feat: add docs-hygiene plugin - #57
Conversation
Bundles five documentation-hygiene skills adapted repo-agnostic from the authoring repo: compress (flavor-trim behind a mandatory fresh-context semantic-diff audit, optional caveman-plugin backend with in-session fallback), declutter (read-only five-shape noise classifier with internalized shape definitions and treatments), extract-ssot (Rule-of-Three deduplication with refuse-fast verification gates), encapsulation-audit (skill-private-surface citation detector shipping its own public-surface contract), and rename-references (12-form stale reference sweep). Source-repo rule citations are internalized or routed to the consuming repo's own CLAUDE.md/rules; scripts resolve paths relative to themselves and are read-only with zero network egress; eval suites are intentionally not shipped (the eval runner is authoring-repo-side). Co-Authored-By: Claude <noreply@anthropic.com>
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_ba0b460a-9eef-4e22-9e04-14d8e499c295) |
There was a problem hiding this comment.
Stale comment
Risk: medium. Not approving because Cursor Bugbot skipped (usage limit reached) and did not provide a clean automated review signal. Human review is needed; no reviewers were assigned because no suitable non-author maintainers were identified in this repository.
Sent by Cursor Approval Agent: Pull Request Router and Approver
…iene # Conflicts: # .claude-plugin/marketplace.json # README.md
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_504a51b9-37d9-4649-83f5-562bcfc709ae) |
|
Claude finished @kyle-sexton's task in 3m 58s —— View job PR Review:
|
There was a problem hiding this comment.
Stale comment
Risk: medium. Not approving because Cursor Bugbot skipped (usage limit reached) and did not provide a clean automated review signal. Human review is needed; no reviewers were assigned because no suitable non-author maintainers were identified in this repository.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a1731b8c9e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
detect.sh now expands directory targets to the .md files inside them so `detect.sh <dir>` batch-audits instead of silently skipping non-files; emit-verify-facts.sh passes patterns to git grep via -e so a dash-prefixed cluster phrase (e.g. --no-verify) is not parsed as an option. Both fixes carry regression test cases. Co-Authored-By: Claude <noreply@anthropic.com>
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_81ea0092-d2dc-4ea4-aaf2-314b17b46f91) |
|
Claude finished @kyle-sexton's task in 2m 10s —— View job PR Review:
|
There was a problem hiding this comment.
Stale comment
Risk: medium. Not approving because Cursor Bugbot skipped (usage limit reached) and did not provide a clean automated review signal. Human review is needed; no reviewers were assigned because no suitable non-author maintainers were identified in this repository.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d9b1bf3f0d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…iene # Conflicts: # .claude-plugin/marketplace.json # README.md
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_0e3fe30c-22eb-4fe2-a251-72ec2a88287d) |
|
Claude finished @kyle-sexton's task in 2m 48s —— View job PR Review:
|
There was a problem hiding this comment.
Risk: medium. Not approving because Cursor Bugbot did not complete successfully and did not provide a clean automated review signal. Human review is needed; no reviewers were assigned because no suitable non-author maintainers were identified in this repository.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e19b05cb79
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Closes melodic-software/medley#1293. Publishes the `fable-5-playbook` plugin per `docs/MIGRATION-PLAYBOOK.md` (per-plugin gate + acceptance security review). ## What ships - `plugins/fable-5-playbook/` — one knowledge skill (`/fable-5-playbook:fable-5-playbook`): Claude Fable 5's operating doctrine, authored by Fable 5 as introspected standing instructions. Core doctrine arms the session on invocation; twelve trigger-routed chapters under `context/` (calibration, reasoning-moves, problem-framing, planning, execution, debugging, orchestration, verification, communication, recovery, context-economy, trust-and-authority) plus `context/opus-adaptation.md` for non-Fable models. - Marketplace entry: `category: learning`, tags `knowledge` + component tags. Explicit `version: 0.1.0` in `plugin.json` only. - The source skill was already repo-agnostic (no repo-specific paths, tools, or slash references); the only content deltas from the source are the frontmatter description compressed to two sentences and one typo fix (`mis-framed` → `misframed`). ## Gate evidence - `claude plugin validate ./plugins/fable-5-playbook --strict` — PASS; `claude plugin validate . --strict` (catalog) — PASS - `claude plugin details` token cost: **~207 tok always-on**, ~4.7k on-invoke (single skill) - markdownlint 0 errors (15 files); typos clean; editorconfig-checker clean - `--plugin-dir` smoke test in a clean non-source repo — PASS: skill invoked, answered the four meta-rules (Precedence, One home per doctrine, Model adaptation, Silent application), namespace confirmed as `fable-5-playbook:fable-5-playbook` ## Security review (playbook acceptance) - Pure knowledge skill: no hooks, no MCP servers, no agents, no `userConfig`, no scripts, no state, zero network access. - Cache isolation: all references are skill-internal (`context/*.md` self-citations); no `../` reach-outs. - No PII / secrets. Merge note: open PRs #53, #56, #57 also touch `marketplace.json` + root `README.md` — merge serially; later ones rebase/merge the two shared files (this branch is based on post-context7 main, so it conflicts only with those unmerged siblings). <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > Markdown-only plugin packaging and catalog updates; no executable code, credentials, or runtime side effects beyond skill text loaded into Claude Code. > > **Overview** > Adds the **`fable-5-playbook`** plugin to the marketplace and root catalog — a pure knowledge skill (no hooks, MCP, scripts, or `userConfig`) that arms sessions with Claude Fable 5’s operating doctrine. > > **`SKILL.md`** loads core standing instructions on invoke (bare / `full` / chapter name), defines four meta-rules, effort floors, a chapter routing table, and cites twelve on-demand **`context/*.md`** chapters (calibration through trust-and-authority) plus mandatory **`opus-adaptation.md`** for non-Fable models. Plugin **`README.md`** and **`plugin.json`** (`0.1.0`, learning category) document install and scope. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 03fa989. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> Co-authored-by: Claude <noreply@anthropic.com>
Closes melodic-software/medley#1296. Publishes the `firecrawl` plugin per `docs/MIGRATION-PLAYBOOK.md` (per-plugin gate + acceptance security review). ## What ships - `plugins/firecrawl/` — one skill (`/firecrawl:firecrawl`): wraps the `firecrawl-cli` binary for scrape/search/crawl/map/parse/interact/agent/monitor with the core write-to-disk-then-Read pattern (results land in tempfiles via `-o`; the agent reads only the needed slice — 32–35× token savings vs the MCP per the Scalekit benchmark cited in the skill). - `context/commands.md` (full flag tables, carried verbatim), `context/configuration.md` + `context/update-flow.md` (adapted repo-agnostic). - Maintainer-facing `scripts/update.sh` (`--check` read-only CLI-version + upstream-SHA drift report; `--apply` npm upgrade + `UPSTREAM.md` rewrite behind approval gates; never touches SKILL.md — content integration is a gated manual step) with a new self-contained `update.test.sh` (17 checks, network-free). - `UPSTREAM.md` sidecar (SHA-tracking sync state + rollback version). - Marketplace entry: `category: utilities`. Explicit `version: 0.1.0` in `plugin.json` only. ## Gate evidence - `claude plugin validate ./plugins/firecrawl --strict` — PASS; catalog `--strict` — PASS - `claude plugin details` token cost: **~253 tok always-on**, ~4.9k on-invoke - `update.test.sh` 17/17 PASS; shellcheck (repo rcfile) clean; shfmt clean; markdownlint 0 errors; typos clean; editorconfig-checker clean - Smoke test via `--plugin-dir` — PASS: skill body loaded, answered the write-to-disk flag (`-o`) from the body, namespace confirmed as `firecrawl:firecrawl`. The smoke run surfaced two real headless-permission defects that are fixed in this PR: a credential-shaped `printenv FIRECRAWL_API_KEY` preamble line was rejected by permission preflight (removed — `firecrawl --status` already reports auth), and the status/sync preamble lines needed narrow `allowed-tools` grants (`Bash(command -v firecrawl*)`, `Bash(firecrawl --status*)`, `Bash(grep -m1 *UPSTREAM.md*)`). Caveat: in a fully sandboxed scratch dir the preamble lines may still fall back to their error text; the skill body loads and functions regardless. ## Security review (playbook acceptance) - No hooks, no MCP servers, no agents, no `userConfig`. - Data egress (normal invocation): the user-installed `firecrawl-cli` calls `api.firecrawl.dev` (or a self-hosted `FIRECRAWL_API_URL`) — that is the plugin's documented purpose. The credential is the consumer-owned `FIRECRAWL_API_KEY` env var; never stored in or written by the plugin. Env-var auth is preferred over `firecrawl login`/`config` explicitly to avoid a second credential store. - Data egress (update path, maintainer-invoked only): `registry.npmjs.org` (version metadata) + `www.firecrawl.dev` (upstream skill source, hashed in a tmpdir). `npm install -g` and any SKILL.md rewrite sit behind two explicit approval gates; `--check` is read-only. - The skill hard-prohibits `firecrawl init` (would install a parallel MCP + skill copy) and documents the login/config divergence risk. - Cache isolation: script resolves paths relative to itself; preamble reads its own `UPSTREAM.md` via the skill-dir substitution; no `../` reach-outs. - No PII / secrets. Merge note: open PRs #53, #56, #57, #59 also touch `marketplace.json` + root `README.md` — merge serially; later ones need a conflict-merge of the two shared files. <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Medium Risk** > New plugin steers agents toward external Firecrawl API egress and credit use via a user-installed CLI and `FIRECRAWL_API_KEY`; maintainer `--apply` runs `npm install -g`, but there are no hooks/MCP and updates are gated. > > **Overview** > **Adds a new `firecrawl` plugin** to the marketplace and root catalog, shipping `/firecrawl:firecrawl` as the maintained `firecrawl-cli` integration (scrape, search, crawl, map, parse, interact, agent, monitor) instead of the Firecrawl MCP. > > The skill centers on **write-to-disk then `Read`** (`-o` tempfiles) with escalation tables for when to use Firecrawl vs WebFetch, narrow **`allowed-tools`** for the status/sync preamble (`firecrawl --status`, `UPSTREAM.md` grep), and prohibitions against `firecrawl init` / login-style config drift. Supporting **`context/`** docs cover flags, env defaults, and the maintainer update pipeline; **`UPSTREAM.md`** records upstream SHA and CLI rollback versions. > > **Maintainer tooling:** `scripts/update.sh` (`--check` read-only drift vs npm + upstream skill; `--apply` global `npm install` + `UPSTREAM.md` rewrite only, not `SKILL.md`) and network-free **`update.test.sh`** regression checks. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 3184b4e. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> Co-authored-by: Claude <noreply@anthropic.com>



Closes melodic-software/medley#1285.
Publishes the
docs-hygieneplugin perdocs/MIGRATION-PLAYBOOK.md(per-plugin gate + acceptance security review). One cohesive capability — documentation hygiene — bundling five skills.What ships
/docs-hygiene:compress— flavor-trims markdown behind a mandatory fresh-context semantic-diff audit that reverts any semantic loss; optionalcavemanplugin backend (qualified/caveman:compressinvocation, graceful in-session Edit fallback); optional snapshots persist under the plugin data directory./docs-hygiene:declutter— read-only classifier for five markdown noise shapes with internalized shape definitions, tier semantics, exemptions, and opt-out markers (no source-repo rule dependencies)./docs-hygiene:extract-ssot— Rule-of-Three deduplication into a single source of truth with refuse-fast verification gates and internalized evidence discipline./docs-hygiene:encapsulation-audit— detects citations into skill-private surfaces; ships its owncontext/public-surface-contract.md; detector generalized to scan any consumer repo's instruction surfaces./docs-hygiene:rename-references— 12-form stale-reference pattern library (slash tokens, moved-file relative paths, frontmatter chains/globs) with audit, half-rename, and apply modes.Adaptation notes: source-repo rule citations internalized or routed to the consuming repo's own CLAUDE.md/rules; scripts resolve paths via BASH_SOURCE and scan the repo they run in;
${CLAUDE_SKILL_DIR}anchors all script invocations; taught placeholder names written without dollar-brace wrappers (substitution lesson from PR #53); eval suites intentionally NOT shipped (the eval runner is authoring-repo-side; shipping them would be dead weight with broken references).Gate evidence
claude plugin validate ./plugins/docs-hygiene --strict— PASS;claude plugin validate . --strict(catalog) — PASSclaude plugin detailstoken cost: ~1,161 tok always-on (compress ~340, declutter ~280, encapsulation-audit ~150, extract-ssot ~170, rename-references ~230); on-invoke ~2.6k–6.4k per skill--plugin-dirsmoke test in a clean non-source repo — PASS:/docs-hygiene:declutterinvoked, answered the five noise shapes, namespace confirmed asdocs-hygiene:declutterSecurity review (playbook acceptance)
userConfig.httphit is a URL string inside a test fixture).compresscan delegate mechanical compression to the third-partycavemanplugin ONLY when the consumer has installed it; detection is capability-probing, invocation is the qualified/caveman:compressform, and the built-in fallback keeps the skill fully functional without it. No other plugin is referenced.../reach-outs; state (optional compress snapshots) goes to the plugin data directory.Merge note: PRs #53 and #56 also touch
marketplace.json+ rootREADME.md— the playbook prescribes serializing final merges; whichever lands later rebases the two shared files.Note
Low Risk
Documentation and read-only/local shell tooling only—no hooks, MCP, network calls, or automatic repo writes beyond what users invoke via skills; optional third-party
cavemancompression is opt-in.Overview
Adds the
docs-hygieneplugin to the marketplace catalog and root README, bundling five on-demand skills for keeping tracked markdown lean, deduplicated, and correctly referenced in any consumer repo./docs-hygiene:compresstightens prose by cutting flavor while a mandatory fresh-context semantic-diff pass reverts semantic loss; it optionally uses thecavemanplugin as a mechanical backend with an in-session Edit fallback, snapshots, andmarkdownlint-cli2gates.declutteris read-only noise classification (five shapes, tiered findings) backed bydetect.shand shared shape detectors.extract-ssotencodes Rule-of-Three markdown dedup withidentify/verify/plan/execute/batch/unwind, private action docs, andemit-verify-facts.sh.encapsulation-auditshipspublic-surface-contract.mdplusdetect.sh(private skill paths, heading anchors, schemas;scripts/carve-out).rename-referencesis documented as the post-rename sweep skill (12-form patterns); sibling skills cite it after migrations.Scripts are repo-local, read-only where applicable, always-exit-0 or explicit exit codes for audits, and covered by self-contained bash test suites (
detect-caveman, declutter, encapsulation-audit, extract-ssot).Reviewed by Cursor Bugbot for commit e19b05c. Bugbot is set up for automated code reviews on this repo. Configure here.