ECC/docs
JongHyeok Park 914a58a716
feat(workflows): re-land orch-review workflow + add /orch-review command (#2400)
* feat(workflows): re-land orch-review workflow + add /orch-review command

Re-lands #2363 (reverted by #2393 to unbreak main's lint) and fixes the
root cause so it stays green:

- Restore workflows/orch-review.workflow.js + workflows/README.md.
- eslint.config.js: ignore 'workflows/**/*.workflow.*' and '.claude/workflows/**'
  per the maintainer's note in #2393. Workflow DSL scripts use both top-level
  export (ESM) and top-level return (the runtime wraps them in an async fn),
  which no single eslint sourceType can parse — they must be excluded, not
  lint-fixed. 'npx eslint .' is green with this ignore.
- Add commands/orch-review.md (the /orch-review surface) + regenerate
  docs/COMMAND-REGISTRY.json.

Supersedes #2397 (command-only), which referenced the reverted workflow.

* fix(workflows): address orch-review bot review findings

- Verifier uncertainty no longer demotes blockers (Greptile P1 + CodeRabbit):
  isReal=false only refutes when confidence >= 0.8; low-confidence 'false'
  is treated as uncertain and kept blocking (fail closed).
- Treat the diff (and finding text) as untrusted input in both review and
  verify prompts; ignore embedded directives (prompt-injection hardening).
- Validate changedFiles entries are strings, not just that it is an array.
- Enforce proof for HIGH/CRITICAL in FINDINGS_SCHEMA, not only in the prompt.
- Remove in-place mutation in dimension build + dedup merge (immutable).
- /orch-review: extract & validate a numeric PR id before shelling out to gh.
- Docs: complete the stats example, soften wording, refresh follow-up list.

* style(workflows): apply formatter to orch-review assembly

* fix(plan-orchestrate): detect ecc@ecc marketplace + emit ecc: agent prefix (#2316) (#2409)

* fix(plan-orchestrate): detect ecc@ecc marketplace + emit ecc: agent prefix (#2316)

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(ci): resync lockfiles with package.json (eslint 10) + migrate yarn.lock to Yarn 4 format

package.json requires eslint@^10.6.0 but the committed locks pinned 9.39.2, so
npm ci aborted and Yarn 4 hardened mode rejected the stale v1-classic yarn.lock
(YN0028). Regenerate package-lock.json and rewrite yarn.lock in Yarn 4 (berry)
format so npm ci and immutable yarn installs both pass.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(ci): require clean probe exit for Windows shell/bash detection; add pyyaml dev dep

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

---------

Co-authored-by: affaan <affaan@itomarkets.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* refactor: consolidate duplicated hook-root resolver into shared resolveEccRoot() (#2368) (#2410)

* fix(ci): resync lockfiles with package.json (eslint 10) + migrate yarn.lock to Yarn 4 format

package.json requires eslint@^10.6.0 but the committed locks pinned 9.39.2, so
npm ci aborted and Yarn 4 hardened mode rejected the stale v1-classic yarn.lock
(YN0028). Regenerate package-lock.json and rewrite yarn.lock in Yarn 4 (berry)
format so npm ci and immutable yarn installs both pass.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(ci): require clean probe exit for Windows shell/bash detection; add pyyaml dev dep

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* refactor: consolidate duplicated hook-root resolver into shared resolveEccRoot() (#2368)

The inline node -e resolver blob was duplicated ~60x across hooks.json,
command docs, and translations. Each copy inlined the full ~700-char
plugin-root search using a spread over nested array literals
(p.join(d,'plugins',...s) over [['ecc'],...]), which breaks Windows hook
execution due to shell quoting (#2368).

Collapse every copy to a 250-char locator that loads the committed
resolve-ecc-root module and delegates to resolveEccRoot() — no spread, no
nested array literals, no escaped double quotes. The real search logic now
lives in one tested module. Also route session-start-bootstrap.js through
resolveEccRoot() instead of its own duplicated reimplementation, and fix
the auto-update.md 'marketplace' (singular) typo along the way.

Guard tests updated: discovery behavior is asserted against resolveEccRoot();
the inline is asserted to delegate and to contain no Windows-fragile
constructs.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(resolve-ecc-root): restore full env-unset discovery in inline resolver

Address Greptile review on #2410: when CLAUDE_PLUGIN_ROOT is unset the
delegating inline could only load the resolver module from ~/.claude,
returning ~/.claude without ever reaching the plugin/cache search. Restore
the old inline's discovery breadth (exact plugin roots + versioned cache)
Windows-safely (no spread, nested arrays, or escaped quotes), then delegate
the authoritative decision to resolveEccRoot(). Add regression tests for
plugin-subdir and versioned-cache bootstrap with env unset.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

---------

Co-authored-by: affaan <affaan@itomarkets.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix: docs/COMMAND-REGISTRY.json check fails on fresh Windows clone (missing .gitattributes) (#2437)

* fix: add .gitattributes to force LF line endings for text files

npm run command-registry:check (part of npm test) fails on a fresh clone
on Windows with the common core.autocrlf=true setting: git checks out
docs/COMMAND-REGISTRY.json with CRLF, but generate-command-registry.js
always writes LF, so the strict string comparison in checkRegistry()
never matches. Forcing LF via .gitattributes makes checkouts consistent
across platforms regardless of a contributor's local autocrlf setting.

* fix: normalize CRLF line endings to LF per .gitattributes

pyproject.toml, src/llm/__init__.py, src/llm/prompt/builder.py,
src/llm/providers/claude.py, and tests/test_builder.py had CRLF line
endings committed to the repo, inconsistent with the rest of the
codebase. Renormalized via 'git add --renormalize .' now that
.gitattributes enforces eol=lf.

---------

Co-authored-by: Affaan Mustafa <me@affaanmustafa.com>

* chore(catalog): sync command counts (92->93) + register orch-review in agent.yaml surface

---------

Co-authored-by: devin-ai-integration[bot] <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: affaan <affaan@itomarkets.com>
Co-authored-by: Boube <109886533+Cb2i@users.noreply.github.com>
Co-authored-by: Affaan Mustafa <me@affaanmustafa.com>
2026-07-03 20:26:40 -07:00
..
architecture docs: define ECC platform value loop (#2119) 2026-06-02 19:51:02 +08:00
business feat: add dynamic workflow team orchestration surface 2026-06-04 21:45:13 +08:00
de-DE fix: context-size /compact trigger, Codex marketplace plugin path, live README badges (#2237) 2026-06-11 16:21:53 -04:00
design feat(layer4): line-range channel + trigger firing 2026-06-20 17:30:52 -04:00
drafts docs: mirror agentshield fleet ticket evidence 2026-05-18 10:24:21 -04:00
es fix: context-size /compact trigger, Codex marketplace plugin path, live README badges (#2237) 2026-06-11 16:21:53 -04:00
examples feat: add product capability planning lane 2026-04-05 16:58:02 -07:00
fixes fix: make plugin hooks run on Node 21+ and green the suite under modern Node (#2184) 2026-06-07 16:05:28 +08:00
ja-JP refactor: consolidate duplicated hook-root resolver into shared resolveEccRoot() (#2368) (#2410) 2026-07-03 20:01:17 -07:00
ko-KR fix: context-size /compact trigger, Codex marketplace plugin path, live README badges (#2237) 2026-06-11 16:21:53 -04:00
pt-BR fix: context-size /compact trigger, Codex marketplace plugin path, live README badges (#2237) 2026-06-11 16:21:53 -04:00
releases release: 2.0.0 — the agent harness operating system 2026-06-09 21:40:40 -04:00
ru fix: context-size /compact trigger, Codex marketplace plugin path, live README badges (#2237) 2026-06-11 16:21:53 -04:00
security docs: sync AgentShield adapter evidence 2026-05-19 20:54:15 -04:00
th fix(docs): sync marketplace add URL across translated READMEs (#2050) (#2068) 2026-06-07 13:26:58 +08:00
tr refactor: consolidate duplicated hook-root resolver into shared resolveEccRoot() (#2368) (#2410) 2026-07-03 20:01:17 -07:00
ur fix: context-size /compact trigger, Codex marketplace plugin path, live README badges (#2237) 2026-06-11 16:21:53 -04:00
vi-VN fix(docs): sync marketplace add URL across translated READMEs (#2050) (#2068) 2026-06-07 13:26:58 +08:00
zh-CN feat(workflows): re-land orch-review workflow + add /orch-review command (#2400) 2026-07-03 20:26:40 -07:00
zh-TW fix(docs): sync marketplace add URL across translated READMEs (#2050) (#2068) 2026-06-07 13:26:58 +08:00
ANTIGRAVITY-GUIDE.md docs: add Antigravity setup and usage guide (#552) 2026-03-20 00:21:37 -07:00
ARCHITECTURE-IMPROVEMENTS.md fix: route continuous learning observe hooks through node 2026-04-29 21:28:59 -04:00
ATLAS-CLOUD-GUIDE.md feat: add Atlas Cloud as LLM/AI provider (#2279) 2026-06-18 16:29:11 -04:00
capability-surface-selection.md docs: add capability surface selection guide 2026-04-06 14:21:28 -07:00
COMMAND-AGENT-MAP.md feat(agents): add typescript-reviewer agent (#647) 2026-03-19 20:49:23 -07:00
COMMAND-REGISTRY.json feat(workflows): re-land orch-review workflow + add /orch-review command (#2400) 2026-07-03 20:26:40 -07:00
continuous-learning-v2-spec.md feat: deliver v1.8.0 harness reliability and parity updates 2026-03-04 14:48:06 -08:00
ECC-2.0-GA-ROADMAP.md docs: sync live native payments gate evidence 2026-05-19 23:25:38 -04:00
ECC-2.0-REFERENCE-ARCHITECTURE.md docs: add release plugin publication checklist 2026-05-18 08:56:17 -04:00
ECC-2.0-SESSION-ADAPTER-DISCOVERY.md feat: orchestration harness, selective install, observer improvements 2026-03-14 12:55:25 -07:00
HERMES-OPENCLAW-MIGRATION.md feat: add ecc2 legacy plugin migration import 2026-04-10 11:53:17 -07:00
HERMES-SETUP.md docs: close ecc2 rc1 release policy drift 2026-04-29 19:52:09 -04:00
hook-bug-workarounds.md docs: add canonical hook bug workaround guide 2026-04-06 14:12:21 -07:00
JOYCODE-GUIDE.md feat: add JoyCode install target 2026-05-11 11:10:59 -04:00
legacy-artifact-inventory.md Track legacy localization tail in readiness dashboard 2026-05-17 14:47:29 -04:00
MANUAL-ADAPTATION-GUIDE.md docs: add manual adaptation guide for non-native harnesses 2026-04-05 14:39:55 -07:00
MCP-CONNECTOR-POLICY.md feat(mcp): single-connector default set + connector policy (#2219) 2026-06-09 23:28:35 -04:00
MEGA-PLAN-REPO-PROMPTS-2026-03-12.md feat: orchestration harness, selective install, observer improvements 2026-03-14 12:55:25 -07:00
PHASE1-ISSUE-BUNDLE-2026-03-12.md feat: orchestration harness, selective install, observer improvements 2026-03-14 12:55:25 -07:00
PLAN-PRD-PATTERN.md feat: add PRD planning command flow 2026-05-12 00:06:41 -04:00
PR-399-REVIEW-2026-03-12.md feat: orchestration harness, selective install, observer improvements 2026-03-14 12:55:25 -07:00
PR-QUEUE-TRIAGE-2026-03-13.md feat: orchestration harness, selective install, observer improvements 2026-03-14 12:55:25 -07:00
QWEN-GUIDE.md feat: add Qwen install target 2026-05-11 11:27:46 -04:00
SELECTIVE-INSTALL-ARCHITECTURE.md release: 2.0.0 — the agent harness operating system 2026-06-09 21:40:40 -04:00
SELECTIVE-INSTALL-DESIGN.md feat: orchestration harness, selective install, observer improvements 2026-03-14 12:55:25 -07:00
SESSION-ADAPTER-CONTRACT.md feat(session): add worker health alongside state in ecc.session.v1 (#751) 2026-03-22 15:39:51 -07:00
skill-adaptation-policy.md docs: add skill adaptation policy 2026-04-06 14:30:23 -07:00
SKILL-DEVELOPMENT-GUIDE.md refactor: move project guidelines example into docs 2026-04-05 15:03:59 -07:00
SKILL-PLACEMENT-POLICY.md feat: define skill placement and provenance policy (#748) 2026-03-22 15:39:48 -07:00
stale-pr-salvage-ledger.md docs: finish owner queue cleanup 2026-05-18 06:35:44 -04:00
token-optimization.md fix: add context monitor cost warning opt-out 2026-05-17 01:53:57 -04:00
TROUBLESHOOTING.md docs: add canonical hook bug workaround guide 2026-04-06 14:12:21 -07:00