Skip to content

Watchdog v1.2.3

Choose a tag to compare

@JonyanDunh JonyanDunh released this 11 Apr 02:56
· 5 commits to main since this release
cc2d6d0

Slash command frontmatter cleanup. Non-behavioral — only the .md files under commands/ changed, plus the version bump. All three commands now use only documented Claude Code frontmatter fields, verified against https://code.claude.com/docs/en/skills.md#frontmatter-reference.

Chore

  • chore(commands) Modernize slash command frontmatter. Removed the undocumented hide-from-slash-command-tool field (inherited from upstream ralph-loop as a legacy convention — not listed in any official Claude Code frontmatter reference). Added the documented disable-model-invocation: true to all three commands as the canonical way to block agent programmatic invocation. Added explicit argument-hint to stop.md and help.md. Tightened start.md's argument hint to "<PROMPT>" [--max-iterations N] so autocomplete reminds the user to quote the prompt. (#12)

Threat model clarification

Watchdog is designed against confused or lazy agents, not adversarial escape artists. With just disable-model-invocation: true:

  • Agent cannot call /watchdog:stop programmatically even if it wanted to
  • Classifier subprocess lives in a separate claude process the agent has no handle on
  • Stop hook fires regardless of any agent output; agent cannot suppress or spoof it
  • Even if agent deletes .claude/watchdog.claudepid.*.local.json to break the loop, the rm command shows up in the session transcript and is visible to the user — a self-owning "win"

The removed undocumented field provided zero real protection. The documented fields give all the isolation the realistic threat model needs.

Scope

  • commands/start.md — frontmatter tidy
  • commands/stop.md — frontmatter tidy
  • commands/help.md — frontmatter tidy
  • .claude-plugin/plugin.json — version → 1.2.3
  • .claude-plugin/marketplace.json — version → 1.2.3

Zero changes to lib/, hooks/, scripts/, or test/. The 80-test suite (78 active + 2 skipped-inside-Claude-Code, 0 failures) still passes unchanged.

CI

All 11 jobs green on the standard matrix: ubuntu-latest × macos-latest × windows-latest × Node 18 / 20 / 22 plus jsonlint and markdownlint.

Install / upgrade

/plugin marketplace update claude-code-watchdog
/reload-plugins