factory-audit audits skills and agents only. A hand-edited .apm/hooks/*.json gets no audit, and the reconstruction gotchas (event-name casing between targets, the Copilot bash + powershell split, ${CLAUDE_PLUGIN_ROOT} rewriting) are easy to get wrong.
What to build
Register hooks as a primitive in the generic flow from #147. Hooks differ from the markdown primitives: they are JSON, with no frontmatter, no description budget and no prose body.
A scripts/lib-checks-hooks.sh check suite, sourced from a new hooks mode in scripts/validate.sh, encoding the rules hook-author (#150) already decided are correct. Derive the rubric from that skill's references/.
The flow's Vale step and the description/body dimensions do not apply to hooks; the data table must express "step not applicable" rather than faking a pass. Say how in the PR.
A criteria file and any rubrics the flow needs, under references/.
A row in the primitive data table (target shape .apm/hooks/*.json, coverage line, "Run hook-author to address findings").
Provenance handling: JSON cannot carry frontmatter source_keys; decide whether provenance applies and record the decision.
tests/validate-hooks.bats.
Not in scope
Auditing the hook scripts that the JSON invokes.
Any change to the skill or agent flows or check suites.
Acceptance criteria
factory-audit on a valid hooks file returns PASS; on one with a wrong event-name casing or an unrewritten script-path placeholder, the finding names the target and the fix.
The repo's own plugins/kyberforge/.apm/hooks/hooks.json audits PASS.
tests/validate-hooks.bats passes, with the existing skill and agent bats suites still green.
Step 0 recognises .apm/hooks/*.json and the unrecognised-path message lists the new shape.
factory-auditmetadata.version bumped (ADR-0022); description and body pass ADR-0020 budgets.
Part of #94.
Depends on #147
Depends on #150
## Why
`factory-audit` audits skills and agents only. A hand-edited `.apm/hooks/*.json` gets no audit, and the reconstruction gotchas (event-name casing between targets, the Copilot `bash` + `powershell` split, `${CLAUDE_PLUGIN_ROOT}` rewriting) are easy to get wrong.
## What to build
Register hooks as a primitive in the generic flow from #147. Hooks differ from the markdown primitives: they are JSON, with no frontmatter, no description budget and no prose body.
- A `scripts/lib-checks-hooks.sh` check suite, sourced from a new `hooks` mode in `scripts/validate.sh`, encoding the rules `hook-author` (#150) already decided are correct. Derive the rubric from that skill's `references/`.
- The flow's Vale step and the description/body dimensions do not apply to hooks; the data table must express "step not applicable" rather than faking a pass. Say how in the PR.
- A criteria file and any rubrics the flow needs, under `references/`.
- A row in the primitive data table (target shape `.apm/hooks/*.json`, coverage line, "Run hook-author to address findings").
- Provenance handling: JSON cannot carry frontmatter `source_keys`; decide whether provenance applies and record the decision.
- `tests/validate-hooks.bats`.
## Not in scope
- Auditing the hook scripts that the JSON invokes.
- Any change to the skill or agent flows or check suites.
## Acceptance criteria
- [ ] `factory-audit` on a valid hooks file returns PASS; on one with a wrong event-name casing or an unrewritten script-path placeholder, the finding names the target and the fix.
- [ ] The repo's own `plugins/kyberforge/.apm/hooks/hooks.json` audits PASS.
- [ ] `tests/validate-hooks.bats` passes, with the existing skill and agent bats suites still green.
- [ ] Step 0 recognises `.apm/hooks/*.json` and the unrecognised-path message lists the new shape.
- [ ] `factory-audit` `metadata.version` bumped (ADR-0022); description and body pass ADR-0020 budgets.
- [ ] `apm audit --ci` clean.
## References
- `plugins/kyberforge/docs/research/docs/microsoft-apm/hooks-primitive-schema.md`
- ADR-0019, ADR-0020, ADR-0022, ADR-0025
Claude
added this to the Kyberforge basics milestone 2026-10-01 06:23:58 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Part of #94.
Depends on #147
Depends on #150
Why
factory-auditaudits skills and agents only. A hand-edited.apm/hooks/*.jsongets no audit, and the reconstruction gotchas (event-name casing between targets, the Copilotbash+powershellsplit,${CLAUDE_PLUGIN_ROOT}rewriting) are easy to get wrong.What to build
Register hooks as a primitive in the generic flow from #147. Hooks differ from the markdown primitives: they are JSON, with no frontmatter, no description budget and no prose body.
scripts/lib-checks-hooks.shcheck suite, sourced from a newhooksmode inscripts/validate.sh, encoding the ruleshook-author(#150) already decided are correct. Derive the rubric from that skill'sreferences/.references/..apm/hooks/*.json, coverage line, "Run hook-author to address findings").source_keys; decide whether provenance applies and record the decision.tests/validate-hooks.bats.Not in scope
Acceptance criteria
factory-auditon a valid hooks file returns PASS; on one with a wrong event-name casing or an unrewritten script-path placeholder, the finding names the target and the fix.plugins/kyberforge/.apm/hooks/hooks.jsonaudits PASS.tests/validate-hooks.batspasses, with the existing skill and agent bats suites still green..apm/hooks/*.jsonand the unrecognised-path message lists the new shape.factory-auditmetadata.versionbumped (ADR-0022); description and body pass ADR-0020 budgets.apm audit --ciclean.References
plugins/kyberforge/docs/research/docs/microsoft-apm/hooks-primitive-schema.md