Skip to content

fix(disk-hygiene): add model-invocable /disk-hygiene:check and name it in the missing-Python notice - #5615

Merged
kyle-sexton merged 9 commits into
mainfrom
fix/5436-disk-hygiene-check-skill
Sep 30, 2026
Merged

kyle-sexton merged 9 commits into
mainfrom
fix/5436-disk-hygiene-check-skill

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Closes #5436

Summary

The missing-Python hook notice in disk-hygiene told the user to run /disk-hygiene:setup check, which carries disable-model-invocation: true, so Claude could not run it. docs/plugin-philosophy.md says a hook or probe names /<plugin>:check instead.

Fix

  • New plugins/disk-hygiene/skills/check/SKILL.md (with evals): a model-invocable, read-only probe that reads setup's check section and installs nothing.
  • _NO_PYTHON_FIX in hooks/run-python-hook.sh now ends with /disk-hygiene:check; the two assertions in run-python-hook.test.sh follow.
  • README, docs/skill-cheat-sheet.md and scripts/skill-leaf-name-registry.txt list the new skill.
  • disk-hygiene bumped to 0.38.0 with a CHANGELOG entry.

Verification

  • bash plugins/disk-hygiene/hooks/run-python-hook.test.sh: PASS, all run-python-hook contract checks.
  • scripts/validate-plugins.sh: all plugin manifests and the catalog validated.
  • scripts/check-changelog-parity.sh --check, --check-order, --check-bump origin/main: all pass.

Related

Refs #4240, #5377 (the rule this notice now follows).

🤖 Generated with Claude Code

kyle-sexton and others added 4 commits September 30, 2026 14:04
Refs #5436

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ene:check

Refs #5436

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kyle-sexton
kyle-sexton marked this pull request as ready for review September 30, 2026 18:12
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T18:18:08.437290Z bf9f4e8 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 42s —— View job


Security review — PR #5615

  • Gather context (diff, changed files, CLAUDE.md/AGENTS.md conventions)
  • Invoke /review:security-review and follow its instructions exactly
  • Post findings (or clean bill) to this comment

Scope reviewed (all 9 changed files, diffed against origin/main): the new model-invocable
/disk-hygiene:check skill and its evals, the run-python-hook.sh/.test.sh remedy-string
change, and the README/CHANGELOG/plugin.json/registry doc updates.

No security issues found.

Notes from the pass:

  • Instruction-surface lens: the diff redirects a hook remedy string from
    /disk-hygiene:setup check (disable-model-invocation: true) to the new
    /disk-hygiene:check (disable-model-invocation: false), which does widen what Claude can
    auto-invoke. This isn't a Gate 0 deletion/softening, though: the new skill is read-only by its
    own allowed-tools allowlist, explicitly forbids apply/install/PATH changes in its Gotchas
    section, and the skill's own evals (evals.json)
    assert that an install request routed through it is not performed and gets redirected to
    /disk-hygiene:setup apply instead. docs/conventions/instruction-exception-register/README.md
    is present and was consulted; no Gate 0 class (irreversible-action, secret-handling,
    data-integrity, external-publication, legal-compliance, agent-authority) is weakened here.
  • Bash allowed-tools wildcards: skills/check/SKILL.md
    adds patterns like Bash(command -v *) and Bash(grep -m1 *). Bash allow-rules match as a glob
    over the literal command string, so a trailing * doesn't itself guarantee argument-safety —
    but this is an existing, repo-wide convention (e.g. plugins/playwright/skills/check/SKILL.md's
    Bash(command -v *), plugins/firecrawl/skills/update/SKILL.md's
    Bash(grep -m1 *UPSTREAM.md*)), not something new introduced by this PR, and the permission-grant
    hygiene convention/detector (plugins/claude-config/skills/audit-permission-grants) already owns
    auditing this shape. Not raised as a PR-specific finding.
  • GitHub Actions hardening is out of scope for this lane (zizmor's), and none of the changed files
    touch workflow config regardless.

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 49s —— View job


Code review complete

  • Gather context (PR diff, changed files, custom instructions)
  • Invoke /review:code-review per custom instructions
  • Post inline findings
  • Post summary comment

Summary

Reviewed the diff against origin/main (9 files, +102/-7). The PR does what it says: it adds a model-invocable /disk-hygiene:check skill and repoints _NO_PYTHON_FIX and the README at it instead of the manual-only /disk-hygiene:setup check. README/CHANGELOG/registry/cheat-sheet updates and the run-python-hook.test.sh assertion updates are consistent with the change.

1 finding posted inline on plugins/disk-hygiene/skills/check/SKILL.md (lines 5-12):

The new skill's allowed-tools list doesn't cover everything the check section it delegates to (setup/SKILL.md) actually needs to run under the Bash tool:

  • Step 2's Python-floor version probe (distinct from the stub-classification python3_alias_probe.py, which I confirmed never reports a version) has no matching allowed-tools pattern at all.
  • Step 5's kill_switch_probe.py is only permitted via the literal python3 launcher, but setup instructs running it "with the step-2 interpreter" — which is python, py -3, or an absolute path whenever python3 is the WindowsApps stub, exactly the scenario this skill exists to diagnose.

Since this skill is meant to run without a permission prompt (that's the whole point of making it model-invocable instead of routing through the manual setup skill), a Bash call outside the allow-list either stalls on a prompt or fails outright in a non-interactive caller. Details and a repro scenario are in the inline comment:

allowed-tools:
- "Bash(command -v *)"
- "Bash(git --version*)"
- "Bash(grep -m1 *)"
- "Bash(py -3 *python3_alias_probe.py*)"
- "Bash(python *python3_alias_probe.py*)"
- "Bash(python3 *kill_switch_probe.py*)"
- "Bash(python3 *python3_alias_probe.py*)"

Everything else in the diff (hook fix, tests, docs, registry, CHANGELOG/version bump) looked correct and consistent; I didn't find other issues meeting the high-signal bar.

Comment thread plugins/disk-hygiene/skills/check/SKILL.md Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bf9f4e8e0e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/disk-hygiene/skills/check/SKILL.md Outdated
…owed-tools

Wildcarded python/py rules grant nothing under auto mode and trip the
permission-rule-hygiene P1 check, so the probes run under the session's
normal permissions. Merges origin/main.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 17s —— View job


Code review complete

  • Gather context (PR diff, changed files, CLAUDE.md/AGENTS.md conventions)
  • Invoke /review:code-review and follow its instructions exactly
  • Post inline findings
  • Post summary comment

Summary

Reviewed the diff against origin/main at head 0a4aff6 (9 files, +101/-7). This head adds the
latest commit, 0a4aff6, which drops the python3/python/py -3 wildcard grants that the
prior review round (Codex P2, and the earlier Claude inline finding on this PR) flagged —
the remaining allowed-tools now covers only command -v, git --version, and grep -m1, and
the skill text now says explicitly that the interpreter probes "are not pre-granted" and run
under the session's normal permissions instead. That's a reasonable, self-aware trade (documented
in the skill body and the CHANGELOG) rather than an oversight, so I didn't re-raise it. The hook
fix, test assertion updates, README/CHANGELOG/registry/cheat-sheet updates, and evals.json schema
all check out against precedent (plugins/playwright/skills/check/) and the repo's ## Next
convention.

1 finding posted inline on plugins/disk-hygiene/skills/check/SKILL.md:7:

Bash(git --version*) in the skill's allowed-tools doesn't correspond to anything the check
flow actually runs. The check section it delegates to
(setup/SKILL.md step 3, "Git")
only ever runs command -v git, already covered by the Bash(command -v *) pattern on line 6.
git --version doesn't appear anywhere else in either setup/SKILL.md or check/SKILL.md — I
grepped both files and the only hit is the allow-rule itself. It's dead permission surface in a
file whose latest commit specifically trimmed allowed-tools to match exactly what check
needs.

Everything else in the diff (hook fix, tests, docs, registry, CHANGELOG/version bump) looked
correct and consistent; I didn't find other issues meeting the high-signal bar.

Verification: I was not able to run the author's cited commands
(run-python-hook.test.sh, validate-plugins.sh, check-changelog-parity.sh) myself — Bash
execution in this environment required interactive approval that wasn't available — so those
results are author-claimed and unverified by me. Everything above is from static reading of the
diff and the files it references.

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 38s —— View job


Security review — PR #5615 (re-run at 0a4aff6)

  • Gather context (diff, changed files, CLAUDE.md/AGENTS.md conventions)
  • Invoke /review:security-review and follow its instructions exactly
  • Post findings to this comment and inline

Scope reviewed (all 9 changed files, origin/main...HEAD at 0a4aff61a9bd06c08d3ee3473a4e05bfde06ce00): the new model-invocable /disk-hygiene:check skill and its evals, the run-python-hook.sh / .test.sh remedy-string change, and the README/CHANGELOG/plugin.json/registry doc updates. The latest commit (0a4aff6) already dropped the wildcarded python/py interpreter grants that the earlier Codex review flagged as a P1 permission-rule-hygiene violation — that issue is resolved.

1 new finding, posted inline on plugins/disk-hygiene/skills/check/SKILL.md line 8 (IMPORTANT):

The allowed-tools grant "Bash(grep -m1 *)" is unscoped — it matches grep -m1 against any pattern and any file, not just the one call this skill's delegated check section actually makes (grep -m1 '^MIN_PYTHON' "${CLAUDE_PLUGIN_ROOT}/skills/clean/scripts/hygiene.py"). Because this skill is disable-model-invocation: false specifically so it runs without a permission prompt, any grep -m1 <pattern> <path> issued while it's active — e.g. grep -m1 '.' ~/.ssh/id_rsa or grep -m1 password some/.env — executes unattended. A model nudged off-script mid-check (injected instruction elsewhere in context, or its own misreading of "run each probe it names") can read the first line of any file on the host with no confirmation dialog. plugins/firecrawl/skills/update/SKILL.md's grant for the analogous check is anchored to the one file it reads (Bash(grep -m1 *UPSTREAM.md*)); this grant has no equivalent anchor. Fix direction: scope to what the probe actually runs, e.g. Bash(grep -m1 '^MIN_PYTHON' *) or Bash(grep -m1 *hygiene.py*).

Instruction-surface lens (consulted docs/conventions/instruction-exception-register/README.md, present in the tree): repointing the hook notice and README from /disk-hygiene:setup check (disable-model-invocation: true) to the new /disk-hygiene:check (disable-model-invocation: false) does widen what Claude can auto-invoke, but it's additive — /disk-hygiene:setup check still exists unchanged — not a deletion, narrowing, or softening of a standing instruction. No Gate 0 class (irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority) is weakened by the repoint itself; the grep grant above is the concrete way this new surface falls short of its own read-only intent, not the repoint.

Everything else in the diff (hook remedy string, test assertions, README/CHANGELOG/registry/plugin.json updates, evals.json) is doc/version/string-only and carries no security-relevant surface.
· branch fix/5436-disk-hygiene-check-skill

Comment thread plugins/disk-hygiene/skills/check/SKILL.md Outdated
Comment thread plugins/disk-hygiene/skills/check/SKILL.md Outdated
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 8s —— View job


Security review — PR #5615 (re-run at ebad52e)

  • Gather context (diff, changed files, CLAUDE.md/AGENTS.md conventions)
  • Invoke /review:security-review and follow its instructions exactly
  • Post findings to this comment

Skip gate hit: no new security-relevant surface since the last completed review.

ebad52e is chore(disk-hygiene): merge origin/main into the check skill branch — a merge
commit. Diffed against the previously security-reviewed commit 0a4aff6, every file this PR
touches (plugins/disk-hygiene/skills/check/SKILL.md, evals/evals.json, hooks/run-python-hook.sh,
hooks/run-python-hook.test.sh, README.md, CHANGELOG.md, .claude-plugin/plugin.json,
docs/skill-cheat-sheet.md, scripts/skill-leaf-name-registry.txt) is byte-identical — I ran
git diff 0a4aff6 ebad52e -- scoped to each and got no output. The merge only pulled in unrelated
origin/main history (code-metrics changes, destructive_guard.py, a new test_hygiene.py),
none of which are part of this PR's diff against origin/main (git diff origin/main...HEAD --stat
still shows exactly the 9 files / +101/-7 from the PR description).

That means the prior completed security review at 0a4aff6
still applies as-is:

  • Its one finding — Bash(grep -m1 *) in
    plugins/disk-hygiene/skills/check/SKILL.md
    is unscoped, letting this no-prompt, model-invocable skill run grep -m1 <any-pattern> <any-file>
    unattended — remains present and unresolved in the current diff. The author's reply on that
    thread addressed the interpreter-wildcard removal (0a4aff6), not this grant; it's still open.
  • The instruction-surface repoint (/disk-hygiene:setup check, disable-model-invocation: true →
    /disk-hygiene:check, disable-model-invocation: false) is still additive, not a Gate-0
    deletion/narrowing (docs/conventions/instruction-exception-register/README.md consulted again,
    present in the tree) — unchanged assessment from the prior pass.
  • No new files or lines were introduced by this synchronize event for this lane to review.

No new findings to post. Re-flagging only as a pointer since the underlying issue is unresolved:
scope the grant, e.g. Bash(grep -m1 '^MIN_PYTHON' *).
· branch fix/5436-disk-hygiene-check-skill

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 53s —— View job


Code review complete

  • Gather context (PR diff, changed files, CLAUDE.md/AGENTS.md conventions)
  • Invoke /review:code-review and follow its instructions exactly
  • Post inline findings
  • Post summary comment

Summary

This run was triggered by a synchronize event, but the new commit (ebad52e, "merge origin/main
into the check skill branch") is a merge commit only. I diffed the PR's 9 files between the
previously-reviewed head (0a4aff6) and the current head (ebad52e): they are byte-identical.
The merge pulled in unrelated origin/main history (e.g. the engine-gate dedupe fix, #5526) that
lands outside this PR's diff against origin/main — git diff origin/main...HEAD --stat still
shows exactly the same 9 files, +101/-7, as the last reviewed round.

Per the lane's skip gate ("this head already has a successful review from this lane that still
applies"), there's no new review surface to cover. The prior round's findings stand:

  • The Bash(git --version*) dead-permission finding on
    skills/check/SKILL.md:7
    is still unresolved in this diff — git --version still doesn't appear anywhere in setup/SKILL.md
    or check/SKILL.md, and command -v git (already covered by line 6's pattern) remains the only
    git-related check the delegated check section runs.
  • The unscoped Bash(grep -m1 *) finding on
    skills/check/SKILL.md:8
    is also unresolved (flagged separately by this lane and by security review); that's a
    security-classed finding and is properly the security lane's to re-raise, not re-posted here.

No new inline comments posted since no new lines changed. If a future push touches
skills/check/SKILL.md's allowed-tools block, this lane will re-review it fresh.
· branch fix/5436-disk-hygiene-check-skill

…37.0

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 2s —— View job


Security review — PR #5615 (re-run at 20c7b80)

  • Gather context (diff, changed files, CLAUDE.md/AGENTS.md conventions)
  • Invoke /review:security-review and follow its instructions exactly
  • Post findings to this comment

Skip gate hit: no new security-relevant surface since the last completed review.

20c7b80 is chore(disk-hygiene): merge origin/main and bump the check skill to 0.37.0. Diffed
against the previously security-reviewed commit ebad52e, none of this PR's 9 files changed in
content:

  • plugins/disk-hygiene/skills/check/SKILL.md, evals/evals.json, hooks/run-python-hook.sh,
    hooks/run-python-hook.test.sh are byte-identical to ebad52e.
  • plugins/disk-hygiene/.claude-plugin/plugin.json (0.36.0 → 0.37.0), CHANGELOG.md (new
    [0.37.0] heading), docs/skill-cheat-sheet.md, and scripts/skill-leaf-name-registry.txt only
    picked up an unrelated /disk-hygiene:audit entry (issue disk-hygiene: model-invocable read-only audit skill for orchestrators and subagents #5516 / PR feat(disk-hygiene): add model-invocable read-only audit skill #5590) that landed on
    origin/main and was pulled in by the merge — not part of this PR's own diff. README.md is
    unchanged from ebad52e.
  • git diff origin/main...HEAD --stat still shows exactly the 9 files / +101/-7 from the PR
    description; git diff origin/main...HEAD for each file above confirms the version bump and
    registry line are the only new content, both doc/metadata-only.

That means the prior completed security review at ebad52e
still applies as-is:

  • Its one open finding — Bash(grep -m1 *) in
    plugins/disk-hygiene/skills/check/SKILL.md
    is still unscoped, letting this no-prompt, model-invocable skill run grep -m1 <any-pattern> <any-file>
    unattended — remains present and unresolved. Fix direction unchanged: scope it to the one probe
    setup/SKILL.md's check section actually runs, e.g. Bash(grep -m1 '^MIN_PYTHON' *).
  • The instruction-surface repoint (/disk-hygiene:setup check, disable-model-invocation: true →
    /disk-hygiene:check, disable-model-invocation: false) is still additive, not a Gate-0
    deletion/narrowing (docs/conventions/instruction-exception-register/README.md present in the
    tree and consulted again) — unchanged assessment from every prior pass.
  • No new files or lines were introduced by this merge for this lane to review.

No new findings to post. Re-flagging only as a pointer since the underlying issue is unresolved:
scope the grep -m1 grant, e.g. Bash(grep -m1 '^MIN_PYTHON' *).
· branch fix/5436-disk-hygiene-check-skill

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 9s —— View job


Code review complete

  • Gather context (PR diff, changed files, CLAUDE.md/AGENTS.md conventions)
  • Invoke /review:code-review and follow its instructions exactly
  • Post inline findings
  • Post summary comment

Summary

This run was triggered by a synchronize event for the new head 20c7b80 ("merge origin/main and
bump the check skill to 0.37.0"). I diffed the reviewed file set between the last
code-review-lane-reviewed head (ebad52e) and 20c7b80: plugins/disk-hygiene/skills/check/SKILL.md,
skills/check/evals/evals.json, hooks/run-python-hook.sh, and hooks/run-python-hook.test.sh are
byte-identical. The only files that changed are README.md, CHANGELOG.md, .claude-plugin/plugin.json,
docs/skill-cheat-sheet.md, and scripts/skill-leaf-name-registry.txt — and those changes are purely
version-collision bookkeeping from merging origin/main (which meanwhile landed the unrelated
/disk-hygiene:audit skill, #5590, also at 0.36.0): this PR's own version bump moved from 0.36.0
to 0.37.0, the CHANGELOG entry moved under the new heading, and the cheat-sheet/registry lines
were re-sorted alongside audit's new entries. git diff origin/main...HEAD --stat still shows
exactly the same 9 files, +101/-7, as every prior round — no new review surface.

Per the lane's skip gate ("this head already has a successful review from this lane that still
applies"), there's nothing new to review here. The prior round's open finding still stands:

  • Bash(git --version*) in
    plugins/disk-hygiene/skills/check/SKILL.md:7
    is still unresolved — dead permission surface. The check section it delegates to
    (setup/SKILL.md step 3, "Git") only ever runs command -v git, already covered by
    Bash(command -v *) on line 6; git --version doesn't appear anywhere in setup/SKILL.md or
    check/SKILL.md.

The unscoped Bash(grep -m1 *) finding on line 8 remains open too but is security-classed and is
the security lane's to re-raise, not this one's.

No new inline comments posted since no line in the reviewed set changed.
· branch fix/5436-disk-hygiene-check-skill

…used git probe

The check flow only runs `grep -m1 '^MIN_PYTHON'` and `command -v git`,
so the grep grant is anchored to that pattern and `git --version` is removed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 5s —— View job


Code review complete

  • Gather context (PR diff, changed files, CLAUDE.md/AGENTS.md conventions)
  • Invoke /review:code-review and follow its instructions exactly
  • Post inline findings
  • Post summary comment

Summary

This run was triggered by a synchronize event for the new head 626f885 ("scope the check
skill's grep grant and drop the unused git probe"). This commit is a direct, targeted fix for
both findings this lane and the security lane had open against 20c7b80:

-  - "Bash(git --version*)"
-  - "Bash(grep -m1 *)"
+  - "Bash(grep -m1 '^MIN_PYTHON' *)"

Verified against
plugins/disk-hygiene/skills/check/SKILL.md
and the check section it delegates to
(setup/SKILL.md:91):

  • Bash(git --version*) dead-permission finding (this lane, 20c7b80): resolved. The grant
    is removed entirely. command -v git (the only git check check runs) remains covered by
    Bash(command -v *) on line 5.
  • Unscoped Bash(grep -m1 *) finding (security lane, same head): resolved. The grant is now
    anchored to the literal pattern the check flow actually runs,
    grep -m1 '^MIN_PYTHON' "${CLAUDE_PLUGIN_ROOT}/skills/clean/scripts/hygiene.py", matching the
    precedent cited earlier (plugins/firecrawl/skills/update/SKILL.md's
    Bash(grep -m1 *UPSTREAM.md*)). It no longer matches an arbitrary grep -m1 <pattern> <file>
    call.

No other lines changed in this commit, and no new issues were introduced by the fix. CHANGELOG.md's
existing [0.37.0] entry still accurately describes the feature; this tweak to an already-unreleased
skill doesn't need its own line.

No findings to report. Everything flagged across this PR's prior rounds (both lanes) is now
addressed.
· branch fix/5436-disk-hygiene-check-skill

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 48s —— View job


Security review — PR #5615 (re-run at 626f885)

  • Gather context (diff, changed files, CLAUDE.md/AGENTS.md conventions)
  • Invoke /review:security-review and follow its instructions exactly
  • Post findings to this comment

Scope reviewed: 626f885 is fix(disk-hygiene): scope the check skill's grep grant and drop the unused git probe, a single-file change against the previously-reviewed 20c7b80:

 allowed-tools:
   - "Bash(command -v *)"
-  - "Bash(git --version*)"
-  - "Bash(grep -m1 *)"
+  - "Bash(grep -m1 '^MIN_PYTHON' *)"

This resolves both open findings from the prior rounds:

  • Unscoped grep -m1 (security, IMPORTANT) — the grant is now anchored to '^MIN_PYTHON', matching the one call setup/SKILL.md line 91 makes (grep -m1 '^MIN_PYTHON' "${CLAUDE_PLUGIN_ROOT}/skills/clean/scripts/hygiene.py"). It can no longer be used to read an arbitrary file's first line via an unrelated pattern. Resolved.
  • Dead git --version* grant (code-review lane) — removed. check's delegated flow only ever runs command -v git (setup/SKILL.md:149), already covered by Bash(command -v *). Resolved.

No other files in the PR's diff changed in this commit (evals/evals.json, hooks/run-python-hook.sh/.test.sh, README/CHANGELOG/plugin.json/registry are untouched since the last reviewed head), so there's no new surface beyond the allowed-tools narrowing.

Instruction-surface lens (docs/conventions/instruction-exception-register/README.md consulted again): unchanged assessment from every prior pass — the repoint from /disk-hygiene:setup check (disable-model-invocation: true) to /disk-hygiene:check (disable-model-invocation: false) is additive, not a Gate-0 deletion/narrowing.

No open findings remain.
· branch fix/5436-disk-hygiene-check-skill

…38.0

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 54s —— View job


Security review — PR #5615 (re-run at 4eef663)

  • Gather context (diff, changed files, CLAUDE.md/AGENTS.md conventions)
  • Invoke /review:security-review and follow its instructions exactly
  • Post findings to this comment

Skip gate hit: no new security-relevant surface since the last completed review.

4eef663 is chore(disk-hygiene): merge origin/main and bump the check skill to 0.38.0. Diffed
against the previously security-reviewed commit 626f885:

  • plugins/disk-hygiene/skills/check/SKILL.md, skills/check/evals/evals.json, and
    hooks/run-python-hook.sh are byte-identical to 626f885.
  • hooks/run-python-hook.test.sh only gained an appended block (the SessionStart no-node
    notice test) pulled in from origin/main's unrelated #5547; the two remedy-string assertions
    this PR itself added are untouched.
  • README.md, CHANGELOG.md, .claude-plugin/plugin.json picked up the version-collision bump
    to 0.38.0 and merged-in #5547 content; docs/skill-cheat-sheet.md and
    scripts/skill-leaf-name-registry.txt are unchanged since 626f885.
  • This PR's own diff against origin/main is still exactly the 9 files it has been for every
    round (docs/skill-cheat-sheet.md, plugin.json, CHANGELOG.md, README.md,
    hooks/run-python-hook.sh, hooks/run-python-hook.test.sh, skills/check/SKILL.md,
    skills/check/evals/evals.json, scripts/skill-leaf-name-registry.txt) — no new file, no new line
    in the security-relevant surface.

That means the prior completed security review at 626f885
still applies as-is:

  • Both previously open findings — the unscoped Bash(grep -m1 *) grant and the dead
    Bash(git --version*) grant on
    plugins/disk-hygiene/skills/check/SKILL.md —
    are resolved and remain resolved: allowed-tools still reads
    Bash(command -v *) / Bash(grep -m1 '^MIN_PYTHON' *), anchored to the one probe
    setup/SKILL.md (line 91) actually runs.
  • The instruction-surface repoint (/disk-hygiene:setup check,
    disable-model-invocation: true → /disk-hygiene:check, disable-model-invocation: false) is
    still additive, not a Gate-0 deletion/narrowing
    (docs/conventions/instruction-exception-register/README.md present in the tree and consulted
    again) — unchanged assessment from every prior pass.

No open findings remain.
· branch fix/5436-disk-hygiene-check-skill

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 13s —— View job


Code review complete

  • Gather context (PR diff, changed files, CLAUDE.md/AGENTS.md conventions)
  • Invoke /review:code-review and follow its instructions exactly
  • Post inline findings
  • Post summary comment

Summary

This run was triggered by a mention on the PR at head 4eef663 ("merge origin/main and bump the
check skill to 0.38.0"). gh pr diff 5615 confirms the PR's diff against origin/main is still
exactly the same 9 files, +100/-7, as the last fully-reviewed head (626f885):
docs/skill-cheat-sheet.md, plugins/disk-hygiene/.claude-plugin/plugin.json, CHANGELOG.md,
README.md, hooks/run-python-hook.sh, hooks/run-python-hook.test.sh,
skills/check/SKILL.md, skills/check/evals/evals.json, and
scripts/skill-leaf-name-registry.txt.

I diffed each of those files between 626f885 and 4eef663. The only changes are a version
bump (0.37.0 → 0.38.0), a new [0.38.0] CHANGELOG heading, and README/test.sh content pulled
in by merging the unrelated, already-merged #5547 ("declare node requirement and warn at
session start when it is missing") from origin/main — none of which touches this PR's own
review surface. skills/check/SKILL.md and skills/check/evals/evals.json are byte-identical to
626f885: the allowed-tools block is still

allowed-tools:
  - "Bash(command -v *)"
  - "Bash(grep -m1 '^MIN_PYTHON' *)"

with both previously-open findings — the dead Bash(git --version*) grant and the unscoped
Bash(grep -m1 *) grant — still resolved exactly as fixed in 626f885. hooks/run-python-hook.sh's
_NO_PYTHON_FIX remedy string and the two run-python-hook.test.sh assertions still read
/disk-hygiene:check, consistent with the new skill.

Per the lane's skip gate ("this head already has a successful review from this lane that still
applies"), there is no new review surface since the prior clean round at 626f885,
which reported no findings after the git --version / grep -m1 fixes landed. I re-verified that
conclusion still holds rather than re-deriving it.

No findings to report.
· branch fix/5436-disk-hygiene-check-skill

@kyle-sexton
kyle-sexton merged commit e8a4228 into main Sep 30, 2026
28 of 29 checks passed
@kyle-sexton
kyle-sexton deleted the fix/5436-disk-hygiene-check-skill branch September 30, 2026 19:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

hooks: disk-hygiene's missing-Python notice names /disk-hygiene:setup check, which the model cannot run

1 participant