fix(ai-slop): clear the post-purge full-repo audit findings (#4606) - #5586
Conversation
… surfaces (#4606) Rewrite the standards contract and its two generated plugin copies, the out-of-scope records and the attribution persist-findings note with the punctuation each sentence needs. Declare the purged paths in the ratchet list and exempt the generated native-surfaces view, which quotes native descriptions verbatim. Refs #4606 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Refs #4606 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Refs #4606 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Refs #4606 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Refs #4606 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Refs #4606 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Refs #4606 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Refs #4606 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Refs #4606 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Refs #4606 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Refs #4606 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Patch bumps and changelog entries for attribution, discovery, planning, rate-limit-guard and review, whose files lost em dashes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…udit-findings Conflict in plugins/planning/CHANGELOG.md resolved to main's side. The standards contract, its two plugin copies, and the planning and review manifests and changelogs take main's version, so the contract keeps its em dashes and no contract or plugin bump is needed for it. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ect changelog entries (#4606) The standards contract carries a semver, and changing it needs a contract version bump, a contract CHANGELOG entry, and a bump of both carrying plugins. The bump makes every consumer index at the current version mismatch until setup is re-run. Instead of paying that for a punctuation pass, the contract README and its two plugin copies stay as on main, are listed in em_dash_allowed_paths with the reason, and the comments in scripts/em-dash-purged-paths.txt that explain the exclusion are restored. - planning and review carry no change, so neither is bumped. - rate-limit-guard changed only its changelog wording, so the 0.9.1 bump and entry are dropped and the wording edit stays. - The discovery 0.25.14 entry now names the real change, the filler "in order to". - docs/out-of-scope/*.md gets its own comment in the purged-paths list instead of sitting under the convention documents comment. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…udit-findings Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…es, mark the native quote (#4606) Follow the owner's step 3 for planning, review and docs/conventions: purge the 31 em dashes in the standards contract, bump it to 1.0.1 with a changelog entry, regenerate both plugin copies, and bump planning and review. Declare the contract and its copies in em-dash-purged-paths.txt and drop their em_dash_allowed_paths entries. Fix the seven em dashes main's attribution golden fixtures added without moving any line, and have the native-overlap view generator mark an evidence line that quotes a native description with an ai-slop-ignore comment, so docs/native-surfaces.md needs no config exemption. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…udit-findings Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…are docs/adr as purged (#4606) The native-overlap view generator now adds the ai-slop-ignore comment to a `native description:` evidence line only, so an authored evidence line with an em dash is still reported. docs/adr is now in em-dash-purged-paths.txt so the purged decision records stay purged, and the list's header no longer names docs/adr as unpurged. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…udit-findings Main carries planning 0.51.0; the standards-contract purge entry moves to 0.51.1. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…nd narrow its scope (#4606) The em_dash_allowed_paths reason called docs/upstream snapshots of upstream material this repository does not author. The repository's own record says the reverse: the per-source ledgers are first-party prose, and the tree is not a vendor tree. The glob also covered docs/upstream/claude-code-mods, which scripts/em-dash-purged-paths.txt declares purged. - Name the six ledgers that still carry em dashes instead of docs/upstream/**, and describe them as unpurged campaign backlog, each entry deleted when its file is purged. - Narrow .claude/unhobble/** to .claude/unhobble/*/evidence/** so the live ledger and README stay at zero tolerance. - Reword the docs/upstream paragraph in em-dash-purged-paths.txt so it agrees with the new entries. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… by a separate reason (#4606) The _comment lead-in still said no authored file is exempt by volume and that both groups are allowed for a reason other than volume. The docs/upstream entries defer a purge of first-party prose, so only the unhobble evidence rests on a reason other than purge cost. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…udit-findings Renumber claude-ops to 0.77.1 above main's 0.77.0 and discovery to 0.25.18 above main's 0.25.17. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…udit-findings # Conflicts: # plugins/claude-ops/CHANGELOG.md
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Claude finished @kyle-sexton's task in 1m 1s —— View job Security review
No security issues found. This PR is a documentation/config punctuation-purge campaign (em dashes) plus one small script change. Reviewed under
Actions/CI hardening findings, if any existed, are out of scope for this lane (zizmor's advisory lane) — not applicable here since no workflow files changed. |
|
Claude finished @kyle-sexton's task in 4m 38s —— View job
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e24744927a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…udit-findings Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ption Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 1m 3s —— View job Security review
No security issues found. This head (
|
|
Claude finished @kyle-sexton's task in 2m 46s —— View job
|
Closes #4606
Summary
The full-repo ai-slop detector reports zero findings. The rule half landed in #5380; this PR clears the rest of criterion 1 by following the owner's 2026-09-30 decision on the issue. The four non-em-dash findings are fixed. Em dashes are purged in
docs/adr,docs/conventions(including the standards contract and its two plugin copies inplugins/planningandplugins/review),docs/out-of-scopeandplugins/attribution. Six first-partydocs/upstreamledgers and the frozen.claude/unhobbleevidence memos are allowed in.claude/ai-slop.jsonfor now, each with its reason written in_comment. Three decisions are left to the owner (see "Owner veto").Fix
docs/conventions/loop-lane/README.md, the filler "in order to" inplugins/discovery/skills/explore/SKILL.mdandreference/workflow.md, and the same filler inplugins/rate-limit-guard/CHANGELOG.md.docs/adr(ADR 0001 onward, one commit per ADR range), rewriting each with the punctuation the sentence needs. Indocs/out-of-scope,shared-surface-instruction-governance.mdwas the only record with an em dash, and it is purged.plugins/attribution:skills/audit/context/persist-findings.md, and therestated-factgolden casesc12,c14andc16, rewritten on the same lines so every expected span is unchanged. Thec24source is a verbatim upstream excerpt, so its passage sits inside anai-slop-ignoreregion instead of being rewritten. This is the repo's existing rule in the header ofscripts/em-dash-purged-paths.txt: what a file quotes from upstream "stays byte-exact inside ai-slop-ignore-marked regions". It is not a config exemption.docs/conventions/standards/README.mdhas its 31 em-dash lines rewritten, the contract isstandards-contract: 1.0.1with adocs/conventions/standards/CHANGELOG.mdentry, and both plugin copies are regenerated withscripts/sync-standards-contract.sh. Planning is 0.52.1 and review is 0.34.3. The contract and its copies are declared inscripts/em-dash-purged-paths.txt, socheck-purged-em-dashes.shholds them.audit-native-overlap generateappend anai-slop-ignorecomment to anative description:evidence line that carries an em dash, because the native description is quoted verbatim indocs/native-surfaces.md(the same byte-exact-quote rule as above). Authored evidence lines are never marked. The view is regenerated (two lines change), claude-ops is 0.77.2, andtest_overlap.pyhas a test for the marker.docs/native-surfaces.mdneeds no config exemption, so the exemption an earlier version of this PR carried is gone.docs/adr/*.mdanddocs/out-of-scope/*.mdinscripts/em-dash-purged-paths.txtand removeddocs/adr/**from that file's "absent on purpose" list, so the purged records stay purged (see "Owner veto", item 2).em_dash_allowed_pathsin.claude/ai-slop.jsonholds seven entries: the sixdocs/upstream/*.mdledgers that still carry em dashes, each named by file, and.claude/unhobble/*/evidence/**._commentstates the reasons (see "Owner veto", item 1).scripts/em-dash-purged-paths.txtnow says these entries defer a purge of first-party prose, so the two files agree.docs/upstream/claude-code-mods(declared purged) and every otherdocs/upstreamfile are not covered and stay at zero tolerance.origin/main: attribution 0.8.1, discovery 0.25.18, planning 0.52.1, review 0.34.3, claude-ops 0.77.2, each with a changelog entry. Therate-limit-guardchangelog wording fix carries no version change.The contract change has this consumer effect: a consuming repository's standards index at
standards-contract: 1.0.0is older than the bundled 1.0.1 contract. Skills report "index at v1.0.0, contract at v1.0.1: re-run setup to migrate" and route best-effort, and setup offers the guided migration. The step-3 purge is the reason for the bump. It also reverses the non-purge thatscripts/em-dash-purged-paths.txtused to document for the contract (see "Owner veto", item 3).Owner veto
em_dash_allowed_paths: sixdocs/upstreamledgers and.claude/unhobble/*/evidence/**. They reverse the config's zero-tolerance wording. The issue's step 4 recommended (b) on the premise thatdocs/upstreamholds upstream snapshots. By the repository's own record it does not:scripts/em-dash-purged-paths.txtsays "docs/upstream/ IS NOT A VENDOR TREE" and calls these per-source ledgers first-party prose, and the files agree (claude-code.mdis "What this marketplace decided about its own components";aihero-course.mdlists decided lanes). So thedocs/upstreamentries defer a purge of first-party prose; they do not exempt vendored text.aihero-shipping-course.md93,cursor-pstack.md67,aihero-course.md53,mattpocock-skills.md47,mattpocock-skills-v12-map.md37,humanlayer-skills.md7. Each is one file, sodocs/upstream/claude-code-modsand every other file there stay at zero tolerance, and an entry is deleted in the change that purges its file..claude/unhobble/*/evidence/**entry covers five research memos and decision verdicts (119 em dashes), the frozen record of one experiment run. The livestumbles.mdand the README are not exempt.docs/upstreamentries, the 304 rewrites follow as per-file PRs and those six entries are dropped. If the owner rejects the.claude/unhobbleentry, 119 rewrites of the frozen memos follow and that entry is dropped.docs/adr/*.mdanddocs/out-of-scope/*.mdinscripts/em-dash-purged-paths.txt. The file's own convention is to add a surface in the PR that purges it, so this PR does. It also turns the one-time purge of each directory into a standing CI gate (check-purged-em-dashes.sh): once this merges, an ADR or an out-of-scope record with an em dash fails CI, and any open PR that adds one goes red. The alternative is to drop either line (fordocs/adr/**, also restoring its "absent on purpose" wording), which leaves those records purged but not enforced.standards-contractbump to 1.0.1. The owner's step 3 ordered the contract purged, and changing the contract text forces a version bump. The bump makes every consuming repository's standards index (at 1.0.0) older than the bundled contract, so each gets the "re-run setup" prompt and best-effort routing until it does. It also reverses the non-purge thatscripts/em-dash-purged-paths.txtdocumented on purpose, because the contract and its two plugin copies inplugins/planningandplugins/reviewnow sit on that list. The alternative is to revert the contract, its changelog entry, the two copies and the planning and review bumps (0.51.1 and 0.34.3), restore the non-purge wording, and addem_dash_allowed_pathsentries for the contract and its two copies so the full-repo detector run stays at zero.Verification
Run from the worktree at head
9697ca0e2, which includesorigin/mainat27206c96e.bash plugins/ai-slop/skills/audit/scripts/detect.sh, every Summary line:scripts/check-changelog-parity.sh --check,--check-order,--check-bump origin/mainand--check-preserved origin/mainall exit 0.scripts/sync-standards-contract.sh --check:All 2 plugin copies match docs/conventions/standards/README.md.--check-bump origin/main:Contract changed vs origin/main with frontmatter, changelog, and every carrying plugin bumped.scripts/check-purged-em-dashes.sh:check-purged-em-dashes: 391 declared paths, 1382 files scanned, no em dashes.Its testscripts/check-purged-em-dashes.test.shpasses (24 of 24).scripts/check-adr-numbers.sh --checkexits 0.scripts/validate-plugins.sh:All plugin manifests and the catalog validated.overlap.py generate --check:docs/native-surfaces.md is in sync with docs/native-surfaces/records.json.scripts/run-ruff.sh checkandformat --checkpass onoverlap.pyandtest_overlap.py.markdownlint-cli2over the 49 changed markdown files:Summary: 0 issues in 0 files.scripts/affected-tests.sh --run --jobs 4over the diff, run at this head. Every selected suite passed except three that this worktree cannot run:scripts/check-html-assets.test.shandscripts/check-script-contract.test.sh(htmlhint is not installed here) andscripts/hook-census.test.sh(no strace). The runner does not execute 23 selected Python and Node suites; I ran 22 of them directly at this head and they pass, and the 23rd,plugins/session-flow/scripts/tests/test_save_point.py, needs pytest, which is not installed here. CI runscheck-html-assets.test.shandhook-census.test.shintest-linuxlegs 2 and 0; I did not findcheck-script-contract.test.shortest_save_point.pyin the job steps, so those two are unrun by me. The three failures are the missing tool, not an assertion. The ai-slopdetect.test.sh(242 cases),cross-check.test.sh(24 cases),overlap.test.shandtest_overlap.py(179 tests) were also run directly at this head and pass.CI on head
9697ca0e2(run 36770676069):lint,lint-2,hook-utils,test-linux (0)to(3)andci-statuspass. The PR is mergeable and its merge state is clean.Related
#5269, #5380, #3988, #4288, #5288
🤖 Generated with Claude Code