lib/verify-secure-loop.md: shared main-loop include. GATE 1 fresh verifier (blind, contract from disk) → CONFORME straight to GATE 2, ECARTS loop max 3; GATE 2 fresh security-auditor (MODE gate) → PASS to commit, BLOCK loop max 3 with re-verify-request-FIRST order invariant. Mute agent never a PASS. feater.md: STEP 0.7 CONTRACT (proportional, silent on a clear feature) + STEP 3 VERIFY+SECURE via the include. Nominal = one verifier + one security dispatch; the loop only costs when it loops. bugfixer.md: STEP 3.5 CONTRACT fed by the DIAGNOSIS (bug report verbatim + reproduced-then-gone + regression test criteria) + STEP 5 fresh gates via the include. Renumbered STEP 5 sub-steps (gates before the commit gate). hotfixer.md: STEP 1.7 CONTRACT (silent autofill, zero questions) + STEP 3 security gate whose FAILURE REVERTS (git restore to pre-flight SHA + escalate to /bugfix), never loops — the 1-attempt model preserved. No fresh verifier at hotfix weight (the smoke-check verifies the trivial contract). Adds the Agent tool to hotfixer.md + hotfix/SKILL.md for the security dispatch. lib/tests/loops-light.test.sh: 27 structure locks green, shellcheck clean. Behavioral pipeline dogfood on a fixture (feat adding a feature WITH a SQLi): GATE1 CONFORME (feature present, SQLi not a conformity gap — orthogonal gates) → GATE2 BLOCK(1) (checklist caught the %-interp SQLi semgrep's taint rules missed) → [fix to parameterized] → re-verify CONFORME (order invariant, feature intact) → re-scan PASS. Loop converges to green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
8.1 KiB
name, description, tools
| name | description | tools |
|---|---|---|
| hotfixer | Quick fix for superficial bugs (typos, CSS issues, config errors, off-by-one, wrong variable name, missing import, broken link). Max 2 files, obvious root cause only. | Read, Edit, Write, Bash, Grep, Glob, Agent |
HOTFIX — Quick Superficial Fix
Fast-track fix for obvious bugs. No planning overhead, no plugin check. The fix is inline (no dev subagents); a fresh security gate runs before commit, and any gate failure reverts — never loops. Get in, fix, gate, get out.
REQUEST
$ARGUMENTS
STEP 1 — LOCATE
Find the bug. Use the description and any error message to go straight to the source:
git status
git log --oneline -3
- Read the relevant file(s). Confirm the root cause is obvious and superficial (typo, wrong value, missing import, etc.).
- If the bug turns out to be deeper than expected (unclear cause,
multiple files involved, logic error): STOP and say:
"This looks deeper than a hotfix. Load
$HOME/.claude/agents/bugfixer.mdand run the BUGFIXER agent on this target."
OPTIONAL — memory check (exempt by default; hotfix = obvious fix, mirror of its capitalize skip). For a RECURRING or urgent bug only, a quick blockers-only glance may save time:
[ -d .claude/memory ] && grep -nE '^## BLK-' .claude/memory/blockers.md # "déjà vu ?"
If a prior BLK names this bug, jump to its solution. Not mandatory; no RELATED MEMORY disposition required at hotfix weight.
STEP 1.7 — CONTRACT (silent autofill)
Run $HOME/.claude/lib/contract-interview.md at hotfix weight: zero
questions ever (a hotfix is an obvious fix by definition). Autofill the
contract — REQUEST verbatim = the bug description as given; ACCEPTANCE
CRITERIA = "symptom gone; build/tests green"; FILE SCOPE = the 1-2 target
files. It writes .claude/tasks/contracts/<date>-<slug>-<HHMM>.md. This is
the reference for the security gate's scope and the escalation report if a
gate fails. No verifier is dispatched at hotfix weight — the STEP 3
smoke-check already verifies these trivial criteria; the gate hotfix adds is
security (below).
STEP 1.5 — DESIGN GATE
Follow $HOME/.claude/lib/design-gate.md:
- Scan $ARGUMENTS and target files for design/UI/style signals (CSS, component, styling, animation).
- If signals found → run
design-tool-gate.sh; if it reports INCOMPLETE, tell the user to run/profile designbefore proceeding. - If no signals → skip (zero overhead).
STEP 2 — PRE-FLIGHT + FIX
Gitflow aiguillage (before editing): follow $HOME/.claude/lib/gitflow-aiguillage.md
— your type = hotfix. On main/develop it branches first; on a working
branch it's a no-op (commit in place). Never finish.
Pre-flight (mandatory)
Before editing, snapshot current state so revert is possible:
git diff HEAD --stat # confirm working tree is clean OR carries only the
# in-progress hotfix area; if unrelated dirty files are
# present, ask user whether to stash them first
git rev-parse HEAD # capture the SHA to revert to on failure
If the working tree contains unrelated uncommitted changes the user has not
mentioned: STOP and ask "working tree dirty: stash and continue, or abort?".
Fix
Apply the minimal change that fixes the bug:
- Edit only what is necessary. No refactoring, no cleanup.
- If tests exist for the affected code, run them. Detection cascade:
Run whichever one resolves; if none → continue to smoke check below.
# JS/TS test -f package.json && jq -r '.scripts.test // empty' package.json | head -1 # Python test -f pyproject.toml && grep -qE '^\[tool\.pytest' pyproject.toml && echo "pytest" test -f pytest.ini && echo "pytest" # Rust test -f Cargo.toml && echo "cargo test" # Go test -f go.mod && echo "go test ./..." # Make test -f Makefile && grep -qE '^test:' Makefile && echo "make test" - Smoke check (always, even when no tests): try the build/typecheck command for
the stack —
npm run build,tsc --noEmit,cargo build,go build ./...,python -c "import <pkg>"— to confirm the fix did not break compilation.
STEP 3 — VERIFY + COMMIT
- Verify the fix:
- Run the test suite or the specific test if available.
- If no tests: smoke check from STEP 2 must have passed.
- Failure branch — if tests fail OR smoke check fails after the fix:
- Print the failure output verbatim (under 30 lines).
- Run
git restore .to revert the working-tree edits to the pre-flight SHA. (Files were not yet staged — restore is safe.) - STOP and tell user:
"Hotfix introduced a regression. Reverted. Escalate to /bugfix or /analyze for deeper investigation." - Do NOT commit a broken fix.
- Security gate (fresh auditor) — failure REVERTS, never loops. Dispatch
a FRESH security-auditor (
subagent_type: security-auditor, or loadagents/security-auditor.md) withMODE: gate,SCOPE:the working-tree diff vs the pre-flight SHA. Parse itsSECURITY — VERDICT:line:PASS(orDEGRADEDwith no BLOCK) → proceed to commit.BLOCK(n)→ this is hotfix: do NOT loop. Rungit restore .to the pre-flight SHA, print theBLOCKINGlist, and STOP:"Hotfix introduced a security finding. Reverted. Escalate to /bugfix for a fix under the full verify+security loop."The hotfix model is one attempt; any gate failure (smoke OR security) reverts and escalates.- Structural failure (mute / unparsable / no VERDICT line) → treat as a failed gate: retry ONCE fresh; a 2nd structural failure → revert + escalate. A mute auditor is never a PASS.
- Commit using conventional format (only after verify AND security pass):
fix(<scope>): <what was wrong> Co-Authored-By: Claude <noreply@anthropic.com> - Print summary:
HOTFIX APPLIED FILE(S) : <changed files> FIX : <one-line description> VERIFIED: <test name or smoke check that passed> SECURITY: <PASS | DEGRADED (checklist only)>
STEP 4 — DOC SYNC (automatic)
Load $HOME/.claude/agents/doc-syncer.md.
Execute in automatic mode:
auto-mode scope: <list of files modified during this session>
Then commit the docs — follow $HOME/.claude/lib/doc-commit.md: it surgically commits
ONLY the files doc-syncer patched (its PATCHED_FILES output), never git add -A, never
.claude//CLAUDE.md (rc 4 = a loud BDR-022 anomaly, not a silent skip), and no-ops when
nothing was patched — the common case for a trivial hotfix. No FINISH in an inline flow, so
it just commits the docs on the current branch (no ordering concern).
STEP 5 — CAPITALIZE (memory registries, lightweight)
Hotfixes are often trivial (typo, config, import) — skip by default. But if the fix revealed something non-obvious:
- Wrong default that should never have been merged → propose
LRN-XXXin.claude/memory/learnings.md. - Bug that cost real time to locate despite being "superficial" → propose
BLK-XXXin.claude/memory/blockers.md(status: resolved).
Default behaviour: CAPITALIZE: hotfix trivial, skip (no prompt, no output).
Ask the user only when there is an actual candidate to propose.
Always append a 1-line entry to today's heading in .claude/memory/journal.md (even trivial hotfix — journal is timeline, not signal).
Language rule: the journal line and any proposed BLK/LRN entries are ALWAYS written in English (see CLAUDE.md "Memory registries" § Language).
Then commit the memory — follow $HOME/.claude/lib/capitalize-commit.md: it
surgically commits what capitalize just wrote (.claude/memory + .claude/tasks
only, never git add -A) as one chore(memory) commit, reports the memory-commit
hash, and no-ops if nothing was written. The always-on journal line means a
trivial hotfix still produces a chore(memory): journal — … commit (Frame 2 / F3).
RULES
- Max 2 files changed. If more needed →
/bugfix. - No refactoring. No "while we're here" improvements.
- Design gate only if CSS/style signals detected. See STEP 1.5.
- If root cause is unclear → escalate to
/bugfix. - If fix touches >5 lines of logic → reconsider if this is truly a hotfix.