Skip to content

fix(playbooks): run the repo-sweep lint step over the whole tree - #5345

Merged
kyle-sexton merged 6 commits into
mainfrom
fix/5201-repo-sweep-lint-all
Sep 29, 2026
Merged

kyle-sexton merged 6 commits into
mainfrom
fix/5201-repo-sweep-lint-all

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Closes #5201

Summary

The lint entry in the repo-sweep hygiene catalog passed only --fix to toolchain:lint. With no ecosystem filter, that skill lints the changed files, which on a clean sweep tree are only the files earlier sweep steps touched. The step never covered the rest of the repository.

Fix

plugins/playbooks/skills/repo-sweep/catalogs/hygiene.md: the ### lint entry now has - args: all --fix and a Notes block directing a following /toolchain:lint all check-mode run (--fix runs only format commands). The claude-config entry is unchanged. playbooks is bumped to 0.14.1 with a CHANGELOG entry.

Verification

  • plugins/playbooks/skills/repo-sweep/scripts/catalog.test.sh, render.test.sh, state.test.sh: all passed.
  • scripts/check-changelog-parity.sh --check --check-order: passed.
  • scripts/validate-plugins.sh: all manifests and the catalog validated.
  • Whole-repo coverage of /toolchain:lint all on a clean tree with a non-empty branch diff (the acceptance criterion): every ecosystem widens, so no toolchain issue was needed.
    • bash: shellcheck and shfmt ran over 1104 tracked *.sh files (diff-only would be 0).
    • markdown: markdownlint-cli2 linted 1767 files (diff-only would be 1).
    • python, typescript, go, powershell: the check commands use ., ./..., or -Path . -Recurse.
    • yaml: actionlint discovers all workflows. typos, gitleaks, editorconfig and lychee take no <files> list.
    • Basis: toolchain:lint SKILL.md step 1 computes no changed-file list under all.

Related

🤖 Generated with Claude Code

@kyle-sexton
kyle-sexton marked this pull request as ready for review September 29, 2026 17:40
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T17:42:39.825955Z 3198bab Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 28s —— View job


Security review

No security issues found.

This PR changes three files:

  • plugins/playbooks/.claude-plugin/plugin.json: version bump 0.14.0 → 0.14.1.
  • plugins/playbooks/CHANGELOG.md: changelog entry for the fix.
  • plugins/playbooks/skills/repo-sweep/catalogs/hygiene.md: the lint catalog entry's args value changes from --fix to all --fix (line 317).

The args change is a static, maintainer-authored config literal (not derived from user or PR input) consumed by repo-sweep's catalog rendering to invoke toolchain:lint. It widens lint coverage from diff-only to the whole repository — a coverage increase, not a new injection, authorization, or trust-boundary surface. No secrets, credentials, auth, or Actions workflow permissions are touched, and no standing instruction/guardrail is deleted or narrowed (the change only broadens what already ran). This falls under the skip gate: no security-relevant surface in this diff.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 49s —— View job


CI Code Review

  • Gather context (PR diff, changed files, CLAUDE.md guidelines)
  • Understand the request (invoke /review:code-review lane)
  • Review changed files for correctness/maintainability
  • Adversarial validation of findings
  • Post findings (inline + summary)

Summary

No blocking findings. This is a minimal, well-scoped fix:

  • plugins/playbooks/skills/repo-sweep/catalogs/hygiene.md#L316: args: all --fix matches plugins/toolchain/skills/lint/SKILL.md's documented grammar — all is the literal ecosystem filter that runs every applicable ecosystem, and it combines with mode flags the same way the SKILL.md's own examples do (/toolchain:lint dotnet --fix).
  • Confirmed via plugins/playbooks/skills/repo-sweep/scripts/catalog.sh and render.sh that the args column is passed through as free text to the invoked skill, so no parsing/quoting concern with the new two-token value.
  • Checked for sibling instances of the same bug: toolchain:lint is referenced only once across plugins/playbooks/skills/repo-sweep/catalogs/, so there's no other catalog entry left with the same gap.
  • Version bump (0.14.0 → 0.14.1) and CHANGELOG entry are present and consistent with the diff.

I was not able to independently re-run catalog.test.sh / render.test.sh / state.test.sh or scripts/check-changelog-parity.sh in this sandbox (command execution required approval that isn't available in this unattended lane), so the PR body's test-run claims are author-reported and unverified by me, not confirmed independently. Static review of the change against the parsing scripts and the target skill's argument grammar found nothing that would make those commands fail.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3198bab390

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/playbooks/skills/repo-sweep/catalogs/hygiene.md
… fix step

Refs #5201

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 37s —— View job


Tasks

CI Code Review

Scope: git diff origin/main...HEAD at 2b9c57c — 3 files: plugins/playbooks/.claude-plugin/plugin.json (version bump), plugins/playbooks/CHANGELOG.md (entry), plugins/playbooks/skills/repo-sweep/catalogs/hygiene.md (the lint entry's args change plus a new #### Notes block added in the latest commit).

The latest commit (2b9c57c) responds to Codex's earlier finding that --fix alone only widens format-only commands, not check-cmd. It adds a #### Notes block instructing the sweep operator to also run /toolchain:lint all in check mode and report its failures. I confirmed against plugins/toolchain/skills/lint/SKILL.md's "Mode flags" table that this is accurate: check mode (no --fix) runs check-cmd, and all covers every applicable ecosystem regardless of changed-file detection. I also confirmed the #### Notes mechanism is a real, already-load-bearing part of this catalog format (repo-sweep/reference/next.md §3.1: "Follow the notes the same way [as an override]"; §2.2 explicitly reads catalog.sh --notes <id> before running a step), and that catalog.sh's parser (verified by reading scripts/catalog.sh and its test, which runs the parser over every shipped catalog including this one) handles the new block without ambiguity — no stray ####/blank-line issues.

One finding, posted inline:

  • plugins/playbooks/skills/repo-sweep/catalogs/hygiene.md#L322-L326 — the new Notes block restates toolchain:lint's --fix-vs-check-mode semantics as fact but carries no verification stamp. .claude/rules/skill-bodies-state-current-rules.md requires a four-part record (claim/basis/as-of/recheck) for exactly this — a skill body restating a volatile specific of another surface — and this same file already establishes the expected form: the tidy entry a few dozen lines above (L79-84) restates code-tidying:tidy's semantics with Claim: ... Basis: code-tidying 0.23.20 ... As of: 2026-09-29. Recheck: .... The new lint note is the same kind of restatement (cross-plugin flag/mode semantics) without the anchor, so it's inconsistent with the file's own established convention and would go stale silently if toolchain:lint's mode split ever changes.

Everything else checked out:

  • args: all --fix matches toolchain:lint's documented grammar; no parsing/quoting issue in catalog.sh/render.sh (both treat args as opaque free text).
  • Version bump (0.14.0 → 0.14.1) and CHANGELOG entry are present, consistent with the diff, and accurately describe both the args change and the new Notes-driven check-mode instruction.
  • No sibling catalog entries reference toolchain:lint, so there's no second instance of the same gap to fix.

I was not able to run catalog.test.sh / render.test.sh / state.test.sh or check-changelog-parity.sh myself in this sandbox (script execution was denied), so the PR body's test-run claims remain author-reported and unverified by me; I instead statically verified the specific mechanics the change touches (parser behavior, notes-following procedure, lint mode semantics) by reading the scripts and skill docs directly.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 59s —— View job


Security review

No security issues found.

The new commit (2b9c57c) on top of the prior review's commit (3198bab) only adds a #### Notes subsection to the lint catalog entry in plugins/playbooks/skills/repo-sweep/catalogs/hygiene.md, documenting that --fix only runs format commands and that a following /toolchain:lint all check-mode run is needed. No other diff lines changed since the prior review.

This is prose guidance in a maintainer-authored, PR-reviewed catalog file — the same trust tier as the args field already assessed in the earlier review on this PR. catalog.sh --notes <id> <catalog-file> extracts this block verbatim for the sweep operator/agent to read; it isn't parsed as a command or interpolated into one, so it introduces no new injection, authorization, or trust-boundary surface. No secrets, credentials, auth, or Actions workflow permissions are touched, and no standing instruction/guardrail is deleted or narrowed.

Full diff since PR open (plugin.json version bump, CHANGELOG.md entry, and the hygiene.md lint entry args/Notes changes) stays within the skip gate: no security-relevant surface.

Comment thread plugins/playbooks/skills/repo-sweep/catalogs/hygiene.md
… lint note

Refs #5201

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 50s —— View job


Tasks

CI Code Review

Scope: git diff origin/main...HEAD at a9bedf8 — 3 files: plugins/playbooks/.claude-plugin/plugin.json (version bump, unchanged since last review), plugins/playbooks/CHANGELOG.md (entry, unchanged since last review), plugins/playbooks/skills/repo-sweep/catalogs/hygiene.md (the lint entry: args, Notes block, and now a verification-record paragraph).

No blocking findings. The latest commit (a9bedf8) is a direct response to this lane's prior finding on 2b9c57c (missing verification stamp on the restated toolchain:lint mode semantics). It adds, at hygiene.md#L328-332:

Claim: toolchain:lint with --fix runs only each ecosystem's format-only fix-cmd, check mode runs check-cmd, and the all filter widens the file list to the whole repository. Basis: toolchain 0.13.18 skills/lint/SKILL.md (Mode flags table, command-selection table, and the all filter rule). As of: 2026-09-29. Recheck: ...

I verified this against plugins/toolchain/skills/lint/SKILL.md directly (currently toolchain 0.13.18, matching the cited version):

  • Line 59: --fix is documented as "Format-only fix mode... Does not run code-fix-cmd" (and by the mode table, not check-cmd either).
  • Lines 121-124: the mode table confirms check(default)→check-cmd, --fix→fix-cmd, --code-fix→code-fix-cmd.
  • Line 52: "Literal all runs every applicable ecosystem."

The claim is accurate and matches the cited basis exactly — no drift between the restatement and the source. The added paragraph also follows .claude/rules/skill-bodies-state-current-rules.md's required four-part form (claim/basis/as-of/recheck) and mirrors the file's own established precedent, the tidy entry's Notes block at lines 79-84, in structure and phrasing style. This closes out the only finding this lane raised on this PR.

Everything else is unchanged from the prior review on 2b9c57c:

  • args: all --fix matches toolchain:lint's documented grammar; no parsing/quoting issue in catalog.sh/render.sh (both treat args as opaque free text).
  • Version bump (0.14.0 → 0.14.1) and CHANGELOG entry are present, consistent with the diff, and accurately describe the final fix (both the args change and the check-mode Notes instruction).
  • No sibling catalog entries reference toolchain:lint, so there's no second instance of the same gap.

I was not able to run catalog.test.sh / render.test.sh / state.test.sh or check-changelog-parity.sh myself in this sandbox (script execution requires approval unavailable in this unattended lane), so the PR body's and author's comment's test-run claims remain author-reported and unverified by me; I instead statically verified the specific mechanics the change touches (the restated claim against its cited source file) by reading it directly.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 31s —— View job


Security review

No security issues found.

Since the last review (commit 2b9c57c), the only new commit is a9bedf8, which adds a verification-stamp block (Claim: ... Basis: ... As of: ... Recheck: ...) to the lint catalog entry's #### Notes section in plugins/playbooks/skills/repo-sweep/catalogs/hygiene.md. This responds to the earlier code-review finding about the missing anchor for the restated toolchain:lint mode semantics.

This is prose documentation in a maintainer-authored, PR-reviewed catalog file — the same trust tier as the args/Notes content already assessed in the prior reviews on this PR. It's read verbatim by catalog.sh --notes <id> for a human/agent operator, not parsed as a command or interpolated into one, so it introduces no new injection, authorization, or trust-boundary surface. No secrets, credentials, auth, or Actions workflow permissions are touched.

Checked for the instruction-surface-deletion case (removing/narrowing a standing guardrail): this commit only adds content — it doesn't delete or soften any existing instruction — so that lens doesn't apply here.

Full diff across all three changed files since PR open (plugin.json version bump, CHANGELOG.md entry, and the hygiene.md lint entry's args change plus the two Notes additions) stays within the skip gate: no security-relevant surface.

@kyle-sexton
kyle-sexton merged commit 11c5000 into main Sep 29, 2026
19 checks passed
@kyle-sexton
kyle-sexton deleted the fix/5201-repo-sweep-lint-all branch September 29, 2026 18:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

playbooks: repo-sweep hygiene catalog runs lint on changed files only

1 participant