v1.3.12
What's Changed in v1.3.12
docs: sync upstream baseline to 393d397 (#76) by @Jamkris
Summary
Final PR of the 2026-05-13 upstream sync round. Advances the recorded baseline from e9c88458 (2026-05-11) to 393d397 (2026-05-12) — the upstream HEAD at triage time and the last commit evaluated this round.
Round 3 PRs
- #74 — triage / audit log (
upstream/sync-rounds/2026-05-13.md) - #75 — port: code-reviewer guardrails + prompt defense baselines
Of 67 commits in the focused range: 2 ported, 8 deferred (net-new feature additions: PRD command, network architect agents, motion skills, Quarkus, Django Celery, cost tracking, frontend design, homelab configs), 57 skipped with rationale.
Files updated (4)
upstream/.upstream-sync.json—lastSyncedSha+lastSyncedAt+ round notes pointing at the new audit log.upstream/README.md— baseline badge, Last-synced commit, date, round-notes pointer (now references both 2026-05-13 and 2026-05-12).upstream/ko-KR/README.md+upstream/zh-CN/README.md— mirrored.
Expected post-merge behaviour
- The validator passes — the prose SHA and JSON SHA agree on
393d397. - Next scheduled or manually-dispatched
upstream-driftworkflow run will compute the delta against ECC's current HEAD. If ECC has moved past393d397(likely — they merge daily), issue #71 updates with the new (small) count. If no new ECC commits since393d397, #71 auto-closes.
Test plan
-
node scripts/ci/validate-upstream-sync.js— "OK — both files reference 393d397" -
npm run lintclean -
npm test279/279 - Manual link check — README baseline → ECC commit, audit log links → 2026-05-13.md + 2026-05-12.md
Round end
This PR closes round 3.
Related to #71.
port: code-reviewer guardrails + prompt defense baselines from ECC (#75) by @Jamkris
Summary
Two ports from the 2026-05-13 sync round:
agents/code-reviewer.md (df60af9)
Adds false-positive guardrails directly to the agent prompt:
- Pre-Report Gate — 4-question filter before writing any finding (cite line, name failure mode, read context, defensible severity).
- HIGH / CRITICAL require proof — exact snippet + scenario + why existing guards don't catch it. Demote or drop otherwise.
- "Zero findings is valid" — explicit license to APPROVE clean diffs instead of manufacturing nits.
- Common False Positives catalog — 12 patterns LLM reviewers consistently mis-flag (error handling already at framework level, magic numbers for well-known constants, missing JSDoc on self-describing helpers, security theater on
Math.random(), etc.). - Approval criteria updated — clean review is valid; don't withhold APPROVE to appear rigorous.
The intent is to reduce the kind of noise this very repo has been seeing in PR reviews — pattern-match nits with no concrete failure scenario.
GEMINI.md + 48 agent files (393d397)
Prepends a uniform Prompt Defense Baseline 6-bullet block:
- role / persona / identity protection
- confidential-data / secret protection
- executable-code output restraint
- unicode / homoglyph / encoded-trick suspicion
- external / untrusted data validation
- harmful-content prohibition
Block content is harness-agnostic; same text as upstream ECC. Inserted right after the closing frontmatter --- on every agent, and after the H1 + intro paragraph on GEMINI.md.
Applied via a one-shot script (idempotent — skips files already containing the block).
ECC commit in scope that did not port
cb2a70c(motion skill fix) — EGC hasremotion-video-creationbut notmotion-advanced/motion-foundations. The upstream motion skills are deferred net-new candidates for a future "ECC net-new" round.
Files changed (49)
| Group | Count | Source |
|---|---|---|
agents/code-reviewer.md |
1 (both ports) | df60af9 + 393d397 |
agents/*.md (other 47) |
47 | 393d397 |
GEMINI.md |
1 | 393d397 |
Total: +520 lines / -1 line.
Test plan
-
npm run lintclean -
npm test279/279 -
node scripts/ci/validate-agents.js— 48 agent files validated - Spot-checked 3 agents (architect, tdd-guide, code-reviewer) — block correctly inserted after frontmatter
- Spot-checked GEMINI.md — block inserted between intro paragraph and Guidelines section
Summary by cubic
Adds strict false-positive guardrails to the code-reviewer and applies a 6-point Prompt Defense Baseline to all agents and GEMINI.md to reduce review noise and strengthen prompt safety. This cuts low-signal findings and hardens prompts against injection and unsafe outputs.
-
New Features
- Code reviewer guardrails: 4-question pre-report gate; proof required for HIGH/CRITICAL; zero-findings APPROVE; skip common false positives; updated approval criteria.
- Prompt Defense Baseline: 6 rules (role/identity protection, secret protection, executable-output restraint, Unicode/encoding trick suspicion, untrusted-data validation, harmful-content ban) inserted across 48 agents and
GEMINI.md.
-
Migration
- No action needed. The baseline is auto-inserted after frontmatter; the script is idempotent and avoids duplicates.
Written for commit 92a84ba. Summary will update on new commits.
Summary by CodeRabbit
- Documentation
- Added comprehensive safety baselines to agent instructions, enforcing explicit constraints for identity preservation, data confidentiality, restricted output formats, and validation of untrusted inputs to ensure consistent secure behavior across all agents.
docs: triage ECC upstream commits e9c8845..393d397 (#74) by @Jamkris
Summary
Round 3 audit log. ECC moved 67 commits forward of the baseline recorded at the end of round 2 (#71 reported 65 when the drift tracker opened; ECC merged 2 more before triage).
Round 3 totals
| Category | Port now | Defer (net-new) | Skip |
|---|---|---|---|
| skills | 0 | — | 1 |
| docs | 0 | — | 30 |
| agents | 2 | — | 0 |
| commands | 0 | — | 0 |
| shared logic | 0 | — | 6 |
| CI / packaging | 0 | — | 2 |
| other-harness (net-new features) | 0 | 8 | 0 |
| meta | 0 | — | 1 |
| needs-review (edge cases) | 0 | — | 17 |
| Total | 2 | 8 | 57 |
Notable findings
df60af9(code-reviewer guardrails) — adds Pre-Report Gate, HIGH/CRITICAL proof rules, "zero findings is valid" guidance, and a Common False Positives catalog to ECC's code-reviewer agent. All harness-agnostic. Port target.393d397(prompt defense baselines) — adds a uniform 6-bullet prompt-defense block to ECC'sCLAUDE.mdand every agent file (71 files total upstream). Port target — apply to EGC'sGEMINI.mdand all agents.
Deferred (8 net-new features)
ECC added meaningful new surfaces this round that exceed a sync-round port scope: PRD planning command, network architect agents, motion system skills, Quarkus handling, Django Celery workflow, cost tracking + skill scout, frontend design guidance, homelab config skills. These join the deferred net-new candidates from round 2 (tinystruct-patterns, ios-icon-gen, flox-environments) — should be opened as a dedicated "ECC net-new" PR set in a future round.
Follow-up PRs
- `port: code-reviewer guardrails + prompt defense baselines from ECC`
- `docs: sync upstream baseline to 393d397` — closes #71
Test plan
- `npm run lint` clean
- `npm test` 279/279
- Doc-only change
Summary by cubic
Adds the 2026-05-13 upstream sync inventory documenting ECC drift (67 commits from e9c8845 to 393d397). It calls out two port targets (code-reviewer guardrails and prompt-defense baselines), defers eight net-new features, and marks 57 skips to guide follow-ups.
Written for commit 925b1c8. Summary will update on new commits.
Summary by CodeRabbit
- Documentation
- Added comprehensive documentation for the 2026-05-13 upstream sync round, including triage inventory results across multiple categories, summary statistics, and suggested follow-up actions.
docs: record ECC backport in 2026-05-12 sync round log (#73) by @Jamkris
Summary
Adds a "Backports to upstream ECC" section to upstream/sync-rounds/2026-05-12.md recording the two block-no-verify bypass holes that flowed back upstream as affaan-m/everything-claude-code#1843.
Why
Per the dual-PR pattern in CONTRIBUTING.md: when a contribution to EGC is harness-agnostic and would also benefit ECC users, cross-link the two PRs so reviewers on either side can see the upstream/downstream pair. This is the first sync round where work flowed from EGC back to ECC, so the audit log should record it.
Test plan
- `npm run lint` clean
- `npm test` 279/279
- Doc-only change; no source/script modifications
What ships in the upstream PR (cross-link)
- core.hooksPath case-sensitivity bypass — was case-sensitive; `git -c core.hookspath=…` slipped past the guard.
- -tn false positive — `COMMIT_SHORT_OPTIONS_WITH_VALUE` missing `'t'` falsely blocked legitimate `git commit -tn template`.
Both originally discovered in EGC PR #68 (commit fbf7908) by CodeRabbit's round-3 review.
Summary by cubic
Adds a “Backports to upstream ECC” section to upstream/sync-rounds/2026-05-12.md documenting two block-no-verify bypass fixes and cross-linking the upstream/downstream pair per the dual-PR pattern.
- Bug Fixes
core.hooksPathcase-insensitivity bypass:git -c core.hookspath=…was not caught.-tnfalse positive: missing't'in short options caused validgit commit -tn templateto be blocked.
Written for commit e67c5e1. Summary will update on new commits.
Summary by CodeRabbit
- Documentation
- Updated audit log to document security fixes addressing two bypass vulnerabilities.
- Added backport information detailing fixes shipped to upstream systems.
chore: release v1.3.11 (#72) by @Jamkris
Bump version to 1.3.11
Summary by cubic
Prepare v1.3.11 release by updating version fields in .gemini-plugin/plugin.json, gemini-extension.json, and package.json. No functional changes.
Written for commit 5b96bf7. Summary will update on new commits.