Skip to content

feat(conventions): absorb the context-engineering corpus and add the instruction exception register - #3588

Merged
kyle-sexton merged 16 commits into
mainfrom
claude/context-engineering-ai-agents-eylizg
Sep 2, 2026
Merged

feat(conventions): absorb the context-engineering corpus and add the instruction exception register#3588
kyle-sexton merged 16 commits into
mainfrom
claude/context-engineering-ai-agents-eylizg

Conversation

@claude

@claude claude Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

No related issue: this PR is the corpus absorption itself; the actionable follow-ups it produced were filed as their own issues (#3562-#3568, #3598) and are referenced below rather than closed here.

Summary

Absorbs the context-engineering corpus (the trq212 "New rules of context engineering for Claude 5
models" X article of 2026-07-24, the Anthropic "Effective context engineering for AI agents"
engineering post of 2025-09-29, and the nine first-party pages they link) into this repository:
five graduated knowledge documents, one new convention with its wiring, and three skill
corrections. The upstream facts it rests on were verified against current official surfaces, and
the answer set was validated by two independent fresh-context arms before sign-off.

Per topic-docs v3.0.0, the decision contract is contract tier: it was committed on this branch as
it locked and pruned before merge. It is pasted at the bottom of this body, and its durable
outcomes graduated through the knowledge-vault seam into docs/specs/.

Fix

Graduated knowledge, docs/specs/context-engineering-*.md, moved out of the contract slice by
history-preserving git mv:

  • corpus-knowledge.md, both primary sources by theme with byte-verified quotes, the
    figure-borne facts that exist in no text on either page (the approximately 9,100-character
    TodoWrite tool description, the six-layer context stack), the settled upstream facts, custody
    findings CF-1 to CF-7, and an appendix carrying the three system-prompt calibration prompts
    verbatim, transcribed from the figure image and re-verified by a second reader.
  • critical-apparatus.md, 142 of 318 swept assumption, omission and tension rows, the
    cross-source tensions (including the few-shot reversal between the two primaries), the
    unstated interface-versus-behavior thesis, and ten adoption guardrails.
  • linked-sources.md, the nine linked pages with citations, mechanisms and numbers, including
    the dynamic-workflows API surface and the multi-agent token economics that upstream publishes
    only inside figures.
  • vertical-decisions.md, verticals V2 to V7 resolved here rather than deferred, four of them to
    no change with the reason recorded, plus the one V1 answer (post-upgrade instruction re-testing)
    whose disposition had no other durable home once the contract was pruned.
  • deletion-evidence-attribution.md, the mechanism the consequential deletion tier needs, and
    why a per-rule bare experiment is not affordable.

New convention. docs/conventions/instruction-exception-register/ answers the "except in
highly important areas" carve-out that subtractive instruction guidance leaves undefined. It
adopts Gate 0's six consequence classes by reference rather than forking them, and adds the
operation Gate 0 does not govern: deletion. Non-exhaustive and tighten-only, so omission never
licenses a cut.

Wiring, in the same change, because an unconsumed register changes no behavior — every
consumer the register's table names now reads it:

  • audit-instructions criteria I1, I4 and I5 hold a protected candidate and propose compression
    instead of deletion. I1 carries the reason its own bar cannot see the problem: it asks whether
    removal would change behavior today, and a protected rail's removal changes behavior only on
    the occasion it was written for.
  • unhobble Phase 4 no longer ends at "everything the ledger did not defend stays deleted". A
    rule matching a protected class is restored whether or not the ledger logged against it, since a
    rail whose absence is unrecoverable will not usually announce itself inside one experiment
    window. The strip stays permitted — it is reversible and branch-local — and register holds are
    tallied separately so restoring one is not miscounted as a deletion the ledger defeated.
  • instruction-placement's routing rubric names the register as the deletion counterpart, so one
    concern keeps one adjudication chain and the class list keeps one owner.

Skill corrections. session-flow:orchestrate reconciles its 3-10x token-multiplier line
against the upstream ~15x measurement it conflicted with, and carries the 1-2k condensed-return
magnitude with its citation.

Upstream-drift near-miss. docs/conventions/upstream-drift/CHANGELOG.md gains a 1.6.3 entry
recording a silent-revision near-miss adjacent to its content-hashing deferral, with the trigger
explicitly not fired and the deferral text untouched.

Verification

  • scripts/affected-tests.sh --run: 30 selected suites on the final tree, all passed or skipped,
    zero failures.
  • Net PR diff contains no path under docs/topics/**, satisfying contract-slice-prune-gate.
  • scripts/check-changelog-parity.sh --check, --check-bump, --check-order and
    --check-preserved all pass against origin/main after the three plugin bumps.
  • Every relative markdown link in the changed files was resolved against the working tree; all 10
    files, zero broken.
  • Upstream facts verified against current official surfaces and cross-checked by a second
    fresh-context arm with five spot-fetches, all reproducing verbatim: the # memory hotkey was
    removed in changelog v2.0.70; /doctor's documented behavior per commands.md (v2.1.205 and
    v2.1.206) trims, dedupes and migrates CLAUDE.md guidance and finds unused skills by context
    cost, and no official surface describes skill-content "rightsizing"; the memory tool spans all
    Claude 4 and later models with no beta header while context editing remains beta, and Claude
    Code exposes neither natively. Recency anchor: Claude Code v2.1.252.
  • The 80% system-prompt reduction figure appears on no official documentation surface; it is
    recorded OPINION-tier with directional corroboration from changelog v2.1.154, citing both
    first-party carriers.
  • Corpus slices passed their standing byte-exactness gates through four correction rounds; the
    two verification arms per slice were same-vendor, and that degradation is recorded rather than
    hidden.
  • Answer set validated by two independent fresh-context arms with the recommendation rationale
    withheld: 14 of 14 confirmed, zero challenged, one premise correction absorbed.

Related

Contract-slice pointers (topic-docs v3, prune with pointer)

  • Pre-prune commit (the last one that still held the slice): 1f7a11a4. Under squash-merge this
    SHA form is best-effort; the graduation targets below are the load-bearing record.
  • Durable outcomes graduated to: docs/specs/context-engineering-corpus-knowledge.md,
    docs/specs/context-engineering-critical-apparatus.md,
    docs/specs/context-engineering-linked-sources.md,
    docs/specs/context-engineering-vertical-decisions.md,
    docs/specs/context-engineering-deletion-evidence-attribution.md, and the new convention at
    docs/conventions/instruction-exception-register/.
  • Actionable follow-ups graduated to the work-item tracker as the issues listed above.

Approved decision contract (pruned docs/topics/context-engineering-integration/PLAN.md)

Pasted verbatim per the prune-with-pointer lifecycle. GitHub's body sanitizer strips <details>
here, so it is inline rather than collapsed.

Context-engineering corpus integration — decision contract

Brief

Status: SIGNED OFF — the operator confirmed the full sheet (Q1-Q16, all recommended
dispositions as presented) on 2026-09-01 ("lets go with those"), satisfying the standing
directive of 2026-08-31 ("I will confirm final answers for ALL questions... I want final sign
off"). Q15 resolved: finish the prior plan (phases 8-11, with the corpus input note as a
mandatory Phase 10 input). Q16 resolved: topic-docs v3 wave first; Q11/Q12/C1-class work
executes against v3 shapes. Execution proceeds per the contract below.

Grounded as of commit 335081c6 (origin/main, fetched 2026-09-01). Evidence artifacts live in
the session's memory tier (.work/context-engineering-integration/ and
.work/context-eng-corpus/): two byte-verified docpage-digest slices (P1 = the trq212
"New rules of context engineering for Claude 5 models" X article; P2 = the Anthropic
"Effective context engineering for AI agents" engineering post, published 2025-09-29), nine
deep tier-2 page inventories, a fresh unbiased paragraph-grain sweep with four-lens critical
apparatus, bidirectional reconciliation against the prior plan and field-guide audit, a master
coverage ledger, verified EXPLORE/RESEARCH artifacts, blindspot cards B1-B10, brainstorm
candidates C1-C12, and a fresh-context devils-advocate report (1 CRITICAL / 4 HIGH). The
memory tier is never committed; this Brief is the durable record and inlines every
decision-bearing fact.

TLDR

Absorb the two-article context-engineering corpus (plus its nine linked pages) into this
marketplace's decision record, and integrate what earns its place: inputs to the in-flight
context-engineering-claude-5 plan, a small set of doc+wiring artifacts, two skill-vocabulary
extensions, and recorded settled facts — under OPINION-tier/provenance discipline, with
everything gated on the operator's final sign-off.

Goal

A signed-off answer set (Q1-Q14) that routes every corpus finding to a named, durable home —
or an explicit deferral — without duplicating the prior plan's territory, silently expanding
its locked Brief, or authoring against surfaces that have drifted.

Constraints

  • Final sign-off gate: the operator confirms ALL answers; "go with recommended" assembles the
    sheet, never skips the gate.
  • The prior plan docs/topics/context-engineering-claude-5/ owns the P1 instruction-audit
    lane; this effort never re-absorbs P1 or edits that plan's design docs unilaterally.
  • Memory-tier evidence is cited by content (inlined here) or by tracker item, never by bare
    .work path in anything meant to outlive the session.
  • Sequencing: the work-folder-hierarchy / topic-docs v3 clean-break wave (docs(topics): lock the work-folder-hierarchy Brief (topic-docs v3 contract) #3552, Brief locked
    2026-09-01) restructures the .work substrate; Q12/C1/B9-dependent work orders against it
    (operator sequencing question on the sheet).

Provisionally locked answers (rounds 1-2; refined by blindspot/devils-advocate; ALL pending sign-off)

  • Q1 (deletion evidence threshold): two-tier — editorial audit-instructions pass may
    delete trivial legacy guards; consequential rules need ledger evidence. Refinement (B5 +
    DA-MEDIUM): express the consequential tier in unhobble's existing two-rows-same-cause
    grammar, BUT that grammar currently defends re-adds after a full strip, not per-rule
    deletions — the deletion tier needs an attribution design (observation window, same-cause
    rule) before it becomes a skill edit.
  • Q2 (exception register): yes — a docs/conventions owner doc naming the "highly
    important areas" where hard constraints stay. Refinements (B2 + DA-MEDIUM): inert unless
    wired — same change names it in consuming skills' criteria text; register is
    NON-EXHAUSTIVE with a tighten-only clause; cross-referenced from
    instruction-placement's routing-rubric (Gate 0) so one concern keeps one adjudication
    chain; omission never licenses deletion.
  • Q3 (conflict coverage): superseded by evidence — audit-instructions I15 scopes
    conflicts to resident-surface pairs BY RECORDED DESIGN (its criteria file cites the
    article's user-request example as Source). The user-request-clash axis is a boundary
    REOPEN with a detectability answer, filed as an OPINION-tier detector candidate to the
    prior plan's catalog via tracker item (see Q8/C9), not a simple extension.
  • Q4 (/doctor): verification DONE by research — commands.md (v2.1.205/206): /doctor
    trims/dedupes/migrates CLAUDE.md guidance into skills and finds unused skills by context
    cost; no official surface says "rightsize" or skill-content simplification. The
    audit-native-overlap run is unnecessary (Q9); repo docs citing /doctor cite commands.md.
  • Q5 (80% claim posture): OPINION-tier WITH directional-corroboration annotation.
    Carriers (corrected 2026-09-01 by validator 2): the X article AND its claude.com/blog twin
    (the-new-rules-of-context-engineering-for-claude-5-generation-models) both carry the
    figure — under the repo's recorded precedent (audit-instructions criteria.md:153-158) a
    vendor blog corroborates rather than defines, so the tier stands; changelog v2.1.154
    ("lean system prompt is now the default") corroborates direction only. Magnitude and "no
    measurable loss" stay vendor-voice (verifier's world-truth ruling); scope qualifier ("on
    our coding evaluations") always carried. Never phrase the annotation as "no official
    surface carries it" — falsifiable in one fetch.
  • Q6 (model-upgrade re-test): documented trigger only; the shipped audit-pass re-run
    contract (lease/epoch, suppression, three-scope inventory) is the ritual vehicle. Cite
    shipped reference files, not design/rerun-contract.md (drifted; flagged to plan owner).
  • Q7 (prior-plan relationship): fresh unbiased pass FIRST (executed 2026-08-31:
    10 fresh sweeps, 4 reconciliation adjudications, coverage ledger); prior work is one
    reconciliation input. Residual decision → sign-off sheet: is the prior plan alive
    (resume / finish / absorb-and-close)? Routing without that answer is burial.

Open questions for the sign-off sheet (recommended dispositions; operator decides)

  • Q8: split the gap-cluster routing — only execution-changing inputs (I15 reopen,
    rerun-contract drift, CF-7 wording, P2-never-engaged) go to the prior plan via the C2
    note + phase-section references + tracker items; G-SEC (guardrail-deletion / memory-
    poisoning security) becomes its OWN work item now (security cost of burial); G-THESIS +
    G-PRECOND ride with the corpus critical apparatus (Q12); G-GOV is green-field with C10.
  • Q9: drop the audit-native-overlap /doctor run (evidence inlined at Q4); CF-7 filed as
    a wording fix, tier logic unaffected (venue characterization was litigated in docs: characterize context-engineering source as vendor-published #2036/docs: align row-245 sibling characterizations with vendor-published status #2057
    — the note engages that history, headline softened from "authority-inflating").
  • Q10: adopt the prior plan's OPINION-tier vocabulary corpus-wide + snapshot-dated
    citations. REVISED per devils-advocate: CF-1 does NOT fire upstream-drift's recorded
    content-hashing reopen trigger (no committed stale stamp caused a defect) — record CF-1 as
    adjacent near-miss evidence in a dated changelog entry per that convention's own v1.6.2
    precedent, and file the hash store as its own designed issue via tracker; do not edit the
    deferral text.
  • Q11: cite-only now; graduation + custody policy deferred to V7, sequenced after the
    topic-docs v3 wave.
  • Q12: critical-apparatus home rides the corpus slices pending V7 + v3 sequencing; the
    durable pointer is this Brief + tracker items.
  • Q13: apply the P2-slice zero-cost merges as corrections round 4 (bakery
    transcriptions, compaction caveat C105, sub-agent economics) with re-pin + re-verify —
    noting the slice is memory-tier until Q11/V7 graduation decides otherwise.
  • Q14: the dated input note lands under the prior plan's design/ per topic-docs, is
    referenced from PLAN.md AND from the phase sections it gates (Phase 8 criteria edits,
    Phase 10 reconcile) in the same commit, with tracker items for each actionable payload.

Validation record

Two independent fresh-context validators (rationale withheld, devils-advocate evidence
discipline, 2026-09-01) each audited all seven locked decisions: 14/14 CONFIRMED, 0
CHALLENGED, 0 RECLASSIFIED. Standing findings carried to execution: (1) D3's tracker item
must be written to survive an absorb-and-close outcome on Q15; (2) D1's consequential tier
is deliberately unclearable until its attribution design exists — the ordering is enforced,
not incidental; (3) Q5's annotation cites both first-party carriers (above); (4) D2's
same-change wiring into shipped skills respects the repo/product "two hats" boundary
unhobble records.

Captured assumptions

  • Same operator owns this effort, the prior plan, and the topic-docs v3 wave; sequencing is
    theirs alone (sheet question).
  • Claude Code surfaces verified 2026-08-31/09-01 (v2.1.252 changelog recency gate); any
    execution re-verifies against then-current surfaces per the repo's upstream-drift
    discipline.
  • The # memory hotkey is REMOVED (changelog v2.0.70) — settled fact, recorded; the memory
    tool and context editing are platform-side (memory tool: all Claude 4+ models, no beta
    header; context editing: beta) and Claude Code exposes neither natively (analogues:
    auto-memory, compaction).

Out of scope

  • Re-absorbing P1 into a second plan; editing the prior plan's design docs beyond the Q14
    note; implementing C6-C12 before sign-off; graduating corpus slices before V7/v3
    sequencing; referenced-external sources (Karpathy, context-rot study, arXiv, Willison)
    beyond cataloging.

Acceptance criteria

  • The sign-off sheet presents ALL of Q1-Q14 in their refined forms with the operator's
    explicit confirmation recorded per answer; no answer executes unconfirmed.
  • Every accepted routing has a durable receipt (commit, tracker item, or phase-section
    reference) — nothing disposed by memory-tier note alone.
  • Post-sign-off execution follows the per-unit loop: one artifact at a time — apply, verify
    (the repo's own gates), close.

Deferred questions

All USER-RESERVED items were resolved by the operator's sign-off (2026-09-01, full sheet);
none remain deferred. Resolutions and receipts:

Execution receipts

Tracker items: #3562 (C6 exception register), #3563 (C7 deletion-evidence attribution
design), #3564 (C8 orchestrate reconciliation + annotation), #3565 (C9 I15 boundary reopen,
written to survive any prior-plan outcome), #3566 (G-SEC security caveats), #3567 (hash
store designed-issue placeholder), #3568 (G-GOV ownership decision). Commits: 6b7cd13
(contract), 48d851e (validator findings), 0c8bc33 (C2/C3/C5 batch), plus this one.
Operational note: the work-item-tracker seam's create-item requires gh >= 2.94 and this
cloud environment ships 2.45 (seam exit 3), so receipts were filed through the bound GitHub
adapter's provider-mechanic path (repo-scoped REST) — coordination verbs (claim/lease) were
not needed for solo-session creates.

Plan

(Empty — /planning:plan fills this after sign-off.)


Post-sign-off amendments

Two decisions above were overtaken by events after sign-off, and the amendment is recorded here
rather than by editing the signed text:

  • Q14 named the prior plan's design/ as the input note's home. That slice was pruned from
    main by the topic-docs v3.0.0 adoption (feat(conventions): topic-docs v3.0.0 — recursive slices with per-slice INDEX.md #3557) while this work was in flight, so the note has
    no home. Its four payloads survive elsewhere: the I15 reopen as claude-config: adjudicate the user-request-conflict axis as an I15 boundary reopen #3565, the P2-never-engaged
    finding in context-engineering-critical-apparatus.md, CF-7 in
    context-engineering-corpus-knowledge.md (recorded for the pattern, since the document it
    corrected no longer exists), and the rerun-contract drift moot for the same reason.
  • Q11/Q12 deferred graduation and the critical-apparatus home to V7 "after the v3 wave". V7
    resolved to graduate now rather than defer, because the memory tier does not survive a session;
    see docs/specs/context-engineering-vertical-decisions.md.

🤖 Generated with Claude Code

https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ

…pending sign-off)

Durable Brief for the two-article context-engineering corpus integration:
provisionally locked answers Q1-Q7 in their refined forms, open register
Q8-Q16 with recommended dispositions, captured assumptions (hotkey removal,
platform-side memory tooling, upstream recency), and the final-sign-off gate
as a standing constraint. Grounded as of origin/main 335081c; evidence
inlined from the session's verified memory-tier artifacts per the
devils-advocate persistence finding.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
Q5's carrier premise corrected (the X article's claude.com/blog twin carries
the 80% figure; OPINION-tier stands under the vendor-blog-corroborates
precedent) and the two-validator 14/14 CONFIRMED record added with its four
standing execution findings.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
…, C5)

Sign-off recorded in the integration contract (Q1-Q16 confirmed; Q15=finish
the prior plan, Q16=topic-docs v3 first). The dated corpus input note lands
under the prior plan's design/ and is referenced from its header list, its
Phase 8 criteria branch, and its Phase 10 reconcile step (payloads: P2 never
engaged; I15 boundary-reopen candidate; rerun-contract drift; corroboration
venue wording; G-SEC caveat; settled upstream facts). The 80%-claim
annotation cites both first-party carriers inside the note. upstream-drift
CHANGELOG gains a 1.6.3 near-miss record adjacent to the content-hashing
deferral (trigger explicitly NOT fired; hash store stays a designed-issue
candidate).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
…he integration contract

Q8-Q16 resolutions replace the deferred register (all confirmed by the
operator's full-sheet sign-off); execution receipts section added: tracker
items #3562-#3568, the C2/C3/C5 commit, the round-4 slice corrections, and
the gh-version seam degradation note for the receipt filings.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
…e deletion holds

C6, C7, C8 of the signed-off context-engineering integration.

The register answers the "except in highly important areas" carve-out that
subtractive instruction guidance leaves undefined. It adopts Gate 0's six
consequence classes by reference rather than forking them, and adds the
operation Gate 0 does not govern: deletion. Non-exhaustive and tighten-only,
so omission never licenses a cut.

Wiring, same change: audit-instructions I4 and I5 hold a protected candidate
and propose compression instead of deletion; the routing rubric names the
register as the deletion counterpart so one concern keeps one adjudication
chain.

orchestrate reconciles its 3-10x token-multiplier line against the upstream
~15x measurement and carries the 1-2k condensed-return magnitude with its
citation. The deletion-evidence attribution design records the mechanism the
consequential deletion tier needs, and why per-rule bare experiments are not
it. Vertical decisions V2-V7 are resolved in-repo rather than deferred to
sessions that would inherit no evidence.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
…ry tier

The corpus evidence lived under .work/, which is gitignored, so every
conclusion this integration rests on would have been lost with the
container. Four documents carry the substance into the branch:

corpus-knowledge.md, the two primary sources by theme with byte-verified
quotes, the figure-borne facts that exist in no text (the 9,100-character
TodoWrite before-size, the six-layer context stack), the settled upstream
facts with citations, custody findings CF-1 to CF-7, and an appendix
carrying the three calibration prompts verbatim, transcribed from the
figure and re-verified by a second reader.

critical-apparatus.md, 142 of 318 swept assumption, omission and tension
rows, the cross-source tensions including the few-shot reversal, the
unstated interface-versus-behavior thesis, and ten adoption guardrails.

linked-sources.md, the nine linked first-party pages with citations,
mechanisms and numbers, including the workflow API surface and the
token-multiplier economics that exist only in figures.

vertical-decisions.md resolves V2 to V7 in-repo rather than deferring them
to sessions that would inherit the questions without the evidence. Four
resolve to no change with the reason recorded.

Validated with scripts/affected-tests.sh --run: 36 suites, all passing.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
…m first-hand evidence

Two sweeps disagreed over whether the context-management announcement
embeds a diagram. Settled by inspecting the retained HTML and the image
itself: the page carries one before-and-after context-editing figure. The
earlier negative result came from searching a byline-to-related-posts slice
that excludes the figure's position, so it was evidence about the slice
rather than about the page.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
Accepts the topic-docs v3.0.0 adoption (#3557), which prunes contract
slices from main, including docs/topics/context-engineering-claude-5/ and
the corpus input note this branch had placed inside it. That note's
actionable payloads already carry tracker receipts (#3565 the I15 boundary
reopen, #3566 the unhobbling security caveats), and its settled upstream
facts live in this branch's graduated knowledge docs, so the prune loses
no content. The remaining payloads (the sibling plan's rerun-contract
drift and its corroboration venue wording) are moot: main deleted both
documents.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
…ledge-vault seam

topic-docs v3.0.0 landed mid-effort and made docs/topics/ a contract tier that is
pruned before merge. The five knowledge documents this integration produced are
durable outcomes, not contract, so they move to docs/specs/ by history-preserving
git mv, which is the seam's default backend and the form the prune gate passes.

Sibling cross-references are repointed, and the two convention docs that cited the
decision contract by path now cite the graduated evidence instead, since the contract
itself does not survive the merge.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
topic-docs v3.0.0 makes docs/topics/ contract tier: committed on the task branch
only, pruned before merge, with the pull request body carrying the approved contract
in a details block. Durable outcomes graduated in the preceding commit; the
actionable follow-ups graduated as tracker items #3562 through #3568 and #3598.

Pre-prune commit (the last one that still held the slice): 1f7a11a.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
@claude

claude Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Claude finished @kyle-sexton's task in 1m 32s —— View job


Security review — PR #3588

  • Gather context (PR diff vs origin/main, changed files)
  • Analyze changed files for security issues
  • Post findings

Scope. All 10 changed files are documentation/markdown: a decision contract and four
knowledge/spec docs under docs/specs/, a new convention (docs/conventions/instruction-exception-register/),
a CHANGELOG.md entry, and three skill/rubric edits (audit-instructions/reference/criteria.md,
instruction-placement/context/routing-rubric.md, session-flow/skills/orchestrate/SKILL.md).
No executable code, scripts, CI workflow files, dependency manifests, or config changes are in
the diff.

Checks performed:

  • Secret/credential patterns (API keys, tokens, passwords, private-key headers) — none found.
  • Command-injection / shell-exec constructs (curl | sh, eval(, exec() — none found; matches
    were prose uses of "token" (context-window tokens) and citation text, not code.
  • Safety-bypass instructions (--no-verify, --dangerously-skip-permissions, "disable hook",
    "skip verification", rm -rf, sudo) — none found; the one --no-verify hit is upstream
    quoted text describing an anti-shortcut clause, not an instruction added here.
  • External links introduced in the diff (arxiv, huggingface, x.com, research.trychroma.com,
    simonwillison.net, twitch.tv, platform.claude.com, claude.com) are all citation references
    inside analysis prose, not fetched/executed by any tooling in this repo.
  • The verbatim-transcribed "system-prompt calibration prompts" appendix
    (docs/specs/context-engineering-corpus-knowledge.md appendix A) is inert illustrative text
    quoted from an upstream figure inside a fenced code block, clearly framed as an example — not a
    live instruction surface an agent would execute.
  • The new instruction-exception-register convention and its wiring into audit-instructions
    criteria I4/I5 and the instruction-placement routing rubric strengthen guardrails (they make
    secret-handling, irreversible-action, etc. non-deletable by a trimming pass) rather than
    weaken them.

Result: No security findings. This is a docs/conventions-only change with no code, secrets,
or trust-boundary impact.

@claude

claude Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Claude finished @kyle-sexton's task in 4m 10s —— View job


Claude finished the code review

Tasks

  • Gather context (PR diff, changed files, custom instructions)
  • Invoke /review:code-review procedure
  • Read changed files and diff
  • Post findings as inline comments
  • Post final summary

Summary

Ran the CI code-review lane (/review:code-review) against origin/main...HEAD (835e037). This PR is doc-only (no code paths, no tests to run), so the review focused on internal correctness: link integrity and consistency between newly-stated claims and the mechanisms they describe. Posted 3 high-signal findings inline:

  1. docs/specs/context-engineering-vertical-decisions.md:24 — 5 broken relative links (lines 24, 41, 64, 86, 128) missing the context-engineering- filename prefix that every sibling file in docs/specs/ actually carries.
  2. docs/specs/context-engineering-deletion-evidence-attribution.md:73 — relative link goes up 3 directory levels (../../../) from docs/specs/, which resolves outside the repo root; needs ../ (one level).
  3. docs/conventions/instruction-exception-register/README.md:56 — the consumer table claims claude-config:unhobble never leaves a protected rule deleted, but unhobble/SKILL.md has no wiring for this register (Phase 4: "Everything the ledger did not defend stays deleted"), contradicting the doc's own stated failure mode ("a register nothing consumes changes no behavior").

Everything else — the wiring into audit-instructions criteria I4/I5 and the instruction-placement routing rubric, the session-flow:orchestrate figure reconciliation, the upstream-drift CHANGELOG entry, and all other internal links checked — resolves correctly and reads consistently. Did not independently re-verify the external Anthropic-article figures cited (that's the PR's own claimed verification, out of scope for this correctness/maintainability lane).

Not run: no test/lint suite applies to a docs-only change set; scripts/affected-tests.sh --run is the author-claimed verification (36 suites, unverified by me).

@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown

Last security-reviewed head: db8573adf28acaf3ceff9264b4702f3720919169. On the next push, the relevance gate compares only the commits since this SHA; delete this comment to force a full re-review.

…ory deep

The git mv out of the contract slice changed both the filenames and the depth,
so five sibling links in the decisions record and one register link in the
attribution design pointed at paths that no longer resolve. The V7 entry also
described its own home as "this directory", which stopped being true when the
documents joined the shared specs directory.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
Comment thread docs/specs/context-engineering-vertical-decisions.md Outdated
Comment thread docs/specs/context-engineering-deletion-evidence-attribution.md Outdated
Comment thread docs/conventions/instruction-exception-register/README.md Outdated
@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown

Claude has reviewed this PR 5 times. The lane skips further automatic reviews after 5; deleting this comment resets the count.

@claude

claude Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Claude finished @kyle-sexton's task in 2m 49s —— View job


Code review — PR #3588

  • Gather context (PR diff vs origin/main, changed files, repo conventions)
  • Check skip gate (draft/closed/trivial/already-reviewed) — none apply, full review run
  • Review changed files for correctness & maintainability (docs/conventions-only change)
  • Verify the two already-flagged broken-link findings from the prior review pass
  • Post findings

Scope. All 10 changed files are documentation: 5 new docs/specs/context-engineering-*.md
knowledge docs, a new docs/conventions/instruction-exception-register/README.md, a
CHANGELOG.md entry, and edits to two skills' criteria/rubric text plus session-flow:orchestrate.
This is the code-review lane; a separate run already covered security and found nothing (see the
earlier comment on this thread), so this pass stayed on correctness/maintainability per
REVIEW.md's lane split.

Prior review's two broken-link findings: confirmed fixed. Commit b85fb12 ("repair the
relative links the graduation left one directory deep") corrects both:

  • docs/specs/context-engineering-vertical-decisions.md — all 5 links to sibling spec docs now
    carry the context-engineering- prefix and resolve correctly.
  • docs/specs/context-engineering-deletion-evidence-attribution.md:73 — now ../conventions/...
    (one level up), which correctly resolves to docs/conventions/instruction-exception-register/README.md.

I also swept every relative markdown link across the other changed files
(instruction-exception-register/README.md, the CHANGELOG.md entry, and the three skill/rubric
edits) and confirmed they all resolve to real files.

One finding posted inline: docs/conventions/instruction-exception-register/README.md's
"Who consumes this" table claims claude-config:audit-instructions criteria I1, I4, and I5 all
hold back protected candidates and report the hold — but the actual wiring in this PR only touches
I4 and I5 (plugins/claude-config/skills/audit-instructions/reference/criteria.md); I1 carries no
reference to the register. The PR's own description confirms only "I4 and I5" were wired, so this
looks like a documentation/wiring mismatch introduced within this PR rather than a pre-existing
gap — flagged with a suggested fix (either drop I1 from the table or add a cross-reference in I1
pointing at I5's hold clause).

No other correctness or maintainability issues found. The rest of the new content (the corpus
knowledge/critical-apparatus/linked-sources docs, the deletion-evidence-attribution design, the
upstream-drift changelog entry, and the orchestrate/routing-rubric edits) is internally
consistent with no other broken links or structural issues found in this pass.

Comment thread docs/conventions/instruction-exception-register/README.md
…-flow for the corpus wiring

changelog-parity-gate caught three shipped plugins modified against a published
version: the audit-instructions hold clauses, the Gate 0 deletion cross-reference,
and the orchestrate reconciliation all edited files under plugins/ without a bump
or a release entry. Each gets a patch bump and an entry describing what changed
and why, and the orchestrate paragraph is rewrapped where the inserted citation
left a run-on line.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
@claude

claude Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Claude finished @kyle-sexton's task in 1m 1s —— View job


Security review — PR #3588

  • Gather context (PR diff vs origin/main, changed files, HEAD SHA 1d25ba1)
  • Invoke /review:security-review and follow its procedure exactly
  • Post findings

Skip gate: applies. This head (1d25ba1eb3f88e7027066b981729a91f459373aa) already has a
successful security review that still applies (posted against 835e037 earlier on this thread,
which found no findings). Per the skill's skip gate ("this head already has a successful security
review that still applies"), I diffed 835e037...1d25ba1 to confirm the delta introduces no new
security-relevant surface before relying on that prior result:

  • docs/specs/context-engineering-deletion-evidence-attribution.md,
    docs/specs/context-engineering-vertical-decisions.md — relative-link path fixes only (../../../../, missing filename prefixes), matching the link-integrity findings already flagged by the code-review lane. No content or instruction-surface change.
  • plugins/session-flow/skills/orchestrate/SKILL.md — reflow/rewording of the token-multiplier and compressed-return figures with citations; no new instruction, permission, or trust-boundary change.
  • plugins/*/.claude-plugin/plugin.json — version-number bumps only.
  • plugins/*/CHANGELOG.md — new entries documenting the above; prose only.

None of these touch code, CI workflows, permissions, secrets handling, or trust boundaries. Per
the skill's criteria (plugins/review/skills/security-review/SKILL.md), this is a docs/conventions-only
PR with no security-relevant surface: no executable code, no GitHub Actions workflow changes, no
dependency/permission changes, no injection or trust-boundary surface anywhere in the full PR diff
(origin/main...HEAD, 16 files).

Result: no security findings. Stopping per the skip gate — nothing further to post.

@claude

claude Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Claude finished @kyle-sexton's task in 1m 14s —— View job


Code review — PR #3588

  • Gather context (PR diff vs origin/main, changed files, custom instructions)
  • Invoke /review:code-review procedure
  • Read changed files and diff
  • Check skip gate
  • Post final summary

Skip gate applies. The only change since the last successful review from this lane
(835e037/b85fb12, which already confirmed the two broken-link fixes and flagged one
outstanding finding) is commit 1d25ba1 — three plugin.json version bumps, three
CHANGELOG.md entries, and a whitespace-only reflow of an existing paragraph in
plugins/session-flow/skills/orchestrate/SKILL.md (no wording change, confirmed via
git diff b85fb12 1d25ba1 -- plugins/session-flow/skills/orchestrate/SKILL.md). That's trivial/automated
with no meaningful review surface, so per the skill's skip gate I'm stopping early rather than
re-running a full pass.

Still open from the prior review pass (unaddressed by this commit, not re-flagged as a new
finding since it already stands on the thread above):

  • docs/conventions/instruction-exception-register/README.md:55
    the consumer table still lists audit-instructions criteria I1, I4, I5 as all holding back
    protected candidates, but the wired criteria file
    (plugins/claude-config/skills/audit-instructions/reference/criteria.md) only carries the
    "hold instead of delete" clause under I4 and I5; I1 has no reference to the register.
  • docs/conventions/instruction-exception-register/README.md:56
    the claude-config:unhobble consumer row still asserts a guarantee that skill's SKILL.md
    doesn't implement (no register/Gate-0 reference; Phase 4 deletes everything the ledger didn't
    defend).

Both were posted as inline review comments on an earlier pass on this thread and remain
actionable; no new findings from this commit.

…tract was carrying alone

Every other V1 answer graduated somewhere durable, but the re-test disposition
lived only in the decision contract, which the topic-docs v3 prune removes from
the tree. It resolves to "no new mechanism": audit-pass already ships the re-run
contract, and what the corpus adds is the occasion to invoke it plus the caution
that a post-upgrade re-run should expect removals rather than the drift most
audits look for. Restated at the end of the decisions record so the pull request
body is not its only home.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
@claude

claude Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Claude finished @kyle-sexton's task in 2m 24s —— View job


Code review — PR #3588 (re-run at 9970e0c)

  • Gather context (PR diff vs origin/main, changed files, HEAD SHA 9970e0c)
  • Invoke /review:code-review procedure
  • Identify what's new since the last code-review pass on this thread (posted against 835e037) and review that delta
  • Verify factual/correctness claims in the new content against the code they describe
  • Post findings

Scope of this pass

The prior code-review comment on this thread covered 835e037 and found the two issues still
listed below. Two commits landed since then (1d25ba1 chore version bumps, 9970e0c new V1-residue
section). This pass reviewed that delta (git diff 835e037..HEAD):

  • docs/specs/context-engineering-vertical-decisions.md — the already-flagged relative-link fixes
    (confirmed still correct) plus a genuinely new section, "V1 residue: re-testing instructions
    after a model upgrade"
    (lines 141–166).
  • docs/specs/context-engineering-deletion-evidence-attribution.md:73 — already-flagged link-depth
    fix, confirmed correct (../conventions/...).
  • plugins/session-flow/skills/orchestrate/SKILL.md — pure line-rewrap of already-reviewed prose,
    no semantic change.
  • Three CHANGELOG.md entries + three plugin.json version bumps — prose-only, version numbers
    match the actual wiring changes.

New-content verification

The new V1-residue section claims claude-config's audit-pass "already ships the ritual: a
re-run contract with a lease and epoch, finding suppression that survives across runs, and a
three-scope inventory." Checked this against the actual skill files rather than trusting the
prose:

  • plugins/claude-config/skills/audit-pass/reference/run-contract.md and
    run-state-and-resumability.md do document a lease/liveness test.
  • plugins/claude-config/skills/audit-pass/reference/suppression.md and
    finding-identity.md back the cross-run suppression claim.
  • three-scope inventory is real terminology used throughout SKILL.md,
    determinism-tiers.md, and report-location-and-schema.md.

Claim holds up. Both new relative links in this section
(context-engineering-corpus-knowledge.md)
resolve correctly. No new findings in the delta.

Still open from the prior pass (unchanged files, not re-flagged to avoid duplicate inline comments)

docs/conventions/instruction-exception-register/README.md was not touched by either new commit,
so these two previously-posted inline findings still stand as of 9970e0c:

  1. Line 55 — consumer table claims audit-instructions I1/I4/I5 all hold protected candidates; only I4 and I5 are actually wired (plugins/claude-config/skills/audit-instructions/reference/criteria.md — re-verified this pass, I1 still carries no register reference).
  2. Line 56 — table asserts unhobble never leaves a protected rule deleted, but unhobble/SKILL.md has no wiring for this register at all.

Result

No new correctness or maintainability issues in the delta since the last review. The two
pre-existing findings above remain unresolved and are the only outstanding items from this lane.

…ble was only claiming

The review lane caught the register's consumer table promising wiring that did
not exist: it listed audit-instructions I1 alongside I4 and I5, and asserted that
unhobble never leaves a protected rule deleted, while neither surface referenced
the register at all. That is the exact failure the table's own footnote names, so
the fix is to wire them rather than to shrink the claim.

I1 gains the hold clause with the reason its own bar cannot see the problem: it
asks whether removal changes behavior today, and a protected rail's removal
changes behavior only on the occasion it was written for. unhobble's Phase 4
restores a protected rule whether or not the ledger logged against it, since a
rail whose absence is unrecoverable will not usually announce itself inside one
experiment window. The strip stays permitted; only leaving it deleted on silence
does not.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
@claude

claude Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Claude finished @kyle-sexton's task in 1m 47s —— View job


Code review — PR #3588 (re-run at 1d27afd)

  • Gather context (PR diff vs origin/main, changed files, HEAD SHA 1d27afd)
  • Invoke /review:code-review procedure
  • Read changed files and diff
  • Verify prior findings (broken links, register wiring claims)
  • Post findings

Scope of this pass

The only commit since the last full code-review pass on this thread (9970e0c) is 1d27afd,
which is a direct fix for the two open findings from earlier passes:

  1. docs/conventions/instruction-exception-register/README.md:55 — previously claimed audit-instructions I1/I4/I5 all held back protected candidates, but only I4/I5 were wired. Fixed: plugins/claude-config/skills/audit-instructions/reference/criteria.md:215-219 now adds a "Hold instead of delete" clause to I1 itself, cross-referencing I5's terms, with a clear rationale (I1's bar asks whether removal changes behavior today, which can't see a protected rail's occasion-only risk). Verified I1's clause is internally consistent with I5's existing hold clause (criteria.md:313-317) rather than duplicating or contradicting it.
  2. docs/conventions/instruction-exception-register/README.md:56 — previously claimed unhobble never leaves a protected rule deleted, but SKILL.md had no such wiring. Fixed: plugins/claude-config/skills/unhobble/SKILL.md:166-176 (Phase 4, now split into steps 4-5) adds the exception explicitly — a rule matching a register-protected class is restored regardless of ledger evidence, with the strip/leave-deleted distinction stated plainly and register holds tracked separately from the ledger's defence tally. Confirmed no other part of the file still references the old single-step-4 numbering.

Both fixes are wired at the actual point of remediation (not just asserted in the README), match the register's own "non-exhaustive, tighten-only" framing, and the accompanying CHANGELOG.md entries in plugins/claude-config/CHANGELOG.md accurately describe the change under the still-unreleased [0.40.24] bucket (consistent with the prior bump commit 1d25ba1, since this version hasn't shipped yet).

Result

No new correctness or maintainability issues. Both previously-flagged findings are resolved by this commit; nothing outstanding from this lane.
· branch claude/context-engineering-ai-agents-eylizg

@claude

claude Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Claude finished @kyle-sexton's task in 59s —— View job


Security review — PR #3588 (re-run at 1d27afd)

  • Gather context (PR diff vs origin/main, HEAD SHA 1d27afd)
  • Invoke /review:security-review and follow its procedure exactly
  • Post findings

Skip gate: applies. This head's predecessor (1d25ba1) already carried a successful security
review on this thread that found no issues. Per the skill's skip gate ("this head already has a
successful security review that still applies"), I diffed 1d25ba1..1d27afd to confirm the new
commit introduces no security-relevant surface before relying on that prior result:

  • docs/conventions/instruction-exception-register/README.md,
    plugins/claude-config/skills/audit-instructions/reference/criteria.md,
    plugins/claude-config/skills/unhobble/SKILL.md
    this commit is the fix for the two wiring findings the code-review lane flagged earlier on this
    thread (I1 had no register reference; unhobble Phase 4 didn't restore protected rules). The
    change strengthens the guardrail: audit-instructions I1 now defers protected candidates to
    I5's hold clause, and unhobble Phase 4 now restores a register-protected rule regardless of
    whether the ledger logged a stumble against it, instead of leaving it deleted on silence. No new
    instruction, permission, secret-handling, or trust-boundary surface.
  • docs/specs/context-engineering-vertical-decisions.md, plugins/claude-config/CHANGELOG.md
    prose additions describing the above; no code or executable surface.

None of this touches code, CI workflows, permissions, secrets handling, or dependency pins.

Result: no security findings. Stopping per the skip gate — nothing further to post.

Copy link
Copy Markdown
Contributor

hygiene / ci-status are red, and the failure is not this PR's

hygiene fails on one sub-check, gitleaks; the other sixteen pass, and ci-status is its
rollup. Every other check on this PR is green, including contract-slice-prune-gate,
changelog-parity-gate, pr-issue-linkage, both review lanes and the security lane.

What is failing. Reproduced locally with the CI-pinned gitleaks 8.30.1 and this repo's
.gitleaks.toml:

RuleID:      generic-api-key
Secret:      CLAUDE_SHIM=0
File:        plugins/claude-config/lib/resolve-convention-home.sh
Line:        248
Commit:      f7aec1549dec60407a24a7d8ea720696b7b099af

The source line is a shell variable initialization sitting under a CLAUDE_TOKEN="" line, which
supplies the keyword context generic-api-key needs. There is no secret.

Why it is not this PR's. That commit is not an ancestor of this branch and is not on main.
It is reachable from origin/chore/bespoke-conversion and
origin/chore/retired-conventions-mechanism, both pushed 2026-09-01T21:47Z. The CI checkout
fetches every branch and the gitleaks step's git scan reaches the commit through those refs: the
failing run reports 1,987 commits scanned where this branch's own history is 1,976. A scan
confined to this PR's head resolves clean; adding --log-opts=--all reproduces the finding
exactly. This PR's diff is documentation and skill prose and does not touch that file, that
plugin's lib/, or .gitleaks.toml.

main is still green because its last push run (21:40Z) predates the offending push by seven
minutes. Any PR opened or pushed after that is red on this check.

No fix exists to port. .gitleaks.toml states its own policy — inherit the upstream ruleset,
add nothing repo-specific, and route intentional findings through a repository-owned
.gitleaksignore or an inline gitleaks:allow marker — so the config is not the place to fix it,
and the durable fix (an allow marker or a variable rename) belongs on the branch that introduced
the line. Filed as #3610 with the reproduction and a proposed patch rather than widening this PR
with a security-scanner allowlist.

No re-run spent. The failure is deterministic, not a flake: it reproduces byte-for-byte
locally and will keep reproducing while that branch exists, so a re-run would only burn a cycle.

This PR stays watched until it is green and merged.


Generated by Claude Code

@kyle-sexton
kyle-sexton enabled auto-merge (squash) September 1, 2026 23:03
The hygiene lane's gitleaks step has been red on every open pull request since
21:47Z, not just this one: PR #3611, unrelated, shows the same signature with
every other check green. The finding is `CLAUDE_SHIM=0`, a shell flag set to
zero, reported as generic-api-key because the AGENTS_TOKEN and CLAUDE_TOKEN
initializations above it supply the rule's keyword context and it takes the
following line as the value. TOKEN there is the parser sense, never a
credential.

The branches carrying that line already annotate it with an inline marker, and
that is correct for the file but cannot clear CI: the scan walks git history,
so the original unmarked blob keeps reporting from its own commit no matter
what a later commit says. A second, unmarked copy has since appeared under
plugins/plugin-quality/lib/ on another branch. Fingerprint entries are the
mechanism .gitleaks.toml points at for exactly this, and unlike an edit to that
file they add no repo-specific rule to the shared ruleset.

Verified against CI's pinned gitleaks 8.30.1 with this repo's config: the
all-refs scan goes from two findings to none across 2008 commits. Also verified
what does NOT work, so the next reader does not retry it: renaming the flag
still fires, and so does separating it from the TOKEN lines by a blank line.

Each entry names a commit on an unmerged branch and becomes removable once that
branch squash-merges or is deleted; the file says so, and #3610 tracks both the
cleanup and the underlying scan-scoping question.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
main landed the same .gitleaksignore independently (#3611), with the identical
two fingerprints, so the only conflict was the header prose. Resolved onto
main's wording, with one correction and the verification folded in: the flagged
secret is CLAUDE_SHIM=0 rather than an empty string, renaming the flag and
separating it from the TOKEN lines were both tested and still fire, and an
inline marker cannot clear a finding already recorded against an earlier commit
because the scan walks history.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uCQCPBraw7iVZ61F83EAJ
@claude

claude Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

Claude finished @kyle-sexton's task in 1m 32s —— View job


Security review — PR #3588 (re-run at db8573a)

  • Gather context (PR diff vs origin/main, HEAD SHA db8573a)
  • Invoke /review:security-review and follow its procedure exactly
  • Post findings

Skip gate: applies. This head's predecessor (1d27afd) already carried a successful security
review on this thread that found no issues. Per the skill's skip gate ("this head already has a
successful security review that still applies"), I diffed 1d27afd..db8573a to confirm the two
new commits introduce no security-relevant surface before relying on that prior result:

  • 1e2a073 (fix(ci): accept the CLAUDE_SHIM gitleaks false positive by fingerprint) adds
    .gitleaksignore to this branch. It is not a new suppression: the two fingerprints
    (f7aec1549d...:...resolve-convention-home.sh:generic-api-key:248 and
    708739fb2b...:...resolve-convention-home.sh:generic-api-key:249) already exist verbatim on
    origin/main (landed there via gitleaks false positive on CLAUDE_SHIM=0 turns the hygiene lane red for every open PR #3610, per the reproduction @kyle-sexton posted on this thread).
    This commit only expands the explanatory comment above them — no new commit hash, rule, or line
    is being ignored beyond what's already merged and reviewed on main.
  • db8573a is a merge of origin/main into this branch (pulls in unrelated work, e.g. the
    visualization plugin changes from feat(visualization): adopt the rendered-views doctrine (html-effectiveness wave 1) #3611) and resolves the .gitleaksignore file to the
    version above. It introduces nothing new to this PR's actual diff — git diff origin/main...HEAD is still the same 18 files / 2775+ / 16− as previously reviewed.

Neither change touches code, CI workflow permissions, secrets handling, dependency pins, or any
trust boundary.

Result: no security findings. Stopping per the skip gate — nothing further to post.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants