ECC/commands
JongHyeok Park 914a58a716
feat(workflows): re-land orch-review workflow + add /orch-review command (#2400)
* feat(workflows): re-land orch-review workflow + add /orch-review command

Re-lands #2363 (reverted by #2393 to unbreak main's lint) and fixes the
root cause so it stays green:

- Restore workflows/orch-review.workflow.js + workflows/README.md.
- eslint.config.js: ignore 'workflows/**/*.workflow.*' and '.claude/workflows/**'
  per the maintainer's note in #2393. Workflow DSL scripts use both top-level
  export (ESM) and top-level return (the runtime wraps them in an async fn),
  which no single eslint sourceType can parse — they must be excluded, not
  lint-fixed. 'npx eslint .' is green with this ignore.
- Add commands/orch-review.md (the /orch-review surface) + regenerate
  docs/COMMAND-REGISTRY.json.

Supersedes #2397 (command-only), which referenced the reverted workflow.

* fix(workflows): address orch-review bot review findings

- Verifier uncertainty no longer demotes blockers (Greptile P1 + CodeRabbit):
  isReal=false only refutes when confidence >= 0.8; low-confidence 'false'
  is treated as uncertain and kept blocking (fail closed).
- Treat the diff (and finding text) as untrusted input in both review and
  verify prompts; ignore embedded directives (prompt-injection hardening).
- Validate changedFiles entries are strings, not just that it is an array.
- Enforce proof for HIGH/CRITICAL in FINDINGS_SCHEMA, not only in the prompt.
- Remove in-place mutation in dimension build + dedup merge (immutable).
- /orch-review: extract & validate a numeric PR id before shelling out to gh.
- Docs: complete the stats example, soften wording, refresh follow-up list.

* style(workflows): apply formatter to orch-review assembly

* fix(plan-orchestrate): detect ecc@ecc marketplace + emit ecc: agent prefix (#2316) (#2409)

* fix(plan-orchestrate): detect ecc@ecc marketplace + emit ecc: agent prefix (#2316)

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(ci): resync lockfiles with package.json (eslint 10) + migrate yarn.lock to Yarn 4 format

package.json requires eslint@^10.6.0 but the committed locks pinned 9.39.2, so
npm ci aborted and Yarn 4 hardened mode rejected the stale v1-classic yarn.lock
(YN0028). Regenerate package-lock.json and rewrite yarn.lock in Yarn 4 (berry)
format so npm ci and immutable yarn installs both pass.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(ci): require clean probe exit for Windows shell/bash detection; add pyyaml dev dep

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

---------

Co-authored-by: affaan <affaan@itomarkets.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* refactor: consolidate duplicated hook-root resolver into shared resolveEccRoot() (#2368) (#2410)

* fix(ci): resync lockfiles with package.json (eslint 10) + migrate yarn.lock to Yarn 4 format

package.json requires eslint@^10.6.0 but the committed locks pinned 9.39.2, so
npm ci aborted and Yarn 4 hardened mode rejected the stale v1-classic yarn.lock
(YN0028). Regenerate package-lock.json and rewrite yarn.lock in Yarn 4 (berry)
format so npm ci and immutable yarn installs both pass.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(ci): require clean probe exit for Windows shell/bash detection; add pyyaml dev dep

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* refactor: consolidate duplicated hook-root resolver into shared resolveEccRoot() (#2368)

The inline node -e resolver blob was duplicated ~60x across hooks.json,
command docs, and translations. Each copy inlined the full ~700-char
plugin-root search using a spread over nested array literals
(p.join(d,'plugins',...s) over [['ecc'],...]), which breaks Windows hook
execution due to shell quoting (#2368).

Collapse every copy to a 250-char locator that loads the committed
resolve-ecc-root module and delegates to resolveEccRoot() — no spread, no
nested array literals, no escaped double quotes. The real search logic now
lives in one tested module. Also route session-start-bootstrap.js through
resolveEccRoot() instead of its own duplicated reimplementation, and fix
the auto-update.md 'marketplace' (singular) typo along the way.

Guard tests updated: discovery behavior is asserted against resolveEccRoot();
the inline is asserted to delegate and to contain no Windows-fragile
constructs.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(resolve-ecc-root): restore full env-unset discovery in inline resolver

Address Greptile review on #2410: when CLAUDE_PLUGIN_ROOT is unset the
delegating inline could only load the resolver module from ~/.claude,
returning ~/.claude without ever reaching the plugin/cache search. Restore
the old inline's discovery breadth (exact plugin roots + versioned cache)
Windows-safely (no spread, nested arrays, or escaped quotes), then delegate
the authoritative decision to resolveEccRoot(). Add regression tests for
plugin-subdir and versioned-cache bootstrap with env unset.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

---------

Co-authored-by: affaan <affaan@itomarkets.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix: docs/COMMAND-REGISTRY.json check fails on fresh Windows clone (missing .gitattributes) (#2437)

* fix: add .gitattributes to force LF line endings for text files

npm run command-registry:check (part of npm test) fails on a fresh clone
on Windows with the common core.autocrlf=true setting: git checks out
docs/COMMAND-REGISTRY.json with CRLF, but generate-command-registry.js
always writes LF, so the strict string comparison in checkRegistry()
never matches. Forcing LF via .gitattributes makes checkouts consistent
across platforms regardless of a contributor's local autocrlf setting.

* fix: normalize CRLF line endings to LF per .gitattributes

pyproject.toml, src/llm/__init__.py, src/llm/prompt/builder.py,
src/llm/providers/claude.py, and tests/test_builder.py had CRLF line
endings committed to the repo, inconsistent with the rest of the
codebase. Renormalized via 'git add --renormalize .' now that
.gitattributes enforces eol=lf.

---------

Co-authored-by: Affaan Mustafa <me@affaanmustafa.com>

* chore(catalog): sync command counts (92->93) + register orch-review in agent.yaml surface

---------

Co-authored-by: devin-ai-integration[bot] <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: affaan <affaan@itomarkets.com>
Co-authored-by: Boube <109886533+Cb2i@users.noreply.github.com>
Co-authored-by: Affaan Mustafa <me@affaanmustafa.com>
2026-07-03 20:26:40 -07:00
..
aside.md fix: harden unicode safety checks 2026-03-29 21:21:18 -04:00
auto-update.md refactor: consolidate duplicated hook-root resolver into shared resolveEccRoot() (#2368) (#2410) 2026-07-03 20:01:17 -07:00
build-fix.md fix: add command metadata frontmatter 2026-04-30 03:41:18 -04:00
checkpoint.md fix: add command metadata frontmatter 2026-04-30 03:41:18 -04:00
code-review.md feat: add PRD planning command flow 2026-05-12 00:06:41 -04:00
cost-report.md fix: resolve four bug reports (#2290, #2282, #2276, #2272) 2026-06-18 16:49:58 -04:00
cpp-build.md fix: retire legacy command shims from default surface 2026-04-29 23:56:40 -04:00
cpp-review.md fix: harden unicode safety checks 2026-03-29 21:21:18 -04:00
cpp-test.md fix: retire legacy command shims from default surface 2026-04-29 23:56:40 -04:00
ecc-guide.md docs: salvage ECC onboarding guide commands 2026-05-11 21:09:20 -04:00
epic-claim.md feat: add github-native coordination (epic-* commands + scripts + tests) 2026-06-11 12:58:11 -04:00
epic-decompose.md feat: add github-native coordination (epic-* commands + scripts + tests) 2026-06-11 12:58:11 -04:00
epic-publish.md feat: add github-native coordination (epic-* commands + scripts + tests) 2026-06-11 12:58:11 -04:00
epic-review.md feat: add github-native coordination (epic-* commands + scripts + tests) 2026-06-11 12:58:11 -04:00
epic-sync.md feat: add github-native coordination (epic-* commands + scripts + tests) 2026-06-11 12:58:11 -04:00
epic-unblock.md feat: add github-native coordination (epic-* commands + scripts + tests) 2026-06-11 12:58:11 -04:00
epic-validate.md feat: add github-native coordination (epic-* commands + scripts + tests) 2026-06-11 12:58:11 -04:00
evolve.md feat: project-scoped instinct isolation 2026-03-01 12:07:13 -08:00
fastapi-review.md docs: salvage FastAPI review patterns 2026-05-11 07:44:26 -04:00
feature-dev.md feat: restore review and planning bundles 2026-04-05 17:51:56 -07:00
flutter-build.md fix: retire legacy command shims from default surface 2026-04-29 23:56:40 -04:00
flutter-review.md feat: add C# and Dart language support 2026-04-02 17:48:43 -07:00
flutter-test.md fix: retire legacy command shims from default surface 2026-04-29 23:56:40 -04:00
gan-build.md fix: add command metadata frontmatter 2026-04-30 03:41:18 -04:00
gan-design.md fix: add command metadata frontmatter 2026-04-30 03:41:18 -04:00
go-build.md fix: retire legacy command shims from default surface 2026-04-29 23:56:40 -04:00
go-review.md fix: harden unicode safety checks 2026-03-29 21:21:18 -04:00
go-test.md fix: retire legacy command shims from default surface 2026-04-29 23:56:40 -04:00
gradle-build.md feat: add Kotlin, Android, and KMP rules, agent, skills, and command 2026-03-10 20:53:39 -07:00
harness-audit.md feat: extend harness audit integration scoring (#1990) 2026-05-19 06:20:54 -04:00
hookify-configure.md feat: restore hookify command bundle 2026-04-05 17:50:31 -07:00
hookify-help.md feat: restore hookify command bundle 2026-04-05 17:50:31 -07:00
hookify-list.md feat: restore hookify command bundle 2026-04-05 17:50:31 -07:00
hookify.md feat: restore hookify command bundle 2026-04-05 17:50:31 -07:00
instinct-export.md feat: project-scoped instinct isolation 2026-03-01 12:07:13 -08:00
instinct-import.md fix: harden unicode safety checks 2026-03-29 21:21:18 -04:00
instinct-status.md refactor: consolidate duplicated hook-root resolver into shared resolveEccRoot() (#2368) (#2410) 2026-07-03 20:01:17 -07:00
jira.md fix: retire legacy command shims from default surface 2026-04-29 23:56:40 -04:00
kotlin-build.md fix: retire legacy command shims from default surface 2026-04-29 23:56:40 -04:00
kotlin-review.md fix: harden unicode safety checks 2026-03-29 21:21:18 -04:00
kotlin-test.md fix: retire legacy command shims from default surface 2026-04-29 23:56:40 -04:00
learn-eval.md refactor(commands): remove duplicated content in skill-create and learn-eval (#2348) 2026-06-29 18:38:36 -07:00
learn.md fix: add command metadata frontmatter 2026-04-30 03:41:18 -04:00
loop-start.md fix: add command metadata frontmatter 2026-04-30 03:41:18 -04:00
loop-status.md feat: write loop-status snapshots 2026-04-30 12:25:14 -04:00
marketing-campaign.md feat: add marketing campaign agent skill and command (#2031) 2026-05-25 14:10:35 -04:00
model-route.md fix: add command metadata frontmatter 2026-04-30 03:41:18 -04:00
multi-backend.md docs: align command docs with shipped behavior (#2169) 2026-06-07 13:25:58 +08:00
multi-execute.md docs: align command docs with shipped behavior (#2169) 2026-06-07 13:25:58 +08:00
multi-frontend.md docs: align command docs with shipped behavior (#2169) 2026-06-07 13:25:58 +08:00
multi-plan.md docs: align command docs with shipped behavior (#2169) 2026-06-07 13:25:58 +08:00
multi-workflow.md docs: align command docs with shipped behavior (#2169) 2026-06-07 13:25:58 +08:00
orch-add-feature.md feat: add orch-* orchestrator skill family (#2153) 2026-06-07 16:15:31 +08:00
orch-build-mvp.md chore: reconcile publish/agent surfaces after PR batch 2026-06-15 14:21:28 -04:00
orch-change-feature.md feat: add orch-* orchestrator skill family (#2153) 2026-06-07 16:15:31 +08:00
orch-fix-defect.md feat: add orch-* orchestrator skill family (#2153) 2026-06-07 16:15:31 +08:00
orch-refine-code.md feat: add orch-* orchestrator skill family (#2153) 2026-06-07 16:15:31 +08:00
orch-review.md feat(workflows): re-land orch-review workflow + add /orch-review command (#2400) 2026-07-03 20:26:40 -07:00
plan-prd.md feat: add PRD planning command flow 2026-05-12 00:06:41 -04:00
plan.md feat: add PRD planning command flow 2026-05-12 00:06:41 -04:00
pm2.md fix: add command metadata frontmatter 2026-04-30 03:41:18 -04:00
pr.md feat: add PRD planning command flow 2026-05-12 00:06:41 -04:00
project-init.md docs: salvage ECC onboarding guide commands 2026-05-11 21:09:20 -04:00
projects.md fix: resolve CI failures on main — lint, hooks validator, and test alignment 2026-03-02 22:15:46 -08:00
promote.md fix: resolve CI failures on main — lint, hooks validator, and test alignment 2026-03-02 22:15:46 -08:00
prp-commit.md fix: harden claude plugin manifest surfaces 2026-04-08 16:27:30 -07:00
prp-implement.md fix: harden install planning and sync tracked catalogs 2026-03-31 22:57:48 -07:00
prp-plan.md feat: add PRP workflow commands adapted from PRPs-agentic-eng (#848) 2026-03-31 14:12:23 -07:00
prp-pr.md fix: harden claude plugin manifest surfaces 2026-04-08 16:27:30 -07:00
prp-prd.md fix: harden claude plugin manifest surfaces 2026-04-08 16:27:30 -07:00
prune.md feat: pending instinct TTL pruning and /prune command (#725) 2026-03-22 15:40:58 -07:00
python-review.md fix: retire legacy command shims from default surface 2026-04-29 23:56:40 -04:00
quality-gate.md docs: align command docs with shipped behavior (#2169) 2026-06-07 13:25:58 +08:00
react-build.md Add React language track with agents, skills, rules, and commands (#2024) 2026-05-28 07:32:52 -04:00
react-review.md Add React language track with agents, skills, rules, and commands (#2024) 2026-05-28 07:32:52 -04:00
react-test.md Add React language track with agents, skills, rules, and commands (#2024) 2026-05-28 07:32:52 -04:00
refactor-clean.md fix: add command metadata frontmatter 2026-04-30 03:41:18 -04:00
resume-session.md fix: harden unicode safety checks 2026-03-29 21:21:18 -04:00
review-pr.md feat: restore review and planning bundles 2026-04-05 17:51:56 -07:00
rust-build.md fix: retire legacy command shims from default surface 2026-04-29 23:56:40 -04:00
rust-review.md feat(agents): add Rust language support (#523) 2026-03-16 13:34:25 -07:00
rust-test.md fix: retire legacy command shims from default surface 2026-04-29 23:56:40 -04:00
santa-loop.md feat(commands): add santa-loop adversarial review command (#1052) 2026-03-31 14:05:31 -07:00
save-session.md fix: harden unicode safety checks 2026-03-29 21:21:18 -04:00
security-scan.md fix(plan-orchestrate): detect ecc@ecc marketplace + emit ecc: agent prefix (#2316) (#2409) 2026-07-03 20:00:51 -07:00
sessions.md refactor: consolidate duplicated hook-root resolver into shared resolveEccRoot() (#2368) (#2410) 2026-07-03 20:01:17 -07:00
setup-pm.md Revert "feat(ecc): prune plugin 43→12 items, promote 7 rules to .claude/rules/ (#245)" 2026-02-20 01:11:30 -08:00
skill-create.md refactor(commands): remove duplicated content in skill-create and learn-eval (#2348) 2026-06-29 18:38:36 -07:00
skill-health.md refactor: consolidate duplicated hook-root resolver into shared resolveEccRoot() (#2368) (#2410) 2026-07-03 20:01:17 -07:00
test-coverage.md fix: add command metadata frontmatter 2026-04-30 03:41:18 -04:00
update-codemaps.md fix: add command metadata frontmatter 2026-04-30 03:41:18 -04:00
update-docs.md fix: add command metadata frontmatter 2026-04-30 03:41:18 -04:00
vue-review.md fix: address Vue review PR feedback 2026-06-12 19:44:39 +08:00