diff --git a/plugins/claude-config/.claude-plugin/plugin.json b/plugins/claude-config/.claude-plugin/plugin.json index d98af9a96c..e0bf4ac790 100644 --- a/plugins/claude-config/.claude-plugin/plugin.json +++ b/plugins/claude-config/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "claude-config", - "version": "0.53.5", + "version": "0.53.6", "description": "Nine configuration-health skills (plus setup) for a repo's Claude Code configuration: audit (settings.json / .mcp.json / hooks / plugins / permissions drift), audit-automation-gaps (evidence-gated verdicts on automation gaps), audit-permission-grants (allow-rule / allowed-tools grants for auto-mode durability and portability), audit-permission-state (the permission rules actually in effect: every settings scope merged with per-rule provenance, what auto mode drops on entry, config written where nothing reads it, and which managed intents are enforced versus loosenable), draft-auto-mode-rules (interview and draft a paste-ready autoMode classifier block; prints only, never writes), audit-instructions (locally-owned instruction surfaces vs current model capability, proposing removals/rewrites of instructions the model no longer needs, and detecting cross-surface instruction conflicts), audit-prompting-postures (the additive lane: posture guidance the prompting guide says a component's purpose needs but the component does not carry), audit-pass (one coordinated, ordered, resumable pass over a named target: three-scope inventory, run-time-derived exclusion set, stable finding identity, suppression memory, resume, one human gate, delegating every check to the plugin that owns it), and unhobble (the empirical bare-baseline experiment: reversibly strip a repo's standing instructions, log real stumbles against the current model, re-add only what evidence earns).", "author": { "name": "Melodic Software", diff --git a/plugins/claude-config/CHANGELOG.md b/plugins/claude-config/CHANGELOG.md index 7f0f06136f..93df2ac628 100644 --- a/plugins/claude-config/CHANGELOG.md +++ b/plugins/claude-config/CHANGELOG.md @@ -5,6 +5,16 @@ All notable changes to the `claude-config` plugin are documented here. Format fo Versions 0.51.8 to 0.51.9 and 0.51.11 to 0.51.14 were reserved by parallel branches and never released. +## [0.53.6] - 2026-09-30 + +### Changed + +- **`audit` / Phase 5:** route approved `settings.json` and `settings.local.json` edits through `update-config` with + the `[Self-Modification]` handshake, and document the two auto-mode refusals + (`.claude/audit-pass.md` as `[Instruction Poisoning]`, the `audit-engine.sh` re-run as + `[Self-Modification]`) with the operator fallback + ([#5376](https://github.com/melodic-software/claude-code-plugins/issues/5376)). + ## [0.53.5] - 2026-09-29 ### Changed diff --git a/plugins/claude-config/skills/audit/SKILL.md b/plugins/claude-config/skills/audit/SKILL.md index 40cdba9eb8..67dff28234 100644 --- a/plugins/claude-config/skills/audit/SKILL.md +++ b/plugins/claude-config/skills/audit/SKILL.md @@ -326,7 +326,12 @@ environment. For each user-approved fix: -1. Make the edit. Done when the target file carries the change and nothing else in it moved. +1. Make the edit. Route each approved edit to `settings.json` or `settings.local.json` + through the built-in `update-config` skill when it resolves in this session, and write directly + when it does not (`.mcp.json` is outside its scope; edit it directly); the one exception is orphan-`false` plugin removal, which goes through `scripts/fix-plugin-drift.sh --yes` so its lower-precedence-scope + check still runs. In auto mode a settings edit needs the `[Self-Modification]` handshake: the + classifier asks, and the user's explicit approval of that fix is the consent. Done when the + target file carries the change and nothing else in it moved. 2. Validate with `jq . >/dev/null` after each edit. Done when jq exits 0; on a parse error, revert that edit before touching the next one. 3. Report what changed, as the file, the key, and the before and after values. Done when every @@ -338,6 +343,20 @@ After all fixes: server counts) - Verify all config files are still valid JSON +### Refusals in auto mode + +Two operations are refused in auto mode. Writing the team-layer suppression record +`.claude/audit-pass.md` is refused as `[Instruction Poisoning]`. Re-running `scripts/audit-engine.sh` +for the after-fix summary is refused as `[Self-Modification]`. Never retry around a refusal. Hand the +operator the fallback: they apply the `.claude/audit-pass.md` edit themselves, or run the engine +re-run and paste its output back. Report the before/after comparison from what they return. + +Claim: auto mode refuses those two operations under those two category names. Basis: an empirical +`claude-config:audit@0.48.2` `--fix` run in auto mode on Claude Code 2.1.283, recorded in +[melodic-software/.github PR #153](https://github.com/melodic-software/.github/pull/153). As of +2026-09-27. Recheck when a Claude Code release changes auto-mode classifier categories, or a run +where either refusal no longer fires. + ### Fixes the skill can apply Auto-fixable (add `$schema`, **move** deny rules from local to project, plugin orphan-`false` @@ -392,8 +411,8 @@ request such as "allow npm commands" or "add a hook that runs when Claude stops" an audit. **Mutation gate.** `update-config` writes settings files as its job. This skill writes only in -Phase 5, under `--fix`, one confirmed fix at a time, and never chains into `update-config` on its -own behalf. +Phase 5, under `--fix`, one confirmed fix at a time; Phase 5 routes each such settings edit through +`update-config`, and outside `--fix` this skill never chains into it on its own behalf. **Availability is never assumed.** Bundled skills are gated by settings such as `disableBundledSkills` and vary by version and host; this section states what to do when the diff --git a/plugins/claude-config/skills/audit/context/procedures.md b/plugins/claude-config/skills/audit/context/procedures.md index d730575320..933c76f86a 100644 --- a/plugins/claude-config/skills/audit/context/procedures.md +++ b/plugins/claude-config/skills/audit/context/procedures.md @@ -57,6 +57,17 @@ cat .claude/settings.local.json | tr -d '\r' | jq '.permissions.deny // empty' | Remove orphan plugins (`true`) | No | Yes (user enabled a now-removed plugin, so investigate intent) | | Rename plugins (heuristic match) | No | Yes (verify upstream rename, update key, preserve `enabled` value) | +Each approved edit to `settings.json` or `settings.local.json` goes through the +built-in `update-config` skill when it resolves in this session, and directly when it does not +(`.mcp.json` is always edited directly), except orphan-`false` plugin removal, which stays on +`scripts/fix-plugin-drift.sh --yes` for its lower-precedence-scope check. In auto mode it needs the +`[Self-Modification]` handshake: the classifier asks, and the user's explicit approval of that fix +is the consent. Two operations are refused in auto mode: writing `.claude/audit-pass.md` +(`[Instruction Poisoning]`) and re-running `scripts/audit-engine.sh` for the after-fix summary +(`[Self-Modification]`). The fallback for each is the operator applying the edit or running the +re-run and pasting the output back; never retry around the refusal. The verification record for the +category names is in [SKILL.md](../SKILL.md) "Refusals in auto mode". + **The judgment on a baseline deny addition, stated.** Two things have to be checked before the rule is added, and neither is mechanical: diff --git a/plugins/claude-config/skills/audit/reference/native-update-config.md b/plugins/claude-config/skills/audit/reference/native-update-config.md index a8666d9c36..9224cf535c 100644 --- a/plugins/claude-config/skills/audit/reference/native-update-config.md +++ b/plugins/claude-config/skills/audit/reference/native-update-config.md @@ -15,10 +15,10 @@ in any session. `update-config` makes a change the person asks for. This skill checks what is already configured against current docs and the project's conventions and reports findings; its `--fix` phase applies -only findings it produced, each behind a confirmation. One writes on request, the other judges the -result, so an audit finding the person wants fixed in a way `--fix` does not cover is a natural -request to hand to `update-config`, which the person or the model makes as a new request, not a -chain from this skill. +only findings it produced, each behind a confirmation, and routes those settings edits through +`update-config` when it resolves. One writes on request, the other judges the result, so an audit +finding the person wants fixed in a way `--fix` does not cover is a natural request to hand to +`update-config`, which the person or the model makes as a new request, not a chain from this skill. ## Presence