forked from bchanot/claude
graphify: `graphify claude install` (install-plugins.sh STEP graphify)
writes SKILL.md, references/ and .graphify_version straight into the repo,
because ~/.claude/skills is a symlink to skills/. Every `pipx upgrade
graphifyy` therefore dirtied the tree and cost a `chore(graphify): sync
vendored skill X -> Y` commit. Now gitignored and untracked; a fresh clone
gets them back from `make plugin`. test-prompts.json is hand-written for
darwin and stays tracked. The accepted trade-off, documented in CLAUDE.md,
is that an upstream release can change the skill's prompt with no diff to
review.
settings.local.json (gitignored, so not in this commit) went from 14.6 KB
to 6.2 KB. It was a near-complete shadow copy of the global settings at a
higher precedence tier, which hid its own drift until the global moved.
Two entries were actively defeating BDR-090, merged an hour earlier:
- local `deny` still carried rsync / kill -9 / killall / pkill, the four
rules deliberately moved out of global deny. deny wins across sources,
so autoMode.soft_deny was a dead letter in this repo.
- local `allow` carried `sed *`, `cp *` and `python3 -`. An allow rule
short-circuits the classifier, punching a hole through the same
soft_deny rules.
deny and ask are dropped whole (102 and 27 of their entries duplicated the
global; ask gates nothing under defaultMode auto). allow went 185 -> 98:
81 duplicates plus six policy conflicts, the three above and
Read(//home/bchanot/**), WebSearch, and a leftover command-injection test
payload that had been allowlisted verbatim. Every non-permissions key was
a verbatim copy of the global, including a hooks block whose only original
entry pointed at hooks/config-protection.sh, a script that exists nowhere.
179 lines
4.9 KiB
Plaintext
179 lines
4.9 KiB
Plaintext
# ── claude-config repo ignores ──
|
|
|
|
# GStack skill symlinks — auto-created by gstack setup
|
|
# Only the gstack/ dir itself + all symlinked skills inside skills/
|
|
skills/gstack
|
|
skills/autoplan
|
|
skills/benchmark
|
|
skills/browse
|
|
skills/canary
|
|
skills/careful
|
|
skills/codex
|
|
skills/connect-chrome
|
|
skills/cso
|
|
skills/design-consultation
|
|
skills/design-html
|
|
skills/design-review
|
|
skills/design-shotgun
|
|
skills/devex-review
|
|
skills/document-release
|
|
skills/freeze
|
|
skills/gstack-upgrade
|
|
skills/guard
|
|
skills/health
|
|
skills/investigate
|
|
skills/land-and-deploy
|
|
skills/learn
|
|
skills/office-hours
|
|
skills/open-gstack-browser
|
|
skills/pair-agent
|
|
skills/plan-ceo-review
|
|
skills/plan-design-review
|
|
skills/plan-devex-review
|
|
skills/plan-eng-review
|
|
skills/qa
|
|
skills/qa-only
|
|
skills/retro
|
|
skills/review
|
|
skills/setup-browser-cookies
|
|
skills/setup-deploy
|
|
skills/ship
|
|
skills/unfreeze
|
|
skills/benchmark-models
|
|
skills/context-restore
|
|
skills/context-save
|
|
skills/make-pdf
|
|
skills/plan-tune
|
|
skills/spec
|
|
skills/document-generate
|
|
skills/landing-report
|
|
skills/scrape
|
|
skills/setup-gbrain
|
|
skills/skillify
|
|
skills/sync-gbrain
|
|
# iOS device-farm skills (need a Mac daemon + Tailscale + iOS devices) —
|
|
# not linked on this Linux host; ignored so they stay out of git if a
|
|
# future gstack setup on a Mac host materializes the symlinks.
|
|
skills/ios-clean
|
|
skills/ios-design-review
|
|
skills/ios-fix
|
|
skills/ios-qa
|
|
skills/ios-sync
|
|
|
|
# External skill symlinks — auto-created by link.sh
|
|
skills/design-motion-principles
|
|
skills/emil-design-eng
|
|
skills/frontend-design
|
|
skills/impeccable
|
|
|
|
# External skills installed via `npx skills add` — auto-created by link.sh
|
|
skills/darwin-skill
|
|
|
|
# Context7 docs-lookup skill — installed by `ctx7 setup --claude --cli`
|
|
# (install-plugins.sh Step 6, when absent) into ~/.claude/skills (a symlink to
|
|
# this repo's skills/). ctx7-managed and re-created on demand — not vendored here.
|
|
skills/find-docs/
|
|
|
|
# Context7 rule — (re)written by the same `ctx7 setup` into ~/.claude/rules (a
|
|
# symlink to this repo's rules/). ctx7-managed — not vendored here.
|
|
rules/context7.md
|
|
|
|
# Staging area used by lib/toggle-external.sh when disabling a tool
|
|
skills-disabled/
|
|
|
|
# Local project config (per-machine, not shared)
|
|
.claude/*
|
|
!.claude/tasks/
|
|
!.claude/memory/
|
|
!.claude/audits/
|
|
!.claude/settings.json
|
|
# But keep local stuff ignored within .claude/
|
|
.claude/settings.local.json
|
|
.claude/agent-memory/
|
|
.claude/gstack/
|
|
.audit/
|
|
|
|
# Generated outputs
|
|
graphify-out/
|
|
.ctx7-cache/
|
|
|
|
# graphify's vendored skill — written into the repo by `graphify claude
|
|
# install` (install-plugins.sh STEP graphify), since ~/.claude/skills is a
|
|
# symlink to skills/. Untracked so a tool upgrade stops dirtying the tree.
|
|
# test-prompts.json is hand-written for darwin and stays tracked.
|
|
skills/graphify/SKILL.md
|
|
skills/graphify/references/
|
|
skills/graphify/.graphify_version
|
|
|
|
# /client-handover test artifacts (project-local renders)
|
|
LIVRAISON.md
|
|
LIVRAISON.html
|
|
LIVRAISON.pdf
|
|
HANDOVER.md
|
|
HANDOVER.html
|
|
HANDOVER.pdf
|
|
|
|
# Install logs
|
|
install-*.log
|
|
|
|
# Local secrets (MCP API keys etc.) — real key lives in ~/.claude/.env;
|
|
# repo/.env is a symlink to it (created by link.sh). Never commit the secret.
|
|
.env
|
|
.env.*
|
|
!.env.example
|
|
|
|
# seo-data engine local artifacts (live under ~/.claude, never committed)
|
|
.venv-seo-data/
|
|
seo-data/tokens.json
|
|
__pycache__/
|
|
|
|
# OS
|
|
.DS_Store
|
|
Thumbs.db
|
|
desktop.ini
|
|
|
|
# Editors
|
|
*.swp
|
|
*.swo
|
|
*~
|
|
*.bak
|
|
.idea/
|
|
.vscode/
|
|
|
|
# Profile cache — written by lib/profile.sh, read by hooks/statusline.sh
|
|
.active-profile
|
|
.gstack/
|
|
|
|
# Frontend Design (Anthropic) — installed/refreshed from the example-skills
|
|
# plugin cache by install-plugins.sh (Step 8b) and update-all.sh on every run.
|
|
# Not vendored: tracking it produced a repo diff each time Anthropic shipped
|
|
# an update. The source is always re-synced, so no offline copy is needed.
|
|
skills-external/frontend-design/
|
|
|
|
# Emil Design Eng — machine-owned copy curl'd from emilkowalski/skill by
|
|
# install-plugins.sh (Step 8, when absent) and re-fetched on every update-all.sh
|
|
# run. Not vendored: tracking it produced a repo diff each time upstream shipped
|
|
# an edit. The source is always re-fetched, so no offline copy is needed.
|
|
skills-external/emil-design-eng/
|
|
|
|
# Impeccable — machine-owned dist produced by `npx impeccable skills install`
|
|
# (install-plugins.sh Step 8d, update-all.sh), pinned in plugins.lock.json.
|
|
# Not vendored: the installer owns the layout and rewrites it on update
|
|
# (ctx7 pattern). Symlinked into skills/ by link.sh.
|
|
skills-external/impeccable/
|
|
|
|
# npx `skills add` project-scope artifacts — darwin-skill copies itself into
|
|
# the repo's .agents/ and writes skills-lock.json at root. Our own agents live
|
|
# in agents/ (no dot) and stay tracked. Anchored to root so only the dotted
|
|
# pollution dir is ignored.
|
|
/.agents/
|
|
/skills-lock.json
|
|
|
|
# deploy: transient per-deploy state (the runbook/ledger/oracle ARE committed)
|
|
.claude/deploy/NEXT.sh
|
|
.claude/deploy/PENDING.json
|
|
|
|
# ── gitflow standard socle (added by gitflow_init; additive, safe to edit) ──
|
|
*.log
|
|
!.claude/deploy/
|