fix(kyberforge): resolve PR #144 review and audit round 3

- factory-audit: hook events judged per deployed target after apm's
  rename (Claude/Copilot event sets FAIL, others SUGGESTION); Claude
  plugin layouts accepted as hook sources; interpreter options and
  sh -c strings checked; bats 378 -> 386
- primitive-author: Must 4/5 match the audit; reference hand-back
  points at the right steps; Step 4.2 --target all fallback
- skill-author: new-skill.sh repair only on the template marker line,
  so complete skills stay a no-op; provenance and calibration text
- forge: restore "already named" qualifier; drop false HITL claim
- apm-workflow: token example uses an env var
- docs/hooks.md: the apm-hooks.json sidecar is committed, not ignored

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KkT7RSDwDbmrM9T34b6sTi
This commit is contained in:
2026-09-28 21:32:18 +00:00
parent 965208bddd
commit 5d0f988ed8
18 changed files with 395 additions and 140 deletions

View File

@@ -6,8 +6,8 @@ source_keys:
# Authoring an apm hook
Reached from `SKILL.md` Step 1 for a hook. Run the Gate, then write against the shape and the
checklist, then return to `SKILL.md` Step 3.
Reached from `SKILL.md` Step 1 for a hook. `SKILL.md` Step 2 runs the Gate below; Step 3 writes
against the shape and the checklist.
## Gate
@@ -68,15 +68,18 @@ Must:
else fails the Copilot install outright. The file contributes at least one entry, and every
entry carries at least one handler: an empty list or a handler-less entry deploys nothing, with
only a warning.
4. Event names are PascalCase (`PreToolUse`, `PostToolUse`, `UserPromptSubmit`, `SessionStart`,
`Stop`, …). An all-lowercase name never warns: only Kiro's rename map covers one (`stop` →
`Stop`), and every other target deploys it verbatim, where it never fires. A camelCase name
outside apm's rename map (`userPromptSubmit`) likewise deploys verbatim to Claude and never
fires.
4. Every event is one each target the package deploys to fires, after apm's rename for that target
(`_HOOK_EVENT_MAP`; no `targets:` means every target). Write Claude's PascalCase names
(`PreToolUse`, `PostToolUse`, `UserPromptSubmit`, `SessionStart`, `Stop`, …), which apm renames
for each target its map covers. A name the map does not cover deploys verbatim with no warning,
so a lowercase `stop`, a camelCase `userPromptSubmit` or a typo such as `PreToolUSe` never fires
on Claude or Copilot. A harness's own spelling (Cursor's `stop`, Windsurf's `pre_run_command`)
belongs only in a package whose `targets:` reach no harness that would break it.
5. The script is referenced as `${PLUGIN_ROOT}/…` (or `${CLAUDE_PLUGIN_ROOT}/…`, see Shape) for
the package root, or `./…` for the hook directory, and exists inside the package. The script is
the command's first token or the first argument after an interpreter (`bash`, `sh`, `zsh`,
`python`, `python3`, `node`, `pwsh`, `ruby`, `perl`); in either position, no absolute path and
`python`, `python3`, `node`, `pwsh`, `ruby`, `perl`), skipping its options (`-e`, `-u`, …) —
after `-c`, the first token of the command string. In any position, no absolute path and
no bare relative path (`scripts/x.sh`): apm bundles and rewrites neither. No `$` or backtick in
the path itself, and no space. When quoting, quote the whole token —
`"${PLUGIN_ROOT}/scripts/my-hook.sh"`, never `"${PLUGIN_ROOT}"/scripts/x.sh`: apm rewrites

View File

@@ -6,8 +6,8 @@ source_keys:
# Authoring an apm instruction
Reached from `SKILL.md` Step 1 for an instruction. Run the Gate, then write against the checklist,
then return to `SKILL.md` Step 3.
Reached from `SKILL.md` Step 1 for an instruction. `SKILL.md` Step 2 runs the Gate below; Step 3
writes against the checklist.
## Gate

View File

@@ -7,8 +7,8 @@ source_keys:
# Authoring an apm prompt
Reached from `SKILL.md` Step 1 for a prompt. Run the Gate, then write against the description
contract and the checklist, then return to `SKILL.md` Step 3.
Reached from `SKILL.md` Step 1 for a prompt. `SKILL.md` Step 2 runs the Gate below; Step 3 writes
against the description contract and the checklist.
## Gate