graphify: `graphify claude install` (install-plugins.sh STEP graphify)
writes SKILL.md, references/ and .graphify_version straight into the repo,
because ~/.claude/skills is a symlink to skills/. Every `pipx upgrade
graphifyy` therefore dirtied the tree and cost a `chore(graphify): sync
vendored skill X -> Y` commit. Now gitignored and untracked; a fresh clone
gets them back from `make plugin`. test-prompts.json is hand-written for
darwin and stays tracked. The accepted trade-off, documented in CLAUDE.md,
is that an upstream release can change the skill's prompt with no diff to
review.
settings.local.json (gitignored, so not in this commit) went from 14.6 KB
to 6.2 KB. It was a near-complete shadow copy of the global settings at a
higher precedence tier, which hid its own drift until the global moved.
Two entries were actively defeating BDR-090, merged an hour earlier:
- local `deny` still carried rsync / kill -9 / killall / pkill, the four
rules deliberately moved out of global deny. deny wins across sources,
so autoMode.soft_deny was a dead letter in this repo.
- local `allow` carried `sed *`, `cp *` and `python3 -`. An allow rule
short-circuits the classifier, punching a hole through the same
soft_deny rules.
deny and ask are dropped whole (102 and 27 of their entries duplicated the
global; ask gates nothing under defaultMode auto). allow went 185 -> 98:
81 duplicates plus six policy conflicts, the three above and
Read(//home/bchanot/**), WebSearch, and a leftover command-injection test
payload that had been allowlisted verbatim. Every non-permissions key was
a verbatim copy of the global, including a hooks block whose only original
entry pointed at hooks/config-protection.sh, a script that exists nowhere.
3.1 KiB
claude-config — project instructions
Health Stack
- shell:
shellcheck *.sh hooks/*.sh lib/*.sh
rules/ maintenance
Modular instruction files loaded by Claude Code alongside the global memory.
rules/ is symlinked to ~/.claude/rules by link.sh (user scope, ALL
projects). One rule = one file = one concern.
A rule WITH paths: YAML frontmatter (glob list) loads lazily — only when
Claude reads a file matching a glob; a rule WITHOUT it loads at session
start, same cost as the global memory. Extract from CLAUDE.global.md only
what can be path-scoped (the token win) or what is generated; always-on
doctrine stays in CLAUDE.global.md. Exception: a standalone user-authored
rule set that would bust the 320-line density budget may live here WITHOUT
paths: (always-on load) — writing-style.md (BDR-085). paths: globs match against the
CURRENT project's tree — a broad glob (e.g. rules/**) can fire in foreign
projects; keep rule bodies tiny.
Docs: https://code.claude.com/docs/en/memory.md#path-specific-rules
Machine-owned: rules/context7.md is DELETED BY DESIGN (BDR-053,
2026-07-06) — ctx7 setup --claude --cli still writes it, but
install-plugins.sh STEP ctx7 purges it right after; the find-docs skill is
the single ctx7 surface. If it reappears (manual ctx7 setup), delete it
or re-run make plugin.
Machine-owned: the vendored graphify skill
skills/graphify/SKILL.md, skills/graphify/references/ and
.graphify_version are written by graphify claude install
(install-plugins.sh STEP graphify), which lands in the repo because
~/.claude/skills is a symlink to skills/. They are gitignored: a
pipx upgrade graphifyy used to dirty the tree and cost a
chore(graphify): sync vendored skill X -> Y commit each time. A fresh
clone gets them back from make plugin.
Trade-off accepted: an upstream release can now change the skill's prompt
with no diff to review. skills/graphify/test-prompts.json is hand-written
for darwin and stays tracked. To inspect what upstream changed, read the
files on disk or diff against a previous pipx version.
Transient planning artifacts
docs/superpowers/specs/** and docs/superpowers/plans/** are run-time
artifacts of a feature pipeline (subagent briefs, reviewer references).
They are committed DURING the run (the SDD worktree + reviewers read them
from disk — NOT gitignored), then AUTO-PURGED by gitflow finish on a
feature/bugfix branch, before the merge, so develop's tip stays clean
(BDR-065, lib/gitflow.sh _gitflow_purge_transient). The feature commits
stay reachable from develop, so git show <sha>:docs/… is still the archive.
Opt out with GITFLOW_PURGE_TRANSIENT=0. NOT in scope: .claude/tasks/{contracts,plans}
(durable, versioned, referenced by decisions.md). Durable knowledge goes to
.claude/memory/ registries, never to these files. Derived scan/audit
outputs (.audit/**) are gitignored and never committed, even redacted
(LRN-124).