docs(disk-hygiene): fix run-directory, fan-out brief and --project-dir wording - #5571
Conversation
…r wording Refs #5520 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fae2dc29d6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Claude finished @kyle-sexton's task in 1m 25s —— View job Security review: no issues found
This is a docs-only change ( What changed, security-relevant angle:
Instruction-surface deletion lens: I checked this diff's wording changes to No CRITICAL, IMPORTANT, or SUGGESTION findings. |
Renumber disk-hygiene to 0.29.2 above main's 0.29.1 and lower the fan-out brief spoke-plugin-root baseline to its current count. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 1m 11s —— View job Security review: no issues found
This is a docs-only change to the Scoping this run: Content review (unchanged from the prior pass, re-verified here):
Instruction-surface deletion lens: none of the reworded lines in Out of scope for this lane: Codex's review-comment finding on this PR (missing Claim/Basis/As-of/Recheck record for the "workers never receive the guard-values note" assumption) is a documentation-process concern under No CRITICAL, IMPORTANT, or SUGGESTION findings. |
…ed record Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 52s —— View job Security review: no issues found
This is a docs-only change to the Scoping this run: current head This is exactly the fix for Codex's earlier P1 finding on this PR (missing Claim/Basis/As-of/Recheck record for the volatile hook-delivery assumption) — it's a documentation-accuracy correction, not a security-relevant change. It doesn't touch the mutation-guard rules (no Content review (unchanged from prior passes on this PR, re-verified here):
Instruction-surface deletion lens: no removed or softened rule in the protected classes (irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority). The mutation-guard contract is carried forward verbatim; this commit only re-scopes a factual claim to a verified source. No CRITICAL, IMPORTANT, or SUGGESTION findings. |
|
Claude finished @kyle-sexton's task in 2m 59s —— View job Code review
This is a docs-only change to the 1 finding, posted inline on Other things I checked, no findings:
Author-claimed, not independently verified by me: Out of scope for this lane: the security angle of the same diff was already covered by the security-review lane on this PR (no issues found, twice). |
Renumber disk-hygiene to 0.30.1 above main's 0.30.0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 1m 54s —— View job Code review
Reviewed 1 finding, posted inline on Other changed files, no findings:
Author-claimed, not independently re-run by me: Out of scope for this lane: security angle of this diff already covered by the security-review lane on this PR (no issues found, run multiple times). |
|
Claude finished @kyle-sexton's task in 1m 59s —— View job Security review: no issues found
This is a docs-only change to the Content review:
Instruction-surface deletion lens (register, Gate 0 classes: irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority): none of the reworded lines in Out of scope for this lane: the open code-review thread on whether the No CRITICAL, IMPORTANT, or SUGGESTION findings. |
… brief Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Renumber disk-hygiene to 0.31.1 above main's 0.31.0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 3m 13s —— View job Code review
Reviewed at head 1 finding, posted inline on Good news on the prior open thread: Codex's and this lane's earlier P1 (cited record for "worker sees only its spawn prompt, not the guard-values note" didn't verify subagent isolation) is resolved — Other changed content, no findings:
Author-claimed, not independently re-run by me: Out of scope for this lane: security angle of this diff already covered by the security-review lane on this PR (no issues found, run multiple times). |
|
Claude finished @kyle-sexton's task in 1m 44s —— View job Security review: no issues found
This is a docs-only change to the Content review:
Instruction-surface deletion lens (register, Gate 0 classes: irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority): none of the reworded lines in No CRITICAL, IMPORTANT, or SUGGESTION findings. |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 3m 16s —— View job Security review: no issues found
Reviewed at the pinned This is a docs-only change to the Content review:
Instruction-surface deletion lens (register, Gate 0 classes: irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority): none of the reworded or removed lines in Out of scope for this lane: the earlier code-review thread on whether the "guard-values note or the kill-switch probe" attribution covers all five placeholders is a documentation-accuracy question under No CRITICAL, IMPORTANT, or SUGGESTION findings. |
|
Claude finished @kyle-sexton's task in 3m 34s —— View job Code review
Reviewed at head No findings — every issue raised earlier in this PR's review history is resolved at this head:
Author-claimed, not independently re-run by me (Bash tool required approval I didn't have in this session): Out of scope for this lane: security angle of this diff already covered by the security-review lane on this PR (no issues found, run multiple times). |
|
Claude finished @kyle-sexton's task in 2m 13s —— View job Security review: no issues found
This is a docs-only change to the Scoping this run: confirmed via Content review:
Instruction-surface deletion lens (register, present in this checkout; Gate 0 classes: irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority): none of the reworded lines remove or soften a rule in those classes. The mutation-guard contract is carried forward verbatim; this diff only re-attributes placeholder sources more precisely. No CRITICAL, IMPORTANT, or SUGGESTION findings. |
Renumber disk-hygiene to 0.32.2 above main's 0.32.1. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Renumber disk-hygiene to 0.33.1 above main's 0.33.0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 2m 1s —— View job Code review
Reviewed via No new findings. This PR has had 8 prior review passes (code-review and security-review) across its commit history, and every finding raised along the way — Codex's P1 on the unverifiable hook-delivery claim, and this lane's finding that the "guard-values note or kill-switch probe" attribution overstated the source for Independently re-verified against source for this pass:
Out of scope for this lane: security angle already covered by the security-review lane on this PR (no issues found, run multiple times). |
|
Claude finished @kyle-sexton's task in 1m 7s —— View job Security review: no issues found
This is a docs-only change to the Scoping this run: Content review:
Instruction-surface deletion lens: consulted No CRITICAL, IMPORTANT, or SUGGESTION findings. |
Renumber disk-hygiene to 0.33.2 above main's 0.33.1. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 54s —— View job Code review
Reviewed No new findings. produces no output — both files are byte-identical to the already-cleared commit. The only change since is administrative: Verified for this pass:
Out of scope for this lane: security angle of this diff already covered by the security-review lane on this PR (no issues found, run multiple times). |
|
Claude finished @kyle-sexton's task in 1m 28s —— View job Security review: no issues found
Skip-gate hit: this head already has a successful security review that still applies. Current head
Content already verified in prior passes on this PR (re-confirmed unchanged here):
Instruction-surface deletion lens ( No CRITICAL, IMPORTANT, or SUGGESTION findings. |
|
Claude finished @kyle-sexton's task in 33s —— View job Security review: no issues found
Skip-gate hit: this head already has a successful security review that still applies. Current head produces no output — all five files this PR actually touches (per the changed-files list) are byte-identical to Content already verified in prior passes on this PR (unchanged at this head):
Instruction-surface deletion lens ( No CRITICAL, IMPORTANT, or SUGGESTION findings. |
|
Claude finished @kyle-sexton's task in 31s —— View job Code review
Skip-gate hit: this head already has a successful review from this lane that still applies. Current head produces no output — all five files this PR touches (confirmed against Content already verified in prior passes on this PR (unchanged at this head):
No new findings. Out of scope for this lane: security angle of this diff already covered by the security-review lane on this PR (no issues found, run multiple times). |
Renumber disk-hygiene to 0.34.1 above main's 0.34.0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 55s —— View job Security review: no issues found
Skip-gate hit: this head already has a successful security review that still applies. Current head The actual PR diff ( Content already verified in prior passes on this PR (unchanged at this head):
Instruction-surface deletion lens ( No CRITICAL, IMPORTANT, or SUGGESTION findings. |
|
Claude finished @kyle-sexton's task in 1m 34s —— View job Code review
Skip-gate hit: this head already has a successful review from this lane that still applies. Current head I confirmed via
No new findings. Every substantive issue raised across this PR's review history — Codex's P1 on the unverifiable hook-delivery claim, and this lane's finding that the "guard-values note or kill-switch probe" attribution overstated the source for Out of scope for this lane: security angle of this diff already covered by the security-review lane on this PR (no issues found, run multiple times). Branch: |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 49s —— View job Code review
Skip-gate hit: this head already has a successful review from this lane that still applies. Current head
Content already verified in prior passes on this PR (unchanged at this head):
No new findings. Every substantive issue raised across this PR's review history — Codex's P1 on the unverifiable hook-delivery claim, and this lane's finding that the "guard-values note or kill-switch probe" attribution overstated the source for Out of scope for this lane: security angle of this diff already covered by the security-review lane on this PR (no issues found, run multiple times). |
|
Claude finished @kyle-sexton's task in 1m 3s —— View job Security review: no issues found
Skip-gate hit: this head already has a successful security review that still applies. Current head
Content already verified in prior passes on this PR (unchanged at this head):
Instruction-surface deletion lens ( No CRITICAL, IMPORTANT, or SUGGESTION findings. |
…on and keep no per-path entries (#5587) Closes #4009 ## Summary The owner decided on 2026-09-29 and 2026-09-30 that `scan --sizes-only` keeps walking VCS and protected directories but goes through the same large-scan confirmation gate as an ordinary unbounded walk, and sums sizes without keeping one entry per path in memory. This PR implements that decision. ## Fix - `hygiene.py`: removed the `not sizes_only` exemption from both large-scan confirmation checks (plain-target and `--root-children` paths). VCS and protected-path walking under `sizes_only` is unchanged, so totals stay exact. - `scan_tree` adds sizes straight into the per-child rollup and target total when `sizes_only` is set and appends no entries. Payload shape and the `inventory_mode: sizes-only` / `rollup_precision` markers are unchanged; ordinary scans and their entry cap are unchanged. - Tests: gate test (both paths, with and without `--confirmed-large-scan`), and a memory test (no per-path entries, totals equal to an ordinary unbounded scan). - Docs: SKILL.md, `scan-flags.md`, `safety-model.md`, README and the fan-out worker brief (template carries `--confirmed-large-scan`) state the gated behavior. - disk-hygiene 0.30.0 to 0.30.1 with a CHANGELOG entry; released entries are left as written and the new entry supersedes them. ## Verification - `scripts/check-changelog-parity.sh --check`, `--check-order`, `--check-bump origin/main`: pass. - `scripts/validate-plugins.sh`: all manifests and the catalog validated. - `python3 test_hygiene.py` (549 tests), `test_engine_context.py` (8), `test_guard_launch_monitor.py` (46), `test_kill_switch_probe.py` (20): OK. - `scripts/affected-tests.sh --run` reports failing suites outside disk-hygiene's touched behavior (evals, session-flow, babysit-prs, contract-clause coverage); these come from merged main content and are not changed here. CI is the record. ## Related Refs #4832 (introduced `--sizes-only`), #5336 (documented the earlier behavior), #5571 (docs PR touching the same brief). 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Refs: #5516 ## Hold: do not merge The `do-not-merge` label is applied. Owner condition 4 on #5516 says to probe the guard `ask` on `apply --execute` under `bypassPermissions` before the skill ships. Lane c was not run: the auto-mode classifier denied the launch script and the denial was not worked around. Auto mode, this machine's default, was not probed either. Release the hold only after the owner runs lane c (`claude -p --permission-mode bypassPermissions --tools Bash`, same scratch target and prompt as lanes a and b) or accepts the gap in a comment here or on #5516. If lane c fails open, condition 4 says fall back to A2 for that lane. Second owner question: the argument-free kill-switch probe is not matched by the engine-gate filter, so a delegated audit in default mode stops at step 1 without a user allow rule for the probe. Accept that, or add the allow rule. Merge order: #5571 first, then this PR (see Related). ## Summary Adds `/disk-hygiene:audit`, a model-invocable, read-only skill that runs the kill-switch probe and one engine `scan` and reports the snapshot. It runs no `preview` or `apply`; removal stays a separate `/disk-hygiene:clean` run a person invokes. `clean` is unchanged. Ships together with #5571 (#5520). ## Fix - `skills/audit/SKILL.md` and `evals/evals.json` (three delegated-audit cases and one negative case where "clean up my disk / delete these" must route to `/disk-hygiene:clean`). - The scan template takes a `<project-dir>` placeholder (a literal absolute path, optional) in place of `${CLAUDE_PROJECT_DIR}`, and the skill tells the parent to replace every `${...}` token and `<placeholder>` in the fan-out worker brief with the probe's `hook_python` and `data_root` before spawning, since a worker cannot expand tokens. - The inline `--plugin-dir` `data_root: null` gotcha carries a claim, basis, as-of and recheck record. The null-`data_root` eval no longer expects a guard denial to relay: no engine call is submitted in that case. - `audit` is registered in `scripts/skill-leaf-name-registry.txt` with disk-hygiene as its 17th owner and a rationale paragraph. - README lists the skill; plugin 0.30.0 to 0.35.0 (main took 0.31.0 to 0.34.1 for other disk-hygiene changes while this PR was open) with a CHANGELOG entry linked to #5516; cheat sheet regenerated. - Audit-only (toggle off) still runs the read-only scan and drops the removal handoff, instead of stopping. The owner decision is silent on this; the owner may overrule. ## Verification Probe results (claude 2.1.285, worktree plugin loaded with `--plugin-dir`, `permission-mode default`, fresh scratch target): - Lane a, headless default: `apply --execute` denied by the guard (`exact-engine-apply`, ask); `staging.tmp` survived. - Lane b, `--bg` default: parked at a permission prompt on the apply; `staging.tmp` survived. - Lane c, `bypassPermissions`: not probed. Auto mode (this machine's default) not probed. - The argument-free probe is not matched by the engine-gate filter (`Bash(*hygiene.py*)`), so a default-mode model-invoked session needs a user approval or allow rule to run it. Under `--plugin-dir` the probe reports `data_root` null. Checks run locally on a9f61a8 (after merging origin/main and renumbering 0.34.0 to 0.35.0), all exit 0: `check-skill-leaf-names.sh --check` and its `.test.sh`; `check-adr-numbers.sh --check`; `check-changelog-parity.sh --check`, `--check-order`, `--check-bump origin/main`; `validate-plugins.sh`; `check-changed-skills.sh origin/main`; `check-skill-count-claims.sh`; `check-spoke-plugin-root.sh --check`; `check-docs-naming.sh --check`; `check-orphaned-fixtures.sh --check`; `generate-cheatsheet.mjs --check`; `check-evals-quality.sh` and `json.tool` on the audit evals; `hygiene.test.sh` (592 tests, 1 skipped) and `kill_switch_probe.test.sh`. The earlier "all pass" was wrong: on 4c4faf7 CI `lint-2` failed `skill-leaf-names` (fixed by the registry entry) and `adr-numbers` (a duplicate 0042 on main, fixed by main's renumber, which this branch now includes). The A2 fallback and the final call on closing #5516 stay with the owner, so this PR uses `Refs`, not `Closes`. ## Related #5516; #5520 / #5571 (ships together). Merge order: #5571 lands first. This PR links its worker brief, which still shows `${CLAUDE_PLUGIN_DATA}` and `${CLAUDE_PROJECT_DIR}` tokens until #5571 lands. #5571 is stale: its base predates main's 0.29.2 through 0.31.0 changelog entries, so it needs a rebase and a renumber above main's current version before it can merge. disk-hygiene versions on main keep moving, so before this PR merges, merge main and re-run `scripts/check-changelog-parity.sh --check-bump origin/main`, renumbering above main's then-current version. The repo squash-merges only, so the branch's `bump to 0.30.0` commit subject does not reach main. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

Closes #5520
Summary
/disk-hygiene:cleandocs said the agent creates the run directory (the engine does), the fan-out worker brief used${...}tokens a subagent cannot expand, and every template showed--project-diralthough it is optional.Fix
skills/clean/SKILL.mdsection 1: choose a unique run-directory path; the engine creates it.skills/clean/reference/fan-out-worker-brief.md: new parent step fills<hook-python>,<engine>,<data-root>,<run-dir>and optional<project-dir>with literal absolute values before spawning; templates use those placeholders;--project-diris documented as optional. The engine-gate wording (item 3) was already correct on main.disk-hygiene0.29.0 to 0.29.1 with a CHANGELOG entry.Verification
scripts/check-changelog-parity.sh --check --check-order: passes.scripts/validate-plugins.sh: all manifests and the catalog validate.Related
Split from #5214. Related: #4215, #4009.
🤖 Generated with Claude Code