Skip to content

feat(rendered-views): add the status report and triage board views - #6012

Merged
cursor[bot] merged 13 commits into
mainfrom
feat/5865-status-report-and-triage-board-views
Oct 3, 2026
Merged

cursor[bot] merged 13 commits into
mainfrom
feat/5865-status-report-and-triage-board-views

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

Closes #5865

Summary

Adds the two views from the comprehension program (#5835, C5), both built only with lib/view-builder.mjs and lib/view-runtime.js:

  • Status report: harness-ops:morning-brief builds a page from the brief's own text. Each == Section == is a collapsible block and one filter box matches any line.
  • Triage board: work-items:triage builds a board for the attention view, grouped by state, blocker and label, each section collapsible with its own filter box.

The printed brief and the attention table stay the record; the page is a view of them (rendered-views convention, "markdown is the record").

Fix

  • Each skill has a checked-in template (templates/brief.html, templates/board.html) and a small builder script (scripts/build-brief-view.mjs, scripts/build-board.mjs) that calls buildView with the interactive profile. Issue and PR text is K2: it reaches the page only as the escaped JSON data block, never as markup or script. The skills tell the model not to hand-write or edit the page.
  • The publish destination resolves from the medium cascade key (terminal, file, artifact; auto and unset mean a local file in an interactive session and no page in a lane or CI run). artifact publishes the built file with the Artifact tool and falls back to a file with a stated reason. The steps live in context/view.md and context/board.md, each referenced from a short SKILL.md section.
  • scripts/shared-copies.txt registers generated copies of view-builder.mjs, view-runtime.js (both plugins) and html-escape.mjs (work-items); sync-shared-copies.sh generated them. harness-ops is bumped to 3.3.0 and work-items to 0.46.0, each with a CHANGELOG entry.
  • An item whose blockers were not read is grouped under "blockers not read" instead of "unblocked".

Limits, by choice: the runtime has no re-group or re-sort control, so the board renders the three groupings as sections and keeps the table's oldest-first order inside a group; the filter box matches row text, which carries the label, state and blocker. I left view-runtime.js alone because changing it changes every page's hash.

Verification

  • plugins/work-items/tests/triage-board.test.sh: grouping, the interactive profile, a hostile corpus (script tags, event handlers, javascript: URL, SVG script, </script> breakout, slot syntax) in titles, labels, state, kind and repo, exit codes, and a headless Chrome load from file:// that reads the rendered DOM back. Passes.
  • plugins/harness-ops/skills/morning-brief/morning-brief-view.test.sh: runs the real morning-brief.sh on fixtures with hostile titles, builds the page, checks it passes the profile, and loads it in headless Chrome. Passes. The existing morning-brief.test.sh still passes (143 cases).
  • lib/view-builder.test.sh, sync-shared-copies.sh --check and --check-bump origin/main, check-changelog-parity.sh, validate-plugin-contracts.mjs, check-declared-prerequisites.mjs, markdownlint, typos and shellcheck pass. check-changed-skills.sh reports 0 errors for both skills.
  • check-script-contract.test.sh fails 2 cases here because htmlhint is not installed in this worktree (npm ci not run); it is unrelated to this change.
  • Not run: a published-Artifact render of these two pages. The shared builder's own test covers the Artifact host wrapper; these pages use the same runtime and profile.

Related

🤖 Generated with Claude Code

kyle-sexton and others added 3 commits October 3, 2026 01:04
harness-ops:morning-brief builds a collapsible, filterable status report page
and work-items:triage builds a triage board page grouped by state, blocker and
label. Both go through lib/view-builder.mjs and lib/view-runtime.js: a
checked-in template plus the tracker text as escaped JSON data, never
model-written markup or script. The rendered-views `medium` cascade key picks
terminal, file or artifact; the printed brief and the attention table stay the
record.

Registers generated copies of the builder, runtime and escape helper in the
two plugins, and bumps harness-ops to 3.3.0 and work-items to 0.46.0.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…rt-and-triage-board-views

# Conflicts:
#	plugins/harness-ops/.claude-plugin/plugin.json
#	plugins/harness-ops/CHANGELOG.md
#	plugins/work-items/.claude-plugin/plugin.json
#	plugins/work-items/CHANGELOG.md
…rt-and-triage-board-views

# Conflicts:
#	plugins/harness-ops/CHANGELOG.md
@kyle-sexton
kyle-sexton marked this pull request as ready for review October 3, 2026 05:35
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T05:39:30.156185Z 082b0de Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 082b0de424

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/harness-ops/skills/morning-brief/context/view.md Outdated
Comment thread plugins/harness-ops/skills/morning-brief/context/view.md Outdated
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 4m 22s —— View job


Security review (/review:security-review)

  • Invoke /review:security-review and follow its instructions
  • Post findings to this comment

Scope: files changed in this PR only (git diff origin/main...HEAD), per the skill's criteria — logic flaws, trust-boundary and authorization gaps, injection surfaces, unsafe secret handling. Style/correctness issues outside security are out of scope for this lane.

Findings

IMPORTANT — the rendered-views cascade resolver skips the trust-boundary checks the contract it cites requires.
plugins/harness-ops/skills/morning-brief/context/view.md lines 21-24 and the identical text in plugins/work-items/skills/triage/context/board.md lines 22-24 implement the rendered-views config-cascade resolution (which medium governs: terminal/file/artifact). Both diverge from the config-cascade contract their own "Pointer" line cites:

  • No ${CLAUDE_PROJECT_DIR} anchoring — <root> is git rev-parse --show-toplevel only.
  • No home/non-repo root classification — at a $HOME (or ancestor) or non-git root, the contract requires team/overlay to be reported not-applicable, specifically so $HOME/.claude/rendered-views.md is never read as a team layer (it's physically the user-global file).
  • No staged/gitignored verification on the local overlay — the contract's per-layer verdicts require the overlay to be verified as gitignored, never staged, and to FAIL otherwise. This text reads rendered-views.local.md whenever present, with no such check.

Exploit path: a PR force-adds .claude/rendered-views.local.md with medium: artifact (bypassing the repo's .claude/**/*.local.* .gitignore line, which is a review habit, not a gate). Once merged, this prose is the only enforcement surface — there is no reader script for this surface (docs/conventions/config-cascade/README.md lists rendered-views as "prose only ... no layer-reader script") — so every operator who runs morning-brief or triage afterward has their brief/board silently published through the Artifact tool instead of staying local, with no warning that the "personal" override is attacker-supplied, checked-in content.

Permalinks: view.md#L21-L24, board.md#L22-L24 — inline comments posted on both.

Fix this →

What I checked and found clean

  • lib/html-escape.mjs / lib/view-builder.mjs (both plugins): the interactive-profile builder never writes data into markup — it goes only into the id="rv-data" JSON block, < escaped so it can't break out of the <script> element, and validateInteractivePage structurally rejects any hostile tag/attribute/URL/style that profile forbids. lib/view-runtime.js renders every bound value through textContent only, never innerHTML/eval, and makes no network calls. These files are generated copies of an already-reviewed shared implementation (from feat(lib): add view-builder.mjs and view-runtime.js with report and interactive profiles #5937), newly vendored into these two plugins — logic unchanged.
  • build-brief-view.mjs / build-board.mjs: no shell/command injection (pure Node, readFileSync/JSON.parse, no exec), inputs are typed/coerced (text(), number()) before reaching the template data.
  • templates/brief.html / templates/board.html: only data-rv-text/data-rv-each/data-rv-filter bindings, no href/src ever bound to data.
  • triage-board.test.sh / morning-brief-view.test.sh: exercise a hostile corpus (script tags, event handlers, javascript: URLs, SVG script, </script> breakout) and confirm it never reaches markup outside the data block; tests use mktemp -d + trap cleanup, no injection surface in the harness itself.
  • SKILL.md / scripts/shared-copies.txt diffs are additive only — no removed guardrail or softened instruction (checked against the instruction-exception-register lens).

A pipeline exit-status bug also visible in view.md (morning-brief.sh | tee ... loses the brief generator's exit code, so the builder can run on a failed/empty brief) was considered but is a correctness/reliability issue, not a security one — no injection, no trust-boundary crossing — so it's left for /review:code-review rather than reported here.

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 4m 35s —— View job


Code review complete

  • Gather context (PR diff, CLAUDE.md/REVIEW.md, changed files)
  • Run /review:code-review criteria over the diff (origin/main...HEAD)
  • Check CLAUDE.md / REVIEW.md alignment (a security lane exists in this repo, so security findings are left to it)
  • Independently verify candidate findings against the config-cascade contract and shell semantics
  • Post inline findings via mcp__github_inline_comment__create_inline_comment
  • Final summary

This repo runs a dedicated security lane (.github/workflows/claude-security-review-hosted.yml), so per REVIEW.md this review stays scoped to correctness, design, conventions, error handling, and tests — no security findings reported here.

Findings (posted inline)

  1. Cascade resolver skips required layer validation — morning-brief/context/view.md:21-24, duplicated at triage/context/board.md:22-24. Both resolvers anchor at git rev-parse --show-toplevel directly (no ${CLAUDE_PROJECT_DIR} check), never classify a $HOME/non-repo root, and never verify the team file is tracked or the overlay is gitignored-not-staged before honoring medium:. The config-cascade contract (docs/conventions/config-cascade/README.md, "Resolution algorithm" + "Per-layer verification verdicts") requires all of this, and the contract's own exemplar for this surface, plugins/visualization/skills/visualize/SKILL.md (Step 3, rung 3), does it correctly. Net effect: an untracked .claude/rendered-views.md, or a rendered-views.local.md that got accidentally staged, silently controls page output instead of hard-stopping/failing as required.
  2. tee masks morning-brief.sh's real exit code, so the page builds even when the brief failed — morning-brief/context/view.md:42-44. bash morning-brief.sh ... | tee file reports tee's exit status (always 0), not the script's. morning-brief.sh exits 3/4/5 on usage, repo-resolution, or all-sections-unreadable failures, writing only to stderr with little/no stdout — the builder still runs unconditionally on that empty/garbage brief and produces a hollow page, contradicting the SKILL.md's own "Degraded sections" stop-and-report contract one section above.

Both were independently verified (the convention doc, the canonical implementation it should match, and morning-brief.sh's exit paths at lines 122-130/240-253/415/450/1167), not just taken on faith from Codex's earlier review comments, which flagged the same two spots.

Scope checked, no issues found

build-brief-view.mjs, build-board.mjs, the shared view-builder.mjs/view-runtime.js/html-escape.mjs copies (verified byte-identical to their canonical sources aside from the generated-file banner), both templates, both test suites, evals.json additions, and the CHANGELOG/plugin.json version bumps all look correct — the hostile-input test coverage in particular (triage-board.test.sh, morning-brief-view.test.sh) is thorough and the K2 data-only boundary is enforced by the shared validator, not just by convention.
· branch

Comment thread plugins/harness-ops/skills/morning-brief/context/view.md Outdated
Comment thread plugins/work-items/skills/triage/context/board.md Outdated
Comment thread plugins/harness-ops/skills/morning-brief/context/view.md Outdated
Comment thread plugins/harness-ops/skills/morning-brief/context/view.md
Comment thread plugins/work-items/skills/triage/context/board.md Outdated
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

claude-security-review has reviewed this pull request through 44d9d86; a later push is reviewed from there.

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

claude-review has reviewed this pull request through 44d9d86; a later push is reviewed from there.

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 15s —— View job


Security review (/review:security-review)

  • Invoke /review:security-review and follow its instructions
  • Post findings to this comment

Scope: full PR diff origin/main...HEAD (22 files, same file set and line counts as the last reviewed head). Compared that against the diff since the last security review (at 28db547f, which already posted the cascade-resolver findings below) to see what this push actually changed.

Skip gate: no new security-relevant surface since the last review

This head (76a0197) differs from the previously reviewed commit (28db547f) only in:

  • plugins/harness-ops/CHANGELOG.md — a changelog entry for an unrelated merged fix (fix(harness-ops): point at the mergeable schema instead of quoting it #6026).
  • plugins/harness-ops/skills/morning-brief/SKILL.md — prose edits to the pre-existing "Degraded sections" mergeable/reviewDecision documentation (unrelated to this PR's rendered-views feature).
  • plugins/harness-ops/skills/morning-brief/morning-brief-view.test.sh and plugins/work-items/tests/triage-board.test.sh — mechanical regex portability fixes ([\s\S] → [^]), semantically equivalent, plus an explanatory inline comment.

None of lib/view-builder.mjs, lib/view-runtime.js, lib/html-escape.mjs, context/view.md, context/board.md, the two build-*.mjs scripts, or either template changed since the last review. Per the skill's skip gate ("this head already has a successful security review that still applies"), I'm not re-running the full hunt.

Status of the prior findings

The prior review (commit 28db547f) reported one IMPORTANT finding, posted inline on both resolver files and still open/unaddressed in this diff:

  • rendered-views cascade resolver skips required trust-boundary checks — morning-brief/context/view.md#L21-L24, duplicated at triage/context/board.md#L22-L24. The resolver text omits ${CLAUDE_PROJECT_DIR} anchoring, home/non-repo root classification, and a staged/gitignored check on the local overlay, all required by the config-cascade contract it cites. Exploit path unchanged: a force-added .claude/rendered-views.local.md with medium: artifact is honored with no verification that it's actually untracked, silently routing brief/board output through the Artifact tool. See the earlier inline comments for full detail — not re-posting duplicates since the lines are unchanged.

The tee-masks-exit-code issue noted by the prior pass is a reliability/correctness issue, not security, and is out of this lane's scope (left to /review:code-review).

No new security findings from this push.
· branch

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 7s —— View job


Code review complete

  • Gather context (PR diff at origin/main...HEAD, CLAUDE.md/REVIEW.md, changed files)
  • Run /review:code-review criteria over the diff
  • Check CLAUDE.md / REVIEW.md alignment and lane-split (security lane exists, so security findings stay there)
  • Independently verify candidate findings
  • Post inline findings via mcp__github_inline_comment__create_inline_comment
  • Final summary

Skip gate hit: this lane's prior review of this content still applies. The diff at the current
head (746c9ae) against origin/main is byte-identical in substance to the diff already reviewed
by both this lane and the security lane at 28db547f — same 22 files, same 2421/-2 totals. I
diffed 28db547f..HEAD directly to confirm: the only changes are (1) unrelated commits merged in
from main (CHANGELOG entries, SKILL.md wording for an unrelated mergeable-schema fix, CI
workflow files) and (2) a mechanical regex portability fix in the two new test scripts
([\s\S] → [^], plus a # portability-ok: shellcheck comment), made to satisfy the
shell-portability gate. Neither touches view.md, board.md, the build scripts, templates, or the
shared view-builder/runtime/escape libs that carry this PR's actual review surface. The bot comments
on the thread already note both lanes reviewed through 28db547f and treat a later push as
reviewed from there, which matches.

Per REVIEW.md's lane split (this repo runs claude-security-review-hosted.yml), the cascade-resolver
trust-boundary gap in view.md/board.md already reported by the security lane stays out of scope
here.

One correctness finding from this lane's prior pass on 28db547f still stands, unchanged, at the
current head — not re-posted as a new inline comment since the line content and commit history are
identical to what's already on the thread, but flagging that it remains open:

  • tee masks morning-brief.sh's exit code, so the page builds even when the brief failed —
    plugins/harness-ops/skills/morning-brief/context/view.md#L42-L44.
    bash morning-brief.sh ... | tee file reports tee's status (always 0), not the script's; on
    exit 3/4/5 (scripts/morning-brief.sh lines ~122-130, 240-253, 415, 450, 1167) stdout is
    empty/near-empty but the builder still runs, contradicting the skill's own "Degraded sections"
    stop-and-report contract. No new inline comment posted since the anchored lines are unchanged
    from the already-flagged commit.

No new findings surfaced on top of what's already on this PR's review thread.
· branch

kyle-sexton and others added 2 commits October 3, 2026 02:41
…and stop the brief page when the brief fails

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 33s —— View job


Code review complete

  • Gather context (PR diff at origin/main...HEAD, CLAUDE.md/REVIEW.md, skip gate check)
  • Run /review:code-review criteria over the diff
  • Verify candidate findings
  • Post inline findings (1)
  • Final summary

Scope: full PR diff against origin/main's local tip (c3b6928) — same 22 files, +2436/-2, as the PR description states. Per REVIEW.md's lane split, a dedicated security lane runs on this repo, so security findings stay out of this lane; those (the rendered-views cascade trust-boundary gap and the tee exit-code bug) were already reported by earlier review rounds and are now fixed in this diff — I verified context/view.md/board.md against commit 9a8f366's diff and confirmed both resolvers now anchor at ${CLAUDE_PROJECT_DIR}/git-toplevel, classify a home/non-repo root, hard-stop on an untracked team layer, refuse a staged/non-gitignored overlay, and build the page only after morning-brief.sh exits 0 (no tee).

Finding (posted inline)

  1. Eval case still documents the removed tee flow — plugins/harness-ops/skills/morning-brief/evals/evals.json:95. Eval case 8's expected_output says the skill "runs scripts/morning-brief.sh once with tee," but the fix commit (9a8f366) removed tee from context/view.md's Build section specifically because it masked the script's real exit code. evals.json wasn't touched by that fix, so this case now grades transcripts against the behavior that was just fixed away.

Checked, no other issues found

  • Shared libs: lib/view-builder.mjs, lib/view-runtime.js are byte-identical between the two plugins, and the newly-added plugins/work-items/lib/html-escape.mjs is byte-identical to the pre-existing plugins/harness-ops/lib/html-escape.mjs it's modeled on — scripts/shared-copies.txt's 5 new lines correctly register all three.
  • Builders (build-brief-view.mjs, build-board.mjs): data shaping (section/group derivation, blockedBy→"blockers not read" vs "unblocked", non-integer blocker numbers → ?) is correct, and exit codes (0/1/2) match what the context docs and tests assert.
  • Templates: data-rv-each="notes" binding an array of plain strings onto <li> is correct under view-runtime.js's own()/asText() semantics (non-object scope renders directly, independent of the data-rv-text key name) — not a bug.
  • Filter scoping: the single top-level filter box in brief.html keying on lines intentionally aggregates rows across all sections (module-level rowsByKey keyed by name), matching "one filter box matches any line"; board.html's three distinct keys (srows/brows/lrows) keep each view's filter scoped correctly.
  • SKILL.md additions, CHANGELOG.md entries, and plugin.json version bumps (harness-ops 3.4.2→3.5.0, work-items 0.46.0→0.47.0) are consistent with the added features and semver.
  • Test scripts (triage-board.test.sh, morning-brief-view.test.sh) correctly exercise the builders' CLI contracts (including lib/view-builder.mjs --check).
    · branch

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 15s —— View job


Security review (/review:security-review)

  • Gather context (PR diff, prior review threads, custom instructions)
  • Invoke /review:security-review and follow its instructions
  • Verify the prior findings against the current head
  • Post findings to this comment

Scope: full PR diff (22 files). This push's only security-relevant change since the last full review (at 746c9ae/28db547f) is commit 9a8f366, which the author's inline replies said fixes the previously reported cascade-resolver and exit-code findings; the other new commit pulled in (5f9e04f, shared-lib sync migration) doesn't touch any file in this PR's own change set. I read the fix directly rather than taking the inline replies on faith.

Prior findings — now resolved

Both previously reported IMPORTANT findings are fixed at the current head:

  1. Cascade resolver trust-boundary gap — morning-brief/context/view.md#L21-L28 and the identical text at triage/context/board.md#L22-L29 now: anchor <root> at ${CLAUDE_PROJECT_DIR} before falling back to git rev-parse --show-toplevel; treat team/overlay as not-applicable at $HOME, an ancestor of $HOME, or a non-git root (so $HOME/.claude/rendered-views.md is never read as the team layer); skip a team/overlay path that resolves to the same file as the user-global one; hard-stop on an untracked team layer; and report-not-honor an overlay that is staged or not gitignored. This closes the exploit path (a force-added .claude/rendered-views.local.md with medium: artifact is now reported, not honored).
  2. tee masking the brief script's exit code — morning-brief/context/view.md#L43-L55 now redirects to a file with > (no pipe) and explicitly instructs: "When that exits non-zero (4 or 5 included), print the script's message, build nothing, and stop." Verified against morning-brief.sh's actual exit points (3/4/5 at lines 123-253, 415, 450, 1167) — the doc's claim matches the script.

This was a correctness/reliability issue rather than a security one on its own, but it compounded finding 1 (a page could be built and routed to medium: artifact from a failed/empty brief), so it's worth confirming resolved here too.

No new findings

No new security-relevant surface was introduced by this push. Everything else previously reviewed (lib/view-builder.mjs, lib/view-runtime.js, lib/html-escape.mjs, the two build-*.mjs scripts, both templates, both test suites) is unchanged since the last full pass and already cleared: data reaches the page only through the escaped id="rv-data" JSON block, never markup/script; view-runtime.js binds via textContent only; inputs are typed/coerced before reaching templates; no shell/command injection in the Node builders.

No open security findings on this PR.
· branch

Comment thread plugins/harness-ops/skills/morning-brief/evals/evals.json Outdated
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 9s —— View job


Code review complete

  • Gather context (PR diff at origin/main...HEAD, CLAUDE.md/REVIEW.md, prior review threads)
  • Check skip gate (has this head already been reviewed by this lane?)
  • Run /review:code-review criteria over the diff
  • Verify candidate findings
  • Post inline findings (none — see below)
  • Final summary

Skip gate hit: this lane's prior review of this content still applies. I diffed the last
fully-reviewed head (b591829, where this lane's prior pass reported "No new findings surfaced"
and the security lane separately confirmed both earlier findings fixed) against the current head
(b4fae2c):

git diff --stat b591829..b4fae2c -- plugins/harness-ops plugins/work-items scripts/shared-copies.txt
 scripts/shared-copies.txt | 5 +++++
 1 file changed, 5 insertions(+)

That's the only change touching this PR's file set, and it's noise pulled in by the two
chore: merge origin/main into ... commits (c3b6928/b0a962c), not new content from this PR:
three new prerequisites.* registrations for the visualization plugin and two new
mermaid-gate.mjs registrations, from unrelated PR #5974 merged into main and then into this
branch. None of view.md, board.md, evals.json, the builders, templates, shared libs, or
tests changed.

This lane's own prior review already covered this content in full (correctness pass at 28db547f/746c9ae, confirmed the evals.json stale-tee-wording finding posted inline and still open, then a second pass at b591829 after the 9a8f366 fix landed, finding nothing new). No new review surface exists at this head, so no new findings to report.

One previously-reported finding from this lane remains open on the thread (not re-posted, since
the anchored line is unchanged):

  • evals.json eval case 8 still documents the removed tee flow —
    plugins/harness-ops/skills/morning-brief/evals/evals.json#L95.
    expected_output says the skill "runs scripts/morning-brief.sh once with tee," but the
    9a8f366 fix removed tee from context/view.md's Build section precisely because it masked
    the script's real exit code. The case still grades a transcript against the old, buggy behavior.
    · branch

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 1s —— View job


Security review (/review:security-review)

  • Gather context (PR diff, custom instructions, prior review threads)
  • Invoke /review:security-review and follow its instructions
  • Post findings to this comment

Scope: full PR diff (22 files, origin/main...HEAD), per the skill's criteria.

Skip gate: no new security-relevant surface since the last review

Current head is b4fae2c50b87280676c11a374af445074f07a098. The last full security review on this thread already covered head b591829 and concluded "No open security findings on this PR." I diffed b591829..HEAD to check what changed since:

b4fae2c chore: merge origin/main into the status report and triage board branch
b0a962c feat(visualization): mermaid gate with parse and optional pinned-mmdc svg pre-render (#5974)
c3b6928 chore(deps-dev): Bump @anthropic-ai/claude-code from 2.1.287 to 2.1.288 in the npm-minor-patch group across 1 directory (#5998)

All three are merges of unrelated main work into this branch — a dependency bump and an unrelated visualization feature (mermaid-gate). None of it touches this PR's own surface: plugins/harness-ops/skills/morning-brief/context/view.md, plugins/work-items/skills/triage/context/board.md, lib/view-builder.mjs, lib/view-runtime.js, lib/html-escape.mjs, either build-*.mjs script, either template, or either test suite are byte-identical to the already-reviewed b591829 state.

The only line-level change touching a file this PR itself modifies is in scripts/shared-copies.txt, and it's additive registration for the unrelated merged-in feature, not this PR's rendered-views copies:

+lib/prerequisites.mjs plugins/visualization/lib/prerequisites.mjs
+lib/prerequisites.sh plugins/visualization/lib/prerequisites.sh
+lib/prerequisites.ps1 plugins/visualization/lib/prerequisites.ps1
+lib/mermaid-gate.mjs plugins/visualization/lib/mermaid-gate.mjs
+lib/mermaid-gate.mjs plugins/architecture/lib/mermaid-gate.mjs

This PR's own 5 registry lines (for view-builder.mjs, view-runtime.js ×2, html-escape.mjs) are untouched and already cleared in the prior review.

Per the skip gate ("this head already has a successful security review that still applies"), no new hunt was run. The two previously-reported findings (rendered-views cascade trust-boundary gap, and tee masking morning-brief.sh's exit code) were confirmed fixed in the prior review round (commit 9a8f366) and remain fixed at this head.

No open security findings on this PR.
· branch

kyle-sexton and others added 2 commits October 3, 2026 03:20
…ief page eval

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 44s —— View job


Security review (/review:security-review)

  • Gather context (incremental diff scope, prior review state)
  • Invoke /review:security-review and follow its instructions
  • Post findings to this comment

Scope: incremental. This lane last reviewed b4fae2c50b87280676c11a374af445074f07a098. I diffed that commit against the current head (44d9d86) to confirm the only file in this PR's own change set that moved is plugins/harness-ops/skills/morning-brief/evals/evals.json, matching .claude-lane/incremental.diff exactly (the other files touched by the merge commit — .github/requirements-ci.txt, plugins/miro/** — belong to unrelated PRs merged from origin/main and aren't part of this PR's file set).

Change reviewed

plugins/harness-ops/skills/morning-brief/evals/evals.json#L95 — eval case 8's expected_output is reworded from describing the old morning-brief.sh ... | tee file flow to describing the current file-redirect-then-check-exit-code flow (morning-brief.sh ... > file, stop on non-zero, otherwise print and build). This is exactly the fix for this lane's own previously-reported finding ("eval case still documents the removed tee flow"), and I confirmed the new wording matches context/view.md's current "Build" section (lines 42-54) verbatim in substance.

Assessment: no security-relevant surface

This is a prose-only change to a test fixture's natural-language expected_output string, used to grade eval transcripts. It:

  • Introduces no new code path, no new input handling, no new trust boundary.
  • Doesn't touch the hostile-title fixture in the same case (</script><script>fetch(...)</script> as a decision title), which is unchanged and still exercises the existing K2/escaped-JSON-data boundary that the shared view-builder.mjs/view-runtime.js already enforce.
  • Doesn't touch context/view.md, context/board.md, any builder script, template, or shared lib — all previously reviewed and already confirmed fixed (cascade trust-boundary checks, tee exit-code masking) in earlier rounds on this PR.

No security findings on this change. Combined with the prior rounds' "No open security findings on this PR," there are no open security findings on this PR at the current head.
· branch

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 57s —— View job


Code review complete

  • Read .claude-lane/incremental.diff
  • Run /review:code-review criteria over the scoped change
  • Verify candidate findings
  • Post inline findings (none — see below)
  • Final summary

Scope: incremental, per the lane header — this lane last reviewed b4fae2c50b87280676c11a374af445074f07a098; only plugins/harness-ops/skills/morning-brief/evals/evals.json changed since then (confirmed against .claude-lane/incremental.diff, a single-line change to eval case 8's expected_output).

Finding resolved, no new findings

This change is the fix for this lane's own previously-reported finding: eval case 8 (status-report-page-built-only-by-the-builder, line 95) described the skill as running scripts/morning-brief.sh "once with tee," which the earlier 9a8f366 fix to context/view.md had made stale (that commit removed tee because it masked the script's exit status).

The new wording — "runs scripts/morning-brief.sh once into a file and builds nothing if it exits non-zero, otherwise prints the brief verbatim from that file, then builds the page" — matches the current context/view.md Build section verbatim: run into a file (view.md#L43-L48), stop and build nothing on non-zero exit, otherwise print the file and run the builder (view.md#L50-L55).

Checked and unaffected by this edit:

  • The expectations bullet at evals.json#L99 ("Runs morning-brief.sh once, saving the same output it prints, rather than re-querying for the page") was flagged in the earlier review as worth checking too — it names no mechanism (no tee reference), so it's still accurate under the current flow and didn't need a change.
  • JSON structure is intact (brace/bracket balance verified by inspection; sandboxed node -e validation wasn't permitted in this lane).

No open findings on this incremental diff.
· branch

cursoragent and others added 2 commits October 3, 2026 08:04
Co-authored-by: ksextonmelodic <ksextonmelodic@gmail.com>
…rt-and-triage-board-views

# Conflicts:
#	plugins/harness-ops/CHANGELOG.md
#	plugins/work-items/.claude-plugin/plugin.json
#	plugins/work-items/CHANGELOG.md

Co-authored-by: ksextonmelodic <ksextonmelodic@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

rendered-views: status report and triage board views

2 participants