mirror of
https://github.com/alirezarezvani/claude-skills.git
synced 2026-10-11 03:37:58 +00:00
A fourth automated review pass on PR #907 found the deviation count had drifted out of sync across the three places that document it, plus two more real gaps in the vendored plugin: 1. Deviation count inconsistency: plugin.json and README.md both said 13 (after round 3), but CLAUDE.md's v2.11.2 section said "8 deviations" with an itemized list that didn't map onto the real 13-item README list -- it named a "dead cross-reference to a non-vendored design doc" as a cosmetic item that was never actually added as a numbered README deviation (it was fixed in round 3's commit but never itemized). Fixed: added it as README deviation #14, updated plugin.json's derivation_note with a note that README.md's numbered list is the single source of truth if any summary disagrees again, and rewrote CLAUDE.md's bullet to match. 2. commands/skillopt-sleep.md's action table listed `schedule` as an ordinary action alongside safe previews (`status`/`dry-run`/`run`), while its own "Safety reminders" section separately said to point users at the print-only install-cron.sh instead -- two uncoordinated stories about the same action. scheduler.schedule() writes directly to the user's real crontab the moment it runs, with no confirmation step. Fixed (README deviation #15): "Steps to follow" now has an explicit step 1 telling the agent to confirm with the user before running `schedule`; "Safety reminders" no longer contradicts the action table. 3. state.json (the cross-night task archive) and .skillopt-sleep/staging/<ts>/'s proposal/report/diagnostics files contain real harvested session content in plaintext, created via plain os.makedirs/open(...,"w") -- world-readable-by-default on a typical multi-user box. Fixed (README deviation #16): state.py and staging.py now chmod every directory they create to 0700 and every file they write to 0600 (best-effort). Live CLAUDE.md/SKILL.md files are intentionally left alone -- those are the user's own, often-committed files, not new output this plugin introduces. All three documents (README.md's numbered list, plugin.json's derivation_note, CLAUDE.md's v2.11.2 section) now agree on 16 deviations (3 cosmetic, 13 safety/hardening) -- verified by grep. Verified: py_compile clean, mock-backend dry-run still exits 0, a synthetic test confirms state dir/state.json/staging dir/staging files land at 0700/0600/0700/0600 respectively after this fix (previously default umask permissions), all 4 repo CI gates pass locally. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TX374i2YGrjNV4Yi3AmaKS |
||
|---|---|---|
| .. | ||
| .claude-plugin | ||
| .codex | ||
| agent-harness | ||
| agenthub | ||
| autoresearch-agent | ||
| behuman | ||
| caveman | ||
| chaos-engineering | ||
| claude-coach | ||
| code-tour | ||
| collab-proof | ||
| data-quality-auditor | ||
| demo-video | ||
| docker-development | ||
| feature-flags-architect | ||
| grill-me | ||
| grill-with-docs | ||
| handoff | ||
| helm-chart-builder | ||
| karpathy-coder | ||
| kubernetes-operator | ||
| llm-cost-optimizer | ||
| llm-wiki | ||
| minimalist | ||
| prompt-governance | ||
| security-guidance | ||
| skillopt-sleep | ||
| skills | ||
| slo-architect | ||
| statistical-analyst | ||
| strict-api | ||
| terraform-patterns | ||
| universal-scraping-architect | ||
| workflow-builder | ||
| write-a-skill | ||
| zero-hallucination-coder | ||