Skip to content

fix(instruction-placement): align /memory claims, consolidate cutover records, neutralize owner-decision records - #5285

Merged
kyle-sexton merged 13 commits into
mainfrom
fix/audit-instruction-placement
Sep 30, 2026
Merged

kyle-sexton merged 13 commits into
mainfrom
fix/audit-instruction-placement

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

No related issue: audit remediation; #4281 is a standing tracker, #4282 was closed after its canary ran, #4283 and #5163 stay open for owner decisions.

Refs: #4281
Refs: #4282
Refs: #4283
Refs: #5163

Summary

Fixes the instruction-placement findings from the audit of the 2026-09-27..29 agent PRs (.work/audit/REPORT.md rows 3a #4281, 3b/3c #4281, 3d #4282 and #4283), and records the #4282 CI canary the owner chose (Option B). Nothing here closes an issue: #4281 is a standing tracker, #4282 was closed on the issue once the canary ran, and #4283 is an owner decision the agent had taken on its own.

Fix

Verification

  • scripts/check-changelog-parity.sh --check --check-order: passes.
  • scripts/validate-plugins.sh: all manifests and the catalog validated.
  • scripts/check-skill-portability.sh origin/main: no unexcused coupling tokens.
  • All 11 plugins/instruction-placement/**/*.test.sh suites: exit 0 (cutover-check.test.sh 73 checks after the canary record).
  • Fresh read-only cutover-check.sh over the ten in-scope repositories (CLI 2.1.284): exit 0, every graded condition MET; the per-condition table goes on [Maintenance] Run /instruction-placement:migrate cutover-check #4281. Not re-run after the canary record; the grade note says so.
  • Canary: https://github.com/melodic-software/knowledge-corpus/actions/runs/36666844023 (workflow_dispatch, pin 756cc22e19660d20e8cc9496b4f242475a7f7790); branch test/agents-md-ci-canary deleted afterwards.
  • origin/main merged into the branch (clean, no conflicts).

Related

🤖 Generated with Claude Code

kyle-sexton and others added 5 commits September 29, 2026 01:30
…lity claims with the memory page

migrate/SKILL.md said a directly read AGENTS.md does not appear in /memory, which contradicts
its own record and sources.md: /memory lists it from v2.1.280. Rewrite that sentence to the
current record and point at sources.md for the version detail.

Re-fetched the memory page; its AGENTS.md sections match the records. Refresh the four-part
copies in README, check, setup, verified-mechanics, render-index.sh and migrate, and replace
the vague "unavailable in some sessions" with a pointer to "The minimum CLI version". Reword
the shim-deletion eval to the current record without changing its routing expectations.

Refs #4281

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
… Write payload

The minimal-payload case exits at the hot-path guard, so the advisory abort
boundary was never exercised on a payload that reaches the hook body. Rename it
as the hot-path case and add drifted and in-sync rules-tree cases that assert
exit 0, empty stderr, and the stale notice on the drifted repo.

Refs #3713

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…md and make the #4282/#4283 records decision-neutral

Merge the three fleet-grade sections into a single four-part Current fleet
grade record (ten repositories, graded 2026-09-29) and move the per-run
commit tables to the tracker comment. Mark condition 2 provisional: its
CI-canary component rests on the v1.0.231 run and a re-run is an open owner
decision. Replace the Canary host and install-dependent loader test records
with four-part records that name the pending owner decisions and drop the
encoded options.

Refs #4281, #4282, #4283, #5163

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

PR body contract — issue linkage

This PR body conforms to the issue-linkage contract. Nothing to do.

kyle-sexton and others added 3 commits September 29, 2026 02:00
…fier review

Drop the false "not logged in" reason from the displacement canary basis,
point the fleet grade record at the comment on #4281, re-wrap one long line,
and refresh the memory and hooks page records to the 2026-09-29 fetch.

Refs #4281

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…ext sections

Every hook row launches through node hooks/exec-bash.mjs, so without node the
index-drift hook does not run. Add Node.js to the README requirements and a node
probe to setup check. audit, check and delta name realign in a Next section.

Refs #4281

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
…-grade basis

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T13:49:36.130068Z bdc59f3 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 21s —— View job


Code review — PR #5285

  • Gather context
  • Invoke /review:code-review per custom instructions
  • Post inline findings (none — see below)
  • Summarize in this comment

Scope reviewed: all 13 changed files (git diff origin/main...HEAD), per the code-review lane's correctness/maintainability/CLAUDE.md-alignment criteria.

Findings: none that clear the high-signal bar. No inline comments posted.

What I checked in detail:

  • hooks/index-drift.test.sh: the new idx_body_case helper and its two call sites correctly exercise the hook body past the hot-path guard (payload targets .claude/rules/csharp.md, which matches the guard's */.claude/rules/*.md case). It uses file-fed stdin (<"$dir/body.in") rather than a pipe, consistent with the file's own Shell test suites pipe a payload into hooks that exit before reading stdin, so pipefail fails them intermittently #4458 note about pipe/SIGPIPE issues elsewhere in the suite. $repo's "in-sync" state at the point of the no-stale call is genuinely in sync (rendered earlier in the file via render-index.sh write), so the assertion is sound, not accidentally passing.
  • hooks/hooks.json: confirmed the new README/setup claim that every hook row launches via node hooks/exec-bash.mjs — there's exactly one row, and it does.
  • skills/migrate/reference/sources.md: cross-checked the new "Current fleet grade" claim (condition 2, medley's v1.0.231 → CLI 2.1.278, "at or above 2.1.277") against the unmodified release-map table above it — consistent. The consolidated "Canary host (CI canary: verify a lone AGENTS.md loads on a fresh-install claude-code-action run #4282)" and "Install-dependent loader tests (Install-dependent loader tests for Cursor, Grok Build, and Muse Code #4283)" sections read as genuinely pending-decision framing (no more "Option A taken"), matching the PR description.
  • skills/{audit,check,delta}/SKILL.md: the new ## Next sections comply with .claude/rules/skill-bodies-state-current-rules.md — placed immediately before ## Gotchas, exactly one /instruction-placement:realign invocation line plus an explanatory sentence.
  • CHANGELOG.md / plugin.json: version bump (0.15.21 → 0.15.22) and changelog entries match the diff's actual content.
  • Dated four-part records touched by this PR (README, check, setup, migrate, verified-mechanics.md) now point at sources.md's "The minimum CLI version" instead of restating the CLI-floor specifics inline — reduces duplication of a volatile fact rather than adding drift risk.

Not independently verified: the auto-mode permission classifier for this lane declined to run shell/python commands beyond read-only git (bash scripts/check-changelog-parity.sh …, python3 -c "json.load(...)", etc. were all denied). I did not re-run check-changelog-parity.sh, validate-plugins.sh, check-skill-portability.sh, the plugin's own test suites, or cutover-check.sh. The PR body's Verification section describing those runs is author-claimed and unverified by me.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 19s —— View job


Security review complete

  • Gather context (PR diff, changed files)
  • Check skip-gate conditions
  • Review diff for security-relevant surface, incl. instruction-surface deletions
  • Post findings

No security issues found.

Scope reviewed: all 13 changed files (git diff origin/main...HEAD). This PR is documentation/test-only: /memory claim corrections across migrate, check, setup, verified-mechanics.md, README.md, render-index.sh, a node prerequisite check added to setup, ## Next pointers, a test that now exercises the index-drift hook body instead of exiting at the hot-path guard, and a large prose consolidation in skills/migrate/reference/sources.md. No script logic, hook logic, workflow files, or permission/config surfaces changed.

Instruction-surface deletion lens (specifically checked): sources.md drops the Canary host decision (#4282) and Install-dependent loader tests parked (#4283) sections' "Option A (taken) / Option B (declined)" framing — including the explicit "Do not unarchive claude-lane-sandbox" / "Do not create a throwaway host" / "Do not install those tools" bullets — in favor of "pending an owner decision on #4282/#4283" language. Two reasons this isn't a finding:

  • The candidate actions this record used to name (touching another repository, standing up a fleet host) are already gated by this repo's root AGENTS.md "When to stop and when to keep going" stop-and-ask list, which any session in this tree loads independently of sources.md, plus Claude Code's baseline confirm-before-CI/infra-change behavior. The mechanism that actually blocks the action survives; only a redundant restatement was removed.
  • The removed framing was itself the finding the PR is fixing, not a guardrail worth keeping: it was an agent's own prior "Option A taken" decision written into a reference doc as if authoritative on an owner call, and the PR body says so directly (#4282 and #4283 are owner decisions the agent had taken on its own). Replacing it with explicit "pending an owner decision" text is a correction toward the agent-authority class, not away from it.

Parsed-record integrity: cutover-check.sh (unchanged in this diff) only parses three sources.md sections — ## The minimum CLI version, ## The CI canary, and ## `claude-code-action` release to installed CLI version — via fixed awk/grep section extraction. None of those headers or their parsed fields (version floor, canary run id, release-map table) were restructured here; only fetch dates/byte counts were refreshed, consistent with a real re-fetch. The consolidated/removed sections (Accessible fleet graded, Standing refresh (#5163), This-repo cutover run (#4281)) are narrative history the script never reads, so the remove-shims gate's actual enforcement is unaffected.

GitHub Actions hardening (triggers, permissions:, pin provenance) is out of scope for this lane and none of the changed files are workflow files regardless.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bdc59f3494

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/instruction-placement/skills/migrate/reference/sources.md Outdated
Comment thread plugins/instruction-placement/skills/delta/SKILL.md Outdated
kyle-sexton and others added 2 commits September 29, 2026 10:34
A quiet delta run has nothing for realign to apply, so the Next section
names realign only when findings moved.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 56s —— View job


Task list

  • Gather context (PR diff, changed files, custom instructions)
  • Invoke /review:security-review per custom instructions and follow it exactly
  • Post findings

Security review complete

No security issues found.

Scope reviewed: the full PR diff, git diff origin/main...HEAD (13 files), with particular attention to what changed since the prior two security-review runs on this PR — the branch was re-synced with origin/main and one new commit landed, 46b8896, which splits the delta skill's ## Next section into two outcome-dependent bullets (findings-moved → realign; quiet-run → none) in response to Codex's P2 comment.

New commit checked under the instruction-surface lens: this change adds routing prose only — it does not remove, narrow, or soften any standing rule, permission, or guardrail. The ## Hard rules section immediately above (Never resurrect a declined finding, Never suppress silently, Never re-classify an unchanged finding, etc.) is untouched. No finding.

Confirmed unchanged from the prior reviews on this PR (still holds against the current head):

  • sources.md's consolidation of the #4282/#4283 "Option A taken / Option B declined" framing into "pending an owner decision" text removes a redundant restatement, not the controlling guardrail — the actions it used to name (unarchiving a sandbox repo, standing up a fleet host, installing untested tools) are still gated by this repo's root AGENTS.md stop-and-ask list, which loads independently of sources.md.
  • cutover-check.sh (unchanged in this diff) only parses three fixed sources.md sections via awk/grep; none of those headers or their parsed fields were restructured, so the remove-shims gate's enforcement is unaffected by the narrative consolidation.
  • hooks/index-drift.test.sh's new idx_body_case cases build hook stdin from fixed, non-attacker-controlled paths (.claude/rules/csharp.md) — no injection surface.
  • No script logic, hook logic, workflow files, or permission/config surfaces changed anywhere in the diff; the remainder is documentation and a version/changelog bump.

GitHub Actions hardening is out of scope for this lane and no workflow files are part of this diff.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 53s —— View job


Code review — PR #5285

  • Gather context
  • Invoke /review:code-review per custom instructions
  • Post inline findings (none — see below)
  • Summarize in this comment

Scope reviewed: full diff at HEAD 46b8896 (gh pr diff 5285, all 13 changed files), per the code-review lane's correctness/maintainability criteria. This head adds one commit past the last review (bdc59f3): 46b8896, touching only skills/delta/SKILL.md.

Findings: none that clear the high-signal bar. No inline comments posted.

What changed since the last review, and what I checked:

  • skills/delta/SKILL.md — this commit resolves Codex's P2 finding (unconditional ## Next pointing at the mutating realign skill even on a quiet run with nothing to apply). The ## Next section now has two outcome bullets: "Findings moved" → /instruction-placement:realign, "Quiet run" → none. This matches .claude/rules/skill-bodies-state-current-rules.md's "two to four bullets of <outcome>: /plugin:skill [args]." form for outcome-dependent successors, and is consistent with the file's own "a quiet run is the expected outcome, not a failed one" gotcha a few lines above.
  • Re-checked hooks/index-drift.test.sh's new idx_body_case cases against hooks/index-drift.sh's hot-path guard (*/.claude/rules/*.md) — both fixture paths correctly reach the hook body rather than short-circuiting, so the "in-sync → empty stdout" and "drifted → stale notice" assertions are exercising what they claim to.
  • Checked for dangling references to the four sources.md sections this PR collapses (Canary host decision, Accessible fleet graded, Standing refresh, This-repo cutover run, Install-dependent loader tests parked) — only one hit, an unchanged historical CHANGELOG.md entry under [0.15.21] (Standing refresh — not a live link, no action needed).
  • Verified the new ## Canary host (#4282) and ## Current fleet grade anchors (#canary-host-4282, #the-ci-canary) resolve correctly under GitHub's heading-to-anchor rules.
  • hooks/hooks.json still backs the new README/setup claim that every hook row launches via node hooks/exec-bash.mjs.
  • skills/setup/SKILL.md's renumbered prerequisite list (1–5, node inserted as 3) is internally consistent; no other file references the old numbering.

I considered but did not raise two points, on the reasoning below — flagging here in case it's useful:

  • Codex's P1 finding (sources.md:154, condition 2 graded [MET] while the CI-canary is stale/pending) is about cutover-check.sh's condition_2() logic, which this PR does not touch — it only rewords the record from "Option A taken" (settled) to "pending an owner decision" (the PR's stated purpose). The doc now accurately describes existing, unchanged script behavior; the gap between "pin arithmetic says MET" and "canary is stale" predates this PR.
  • delta/SKILL.md's new "Quiet run: none." bullet doesn't literally fit the convention's <outcome>: /plugin:skill [args]. grammar (no skill invocation) — it's the first "no successor" outcome bullet in the repo (checked; no other ## Next has this shape). Reads as a reasonable, unambiguous extension of the convention's intent rather than a defect worth blocking on.

Not independently verified: I did not re-run scripts/check-changelog-parity.sh, scripts/validate-plugins.sh, scripts/check-skill-portability.sh, the plugin's test suites, or cutover-check.sh — the sandbox's command approval declined python3/scoped git show/git status calls during this pass. The PR body's Verification section is author-claimed and unverified by me.
· branch fix/audit-instruction-placement



Case A at claude-code-action v1.0.235 (CLI 2.1.283) loaded a lone
AGENTS.md in both sessions: knowledge-corpus run 36666844023. The CI
canary, Canary host and Current fleet grade records name that run in
place of the pending owner decision, and cutover-check.test.sh expects
the new run id. The CHANGELOG entry for 0.15.22 is extended, not bumped.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
kyle-sexton and others added 2 commits September 30, 2026 00:09
…-placement

Take main's 0.16.0 and bump to 0.16.1 with this PR's changelog entry on top.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 35s —— View job


Task list

  • Gather context (PR diff at HEAD, custom instructions)
  • Invoke /review:security-review per custom instructions and follow it exactly
  • Post findings

Security review complete

No security issues found.

Scope reviewed: full diff at HEAD b9b722d (gh pr diff 5285, all 14 changed files). Three commits landed since the last security-review pass on this PR (at 46b8896): 112545b (records the real #4282 canary run in sources.md), 275b444 (merge of origin/main, no net content beyond what's already reflected in the PR diff), and b9b722d (empty, CI-retrigger only, git show --stat confirms zero files changed).

New commit checked under the instruction-surface lens: 112545b rewrites sources.md's ## The CI canary, ## Canary host (#4282), and ## Current fleet grade records to name a real knowledge-corpus run (36666844023, claude-code-action v1.0.235, CLI 2.1.283) in place of the previous "pending owner decision" text. This is the resolution of Codex's P1 finding on this PR, not a new instance of it: that finding warned that grading cutover condition 2 [MET] off a stale run (35475056935 at the older v1.0.231 pin) operationally decided the pending #4282 question by default. The new record replaces the stale evidence with a run genuinely taken at the current pin, so the gap the finding described no longer exists.

Parsing verified independently (not just read as prose): cutover-check.sh's section() helper (plugins/instruction-placement/skills/migrate/scripts/cutover-check.sh:205-207) bounds ## The CI canary at the next ## heading via awk, and CI_CANARY_RUN (line 222-223) takes the first run `[0-9]{6,}` match with head -n 1. Within the rewritten section, run `36666844023` (the new run) appears before the later The earlier run `35475056935` reference, so the script correctly parses the new run id — matching cutover-check.test.sh's updated assertion. No ambiguity or wrong-value risk from having two run ids in the same section.

Confirmed unchanged from the prior three reviews on this PR (still holds against the current head):

  • sources.md's consolidation of the #4282/#4283 "Option A taken / Option B declined" framing removes a redundant restatement, not a controlling guardrail — the actions it used to name (unarchiving a sandbox repo, standing up a fleet host, installing untested tools) are still gated by this repo's root AGENTS.md stop-and-ask list, independent of sources.md.
  • cutover-check.sh itself is unchanged in this diff; only the three fixed sections it parses (## The minimum CLI version, ## The CI canary, the release-map table) had their content refreshed, never restructured.
  • hooks/index-drift.test.sh's new idx_body_case cases use fixed, non-attacker-controlled paths — no injection surface.
  • No script logic (besides the parsed-data refresh above), hook logic, workflow files, or permission/config surfaces changed anywhere in the diff.

GitHub Actions hardening is out of scope for this lane and no workflow files are part of this diff.
· branch fix/audit-instruction-placement

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 16s —— View job


Code review — PR #5285

  • Gather context
  • Invoke /review:code-review per custom instructions
  • Post inline findings (none — see below)
  • Summarize in this comment

Scope reviewed: the full diff at HEAD b9b722d (gh pr diff 5285, all 14 changed files vs origin/main), with focus on what changed since the last full review on this lane (commit 46b8896, 2026-09-29T14:41:56Z):

Findings: none that clear the high-signal bar. No inline comments posted.

What I checked on 112545b, since it resolves Codex's earlier P1 (sources.md:154, "block removal while the CI-canary decision is pending"):

  • cutover-check.sh's section() helper (skills/migrate/scripts/cutover-check.sh:205-206) extracts text strictly between the ## The CI canary heading and the next ## heading, so it never reads into ## Canary host (#4282). Within that section, CI_CANARY_RUN_ID (cutover-check.sh:223) takes the first run `NNNNNN` match via head -n 1. In the new "Basis" paragraph, the first such match is run `36666844023` (the new run); the older earlier run `35475056935` appears later in the same paragraph and is correctly not picked up. This matches the doc's own updated claim ("it parses the first run id in this section").
  • Since the new canary run is recorded at v1.0.235 (the pin condition_2 actually resolves against the in-scope fleet), the record no longer describes a stale canary sitting behind a newer pin — the specific gap Codex's P1 flagged is closed by this commit, not routed around it.
  • sources.md's "Canary host (CI canary: verify a lone AGENTS.md loads on a fresh-install claude-code-action run #4282)" section now states the owner's decision and the run outcome as settled fact ("the owner chose... and the run passed"), consistent with Kyle's own resolving comment on the thread, and no longer frames this as a still-open agent-side option A/B choice.
  • The cutover-check.test.sh diff is a single literal swap (old run id → new run id) against the test's own synthetic fixture data; it doesn't touch the CLI-version assertion on the same block, which is unrelated (it's the test's mocked pin, not tied to the real fleet's CLI floor).

Not independently verified: this lane's auto-mode permission classifier declined bash scripts/check-changelog-parity.sh --check --check-order and other non-git shell invocations during this pass, consistent with the two prior reviews on this PR. I did not re-run the changelog-parity check, validate-plugins.sh, check-skill-portability.sh, or the plugin's test suites. The PR body's Verification section (including the canary run itself, 36666844023) is author-claimed and unverified by me.

Branch: fix/audit-instruction-placement

@kyle-sexton
kyle-sexton merged commit 6fa0d73 into main Sep 30, 2026
19 checks passed
@kyle-sexton
kyle-sexton deleted the fix/audit-instruction-placement branch September 30, 2026 05:47
kyle-sexton added a commit that referenced this pull request Sep 30, 2026
…Muse Code loader results (#5563)

Refs: #4283

## Summary

Cursor, Grok Build and Muse Code loader claims were graded docs/source
because none of the tools had been run. Cursor (cursor-agent
2026.09.28-64d2043), Grok Build (1.0.41) and Muse Code (1.4.1) are now
installed on the desktop host, and the loader recipe was run against
each. This PR replaces the parked record with the observed results and
lists the bullets that stay open, each with its reason.

## Fix

- `plugins/instruction-placement/skills/migrate/reference/sources.md`:
the parked-install record is replaced by a four-part record (claim,
basis with tool versions and recipe, as-of, recheck trigger) holding the
per-tool results and the open bullets.
- `docs/specs/agent-doc-surfaces.md`: rows corrected where the observed
behavior differs from the docs-grade claim.

Open bullets: Cursor Team/Project/User precedence, `~/.cursor/rules` on
disk and sync, Cursor editor-vs-CLI comparison, Grok path-only reminder
text, Grok MAX_WALK_DEPTH=10, Muse user-rules path and Windows
resolution. Each needs the editor, a Team plan, a Windows host or an
observation not available headless.

`Refs`, not `Closes`: the issue's acceptance criteria say no write to
user-scope config. No probe wrote any file there, but the tools rewrote
their own state on first run (`~/.config/muse/settings.json`,
chezmoi-managed; `~/.grok/config.toml`; `~/.cursor` chats and projects
entries). The owner decides whether that meets the criterion and whether
the issue closes.

## Verification

- Recipe tree built in the session scratchpad, outside every repo, with
per-file random canary tokens; one git copy and one non-git copy.
Headless runs of `cursor-agent -p`, `grok -p` and `grok inspect`, and
`muse exec`, from the root and from nested directories.
- `git status --porcelain` in the worktree was empty after the runs.
- Transcripts and the results table are kept locally in the gitignored
`.work/4283/`.
- instruction-placement bumped to 0.16.1 with a CHANGELOG entry;
check-changelog-parity (--check --check-order), validate-plugins (108
checks) and plan-migration.test.sh pass.

## Related

- Issue #4283
- PR #4914 (earlier parked record, replaced here)
- PR #5285 (rewrites the same `sources.md` section as "pending owner
decision"; resolve the overlap when merging the base and keep this
record)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
kyle-sexton added a commit that referenced this pull request Sep 30, 2026
)

Closes #3614

Refs #3172 #3593 #3756 #3568 #4666 #4661 #4657 #4281 #5163 #3544 #3138
#3465 #4240 #5255

## Summary

Docs-only remediation for the audit group "decisions-docs" (docs/adr/,
docs/out-of-scope/, docs/specs/). It takes agent-encoded decisions off
main where the owner had not ruled, corrects false facts in the records
that stay, records a current-version probe in ADR 0007, and delivers the
two unmet acceptance criteria of #3614 in the eval gap analysis. No
plugin file changes, so no version bump or CHANGELOG entry applies.

## Fix

One commit per change so the owner can drop any of them:

1. Reverse three decisions (#3172, #3593, #3756): delete
`docs/out-of-scope/cloud-session-permission-floor.md` and
`docs/out-of-scope/context-engineering-effort-candidates.md`; restore
ADR 0003 to its pre-run text (removes the `Session-log grading (#3756)`
section and its Sources suffix).
2. Out-of-scope ledger. `docs/out-of-scope/README.md` is one paragraph:
one file per settled rejection, matched and appended to as the
`/work-items:triage` "Rejected-concept ledger" step defines, rejections
only, never deferred work. `machine-profile.md` drops the false claims
about #4240 and the invocation-mode amendment, names #4240 question 2
(keep the per-plugin `check` skills or replace them with one shared
script) as the open owner question, says in a status line that the park
is an unratified agent proposal (the owner rules under #4666), and
counts the five plugins with a model-invocable `check` skill
(`actionlint`, `biome-format`, `context7`, `go-format`,
`markdown-format`) and the seven `prerequisites.json` declarations; no
Decision line changes. `shared-surface-instruction-governance.md` says
the #3568 "No" was an AI triage default with owner confirmation open.
3. Delete `docs/out-of-scope/skill-listing-500-char-exceptions.md`
(stale branch and PR bookkeeping, an unrecorded "operator skip").
Judgment call kept as its own commit (#4661, #4657).
4. ADR 0036: the "Native only" row no longer reads "Accepted" under a
"Rejected" heading; the run-log Update is one dated paragraph that says
the remote flag is no longer the blocker and points at the `sources.md`
section "Current fleet grade" (lands with #5285, see Merge order); one
broken line reflow is rejoined. The tracker pointer is unchanged:
choosing #4281 or #5163 as the canonical tracker is an owner question
(#4281, #5163).
5. Delete `docs/specs/precompute-injection-sweep-status.md`, re-verified
as derivable on the branch tip before the deletion (#3544; result under
Verification). The durable record is the #3544 comment.
6. ADR 0007: add a Claude Code 2.1.284 probe of `${CLAUDE_PLUGIN_ROOT}`
on three surfaces (skill body expanded, single-quoted shell-form hook
command literal with the variable set in the hook environment, Bash-tool
environment unset), plus one sentence: the shell-form hook command does
not show the documented inline substitution, while an exec-form `args`
element expanded. This delivers only the probe half of #3138 AC1. The
`context/` call sites
(`plugins/source-control/skills/worktree/context/status.md:7,24` and
`audit.md:12,15,16`) were not probed; fixing them versus documenting the
resolution order is put to the owner in the #3138 packet.
7. Eval gap analysis
(`docs/specs/evaluation-methodology-gap-analysis.md`, #3614). New
section "Reference implementation: skill-creator coverage": what
`skill-creator` ships (read at `fbe07fb6ce7d`), which pipeline row each
file covers, what it does not ship. New section "Assertion discipline
measurement": 303 files, 2,230 cases, 8,327 expectation strings, 230
under six words, 186 with a quality word, 20 with a strongly evaluative
word; the rule and the script are in the doc, both broad screens are
stated as heuristics that over-match, and no count of vague expectations
is claimed. The last table row cites the comparison, the
assertion-discipline row cites the measurement, the snapshot line is
re-dated (303 files on 2026-09-29), and the proposed adoptions link
#5255. No verdict changes; every adopt stays a proposal for the operator
gate.
8. `docs/specs/plugin-conformance-capability-matrix.md`: the
trigger-register clause says the `music` to `audio` rename has fired,
without naming the plugin or the landing.

The branch also carries merges of origin/main (no conflicts). Not
touched, on purpose: ADR 0025 (true again once #3593 is reopened),
`docs/cloud-sessions.md` and
`docs/setup-contract-campaign-follow-ups.md` (other groups' files).

## Merge order

- `docs/cloud-sessions.md:54,492` and
`docs/conventions/invocation-mode/README.md:92` link files this PR
deletes. #5268 (core-docs) removes the two `cloud-sessions.md` links and
#5313 (conventions) removes the `invocation-mode` link. Land #5268 and
#5313 in the same merge pass as this PR; this PR alone leaves three
dangling links.
- ADR 0036 cites the `sources.md` section "Current fleet grade", which
exists only on #5285 (instruction-placement); main still carries
"Standing refresh (#5163)", which grades condition 3 `[UNREACH]`. Land
#5285 before this PR or in the same pass.

## Verification

Run in the worktree at the merged head:

- `bash scripts/check-changelog-parity.sh --check --check-order`: pass.
- `bash scripts/validate-plugins.sh`: all manifests and the catalog
validated.
- `bash scripts/check-adr-numbers.sh --check`: pass.
- `bash scripts/check-docs-naming.sh --check`: pass.
- `bash scripts/check-purged-em-dashes.sh --check`: 1288 files scanned,
no em dashes.
- `markdownlint-cli2` and `typos` on the edited ADRs,
`docs/out-of-scope/` files and `docs/specs/` files: 0 issues; `lychee
--offline` on the eval gap analysis and the two ledger files: 0 errors.
- `bash scripts/check-docs-only.sh origin/main`: reports docs_only=false
because `docs/adr/0003-*` is outside its allowlist, so CI runs the full
suite; no plugin file is in the diff. `bash scripts/affected-tests.sh`:
no suites selected.
- ADR 0003 vs baseline 7acaf08: identical.
- Gap-analysis counts: the script printed in the doc, run on the branch
tip, prints `303 2230 47 8327 230 186 20`. The 47 cases without
`expectations[]` all carry `expected_output`.
- #3614 acceptance, for the owner to audit the close:
- AC1 (reference implementation examined, coverage recorded): met by
"Reference implementation: skill-creator coverage".
- AC2 (every pipeline element has a verdict): already met on main;
unchanged.
- AC3 (measured counts, not estimates): met by "Assertion discipline
measurement". It reports what the screen matches, not how many
expectations are vague, and the doc says so.
- AC4 (adopted pieces implemented, rejected ones recorded): waived by
the owner's 2026-09-27 narrowing to the read-only analysis
(#3614 (comment)).
The rejected row keeps its reason. If the owner rejects the waiver, drop
the closing line from the squash message.
- AC5 (adopted run mechanisms reuse existing facilities): not
applicable, nothing is adopted.
- AC6 (affected tests pass): `scripts/affected-tests.sh` selects no
suites for this diff.
- T6 probe: real `claude -p` on CLI 2.1.284, run twice with identical
results. An exec-form hook probe on the same CLI: the `args` element
expanded to the plugin root, the single-quoted shell-form token stayed
literal.
- #3544 re-verification of the deleted status spec, on the branch tip:
- Each of the 23 setup skills in the issue's sweep table injects its
probes: counting inline `!` and fenced `!` injection lines in
`plugins/<name>/skills/setup/SKILL.md` gives 1 to 4 for all 23, none 0.
- The five consolidations are present: `claude-memory:audit` (one
`audit-spine.sh` call), `knowledge:video-digest` and
`knowledge:course-digest` (one fenced `!` block each),
`claude-ops:observability` and `claude-ops:lanes` (merged probe lines).
- `bash scripts/check-skill-precompute-compose.sh --all`: 312 skills
scanned, 2 warn-only violations, exit 0. Both are outside #3544's sweep
and are not fixed here: `claude-ops:morning-brief` (3 precompute lines
with a git command) and `code-tidying:dissolve-comments` (2 such lines),
under the #1619 composition rule.
  - The per-plugin counts are in the #3544 comment.

## Related

Findings from `.work/audit/REPORT.md` (local, not committed), by issue:
#3172, #3593, #3756 (3d reverse); #3568, #4666 (out-of-scope ledger,
3e); #4661, #4657 (exceptions ledger, 3b); #4281, #5163 (ADR 0036);
#3544 (status spec); #3138 (3c and 3d decide fresh, item 1 probe only);
#4240 (machine-profile pointer to its open question 2); #3465 (decision
packet only); #3614 (gap analysis, AC1 and AC3).

Requests from other fix groups (twelve), applied here:

- evals: the skill-creator comparison, the measured counts and the #5255
link in the eval gap analysis (item 7).
- retro-audio: the capability-matrix wording (item 8).
- instruction-placement: ADR 0036 history parenthetical dropped, run-log
detail cut to a pointer at "Current fleet grade", and the "flag is the
blocker" implication replaced by a dated Update (item 4).
- work-items: the ledger README points at the triage skill's definition
and drops the unsourced consumer claim; machine-profile is marked an
unratified proposal (item 2).
- claude-ops: the stale #4240 facts in `machine-profile.md` are
corrected and what remains blocked is named; Decision, options and
Recheck outcome are unchanged (item 2).
- core-docs (ledger findings F0, F10, F12) and conventions (a): already
delivered by items 1 to 3, with the reopened issues #3172, #3593, #3756
and #4666.

Not applied:

- core-docs, `docs/plugin-philosophy.md` finding: that file and the fix
are core-docs's.
- source-control, #3138 comment, Windows child and follow-ups edit: the
guard-versus-support question is an owner decision in the #3138 packet,
`docs/setup-contract-campaign-follow-ups.md` is core-docs's, and #5317
changes neither Windows test suite.
- instruction-placement, tracker repoint in ADR 0036: waits on the
owner's canonical-tracker choice.
- conventions (b): the #3615 comment already cites the house position in
`docs/conventions/permission-rule-hygiene/README.md`.
- tracker and scripts, reopening #4658, #3465, #3617, #2954, #3615 and
#3138: done as issue operations, with #4655 linked as the blocker of
#4658.

Cross-group requests (owners of those groups act on them; this PR does
not):

- core-docs: decision-neutral fixes to
`docs/setup-contract-campaign-follow-ups.md` (cite ADR 0007's
version-stamped record) and `docs/plugin-philosophy.md:1286`.
- claude-config: add the ledger-README and #3568 questions to its
packet; claude-ops: #4666 packet, #4049 and #4047 items; scripts:
`scripts/adr-numbers-baseline.txt` header; evals: the comparison narrows
#5255 items 1, 2 and 7 and raises a question on the "rejected"
task-completion-notification row, none of which #5255 carries;
source-control, session-flow, planning, review, skill-quality,
instruction-placement, attribution, context-budget: see the group plan.

Issue operations (reopen, decision packets) for #2954, #3138, #3172,
#3465, #3593, #3615, #3617, #3756, #4658 are performed separately from
this PR.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
kyle-sexton added a commit that referenced this pull request Sep 30, 2026
…when it is missing (#5547)

Refs: #3708

## Summary

Hook rows launch through `node`, and Claude Code's native binary does
not ship Node. A host without `node` therefore ran guards that enforced
nothing, with no signal. This implements the owner decision (2026-09-29)
on #3708: Q1(A) declare the requirement, Q1(B) add a shell-form notice,
Q3(a) move the detector row to shell form. Q2 (whether a missing `node`
should block) stays with the owner; the evidence is posted on the issue,
which stays open with `needs-human`.

## Fix

- Q1(A): testing gets a Requirements section and a `node` probe in its
setup `check`; source-control's existing Node.js line moves into a
Requirements section. claude-ops and instruction-placement already
declare it on main (instruction-placement from #5285, which this PR does
not touch); claude-ops changes only to name the `hook-failure-audit`
exception.
- Q1(B): guardrails and disk-hygiene get a shell-form SessionStart row
that prints a system message and model context when `node` is not on
`PATH`.
- Q3(a): the claude-ops `hook-failure-audit` Stop row runs in shell
form, so the detector works when `node` is the missing piece.
- `docs/plugin-philosophy.md` Hooks row and
`docs/conventions/hook-budget/README.md` name the three shell-form
exceptions; `scripts/check-killswitch-hoist.sh` documents the inline
rows as not scanned.
- Version bumps and changelog entries, each above origin/main:
guardrails 0.44.0, disk-hygiene 0.37.0, claude-ops 0.77.1,
source-control 0.67.2, testing 0.11.9.

## Verification

Run on the merged head 365c8f9, which merges origin/main at 681789d:

- `git merge-tree --write-tree HEAD origin/main`: no conflicts.
- `scripts/check-changelog-parity.sh --check`, `--check-order`,
`--check-bump origin/main`, `--check-preserved origin/main`: pass;
`scripts/check-stale-base-overlap.sh --check origin/main`: up to date.
- `scripts/validate-plugins.sh`: all manifests and the catalog
validated.
- `bash plugins/guardrails/hooks/exec-bash.test.sh`: pass, including the
notice row with and without node.
- `bash plugins/disk-hygiene/hooks/run-python-hook.test.sh`: pass.
- `bash plugins/claude-ops/hooks/hook-failure-audit.test.sh`: pass (126
checks), including a pin that the Stop row stays shell form.
- `bash scripts/check-killswitch-hoist.sh`, `check-hook-exec-form.sh`,
`check-hook-slow-shapes.sh`, `check-hook-userconfig-argv.sh`,
`check-hooks-description.sh`: clean.
- Not run: `hook-census.test.sh` (needs strace, unavailable here).
- Node-absent spawn failure reproduced on Claude Code 2.1.285; evidence
in the [issue
comment](#3708 (comment)).

## Related

- #3708 (stays open: Q2 is the owner's call)
- #5309, #5340, #5336, #5285

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant