You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
sensitive-file-guard.py (PreToolUse hook) — blocks reads of .env, SSH keys, credentials, AWS configs, and package tokens. Intercepts both Read tool and Bash commands via shlex.split() tokenization. Case-insensitive basename matching with explicit allowlists (.env.example, .envrc). *.key requires keyword guard to avoid false positives. 83 tests.
Output Contracts for /code-review, /critical-review, /security-audit — each skill now defines the required structure of its final synthesized report (findings table, aggregate counts, verdict, remediation offer).
Rationalizations to Reject — 9 security dismissals injected into /security-audit subagent prompts ("It's behind a VPN", "Only admins can reach this", etc.) and 6 code quality dismissals into /code-review.
Red Flags — thought-pattern watchlists injected into /security-audit (5 items) and /code-review (5 items) targeting the agent's own corner-cutting impulses.
Implementer status protocol for /implement-batch — subagents report STATUS: DONE, DONE_WITH_CONCERNS, NEEDS_CONTEXT, or BLOCKED. Main session handles each status with defined escalation paths.
Contradiction detection for /implement-batch — scans subagent output for phrases like "requires manual", "should work", "TODO" alongside success claims. Catches the "claims done but admits failure" pattern.
Cascading-fix escalation for /implement-batch — 3-strike rule. If fixes keep breaking previously-passing modules, stop and flag as architectural issue.
Complexity gate for /implement-batch — flags tasks meeting 2-of-3 conditions (>5 files, >3 acceptance criteria, cross-module dependencies) before spawning subagents. Soft gate — user can override.
Decision logging for /critical-review — appends accept/reject/defer decisions to decision-log.md with rationale. Triggers on all user response paths.
Task Delivery States in CLAUDE.md — mental model for task progression (intake → planning → executing → validating → reviewing → done / blocked).
Subagent context isolation rule in CLAUDE.md — always paste full task text into subagent prompts, never make subagents read plan files.
Blast radius risk labeling for /code-review — findings include Risk: HIGH|MED|LOW based on structural heuristics. Secondary sort by risk within same severity.
Mock quality detection for /code-review — Agent 5 now flags mock-heavy tests (3:1 ratio), missing real module imports, behavioral-only assertions, and over-mocked integration tests.
BEFORE/AFTER remediation verification for /code-review and /security-audit — records failing state before fix, verifies passing state after. Uses function/symbol anchors for non-testable findings.
Changed
Skill descriptions — all 6 skills rewritten for CSO compliance (trigger conditions only, no workflow summaries). Prevents Claude from shortcutting skill bodies.
Skill frontmatter — all 6 skills now include risk: safe|critical field and optional risk-note.
Rules frontmatter — python.md, javascript.md, shell.md now include paths frontmatter for file-type-specific loading.
/implement-batch step 4 — split into 4 (triage: status + contradiction), 4b (consistency review), 4c (validation).
/implement-batch step 7 — phase gate: recommends new session for batch ≥ 3.
/critical-review — renumbered to 8 steps (decision logging is step 5; non-approval path explicitly logs rejections).
CLAUDE.md Code Quality — overloaded paragraph broken into sub-bullets.
CLAUDE.md Planning — batch numbering convention: always start at 1, never 0.
install.sh — now fully supports upgrades in addition to fresh installs:
install_settings() function: jq-based merge of hooks and statusLine from settings.json.reference into ~/.claude/settings.json. Backs up before modifying.
Already-installed symlinks detected and skipped without prompting (compares raw and resolved paths).
Stale symlink cleanup: broken symlinks pointing into the repo (from removed/renamed components) are detected and offered for removal.
Settings.json upgrade: repo-managed hook entries are stripped and re-added from the current reference on every run, handling renamed hooks, changed command formats, and removed hooks. User hooks are preserved.
Duplicate hook entries from older installer versions are deduplicated.
Repo-managed statusLine is updated to match the current reference; custom statusLine configurations are preserved.
CLAUDE.md, settings.json, and component prompts all skip when already current — a fully up-to-date install produces no prompts.
Extracted merge_settings_json() and install_settings_needed() helpers to eliminate logic duplication.
uninstall.sh — new uninstall_settings() function: removes hook entries pointing to /.claude/hooks/ and statusLine from ~/.claude/settings.json. Replaces old manual reminder.