Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .cursor/rules/skeleton.mdc
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,6 @@ alwaysApply: true
Follow [AGENTS.md](AGENTS.md) for cold-start and validation lanes.

- Docs / config (non-policy) → `bun run validate:changed -- <path>` or `bun run audit:self`
- Plugin-wired policy YAML → `bun run validate:changed -- <path>` (local → `audit docs` **and** `audit skills`; `audit self` alone is not enough)
- Skill body → `bun run audit:skills` (path-scoped validate exits non-zero)
- TypeScript → `bun test` + `bun run typecheck` + `bun run build`
- Plugin-wired policy YAML → `bun run validate:changed -- <path>` (runs full docs and owned-skill prose)
- Skill body → `bun run validate:changed -- <path>` (runs `audit skills`) or `bun run audit:skills`
- TypeScript → `bun test` + `bun run typecheck` + `bun run build`. `validate:changed` fails uncovered coverage-candidate paths
2 changes: 1 addition & 1 deletion .pre-commit-config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ repos:
hooks:
- id: skeleton-validate-staged
name: skeleton validate changed (staged)
entry: bun run validate:changed -- --staged
entry: bun src/cli.ts validate changed --staged
language: system
pass_filenames: false
- id: skeleton-test
Expand Down
18 changes: 9 additions & 9 deletions .skeleton/customize/code-review.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@

<!-- source-of-truth: skeleton-specific code-review overlays (validation ladder, invariant matrices, Action bar) -->

<!-- doc-meta: owner=eng | last-reviewed=2026-09-02 -->
<!-- doc-meta: owner=eng | last-reviewed=2026-09-13 -->

<!-- review-deps: paths=AGENTS.md,src/validate/changed.ts,docs/developer/validation.md -->
<!-- review-deps: paths=AGENTS.md,src/validate/**,docs/developer/validation.md -->

Injected on skill read. Prefer this overlay over portable thinned sections when both apply. Portable ledger / exit-gate rules still apply and must not be weakened.

Expand All @@ -14,11 +14,11 @@ Match [AGENTS.md](../../AGENTS.md) validation split:

| Change type | Run before claiming validate / merge-ready |
| ------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |
| TypeScript under `src/` | `bun test` (or scoped path) + `bun run typecheck` + `bun run build`; validate also audits documents whose `review-deps` match changed paths |
| Docs / config (non-policy) | `bun run validate:changed -- <path>` or `bun run audit:self` |
| Plugin-wired policy YAML under `.skeleton/` | `bun run validate:changed -- <path>` (local → `audit docs` **and** `audit skills`; `audit self` alone is not enough — excluded skill trees stay uncovered) |
| Owned skill body (`SKILL.md` trees) | `bun run audit:skills` — path-scoped validate exits non-zero and redirects here (`audit self` does not cover excluded skill trees) |
| Foreign / lockfile-synced skill body | skipped — lint in the owning skills/toolbox repo |
| TypeScript under `src/` | `bun test` + `typecheck` + `build`. `validate:changed` fails uncovered coverage-candidate paths and audits owning papers |
| Docs / config (non-policy) | `bun run validate:changed -- <path>` or `bun run audit:self` |
| Plugin-wired policy YAML under `.skeleton/` | `bun run validate:changed -- <path>` (runs full docs and owned-skill prose) |
| Owned skill body (`SKILL.md` trees) | `bun run validate:changed -- <path>` (runs `audit skills`) or `bun run audit:skills` |
| Foreign / lockfile-synced skill body | skipped — lint in the owning skills/toolbox repo |

`validate:changed` classifies code separately and leaves its correctness to native gates. It also discovers documents whose `review-deps` path or glob matched a changed file. A hash review-proof failure blocks until the document is re-read and explicitly attested. Code-only green is never code coverage.

Expand All @@ -43,7 +43,7 @@ Close themes only after variant coverage for applicable rows
| ---------------- | ------------------------------------------------------------------------------------------- |
| Input mixes | code with/without impacted docs, skill-only, policy-only, docs+policy, docs+skills, mixed inputs |
| Modes | local / pre-commit (no `--base`) vs CI `--base` |
| Fail posture | fail-closed redirects, fail-open “green means coverage” lies, orphan `.skeleton` YAML |
| Fail posture | uncovered-changed-path, stage-required, orphan `.skeleton` YAML, fail-open coverage lies |
| Policy | plugin-wired vs unwired YAML; `config.yaml` not treated as policy |
| Equivalence tips | `audit docs` / `audit skills` / `audit self` only when they truly cover the same corpus |
| Review mode | date compatibility vs hash proof; changed doc bytes vs changed target bytes |
Expand All @@ -57,7 +57,7 @@ Hotspots: `src/validate/changed.ts`, `AGENTS.md`, `docs/developer/validation.md`
| Trees | configured scan roots, `.agents`, `.claude`, other excluded skill dirs |
| Suites | path-scoped audit, bare `audit skills`, `audit self`, skills+prose-policy |
| Exclude behavior | `scan.exclude` vs deliberate include of excluded skill trees for skill-body prose |
| Policy prove | local redirect vs `--base` full docs + path-scoped skills prove |
| Policy prove | local and `--base` full docs + path-scoped skills prove |

Hotspots: `src/audit/core/collect.ts`, `src/audit/core/context.ts`, `src/audit/core/skill-roots.ts`, `src/audit/run.ts`.

Expand Down
Loading
Loading