forked from bchanot/claude
feat(skills): wire verify+secure into ship-feature/init-project; onboard no-loop + LRN-093 backstop (verify-loops lot 5)
ship-feature: STEP 0e CONTRACT (request verbatim) → ENRICHED at the STEP 3 validation gate (design criteria appended [gated <date>], the human micro-gate) → STEP 5 VERIFY+SECURE judges the branch against the ENRICHED contract via the shared include. Distinct axis from STEP 6 code review, both run (LRN-095). init-project: contract seeded from the PROJECT BRIEF (V1 features → criteria) → ENRICHED at VALIDATION GATE #1 → STEP 9 VERIFY+SECURE. Adds the security gate init-project previously lacked (was deferred to a later /onboard). onboard: explicit NO verify-loop — it produces an audit report, not a change to verify against a request; contract is scope-only, security-auditor runs MODE audit (report-only), never a gate. Documented to prevent a misplaced symmetry loop (BDR-050: dev pipeline != audit). lib/tests/no-vacuous-locks.test.sh: deterministic backstop for LRN-093 (2nd recurrence in this chantier → the advisory alone did not hold). Refuses a literal \n in any grep/tf/tr_/tn pattern across lib/tests/*.test.sh; flip-tested against a synthetic offender so the guard proves it bites. lib/tests/loops-heavy.test.sh: 18 structure locks green. Behavioral dogfood (both vigilance points, real): (1) enrichment — a fresh verifier reads and checks a [gated] design criterion (ECARTS naming it precisely); (2) escalation — 3 consecutive ECARTS on the same criterion → orchestrator STOPs at the max-3 bound + presents the CONTRACT-vs-REALIZED table, no 4th loop, no commit. First real exercise of the infinite-loop guard. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
65edf8c1ba
commit
1c69de2f40
@@ -48,6 +48,14 @@ ls CLAUDE.md .claude/CLAUDE.md 2>/dev/null | head -1
|
||||
|
||||
In both cases: MANDATORY STOP until user answers remaining questions. Produce PROJECT BRIEF.
|
||||
|
||||
**Then run `$HOME/.claude/lib/contract-interview.md`** seeded from the BRIEF:
|
||||
REQUEST verbatim = the user's project description; ACCEPTANCE CRITERIA = the
|
||||
V1 FEATURES (each testable); FILE SCOPE = the planned tree. No new questions
|
||||
(the interview already asked). It writes
|
||||
`.claude/tasks/contracts/<date>-<slug>-<HHMM>.md`; the DESIGN approved at STEP
|
||||
4 ENRICHES it, and STEP 9's verifier judges the MVP against the enriched
|
||||
contract.
|
||||
|
||||
## STEP 2 — ANALYZE
|
||||
Load `$HOME/.claude/agents/analyzer.md`. Analyze BRIEF: existing code, stack constraints, infra risks, open decisions. Produce ANALYSIS REPORT.
|
||||
|
||||
@@ -70,6 +78,11 @@ Approve? (yes / request changes)
|
||||
```
|
||||
Changes → back to STEP 3. Approved → continue.
|
||||
|
||||
**On approval — ENRICH the STEP 1 contract**: append the DESIGN-derived
|
||||
acceptance criteria (resolved decisions, interfaces, test strategy) to the
|
||||
contract, each tagged `[gated <date>]`. STEP 9's verifier judges against this
|
||||
enriched contract.
|
||||
|
||||
## STEP 5 — SCAFFOLD
|
||||
Load `$HOME/.claude/agents/scaffolder.md`. Pass: BRIEF + DESIGN + `~/.claude/templates/project-CLAUDE.md` + `~/.claude/CLAUDE.md`.
|
||||
Creates: CLAUDE.md, settings, structure, config, empty entry points, .gitignore, .env.example, .claude/tasks/TODO.md, .claude/memory/{decisions,learnings,blockers,journal,evals}.md, .claude/audits/. NO README, NO features.
|
||||
@@ -175,8 +188,21 @@ If `graphify` CLI is installed AND complexity >= 30%:
|
||||
2. Print: `🔗 Full project graph updated at graphify-out/`
|
||||
If `graphify` not installed or complexity < 30% → skip silently.
|
||||
|
||||
## STEP 9 — ANALYZE
|
||||
Load `$HOME/.claude/agents/analyzer.md`. Check: no regressions, no deviations, no stale scaffold, conventions respected.
|
||||
## STEP 9 — VERIFY + SECURE (fresh gates, bounded loops)
|
||||
Run the two fresh gates per `$HOME/.claude/lib/verify-secure-loop.md` with
|
||||
`CONTRACT` = the STEP 1 path (ENRICHED at STEP 4), `DIFF` = the MVP branch
|
||||
diff (`develop..HEAD`), `TEST` = the project suite:
|
||||
- GATE 1 — a FRESH verifier judges the MVP against the enriched contract (V1
|
||||
features + `[gated]` design criteria). CONFORME → GATE 2. ECARTS → fix,
|
||||
re-verify, max 3 → STOP + human escalation with the CRITERIA table.
|
||||
- GATE 2 — a FRESH security-auditor (`MODE: gate`, `SCOPE: develop..HEAD`).
|
||||
PASS → STEP 10. BLOCK → fix, re-verify request THEN re-scan, max 3 →
|
||||
escalate.
|
||||
|
||||
This adds the security gate init-project previously lacked (security was only
|
||||
deferred to a later /onboard) and turns the informal analyze into a verdict
|
||||
against the founding contract. Distinct axis from STEP 10 code review
|
||||
([[LRN-095]]) — both run.
|
||||
|
||||
## STEP 10 — CODE REVIEW
|
||||
Invoke `superpowers:requesting-code-review`. Fix all CRITICAL before proceeding.
|
||||
|
||||
Reference in New Issue
Block a user