From ddea411491ee3bd4309d25d06a59239f203713bb Mon Sep 17 00:00:00 2001 From: bastien Date: Mon, 28 Sep 2026 14:54:53 +0200 Subject: [PATCH] chore(config): superpowers citers by bare name, routing map, docs, settings Every superpowers-prefixed skill call in ship-feature, init-project, tour, deploy, audit-delta, plugin-advisor and lib/analyze-before-plan now names the vendored skill directly. finishing-a-development-branch is described as the upstream skill this config does not vendor (gitflow finish is the integration path). CLAUDE.global.md Skill routing maps the four non-vendored skills the vendored text still references. settings.json loses the plugin key and its marketplace block; README, USAGE, plugin-advisor and the profile skill describe superpowers as vendored skills, always on, zero plugin cost. CHANGELOG entry with a known residual. --- CHANGELOG.md | 32 ++++++++++++++++++++++++++ CLAUDE.global.md | 6 +++++ README.md | 2 +- USAGE.md | 31 +++++++++++++------------ agents/plugin-advisor.md | 44 +++++++++++++++++++----------------- lib/analyze-before-plan.md | 7 +++--- lib/capitalize-commit.md | 18 ++++++++------- lib/doc-commit.md | 9 ++++---- settings.json | 7 ------ skills/audit-delta/SKILL.md | 3 ++- skills/deploy/SKILL.md | 2 +- skills/gitflow/SKILL.md | 8 ++++--- skills/init-project/SKILL.md | 8 +++---- skills/profile/SKILL.md | 6 +++-- skills/ship-feature/SKILL.md | 8 +++---- skills/tour/SKILL.md | 7 +++--- 16 files changed, 121 insertions(+), 77 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index d4eba6b..46be703 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -379,6 +379,21 @@ Format follows [Keep a Changelog](https://keepachangelog.com/). `plugins.lock.json` pin 3.2.0 → 4.1.0 (the CLI only: the skill dist and the engine binary have their own release tracks). `link.sh` drops impeccable from `EXTERNAL_SKILLS`; `skills-external/impeccable/` is gone. +- **Superpowers plugin replaced by 7 vendored skills** (tier 2 of the + skill-catalog prune, BDR-105/106). `brainstorming`, `writing-plans`, + `subagent-driven-development`, `test-driven-development`, + `requesting-code-review`, `using-git-worktrees` and `writing-skills` are + curled byte-for-byte from `obra/superpowers` at the v6.4.1 commit + (`5bf4e78011075bcfc0dc295f0724994cd123ee71`) via `lib/vendor-skills.sh` + (new `superpowers` entry in `plugins.lock.json`, `always_on: true`), + linked by `link.sh` like the other externals: always on, no profile lists + them, same as `darwin-skill`. Every `superpowers:` citer across + `skills/`, `agents/` and `lib/` is renamed to the bare skill name. + `CLAUDE.global.md` Skill routing gains a map for the 4 dropped skills this + config used to reference: `executing-plans` to + `subagent-driven-development`, `finishing-a-development-branch` to + `gitflow finish`, `systematic-debugging` to `/bugfix`, + `verification-before-completion` to the verifier gates. ### Security - **Ten secret-reader deny rules added**: `sed`, `awk`, `cut`, `tr`, @@ -433,6 +448,15 @@ Format follows [Keep a Changelog](https://keepachangelog.com/). with it: the 4 `mcp__magic__*` `permissions.ask` entries (BDR-059), the `MAGIC_API_KEY` block in `.env.example`, `link.sh`'s missing-key warning, and the dead `MAGIC_API_KEY=abc123` gitleaks allowlist regex. +- **Superpowers plugin uninstalled**: its 8 other skills + (`executing-plans`, `finishing-a-development-branch`, + `systematic-debugging`, `verification-before-completion`, + `dispatching-parallel-agents`, `receiving-code-review`, + `using-superpowers`, `diagnosing-superpowers`) and its SessionStart + injection (`using-superpowers`, ~3.6 KB every session start) are gone + with it. `lib/profile.sh` no longer protects it; `lib/detect-plugins.sh` + `detect_superpowers` now checks the linked vendored skill instead of the + plugin cache or `claude plugin list`. ### Fixed - **gstack's shared helper tree was mostly unreachable.** gstack skills @@ -505,6 +529,14 @@ Format follows [Keep a Changelog](https://keepachangelog.com/). `21st-ui-build` and `21st-cli-use` still point at the now-`max`-only 21st trio. A Skill call on a parked name fails, and the doctrine routing in `CLAUDE.global.md` applies instead. +- The 7 vendored superpowers skills are byte-for-byte upstream text, never + edited: their internal `superpowers:` mentions and references to the + 8 non-vendored skills stay in the prose (their own text, not ours to + patch). `CLAUDE.global.md` Skill routing carries the map for the 4 of + those this config used to reference. After a rollback that re-installs + the plugin while the 7 symlinks are still linked, delete the + `skills/<7>` symlinks or re-run `make plugin` to avoid duplicate skill + descriptions. ## [1.5.0] — 2026-09-13 diff --git a/CLAUDE.global.md b/CLAUDE.global.md index 505fe6e..220c268 100644 --- a/CLAUDE.global.md +++ b/CLAUDE.global.md @@ -258,6 +258,12 @@ cryptic names. - Design / UI (build, system, audit, polish) → "Design work" below - Architecture review → plan-eng-review - Before /clear or /compact → capitalize; end-of-session ritual → close +- superpowers skills are vendored, called by bare name; an upstream + `superpowers` prefix names the same skill. Not vendored here: + executing-plans → subagent-driven-development + finishing-a-development-branch → `gitflow finish` (human signal) + systematic-debugging → bugfix + verification-before-completion → the verifier gates - SEO+GEO → seo (GEO only → geo); W3C + WCAG a11y → web-validate; security audit (secrets, CVE, OWASP) → cso gstack OFF → its skills (investigate, qa, review, health, retro, diff --git a/README.md b/README.md index 2716368..3a5ad36 100644 --- a/README.md +++ b/README.md @@ -118,7 +118,7 @@ ctx7 login # optional: OAuth / API key for higher rate limits | Component | Type | Description | Docs | |---|---|---|---| -| **Superpowers** | Plugin (required) | Brainstorming, planning, subagent-driven dev, code review, branch finishing. Required by `/init-project` and `/ship-feature`. | [obra/superpowers-marketplace](https://github.com/obra/superpowers-marketplace) | +| **Superpowers skills** | Vendored (7, always on) | brainstorming, writing-plans, subagent-driven development, TDD, code review request, git worktrees, writing-skills — pinned v6.4.1 in plugins.lock.json, no plugin, no session injection | [obra/superpowers](https://github.com/obra/superpowers) | | **GStack** | Plugin (toggle) | Full-product workflow: UI + design + deploy + browser QA. Skip for backend/CLI projects. | [garrytan/gstack](https://github.com/garrytan/gstack) | | **GSD v2** | External CLI | Multi-session orchestration: crash recovery, cost tracking, parallel workers, context-fresh execution. | [gsd-build/gsd-2](https://github.com/gsd-build/gsd-2) | | **RTK** | Plugin (always on) | Code rewrite hook. Zero passive cost. | [rtk-ai/rtk](https://github.com/rtk-ai/rtk) | diff --git a/USAGE.md b/USAGE.md index 7b36a20..55fe619 100644 --- a/USAGE.md +++ b/USAGE.md @@ -181,8 +181,8 @@ Deploy + QA browser → gstack ON Next.js/React/Prisma → context7 ON (WARN si absent, pas BLOCK) Multi-session (>1 jour) → gsd v2 CLI (gsd dans terminal) -Backend/CLI seulement → tout OFF sauf superpowers -Hotfix/quick fix → tout OFF sauf superpowers +Backend/CLI seulement → tout OFF (skills superpowers vendorisés, toujours actifs, 0 t passif) +Hotfix/quick fix → tout OFF (skills superpowers vendorisés, toujours actifs, 0 t passif) ``` **GSD v2** n'est pas un plugin Claude Code — c'est un CLI externe. Il ne consomme pas de tokens passifs. Tu le lances dans un terminal séparé avec `gsd`, puis `/gsd auto` pour le mode autonome. @@ -586,7 +586,7 @@ ONBOARD COMPLETE: mycli → SIGNALS: none (CLI pur) → DISABLE: ui-ux-pro-max, gstack, context7 -→ KEEP: superpowers +→ (skills superpowers vendorisés, toujours actifs, 0 t passif) → COST: ~800t (minimal) → ACTION REQUIRED? NO ``` @@ -647,7 +647,7 @@ DO NOT TOUCH: /plugin-check "CLI Rust, convertisseur de fichiers JSON/CSV/TOML, pas de réseau, pas de frontend" → SIGNALS: none (CLI pur, pas de deploy, pas de frontend) -→ KEEP: superpowers +→ (skills superpowers vendorisés, toujours actifs, 0 t passif) → DISABLE: ui-ux-pro-max, gstack, context7 → COST: ~800t (base seulement) → ACTION REQUIRED? NO @@ -748,7 +748,7 @@ Simple à valider. L'architecture proposée est plate, pas de surprise. **Contexte :** module `services/payment_service.py` dans un projet FastAPI existant. Écrit il y a 2 ans, jamais refactorisé. Violations connues : fonctions de 80 lignes, global state, pas de tests unitaires, logique métier mélangée avec appels HTTP. -**Setup :** projet déjà onboardé (CLAUDE.md présent), superpowers actif, plugins inutiles désactivés. +**Setup :** projet déjà onboardé (CLAUDE.md présent), skills superpowers vendorisés (toujours actifs, 0 t passif), plugins inutiles désactivés. #### Étape 1 — Analyse avant toute modification @@ -861,7 +861,7 @@ PROJECT STATUS CONFIG Version : v2.5.0 - Plugins ON: superpowers, context7 (~1000t) + Plugins ON: context7 (~200t), skills superpowers vendorisés (toujours actifs, 0 t passif) GSD v2 : installed (2.64.0) PROJECT @@ -956,19 +956,20 @@ GSD v2 met à jour le plan dans `.gsd/ROADMAP.md` sans perdre le travail déjà /plugin-check "Firmware C STM32, bare-metal, pas de réseau, pas de frontend, pas de Docker" SIGNALS: simple, CLI/embedded -COST: ~800t (superpowers seul) +COST: ~0t (skills superpowers vendorisés, toujours actifs, 0 t passif) RECOMMENDATIONS: - OK KEEP : superpowers (peut être utile pour brainstorm initial) DISABLE : ui-ux-pro-max, gstack, context7 - NOTE : Pour un firmware vraiment simple (hotfix, modification ciblée), - même superpowers peut être désactivé → ~0t passif + NOTE : skills superpowers (brainstorming, writing-plans...) restent + disponibles par nom bare sans coût passif, même pour un + firmware minimal. ``` **Workflow minimaliste — modification d'un driver existant :** ``` -# Pas de /init-project, pas de GSD, pas de superpowers +# Pas de /init-project, pas de GSD ; skills superpowers vendorisés +# (toujours actifs, 0 t passif) mais non invoqués ici # 1. Comprendre avant de modifier /analyze src/drivers/uart.c @@ -992,7 +993,7 @@ OUTPUT: /ship-feature "Corriger l'accès non-atomique au ring_buffer_head dans l'ISR" STEP 0b — CLAUDE.md found -STEP 0 — plugin check: superpowers OK (ou désactivé si YOLO mode) +STEP 0 — plugin check: skills superpowers vendorisés (toujours actifs, 0 t passif) STEP 1 — BRAINSTORM (rapide, contexte déjà clair depuis /analyze): Design: protéger ring_buffer_head avec __disable_irq()/__enable_irq() @@ -1015,7 +1016,7 @@ STEP 4 — IMPLEMENT (subagents légers, modifications chirurgicales) ``` **Points clés :** -- `/plugin-check` confirme "superpowers seulement" → aucun plugin inutile actif. +- `/plugin-check` confirme qu'aucun plugin inutile n'est actif (skills superpowers vendorisés, toujours actifs, 0 t passif). - `/analyze` est particulièrement utile sur du code C bas-niveau : l'analyzer identifie les accès non-atomiques, les race conditions, les violations de normes, **sans proposer de fix**. - Pour un firmware, le workflow `analyze → ship-feature` peut se réduire à `analyze → edit direct` si la modification est triviale. - GSD v2 n'est jamais pertinent pour du firmware : les sessions sont courtes et les tâches atomiques. @@ -1031,7 +1032,7 @@ Prisma / Supabase → context7 ON "design élaboré" / tokens → ui-ux-pro-max ON Docker + QA browser → gstack ON "plusieurs semaines" → gsd v2 CLI -Rust / Python / Go / C → tout OFF sauf superpowers +Rust / Python / Go / C → tout OFF (skills superpowers vendorisés, 0t) Mobile / Flutter / RN → gstack OFF -Hotfix / script rapide → tout OFF sauf superpowers +Hotfix / script rapide → tout OFF (skills superpowers vendorisés, 0t) ``` diff --git a/agents/plugin-advisor.md b/agents/plugin-advisor.md index 61c5f1c..1772299 100644 --- a/agents/plugin-advisor.md +++ b/agents/plugin-advisor.md @@ -77,7 +77,7 @@ Factors (weighted): | Infra/deploy | 15% | Local only | Single deploy target | Multi-env, CI/CD, containers, monitoring | **Score thresholds:** -- **0-30% (simple)**: superpowers only. No gstack, no gsd, no ctx7, no graphify. +- **0-30% (simple)**: superpowers skills only (vendored, always on). No gstack, no gsd, no ctx7, no graphify. _Examples: site vitrine, landing page, script CLI, simple CRUD._ - **30-60% (moderate)**: + context7 if fast-libs. graphify only once the codebase passes 200 tracked code files (session-start banner informs, the user decides — BDR-097), never at scaffold. _Examples: blog with auth, dashboard with charts, API with validation._ @@ -143,7 +143,7 @@ ACTION REQUIRED? YES / NO | `fast-libs` | context7 | — | Doc freshness critical | | `multi-agent` + `complex-arch` | gsd v2 CLI | — | GSD v2 preferred for multi-session coordination | | `simple` / single-session | — | gsd, gstack, ui-ux-pro-max | Saves ~3000-5000t | -| `embedded` / firmware | — | all toggles; superpowers optional | workflow: /analyze → /hotfix or /bugfix or /ship-feature | +| `embedded` / firmware | — | all toggles (superpowers skills vendored, always on) | workflow: /analyze → /hotfix or /bugfix or /ship-feature | | backend/lib/CLI only | — | ui-ux-pro-max, gstack | ~3100t saved | | small project / hotfix | — | gstack, gsd | Use /hotfix, /bugfix, or /feat | @@ -174,12 +174,12 @@ When the plugin-advisor detects a `simple` or `hotfix` signal, suggest the appro | Pair | Relation | Verdict | |---|---|---| | gstack ↔ gsd v2 | ✅ Complementary | GStack = full-product CC workflow. GSD v2 = multi-session CLI. Different scopes, no conflict. | -| superpowers ↔ gsd v2 | ✅ Complementary | Superpowers = single-session execution. GSD v2 = multi-session CLI orchestration. No conflict. | -| superpowers ↔ gstack | ✅ Complementary | Used together in /init-project and /ship-feature. Superpowers = engine, GStack = full-product skills. | +| superpowers ↔ gsd v2 | ✅ Complementary | superpowers skills (vendored) = single-session execution. GSD v2 = multi-session CLI orchestration. No conflict. | +| superpowers ↔ gstack | ✅ Complementary | Used together in /init-project and /ship-feature. superpowers skills (vendored) = engine, GStack = full-product skills. | | context7 ↔ any | ✅ Independent | Doc lookup CLI (ctx7), no workflow overlap. Always safe to combine. | -| plugin-dev ↔ superpowers | ⚠️ Minor overlap | Superpowers can create skills too. Keep plugin-dev only when actively building new plugins/skills. | +| plugin-dev ↔ superpowers | ⚠️ Minor overlap | superpowers skills (vendored) can create skills too (writing-skills). Keep plugin-dev only when actively building new plugins. | | ui-ux-pro-max ↔ gstack | ✅ Complementary | GStack = deploy/QA layer; ui-ux-pro-max = UI quality layer. Different concerns. | -| pr-review-toolkit ↔ superpowers | ✅ Complementary | superpowers:requesting-code-review and /pr-review-toolkit:review-pr cover different review styles. | +| pr-review-toolkit ↔ superpowers | ✅ Complementary | `requesting-code-review` (vendored superpowers skill) and /pr-review-toolkit:review-pr cover different review styles. | | rtk ↔ any | ✅ Independent | Hook-only token compression. Zero interaction with any plugin. | | security-guidance ↔ any | ✅ Independent | Hooks + out-of-band LLM reviews (agentic review on commit/push; Stop diff review disabled by ENABLE_STOP_REVIEW=0). No context injection unless a regex hits. | @@ -187,15 +187,15 @@ When the plugin-advisor detects a `simple` or `hotfix` signal, suggest the appro | Project type | Plugins ON | OFF | Passive cost | |---|---|---|---| -| Backend API / microservice | superpowers, context7 (if fast libs) | ui-ux-pro-max, gstack | ~800t | -| Frontend SPA / SSR | superpowers, ui-ux-pro-max, frontend-design, design-motion-principles, context7 | gstack | ~1400t | -| Full-stack SaaS | superpowers, gstack, ui-ux-pro-max, frontend-design, design-motion-principles, context7 | — | ~4200t | -| CLI tool / library | superpowers | all toggles | ~800t | -| Multi-session large feature | superpowers + gsd v2 CLI (external) | — | ~800t CC | -| Quick fix / hotfix | superpowers | all toggles | ~800t | -| Design system / component lib | superpowers, ui-ux-pro-max, frontend-design, design-motion-principles | gstack, gsd | ~1200t | -| Fast-evolving libs (Next.js etc.) | superpowers, context7 | — | ~1000t | -| Enterprise multi-agent orchestration | superpowers + gsd v2 (external) | plugin-dev | ~800t CC | +| Backend API / microservice | (superpowers skills always on), context7 (if fast libs) | ui-ux-pro-max, gstack | ~0t | +| Frontend SPA / SSR | (superpowers skills always on), ui-ux-pro-max, frontend-design, design-motion-principles, context7 | gstack | ~600t | +| Full-stack SaaS | (superpowers skills always on), gstack, ui-ux-pro-max, frontend-design, design-motion-principles, context7 | — | ~3400t | +| CLI tool / library | (superpowers skills always on) | all toggles | ~0t | +| Multi-session large feature | (superpowers skills always on) + gsd v2 CLI (external) | — | ~0t CC | +| Quick fix / hotfix | (superpowers skills always on) | all toggles | ~0t | +| Design system / component lib | (superpowers skills always on), ui-ux-pro-max, frontend-design, design-motion-principles | gstack, gsd | ~400t | +| Fast-evolving libs (Next.js etc.) | (superpowers skills always on), context7 | — | ~200t | +| Enterprise multi-agent orchestration | (superpowers skills always on) + gsd v2 (external) | plugin-dev | ~0t CC | > rtk is always on at 0 context tokens; security-guidance is always on and > costs quota out of band (LLM reviews), not context — both omitted from @@ -239,8 +239,9 @@ RULE: IF "simple" OR "hotfix": RULE: IF "embedded" signal (firmware, bare-metal, microcontroller, or Makefile+C without Node/Rust/Go): → Disable ALL toggles including gstack, context7, plugin-dev - → superpowers OPTIONAL: useful for initial design brainstorm on complex drivers, - but unnecessary for single-function patches — user decides + → superpowers skills stay on (vendored, no toggle): useful for initial + design brainstorm on complex drivers, unnecessary for single-function + patches; just don't invoke them, no disable needed → GSD v2 CLI: not recommended (sessions are short, tasks are atomic) → Recommend workflow: /analyze → /hotfix (patch) or /bugfix (investigation) or /ship-feature (multi-file) → NOTE: print "embedded project detected — minimal plugin footprint recommended" @@ -251,7 +252,7 @@ RULE: IF plugin-dev ON AND no `skill-creation` signal detected: RULE: IF `skill-creation` signal: → plugin-dev ON (~100t) - → superpowers ON — required for skill scaffolding + → superpowers skills (vendored, always on): used for skill scaffolding (writing-skills) RULE: IF `browser-qa` signal (e2e tests, Playwright/Cypress/Puppeteer in deps): → gstack ON — browser automation and QA @@ -295,8 +296,9 @@ gstack + managed plugins — sessions stay focused and passive token cost drops. `profile set ` actually toggles plugins (`claude plugin enable|disable`) and external skill packs (delegates to `lib/toggle-external.sh`) — not just -advisory. No MCP server is auto-toggled today. Always-on plugins (`security-guidance`, `superpowers`) -are protected. Managed plugins that `set` may toggle: +advisory. No MCP server is auto-toggled today. Always-on plugins (`security-guidance`) +and the vendored superpowers skills are never toggled by a profile. Managed +plugins that `set` may toggle: `ui-ux-pro-max@ui-ux-pro-max-skill`, `plugin-dev@claude-code-plugins`, `pr-review-toolkit@claude-code-plugins`. Other plugins are never auto-toggled. @@ -321,7 +323,7 @@ toggles the managed plugins like any `set`). ## BLOCK if -- Superpowers not active → install: `claude plugin marketplace add obra/superpowers-marketplace && claude plugin install --scope user superpowers@superpowers-marketplace` +- Superpowers skills missing → `make plugin` (vendors them) then `make link` - Full-product (UI+deploy+QA) + gstack not installed ## WARN (no block) diff --git a/lib/analyze-before-plan.md b/lib/analyze-before-plan.md index 7be44a4..6a7eca0 100644 --- a/lib/analyze-before-plan.md +++ b/lib/analyze-before-plan.md @@ -103,9 +103,10 @@ backfill, if ever wanted, is `/prune-memory` passe D — never this snippet. ## ORDERING (orchestrators only) -`superpowers:brainstorming` / `writing-plans` are external skills — we cannot make them -read our registries. So this runs BEFORE them, pre-loading the disposition into the plan -they form. Mirror of capitalize-commit running BEFORE finishing-a-development-branch: there +`brainstorming` / `writing-plans` (vendored superpowers skills) are external skills — we +cannot make them read our registries. So this runs BEFORE them, pre-loading the +disposition into the plan they form. Mirror of capitalize-commit running BEFORE +`gitflow finish` (the upstream finishing-a-development-branch is not vendored): there the memory commit must precede integration; here the memory read must precede planning. ## NO-OP / IDEMPOTENT diff --git a/lib/capitalize-commit.md b/lib/capitalize-commit.md index 5c96210..c433631 100644 --- a/lib/capitalize-commit.md +++ b/lib/capitalize-commit.md @@ -17,9 +17,10 @@ code already committed. - Inline-commit flows (feat / hotfix / bugfix / commit-change): run it right after writing the entries, on the current branch. -- Orchestrators that integrate via `superpowers:finishing-a-development-branch` - (ship-feature / init-project): run it BEFORE the FINISH step — otherwise the - memory commit strands outside the merge/PR. See ORDERING. +- Orchestrators that integrate via `gitflow finish` (the upstream + finishing-a-development-branch is not vendored; ship-feature / init-project): + run it BEFORE the FINISH step — otherwise the memory commit strands outside + the merge/PR. See ORDERING. This snippet commits whatever is PENDING under `.claude/memory` + `.claude/tasks`; it does NOT decide content. A flow whose gate wrote only a journal line yields a @@ -65,11 +66,12 @@ no-match pathspec is filtered, not fatal). ## ORDERING (orchestrators only) -`finishing-a-development-branch` may merge-and-delete the branch or push a PR. A -memory commit created AFTER it lands outside the integrated history — stranded -on the PR path. So in ship-feature / init-project this snippet runs BEFORE -FINISH. The code commits already exist (implementation step), so the entries' -hash references are valid at this point. +`finishing-a-development-branch` (upstream superpowers skill, not vendored +here; `gitflow finish` is the only integration path) may merge-and-delete the +branch or push a PR. A memory commit created AFTER it lands outside the +integrated history — stranded on the PR path. So in ship-feature / init-project +this snippet runs BEFORE FINISH. The code commits already exist (implementation +step), so the entries' hash references are valid at this point. ## WHAT THIS DOES NOT DO diff --git a/lib/doc-commit.md b/lib/doc-commit.md index f7e0d1b..2a2ee6e 100644 --- a/lib/doc-commit.md +++ b/lib/doc-commit.md @@ -81,10 +81,11 @@ do NOT bypass them: ## ORDERING (orchestrators) -`finishing-a-development-branch` merges/pushes COMMITTED history only — it never commits -working-tree changes. A doc patch left uncommitted (or committed AFTER it) never reaches -the merge/PR. So this snippet runs BEFORE FINISH: the doc commit lands on the branch FINISH -integrates. Consumption is MECHANICAL (LRN-057 case a, like the memory commit) — production +`finishing-a-development-branch` (upstream superpowers skill, not vendored here; +`gitflow finish` is the only integration path) merges/pushes COMMITTED history only — it +never commits working-tree changes. A doc patch left uncommitted (or committed AFTER it) +never reaches the merge/PR. So this snippet runs BEFORE FINISH: the doc commit lands on +the branch FINISH integrates. Consumption is MECHANICAL (LRN-057 case a, like the memory commit) — production on the branch = consumption by the merge, automatic. ## ACKNOWLEDGMENTS (conscious, not glossed) diff --git a/settings.json b/settings.json index d161da1..d34217e 100644 --- a/settings.json +++ b/settings.json @@ -420,7 +420,6 @@ "example-skills@anthropic-agent-skills": false, "ui-ux-pro-max@ui-ux-pro-max-skill": true, "security-guidance@claude-code-plugins": true, - "superpowers@superpowers-marketplace": true, "pr-review-toolkit@claude-code-plugins": false, "brightdata-plugin@synced": false }, @@ -431,12 +430,6 @@ "repo": "anthropics/claude-code" } }, - "superpowers-marketplace": { - "source": { - "source": "github", - "repo": "obra/superpowers-marketplace" - } - }, "ui-ux-pro-max-skill": { "source": { "source": "github", diff --git a/skills/audit-delta/SKILL.md b/skills/audit-delta/SKILL.md index a5195f4..82f8b43 100644 --- a/skills/audit-delta/SKILL.md +++ b/skills/audit-delta/SKILL.md @@ -318,7 +318,8 @@ Then offer to capitalize (per CLAUDE.md): recurring finding patterns → ## TDD note (skill itself) -Baseline-tested per superpowers:writing-skills (2026-06-11, isolated +Baseline-tested per writing-skills (vendored superpowers skill; +2026-06-11, isolated worktree, no skill): the agent (1) guessed the boundary from the most recent file date in `.claude/audits/` — wrong file, date-based; (2) wrote its checkpoint as prose in a dated report — unparseable next run; (3) kept diff --git a/skills/deploy/SKILL.md b/skills/deploy/SKILL.md index d23c995..7413e52 100644 --- a/skills/deploy/SKILL.md +++ b/skills/deploy/SKILL.md @@ -512,7 +512,7 @@ The deploy succeeded. Lay the oracle and close out. ## Note on this skill (authoring) -Shaped via `superpowers:writing-skills`. The **cold cross-session resume** is the +Shaped via `writing-skills` (vendored superpowers skill). The **cold cross-session resume** is the novel form (design §10): the disk alone must carry the deploy across the out-of-band gap, so `PENDING.json`'s presence marks the wait and STEP 0 resumes from it without conversation memory — the `audit-delta` "state file is the only diff --git a/skills/gitflow/SKILL.md b/skills/gitflow/SKILL.md index efc9109..fdffdd3 100644 --- a/skills/gitflow/SKILL.md +++ b/skills/gitflow/SKILL.md @@ -13,8 +13,10 @@ fan-out, init, `.gitignore` reconcile, the protected-base predicate — are in and bulletproofs the single judgment call: **`finish` merges only on an explicit human signal.** -Replaces `finishing-a-development-branch` for gitflow flows — that skill is -single-target and cannot do the directed / fan-out merges below. +Replaces `finishing-a-development-branch` (upstream superpowers skill, not +vendored here; `gitflow finish` is the only integration path) for gitflow +flows — that skill is single-target and cannot do the directed / fan-out +merges below. ## When to Use @@ -107,7 +109,7 @@ stays human-gated. ## Common Mistakes -- Using `finishing-a-development-branch` for a gitflow merge → it can't do directed/fan-out merges. Use `gitflow finish`. +- Using `finishing-a-development-branch` (upstream superpowers skill, not vendored here) for a gitflow merge → it can't do directed/fan-out merges anyway. Use `gitflow finish`, the only integration path. - Hand-writing `git merge` instead of `gitflow finish` → loses fan-out, branch delete, base sync. - Calling `finish` because the work *looks* done → see the gate. - `git branch -d`/`-D` by hand → denied; a branch the lib refuses to delete still holds work. Keep it, say so. diff --git a/skills/init-project/SKILL.md b/skills/init-project/SKILL.md index 239f702..a156cf7 100644 --- a/skills/init-project/SKILL.md +++ b/skills/init-project/SKILL.md @@ -68,7 +68,7 @@ contract. Load `$HOME/.claude/agents/analyzer.md`. Analyze BRIEF: existing code, stack constraints, infra risks, open decisions. Produce ANALYSIS REPORT. ## STEP 3 — DESIGN -Invoke `superpowers:brainstorming` with BRIEF + ANALYSIS REPORT. +Invoke `brainstorming` (vendored superpowers skill) with BRIEF + ANALYSIS REPORT. Produce DESIGN: stack+versions, full folder tree, module responsibilities, data flow, interfaces (signatures only), config+tooling, test strategy, resolved decisions, prereqs list. Then run pass B of `$HOME/.claude/lib/contract-interview.md` against the DESIGN (minus what the BRIEF and the brainstorm settled): one batch before STEP 4; @@ -179,7 +179,7 @@ This is the deterministic scaffold commit owner (closes BLK-010). The MVP is implemented on a `feature/*` branch off `develop` (STEP 8). ## STEP 6 — PLAN -Invoke `superpowers:writing-plans` with BRIEF + skeleton. +Invoke `writing-plans` (vendored superpowers skill) with BRIEF + skeleton. Granular tasks (2-5 min each), exact file paths, TDD: tests before code. ## STEP 6b — CHALLENGE THE PLAN (before the gate) @@ -212,7 +212,7 @@ Start the MVP feature branch off develop, then implement on it: ```bash bash "$HOME/.claude/lib/gitflow.sh" start feature mvp ``` -Invoke `superpowers:subagent-driven-development` for the per-task implement loop +Invoke `subagent-driven-development` (vendored superpowers skill) for the per-task implement loop **and** the final whole-branch review **only**. Do NOT run its terminal `finishing-a-development-branch` step — this orchestrator owns integration via `gitflow finish` (STEP 11). When SDD's flow reaches "Use @@ -256,7 +256,7 @@ against the founding contract. Distinct axis from STEP 10 code review ([[LRN-095]]) — both run. ## STEP 10 — CODE REVIEW -Invoke `superpowers:requesting-code-review`. **Model routing (BDR-077):** the +Invoke `requesting-code-review` (vendored superpowers skill). **Model routing (BDR-077):** the review subagent it dispatches MUST carry `model: "opus"` in the Agent call — craft review is dispatched judgment, never inherited from the session. Fix all CRITICAL before proceeding. diff --git a/skills/profile/SKILL.md b/skills/profile/SKILL.md index 6351a67..1815d51 100644 --- a/skills/profile/SKILL.md +++ b/skills/profile/SKILL.md @@ -56,8 +56,10 @@ lists items + types: | `mcp` | advisory — prints manual `claude mcp add …` command (no server is managed today: `MANAGED_MCPS` is empty since 21st.dev moved to a CLI) | | `cli` | advisory only — reports installed/not-installed | -**Always-on plugins** (`security-guidance`, `superpowers`) are -protected — `set` will refuse to disable them even if the profile omits them. +**Always-on plugins** (`security-guidance`) and the vendored superpowers +skills are never toggled by a profile — `set` will refuse to disable the +plugin even if the profile omits it, and the 7 superpowers skills are +linked outside any profile. **Managed plugins** that `set` may disable when not in profile: `ui-ux-pro-max@ui-ux-pro-max-skill`, `plugin-dev@claude-code-plugins`, `pr-review-toolkit@claude-code-plugins`. Other plugins are never auto-toggled. diff --git a/skills/ship-feature/SKILL.md b/skills/ship-feature/SKILL.md index bc01d3e..17a4233 100644 --- a/skills/ship-feature/SKILL.md +++ b/skills/ship-feature/SKILL.md @@ -100,7 +100,7 @@ approved at STEP 3 ENRICHES it, and STEP 5's verifier judges the diff against the ENRICHED contract. This is the only flow where the contract grows mid-run. ## STEP 1 — BRAINSTORM -Invoke `superpowers:brainstorming` — but FEED it the STEP 0d digest as binding context, +Invoke `brainstorming` (vendored superpowers skill) — but FEED it the STEP 0d digest as binding context, not the raw request alone: "Feature request: <$ARGUMENTS>. In-force constraints (must hold): ``` -Invoke `superpowers:subagent-driven-development` for the per-task implement loop +Invoke `subagent-driven-development` (vendored superpowers skill) for the per-task implement loop **and** the final whole-branch review **only**. Do NOT run its terminal `finishing-a-development-branch` step — this orchestrator owns integration via `gitflow finish` (STEP 9). When SDD's flow reaches "Use @@ -234,7 +234,7 @@ conformity + security vs. craft/design) — both run, neither subsumes the other ([[LRN-095]]). ## STEP 6 — CODE REVIEW -Invoke `superpowers:requesting-code-review`. **Model routing (BDR-077):** the +Invoke `requesting-code-review` (vendored superpowers skill). **Model routing (BDR-077):** the review subagent it dispatches MUST carry `model: "opus"` in the Agent call — craft review is dispatched judgment, never inherited from the session. Fix all CRITICAL before proceeding. diff --git a/skills/tour/SKILL.md b/skills/tour/SKILL.md index b334aac..7cb455f 100644 --- a/skills/tour/SKILL.md +++ b/skills/tour/SKILL.md @@ -315,9 +315,10 @@ without that approval — neither this repo's nor any target project's. ## TDD note (skill itself) -Baseline-tested per superpowers:writing-skills (2026-07-04, seeded -fixture, no skill): the agent branched correctly via gitflow and did not -merge, BUT (1) silently rewrote the target TODO (checked boxes, +Baseline-tested per writing-skills (vendored superpowers skill; +2026-07-04, seeded fixture, no skill): the agent branched correctly via +gitflow and did not merge, BUT (1) silently rewrote the target TODO (checked +boxes, restructured) during "reconcile"; (2) authored BDR/journal registry entries autonomously; (3) ran security as ad-hoc grep + ruff — no semgrep, no pinned rulesets; (4) left findings only in its final chat