forked from bchanot/claude
chore(config): untrack the vendored graphify skill, prune the project-local settings override
graphify: `graphify claude install` (install-plugins.sh STEP graphify)
writes SKILL.md, references/ and .graphify_version straight into the repo,
because ~/.claude/skills is a symlink to skills/. Every `pipx upgrade
graphifyy` therefore dirtied the tree and cost a `chore(graphify): sync
vendored skill X -> Y` commit. Now gitignored and untracked; a fresh clone
gets them back from `make plugin`. test-prompts.json is hand-written for
darwin and stays tracked. The accepted trade-off, documented in CLAUDE.md,
is that an upstream release can change the skill's prompt with no diff to
review.
settings.local.json (gitignored, so not in this commit) went from 14.6 KB
to 6.2 KB. It was a near-complete shadow copy of the global settings at a
higher precedence tier, which hid its own drift until the global moved.
Two entries were actively defeating BDR-090, merged an hour earlier:
- local `deny` still carried rsync / kill -9 / killall / pkill, the four
rules deliberately moved out of global deny. deny wins across sources,
so autoMode.soft_deny was a dead letter in this repo.
- local `allow` carried `sed *`, `cp *` and `python3 -`. An allow rule
short-circuits the classifier, punching a hole through the same
soft_deny rules.
deny and ask are dropped whole (102 and 27 of their entries duplicated the
global; ask gates nothing under defaultMode auto). allow went 185 -> 98:
81 duplicates plus six policy conflicts, the three above and
Read(//home/bchanot/**), WebSearch, and a leftover command-injection test
payload that had been allowlisted verbatim. Every non-permissions key was
a verbatim copy of the global, including a hooks block whose only original
entry pointed at hooks/config-protection.sh, a script that exists nowhere.
This commit is contained in:
@@ -30,6 +30,21 @@ install-plugins.sh STEP ctx7 purges it right after; the find-docs skill is
|
||||
the single ctx7 surface. If it reappears (manual `ctx7 setup`), delete it
|
||||
or re-run `make plugin`.
|
||||
|
||||
## Machine-owned: the vendored graphify skill
|
||||
|
||||
`skills/graphify/SKILL.md`, `skills/graphify/references/` and
|
||||
`.graphify_version` are written by `graphify claude install`
|
||||
(`install-plugins.sh` STEP graphify), which lands in the repo because
|
||||
`~/.claude/skills` is a symlink to `skills/`. They are gitignored: a
|
||||
`pipx upgrade graphifyy` used to dirty the tree and cost a
|
||||
`chore(graphify): sync vendored skill X -> Y` commit each time. A fresh
|
||||
clone gets them back from `make plugin`.
|
||||
|
||||
Trade-off accepted: an upstream release can now change the skill's prompt
|
||||
with no diff to review. `skills/graphify/test-prompts.json` is hand-written
|
||||
for darwin and stays tracked. To inspect what upstream changed, read the
|
||||
files on disk or diff against a previous `pipx` version.
|
||||
|
||||
## Transient planning artifacts
|
||||
|
||||
`docs/superpowers/specs/**` and `docs/superpowers/plans/**` are run-time
|
||||
|
||||
Reference in New Issue
Block a user