28 Commits

Author SHA1 Message Date
Vincent b75b7f351b fix: prepare complete issues and enforce delivery gates (#149)
* fix: unify execution-ready issue preparation

* fix: require prepared issues and explicit dispatch roles

* fix: provision prepared workflow skills with dispatch setup

* fix: gate prepared delivery on independent review and CI

* chore: record reviewed delivery adaptations

* fix: align legacy loops with prepared delivery contract

* fix: preserve dispatch claim ownership and validate runtime trust

* fix: synchronize reviewed workflow adapters and provenance

* fix: reject hidden plan input and isolate planner credentials
2026-09-14 14:55:42 +02:00
Vincent 17d3741104 feat: consolidate Pstack with pinned upstream synchronization (#142)
* feat: consolidate Pstack capabilities into canonical skills

* fix: preserve harness portability and canonical cleanup

* ci: verify pinned Pstack imports and packaged runtime

* feat: track pinned Pstack imports and verify packaged runtime

* fix: exclude installed dependency tests from CI discovery

* fix: complete Pstack semantic and synchronization review

* fix: clarify canonical Pstack capture and cleanup guidance
2026-09-05 02:22:30 -07:00
Vincent 51bebea40d fix!: bind cleanup deletion to immutable scoped proof (#134)
* fix: bind cleanup deletion to immutable scoped proof

* fix: preserve exact cleanup patch and final state evidence

* test: collect packaged skill helper regressions in CI

* fix: preserve dependent PRs and bounded cleanup execution
2026-09-04 23:51:05 -07:00
Vincent ddeb8fe662 chore: open the release PR as a draft (#115)
The rolling release PR sits open accumulating every merge to master, so a
ready-for-review PR misrepresents its state and invites an accidental merge.
draft-pull-request makes readiness an explicit act: mark it ready when you
actually intend to cut the version.
2026-08-18 07:53:01 +02:00
Vincent 9e6af98527 chore: drop the no-op CI dispatch from the release workflow (#113)
The workflow_dispatch CI kick attached its `checks` run to the release
branch head SHA, but GitHub never counted it in the PR's status rollup, so
branch protection still saw the required check as missing. What actually
unblocks the release PR is approving the queued `action_required`
pull_request run. Removing the step and its `actions: write` grant so the
workflow no longer implies a guarantee it does not provide.
2026-08-17 16:40:33 +02:00
Vincent 4a063e6ced fix: run release-please on GITHUB_TOKEN and dispatch CI on the release branch (#111) 2026-08-17 10:08:26 +02:00
Vincent 90e47be70d feat: add release-please for automated versioning and GitHub releases (#110)
* feat: add release-please for automated versioning and GitHub releases

* ci: run checks on every PR since it is now a required status
2026-08-16 20:31:31 +02:00
Vincent 9509240b83 fix: enforce skill version sync and require bumps on content changes (#109)
- validate-skill-sync.sh: hard-error when plugin.json version != SKILL.md
  metadata.version, or plugin.json description is a YAML block marker
- new scripts/check-skill-version-bumps.sh (bun run version:check): CI fails
  when a skill's content changes without a metadata.version bump vs base
- CI: fetch-depth 0 + version:check step after validate
- sync 12 drifted plugin.json versions to SKILL.md; fix turborepo/html-style
  junk descriptions
- bundle plugin.json + marketplace.json versions now come from
  package.json / skill plugin.json instead of hardcoded 1.0.0
- fixtures + regression tests for both validator gates
2026-08-16 20:27:14 +02:00
Vincent b492a53d7b fix: keep the item id item-add returns instead of re-querying a lagging replica (#108)
Issue Governance failed on every issue opened in the last batch (#97-#101)
with gh's item-edit usage text. The step added the issue to the board, threw
away the item id that item-add returned, and re-ran the paginated items query
to find it again. That query reads a replica that lags behind the write, so
it came back empty, ITEM resolved to the empty string, and
'item-edit --id ""' failed before any field was set — leaving those issues
on the board with no Priority, no Type, and no needs-triage label.

Keep the id from item-add, and hard-fail with a readable message if the id
still cannot be resolved rather than calling item-edit with a blank --id.
2026-08-16 19:47:57 +02:00
Vincent 768efb9bd2 docs: generate catalog facts from canonical sources (#88) 2026-07-13 10:41:28 +02:00
Vincent 400068dcba feat: enforce portable skill validation boundaries (#85) 2026-07-13 10:34:09 +02:00
Vincent f167825407 fix: make agent-folder-init non-destructive and portable (#84)
* docs: define harness execution boundary

* fix: replace inert platform markers

* fix: harden agent config audit

* fix: make agent folder scaffold safe

* fix: satisfy shellcheck for adapter validation
2026-07-13 10:32:18 +02:00
Vincent 1bc82fab39 fix: harden project governance fallbacks (#79) 2026-07-13 10:28:21 +02:00
VincentShipsIt 17064c1bdd Merge remote-tracking branch 'origin/master' into claude/admiring-bouman-a5deca
# Conflicts:
#	.claude-plugin/marketplace.json
#	README.md
#	bundles/ai-agents/README.md
#	scripts/plugin-categories.json
2026-06-21 13:46:28 +02:00
VincentShipsIt 25e7995bb7 feat(dev-loop): add codex-image-gen skill, dispatch:plan gate, and local /codex-loop
Implements three independent enhancements (#39, #26, #27):

#39 codex-image-gen skill (ai-agents bundle)
- New skill that drives the Codex CLI image tool and extracts the finished
  PNG from the session rollout JSONL (the headless `codex exec` path never
  writes the image to disk). Ships SKILL.md, plugin.json, and a Python
  extractor helper, plus an AppIcon.appiconset worked example and the
  alias/sandbox, size/alpha, and fragility caveats.

#26 dispatch:plan planning gate
- New plan-dispatch.yml: a human applies `dispatch:plan` to a Backlog issue;
  the Claude lane runs the writing-plans contract, posts/updates a trusted
  `## Implementation Plan` comment, moves the board to Human Review, assigns
  the gate-applier, and applies NO execution gate. Planning and execution stay
  separated by human validation.
- setup-dev-loop.sh seeds the dispatch:plan label and installs the workflow.
- Documented in triage-labels.md, setup-agent-routing, loop.md, ai-dev-loop.md
  (incl. HITL issues never receiving any gate, dispatch:plan included).

#27 local /codex-loop command
- Codex twin of /loop: claims one dispatch:codex Backlog issue, runs the
  executing-plans contract through `codex exec`, opens a PR, hands off to
  Human Review. Same 30-min claim lock, reads the `## Implementation Plan`
  comment, one issue per invocation. loop.md no longer calls the Codex lane
  push-only and cross-references /codex-loop.

Bundles + marketplace.json regenerated; README counts updated (147 skills,
21 commands). All gates green: bun run validate, bun run lint (markdownlint +
biome + shellcheck), actionlint.
2026-06-21 13:31:50 +02:00
VincentShipsIt 58ce9c281c feat(governance): require board + status + priority + type on every issue
GitHub can't block issue creation on missing fields, so enforce continuously:

- .github/workflows/issue-governance.yml — on every issue event, ensure the
  issue is on the Dev Loop board (#7) and auto-fill any empty field (Status=Backlog,
  Priority=P2, Type=Task), then label needs-triage + comment so a human sets real
  values. Idempotent: only writes when a field is empty. Needs PROJECTS_TOKEN
  (project-scoped PAT) — default GITHUB_TOKEN can't write an org board.
- .github/ISSUE_TEMPLATE/ — Feature/Bug/Task forms set the native issue Type and
  add the issue to the board at creation; blank issues disabled so every issue
  starts typed + boarded.
2026-06-21 12:54:44 +02:00
Vincent c825953183 fix(ci): verify bundles without protected-branch push 2026-06-18 12:23:30 +02:00
VincentShipsIt 5ad5df44d5 Bump markdownlint-cli and simplify setup loop logging 2026-06-18 11:23:41 +02:00
Vincent 869fec26e8 fix(skills): resolve GitHub review feedback (#29)
Address actionable review comments from unread shipshitdev/skills GitHub notifications.

- quote skill metadata and neutralize PRD wording

- add release safety guards and dev-loop setup validation

- pin dispatch workflow actions and disable checkout credential persistence
2026-06-18 10:32:57 +02:00
Vincent 93b5ca4e84 feat(dev-loop): board-driven autonomous dev loop — 5-column board, AI-loop phase labels, Claude/Codex/OpenRouter lanes, dev-loop bundle (#28)
Supersedes the earlier #25 dev-loop. Board-as-truth status (Backlog/In Progress/Human Review/Done/Deferred), loop:* phase labels, three engine lanes (dispatch:claude/codex/openrouter), auto-assign on Human Review, dedicated dev-loop bundle, ShipCode-aligned. Coherence-audited; README catalog reconciled.
2026-06-16 22:45:50 +02:00
Vincent d3a57884ee feat(dev-loop): two-engine autonomous dev loop (Claude + Codex), issue-as-source-of-truth planning (#25)
* feat(dev-loop): add ready-for-agent dispatch + setup-agent-routing skill

Human-gated autonomous execution for the AI dev loop, in two phases that share
one dispatch contract: an issue runs only when a human applies `ready-for-agent`
(opt-in) and it sits in `status:todo`.

- setup-agent-routing: new skill that writes an `## Agent skills` routing block
  + docs/agents/ so the dev-loop skills (executing-plans, feature-intake,
  writing-prds, qa-reviewer) know a consumer repo's tracker, label vocabulary,
  and domain layout. Adapted port of setup-matt-pocock-skills.
- commands/loop.md: Phase 1 local pull loop (/loop, --status, --list) wrapping
  executing-plans. One invocation = one task, never a daemon.
- .github/workflows/agent-dispatch.yml: Phase 2 push dispatch on the
  `ready-for-agent` label. OAuth-token-only auth (never ANTHROPIC_API_KEY),
  per-issue concurrency, least-privilege permissions, untrusted issue body.
- executing-plans: candidate query now requires ready-for-agent + status:todo;
  completion strips the gate; QA reject re-arms it (status:todo + ready-for-agent).
- .github/actionlint.yaml: register the Blacksmith runner label (also clears the
  pre-existing false positive on generate-bundles.yml).
- Regenerate bundles + marketplace.json (session bundle 6 -> 7 skills).

* feat(dev-loop): add Codex/GPT lane + model-as-variable + setup script

Extend the ready-for-agent loop into a two-engine design:

- New codex-dispatch.yml: ready-for-codex gate routes to openai/codex-action@v1
  (sandbox: workspace-write, safety-strategy: drop-sudo). The executing-plans
  contract is inlined into the prompt since codex-action has no plugin-loading
  equivalent; Codex auto-reads AGENTS.md/.codex. At most one gate per issue.
- Model selection is now a repo VARIABLE, not hardcoded or secret. Claude lane:
  claude_args --model vars.AGENT_MODEL (fallback sonnet-4-6). Codex lane:
  vars.CODEX_MODEL / vars.CODEX_EFFORT. Only auth tokens stay secret.
- scripts/setup-dev-loop.sh: one-shot per-repo provisioning — seeds labels
  (incl. ready-for-codex), installs both workflows, arms CLAUDE_CODE_OAUTH_TOKEN
  + OPENAI_API_KEY, prints the gh variable set commands. --dry-run/--skip flags.
- Docs: AI-DEV-LOOP.md two-lane rewrite + planner/executor/QA role table;
  setup-agent-routing SKILL + triage-labels seed gain the ready-for-codex gate;
  commands/loop.md notes /loop is the Claude lane (Codex is push-only).

Verified: validate, shellcheck, markdownlint, actionlint all green.

* feat(skills): store implementation plans as issue comments, not local docs/plans files

writing-plans (ported from obra/superpowers) was saving the plan to a local
docs/plans/YYYY-MM-DD-<feature>.md file. That file desyncs from the project the
moment work starts and never crosses to CI, so the cross-engine "Claude plans ->
Codex executes" handoff silently failed on the plan path.

Now the plan is posted as a `## Implementation Plan` comment on the work/PRD
issue, mirroring how writing-prds stores the PRD in the issue body. A comment
co-locates plan + PRD on one issue while keeping the PRD body clean (feature-intake
forbids plans in the body). The executor and both dispatch lanes already read the
issue body, linked PRD, and ALL comments, so the plan reaches CI for either engine
with no executor/workflow/label change — the handoff gap closes for free.

- writing-plans: "Saving the Plan" -> "Storing the Plan" (gh issue comment
  --body-file -); killed the docs/plans default; confirm-before-post; no-tracker
  fallback; >65k-char split note; label-driven Execution Handoff; version 1.0.0 -> 1.1.0
- writing-plans/README: recorded the storage divergence so future upstream syncs preserve it
- executing-plans: the `## Implementation Plan` comment is the authoritative plan
- AI-DEV-LOOP: both planning artifacts live on the issue (PRD=body, plan=comment)
- writing-prds: "plan the X PRD" flow points at the plan comment
- regenerated planning + session bundles
2026-06-16 12:52:29 +02:00
Vincent 218a3e50d6 feat(skills): add backend/frontend/security skills, restructure references, regenerate bundles (#15)
Source changes:
- Add github project/workflow skills and new skill set (backend: graphql-architect,
  nestjs-expert, turborepo, typescript-expert/refactor; frontend: react-*, shadcn,
  tailwind, audit/clarify/critique/layout/polish; security; session-end/start; x-algorithm-optimizer)
- Rename reference/ -> references/ in critique, mcp-builder, youtube-video-analyst
- Remove obsolete build scripts (generate-bundle, generate-manifest, generate-plugin, sync-marketplace)
- Refresh memory/system docs, READMEs, configs (biome, markdownlint, workflows)

Generated:
- Regenerate all 16 marketplace bundles (186 plugins: 16 bundles + 170 skills)

Validated: 170 skills pass skill-sync (Claude + Codex); lint clean (md/code/sh).
2026-06-08 13:27:19 +02:00
vincentonchain ef42a98c27 Refactor the library for skills.sh 2026-01-20 22:48:25 +01:00
vincentonchain e6b16a35a8 Merge branch 'master' of github.com:shipshitdev/library 2026-01-20 20:38:24 +01:00
vincentonchain bf04d50c8c chore: set timeout for generate-bundles workflow
- Added a timeout of 15 minutes to the generate-bundles job in the GitHub Actions workflow to prevent long-running processes.
2026-01-20 20:37:54 +01:00
blacksmith-sh[bot] 8ed047cd29 Migrate workflows to Blacksmith 2026-01-20 19:36:16 +00:00
vincentonchain 7d3a8d66be chore: add marketplace bundles and individual plugins to git
- Generate 14 category bundles (startup, testing, payments, etc.)
- Generate marketplace.json with 118 plugins:
  - 1 full bundle (shipshitdev-full)
  - 14 category bundles
  - 103 individual skills
- Add generate-marketplace-json.js script
- Update CI/CD to auto-regenerate on push

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-08 23:43:29 +01:00
vincentonchain 915bce3112 Update package.json and README.md for project rebranding and enhanced documentation
- Changed project name to "claude-plugin-shipshitdev" and updated versioning in package.json.
- Revised project description to highlight 100+ AI agent skills for indie developers.
- Added repository and bug tracking links in package.json.
- Enhanced README.md with installation instructions for various platforms and added npm version badge for visibility.
- Updated symlink paths in the manual installation section for clarity.

Total sessions today: 4
2026-01-08 23:17:45 +01:00