- #954: strip non-spec source/attribution keys from all 39 plugin.json
manifests so Claude Code's validator accepts them; metadata preserved in
new .claude-plugin/authoring-notes.json sidecars; check_plugin_json.py now
hard-fails manifests carrying those keys and sanity-checks the sidecar;
CLAUDE.md ClawHub schema section updated to the new rule.
- #949: move the c-level-agents plugin out of c-level-advisor/ to a
top-level directory so the two marketplace sources no longer overlap;
updated marketplace.json source, homepage, descriptions, all
cross-references, docs, harness manifest, mirror-tree symlinks/indexes,
and rebased the moved files' relative links; domain counters trued up
(18 -> 19 domains).
- #933: replace dead links to the gitignored maintainer-local megaprompts/
tree with annotated plain-text references (44 files: SKILL.md, READMEs,
agents, commands).
- #931: DynamoDB on-demand pricing updated to post-Nov-2024 rates
($0.625/M writes, $0.125/M strongly consistent reads).
- #969: skill_security_auditor.py and the three dossier scripts reconfigure
stdout/stderr to UTF-8 (errors=replace) so legacy Windows codepages no
longer crash at print time; PYTHONUTF8=1 documented.
- #968: Windows Notes section in INSTALLATION.md + README pointer for the
core.symlinks mirror-tree checkout caveat.
- #924/#885 residuals: hook commands quote "${CLAUDE_PLUGIN_ROOT}" paths in
all plugin hooks.json/settings.json (space-safe roots); removed the stale
pre-rename status/review mirror symlinks and index entries left over from
the memory-status/memory-review rename.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qgc6RYXWJPr5oW9DHU7zR4
Implements issue #654 Option A (embedded-sample convention) plus the
verification harness the issue asked for:
- scripts/smoke_json_output.py — new advisory gate (G9) that discovers
every tool whose --help advertises JSON output, runs <tool> --sample
<json-flag>, and asserts the stdout parses as JSON. Tools advertising
JSON without --sample are reported as 'uncovered' (a backlog, not a
failure) so the gate can be adopted incrementally; --strict flips that
to a hard failure once coverage is high. Wired into ci-quality-gate.yml
alongside G8.
- Added --sample embedded fixtures to the 5 tools named in #654:
error_budget_calculator, slo_review, blast_radius_calculator,
audit_log_analyzer, api_linter. Their required args are now optional
when --sample is passed; missing-arg behavior is unchanged otherwise.
- Fixed 4 tools the new gate surfaced (prompt_rater, coach_tip_classifier,
cheat_code_filter, redaction_linter): their --sample path printed human
text and ignored --json; it now honors the JSON flag.
- Synced the 3 dual-published standalone copies (slo-architect x2,
chaos-engineering) so the drift guard stays green.
Gate now reports 16 tools covered, 16 verified, 0 failures.
https://claude.ai/code/session_01CUWsrUNZP9jpxvAwq67UiT
PR #756 normalized most marketplace versions to 2.9.0, but 20 newer
plugins (added after the normalization pass) remained on their own
versions on both marketplace.json and their plugin.json. Bump them all
to 2.9.0 so the registry advertises one unified release version, with
marketplace.json and every plugin.json fully in sync (62/62 at 2.9.0).
https://claude.ai/code/session_01JGwZR83iSg59EAtpTSCBjH
v2.8.1 was already taken by the engineering role-skill upgrade
(senior-fullstack / senior-frontend / senior-backend with karpathy-coder
+ Matt Pocock decision engines), released 2026-05-20 — before the
handoff PRs even merged. The auto-release workflow created the v2.8.1
tag from that work via CHANGELOG.md parsing.
The productivity/handoff skill is the next minor on top of v2.8.1:
v2.8.2.
Changes:
- CHANGELOG.md: prepend a new [2.8.2] entry documenting the handoff
skill (PRs #724, #728, #729). The auto-release workflow
(.github/workflows/release.yml) will pick up this entry and create
the v2.8.2 git tag + GitHub Release on the next push to main.
- productivity/handoff/.claude-plugin/plugin.json: 2.8.1 -> 2.8.2
- .claude-plugin/marketplace.json (handoff entry): 2.8.1 -> 2.8.2
- CLAUDE.md: 4 spots bumped to v2.8.2; v2.8.1 references kept where
they correctly point to the engineering role-skill release
- README.md: Productivity table row ✨v2.8.1 -> ✨v2.8.2
- docs/index.md: description, hero subtitle, "329 Skills" card text
- docs/getting-started.md: description meta + FAQ count text
- mkdocs.yml: site_description
The narrative across all top-level docs now reads correctly:
v2.8.0 (bizops + commercial) -> v2.8.1 (engineering role-skills) ->
v2.8.2 (productivity/handoff).
Verified:
- 0 v2.7.5 references remain (earlier typo)
- All v2.8.1 references that remain point to engineering role-skills
- CHANGELOG topmost entry: [2.8.2] - 2026-05-23
- plugin.json + marketplace.json both at 2.8.2
- mkdocs build clean (will re-verify in CI)
https://claude.ai/code/session_01KLhHBAfEDXdQMeRe6G8sRa
Ships the three improvements judged most impactful in v1.1 design review:
1. SessionEnd hook (hooks/session_end.py)
Pairs with SessionStart. When a session ends with no handoff in the
last 30 minutes, prints a one-line reminder. Cannot prompt
interactively or block session end — surfaces text via stdout.
Disable per-session with HANDOFF_SESSIONEND=0. hooks.json updated to
wire both SessionStart and SessionEnd.
2. handoff_self_check.py — fidelity script (~300 LOC, stdlib-only)
Operationalizes handoff_prompt.md. Six checks:
- All 5 sections present
- Goal is non-empty and non-placeholder
- State-of-play bullets reference at least one artifact (commit hash,
PR/issue number, file path, URL)
- Open decisions are present (or explicit "- None.") when git is dirty
or has recent commits
- Skills to use: 3-5 entries, hard cap enforced
- Artifacts contain paths/URLs only, no inline content
Severity: high/medium/low. Strict mode exits 1 only on HIGH findings.
--sample fixture has 3 planted issues (2 high + 1 medium) and exits 1.
Canonical example_handoff.md passes clean (exit 0).
/cs:handoff command updated to run self-check between scaffold-fill
and redaction linter.
3. --refresh flag on handoff_template_generator.py
Reuses the most recent handoff in the configured save location
instead of creating a new file. Falls through to create-if-missing
when no existing handoff is found. Keeps the save location
uncluttered when work continues past the original handoff time;
ensures the SessionStart hook always loads the up-to-date version.
Version bump: 2.7.4 -> 2.7.5. Marketplace description and keywords
updated. README v1.1 section added. SKILL.md gains "Refreshing an
Existing Handoff" and "SessionEnd Reminder" subsections.
Verified:
- All 9 Python files compile clean
- self-check --sample correctly fails (3 findings, exit 1)
- self-check passes clean against assets/example_handoff.md (exit 0)
- --refresh finds the latest /tmp/handoff-*.md and prints its path
- SessionEnd hook prints the reminder when no recent handoff exists
- check_plugin_json.py + marketplace.json + hooks.json all parse
- Plugin audit re-run: structure 84.2 -> 86.0, quality 62.2 -> 63.0,
security PASS (0 critical, 0 high)
- Codex + Gemini sync re-ran clean
https://claude.ai/code/session_01KLhHBAfEDXdQMeRe6G8sRa
Auto-fixes from the 8-phase plugin audit:
- Drop `from __future__ import annotations` from all 7 Python files. The
validator flagged it as an "external import" (false positive — it's
stdlib). Type hints already use 3.10+ syntax (`Path | None`,
`dict[str, Any]`), so the import was redundant.
- Add `assets/example_handoff.md` — complete worked example of the
5-section output. Lifts quality scorer's "practical_examples" and
"assets_existence" dimensions.
- Add skill-level `README.md` (in addition to existing plugin-level one)
pointing at SKILL.md, scripts, references, and assets. Closes the
scorer's "readme_existence" warning.
- Extend SKILL.md from 90 -> 178 lines: add `## Examples` (4 scenarios)
and `## Usage` (command-to-step table). Clears the validator's
"SKILL.md too short" error and lifts the scorer's documentation depth.
- Sync Codex + Gemini indexes (auto-regenerated by the sync scripts).
Audit results after fixes:
Phase 2 (structure): 73.0 -> 84.2 (GOOD, threshold 75)
Phase 3 (quality): 53.9 -> 62.2 (C, sibling capture scores 46.4)
Phase 5 (security): 0 critical, 0 high (PASS)
All 6 scripts pass --help and --sample. End-to-end smoke test re-run
clean: template generator writes, hook surfaces, linter blocks
planted secrets in strict mode.
Verdict: PASS WITH WARNINGS (warnings are validator quirks — sibling
`config_loader` import flagged as external, same way `capture` and
`reflect` get flagged).
https://claude.ai/code/session_01KLhHBAfEDXdQMeRe6G8sRa
Ships the 5 must-haves for a handoff skill to fulfill its purpose:
1. SessionStart hook auto-loads the latest handoff (hooks/session_start.py).
Wrapped in <handoff_from_previous_session> tags so the next agent reads
it as data, not instructions. Disable per-session via HANDOFF_SESSIONSTART=0.
2. First-run setup with explicit save-location choice (no pre-selected
default). 5 core questions: save location, retention, redaction
strictness, git context, recommender scope. Prompt-once-then-default
model — declined setup leaves a sentinel so the prompt never re-appears.
3. Mandatory checklist for the agent (references/handoff_prompt.md) — 7
steps forcing topic-by-topic classification (State / Decision / drop)
instead of free-handing prose.
4. Redaction linter (scripts/redaction_linter.py) — 17 stdlib regex
patterns covering AWS/GitHub/OpenAI/Anthropic/Slack/Stripe keys, JWT,
private-key blocks, env-style secret assignments, DB connection strings
with creds, bearer tokens, URL token params, email, phone. Inline
whitelist marker for true false positives. Strict/warn/off modes.
5. mtime-guarded cleanup (scripts/cleanup.py) — never deletes a handoff
the user edited as a working surface.
Wrapper layout matches productivity/capture and productivity/reflect:
SKILL.md preserves Matt's seven sentences verbatim, surrounded by
invocation triggers, output path discipline, 5-section template, and an
anti-patterns block. Plus cs-handoff-author agent, /cs:handoff and
/cs:handoff-setup commands, 5 reference docs (each citing 5-6 sources),
6 stdlib-only scripts (all pass --help and --sample).
Coexists with engineering/handoff/ (code/PR-focused, no setup, no
redaction enforcement, no SessionStart hook). Both shipped in
marketplace.json. Codex slug collision: the productivity variant wins
the .codex/skills/handoff symlink because it's the more general-purpose
version; both remain in .codex/skills-index.json.
Credit to Matt Pocock surfaces in README + SKILL.md footer + scaffold
footer, not as a manifest attribution block (cleaner plugin.json).
Verified:
- All 6 Python tools pass --help and --sample
- redaction_linter --sample finds 8 planted secrets, exits 1 (strict)
- SessionStart hook smoke-tested end-to-end against a real scaffold
- check_plugin_json.py --all clean (0 failures across all plugins)
- sync-codex-skills.py re-ran clean (productivity: 4 -> 5)
https://claude.ai/code/session_01KLhHBAfEDXdQMeRe6G8sRa