Skip to content

1.3.3 — advice, never a block

Latest

Choose a tag to compare

@smixs smixs released this 28 Sep 07:46

The plugin now advises and never blocks. It trusts the agent the way a good reviewer trusts a colleague: it measures, shows its work and says loudly when something is dangerous; the agent decides and says why.

What's new in 1.3.3

  • No hook stops the agent. pre-commit, commit-msg and pre-push print their report and let git go on; only an interrupt (Ctrl-C) stops it. The shell guard no longer denies --no-verify, commit -n or core.hooksPath: the command runs and a red flag sits next to its output.
  • Red flags first. Dangerous moves open every output as one line: RED FLAG: <what you are doing> -- <why it is dangerous>; check: <what to verify>. They cover a secret in the change or the pushed history, a deleted, skipped or weakened test, a baseline refreshed with the code, red touched tests on push, and a git command that skips the hooks. Secret checks stay.
  • The Stop hook never holds the turn. The user sees the red flags at once; the agent gets the full report once, with its next message (agent-notes on UserPromptSubmit in Claude Code and Codex, the next-turn channel in pi and omp, a message without a reply in OpenCode). Grok drops UserPromptSubmit context, so there the report reaches the user only.
  • Findings are advice. CRAP, complexity, diff coverage, cycles, dead code, clones, glossary, AI attribution and Jev appear under FINDINGS (n), advice, nothing blocked: or as notes. check, the full run and mutant still exit 1 on findings, so a script or CI can decide for itself.
  • [hooks] flag_bypass replaces block_bypass (still read); false silences the shell guard's flag.

Verified: 407 tests; live git hooks in a scratch repository (a commit with a secret, a deleted test, a push with red tests all go through with the flags first); a live Claude Code session where the turn ended after one answer and the next message carried the red flag verbatim.

Upgrade: claude plugin update code-quality@code-quality, or your agent's plugin update. Running install-hooks again is not needed: the hooks pick up the new copy the next time an agent runs. No config change is needed.