feat(factory-audit): audit hooks, instructions and prompts

factory-audit gains three Step 0 rows and flows for the apm primitives
that have no container of their own: a .json file under hooks/, a
*.instructions.md and a *.prompt.md. apm validates almost none of them
(invalid hook JSON is skipped silently, instruction validate() only
warns, input: names are never checked against ${input:x}), so the
deterministic checks live in a new scripts/lib-checks-primitive.sh,
wired into validate.sh's path-shape detection. Each check and tier
traces to the Authoring checklists in the microsoft-apm research docs.

- Hook: JSON/shape/event-list checks mirroring the Copilot payload
  validator, never-firing event casing, missing/escaping/non-executable
  scripts (FAIL); deprecated filename routing and ${CLAUDE_PLUGIN_ROOT}
  (SUGGESTION).
- Instruction: location, frontmatter, description, body, stem clash
  (FAIL); missing or list applyTo and unread keys (SUGGESTION).
- Prompt: location/name, frontmatter, description, input names, the
  upstream `- name: x` docs bug, declared-vs-used ${input:x} (FAIL);
  ADR-0029 description length and trigger clause, dropped keys,
  camelCase aliases, argument-hint with input (SUGGESTION). Whether a
  prompt carries procedure is judgment in prompt-flow.md, not a script
  heuristic.

Vale now lints *.instructions.md and *.prompt.md with the Kyberforge
style; test-vale-wrap.sh gains their probe rows. New
tests/validate-primitive.bats (31 cases). kyberforge 2.0.1 -> 2.1.0 with
the executables.allow key, catalog 0.5.1 -> 0.5.2, marketplace.json
regenerated.

Refs #94

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KkT7RSDwDbmrM9T34b6sTi
This commit is contained in:
2026-09-28 17:02:04 +00:00
parent 701e96d4b3
commit 70210d6a7e
14 changed files with 1062 additions and 29 deletions

View File

@@ -36,13 +36,16 @@ bats plugins/kyberforge/.apm/skills/factory-audit/tests/
| `validate-agent.bats` | `scripts/validate.sh` against agent files |
| `validate-provenance-skill.bats` | `scripts/validate-provenance.sh` against skill directories |
| `validate-provenance-agent.bats` | `scripts/validate-provenance.sh` against agent files |
| `validate-primitive.bats` | `scripts/validate.sh` against apm hook, instruction and prompt files |
## Two scripts, four suites
## Two scripts, five suites
`factory-audit` merges what were two skills — `skill-audit` and `agent-audit` —
each of which shipped its own `validate.sh` and `validate-provenance.sh`. The
merged skill has **one** of each. Every suite here invokes one of those two
scripts; the four files are two scripts × two artifact types, not four scripts.
scripts; the four skill and agent files are two scripts × two artifact types, not four scripts.
`validate-primitive.bats` is a fifth suite over the same `scripts/validate.sh`, for hooks,
instructions and prompts, which have no provenance mode and so no provenance suite.
`validate-skill.bats` and `validate-agent.bats` run the same
`scripts/validate.sh` and differ only in the fixtures they point it at. The two