fix: align todos-plan with deployment doctrine - #87
Conversation
Agent: vitruvius
|
[REVIEW] NO_GO — #87 @ 5444e5a — lens: correctness+security+gates, reviewer Trebius (1 of 1) Reviewed the exact PR base Commands run, unpiped:
Blocking P0/P1 findings:
Required remedy:
Non-blocking follow-ups:
GitHub already reported this PR merged before this review completed. The finding therefore needs a forward fix on the landed code; the green gates do not waive the P1. |
|
The named P1 is fixed forward in commit The repair rejects malformed skill names before any source lookup or target-path construction. The focused regression is now PR #87 was already merged before the review verdict, so #88 is the forward landing path. |
|
The blocking path-containment finding is fixed and landed through #88.
|
Summary
todos-planskill with independent product-story, server-backend, authenticated-authority, and provider-role factsProvenance
The detailed active Codewith copy was manually synchronized on June 30, 2026 (Conversations messages 33579 and 33583; Todos plan
4bc933b6-8b0a-4e38-8807-aa11b034a9af). It had no.hasna-skills.jsonownership marker and its detailed content was absent from reachable repository history, so the active copy had diverged without a source-owned update route.Regression evidence
Red before implementation:
bun test src/lib/todos-plan-contract.test.ts: 1 pass, 2 failGreen candidate:
python3 .../quick_validate.py skills/todos-plan:Skill is valid!bun run typecheck: passbun run build: passbun test: 1076 pass, 0 fail, 6628 assertionsbun run verify:release: pass5513685f72f3c305481d69be0e936dca57f1a76c93f51b092fee918f54a224b5, management marker presentScope boundary
This PR does not merge, publish, install, edit profiles, or change the active
~/.codewith/skills/todos-plancopy. Independent review and installed rollout remain with the parent coordinator.Todos task:
2ba4d4c0-89dd-4525-b4dc-fbc8331e9383Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.