Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
43 commits
Select commit Hold shift + click to select a range
4f41e52
docs(topics): add Sonnet 5.5 prompting-digest brief
kyle-sexton Sep 30, 2026
491d401
docs(topics): add the approved Sonnet 5.5 prompting-digest plan
kyle-sexton Oct 1, 2026
4c14e79
docs(topics): record the Sonnet 5.5 parent and follow-on issues in th…
kyle-sexton Oct 1, 2026
d4ab318
Merge remote-tracking branch 'origin/main' into feat/sonnet-5-5-promp…
kyle-sexton Oct 1, 2026
11fcbe3
docs: adopt links-only verification records and convert existing records
kyle-sexton Oct 1, 2026
8e6534a
feat(playbooks): add the Sonnet 5.5 adaptation chapter and route Sonn…
kyle-sexton Oct 1, 2026
8f26f36
docs: name model aliases in tier tables and set a medium effort floor
kyle-sexton Oct 1, 2026
d0da46d
fix(verification): count only real checks and install declared depend…
kyle-sexton Oct 1, 2026
cf83b4d
fix(knowledge): repair docpage-digest pipeline defects and add the bl…
kyle-sexton Oct 1, 2026
ac6ee4a
fix(knowledge): tag blog rows by class and pair correction-round sear…
kyle-sexton Oct 1, 2026
e9a516d
fix(review): pin the verification agents at high effort and state the…
kyle-sexton Oct 1, 2026
2d1b04d
fix(playbooks): list Fable 5 as a current model
kyle-sexton Oct 1, 2026
a9f3620
feat(claude-config): extend audit and posture catalogs for Sonnet 5.5
kyle-sexton Oct 1, 2026
b7876f9
Merge remote-tracking branch 'origin/main' into feat/sonnet-5-5-promp…
kyle-sexton Oct 1, 2026
d891de9
fix(playbooks): replace the guide-quoting Sonnet 5.5 content from #5746
kyle-sexton Oct 1, 2026
5043c2a
revert(performance): hand the performance catalog to its source-artic…
kyle-sexton Oct 2, 2026
46a0f69
fix: re-derive drifted records and fold in the effort-pointer decisions
kyle-sexton Oct 2, 2026
510a641
fix: replace copied upstream passages found by the no-copy gate
kyle-sexton Oct 2, 2026
39f1ced
Merge remote-tracking branch 'origin/main' into feat/sonnet-5-5-promp…
kyle-sexton Oct 2, 2026
7061287
chore: move the Sonnet 5.5 plan out of docs/topics
kyle-sexton Oct 2, 2026
b23af40
fix(knowledge): point the model-alias record at its recorded probe
kyle-sexton Oct 2, 2026
d915c0e
Merge remote-tracking branch 'origin/main' into feat/sonnet-5-5-promp…
kyle-sexton Oct 2, 2026
0ad75bf
fix: clear the shell-portability lint on converted markdown
kyle-sexton Oct 2, 2026
c806020
docs: fold in the Spending Your Effort effort-doctrine decisions
kyle-sexton Oct 2, 2026
5559a70
fix(knowledge): dispatch docpage-digest's verifier A through Workflow…
kyle-sexton Oct 2, 2026
33a61b7
docs(philosophy): every named agent pins its effort
kyle-sexton Oct 2, 2026
e9cfaf2
Merge remote-tracking branch 'origin/main' into feat/sonnet-5-5-promp…
kyle-sexton Oct 2, 2026
570f965
Merge remote-tracking branch 'origin/main' into feat/sonnet-5-5-promp…
kyle-sexton Oct 2, 2026
009147d
fix(toolchain): tighten the dependency-install rule
kyle-sexton Oct 2, 2026
30ddfb9
Merge origin/main into feat/sonnet-5-5-prompting-digest
kyle-sexton Oct 2, 2026
750341a
fix(knowledge): verifier A falls back to an Agent dispatch without Wo…
kyle-sexton Oct 2, 2026
6161302
Merge origin/main into feat/sonnet-5-5-prompting-digest
kyle-sexton Oct 2, 2026
0bd968c
Merge origin/main into feat/sonnet-5-5-prompting-digest
kyle-sexton Oct 2, 2026
b89f93b
fix(harness-config): keep audit-instructions SKILL.md under the 500-l…
kyle-sexton Oct 2, 2026
3a76b08
Merge origin/main into feat/sonnet-5-5-prompting-digest
kyle-sexton Oct 2, 2026
eaa4f0f
fix: address the Codex review findings on #5767
kyle-sexton Oct 2, 2026
979d945
fix: address the substitute code review on #5767
kyle-sexton Oct 2, 2026
904924b
Merge origin/main into feat/sonnet-5-5-prompting-digest
kyle-sexton Oct 2, 2026
49ceccf
fix: address the Claude review findings on #5767
kyle-sexton Oct 2, 2026
a8d9f92
Merge origin/main into feat/sonnet-5-5-prompting-digest
kyle-sexton Oct 2, 2026
19884e0
Merge remote-tracking branch 'origin/main' into feat/sonnet-5-5-promp…
kyle-sexton Oct 2, 2026
7e0634b
Merge remote-tracking branch 'origin/main' into feat/sonnet-5-5-promp…
kyle-sexton Oct 2, 2026
cd9f363
Merge remote-tracking branch 'origin/main' into feat/sonnet-5-5-promp…
kyle-sexton Oct 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 8 additions & 7 deletions .claude/rules/skill-bodies-state-current-rules.md
Original file line number Diff line number Diff line change
@@ -1,18 +1,19 @@
---
description: "Skill and agent bodies carry a four-part verification record for any volatile specific they restate, and name their successor in a `## Next` section; read before editing any skill body"
description: "Skill and agent bodies point at the live upstream source for any volatile specific instead of restating it, recorded as pointer, as-of date and recheck trigger, and name their successor in a `## Next` section; read before editing any skill body"
paths:
- "plugins/*/skills/**"
- "plugins/*/agents/**"
---

# Skill bodies state current rules

A pointer to an external upstream source (an official doc page, an upstream issue) is required
when a skill or agent body restates a volatile specific it cannot defer to at read time, recorded
as the four-part verification record the
[upstream-drift convention](../../docs/conventions/upstream-drift/README.md) defines: claim,
basis, as-of date, recheck trigger. A dated verification with a trigger is the correct form; an
undated claim is the defect.
A skill or agent body that depends on a volatile upstream specific (an official doc page, an
upstream issue) never restates it, quoted or paraphrased. It states our decision in our own words
and records where to read the specific live, in the links-only record the
[upstream-drift convention](../../docs/conventions/upstream-drift/README.md#required-parts)
defines: pointer to the exact section, as-of date, recheck trigger. A body that needs the specific
at run time fetches it from the pointer. Restated upstream text is the defect, and so is a pointer
with no as-of date or no trigger.

## Successor sections

Expand Down
2 changes: 1 addition & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ and its content is not already in context, read the file directly.
|---|---|---|
| `.claude/rules/mod-authoring.md` | `plugins/*/hooks/**, plugins/*/types/**` | Mods stay deferred under ADR 0035: no plugin gains a `modules` key until its five go criteria pass; when they do, load the built-in `plugin-authoring` skill and the upstream mods docs first |
| `.claude/rules/ruff-pin.md` | `**/*.py` | Python linting runs through the pinned ruff wrapper, never a bare ruff on PATH |
| `.claude/rules/skill-bodies-state-current-rules.md` | `plugins/*/skills/**, plugins/*/agents/**` | Skill and agent bodies carry a four-part verification record for any volatile specific they restate, and name their successor in a `## Next` section; read before editing any skill body |
| `.claude/rules/skill-bodies-state-current-rules.md` | `plugins/*/skills/**, plugins/*/agents/**` | Skill and agent bodies point at the live upstream source for any volatile specific instead of restating it, recorded as pointer, as-of date and recheck trigger, and name their successor in a `## Next` section; read before editing any skill body |
| `plugins/attribution/skills/audit/AGENTS.md` | `plugins/attribution/skills/audit/**` | Editing the attribution audit skill: contributor conventions |
| `plugins/autonomy/AGENTS.md` | `plugins/autonomy/**` | autonomy plugin: contributor conventions |
| `plugins/machine-health/skills/audit/AGENTS.md` | `plugins/machine-health/skills/audit/**` | machine-health audit skill: contributor conventions |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ not mean a review blocks a merge.

This rule is the operator's. Anthropic does not document review on every pull request as a
requirement. Its launch post says it runs Code Review "on nearly every PR at Anthropic"
(<https://claude.com/blog/code-review>, fetched 2026-09-24); the product docs set no default
(correlate with <https://claude.com/blog/code-review>, fetched 2026-09-24); the product docs set no default
trigger, leaving an Owner to pick once, every push, or manual per repository
(<https://code.claude.com/docs/en/code-review>, fetched 2026-09-24); and Boris Cherny's Steps of
AI Adoption says "Automated code review and security review are on by default"
Expand Down
8 changes: 8 additions & 0 deletions docs/conventions/detector-findings/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,14 @@ Notable changes to the detector-findings contract (SemVer). Changing a producer-
the coexistence obligations, or an enforceability verdict is a major bump; additive guidance or a new
adopter row is a minor bump; docs-only clarification is a patch.

## [3.6.2] - 2026-10-01

**Patch, docs-only.** The `attribution/audit/rule-stamp-expired` and
`attribution/audit/rule-restated-upstream-fact` crosswalk rows and the
`harness-config/audit-instructions/rule-trigger-less-stamp` row describe the stamped record by its
current shape (pointer, as-of date, observable recheck trigger beside the decision) instead of the
claim, basis, as-of and trigger shape. No producer-owned field's rule, tier, coexistence obligation or enforceability verdict moves.

## [3.6.1] - 2026-10-01

**Patch, docs-only.** The rationale of `mutation-testing/audit/rule-survivor-productive` and
Expand Down
6 changes: 3 additions & 3 deletions docs/conventions/detector-findings/README.md

Large diffs are not rendered by default.

45 changes: 24 additions & 21 deletions docs/conventions/hook-config-delivery/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,28 +26,30 @@ with each plugin's own docs.

## Verified upstream behavior (version-pinned)

Each row carries its own verified version and date in the **Verified** column. Facts 1-8 were
verified on **Claude Code 2.1.218**: doc-stated facts re-fetched from the live official docs on
2026-07-24, behavioral facts proven by a controlled fresh-session probe (isolated
`claude -p --plugin-dir` runs with positive controls) on 2026-07-23. Facts 9-12 were measured on
**Claude Code 2.1.283** by a sandbox probe on 2026-09-27 (fixture `CLAUDE_CONFIG_DIR`, `HOME` and
`USERPROFILE` under a scratch directory, positive control of an empty plugin list before any write).
Existing state is not evidence of its own correctness: **recheck these facts** (triggers at the end
of this doc) before extending the matrix or relying on a row in new work.

| # | Fact | Basis | Verified |
Each row carries its own Claude Code version and date in the **As of** column. A doc-stated row
records what we rely on, in our words, and points at the section that states it; a probed row
records what our own probe observed. Rows 1-8 date from **Claude Code 2.1.218**: doc-stated rows
re-read from the live official docs on 2026-07-24, behavioral rows proven by a controlled
fresh-session probe (isolated `claude -p --plugin-dir` runs with positive controls) on 2026-07-23.
Rows 9-12 were measured on **Claude Code 2.1.283** by a sandbox probe on 2026-09-27 (fixture
`CLAUDE_CONFIG_DIR`, `HOME` and `USERPROFILE` under a scratch directory, positive control of an
empty plugin list before any write). Existing state is not evidence of its own correctness:
**recheck these facts** (triggers at the end of this doc) before extending the matrix or relying on
a row in new work.

| # | What we rely on | Pointer | As of |
|---|---|---|---|
| 1 | Plugin `hooks.json` hooks receive `${user_config.KEY}` in **exec form only**, substituted into `command` and each `args` element as a plain string; a shell-form command referencing it fails with an error instead of running (since 2.1.207) | doc-stated ([hooks](https://code.claude.com/docs/en/hooks)) | 2.1.218, 2026-07-24 |
| 2 | Configured values are exported to hook processes as `CLAUDE_PLUGIN_OPTION_<KEY>` (key uppercased) | doc-stated ([plugins-reference](https://code.claude.com/docs/en/plugins-reference#user-configuration)); scope narrowed by fact 4 | 2.1.218, 2026-07-24 |
| 3 | The declared `default` field ("Value used when the user provides nothing") is in the schema but **implemented for neither argv substitution nor env export**. An unset-but-defaulted `${user_config.*}` argv token **silently drops the entire hook entry**. It is not passed literally and not empty-substituted; the same unset key exports **no** env var | proven (probe T1); upstream [#46477](https://github.com/anthropics/claude-code/issues/46477) closed not-planned, [#39455](https://github.com/anthropics/claude-code/issues/39455) open, [#39827](https://github.com/anthropics/claude-code/issues/39827) closed not-planned; undocumented | 2.1.218, 2026-07-23 |
| 1 | `${user_config.KEY}` reaches a plugin `hooks.json` hook only in **exec form**, as a plain string in `command` and each `args` element; we never write it in a shell-form command | doc-stated ([Exec form and shell form](https://code.claude.com/docs/en/hooks#exec-form-and-shell-form)) | 2.1.218, 2026-07-24 |
| 2 | A hook process reads a configured value from `CLAUDE_PLUGIN_OPTION_<KEY>` (key uppercased) | doc-stated ([User configuration](https://code.claude.com/docs/en/plugins-reference#user-configuration)); scope narrowed by fact 4 | 2.1.218, 2026-07-24 |
| 3 | The declared `default` field is in the schema but **implemented for neither argv substitution nor env export**. An unset-but-defaulted `${user_config.*}` argv token **silently drops the entire hook entry**. It is not passed literally and not empty-substituted; the same unset key exports **no** env var | proven (probe T1); upstream [#46477](https://github.com/anthropics/claude-code/issues/46477) closed not-planned, [#39455](https://github.com/anthropics/claude-code/issues/39455) open, [#39827](https://github.com/anthropics/claude-code/issues/39827) closed not-planned; undocumented | 2.1.218, 2026-07-23 |
| 4 | Tamper split on the env channel: for a **configured** key, harness injection overwrites a repo `.claude/settings.json` `env` block (injection wins); for an **unconfigured** key nothing is injected and the repo's `env` block freely populates `CLAUDE_PLUGIN_OPTION_<KEY>`. Env carries no provenance, so a hook cannot tell the two apart | proven (probe T2/T2b); undocumented | 2.1.218, 2026-07-23 |
| 5 | `pluginConfigs` is written to user settings and read back from **user settings, the `--settings` flag, and managed settings only**; entries in a project's `.claude/settings.json` / `.claude/settings.local.json` are ignored (since 2.1.207) | doc-stated ([plugins-reference](https://code.claude.com/docs/en/plugins-reference#user-configuration)) | 2.1.218, 2026-07-24 |
| 5 | We treat `pluginConfigs` as living in **user settings, the `--settings` flag, and managed settings only**, and an entry in a project's `.claude/settings.json` / `.claude/settings.local.json` as ignored | doc-stated ([User configuration](https://code.claude.com/docs/en/plugins-reference#user-configuration)) | 2.1.218, 2026-07-24 |
| 6 | Skill- and agent-frontmatter hooks receive **neither** the argv substitution nor `CLAUDE_PLUGIN_OPTION_*` | evidence-strong (probe + field repro); CC docs silent | 2.1.218, 2026-07-23 |
| 7 | Skill/agent **body** `${user_config.KEY}` substitutes into model-visible content, non-sensitive values only | doc-stated ([plugins-reference](https://code.claude.com/docs/en/plugins-reference#user-configuration)) | 2.1.218, 2026-07-24 |
| 8 | Sensitive values are stored in the OS keychain (or `~/.claude/.credentials.json`), never in `settings.json` | doc-stated ([plugins-reference](https://code.claude.com/docs/en/plugins-reference#user-configuration)) | 2.1.218, 2026-07-24 |
| 7 | We use skill/agent **body** `${user_config.KEY}` only as model-visible content, and only for non-sensitive values | doc-stated ([User configuration](https://code.claude.com/docs/en/plugins-reference#user-configuration)) | 2.1.218, 2026-07-24 |
| 8 | We never expect a sensitive value in `settings.json`, so no settings reader can see one | doc-stated ([User configuration](https://code.claude.com/docs/en/plugins-reference#user-configuration)) | 2.1.218, 2026-07-24 |
| 9 | `claude plugin install --config` writes `pluginConfigs` to **user settings whatever `-s` says**; `-s project` / `-s local` governs only the install record and the `enabledPlugins` entry in that scope's settings file. Exit 0, no warning about the scope. A consequence of fact 5, so no setup recipe may document `-s project --config` as a per-repo value | proven (sandbox probe, Claude Code 2.1.283, 2026-09-27) | 2.1.283, 2026-09-27 |
| 10 | `--config` validates at write time but **never fails the command**: a wrong-type boolean and an undeclared key are rejected with a warning and exit 0; a prose-enumerated string and a non-existent `directory` path are stored without a warning. A declared `options` fixed list is enforced (a value outside it is rejected with a warning, exit 0); a plugin declaring `options` cannot load on Claude Code before v2.1.271. So an in-consumer fallback is mandatory for any key without `options`, and a headless caller reads the CLI output, not the exit code | proven (sandbox probe, Claude Code 2.1.283, 2026-09-27); `options` doc-stated ([plugins-reference](https://code.claude.com/docs/en/plugins-reference), "Limit a field to fixed options", fetched 2026-09-27) and probed | 2.1.283, 2026-09-27 |
| 11 | There is **no CLI path to unset a key**: `claude plugin --help` lists `details`, `disable`, `enable`, `eval`, `help`, `init`, `install`, `list`, `marketplace`, `prune`, `tag`, `uninstall`, `update`, `validate` (no `config` or `configure`), and `--config KEY=` with an empty value is rejected ("Omit the flag to leave ... unset"). A key using the declare-no-default idiom (for example work-items `work_dispatch_concurrency_cap`) cannot be cleared from the CLI once set: clearing it means hand-editing user settings or uninstalling, which drops every option | proven (sandbox probe, Claude Code 2.1.283, 2026-09-27) | 2.1.283, 2026-09-27 |
| 10 | `--config` validates at write time but **never fails the command**: a wrong-type boolean and an undeclared key are rejected with a warning and exit 0; a prose-enumerated string and a non-existent `directory` path are stored without a warning. A declared `options` fixed list is enforced (a value outside it is rejected with a warning, exit 0); a plugin declaring `options` needs Claude Code v2.1.271 or later. So an in-consumer fallback is mandatory for any key without `options`, and a headless caller reads the CLI output, not the exit code | proven (sandbox probe, Claude Code 2.1.283, 2026-09-27); `options` doc-stated ([Limit a field to fixed options](https://code.claude.com/docs/en/plugins-reference#limit-a-field-to-fixed-options), read 2026-09-27) and probed | 2.1.283, 2026-09-27 |
| 11 | There is **no CLI path to unset a key**: `claude plugin --help` lists `details`, `disable`, `enable`, `eval`, `help`, `init`, `install`, `list`, `marketplace`, `prune`, `tag`, `uninstall`, `update`, `validate` (no `config` or `configure`), and `--config KEY=` with an empty value is rejected with a message to omit the flag instead. A key using the declare-no-default idiom (for example work-items `work_dispatch_concurrency_cap`) cannot be cleared from the CLI once set: clearing it means hand-editing user settings or uninstalling, which drops every option | proven (sandbox probe, Claude Code 2.1.283, 2026-09-27) | 2.1.283, 2026-09-27 |
| 12 | Rerunning `install --config` on a plugin already installed at the same scope is a pure config write: the install record is byte-identical and only the named option keys change. Measured for a `string` option at `user` and `project` scope and for `boolean` and `directory` options at `local` scope | proven (sandbox probe, Claude Code 2.1.283, 2026-09-27); the reconfigure guidance built on it is owned by [plugin-reconfiguration's verified-version record](../plugin-reconfiguration/README.md#verified-version-record) | 2.1.283, 2026-09-27 |

## The channels
Expand Down Expand Up @@ -139,8 +141,9 @@ unproven. A ratified D adoption (after the Open-gaps probe) is recorded in
## Open gaps

- **G-required (channel D's premise).** That `required:true` forces a prompt and so removes the
unset case is inferred from the schema (`required`: "validation fails when the field is empty")
and upstream discussion, not doc-stated and not yet probed: the verification probe declared
unset case is inferred from the schema's `required` field (see
[User configuration](https://code.claude.com/docs/en/plugins-reference#user-configuration)) and
upstream discussion, not doc-stated and not yet probed: the verification probe declared
optional keys only. Cheap to settle. Add a `required:true` key to the probe plugin and rerun the
unset-key test. Until then D stays in the matrix as unproven and the CI gate has no allowlist
entries.
Expand All @@ -161,7 +164,7 @@ authority it points to.

## Recheck triggers

Stamp-and-trigger discipline: [upstream-drift](../upstream-drift/README.md). Recheck the facts
Record shape and trigger discipline: [upstream-drift](../upstream-drift/README.md). Recheck the facts
table (and re-derive the decision rule) when any of these fires:

- A Claude Code CHANGELOG entry touches `userConfig` substitution, the `default` field, or
Expand Down
Loading
Loading