Skip to content

disk-hygiene:clean — audit of a real home-directory run (Windows, v0.23.3): 726 bytes engine-eligible against ~60 GB product-managed; 9 decisions and 1 bug #4004

Description

@kyle-sexton

Drafted by an AI agent from an operator-confirmed interview (run 20260908-home-d1).

plugins/disk-hygiene, skill clean, v0.23.3. Windows 11, PowerShell 7 + Git Bash, Claude Code on Fable 5.1.

The run

  • Target: C:\Users\KyleSexton, the whole home directory.
  • Mode: audit, then approval, landing in the manual handoff lane because the engine reports execution-platform-unsupported on Windows.
  • 30 engine scans, 46 snapshots, 3 fan-out subagents (~550k subagent tokens).
  • 5 handoff-verify runs and 5 model-composed PowerShell deletions.
  • Depth-1 frontier: 81 entries, 0 hinted, 4 empty directories, 48 subtrees truncated at depth 1 and fanned out below.
  • Hint coverage across all 46 snapshots: 570 hinted of 15,042 inventoried entries (3.8 %). 538 of the 570 were common-temp-file / atomic-write-staging-remnant inside AppData\Local\Temp. None changed a disposition.
  • Scan errors: none, in any of the 30 scans.

Outcome: 5 Medium-tier unmanaged paths recycled, 726 bytes, 3 of the 5 empty directories. Roughly 60 GB was identified in product-managed state and handed off as native commands the engine is designed never to run. No High-tier finding.

The safety machinery was correct throughout. Every path was verified clear immediately before its own deletion, nothing was skipped, nothing was wrongly deleted. What this umbrella tracks is the ratio, and the shape it implies: 30 scans, 3 subagents and ~550k tokens produced 726 engine-eligible bytes, while the disk's actual bulk sat in managed state the component can see, can size, and has no lane for handing off.

Decisions

Nine questions were put to the operator after the run and answered. Q3 and Q8 were answered together, so eight rows cover the nine.

Q Decision Child
Q1 Scope stays unmanaged residue, unchanged. Add a gated managed-state lane driven by a bundled owner registry (owner, read-only dry-run command, destructive native command), the destructive command under the same tier-and-exact-list approval as the engine lane. #4006
Q2 Build an engine-native Windows Recycle Bin apply (IFileOperation with the recycle flag, snapshot token, bottom-up per-entry revalidation as on Linux), refusing a path the bin cannot take rather than falling through to a permanent delete. #4007
Q3 + Q8 Persist a catalog: catalog.json plus a rendered CATALOG.md under the plugin data root, one record per catalogued entry with identity, owner, provenance narrative, evidence with sources, disposition, tier, size, run stamps and source. A record is a hint, never authorization. #4008
Q4 Add scan --sizes-only (full walk, no per-entry inventory, no entry cap, exact children_rollup in one pass) and ship the fan-out worker brief as a skill reference file. #4009
Q6 Catalog scope: every immediate child of the target, every hinted or empty entry at any depth, every entry flagged out of place. Deeper entries catalogue at owner level. Nothing that looks out of place is skipped. #4008
Q7 Investigation procedure: the skill ships a required local procedure per catalogued entry, escalating to /discovery:research only when the local procedure finds no owner. #4008
Q9 Unknowns: the report ends with one question per entry whose owner is still unknown; the operator's answer is written back into the catalog as human-sourced provenance and not asked again while identity holds. #4008
Q5 Filing: one umbrella per run in the #3347 pattern, one child per item, each child linking the existing issue it overlaps rather than duplicating it. this issue

Q3, Q6, Q7 and Q9 are one build and share one child.

Bug found this run

Item Child
same_stat_identity compares a directory's st_size, so preview and handoff-verify flapped drifted / clear across five consecutive runs on an unchanged empty directory (Windows NTFS). #4005

Smaller items

Item Child
os_autoclean.recommendation stayed null with AppData\Local\Temp at 7.0 GB and Storage Sense enabled weekly. #4010
preview exits 3 on Windows when the only blocker is execution-platform-unsupported, making the skill's mandatory preview step a guaranteed failure. Superseded if #4007 lands. #4011
handoff-verify exits 3 once any approved path is gone, so every round after the first reads as a failure. #4012
--quiet still prints the full truncated_paths list, about 140 lines on a depth-2 home scan. #4013

Not filed: the Bash belt denied mkdir, git, and the planning plugin's own gate script for the rest of the session. That is a live reproduction of #3856 and #2591 (closed), not a new issue.

Existing issues this run overlaps

Open: #3347 (the ceremony umbrella this one follows), #3351 (handoff-verify --path), #3855 (proportionality decision carrier), #3856 (belt escape hatch), #3857 (per-primitive platform gates), #3858 (ranking signals, hint coverage), #3860 (managed-state exclusion).

Closed: #3352 (--quiet), #2591 (belt denies read-only commands), #2595 and #2850 (Recycle Bin spelling in the belt), #228 (OS auto-clean awareness), #1109 (handoff-verify origin), #2851 (per-immediate-child roll-up).

Each child names the ones it touches and states why it is not a duplicate.

Evidence

The interview summary, the full audit report and all 46 snapshots live in the operator's plugin data directory under disk-hygiene-melodic-software/runs/20260908-home-d1/. They are not pasted here; each child quotes the specific figures it rests on.

Limits of this run

  • Single platform (Windows), single target, single operator.
  • The engine apply lane was never exercised; all five deletions went through the manual handoff lane.
  • Engine target_reclaimable_local_bytes for .aspire, Saved Games, claude-lane-sandbox, .cache\huggingface, .bun\install and all of AppData are floors because of depth cuts. Every managed-state size quoted in the report came from a read-only PowerShell recursion outside the engine.
  • Eight protected shell roots, .claude below depth 2, and a list of AppData subtrees were never walked and are recorded as coverage gaps, not as clean.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    work-class: read-onlyAudits, research, reports. No repository mutation; tracker and queue writes only.work-mapDecision map container for /planning:wayfind; sub-issues are its typed decision items.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions