Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions PROVENANCE.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,13 +4,13 @@
"bundles": [
{
"name": "engineering-workflow",
"version": "0.9.9",
"version": "0.9.10",
"source_repository": "https://github.com/xeonvs/codex-engineering-workflow",
"source_policy": "latest-tag",
"source_ref": "v0.9.9",
"source_commit": "e73c8af994350ae0e463ab8856dff12b761f12ee",
"source_ref": "v0.9.10",
"source_commit": "5db6b8422e39a84c090ff52b60861f7642152f55",
"source_path": "plugins/engineering-workflow",
"bundle_sha256": "5aa3b74527d7cd4260ef90223222e3c2e998fae016b3c02919de676449f2e0f3"
"bundle_sha256": "65ea54e0f3bacedca91dd73a0ad7bd9f36ad6f2617fc0c4809edc54902e6931a"
},
{
"name": "tgrep-search",
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ reviewed local bundle held in this repository.
<!-- BEGIN GENERATED PLUGIN VERSIONS -->
| Plugin | Version | Purpose | Canonical source |
| --- | --- | --- | --- |
| [`engineering-workflow`](plugins/engineering-workflow/) | 0.9.9 | Audit, plan, migrate, validate, and maintain repository engineering workflows. | [`xeonvs/codex-engineering-workflow`](https://github.com/xeonvs/codex-engineering-workflow) |
| [`engineering-workflow`](plugins/engineering-workflow/) | 0.9.10 | Audit, plan, migrate, validate, and maintain repository engineering workflows. | [`xeonvs/codex-engineering-workflow`](https://github.com/xeonvs/codex-engineering-workflow) |
| [`tgrep-search`](plugins/tgrep-search/) | 1.0.3 | Search local source trees efficiently with the tgrep trigram index. | [`xeonvs/tgrep-search`](https://github.com/xeonvs/tgrep-search) |
<!-- END GENERATED PLUGIN VERSIONS -->

Expand Down
2 changes: 1 addition & 1 deletion plugins/engineering-workflow/.claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "engineering-workflow",
"version": "0.9.9",
"version": "0.9.10",
"description": "Audit, plan, migrate, validate, and maintain repository engineering workflows.",
"author": {
"name": "xeonvs",
Expand Down
2 changes: 1 addition & 1 deletion plugins/engineering-workflow/.codex-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "engineering-workflow",
"version": "0.9.9",
"version": "0.9.10",
"description": "Audit, plan, migrate, validate, and maintain repository engineering workflows.",
"author": {
"name": "xeonvs",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
name: engineering-workflow
description: Set up, audit, or upgrade repository workflow instructions and planning. Use for workflow changes or explicit skill refresh/update; ordinary repository work does not invoke migration.
metadata:
version: 0.9.9
version: 0.9.10
---

# Engineering Workflow
Expand Down Expand Up @@ -64,6 +64,7 @@ Use this skill for the workflow layer around a repository. Keep product, domain,
- Host capability boundaries and verified Codex/Claude integrations: `references/platform_compatibility.md`
- Programmatic tool routing, agent routing, and shared-state ownership: `references/agent_orchestration.md`
- Current capability-to-model mapping: `references/model_profiles.md`
- Claude Code project-agent model mapping after explicit opt-in: `references/claude_model_profiles.md`
- Installed-skill refresh and update: `references/skill_update.md`
- Target workflow migration: `references/target_workflow_upgrade.md`
- Validation command and isolation policy: `references/validation_safety.md`
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
---
name: workflow-explorer
description: Collect bounded read-heavy repository evidence for the root.
tools: Read, Grep, Glob
model: sonnet
effort: medium
---

Inspect only the path scope and accessible inputs in the root's self-contained packet. Do not edit files, write shared state, or spawn child agents. Return status, distilled findings, file references, checks performed, blockers, and accessible artifact paths. Keep raw output bounded; report an inaccessible required input instead of reconstructing missing context. Stop when the requested evidence is sufficient.
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
---
name: workflow-reviewer
description: Review a bounded change packet for correctness and risk, then report findings to the root.
tools: Read, Grep, Glob
model: sonnet
effort: medium
---

Review only the self-contained change packet and accessible evidence supplied by the root. Do not edit files, write shared state, or spawn child agents. Return status; findings with severity, confidence, exact evidence paths, and assumptions; checks performed; blockers; and the stopping or escalation condition. State clearly when there are no findings. Report missing required context rather than inferring it.
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
name: workflow-utility
description: Handle small bounded semantic checks and return a compact result to the root.
tools: Read, Grep, Glob
model: haiku
---

Use only the self-contained packet and accessible inputs supplied by the root. Do not expand scope, edit files, write shared state, or spawn child agents. Return status, concise findings, evidence paths, blockers, `needs_escalation`, and whether the stopping condition was met. If a required input is inaccessible, report that blocker instead of guessing. Make at most one transient retry when the packet permits it.
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,7 @@ plan_archive_indexes:
- docs/README.md
active_plan: PLANS.md
runtime_agent_config_managed: false
runtime_claude_agent_config_managed: false
instruction_contract_version: 3
planning_contract_version: 2
orchestration_contract_version: 3
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
# Claude Code Model Profiles

Use this file only in Claude Code as the canonical owner of concrete Claude model and effort recommendations. `agent_orchestration.md` owns task-shape routing; `platform_compatibility.md` selects the invoking host. These profiles apply only when the user explicitly opts in to project-level Claude Code agents during a target workflow upgrade.

## Source Snapshot

Verified against the official Claude Code [subagent](https://code.claude.com/docs/en/sub-agents) and [model configuration](https://code.claude.com/docs/en/model-config) documentation on 2026-09-25. Check the active client's model availability, provider restrictions, and supported effort levels when invoking a profile; a repository upgrader cannot infer those properties from project files alone.

## Claude Capability Mapping

| Route | Claude Code model | Effort | Project agent |
| --- | --- | --- | --- |
| Bounded semantic utility | `haiku` | Inherit the client's choice; no fixed `effort` field | `workflow-utility` |
| Read-heavy exploration | `sonnet` | `medium` | `workflow-explorer` |
| Evidence-first review | `sonnet` | `medium` | `workflow-reviewer` |
| Bounded implementation | `sonnet` | `medium` | Select natively for the task; no persistent project agent is required |

The three optional project agents are read-only and cannot spawn child agents. The root supplies each agent a bounded, self-contained packet with accessible paths and a stopping condition. The utility handles small semantic work, not deterministic commands or polling. Review findings return to the root for acceptance and final validation.

Reserve `opus` for exceptionally difficult, high-consequence semantic work when the user selects it or confirms a proposed escalation. Give the concrete quality or risk reason before proposing that escalation. A user-selected Opus session already provides the choice. Do not change the session's model or create a persistent Opus profile on the agent's initiative.

## Configuration Boundary

The target upgrader creates `.claude/agents/workflow-{utility,explorer,reviewer}.md` only after the separate Claude opt-in or a valid workflow state recording that prior choice. The existing Codex opt-in does not imply Claude opt-in. An existing agent definition is replaceable only when its complete bytes match a registered prior generated template; preserve customized model pins and instructions. Keep `CLAUDE.md`, native settings, and unrelated agents under their existing owners.

Claude Code's model choice can be constrained by the invoking client, provider, and managed policy; effort can be capped. Report an unavailable model or restriction instead of silently substituting a model, weakening a restriction, or mutating global settings. Do not set `CLAUDE_CODE_SUBAGENT_MODEL_FORCE`: it overrides the per-agent model field and defeats role-based selection. The same effort label is not equivalent across different models or providers.
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ Select this mode only when the actual invoking host is Codex. Codex mode may use

Select this mode only when the actual invoking host is Claude Code. When invoked as `/engineering-workflow:engineering-workflow`, explicitly read the target repository's applicable root and nested `AGENTS.md` files as workflow artifacts before acting. Do not claim that Claude Code automatically discovers or applies Codex-specific `AGENTS.md` semantics.

Preserve Claude Code's native session, built-in-agent, and custom-agent model/effort choices, including provider and managed-setting restrictions. Do not set a per-call model/effort override merely because a Codex role recommends one. Model aliases and available effort levels depend on the Claude client, provider, and selected model; matching effort names do not establish equivalent reasoning across providers. Native `CLAUDE.md`, rules, permissions, and existing `.claude` configuration remain authoritative within the host's instruction hierarchy.
Preserve Claude Code's native session, built-in-agent, and custom-agent model/effort choices, including provider and managed-setting restrictions. Do not set a per-call model/effort override merely because a Codex role recommends one. For an explicitly requested project-agent opt-in, use the Claude-only mapping in `claude_model_profiles.md` and retain its ownership and availability checks. Model aliases and available effort levels depend on the Claude client, provider, and selected model; matching effort names do not establish equivalent reasoning across providers. Native `CLAUDE.md`, rules, permissions, and existing `.claude` configuration remain authoritative within the host's instruction hierarchy.

For continuation, delegation scope, and handoff, read the shared Default Route, Task Continuity And Handoff, Subagent Contract, and Monitoring And Long-Running Work sections of `agent_orchestration.md`. Use only delegation and waiting capabilities exposed by Claude Code; the skill does not enable agent teams, recursive delegation, or experimental workflows. Keep bounded independent work with the root when native delegation is unavailable.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,15 +16,16 @@ Use this canonical reference for `upgrade_target_workflow`, which migrates the w
10. Mutation Boundaries
11. Apply Sequence
12. Codex Configuration
13. Workflow State Manifest
14. Validation And Rollback
13. Claude Code Configuration
14. Workflow State Manifest
15. Validation And Rollback

## Prompt Invocation

Treat `Upgrade A Target Workflow` plus a target repository as an authorized repo-changing prompt, not as a request for CLI instructions.

1. Resolve the target path and requested version from context; default to the installed skill version.
2. Before prompt apply, review target-local owners affected by the requested release's changed semantics when adoption has not already been established. For customized owners, preserve equivalent rules or make the narrow requested correction under the full planning and privacy gates; ask only for a real ownership conflict. A same-version stamp or `already_current` result proves structural state, not semantic adoption. Version 0.9.9 changes only the installed migration privacy-review boundary and requires no target-local instruction rewrite. Version 0.9.8 updates Codex model profiles and refreshes only exact prior generated agent templates when that configuration was already opted in; it requires no target-local instruction rewrite. Version 0.9.7 changes audit discovery and output only, so it also requires no target-local instruction rewrite. For the 0.9.6 changes, inspect the task-handoff route and efficient-execution owner for root working state, self-contained worker context, transient-versus-durable evidence, and artifact-based recovery. Use already-current evidence, and do not sweep unrelated owners. Then invoke `scripts/upgrade_target_workflow.py --prompt` yourself.
2. Before prompt apply, review target-local owners affected by the requested release's changed semantics when adoption has not already been established. For customized owners, preserve equivalent rules or make the narrow requested correction under the full planning and privacy gates; ask only for a real ownership conflict. A same-version stamp or `already_current` result proves structural state, not semantic adoption. Version 0.9.10 fixes custom archive index preservation and adds separately opted-in Claude project agents; it requires no target-local instruction rewrite. Version 0.9.9 changes only the installed migration privacy-review boundary and requires no target-local instruction rewrite. Version 0.9.8 updates Codex model profiles and refreshes only exact prior generated agent templates when that configuration was already opted in; it requires no target-local instruction rewrite. Version 0.9.7 changes audit discovery and output only, so it also requires no target-local instruction rewrite. For the 0.9.6 changes, inspect the task-handoff route and efficient-execution owner for root working state, self-contained worker context, transient-versus-durable evidence, and artifact-based recovery. Use already-current evidence, and do not sweep unrelated owners. Then invoke `scripts/upgrade_target_workflow.py --prompt` yourself.
3. Prompt mode builds and reviews the read-only migration report first.
4. If ownership, conflicts, privacy, and approvals are resolved, it proceeds through guarded apply and validation automatically.
5. If the result returns `agent_action: ask_targeted_question`, ask only `question_to_ask`; keep any later questions deferred and do not write target files.
Expand All @@ -34,7 +35,7 @@ Treat `Upgrade A Target Workflow` plus a target repository as an authorized repo

If the target already records the requested version, all canonical artifacts exist, instruction and index contracts pass, privacy/conflict checks are clear, no registered pristine bytes need an actual update, and any requested optional agent configuration is already fully present, prompt/apply returns `update_status: already_current` with an empty mutation log. It does not create a plan or rewrite state/index files merely to reconfirm that unchanged result. A missing artifact, older contract, drift, conflict, privacy boundary, or requested but incomplete optional configuration keeps the normal guarded path.

The user may explicitly request report-only behavior; then invoke `--plan`. New runtime agent configuration remains opt-in through the user's prompt and `--include-agent-config`; a valid workflow state manifest recording an earlier opt-in carries that choice into subsequent upgrades.
The user may explicitly request report-only behavior; then invoke `--plan`. Codex runtime agent configuration remains opt-in through the user's prompt and `--include-agent-config`; Claude Code project agents have a separate `--include-claude-agent-config` opt-in. A valid workflow state manifest recording either earlier choice carries only that choice into subsequent upgrades.

## CLI Contract

Expand All @@ -46,6 +47,7 @@ The user may explicitly request report-only behavior; then invoke `--plan`. New
- `--prompt`
- `--target-version`
- `--include-agent-config`
- `--include-claude-agent-config`
- `--approve-privacy-review`
- `--format json`

Expand All @@ -70,6 +72,7 @@ Inspect:
- `PLANS.md` and older execution-plan locations
- backlog, incident catalog, project principles, compatibility instructions, and equivalent names
- `.codex/config.toml` and `.codex/agents/*.toml`
- `.claude/agents/workflow-{utility,explorer,reviewer}.md` when Claude configuration is requested or previously opted in
- workflow state manifest and migration notes
- external tracker references
- repository-owned domain, product, architecture, QA, security, and operational documentation
Expand Down Expand Up @@ -160,7 +163,7 @@ Do not replace a customized shared file wholesale. Create missing files, replace
4. Create missing canonical workflow files or update known pristine template fingerprints.
5. Create/update managed navigation indexes without replacing unmarked repository prose.
6. Validate the complete instruction graph and indexes; stop before version stamping on any finding.
7. Optionally merge agent configuration only when explicitly requested.
7. Optionally merge each platform's agent configuration only when separately requested or recorded by valid prior state.
8. Write the state manifest with relative paths and contract versions.
9. Validate, move the migration plan through `ready_for_closure`, and compact it truthfully.
10. Re-run the public privacy scan immediately before success. Compare it with the in-memory approved pre-apply fingerprint multiset: a disappeared candidate is safe, while a new, changed, moved, or duplicated finding fails and rolls back, regardless of category.
Expand All @@ -183,6 +186,12 @@ When `--include-agent-config` is present or the target's valid workflow state re

Never place Responses API-only fields in Codex TOML.

## Claude Code Configuration

When `--include-claude-agent-config` is present or the target's valid workflow state records a prior Claude opt-in, apply the three project-agent templates under `.claude/agents/` using `claude_model_profiles.md` as the model and effort owner. The Codex flag or Codex state field alone never enables this step. Without Claude opt-in, leave `.claude/**` byte-for-byte unchanged.

Create missing project-agent files only after opt-in. Replace an existing agent file only when its complete bytes match a registered prior generated template. Preserve customized model pins, instructions, unrelated agents, `CLAUDE.md`, settings, and managed configuration. Refuse symbolic or unsafe target paths and keep partial writes within the common rollback transaction. Report an unavailable model or an administrative restriction without overriding the user's client or provider settings. Never set a global model or `CLAUDE_CODE_SUBAGENT_MODEL_FORCE`.

## Workflow State Manifest

Target path: `docs/codex/ENGINEERING_WORKFLOW_STATE.yaml`.
Expand All @@ -201,11 +210,12 @@ Required fields:
- `shared_paths`
- `protected_paths`
- `runtime_agent_config_managed`
- `runtime_claude_agent_config_managed`
- `instruction_contract_version`
- `planning_contract_version`
- `orchestration_contract_version`

Use repository-relative paths. Never record a workstation path, username, home directory, credential, or private hostname. The manifest governs only listed paths or explicit managed sections; it does not claim an entire documentation directory.
In a valid legacy manifest without `runtime_claude_agent_config_managed`, treat Claude configuration as not opted in; a prior Codex opt-in does not imply it. Use repository-relative paths. Never record a workstation path, username, home directory, credential, or private hostname. The manifest governs only listed paths or explicit managed sections; it does not claim an entire documentation directory.

## Validation And Rollback

Expand Down
Loading
Loading