feat(skills): wire verify+secure into ship-feature/init-project; onboard no-loop + LRN-093 backstop (verify-loops lot 5)

ship-feature: STEP 0e CONTRACT (request verbatim) → ENRICHED at the STEP 3
validation gate (design criteria appended [gated <date>], the human
micro-gate) → STEP 5 VERIFY+SECURE judges the branch against the ENRICHED
contract via the shared include. Distinct axis from STEP 6 code review, both
run (LRN-095).

init-project: contract seeded from the PROJECT BRIEF (V1 features → criteria)
→ ENRICHED at VALIDATION GATE #1 → STEP 9 VERIFY+SECURE. Adds the security
gate init-project previously lacked (was deferred to a later /onboard).

onboard: explicit NO verify-loop — it produces an audit report, not a change
to verify against a request; contract is scope-only, security-auditor runs
MODE audit (report-only), never a gate. Documented to prevent a misplaced
symmetry loop (BDR-050: dev pipeline != audit).

lib/tests/no-vacuous-locks.test.sh: deterministic backstop for LRN-093 (2nd
recurrence in this chantier → the advisory alone did not hold). Refuses a
literal \n in any grep/tf/tr_/tn pattern across lib/tests/*.test.sh;
flip-tested against a synthetic offender so the guard proves it bites.
lib/tests/loops-heavy.test.sh: 18 structure locks green.

Behavioral dogfood (both vigilance points, real): (1) enrichment — a fresh
verifier reads and checks a [gated] design criterion (ECARTS naming it
precisely); (2) escalation — 3 consecutive ECARTS on the same criterion →
orchestrator STOPs at the max-3 bound + presents the CONTRACT-vs-REALIZED
table, no 4th loop, no commit. First real exercise of the infinite-loop guard.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
This commit is contained in:
Bastien Chanot
2026-07-04 04:46:52 +02:00
co-authored by Claude Opus 4.8
parent 65edf8c1ba
commit 1c69de2f40
5 changed files with 174 additions and 5 deletions
+33 -3
View File
@@ -78,7 +78,16 @@ The returned digest (ANALYSIS + RELATED MEMORY) stays in the orchestrator's cont
is FED to STEP 1 and STEP 2 and reconciled at STEP 3. Degradation: request too vague →
analyzer flags ambiguous zones, does not block (STEP 1 refines). `.claude/memory/` empty or
absent → analyzer omits RELATED MEMORY (no-op); the step still returns the code ANALYSIS.
Additive — distinct from STEP 5 ANALYZE (post-impl regression) and STEP 4b DEBUG.
Additive — distinct from STEP 5 VERIFY + SECURE (post-impl) and STEP 4b DEBUG.
## STEP 0e — CONTRACT
Run `$HOME/.claude/lib/contract-interview.md`. REQUEST verbatim = the feature
request as typed; initial ACCEPTANCE CRITERIA from the request; FILE SCOPE
seeded from 0d's KEY COMPONENTS. It writes
`.claude/tasks/contracts/<date>-<slug>-<HHMM>.md`; keep the path — the design
approved at STEP 3 ENRICHES it, and STEP 5's verifier judges the diff against
the ENRICHED contract. This is the only flow where the contract grows mid-run.
## STEP 1 — BRAINSTORM
Invoke `superpowers:brainstorming` — but FEED it the STEP 0d digest as binding context,
@@ -120,6 +129,13 @@ never a guarantee (same discipline as the memory-commit `✅<hash>`: show what's
assert a check not performed). No RELATED MEMORY from 0d → omit the block.
Changes → back to STEP 2. Approved → continue.
**On approval — ENRICH the STEP 0e contract.** The design just validated adds
detail the raw request lacked: append the design-derived acceptance criteria
to the contract's ACCEPTANCE CRITERIA, each tagged `[gated <date>]` (this is
the human micro-gate that authorizes contract growth). STEP 5's verifier
judges the diff against this ENRICHED contract, not the STEP 0e seed — so a
criterion the design introduced is verified, not lost.
## STEP 4 — IMPLEMENT
Start the feature branch off develop, then implement on it:
```bash
@@ -157,8 +173,22 @@ OPTIONS :
Skip them too? (yes / keep and accept partial implementation)"
If no dependents → skip cleanly and continue.
## STEP 5 — ANALYZE
Load `$HOME/.claude/agents/analyzer.md`. Check: no regressions, no stale code, no plan deviations.
## STEP 5 — VERIFY + SECURE (fresh gates, bounded loops)
Run the two fresh gates per `$HOME/.claude/lib/verify-secure-loop.md` with
`CONTRACT` = the STEP 0e path (ENRICHED at STEP 3), `DIFF` = the branch diff
(`develop..HEAD`), `TEST` = the project suite:
- GATE 1 — a FRESH verifier judges the branch against the ENRICHED contract
(all criteria, including the `[gated]` design ones). CONFORME → GATE 2.
ECARTS → hand the dev the gap list, fix, re-verify, max 3 → STOP + human
escalation with the CRITERIA table.
- GATE 2 — a FRESH security-auditor (`MODE: gate`, `SCOPE: develop..HEAD`)
scans the branch. PASS → STEP 6. BLOCK → fix, re-verify the request THEN
re-scan, max 3 → escalate.
This replaces the old informal "analyze for regressions" with a verdict
against the contract. It is a DISTINCT axis from STEP 6 code review (contract
conformity + security vs. craft/design) — both run, neither subsumes the
other ([[LRN-095]]).
## STEP 6 — CODE REVIEW
Invoke `superpowers:requesting-code-review`. Fix all CRITICAL before proceeding.