feat(hooks): add deterministic validation layer via git hooks

Adds setup-hooks.sh and check-manifests.sh as the deterministic
enforcement layer described in docs/research/governance_principles/CONTROLS.md.

- commit-msg: conventional commits pattern check (hard block)
- pre-commit: shellcheck on .sh, jq on .json, yq on .yaml/.yml,
  SKILL.md frontmatter validation; optional tools degrade gracefully
- pre-push: full test suite + manifest cross-reference check
- check-manifests.sh: validates marketplace.json plugin sources,
  plugin.json skill/hooks/mcpServers path references
- Marker-based blocks (idempotent, composable with gitleaks)
- 33 integration tests across two test scripts

Run scripts/setup-hooks.sh to install into any repo's .git/hooks/.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TP4EGbBg3XMcyF28Lx78XJ
This commit is contained in:
2026-06-20 21:50:08 +00:00
parent d245807cae
commit ce673ca5e2
4 changed files with 559 additions and 0 deletions

67
scripts/check-manifests.sh Executable file
View File

@@ -0,0 +1,67 @@
#!/usr/bin/env bash
set -euo pipefail
# Validates that all paths referenced in marketplace.json and plugin.json manifests
# resolve to existing files or directories. Run from repo root or pass REPO_ROOT as arg.
REPO_ROOT="${1:-$(git rev-parse --show-toplevel 2>/dev/null || pwd)}"
FAIL=0
err() { echo " FAIL: $1" >&2; FAIL=$((FAIL + 1)); }
if ! command -v jq &>/dev/null; then
echo "Error: jq is required but not installed" >&2
exit 1
fi
MARKETPLACE="$REPO_ROOT/.claude-plugin/marketplace.json"
if [[ ! -f "$MARKETPLACE" ]]; then
exit 0
fi
plugin_count=$(jq '.plugins | length' "$MARKETPLACE")
for ((i = 0; i < plugin_count; i++)); do
name=$(jq -r ".plugins[$i].name" "$MARKETPLACE")
source=$(jq -r ".plugins[$i].source" "$MARKETPLACE")
source="${source#./}"
plugin_dir="$REPO_ROOT/$source"
if [[ ! -d "$plugin_dir" ]]; then
err "plugin '$name': source directory not found: $source"
continue
fi
manifest="$plugin_dir/plugin.json"
if [[ ! -f "$manifest" ]]; then
err "plugin '$name': plugin.json not found in $source"
continue
fi
# Check skills directories
skill_count=$(jq '.skills | if . then length else 0 end' "$manifest")
for ((s = 0; s < skill_count; s++)); do
skill_path=$(jq -r ".skills[$s]" "$manifest")
full_path="$plugin_dir/$skill_path"
full_path="${full_path%/}"
if [[ ! -d "$full_path" ]]; then
err "plugin '$name': skills path not found: $skill_path"
fi
done
# Check file references (hooks, mcpServers, agents)
for field in hooks mcpServers agents; do
ref=$(jq -r ".${field} // empty" "$manifest")
[[ -z "$ref" ]] && continue
full_path="$plugin_dir/$ref"
full_path="${full_path%/}"
if [[ ! -e "$full_path" ]]; then
err "plugin '$name': $field path not found: $ref"
fi
done
done
if [[ $FAIL -gt 0 ]]; then
echo "Manifest check failed: $FAIL error(s)" >&2
exit 1
fi