fix(kyberforge): bridge apm content to Claude Code's flat plugin discovery

Claude Code's (and Copilot's) native plugin installer has zero awareness of
.apm/ nesting -- it convention-scans only flat skills/, agents/, commands/,
hooks.json at each plugin's root. Confirmed via strings on the installed
claude binary and live installs of git@holocron/gitea@holocron/kyberforge@
holocron, all reporting Skills(0) Agents(0) Hooks(0) post ADR-0015's apm
conversion. Root cause (apm_cli/core/plugin_manifest.py): apm's plugin.json
compiler deliberately strips skills/agents/commands keys, assuming the host
already auto-discovers those convention directories -- it has no model of
.apm/ being host-visible at all. Separately, apm's own bundle exporter
(apm_cli/bundle/plugin_exporter.py, behind `apm pack --format plugin`)
implements the correct .apm/ -> flat mapping, but only ever targeted
build/<name>-<version>/, a path nothing in marketplace.json's source: points
at.

scripts/sync-plugin-content.sh wraps that bundle exporter and copies its
agents/, skills/, commands/, instructions/, extensions/, and merged
hooks.json back into each plugin's own root as a second tracked
compiled-output category -- same governance status as
.claude-plugin/plugin.json: generated from .apm/, never hand-edited. tests/
subdirectories are excluded from the mirror (dev fixtures, not host-visible
runtime content; several hardcode a relative repo-root walk-up sized for the
.apm/-nested depth, which breaks when duplicated one level shallower).
Applied for real across all 6 plugins and verified two ways: `claude plugin
validate --strict` passes on every real plugin directory, and a live
`claude --plugin-dir <path> -p "list skills/agents"` behavioral test
confirms content is now actually discovered.

Also, from the same issue #90 review round:
- scripts/check-manifests.sh pointed at each plugin's root-level plugin.json
  (checking skills/hooks/mcpServers/agents pointer fields) -- that file was a
  stale near-duplicate of .claude-plugin/plugin.json nothing else read or
  wrote, now deleted across all 6 plugins. check-manifests.sh is rewritten to
  validate .claude-plugin/plugin.json instead, and drops the pointer-field
  checks entirely (nothing to check -- those fields are correctly absent by
  design). Content-presence drift is now check-plugin-content-sync's job, a
  new pre-push hook wired in .pre-commit-config.yaml.

docs/adr/0017 records the root cause and decision in full, including two
rejected alternatives (patching plugin.json's path fields directly -- apm's
compiler strips them on every run; pointing marketplace.json at apm pack's
build/ output -- a version-suffixed non-source directory nothing can install
from without an extra build step). ADR-0015 and CONTEXT.md are updated to
point at it.

Refs: #90
This commit is contained in:
2026-08-13 16:59:03 +00:00
parent 7910b8b12c
commit 38f1ba4e03
217 changed files with 14455 additions and 175 deletions

View File

@@ -0,0 +1,29 @@
# pc-run
Runs, installs, updates, and maintains pre-commit hooks in a local git clone.
## What it does
`pc-run` handles everything that happens *after* `.pre-commit-config.yaml` exists: wiring hooks into git, running them, bumping their versions, and maintaining the cache. When hooks fail, it identifies the cause and suggests a concrete fix — it does not auto-fix files or edit the config. For creating or editing `.pre-commit-config.yaml`, use `pc-author` instead.
## Before you start
- `pre-commit` must be installed and available on `PATH`
- A `.pre-commit-config.yaml` must exist at the repo root (use `pc-author` to create one)
## Usage
Common invocations:
- `/pc-run` — run all hooks against all files (default)
- `/pc-run install` — wire hooks into `.git/hooks/`
- `/pc-run autoupdate` — bump all `rev` values to latest
- `/pc-run clean` — wipe the pre-commit cache (requires confirmation)
## Files
| File | Purpose |
|------|---------|
| `SKILL.md` | Skill instructions for agents |
| `references/failure-patterns.md` | Hook failure causes and concrete fix suggestions |
| `references/sources.md` | Provenance: research sources that informed this skill |
| `references/README.md` | Directory index for references/ |

View File

@@ -0,0 +1,123 @@
---
name: pc-run
description: >
Use when the user wants to run pre-commit hooks, install git hooks, update
hook versions, or maintain the pre-commit cache. Triggers on: "run
pre-commit", "run all hooks", "check everything passes", "install hooks",
"wire hooks into git", "update hook versions", "autoupdate", "bump revs",
"clean the cache", "rebuild environments", "gc", "why is my hook failing",
"hooks aren't running". Do not use for creating or editing
`.pre-commit-config.yaml` — use `pc-author` for that.
compatibility: Requires pre-commit installed and available on PATH.
metadata:
category: devtools
source_keys:
- context7-pre-commit-com
- pre-commit-com
allowed-tools: Bash Read
---
## Gotchas
- Hooks not running on `git commit` almost always means `pre-commit install` was never run in this clone. Git hooks are per-clone — they are not committed to the repo.
- When a hook modifies files (e.g. `trailing-whitespace`, `end-of-file-fixer`), the commit is blocked intentionally — the staged version is stale. The fix is `git add -u && git commit`. Do NOT call `pre-commit install -f` here; that is for overwriting existing hooks, not re-staging.
- `pre-commit autoupdate` modifies `.pre-commit-config.yaml` in-place. Re-read the file after calling it to show the user the updated `rev` values.
- The `SKIP` env var requires exact hook `id` values, comma-separated, no spaces: `SKIP=check-yaml,gitleaks git commit -m "msg"`. A space after the comma silently skips nothing.
- Never use `git commit --no-verify` (or `-n`) to bypass a failing hook. Hooks are the automated QA gate; bypassing them breaks the pipeline. Diagnose and fix the failure instead — see the hook-specific guidance below and in `references/failure-patterns.md`.
- A stages mismatch — hook stage not installed — means the hook was added to the config but `pre-commit install` was not re-run with the correct `-t` flags. Hooks in stages not listed under `default_install_hook_types` will never fire.
## Route
Determine intent from the user's request, then execute the matching operation:
| User intent | Operation |
|---|---|
| "run", "check", "verify", "test hooks" | `pre-commit run --all-files` (default) |
| "staged", "simulate commit" | `pre-commit run` (staged files only) |
| "CI", "changed files only", "diff range" | `pre-commit run --from-ref <base> --to-ref <head>` — prefer this over `--all-files` on large repos |
| "install", "set up hooks", "wire into git" | `pre-commit install` — see Install |
| "pre-create environments", "install-hooks", "warm cache" | `pre-commit install-hooks` — see Install |
| "remove hooks", "uninstall", "tear down pre-commit" | `pre-commit uninstall` |
| "autoupdate", "update versions", "bump revs" | `pre-commit autoupdate` |
| "gc", "garbage collect" | `pre-commit gc` |
| "clean", "wipe cache", "rebuild from scratch" | `pre-commit clean` — see Clean |
If the intent is ambiguous, default to `pre-commit run --all-files`.
## Run
Default: `pre-commit run --all-files`. Never silently run staged-only.
```bash
pre-commit run --all-files
```
**When hooks fail**, read the output and:
1. Identify which hook failed and the specific cause. Be concrete: "gitleaks blocked `config.json` (high-entropy string on line 12)", not just "gitleaks failed".
2. Suggest a concrete next step. Common patterns are in `references/failure-patterns.md`.
3. Do NOT auto-fix code files. Do NOT modify `.pre-commit-config.yaml`. Those are the user's or `pc-author`'s responsibility.
If the user asks to run only staged files: `pre-commit run` (no `--all-files`).
If the user names a specific hook: `pre-commit run <hook-id>`.
## Install
Only run when the user explicitly asks to install or set up hooks.
Before running, check for existing hook files:
```bash
ls .git/hooks/
```
If any hook files exist (e.g. a hand-written `pre-commit`), `pre-commit install` does NOT refuse or error — it defaults to migration mode, which runs the existing hook and pre-commit's hooks both. Only `-f` replaces the existing hook file outright, and that replacement is not reversible via `pre-commit uninstall` — uninstall only removes pre-commit from `.git/hooks/`, it does not restore whatever hand-written hook `-f` overwrote. If files are present, tell the user: "Existing hook files found at `.git/hooks/<names>`. Plain `pre-commit install` will run both; `pre-commit install -f` will overwrite them permanently instead. Proceed with plain install, or overwrite?" Wait for confirmation before using `-f`.
```bash
pre-commit install
```
Re-run with `-t` flags when `default_install_hook_types` was changed or when hooks in non-default stages aren't firing:
```bash
pre-commit install -t pre-commit -t pre-push -t commit-msg
```
To pre-create all hook environments without running hooks (useful for CI warm-up or first-time setup):
```bash
pre-commit install-hooks
```
To remove pre-commit from `.git/hooks/` entirely:
```bash
pre-commit uninstall
```
## Autoupdate
```bash
pre-commit autoupdate
```
After it completes, read `.pre-commit-config.yaml` and report which `rev` values changed. If the user wants to pin to exact SHAs (for reproducibility): `pre-commit autoupdate --freeze`.
## Clean and GC
**`gc`** — removes only unused cached environments. Safe to run at any time:
```bash
pre-commit gc
```
**`clean`** — wipes the entire cache at `~/.cache/pre-commit`. All hook environments will be re-downloaded on next run. Require explicit confirmation before running:
> "This will wipe the entire pre-commit cache. All hook environments will be re-downloaded on next run. Proceed?"
Wait for the user to say yes before executing:
```bash
pre-commit clean
```

View File

@@ -0,0 +1,14 @@
---
source_keys:
- context7-pre-commit-com
- pre-commit-com
- context7-pre-commit-hooks
- pre-commit-hooks-github
---
# references/
| File | Purpose |
|---|---|
| `failure-patterns.md` | Hook failure causes and concrete fix suggestions — loaded when hooks fail |
| `sources.md` | Provenance: research sources that informed this skill |

View File

@@ -0,0 +1,130 @@
---
source_keys:
- context7-pre-commit-com
- pre-commit-com
---
# Hook Failure Patterns
Common hook failure causes and concrete next-step suggestions.
## Hook modified files — commit blocked
Cause: A fixer hook (e.g. `trailing-whitespace`, `end-of-file-fixer`, `pretty-format-json`) modified staged files. The commit is blocked because the staged version is now stale.
Fix: Re-stage and recommit.
```bash
git add -u
git commit -m "same message"
```
## Secret detected (gitleaks)
> Not sourced from the pre-commit research corpus (`context7-pre-commit-com`/`pre-commit-com` cover pre-commit itself, not gitleaks) — general tool knowledge, verify against gitleaks' own docs if precision matters.
Cause: gitleaks found a high-entropy string or known secret pattern in a staged file.
Suggestions:
- If it's a false positive: add a `# gitleaks:allow` inline comment, or add the path to `.gitleaksignore`.
- If it's a real secret: remove it from the file, rotate the credential, then commit.
## Shellcheck warning
> Not sourced from the pre-commit research corpus — general tool knowledge, verify against shellcheck's own docs if precision matters.
Cause: shellcheck found a shell script issue. The output includes the file path, line number, and SC-code.
Fix: Look up the SC-code on shellcheck.net or pass `--explain SCxxxx` to shellcheck for a detailed explanation. The most common fixes:
- SC2086 (unquoted variable): wrap in double quotes.
- SC2046 (unquoted command substitution): wrap in double quotes.
- SC2181 (check exit code of `$?`): use `if command; then` directly.
## `check-hooks-apply` fails
Cause: A hook's `files`/`types` filter matches zero files in the repo — the hook is dead weight.
Fix: Broaden the filter, or remove the hook if it no longer applies to this repo.
## `check-useless-excludes` fails
Cause: An `exclude` pattern matches no files.
Fix: Remove or fix the pattern.
## SSH cloning fails in CI
Cause: The CI environment lacks SSH credentials to clone hook repos over SSH.
Fix: Export `SSH_AUTH_SOCK` in the CI environment, or switch hook repo URLs to HTTPS.
## HTTP proxy needed
Cause: The CI/sandbox network requires a proxy to reach hook repos.
Fix:
```bash
export http_proxy=http://proxy.example.com:3128
export https_proxy=http://proxy.example.com:3128
export no_proxy=localhost,127.0.0.1
```
## `rev` is a branch name — `autoupdate` broke it
Cause: Branch refs are mutable and drift over time; pre-commit resolves them once at install time, so pinning to a branch name (instead of a tag or commit SHA) leads to silent version drift.
Fix:
```bash
pre-commit autoupdate # finds the latest tag and rewrites rev in place
```
## pretty-format-json fails but doesn't fix
Cause: `pretty-format-json` requires `args: [--autofix]` to modify files. Without it, the hook only fails.
Fix: The user (or `pc-author`) must add `args: [--autofix]` to the hook override in `.pre-commit-config.yaml`.
## Environment stale or broken
Cause: A hook's cached environment is corrupted or out of date.
Fix:
```bash
pre-commit clean # wipe all environments
pre-commit install-hooks # rebuild everything
```
Or less destructively:
```bash
pre-commit gc # remove only unused environments
```
## Hooks don't run on `git commit`
Cause: `pre-commit install` was never run in this clone.
Fix: `pre-commit install`. Git hooks are per-clone — they are not committed to the repo.
## Hook runs but matches wrong files (or no files)
Cause: The `files:` pattern uses `re.search()` not full-string match. A pattern that looks correct may match unexpectedly.
Diagnosis: `identify-cli <filename>` shows the type tags for a file. Verify `types:` filters against these.
## stages mismatch — hook never fires
Cause: Hook is defined for a stage (e.g. `pre-push`) but `pre-commit install` was not run with `-t pre-push`.
Fix:
```bash
pre-commit install -t pre-commit -t pre-push -t commit-msg
```
Or add `default_install_hook_types` to `.pre-commit-config.yaml` and re-run `pre-commit install`.
## `validate-config` schema error
Common causes:
- Missing `id` under a hook block
- Missing `rev` under a non-local repo block
- `repo: local` hook missing `language` or `entry`
- Indentation error (valid YAML but invalid pre-commit schema)

View File

@@ -0,0 +1,33 @@
# Sources
## context7-pre-commit-com
- **URL:** context7:/pre-commit/pre-commit.com
- **Description:** Official pre-commit.com documentation — installation, configuration schema, CLI reference, hook authoring, advanced features, troubleshooting
- **Contributing files:** SKILL.md, references/failure-patterns.md
- **Research doc:** plugins/git/docs/research/docs/pre-commit/{overview,cli-reference,troubleshooting}.md
- **Status:** `extracted`
## pre-commit-com
- **URL:** https://pre-commit.com/
- **Description:** Pre-commit framework homepage — full docs covering install, config, CLI, hook authoring, stages, local hooks, meta hooks, hazmat helpers, CI integration
- **Contributing files:** SKILL.md, references/failure-patterns.md
- **Research doc:** plugins/git/docs/research/docs/pre-commit/{overview,cli-reference,troubleshooting}.md
- **Status:** `extracted`
## context7-pre-commit-hooks
- **URL:** context7:/pre-commit/pre-commit-hooks
- **Description:** Official pre-commit-hooks collection — all available hook IDs with options and examples
- **Contributing files:** (none)
- **Research doc:** plugins/git/docs/research/docs/pre-commit/hooks-reference.md § "pre-commit-hooks (official collection)"
- **Status:** `extracted`
## pre-commit-hooks-github
- **URL:** https://raw.githubusercontent.com/pre-commit/pre-commit-hooks/main/README.md
- **Description:** Official pre-commit-hooks README — complete hook listing with all args, categories, deprecated hooks, and latest version
- **Contributing files:** (none)
- **Research doc:** plugins/git/docs/research/docs/pre-commit/hooks-reference.md § "pre-commit-hooks (official collection)"
- **Status:** `extracted`