forked from bchanot/claude
68 KiB
68 KiB
Changelog
All notable changes to claude-config will be documented in this file.
Format follows Keep a Changelog.
[Unreleased]
[1.5.0] — 2026-09-13
Added
- Attention signals on the terminal (BDR-087) — new
hooks/notify-attention.sh, wired onNotification(input-needed matcher) and onStop(no matcher). Returns a double BEL plus an OSC 777 toast through theterminalSequenceJSON field, since hooks have no controlling TTY. Signal only:suppressOutput, exit 0, zero control-flow effect, which is what separates it from thedecision: "block"Stop hook BDR-083 refused. Each event reaches the toast as a readable label instead of a snake_case type; events needing no attention (agent_completed,auth_success) exit silently; a turn that ends withbackground_tasksstill running stays quiet and signals at the real end. Client-side prerequisites over Remote-SSH are documented in the script header (BLK-020): VS Codeaccessibility.signals.terminalBellfor the beep, an OSC notifier extension for the Windows toast. - User permanent rules (BDR-085) — three new rules/ files from the
user's rule text:
writing-style.md(always-on: em-dash ban, no slop vocabulary, no hedging chains, deliverable self-check),web-building.md(path-scoped: design anti-defaults + public-site done checklist),web-security.md(path-scoped: RLS, service-key/client split, IDOR, cookie flags, rate limiting — extends §Security, no dup). Project CLAUDE.md rules/ doctrine gains the 320-budget exception. - /tour multi-project parallel fan-out (BDR-084) — two or more
project paths now dispatch one runner per repo in a single message
(independent working trees, nothing collides) instead of processing
them one by one. The runner inherits the session model (no pin — it
carries tour's reflection); every agent inside keeps its defined tier.
A dead runner surfaces as an explicit
RUNNER FAILEDsummary row; the gated capitalize offer stays in the main loop. Bounded LRN-083 derogation recorded in BDR-084. Census §12: 6 locks, flip-tested. Mechanics proven first: nested probe, 3 overlapping agent windows, 9.1s vs ~18s sequential. - Contract gates — deterministic floor under the fresh verifier (BDR-083) —
an acceptance criterion can now carry an oracle (
CHECK:command +EXPECT:success-only marker +EVIDENCE:slot).lib/gates.sh run <contract>executes them fail-closed — MET requires exit 0 and the marker — and writes the outcome back into the contract, so the fresh verifier reads evidence as fact instead of trusting the executor's report. NewGATE 0inlib/verify-secure-loop.mdruns the floor before any verifier is dispatched: a red build no longer costs an LLM dispatch to discover.ABANDON: <id> <reason>makes an impossible criterion a visible handoff that blocksCONFORMEand routes to the human gate (new verifier verdictABANDONED(n)).featerandbugfixergain a four-pass completion discipline, scoped so it can never widen the contract. Adapted from theunlazyskill (Leonxlnx/unlazy, MIT); its Stop hook, approval store,.unlazy/tree, depth-tree arithmetic and Node checker were deliberately refused — see BDR-083 for each reason. The four orchestrator skills (feat,bugfix,ship-feature,init-project) restate the GATE 0 bullet ahead of GATE 1 (locked); hotfix explicitly runs no floor. Behavioral RED: 16/16 fresh unprimed runs followed the new doctrine (EVAL-027). 64 new assertions inlib/tests/gates.test.sh. lib/tests/seo-geo-contract.test.sh— census locking the seo/geo agent ⇄ dispatcher machine contract: judge verdict grammar, FIX BUNDLE + READY-TO-APPLY sentinel, signals handoff, every STEP header (interiors included), bundle item fields, score labels, scoring blocks, envelope keys (46→71 assertions across the C1 chantier).
Changed
- Skill and agent quality campaign, 54 units (BDR-086) — full darwin
v2.1 pass over the 31 personal skill-systems and 23 agents, excluding
the gstack/external symlinks and machine-owned units. Fresh baseline
mean 83.4; the 13 units under the user-set threshold of 80 were
optimized to completion, and verified defects in above-threshold units
were fixed in a grouped pass rather than left to ship because the score
was good enough. Every round was validated by a paired 3-judge majority
reading before and after in one call: 36 unit-round verdicts, 24 batch
verdicts, all better, zero reverts. Full report and residual findings:
.claude/audits/DARWIN-2026-08-26.md. - seo-analyzer + geo-analyzer de-prescribed for Opus 5 (BDR-082) —
process choreography converted to when-guidance under an
audience×mode-range invariant; self-output verification demands removed
(the score-engine "run it twice" became a conditional integrity guard);
two pre-BDR-061 vestigial rules fixed; P0/MANDATORY/ALWAYS caps softened
to plain content rules. Machine contract byte-frozen and locked by the
new
lib/tests/seo-geo-contract.test.shcensus (71 locks, flip-proven); proven by a controlled before/after/seodogfood — judge replay on frozen signals, 42/42 presence assertions on both runs, blind structural reader: interchangeable, recall improved. - Global instruction layer recalibrated for the Claude 5 family (BDR-081) — delegation block is now model-neutral when-guidance (the Opus 4.8 under-delegation counter inverted on Opus 5, which over-delegates and gets an injected harness cap); "staff engineer" self-check bar dropped (Opus 5 over-verification trigger); finish-whole-task clause added to Deviations; written-deliverable length rule added. 308/320 lines.
- Default session model is now
opus[1m](wasclaude-fable-5[1m]). skills-external/emil-design-eng/untracked — the file is curl'd from upstream byinstall-plugins.shwhen absent and re-fetched by everyupdate-all.shrun, so tracking it produced a repo diff on each upstream edit. Same category asfrontend-design/andimpeccable/, already ignored on that rationale; a fresh clone re-fetches it.design-motion-principles/has the same overwrite behaviour but no bootstrap clone yet, so it stays tracked until that gap closes.
Fixed
- hotfix wiped tolerated in-progress edits on its revert path — every
failure branch ran
git restore ., destroying user edits the run had tolerated. Now agit stash createpre-flight snapshot plus a file-scoped restore, and the security gate is fresh-dispatch only. - skills-perso listed 8 of 31 personal skills — detection rebuilt on
the
link.shsymlink convention (symlink = external, real dir = personal, gitignored = machine-generated). Live result 31/31, no false positives. - plan-challenger —
ERRORjoined the load-bearing verdict grammar (STEP 1 emitted it, the parser enum omitted it); grounded-but-uncertain findings now file as[MINOR]with the uncertainty stated, instead of being self-censored (Opus 5 follows conservative-reporting clauses literally). - design-toolchain hook — dropped
\bux\b(2 French-prose false positives; 3rd tightening pass, series LRN-1005/1007);\bui\bkept and locked by a must-fire test row. - Agent and skill defects found by the campaign's judges —
init-projectallowed-tools lackedAgentandSkillwhile every step dispatches;commit-changeconflict grep now covers all 7 unmerged codes;tour --report-onlyno longer commits;hardenseverity defers to the calibrated guide and the late SSL Labs grade has an assigned actor; handover writers' stale chapter refs corrected and the anchor gate ordered;security-auditordocuments the hotfix no-verifier carve-out;closeenumerates STEP 5C and passes--no-pushthrough;prune-memorydrops a false "v1-untested" note;code-cleanattributes its executor correctly; plugin-check and onboard fixtures de-drifted.
[1.4.0] — 2026-07-22
Added
- Transient planning artifacts auto-purged at feature-finish (BDR-065) —
gitflow finishon afeature/bugfixbranch now removes the run-time superpowers artifacts (docs/superpowers/{specs,plans}) on the working branch just before the directed merge, sodevelop's tip lands clean while the feature commits stay reachable as the archive (git show <sha>:…). This automates the manual post-merge cleanup that BDR-065 had left as doctrine — the step that slipped in 1.3.0 and needed a hand purge. Best-effort by contract: a purge that finds nothing, meets uncommitted changes under those paths, or fails to commit never aborts the finish (index/tree restored); opt out withGITFLOW_PURGE_TRANSIENT=0. Newgitflow.sh purge-transientverb..claude/tasks/{contracts,plans}are deliberately out of scope (durable, versioned, referenced by the decision registry). Live in every project via the~/.claude/libsymlink; covered bylib/gitflow-test.shT17 (a–d).
Changed
- Bug routing inverted:
/bugfixprimary,/investigateexplicit-only (BDR-080) — a bug / error / 500 now routes to/bugfixby default (the full framework: gitflow, contract, fresh verifier + security gates, registries). The gstack/investigatemonolith — its own~/.gstackmemory, no gitflow or gates — is reserved for explicit requests (cross-project learnings,/freezescope lock, long investigation with no immediate commit intent). Same core debugging doctrine, incompatible wrappers; the default now favours the gated, integrated path.
[1.3.1] — 2026-07-20
Changed
- README rebuilt around a short pitch — new top half: what it is / how it works / why it's good in ~60 lines (skills = entry points, agents = model-tiered execution units, hooks = deterministic guardrails, templates/memory = compounding per-project registries); all previous content demoted to an explicit reference-manual half below a separator. Deduplicated in the process: old title/tagline, Overview prose and the duplicated fresh-install block removed (unique install notes kept under a new "Install notes" section); hardcoded version number dropped from the footer (staleness risk). Docs-only release — no code change.
[1.3.0] — 2026-07-20
Added
- Profile switches now toggle external packs and MCPs both ways (BDR-079) —
profile.sh setwas asymmetric: it enabled what a profile listed (including gstack skills on demand when the whole pack is off, and themagicMCP) but never disabled the managed leftovers, soset backendafter design work kept emil-design-eng / frontend-design / design-motion-principles / impeccable active and magic registered.setnow trims managed externals (MANAGED_EXTERNALS) and managed MCPs (MANAGED_MCPS, delegated totoggle-external.sh) not listed in the profile — same allowlist doctrine asMANAGED_PLUGINS, nothing outside the allowlists is ever auto-touched (darwin-skill stays manual). Also: anexternalentry whose symlink never existed is now created fromskills-external/(mirroring toggle-external's from-source path), and the stale "NOT toggled automatically" note inprofile.shusage was corrected. Covered by a hermetic 16-check test (lib/tests/profile-set-managed.test.sh) with a fakeclaudeshim.
Changed
- README restructured for public readers — the project-layout tree and architecture principles moved verbatim to a new
ARCHITECTURE.md(README links it); bare decision-registry citations (BDR-XXX) stripped from README prose, meaning preserved;/profiledocumentation corrected in three places to the real 10-profile set (web / seo / web-full / full / backend / design / dev / qa / audit / minimal); fresh-install block now uses the real clone URL +make install/make doctor; new "SEO data layer" subsection documents theGOOGLE_OAUTH_CLIENT_ID/GOOGLE_OAUTH_CLIENT_SECRET/CRUX_API_KEYvars in~/.claude/.env(mirrors.env.example,make seo-connectone-time consent).
Fixed
- Transient planning artifacts purged from the repo —
docs/plans,docs/specs,docs/superpowers/{plans,specs}(deploy-skill 2026-06-27, model-routing 2026-07-15) were run-time pipeline artifacts that should have been deleted in their chantiers' post-merge cleanup and slipped through (one pair predates the lifecycle rule, one missed the purge step of a 6-wave chantier). Git history at the feature commits remains their archive;docs/no longer exists.
[1.2.1] — 2026-07-20
Fixed
- README caught up with the code it describes — the "Agent model routing" section still presented the BDR-066 v1 scheme (7 rows factually wrong after model-tiering v2): reframed to the BDR-076/077 4-tier table verified against agent frontmatters (opus-pinned judgment agents, per-mode splits for doc-syncer / handover-doc-writer / seo-geo pipelines, plugin-probe added, unpinned inline agents listed as such). Also: Context7 paragraph rewritten to the two-surface model (find-docs = sole doc-fetch surface,
ctx7-reminderhook = scoped session nudge, BDR-078),hooks/tree line now mentions the ctx7 reminder, and the/ship-featureworkflow block gained its STEP 2b (adversarial plan-challenge) line. Docs-only release — no code change.
[1.2.0] — 2026-07-20
Added
- ctx7 coverage extension (BDR-078) — the "consult current docs before coding against a fast-moving lib" doctrine now covers every code path, not just the two big pipelines. (1)
lib/fast-libs.sh: single source of truth for fast-lib detection (detect/cache-statusverbs; JS package.json anchored keys + Python requirements/pyproject; 7-day.ctx7-cache/freshness; locale-independent sort), replacing three hardcoded lists (/ship-featureSTEP 0c,/init-projectSTEP 5c,/onboardSTEP 3.5). (2)hooks/ctx7-reminder.sh: once-per-session UserPromptSubmit nudge when the project carries fast-libs and the cache is missing/stale — closes the ad-hoc-coding gap. (3) find-docs description extended with a before-writing-code trigger + a cache-first rule (read fresh cache, tee fetched docs back into it). (4) feater/bugfixer executor briefs gain the fast-lib docs rule (read fresh cache, else 2-topicnpx ctx7@latestfetch, else reportctx7 cache missand proceed). Second deliberate ctx7 surface — a scoped refinement of BDR-053's single-surface rule, not a reversal. - Adversarial plan-challenge phase — reflection orchestrators now run a blind 3-lens challenge (correctness / robustness / simplicity) via a dedicated
plan-challengeragent before implementation; severity-driven (a single-lens BLOCKER stops the plan), report-only./hotfixjoins behind a logic-only guard: cosmetic fixes skip it, logic fixes get challenged, a BLOCKER reroutes to/bugfix(BDR-075). - seo-data engine: measured coverage + new verbs — the
/seoFULL audit measures instead of feeling:sitemapverb gives COVERAGE a real denominator (source/live split); internal-link graph computes orphan pages + click depth; cannibalisation detected from GSC's own query data;rich_resultssurfaced from URL Inspection data already fetched;sameAsprofiles actually resolved;schema_gengenerates JSON-LD instead of only auditing it;content_qualityruns a deterministic filler/AI-slop scan; the axis score is computed, not felt;driftbaseline reports regressions vs changes. SPA pages: the audit refuses to score what JS paints instead of scoring the empty shell (no Playwright dependency). Common Crawl backlinks were measured (17 GB edges file) and killed as a source — the Off-page axis stays scoped to what is actually measured.
Changed
- Model-tiering v2: 4-tier explicit routing (BDR-076/077) — the session model (Fable) does main-loop reflection/orchestration only; every dispatched subagent is explicitly tiered: judgment agents pinned opus (analyzer, plan-challenger, seo/geo audit agents…), mechanical executors sonnet, skill-runner children fable — nothing inherits silently. Mode-based splits so pins take effect: doc-syncer audit(opus)/patch(sonnet), handover-doc-writer synthesize(opus)/render(sonnet), seo/geo collect(sonnet)/judge(opus, fail-closed)/template(sonnet), plugin gate split probe(sonnet)/advisor(opus). Census locks (125) + per-wave planted-input smokes.
- config-protection edit-block guardrail removed (BDR-074) — the hook blocked more than it protected; deny-list design pass recorded in BDR-069.
- graphify vendored skill dist synced 0.9.6 → 0.9.15.
Fixed
- seo/geo integrity pass (I1–I8) — Off-page axis scoped to measured data only; VSI (an SEO-blog fiction) removed from CWV thresholds; NAP direction rule ported into geo-analyzer (standalone
/geocan no longer write unverified NAP); security headers no longer double-counted (/hardenowns them); sampling coverage disclosed instead of implied; stats reattached to the claims they support; phantom audit precondition dropped. Plus two real bugs caught by a second-site backtest and two process anomalies from live dogfooding. settings.jsonWrite() deny rules were inert — converted to Edit() rules, closing the write hole they left open.- Model-routing W6 ronde: 6 findings closed (README bootstrap path, 2 census gaps, 3 stale refs).
Security
safe_fetchresolve-then-pin inlib/seo-data— DNS-rebinding closed on audit fetches: the audited host is resolved once, validated, then pinned for the actual fetch.url-guard— shell-injection + local-target refusal before any user-supplied or sitemap-crawled URL reaches curl (SSRF guard on the seo/geo fetch paths).
[1.1.0] — 2026-07-16
Added
/close+/capitalizenow auto-persist the memory they write. When the ritual branches achore/*branch off develop, it finishes that branch into develop and pushesorigin/developautomatically (new STEP 5C), so capitalized decisions / learnings / evals reach the next session instead of stranding on an unmerged branch. Scoped to memory-only ritual commits: a--no-pushflag holds the commit on the branch instead; a run on a feature branch (where the memory already rides the work) or an unsafe git state skips the auto-persist; and a failed push leaves the local merge intact with a manual-push note. Recorded as BDR-068, a deliberate scoped exception to the push-needs-an-explicit-go rule (which guards surprise code/release pushes, not an end-of-session memory persist).
[1.0.0] — 2026-07-16 — Initial public release
First public release of claude-config. The feature set below is the accumulated work previously staged as internal versions 1.0.0–4.0.0 (see "Pre-release (internal history)" further down for that lineage).
Changed
- BREAKING(layout): repo-root global memory renamed CLAUDE.md → CLAUDE.global.md; run
bash link.shonce after pulling (doctor.sh now checks the exact target) - graphify skill dist refreshed 0.8.45 → 0.9.6 (out-of-band
make plugin; SKILL.md + query/extraction references updated by the generator). /deploychecklist reshaped on first-real-run feedback, in two passes: runbook steps are one command per line, interactive-session style (an early step opens the ssh session; later lines run on the box; local steps say "from your machine") instead of foldedssh host "cd … && …"one-liners — step = comment header + command lines up to the next blank line, a@delta:directive governs the whole block; and the checklist is now display-only —NEXT.shis no longer written at all (throwaway artifact;PENDING.json+ the live runbook regenerate it in any session) and every hand-back ends the turn with the full checklist as the final text, no tool call after it (a checklist printed above a blocking question tool was observed never reaching the user). Templatetemplates/deploy/PROCEDURE.mdrestyled to match.settings.json:inputNeededNotifEnabled: trueadopted (harness notification toggle); committed layout otherwise unchanged.- gsd-pi upgraded 2.64.0 → 3.0.0 —
status-reporteroutput parser adapted to the ADR-013 cutover. hotfixerpinnedmodel: sonnet(seo/geo/web-validate L1 applier);analyzerhaiku pin removed (inherits the session model).- ship-feature / init-project: SDD implementation + review subagents dispatched with
model: "sonnet". - web-validate
--fix: bundle applied viahotfixerat L1 instead of inline Edit (BDR-061 alignment). - Model routing wave 2 — the pure-execution + reflection-split skills stop running execution on the big session model.
/docand/statusnow dispatch their agent (doc-syncer sonnet, status-reporter haiku) instead of inline-loading it, so the pin takes effect./hotfixsplit like/feat: reflection (LOCATE root cause) inline behind the model gate, the fix applied by ahotfixersonnet executor (rewritten dual-use — it is also the seo/geo/web-validate L1 applier); revert-not-loop preserved; hotfix joins the gated group (13th)./commit-changedispatches a sonnetcommit-changer(propose → dispatcher-owned approval gates → apply; grouping runs on sonnet,AskUserQuestionremoved from the agent)./release-candidatedispatches a new sonnetrelease-executorfor the mechanical spans (prep / finish+tag), the two human gates (when-to-release, push) and the version-number decision staying in the dispatcher. - Model routing wave 3 — the last two inline execution-carrying skills split like
/feat./bugfix: root-cause investigation, diagnosis and contract run inline behind the model gate; the fix + regression test are applied by abugfixersonnet executor (was a single inline agent), with the verify+secure loop staying in the main loop and the executor as its re-dispatched dev./code-clean: the dead-code / style / structural audit and the approval gate run inline; acode-cleanersonnet PHASE-2 executor then applies the approved scope — and the style/structural refactor (which inline-loadsrefactorer) now finally runs on sonnet, its pin having been inert under the old inline-load. Both skills stay gated (they keep reflection); their read-only-audit consumers (onboard,tour) reroute to a big-model agent so an audit never runs on the sonnet executor. Supersedes the BDR-050 "bugfix stays inline" carve-out. The built-inExploresearch agent is deliberately left inheriting the session (search feeds reflection). - Model routing wave 4 — client-handover doc-generation moved to sonnet (redaction-only). The ship-and-handover pipeline (baseline audits, fix loops, commit/push, deploy pause, live validate, gate) stays inline on the big session model in
client-handover-writer— its interactive gates work natively and its nested/seo//harden//web-validateaudits inherit the big model — and only the deliverable writing is delegated to a new sonnethandover-doc-writer(gate-free: reads memory + git, synthesizes the 6-chapter doc from a resolved PACKAGE, runs the word-count / skill-leak / anchor gates, renders branded HTML+PDF).client-handoverjoins the gated group (it orchestrates audits = reflection). Chosen over the whole-writer dispatch: the nested audits must run big either way, so whole-writer would have added ~7 gate-yields + a resumable state machine on a client deliverable for ~zero extra sonnet work.
Security
- Magic MCP fully ask-gated — all four
mcp__magic__*tools (builder, refiner, inspiration, logo_search) moved topermissions.askinsettings.json; no magic call can auto-execute. The builder opens an unauthenticated local callback server (127.0.0.1:9221+,Access-Control-Allow-Origin: *, no token check) whose POST body is injected verbatim into the tool result the model consumes — the ask-gate is the mitigation on our side (BDR-059). MAGIC_API_KEYpassed by reference, not by value — the MCP server is registered with--env 'API_KEY=${MAGIC_API_KEY}'(Claude Code expands it at launch from its own process env) instead of the literal secret, whichclaude mcp addwould otherwise materialize in plaintext in~/.claude.json, outside the repo's.envallowlist reach (BDR-026).printenv/envdumps redacted inrtk-rewrite.sh— closes a leak vector where a rewritten environment dump could surface a Gitea token.- gitleaks secret-scanning backstop —
.gitleaks.toml, a pre-commit hook, andmake scan-secretsadded to catch secrets before they land; pre-existing stale secret-bearing artifacts purged (GO-gated).
Added
- GSC + CrUX data layer for
/seoFULL —lib/seo-data/engine pulls real Google Search Console (Search Analytics + URL Inspection) and Chrome UX Report field data into the/seoFULL audit: CrUX p75 field metrics become the primary Core Web Vitals signal (anonymous PageSpeed lab stays the fallback), and a "Performance GSC (90 j)" section flags position 4-10 quick wins. Multi-account via OAuth2 (make seo-connect, one-time consent,webmasters.readonlyscope only) with a per-label token store (0600 file / 0700 dir, atomic write, refresh tokens redacted, gitleaks-allowlisted) so two concurrent site audits never conflict. Absent credentials degrade gracefully to anonymous PageSpeed — the audit never fails. Config:GOOGLE_OAUTH_CLIENT_ID/GOOGLE_OAUTH_CLIENT_SECRET/CRUX_API_KEYin~/.claude/.env. Engine contract documented inlib/seo-data/README.md. - impeccable (pbakaus, Apache-2.0) wired into the toolchain as the design counterpart of semgrep: the
/impeccableskill (23 verbs under one command: audit, polish, bolder, quieter…) plus the 45-rule deterministic anti-pattern detector (npx impeccable detect, exit 0/2,--json). Complementary tofrontend-design(kept — aesthetic direction at build time); impeccable adds the deterministic audit floor and per-project design context (/impeccable init). CLI pinned inplugins.lock.json(3.2.0 — a silent rules update would change audit output on unchanged code); dist is machine-owned underskills-external/impeccable/(gitignored, ctx7 pattern), staged-installed byinstall-plugins.shStep 8d, refreshed pin-honored byupdate-all.sh, symlinked bylink.sh, listed in the design/web/web-full/full profiles and the design-work routing. Requires Node ≥ 24: the install baseline is bumped from 22 to 24 LTS (NodeSourcesetup_24.x/ brewnode@24), somake pluginupgrades a too-old host in place; the impeccable steps still skip gracefully if Node stays below 24. Not in the design gate's GATE-BLOCK list yet — promotion deliberate, after first dogfood. /tourskill — grouped all-axes sweep over one or several projects: security (pinned-semgrepsecurity-auditoragent +/csoposture when gstack is ON) → cleanup → re-verify → reconcile (report-only, never edits the target TODO/registries) → doc sync, looping until a full pass applies zero fixes (bounded at 3 iterations). Fixes land on achore/tour-<date>branch the skill never merges; each project gets an append-only.claude/audits/TOUR.mdreport with BREAKING tags on contract-changing security fixes. Built TDD (superpowers:writing-skills): baseline run showed silent TODO rewrites, autonomous registry writes, grep-as-security-pass, no persistent report, scope creep and an unbounded loop — each countered and verified on a seeded fixture.- Model routing (BDR-066): blocking model gate (
lib/model-gate.md+lib/model-check.sh, flip-tested) wired into 12 reflection orchestrators; census guardlib/tests/model-routing.test.sh. /featre-architected: reflection inline (scope/plan/contract), execution dispatched to the sonnet-pinnedfeaterexecutor; verify+secure loop decided in the main loop with fresh executor re-dispatches.
Removed
lib/detect-plugins.sh:detect_security_guidance— dead since its re-add at45c3507; zero callers on any surface, including the dynamicsession-start.shdetection loop (the banner's row derives fromenabledPluginsinstead). Nothing invokes it — removal, not a breaking change.lib/detect-plugins.sh:plugin_enabled— its last two callers were replaced by the inlineenabledPluginsgrep atsession-start.sh:145-146(6d72d0a); zero callers remained. Nothing invokes it — removal, not a breaking change.templates/settings/settings.local.json— orphan template, zero automated consumer since creation (a145e3c); its README tree-line reference was already dropped ate48c834. Content recoverable from git history.lib/memory-commit.sh/lib/doc-commit.sh: thependingCLI verb + sourceablememory_pending()/docs_pending()helpers — earmarked "for the v2 hook", which BDR-037 rejected (no code ever written); zero production or test callers.commit "<message>" [<file>...]is now the only verb on both scripts.
Fixed
gitflow_finishignored its<type> <name>arguments and always merged the checked-out branch — naming a different branch silently merged the wrong one. The arguments are now an optional safety assertion: if given and not equal to the current branch,finishrefuses with a clear error instead of merging. No-argument calls (the only real caller) are unchanged.doctor.shfalse-warnings removed (a check that cries wolf is one you learn to ignore):cargoabsence no longer claims "RTK unavailable" (RTK ships as a prebuilt binary);check_symlinkno longer flags files reached through directory-level symlinks (e.g.hooks/session-start.sh); the GStack check counts the per-skill symlinks instead of askills/gstacklink thatlink.shdeliberately removes; the token-budget estimate is measured against the ~200k context window instead of a mis-framed "~11k session budget" that produced a false "92% CRITICAL".
Removed
- find-skills (alchaincyf) — skill-discovery helper dropped from the toolchain (install/update/link/toggle/advisor). Never used, and its
make updaterefresh step had started failing on clone timeouts. The discovery use case stays reachable manually:npx -y skills find <query>.
Pre-release (internal history)
The versions below (4.0.0 down to the original 1.0.0) were internal development milestones predating the first public release. They are kept for provenance; the full detail lives in git history. Their numbering does not continue past the public 1.0.0 above.
[4.0.0] — 2026-06-30
Added
- Gitflow universal model —
/gitflow+lib/gitflow.sh: branch model (main/develop/feature/bugfix/release/hotfix) with directed--no-ffmerges + hotfix fan-out (main + develop + openrelease/*);start/finish/initverbs.lib/gitflow-migrate.shonboards an existing repo (master→main, seeddevelop, install the pre-commit hook, set Gitea Option-1 owner-pushable protection onmain+develop), applied to all 6 repos. Wired into/init-project(STEP 5fgitflow initowns the scaffold root commit) +/onboard(STEP 2.6). See BREAKING under Changed /deploy— per-project deploy runbook in.claude/deploy/(PROCEDURE.md/INCIDENTS.mdledger /STATE.jsonoracle /PENDING.jsoncold-resume bridge /NEXT.sh); two-moment spine (instantiate checklist → out-of-band deploy → MARK success or LEARN from failure, patching the runbook in place); surgicallib/deploy-commit.sh; plus/setup-deploy- Analyze-before-plan invariant — dev flows (
feat/bugfix/hotfix,ship-feature) READ related memory before planning (ship-feature also reads related code) and must NAME each surfaced ID in the plan; sharedlib/analyze-before-plan.md(read-before bookend of coupled-capitalize) - Animation-library auto-detection/install —
motion(motion-vfor Vue 3 / Nuxt) auto-installed in/init-project(STEP 5e), opt-in in/onboard(STEP 2.5) on eligible stacks;plugin-advisordetects + reports only; logic inlib/animation-lib-check.sh - Design-toolchain gate —
lib/design-tool-gate.sh+lib/design-gate.md+ adesign-toolchain-reminderhook enforce the full design toolchain on UI work (profile-based), with a suggest-only non-blocking anim-lib note when a motion signal hits an eligible stack lib/toggle-external.sh— enable/disable non-marketplace tools; gstack now OFF by default (opt-in, activated on-demand per profile), Magic MCP (21st-dev) installed disabled by default- Secrets single source-of-truth — real secret in
~/.claude/.envreached via a repo.envsymlink +.env.exampleplaceholder;MAGIC_API_KEYresolved from it /reconcile— declared-vs-real reconciler: confronts TODO checkboxes + registry statuses (never the## Index) against real git/fs and surfaces the gaps in four categories + contradiction candidates, with a gated TODO write-back. Enginelib/reconcile.sh(body enumeration, git/fs oracles, last-block-wins status); thin skill/release-candidate— orchestrator over the gitflow release mechanic that adds the version tag the lib doesn't: finalizeversion.txt+ CHANGELOG, fan-outdevelop→main+ back, tagvX.Y.Z, push (gated). Lib stays the generic mechanic; the skill owns the tag- Coupled-capitalize: dev flows (feat / hotfix / bugfix / commit-change, ship-feature, init-project) auto-commit their memory in the same breath, via shared
lib/capitalize-commit.md+lib/memory-commit.sh(surgical —.claude/memory+.claude/tasksonly, nevergit add -A) - Coupled doc-sync: dev flows (feat / bugfix / hotfix, ship-feature, init-project) auto-commit the public docs
doc-syncerpatches, via sharedlib/doc-commit.md+lib/doc-commit.sh(surgical — only the patched files, nevergit add -A, never.claude//CLAUDE.md; refuses an out-of-scope path loudly with exit 4).doc-syncersurfacesPATCHED_FILES(one path per line) as the handoff lib/doc-shape.sh— deterministic MINOR-shape oracle fordoc-syncerAUTO MODE: re-checks each LLM-classified MINOR patch (added-heading / size / new-file / non-doc envelope, thresholds env-overridable) and escalates a shape-suspect patch to the existing SIGNIFICANT gate instead of silently auto-committing it. A structural floor under the LLM's classification, not a blocking gate (genuine MINOR still auto-commits, zero friction); catches structural/size significance, not semantic/audit-delta— recurring multi-axis audit (norms / bugs / dead code / security) scoped to changes since last run, with per-axis SHA markers/capitalize— flush uncapitalized context to the memory registries before/clearor/compact/prune-memory— curate and compress the.claude/memory/registries/close— end-of-session memory ritual (decisions / learnings / blockers)/pdf-translate— translate a PDF to another language, output as HTML (via Vision)/harden— web hardening audit (SSL/TLS, HSTS, CSP, headers)/web-validate— W3C HTML/CSS validity + WCAG accessibility audit/client-handover— final ship + branded client deliverable (Markdown / HTML / PDF)/profile— partition skills by usage profile (design / dev / qa / audit / minimal / full)frontend-designanddesign-motion-principlesskills (external marketplaces)- Project archetype library + detection for
/onboard .claude/{tasks,memory,audits}/governance layout + 5 memory registries (decisions, learnings, blockers, journal, evals)
Changed
- BREAKING (gitflow): never commit code directly on
main/develop— branch first (gitflow start <type> <name>) and integrate viagitflow finish. A generated per-repo pre-commit hook BLOCKS direct code commits onmain/develop(exempts.claude/**, merges, the root commit). Existing repos must runlib/gitflow-migrate.sh. This workflow rupture is what takes the project from 3.x to 4.0.0 settings.json:git push/git tagmoved to the ask permission tier — a tool-call backstop for the "finish / release only on an explicit human signal" ruleinstall.sh/install-plugins.shmade self-sufficient — nvm-installs Node/npm when missing, installs thejqprerequisite, runsnpx skills addfrom$HOME; auto-reverts hand-curated config (CLAUDE.md+settings.json+.claude/settings.json) after install via an EXIT trap (install-immutable guard); auto-fixes the gstack browser on an OS newer than the pinned Playwright supports (Ubuntu 26.04)- graphify upgraded to 0.8.x (skill pinned 0.8.45) — Gemini backend, monorepo support, CLI export, encoding fixes; CLAUDE.md + the pre-tool hook now prefer
graphify queryoverGRAPH_REPORT.md /seo+/geo: CMS-plugin-first + shared-file edit discipline; Bing / IndexNow submission now mandatory/ship-feature: capitalize + memory commit moved before FINISH (was after) — fixes memory committed after a push/PR and stranded outside it/init-project: new STEP 10b captures founding architecture decisions as BDRs before FINISH/ship-feature+/init-project: DOC SYNC moved before FINISH (was after) — fixes public docs patched then left uncommitted and stranded outside the push/PR (ship-feature STEP 9→8, init-project STEP 12→10c; GSD 13→12)/seosplit into parallelseo+geoagents with shared resources/onboardrewritten: archetype-aware pipeline (orchestrator + config-only agent), security audit archetype-awaredoc-syncer: stack-aware audit + deploy-doc gating; later scoped to public docs only,.claude/read-only; sync-only ROADMAP handling — planned→shipped reconciliation from code/git, never from.claude/; numeric incoherence → HUMAN questionCLAUDE.md: major refactor (contradiction purge, restructure), subagent-delegation rule, design-toolchain mandate, memory-registry governance- Memory registries: enforced English + caveman format
settings.json:permissions.defaultMode→auto(classifier-gated autonomy;disableAutoModedropped) +remoteControlAtStartup+skipAutoPermissionPrompt+effortLevel: xhigh; model pin removed
Removed
/init-project: STEP 12 (speculative GSD v2 auto-bootstrap at project creation) removed — it rangsd initAFTER FINISH, creatingROADMAP.md+.gsd/stranded outside the merge/PR (BLK-011), to bootstrap a multi-session engine that is opt-in and rarely used. Resolved by removal, not by plumbing a commit: GSD stays initializable on-demand (/onboard add gsd, orgsd initin a terminal),/statusstill reads.gsd/, and plugin-advisor still recommends it for multi-session work. init-project is now an 11-step pipelinedisable-model-invocationfrontmatter removed repo-wide (aligns skills with CLAUDE.md routing)- Caveman plugin always-on integration purged — plugin disabled + uninstalled; SessionStart/UserPromptSubmit hooks, standalone hook files,
install-plugins.shSTEP 5.5,update-all.shrefresh step,plugins.lock.jsonentry,doctor.shchecks, and docs removed. On a subscription plan its ~75% output-token compression has no cost benefit, and the always-on hooks added friction on validation gates + client deliverables. The unrelated memory-registry terse-format convention is kept. - Installer-managed skills de-vendored —
frontend-designun-tracked + npx-skills artifacts gitignored (re-synced from the plugin cache each run); obsoleteclaude --effort maxshell alias removed (settings.jsoneffortLevelis the source of truth)
Fixed
lib/doc-commit.shno longer masks a rejectedgit commitas success: a pre-commit hook / protected branch / signing failure now fails loud with exit 5 and empty stdout (was: false "committed" + the previous HEAD's hash + exit 0, leaving docs silently uncommitted on a dirty tree)- Numerous skill/agent fixes across darwin optimization rounds (geo-analyzer, onboard, init-project, analyzer, plugin-check, prune-memory, …)
[3.4.0] — 2026-04-15
Added
- 9 new skills:
/bugfix,/code-clean,/commit-change,/doc,/feat,/graphify,/hotfix,/seo,/skills-perso - 7 new agents:
bugfixer.md,code-cleaner.md,commit-changer.md,doc-syncer.md,feater.md,hotfixer.md,seo-analyzer.md install.sh: bootstrap script — installs Claude Code CLI, authenticates, sets up shell env vars, then runs link.sh + install-plugins.shhooks/statusline.sh: Claude Code status line configuration hookhooks/rtk-rewrite.sh: RTK hook for code rewritesplugins.lock.json: ctx7, graphifyy, and emil-design-eng entries addedskills-perso: lists personal (user-created) skills from~/.claude/skills/.graphifyignore: excludes gstack submodule and install logs from graphify indexing
Changed
Makefile:installtarget now runsinstall.sh(bootstrap); newplugintarget runsinstall-plugins.shonlyupdate-all.sh: now also updates Claude CLI, ctx7, graphifyy, and marketplace pluginsinstall-plugins.sh: added emil-design-eng skill download step; fixed skill-creator install to useanthropics/skillsmarketplaceskills/: logic extracted from inline SKILL.md into standalone agent.mdfiles — skills now delegate to agentsskills/commit-change/: renamed fromgit-smart-commit; confirmation step removedsettings.json: keys reordered for readabilityCLAUDE.md: added architecture decisions (no SPA for public sites, versioned APIs, security defaults), communication mode (radical honesty), graphify context navigation guidelinesREADME.md: file tree, skill table, install section, plugins.lock section, Makefile targets, update-all description all updated for new skills/agentsUSAGE.md: command table expanded (9 → 18), decision tree restructured with lightweight skill routingversion.txt: 3.3.0 → 3.4.0
Removed
agents/readme-updater.md: replaced byagents/doc-syncer.md(broader scope — all docs, not just README)skills/readme/: replaced byskills/doc/
Fixed
skills-perso: YAML description parsing handles both inline and block formats; detects personal skills via agent reference; excludes framework/gstack skills from listinginstall-plugins.sh: skill-creator install corrected to useanthropics/skillsmarketplace- GStack skill symlinks untracked from git — auto-created by
install-plugins.sh
[3.3.0] — 2026-04-08
Fixed
install-plugins.sh: marketplace org wasanthropic(missing 's') — corrected toanthropicsinstall-plugins.sh: pluginssecurity-guidance,frontend-design,pr-review-toolkitwere installed from non-existent marketplaceclaude-plugins-official— corrected toclaude-code-plugins(fromanthropics/claude-coderepo)install-plugins.sh:skill-creatorplugin does not exist — replaced withplugin-dev@claude-code-plugins(correct plugin name)
Changed
install-plugins.sh: addsanthropics/claude-codemarketplace before installing bundled plugins; install summary updated with correct marketplace sourceslib/detect-plugins.sh: addeddetect_security_guidance(),detect_plugin_dev()functions; removed reference to non-existentdetect_skill_creatorhooks/session-start.sh: addedplugin_devto toggle loop and token cost estimateagents/plugin-advisor.md: all references toskill-creator→plugin-dev; signalskill-creationnow recommendsplugin-dev ONREADME.md: plugin table updated with correct marketplace sources per plugin; new "Marketplaces" subsection documenting all 4 marketplace sources and manual install commands;/plugin-dev:create-pluginreplaces/skill-creatorUSAGE.md: all references toskill-creator→plugin-devversion.txt: 3.2.1 → 3.3.0
[3.2.1] — 2026-04-07
Fixed
agents/plugin-advisor.md: 4 signals had entries in the signal table but no conditional rule — added rules forskill-creation,browser-qa,design-system, andcomplex-arch
Changed
version.txt: 3.2.0 → 3.2.1
[3.2.0] — 2026-04-07
Fixed
doctor.sh: EXPECTED_SKILLS pass message uses${#EXPECTED_SKILLS[@]}(dynamic count) instead of hardcoded 9agents/plugin-advisor.md:setup.pyandpyproject.tomladded as counterindicators for embedded signal — prevents Python C-extensions from false-triggering embeddedagents/status-reporter.md: PHP phpunit added to manifest fallback (composer.json→./vendor/bin/phpunit)skills/health/SKILL.md: post-result guidance added — CRITICAL/WARNING/errors/warnings/all-pass handling
Added
USAGE.md: "Erreurs fréquentes" — embedded signal not detected entry
Changed
version.txt: 3.1.0 → 3.2.0
[3.1.0] — 2026-04-07
Fixed
agents/plugin-advisor.md:Makefilerestored as embedded indicator —Makefile+src/*.c+ no Node/Rust/Go manifest = embedded;.cfiles alone still not sufficient (Rust FFI counterindicated)agents/onboarder.md: PHASE 6 — checkcommand -v gsdbefore generating ROADMAP.md; if absent, ROADMAP.md still generated with install instructions; same pattern as init-project STEP 13
Added
doctor.sh: expected skills check — verifies all 9 skills (analyze, health, init-project, onboard, plugin-check, readme, refactor, ship-feature, status) present in~/.claude/skills/skills/analyze/SKILL.md: description updated to mention DEBUG mode (read-only analysis OR error/stack trace → DEBUG mode)USAGE.md: token cost estimates on workflow patterns (Pattern A ~3000-5000t, B ~1500-2500t/session, D ~500-800t, E ~600-900t); budget note at top of Patterns section
Changed
version.txt: 3.0.0 → 3.1.0
[3.0.0] — 2026-04-07
Fixed
agents/plugin-advisor.md: embedded false positive removed —src/*.calone no longer triggers embedded signal (Rust FFI projects have .c files); onlyplatformio.inior*.ld/*.ldslinker scripts are reliable triggersagents/status-reporter.md: flat awk scoped to## Milestoneheadings — no longer matches## Prerequisites,## Notes, or other non-milestone##headings in ROADMAP.md
Added
agents/status-reporter.md: Go test runner in manifest fallback (go.mod→ "go test ./...")USAGE.md: GSD v2 active/interrupted node in decision tree — /gsd auto, /gsd steer, /gsd forensicsskills/analyze/SKILL.md: argument-hint updated to mention DEBUG mode (pass error/stack trace)
Breaking
agents/plugin-advisor.md: embedded detection no longer triggers on C/C++ files alone — projects relying on .c file detection must addplatformio.inior a*.ldlinker script
Changed
version.txt: 2.9.0 → 3.0.0
[2.9.0] — 2026-04-07
Fixed
agents/plugin-advisor.md: PHASE 1 — filesystem embedded detection added (platformio.ini, .ld linker scripts, src/.c without package.json/Dockerfile); signal description updatedagents/status-reporter.md: PHASE 3 — flat ROADMAP fallback awk command for milestones with tasks directly under ## (no ### slices); marked with "(flat)" in outputagents/status-reporter.md: pytest cache parsing — JSON{}= "all passing" instead of "0 failing"; uses python3 for proper JSON parse instead ofcat | head
Added
USAGE.md: analyze → refactor → analyze cycle documented in decision tree (refactoring profond)README.md: link to USAGE.md in intro section
Changed
version.txt: 2.8.0 → 2.9.0
[2.8.0] — 2026-04-07
Fixed
agents/status-reporter.md: awk milestone detection usesindex()instead of regex negation — portable across macOS nawk and GNU awkagents/status-reporter.md: Tests field fallback improved — shows "run '' to check" when no result found but test manifest exists; shows "N/A" only when no test infrastructure at all
Added
agents/plugin-advisor.md:embeddedsignal added — firmware/bare-metal/microcontroller detection; DECISION TABLE row; conditional rule disabling all toggles, superpowers optionaldoctor.sh: agents pass message now lists all 8 agent names inline for quick visual confirmationUSAGE.md: section "Quel skill utiliser ?" — decision tree for all 9 skills with quick-reference tableREADME.md:/statusadded to Maintenance Diagnostic section alongside/health
Changed
version.txt: 2.7.0 → 2.8.0
[2.7.0] — 2026-04-07
Fixed
agents/status-reporter.md: milestone detection algorithm — usesawkto find first##heading with pending###slices (top-to-bottom scan), nottail -5of all##headingsskills/ship-feature/SKILL.md:git lognow uses--format="%h %<(50,trunc)%s"to truncate long commit messages at 50 chars
Added
agents/status-reporter.md: PHASE 2 — best-effort build/test status check (pytest cache, Jest coverage, log files);Testsfield in outputdoctor.sh:check_symlink "lib"added;_EXPECTED_LINKSupdated 6 → 7agents/plugin-advisor.md:skill-creationsignal added to PHASE 2; WARN rule if skill-creator active without skill-creation signalUSAGE.md: Exemple 9 — firmware C/C++ STM32, workflow minimaliste sans superpowers ni GSD
Changed
version.txt: 2.6.0 → 2.7.0
[2.6.0] — 2026-04-07
Fixed
agents/status-reporter.md: PHASE 3 now counts slices (### headings) not tasks (- [ ]) — correct progress metric matching GSD v2 dashboardhooks/session-start.sh: continuation line uses 13-space prefix (verified 60 bytes) for consistent box alignmentagents/onboarder.md: PHASE 5b clarifies .gitignore target path per mode (A=workspace root, B=PACKAGE_ROOT, C=per-package)
Added
skills/ship-feature/SKILL.md: STEP 0b now prints PROJECT CONTEXT header when CLAUDE.md found — project name, stack, current branch, last 3 commits, GSD milestoneUSAGE.md: Exemple 8 — full session resume workflow with /status + GSD v2 step mode + /gsd discuss
Changed
version.txt: 2.5.0 → 2.6.0
[2.5.0] — 2026-04-07
Fixed
skills/init-project/SKILL.md: STEP 1 — checks bothCLAUDE.mdand.claude/CLAUDE.md; pre-fills interview from either locationagents/status-reporter.md: PHASE 3 GSD — replaced fragileSTATUS.mdread with robust ROADMAP.md checkbox parsing; handles missing ROADMAP.md; never reads binarystate.dbagents/onboarder.md: PHASE 5b added — .gitignore safety check; appends.claude/settings.local.jsonto existing .gitignore or creates minimal one; applies to all monorepo options
Added
doctor.sh: expected agents check in Consistency section — warns if any of 8 expected.mdagent files are missing from~/.claude/agents/README.md+USAGE.md:/statusadded to Pattern B (multi-session) and Pattern C (onboarding) workflowshooks/session-start.sh: 2-line display for >4 active/inactive plugins — all plugin names shown, split at 4 per line
Changed
version.txt: 2.4.0 → 2.5.0
[2.4.0] — 2026-04-07
Fixed
skills/init-project/SKILL.md: STEP 1 — reads existing CLAUDE.md if present; pre-fills interview answers already documented; asks only genuinely missing fieldsagents/onboarder.md: Option B fully implemented — explicit PACKAGE_ROOT scoping; all PHASE 3-5 paths relative to selected package; no root CLAUDE.md generatedagents/plugin-advisor.md: upstream monorepo detection in PHASE 1 — checks../turbo.json,../pnpm-workspace.yaml,../../turbo.jsonfor sub-package context; signal table updated to describe upstream detection
Added
agents/status-reporter.md+skills/status/SKILL.md: new/statusskill — consolidated read-only snapshot (plugins + token cost + git state + recent commits + GSD v2 milestone)USAGE.md: section "Erreurs fréquentes" — quick-reference table of 14 common errors with causes and solutionsdoctor.sh: symlink counter — reportsN/6 OKafter symlink checkshooks/session-start.sh:+N moredisplay — shows first 2 active/inactive plugins + count of remaining instead of truncated stringREADME.md: /status added to skill table and file tree
Changed
version.txt: 2.3.0 → 2.4.0
[2.3.0] — 2026-04-07
Fixed
skills/ship-feature/SKILL.md: STEP 0b added — checks for CLAUDE.md before starting; blocks with/onboardinstruction if missingskills/ship-feature/SKILL.md: STEP 4b option B enhanced — scans remaining tasks for dependents before skipping a failed task; prompts to skip dependent tasks tooagents/onboarder.md: Option C (sequential monorepo onboarding) fully implemented — iterates all packages, generates per-package CLAUDE.md + settings + .claudeignore, summary table, optional root ROADMAP.mdagents/plugin-advisor.md:monoreposignal added to PHASE 1 detection (turbo.json, pnpm-workspace, nx.json), PHASE 2 signal table, DECISION TABLE, and conditional rules — recommends plugins per-package, not for the whole repodoctor.sh:check_symlink "templates"added — detects missing templates/ symlink (pre-v2.0.0 installations)hooks/session-start.sh: ACTIVE_STR and INACTIVE_STR truncated to 37 chars +…indicator when overflow detected
Added
USAGE.md: Exemple 7 — refactoring module Python legacy; full/analyze→/refactor→/analyzecycle; shows report-before-modify behavior and test-first recommendation
Changed
version.txt: 2.2.0 → 2.3.0
[2.2.0] — 2026-04-07
Fixed (bugs identified via case study simulation)
skills/init-project/SKILL.md: STEP 13 — guardcommand -v gsdbefore runninggsd init; prints install instructions if GSD v2 not in PATH instead of failing silentlyskills/ship-feature/SKILL.md: STEP 4b added — structured error recovery when a subagent fails (build error, failing test, type error); DEBUG mode analysis + user gate before any fix; max 2 retry attempts; never auto-patchesagents/onboarder.md: monorepo detection added (PHASE 1) — detectsapps/,packages/,pnpm-workspace.yaml,turbo.json,nx.json,lerna.json; interactive gate (onboard whole workspace / single package / each separately)agents/plugin-advisor.md:mobilesignal added to PHASE 2 signal table + DECISION TABLE + conditional rules — React Native / Expo / Flutter explicitly handled; gstack disabled for mobile, Docker N/Adoctor.sh: GStackskills/subdirectory check added after symlink verification — warns if GStack is symlinked but has no skills (needs./setup)hooks/session-start.sh: TOKEN_WARN truncated to 44 chars to prevent box overflow with emoji width
Added
USAGE.md: Exemple 6 — CLI Rust from scratch; illustrates minimal workflow (superpowers only, no frontend plugins, cargo check as verify, no GSD v2)
Changed
version.txt: 2.1.0 → 2.2.0
[2.1.0] — 2026-04-07
Added
agents/scaffolder.md: React Native/Expo + Flutter support — PHASE 0 (Docker exclusion), PHASE 3 (stack templates), PHASE 4 (install commands), PHASE 5 (verify commands per stack)agents/analyzer.md: DEBUG MODE section — structured error diagnosis with root cause hypotheses, trace, and affected filesagents/onboarder.md: new agent — onboard existing projects (discovery → interview → CLAUDE.md + settings + .claudeignore + optional GSD v2 ROADMAP)skills/onboard/SKILL.md: new skill/onboardinvoking the onboarder agentskills/init-project/SKILL.md: STEP 13 (optional) — propose GSD v2 init at end of init-project when multi-session signal detectedMakefile:make onboardtargetREADME.md: Workflow patterns section (5 patterns: new short, new long, onboarding, hotfix, refactor); /onboard in skill table and tree; make onboard in maintenance
Fixed
agents/plugin-advisor.md: "Next.js + context7 not configured" moved from BLOCK → WARN with force option — Context7 requires manual API key, should not hard-block project startlib/detect-plugins.sh:detect_ruflo()now uses 3-level fallback (npm binary → MCP config grep + ruvnet/claude-flow variants →claude mcp list)hooks/session-start.sh: passive token cost estimate added to session display — warns at >25%, alerts at >50% of Pro session budget
Changed
version.txt: 2.0.0 → 2.1.0
[2.0.0] — 2026-04-06
Breaking
- GSD v1 (
glittercowboy/get-shit-done-cc) removed entirely - GSD v1 commands (
/gsd:discuss-phase,/gsd:plan-phase,/gsd:execute-phase,/gsd:ship,/gsd:next) no longer available — these were Claude Code slash commands; they do not exist in v2 - GSD v2 (
gsd-pi) is a standalone CLI (Pi SDK), not a Claude Code plugin — usage model is entirely different
Added
- GSD v2 integration (
gsd-build/gsd-2, npm:gsd-pi2.64.0) — standalone CLI with autonomous mode (/gsd auto), state machine per-task execution, crash recovery, cost tracking, parallel workers, worktree isolation - Ruflo plugin (
ruvnet/ruflo, npm:ruflo3.5.58) — enterprise multi-agent MCP server (formerly claude-flow), 310+ tools, 100+ agent types, WASM kernel; 🔄 TOGGLE, ~500-1500t passive - Full plugin compatibility matrix in
agents/plugin-advisor.md— all 12 plugins analyzed pairwise, conditional rules, recommended sets by project type - Ruflo auto-detection in
lib/detect-plugins.sh,doctor.sh,hooks/session-start.sh - GSD v2 CLI status in
session-start.sh— dedicated🖥️ CLIline (separate from CC plugin toggles) - 8 new deny rules in
settings.json:source /dev/stdin,mkfifo *,python3 -c *,node -e *,xargs * .env*,tar * .env*,zip * .env*,base64 .env*— covers runtime secret access and exfiltration vectors disableAutoMode: "disable"added to globalsettings.json# TODO: VERIFY syntax in CC v2.1.89templates/symlink inlink.sh—~/.claude/templates/now resolves correctly for scaffolder and init-project- Token budget breakdown in
doctor.sh— CLAUDE.md + skill descriptions + plugin passive cost, thresholds vs Pro session budget (~11k tokens/5h) - GStack pinning warning in
doctor.shandupdate-all.sh(confirmation prompt before--remoteupdate) - GStack false-positive fix in
doctor.sh— submodule check now requires.gitpresence, not just directory existence - Ruflo install instructions in
install-plugins.sh(Step 5, manual — enterprise tool) - Ruflo update step in
update-all.sh - GSD v2 update step in
update-all.sh
Changed
plugins.lock.json: GSD v1 (npm:get-shit-done-cc) → GSD v2 (npm:gsd-pi2.64.0); ruflo (npm:ruflo3.5.58) addedinstall-plugins.sh: STEP 4 GSD v2 (npm install -g gsd-pi), STEP 5 ruflo (manual instructions), steps renumbered 6-7lib/detect-plugins.sh:detect_gsd()now checkscommand -v gsd(not~/.claude/skills/grep);detect_ruflo()addeddoctor.sh: GSD v2 check, ruflo check, GStack false-positive fix, GStack pinning warning, EXPECTED_DENY 92→100, token budget Pro-aware with breakdown,readlink -fportability fixhooks/session-start.sh: GSD v2 removed from toggle loop → dedicated🖥️ CLIline; ruflo added to toggle loopupdate-all.sh: GStack confirmation prompt, GSD v2 update step, ruflo update step, steps renumbered 1-7agents/plugin-advisor.md: complete rewrite — PHASE 1 detection (GSD v2, ruflo), PHASE 2 signal table, full compatibility matrix, conditional rules, recommended sets by project type, WARN/BLOCK updatedlink.sh:templates/added to symlink loopsettings.json: 92→100 deny rules,disableAutoModeaddedREADME.md: comprehensive update — GSD v2 full usage guide, ruflo install/usage, plugin compatibility matrix section, updated plugin table (GSD v2 as CLI, ruflo as TOGGLE), version pinning examples, troubleshooting entries for GSD v2 and ruflo, Known Limitations updatedversion.txt: 1.0.4 → 2.0.0
Fixed
link.sh:templates/not symlinked — scaffolder and init-project now find~/.claude/templates/project-CLAUDE.mddoctor.sh: GStack submodule check was a false positive when directory existed but submodule was uninitialiseddoctor.sh:readlink -ffallback made explicit for BSD macOS compatibilitydoctor.sh: token budget used incorrect "~8000 tokens" reference — now uses Pro session budget (~11k)doctor.sh: EXPECTED_DENY hardcoded at 92 — updated to 100 after new deny rulesupdate-all.sh: GStack update had no confirmation prompt — added; GStack step structure had mismatchedif/fiagents/plugin-advisor.md: GSD detection usedls ~/.claude/skills/ | grep gsd— broken for v2 (CLI not a skill)hooks/session-start.sh: GSD v2 (standalone CLI) was in the CC plugin toggle loop — incorrect, moved to dedicated CLI line
[1.0.4] — 2026-04-05
Fixed
skills/*/SKILL.md: agent paths changed from.claude/agents/to$HOME/.claude/agents/— unambiguous user-scope resolution regardless of working directoryhooks/session-start.sh:CONFIG_VERSIONnow displayed in session-start box (was computed but never shown)settings.json+ templates: removed non-standard_readmekey (silently ignored by Claude Code but triggers schema warnings)agents/plugin-advisor.md: RTK detection re-added in PHASE 1 (was removed in v1.0.3 compression)skills/health/SKILL.md: fallback command simplified — removed 3-level quote nestinginstall-plugins.sh: removed duplicate "→ Restart Claude Code" line
Changed
- README: Superpowers command table now shows actual skill names (
superpowers:brainstorming,superpowers:writing-plans,superpowers:subagent-driven-development, etc.) - README: install step 6 — replaced
/reload-plugins(nonexistent command) with "Restart Claude Code — plugins load automatically" - README: Context7 API key URL corrected from
context7.comtoupstash.com - README: Known Limitations — clarified agent frontmatter fields ARE enforced in v2.1.x; added
disableAutoModenote - README: Makefile command list in Maintenance section now includes
make new-skill lib/detect-plugins.sh:detect_context7()no longer spawnsclaudeCLI — reads~/.claude.jsonand~/.mcp.jsondirectly (no subprocess overhead at session start)
[1.0.3] — 2026-04-05
Token savings (~57% reduction across agents/skills)
CLAUDE.md: 1414t → 418t (-70%) — rewritten as dense rule list, no prose paddingagents/plugin-advisor.md: 1251t → 536t (-57%) — DECISION MATRIX removed (duplicated THRESHOLDS), output template compressedagents/interviewer.md: 1088t → 438t (-60%) — PROJECT BRIEF ASCII art → compact YAML-style, question groups flattenedagents/readme-updater.md: 2224t → 792t (-64%) — Docker detection unified to one block, template skeleton condensed, phases as tight checklistsagents/scaffolder.md: 2402t → 1041t (-57%) — Dockerfile/compose templates replaced by 3-line descriptions, Phase 0 compressedskills/init-project/SKILL.md: 2452t → 915t (-63%) — AGENTS LOADED section removed, each STEP condensed to 2-4 linesskills/ship-feature/SKILL.md: 1236t → 537t (-57%) — same treatment as init-project
Changed behavior
agents/interviewer.md: if prompt already contains name + purpose + stack + features + architecture → generate BRIEF directly, no questions askedagents/readme-updater.md: Docker detection defined once at top, referenced in all modes (no duplication)hooks/session-start.sh: always-on plugins (security-guidance, rtk, superpowers) now explicitly shown in session start displayskills/health/SKILL.md: fallback path when~/.claude/doctor.shnot found (follows CLAUDE.md symlink to locate repo)skills/plugin-check/SKILL.md: argument-hint now shows concrete example
Added
Makefile:make new-skill name=<n>— scaffolds agent + skill files from template in one commandtemplates/project-CLAUDE.md: inline examples per section (FastAPI-based) — usable without /init-project- README: bundled skills section (
/batch,/debug,/simplify) - README: accurate progressive loading explanation (description only at startup, body on-demand)
link.sh: idempotent — reports "already up to date" or count of updated symlinks
[1.0.2] — 2026-04-04
Security
Bash(git add .env*)andBash(git add **/.env*)added to deny — prevents staging secretsBash(cp **/id_rsa*),Bash(cp **/id_ed25519*),Bash(cp **/.ssh/*)added to deny — closes SSH key copy bypassdenytotal: 87 → 92 rulesnpx *moved from allow to ask in project template settings — arbitrary npm package execution now requires confirmationdocker stop *anddocker rm *moved from allow to ask in project template settings
Changed
skill-creatorandpr-review-toolkitreclassified from ALWAYS ON to TOGGLE — saves ~400 tokens/session by defaultagents/scaffolder.md: removed Go, PHP/WordPress, Flutter/Dart stack templates (unused)CLAUDE.md: STRICT MODE section removed — rules inlined intoskills/init-project/SKILL.mdandskills/ship-feature/SKILL.mdwhere they apply, reducing global context weightCLAUDE.md: FAIL FAST MODE cleaned up (removed contradictory "override all" claim)agents/readme-updater.md: mode detection changed from substring match to exact first-word match —/readme update Xno longer silently triggers SYNC modetemplates/settings/SETTINGS.md: stripped sections duplicating README (precedence table, what-goes-where) — 132 → 58 linesplugins.lock.json: removed unusedinstall_cmdandnodefields- README: GStack 14-command table collapsed to a single reference line
- README: plugin table updated to reflect new toggle status
Fixed
install-plugins.sh: GStack./setupnow runs in subshell with existence+executable guard (same fix as update-all.sh)install-plugins.sh: log setup guarded against read-only filesystem — no longer crashes before outputinstall-plugins.sh:rtk init -gnow skipped if RTK hook already present in settings.jsondoctor.sh: CRLF detection ported fromgrep -qP(Linux-only) togrep -c $'\r'(portable macOS/Linux)doctor.sh: token budget breakdown now lists top consumers per file when estimate exceeds 2000 tokenslib/detect-plugins.sh: removed three never-called functions (detect_security_guidance,detect_skill_creator,detect_pr_review_toolkit)hooks/session-start.sh: removed unreachable inline fallback — replaced with clean exit message
[1.0.1] — 2026-04-03
Security
envandprintenv *moved from allow to deny — blocks secret exposure via process environmentexport *added to deny — prevents environment variable injectioncp .env*,cp **/.env*,mv .env*,mv **/.env*added to deny — closes copy-then-read bypass on secret filescp **/secrets/*,mv **/secrets/*added to deny — extends secret move protection to secrets/ directorysed *moved from allow to ask — all sed (including in-place-i) now requires confirmationsed -i *andsed -i'' *removed from ask (consolidated intosed *)
Changed
git stash*(broad allow) split into safe variants in allow (git stash,push*,list*,show*) and destructive variants in ask (pop*,drop*,clear)doctor.shtoken budget estimate now uses full skill/agent file sizes instead of description-only char count — produces accurate token estimates (~4 chars/token)doctor.shdeny rule count now checks against expected value (87) and warns on mismatchdoctor.shpython3 one-liner wrapped in|| echo "?"— diagnosis no longer crashes on missing python3
Fixed
update-all.shGStack./setupnow runs in a subshell — upstream setup failure no longer crashes the update script mid-execution underset -euo pipefailupdate-all.shguards./setupexistence and executable bit before invoking it
[1.0.0] — 2025-04-03
Added
- 6 custom agents: analyzer, interviewer, plugin-advisor, readme-updater, refactorer, scaffolder
- 6 custom skills: analyze, init-project, plugin-check, readme, refactor, ship-feature
- 2 orchestrators with validation gates: init-project (13 steps), ship-feature (8 steps)
- Multi-OS install script (apt/dnf/pacman/brew)
- GStack as git submodule at skills-external/gstack
- Session start hook with plugin toggle status and health check
- Global settings.json with deny/ask/allow permission tiers
- Per-project templates: settings.json, settings.local.json, .claudeignore, project-CLAUDE.md
- Settings reference (SETTINGS.md)
- doctor.sh — full setup diagnostic
- update-all.sh — one-command update for all components
- plugins.lock.json — version pinning for non-marketplace dependencies
- /health skill — run doctor.sh from within Claude Code
- Makefile — unified entry point for install/link/doctor/update
Security
- deny rules cover: destructive commands, secrets access, privilege escalation, code injection (eval, bash -c, xargs), pipe-to-shell, and secrets via bash (cat .env)
- disableBypassPermissionsMode enforced globally
- .claudeignore template with comprehensive exclusions