Commit graph

1285 commits

Author SHA1 Message Date
Mahdi
2d892df70d feat(productivity): add swedish-mentor skill 2026-08-05 21:25:40 +02:00
Alireza Rezvani
2800f83337
Merge pull request #921 from alirezarezvani/claude/productivity-skills-audit-obucop
Some checks failed
Sync Codex Skills Symlinks / sync (push) Has been cancelled
2026-07-17 15:00:03 +02:00
Claude
eec8fb61ec
fix(meetings): stop crediting capitalized non-names in 'Name will ...' prose
Review round 8 on PR #921 found the third misattribution path: plain
'Name will ...' lines credited any sentence-initial capitalized word
outside a small pronoun list — 'Friday will be a half day' rendered as
a commitment owned by 'Friday' with no ORPHAN flag. Two deterministic
guards added, applied to both the entry pattern and the checkbox
refine pass:

- NON_OWNER_WORDS: pronouns + weekdays + months + common non-name
  sentence starters (Today/Tomorrow/Next/Last/There/...)
- STATIVE_CONTINUATIONS: 'will be/need/probably/likely/not/...' reads
  as a prediction or status, not a commitment — the line is simply not
  an action item

Verified: all three reviewer examples no longer captured; real
commitments (Maria will send..., Alex will confirm...), checkbox
refines, the round-5 committer case, and the round-7 ORPHAN case all
unchanged; --help/--sample clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 07:05:45 +00:00
Claude
908c48e40e
fix(meetings): only a leading @mention confers action-item ownership
Review round 7 gut-check on the MENTION_ANY fallback, resolved in favor
of scoping: '- [ ] follow up with @sam about pricing' no longer credits
sam — a mid-text mention is the task's object, not its owner (the same
misattribution shape as the round-5 bug, via a different entry path).
Head-anchored mentions ('@sam: book the room', '@sam book the room',
'@sam to book the room') still attribute and strip the owner phrase;
object-only lines now flag ORPHAN for a human to assign, per the
skill's never-silently-guess rule. Docstrings updated; unused
MENTION_ANY_RE removed.

Verified across six patterns incl. the round-5 regression case;
--help/--sample clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 06:59:44 +00:00
Claude
ecb0c9fce0
fix(deep-work): enforce the 10-min buffer before the end-of-day shallow batch
Review round 6 on PR #921 found (and execution confirmed) that batch B
was appended directly, bypassing advance(): on tight schedules
(start_b == cursor) two work blocks landed back-to-back with
'Buffers 0min', violating the docstring's own buffer invariant. The
backward pass now reserves BUFFER_MIN whenever batch B would directly
follow a work block: the overflow check includes it (a day that only
fits without the buffer is now correctly refused, exit 2) and a
explicit Buffer event is emitted when it fits.

Also fixes the cosmetic inconsistency in action_item_extractor's
ACTION:/TODO: path — a leading '@owner will/to' inside the captured
text now strips the owner phrase (matching the Name-will branch), so
'ACTION: @sam to book X' renders as 'book X' under sam.

Verified: tight two-batch day refuses by exactly 10 min; +10-min day
fits with visible buffer; deep->batchB and roomy (buffer+flex) days
correct; --help/--sample clean on both scripts; mid-text-mention and
ORPHAN behavior unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 06:54:00 +00:00
Claude
8568483a4c
fix(meetings): action_item_extractor no longer reassigns owner to a mid-text @mention
Review round 5 on PR #921 found a real, silent misattribution:
'@maria will ask @sam to review the doc by Friday' credited sam (the
person being asked) instead of maria (the committer), because
extract() ran the _extract_owner_and_text refine pass unconditionally
and MENTION_ANY_RE matched the second @mention. The refine pass now
runs only when no owner was captured at the head of the line — its
original purpose (checkbox/ACTION-prefix lines that start ownerless).

Verified all four paths: owned-@mention keeps the committer, 'Name
will ... @other' prose keeps the committer, checkbox '@sam to ...'
still refines to sam, ownerless lines still flag ORPHAN; --help and
--sample unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 06:47:19 +00:00
Claude
c17b2f59e6
refactor(meetings): agenda_builder usage errors exit 1, matching the batch contract
Closes the last open note from PR #921's review loop: usage errors
(malformed --topic, missing/bad flags) now exit 1 like
meeting_cost_calculator, keeping exit codes 0/2/3 exclusively for
verdicts across the 9-script batch. Epilog updated; all five exit
paths re-verified (usage=1, no-outcome=2, overflow=3, sample/help=0).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 06:41:49 +00:00
Claude
1d18477b60
fix(productivity): exit-code and --sample --json contract fixes from review
- meeting_cost_calculator.py: usage errors now exit 1 instead of 2, so
  the ASYNC verdict (exit 2) is unambiguous for exit-code-driven
  callers; epilog documents the new code
- focus_session_logger.py: top-level --json now works with --sample
  (canned JSON status), matching the uniform --sample --json contract
  of the other 8 scripts; subcommand --json unchanged
- time_block_planner.py: deep-only overflow no longer says 'defer
  shallow work ... trim the deep blocks' — it now names deep demand as
  the cause when there is no shallow work to defer

Verified: usage-err=1 / ASYNC=2 / MEET-sample=0; --sample --json parses
as JSON; subcommand --json regression-checked against a real state
file; deep-only overflow message exercised; --help sweep clean on all
30 productivity scripts.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 06:37:57 +00:00
Claude
3f7f806e16
chore(productivity): align new plugin versions with current release (2.11.2)
Per review note on PR #921 — the three new plugins were stamped 2.11.1;
new entries should carry the current release version. plugin.json +
marketplace entries updated; validators and counter check still clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 06:31:50 +00:00
Claude
a775d211c0
refactor(productivity): address reviewer feedback on PR #921
- agenda_builder.py: parse --topic with right-anchored split so desired
  outcomes may contain colons (structured minutes/owner fields split
  from the right, title at the first colon); clearer malformed-spec
  error text
- focus_session_logger.py / action_item_extractor.py: bare tuple return
  annotations -> typing.Tuple for consistency with the files' own style

Verified: --help/--sample exit 0 on all touched scripts; colon-bearing
outcome ('Decide: usage-based vs seat-based') parses and still sorts
decision-first; malformed topic still hard-errors. The reviewer's
time_block_planner lunch/overflow edge case was checked empirically:
batch B is anchored to --end and backward-pass lunch insertion is
guarded by 'lunch + 30 <= start_b', so the day never extends past
--end; the worst case is an explicit 'lunch could not be placed' note.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 06:27:39 +00:00
Claude
3691fcf5de
chore(sync): regenerate codex + gemini skill symlinks and indexes
Picks up weekly-review, deep-work, meetings — plus previously unsynced
skills (fable-goal, skillopt-sleep, agent-harness, and other strays the
automation had not yet mirrored). Vibe/Hermes/Codebuff home-dir syncs
verified in-session (11 productivity skills discovered each).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 06:20:15 +00:00
Claude
8232162630
fix(productivity): resolve deep-work asset paths + lift meetings agentic signals
- check_paths.py: fix two unresolvable shutdown_checklist.md references
  in cs-deep-work agent/command (correct ../skills/ prefix)
- meetings SKILL.md: add genuine intake/iteration/close-out discipline
  (clarify-the-decision intake, re-run-until-fit stop condition,
  owner+date completion check) -> manifest signals now 5/5, checklist
  still PASS at 97 lines
- productivity harness manifest regenerated

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 06:17:54 +00:00
Claude
7a1c351281
feat(marketplace): register weekly-review, deep-work, meetings plugins + counter true-up
- 3 new marketplace entries (85 -> 88 plugins)
- Headline counters trued up via derive_counters.py: 362 skills, 644
  Python tools, 741 references, 102 agents, 116 commands (also clears
  the counter drift inherited from the branch base)
- Productivity harness manifest regenerated (11 skills)
- CLAUDE.md unreleased-changes note + footer refresh

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 06:16:15 +00:00
Claude
5ade746eea
feat(productivity): add deep-work plugin — time-blocking + shallow-work budget
Fills the time/attention-management gap identified by
audit/productivity-2026-07. Full Path-B contract: cs-deep-work agent,
/cs:deep-work command, SKILL.md (checklist PASS), 3 stdlib scripts
(time_block_planner with 4h deep-cap refusal, shallow_work_auditor with
budget verdict + recent-graduate forcing question, focus_session_logger
with weekly target + streaks), 3 references, 2 assets.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 06:13:36 +00:00
Claude
8cbd2b6ee9
feat(productivity): add meetings plugin — cost gate + agenda + action discipline
Fills the meeting-hygiene gap identified by audit/productivity-2026-07.
Full Path-B contract: cs-meeting-discipline agent, /cs:meeting-prep +
/cs:meeting-actions commands, SKILL.md (checklist PASS), 3 stdlib scripts
(meeting_cost_calculator with MEET/ASYNC/NOT-READY exit-coded verdicts,
agenda_builder refusing outcome-less topics and timebox overflow,
action_item_extractor with ORPHAN/NO-DUE flags), 3 references, 2 assets.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 06:11:40 +00:00
Claude
347529d8b7
feat(productivity): add weekly-review plugin — GTD weekly-review loop
Fills the periodic-review gap identified by audit/productivity-2026-07.
Full Path-B contract: cs-weekly-review agent, /cs:weekly-review command,
SKILL.md (checklist PASS), 3 stdlib scripts (open_loop_scanner,
weekly_review_gate with mandatory GET CURRENT refusal gate,
commitment_auditor), 3 references (5-7 sources each), 2 assets.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 06:10:42 +00:00
alirezarezvani
6d578c28f0 chore: sync codex skills symlinks [automated] 2026-07-17 06:07:33 +00:00
Alireza Rezvani
5a8fc61582
Merge pull request #920 from alirezarezvani/claude/productivity-skills-audit-obucop 2026-07-17 08:07:21 +02:00
Claude
c3460dd78f
docs(audit): note fable-goal landing on dev mid-audit in coverage map
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 06:06:25 +00:00
Claude
f8f9513e6f
Merge remote-tracking branch 'origin/dev' into claude/productivity-skills-audit-obucop 2026-07-17 06:05:37 +00:00
alirezarezvani
6c70e16106 chore: sync codex skills symlinks [automated] 2026-07-17 06:05:01 +00:00
Alireza Rezvani
0b691f77dc
Merge pull request #907 from alirezarezvani/claude/skillopt-microsoft-integration-7wmz3r 2026-07-17 08:04:50 +02:00
Claude
eddbb03451
Merge origin/dev into skillopt-sleep branch, reconcile counters
Resolves conflicts in CLAUDE.md, README.md, and marketplace.json between
this branch's v2.11.2 skillopt-sleep vendoring and dev's productivity/fable-goal
addition — both narratives are kept, ordered by landing time. Headline
counters (skills/tools/refs/agents/commands/plugins) re-derived from the
merged tree via scripts/derive_counters.py and brought back into agreement
across all three files (--check now passes).
2026-07-17 06:04:03 +00:00
Claude
2e07d13fc8
docs(audit): add productivity domain audit record + update codex sync domain description
Audit of all 7 productivity skills (checklist verdicts, script smoke tests,
harness agentic signals) plus coverage gap analysis identifying the three
missing lanes: weekly-review (GTD), deep-work (time-blocking), meetings
(cost gate + agenda + action items).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TQLKzYb1bR2LYqwYUupm5f
2026-07-17 06:03:12 +00:00
Alireza Rezvani
5bf15d8e6b
Merge pull request #917 from Jrtorres13/fix/c-level-advisor-readme-links 2026-07-17 07:56:20 +02:00
alirezarezvani
a5d0aae1a8 chore: sync codex skills symlinks [automated]
Some checks are pending
Sync Codex Skills Symlinks / sync (push) Waiting to run
2026-07-16 13:08:17 +00:00
Alireza Rezvani
91fd7386bf
Merge pull request #918 from alirezarezvani/claude/freeskills-fable-goal-improve-zq67vm 2026-07-16 15:08:07 +02:00
Claude
2c86cc1d49
fix(productivity): fable-goal self-check — error on conflicting path + --sample
parser.error (exit 2) instead of silently preferring --sample when both
a prompt file and --sample are passed.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YYh4KrhicuBaS5nRtBeLXK
2026-07-16 07:00:29 +00:00
Claude
5892c631b3
docs(changelog): add fable-goal Unreleased entry
Sixth review round asked for the CHANGELOG.md entry matching the
established [Unreleased] backfill convention (roast, local-seo-manager).
Mirrors the CLAUDE.md post-v2.11.1 narrative block.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YYh4KrhicuBaS5nRtBeLXK
2026-07-16 06:55:33 +00:00
Claude
e3a6940902
docs: fable-goal CLAUDE.md changelog entry + destination-regex tighten
- CLAUDE.md gains an 'Unreleased (post-v2.11.1)' narrative block for
  fable-goal so the changelog-of-record covers the addition without
  inventing a release version (review round 5 ask; counters in arrow
  form to stay clear of derive_counters claim regexes — check passes)
- goal_prompt_self_check.py destination pattern now matches 'the N
  links' phrasing ('the \d*\s*links?'); --sample still 6/6, verified
  'the 3 links' now matches standalone

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YYh4KrhicuBaS5nRtBeLXK
2026-07-16 06:48:46 +00:00
Claude
f9c80986b2
docs: fable-goal README design-notes + fix stale 711 reference count
- plugin README documents the intentional agents/ + assets/ omission and
  the self-check script's scope, per review
- root README line 30 still claimed 711 reference docs (pre-existing
  drift outside derive_counters' claim regexes); trued to 732

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YYh4KrhicuBaS5nRtBeLXK
2026-07-16 06:45:06 +00:00
Claude
e84a53e824
feat(productivity): fable-goal — add goal_prompt_self_check.py per review
Two independent reviews flagged the missing scripts/ folder against the
productivity-domain convention and the repo's 'Algorithm over AI'
principle. Adds one stdlib tool, goal_prompt_self_check.py, which
mechanically verifies the checkable subset of the SKILL.md step-5
self-check on a drafted /goal prompt: word count in the 150-350 band,
goal line, autonomy directive, verification-loop language,
creative-freedom grant, and delivery destination. Exit 0/1/2; --sample
and --output json supported; judgment calls (deliverable concreteness,
resource verification) explicitly stay with the author.

Smoke-verified: --help OK, --sample passes 6/6, degenerate prompt fails
0/6 with exit 1. SKILL.md references the runner in step 5 (79 lines,
checklist still full PASS). agents/ and assets/ remain intentionally
omitted: a single reasoning pass has nothing to orchestrate and no
templates to ship. Counters: python_tools 602 -> 603.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YYh4KrhicuBaS5nRtBeLXK
2026-07-16 06:38:25 +00:00
Claude
7e7074ae76
docs(productivity): fable-goal — fix citation link to specific article URL
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YYh4KrhicuBaS5nRtBeLXK
2026-07-16 06:30:41 +00:00
Claude
10075bff3d
fix(productivity): fable-goal review fixes — version 2.11.1, license clarity, argument-hint
- plugin.json + marketplace version 2.11.2 → 2.11.1 (tracks repo version
  at touch time, matching sibling plugins)
- attribution block clarifies the upstream informal grant is not SPDX and
  that the MIT declaration covers only text authored in this repository
- /cs:fable-goal command gains argument-hint frontmatter (roast/handoff
  convention)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YYh4KrhicuBaS5nRtBeLXK
2026-07-16 06:26:30 +00:00
Claude
fc6177d063
feat(productivity): add fable-goal skill — ramble to autonomous /goal prompt
Improved port of duncan-buildroom/freeskills fable-goal ('free to use and
modify'). Converts a rambling description of a desired outcome into one
polished, copy-paste /goal prompt for a fresh autonomous session.

Improvements over upstream:
- Wrong-tool check (build-now vs write-the-prompt) promoted into the body
- Observable-done principle: every deliverable gets a self-checkable
  completion condition
- Six-slot extraction (deliverable/quantity/stakes/tools/quality/destination)
- Per-medium verification defaults (web, CLI, video, written, data, design)
- Six-point pre-delivery self-check
- Anti-pattern list + failure-mode catalog reference with rationale per
  anatomy part
- Second worked example in a non-web medium (CLI with dry-run verification)
- /cs:fable-goal command; attribution block in plugin.json

SKILL.md passes the write-a-skill 6-item checklist (full PASS, 77 lines).
Counters trued up via scripts/derive_counters.py (includes pre-existing
engineering drift 81→83): skills 355→358, refs 731→732, commands 109→110,
plugins 83→84.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YYh4KrhicuBaS5nRtBeLXK
2026-07-16 06:21:15 +00:00
Jrtorres13
b95311a3a4 docs(c-level-advisor): fix broken SKILL.md links in README
ceo-advisor and cto-advisor SKILL.md files live under skills/, but the
README links pointed one directory too shallow.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-15 21:51:26 -04:00
Alireza Rezvani
84dc5a4f6a
Merge pull request #916 from alirezarezvani/dev
Some checks failed
Deploy Documentation to Pages / build (push) Has been cancelled
Sync Codex Skills Symlinks / sync (push) Has been cancelled
Deploy Documentation to Pages / deploy (push) Has been cancelled
Dev
2026-07-14 09:46:55 +02:00
Alireza Rezvani
c263db903a
Merge pull request #915 from alirezarezvani/alirezarezvani-patch-1
Fix Star History Chart link in README
2026-07-14 09:46:32 +02:00
Alireza Rezvani
4a6a87fa15
Fix Star History Chart link in README
Updated the link for the Star History Chart in the README.
2026-07-14 09:45:59 +02:00
Claude
7eb198ff42
fix(engineering): require --yes for schedule + close mkdir/chmod race (round-10)
A tenth review pass, after confirming all nine prior rounds of fixes
hold up under independent re-reading, found two more low-severity
gaps and offered to accept a follow-up -- fixed both now for
consistency with how every prior round's findings were handled:

1. schedule had no confirmation gate at the CLI layer. The "confirm
   with the user before schedule" safeguard (deviation #15) lived only
   in commands/skillopt-sleep.md's agent-facing instructions --
   cmd_schedule() called scheduler.schedule() directly and installed a
   real crontab entry immediately. Fine for the documented Claude Code
   agent workflow (which confirms in chat first), but anyone invoking
   `python -m skillopt_sleep schedule` directly bypassed it entirely.
   Fixed: schedule now requires --yes; an interactive terminal without
   it gets a [y/N] prompt, a non-interactive one refuses outright
   (exit 2) pointing at --yes. commands/skillopt-sleep.md updated so
   the driving agent passes --yes once it has confirmed with the user
   in chat -- that's what --yes records, not a redundant re-prompt
   that would hang forever with no TTY inside a non-interactive Bash
   tool call.

2. mkdir-then-chmod wasn't atomic in write_staging()/SleepState.save(),
   leaving a brief window where a freshly-created sensitive directory
   sat at the process's default umask. Fixed: the os.makedirs() calls
   creating the state dir, staging leaf dir, and backup dir now pass
   mode=0o700 directly, on top of (not instead of) the existing
   post-creation chmod calls, which still matter for intermediate
   parent dirs and pre-existing directories that mode= doesn't cover.
   The equivalent race for individual files was judged a larger
   rewrite (every open() call site would need os.open() with an
   explicit mode) than this specific low-severity finding warranted --
   documented as a known, narrower residual gap rather than silently
   claimed as fully closed.

Verified: non-interactive schedule without --yes refuses with exit 2,
with --yes it proceeds to the same scheduler.schedule() call as
before; a synthetic run confirms state dir/state.json/staging leaf
still land at 0700/0600/0700 after the mode= change.

Added as README deviations #22-23 and reconciled the count across all
three documents to 23 (6 cosmetic, 17 safety/hardening) across ten
review rounds -- cross-checked with grep.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TX374i2YGrjNV4Yi3AmaKS
2026-07-11 19:43:30 +00:00
Claude
a227b06e6f
fix(engineering): anchor scheduler.py's project marker match (round-9 bug)
A ninth review pass found scheduler.py's schedule()/unschedule() both
located "this project's" managed cron line via marker not in ln, a
bare substring test, not an exact-match or delimiter-anchored check.

Failure scenario: two projects scheduled where one path is a literal
prefix of the other (e.g. /home/user/app and /home/user/app-v2) --
"# project=/home/user/app" is itself a substring of
"# project=/home/user/app-v2"'s line. Running schedule() or
unschedule() for /home/user/app would silently drop app-v2's cron
entry too, with no error or warning.

harvest.py's _project_matches() (added in this same PR) already gets
this right via delimiter-anchored comparison; scheduler.py's marker
matching didn't follow the same discipline.

Fixed: added _line_matches_project(), anchored on
ln.rstrip().endswith(marker) since the marker is always the last token
of a generated line -- used at both call sites.

Also fixed the related minor nit: install-cron.sh's printed --backend
value was unquoted next to otherwise-quoted ${RUNNER}/${PROJECT} in
its heredoc (low risk since that script only prints a line for the
user to copy, never executes anything itself, but inconsistent with
the quoting discipline everywhere else).

Verified two ways: a standalone reproduction confirmed the bug before
the fix and its absence after, and a full schedule()/unschedule()
round-trip through the actual public API (crontab -l/crontab - swapped
for an in-memory fake) confirmed scheduling both /home/user/app and
/home/user/app-v2, then unscheduling only app, correctly leaves
app-v2's line intact.

Added as README deviations #20-21 and reconciled the count across all
three documents to 21 (6 cosmetic, 15 safety/hardening) across nine
review rounds -- cross-checked with grep.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TX374i2YGrjNV4Yi3AmaKS
2026-07-11 19:32:33 +00:00
Claude
4d68c542f2
fix(engineering): close CLI-output redaction gap (round-8 HIGH finding)
An eighth review pass found that seven rounds of redaction fixes were
all file-level (write_staging(), diagnostics.json, state.json's
archive) but __main__.py's cmd_run() reads the same in-memory Report
object and prints EditRecord.content directly to the console, and
_report_payload() serializes it unredacted for --json --
write_staging()'s redaction runs on a copy (report.to_dict()) used
only for the on-disk JSON, it never touches report.edits itself.

Concretely: scheduler.py's cron entry redirects run's stdout/stderr
straight into <project>/.skillopt-sleep/cron.log -- a secret that
leaked into a proposed edit's content would land there in plaintext on
every scheduled night, in a file that (unlike state.json/staged files)
also had no chmod protection.

Fixed:
- _report_payload() and cmd_run()'s plain-text edit printing now run
  through redact_secrets(), gated on the same redact_secrets config
  flag as everywhere else.
- cmd_harvest()'s debug output (--json, --output <file>, and the
  plain-text loop) gets the same treatment -- it prints raw mined
  TaskRecord.intent text so a human can review it before setting
  "reviewed": true on a --tasks-file, and redaction only strips
  secret-shaped substrings, so it doesn't reduce what's reviewable
  while closing the same leak path.
- scheduler.py's generated cron line now chmod 700s the .skillopt-sleep
  log dir and chmod 600s cron.log itself (best-effort, 2>/dev/null)
  before each run appends to it -- that file was never covered by the
  state/staging chmod pass in an earlier round.

Verified: a synthetic secret seeded into a task's intent no longer
appears in cmd_run's --json payload, plain-text edit output, or
cmd_harvest's redacted payload; executing the actual generated cron
line end-to-end (not just inspecting the string) produces a 0700 log
dir and 0600 log file on disk.

Added as README deviation #19 and reconciled the count across all
three documents to 19 (5 cosmetic, 14 safety/hardening) across eight
review rounds -- cross-checked with grep.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TX374i2YGrjNV4Yi3AmaKS
2026-07-11 19:24:29 +00:00
Claude
73c2570796
docs(engineering): trim skillopt-sleep plugin.json's overlong description
A seventh review pass noted plugin.json's top-level description
(930 chars) was noticeably longer than this repo's typical plugin.json
descriptions (median ~600 chars) -- it duplicated detail that
attribution.derivation_note already carries in full. Trimmed to a
single dense paragraph (705 chars) that keeps the essential
what-it-does/safety-model/trigger-phrase content and points to
derivation_note for the full vendoring story, rather than repeating it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TX374i2YGrjNV4Yi3AmaKS
2026-07-11 19:07:45 +00:00
Claude
19fd75a2d6
fix(engineering): correct stale upstream-layout paths in shell launchers
A sixth review pass found sleep.sh and run-sleep.sh still described and
partially resolved against upstream's <repo>/plugins/claude-code/ and
<repo>/plugins/run-sleep.sh layout, not this vendored copy's actual
layout (scripts/ and skillopt_sleep/ as siblings directly under the
plugin root, engineering/skillopt-sleep/). The primary co-located and
repo-relative resolution branches happen to still succeed regardless
(so this was unreachable in normal operation), but the documented
SKILLOPT_SLEEP_REPO and CLAUDE_PLUGIN_ROOT escape hatches would have
silently failed for anyone actually relying on them -- e.g. after a
future re-vendor that missed copying run-sleep.sh into scripts/.

Fixed: sleep.sh's SKILLOPT_SLEEP_REPO branch now checks
$SKILLOPT_SLEEP_REPO/scripts/run-sleep.sh; run-sleep.sh's
CLAUDE_PLUGIN_ROOT branch now checks $CLAUDE_PLUGIN_ROOT/skillopt_sleep
(this repo's actual layout) ahead of the upstream two-levels-up check
(kept for portability if this script is ever reused in that shape
again). Header comments in both files corrected to describe the real
layout instead of upstream's.

Verified both previously-broken fallback branches resolve correctly
when isolated from the co-located script (copied each launcher to a
scratch dir and ran it standalone with only the relevant env var set).

Added as README deviation #18 (cosmetic/hardening) and reconciled the
count across all three documents to 18 (5 cosmetic, 13 safety/
hardening) across six review rounds -- cross-checked with grep.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TX374i2YGrjNV4Yi3AmaKS
2026-07-11 19:01:56 +00:00
Claude
e64c1cdd44
fix(engineering): relabel misleading redaction placeholder (round-5 review)
A fifth review pass found staging.py's sk-[A-Za-z0-9_-]{10,} secret
pattern -- which matches OpenAI, Anthropic (sk-ant-...), and other
vendors sharing the sk- prefix convention -- was labeled
[REDACTED_OPENAI_KEY] regardless of which vendor's key shape it
actually matched. Redaction itself was unaffected (the text was
scrubbed either way), just a misleading placeholder if a user reads it
literally. Relabeled to [REDACTED_API_KEY].

Added as README deviation #17 (cosmetic) and reconciled the count
across all three documents (README.md's numbered list, plugin.json,
CLAUDE.md) to 17 (4 cosmetic, 13 safety/hardening) across five review
rounds -- cross-checked with grep, not just eyeballed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TX374i2YGrjNV4Yi3AmaKS
2026-07-11 18:48:21 +00:00
Claude
e729f157ee
fix(engineering): close round-4 review findings on vendored skillopt-sleep
A fourth automated review pass on PR #907 found the deviation count had
drifted out of sync across the three places that document it, plus two
more real gaps in the vendored plugin:

1. Deviation count inconsistency: plugin.json and README.md both said
   13 (after round 3), but CLAUDE.md's v2.11.2 section said "8
   deviations" with an itemized list that didn't map onto the real
   13-item README list -- it named a "dead cross-reference to a
   non-vendored design doc" as a cosmetic item that was never actually
   added as a numbered README deviation (it was fixed in round 3's
   commit but never itemized). Fixed: added it as README deviation
   #14, updated plugin.json's derivation_note with a note that
   README.md's numbered list is the single source of truth if any
   summary disagrees again, and rewrote CLAUDE.md's bullet to match.

2. commands/skillopt-sleep.md's action table listed `schedule` as an
   ordinary action alongside safe previews (`status`/`dry-run`/`run`),
   while its own "Safety reminders" section separately said to point
   users at the print-only install-cron.sh instead -- two
   uncoordinated stories about the same action. scheduler.schedule()
   writes directly to the user's real crontab the moment it runs, with
   no confirmation step. Fixed (README deviation #15): "Steps to
   follow" now has an explicit step 1 telling the agent to confirm
   with the user before running `schedule`; "Safety reminders" no
   longer contradicts the action table.

3. state.json (the cross-night task archive) and
   .skillopt-sleep/staging/<ts>/'s proposal/report/diagnostics files
   contain real harvested session content in plaintext, created via
   plain os.makedirs/open(...,"w") -- world-readable-by-default on a
   typical multi-user box. Fixed (README deviation #16): state.py and
   staging.py now chmod every directory they create to 0700 and every
   file they write to 0600 (best-effort). Live CLAUDE.md/SKILL.md
   files are intentionally left alone -- those are the user's own,
   often-committed files, not new output this plugin introduces.

All three documents (README.md's numbered list, plugin.json's
derivation_note, CLAUDE.md's v2.11.2 section) now agree on 16
deviations (3 cosmetic, 13 safety/hardening) -- verified by grep.

Verified: py_compile clean, mock-backend dry-run still exits 0, a
synthetic test confirms state dir/state.json/staging dir/staging files
land at 0700/0600/0700/0600 respectively after this fix (previously
default umask permissions), all 4 repo CI gates pass locally.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TX374i2YGrjNV4Yi3AmaKS
2026-07-11 13:47:56 +00:00
Claude
32446887e6
fix(engineering): close round-3 review findings on vendored skillopt-sleep
A third automated review pass on PR #907 found 2 HIGH and 5 further
gaps in the vendored skillopt-sleep plugin, all in the same family as
rounds 1-2 (a safety claim in the docs the code didn't fully back up):

HIGH:
1. state.py's add_to_archive() persisted raw TaskRecord content
   (intent/context_excerpt/attempted_solution -- real harvested
   prompt/response text) to ~/.skillopt-sleep/state.json indefinitely,
   entirely outside the staging dir a user is ever told to review.
   Fixed: cycle.py now redacts each task dict before archiving, using
   the same redact_enabled flag as everything else.
2. report.md / report.json were never redacted, despite being the two
   files a human is told to read FIRST (the SKILL.md's own workflow:
   "show the user the exact proposed edits"). EditRecord.content/
   .rationale come from the optimizer's reflect() output over real
   failing task responses. Fixed: write_staging() now redacts the
   rendered report_md string and report.to_dict() before writing.

MEDIUM/LOW:
3. replay_mode: "fresh" (worktree replay) was declared in config but
   never implemented anywhere -- only fed a cosmetic report label.
   Implementing real worktree isolation was judged too invasive for a
   vendored copy; instead cycle.py now warns loudly when it's set to
   anything but "mock" rather than silently implying isolation that
   isn't happening.
4. backend.py shipped an AzureOpenAIBackend/AzureResponsesBackend pair
   with 5 internal-looking Azure endpoint hostnames and a hardcoded
   Managed Identity client ID, commented as sourced from "the intern's
   avail_api.md" -- reads like leaked internal Microsoft dev infra.
   Already unreachable from this plugin's documented mock/claude/
   codex/copilot --backend choices and requires deps this repo doesn't
   vendor. Removed entirely (classes, constants, get_backend()/
   build_backend() dispatch branches, the now-unused azure_endpoint
   param); get_backend("azure") now safely falls back to MockBackend.
5. attempt_with_tools() (all three CLI backends) used a task's tool
   name both as a shim filename and interpolated unescaped into the
   shim's generated shell body. Tool names originate from a
   hand-authored --tasks-file's judge.checks[].arg, never validated --
   not reachable via harvest/mine today, but a documented user-facing
   input. Fixed: a shared _sanitize_tool_names() helper filters to a
   safe-identifier allowlist before any name is used as a filename or
   shell text.
6. SKILL.md pointed to a design doc path (docs/superpowers/specs/...)
   that was deliberately not vendored. Fixed: points to the real
   upstream guide URL instead, with a note on why the local path is
   absent.
7. CLAUDE.md's "Current Scope" line claimed v2.11.2 but no dated
   version section existed for it. Added one matching the repo's
   established per-release convention.

All 13 deviations (2 cosmetic, 11 safety/hardening) cross-documented
in plugin.json's derivation_note and README.md's "Deviations from
upstream" + "Safety model" + "What was and wasn't vendored" sections.

Verified: py_compile clean, mock-backend dry-run still exits 0, all 4
repo CI gates pass, and a synthetic test with a real API-key-shaped
secret confirms it appears in NONE of state.json's task archive,
report.md, or report.json after this fix (all three fired positive
signal for the leak before it).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TX374i2YGrjNV4Yi3AmaKS
2026-07-11 13:36:00 +00:00
Alireza Rezvani
8c4a374a44
Merge pull request #906 from alirezarezvani/claude/github-issues-auesiu
Some checks failed
Sync Codex Skills Symlinks / sync (push) Has been cancelled
2026-07-11 15:25:14 +02:00
Claude
316982fa9f
fix(engineering): address round-2 review findings on vendored skillopt-sleep
A second automated review pass on PR #907 confirmed the prior 3 safety
patches and found 3 more small gaps:

1. plugin.json's attribution.derivation_note still asserted "no logic
   modified" after the round-1 patches changed staging.py/scheduler.py/
   cycle.py/backend.py. Updated to match README.md's deviation log.

2. redact_secrets was declared in config.py's DEFAULTS but never read
   anywhere -- write_staging() redacted unconditionally regardless of
   the flag (safe direction, but a dead config knob). Wired
   cfg.get("redact_secrets", True) through write_staging() and the
   diagnostics.json fields; disabling it is honored but never
   silently -- fires a loud report note.

3. scheduler.py's _runner_cmd shlex.quote()-d project/logdir/log/repo
   root (round-1 fix) but left the `extra` flags parameter raw. Not
   exploitable today (it's only ever a hardcoded literal), but closes
   the same class of gap defensively via shlex.split + per-token
   shlex.quote so a future multi-flag `extra` can't reopen it.

Also applied the reviewer's non-blocking hardening suggestion: adopt()
now re-runs redact_secrets() on staged content before writing to the
live path (read+redact+write instead of a raw shutil.copy2), covering
the case where a staged proposal is hand-edited between `stage` and
`adopt` -- exactly the workflow staging exists to allow.

All 6 deviations now cross-documented in plugin.json's
derivation_note and README.md's "Deviations from upstream" +
"Safety model" sections so re-vendoring can't silently drop them.

Verified: py_compile clean, mock-backend dry-run still exits 0,
synthetic tests confirm both the empty/populated extra-quoting paths
and the redact_secrets on/off report-note behavior, all four repo CI
gates (smoke_scripts, check_plugin_json, check_paths, derive_counters)
pass locally.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TX374i2YGrjNV4Yi3AmaKS
2026-07-11 11:57:35 +00:00
Claude
186c0f6d11
fix(engineering): close 3 safety gaps found by PR review in vendored skillopt-sleep
Automated review on PR #907 read the actual module code (not just the
surface docs) and found the vendored plugin's own safety claims didn't
fully match its behavior. Patches applied directly to our vendored copy
(documented as deviations in the plugin README for re-vendor):

1. staging.py: redact_secrets() was applied to diagnostics.json but not
   to proposed_SKILL.md/proposed_CLAUDE.md -- the exact files adopt()
   copies over the live CLAUDE.md/SKILL.md (with --auto-adopt, with no
   human in the loop). A secret pasted into a real debugging session
   could have landed in live memory unredacted. Now redacted before
   write_staging() persists either file.

2. scheduler.py: the generated crontab line interpolated an arbitrary
   project path via unescaped f-string into a command cron runs through
   sh -c on every fire. A path containing shell metacharacters could
   break out of the quoting. Now shlex.quote()-d.

3. cycle.py: max_tokens_per_night was declared in config.py's DEFAULTS
   and budget.py already had a Budget/plan_depth heuristic built for
   it, but nothing in the production run_sleep_cycle() path ever read
   it -- a real-backend night had no actual token ceiling. Now a
   Budget starts right after backend construction (harvest/mine spend
   counts too), sizes dream_rollouts down via plan_depth() when
   remaining budget is tight, and the report notes when it caps
   rollouts or the budget is exhausted -- no silent truncation. This
   caps rollout depth per task, not a hard mid-call abort; documented
   as a residual limitation in the README.

Also dropped a leftover hardcoded nvm path in backend.py's
resolve_codex_path() (the generic scan a few lines below already
covers it) and added a one-line acknowledgment to CLAUDE.md's
Anti-Patterns list that this plugin's non-mock backends are a
documented, opt-in exception to "no LLM calls in scripts" -- not
precedent for adding LLM calls to analysis/reference skills.

Verified: py_compile clean, mock-backend dry-run still exits 0,
synthetic test confirms dream_rollouts capping actually engages under
a tight budget and is a no-op under the default budget, all repo CI
gates (smoke_scripts, check_plugin_json, check_paths, derive_counters)
still pass.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TX374i2YGrjNV4Yi3AmaKS
2026-07-08 06:41:32 +00:00