forked from bchanot/claude
fix(security-auditor,close): hotfix no-verifier carve-out documented; close enumerates STEP 5C + --no-push passthrough
This commit is contained in:
@@ -147,7 +147,9 @@ In audit mode, ALSO write this same block (plus per-finding detail) to
|
||||
## ORCHESTRATOR PROTOCOL (consumer contract — wiring reference)
|
||||
|
||||
- The security gate runs AFTER the request-conformity verdict is CONFORME
|
||||
(verifier), never before.
|
||||
(verifier), never before — EXCEPT under /hotfix, which by design runs no
|
||||
verifier: there the gate fires directly on the smoke-passed diff (its
|
||||
one-attempt model reverts on BLOCK instead of looping).
|
||||
- Dispatch a FRESH auditor each iteration — no context reuse. Input = mode +
|
||||
scope + (report) + (context), nothing else.
|
||||
- Parse the `SECURITY — VERDICT:` line:
|
||||
|
||||
@@ -8,7 +8,7 @@ description: |
|
||||
(that is /prune-memory).
|
||||
Triggers: "close", "end session", "ferme la session", "session close",
|
||||
"checkpoint memory", "what did we learn", "retro rapide", "fin de journée".
|
||||
argument-hint: (none — runs capitalize in ritual mode on the current conversation)
|
||||
argument-hint: "[--no-push] (runs capitalize in ritual mode; --no-push holds memory on the chore branch instead of the default auto-merge+push)"
|
||||
allowed-tools:
|
||||
- Read
|
||||
- Edit
|
||||
@@ -27,8 +27,10 @@ allowed-tools:
|
||||
Invoke the `capitalize` skill now and run it in **ritual mode**: the full
|
||||
pipeline (STEP 0 precheck → STEP 1 auto-scan → STEP 2 dedup → STEP 2B TODO
|
||||
reconcile → STEP 3 approval gate → STEP 4 write → STEP 5 journal → STEP 5B
|
||||
memory commit → STEP 6 handoff), PLUS STEP 1B's explicit 3-question reflection
|
||||
(what did you decide / learn / block).
|
||||
memory commit → STEP 5C auto-persist: finish + push, BDR-068 — pass
|
||||
`--no-push` through to hold the chore branch instead → STEP 6 handoff),
|
||||
PLUS STEP 1B's explicit 3-question reflection (what did you decide / learn
|
||||
/ block).
|
||||
|
||||
Ritual answers are deduped like any other candidate — a dup is dropped and its
|
||||
existing ID shown, not re-logged. This is the upgrade over the legacy `/close`,
|
||||
|
||||
Reference in New Issue
Block a user