Commit Graph
969 Commits
Author SHA1 Message Date
bastien f83f8f755b feat(profiles): prune the gstack catalog, add max, honor a removed denylist
Nine gstack skills leave every profile (ship is trunk-based on Gitea,
land-and-deploy auto-merges and deploys, setup-deploy, autoplan reads
paths that do not exist here, context-save has no restore, learn is an
unused parallel store, careful and guard hooks never fired, design-shotgun
needs an absent OpenAI key). lib/gstack-removed.sh is the single denylist;
profile.sh gstack on and toggle-external.sh enable gstack skip it.

full now carries everything every other profile carries (user rule), minus
the parked make-pdf, diagram and 21st-ai/ui-explore/ui-review, which live
in the new max profile together with pr-review-toolkit. The 21st trio also
leaves web, web-full and design (redundant with impeccable + ui-ux-pro-max).

lib/tests/profile-census.test.sh asserts the invariants live and on a
baseline fixture plus one mutant per invariant; gstack-removed.test.sh
covers both restore paths.
2026-09-28 11:48:44 +02:00
bastien d91d8d820a chore(memory): journal — doctor vendored check merged to develop 2026-09-28 2026-09-28 04:14:35 +02:00
bastien 2c94a0cc5e Merge feature/doctor-vendored-skills into develop 2026-09-28 04:14:27 +02:00
bastien 47c9650ef8 chore(memory): doctor vendored check — contract, CHANGELOG, BDR-104 amendment, journal 2026-09-28 04:11:17 +02:00
bastien 6394fa79fc feat(doctor): check the vendored external skills
lib/doctor-vendored.sh check_vendored_skills: every curl-pinned lock entry
has its files under skills-external/ (list, dict, single-path shapes),
every link.sh EXTERNAL_SKILLS name is symlinked into ~/.claude/skills when
the active profile lists it, parked names reported not failed, hints make
plugin / make link. Lock shape-validated (warn, never a traceback), profile
and item names allowlisted before becoming paths. Suite: 11 cases.
2026-09-28 04:11:16 +02:00
bastien dbcfbe9221 chore(memory): journal — case 7 merged to develop 2026-09-28 2026-09-28 02:36:08 +02:00
bastien d3633db1db Merge feature/mengto-site-motion into develop 2026-09-28 02:35:54 +02:00
bastien 36f94b23e8 chore(memory): BDR-104 amendment, journal, TODO — LOW hardening closed 2026-09-28 02:35:53 +02:00
bastien 415b44ed25 fix(lib): vendor-skills validates lock fields, fullmatch guard
Two security-gate LOW notes closed on user ask: the SAFE guard uses
re.fullmatch so a trailing newline is rejected; commit (40 hex), source
(github.com owner/repo) and path (SAFE class, no traversal) are validated
before any URL is built, INVALID marker names the field. Suite 12 cases.
2026-09-28 02:35:52 +02:00
bastien 8dcf8d3680 chore(memory): case 7 registries, contracts, CHANGELOG — BDR-104 LRN-174 EVAL-033 2026-09-28 01:40:02 +02:00
bastien ba14b5ea03 feat(skills): site-motion, site-level scroll and transition choreography
Personal skill distilling the MengTo motion pack invariants (LRN-141):
gates first (reduced motion renders final states, content visible without
JS, compositor-only, offscreen pause), one smooth-scroll engine with the
Lenis/ScrollTrigger sync, Astro ClientRouter lifecycle, numbered recipes
(reveal, scrub, sticky stack, video and image scrub, TreeWalker split,
progressive blur, marquee, WebGL budgets), upstream pitfalls, checklist.
Routed into the Build UI chain of CLAUDE.global.md and lib/design-gate.md.
2026-09-28 01:40:01 +02:00
bastien 2a1ad1797b feat(lib): vendor-skills helper, five MengTo scroll skills pinned
lib/vendor-skills.sh: vendor_pinned_skills <lock-key> [refresh], list or
dict lock shapes, lock read via python argv, traversal and charset guard
on lock values, VENDOR_BASE_URL honoured only as file:// (hermetic suite),
per-file tmp+mv, refresh skips a skill never installed. install-plugins.sh
Step 8e and update-all.sh 7.3 call it for agent-skills and mengto-skills.
Vendored at a965851: scroll-world-storytelling, build-threejs-scroll-worlds
(+5 references), scroll-scrubbed-visual-sequence, scroll-scrubbed-word-
reveal, scroll-progress-timeline; text files only. Registered in link.sh,
.gitignore, toggle-external, profile.sh and the design/web/web-full/full
profiles, which also list site-motion (personal). Suite: 8 cases.
2026-09-28 01:40:01 +02:00
bastien 7bec2fc51b chore(memory): journal — motion census correction (ui-ux-pro-max data CSVs) 2026-09-27 23:43:39 +02:00
bastien 2f81b2f3fc chore(memory): journal — 6-repo review merged to develop 2026-09-27, motion census 2026-09-27 23:30:27 +02:00
bastien 39d5b159f4 Merge chore/six-repo-review-notes into develop
# Conflicts:
#	.claude/memory/decisions.md
#	.claude/memory/journal.md
#	.claude/tasks/TODO.md
2026-09-27 23:29:05 +02:00
bastien 68fcdaf4d0 Merge feature/web-building-microrules into develop
# Conflicts:
#	.claude/memory/journal.md
#	.claude/tasks/TODO.md
#	CHANGELOG.md
2026-09-27 23:29:02 +02:00
bastien 04cb0576d6 Merge feature/agent-skills-borrow into develop
# Conflicts:
#	.claude/memory/journal.md
#	.claude/tasks/TODO.md
2026-09-27 23:28:44 +02:00
bastien b3597eb627 Merge feature/yagni-ladder into develop 2026-09-27 23:28:22 +02:00
bastien 7b0d4977ad chore(memory): BDR-103 — 6-repo review verdicts and criteria 2026-09-27 23:27:30 +02:00
bastien 197225ab46 chore(memory): case 5 OmniRoute rejected — TODO + journal, review complete 2026-09-27 21:34:10 +02:00
bastien da35cdee2d chore(memory): case 4 reticle parked with a pilot recipe — TODO + journal 2026-09-27 21:26:55 +02:00
bastien d71f3a7d56 chore(memory): BDR-102 amendment + journal — strict waiver policy 2026-09-27 21:20:36 +02:00
bastien 6617889b77 feat(verifier): floor-guard waivers outside test files need a CLARIFICATIONS ack
Security-gate MEDIUM: a self-service floor-guard: allow <reason> neutralised
the detector in the same commit. User chose strict: the tool prints WAIVED,
the contract authorizes, the verifier counts the rest as gaps. BDR-102
amendment.
2026-09-27 21:20:36 +02:00
bastien 5a27372179 chore(memory): journal + TODO — case 3 web-building micro-rules 2026-09-27 20:23:52 +02:00
bastien a2e654d89f feat(rules): write-time UI reflexes in web-building.md, from ui-skills
Fourteen lines of stack-agnostic micro-rules (dvh, safe-area, paste,
tabular-nums, text-wrap, z-index scale, compositor-only motion, 44 px
targets, focus-visible, status not by color alone, errors by the field,
one accent per view). Case 3 of the 6-repo review: nothing installed.
2026-09-27 20:23:52 +02:00
bastien de7371de36 docs(changelog): YAGNI ladder + shortcut marker, case 1 of the 6-repo review 2026-09-27 20:19:08 +02:00
bastien 740138337c chore(memory): case 2 registries, contracts, CHANGELOG — BDR-102 LRN-172 LRN-173 EVAL-032 2026-09-27 20:18:41 +02:00
bastien 1a8e6decdb feat(rules): rest-api path-scoped rule distilled from agent-skills
Contract-first order, one error envelope + HTTP map, paginated lists,
idempotency (key from intent, atomic claim, payload guard, duplicate
policy, retention), naming, Hyrum's law. Versioning points to CLAUDE.md
§ Web APIs — always versioned; the upstream one-version rule is dropped.
2026-09-27 20:17:38 +02:00
bastien 409db51af9 test(lib): skill-routing census, TF-IDF collisions across the live catalog
Top 10 description pairs, WARN >= 0.50, FAIL >= 0.75, fixture flip-test
with a positive control and a sensitivity re-run (2-doc corpora are
degenerate, LRN-172). Baseline 2026-09-27: 120 skills, max 0.52
(careful ~ guard). Adapted from agent-skills evals Tier 2.
2026-09-27 20:17:37 +02:00
bastien 2b25cb4704 feat(lib): floor-guard, diff-scoped detector of a weakened quality bar
SUPPRESS / SKIP / DELETED_TEST / ASSERT_DROP / STUB / THRESHOLD_DOWN over
git diff <base> (untracked files included), floor-guard: allow <reason>
waiver printed as WAIVED, rc 0/2/3. Mandatory verifier STEP 3, documented
under GATE 1 of verify-secure-loop.md. Suite: 6 kinds + WAIVED + CLEAN,
flip-tested. Adapted from agent-skills constraint-driven-development.
2026-09-27 20:17:36 +02:00
bastien d28c45ed19 feat(skills): vendor agent-skills trio at a pinned commit, emil precedent
observability-and-instrumentation, deprecation-and-migration,
ci-cd-and-automation from addyosmani/agent-skills 2686b620, curl'd into
skills-external/<name>/ by install-plugins.sh Step 8e (tmp+mv), refreshed
by update-all.sh 7.3, symlinked by link.sh, registered in toggle-external,
profile.sh and the full/backend/dev profiles. Pin read from the lock via
argv, never hardcoded. Case 2 of the 6-repo review, BDR-102.
2026-09-27 20:17:36 +02:00
bastien ffb5b73373 chore(memory): journal + TODO — case 1 yagni-ladder 2026-09-27 15:06:20 +02:00
bastien 9315c6cb39 feat(doctrine): YAGNI decision ladder + shortcut marker in § Code style
Case 1 of the 6-repo review (ponytail, chisle): both rejected as plugins,
the ordered ladder borrowed as 6 doctrine lines. 287 -> 293, budget 320.
2026-09-27 15:06:20 +02:00
bastien 642fea826e chore(memory): journal, gitignore allowlist merged to develop 2026-09-27 2026-09-27 14:19:09 +02:00
bastien facd26db75 Merge bugfix/gitignore-diagram-allowlist into develop 2026-09-27 14:18:59 +02:00
bastien 6bebc6f70c chore(memory): journal + TODO — hotfix gitignore-diagram-allowlist 2026-09-25 19:32:55 +02:00
bastien f363f114ee fix(gitignore): gstack symlink allowlist lacked skills/diagram
`profile.sh apply full` linked skills/diagram (added to full today) and it
showed as untracked: the per-skill allowlist never listed it (LRN-025
class). One literal line, alphabetical slot; the full.profile census now
finds every bare gstack entry ignored.
2026-09-25 19:32:31 +02:00
bastien fbb67b43d1 chore(memory): journal, full profile +4 merged to develop 2026-09-25 2026-09-25 19:29:30 +02:00
bastien db8c179725 Merge bugfix/full-profile-web-doc-skills into develop 2026-09-25 19:28:56 +02:00
bastien 6104ee5c6b chore(memory): journal + TODO — hotfix full-profile-web-doc-skills 2026-09-25 18:44:27 +02:00
bastien d7ac457376 docs: CHANGELOG full profile +4 gstack skills — hotfix full-profile-web-doc-skills 2026-09-25 18:44:27 +02:00
bastien bbe1087bd8 fix(profiles): full lacked the web/doc gstack tools superpowers does not cover
`scrape`, `skillify` (Browser + dogfooding) and `diagram`, `make-pdf`
(Docs + translation) join the default profile, user go. The rest of the
BDR-017 exclusion list (ios-*, connect-chrome duplicate of
open-gstack-browser, gstack-internal tooling) stays out; enable it per
session with `profile apply` when needed.
2026-09-25 18:12:15 +02:00
bastien 4cd6e6ece9 chore(memory): journal, default profile merged to develop 2026-09-25 2026-09-25 17:06:13 +02:00
bastien 1ee6cf667b Merge feature/default-profile-full into develop 2026-09-25 17:05:59 +02:00
bastien 16fea1106d add .env without magix api 2026-09-25 17:05:33 +02:00
bastien 1b418cae84 chore(memory): BDR-101 + LRN-170 + LRN-171 + EVAL-031 — feat default-profile-full 2026-09-25 16:38:53 +02:00
bastien 0926cc74b5 docs: README profile default + 21st section, CHANGELOG default-profile entries — feat default-profile-full 2026-09-25 16:38:39 +02:00
bastien 1bbdad039c feat(install): apply the default profile at the end of make plugin
New Step 11 after the link.sh refresh: no profile selected → `profile.sh
reset` (default = full); an existing selection → `profile.sh set <sel>`, so
its state comes back after Step 2 re-parks gstack and Step 10 re-links the
design externals. Both calls are `|| warn`-guarded (installer runs under
set -e). Step 8.7 no longer parks the 21st pack unconditionally: the
selected profile governs it (full links the five design skills, the two
publishing skills stay on demand). Plugin legs stay install-immutable
(BDR-028 EXIT guard); the committed enabledPlugins already match full.
2026-09-25 16:28:22 +02:00
bastien 0d035fcab6 feat(profile): default profile = full; reset applies it, current is label-driven
No profile selected (.active-profile absent, empty or legacy "none") now
means the `full` profile is in force: DEFAULT_PROFILE declared once in
lib/profile.sh, resolved by active_profile(); the statusline reads the
constant and shows `full` instead of `?`; `gstack off` trims to it instead
of erroring. `reset` goes to the default profile (= `set full`: enables its
list, parks any non-listed gstack or managed item). `current` names the
active label and scores that profile only, saying `default — not applied
yet` until a set/apply/reset wrote the cache; the "none" sentinel and the
cross-profile best-guess scan are gone (they keyed on the parked-gstack
count, which says nothing under BDR-030's gstack-off default). Hermetic
suite lib/tests/profile-default.test.sh (29 checks) seeds gstack as OFF like
a real tree. Citers updated: profile SKILL, Makefile help, plugin-advisor
PROFILE line + reset paragraph, toggle-external header.
2026-09-25 16:28:21 +02:00
bastien e1963284d2 chore(21st): drop magic MCP residue
The magic MCP wiring left with BDR-093; this removes the prose that still
described it: gitleaks allowlist note, Step 8.7 header, plugins.lock note,
profile.sh comments and the usage() NOTE that still claimed `set` toggles
"the magic MCP", the managed-set test header, README (one history sentence
kept; MCP-era risk paragraph and the retired bashrc wrapper claim dropped).
.env.example carries the same scrub in the working tree; staging it is
denied to the agent (`git add .env*`), the user stages it.
2026-09-25 16:06:20 +02:00