Repository navigation
Conversation
commands/doctor.md granted bare `Bash` -- unrestricted shell for the whole
command run -- when the command body only ever needs one script. Scope the
grant to Bash(${CLAUDE_PLUGIN_ROOT}/scripts/doctor.sh:*), mirroring
skills/remember/SKILL.md's existing narrow grant for write-handoff.sh, and
invoke doctor.sh directly instead of through `bash "..."` (a scoped pattern
cannot match a `bash` prefix). Make scripts/doctor.sh executable in git
(mode 100755) so the direct exec works, the same as write-handoff.sh already
is.
Add a preflight rule to check_release_tree.py: fail on any shipped skill,
command or agent whose allowed-tools grants unrestricted shell -- bare Bash,
Bash(*), Bash(:*), or a bare shell/interpreter wildcard (bash, sh, zsh, env,
python/python2/python3, with or without a trailing *) -- in both the string
and YAML-list form, so this class is caught before a release tree ships. A
narrow Bash(<path>:*) naming one script still passes.
Co-Authored-By: Claude Sonnet 5 <[email protected]>
…eword two comments behind RUNTIME_FETCH_EXEC, document the observed portal scans Co-Authored-By: Max <noreply>
…ory leaves the machine Co-Authored-By: Max <noreply>
…elease validator to claude 2.1.287, which accepts them under --strict Co-Authored-By: Max <noreply>
…/powershell grants as broad releasing.md: .gitattributes filters stop validation rather than hold it; the directory follows release since 2026-10-02; release commits are direct on main; the verify job pins claude >= 2.1.281 and skips validate with only a warning if npm fails; release_publish.py belongs to the oss plugin; a flagged listing blocks newer versions; REVIEW lines are a starting list, not a prediction; nothing enforces a version bump per release commit; the listing switch and webhook are written up as done, with the steps for another repository; the marketplace ref switch is a pending follow-up; inferences are labelled. New section on where listing details come from and how to contact the directory team. The reuse section now says which script reads which config key and what is hard-coded. check_release_tree.py: pwsh and powershell join the unscoped shells, and the module docstring lists what the code actually holds. Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
This was referenced Oct 2, 2026
fdaviddpt
added a commit
that referenced
this pull request
Oct 2, 2026
… guess on v0.38.0 (#871) * docs(#864): narrow (not confirm) the RUNTIME_FETCH_EXEC third-finding guess on v0.38.0 #861's rewording of pipeline/shell.py and scripts/log.sh did not clear the directory portal's RUNTIME_FETCH_EXEC warning; v0.38.0 raised the count from 2 to 3 instead. Which third file matched is only visible behind the expanded row in the portal's web UI, which this lane has no access to, so the real trigger stays unconfirmed. Source-only follow-up: grepped the two largest v0.37.0->v0.38.0 diffs (scripts/lib-memory-context.sh, scripts/session-start-hook.sh, both from #842/#845) for curl, wget, download, fetch, eval and exec and found nothing in either -- the existing doc guess that #842/#845's SessionStart budget code is the new third match has no textual support. scripts/log.sh is the one file here with real eval calls on validated input, the strongest literal (still unconfirmed) candidate for why it keeps matching. No code changed. docs/releasing.md records the narrowed state and flags that a human with portal access still needs to expand the row and record the file/line before this can be closed. Co-Authored-By: Claude Sonnet 5 <[email protected]> * docs(#864): precise churn figures, clarify grep scope per self-review Explore review flagged two accuracy issues in 4ccd6dd's docs/releasing.md text: "+164"/"+74 lines" were git diff --stat churn totals (insertions plus deletions), not insertion counts, misleading by ~2 and ~11 lines respectively -- replaced with explicit insertions/deletions. The "found nothing" grep claim was ambiguous between grepping the whole shipped file vs only the diff's added lines; under the whole-file reading it is false (scripts/session-start-hook.sh has 9 pre-existing `exec` hits). Clarified that only the added (+) lines were grepped, gave the exact command, and noted why the whole-file reading is misleading (those hits pre-date v0.38.0 and cannot explain a count that only rose between versions). Co-Authored-By: Claude Sonnet 5 <[email protected]> --------- Co-authored-by: Claude Sonnet 5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The Anthropic directory's scan of the slim
releasetree (v0.37.0,e6cf58f) holds it on exactly one rule:ALLOWED_TOOLS_BROAD, fromcommands/doctor.md'sallowed-tools: Bash. This PR clears that hold, adds the listing fields we control, and records what the portal actually checks, for claude-supertool and claude-jit-context to reuse.Closes #859
Plugin
commands/doctor.md:allowed-tools: Bash(${CLAUDE_PLUGIN_ROOT}/scripts/doctor.sh:*). The script is now run directly, andscripts/doctor.shis executable (100755). This is the same formskills/remember/SKILL.mdalready uses, and the portal accepted it there..claude-plugin/plugin.json: addsdocumentationUrl,supportUrl,privacyPolicyUrlandtermsOfServiceUrl, the fields the directory reads for the listing (Claude Code ignores them).pipeline/shell.pyandscripts/log.sh. They are the likely trigger of theRUNTIME_FETCH_EXECwarning onrelease; this is inferred, and the next scan will confirm or refute it. Theshell.pydocstring was also wrong: the real consumer issafe_eval.docs/privacy.md: names the git backup push, the one way memory leaves the machine.Release tooling
check_release_tree.py: now matches the portal's fullALLOWED_TOOLS_BROADwording. It holds bareBash,Bash(*), a wildcard after a shell (including pwsh/powershell), an interpreter, a package manager or runner, or curl/wget, a relative path, and a wildcard inside the path. The portal's own accepted examples still pass.CLAUDE_CLI_VERSION2.1.280 → 2.1.287. Observed:claude plugin validate --strictfails on 2.1.280 with "Unknown field 'privacyPolicyUrl'" and passes on 2.1.287. The minimum is 2.1.281.Docs
docs/releasing.md:release, and each rule with its trigger and fix;Testing
check_release_tree.pyandclaude plugin validate --stricton 2.1.287.Cross-platform
doctor.sh..shon Windows Git Bash works the waywrite-handoff.shalready does there.🤖 Generated with Claude Code
[AI-generated]