2.12.0 — consolidated release: 20 domains, 380 skills, full issue-triage sweep
Released 2026-08-24
First tagged release since v2.9.0. Versions 2.10.0–2.11.2 were documented in
CLAUDE.md/README at the time but never entered here, so the Release workflow never
tagged them; this entry consolidates everything since the v2.9.0 tag — the
previously documented v2.10.x/v2.11.x work plus all post-2.11.2 merges. Headline
counters at this release: 380 skills · 96 marketplace plugins · 20 domains ·
706 Python tools · 823 reference docs · 114 agents · 138 slash commands
(derived and gated by scripts/derive_counters.py --check).
Added — consolidated from the untagged v2.10.0–v2.11.2 releases
- markdown-html/ domain complete (v2.10.0–v2.10.3): orchestrator +
design-system foundation, thenmd-document(long-form),md-review
(2-col code review),md-slides(single-file deck with presenter mode). - engineering/agent-harness (v2.11.0): manifest builder + goal compiler +
loop controller turning any domain into a bounded, self-verifying agent loop;
agentic-readiness audit of both engineering folders. - product-team + project-management as agent-harness domains (v2.11.1):
fork-orchestrators, deterministic goal routers, Jira snapshot bridge with
Monte Carlo forecasting, delegation-governance loop gate, discovery cadence
tracker + OST linter; audit recordaudit/pm-product-agentic-2026-07/. - engineering/skillopt-sleep (v2.11.2): vendored microsoft/SkillOpt nightly
self-improvement engine with 23 documented hardening deviations.
Added — post-v2.11.2 merges in this release
- agent-launcher/ — 20th top-level domain: Claude Managed Agent launcher
(full detail in its section below). - engineering/memory-engineering — design/price/audit agent memory systems
(cost profiler, architecture picker, density auditor, forgetting-policy linter). - engineering/agent-memory — four-tier (L0–L3) promotion-gated memory ladder
over Claude Code hooks; nothing reaches a CLAUDE.md without a human adopt. - engineering/human-gate, engineering/book-to-skill,
engineering/hivemind (PR #979), productivity/fable-goal,
productivity coverage expansion (weekly-review, deep-work, meetings +
public auditaudit/productivity-2026-07/),
marketing local-seo-manager, code-reviewer language expansion —
detailed sections below. - c-level-agents/ promoted to its own top-level domain directory (issue #949).
Fixed — full reported-issue triage sweep (PRs #972, #973, #982)
All 17 open issues driven to a final state; the 14 resolvable ones fixed and closed:
- #954 — 39
plugin.jsonmanifests carried non-specsource/attribution
keys that made Claude Code reject the whole manifest (40% of the marketplace
uninstallable). Keys relocated to.claude-plugin/authoring-notes.json
sidecars;check_plugin_json.pynow hard-fails any recurrence in CI. - #949 —
c-level-skillsnever loaded becausec-level-agentswas nested
inside its marketplace source; moved to a top-level directory. - #885 — plugin skills shadowing built-in commands (
status,review,
init,resume) renamed across four plugins (memory-status,
pw-init/pw-review,hub-init/hub-status,ar-status/ar-resume);
new blocking CI gatescripts/check_skill_names.py+ rule in
SKILL-AUTHORING-STANDARD.md. - #969 —
UnicodeEncodeErroron legacy Windows codepages: nine scripts now
reconfigure stdout/stderr to UTF-8;PYTHONUTF8=1documented. - #968 — Windows symlink-checkout caveat documented (INSTALLATION.md
"Windows Notes" + README pointer). - #933 — all dead links to the maintainer-local
megaprompts/tree
(~75 files incl. the docs site) replaced with annotated plain text. - #931 — DynamoDB on-demand pricing corrected to post-Nov-2024 rates.
- #924 — plugin hook commands quote
"${CLAUDE_PLUGIN_ROOT}"(space-safe). - #978 — playwright-pro's TestRail/BrowserStack MCP servers (which could
never start — dependencies never installed) are now a documented opt-in
instead of a permanentFailed to connectpair for every user. - #977 — two agents shipping without YAML frontmatter, repaired via the
G10 frontmatter gate work (PR #936). - Spam/out-of-scope issues #925, #960, #923, #951 closed with rationale;
proposals #910, #952, #962 triaged with approval/scoping replies;
superseded PRs #932/#966 closed with credit.
CI
- New blocking gates since v2.9.0: built-in-shadowing skill names (#885),
frontmatter YAML validation (G10), retired-model lint (G7), path linter G1
and script smoke G8 flipped blocking, plugin-manifest key rejection (#954),
marketplace description 1024-char cap (Copilot CLI, PR #964).
The sections below — formerly stacked as [Unreleased] — are part of this release.
agent-launcher: session-goal domain plugin for Claude Managed Agents (PR #961, merged 2026-08-21)
Added — agent-launcher/ (new top-level domain, 19th)
Plugin re-implementation of Anthropic's
launch-your-agent reference
skill (Apache-2.0; independent, not a fork) for building Claude Managed
Agents (CMA) in the user's own Anthropic account. Organizing idea: every
session starts with a goal (./my-agent/goal.json, surfaced by an opt-in
AGENT_LAUNCHER_SESSION=1 SessionStart hook and driven by /cs:goal);
loop_compiler.py compiles that goal into a bounded grade→iterate loop
(CMA user.define_outcome self-grading, max_iterations clamped 1..20 — never
unbounded), a recurring POSIX-cron scheduled-deployment loop ("run without
you", optionally self-grading each firing via a nested outcome), or a
single-pass interview→stage→launch workflow.
- 6 skills:
agent-launcher-orchestrator(context: forkgoal router with
exit-code route/ask/refuse) +interview(six intake slots → build sheet with
primitives table + v1/v2 deferrals + eval plan) +stage-launch(validated
env/agent/session/kickoff payloads + resumable BYOK curl launch script
that reads$ANTHROPIC_API_KEYat runtime and never embeds it) +
grade-iterate(outcome/rubric + verdict reader + held-back eval scaffold
capped at the 25-thread ceiling) +run-without-you(5-field POSIX cron +
IANA tz + wall-clock-DST validation, deployment payload with test-run curl,
NEXT-DIRECTIONS writer) +wrap-up(primitives inventory + regenerated
single-file overview HTML + ranked next upgrades). - 18 stdlib-only deterministic scaffolder tools (3 per skill; NO network/API
calls; all pass--help+--sample), 4 agents (orchestrator +
interviewer + grader + deployer), 8/cs:*commands (launch, goal,
interview, stage-launch, grade, run-without-you, wrap-up,
grill-agent-launcher), opt-in SessionStart/SessionEnd hooks (exit 0 on any
error — can never break a session), 5 shared references, 4 assets
(build-sheet JSON schema + overview/NEXT-DIRECTIONS templates + example). - Validators enforce CMA limits (≤20 skills/session, ≤8 memory stores, depth-1
multiagent ≤20 roster / ≤25 threads,max_iterations≤20, ≤20 creds/vault,
≤1,000 deployments/org);payload_validator.pyFAILs on any embedded API key. - Verification: independent 10-agent workflow re-checked every SPEC.md part
against disk — 9/9 PASS, zero differences from spec (delivery report kept in
maintainer-localdocumentation/, per the sprint-artifact convention; the
public build target isagent-launcher/SPEC.md). Full 4-phase pipeline
verified end-to-end; generatedlaunch.shpassesbash -n. - Counters (at merge): skills 362 → 368, domains 18 → 19, tools 644 → 664,
refs 741 → 746, agents 102 → 106, commands 116 → 124, plugins 88 → 89
(derived viascripts/derive_counters.py --check). - Distinct from
engineering/agent-harness(generic bounded loop over any repo
domain) andengineering/write-a-skill(authors Claude Code skills, not CMAs).
human-gate: batched human review as a verification artifact (this PR)
Audited — petergyang/human-review
Public audit record at audit/human-review-2026-08/AUDIT.md. Upstream (npm
human-review@0.6.0, MIT © Peter Yang) is a ~5,200 LOC Node application that opens
an HTML/Markdown file or localhost page in the browser for direct editing and
anchored comments, then ships the batch back to the agent as JSON. Verified: its
own test suite passes 90/90. Security posture is better than most local-server
tools — loopback-only bind, DNS-rebinding Host check, constant-time token compare,
realpath-checked traversal guard, a deliberately inert Markdown renderer, and a
45-minute idle self-shutdown.
Verdict: do not vendor, do adopt the pattern. Node 20 + an npm runtime dependency
fails the same stdlib-only test that kept the heavier skillopt package out in
v2.11.2. Seven findings recorded, three material: F1 (HIGH) the skill instructs
the agent to run unpinned npx -y human-review, so every invocation may fetch and
execute a newly published version; F2 (MED) "do not end your turn" plus re-poll
on timeout, with no headless guard and no retry cap — the AR5 loop-discipline gap
audit/engineering-agentic-2026-07/ already named as repo-wide; F3 (MED) only
/api/* is token-gated, not /artifact/<key> or /s/<id>.
Also worth stating plainly: despite the name, this is not a humanizer. It is
human approval, not human voice — no overlap with engineering/behuman or
marketing-skill/content-humanizer.
Added — engineering/human-gate
Conceptual derivation (no upstream code copied), built to this repo's conventions:
three stdlib-only Python scripts, no server, no socket, no network fetch.
review_page_builder.py— Markdown/HTML → single-file review page with every
block anchored (data-hg="b7"). Zero network requests — no CDN, no fonts, no
Prism; ~11 KB, opens overfile://. Markdown is rendered by a stdlib subset parser
that escapes before applying inline markup and scheme-allowlists every href;
HTML input is re-emitted throughhtml.parserwith<script>/<style>/<head>
dropped and top-level block elements tagged. Review UI is vanilla JS with
localStorage persistence and an export that writes the sidecar.feedback_parser.py— sidecar Markdown →batch.v1JSON. Severities
BLOCKER/MAJOR/MINOR/NIT (matchingmarkdown-html/md-review, from Google's
code-review guidance) plus EDIT/NOTE/APPROVE. Verifies every quote against the real
file and reports mismatches rather than swallowing them. Strips HTML comments so an
example written inside one cannot parse as a real sign-off.human_gate.py—open/status/collect/close/resetstate machine with
atomic writes and0700/0600state permissions. Gate rules G1–G7: refuses to
close with no collected round, an open BLOCKER/MAJOR, an unnamed reviewer, a sidecar
changed after collection, an exhausted round cap (exit 5 = escalate, never pass), a
waiver without a recorded reason, or a round carrying unresolved integrity problems.
Waivers store both the reason and every refusal they overrode.
Four more fixes came out of a second PR review round, each reproduced before fixing:
(a) the HTML artifact path re-emitted attributes verbatim, so a reviewed draft containing
<img src=x onerror=...>, <a href="javascript:..."> or an <iframe> executed inside the
review page — the Markdown path had _safe_href scheme-allowlisting all along and the HTML
path had nothing. sanitize_attrs() now drops on*/srcdoc/srcset, runs every URL
attribute through the same allowlist (control characters stripped first, so java\tscript:
cannot smuggle a scheme), and DROP_TAGS removes iframe/object/embed/base. Legitimate
https: links and relative images survive. (b) verify_quotes() compared a browser
selection (rendered text) against raw markup, so quoting a sentence containing **bold** or a
link failed — and since G7 made that blocking, it refused a legitimate close. It now matches
against raw or a rendered-text projection, while a genuinely fabricated quote is still
caught. (c) state["waiver"] was never cleared, so a clean unwaived round N+1 still
printed round N's waiver reason — in a tool whose premise is an honest record, that is its own
integrity bug. (d) status returned 4 for both "no sidecar yet" and "collected, blockers
open"; the blocked case now returns 2, matching close, so an agent can branch on the exit
code alone (0 clear · 2 blocked · 3 collect · 4 nothing yet).
A fifth round found two more. state_dir() anchored gate state to os.getcwd() while
keying it by the artifact's realpath, so an agent whose shell cwd drifted between turns
silently started from empty state — close from a subdirectory reported G1 "nobody has
looked at this" for a round that really was collected. It failed closed rather than falsely
passing, but it lost real feedback; state now follows the artifact, the same way the sidecar
and review page already do (--state-dir still wins). Separately, build_page() substituted
__CONTENT__ before __TITLE__/__CONFIG__, so reviewing a document that mentions those
tokens — this skill's own docs, for instance — re-substituted inside the inserted body and
injected the entire JSON config into the visible page. All three slots now fill in a single
re.sub pass, and the Markdown --sample fixture carries the token text so the case is
guarded. Minor: --waive with nothing to waive now says so instead of silently no-opping.
A fourth round found the gate itself was one flag away from opt-out. --waive applied to
whatever gate_refusals() returned — including G1, "no review round has been collected" —
so an agent could close having had no review at all by supplying any reason string. That is the
most tempting shortcut under time pressure and it defeats the skill's entire premise, so G1 is
now unwaivable: a waiver accepts objections a reviewer raised, it cannot manufacture a
review that never happened. Waiving a genuine objection still works. Same round: inline
style joined DROP_ATTRS (a background-image:url(https://…) beacons the reviewer's IP on
open with no script involved, breaking the stated no-network property — and the <style> tag
was already dropped, so keeping the attribute was inconsistent too); Markdown 
now renders a real scheme-checked <img> instead of leaking a stray ! before a link (which
also made _safe_href(image=True) dead code on that path); an unterminated <script> now
emits a diagnostic instead of silently truncating the body; and raw-HTML target="_blank"
anchors get the same rel="noreferrer noopener" the Markdown path already added.
A third review round found the HTML path was broken outright. meta, link and
base are void elements: html.parser fires handle_starttag for them but never a
matching handle_endtag. Because they were also in DROP_TAGS, each bare <meta charset>
incremented the skip counter permanently, so every real HTML5 document — anything with a
charset meta or a stylesheet link in <head> — swallowed its entire body and reported
"No reviewable blocks". The documented landing-page use case simply did not work; earlier
HTML fixtures happened to use <title>/<style> only, which is why three rounds missed it.
Void drop-tags no longer touch the counter. --sample now builds both a Markdown and a
full-DOCTYPE HTML fixture, asserts the expected block count for each, exits 2 on regression,
and writes to a temp dir so a sample run cannot litter the caller's cwd. Same round:
xlink:href joined the URL allowlist (SVG anchors still honour it, so
<svg><a xlink:href="javascript:..."> bypassed the plain href check), and status now
previews every gate rule through a shared gate_refusals() — previously it looked only
at blocking items, so a round with no named reviewer reported 0 while close refused on G3.
A sixth round caught the void-element fix having been only half-applied, and a forgery
route through the artifact itself. The round-three commit message claimed "meta, link and
base are void elements", but only meta and link reached VOID — so <base href="/">,
which sits in the <head> of a great many real pages, still swallowed the whole body and
returned "No reviewable blocks". VOID is now the complete HTML spec list rather than a
hand-picked subset, and SAMPLE_HTML carries a <base> tag so the regression gate would
catch a third recurrence. Separately: a reviewed HTML artifact carrying its own
data-hg="..." attribute kept it, and the builder appended a second — browsers honour the
first, and attribute values may contain raw newlines, so a crafted artifact could inject
a forged ## APPROVE heading into the exported sidecar. That is the same silent-false-approval
failure G7 exists to prevent, arriving through the artifact instead of the sidecar. Reserved
attributes (data-hg) and reserved element ids (the page's own doc, items, reviewer,
export, …) are now stripped from reviewed HTML before anchoring.
G7 came out of the first PR review round and closes a real hole: a mistyped severity heading
(## BLOKCER) silently downgrades to NIT, so before this a reviewer's genuine blocker
could be lost to a typo and close would still exit 0. Reproduced, then fixed — the
parser's integrity problems (unknown severity, EDIT with no replacement text, a quote
that is not in the target file) are now closer-blocking rather than advisory prose.
Problems that already have their own rule (G2, G3) are filtered so they are not
double-reported.
Loop discipline — the deliberate inversion of upstream. There is no blocking poll:
status returns immediately, open detects a headless host (CI, SSH, no DISPLAY)
and says so rather than sending the agent to wait at a browser that will never appear,
and rounds are capped with escalation on exhaustion. The sidecar is plain, hand-writable
Markdown, so the loop still closes over SSH and in CI where no browser exists.
Optional bridge, opt-in and asked-first: npx -y human-review@0.6.0 — always
pinned, never bare. It changes the editor; the gate still governs closure.
Ships 3 references citing 7–8 sources each (Bainbridge Ironies of Automation,
Parasuraman & Riley, Fagan inspection, Wiegers, Weinberg, SWE at Google ch. 9,
W3C Web Annotation TextQuoteSelector, Conventional Comments, Klein pre-mortem,
Nygard Release It!), a batch.v1 JSON schema, a worked sidecar example,
cs-human-gate agent, and /cs:human-gate. SKILL.md is a full PASS on the
write-a-skill 6-item checklist; description validator PASS.
Changed — counters
Merged on top of book-to-skill, which landed in dev while this branch was open:
skills 363 → 364, tools 663 → 666, refs 746 → 749, agents 103 → 104,
commands 118 → 119, plugins 89 → 90, engineering row 85 → 86
(derived via scripts/derive_counters.py --check).
book-to-skill: document → knowledge-base skill → plugin (this PR)
Added — engineering/book-to-skill
Derived from virgiliojr94/book-to-skill
(MIT). Compiles a book, documentation folder, or spec collection (PDF, EPUB, DOCX,
HTML, Markdown, RST, AsciiDoc, RTF, MOBI/AZW) into an agent skill: a resident master
SKILL.md (core frameworks + chapter index + topic index, capped at 4k tokens) plus
on-demand chapters/chNN-*.md, glossary.md, patterns.md, and a decision
cheatsheet.md. The agent reads the core, then one chapter — never the whole source
again.
The extraction library (scripts/book_to_skill/ — 12 modules including 7 per-format
parsers) is vendored close to verbatim and keeps upstream's format chains, chapter
detection across Latin/Roman/Chinese/Thai/Korean heading styles, invisible-Unicode
(Trojan Source) sanitization, and the DOCX entity-expansion guard.
25 numbered deviations are recorded in engineering/book-to-skill/README.md,
which is the authoritative list. Highlights:
-
(5) No implicit installs.
--install-missingdefaults toreport— it prints
the pip command and uses the stdlib fallback, where upstream prompts on a TTY and
runspip installinto the caller's environment. -
(6) Rights gate.
skill_plugin_emitter.py --distribution shareablerefuses
without--rightsfrompublic-domain|open-license|internal-docs|author-permission.
fair-useis deliberately excluded — a defence, not a licence. -
(10) Merged, extended validator. Upstream's two validators become one
four-family gate, adding budget (token caps) and index (dead chapter links,
unindexed chapter files, dangling topic refs) — the failure that silently breaks
navigation while the skill still looks complete, and which upstream did not check. -
(11) Folded YAML scalars now parse, so a wrapped description no longer
under-reports its length past the 1024-char cap. -
(12)
discovery_tax.py→token_budget_estimator.py: optionaltiktokenpath
dropped, post-flight budget audit added, and an explicit worth-converting
verdict that says "just read it" when the source is under ~3× the compiled skill. -
(15) Private, per-invocation working directory. Upstream's fixed
<tempdir>/book_skill_workis CWE-377/CWE-59 on a shared host — a local user can
pre-create it and plant a symlink namedfull_text.txt, andPath.write_textfollows
symlinks. Now a freshmkdtemp(0700, unpredictable) with 0600 artifacts; an explicit
--workdiris symlink-refused and mode-restricted. Also fixes a real bug:parsers/calibre.py
read a module-level path constant and so ignored--workdirentirely. -
(17) Zip-of-XML hardening generalized, plus decompression-bomb caps. Upstream's
DTD/entity guard covered DOCX only; EPUB'sebooklibpath handed the archive straight to a
third-party XML stack. The guard now lives inbook_to_skill/zip_safety.pyand runs for
both, and every archive read checks declared size and compression ratio before
decompressing — a 200 MB zip bomb is refused at ~14 MB peak RSS. -
(18) Packaging refuses a source tree containing symlinks.
shutil.copytreedefaults to
following links, which would bake a link target's real content into a package that may be
emitted as--distribution shareable._assert_no_symlinks()walks the whole tree and
refuses, before the validation branch so--skip-validationcannot bypass it. -
(19) The magic-byte sniff path goes through the size budget too. Unknown-extension
files read amimetypemember with a barezf.read()before any format was chosen —
ahead of every check inzip_safety.py. Now routed throughsafe_read(); a 200 MB
extensionless bomb is refused at ~15 MB peak RSS. -
(20) Emitter correctness and scope.
--author/--author-urlnow reach the printed
marketplace entry; a post-copy re-walk deletes the package if a symlink appears during the
copy (closing the check-then-act window); andsource.license_scoperecords that the
top-levellicensecovers the scaffolding, not the compiled notes. -
(21-24) Skill-quality audit — read as a skill rather than as code. SKILL.md's
quick-start referenced$WORKDIR/$SKILLS_HOMEwithout defining them (traceback if
followed literally; all five steps now execute verbatim);token_budget_estimator.py --skill-dir <typo>reported a clean audit at exit 0 and now refuses;epub.py's
except (KeyError, Exception)was silently disarming the zip-size refusal at that call
site; andtool | headno longer tracebacks. -
(25) Workdir race closed by fd pinning.
mkdir(exist_ok=True)does not raise on a
symlink-to-directory (its exists-branch follows symlinks), and a file inside a swapped
directory is not itself a link — so the artifact-level check could not back up the
directory-level one. The directory is now pinned withO_NOFOLLOW|O_DIRECTORYand both
artifacts written through that fd;_write_privatecreates withO_CREAT|O_EXCL|O_NOFOLLOW
at 0600. Verified against a live mid-write directory swap.
Repo-native addition with no upstream counterpart — Step 11 / /cs:book-to-plugin.
Upstream stops at a bare folder in ~/.claude/skills/, which this library cannot route
to. skill_plugin_emitter.py wraps a compiled skill as a full plugin package (manifest
cs-<slug>agent +/cs:<slug>command + README) and prints the marketplace entry.
It never editsmarketplace.jsonitself, refuses to wrap a skill carrying validation
errors, and guards its--forceoverwrite path against symlinks, paths outside the
destination root, and directories that are not plugin packages.
Ships 4 stdlib-only tools (all --help / --sample / --output json), 5 references
citing 7-8 sources each, 3 asset templates, a cs-book-to-skill agent, and
/cs:book-to-skill + /cs:book-to-plugin.
Changed — engineering/write-a-skill
Cross-linked to the new skill: "author first, compile second" — write-a-skill authors
from expertise in your head, book-to-skill compiles from a document on disk.
Changed — engineering harness manifest
Regenerated engineering/agent-harness/.../assets/harnesses/engineering.json. Picked up
book-to-skill plus three skills that had drifted out of the manifest (minimalist,
skillopt-sleep, strict-api): skill_count 81 → 85.
Changed — counters
skills 362 → 363, tools 644 → 663, refs 741 → 746, agents 102 → 103, commands
116 → 118, plugins 88 → 89 (derived via scripts/derive_counters.py --check).
fable-goal: ramble → autonomous /goal prompt (previous PR)
Added — productivity/fable-goal
Improved port of duncan-buildroom/freeskills fable-goal (informal "free to use
and modify" grant — quoted in the attribution block, not relicensed). Converts a
rambling description of a desired outcome into one polished, copy-paste /goal
prompt for a fresh autonomous session — the prompt is the deliverable, never the
build. Adds over upstream: wrong-tool check, observable-done principle, six-slot
extraction (deliverable/quantity/stakes/tools/quality/destination), per-medium
verification defaults, six-point pre-delivery self-check, anti-pattern list +
failure-mode catalog reference, second worked example in a non-web medium. Ships
goal_prompt_self_check.py (stdlib runner for the mechanically checkable
self-check subset; exit 0/1, --sample, --output json) and the
/cs:fable-goal command. Intentionally no agents//assets/ (single reasoning
pass; see plugin README design notes). SKILL.md is a full PASS on the
write-a-skill 6-item checklist.
Changed — counters trued up
skills 357 → 358 (this PR also trues up pre-existing engineering-row drift
355 → 357), tools 602 → 603, refs 731 → 732, commands 109 → 110, plugins
83 → 84; plus a stale "711 reference docs" claim in README line 30 fixed to 732.
housekeeping: CHANGELOG backfill + per-domain counter validation
Added — derive_counters.py per-domain table validation
scripts/derive_counters.py --check now also validates the README "Skills Overview"
per-domain table: each domain row's count must equal the SKILL.md count in its linked
folder, and every on-disk domain must have a row. Previously --check only validated
the headline aggregates, so per-domain rows drifted silently (e.g. the markdown-html
domain was missing from the table entirely, and several rows lagged new-skill merges).
This closes that gap — CI gate G3 now catches per-domain drift too.
Changed — README per-domain table trued up
Fixed six stale domain-row counts and added the missing markdown-html row so the
per-domain rows sum to the headline total (354).
Added — backfill: five skill additions that merged without their own changelog entries
Earlier contributor-PR hardening merges updated headline counters but not this log.
Backfilled, newest-first:
research/deep-research(PR #872, hardened from #851 by @Socialpranker) — rigor-first multi-source meta-research: 9-phase pipeline, triangulation (>=3 independent differently-typed sources per thesis), mandatory adversarial pass, per-source files with verbatim quotes, no fabricated citations. Full research/ plugin parity.engineering/zero-hallucination-coder(PR #870, hardened from #854 by @mehanshbarthwal-lab) — opt-in Discuss → Map → Decompose → Execute → Verify coding loop + lazy-senior YAGNI ladder; no invented APIs / assumed imports / placeholder code. Synthesizes Ralph, GSD Core, Graphify, Ponytail.ra-qm-team/skills/agent-decision-receipts(PR #868 + #869, hardened from #863 by @CWNApps) — tamper-evident, post-quantum-signed receipts for consequential agent actions (EU AI Act Art 12). Stdlib manifest builder; signing delegated to the Apache-2.0openagentontologypackage (opt-in install).engineering-team/skills/named-persona-adversarial-review(PR #867, superseding #866 by @YuhaoLin2005) — code review through named, sourced engineering philosophies with confidence-leveled attribution and an anti-fabrication rule for quotes.productivity/roast(PR #865) — 5-angle adversarial idea panel (Critic/Champion/Analyst/Investigator/Customer) → one GO/RESHAPE/KILL verdict, with a weighted veto-gated synthesizer + cheapest-48h-test designer.
local-seo-manager: local / Map-Pack SEO skill (this PR)
Added — marketing-skill/skills/local-seo-manager
Hardened port of external contribution #797 (@Steffonet). Fills a gap: the library
had national/technical SEO (seo-audit, programmatic-seo) but no local /
Google Map-Pack SEO skill for service-area businesses (appliance repair, HVAC,
plumbing, cleaning, electrical).
- 4-mode SKILL.md — GBP audit, service-area page generation, NAP consistency, LocalBusiness schema.
- 3 stdlib scripts —
nap_checker.py(NAP consistency scanner),service_area_generator.py
(neighborhood page-brief generator),schema_generator.py(LocalBusiness / HomeAndConstructionBusiness JSON-LD). - 3 references — 80-point local-SEO checklist, local schema types, review-response templates.
- Hardening applied before merge: fixed dangling cross-refs (
ai-seo→aeo, removed the
non-existentgbp-content-creatorcompanion), description now passesskill_description_validator,
and (per automated review)service_area_generatornow renders the previously-dropped
business_type/services/stateinputs,schema_generatorno longer emits an empty
geoblock, and the unusedimport syswas removed from all three scripts. - No
plugin.json/ marketplace entry needed — themarketing-skillsplugin globs./skills. - Counters: 352 → 353 skills, 590 → 593 Python tools, 718 → 721 references.
newgen audit follow-up: P0 fixes, path sweep, CI guards
Deprecated / Removed Skills (migration notes)
Three skills were retired or merged in the newgen-audit follow-up (PR #835). If
you installed or pinned any of these, migrate as follows:
| Removed skill | Why | Migrate to |
|---|---|---|
engineering/skills/command-guide |
Documented a different repository's commands and agents; instructed models to invoke agents that don't exist here | No replacement needed — the root commands/ folder and each plugin's own commands are the canonical command surface |
marketing-skill/skills/ai-seo |
Near-total overlap with the newer, tool-backed AEO skill | marketing-skill/skills/aeo — unique ai-seo content was preserved in aeo/references/bot_access_and_monitoring.md and aeo/references/extractable_content_patterns.md |
engineering/skills/release-manager |
489-line SemVer/Git-Flow textbook duplicating changelog-generator; its readiness checker crashed | engineering/skills/changelog-generator — now includes version_bumper.py, hotfix/rollback procedures, and the severity-SLA table. For release-readiness audits use engineering/skills/ship-gate |
Also restructured (no content change): engineering/universal-scraping-architect
moved its SKILL.md from plugin root to the standard skills/universal-scraping-architect/
layout. Marketplace source path is unchanged.
code-reviewer: C-specific smell detector + fixtures
Added — language-specific smell pack for C (this PR)
Closes Phase 2 / Tier 1 of the post-#769 audit: brings C onto the same footing as C# and Java for deterministic detection. Until now, code_quality_checker.py only had check_<name>_specific_smells for C# and Java; C / C++ / Rust / Ruby / PHP / Dart all fell through to generic checks.
check_c_specific_smells()inscripts/code_quality_checker.py(~110 lines). Detects:- Banned functions —
gets,strcpy,strcat,sprintf,vsprintf(all no-bounds; CWE-242 and CWE-120 family). - Format-string vulnerability —
printf(var)/syslog(var)with a bare identifier as the format argument (CWE-134). Skips literal-string first args. - Unbounded
scanf—%sspecifier without a width (CWE-120). Suppressed when a width is present (%31s, etc.). malloc/calloc/reallocwithout NULL check — result variable not checked within 5 lines (CWE-690 NULL pointer dereference). Recognisesif (p == NULL),if (NULL == p),if (!p),if (p != NULL).free()without zeroing — pointer not set toNULLon the next real line (CWE-416 use-after-free guardrail). Low severity since some style guides skip it.system()with non-literal argument — command-injection surface (CWE-78). Suppressed when the argument is a string literal orNULL.
- Banned functions —
- Wired into
analyze_file()after the C# and Java dispatchers. assets/sample_c_smells.c+assets/sample_c_clean.c— labelled fixtures; every smell is annotated inline with the CWE it maps to. Smells fixture has 10 C-specific detector hits (some rules fire more than once); clean fixture has 0 hits and scores 100/A.expected_outputs/sample_c_smells_quality.json+expected_outputs/sample_c_clean_quality.json— regression-detection harness following the C# / Java pattern.- Documentation refreshed:
README.mdadds C to the "Language-specific smell packs" line and the bundled-fixtures table;SKILL.mdanddocs/skills/engineering-team/code-reviewer.mdupdate the "Adding a New Language" guide and "Regression Fixtures" section to reference C# + Java + C.
Verification: all 6 fixtures (C# / Java / C × smells / clean) match their committed expected_outputs/*.json byte-for-byte. C smells fixture scores 4/100 (F); C clean fixture scores 100/100 (A).
Not yet (separate PRs): check_<name>_specific_smells for C++, Rust, Python, Kotlin, PHP, Ruby, Dart, Go, Swift, TypeScript, JavaScript (audit-ranked sequence). C++ and Rust are next — security delta is highest there (smart-pointer ownership, unsafe block discipline).
code-reviewer: 6 new languages + analyzer wiring + doc sync
Added — language coverage 7 → 13 (PR #769)
Six new language-rule files in engineering-team/skills/code-reviewer/languages/. Each follows the established 8-section contract (PR Analyzer Signals / Code Quality Checks / Security / Async / Resource Management / Exception Handling / Performance / Idioms). Contributor: @mitnick2012.
c.md— memory safety, banned functions (gets,strcpy,sprintfwithout bounds), pointer ownership, buffer-bounds discipline, undefined-behavior patterns.cpp.md— smart-pointer ownership transfer, RAII discipline,reinterpret_castaudit, missing virtual destructors, C++17/20 idioms.rust.md—unsafeblock justification,.unwrap()in production paths, Tokio runtime pitfalls,thiserrorvsanyhowseparation, clippy compliance.ruby.md— Rails-aware: N+1 withincludes,strong_parameters,YAML.safe_loadvsYAML.load,Marshal.load, Ruby 3.x idioms.php.md— SQL injection,unserialize,eval, file inclusion, CSRF, XSS, PHP 8.x idioms (match, enums,readonly).dart.md— Dart + Flutter unified: widgetdispose()lifecycle,BuildContextacross async gaps,constwidget optimization, state-management patterns.
SKILL.md dispatch table and --language valid-values comment updated accordingly. No existing language files were modified.
Fixed — deterministic analyzer wiring (PR #772)
Post-merge audit of PR #769 surfaced a gap: SKILL.md's dispatch table and the --language help text both advertised coverage for the 6 new languages, but scripts/code_quality_checker.py was never updated — files in those languages were silently skipped by the deterministic analyzer.
Three structures in code_quality_checker.py extended (+94 / -1, stdlib-only):
LANGUAGE_EXTENSIONS— 6 new dict entries matchingSKILL.mdexactly.cdeclared beforecppso plain.hresolves to C per the dispatch-table contract.find_functionspatterns — language-aware function regexes. C/C++ require a trailing{(filters prototypes and call sites) plus negative-lookahead on control-flow keywords. Rust uses the unambiguousfnkeyword. Ruby handlesdef,def self.x, predicate (?) / bang (!) suffixes, parenthesised-or-bare params. PHP requires thefunctionkeyword. Dart matches typed-return-then-name with optionalasync/async*/sync*markers.find_classespatterns + nestedmethod_patterns— type-def regexes:struct/typedef structfor C;class/structfor C++;struct/enum/trait/unionfor Rust;class/modulefor Ruby;class/interface/trait/enumfor PHP;class/mixin/enum/extensionwith all 5 Dart 3 class modifiers (abstract/sealed/final/base/interface).
Verification: python3 scripts/code_quality_checker.py --help now lists all 14 languages as --language choices. Smoke-tested with a minimal sample per new language; each correctly detects functions and classes. All 4 bundled regression fixtures (csharp/java × smells/clean) still match their committed expected_outputs/*.json byte-for-byte.
Not yet: language-specific check_<name>_specific_smells detectors for the 6 new languages (only C# and Java have these today). Audit ranked C / C++ / Rust as the next-highest-leverage additions.
Changed — documentation sync (this PR)
engineering-team/skills/code-reviewer/README.md— language list (line 3) and the "Review rules" guide-per-language reference (line 90) updated 7 → 13 languages.docs/skills/engineering-team/code-reviewer.md— MkDocs page synced: frontmatter description, file-tree, dispatch table (6 new rows), and--languagevalid-values comment.- Cross-platform sync indexes —
.gemini/skills-index.jsonand.vibe/skills/claude-skills/skills-index.jsonregenerated viascripts/sync-gemini-skills.py/scripts/sync-vibe-skills.py;.hermes/skills/claude-skills/skills-index.jsonhand-patched (full regen would have bundled 33 unrelated new-skill entries — left for a separate mirror-refresh PR)..codex/skills-index.jsonwas already current. All 3 updated mirrors now show the canonical 13-language description fromSKILL.mdfrontmatter.
Mistral Vibe cross-platform installation (closes #705)
Added
scripts/sync-vibe-skills.py— installs claude-code-skills into Mistral Vibe (Apache-2.0 CLI coding agent). Fork ofsync-hermes-skills.pywith target~/.vibe/skills/claude-skills/<domain>/<skill>/, namespaced to avoid collisions with Vibe built-ins. Same flags:--verbose,--domain,--dry-run,--copy,--json,--target.scripts/vibe-install.sh— bash one-liner wrapper for parity withgemini-install.shandcodex-install.sh. Surfaces Vibe-specific post-install usage tips (/skills,/<slug>)..vibe/skills/claude-skills/— pre-generated tree committed to the repo: 306 skill symlinks across 14 domains plus askills-index.jsonmanifest. Lets users inspect the install surface without running the script. Mirrors the existing.hermes/skills/claude-skills/precedent.INSTALLATION.md— new "Mistral Vibe Installation" section (setup, direct Python invocation, verify, uninstall, Python CLI tools), plus TOC entry and a row in the cross-tool compatibility table.README.md— Mistral Vibe added to the "Works with" line, footnote describing the BYO-sync tier (mirrors the Hermes footnote), row in the Multi-Tool Support table, and FAQ updated from 12 → 13 supported tools.docs/index.md,docs/getting-started.md,docs/integrations.md— Mistral Vibe install tab added to all three pages, full ~130-line integration section parallel to Hermes section inintegrations.md, description meta tags updated 12 → 13 AI coding tools..claude-plugin/marketplace.json,mkdocs.yml— platform compatibility taglines updated; all 13 tools named explicitly inmkdocs.yml.
Why
Mistral Vibe (released Jan 2026, v2.0) uses the Agent Skills spec — exactly the same SKILL.md + YAML frontmatter contract this repo already ships. Zero format conversion needed; the integration slots cleanly into the existing 5-target cross-platform sync pattern (.claude / .codex / .gemini / .hermes / .vibe). Issue #705 requested this from @saifjarboui.