mirror of
https://github.com/alirezarezvani/claude-skills.git
synced 2026-08-28 04:24:58 +00:00
Fourth review on PR #947 reported two functional bugs, explicitly noting it had not run anything. Both reproduced, and the first is severe. 1. F1 -- the blocking gate -- could be bypassed by a typo. _check_forgetting_rule() failed only when `rule` was literally "none"/""/"never", and otherwise inferred PASS from what the rule was *not*. So anything unrecognized fell through to the PASS branch with an empty mechanism list. Reproduced: {"rule": "asdf"} -> F1=PASS "Forgetting is designed: ." {"rule": "ttl"} (no ttl_days)-> F1=PASS "Forgetting is designed: ." A misspelling silently passed the one check this entire skill is built around, and the nonsensical detail string was the only hint. The check is now allowlist-based: PASS is unreachable unless a concrete mechanism is actually found (ttl_days > 0, max_records/max_bytes > 0, or a decay setting). Failure messages now distinguish an unrecognized rule from a declared-but-unconfigured one, so a typo is never mistaken for a deliberate decision not to forget. Booleans are rejected where a number is expected, and ttl_days=0 counts as absent. Verified across 10 cases: all six bypass variants now FAIL at exit 4, all four legitimate mechanisms still PASS, and the empty-mechanism string can no longer be emitted. 2. --print-sample-spec was unreachable on all three scripts that offer it. The flag sat outside a mutually-exclusive group declared required=True, and argparse enforces that during parse_args() -- before any of our code runs. So the flag alone exited 2 with a usage error, which broke the first line of the workflow SKILL.md documents verbatim: python scripts/memory_cost_profiler.py --print-sample-spec > workload.json The group is now required=False with explicit post-parse validation, so no-args still errors helpfully and names all valid entry points. Verified the full round-trip on all three: --print-sample-spec > f.json, then feed f.json back in. This slipped through because the PR's own checklist covered --help, --sample and --output json, but never ran --print-sample-spec standalone. Also removed the identity dict in render() flagged as a nit. Verified: 4/4 scripts help/sample/json; error paths 3/4/4; all six blocking gates; checklist 6/6 PASS; security auditor PASS (0 critical, 0 high, 0 info). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jt1sqt5kQmopyfXu2Hhjnv |
||
|---|---|---|
| .. | ||
| .claude-plugin | ||
| .codex | ||
| agent-harness | ||
| agenthub | ||
| autoresearch-agent | ||
| behuman | ||
| book-to-skill | ||
| caveman | ||
| chaos-engineering | ||
| claude-coach | ||
| code-tour | ||
| collab-proof | ||
| data-quality-auditor | ||
| demo-video | ||
| docker-development | ||
| feature-flags-architect | ||
| grill-me | ||
| grill-with-docs | ||
| handoff | ||
| helm-chart-builder | ||
| karpathy-coder | ||
| kubernetes-operator | ||
| llm-cost-optimizer | ||
| llm-wiki | ||
| memory-engineering | ||
| minimalist | ||
| prompt-governance | ||
| security-guidance | ||
| skillopt-sleep | ||
| skills | ||
| slo-architect | ||
| statistical-analyst | ||
| strict-api | ||
| terraform-patterns | ||
| universal-scraping-architect | ||
| workflow-builder | ||
| write-a-skill | ||
| zero-hallucination-coder | ||