Stream A Phase 1 — Plugin 2 of 3 (compliance OS MVP).
Three stdlib Python tools at the Article level:
- ai_system_risk_classifier.py: Article 5 prohibitions check, then
Article 6 + Annex III, then Article 6(3) carve-out test (overridden by
profiling), then Article 50 transparency, then minimal-risk default.
GPAI detection + Article 51 10^25 FLOPs systemic-risk threshold.
- conformity_assessment_planner.py: Article 43 Module A vs Module H routing
(biometrics -> Module H by default); Annex IV 8-item technical
documentation checklist with ISO 42001/27001 reuse map.
- ai_act_obligation_tracker.py: per-role (provider/deployer/importer/
distributor/auth-rep) obligation matrix with Article 113 phasing
deadlines (2 Feb 2025 / 2 Aug 2025 / 2 Aug 2026 / 2 Aug 2027).
Verified per Phase 1 success criteria: emotion-recognition-in-workplace
classified as prohibited (Article 5(1)(f)); CV-screening as high-risk
(Annex III §4); chatbot as limited-risk (Article 50); spam filter as
minimal-risk.
Four references each citing 5+ authoritative sources (the Regulation,
EDPB Opinion 28/2024, Commission Feb 2025 Guidelines, ENISA, IAPP Tracker,
CEN-CENELEC JTC 21, BSI, NIST AI 600-1):
- eu_ai_act_titles.md: Titles I-XII Article-by-Article walkthrough
- high_risk_systems_annex_iii.md: 8 categories + Article 6(3) decision tree
- gpai_obligations.md: Articles 51-55 + Annex XI-XIII + Code of Practice
- cross_framework_mapping_ai_act.md: AI Act <-> ISO 42001 <-> NIST AI RMF
<-> GDPR cross-walk with Article 17(1) item-by-item mapping
Dual-published: standalone plugin (ra-qm-team/compliance-team-eu-ai-act/) +
mirror under ra-qm-team/skills/eu-ai-act-specialist/.
Karpathy gate: complexity_checker 100/100 (0 findings).
https://claude.ai/code/session_01VFreMf7XLBqMgjsrG4wSYe
Two small polish tasks ahead of any future Pages deploy.
1. Add /cs:* command nav entries (22 new entries)
The 21 c-level-agents-* sub-skill pages now exist (since #632) but weren't
surfaced in mkdocs.yml sidebar nav. Added a "Founder-Mode Commands" nested
section under C-Level Advisory with:
- c-level-agents index
- 10 forcing-question reviews (/cs:cfo-review through /cs:vpe-review)
- 5 strategic sprint pipeline commands (brief/boardroom/decide/execute/post-mortem)
- 4 meta+safety commands (founder-mode/onboard/cross-eval/freeze)
- /cs:office-hours
2. Clear 33 mkdocs INFO warnings
mkdocs build was emitting 33 INFO-level warnings during the docs deploy.
Pre-existing noise; not regressions. Three categories:
a) 27 unrecognized-link warnings: relative links like `[Skills](skills/)`
that mkdocs flags because the path doesn't end in .md. Fix: added
explicit `index.md` suffix in 3 manual doc files.
- docs/index.md: 15 links
- docs/skills/index.md: 11 links
- docs/custom-gpts.md: 1 link
b) 2 anchor warnings in scrum-master TOC: links pointed to
`#analysis-tools--usage` and `#key-metrics--targets` (double hyphen
from ampersand) but mkdocs Material's slugify produces single-hyphen
slugs. Fix: changed to `#analysis-tools-usage` and `#key-metrics-targets`.
c) 4 anchor warnings in senior-computer-vision + senior-data-engineer TOCs:
links pointed to non-existent sections.
- senior-computer-vision: `#common-commands` TOC entry — no such heading
anywhere; removed the entry.
- senior-data-engineer: 3 sub-bullets pointing to `#workflow-1-...`,
`#workflow-2-...`, `#workflow-3-...` — no such headings (only a
parent `## Workflows`); removed the sub-bullets.
Verification:
- mkdocs build now emits 0 INFO warnings
- karpathy diff_surgeon: 0 findings on staged diff
- All 22 new nav entries verified to point to existing HTML pages
- generate-docs.py re-run picked up the upstream SKILL.md fixes; docs/skills/
now matches sources
10 files changed, +54/-39. After the next dev->main release, the Pages
deploy will have:
- Cleaner build output (no INFO noise)
- Fully discoverable /cs:* command pages in the sidebar nav
https://claude.ai/code/session_012WtZMm5NJHqkYoRqA9fHMN
generate-docs.py had a longstanding bug: the rendering loop only iterated
top-level skills and only rendered their direct children. Sub-skills whose
parent is a plugin folder (not a top-level skill at <domain>/skills/<name>/)
were silently dropped.
Affected plugins (standalone-only, no bundled mirror at <domain>/skills/):
- executive-mentor (1 index + 5 sub-skills)
- agenthub (1 index + 7 sub-skills)
- autoresearch-agent (1 index + 5 sub-skills)
- playwright-pro (1 index + 9 sub-skills)
- self-improving-agent (1 index + 5 sub-skills)
- c-level-agents (1 index + 17 sub-skills — the new /cs:* commands)
- llm-wiki (1 index + sub-skills)
- behuman, code-tour, demo-video, helm-chart-builder, karpathy-coder,
llm-cost-optimizer, prompt-governance, statistical-analyst, terraform-patterns,
data-quality-auditor, docker-development (single-skill plugins)
Total: 79 sub-skills + 12 plugin-index skills = 91 pages were being dropped.
(Some plugins like behuman are single-skill so only their index is dropped.)
The bug: rendering loop at line 414 only handled `for skill in top_level`,
then for each top-level found `children = [s for s in sub_skills if
s["parent"] == skill["name"]]`. Plugins where the SKILL.md lives only at
<plugin>/skills/<plugin>/SKILL.md don't appear in top_level (their detection
puts them in sub_skills with parent=themselves), so their children were
orphaned.
The fix: after the existing top-level loop, render orphan sub-skills grouped
by their plugin parent. Index sub-skill (named same as parent) renders as
<parent>.md; other children render as <parent>-<child>.md. This matches the
URL convention already in use (e.g., executive-mentor-challenge.md), so
existing SEO equity is preserved.
Result: skill pages generated 193 → 272 (+79 recovered). Total docs pages
280 → 359. mkdocs build succeeds.
Verified:
- All 12 previously-dropped plugins render their index page
- All 79 previously-dropped sub-skills render their detail pages
- URL convention preserved (executive-mentor-challenge.md, agenthub-board.md,
playwright-pro-coverage.md, etc.)
- karpathy diff_surgeon: 0 findings
After dev → main release: GitHub Pages redeploys with the recovered 79 pages.
The docs site finally has 1:1 correspondence between SKILL.md files in the
repo and pages on the site.
https://claude.ai/code/session_012WtZMm5NJHqkYoRqA9fHMN
PR #628 added 13 new cs-* agent nav entries to mkdocs.yml (cs-cfo-advisor,
cs-cmo-advisor, cs-cro-advisor, cs-cpo-advisor, cs-coo-advisor, cs-chro-advisor,
cs-ciso-advisor, cs-chief-of-staff, cs-general-counsel-advisor, cs-cdo-advisor,
cs-caio-advisor, cs-cco-advisor, cs-vpe-advisor) — but the agent pages they
pointed to didn't exist because generate-docs.py only walked /agents/, not
plugin-internal <domain>/<plugin>/agents/ folders.
Without this fix, those 13 nav links would 404 in production.
Extended generate-docs.py:
Pass 1 (existing): walk /agents/<domain>/*.md (28 canonical agents)
Pass 2 (new): walk <domain>/<plugin>/agents/*.md for each known DOMAINS root
Pass 2 dedupes against pass 1 by slug. Uses a SKILL_TO_AGENT_DOMAIN mapping
(c-level-advisor -> c-level, marketing-skill -> marketing, etc.) since skill
DOMAINS keys differ from AGENT_DOMAINS keys.
Result: 29 → 54 agent pages (+25 plugin-internal agents recovered):
c-level-advisor/c-level-agents/agents/ → 13 new cs-* agents (this session)
c-level-advisor/executive-mentor/agents/ → devils-advocate
engineering/llm-wiki/agents/ → wiki-linter, wiki-ingestor, wiki-librarian
engineering/agenthub/agents/ → hub-coordinator
engineering/autoresearch-agent/agents/ → experiment-runner
engineering-team/self-improving-agent/agents/ → memory-analyst, skill-extractor,
migration-planner, test-architect,
test-debugger
Verified:
- mkdocs build succeeds (357 → 380+ HTML pages)
- All 13 cs-* nav entries from PR #628 now resolve to valid HTML pages
- karpathy diff_surgeon: 0 findings
- Existing /agents/ canonical pass unaffected (dedupe by slug)
After dev → main release: GitHub Pages deploy will surface the recovered
25 agent pages. The 13 cs-* nav entries from the v2.5.7 release will no
longer 404.
https://claude.ai/code/session_012WtZMm5NJHqkYoRqA9fHMN
Pure-cleanup PR addressing carry-over items deferred across PRs #618-#626 per
karpathy principle #3 (surgical scope — no unrelated cleanups inside scoped
feature PRs).
Voice specs added to persona-voices.md (3 missing entries):
- cs-ceo-advisor — The Strategic Translator (tree-of-thought reasoning;
refuses to debate tactics until the strategic question is named)
- cs-cto-advisor — The Architecture-First Pragmatist (ReAct reasoning;
treats every architecture decision as a 3-year commitment)
- cs-general-counsel-advisor — The Risk-Paranoid Lawyer (Not Your Lawyer);
carry-over from v2.5.1
All three agents existed but were never added to the persona reference. The
voice catalog now matches the cs-* agent set 1:1.
Broken paths fixed in 2 pre-existing agent files:
- agents/c-level/cs-ceo-advisor.md: 32 path corrections from
'../../c-level-advisor/ceo-advisor/' to '../../c-level-advisor/skills/ceo-advisor/'
(correct path; the bundled skill lives under skills/)
- agents/c-level/cs-cto-advisor.md: 25 path corrections from
'../../c-level-advisor/cto-advisor/' to '../../c-level-advisor/skills/cto-advisor/'
- YAML 'skills:' frontmatter field also corrected in both
Validation:
- karpathy-coder/diff_surgeon: 0 findings
- Verified target folders exist (c-level-advisor/skills/ceo-advisor/SKILL.md +
c-level-advisor/skills/cto-advisor/SKILL.md)
No skill/agent/command count changes; no manifest version bumps. This is a
pure-fix PR. CHANGELOG entry as v2.5.6.
https://claude.ai/code/session_012WtZMm5NJHqkYoRqA9fHMN
Per user request: register general-counsel-advisor, chief-data-officer-advisor,
and chief-ai-officer-advisor as standalone marketplace plugins (in addition to
their existing inclusion in the c-level-skills bundle). Matches the dual-publish
pattern established by feature-flags-architect / kubernetes-operator /
chaos-engineering / ship-gate / slo-architect in engineering.
Layout (per scripts/sync_skill_bundles.py spec):
Standalone: c-level-advisor/<skill>/skills/<skill>/{SKILL.md, scripts, references}
Bundled: c-level-advisor/skills/<skill>/{SKILL.md, scripts, references} (already existed)
The two locations are kept in sync by scripts/sync_skill_bundles.py;
`--check` passes for all 3 new standalone wrappers.
Added (per skill):
- <skill>/.claude-plugin/plugin.json (ClawHub-compliant 8 fields, "skills": "./skills")
- <skill>/README.md (notes dual-publish + sync mechanism)
- <skill>/skills/<skill>/SKILL.md (mirror)
- <skill>/skills/<skill>/scripts/* (mirror; 2 for GC, 3 each for CDO/CAIO)
- <skill>/skills/<skill>/references/* (mirror; 3 for GC, 4 each for CDO/CAIO)
marketplace.json: 3 new entries (category: leadership), now 37 plugins total.
Validation:
- scripts/check_plugin_json.py: OK on all 3 new plugin.json files (rejects bare "./")
- scripts/sync_skill_bundles.py --check: OK on all 3 standalone wrappers
- karpathy-coder/diff_surgeon: 0 findings
- All JSON validates
Discoverability gain: a founder who wants ONLY the General Counsel skill
(or only CDO or CAIO) can install it standalone, without pulling the full
31-skill c-level-skills bundle. The c-level-skills bundle continues to work
unchanged; this PR is purely additive.
Carried over (still not in scope for this PR):
- cs-general-counsel-advisor voice spec missing from persona-voices.md
- broken paths in pre-existing cs-ceo-advisor.md / cs-cto-advisor.md
- Phase 2 remainder (CCO-customer, VPE, CCO-comms)
https://claude.ai/code/session_012WtZMm5NJHqkYoRqA9fHMN
World-class, in-depth Chief AI Officer skill covering 4 specific decisions
(not a generic AI strategy survey):
1. Should we use an API, fine-tune, or build our own? (3-yr TCO + breakeven)
2. Is this AI use case high-risk under regulation? (EU AI Act + US state +
industry overlays with Article-level citations)
3. When do we switch from API to self-hosted, and at what cost? (2026
pricing + GPU economics + hidden costs)
4. What AI role do we hire next? (5-stage map + 9-role definition table)
Built under karpathy-coder discipline (third in a row):
- Assumptions surfaced upfront before code (principle 1)
- Each tool/reference covers ONE decision; rejected generic-survey scope (#2)
- Surgical changes only; no scope creep (#3)
- All 3 tools smoke-tested with embedded samples before commit (#4)
- karpathy/complexity_checker.py: 0 findings on 3 new tools
- karpathy/diff_surgeon.py: 0 findings on staged diff
3 stdlib Python tools with deterministic logic:
- model_buildvsbuy_calculator.py — Returns API/FINE_TUNE/BUILD recommendation,
3-year TCO across 6 paths, breakeven analysis. Balances economic crossover
with practical feasibility (data availability, ML team capacity, compliance).
Embedded sample (B2B customer support, 4M queries/mo) -> API recommended
despite breakeven crossed, because no fine-tune data + 1-engineer ML team.
- ai_risk_classifier.py — Returns EU AI Act tier (PROHIBITED/HIGH/LIMITED/
MINIMAL) with 7 Article citations + US state triggers (NYC LL 144, CO AI
Act, IL HB 53, CA SB 1001, IL BIPA) + industry overlays (FDA, CFPB, NAIC,
ECOA, Fed SR 11-7). Sample (AI hiring in EU+NY+CO+IL+CA) -> HIGH,
conformity required, 3 US triggers, 14 controls.
- ai_cost_economics.py — Returns API costs (3 tiers) + self-hosted costs (low/
mid/high GPU rates with 24/7 warm + ops attribution) + breakeven analysis.
Reveals key insight: self-hosted floor makes API economics dominate at
typical B2B SaaS scale. Sample (5M tokens/day, 750M/mo) -> API at $1,500/mo
beats self-hosted at $13,450/mo by 9x; breakeven at 6.7B tokens/mo.
4 in-depth references, each citing 5+ authoritative sources:
- model_buildvsbuy_strategy.md — 3 paths with failure modes, 6 fine-tuning
approaches ranked by cost (RAG/LoRA/full FT/RLHF/DPO/continued pre-training),
decision tree, eval-first discipline. Cites Anthropic/OpenAI/Google/Meta
model cards, LoRA paper, RLHF paper, DPO paper, Stanford CRFM Foundation
Models report, Foundation Models and Fair Use (Henderson et al.).
- ai_risk_governance.md — Full EU AI Act tier map (Art. 5 prohibited, Art. 6
+ Annex III high-risk, Art. 50 limited-risk) with all 8 high-risk domains
+ 11 obligation articles. NIST AI RMF 1.0. US state patchwork (9 laws).
Industry overlays (FDA AI/ML, CFPB, NYDFS, NAIC). 10-item governance
program checklist. When-to-hire-AI-counsel criteria.
- ai_cost_economics.md — 2026 API pricing (4 tiers), GPU rental (A100/H100/
H200/B200), throughput estimates, GPU count by model size, utilization
reality (20-80%), 6 hidden costs of self-hosted, 6 hidden costs of API,
migration cost, prompt caching as economics lever. Cites vLLM paper,
DistServe, HELM, Artificial Analysis.
- ai_team_org_evolution.md — 5-stage role map (pre-seed -> late-stage),
9-role definition table (AI engineer != ML engineer != research scientist),
AI team vs data team contrast (8 dimensions), 7 anti-patterns, hiring
sequencing rule. Cites Huyen "Designing ML Systems" + "AI Engineering",
State of AI Report.
cs-caio-advisor agent (c-level-agents/agents/cs-caio-advisor.md):
- Eval-demanding realist voice
- Hard rule: does not duplicate engineering AI/ML skills (rag-architect,
agent-designer, prompt-governance, self-eval, llm-cost-optimizer)
- Treats every AI use case as a hiring decision; pushes back on AI hype
/cs:caio-review slash command:
- 6-question forcing interrogation: eval set, hallucination SLO, regulatory
tier, model selection, cost trajectory, role-that-unblocks
- Routes to /cs:cdo-review, /cs:gc-review, /cs:ciso-review, /cs:cfo-review,
/cs:chro-review
cs-caio-advisor voice spec added to persona-voices.md.
Updates:
- c-level plugin.json: v2.5.2 -> v2.5.3 (31 skills, 11 cs-* agents)
- c-level-agents plugin.json: v1.2.0 -> v1.3.0 (11 agents, 19 commands)
- marketplace.json: both c-level entries; new CAIO keywords (chief-ai-officer,
caio, ai-strategy, model-buildvsbuy, eu-ai-act, ai-cost-economics)
- c-level CLAUDE.md: CAIO row added; agent + count tables updated
- Root CLAUDE.md: 265->266 skills, 30->31 cs-* agents, 364->367 tools,
494->498 references, 51->52 commands; v2.5.3 highlight section
- CHANGELOG.md: v2.5.3 entry with full rationale
Known follow-up (out of scope this PR): cs-general-counsel-advisor voice spec
still missing from persona-voices.md (carried from v2.5.1); separate PR.
Disclaimer in every output: not legal advice; not a replacement for AI
counsel on EU AI Act conformity; not a tactical AI/ML engineering skill.
https://claude.ai/code/session_012WtZMm5NJHqkYoRqA9fHMN
Closes the gstack-can't-touch lane: gstack has zero legal coverage; this is
the first plugin in the founder-mode lineup to outclass it on a domain it
doesn't even attempt. Legal exposure is where startups most often discover a
problem after it's expensive to fix.
New skill (c-level-advisor/skills/general-counsel-advisor/):
- SKILL.md with 4 workflows (contract review, term sheet response, IP hygiene
audit, regulatory trigger assessment), keywords, output standards
- scripts/contract_risk_scanner.py — scans contract text for 12 founder-killer
patterns (auto-renew traps, uncapped indemnity, vague IP, aggressive
non-compete, missing DPA when personal data flows, MFN pricing, perpetual
license-back, one-sided force majeure/venue/audit, broad non-solicit).
Stdlib-only, JSON+text output, --help. Smoke-tested: 7 findings on embedded
sample MSA across CRITICAL/HIGH/MEDIUM.
- scripts/term_sheet_analyzer.py — scores term sheet 0-100 across 12 dimensions
(liquidation preference, anti-dilution, option pool pre/post-money, board,
vesting, pro-rata, drag-along, protective provisions, info rights, dividends,
valuation, holistic). Stdlib-only, JSON-input + JSON+text output, --help.
Smoke-tested: founder-friendly Series A sample scores 94/100.
- references/contracts_playbook.md — 7 startup contract types with top redlines
- references/ip_and_regulatory.md — IP strategy + regulatory trigger matrix
(HIPAA/GDPR/FDA/fintech/AI Act) + SOC 2 -> ISO sequencing
- references/term_sheet_decoder.md — full glossary, founder-friendly defaults,
the 3 clauses that matter most, negotiation strategy
New agent (c-level-advisor/c-level-agents/agents/cs-general-counsel-advisor.md):
- Risk-paranoid persona orchestrating the skill
- Voice: "Before we sign, three things need to be settled in writing."
- Hard rule: never substitutes for licensed counsel; always escalates
Updates:
- /cs:gc-review SKILL.md: now points at the real skill + tools (was a planned-
skill placeholder before)
- c-level-advisor/.claude-plugin/plugin.json: v2.5.0 -> v2.5.1, description
updated to 29 skills (was 28)
- c-level-advisor/c-level-agents/.claude-plugin/plugin.json: v1.0.0 -> v1.1.0,
9 cs-* agents (was 8)
- marketplace.json: both c-level entries bumped, +contract-review, +term-sheet,
+ip-strategy keywords
- c-level-advisor/CLAUDE.md: General Counsel added to roles table; agents and
counts updated
- Root CLAUDE.md: 263 -> 264 skills, 28 -> 29 cs-* agents, 359 -> 361 Python
tools, 487 -> 490 references; v2.5.1 highlight section added
- CHANGELOG.md: full v2.5.1 entry with rationale
Disclaimer: every tool/reference/agent output reminds users this is not legal
advice; always engage qualified counsel. The skill is positioned as triage
before $500/hour counsel time, never as a substitute.
https://claude.ai/code/session_012WtZMm5NJHqkYoRqA9fHMN
The skill directory layout changed from depth-3 (category/skill/SKILL.md)
to depth-4+ (team/skills/skill-name/SKILL.md). The find command in
convert.sh still used -mindepth 3 -maxdepth 3, causing "No skills found"
errors. Updated to -mindepth 4 -maxdepth 6 and excluded integrations/ to
avoid picking up already-converted output.
Co-authored-by: Cursor <cursoragent@cursor.com>
Bitdefender (and similar heuristic AV/EDR products) quarantine the
hunt-playbooks reference because it lists the command-line patterns
associated with LOLBin abuse (certutil -decode, regsvr32 /s /u /i:http
scrobj.dll, mshta URL, etc.). The strings appear inside markdown
tables and cannot execute from a .md file — this is defensive
threat-hunting documentation.
Added a banner at the top that:
- States the defensive-doc intent explicitly
- Lists the binaries cited and why they appear
- Tells affected users how to allow-list the path
- Links to the tracking issue
Closes#533
The /si:extract command and its skill-extractor agent had no guard
against the Claude Code skill-spec reserved name fragments. Users
reported the agent autogenerating skills like 'claude-code-settings',
'claude-mcp-tools', etc. — all of which violate the spec.
- Add explicit reserved-fragment rule to both the slash-command
SKILL.md and the agent definition.
- Recommend the 'cc-' prefix for Claude Code-specific skills
(cc-settings, cc-maintenance, cc-mcp-tools).
- Add the check to both quality-gate checklists so the agent
surfaces a rename before writing files.
Closes#537
Five SKILL.md files linked to references/*.md files that don't exist
on disk:
- onboarding-cro, paywall-upgrade-cro, page-cro → references/experiments.md
- programmatic-seo → references/playbooks.md
- seo-audit → references/ai-writing-detection.md, references/aeo-geo-patterns.md
The 4 CRO/pSEO links pointed to placeholder content that was never
authored — removed the link lines (the surrounding sections still
hold the substantive guidance). The seo-audit References section is
re-anchored to the 4 reference files that actually exist
(seo-audit-reference, cwv-thresholds, eeat-framework, schema-types).
Closes#586
The lowercase pull_request_template.md was an exact duplicate of
PULL_REQUEST_TEMPLATE.md. On case-insensitive filesystems (Windows,
default macOS), git clone emits a path-collision warning and only
one file lands in the working tree.
Closes#545
Promotes the 11 commits accumulated on dev since v2.4.4 into a tagged
release before opening the dev->main PR.
Version bumps (root-level only — per-skill version stamps unchanged):
.claude-plugin/marketplace.json metadata.version: 2.4.4 -> 2.4.5
CLAUDE.md 'Version:' headers (x2): v2.4.4 -> v2.4.5
CLAUDE.md 'Last Updated': May 10 -> May 11, 2026
Deliberately NOT bumped:
- slo-architect plugin version (marketplace.json line 643) stays 2.4.4
-- that's the skill's own release stamp, not the repo version
- SKILL.md frontmatter versions in engineering/skills/slo-architect/
and engineering/slo-architect/skills/slo-architect/ -- same reason
CHANGELOG.md changes:
- [Unreleased] block renamed to [2.4.5] - 2026-05-11
- Title broadened to include 'Count-Truth Reconciliation' alongside the
original 'Skill Expansion Phase 1+2+3+4 (+ ship-gate)'
- 'Changed' totals corrected to file-system truth:
Skills: 235 -> 246 (was claimed 235 -> 238)
Tools: 314 -> 359 (was claimed 314 -> 325)
References:435 -> 485 (was claimed 435 -> 447)
Agents: added (28 -> 27, was missing)
Commands: 27 -> 33 (was claimed 27 -> 30)
Plugins: added (30 -> 33, was missing)
- 'Fixed' subsection: added bullets for #608 (count corrections) and
#609 (marketplace registry + integrations.md), plus
skill-security-auditor self-skip fix
Why the v2.4.4 unreleased totals were wrong: the entry was drafted
mid-cycle and never reconciled before tagging. #608/#609 caught the
drift. The v2.4.5 totals now reproduce from one find/python3 command
each (commands documented inline in the changelog bullets).