Commit Graph

122 Commits

Author SHA1 Message Date
Trevin Chow 4826337c2d fix(ce-update,ce-setup): probe scripts self-locate; tighten ce-setup platform check
Addresses two PR review findings empirically confirmed in a Claude Code
session: `printenv CLAUDE_SKILL_DIR` from the Bash tool returns
`NOT_SET`, proving CLAUDE_SKILL_DIR (and CLAUDE_PLUGIN_ROOT) are
SKILL.md content substitutions only, not environment variables exported
to Bash subprocesses.

ce-update probes (P1, Codex thread):
  Previously, currently-loaded-version.sh and marketplace-name.sh read
  `${CLAUDE_SKILL_DIR:-}` directly from the environment. Since the env
  var is never set in subprocesses, both scripts always emitted
  __CE_UPDATE_NOT_MARKETPLACE__ — meaning ce-update would never actually
  perform version comparison even on real marketplace installs.

  Fix: derive skill_dir from BASH_SOURCE[0] (the script's own location).
  Adds regression tests that copy each script into a fake
  marketplace-shaped path and run it with CLAUDE_SKILL_DIR explicitly
  cleared from the env, asserting the correct version/marketplace
  segments are extracted.

ce-setup platform check (P2, Codex thread):
  The check at line 47 keyed off "non-empty AND not literal
  ${CLAUDE_PLUGIN_ROOT}", which incorrectly accepted unresolved command
  strings like `echo "${CLAUDE_PLUGIN_ROOT}"` left in place by
  non-Claude harnesses that don't process `!` pre-resolution. Tightened
  to "starts with `/` and contains no `${`", which naturally rejects all
  unresolved forms while accepting real absolute paths.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-28 00:03:17 -07:00
Trevin Chow f2c3d772c5 fix(ce-update): probe scripts at runtime via CLAUDE_SKILL_DIR + allowed-tools
The previous commit moved probes from `!` pre-resolution to the runtime
Bash tool, which sidestepped Claude Code's load-time permission gate.
But two empirical issues remained:

1. Bare `bash scripts/<name>.sh` failed with "No such file or directory"
   because the runtime Bash tool runs from the user's project CWD, not
   the skill directory. The AGENTS.md guidance "all platforms resolve
   script paths relative to the skill's directory" is aspirational, not
   reality for the runtime Bash tool path.
2. Falling back to `bash <abs-path>` triggered a runtime permission
   prompt for users without `Bash(bash:*)` allow rules (most users have
   `Bash(bash -c:*)` at most).

Fix:
- Use `${CLAUDE_SKILL_DIR}/scripts/<name>.sh` in each runtime command.
  Claude Code sets that env var to the active skill's directory at
  runtime, so the path resolves correctly in both `--plugin-dir` and
  marketplace-cached installs.
- Declare narrow `allowed-tools` patterns pinned to each script
  filename. The skills docs explicitly state that `allowed-tools`
  grants permission for runtime tool calls "while the skill is active,
  so Claude can use them without prompting" — that coverage was murky
  for pre-resolution but is documented for runtime.

Tests:
- New regression guard fails if any probe lacks the `${CLAUDE_SKILL_DIR}`
  prefix (catching reverts to bare relative paths).
- New regression guard fails if `allowed-tools` is dropped or broadened
  to `Bash(bash *)`.
- Existing guard against `!` pre-resolution stays.

AGENTS.md updated to document both pieces (path form + allow-listing)
that the runtime-Bash pattern requires, with a concrete code-block
example.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 23:18:24 -07:00
Trevin Chow 02f2810b73 fix(ce-update): move probes from ! pre-resolution to runtime Bash tool
Empirical testing showed the previous approach was unreliable. With
`defaultMode: bypassPermissions` ON the `allowed-tools` frontmatter
appeared to work, but with bypass OFF (the configuration most users
have) the narrow `Bash(bash *<script>.sh)` patterns failed the
load-time permission check. The official docs are inconsistent on
whether `*` works as an internal-token glob, and `allowed-tools`
coverage of pre-resolution is undocumented. We can't ship a fix that
only works for users who have bypassPermissions on.

The reliable fix is to remove `!` pre-resolution entirely. Probes now
run from the skill body via the runtime Bash tool, which:
- Honors `defaultMode: bypassPermissions` (silent for those users)
- Falls back to a normal one-time approval prompt that Claude Code
  remembers (acceptable UX for users without bypass)

Skill body restructured with a "Step 1: Probe versions" section that
instructs the agent to run all three scripts in parallel, then "Step
2: Apply decision logic" that reads the captured outputs.

Tests updated:
- Drop the now-obsolete `allowed-tools` and pre-resolution-section
  assertions
- Add a regression guard that fails if `!`bash <path>`` pre-resolution
  is reintroduced
- Add a guard that ensures each of the three probe-script invocations
  appears in the skill body
- Refactor `runUpstreamCommand` -> `runUpstreamScript` since the test
  no longer extracts a pre-resolution command from SKILL.md and just
  runs the script directly

AGENTS.md updated: replace the now-incorrect "declare allowed-tools"
guidance with the correct pattern (invoke from skill body via runtime
Bash tool when the first token would be `bash <path>`).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 23:12:05 -07:00
Trevin Chow b875b4d476 fix(ce-update): pin allowed-tools to specific script filenames instead of broad Bash
Previous fix used `Bash(bash *)` to grant pre-resolution permission for
the three extracted scripts, but that surface is broader than necessary
— it allows any `bash <anything>` command, not just the three scripts
ce-update actually invokes.

Narrows to per-script patterns: `Bash(bash *upstream-version.sh)` etc.
Per Claude Code's permission docs, `*` works at any position and quotes
are stripped before matching, so each pattern matches both the local
checkout path and the marketplace cache path without granting blanket
Bash access.

Updates the regression test to assert each script-specific pattern is
present and to fail if `Bash(bash *)` is reintroduced. Updates AGENTS.md
guidance to recommend script-pinned patterns with an example.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 22:47:03 -07:00
Trevin Chow 74949a95d2 fix(ce-update): declare allowed-tools so pre-resolution scripts pass permission check
The prior fix (commit 8605e0f9) extracted ce-update's pre-resolution
logic into `bash "${CLAUDE_SKILL_DIR}/scripts/<name>.sh"` invocations
to clear Claude Code's safety check. That worked, but introduced a
new failure mode: the *permission* check rejects the resulting
`bash "/abs/path/script.sh"` form because pre-resolution `!` commands
do not honor `defaultMode: bypassPermissions`, and `Bash(bash:*)` is
not a rule most users allow-list (they have `Bash(bash -c:*)` at most).

Fix: declare `allowed-tools: Bash(bash *), Bash(echo *)` in ce-update's
frontmatter so the skill carries its own permission grant instead of
depending on user settings.

- Adds regression test in tests/skills/ce-update.test.ts that fails
  if allowed-tools is dropped or stops covering Bash.
- Updates AGENTS.md with a "Permission gate on extracted scripts"
  subsection so future skills using the same script-extraction pattern
  declare allowed-tools upfront.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 22:18:31 -07:00
Trevin Chow 8605e0f96c fix(skills): replace shell antipatterns blocked by permission check
Two safety-check rejections in `!` backtick pre-resolutions were
breaking skill-load in Claude Code:

- `[A] && B || C` shape ("ambiguous syntax with command separators",
  issue #710): ce-setup, ce-update, ce-work-beta/codex-delegation-workflow.
- `$()` containing a double-quoted string ("Unhandled node type:
  string", issue #709): ce-compound, ce-sessions, ce-update, ce-work-beta.

Replaces each with a safe shape: raw env-var emit, pure-pipe sed,
`${var%suffix}` parameter expansion, or an extracted script under the
skill's `scripts/`. ce-update gets three scripts (upstream-version,
currently-loaded-version, marketplace-name) since it's Claude-only
and has the most complex pre-resolution logic.

Adds regression tests in tests/skill-shell-safety.test.ts that flag
both antipatterns at PR time, and updates AGENTS.md to enumerate the
rejected shapes alongside the existing `case`/`esac` rule.

Closes #709, #710.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 21:05:03 -07:00
Trevin Chow 5952b20d7f fix(skills): replace case statements blocked by permission check (#701)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-26 14:22:20 -07:00
Trevin Chow a91270ccd2 fix(session-historian): cap deep-dives, add keyword filter primitive, tighten dispatch (#699)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-25 23:37:30 -07:00
Trevin Chow 7eea2d1cfe feat(ce-compound): add frontmatter parser-safety validator (#697) 2026-04-25 21:37:57 -07:00
Trevin Chow ad9577e732 fix(ce-code-review): tighten autofix_class rubric for safe_auto/gated_auto boundary (#695)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-25 21:03:43 -07:00
Trevin Chow 50bf65e88c fix(ce-doc-review): rename LFG path to best-judgment to avoid /lfg collision (#691)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-25 19:04:31 -07:00
Trevin Chow f30404e57b fix(ce-demo-reel): wait for network idle and reject blank frames (#692) 2026-04-25 18:59:40 -07:00
Trevin Chow 85e9a2073b fix(ce-code-review): move run artifacts from .context/ to /tmp per AGENTS.md (#690)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-25 18:19:40 -07:00
Trevin Chow 9ba41a14ca fix(ce-code-review): replace LFG with best-judgment auto-resolve (#685)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-25 18:12:09 -07:00
Trevin Chow bc8ae1a6b5 fix(main): recover version drift, fix stale test, document learnings (#678)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-24 15:07:49 -07:00
Trevin Chow ab44d89b0b fix(release): remove stale release-as pin (#674) 2026-04-24 07:23:02 -07:00
Trevin Chow 351d12ec5b fix(ce-update): compare against main plugin.json, not release tags (#660) 2026-04-23 14:36:58 -07:00
Trevin Chow 7ddfbed33b feat(pi): first-class support via pi-subagents + pi-ask-user (#651)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-22 10:26:29 -07:00
Trevin Chow 6155b9de3c fix(ce-update): derive cache dir from CLAUDE_PLUGIN_ROOT parent (#645)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-22 08:42:28 -07:00
Trevin Chow 13f95ba639 fix(skills): cap skill descriptions at harness limit (#643) 2026-04-21 21:56:15 -07:00
Trevin Chow 5a26a8fbd3 refactor(ce-code-review): anchored confidence, staged validation, and model tiering (#641)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-21 21:04:29 -07:00
Trevin Chow b104ce46be fix(lfg): use platform-neutral skill references (#642) 2026-04-21 20:08:48 -07:00
Trevin Chow accbd2adcf refactor(todos): remove internal file-based todo system (#635)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-21 18:16:13 -07:00
Trevin Chow 19bbb60e90 refactor(skills): remove ce-onboarding skill (#639)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-21 18:15:36 -07:00
Trevin Chow ff0eee391e refactor(ce-brainstorm): make doc review opt-in in Phase 4 handoff (#633) 2026-04-21 16:28:20 -07:00
Trevin Chow 6caf330363 refactor(ce-doc-review): anchor-based confidence scoring (#622)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-21 14:54:03 -07:00
Trevin Chow 4c57508c1a refactor(agents): flatten agents directory (#621) 2026-04-21 02:35:21 -07:00
Trevin Chow cd4af86e5e refactor(session-history): move extraction scripts behind skills (#619) 2026-04-21 00:12:11 -07:00
Trevin Chow 3ed4a4fa0f feat(codex): native plugin install manifests + agents-only converter (#616) 2026-04-20 19:44:25 -07:00
Trevin Chow c2d60b47be refactor(install): prefer native plugin install across targets (#609)
Co-authored-by: John Cavanaugh <cavanaug@users.noreply.github.com>
2026-04-20 18:47:07 -07:00
Trevin Chow d8436b9a3c fix(ce-compound): quote YAML array items starting with reserved indicators (#613)
Co-authored-by: Nathan Vale <hi@nathanvale.com>
2026-04-20 14:01:11 -07:00
Trevin Chow c1f68d4d55 feat(doc-review, learnings-researcher): tiers, chain grouping, rewrite (#601)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-19 20:25:47 -07:00
Trevin Chow 2aee4d4203 fix(ce-release-notes): backtick-wrap <skill-name> token in description (#603) 2026-04-19 00:38:15 -07:00
Trevin Chow 5c0ec9137a refactor(cli)!: rename all skills and agents to consistent ce- prefix (#503)
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-18 15:44:22 -07:00
Trevin Chow 27cbaf8161 feat(ce-review): add per-finding judgment loop to Interactive mode (#590)
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-18 13:09:03 -07:00
Trevin Chow 59dbaef376 feat(ce-release-notes): add skill for browsing plugin release history (#589)
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-17 02:00:37 -07:00
Trevin Chow 1995e3d790 chore(claude-permissions-optimizer)!: remove skill (#578) 2026-04-16 16:46:29 -07:00
Kieran Klaassen 070092d997 feat(ce-polish-beta): human-in-the-loop polish phase between /ce:review and merge (#568)
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-16 17:55:10 -05:00
Trevin Chow 3d96c0f074 fix(ce-plan, ce-brainstorm): reliable interactive handoff menus (#575) 2026-04-16 12:04:19 -07:00
alexph-dev ed778e62f1 fix(converters): preserve Codex config on no-MCP install (#564) 2026-04-15 10:06:42 -07:00
alexph-dev ee8e402897 fix(converters): preserve Codex agent sidecar scripts (#563) 2026-04-15 10:06:26 -07:00
Trevin Chow b979143ad0 feat(ce-demo-reel): add demo reel skill with Python capture pipeline (#541)
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-09 21:29:51 -07:00
Trevin Chow bb59547a2e feat(ce-work): reduce token usage by extracting late-sequence references (#540)
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-09 12:48:21 -07:00
Trevin Chow 31b0686c2e feat(ce-work-beta): add beta Codex delegation mode (#476)
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-09 00:29:12 -07:00
Martin Kessler 2c05c43dc8 fix(openclaw): use sync plugin registration (#498)
Co-authored-by: Niemand Assistant <niemand@kessler.io>
2026-04-08 14:13:43 -07:00
Trevin Chow 3208ec71f8 feat(session-historian): cross-platform session history agent and /ce-sessions skill (#534)
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-08 07:52:26 -07:00
Trevin Chow d37f0ed16f feat(ce-update): add plugin version check skill and ce_platforms filtering (#532)
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-08 00:09:02 -07:00
Trevin Chow bdeb7935fc fix(ce-brainstorm): reduce token cost by extracting late-sequence content (#511)
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-05 11:25:12 -07:00
David Torres 6dcb4a3c55 fix(converters): remove invalid tools/infer from Copilot agent frontmatter (#493) 2026-04-02 13:23:40 -07:00
Trevin Chow fd562a0d02 feat(ce-plan): reduce token usage by extracting conditional references (#489)
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-02 01:55:53 -07:00