fix(kyberforge): resolve PR #144 review and audit round 2

- factory-audit: ./ and bare/absolute script checks scoped to command
  position (no false FAILs on ./src or printf); hook sources limited to
  .apm/hooks or package-root hooks/; Kiro-aware lowercase events;
  unfilled template placeholders FAIL; repo-only instructions FAIL at
  any scope; Vale description FAIL documented; bats 367 -> 378
- primitive-author: split-quote/spaced paths and handler-less entries
  promoted to Must; Step 4.2 renders into a scratch consumer instead of
  a no-op dry run; dispatch and gate hand-off trimmed
- apm-workflow 1.0.2: mutual boundary with primitive-author
- forge: no double package bump; gotcha wording
- skill-author: create keeps seeded 0.1.0 (ADR-0022); portable,
  retry-safe new-skill.sh; template and flow consistency fixes
- hook docs: cite the ADR-0019 correction; guard caveat

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KkT7RSDwDbmrM9T34b6sTi
This commit is contained in:
2026-09-28 20:50:22 +00:00
parent df28351d3e
commit 965208bddd
29 changed files with 462 additions and 156 deletions

View File

@@ -274,7 +274,9 @@ no hook at all, for the reasons already documented in `plugins/kyberforge/docs/h
> cwd fallback is gone, and `tests/test-apm-current-hook.sh` pins that an unset or empty
> `CLAUDE_PROJECT_DIR` exits 0 silently without invoking `apm`. apm still deploys the hook to
> Copilot and Codex; it exits immediately there. The acceptance stands on that guard, not on the
> lockfile. The seventh-plugin alternative below remains rejected, now for the same reason.
> lockfile. The seventh-plugin alternative below remains rejected as disproportionate, but no
> longer because either guard keeps the hook off external kyberforge consumers: on Claude Code
> neither guard stops it for an apm consumer, and that is intended.
**`scripts/git-hooks/` is now empty.** `post-push` and `test-post-push.sh` are deleted.
`install.sh`'s copy block is generic and is kept; `test-git-hooks-install.sh` now synthesizes its
@@ -292,3 +294,7 @@ be used again if a hook git actually invokes is ever wanted.
consumers. Rejected as disproportionate: the `apm.lock.yaml` guard already makes the hook inert
for anyone not consuming through apm, and a package exists to be maintained, versioned, and
registered in the marketplace.
*Rationale superseded by the 2026-09-28 correction above: the `CLAUDE_PROJECT_DIR` guard keeps
the hook off non-Claude hosts, and on Claude Code it runs for every apm consumer, including
external kyberforge consumers, by design. The alternative stays rejected as disproportionate.*