capa-officer, quality-documentation-manager, quality-manager-qmr,
quality-manager-qms-iso13485, and the ra-qm-skills router still presented
legacy QSR 820.x subsections as current FDA law — the same P0-class defect
fixed in fda-consultant-specialist (PR #835), deferred by that wave's agent.
Applied the identical validated pattern: QMSR status banner (final rule
89 FR 7496, ISO 13485:2016 incorporated by reference, effective 2026-02-02),
820.x relabeled historical with ISO 13485 clause as current authority
(CAPA -> 8.5.2/8.5.3; doc/record control -> 4.2.3/4.2.4/4.2.5 + retained
820.35; QMR/management review -> 5.5.2/5.6), and decision-discipline blocks
added where missing (closure/compliance calls route to named owners).
Substantive content unchanged; no scripts contained 820.x claims.
Verified: zero present-tense 820.x-as-current-law claims remain (all under
historical labels/banners); check_paths 0 findings; counters unchanged.
https://claude.ai/code/session_019AJddAL1NADWMXsy1qNPQF
- calculate_cac.py: hoist 'import argparse' to module top per repo convention
- smoke_scripts.py: comment the exit-1-over-exit-3 precedence
- check_paths_allowlist.txt: reword the etc/passwd note ('outside repo root if
resolved literally', not 'deep checkouts')
- cs-scraping-architect.md: clarify both warning and error share exit 1 — parse
the JSON status field for the distinction
https://claude.ai/code/session_019AJddAL1NADWMXsy1qNPQF
- smoke_scripts.py: --help epilog now documents the exit-code table
(0 ok / 1 smoke failure / 3 stale exceptions)
- calculate_cac.py: real argparse --help with an epilog stating the
edit-example_data limitation and the planned --file/stdin enhancement
- cs-scraping-architect.md: add 'model: sonnet' to match sibling agents
Item 4 (senior-security references) was a non-issue — all three referenced
files exist and the now-blocking path gate is green.
https://claude.ai/code/session_019AJddAL1NADWMXsy1qNPQF
The blocking G1 path gate flagged '../../../etc/passwd' — a path-traversal
ATTACK EXAMPLE in a pen-testing skill's attack-vector table, not a real file
reference. It passed locally only because a deep checkout makes ../../../ climb
to the host's real /etc/passwd; on the CI runner it doesn't resolve. Allowlisted
with a reason, per the gate's documented edge-case process.
https://claude.ai/code/session_019AJddAL1NADWMXsy1qNPQF
Implements issue #654 Option A (embedded-sample convention) plus the
verification harness the issue asked for:
- scripts/smoke_json_output.py — new advisory gate (G9) that discovers
every tool whose --help advertises JSON output, runs <tool> --sample
<json-flag>, and asserts the stdout parses as JSON. Tools advertising
JSON without --sample are reported as 'uncovered' (a backlog, not a
failure) so the gate can be adopted incrementally; --strict flips that
to a hard failure once coverage is high. Wired into ci-quality-gate.yml
alongside G8.
- Added --sample embedded fixtures to the 5 tools named in #654:
error_budget_calculator, slo_review, blast_radius_calculator,
audit_log_analyzer, api_linter. Their required args are now optional
when --sample is passed; missing-arg behavior is unchanged otherwise.
- Fixed 4 tools the new gate surfaced (prompt_rater, coach_tip_classifier,
cheat_code_filter, redaction_linter): their --sample path printed human
text and ignored --json; it now honors the JSON flag.
- Synced the 3 dual-published standalone copies (slo-architect x2,
chaos-engineering) so the drift guard stays green.
Gate now reports 16 tools covered, 16 verified, 0 failures.
https://claude.ai/code/session_01CUWsrUNZP9jpxvAwq67UiT
- senior-prompt-engineer: rebuilt on the new-gen pattern; 2023-era cheatsheet
dropped; scripts made model-agnostic and rot-proof (user-supplied pricing,
no hardcoded model/cost tables); 5 workflows with executable exit-code
gates; zero stale model names remain
- senior-security: 445 -> 64 lines; owns only its unique STRIDE/DREAD value
with exact CLIs; 10-row lane table routes everything the v2.2 security
suite covers (all paths verified)
- engineering-team docs: all dead computer:/// links repointed to live
skills/ folders; all 14 stale .zip archives deleted (0 references remain;
folders are the canonical distribution)
- universal-scraping-architect: placeholder cs-scraping-architect agent and
cs-scrape command rewritten with verified CLIs, refusal gates, and the
empirically-confirmed validate_extraction.py exit-code contract
Gates at HEAD: check_paths 0 findings; check_dual_publish 0 drifted;
smoke 582/582; counters match; 78 manifests OK; compileall clean.
https://claude.ai/code/session_019AJddAL1NADWMXsy1qNPQF
- cs-content-creator retargeted off the deprecated content-creator stub to
marketing-skill/skills/content-production; Use-when description; all 4
script CLIs verified; workflows end at the skill's documented thresholds
(score >= 70, quality gates as publish blocker)
- cs-demand-gen-specialist now orchestrates all 3 verified targets
(marketing-demand-acquisition, paid-ads, email-sequence); hard rules
(margin-adjusted ROAS, no scaling without verified tracking); honest CLI
for calculate_cac.py (script takes no args — old agent documented a
phantom invocation)
- marketing-demand-acquisition SKILL.md: same phantom calculate_cac
invocation corrected (verified no-args run exits 0)
- marketing_skills_roadmap.md deleted: stale planning material, now
unreferenced after the agent rewrites (was kept in wave-3 only because
these two agents linked it)
Verified: check_paths 0 findings on both agents; 8 documented CLIs pass
--help; descriptions <= 1024 with Use-when phrasing.
https://claude.ai/code/session_019AJddAL1NADWMXsy1qNPQF
- enforce-pr-target.yml: drop the no-op split/trim/join on the comment body
(array join already produces the final text)
- ci-quality-gate.yml: safety findings now emit a workflow warning instead
of being silently absorbed by '|| true'
- check_paths.py: fnmatch import hoisted to module level
- smoke_scripts.py: stale exception entries now fail the gate (exit 3) so
scripts/smoke_exceptions.txt stays tidy
https://claude.ai/code/session_019AJddAL1NADWMXsy1qNPQF
Every advisory run was green through PR #835, so the burn-in SLA
(2026-07-01 or 10 green runs) is satisfied early. Edge cases route to the
in-repo allowlists (check_paths_allowlist.txt, smoke_exceptions.txt)
instead of continue-on-error.
https://claude.ai/code/session_019AJddAL1NADWMXsy1qNPQF
- derive_counters.py: python_tools condition simplified to the equivalent
parts[0] != 'scripts' (reviewer M1); dead root_scripts variable removed;
--check still passes with identical values
- fda-consultant-specialist quick-start: 820.30 example annotated as a legacy
checklist key mapping to ISO 13485 §7.3 (reviewer m3 — note: switching the
example to '--section 7.3' as suggested would break; the checker's CLI keys
are intentionally the legacy 820.x checklist indices, documented in --help)
- CLAUDE.md: audit/ directory documented as an intentional public audit
record, distinct from the gitignored AUDIT_REPORT.md (reviewer m2)
Reviewer m1 (agents/CLAUDE.md 'engineering-team/' link) is a false positive:
agents/engineering-team/ exists as an agents subfolder containing exactly the
two linked files; check_paths.py confirms 0 unresolvable references.
https://claude.ai/code/session_019AJddAL1NADWMXsy1qNPQF
- enforce-pr-target.yml: the maintainer exemption let any maintainer PR
target main — replaced with the branch-based hard rule from CLAUDE.md:
only dev->main promotion PRs are allowed, regardless of author.
Maintainer PRs now fail the check with retarget instructions (not
auto-closed); non-maintainer PRs are commented and closed as before.
Re-checks on edited/ready_for_review so retargeting clears it.
- ci-quality-gate.yml: flip-to-blocking SLA documented for the 4 advisory
gates (2026-07-01 or 10 consecutive green runs on dev)
- CHANGELOG.md: Deprecated/Removed Skills section with migration paths for
command-guide, ai-seo (-> aeo), release-manager (-> changelog-generator)
Addresses automated review feedback on PR #835 (items 1, 3, 6).
https://claude.ai/code/session_019AJddAL1NADWMXsy1qNPQF
The skill was the repo's only SKILL.md at plugin-root depth
(engineering/universal-scraping-architect/SKILL.md). That nonstandard shape:
- made it the only skill the Tessl quality gate's depth-2 detector fires on
(the gate then fails with an error-fallback 0/100 because the workflow has
no Tessl credentials)
- hid it from convert.sh (-mindepth 4)
- was flagged twice in the newgen audit
Now matches the standalone-plugin convention (skills/<name>/SKILL.md, agents/
+ commands/ + .claude-plugin at plugin root, skills: ['./skills']).
No content changes. Marketplace source path unchanged and still valid.
Gates: 78 manifests OK, 0 unresolvable paths, 0 dual-publish drift,
smoke 582/582, counters match.
https://claude.ai/code/session_019AJddAL1NADWMXsy1qNPQF
Adds an unmissable blockquote to the Git Workflow section: every PR (human or
AI) uses --base dev; main only receives dev->main promotion PRs from the
maintainer. Also trues the Current Scope counters to derived values
(344 skills / 579 tools / 698 references after wave-3 merges and removals).
https://claude.ai/code/session_019AJddAL1NADWMXsy1qNPQF
- #805: insert missing skills/ segment in all per-skill install commands
across 5 domain READMEs (engineering-team, project-management,
marketing-skill, c-level-advisor, ra-qm-team); every path now resolves
to a real directory
- #806: pr-review-expert SKILL.md curl examples now pass Jira/Linear
credentials via stdin curl config (-K -) instead of argv, with a netrc
note, so tokens never reach the process list or shell history
- #807: implement the documented interfaces for the three senior-devops
scripts (terraform_scaffolder: aws/gcp/azure module skeletons with
optional terraform fmt/validate; pipeline_generator: GitHub Actions /
CircleCI configs with build,test,security,deploy stages and runtime
detection; deployment_manager: blue-green/rolling manifests + kubectl
runbooks with deploy/rollback/analyze subcommands); align SKILL.md
- #807: ci-cd-pipeline-builder stack_detector now detects Terraform and
Docker stacks and emits their lint/test/build commands; downstream
pipeline_generator gains a generic job for non-node/python/go stacks
- #748: sync-vibe-skills.py defaults to a flat layout one level below
~/.vibe/skills (the only depth Vibe discovers), with collision-safe
naming and a --nested flag for the legacy namespaced layout
- #785: new scripts/sync-codebuff-skills.py syncs all skills into
Codebuff's ~/.agents/skills using the same flat-layout machinery
https://claude.ai/code/session_01CUWsrUNZP9jpxvAwq67UiT
Adds the collab-proof AI-collaboration retrospective skill from PR #788
(contributor: dong7812) without the regressions in that branch:
- Net-add marketplace entry (PR #788 overwrote the youtube-full plugin
slot; that entry is preserved here).
- marketplace.json kept as raw UTF-8 (PR #788 re-serialized with
ensure_ascii, escaping ~109 chars and polluting the diff).
- Header counters bumped from current dev (344 skills / 695 references /
65 plugins) instead of reverting to the stale v2.9.0 header.
Skill content (SKILL.md, 4 references, plugin.json, LICENSE) is taken
verbatim from #788. plugin.json passes check_plugin_json.
https://claude.ai/code/session_012iCc6XcNqiJzCGfKHz1DKi
Adds cs-webinar-marketer agent + /cs:webinar command wiring the webinar-marketing skill (SKILL.md, stdlib funnel scorer, references, templates, evals) under marketing-skill/skills/. Includes a Windows cross-platform fix to scripts/generate-docs.py (normalizes os.sep to forward slashes — verified no-op on Linux) and regenerated docs. Verified: scorer runs (89/100 sample), frontmatter valid, clean merge into dev with no conflicts.