forked from bchanot/claude
When `claude` is unreachable, the plugin/MCP checks (magic, ui-ux-pro-max — the most important design tools) return `unknown`. The old verdict folded that into a silent `READY` exit 0 — a fail-OPEN: the gate granted "proceed" exactly when it had verified nothing. Contradicts the fail-closed-on-uncertainty rule. Now fail-VISIBLE (not strict fail-closed — claude can be merely slow, false blocks would get the gate ignored): a third outcome READY BUT UNVERIFIED with a distinct exit 11. It proceeds, but says so loudly and names the unchecked tools, telling the user to confirm with `claude mcp list` / `claude plugin list`. The distinct non-zero code also stops a naive `if gate; then proceed` shell caller from silently passing. Also covers the non-reproducible "transient claude absent after apply" flake seen in live testing. design-gate.md §DECISION updated: exit-code line + a real branch-3 state for 11. Verified: shellcheck clean; reachable+active -> READY exit 0; claude off PATH -> READY BUT UNVERIFIED exit 11 naming magic+ui-ux-pro-max; magic off -> INCOMPLETE exit 10 (trip branch intact after the restructure). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>