fix(kyberforge): resolve PR #144 review and audit round 2

- factory-audit: ./ and bare/absolute script checks scoped to command
  position (no false FAILs on ./src or printf); hook sources limited to
  .apm/hooks or package-root hooks/; Kiro-aware lowercase events;
  unfilled template placeholders FAIL; repo-only instructions FAIL at
  any scope; Vale description FAIL documented; bats 367 -> 378
- primitive-author: split-quote/spaced paths and handler-less entries
  promoted to Must; Step 4.2 renders into a scratch consumer instead of
  a no-op dry run; dispatch and gate hand-off trimmed
- apm-workflow 1.0.2: mutual boundary with primitive-author
- forge: no double package bump; gotcha wording
- skill-author: create keeps seeded 0.1.0 (ADR-0022); portable,
  retry-safe new-skill.sh; template and flow consistency fixes
- hook docs: cite the ADR-0019 correction; guard caveat

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KkT7RSDwDbmrM9T34b6sTi
This commit is contained in:
2026-09-28 20:50:22 +00:00
parent df28351d3e
commit 965208bddd
29 changed files with 462 additions and 156 deletions

View File

@@ -19,7 +19,9 @@ set -uo pipefail
# guard a non-Claude session start would run `apm update --yes` and rewrite the
# working tree with nothing to re-scan it. Claude Code exports
# CLAUDE_PROJECT_DIR for SessionStart hooks and the other targets do not
# document it, so its absence is the exit (ADR-0019, amendment 2026-09-28).
# document setting it, so its absence is the exit (ADR-0019, correction
# 2026-09-28). A heuristic: if the variable is inherited from the user's
# environment, a non-Claude session start gets past this guard.
[[ -n "${CLAUDE_PROJECT_DIR:-}" ]] || exit 0
# Anchor on the project root, not the session's cwd: a session opened in a
@@ -27,8 +29,8 @@ set -uo pipefail
# run the apm calls below against that wrong directory.
project_dir="$CLAUDE_PROJECT_DIR"
# No lockfile means nothing was installed through apm here — e.g. a host that
# installed this plugin natively. Say nothing and cost nothing.
# No lockfile means this project consumes nothing through apm, so there is
# nothing for apm update to refresh. Say nothing and cost nothing.
[[ -f "$project_dir/apm.lock.yaml" ]] || exit 0
command -v apm > /dev/null 2>&1 || exit 0