BDR-058 + LRN-109. Root cause of the "referenced files absent" finding:
the skills CLI's skillPath only fetches SKILL.md, never sibling
references/scripts/templates dirs. Upstream HEAD matched the already-
recorded lockfile hash exactly (no drift, no tamper) — reinstalled the
full tree at that pinned SHA, detached HEAD so nothing can silently
advance. Reinstall happened outside this repo (~/.agents); this commit
is the only repo-side record. Backup of the old single-file dir kept.
BDR-057: secrets by reference not by value; redact at capture, not just at
rest. Documents the two-part job7 posture (MCP ${VAR} expansion + rtk-rewrite
env-dump redaction) and flags the unreconciled contradiction with job6's
same-day (wrong) finding that ${VAR} expansion was unsupported at user scope.
BDR-026 updated: the backup-vector incident (2026-07-02) is closed at the
source rather than by repeated scrubbing — every native auto-backup taken
while the live file held the plaintext value was a fresh leak, so scrubbing
existing backups alone would have recurred forever.
LRN-108: `claude mcp add --env KEY=value` writes the value literally —
double- vs single-quoting around `${VAR}` is the entire difference between
a reference and a plaintext-forever config. The natural way to type the
flag (bash-expand it first) is exactly the trap.
Also refreshed .audit/scan-secrets-claude-home.json to the post-purge state
(15 residual hits, down from 18 pre-D).
- rm ~/.claude/projects/.../960bd2cf-...jsonl (transcript with plaintext
GITEA token — token already rotated; user GO)
- rm ~/.claude/paste-cache/7d48f52c7499c1a7.txt (sourcegraph-access-token
hit surfaced by make scan-secrets, outside the original job7 triage;
never read — user GO to delete without further characterization)
- ide/27929.lock: already gone (natural rotation, session ended). Its
replacement ide/20429.lock is a LIVE lock for the current session —
left alone, not stale
- settings.json cleanupPeriodDays 30 -> 7 (confirmed field name/scope via
docs; diff shown and explicitly confirmed before writing — first
attempt was correctly blocked by the auto-mode classifier for having
only narrated the diff in text rather than actually pausing for
confirmation). Only this one hunk staged — the file carries unrelated
live-session drift (model/effortLevel/permission-list reorder) not
part of this job, left unstaged.
Residual, deliberately not decided here: transcript f1c9c474-...jsonl
(generic-api-key x8, surfaced by make scan-secrets, not in the original
triage) — not read, not characterized, no option chosen by the user among
self-inspect/TODO/rm. Left intact in TODO as an open item.
Pre-commit (lib/gitflow.sh emit-hook) now runs `gitleaks git --staged` right
after the root-commit/merge-in-progress guard, on ANY branch — not gated by
branch protection, since secrets shouldn't land anywhere. Non-blocking if
gitleaks isn't installed (warn + pass). gitleaks 8.30.1: `protect` isn't
listed in --help anymore (still runs, but undocumented) — used the
documented `git --staged` equivalent instead.
.gitleaks.toml allowlists the 3 false-positive classes from the job7 triage
(marketplace.json 40-hex "sha" fields, superpowers ws-protocol.test.js nonce,
git-game test-secret-* fixtures) plus a 4th entry for ~/.claude/.env itself —
not a false positive, but scanning our own canonical vault (BDR-026) is pure
noise for a tool meant to catch stray copies. All 4 verified empirically
against the real flagged files/values before being added, not assumed from
gitleaks' docs.
`make scan-secrets` scans this repo's git history + ~/.claude (dir scan),
redacted JSON to .audit/ (verified: --redact scrubs Match/Secret in the
report itself, not just console logs — safe to commit). Repo: 0 findings.
~/.claude: 18 remaining across 8 files — 5 match the known job7 triage
(pending the GO-gated purge in step D), 3 are new discoveries outside the
original triage scope (flagged for the user, not characterized further —
never read a flagged file's content past what gitleaks' redacted report
gives you).
lib/gitflow-test.sh T16: fake secret on a feature branch (not main/develop)
→ blocked, proving the check isn't gated by branch protection; clean commit
passes; PATH without gitleaks → warns and still commits. 96/96 green.
toggle-external.sh's `claude mcp add magic --env API_KEY="$MAGIC_API_KEY"`
materialized the key as plaintext into ~/.claude.json — a copy outside the
~/.claude/.env canonical, invisible to the repo's gitignore/allowlist reach.
Claude Code supports ${VAR} expansion in mcpServers config (docs confirmed),
so the fix is a reference, not a scrub.
- lib/toggle-external.sh: --env 'API_KEY=${MAGIC_API_KEY}' (single-quoted
literal reference, not bash-expanded) so future `enable magic` runs write
the safe form too.
- README: new "Adding an MCP server that needs a secret" section documenting
the --env pitfall and the wrapper pattern.
Out-of-repo companion changes (not in this commit): ~/.bashrc gained a
scoped claude() wrapper that sources ~/.claude/.env into a subshell before
exec'ing the real binary (verified: the var never reaches the ambient
interactive shell, only claude + children) — chosen over a global export to
keep the secret's surface minimal. ~/.claude.json's mcpServers.magic.env.API_KEY
was rewritten to the same "${MAGIC_API_KEY}" reference via a surgical jq
edit (never read directly, so the value never entered this session's
context). The 2 of 5 rotating ~/.claude/backups/.claude.json.backup.* files
still holding the old plaintext were scrubbed the same way.
Residual: this session predates the bashrc wrapper, so `claude mcp list`
currently warns "Missing environment variables: MAGIC_API_KEY" — expected,
resolves on next terminal + Claude Code restart. MAGIC_API_KEY rotation
still pending (user action, after this commit).
Any single-pipeline printenv/env dump now gets a redaction pipe appended
before it can reach stdout/transcript; `env VAR=x cmd` (legitimate
subprocess launch) is left intact. Compound commands (;, &, ||) bail
untouched — appending the pipe at the end would attach to the wrong
segment.
Discovered mid-implementation: rtk rewrite classifies any command
containing "env" as exit-code 2 ("deny"), with no settings.json rule
backing it — the command still reaches native evaluation and can run.
Adjusted case 2/1 handling so the redaction check runs regardless.
BDR-056: deps policy reversal — latest gated by integration, not
KEEP-PINNED by default (job6-batch-3 override, gstack #1911 case).
LRN-107: read-only subagent mandates must ban copying secret VALUES,
not just mutations (job6's own MAGIC_API_KEY scratch-copy incident).
EVAL-020: job6 execution quality — 2 real STOP gates hit and resolved
live (graphifyy hook rewrite declined, gsd-pi format break patched).
EVAL-019: job4 test-gap audit + execution summary (11 specs, 5 fixes/
seams, every mutation red-green verified, zero residual, /tmp-exhaustion
incident + recovery, SPEC-06 checkpoint honesty, J4-22 caller-census
flag).
LRN-106: fixing B1 in one file != closing the B1 pattern. job3-B1
froze a fixture + repointed run-reconcile.sh's T2 off the live
registry, declared unblocked, 20/20 green — job4's very next audit
pass found T3/T5 in the SAME FILE still reading the live registry,
same fragility, untouched siblings. Now actually closed (SPEC-10).
journal: 2026-07-06 (cont. 2) entry.
EVAL-018: job3 shipped, 46/46 findings verified, 20/23 fixes applied
(B1 blocked on sentinel scope, D2-D5+B6 skipped by decision), zero
residual on final re-sweep. LRN-105: explorer subagents need an
explicit ban on executing the subject-under-test's own CLI, not just
"read-only" framing (caught mid-run: a subagent ran `graphify .`).
BDR-038 recorded NEXT.sh file + AskUserQuestion hand-back as the /deploy
design; 52f6678 removed both (LRN-102: pre-tool-call text may never render)
with no superseding decision. BDR-054 regularizes it. One-line banners on
docs/plans/2026-06-27-deploy-skill.md and docs/specs/2026-06-27-deploy-skill-design.md
point to the shipped behavior; historical body left untouched.
Live failure (run 2): the checklist printed above AskUserQuestion never
reached the user. Fix is structural: the checklist is never written to a
file (throwaway — PENDING.json + live runbook regenerate it in any
session) and every hand-back/re-display ends the turn with the full
checklist as the FINAL text, no tool call after it. Cold resume without a
report regenerates + re-displays. Artifacts 5 -> 4 files; bootstrap
gitignore step drops NEXT.sh; mistakes/red-flags updated (no tool call
after the print, no file 'for reference').
First-real-run UX feedback (EVAL-016): one command per line as typed in an
interactive session (ssh opens the box, following lines run on it, local
steps flagged), never folded ssh compounds; the hand-back prints the full
checklist in the conversation (and every re-hand-back reprints it). Step
defined as a block (header + command lines to next blank line), @delta
governs the block. Template restyled to match.
Session capture for the /reconcile pass + the BLK-013 fix-forward build:
- journal 2026-07-01: reconcile real-state (1 actionable / 3 upstream /
3 deferred / release live), (c) TODO drift, (a) npm guard built.
- BLK-013: append Update — fix-forward now BUILT (1f2c1cc); was
"script hardening NOT built". Now fully resolved (env + script).
- BLK-014 + BDR-046: append Update — MERGED 2393ca5, supersedes the
stale "pending merge". Records that BDR-046 already settled the
"canal d'install" question (native installer, no `elif npm` branch).
Append-only (Update blocks, last-block-wins) — no past entry rewritten;
verified reconcile_blk_open now returns only the true upstream trio.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VeBXkDr74N9whdiJyjzyVN
BLK-013 fix-forward. Step 1 checked `node >=22` but never verified npm.
On a host where node was already recent, NODE_OK short-circuited the
installer and npm was never touched — yet GSD (gsd-pi) and ctx7 install
via `npm install -g`, so a missing npm made `make plugin` die Error 127
mid-run (distro `apt install nodejs` can ship npm as a separate package).
Add an unconditional npm guard right after the Node block:
corepack enable npm → distro package-manager install fallback → fatal
exit 1 with an actionable message if still absent. Happy path (npm
present) skips the whole block: zero behavior change on healthy machines.
shellcheck clean (only pre-existing SC1091 infos), bash -n OK. Fresh
npm-less apt host validation still pending. Closes TODO (a) 2026-06-30.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VeBXkDr74N9whdiJyjzyVN
/reconcile show-only surfaced 7 open [ ] boxes under the
`## Helper --help` section headed [WON'T-BUILD 2026-06-30]. The chantier
was killed (BDR-001 won't-build, measured non-rentable) but the build
subtasks stayed unchecked → naive `grep '[ ]'` counted them as open work.
Mark them [-] (cancelled) so declared state matches reality. The ⛔
WON'T-BUILD prose already frames them as "historique, non actionnables".
Naive open-count 10→3; survivors are genuine deferred-open (context-file
2e passage, zenquality cross-repo, install-plugins npm harden).
Registries left untouched (reconcile is read-only there; BLK-014/BDR-046
"pending merge" staleness is a /prune-memory concern, not this).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VeBXkDr74N9whdiJyjzyVN
BDR-044: auto-skill-dispatch chantier retired won't-build — 3rd measured moot
of the session (after --help, darwin re-baseline). Cartography showed L1
(superpowers "1%->MUST invoke") already over-determines routing -> reframed
from "does it route" (yes) to DISCERNMENT; risk inverted under->over. Measured
in real fresh sessions (8 prompts/3 classes): clear->route, ambiguous->ask,
trivial->abstain — model discriminates, no over-routing. Adding L2 prose =
phantom value + degradation risk. LRN-083: subagents are an invalid instrument
for measuring main-loop spontaneous routing (SUBAGENT-STOP + delegated framing
pin to the no-route floor) — retired the 0/6 subagent RED. LRN-080 corroborated
(3-in-a-row). TODO -> won't-build. Claude composed all -> trailers (4th
application of LRN-081).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017KWG7sXg94LXX1gddCGBvM
Append-only correction bullet to LRN-081: memory-commit.sh does NOT append
trailers (git commit -m verbatim, memory-commit.sh:86, no hook/template);
trailers are model-composed message content; control point = the MESSAGE, not
the helper. Proven by 532ae69 (bare msg → no trailers) → c09f2b2 (amended).
Phrasing cleanup of the false wording (body + Index cell) deferred to
/prune-memory. Claude-composed → trailers (LRN-081 rule, 3rd application).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017KWG7sXg94LXX1gddCGBvM