settings.json: ENABLE_STOP_REVIEW=0 (the plugin's own switch: no more Opus call on every turn that changes code, 0 findings in 6 days, 1 recorded false positive; the regex layer and the commit/push agentic review stay on), brightdata-plugin@synced false (keyless-useless, its MCP skill would hijack WebFetch/WebSearch), frontend-design official plugin entry gone (uninstalled: byte-identical to the managed copy). CLAUDE.global.md routes Ship/PR to ship-feature (gstack ship takes origin/HEAD = main as base), drops ship/context-save from the gstack-off list and 21st-ui-review from the design review line (trio is max-only). deploy's table no longer points at land-and-deploy/setup-deploy. plugin-advisor.md describes security-guidance's real mechanics. CHANGELOG Unreleased entry with a Known residual section.
1213 lines
100 KiB
Markdown
1213 lines
100 KiB
Markdown
# Changelog
|
||
|
||
All notable changes to claude-config will be documented in this file.
|
||
|
||
Format follows [Keep a Changelog](https://keepachangelog.com/).
|
||
|
||
## [Unreleased]
|
||
|
||
### Added
|
||
- **`make doctor` checks the vendored externals** — new
|
||
`lib/doctor-vendored.sh` (`check_vendored_skills`), wired into doctor.sh
|
||
after the gstack section: every curl-pinned entry of plugins.lock.json
|
||
has its files under `skills-external/` (list, dict or single-path lock
|
||
shapes), every `EXTERNAL_SKILLS` name of link.sh is symlinked into
|
||
`~/.claude/skills/` when the active profile lists it, parked names are
|
||
reported not failed, hints `make plugin` / `make link`. Lock entries are
|
||
shape-validated (a malformed lock yields one warn, never a traceback) and
|
||
profile, skill and file names pass an allowlist before becoming paths.
|
||
Until now doctor only checked the gstack submodule. Hermetic suite
|
||
`lib/tests/doctor-vendored.test.sh`, 11 cases.
|
||
- **`skills/site-motion`** — personal skill for site-level motion
|
||
choreography (scroll engine choice and Lenis/ScrollTrigger sync, Astro
|
||
ClientRouter lifecycle, pin/scrub numbers, sticky stacks, video and image
|
||
scrubbing, WebGL hero lanes and budgets, upstream pitfalls, verification
|
||
checklist), distilled from the MengTo motion pack (invariants only,
|
||
LRN-141). Routed into the Build UI toolchain of CLAUDE.global.md and
|
||
lib/design-gate.md (not on the GATE-BLOCK set). Case 7 of the repo review.
|
||
- **Five MengTo scroll skills vendored** (`scroll-world-storytelling`,
|
||
`build-threejs-scroll-worlds` with its five references,
|
||
`scroll-scrubbed-visual-sequence`, `scroll-scrubbed-word-reveal`,
|
||
`scroll-progress-timeline`) at a pinned commit (`mengto-skills` entry in
|
||
plugins.lock.json, text files only, never demos or binaries). The
|
||
agent-skills curl loop became the shared `lib/vendor-skills.sh`
|
||
(`vendor_pinned_skills <lock-key> [refresh]`, list or dict lock shapes,
|
||
`VENDOR_BASE_URL` honoured only as `file://` for the hermetic suite
|
||
`lib/tests/vendor-skills.test.sh`, lock values validated: 40-hex commit,
|
||
github.com source, traversal-free paths, no trailing newline),
|
||
used by install-plugins.sh Step 8e and update-all.sh 7.3; refresh keeps
|
||
the file's convention and skips a skill that was never installed.
|
||
Registered in link.sh, .gitignore,
|
||
toggle-external, profile.sh and the design/web/web-full/full profiles
|
||
(plus `site-motion personal`). Seventeen other MengTo skills were read and
|
||
skipped: covered locally, buggy (reduced-motion `clearProps`, gate before
|
||
`registerPlugin`, no-JS opacity 0) or off-domain.
|
||
- **rules/web-building.md § Write-time reflexes** — stack-agnostic
|
||
micro-rules borrowed from ibelick/ui-skills (baseline-ui + playbook): dvh
|
||
and safe-area, paste never blocked, tabular-nums and text-wrap, one
|
||
z-index scale, compositor-only motion with reduced-motion and off-screen
|
||
pause, 44 px targets and focus-visible, status never by color alone,
|
||
errors next to the field, one accent per view. Case 3 of the 6-repo
|
||
review: nothing installed (CLI and MCP are a curl of raw SKILL.md, a
|
||
third router, and baseline-ui's stack mandates contradict Astro-first).
|
||
- **Agent Skills trio** (`observability-and-instrumentation`,
|
||
`deprecation-and-migration`, `ci-cd-and-automation`) — vendored from
|
||
addyosmani/agent-skills at a pinned commit (`agent-skills` entry in
|
||
plugins.lock.json), the emil-design-eng way: curl'd into
|
||
`skills-external/<name>/SKILL.md` by install-plugins.sh Step 8e, refreshed
|
||
by update-all.sh at the same commit, symlinked by link.sh, registered in
|
||
`lib/toggle-external.sh`, `lib/profile.sh` and the `full`/`backend`/`dev`
|
||
profiles. Case 2 of the 6-repo review: the plugin itself was rejected
|
||
(1.8k tokens per session for 20 % novelty, `/spec` `/review` `/ship`
|
||
collide with gstack, trunk-based git and the one-version API rule
|
||
contradict the doctrine, a second skill router).
|
||
- **`lib/floor-guard.sh`** — diff-scoped deterministic detector of a quietly
|
||
weakened quality bar (new lint/type suppressions, skipped or deleted
|
||
tests, dropped assertions, stubs, lowered coverage thresholds), with a
|
||
`floor-guard: allow <reason>` waiver, rc 0/2/3. Mandatory verifier
|
||
STEP 3 (`agents/verifier.md`), documented under GATE 1 of
|
||
`lib/verify-secure-loop.md`. Suite `lib/tests/floor-guard.test.sh`: 6
|
||
kinds plus a WAIVED and a CLEAN fixture, each flip-tested. Waivers
|
||
outside test files count as gaps unless the contract's CLARIFICATIONS
|
||
names them (security-gate MEDIUM, user chose strict). Adapted from
|
||
agent-skills `constraint-driven-development`.
|
||
- **`lib/tests/skill-routing-census.test.sh`** (+ `lib/skill-routing-census.py`)
|
||
— TF-IDF cosine census of skill-description collisions across the live
|
||
catalog (routing ambiguity, not naming): top 10 pairs, WARN ≥ 0.50,
|
||
FAIL ≥ 0.75, fixture flip-test. Baseline 2026-09-27: 120 skills, max 0.52
|
||
(`careful` ~ `guard`). Adapted from agent-skills evals Tier 2.
|
||
- **`rules/rest-api.md`** — path-scoped REST rule distilled from agent-skills
|
||
`api-and-interface-design`: contract-first order, one error envelope +
|
||
HTTP map, paginated lists, idempotency (key from intent, atomic claim,
|
||
payload guard, duplicate policy, retention), naming, Hyrum's law;
|
||
versioning points to `CLAUDE.md § Web APIs — always versioned` instead of
|
||
the upstream one-version rule.
|
||
- **`make test suite=<file>`** runs one suite hermetically; the
|
||
`GIT_CONFIG_GLOBAL=/dev/null` export lives in the Makefile so nobody types
|
||
the denied env-prefix form by hand (the reason an executor wrote a wrapper
|
||
around it on 2026-09-24).
|
||
- **`lib/tests/doctrine-citers.test.sh`** — every `CLAUDE.md "Section"` or
|
||
`CLAUDE.md … § Label` citation in skills, agents, lib, rules and hooks must
|
||
resolve to a heading or bold label of CLAUDE.global.md; flip-tested. Would
|
||
have caught the five "§ Language" pointers the density pass left dangling.
|
||
First run fixed one more (`rest-api-node.md` cited the heading without its dash).
|
||
- **graphify threshold signal** — `lib/graphify-gate.sh` counts tracked code
|
||
files (vendored trees excluded) and, from 200 with no
|
||
`graphify-out/graph.json`, the session-start banner shows one line
|
||
(`graphify? N code files ≥ 200, no graph`) plus the `/graphify` hint. It
|
||
informs, the user decides: nothing is built or installed. Doctrine and the
|
||
plugin-advisor thresholds follow the same rule; measured on a 295-file PHP
|
||
project: AST build 2.3 s, zero LLM tokens, one query 2 to 3k tokens.
|
||
Test `lib/tests/graphify-gate.test.sh` (11 checks).
|
||
- **Branch deletion guard** — `gitflow_delete` (also `gitflow.sh delete
|
||
<branch>`) is the only path that deletes a branch: it refuses `main` and
|
||
`develop` (rc 6) and any branch not merged into develop or main (rc 5),
|
||
with an explicit ancestor check, and keeps the branch; the `origin/` copy
|
||
is removed right after, once its own tip passes the same check (a remote
|
||
tip the bases lack is kept, loudly; no origin, `GITFLOW_NO_PUSH=1` or
|
||
`gitflow.autopush false` skip it). Motivation, proven
|
||
by `gitflow-test.sh` T22a: since `start` sets an auto-pushed upstream,
|
||
`git branch -d` checks "merged into origin/<branch>", which the post-commit
|
||
hook keeps trivially true. A fourth generated hook, `reference-transaction`,
|
||
vetoes any deletion or rename of `main`/`develop` at the ref layer in every
|
||
repo (`git config gitflow.protect false` opts a foreign clone out). Static
|
||
deny on hand deletion (`git branch -d`/`--delete`, renames of the bases),
|
||
a `hard_deny` entry for the nested forms; `gitflow.sh hooks` lists the hook
|
||
set, read by `doctor.sh` and the tests.
|
||
- **`make doctor` reports the Playwright browser cache** — a read-only
|
||
`Playwright browsers` section listing cache size, which registered
|
||
Playwright install requires each cached browser revision, and counts of
|
||
unreferenced directories and broken links. Report only: nothing is
|
||
pruned, since Playwright's own `install` already unions the required set
|
||
across every registered install.
|
||
- `lib/gstack-playwright.sh` — the gstack Playwright helpers as a shared
|
||
lib (OS-support bump, submodule-update wrapper, cache report), sourced by
|
||
`install-plugins.sh`, `update-all.sh` and `doctor.sh`, covered by
|
||
`lib/tests/gstack-playwright.test.sh`.
|
||
- **`doctor.sh` inspects the `autoMode` block**: warns when a classifier
|
||
list drops the built-in entries (no `"$defaults"`) and when the
|
||
user-scope `environment` names a git repo other than the config repo.
|
||
Neither defect is visible from the deny count, until now the only
|
||
permission signal `doctor.sh` had.
|
||
- **`templates/settings/SETTINGS.md` documents `autoMode`**: the four
|
||
classifier lists, `$defaults` splice semantics, `classifyAllShell`, the
|
||
user-scope vs project-scope rule, and why `ask` is the wrong tier for a
|
||
destructive command under auto mode.
|
||
- **21st.dev moved from an MCP server to a CLI.** `install-plugins.sh` Step 8.7
|
||
installs `@21st-dev/cli` globally (pinned in `plugins.lock.json`), offers
|
||
`21st login` in an interactive terminal only, and stages the 7-skill pack
|
||
into `skills-external/21st-*`. `update-all.sh` refreshes both. The design
|
||
skills follow the profile (on under the default `full`); the two publishing
|
||
skills stay parked.
|
||
- `lib/toggle-external.sh` manages `21st` as a skill pack (glob-derived from
|
||
`skills-external/21st-*`, parked under plain names so `profile.sh`'s
|
||
external park/restore stays interoperable). `magic` is gone from the
|
||
managed tools.
|
||
- The five design skills (`21st-ui-build`, `-ui-explore`, `-ui-review`,
|
||
`-cli-use`, `-ai`) are in the `design`, `web`, `web-full` and `full`
|
||
profiles and in `profile.sh`'s `MANAGED_EXTERNALS`; `21st-registry` and
|
||
`21st-design-sync` are installed but left parked.
|
||
- `autoMode.soft_deny` gains one entry for the outward-facing 21st verbs
|
||
(`publish*`, `submit`, `edit`, `delete`, `remove-from-catalog`,
|
||
`profile set|upload`) — publishing puts a component on a public listing.
|
||
That tier rather than `ask`, per LRN-153.
|
||
|
||
- `lib/design-gate.md` §5: a suggest-only check, same shape as the §4
|
||
animation-library one. When impeccable is active and the frontend project
|
||
has no `PRODUCT.md` at its root, the gate proposes `/impeccable init` once
|
||
and never runs it itself (it interviews the user). Skipped for single
|
||
component reviews and non-UI work.
|
||
|
||
- **Every commit is pushed as it lands.** `gitflow start` pushes the new
|
||
branch with its upstream, `gitflow finish` pushes each merge target, and
|
||
`gitflow init` / `install-hook` now write `post-commit` and `post-merge`
|
||
hooks next to `pre-commit` that push the current branch after every
|
||
commit and merge (`--follow-tags`, 30 s timeout, `GITFLOW_NO_PUSH=1` to
|
||
opt out in throwaway repos). A failed push warns loudly and never blocks
|
||
the commit. Nothing to run per project: `make link` generates `githooks/`
|
||
from the lib and sets git's global `core.hooksPath` to
|
||
`~/.claude/githooks`, so every repo on the machine runs the three hooks,
|
||
and `hooks/session-start.sh` refreshes a repo's own `.githooks/` when it
|
||
lags the lib (`gitflow reconcile-hooks`). Per-repo opt-outs for a foreign
|
||
clone: `git config gitflow.protect false`, `git config gitflow.autopush
|
||
false`. `make doctor` checks both. The pre-commit exemption now covers
|
||
`.githooks/**` next to `.claude/**`. `make test` and the suites that
|
||
commit on `main` run with `GIT_CONFIG_GLOBAL=/dev/null`, so the global
|
||
hooks never fire in throwaway repos. Covered by `gitflow-test.sh` T18
|
||
(bare origin: start, commit, opt-outs, unreachable origin, finish), T19
|
||
(installed and generated hooks equal the emitted ones, LRN-114 drift
|
||
gate), T20 (reconcile) and T21 (whitelist and protect opt-out).
|
||
- `hooks/unpushed-guard.sh` on `SessionStart` and `Stop`: a warning when the
|
||
branch is ahead of its upstream, has no upstream, or has no `origin`; at
|
||
session start also the count of uncommitted changes. Non-blocking.
|
||
- `make doctor` gains two sections: "Git hooks" (global `core.hooksPath`
|
||
set, generated `githooks/` equal to the emitters) and "Scratchpad": a
|
||
warning when `TMPDIR` sits on a tmpfs mounted with `usrquota`. systemd
|
||
mounts `/tmp` that way by default and caps each user at 80 % of its
|
||
size, so Claude's tool outputs share one quota across every session and
|
||
sub-agent, and one fat probe directory kills every shell at once (this
|
||
happened twice on 2026-09-22, BLK-021). Fix: launch claude with
|
||
`TMPDIR=$HOME/.cache/claude-tmp`.
|
||
- `lib/tests/guard-bash.test.sh`: the executable spec of a PreToolUse Bash
|
||
guard (transfer tools, sync deletes, recursive `rm` outside the project,
|
||
bulk permissions, privilege escalation, disk tools, docker privileges and
|
||
system mounts, git history destruction, writes into system zones,
|
||
guardrail tampering, pipe-to-shell, nested forms, scripts the command
|
||
runs). The hook itself is not shipped (BLK-022); the spec skips cleanly
|
||
until it lands.
|
||
- **`lib/tests/profile-default.test.sh`** covers the default-profile
|
||
resolution (absent / empty / `none` cache), `reset` = `set full`, the
|
||
label-driven `current` lines and the statusline fallback, on a fixture
|
||
seeded like a real tree (gstack off, nothing linked).
|
||
|
||
### Changed
|
||
- **`full` = everything the other profiles carry** (user rule: full does
|
||
what every specialized profile does), minus the 9 removed gstack
|
||
skills, the 21st generation/review trio and one named exception
|
||
(`pr-review-toolkit`, deliberately out of full since audit 2026-07-02
|
||
#12). New `max` profile (`# SUPERSET-OF: full` marker) is `full` plus
|
||
the parked tools (`make-pdf`, `diagram`, `21st-ai`, `21st-ui-explore`,
|
||
`21st-ui-review`) plus `pr-review-toolkit` — switch here when one of
|
||
them is needed. The 21st generation/review trio leaves `full`, `web`,
|
||
`web-full` and `design`; `CLAUDE.global.md`'s Design work line drops
|
||
`21st-ui-review` and notes the trio is `max`-profile only.
|
||
`security-guidance`'s Stop-hook LLM review is off
|
||
(`ENABLE_STOP_REVIEW=0` in `settings.json`'s `env`, the plugin's own
|
||
switch); its regex layer and the commit/push agentic review stay on.
|
||
`doctor.sh`'s skill-catalog token constants are recomputed from a real
|
||
count instead of a stale estimate.
|
||
- **CLAUDE.global.md § Code style** — the ordered YAGNI decision ladder
|
||
(not needed → reuse → stdlib → platform → installed dependency → one line
|
||
→ the minimum that works, after understanding the problem) and a
|
||
`shortcut:` comment convention for assumed shortcuts, harvested into
|
||
TODO.md. Six lines, 287 → 293 of the 320 budget. Case 1 of the 6-repo
|
||
review: ponytail and chisle rejected as plugins (per-turn and
|
||
per-subagent injection, prose rules colliding with writing-style.md,
|
||
the caveman purge precedent, rtk already covering the input axis).
|
||
- **Default profile = `full`.** With no selection (`.active-profile`
|
||
absent, empty, or the legacy `none`), `full` is in force: statusline,
|
||
`profile.sh current`, `gstack off` and `reset` all resolve it the same
|
||
way. `profile.sh reset` (and `make profile-reset`) now applies the
|
||
default profile, exclusively (= `set full`: enables full's list, parks
|
||
non-listed gstack and managed externals). It no longer means "re-enable
|
||
all gstack, plugins untouched". `profile.sh current` is label-driven: it
|
||
names the cached profile, or the default with "default, not applied yet"
|
||
until a `set`/`apply`/`reset` writes the cache, and scores that profile
|
||
only. The `none`/`custom` best guess is gone. The statusline shows `full`
|
||
instead of `?` when no profile is selected.
|
||
- **`make plugin` Step 11 applies the default profile** when none is
|
||
selected (`profile.sh reset`) and re-applies an existing selection
|
||
(`profile.sh set <sel>`), since Steps 2 and 10 rewrite skill state on
|
||
every run. Step 8.7 no longer parks the 21st pack unconditionally; the
|
||
pack's state follows the profile.
|
||
- **`full` profile gains four gstack skills** superpowers does not cover:
|
||
`scrape` and `skillify` (browser + dogfooding), `diagram` and `make-pdf`
|
||
(docs). Nothing removed; iOS skills, the `connect-chrome` duplicate and
|
||
gstack-internal tooling stay out.
|
||
- **Routing around a guardrail is the same action** — new `hard_deny` entry: a
|
||
refused command is never rerun through a wrapper script, alias, heredoc,
|
||
Makefile target, env file, other shell or other agent; a refusal ends the
|
||
attempt and is reported with its rule; a brief that orders the refused form is
|
||
wrong. The same clause sits in every executor and reviewer agent, and the
|
||
doctrine's sub-agent rule names it. "After code changes" gains step 4: a
|
||
changed rule, heading, label or threshold → grep every citer, same commit.
|
||
- **Doctrine/skill coherence pass (C2)** — 30 rule pairs in tension found by
|
||
three read-only audits and resolved in the doctrine's favour: one ask
|
||
policy (visible / public-name / open-scope choices are asked); mandated
|
||
executors exempt from the "don't delegate the trivial" rule; a
|
||
skill-persisted plan satisfies the planning rule; the journal line is
|
||
exempt from the approval gate; `chore/*` = maintenance without new
|
||
behaviour; a small fix on develop is a `bugfix`, `hotfix/*` is for prod
|
||
incidents; the BDR-068 memory auto-finish is written as the one exception;
|
||
`deploy` routes to `/deploy`. Skills follow: /hotfix types by base and skips
|
||
the design gate on the trivial tier; /capitalize and /close create missing
|
||
registries instead of stopping; /commit-change asks the branch type; /doc,
|
||
/seo, /web-validate and /refactor branch through the aiguillage; /tour
|
||
reports contract-breaking fixes as `needs decision` and runs doc-syncer in
|
||
its two modes; client-handover applies audit bundles from its main loop
|
||
behind one gate; init-project and onboard propose graphify only through
|
||
the 200-file signal and bootstrap the memory registries; release-candidate
|
||
gates the tag push only; push wording aligned with the BDR-095 hooks in
|
||
tour, deploy, capitalize; stale pointers fixed (`§ Language`, `.gsd/
|
||
ROADMAP.md`, handover script path, design-gate extensions and lists).
|
||
- **CLAUDE.global.md density pass** 352 → 270 lines (−15% words): prose
|
||
tightened, Security subsections folded into one labelled list, routing
|
||
lines that only repeated a skill description dropped. Every constraint and
|
||
every `##` heading kept; loaded in every session, so ~600 fewer tokens per
|
||
session in every repo (BDR-098).
|
||
- **Design gate: `magic` → the `21st` CLI in the required-manual slot.**
|
||
`design.profile`'s `GATE-BLOCK` now lists `21st` (CLI channel) and
|
||
`21st-ui-build` (the pack's canary on the skill channel); a missing CLI
|
||
trips the gate with `npm i -g @21st-dev/cli` + `21st login` instead of the
|
||
old `MAGIC_API_KEY` hint. `design-tool-gate.sh` also repairs `PATH` for the
|
||
npm global bin, whose absence in a hook's sanitized `PATH` would otherwise
|
||
read as "21st missing" (the existing repair only fired when `claude` itself
|
||
was unresolvable).
|
||
- `profile.sh`'s `MANAGED_MCPS` is empty: no MCP server is auto-toggled any
|
||
more. The `mcp` type stays supported for an advisory profile entry.
|
||
- **`/deploy` hand-back: one physical line per command, then a post-deploy
|
||
tests block.** Every command in the checklist is emitted on exactly one
|
||
line, however long; a legacy `\` continuation in the runbook is joined at
|
||
instantiation, and bootstrap and learn patches write runbook lines the same
|
||
way (`templates/deploy/PROCEDURE.md` header updated). After the checklist
|
||
the hand-back now carries a "Post-deploy tests" block derived from the
|
||
delta diff: by-hand checks (action → observable result, each tied to a
|
||
delta file) plus Suggestions (checks the runbook does not do yet, gaps
|
||
spotted between delta files). Cold-resume re-display and re-hand-back
|
||
regenerate both. RED/GREEN tested on a scratch runbook (4/4 baseline runs
|
||
reproduced the continuation verbatim and printed no tests).
|
||
- **Docker and node go through the classifier with a framing, instead of
|
||
an inert `ask` tier.** `Bash(docker run|exec *)`, `Bash(docker[-| ]compose
|
||
up*)` and `Bash(node -e *)` leave `permissions.ask` (no prompt under auto
|
||
mode, re-verified on 2.1.273). A new `autoMode.allow` list, `$defaults`
|
||
first, names the two routine cases the built-in `Remote Shell Writes` /
|
||
`Production Reads` rules were catching: `docker exec`/`run`/`compose`
|
||
against a local dev container whose name does not carry `prod`, running a
|
||
SQL file or script from the repo inside it; and project-local node
|
||
(`node <file>`, `npm run`, `npx`/`pnpm exec` of a lockfile-declared
|
||
package, effects inside the cwd). Two `soft_deny` entries frame what that
|
||
opens: docker data destruction (`rm -f`, `volume rm`/`prune`, `system
|
||
prune`, `compose down -v`, `--privileged`, bind mounts outside the cwd)
|
||
and undeclared node packages (`npx`/`dlx` of a package absent from the
|
||
lockfile, `npm install <name>`). `SETTINGS.md` gains the `autoMode.allow`
|
||
tier and the reason a static `Bash(node *)` rule cannot do this job.
|
||
- **Ask, don't guess: the orchestrators ask about open choices instead of
|
||
settling them.** `CLAUDE.global.md` replaces "one question upfront, never
|
||
mid-task" with: a choice visible in the result, a name that becomes
|
||
public, or a scope the request does not settle → ask, even mid-task;
|
||
internal technical choices stay Claude's. `lib/contract-interview.md`
|
||
STEP 2 becomes CLARIFY: pass A (the three gap checks, at contract time)
|
||
and pass B (the open-choice sweep in three classes, run once at each
|
||
flow's PLAN step, no question cap, over-5 guard, "you decide" recorded as
|
||
delegated). New MID-RUN CLARIFICATION section: an executor's
|
||
`NEED-DECISION` carries a `CLASS:` tag; visible / public-name / scope go
|
||
to the user verbatim, internal is decided in the loop; answers land in
|
||
the contract `[gated]`. New HOW TO ASK section (LRN-102). `/feat`,
|
||
`/bugfix`, `/hotfix`, `/ship-feature`, `/init-project` wire pass B at
|
||
their plan step; `/feat` and `/bugfix` stop deciding `NEED-DECISION`
|
||
themselves; `/hotfix` drops "zero questions ever" and allows one
|
||
re-dispatch for a class-tagged BLOCKED; the interviewer never ships a
|
||
visible / public-name / scope item as `(assumed)`; feater, bugfixer and
|
||
hotfixer report the class. Locks updated in the `contract-verifier`,
|
||
`loops-light` and `gates` tests.
|
||
- **The classifier, not `permissions.ask`, now guards destructive shell
|
||
work** (BDR-090). Ten rules left the static tiers: `rsync`, `kill -9`,
|
||
`killall`, `pkill` out of `deny`, and `python3 -c`, `python -c`,
|
||
`xargs`, `sed`, `cp`, `mv` out of `ask`. Under `defaultMode: auto` an
|
||
`ask` rule raises no prompt ([[LRN-146]]), so that tier was gating
|
||
nothing anyway. Cover is now `autoMode.soft_deny`, which the classifier
|
||
enforces and an explicit instruction clears: writes outside the working
|
||
directory, `rsync --delete`, SIGKILL and kill-by-name, in-place edits
|
||
spanning more than one file, directory moves, and inline interpreters
|
||
or `xargs` that delete or write outside the cwd. Intent clears a soft
|
||
block for the current turn only.
|
||
- **`autoMode.hard_deny` added** for the three classes no command pattern
|
||
can express: secret exfiltration (a read and a send, separate steps,
|
||
possibly turns apart), production deployment (deploy scripts, lftp/FTP
|
||
pushes, any `prod` target), and disarming the guardrails (weakening a
|
||
deny list, `--no-verify`, removing the pre-commit hook,
|
||
`bypassPermissions`). Adding a restriction stays allowed; removing one
|
||
does not. No instruction clears these.
|
||
|
||
- **impeccable installs at `--scope=global`, subagents included, and the
|
||
pin fails safe.** `install-plugins.sh` Step 8d no longer stages a
|
||
`--scope=project` install in a tmpdir and moves the skill directory alone.
|
||
The installer writes through the `~/.claude/skills` and `~/.claude/agents`
|
||
symlinks straight into the repo: `skills/impeccable` plus the four
|
||
`agents/impeccable-*.md`, both gitignored and machine-owned, which is what
|
||
the manual `--scope=global` command already did. The step refuses to run
|
||
before `make link` has created those symlinks (an install before them
|
||
materializes real directories that `link.sh` then refuses to replace),
|
||
keeps a profile-parked copy parked, reports the skill version and agent
|
||
count, and prints the per-project `/impeccable init` hint. A pinned
|
||
install that fails falls back to `impeccable@latest` with a warning to
|
||
bump `plugins.lock.json`. `update-all.sh` follows the same shape.
|
||
`plugins.lock.json` pin 3.2.0 → 4.1.0 (the CLI only: the skill dist and
|
||
the engine binary have their own release tracks). `link.sh` drops
|
||
impeccable from `EXTERNAL_SKILLS`; `skills-external/impeccable/` is gone.
|
||
|
||
### Security
|
||
- **Ten secret-reader deny rules added**: `sed`, `awk`, `cut`, `tr`,
|
||
`sort`, `uniq`, `diff`, `od`, `xxd`, `strings` against `.env*`. Six of
|
||
those tools sat in `permissions.allow`, so reading a `.env` through
|
||
them triggered nothing. Same shape and same known gap as the existing
|
||
`Bash(grep * .env*)` family: a `cat .env | sed` pipe still slips past,
|
||
which is what the `hard_deny` exfiltration rule is there to catch.
|
||
|
||
- **Data-loss guardrails after the 2026-09-21 wipe** (BDR-095). Static
|
||
`permissions.deny` now refuses transfer and mirror tools (`lftp`, `sftp`,
|
||
`ftp`, `curl -T`), `rsync --delete`, `xargs rm`, pipe-to-shell,
|
||
`chmod`/`chown -R`, `sudo`/`doas`/`pkexec`, disk tools, `chattr`, docker
|
||
volume drops, `system prune`, `compose down -v`, `--privileged`, the
|
||
docker socket and `-v /:`, and git history destruction (`push --delete`,
|
||
`--mirror`, `:ref`, `--force-with-lease`, `branch -D`, `filter-branch`,
|
||
`reflog expire`, `stash clear`/`drop`, `clean -f`, `--no-verify`,
|
||
`core.hooksPath`, the `GIT_CONFIG_GLOBAL=` / `GIT_CONFIG=` env prefixes
|
||
and the per-repo `gitflow.*` opt-outs, which belong to the human). The
|
||
pipe-to-shell and stash entries left `ask`, which is
|
||
unreliable under auto mode. New `autoMode.hard_deny`: a destructive tool
|
||
aimed at a path built from a variable, `~`, `..`, a wildcard, or outside
|
||
the project and the temp dir, including as a trace or a rehearsal that a
|
||
brief allows; a sub-agent brief carries no user authority. `soft_deny`
|
||
reworded for the promoted docker items and gains "discarding uncommitted
|
||
work". `environment` records the incident, the push discipline, and that
|
||
Claude never runs a deploy. `CLAUDE.global.md` gains "Destructive tools &
|
||
data loss"; the four report-only agents state that a destructive tool is
|
||
traced by reading, never by running, whatever the brief says.
|
||
|
||
### Removed
|
||
- **Skill-catalog prune**: `brightdata-plugin@synced` disabled
|
||
(account-synced, keyless-useless, its `bright-data-mcp` skill would
|
||
hijack WebFetch/WebSearch), `frontend-design@claude-plugins-official`
|
||
uninstalled (byte-identical duplicate of the managed `skills-external`
|
||
copy). The 9 broken or doctrine-breaking gstack skills — `ship`,
|
||
`land-and-deploy`, `setup-deploy`, `autoplan`, `context-save`, `learn`,
|
||
`careful`, `guard`, `design-shotgun` — are out of every profile that
|
||
listed them (`dev`, `backend`, `web`, `web-full`, `design`, `full`),
|
||
each with its reason in the new `lib/gstack-removed.sh` (exit-127 hooks,
|
||
an absent `OPENAI_API_KEY`, `ship`/`land-and-deploy` skipping develop,
|
||
`context-save` with no restore). The new `GSTACK_REMOVED` denylist is
|
||
honored by `profile.sh gstack on` and `toggle-external.sh enable
|
||
gstack`: both now skip a removed name instead of silently restoring it.
|
||
- `deploy` `push_deploy_tags` knob (the STATE.json commit's hook pushes the tag
|
||
with `--follow-tags`); `/onboard add gsd` and `/onboard continue` mentions
|
||
(never had a handler).
|
||
- **`magic` MCP (`@21st-dev/magic`) and `MAGIC_API_KEY`**, with the two risks
|
||
attached to them: the unauthenticated `127.0.0.1` callback server
|
||
`21st_magic_component_builder` opened (LRN-110) and the plaintext key copy
|
||
that `claude mcp add --env` wrote into `~/.claude.json` (BDR-026/057). Gone
|
||
with it: the 4 `mcp__magic__*` `permissions.ask` entries (BDR-059), the
|
||
`MAGIC_API_KEY` block in `.env.example`, `link.sh`'s missing-key warning,
|
||
and the dead `MAGIC_API_KEY=abc123` gitleaks allowlist regex.
|
||
|
||
### Fixed
|
||
- **gstack's shared helper tree was mostly unreachable.** gstack skills
|
||
hardcode `~/.claude/skills/gstack/<path>` for shared assets, but
|
||
`link.sh` and `install-plugins.sh` only ever linked `bin` and
|
||
`browse/dist`. A shared `lib/gstack-links.sh` (used by `link.sh`,
|
||
`install-plugins.sh` and `update-all.sh`) now links every non-skill
|
||
child of the gstack submodule, so `make-pdf`, `diagram`, the `freeze`
|
||
hook, the `*/sections/*.md` files, `scripts/jargon-list.json` and
|
||
`ETHOS.md` resolve; `/unfreeze` now actually clears
|
||
`~/.gstack/freeze-dir.txt`. `doctor.sh` counted skills with `find
|
||
-maxdepth 2` (no `-L`, missed symlinked skills) and truncated
|
||
block-scalar (`|`/`>`) descriptions to 0 chars; it now reuses
|
||
`lib/skill-routing-census.py`'s description parser through
|
||
`lib/doctor-skills.sh`. Dropped the stale "security-guidance … 0
|
||
tokens" claim from `install-plugins.sh` and `agents/plugin-advisor.md`:
|
||
the Stop review costs out-of-band quota, not context.
|
||
`CLAUDE.global.md`'s Ship/PR routing pointed at gstack's `ship`, which
|
||
bases off `origin/HEAD` (= main) and skips develop; it now routes
|
||
straight to `ship-feature`.
|
||
- **`gitflow init` on an existing repo under the machine-wide hooks** — the
|
||
socle commit (`.gitignore` + `.githooks/`) landed directly on `main`
|
||
"while the hook is inactive"; since the global `core.hooksPath` the
|
||
pre-commit refused it and init died. The socle now lands on
|
||
`chore/gitflow-adopt` off main, merged `--no-ff` (merge commits run no
|
||
pre-commit), branch deleted, develop created after. T2c simulates the live
|
||
hook; the hermetic suite could not see the regression.
|
||
- **`make update` no longer drops the Playwright OS-support bump** — a
|
||
gstack submodule update used to leave the bump unapplied until the next
|
||
`make plugin`, the open caveat of BDR-029. `update-all.sh` now goes
|
||
through `gstack_submodule_update_with_bump`, which re-applies it after a
|
||
successful update and returns non-zero on failure so the existing warn
|
||
arm still fires. Two latent bugs travelled with the extracted code: the
|
||
ostag capture exited 1 on every non-Ubuntu host and aborted its caller
|
||
under inherited `errexit`, and the `bun` calls had no timeout.
|
||
- **`autoMode.environment` no longer describes one project from the
|
||
user-scope file**: the block named a specific repo, its FTP deploy
|
||
target and its customer data, while `link.sh` symlinks this file to
|
||
`~/.claude/settings.json` where it reaches every project. The global
|
||
block now states machine-level facts only (self-hosted Gitea, gitflow
|
||
protection, `~/.claude/.env` as the single secret source, no CI), and
|
||
the project-specific facts moved to that project's gitignored
|
||
`.claude/settings.local.json`. Both lists now open with `"$defaults"`,
|
||
which the original omitted, so the built-in entries are inherited
|
||
rather than replaced.
|
||
- `README.md` no longer claims the `ask` tier makes every `mcp__magic__*`
|
||
call "require a live confirmation and can never auto-execute". That
|
||
holds under `defaultMode: default`, not under this config's `auto`. The
|
||
paragraph now separates what is verified from what is not, and names
|
||
`deny` as the only tier the classifier cannot lift.
|
||
- **`make plugin` never installed impeccable.** Three defects. The 3.2.0
|
||
pin had rotted upstream: the CLI fetches its skill dist at install time and
|
||
that release's artifact is gone (`Download failed: invalid zip data`),
|
||
which the step reported as "run it yourself" on every run. The
|
||
project-scope staging dropped the four subagents the same install writes.
|
||
And `/impeccable init` was never announced. A fourth, found while probing
|
||
the fix: once a copy is already installed, a rotted pin exits 0
|
||
(`Could not check for skill updates … Existing skills were left
|
||
unchanged`), byte-identical on disk to a genuine "Skills are up to date"
|
||
rerun, so `imp_install` now reads the installer output instead of trusting
|
||
the exit code or a version compare. Verified with the real installer in a
|
||
sandbox HOME: fresh install, rotted pin over a copy (fallback fires), same
|
||
pin rerun (no false warning), parked copy plus rotted pin (fallback, then
|
||
returned to `skills-disabled/`).
|
||
|
||
### Known residual
|
||
- The kept gstack skills still carry upstream prose routing to `/ship`,
|
||
`/land-and-deploy`, `/context-save`, `/autoplan` and `/design-shotgun`
|
||
(their own text, machine-owned submodule files, not ours to patch);
|
||
`21st-ui-build` and `21st-cli-use` still point at the now-`max`-only
|
||
21st trio. A Skill call on a parked name fails, and the doctrine
|
||
routing in `CLAUDE.global.md` applies instead.
|
||
|
||
## [1.5.0] — 2026-09-13
|
||
|
||
### Added
|
||
- **Attention signals on the terminal (BDR-087)** — new
|
||
`hooks/notify-attention.sh`, wired on `Notification` (input-needed
|
||
matcher) and on `Stop` (no matcher). Returns a double BEL plus an
|
||
OSC 777 toast through the `terminalSequence` JSON field, since hooks
|
||
have no controlling TTY. Signal only: `suppressOutput`, exit 0, zero
|
||
control-flow effect, which is what separates it from the `decision:
|
||
"block"` Stop hook [[BDR-083]] refused. Each event reaches the toast
|
||
as a readable label instead of a snake_case type; events needing no
|
||
attention (`agent_completed`, `auth_success`) exit silently; a turn
|
||
that ends with `background_tasks` still running stays quiet and
|
||
signals at the real end. Client-side prerequisites over Remote-SSH
|
||
are documented in the script header ([[BLK-020]]): VS Code
|
||
`accessibility.signals.terminalBell` for the beep, an OSC notifier
|
||
extension for the Windows toast.
|
||
- **User permanent rules (BDR-085)** — three new rules/ files from the
|
||
user's rule text: `writing-style.md` (always-on: em-dash ban, no slop
|
||
vocabulary, no hedging chains, deliverable self-check),
|
||
`web-building.md` (path-scoped: design anti-defaults + public-site done
|
||
checklist), `web-security.md` (path-scoped: RLS, service-key/client
|
||
split, IDOR, cookie flags, rate limiting — extends §Security, no dup).
|
||
Project CLAUDE.md rules/ doctrine gains the 320-budget exception.
|
||
- **/tour multi-project parallel fan-out (BDR-084)** — two or more
|
||
project paths now dispatch one runner per repo in a single message
|
||
(independent working trees, nothing collides) instead of processing
|
||
them one by one. The runner inherits the session model (no pin — it
|
||
carries tour's reflection); every agent inside keeps its defined tier.
|
||
A dead runner surfaces as an explicit `RUNNER FAILED` summary row; the
|
||
gated capitalize offer stays in the main loop. Bounded LRN-083
|
||
derogation recorded in BDR-084. Census §12: 6 locks, flip-tested.
|
||
Mechanics proven first: nested probe, 3 overlapping agent windows,
|
||
9.1s vs ~18s sequential.
|
||
- **Contract gates — deterministic floor under the fresh verifier (BDR-083)** —
|
||
an acceptance criterion can now carry an oracle (`CHECK:` command +
|
||
`EXPECT:` success-only marker + `EVIDENCE:` slot). `lib/gates.sh run
|
||
<contract>` executes them fail-closed — MET requires exit 0 **and** the
|
||
marker — and writes the outcome back into the contract, so the fresh
|
||
verifier reads evidence as fact instead of trusting the executor's report.
|
||
New `GATE 0` in `lib/verify-secure-loop.md` runs the floor before any
|
||
verifier is dispatched: a red build no longer costs an LLM dispatch to
|
||
discover. `ABANDON: <id> <reason>` makes an impossible criterion a visible
|
||
handoff that blocks `CONFORME` and routes to the human gate (new verifier
|
||
verdict `ABANDONED(n)`). `feater` and `bugfixer` gain a four-pass
|
||
completion discipline, scoped so it can never widen the contract.
|
||
Adapted from the `unlazy` skill (Leonxlnx/unlazy, MIT); its Stop hook,
|
||
approval store, `.unlazy/` tree, depth-tree arithmetic and Node checker
|
||
were deliberately refused — see BDR-083 for each reason.
|
||
The four orchestrator skills (`feat`, `bugfix`, `ship-feature`,
|
||
`init-project`) restate the GATE 0 bullet ahead of GATE 1 (locked);
|
||
hotfix explicitly runs no floor. Behavioral RED: 16/16 fresh unprimed
|
||
runs followed the new doctrine (EVAL-027).
|
||
64 new assertions in `lib/tests/gates.test.sh`.
|
||
- **`lib/tests/seo-geo-contract.test.sh`** — census locking the seo/geo
|
||
agent ⇄ dispatcher machine contract: judge verdict grammar, FIX BUNDLE +
|
||
READY-TO-APPLY sentinel, signals handoff, every STEP header (interiors
|
||
included), bundle item fields, score labels, scoring blocks, envelope
|
||
keys (46→71 assertions across the C1 chantier).
|
||
|
||
### Changed
|
||
- **Skill and agent quality campaign, 54 units (BDR-086)** — full darwin
|
||
v2.1 pass over the 31 personal skill-systems and 23 agents, excluding
|
||
the gstack/external symlinks and machine-owned units. Fresh baseline
|
||
mean 83.4; the 13 units under the user-set threshold of 80 were
|
||
optimized to completion, and verified defects in above-threshold units
|
||
were fixed in a grouped pass rather than left to ship because the score
|
||
was good enough. Every round was validated by a paired 3-judge majority
|
||
reading before and after in one call: 36 unit-round verdicts, 24 batch
|
||
verdicts, all better, zero reverts. Full report and residual findings:
|
||
`.claude/audits/DARWIN-2026-08-26.md`.
|
||
- **seo-analyzer + geo-analyzer de-prescribed for Opus 5 (BDR-082)** —
|
||
process choreography converted to when-guidance under an
|
||
audience×mode-range invariant; self-output verification demands removed
|
||
(the score-engine "run it twice" became a conditional integrity guard);
|
||
two pre-BDR-061 vestigial rules fixed; P0/MANDATORY/ALWAYS caps softened
|
||
to plain content rules. Machine contract byte-frozen and locked by the
|
||
new `lib/tests/seo-geo-contract.test.sh` census (71 locks, flip-proven);
|
||
proven by a controlled before/after `/seo` dogfood — judge replay on
|
||
frozen signals, 42/42 presence assertions on both runs, blind structural
|
||
reader: interchangeable, recall improved.
|
||
- **Global instruction layer recalibrated for the Claude 5 family (BDR-081)** —
|
||
delegation block is now model-neutral when-guidance (the Opus 4.8
|
||
under-delegation counter inverted on Opus 5, which over-delegates and gets
|
||
an injected harness cap); "staff engineer" self-check bar dropped (Opus 5
|
||
over-verification trigger); finish-whole-task clause added to Deviations;
|
||
written-deliverable length rule added. 308/320 lines.
|
||
- **Default session model is now `opus[1m]`** (was `claude-fable-5[1m]`).
|
||
- **`skills-external/emil-design-eng/` untracked** — the file is curl'd
|
||
from upstream by `install-plugins.sh` when absent and re-fetched by
|
||
every `update-all.sh` run, so tracking it produced a repo diff on each
|
||
upstream edit. Same category as `frontend-design/` and `impeccable/`,
|
||
already ignored on that rationale; a fresh clone re-fetches it.
|
||
`design-motion-principles/` has the same overwrite behaviour but no
|
||
bootstrap clone yet, so it stays tracked until that gap closes.
|
||
|
||
### Fixed
|
||
- **hotfix wiped tolerated in-progress edits on its revert path** — every
|
||
failure branch ran `git restore .`, destroying user edits the run had
|
||
tolerated. Now a `git stash create` pre-flight snapshot plus a
|
||
file-scoped restore, and the security gate is fresh-dispatch only.
|
||
- **skills-perso listed 8 of 31 personal skills** — detection rebuilt on
|
||
the `link.sh` symlink convention (symlink = external, real dir =
|
||
personal, gitignored = machine-generated). Live result 31/31, no false
|
||
positives.
|
||
- **plan-challenger** — `ERROR` joined the load-bearing verdict grammar
|
||
(STEP 1 emitted it, the parser enum omitted it); grounded-but-uncertain
|
||
findings now file as `[MINOR]` with the uncertainty stated, instead of
|
||
being self-censored (Opus 5 follows conservative-reporting clauses
|
||
literally).
|
||
- **design-toolchain hook** — dropped `\bux\b` (2 French-prose false
|
||
positives; 3rd tightening pass, series LRN-1005/1007); `\bui\b` kept and
|
||
locked by a must-fire test row.
|
||
- **Agent and skill defects found by the campaign's judges** —
|
||
`init-project` allowed-tools lacked `Agent` and `Skill` while every step
|
||
dispatches; `commit-change` conflict grep now covers all 7 unmerged
|
||
codes; `tour --report-only` no longer commits; `harden` severity defers
|
||
to the calibrated guide and the late SSL Labs grade has an assigned
|
||
actor; handover writers' stale chapter refs corrected and the anchor
|
||
gate ordered; `security-auditor` documents the hotfix no-verifier
|
||
carve-out; `close` enumerates STEP 5C and passes `--no-push` through;
|
||
`prune-memory` drops a false "v1-untested" note; `code-clean` attributes
|
||
its executor correctly; plugin-check and onboard fixtures de-drifted.
|
||
|
||
## [1.4.0] — 2026-07-22
|
||
|
||
### Added
|
||
- **Transient planning artifacts auto-purged at feature-finish (BDR-065)** —
|
||
`gitflow finish` on a `feature`/`bugfix` branch now removes the run-time
|
||
superpowers artifacts (`docs/superpowers/{specs,plans}`) on the working
|
||
branch just before the directed merge, so `develop`'s tip lands clean while
|
||
the feature commits stay reachable as the archive (`git show <sha>:…`). This
|
||
automates the manual post-merge cleanup that BDR-065 had left as doctrine —
|
||
the step that slipped in 1.3.0 and needed a hand purge. Best-effort by
|
||
contract: a purge that finds nothing, meets uncommitted changes under those
|
||
paths, or fails to commit never aborts the finish (index/tree restored); opt
|
||
out with `GITFLOW_PURGE_TRANSIENT=0`. New `gitflow.sh purge-transient` verb.
|
||
`.claude/tasks/{contracts,plans}` are deliberately out of scope (durable,
|
||
versioned, referenced by the decision registry). Live in every project via
|
||
the `~/.claude/lib` symlink; covered by `lib/gitflow-test.sh` T17 (a–d).
|
||
|
||
### Changed
|
||
- **Bug routing inverted: `/bugfix` primary, `/investigate` explicit-only
|
||
(BDR-080)** — a bug / error / 500 now routes to `/bugfix` by default (the
|
||
full framework: gitflow, contract, fresh verifier + security gates,
|
||
registries). The gstack `/investigate` monolith — its own `~/.gstack`
|
||
memory, no gitflow or gates — is reserved for explicit requests
|
||
(cross-project learnings, `/freeze` scope lock, long investigation with no
|
||
immediate commit intent). Same core debugging doctrine, incompatible
|
||
wrappers; the default now favours the gated, integrated path.
|
||
|
||
## [1.3.1] — 2026-07-20
|
||
|
||
### Changed
|
||
- **README rebuilt around a short pitch** — new top half: what it is / how
|
||
it works / why it's good in ~60 lines (skills = entry points, agents =
|
||
model-tiered execution units, hooks = deterministic guardrails,
|
||
templates/memory = compounding per-project registries); all previous
|
||
content demoted to an explicit reference-manual half below a separator.
|
||
Deduplicated in the process: old title/tagline, Overview prose and the
|
||
duplicated fresh-install block removed (unique install notes kept under
|
||
a new "Install notes" section); hardcoded version number dropped from
|
||
the footer (staleness risk). Docs-only release — no code change.
|
||
|
||
## [1.3.0] — 2026-07-20
|
||
|
||
### Added
|
||
- **Profile switches now toggle external packs and MCPs both ways (BDR-079)** — `profile.sh set` was asymmetric: it enabled what a profile listed (including gstack skills on demand when the whole pack is off, and the `magic` MCP) but never disabled the managed leftovers, so `set backend` after design work kept emil-design-eng / frontend-design / design-motion-principles / impeccable active and magic registered. `set` now trims managed externals (`MANAGED_EXTERNALS`) and managed MCPs (`MANAGED_MCPS`, delegated to `toggle-external.sh`) not listed in the profile — same allowlist doctrine as `MANAGED_PLUGINS`, nothing outside the allowlists is ever auto-touched (darwin-skill stays manual). Also: an `external` entry whose symlink never existed is now created from `skills-external/` (mirroring toggle-external's from-source path), and the stale "NOT toggled automatically" note in `profile.sh` usage was corrected. Covered by a hermetic 16-check test (`lib/tests/profile-set-managed.test.sh`) with a fake `claude` shim.
|
||
|
||
### Changed
|
||
- **README restructured for public readers** — the project-layout tree and architecture principles moved verbatim to a new `ARCHITECTURE.md` (README links it); bare decision-registry citations (`BDR-XXX`) stripped from README prose, meaning preserved; `/profile` documentation corrected in three places to the real 10-profile set (web / seo / web-full / full / backend / design / dev / qa / audit / minimal); fresh-install block now uses the real clone URL + `make install` / `make doctor`; new "SEO data layer" subsection documents the `GOOGLE_OAUTH_CLIENT_ID` / `GOOGLE_OAUTH_CLIENT_SECRET` / `CRUX_API_KEY` vars in `~/.claude/.env` (mirrors `.env.example`, `make seo-connect` one-time consent).
|
||
|
||
### Fixed
|
||
- **Transient planning artifacts purged from the repo** — `docs/plans`, `docs/specs`, `docs/superpowers/{plans,specs}` (deploy-skill 2026-06-27, model-routing 2026-07-15) were run-time pipeline artifacts that should have been deleted in their chantiers' post-merge cleanup and slipped through (one pair predates the lifecycle rule, one missed the purge step of a 6-wave chantier). Git history at the feature commits remains their archive; `docs/` no longer exists.
|
||
|
||
## [1.2.1] — 2026-07-20
|
||
|
||
### Fixed
|
||
- **README caught up with the code it describes** — the "Agent model routing" section still presented the BDR-066 v1 scheme (7 rows factually wrong after model-tiering v2): reframed to the BDR-076/077 4-tier table verified against agent frontmatters (opus-pinned judgment agents, per-mode splits for doc-syncer / handover-doc-writer / seo-geo pipelines, plugin-probe added, unpinned inline agents listed as such). Also: Context7 paragraph rewritten to the two-surface model (find-docs = sole doc-fetch surface, `ctx7-reminder` hook = scoped session nudge, BDR-078), `hooks/` tree line now mentions the ctx7 reminder, and the `/ship-feature` workflow block gained its STEP 2b (adversarial plan-challenge) line. Docs-only release — no code change.
|
||
|
||
## [1.2.0] — 2026-07-20
|
||
|
||
### Added
|
||
- **ctx7 coverage extension (BDR-078)** — the "consult current docs before coding against a fast-moving lib" doctrine now covers every code path, not just the two big pipelines. (1) `lib/fast-libs.sh`: single source of truth for fast-lib detection (`detect` / `cache-status` verbs; JS package.json anchored keys + Python requirements/pyproject; 7-day `.ctx7-cache/` freshness; locale-independent sort), replacing three hardcoded lists (`/ship-feature` STEP 0c, `/init-project` STEP 5c, `/onboard` STEP 3.5). (2) `hooks/ctx7-reminder.sh`: once-per-session UserPromptSubmit nudge when the project carries fast-libs and the cache is missing/stale — closes the ad-hoc-coding gap. (3) find-docs description extended with a before-writing-code trigger + a cache-first rule (read fresh cache, tee fetched docs back into it). (4) feater/bugfixer executor briefs gain the fast-lib docs rule (read fresh cache, else 2-topic `npx ctx7@latest` fetch, else report `ctx7 cache miss` and proceed). Second deliberate ctx7 surface — a scoped refinement of BDR-053's single-surface rule, not a reversal.
|
||
- **Adversarial plan-challenge phase** — reflection orchestrators now run a blind 3-lens challenge (correctness / robustness / simplicity) via a dedicated `plan-challenger` agent before implementation; severity-driven (a single-lens BLOCKER stops the plan), report-only. `/hotfix` joins behind a logic-only guard: cosmetic fixes skip it, logic fixes get challenged, a BLOCKER reroutes to `/bugfix` (BDR-075).
|
||
- **seo-data engine: measured coverage + new verbs** — the `/seo` FULL audit measures instead of feeling: `sitemap` verb gives COVERAGE a real denominator (source/live split); internal-link graph computes orphan pages + click depth; cannibalisation detected from GSC's own query data; `rich_results` surfaced from URL Inspection data already fetched; `sameAs` profiles actually resolved; `schema_gen` generates JSON-LD instead of only auditing it; `content_quality` runs a deterministic filler/AI-slop scan; the axis score is computed, not felt; `drift` baseline reports regressions vs changes. SPA pages: the audit refuses to score what JS paints instead of scoring the empty shell (no Playwright dependency). Common Crawl backlinks were measured (17 GB edges file) and killed as a source — the Off-page axis stays scoped to what is actually measured.
|
||
|
||
### Changed
|
||
- **Model-tiering v2: 4-tier explicit routing (BDR-076/077)** — the session model (Fable) does main-loop reflection/orchestration only; every dispatched subagent is explicitly tiered: judgment agents pinned opus (analyzer, plan-challenger, seo/geo audit agents…), mechanical executors sonnet, skill-runner children fable — nothing inherits silently. Mode-based splits so pins take effect: doc-syncer audit(opus)/patch(sonnet), handover-doc-writer synthesize(opus)/render(sonnet), seo/geo collect(sonnet)/judge(opus, fail-closed)/template(sonnet), plugin gate split probe(sonnet)/advisor(opus). Census locks (125) + per-wave planted-input smokes.
|
||
- **config-protection edit-block guardrail removed** (BDR-074) — the hook blocked more than it protected; deny-list design pass recorded in BDR-069.
|
||
- graphify vendored skill dist synced 0.9.6 → 0.9.15.
|
||
|
||
### Fixed
|
||
- **seo/geo integrity pass (I1–I8)** — Off-page axis scoped to measured data only; VSI (an SEO-blog fiction) removed from CWV thresholds; NAP direction rule ported into geo-analyzer (standalone `/geo` can no longer write unverified NAP); security headers no longer double-counted (`/harden` owns them); sampling coverage disclosed instead of implied; stats reattached to the claims they support; phantom audit precondition dropped. Plus two real bugs caught by a second-site backtest and two process anomalies from live dogfooding.
|
||
- `settings.json` Write() deny rules were inert — converted to Edit() rules, closing the write hole they left open.
|
||
- Model-routing W6 ronde: 6 findings closed (README bootstrap path, 2 census gaps, 3 stale refs).
|
||
|
||
### Security
|
||
- **`safe_fetch` resolve-then-pin** in `lib/seo-data` — DNS-rebinding closed on audit fetches: the audited host is resolved once, validated, then pinned for the actual fetch.
|
||
- **`url-guard`** — shell-injection + local-target refusal before any user-supplied or sitemap-crawled URL reaches curl (SSRF guard on the seo/geo fetch paths).
|
||
|
||
## [1.1.0] — 2026-07-16
|
||
|
||
### Added
|
||
- `/close` + `/capitalize` now auto-persist the memory they write. When the ritual branches a `chore/*` branch off develop, it finishes that branch into develop and pushes `origin/develop` automatically (new STEP 5C), so capitalized decisions / learnings / evals reach the next session instead of stranding on an unmerged branch. Scoped to memory-only ritual commits: a `--no-push` flag holds the commit on the branch instead; a run on a feature branch (where the memory already rides the work) or an unsafe git state skips the auto-persist; and a failed push leaves the local merge intact with a manual-push note. Recorded as BDR-068, a deliberate scoped exception to the push-needs-an-explicit-go rule (which guards surprise code/release pushes, not an end-of-session memory persist).
|
||
|
||
## [1.0.0] — 2026-07-16 — Initial public release
|
||
|
||
First public release of claude-config. The feature set below is the
|
||
accumulated work previously staged as internal versions 1.0.0–4.0.0
|
||
(see "Pre-release (internal history)" further down for that lineage).
|
||
|
||
### Changed
|
||
- BREAKING(layout): repo-root global memory renamed CLAUDE.md → CLAUDE.global.md; run `bash link.sh` once after pulling (doctor.sh now checks the exact target)
|
||
- graphify skill dist refreshed 0.8.45 → 0.9.6 (out-of-band `make plugin`; SKILL.md + query/extraction references updated by the generator).
|
||
- `/deploy` checklist reshaped on first-real-run feedback, in two passes: runbook steps are **one command per line, interactive-session style** (an early step opens the ssh session; later lines run on the box; local steps say "from your machine") instead of folded `ssh host "cd … && …"` one-liners — step = comment header + command lines up to the next blank line, a `@delta:` directive governs the whole block; and the checklist is now **display-only** — `NEXT.sh` is no longer written at all (throwaway artifact; `PENDING.json` + the live runbook regenerate it in any session) and every hand-back **ends the turn with the full checklist as the final text, no tool call after it** (a checklist printed above a blocking question tool was observed never reaching the user). Template `templates/deploy/PROCEDURE.md` restyled to match.
|
||
- `settings.json`: `inputNeededNotifEnabled: true` adopted (harness notification toggle); committed layout otherwise unchanged.
|
||
- gsd-pi upgraded 2.64.0 → 3.0.0 — `status-reporter` output parser adapted to the ADR-013 cutover.
|
||
- `hotfixer` pinned `model: sonnet` (seo/geo/web-validate L1 applier); `analyzer` haiku pin removed (inherits the session model).
|
||
- ship-feature / init-project: SDD implementation + review subagents dispatched with `model: "sonnet"`.
|
||
- web-validate `--fix`: bundle applied via `hotfixer` at L1 instead of inline Edit (BDR-061 alignment).
|
||
- Model routing wave 2 — the pure-execution + reflection-split skills stop running execution on the big session model. `/doc` and `/status` now **dispatch** their agent (doc-syncer sonnet, status-reporter haiku) instead of inline-loading it, so the pin takes effect. `/hotfix` split like `/feat`: reflection (LOCATE root cause) inline behind the model gate, the fix applied by a `hotfixer` sonnet executor (rewritten dual-use — it is also the seo/geo/web-validate L1 applier); revert-not-loop preserved; hotfix joins the gated group (13th). `/commit-change` dispatches a sonnet `commit-changer` (propose → dispatcher-owned approval gates → apply; grouping runs on sonnet, `AskUserQuestion` removed from the agent). `/release-candidate` dispatches a new sonnet `release-executor` for the mechanical spans (prep / finish+tag), the two human gates (when-to-release, push) and the version-number decision staying in the dispatcher.
|
||
- Model routing wave 3 — the last two inline execution-carrying skills split like `/feat`. `/bugfix`: root-cause investigation, diagnosis and contract run inline behind the model gate; the fix + regression test are applied by a `bugfixer` sonnet executor (was a single inline agent), with the verify+secure loop staying in the main loop and the executor as its re-dispatched dev. `/code-clean`: the dead-code / style / structural audit and the approval gate run inline; a `code-cleaner` sonnet PHASE-2 executor then applies the approved scope — and the style/structural refactor (which inline-loads `refactorer`) now finally runs on sonnet, its pin having been inert under the old inline-load. Both skills stay gated (they keep reflection); their read-only-audit consumers (`onboard`, `tour`) reroute to a big-model agent so an audit never runs on the sonnet executor. Supersedes the BDR-050 "bugfix stays inline" carve-out. The built-in `Explore` search agent is deliberately left inheriting the session (search feeds reflection).
|
||
- Model routing wave 4 — client-handover doc-generation moved to sonnet (redaction-only). The ship-and-handover pipeline (baseline audits, fix loops, commit/push, deploy pause, live validate, gate) stays inline on the big session model in `client-handover-writer` — its interactive gates work natively and its nested `/seo`/`/harden`/`/web-validate` audits inherit the big model — and only the deliverable writing is delegated to a new sonnet `handover-doc-writer` (gate-free: reads memory + git, synthesizes the 6-chapter doc from a resolved PACKAGE, runs the word-count / skill-leak / anchor gates, renders branded HTML+PDF). `client-handover` joins the gated group (it orchestrates audits = reflection). Chosen over the whole-writer dispatch: the nested audits must run big either way, so whole-writer would have added ~7 gate-yields + a resumable state machine on a client deliverable for ~zero extra sonnet work.
|
||
|
||
### Security
|
||
- **Magic MCP fully ask-gated** — all four `mcp__magic__*` tools (builder, refiner, inspiration, logo_search) moved to `permissions.ask` in `settings.json`; no magic call can auto-execute. The builder opens an unauthenticated local callback server (`127.0.0.1:9221+`, `Access-Control-Allow-Origin: *`, no token check) whose POST body is injected verbatim into the tool result the model consumes — the ask-gate is the mitigation on our side (BDR-059).
|
||
- **`MAGIC_API_KEY` passed by reference, not by value** — the MCP server is registered with `--env 'API_KEY=${MAGIC_API_KEY}'` (Claude Code expands it at launch from its own process env) instead of the literal secret, which `claude mcp add` would otherwise materialize in plaintext in `~/.claude.json`, outside the repo's `.env` allowlist reach (BDR-026).
|
||
- **`printenv` / `env` dumps redacted in `rtk-rewrite.sh`** — closes a leak vector where a rewritten environment dump could surface a Gitea token.
|
||
- **gitleaks secret-scanning backstop** — `.gitleaks.toml`, a pre-commit hook, and `make scan-secrets` added to catch secrets before they land; pre-existing stale secret-bearing artifacts purged (GO-gated).
|
||
|
||
### Added
|
||
- **GSC + CrUX data layer for `/seo` FULL** — `lib/seo-data/` engine pulls real Google Search Console (Search Analytics + URL Inspection) and Chrome UX Report field data into the `/seo` FULL audit: CrUX p75 field metrics become the primary Core Web Vitals signal (anonymous PageSpeed lab stays the fallback), and a "Performance GSC (90 j)" section flags position 4-10 quick wins. Multi-account via OAuth2 (`make seo-connect`, one-time consent, `webmasters.readonly` scope only) with a per-label token store (0600 file / 0700 dir, atomic write, refresh tokens redacted, gitleaks-allowlisted) so two concurrent site audits never conflict. Absent credentials degrade gracefully to anonymous PageSpeed — the audit never fails. Config: `GOOGLE_OAUTH_CLIENT_ID` / `GOOGLE_OAUTH_CLIENT_SECRET` / `CRUX_API_KEY` in `~/.claude/.env`. Engine contract documented in `lib/seo-data/README.md`.
|
||
- **impeccable** (pbakaus, Apache-2.0) wired into the toolchain as the design counterpart of semgrep: the `/impeccable` skill (23 verbs under one command: audit, polish, bolder, quieter…) plus the 45-rule deterministic anti-pattern detector (`npx impeccable detect`, exit 0/2, `--json`). Complementary to `frontend-design` (kept — aesthetic direction at build time); impeccable adds the deterministic audit floor and per-project design context (`/impeccable init`). CLI pinned in `plugins.lock.json` (3.2.0 — a silent rules update would change audit output on unchanged code); dist is machine-owned under `skills-external/impeccable/` (gitignored, ctx7 pattern), staged-installed by `install-plugins.sh` Step 8d, refreshed pin-honored by `update-all.sh`, symlinked by `link.sh`, listed in the design/web/web-full/full profiles and the design-work routing. Requires Node ≥ 24: the install baseline is bumped from 22 to 24 LTS (NodeSource `setup_24.x` / brew `node@24`), so `make plugin` upgrades a too-old host in place; the impeccable steps still skip gracefully if Node stays below 24. Not in the design gate's GATE-BLOCK list yet — promotion deliberate, after first dogfood.
|
||
- `/tour` skill — grouped all-axes sweep over one or several projects: security (pinned-semgrep `security-auditor` agent + `/cso` posture when gstack is ON) → cleanup → re-verify → reconcile (report-only, never edits the target TODO/registries) → doc sync, looping until a full pass applies zero fixes (bounded at 3 iterations). Fixes land on a `chore/tour-<date>` branch the skill never merges; each project gets an append-only `.claude/audits/TOUR.md` report with BREAKING tags on contract-changing security fixes. Built TDD (superpowers:writing-skills): baseline run showed silent TODO rewrites, autonomous registry writes, grep-as-security-pass, no persistent report, scope creep and an unbounded loop — each countered and verified on a seeded fixture.
|
||
- Model routing (BDR-066): blocking model gate (`lib/model-gate.md` + `lib/model-check.sh`, flip-tested) wired into 12 reflection orchestrators; census guard `lib/tests/model-routing.test.sh`.
|
||
- `/feat` re-architected: reflection inline (scope/plan/contract), execution dispatched to the sonnet-pinned `feater` executor; verify+secure loop decided in the main loop with fresh executor re-dispatches.
|
||
|
||
### Removed
|
||
- `lib/detect-plugins.sh`: `detect_security_guidance` — dead since its re-add at `45c3507`; zero callers on any surface, including the dynamic `session-start.sh` detection loop (the banner's row derives from `enabledPlugins` instead). Nothing invokes it — removal, not a breaking change.
|
||
- `lib/detect-plugins.sh`: `plugin_enabled` — its last two callers were replaced by the inline `enabledPlugins` grep at `session-start.sh:145-146` (`6d72d0a`); zero callers remained. Nothing invokes it — removal, not a breaking change.
|
||
- `templates/settings/settings.local.json` — orphan template, zero automated consumer since creation (`a145e3c`); its README tree-line reference was already dropped at `e48c834`. Content recoverable from git history.
|
||
- `lib/memory-commit.sh` / `lib/doc-commit.sh`: the `pending` CLI verb + sourceable `memory_pending()` / `docs_pending()` helpers — earmarked "for the v2 hook", which BDR-037 rejected (no code ever written); zero production or test callers. `commit "<message>" [<file>...]` is now the only verb on both scripts.
|
||
|
||
### Fixed
|
||
- `gitflow_finish` ignored its `<type> <name>` arguments and always merged the checked-out branch — naming a different branch silently merged the wrong one. The arguments are now an optional safety assertion: if given and not equal to the current branch, `finish` refuses with a clear error instead of merging. No-argument calls (the only real caller) are unchanged.
|
||
- `doctor.sh` false-warnings removed (a check that cries wolf is one you learn to ignore): `cargo` absence no longer claims "RTK unavailable" (RTK ships as a prebuilt binary); `check_symlink` no longer flags files reached through directory-level symlinks (e.g. `hooks/session-start.sh`); the GStack check counts the per-skill symlinks instead of a `skills/gstack` link that `link.sh` deliberately removes; the token-budget estimate is measured against the ~200k context window instead of a mis-framed "~11k session budget" that produced a false "92% CRITICAL".
|
||
|
||
### Removed
|
||
- **find-skills** (alchaincyf) — skill-discovery helper dropped from the toolchain (install/update/link/toggle/advisor). Never used, and its `make update` refresh step had started failing on clone timeouts. The discovery use case stays reachable manually: `npx -y skills find <query>`.
|
||
|
||
---
|
||
|
||
## Pre-release (internal history)
|
||
|
||
The versions below (4.0.0 down to the original 1.0.0) were internal
|
||
development milestones predating the first public release. They are kept
|
||
for provenance; the full detail lives in git history. Their numbering does
|
||
not continue past the public 1.0.0 above.
|
||
|
||
## [4.0.0] — 2026-06-30
|
||
|
||
### Added
|
||
- **Gitflow universal model** — `/gitflow` + `lib/gitflow.sh`: branch model (`main` / `develop` / `feature` / `bugfix` / `release` / `hotfix`) with directed `--no-ff` merges + hotfix fan-out (main + develop + open `release/*`); `start` / `finish` / `init` verbs. `lib/gitflow-migrate.sh` onboards an existing repo (`master`→`main`, seed `develop`, install the pre-commit hook, set Gitea Option-1 owner-pushable protection on `main`+`develop`), applied to all 6 repos. Wired into `/init-project` (STEP 5f `gitflow init` owns the scaffold root commit) + `/onboard` (STEP 2.6). See **BREAKING** under Changed
|
||
- `/deploy` — per-project deploy runbook in `.claude/deploy/` (`PROCEDURE.md` / `INCIDENTS.md` ledger / `STATE.json` oracle / `PENDING.json` cold-resume bridge / `NEXT.sh`); two-moment spine (instantiate checklist → out-of-band deploy → MARK success or LEARN from failure, patching the runbook in place); surgical `lib/deploy-commit.sh`; plus `/setup-deploy`
|
||
- Analyze-before-plan invariant — dev flows (`feat` / `bugfix` / `hotfix`, `ship-feature`) READ related memory before planning (ship-feature also reads related code) and must NAME each surfaced ID in the plan; shared `lib/analyze-before-plan.md` (read-before bookend of coupled-capitalize)
|
||
- Animation-library auto-detection/install — `motion` (`motion-v` for Vue 3 / Nuxt) auto-installed in `/init-project` (STEP 5e), opt-in in `/onboard` (STEP 2.5) on eligible stacks; `plugin-advisor` detects + reports only; logic in `lib/animation-lib-check.sh`
|
||
- Design-toolchain gate — `lib/design-tool-gate.sh` + `lib/design-gate.md` + a `design-toolchain-reminder` hook enforce the full design toolchain on UI work (profile-based), with a suggest-only non-blocking anim-lib note when a motion signal hits an eligible stack
|
||
- `lib/toggle-external.sh` — enable/disable non-marketplace tools; gstack now OFF by default (opt-in, activated on-demand per profile), Magic MCP (21st-dev) installed disabled by default
|
||
- Secrets single source-of-truth — real secret in `~/.claude/.env` reached via a repo `.env` symlink + `.env.example` placeholder; `MAGIC_API_KEY` resolved from it
|
||
- `/reconcile` — declared-vs-real reconciler: confronts TODO checkboxes + registry statuses (never the `## Index`) against real git/fs and surfaces the gaps in four categories + contradiction candidates, with a gated TODO write-back. Engine `lib/reconcile.sh` (body enumeration, git/fs oracles, last-block-wins status); thin skill
|
||
- `/release-candidate` — orchestrator over the gitflow release mechanic that adds the version tag the lib doesn't: finalize `version.txt` + CHANGELOG, fan-out `develop`→`main` + back, tag `vX.Y.Z`, push (gated). Lib stays the generic mechanic; the skill owns the tag
|
||
- Coupled-capitalize: dev flows (feat / hotfix / bugfix / commit-change, ship-feature, init-project) auto-commit their memory in the same breath, via shared `lib/capitalize-commit.md` + `lib/memory-commit.sh` (surgical — `.claude/memory` + `.claude/tasks` only, never `git add -A`)
|
||
- Coupled doc-sync: dev flows (feat / bugfix / hotfix, ship-feature, init-project) auto-commit the public docs `doc-syncer` patches, via shared `lib/doc-commit.md` + `lib/doc-commit.sh` (surgical — only the patched files, never `git add -A`, never `.claude/` / `CLAUDE.md`; refuses an out-of-scope path loudly with exit 4). `doc-syncer` surfaces `PATCHED_FILES` (one path per line) as the handoff
|
||
- `lib/doc-shape.sh` — deterministic MINOR-shape oracle for `doc-syncer` AUTO MODE: re-checks each LLM-classified MINOR patch (added-heading / size / new-file / non-doc envelope, thresholds env-overridable) and escalates a shape-suspect patch to the existing SIGNIFICANT gate instead of silently auto-committing it. A structural floor under the LLM's classification, not a blocking gate (genuine MINOR still auto-commits, zero friction); catches structural/size significance, not semantic
|
||
- `/audit-delta` — recurring multi-axis audit (norms / bugs / dead code / security) scoped to changes since last run, with per-axis SHA markers
|
||
- `/capitalize` — flush uncapitalized context to the memory registries before `/clear` or `/compact`
|
||
- `/prune-memory` — curate and compress the `.claude/memory/` registries
|
||
- `/close` — end-of-session memory ritual (decisions / learnings / blockers)
|
||
- `/pdf-translate` — translate a PDF to another language, output as HTML (via Vision)
|
||
- `/harden` — web hardening audit (SSL/TLS, HSTS, CSP, headers)
|
||
- `/web-validate` — W3C HTML/CSS validity + WCAG accessibility audit
|
||
- `/client-handover` — final ship + branded client deliverable (Markdown / HTML / PDF)
|
||
- `/profile` — partition skills by usage profile (design / dev / qa / audit / minimal / full)
|
||
- `frontend-design` and `design-motion-principles` skills (external marketplaces)
|
||
- Project archetype library + detection for `/onboard`
|
||
- `.claude/{tasks,memory,audits}/` governance layout + 5 memory registries (decisions, learnings, blockers, journal, evals)
|
||
|
||
### Changed
|
||
- **BREAKING (gitflow):** never commit code directly on `main` / `develop` — branch first (`gitflow start <type> <name>`) and integrate via `gitflow finish`. A generated per-repo pre-commit hook BLOCKS direct code commits on `main` / `develop` (exempts `.claude/**`, merges, the root commit). Existing repos must run `lib/gitflow-migrate.sh`. This workflow rupture is what takes the project from 3.x to 4.0.0
|
||
- `settings.json`: `git push` / `git tag` moved to the **ask** permission tier — a tool-call backstop for the "finish / release only on an explicit human signal" rule
|
||
- `install.sh` / `install-plugins.sh` made self-sufficient — nvm-installs Node/npm when missing, installs the `jq` prerequisite, runs `npx skills add` from `$HOME`; auto-reverts hand-curated config (`CLAUDE.md` + `settings.json` + `.claude/settings.json`) after install via an EXIT trap (install-immutable guard); auto-fixes the gstack browser on an OS newer than the pinned Playwright supports (Ubuntu 26.04)
|
||
- graphify upgraded to 0.8.x (skill pinned 0.8.45) — Gemini backend, monorepo support, CLI export, encoding fixes; CLAUDE.md + the pre-tool hook now prefer `graphify query` over `GRAPH_REPORT.md`
|
||
- `/seo` + `/geo`: CMS-plugin-first + shared-file edit discipline; Bing / IndexNow submission now mandatory
|
||
- `/ship-feature`: capitalize + memory commit moved before FINISH (was after) — fixes memory committed after a push/PR and stranded outside it
|
||
- `/init-project`: new STEP 10b captures founding architecture decisions as BDRs before FINISH
|
||
- `/ship-feature` + `/init-project`: DOC SYNC moved before FINISH (was after) — fixes public docs patched then left uncommitted and stranded outside the push/PR (ship-feature STEP 9→8, init-project STEP 12→10c; GSD 13→12)
|
||
- `/seo` split into parallel `seo` + `geo` agents with shared resources
|
||
- `/onboard` rewritten: archetype-aware pipeline (orchestrator + config-only agent), security audit archetype-aware
|
||
- `doc-syncer`: stack-aware audit + deploy-doc gating; later scoped to public docs only, `.claude/` read-only; sync-only ROADMAP handling — planned→shipped reconciliation from code/git, never from `.claude/`; numeric incoherence → HUMAN question
|
||
- `CLAUDE.md`: major refactor (contradiction purge, restructure), subagent-delegation rule, design-toolchain mandate, memory-registry governance
|
||
- Memory registries: enforced English + caveman format
|
||
- `settings.json`: `permissions.defaultMode` → `auto` (classifier-gated autonomy; `disableAutoMode` dropped) + `remoteControlAtStartup` + `skipAutoPermissionPrompt` + `effortLevel: xhigh`; model pin removed
|
||
|
||
### Removed
|
||
- `/init-project`: STEP 12 (speculative GSD v2 auto-bootstrap at project creation) removed — it ran `gsd init` AFTER FINISH, creating `ROADMAP.md` + `.gsd/` stranded outside the merge/PR (BLK-011), to bootstrap a multi-session engine that is opt-in and rarely used. Resolved by removal, not by plumbing a commit: GSD stays initializable on-demand (`/onboard add gsd`, or `gsd init` in a terminal), `/status` still reads `.gsd/`, and plugin-advisor still recommends it for multi-session work. init-project is now an 11-step pipeline
|
||
- `disable-model-invocation` frontmatter removed repo-wide (aligns skills with CLAUDE.md routing)
|
||
- Caveman plugin always-on integration purged — plugin disabled + uninstalled; SessionStart/UserPromptSubmit hooks, standalone hook files, `install-plugins.sh` STEP 5.5, `update-all.sh` refresh step, `plugins.lock.json` entry, `doctor.sh` checks, and docs removed. On a subscription plan its ~75% output-token compression has no cost benefit, and the always-on hooks added friction on validation gates + client deliverables. The unrelated memory-registry terse-format convention is kept.
|
||
- Installer-managed skills de-vendored — `frontend-design` un-tracked + npx-skills artifacts gitignored (re-synced from the plugin cache each run); obsolete `claude --effort max` shell alias removed (`settings.json` `effortLevel` is the source of truth)
|
||
|
||
### Fixed
|
||
- `lib/doc-commit.sh` no longer masks a rejected `git commit` as success: a pre-commit hook / protected branch / signing failure now fails loud with exit 5 and empty stdout (was: false "committed" + the previous HEAD's hash + exit 0, leaving docs silently uncommitted on a dirty tree)
|
||
- Numerous skill/agent fixes across darwin optimization rounds (geo-analyzer, onboard, init-project, analyzer, plugin-check, prune-memory, …)
|
||
|
||
## [3.4.0] — 2026-04-15
|
||
|
||
### Added
|
||
- **9 new skills**: `/bugfix`, `/code-clean`, `/commit-change`, `/doc`, `/feat`, `/graphify`, `/hotfix`, `/seo`, `/skills-perso`
|
||
- **7 new agents**: `bugfixer.md`, `code-cleaner.md`, `commit-changer.md`, `doc-syncer.md`, `feater.md`, `hotfixer.md`, `seo-analyzer.md`
|
||
- `install.sh`: bootstrap script — installs Claude Code CLI, authenticates, sets up shell env vars, then runs link.sh + install-plugins.sh
|
||
- `hooks/statusline.sh`: Claude Code status line configuration hook
|
||
- `hooks/rtk-rewrite.sh`: RTK hook for code rewrites
|
||
- `plugins.lock.json`: ctx7, graphifyy, and emil-design-eng entries added
|
||
- `skills-perso`: lists personal (user-created) skills from `~/.claude/skills/`
|
||
- `.graphifyignore`: excludes gstack submodule and install logs from graphify indexing
|
||
|
||
### Changed
|
||
- `Makefile`: `install` target now runs `install.sh` (bootstrap); new `plugin` target runs `install-plugins.sh` only
|
||
- `update-all.sh`: now also updates Claude CLI, ctx7, graphifyy, and marketplace plugins
|
||
- `install-plugins.sh`: added emil-design-eng skill download step; fixed skill-creator install to use `anthropics/skills` marketplace
|
||
- `skills/`: logic extracted from inline SKILL.md into standalone agent `.md` files — skills now delegate to agents
|
||
- `skills/commit-change/`: renamed from `git-smart-commit`; confirmation step removed
|
||
- `settings.json`: keys reordered for readability
|
||
- `CLAUDE.md`: added architecture decisions (no SPA for public sites, versioned APIs, security defaults), communication mode (radical honesty), graphify context navigation guidelines
|
||
- `README.md`: file tree, skill table, install section, plugins.lock section, Makefile targets, update-all description all updated for new skills/agents
|
||
- `USAGE.md`: command table expanded (9 → 18), decision tree restructured with lightweight skill routing
|
||
- `version.txt`: 3.3.0 → 3.4.0
|
||
|
||
### Removed
|
||
- `agents/readme-updater.md`: replaced by `agents/doc-syncer.md` (broader scope — all docs, not just README)
|
||
- `skills/readme/`: replaced by `skills/doc/`
|
||
|
||
### Fixed
|
||
- `skills-perso`: YAML description parsing handles both inline and block formats; detects personal skills via agent reference; excludes framework/gstack skills from listing
|
||
- `install-plugins.sh`: skill-creator install corrected to use `anthropics/skills` marketplace
|
||
- GStack skill symlinks untracked from git — auto-created by `install-plugins.sh`
|
||
|
||
## [3.3.0] — 2026-04-08
|
||
|
||
### Fixed
|
||
- `install-plugins.sh`: marketplace org was `anthropic` (missing 's') — corrected to `anthropics`
|
||
- `install-plugins.sh`: plugins `security-guidance`, `frontend-design`, `pr-review-toolkit` were installed from non-existent marketplace `claude-plugins-official` — corrected to `claude-code-plugins` (from `anthropics/claude-code` repo)
|
||
- `install-plugins.sh`: `skill-creator` plugin does not exist — replaced with `plugin-dev@claude-code-plugins` (correct plugin name)
|
||
|
||
### Changed
|
||
- `install-plugins.sh`: adds `anthropics/claude-code` marketplace before installing bundled plugins; install summary updated with correct marketplace sources
|
||
- `lib/detect-plugins.sh`: added `detect_security_guidance()`, `detect_plugin_dev()` functions; removed reference to non-existent `detect_skill_creator`
|
||
- `hooks/session-start.sh`: added `plugin_dev` to toggle loop and token cost estimate
|
||
- `agents/plugin-advisor.md`: all references to `skill-creator` → `plugin-dev`; signal `skill-creation` now recommends `plugin-dev ON`
|
||
- `README.md`: plugin table updated with correct marketplace sources per plugin; new "Marketplaces" subsection documenting all 4 marketplace sources and manual install commands; `/plugin-dev:create-plugin` replaces `/skill-creator`
|
||
- `USAGE.md`: all references to `skill-creator` → `plugin-dev`
|
||
- `version.txt`: 3.2.1 → 3.3.0
|
||
|
||
## [3.2.1] — 2026-04-07
|
||
|
||
### Fixed
|
||
- `agents/plugin-advisor.md`: 4 signals had entries in the signal table but no conditional rule — added rules for `skill-creation`, `browser-qa`, `design-system`, and `complex-arch`
|
||
|
||
### Changed
|
||
- `version.txt`: 3.2.0 → 3.2.1
|
||
|
||
## [3.2.0] — 2026-04-07
|
||
|
||
### Fixed
|
||
- `doctor.sh`: EXPECTED_SKILLS pass message uses `${#EXPECTED_SKILLS[@]}` (dynamic count) instead of hardcoded 9
|
||
- `agents/plugin-advisor.md`: `setup.py` and `pyproject.toml` added as counterindicators for embedded signal — prevents Python C-extensions from false-triggering embedded
|
||
- `agents/status-reporter.md`: PHP phpunit added to manifest fallback (`composer.json` → `./vendor/bin/phpunit`)
|
||
- `skills/health/SKILL.md`: post-result guidance added — CRITICAL/WARNING/errors/warnings/all-pass handling
|
||
|
||
### Added
|
||
- `USAGE.md`: "Erreurs fréquentes" — embedded signal not detected entry
|
||
|
||
### Changed
|
||
- `version.txt`: 3.1.0 → 3.2.0
|
||
|
||
## [3.1.0] — 2026-04-07
|
||
|
||
### Fixed
|
||
- `agents/plugin-advisor.md`: `Makefile` restored as embedded indicator — `Makefile` + `src/*.c` + no Node/Rust/Go manifest = embedded; `.c` files alone still not sufficient (Rust FFI counterindicated)
|
||
- `agents/onboarder.md`: PHASE 6 — check `command -v gsd` before generating ROADMAP.md; if absent, ROADMAP.md still generated with install instructions; same pattern as init-project STEP 13
|
||
|
||
### Added
|
||
- `doctor.sh`: expected skills check — verifies all 9 skills (analyze, health, init-project, onboard, plugin-check, readme, refactor, ship-feature, status) present in `~/.claude/skills/`
|
||
- `skills/analyze/SKILL.md`: description updated to mention DEBUG mode (read-only analysis OR error/stack trace → DEBUG mode)
|
||
- `USAGE.md`: token cost estimates on workflow patterns (Pattern A ~3000-5000t, B ~1500-2500t/session, D ~500-800t, E ~600-900t); budget note at top of Patterns section
|
||
|
||
### Changed
|
||
- `version.txt`: 3.0.0 → 3.1.0
|
||
|
||
## [3.0.0] — 2026-04-07
|
||
|
||
### Fixed
|
||
- `agents/plugin-advisor.md`: embedded false positive removed — `src/*.c` alone no longer triggers embedded signal (Rust FFI projects have .c files); only `platformio.ini` or `*.ld`/`*.lds` linker scripts are reliable triggers
|
||
- `agents/status-reporter.md`: flat awk scoped to `## Milestone` headings — no longer matches `## Prerequisites`, `## Notes`, or other non-milestone `##` headings in ROADMAP.md
|
||
|
||
### Added
|
||
- `agents/status-reporter.md`: Go test runner in manifest fallback (`go.mod` → "go test ./...")
|
||
- `USAGE.md`: GSD v2 active/interrupted node in decision tree — /gsd auto, /gsd steer, /gsd forensics
|
||
- `skills/analyze/SKILL.md`: argument-hint updated to mention DEBUG mode (pass error/stack trace)
|
||
|
||
### Breaking
|
||
- `agents/plugin-advisor.md`: embedded detection no longer triggers on C/C++ files alone — projects relying on .c file detection must add `platformio.ini` or a `*.ld` linker script
|
||
|
||
### Changed
|
||
- `version.txt`: 2.9.0 → 3.0.0
|
||
|
||
## [2.9.0] — 2026-04-07
|
||
|
||
### Fixed
|
||
- `agents/plugin-advisor.md`: PHASE 1 — filesystem embedded detection added (platformio.ini, *.ld linker scripts, src/*.c without package.json/Dockerfile); signal description updated
|
||
- `agents/status-reporter.md`: PHASE 3 — flat ROADMAP fallback awk command for milestones with tasks directly under ## (no ### slices); marked with "(flat)" in output
|
||
- `agents/status-reporter.md`: pytest cache parsing — JSON `{}` = "all passing" instead of "0 failing"; uses python3 for proper JSON parse instead of `cat | head`
|
||
|
||
### Added
|
||
- `USAGE.md`: analyze → refactor → analyze cycle documented in decision tree (refactoring profond)
|
||
- `README.md`: link to USAGE.md in intro section
|
||
|
||
### Changed
|
||
- `version.txt`: 2.8.0 → 2.9.0
|
||
|
||
## [2.8.0] — 2026-04-07
|
||
|
||
### Fixed
|
||
- `agents/status-reporter.md`: awk milestone detection uses `index()` instead of regex negation — portable across macOS nawk and GNU awk
|
||
- `agents/status-reporter.md`: Tests field fallback improved — shows "run '<cmd>' to check" when no result found but test manifest exists; shows "N/A" only when no test infrastructure at all
|
||
|
||
### Added
|
||
- `agents/plugin-advisor.md`: `embedded` signal added — firmware/bare-metal/microcontroller detection; DECISION TABLE row; conditional rule disabling all toggles, superpowers optional
|
||
- `doctor.sh`: agents pass message now lists all 8 agent names inline for quick visual confirmation
|
||
- `USAGE.md`: section "Quel skill utiliser ?" — decision tree for all 9 skills with quick-reference table
|
||
- `README.md`: `/status` added to Maintenance Diagnostic section alongside `/health`
|
||
|
||
### Changed
|
||
- `version.txt`: 2.7.0 → 2.8.0
|
||
|
||
## [2.7.0] — 2026-04-07
|
||
|
||
### Fixed
|
||
- `agents/status-reporter.md`: milestone detection algorithm — uses `awk` to find first `##` heading with pending `###` slices (top-to-bottom scan), not `tail -5` of all `##` headings
|
||
- `skills/ship-feature/SKILL.md`: `git log` now uses `--format="%h %<(50,trunc)%s"` to truncate long commit messages at 50 chars
|
||
|
||
### Added
|
||
- `agents/status-reporter.md`: PHASE 2 — best-effort build/test status check (pytest cache, Jest coverage, log files); `Tests` field in output
|
||
- `doctor.sh`: `check_symlink "lib"` added; `_EXPECTED_LINKS` updated 6 → 7
|
||
- `agents/plugin-advisor.md`: `skill-creation` signal added to PHASE 2; WARN rule if skill-creator active without skill-creation signal
|
||
- `USAGE.md`: Exemple 9 — firmware C/C++ STM32, workflow minimaliste sans superpowers ni GSD
|
||
|
||
### Changed
|
||
- `version.txt`: 2.6.0 → 2.7.0
|
||
|
||
## [2.6.0] — 2026-04-07
|
||
|
||
### Fixed
|
||
- `agents/status-reporter.md`: PHASE 3 now counts slices (### headings) not tasks (- [ ]) — correct progress metric matching GSD v2 dashboard
|
||
- `hooks/session-start.sh`: continuation line uses 13-space prefix (verified 60 bytes) for consistent box alignment
|
||
- `agents/onboarder.md`: PHASE 5b clarifies .gitignore target path per mode (A=workspace root, B=PACKAGE_ROOT, C=per-package)
|
||
|
||
### Added
|
||
- `skills/ship-feature/SKILL.md`: STEP 0b now prints PROJECT CONTEXT header when CLAUDE.md found — project name, stack, current branch, last 3 commits, GSD milestone
|
||
- `USAGE.md`: Exemple 8 — full session resume workflow with /status + GSD v2 step mode + /gsd discuss
|
||
|
||
### Changed
|
||
- `version.txt`: 2.5.0 → 2.6.0
|
||
|
||
## [2.5.0] — 2026-04-07
|
||
|
||
### Fixed
|
||
- `skills/init-project/SKILL.md`: STEP 1 — checks both `CLAUDE.md` and `.claude/CLAUDE.md`; pre-fills interview from either location
|
||
- `agents/status-reporter.md`: PHASE 3 GSD — replaced fragile `STATUS.md` read with robust ROADMAP.md checkbox parsing; handles missing ROADMAP.md; never reads binary `state.db`
|
||
- `agents/onboarder.md`: PHASE 5b added — .gitignore safety check; appends `.claude/settings.local.json` to existing .gitignore or creates minimal one; applies to all monorepo options
|
||
|
||
### Added
|
||
- `doctor.sh`: expected agents check in Consistency section — warns if any of 8 expected `.md` agent files are missing from `~/.claude/agents/`
|
||
- `README.md` + `USAGE.md`: `/status` added to Pattern B (multi-session) and Pattern C (onboarding) workflows
|
||
- `hooks/session-start.sh`: 2-line display for >4 active/inactive plugins — all plugin names shown, split at 4 per line
|
||
|
||
### Changed
|
||
- `version.txt`: 2.4.0 → 2.5.0
|
||
|
||
## [2.4.0] — 2026-04-07
|
||
|
||
### Fixed
|
||
- `skills/init-project/SKILL.md`: STEP 1 — reads existing CLAUDE.md if present; pre-fills interview answers already documented; asks only genuinely missing fields
|
||
- `agents/onboarder.md`: Option B fully implemented — explicit PACKAGE_ROOT scoping; all PHASE 3-5 paths relative to selected package; no root CLAUDE.md generated
|
||
- `agents/plugin-advisor.md`: upstream monorepo detection in PHASE 1 — checks `../turbo.json`, `../pnpm-workspace.yaml`, `../../turbo.json` for sub-package context; signal table updated to describe upstream detection
|
||
|
||
### Added
|
||
- `agents/status-reporter.md` + `skills/status/SKILL.md`: new `/status` skill — consolidated read-only snapshot (plugins + token cost + git state + recent commits + GSD v2 milestone)
|
||
- `USAGE.md`: section "Erreurs fréquentes" — quick-reference table of 14 common errors with causes and solutions
|
||
- `doctor.sh`: symlink counter — reports `N/6 OK` after symlink checks
|
||
- `hooks/session-start.sh`: `+N more` display — shows first 2 active/inactive plugins + count of remaining instead of truncated string
|
||
- `README.md`: /status added to skill table and file tree
|
||
|
||
### Changed
|
||
- `version.txt`: 2.3.0 → 2.4.0
|
||
|
||
## [2.3.0] — 2026-04-07
|
||
|
||
### Fixed
|
||
- `skills/ship-feature/SKILL.md`: STEP 0b added — checks for CLAUDE.md before starting; blocks with `/onboard` instruction if missing
|
||
- `skills/ship-feature/SKILL.md`: STEP 4b option B enhanced — scans remaining tasks for dependents before skipping a failed task; prompts to skip dependent tasks too
|
||
- `agents/onboarder.md`: Option C (sequential monorepo onboarding) fully implemented — iterates all packages, generates per-package CLAUDE.md + settings + .claudeignore, summary table, optional root ROADMAP.md
|
||
- `agents/plugin-advisor.md`: `monorepo` signal added to PHASE 1 detection (turbo.json, pnpm-workspace, nx.json), PHASE 2 signal table, DECISION TABLE, and conditional rules — recommends plugins per-package, not for the whole repo
|
||
- `doctor.sh`: `check_symlink "templates"` added — detects missing templates/ symlink (pre-v2.0.0 installations)
|
||
- `hooks/session-start.sh`: ACTIVE_STR and INACTIVE_STR truncated to 37 chars + `…` indicator when overflow detected
|
||
|
||
### Added
|
||
- `USAGE.md`: Exemple 7 — refactoring module Python legacy; full `/analyze` → `/refactor` → `/analyze` cycle; shows report-before-modify behavior and test-first recommendation
|
||
|
||
### Changed
|
||
- `version.txt`: 2.2.0 → 2.3.0
|
||
|
||
## [2.2.0] — 2026-04-07
|
||
|
||
### Fixed (bugs identified via case study simulation)
|
||
- `skills/init-project/SKILL.md`: STEP 13 — guard `command -v gsd` before running `gsd init`; prints install instructions if GSD v2 not in PATH instead of failing silently
|
||
- `skills/ship-feature/SKILL.md`: STEP 4b added — structured error recovery when a subagent fails (build error, failing test, type error); DEBUG mode analysis + user gate before any fix; max 2 retry attempts; never auto-patches
|
||
- `agents/onboarder.md`: monorepo detection added (PHASE 1) — detects `apps/`, `packages/`, `pnpm-workspace.yaml`, `turbo.json`, `nx.json`, `lerna.json`; interactive gate (onboard whole workspace / single package / each separately)
|
||
- `agents/plugin-advisor.md`: `mobile` signal added to PHASE 2 signal table + DECISION TABLE + conditional rules — React Native / Expo / Flutter explicitly handled; gstack disabled for mobile, Docker N/A
|
||
- `doctor.sh`: GStack `skills/` subdirectory check added after symlink verification — warns if GStack is symlinked but has no skills (needs `./setup`)
|
||
- `hooks/session-start.sh`: TOKEN_WARN truncated to 44 chars to prevent box overflow with emoji width
|
||
|
||
### Added
|
||
- `USAGE.md`: Exemple 6 — CLI Rust from scratch; illustrates minimal workflow (superpowers only, no frontend plugins, cargo check as verify, no GSD v2)
|
||
|
||
### Changed
|
||
- `version.txt`: 2.1.0 → 2.2.0
|
||
|
||
## [2.1.0] — 2026-04-07
|
||
|
||
### Added
|
||
- `agents/scaffolder.md`: React Native/Expo + Flutter support — PHASE 0 (Docker exclusion), PHASE 3 (stack templates), PHASE 4 (install commands), PHASE 5 (verify commands per stack)
|
||
- `agents/analyzer.md`: DEBUG MODE section — structured error diagnosis with root cause hypotheses, trace, and affected files
|
||
- `agents/onboarder.md`: new agent — onboard existing projects (discovery → interview → CLAUDE.md + settings + .claudeignore + optional GSD v2 ROADMAP)
|
||
- `skills/onboard/SKILL.md`: new skill `/onboard` invoking the onboarder agent
|
||
- `skills/init-project/SKILL.md`: STEP 13 (optional) — propose GSD v2 init at end of init-project when multi-session signal detected
|
||
- `Makefile`: `make onboard` target
|
||
- `README.md`: Workflow patterns section (5 patterns: new short, new long, onboarding, hotfix, refactor); /onboard in skill table and tree; make onboard in maintenance
|
||
|
||
### Fixed
|
||
- `agents/plugin-advisor.md`: "Next.js + context7 not configured" moved from BLOCK → WARN with force option — Context7 requires manual API key, should not hard-block project start
|
||
- `lib/detect-plugins.sh`: `detect_ruflo()` now uses 3-level fallback (npm binary → MCP config grep + ruvnet/claude-flow variants → `claude mcp list`)
|
||
- `hooks/session-start.sh`: passive token cost estimate added to session display — warns at >25%, alerts at >50% of Pro session budget
|
||
|
||
### Changed
|
||
- `version.txt`: 2.0.0 → 2.1.0
|
||
|
||
## [2.0.0] — 2026-04-06
|
||
|
||
### Breaking
|
||
- GSD v1 (`glittercowboy/get-shit-done-cc`) removed entirely
|
||
- GSD v1 commands (`/gsd:discuss-phase`, `/gsd:plan-phase`, `/gsd:execute-phase`, `/gsd:ship`, `/gsd:next`) no longer available — these were Claude Code slash commands; they do not exist in v2
|
||
- GSD v2 (`gsd-pi`) is a standalone CLI (Pi SDK), not a Claude Code plugin — usage model is entirely different
|
||
|
||
### Added
|
||
- **GSD v2 integration** (`gsd-build/gsd-2`, npm: `gsd-pi` 2.64.0) — standalone CLI with autonomous mode (`/gsd auto`), state machine per-task execution, crash recovery, cost tracking, parallel workers, worktree isolation
|
||
- **Ruflo plugin** (`ruvnet/ruflo`, npm: `ruflo` 3.5.58) — enterprise multi-agent MCP server (formerly claude-flow), 310+ tools, 100+ agent types, WASM kernel; 🔄 TOGGLE, ~500-1500t passive
|
||
- **Full plugin compatibility matrix** in `agents/plugin-advisor.md` — all 12 plugins analyzed pairwise, conditional rules, recommended sets by project type
|
||
- **Ruflo auto-detection** in `lib/detect-plugins.sh`, `doctor.sh`, `hooks/session-start.sh`
|
||
- **GSD v2 CLI status** in `session-start.sh` — dedicated `🖥️ CLI` line (separate from CC plugin toggles)
|
||
- **8 new deny rules** in `settings.json`: `source /dev/stdin`, `mkfifo *`, `python3 -c *`, `node -e *`, `xargs * .env*`, `tar * .env*`, `zip * .env*`, `base64 .env*` — covers runtime secret access and exfiltration vectors
|
||
- **`disableAutoMode: "disable"`** added to global `settings.json` # TODO: VERIFY syntax in CC v2.1.89
|
||
- **`templates/` symlink** in `link.sh` — `~/.claude/templates/` now resolves correctly for scaffolder and init-project
|
||
- **Token budget breakdown** in `doctor.sh` — CLAUDE.md + skill descriptions + plugin passive cost, thresholds vs Pro session budget (~11k tokens/5h)
|
||
- **GStack pinning warning** in `doctor.sh` and `update-all.sh` (confirmation prompt before `--remote` update)
|
||
- **GStack false-positive fix** in `doctor.sh` — submodule check now requires `.git` presence, not just directory existence
|
||
- Ruflo install instructions in `install-plugins.sh` (Step 5, manual — enterprise tool)
|
||
- Ruflo update step in `update-all.sh`
|
||
- GSD v2 update step in `update-all.sh`
|
||
|
||
### Changed
|
||
- `plugins.lock.json`: GSD v1 (`npm:get-shit-done-cc`) → GSD v2 (`npm:gsd-pi` 2.64.0); ruflo (`npm:ruflo` 3.5.58) added
|
||
- `install-plugins.sh`: STEP 4 GSD v2 (`npm install -g gsd-pi`), STEP 5 ruflo (manual instructions), steps renumbered 6-7
|
||
- `lib/detect-plugins.sh`: `detect_gsd()` now checks `command -v gsd` (not `~/.claude/skills/` grep); `detect_ruflo()` added
|
||
- `doctor.sh`: GSD v2 check, ruflo check, GStack false-positive fix, GStack pinning warning, EXPECTED_DENY 92→100, token budget Pro-aware with breakdown, `readlink -f` portability fix
|
||
- `hooks/session-start.sh`: GSD v2 removed from toggle loop → dedicated `🖥️ CLI` line; ruflo added to toggle loop
|
||
- `update-all.sh`: GStack confirmation prompt, GSD v2 update step, ruflo update step, steps renumbered 1-7
|
||
- `agents/plugin-advisor.md`: complete rewrite — PHASE 1 detection (GSD v2, ruflo), PHASE 2 signal table, full compatibility matrix, conditional rules, recommended sets by project type, WARN/BLOCK updated
|
||
- `link.sh`: `templates/` added to symlink loop
|
||
- `settings.json`: 92→100 deny rules, `disableAutoMode` added
|
||
- `README.md`: comprehensive update — GSD v2 full usage guide, ruflo install/usage, plugin compatibility matrix section, updated plugin table (GSD v2 as CLI, ruflo as TOGGLE), version pinning examples, troubleshooting entries for GSD v2 and ruflo, Known Limitations updated
|
||
- `version.txt`: 1.0.4 → 2.0.0
|
||
|
||
### Fixed
|
||
- `link.sh`: `templates/` not symlinked — scaffolder and init-project now find `~/.claude/templates/project-CLAUDE.md`
|
||
- `doctor.sh`: GStack submodule check was a false positive when directory existed but submodule was uninitialised
|
||
- `doctor.sh`: `readlink -f` fallback made explicit for BSD macOS compatibility
|
||
- `doctor.sh`: token budget used incorrect "~8000 tokens" reference — now uses Pro session budget (~11k)
|
||
- `doctor.sh`: EXPECTED_DENY hardcoded at 92 — updated to 100 after new deny rules
|
||
- `update-all.sh`: GStack update had no confirmation prompt — added; GStack step structure had mismatched `if/fi`
|
||
- `agents/plugin-advisor.md`: GSD detection used `ls ~/.claude/skills/ | grep gsd` — broken for v2 (CLI not a skill)
|
||
- `hooks/session-start.sh`: GSD v2 (standalone CLI) was in the CC plugin toggle loop — incorrect, moved to dedicated CLI line
|
||
|
||
## [1.0.4] — 2026-04-05
|
||
|
||
### Fixed
|
||
- `skills/*/SKILL.md`: agent paths changed from `.claude/agents/` to `$HOME/.claude/agents/` — unambiguous user-scope resolution regardless of working directory
|
||
- `hooks/session-start.sh`: `CONFIG_VERSION` now displayed in session-start box (was computed but never shown)
|
||
- `settings.json` + templates: removed non-standard `_readme` key (silently ignored by Claude Code but triggers schema warnings)
|
||
- `agents/plugin-advisor.md`: RTK detection re-added in PHASE 1 (was removed in v1.0.3 compression)
|
||
- `skills/health/SKILL.md`: fallback command simplified — removed 3-level quote nesting
|
||
- `install-plugins.sh`: removed duplicate "→ Restart Claude Code" line
|
||
|
||
### Changed
|
||
- README: Superpowers command table now shows actual skill names (`superpowers:brainstorming`, `superpowers:writing-plans`, `superpowers:subagent-driven-development`, etc.)
|
||
- README: install step 6 — replaced `/reload-plugins` (nonexistent command) with "Restart Claude Code — plugins load automatically"
|
||
- README: Context7 API key URL corrected from `context7.com` to `upstash.com`
|
||
- README: Known Limitations — clarified agent frontmatter fields ARE enforced in v2.1.x; added `disableAutoMode` note
|
||
- README: Makefile command list in Maintenance section now includes `make new-skill`
|
||
- `lib/detect-plugins.sh`: `detect_context7()` no longer spawns `claude` CLI — reads `~/.claude.json` and `~/.mcp.json` directly (no subprocess overhead at session start)
|
||
|
||
## [1.0.3] — 2026-04-05
|
||
|
||
### Token savings (~57% reduction across agents/skills)
|
||
- `CLAUDE.md`: 1414t → 418t (-70%) — rewritten as dense rule list, no prose padding
|
||
- `agents/plugin-advisor.md`: 1251t → 536t (-57%) — DECISION MATRIX removed (duplicated THRESHOLDS), output template compressed
|
||
- `agents/interviewer.md`: 1088t → 438t (-60%) — PROJECT BRIEF ASCII art → compact YAML-style, question groups flattened
|
||
- `agents/readme-updater.md`: 2224t → 792t (-64%) — Docker detection unified to one block, template skeleton condensed, phases as tight checklists
|
||
- `agents/scaffolder.md`: 2402t → 1041t (-57%) — Dockerfile/compose templates replaced by 3-line descriptions, Phase 0 compressed
|
||
- `skills/init-project/SKILL.md`: 2452t → 915t (-63%) — AGENTS LOADED section removed, each STEP condensed to 2-4 lines
|
||
- `skills/ship-feature/SKILL.md`: 1236t → 537t (-57%) — same treatment as init-project
|
||
|
||
### Changed behavior
|
||
- `agents/interviewer.md`: if prompt already contains name + purpose + stack + features + architecture → generate BRIEF directly, no questions asked
|
||
- `agents/readme-updater.md`: Docker detection defined once at top, referenced in all modes (no duplication)
|
||
- `hooks/session-start.sh`: always-on plugins (security-guidance, rtk, superpowers) now explicitly shown in session start display
|
||
- `skills/health/SKILL.md`: fallback path when `~/.claude/doctor.sh` not found (follows CLAUDE.md symlink to locate repo)
|
||
- `skills/plugin-check/SKILL.md`: argument-hint now shows concrete example
|
||
|
||
### Added
|
||
- `Makefile`: `make new-skill name=<n>` — scaffolds agent + skill files from template in one command
|
||
- `templates/project-CLAUDE.md`: inline examples per section (FastAPI-based) — usable without /init-project
|
||
- README: bundled skills section (`/batch`, `/debug`, `/simplify`)
|
||
- README: accurate progressive loading explanation (description only at startup, body on-demand)
|
||
- `link.sh`: idempotent — reports "already up to date" or count of updated symlinks
|
||
|
||
## [1.0.2] — 2026-04-04
|
||
|
||
### Security
|
||
- `Bash(git add .env*)` and `Bash(git add **/.env*)` added to deny — prevents staging secrets
|
||
- `Bash(cp **/id_rsa*)`, `Bash(cp **/id_ed25519*)`, `Bash(cp **/.ssh/*)` added to deny — closes SSH key copy bypass
|
||
- `deny` total: 87 → 92 rules
|
||
- `npx *` moved from allow to ask in project template settings — arbitrary npm package execution now requires confirmation
|
||
- `docker stop *` and `docker rm *` moved from allow to ask in project template settings
|
||
|
||
### Changed
|
||
- `skill-creator` and `pr-review-toolkit` reclassified from ALWAYS ON to TOGGLE — saves ~400 tokens/session by default
|
||
- `agents/scaffolder.md`: removed Go, PHP/WordPress, Flutter/Dart stack templates (unused)
|
||
- `CLAUDE.md`: STRICT MODE section removed — rules inlined into `skills/init-project/SKILL.md` and `skills/ship-feature/SKILL.md` where they apply, reducing global context weight
|
||
- `CLAUDE.md`: FAIL FAST MODE cleaned up (removed contradictory "override all" claim)
|
||
- `agents/readme-updater.md`: mode detection changed from substring match to exact first-word match — `/readme update X` no longer silently triggers SYNC mode
|
||
- `templates/settings/SETTINGS.md`: stripped sections duplicating README (precedence table, what-goes-where) — 132 → 58 lines
|
||
- `plugins.lock.json`: removed unused `install_cmd` and `node` fields
|
||
- README: GStack 14-command table collapsed to a single reference line
|
||
- README: plugin table updated to reflect new toggle status
|
||
|
||
### Fixed
|
||
- `install-plugins.sh`: GStack `./setup` now runs in subshell with existence+executable guard (same fix as update-all.sh)
|
||
- `install-plugins.sh`: log setup guarded against read-only filesystem — no longer crashes before output
|
||
- `install-plugins.sh`: `rtk init -g` now skipped if RTK hook already present in settings.json
|
||
- `doctor.sh`: CRLF detection ported from `grep -qP` (Linux-only) to `grep -c $'\r'` (portable macOS/Linux)
|
||
- `doctor.sh`: token budget breakdown now lists top consumers per file when estimate exceeds 2000 tokens
|
||
- `lib/detect-plugins.sh`: removed three never-called functions (`detect_security_guidance`, `detect_skill_creator`, `detect_pr_review_toolkit`)
|
||
- `hooks/session-start.sh`: removed unreachable inline fallback — replaced with clean exit message
|
||
|
||
## [1.0.1] — 2026-04-03
|
||
|
||
### Security
|
||
- `env` and `printenv *` moved from allow to deny — blocks secret exposure via process environment
|
||
- `export *` added to deny — prevents environment variable injection
|
||
- `cp .env*`, `cp **/.env*`, `mv .env*`, `mv **/.env*` added to deny — closes copy-then-read bypass on secret files
|
||
- `cp **/secrets/*`, `mv **/secrets/*` added to deny — extends secret move protection to secrets/ directory
|
||
- `sed *` moved from allow to ask — all sed (including in-place `-i`) now requires confirmation
|
||
- `sed -i *` and `sed -i'' *` removed from ask (consolidated into `sed *`)
|
||
|
||
### Changed
|
||
- `git stash*` (broad allow) split into safe variants in allow (`git stash`, `push*`, `list*`, `show*`) and destructive variants in ask (`pop*`, `drop*`, `clear`)
|
||
- `doctor.sh` token budget estimate now uses full skill/agent file sizes instead of description-only char count — produces accurate token estimates (~4 chars/token)
|
||
- `doctor.sh` deny rule count now checks against expected value (87) and warns on mismatch
|
||
- `doctor.sh` python3 one-liner wrapped in `|| echo "?"` — diagnosis no longer crashes on missing python3
|
||
|
||
### Fixed
|
||
- `update-all.sh` GStack `./setup` now runs in a subshell — upstream setup failure no longer crashes the update script mid-execution under `set -euo pipefail`
|
||
- `update-all.sh` guards `./setup` existence and executable bit before invoking it
|
||
|
||
## [1.0.0] — 2025-04-03
|
||
|
||
### Added
|
||
- 6 custom agents: analyzer, interviewer, plugin-advisor, readme-updater, refactorer, scaffolder
|
||
- 6 custom skills: analyze, init-project, plugin-check, readme, refactor, ship-feature
|
||
- 2 orchestrators with validation gates: init-project (13 steps), ship-feature (8 steps)
|
||
- Multi-OS install script (apt/dnf/pacman/brew)
|
||
- GStack as git submodule at skills-external/gstack
|
||
- Session start hook with plugin toggle status and health check
|
||
- Global settings.json with deny/ask/allow permission tiers
|
||
- Per-project templates: settings.json, settings.local.json, .claudeignore, project-CLAUDE.md
|
||
- Settings reference (SETTINGS.md)
|
||
- doctor.sh — full setup diagnostic
|
||
- update-all.sh — one-command update for all components
|
||
- plugins.lock.json — version pinning for non-marketplace dependencies
|
||
- /health skill — run doctor.sh from within Claude Code
|
||
- Makefile — unified entry point for install/link/doctor/update
|
||
|
||
### Security
|
||
- deny rules cover: destructive commands, secrets access, privilege escalation,
|
||
code injection (eval, bash -c, xargs), pipe-to-shell, and secrets via bash (cat .env)
|
||
- disableBypassPermissionsMode enforced globally
|
||
- .claudeignore template with comprehensive exclusions
|