Repository navigation
v1.8.0 — Rules-to-Skills + enforcement hardening
v1.8.0 — Rules-to-Skills conversion + enforcement hardening
This is a minor feature release. It is also the first GitHub Release published since v1.4.0, so it rolls up the previously tagged-but-unreleased work (v1.5.0–v1.7.1) into one current release.
Highlights
Phase 61 — CMM/ctx rules packaged as Claude Code Skills
cmm-rulesandctx-rulesare now Claude Code Skills (skills/{cmm,ctx}-rules/SKILL.md). VBW subagents opt in viaskills:frontmatter with progressive disclosure, so the navigation/retrieval protocols load on demand instead of bloating every subagent prompt.- Per-agent assignment:
dev,lead,scout,debugger,qaget both;docsgetsctx-rules;architectgetscmm-rules. setup.shinstalls.claude/skills/in both global and project scopes.- SubagentStart hooks shrunk to short pointers; PreToolUse block messages append a
See skill <name>reference.
Enforcement hardening (field-tested)
ctx-execute-enforcercloses the compound-shell exemption bypass:cd <dir> && <cmd>prefix peeling (quoted and unquoted paths) plus detection of&&,||,;,|,$(...), backticks, bare&, and embedded newlines — with a newline-aware, quote-scrubbing pass so legitimate multi-linegit commit -m "…"messages are not false-positive blocked.- Context-mode detection now scans the versioned plugin-cache directory and
enabledPlugins, in addition to the legacy.mcp.jsonprobe. - Install-scope detection no longer re-adds redundant
.mcp.jsonentries when the plugin form is already installed. - PostToolUse sentinel-writer matcher covers plugin-form tool names (
mcp__plugin_context-mode_context-mode__*).
Verification
- Enforcer suite (
tests/test-ctx-execute-enforcer.sh) 47/47. CHECKSUMS.sha256regenerated and verifies clean.- The Phase 61 PR (#62) went through 3 QA rounds; all findings resolved.
Full changelog: v1.7.0...v1.8.0