Skip to content

feat(visualization): build slide decks through the claude.ai Slides Artifact type - #6117

Merged
kyle-sexton merged 5 commits into
mainfrom
feat/5867-slides-via-artifact-types
Oct 3, 2026
Merged

kyle-sexton merged 5 commits into
mainfrom
feat/5867-slides-via-artifact-types

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

Closes #5867

Summary

Adds /visualization:present, a skill that builds slide decks with the claude.ai Slides Artifact type. The markdown outline is the record. The deck is a view of it, made from the type that the Artifact tool's quickstart returns at run time. The skill never stores a type_url.

  • Publish gate. Before anything is sent, skills/present/scripts/check-deck.mjs makes three checks. It refuses a deck folder inside a working tree. It refuses a K2 deck that carries anything beyond text and uploaded images: a live embed, script, inline SVG, link, event handler, CSS url(), or a foreign image. It then runs the shared publish gate over every deck file. It runs before the type's create call, because that call already publishes the title.
  • Shared gate. lib/publish-gate.mjs now holds the explain-change publish gate (feat(review): check the explain-change risk map blind, add a quiz and a recording link, and publish as an Artifact by default #6102) and its credential patterns. Review and visualization each carry a generated copy. digest-policy.mjs imports it, and the digest gate makes the same decisions as before; its 71 tests pass unchanged.
  • Explicit artifact. Only layers that a checked-out branch cannot write count as an explicit artifact: the user's argument, the plugin option, ~/.claude/rendered-views.md, or an overlay that is untracked and gitignored. A team-layer artifact is not explicit.
  • Without explicit artifact. The skill names the destination ("a private Artifact on claude.ai") before it publishes. It keeps the deck local when the source repository is not PUBLIC or a file looks like a credential, and it names the opt-in. NONE stands for K0 content with no repository source.
  • Design system. A design system is used only when the user names one or the quickstart attaches the account's default.
  • Fallback. When there is no Slides type or no Artifact tool, the skill delivers the outline and says why.
  • Rendered-views README. A new "Artifact types" section says when a producer uses a type instead of view-builder. present is registered as an emitter and as the second artifact default. Both are recorded in the convention's CHANGELOG.
  • visualize. It now hands slide decks to present.

Fix

  • New: plugins/visualization/skills/present/ (SKILL.md, scripts/check-deck.mjs, evals), lib/publish-gate.mjs plus tests, and plugins/visualization/tests/present.test.*.
  • Changed: plugins/review/skills/explain-change/scripts/digest-policy.mjs now imports the shared gate. scripts/shared-copies.txt registers two copies.
  • Version bumps: visualization 0.10.2 to 0.11.0, review 0.39.1 to 0.39.2. Both CHANGELOGs are updated. docs/catalog.md and docs/skill-cheat-sheet.md are regenerated.

Verification

  • node --test plugins/visualization/tests/present.test.mjs: 19/19 pass.
  • node --test lib/publish-gate.test.mjs: 13/13 pass.
  • node --test plugins/review/tests/explain-change.test.mjs: 71/71 pass. The other review suites pass too.
  • These checks pass: scripts/sync-shared-copies.sh --check and --check-bump origin/main, scripts/validate-plugins.sh, scripts/check-changed-skills.sh origin/main, check-skill-description-voice, check-skill-portability, check-shell-portability, check-changelog-parity --check-bump/--check-order, check-skill-leaf-names.sh --check, check-contract-clause-coverage.py, check-evals-quality.sh (0 warnings), markdownlint (0 issues), and typos.
  • Not run locally: scripts/check-html-assets.sh, because htmlhint is not installed and this change adds no .html asset.
  • Smoke test: I published one throwaway deck through the skill's flow (K0, visibility NONE, gate result artifact): https://claude.ai/artifact/MWHBPC3WwG3vBie9J1aXe1. It is private, and you can delete it after review.

Owner review still open (needs-human):

Related

🤖 Generated with Claude Code

…rtifact type

Add /visualization:present. It writes the markdown outline as the record,
finds the Slides type through the Artifact tool's quickstart at run time,
and fills the deck as the type instructs. check-deck.mjs runs before the
type's create call: it refuses a deck folder inside a working tree, refuses
a K2 deck carrying anything but text and uploaded images, and runs the
shared publish gate over every file.

Move explain-change's publish gate and credential patterns into
lib/publish-gate.mjs, with generated copies in review and visualization.
The rendered-views convention gains an Artifact types section.

Closes #5867

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…layers in the gate

- check-deck replaces the K2 deny-list over a naive tag regex with a
  quote-aware tokenizer and an allowlist of text and layout elements,
  attributes, and uploaded image sources. Attribute values are decoded
  before checking, a K2 style may not hold (, \ or &, and anything the
  tokenizer cannot parse is refused. Every reviewer reproducer is a
  must-refuse test.
- The deck folder, project/, and every file inside must be plain files
  reached through no symlink.
- The script resolves the medium layers itself (argument, plugin option,
  ~/.claude/rendered-views.md, untracked gitignored overlay); a tracked
  team file can keep a deck local but never publish it. --explicit is gone.
- The deck title is gated and printed; the create call uses that title.
- The overlay guard and project-root lookup move to lib/publish-gate.mjs,
  which digest-policy now imports.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T18:01:41.735913Z bbac6b9 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 8s —— View job


Claude's code review (/review:code-review)

Tasks

  • Gather context (PR body, changed files, repo instructions)
  • Invoke /review:code-review and follow it exactly
  • Read diff and changed files in full
  • Post inline findings
  • Post summary

Scope note: .github/workflows/claude-security-review-hosted.yml exists in this repo, so per REVIEW.md this lane omits security findings (e.g. the check-deck.mjs K2 allowlist/tokenizer, credential-pattern coverage) — those belong to the security lane.

Findings

1 inline comment posted:

  • plugins/visualization/skills/visualize/SKILL.md:71 — the new hand-off line makes /visualization:present visualize's natural successor for slide decks, but visualize/SKILL.md has no ## Next section naming it, as .claude/rules/skill-bodies-state-current-rules.md requires when a new skill (here, present, which does add its own ## Next back to visualize) becomes a predecessor's successor.

What I verified by reading, not just trusting the PR body

  • lib/publish-gate.mjs is a faithful extraction of the gate/credential logic previously inline in digest-policy.mjs; the review and visualization copies are byte-identical generated copies (only the generated-file header differs), and both are registered in scripts/shared-copies.txt.
  • digest-policy.mjs's refactored publishGate() remaps NONE → UNKNOWN before calling the shared gate, preserving the pre-existing "a PR always has a repository" behavior; overlayApplies() call sites keep requireIgnored: false, matching the old digest behavior (warn-but-apply for an un-ignored overlay), while check-deck.mjs passes requireIgnored: true for the stricter deck case.
  • check-deck.mjs's K2 tokenizer/allowlist (tags, attributes, image-source regex blocking path traversal via project/ds/.., entity-decoding for style/href values) matches its own test fixtures in present.test.mjs, and the deck-root symlink/working-tree refusals are covered by dedicated tests.
  • Version bumps, CHANGELOGs, docs/catalog.md, and docs/skill-cheat-sheet.md all agree with the actual plugin.json/description changes.
  • I could not execute node --test in this sandbox (command execution required approval that wasn't available), so the 19/19, 13/13, and 71/71 pass counts in the PR body are author-claimed and unverified by me; the test files themselves read as consistent with the implementation.

No other correctness or maintainability issues met the high-signal bar (block-worthy, not already caught by the project's own lint/test scripts).

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 4m 9s —— View job


Security review (/review:security-review) complete

  • Gather context (PR description, changed files)
  • Understand request: invoke /review:security-review for this PR
  • Run /review:security-review skill
  • Post findings

Scope reviewed: lib/publish-gate.mjs (and its generated copies in plugins/review/lib/ and plugins/visualization/lib/), plugins/visualization/skills/present/scripts/check-deck.mjs, plugins/review/skills/explain-change/scripts/digest-policy.mjs (shared-gate refactor), and the present skill's SKILL.md/tool grants. This is the security-relevant surface: it decides whether private-repo or credential-shaped content gets published to a public claude.ai Artifact, and sanitizes untrusted (K2) HTML before it reaches that Artifact.

No security issues found. Specifics checked and found sound:

  • Credential/visibility gate (publishGate in lib/publish-gate.mjs#L48-L57): correctly denies publish for non-PUBLIC/non-NONE visibility and for any credential-shaped line (findSecret), defaulting to local on any miss.
  • Trust-layer resolution (trustedMedium, lib/publish-gate.mjs#L138-L159): only layers a checked-out branch cannot write (CLI argument, plugin option, ~/.claude/rendered-views.md, or an overlay verified untracked+gitignored via overlayApplies) can elevate to artifact; the team .claude/rendered-views.md is correctly excluded from the trusted set for publishing (can only force local). overlayApplies (lib/publish-gate.mjs#L100-L123) also defends against a tracked case-insensitive alias, a .claude submodule/symlink, and a symlinked overlay file.
  • K2 HTML allowlist (k2Refusal, check-deck.mjs#L77-L133): a quote-aware tokenizer that fails closed (UNPARSED on anything it can't parse confidently — bare <, duplicate attrs, unknown entities, unterminated tags), blocks all event handlers, href, script/x-embed/svg/style/iframe/object/etc., and restricts src to an anchored allowlist (/_blob/... or project/ds/...) that structurally can't contain .. even after entity decoding (checked this specifically — the regex forbids literal . outside the fixed extension separator, so an entity-decoded ../ doesn't re-introduce traversal). The style attribute check runs on the raw (pre-decode) value and rejects any &, so an entity-encoded url( can't smuggle a CSS function past the decode step. This matches the extensive adversarial test suite already in plugins/visualization/tests/present.test.mjs (symlinked root/slide, aliased/nested symlinks, tracked vs. gitignored overlays, entity/case-encoding bypass attempts, path-traversal attempts).
  • Deck root checks (check-deck.mjs#L186-L200): refuses a root that is, or is reached through, a symlink, and refuses a root inside a working tree, before any file is read.
  • Title gating (check-deck.mjs#L169-L174): blocks control characters, </>, and bidi-override characters, consistent with the gate running before the type's create call (which the PR notes already publishes the title).
  • digest-policy.mjs refactor: confirmed it now delegates to the shared gate with no behavior drift (NONE intentionally mapped to UNKNOWN since a PR always has a repository) and no leftover references to the removed local dirname/isLink helpers; the generated copies in plugins/review/lib/publish-gate.mjs and plugins/visualization/lib/publish-gate.mjs are byte-identical to the canonical source aside from the generated-file header.
  • Instruction-surface check: this diff only adds rules (docs/conventions/rendered-views/README.md's new "Artifact types" section, visualize's hand-off to present); no existing guardrail, allowlist, or hook is removed or narrowed.
  • Tool grants: present's allowed-tools are scoped to its own check-deck.mjs script and read-only gh repo view, no broad Bash/gh pr/gh issue access.

No CRITICAL, IMPORTANT, or SUGGESTION findings to report.

Comment thread plugins/visualization/skills/visualize/SKILL.md
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

claude-review has reviewed this pull request through c3b1a03; a later push is reviewed from there.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bbac6b9eb9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/visualization/skills/present/SKILL.md
Comment thread plugins/visualization/skills/present/SKILL.md
Comment thread docs/conventions/rendered-views/README.md Outdated
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

claude-security-review has reviewed this pull request through c3b1a03; a later push is reviewed from there.

…oss-plugin registry

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 24s —— View job


Security review (/review:security-review) — incremental

Scope: This lane previously reviewed through bbac6b9. Since then, only scripts/cross-plugin-source-registry.txt changed (per .claude-lane/incremental.diff); the rest of the PR is unchanged from that commit and was already reviewed.

Tasks

  • Gather context (incremental diff, lane scope)
  • Review the changed file
  • Post findings

Findings

No security issues found.

The only change is a plain-text registry addition in scripts/cross-plugin-source-registry.txt, registering lib/publish-gate.mjs as a canonical source with generated copies under plugins/*/lib/publish-gate.mjs, checked by scripts/sync-shared-copies.sh --check. It:

  • Follows the exact format and comment style of the pre-existing lib/view-builder.mjs / lib/view-runtime.js entries directly above it.
  • Is consistent with scripts/shared-copies.txt and the actual generated copies already present at plugins/review/lib/publish-gate.mjs and plugins/visualization/lib/publish-gate.mjs (reviewed as part of the full PR at bbac6b9).
  • Contains no executable content, no path traversal risk, and introduces no new trust boundary — it's data consumed by a drift-detection script, not something that affects the publish-gate's runtime behavior.

No findings to report for this incremental scope.

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 0s —— View job


Claude's code review (/review:code-review, incremental)

Scope: this lane last reviewed bbac6b9. Per the lane header, only the change in scripts/cross-plugin-source-registry.txt (captured in .claude-lane/incremental.diff) is in scope here; every other file was reviewed at bbac6b9 already.

Tasks

  • Gather context (PR body, incremental diff scope, repo instructions)
  • Read .claude-lane/incremental.diff for the only changed file: scripts/cross-plugin-source-registry.txt
  • Invoke /review:code-review and follow it exactly, scoped to that diff
  • Post inline findings (none — see below)
  • Post summary

Findings

None. The diff adds two registry entries for lib/publish-gate.mjs:

lib/publish-gate.mjs

lib/publish-gate.mjs -> plugins/*/lib/publish-gate.mjs

I verified this against scripts/cross-plugin-source-registry.txt:

  • It follows the file's own documented format exactly (lines 11-16): a bare root-relative path line for check-cross-plugin-source-drift.sh --check, plus a <canonical> -> <glob> cluster line for the duplication audit — the identical shape used immediately above it for lib/view-builder.mjs and lib/view-runtime.js.
  • It's consistent with scripts/shared-copies.txt:320-321, which registers the same two concrete copies (plugins/review/lib/publish-gate.mjs, plugins/visualization/lib/publish-gate.mjs) that the plugins/*/lib/publish-gate.mjs glob here resolves to.
  • Read scripts/check-cross-plugin-source-drift.sh to confirm the bare line is interpreted as the plugin-relative path (lib/publish-gate.mjs) the discovery loop clusters on — matches the two added files exactly.
  • No formatting issues: trailing newline and blank-line spacing match the rest of the file.

I wasn't able to execute scripts/check-cross-plugin-source-drift.sh --check in this sandbox (command execution required approval not available here), so I verified by reading the script's parsing logic and cross-referencing scripts/shared-copies.txt by hand instead of running it.

Add the visualize successor section, K2 untrusted-content framing, a dated
pointer for the Artifact quickstart specifics, and slash-prefixed skill
references in the rendered-views convention.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 8s —— View job


Security review (/review:security-review) — incremental

Scope: This lane last reviewed 5e5f94e. Per the lane header, only the diff captured in .claude-lane/incremental.diff is in scope here — all other files were already reviewed at bbac6b9 / 5e5f94e.

Tasks

  • Gather context (incremental diff, lane scope)
  • Invoke /review:security-review and follow it exactly, scoped to this diff
  • Post findings

Findings

No security issues found.

This increment is prose-only — no executable code changed. It touches:

  • docs/conventions/rendered-views/README.md — adds a leading slash to five bare review:explain-change / visualization:present mentions so they read as invocable /plugin:skill citations. Pure formatting; no meaning change.
  • plugins/visualization/skills/present/SKILL.md#L29-L31 — adds explicit untrusted-content framing immediately after the K2 classification step: K2 text is attacker-controllable, is quoted as data, an embedded instruction is a finding rather than something to follow, it never widens tool/write/publish authority, and the model's own summary of K2 material is just as untrusted and must never become markup or script. This sits upstream of every later step that touches K2 content (the gh repo view call, the Artifact quickstart call, and the deck-file write in step 4), so it covers the injection surface before any of those run. This is a direct, adequate fix for the trust-boundary-framing gap flagged on this PR's earlier commit (chatgpt-codex-connector's P1 comment on SKILL.md:27).
  • plugins/visualization/skills/present/SKILL.md#L56-L63 — constrains the quickstart call to name no parameter beyond the two the skill already specifies (intent, design_systems) and adds the required Pointer / As-of / Recheck-trigger record per .claude/rules/skill-bodies-state-current-rules.md, rather than hard-coding the Artifact tool's per-account type behavior. This closes the other P1 Codex finding (volatile upstream specifics) and, as a side effect, removes a potential drift/injection vector where a hard-coded assumption about tool behavior could go stale.
  • plugins/visualization/skills/visualize/SKILL.md#L265-L270 — adds a ## Next section pointing to /visualization:present, satisfying the successor-section rule flagged in my own code-review lane's prior inline comment. No security surface.

Instruction-surface check: nothing in this diff deletes, narrows, or softens a standing instruction or guardrail — every change either adds a new guardrail (K2 framing, parameter restriction) or is a citation-format fix. No finding under the instruction-exception-register lens applies.

No CRITICAL, IMPORTANT, or SUGGESTION findings to report for this incremental scope.

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 9s —— View job


Claude's code review (/review:code-review, incremental)

Scope: this lane last reviewed 5e5f94e. Per the lane header, only the diff in .claude-lane/incremental.diff is in scope — all three edits are fix-ups to content this PR itself added earlier (bbac6b9), addressing findings from the Codex review and my own earlier inline comment:

  • docs/conventions/rendered-views/README.md
  • plugins/visualization/skills/present/SKILL.md
  • plugins/visualization/skills/visualize/SKILL.md

Tasks

  • Gather context (PR body, incremental diff, repo instructions)
  • Invoke /review:code-review and follow it exactly, scoped to this diff
  • Read changed files in full for context
  • Post inline findings (none — see below)
  • Post summary

Findings

None. This commit (982d795) resolves all four previously open findings on this PR, and I verified each fix rather than taking the diff at face value:

  1. Slash-prefixed cross-plugin citations. Codex flagged bare review:explain-change / visualization:present mentions. I grepped the full file after the fix (README.md): all newly-added mentions now carry the / prefix (lines 360, 368, 405, 416, 491). The remaining bare visualization:visualize mentions (lines 469, 477, 501, 677) pre-date this PR (confirmed via git show origin/main:...), so they're correctly left untouched — out of this PR's scope.
  2. K2 trust-boundary framing. Codex's P1 asked for explicit untrusted-content framing at the point present/SKILL.md ingests K2 sources. The new paragraph at present/SKILL.md:29-31 does this correctly: quote K2 as data, treat an embedded instruction as a finding not a request, no widening of tool/write/publish authority, and extends the same treatment to the skill's own summary of K2 content.
  3. Dated pointer for volatile Artifact specifics. Codex's second P1 asked for the required pointer/as-of/recheck-trigger form instead of hard-coded tool behavior. present/SKILL.md:56-63 now states the decision in the skill's own words (no parameter beyond the two it names) and adds the three required parts — pointer (https://code.claude.com/docs/en/artifacts), as-of date, and a concrete recheck trigger — matching .claude/rules/skill-bodies-state-current-rules.md.
  4. ## Next successor section. My own earlier inline comment flagged that visualize/SKILL.md had no ## Next naming present as the slide-deck successor. visualize/SKILL.md:265-269 now adds it, correctly placed immediately before ## Gotchas, in the single-invocation-plus-sentence form the rule requires. present/SKILL.md's own ## Next (pointing back to visualize) is also correctly placed before its ## Gotchas.

No new issues introduced by this commit.

@kyle-sexton
kyle-sexton added this pull request to the merge queue Oct 3, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Oct 3, 2026
…artifact-types

# Conflicts:
#	plugins/review/.claude-plugin/plugin.json
#	plugins/review/CHANGELOG.md
@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 26s —— View job


Claude's code review (/review:code-review)

Tasks

  • Gather context (PR body, changed files, repo instructions)
  • Determine incremental scope since last review (982d795 vs current HEAD c3b1a03)
  • Invoke /review:code-review and follow it exactly
  • Read diff and changed files in full
  • Post inline findings (none)
  • Post summary

Scope note: .github/workflows/claude-security-review-hosted.yml exists in this repo, so per REVIEW.md this lane omits security findings — those belong to the security lane.

What changed in this push

This push (982d795 → c3b1a03) is a merge of origin/main into the branch, resolving a
conflict in plugins/review/.claude-plugin/plugin.json and plugins/review/CHANGELOG.md against
an unrelated main-line bump (review 0.39.1 → 0.40.0, from the session-bridge PR). I verified
the resolution rather than trusting the merge:

  • plugins/review/.claude-plugin/plugin.json now reads 0.40.1, correctly stacked above main's
    0.40.0 (this PR's own +0.0.1 change preserved on top).
  • plugins/review/CHANGELOG.md
    keeps this PR's [0.40.1] entry (publish-gate extraction) correctly ordered above the inherited
    [0.40.0] entry, newest-first.
  • scripts/cross-plugin-source-registry.txt and scripts/shared-copies.txt picked up unrelated
    main-line entries for review/view-bridge (session-bridge); this PR's own lib/publish-gate.mjs
    registry/copy lines are untouched and still correct.

I confirmed with git diff origin/main...HEAD --stat: the effective PR diff is still exactly the
same 23 files, +1455/-88, as the PR body states — the merge introduced no new content into this
PR's diff, only a clean version-bump reconciliation.

Findings

None. All four findings raised earlier on this PR (Codex's two P1s on present/SKILL.md, my own
inline finding on the missing ## Next in visualize/SKILL.md, and Codex's slash-prefix citation
finding) were already fixed in 982d795 and verified by the incremental review lanes at that
commit. This push adds nothing new to re-review.
· branch feat/5867-slides-via-artifact-types

@claude

claude Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 50s —— View job


Security review (/review:security-review) — incremental

Scope: The last security lane reviewed through 982d795. This push (c3b1a03) is a merge of origin/main into this branch; comparing 982d795 against the new head c3b1a03 restricted to this PR's own files (git diff origin/main...HEAD matches the PR's 23-file change list exactly) shows the merge touched only:

None of this PR's own security-relevant files changed in this push: lib/publish-gate.mjs, the generated copies, plugins/visualization/skills/present/scripts/check-deck.mjs, digest-policy.mjs, and all three SKILL.md files (present, visualize, the rendered-views README) are byte-identical to 982d795.

Tasks

  • Gather context (diff since last-reviewed commit, scope of the sync)
  • Invoke /review:security-review and follow it exactly, scoped to this push
  • Read the changed lines in full
  • Post findings

Findings

No security issues found. This sync is a merge-conflict resolution carrying over an unrelated version bump, changelog entry, and registry entries from main; it adds no executable code and touches none of the publish-gate, K2-allowlist, or trust-boundary logic this PR introduces. All prior findings on this PR (the two Codex P1s and the ## Next successor-section gap) remain fixed as of 982d795, unaffected by this push.
· Branch: feat/5867-slides-via-artifact-types

@kyle-sexton
kyle-sexton added this pull request to the merge queue Oct 3, 2026
Merged via the queue into main with commit 4bad242 Oct 3, 2026
19 checks passed
@kyle-sexton
kyle-sexton deleted the feat/5867-slides-via-artifact-types branch October 3, 2026 18:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

rendered-views: slides and design system via claude.ai artifact types

1 participant