fix(factory-audit): flag unbraced plugin-root tokens and close hook check gaps

Why: PR #144 review round 4 reproduced hooks referencing $PLUGIN_ROOT or
${PLUGIN_ROOT} without a path separator passing the audit, although apm
only rewrites ${TOKEN}/ and the deployed hook points nowhere.

- FAIL unbraced or unseparated plugin-root tokens
- check the exec bit for scripts run via an interpreter -c string
- skip env NAME=value prefixes when locating bare relative paths
- correct input: and empty-frontmatter messages, depth-walk applyTo braces
- INFO on unrecognised targets; failing-case tests for untested checks
- document tiers, blind spots and crash exit 2; drop rtk from portable flow
- restore the after-a-hand-edit trigger; pin upstream apm source URL

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KkT7RSDwDbmrM9T34b6sTi
This commit is contained in:
2026-09-29 08:00:17 +00:00
parent 5d0f988ed8
commit 9285b29e3c
11 changed files with 363 additions and 43 deletions

View File

@@ -133,7 +133,8 @@ the target:
hook mode the target is a *.json file directly under a hooks/
directory (.apm/hooks, or a hooks/ at a package root: beside
apm.yml or a plugin.json manifest; any other hooks/
directory is apm's deployed output and FAILs).
directory is deployed output or no package at all, and
FAILs at exit 1).
instruction mode the target is a *.instructions.md file.
prompt mode the target is a *.prompt.md file.
@@ -160,7 +161,8 @@ Exit codes:
target does not exist, an unrecognized file extension, a missing
references/agent-field-inventory.md, a missing or unreadable lib-*.sh
beside this script, or, for a hook, instruction or prompt, a missing
python3 or PyYAML)
python3 or PyYAML, or a crash inside the hook, instruction or prompt
checks)
EOF
}