Skip to content

fix: gate cross-plugin routing on enabled, not installed - #5985

Merged
kyle-sexton merged 7 commits into
mainfrom
fix/5934-enabled-gates
Oct 3, 2026
Merged

kyle-sexton merged 7 commits into
mainfrom
fix/5934-enabled-gates

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Closes #5934

Summary

#5897 turned 44 plugins off by default. A plugin that is installed but disabled exposes no skills, so a default-on plugin that routes to one of them "if installed" takes a branch whose target cannot run. This PR changes those gates to "enabled", wording only.

Fix

  • 72 gate lines in default-on plugins (docs-hygiene, planning README, review, session-flow, source-control, tdd, verification, visualization, work-items, writing) now say "enabled" where they said "installed", for targets the catalog marks defaultEnabled: false: ai-slop, architecture, autonomy, code-metrics, context-guard, discipline, docs-naming, domain-driven-design, education, harness-config, harness-memory, harness-ops, instruction-placement, mutation-testing, performance, playbooks, playgrounds, plugin-quality, prototype, skill-quality. Fallback wording that said "absent plugin" or "when absent" now says the plugin is not enabled.
  • lib/hook-utils.sh: the missing-prerequisite notice says "If the harness-ops plugin is enabled". Synced to all 20 carrying copies with scripts/sync-hook-utils.sh.
  • Gates on default-on targets (writing, toolchain, testing, planning, source-control, and so on) and on external plugins (semgrep-rule-creator, the first-party playground) are unchanged, with two exceptions. In source-control's pull-request/reference/prep.md, the governing sentence covers every gate under it, so the docs-hygiene, review and verification gates there also say "enabled". In review's quality-gate/context/downstream.md, the testing gate also says "enabled", to match the "Neither enabled" fallback that covers both gates. Elsewhere, gates on on-by-default plugins still say "installed". CHANGELOG history is unchanged.
  • 29 plugins get a patch bump and a CHANGELOG entry: every plugin with a reworded gate, plus every plugin that carries hook-utils.sh.

Verification

  • scripts/sync-hook-utils.sh --check and --check-bump origin/main: pass.
  • scripts/check-changelog-parity.sh --check and --check-bump origin/main: pass.
  • node scripts/generate-catalog.mjs --check, scripts/check-skill-count-claims.sh --check, python3 scripts/sync-plugin-options-docs.py --check: pass.
  • markdownlint-cli2 on the 61 changed markdown files: 0 issues. Every changed JSON file parses.
  • No test asserts the reworded strings (searched every *.test.sh, *.test.mjs, test_*.py, and *.Tests.ps1).

Related

  • chore: install 44 non-core plugins disabled by default #5897 (the catalog change) and its planning and testing gate fixes.
  • plugins/session-flow/skills/find-handoff/reference/rung-1-known-location.md mentions the harness-ops lane launcher "when that plugin is installed" as a description, not a gate, so it is unchanged.

🤖 Generated with Claude Code

#5897 turned 44 plugins off by default. An installed but disabled plugin
exposes no skills, so a default-on plugin's "if installed" gate on one of
them now passes when the target is unusable. Change those gates, and the
shared hook library's harness-ops notice, to "enabled". Wording only.

Closes #5934

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
# Conflicts:
#	plugins/actionlint/CHANGELOG.md
#	plugins/animation/.claude-plugin/plugin.json
#	plugins/animation/CHANGELOG.md
#	plugins/autonomy/.claude-plugin/plugin.json
#	plugins/autonomy/CHANGELOG.md
#	plugins/bash-format/CHANGELOG.md
#	plugins/biome-format/CHANGELOG.md
#	plugins/context-guard/.claude-plugin/plugin.json
#	plugins/context-guard/CHANGELOG.md
#	plugins/desktop-notification/CHANGELOG.md
#	plugins/docs-hygiene/.claude-plugin/plugin.json
#	plugins/docs-hygiene/CHANGELOG.md
#	plugins/eol-normalizer/CHANGELOG.md
#	plugins/go-format/CHANGELOG.md
#	plugins/guardrails/CHANGELOG.md
#	plugins/harness-ops/.claude-plugin/plugin.json
#	plugins/harness-ops/CHANGELOG.md
#	plugins/instruction-placement/.claude-plugin/plugin.json
#	plugins/instruction-placement/CHANGELOG.md
#	plugins/markdown-format/CHANGELOG.md
#	plugins/planning/CHANGELOG.md
#	plugins/powershell-format/CHANGELOG.md
#	plugins/rate-limit-guard/CHANGELOG.md
#	plugins/review/.claude-plugin/plugin.json
#	plugins/review/CHANGELOG.md
#	plugins/ruff-format/CHANGELOG.md
#	plugins/session-flow/.claude-plugin/plugin.json
#	plugins/session-flow/CHANGELOG.md
#	plugins/source-control/.claude-plugin/plugin.json
#	plugins/source-control/CHANGELOG.md
#	plugins/tdd/CHANGELOG.md
#	plugins/testing/.claude-plugin/plugin.json
#	plugins/testing/CHANGELOG.md
#	plugins/typos-format/CHANGELOG.md
#	plugins/verification/CHANGELOG.md
#	plugins/visualization/.claude-plugin/plugin.json
#	plugins/visualization/CHANGELOG.md
#	plugins/work-items/.claude-plugin/plugin.json
#	plugins/work-items/CHANGELOG.md
#	plugins/writing/.claude-plugin/plugin.json
#	plugins/writing/CHANGELOG.md
@kyle-sexton
kyle-sexton marked this pull request as ready for review October 3, 2026 04:19
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T04:24:05.114947Z 1e55e9d Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 4m 42s —— View job


Code review complete

This is a wide but mechanical PR: reword "installed" → "enabled" on gate lines whose target plugin ships defaultEnabled: false, sync lib/hook-utils.sh's missing-prerequisite notice to its 19 carrying copies, and bump versions/CHANGELOGs for the 28 touched plugins. I cross-checked the reworded lines against .claude-plugin/marketplace.json's defaultEnabled values and the hook-utils.sh copies against lib/hook-utils.sh; both are correctly and completely applied (all 19 carrying copies match, no defaultEnabled: false plugin reference was missed, and no default-on/external-plugin gate was incorrectly touched).

Two small wording inconsistencies survived the rewording itself, both posted as inline comments:

  1. plugins/source-control/skills/pull-request/reference/prep.md:25 — the governing sentence now claims every skill below is gated on "enabled," but the docs-hygiene (lines 40-41) and review (line 46) bullets right below it still say "installed" (correctly, since those are default-on) — the intro line contradicts its own list.
  2. plugins/review/skills/quality-gate/context/downstream.md:135 — "Neither enabled" summarizes a pair where one bullet (testing, line 131) is still phrased as "installed," so the summary word doesn't match.

Both are prose-precision nits (not functional bugs) in a PR whose entire point is wording precision, so I flagged them rather than treating them as pure style.

Author-claimed verification (sync-hook-utils, check-changelog-parity, catalog generation, markdownlint, JSON parsing) was not independently re-run by me; I took the diff and the marketplace catalog as ground truth instead.

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 2s —— View job


Security review (/review:security-review)

No security issues found.

This PR is a wording-only change plus mechanical housekeeping (version bumps, CHANGELOG entries), scoped exactly as the description states:

  • lib/hook-utils.sh and its 19 synced copies (e.g. plugins/harness-ops/hooks/hook-utils.sh) change only the text of a user-facing notice string (installed → enabled). No control flow, command construction, or input handling changed — confirmed by reading the diff directly rather than relying on the description.
  • All other content changes are prose edits in SKILL.md, README.md, reference docs, and eval fixtures/JSON, swapping the gating word from "installed" to "enabled" (and "absent plugin" → "plugin not enabled"). I checked these against the instruction-surface deletion lens this skill requires for any diff that touches a standing gate: this change is tighten-only — it makes a cross-plugin routing gate harder to satisfy (a plugin must now be enabled, not merely installed-but-possibly-disabled), which is the direction the instruction exception register explicitly permits. It does not loosen, remove, or soften any guardrail, so it is not a finding under that lens.
  • .claude-plugin/plugin.json and CHANGELOG.md edits across the 28 touched plugins are version bumps and changelog text only.
  • No code path that handles secrets, auth, file paths, or external input is touched anywhere in this diff.

No GitHub Actions workflow files are touched, so there's nothing in zizmor's lane either.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1e55e9d9d8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/source-control/skills/pull-request/reference/prep.md
Comment thread plugins/source-control/skills/pull-request/reference/prep.md
Comment thread plugins/review/skills/quality-gate/context/downstream.md
kyle-sexton and others added 2 commits October 3, 2026 00:31
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
# Conflicts:
#	plugins/guardrails/CHANGELOG.md
#	plugins/harness-ops/CHANGELOG.md
#	plugins/session-flow/CHANGELOG.md
#	plugins/source-control/.claude-plugin/plugin.json
#	plugins/source-control/CHANGELOG.md
@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 23s —— View job


Security review (/review:security-review)

No security issues found.

I reviewed the full diff at dff140f (git diff origin/main...HEAD, 115 files, +301/-132) independently against the security criteria:

  • Scope confirmed wording-only. Every hunk is one of: a gate word swapped installed → enabled (or absent plugin/when absent → the plugin is not enabled) in SKILL.md/reference/README prose, a lib/hook-utils.sh notice string synced to its 19 carrying copies (lib/hook-utils.sh#L445, #L486), eval-fixture prompts/expectations reworded to match, or a plugin.json version bump plus its CHANGELOG.md entry. No control flow, command construction, file-path handling, or input parsing changed anywhere in the diff.
  • Instruction-surface lens applied. This diff narrows (not loosens) cross-plugin routing gates: a target plugin that is installed-but-disabled previously still took the "installed" branch toward a skill that cannot run, and now requires "enabled" instead. I checked the changed gate class against the six Gate 0 classes in the instruction exception register (irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority): a "which skill handles this class of file" routing gate bounds none of them, so the register's protected-class check does not apply here, and the change is tighten-only in the direction the register explicitly permits regardless.
  • Verified the extra commits since the prior security pass (abfdf3f, fa532d4, the merge dff140f) add nothing beyond this same pattern — abfdf3f is a one-line autonomy CHANGELOG wording fix (drops an org name), already wording-only.
  • No GitHub Actions workflow files are touched, so nothing for zizmor's lane.

The two prose inconsistencies already flagged by Codex and the prior Claude review — plugins/source-control/skills/pull-request/reference/prep.md:25 (governing sentence says "enabled" but two bullets below still say "installed" for the unchanged default-on plugins) and plugins/review/skills/quality-gate/context/downstream.md:135 ("Neither enabled" summarizing one "installed" + one "enabled" bullet) — are prose-precision issues, not security findings; not re-reported here since that's /review:code-review's lane. I also don't re-report Codex's "gate on actual Skill availability, not enablement alone" comment on prep.md:25: it's a robustness/correctness concern about a cloud session where install fails post-enable, with no attacker-controlled input or exploit path, so it falls outside this lane's security bar.

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 43s —— View job


Code review complete

This pass re-reviews the head produced by this push (dff140f), which added one content commit (abfdf3f, a one-line CHANGELOG wording fix) plus a merge of origin/main on top of the head Codex/Claude already reviewed (1e55e9d). I diffed 1e55e9d..dff140f to scope the new work, and confirmed the merge itself is clean (no leftover conflict markers repo-wide; the five files it listed as conflicted — guardrails, harness-ops, session-flow, and source-control's CHANGELOG.md/plugin.json — all resolved with the manifest version matching the CHANGELOG.md top heading).

New finding (posted inline on plugins/autonomy/CHANGELOG.md:10): abfdf3f reworded that one line's issue citation from ([#5934](https://github.com/melodic-software/claude-code-plugins/issues/5934)) to bare (#5934), apparently to stop naming the org in the URL. It's the only one of the 28 #5934 citations this PR adds that was changed this way — the other 18 copies of the identical "shared hook library's missing-prerequisite notice" sentence, and the 9 copies of the "Cross-plugin routing..." sentence, all still use the full markdown link. Neither gate the PR's Verification section cites catches this: scripts/sync-hook-utils.sh only syncs the hook-utils.sh script body, not CHANGELOG prose, and scripts/check-changelog-parity.sh checks heading/version parity, not cross-plugin text identity. Worth a deliberate choice one way or the other rather than one outlier among 28.

Carried forward, not re-posted: the two wording inconsistencies Codex and Claude already flagged on commit 1e55e9d (plugins/source-control/skills/pull-request/reference/prep.md:25 and plugins/review/skills/quality-gate/context/downstream.md:135) are untouched by this push and remain open — see the existing review threads rather than duplicate comments here.

Author-claimed verification (sync-hook-utils.sh, check-changelog-parity.sh, catalog generation, markdownlint, JSON parsing) was not independently re-run by me for this pass; I relied on reading the diff and the two scripts' own doc comments instead.

Comment thread plugins/autonomy/CHANGELOG.md
…llback

prep.md's governing sentence now says "enabled", so its per-item gates on
docs-hygiene, review and verification say it too; downstream.md's
"Neither enabled" now summarizes two conditions worded the same way.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 11s —— View job


Security review (/review:security-review)

No security issues found.

This push adds one commit (6f90ccc) on top of the head (dff140f) already reviewed by the two prior security passes on this PR. I scoped this pass to what's new: git show 6f90ccc touches exactly two files, both markdown prose, both pure word substitutions:

This resolves the two prose inconsistencies Codex and the prior Claude review had flagged on this PR (the governing sentence vs. its own bullets contradicting each other). I confirmed no new inconsistency was introduced by re-grepping every installed/enabled occurrence in both files after the change — all per-item gates in each file now agree with their governing/summary line.

Applying the instruction-surface deletion lens (checked against docs/conventions/instruction-exception-register/README.md, present in this checkout): this change is tighten-only in the same direction as the rest of the PR — docs-hygiene, review, and verification ship default-on, but a user can still disable an installed, default-on plugin, in which case "installed" was previously the wrong (looser) check for whether its skills are reachable. Moving these three gates from "installed" to "enabled" closes that same gap the rest of the PR closes for default-off plugins. It doesn't loosen, remove, or soften any guardrail, so it is not a finding under that lens.

No control flow, command construction, secrets, or input handling is touched by this commit or anywhere else in the PR. Consistent with both prior security passes on this PR (1e55e9d, dff140f): no security issues found.
(branch)

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 51s —— View job


Code review complete

This pass reviews the head produced by this push (6f90ccc), which adds one commit on top of the already-reviewed dff140f: 6f90ccc touches exactly two files — plugins/review/skills/quality-gate/context/downstream.md and plugins/source-control/skills/pull-request/reference/prep.md — to fix the two wording inconsistencies Codex and the prior Claude pass flagged on 1e55e9d. I confirmed both are now resolved: prep.md's governing line 25 ("every skill ... is enabled") no longer contradicts the per-item bullets below it (docs-hygiene at lines 40–41, review at line 46, verification at line 73 all now say "enabled" too), and downstream.md's "Neither enabled" (line 135) now summarizes two bullets that both say "enabled" (line 131 testing, line 133 mutation-testing).

New finding (cross-file, posted here rather than inline since no single changed line carries it): fixing the internal contradiction this way widens the PR's stated scope rather than reverting the governing sentence. docs-hygiene, review, testing, and verification have no defaultEnabled entry in .claude-plugin/marketplace.json — they're default-on, the exact class the PR's own Fix section says is "unchanged" ("Gates on default-on targets ... are unchanged"). But this commit now gates them on "enabled" in these two files:

Every other reference to these same four plugins across the repo (e.g. plugins/verification/skills/confirm/SKILL.md:134, plugins/writing/skills/be-concise/SKILL.md:132-142, plugins/code-metrics/skills/audit-coverage/SKILL.md:56, plugins/harness-config/skills/unhobble/SKILL.md:374 — none touched by this PR) still says "installed." That's defensible on the merits (a default-on plugin can still be explicitly disabled while remaining installed, so "enabled" is the more correct check everywhere), but as shipped it leaves two different conventions for the identical plugin reference depending on which file you read, and it makes the PR description's own "unchanged" claim inaccurate for these two files. Worth either reconciling the Fix section's wording with the actual (now-broader) scope, or noting explicitly that docs-hygiene/review/testing/verification were deliberately carved out as an exception in these two files to resolve the self-contradiction, rather than leaving it implicit.

Carried forward, not re-posted: the CHANGELOG citation inconsistency flagged on plugins/autonomy/CHANGELOG.md:10 in the prior review pass (bare (#5934) vs. the full ([#5934](...)) link used by the other 27 identical entries) is untouched by this push and remains open — see the existing review thread rather than a duplicate comment here.

Author-claimed verification (sync-hook-utils.sh, check-changelog-parity.sh, catalog generation, markdownlint, JSON parsing) was not independently re-run by me for this pass; I relied on reading the diff and marketplace.json directly instead.

kyle-sexton added a commit that referenced this pull request Oct 3, 2026
…lts (#5987)

No related issue: follow-up to #5897 and #5934, so this repo's own
`enabledPlugins` holds only deltas against the new catalog defaults.

## Summary

`.claude/settings.json` is project scope. Each key in its
`enabledPlugins` block pins that plugin's state, and in every local
checkout it writes a project-scope install record. After #5897, a `true`
for a plugin that is on by default changes nothing in the cloud. Locally
it writes that record and forces the plugin on in this checkout whatever
the user's own scope says. Dropping it leaves the plugin's local state
to the user's own scope, the same as every other on-by-default plugin,
none of which carries a key here. A `true` for a plugin that is off by
default enables it in every session in this repo, and in cloud sessions
too.

## Fix

`.claude/settings.json` `enabledPlugins`:

- Kept unchanged: every `false` (animation, dometrain-mcp, gaming,
pixel-art, playgrounds, retro-audio). No other marketplace has entries
here.
- Dropped `true` for `multi-agent`, which is on by default, and for
`fleet` and `harness-memory`, which are off by default and not needed to
work in this repo.
- Kept or added `true` only for off-by-default plugins this repo's
workflow uses:
- `ai-slop`: the PR prep markdown audit (`/ai-slop:audit`). The repo
keeps its config in `.claude/ai-slop.json`.
- `docs-naming`: the remediation for CI's lower-kebab `docs/` filename
gate (ADR 0034).
- `evals`: authoring and validating the `evals/` suites that skills ship
(`/evals:design`, which `.claude/rules/eval-case-transcripts.md` names).
- `harness-config`: `/harness-config:audit`, whose kept findings live in
`.claude/audit-pass.md`.
- `harness-ops`: lane operation and telemetry that
`docs/conventions/loop-lane` routes to (`/harness-ops:lanes`,
`/harness-ops:morning-brief`).
- `instruction-placement`: the PR prep rules audit, and the generated
rules index in `AGENTS.md`.
- `plugin-quality`: behavioral audits of the plugins this repo
publishes.
  - `skill-quality`: the PR prep skills gate (`/skill-quality:check`).

`docs/cloud-fleet-setup.md`: three places still said the fleet list was
the standards repository's `fleet-plugins.json`, which standards#663
deleted. They now say the list is derived from this repo's catalog
(every entry whose `defaultEnabled` is absent or `true`), which matches
`setup.sh` in standards. `docs/cloud-sessions.md` was already correct.

## Verification

- `scripts/check-plugin-catalog-enablement.sh`: every key names a
catalogued plugin, none orphaned, keys sorted. Its test reports PASS=13
FAIL=0.
- `scripts/check-hook-wiring-liveness.sh`: pass. `jq empty
.claude/settings.json`: valid.
- `markdownlint-cli2 docs/cloud-fleet-setup.md`: 0 issues.
- No other doc in the tree still names `fleet-plugins.json`.

## Related

- #5897 (catalog defaults), #5936 (the gate now checks deltas, not
coverage), #5934 / #5985 (the gate wording sweep).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
@kyle-sexton

Copy link
Copy Markdown
Contributor Author

Reply to the 04:46 review pass:

Finding Classification Evidence
6f90ccc widened the scope in prep.md and downstream.md, but the Fix section still said gates on on-by-default plugins were unchanged VALID (fix now) The PR body's Fix section now names both exceptions and why each was made. Elsewhere, gates on on-by-default plugins stay "installed", as #5934 scoped.
The autonomy CHANGELOG cites (#5934) bare Already answered in that thread scripts/validate-plugin-contracts.mjs rejects an org-naming link in plugins/autonomy/ ("autonomy plugin must not name the org or fleet repos").

# Conflicts:
#	plugins/harness-ops/.claude-plugin/plugin.json
#	plugins/harness-ops/CHANGELOG.md
#	plugins/planning/.claude-plugin/plugin.json
#	plugins/planning/CHANGELOG.md
#	plugins/session-flow/.claude-plugin/plugin.json
#	plugins/session-flow/CHANGELOG.md
@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 40s —— View job


Security review (/review:security-review)

No security issues found.

This push adds one commit on top of the previously-reviewed head 6f90ccc: ec06966 merges origin/main into the branch. I diffed the PR's own files between 6f90ccc and ec06966 directly (git diff 6f90ccc..HEAD -- <files>) and confirmed zero change to any file this PR authors — lib/hook-utils.sh, plugins/source-control/skills/pull-request/reference/prep.md, plugins/review/skills/quality-gate/context/downstream.md, and plugins/autonomy/CHANGELOG.md are byte-identical to the already-reviewed versions.

The merge did touch two files this PR also touches, plugins/session-flow and plugins/harness-ops (.claude-plugin/plugin.json + CHANGELOG.md), because main gained unrelated version bumps for those same plugins (the effort/session-event-log work, PR #5992) while this branch was open. I checked both resolutions line by line:

Neither reconciliation altered the wording-only hook-utils.sh content or any gate text; both are pure version/changelog arithmetic. The merge also pulled in the new speech plugin from main, which now carries its own hooks/hook-utils.sh copy — it already contains this PR's "enabled" wording, correctly synced, matching the SHA of every other carrying copy.

No control flow, command construction, secrets, or input handling is touched by this push or anywhere in the PR. Consistent with all four prior security passes on this PR (1e55e9d, dff140f, 6f90ccc, and now ec06966): no security issues found.

Note: git fetch and gh were blocked by sandbox network restrictions in this run, so I verified the merge's effect via local git diff against the last-reviewed commit already present in the checkout, rather than via gh pr diff/origin/main directly. The repo's shallow clone also left origin/main...HEAD without a computable merge base for the same reason.
(branch)

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 22s —— View job


Code review complete

This push adds one commit on top of the already-reviewed head 6f90ccc: ec06966 is a merge of origin/main into this branch, bringing in unrelated main-line work (the effort-advice/event-log-content feature in #5992, the enabledPlugins cut in #5987, and others) that isn't part of this PR's own diff against origin/main.

Merge conflict resolution checked. The merge reported conflicts in six files — plugins/{harness-ops,planning,session-flow}/.claude-plugin/plugin.json and their CHANGELOG.md. I confirmed no conflict markers survive anywhere in the tree, and in each of the three plugins the manifest version matches the CHANGELOG.md top heading, with this PR's own patch entry layered correctly above the bumped version main had already introduced (e.g. harness-ops is 3.3.1 here on top of main's 3.3.0; planning is 0.63.1 on top of 0.63.0; session-flow is 0.47.1 on top of 0.47.0). No content from this PR's own change was lost or duplicated by the merge.

No new reviewable content. Diffing 6f90ccc..ec06966 and cross-checking each touched file against origin/main's own history (e.g. plugins/speech/scripts/narrate.py, plugins/session-flow/skills/orchestrate/SKILL.md, plugins/knowledge/skills/map-corpus/SKILL.md) confirms those hunks are main-authored content pulled in by the merge, not edits this PR introduces — they don't appear in this PR's diff against origin/main. The three gate-wording fixes from 6f90ccc (prep.md's governing sentence and its docs-hygiene/review/verification bullets; downstream.md's testing bullet and its "Neither enabled" summary) all still read consistently post-merge, and plugins/autonomy/CHANGELOG.md:10's bare (#5934) citation is untouched.

Carried forward, not re-posted: the author already replied in-thread to the prior pass's two findings — the widened "enabled" scope in prep.md/downstream.md now matches the Fix section's stated exceptions, and the autonomy CHANGELOG bare-citation format is required by scripts/validate-plugin-contracts.mjs (which rejects an org-naming link in that plugin). Both are resolved on the existing threads; no new finding to add on top of them.

No new inline comments posted this pass; nothing new to flag.
(branch)

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 28s —— View job


Security review (/review:security-review)

No security issues found.

This push adds one commit on top of the previously-reviewed head ec06966: 4ce8b78 merges origin/main into the branch, pulling in d3accd5 (perf(ci): split test-windows into four parallel jobs (#6002)) and the session-bridge library refactor it carries. None of that is this PR's own content.

I verified this precisely rather than by inspection alone:

  • git diff ec06966..4ce8b78 touches 21 files — .github/workflows/test-windows.yml, the new lib/session-bridge/ library, plugins/planning/surface/*, two architecture-decision docs, and plugins/planning's plugin.json/CHANGELOG.md/README.md. None of this PR's own authored files changed: git diff ec06966..4ce8b78 -- lib/hook-utils.sh plugins/source-control/skills/pull-request/reference/prep.md plugins/review/skills/quality-gate/context/downstream.md plugins/autonomy/CHANGELOG.md 'plugins/*/hooks/hook-utils.sh' is empty.
  • git merge-base HEAD d3accd5 returns d3accd5 itself — i.e. main's tip is now an ancestor of this branch — so git diff d3accd5..HEAD isolates exactly this PR's unique contribution: 118 files, +315/-140, matching the size the PR description claims. No session-bridge, workflow, or test-windows file appears in that set.
  • Merge conflict check: planning had a genuine content conflict (this branch bumped 0.63.0→0.63.1 for the gate-wording fix; main independently bumped 0.63.0→0.63.1 for the session-bridge transport change). The resolution stacked them correctly — main's entry stayed at 0.63.1, this PR's entry moved to 0.63.2, and plugin.json's version (0.63.2) matches the CHANGELOG.md top heading. No content lost or duplicated.
  • Repo-wide conflict-marker scan (^<<<<<<<, ^=======$, ^>>>>>>> at line start) returns no matches; the raw-string hits in grep -rl "<<<<<<<" earlier were test fixtures/detector scripts that reference those literal strings as data, not unresolved conflicts.

No control flow, command construction, secrets, or input handling is touched by this PR's own diff (confirmed again at this head). Consistent with all five prior security passes on this PR (1e55e9d, dff140f, 6f90ccc, ec06966, now 4ce8b78): no security issues found.

Note: network access (git fetch) was unavailable in this sandbox, so I verified the merge's effect via local git diff/git merge-base against commits already present in the checkout rather than via gh pr diff or a fresh origin/main.
(branch)

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 45s —— View job


Code review complete

This push adds two commits on top of the already-reviewed head ec06966: d3accd5 (main's CI job-splitting change, not part of this PR's own diff) and 4ce8b78, a merge of origin/main into this branch bringing the branch fully up to date (git merge-base HEAD origin/main now equals origin/main's tip).

Merge conflict resolution checked. 4ce8b78's own message records exactly one conflicted file, plugins/planning/CHANGELOG.md. I confirmed the resolution is correct: this PR's wording-only patch entry (previously 0.62.4) is now stacked as [0.63.2] on top of main's [0.63.0] and [0.63.1] entries (the interview effort-advice and session-bridge-transport work), with plugins/planning/.claude-plugin/plugin.json's version (0.63.2) matching the CHANGELOG.md top heading and no content lost from either side. A repo-wide search for leftover <<<<<<</=======/>>>>>>> conflict markers found none.

No new reviewable content from this PR. git diff origin/main...HEAD --stat now reports 118 files changed, +315/-140 — matching this PR's own description exactly — confirming the merge contributed zero drift to this PR's authored content (the rest of the merge's diff, e.g. lib/session-bridge/*, plugins/planning/surface/*, .github/workflows/test-windows.yml, is main-authored content pulled in by the merge, not edits this PR introduces).

Previously flagged findings, re-verified at this head:

  • plugins/source-control/skills/pull-request/reference/prep.md — the governing sentence (L25) and every per-item gate below it (L31, L40, L41, L42, L43, L46, L73) now consistently say "enabled." Resolved.
  • plugins/review/skills/quality-gate/context/downstream.md — the testing (L131) and mutation-testing (L133) bullets both say "enabled," matching the "Neither enabled" summary (L135). Resolved.
  • plugins/autonomy/CHANGELOG.md:10 — the bare (#5934) citation remains, and the author's reply is a specific, checkable claim (scripts/validate-plugin-contracts.mjs rejecting an org-naming link in plugins/autonomy/ with the quoted error text). I did not re-run that script myself this pass (execution was denied in this sandbox), so this is author-claimed-and-plausible, not independently re-verified by me — but it was independently verified by the prior review pass against both 1e55e9d9d and dff140fe2, and no new evidence contradicts it here. Treating as resolved.

No new findings and no new inline comments this pass.

Author-claimed verification (sync-hook-utils.sh, check-changelog-parity.sh, catalog generation, markdownlint, JSON parsing) was not independently re-run by me for this pass; I relied on git diff/git log/grep against the merge and the prior reviews' conclusions instead.
(branch)

@kyle-sexton
kyle-sexton merged commit f3c69a5 into main Oct 3, 2026
20 checks passed
@kyle-sexton
kyle-sexton deleted the fix/5934-enabled-gates branch October 3, 2026 05:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chore: sweep cross-plugin 'when installed' gates to 'when enabled' in default-enabled callers

1 participant