Both sides added real content and this merge keeps both rather than picking one.
The branch predates the v2.1.0 release, so merging it straight would have REVERTED that
release: every plugin.json back from 2.1.0 to 2.0.0, and tests/test_consistency.py and
tests/test_validator.py deleted. Merged instead of pushed.
Conflicts, all resolved by combining:
- pm-ai-shipping/.claude-plugin/plugin.json - v2.1.0's version, the branch's description.
- security-audit-static - both checks survive as two steps: verify citations (2.1.0), then
report with the OWASP Top 10 coverage backstop (branch).
- ship-check - the new correctness review becomes Step 3, and 2.1.0's parallel security +
performance pair renumbers to Steps 4 + 5 behind it, keeping the branch's model-mix
carry-through on the security bullet.
- Notes - 2.1.0's untrusted-input rule and both of the branch's bullets.
The v2.1.0 test suite then caught what the branch had missed: a third skill in pm-ai-shipping
without the counts to match. Root README headline 68 -> 69 skills, its pm-ai-shipping summary
2 -> 3, and marketplace.json's total and description synced to plugin.json. 15/15 tests and the
validator pass.
No version bump. The CHANGELOG entry sits under `## Unreleased`, which the tag-on-merge workflow
ignores by design, so this lands the skill without cutting a release - that call is Pawel's.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G42vsxSKL7je39AsHZ5aJm
Restructure, per the ask that code review be the parent and the other two
dimensions its sub-cases:
- SKILL.md gains a "one engine, three anchors" section. Correctness is the
core and stays inline; performance and security move to their own reference
files, loaded only when selected.
- references/performance-review.md (new) — a universal, stack-agnostic core
(repeated work, growth relationships, retention, copying, contention,
amplification) plus the three-part bar for a performance finding. Defers the
database/web checklist to /performance-audit-static instead of restating it.
- references/security-review.md (new) — trust boundaries and sinks for code
with no web surface, and the one rule that INVERTS relative to correctness:
attacker-equals-victim refutes a security finding but never a correctness
one. Defers the full procedure to /security-audit-static.
- Both audit commands now say they are the specialisation behind their
sub-case, so the narrow entry points still lead back to the skill.
ship-check gains two stages it was missing:
- Step 3, correctness review — the pass neither audit performs: logic and
state defects that compile clean and pass the suite.
- Step 6, independent unsteered review — a fresh session of a second model
(Codex or equivalent), given no checklist and no prior findings, with the
subject computed from a diff rather than described. Every finding is
hand-verified against the code before it enters the packet, since an
unsteered reviewer carries no refutation discipline of its own. The packet
reports whether it ran clean or did not run at all - those are different
signals.
Also carries the working-tree edits already in progress: model-and-orchestration
guidance on both audits, the OWASP A02/A06/A09 backstop, CSP in the
output-encoding bullet, the prompt-injection/agent-abuse bullet, and the Audit
Provenance section (now also naming the second model).
No version bump - not tested against the benchmark yet.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G42vsxSKL7je39AsHZ5aJm
pm-ai-shipping: mandatory Evidence citations verified before reporting,
concrete subagent fan-out contract, read-only allowed-tools on both audits,
N+1/waterfall detection and a refute pass in the performance audit,
untrusted-input hardening across the kit, parallel audits in /ship-check,
severity anchors + report consolidation, repo-relative paths.
Repo: CHANGELOG.md as release source of truth with auto-tag-and-release on
merge to main (adapted from phuryn/claude-usage, minus the .vsix build),
Tests workflow on every PR/push, unit + docs-consistency test suite,
contributor-credit conventions in CONTRIBUTING, all manifests synced at 2.1.0.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011URgT9hYuNrXeCvzjnqRxJ