when needed.
2026-09-25 18:12:15 +02:00
bastien 4cd6e6ece9 chore(memory): journal, default profile merged to develop 2026-09-25 2026-09-25 17:06:13 +02:00
bastien 1ee6cf667b Merge feature/default-profile-full into develop 2026-09-25 17:05:59 +02:00
bastien 16fea1106d add .env without magix api 2026-09-25 17:05:33 +02:00
bastien 1b418cae84 chore(memory): BDR-101 + LRN-170 + LRN-171 + EVAL-031 — feat default-profile-full 2026-09-25 16:38:53 +02:00
bastien 0926cc74b5 docs: README profile default + 21st section, CHANGELOG default-profile entries — feat default-profile-full 2026-09-25 16:38:39 +02:00
bastien 1bbdad039c feat(install): apply the default profile at the end of make plugin
New Step 11 after the link.sh refresh: no profile selected → `profile.sh
reset` (default = full); an existing selection → `profile.sh set <sel>`, so
its state comes back after Step 2 re-parks gstack and Step 10 re-links the
design externals. Both calls are `|| warn`-guarded (installer runs under
set -e). Step 8.7 no longer parks the 21st pack unconditionally: the
selected profile governs it (full links the five design skills, the two
publishing skills stay on demand). Plugin legs stay install-immutable
(BDR-028 EXIT guard); the committed enabledPlugins already match full.
2026-09-25 16:28:22 +02:00
bastien 0d035fcab6 feat(profile): default profile = full; reset applies it, current is label-driven
No profile selected (.active-profile absent, empty or legacy "none") now
means the `full` profile is in force: DEFAULT_PROFILE declared once in
lib/profile.sh, resolved by active_profile(); the statusline reads the
constant and shows `full` instead of `?`; `gstack off` trims to it instead
of erroring. `reset` goes to the default profile (= `set full`: enables its
list, parks any non-listed gstack or managed item). `current` names the
active label and scores that profile only, saying `default — not applied
yet` until a set/apply/reset wrote the cache; the "none" sentinel and the
cross-profile best-guess scan are gone (they keyed on the parked-gstack
count, which says nothing under BDR-030's gstack-off default). Hermetic
suite lib/tests/profile-default.test.sh (29 checks) seeds gstack as OFF like
a real tree. Citers updated: profile SKILL, Makefile help, plugin-advisor
PROFILE line + reset paragraph, toggle-external header.
2026-09-25 16:28:21 +02:00
bastien e1963284d2 chore(21st): drop magic MCP residue
The magic MCP wiring left with BDR-093; this removes the prose that still
described it: gitleaks allowlist note, Step 8.7 header, plugins.lock note,
profile.sh comments and the usage() NOTE that still claimed `set` toggles
"the magic MCP", the managed-set test header, README (one history sentence
kept; MCP-era risk paragraph and the retired bashrc wrapper claim dropped).
.env.example carries the same scrub in the working tree; staging it is
denied to the agent (`git add .env*`), the user stages it.
2026-09-25 16:06:20 +02:00
bastien b40dc1e8d4 chore(memory): journal, guardrail mechanisms merged to develop 2026-09-25 2026-09-25 12:07:48 +02:00
bastien 771bb77d79 Merge feature/guardrail-evasion-citers into develop 2026-09-25 12:07:34 +02:00
bastien 2adf985c07 chore(memory): BDR-100 mechanisms, EVAL-030 self-audit, journal + TODO 2026-09-24 2026-09-24 20:58:26 +02:00
bastien 27f201d4aa feat(guardrails): refusal ends the attempt; doctrine-citers census; make test suite=
Root causes of the 2026-09-24 errors turned into mechanisms (BDR-100). hard_deny 'Routing around a guardrail': a refused command is never rerun through a wrapper, alias, heredoc, Makefile target, env file, other shell or other agent; the same clause in 14 agents and in the doctrine's sub-agent rule. make test suite=<file> runs one suite hermetically so the denied env-prefix form is never needed by hand. lib/tests/doctrine-citers.test.sh: every CLAUDE.md "Section" / § Label citation across skills, agents, lib, rules and hooks must resolve to a heading or bold label (flip-tested); its first run fixed rest-api-node.md. Doctrine 'After code changes' step 4: a changed rule, heading, label or threshold → grep every citer in the same commit.
2026-09-24 20:58:25 +02:00
bastien 8f10047ac4 chore(memory): journal, C2 coherence merged to develop 2026-09-24 2026-09-24 20:50:39 +02:00
bastien c0efc8f1c0 Merge feature/c2-coherence into develop 2026-09-24 20:50:28 +02:00
bastien 34132b27e6 chore(memory): BDR-099 C2 coherence, LRN-169 audit method, journal + TODO 2026-09-24 2026-09-24 20:25:41 +02:00
bastien 4a16106940 docs(changelog): C2 coherence pass, gitflow init fix, removed knobs 2026-09-24 20:25:40 +02:00
bastien d82c06f572 refactor(doctrine): C2 coherence — 30 doctrine/skill tensions resolved, doctrine wins (BDR-099)
One ask policy; mandated executors exempt from the delegation rule; skill plan satisfies the planning rule; journal line exempt from the approval gate; chore = maintenance without new behaviour; small fix on develop = bugfix; BDR-068 written as the one auto-finish exception; deploy routes to /deploy. Skills and agents follow: hotfix types by base + skips the design gate on trivial; capitalize/close create missing registries; commit-change asks the branch type; doc/seo/web-validate/refactor branch through the aiguillage; tour reports BREAKING fixes as needs-decision and runs doc-syncer two-mode; client-handover applies audit bundles from its main loop behind one gate; init-project/onboard use the 200-file graphify signal and bootstrap memory; release-candidate gates the tag push only; push wording aligned with the BDR-095 hooks; stale pointers fixed (§ Language, .gsd/ROADMAP.md, handover script path, design-gate lists).
2026-09-24 20:25:40 +02:00
bastien 1b20beccda fix(gitflow): init on an existing repo under the machine-wide hooks lands the socle via a chore/gitflow-adopt merge (T2c) 2026-09-24 20:25:39 +02:00
bastien fe90291cc6 Merge chore/reconcile-2026-09-24 into develop 2026-09-24 18:05:02 +02:00
bastien 2cba37109a chore(memory): journal, reconcile + prune 2026-09-24 2026-09-24 14:44:33 +02:00
bastien 65f8cd1b4c chore(memory): prune-memory 2026-09-24 — index backfill (66 rows), 15 headings normalised, 4 statuses flagged, 6 merges (LRN-163..168), 23 entries compressed
D: every body entry now has an Index row; BDR-074..085, LRN-136, EVAL-026/027 were filed under ### and invisible to the engine and to /reconcile. A: BDR-011/015/031/038 index statuses reflect their supersession; LRN-010 dated path update. B: LRN-147+148, 106+113, 105+107, 142+144, 116+117, 131+132 merged into LRN-163..168, sources kept verbatim and marked superseded. C: tier-1 caveman pass on 23 entries under the negation guard (-5% words: most sentences carry a negation and stay verbatim). Fidelity census: file-level token counts never drop; the per-entry flags on BDR-073 and EVAL-025 are attribution artifacts of the ### fix (bodies byte-identical).
2026-09-24 14:44:32 +02:00
bastien 72a68cca2b chore(reconcile): TODO reconciled 2026-09-24 — T6b done, make link / tmp / synced / 21st notes, Makefile re-verified open 2026-09-24 14:07:18 +02:00
bastien 1e45237ffc chore(memory): journal, settings + synced-skills chore merged to develop 2026-09-24 2026-09-24 13:36:16 +02:00
bastien 87b2615948 Merge chore/settings-and-synced-skills into develop 2026-09-24 13:36:03 +02:00
bastien 128e40616b chore(config): feedbackDrafts off; ignore the app-managed skills/synced mirror
settings.json: the user's hand-edit (feedbackDrafts: off) committed as is. .gitignore: skills/synced/ and its .bucket-* marker are Claude Code's mirror of the claude.ai synced skills (UUID bucket, manifest.json, Anthropic stock skills incl. 117 ISO xsd schemas), rewritten at each sync — same treatment as the graphify and impeccable machine-owned copies (BDR-028, LRN-154).
2026-09-24 13:36:02 +02:00
bastien f08899cf45 chore(memory): journal + TODO, density pass and graphify banner merged to develop 2026-09-24 2026-09-24 13:25:40 +02:00
bastien 10532e3467 Merge feature/graphify-threshold-banner into develop 2026-09-24 13:24:52 +02:00
bastien abec66e11e Merge chore/claude-global-density into develop 2026-09-24 13:24:27 +02:00
bastien 5db2a65fe1 chore(memory): BDR-098 density pass, journal + TODO 2026-09-24 2026-09-24 12:59:12 +02:00