mirror of
https://github.com/phuryn/pm-skills.git
synced 2026-09-20 06:15:53 +03:00
Both sides added real content and this merge keeps both rather than picking one. The branch predates the v2.1.0 release, so merging it straight would have REVERTED that release: every plugin.json back from 2.1.0 to 2.0.0, and tests/test_consistency.py and tests/test_validator.py deleted. Merged instead of pushed. Conflicts, all resolved by combining: - pm-ai-shipping/.claude-plugin/plugin.json - v2.1.0's version, the branch's description. - security-audit-static - both checks survive as two steps: verify citations (2.1.0), then report with the OWASP Top 10 coverage backstop (branch). - ship-check - the new correctness review becomes Step 3, and 2.1.0's parallel security + performance pair renumbers to Steps 4 + 5 behind it, keeping the branch's model-mix carry-through on the security bullet. - Notes - 2.1.0's untrusted-input rule and both of the branch's bullets. The v2.1.0 test suite then caught what the branch had missed: a third skill in pm-ai-shipping without the counts to match. Root README headline 68 -> 69 skills, its pm-ai-shipping summary 2 -> 3, and marketplace.json's total and description synced to plugin.json. 15/15 tests and the validator pass. No version bump. The CHANGELOG entry sits under `## Unreleased`, which the tag-on-merge workflow ignores by design, so this lands the skill without cutting a release - that call is Pawel's. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01G42vsxSKL7je39AsHZ5aJm
3.8 KiB
3.8 KiB
Changelog
Unreleased
pm-ai-shipping
- Added the code-review skill: correctness is the core engine, with performance and security as optional sub-cases of it rather than separate methods. It anchors on agreements between participants across a boundary — the defects that stay invisible file-by-file because each side reads as reasonable alone — forces a violating execution, and refutes every candidate before reporting.
- Added a correctness taxonomy reference built from real fix history, plus performance and security reference sheets the same engine reads.
/ship-checkgained a correctness review as Step 3, before the security and performance audits, and an independent unsteered pass by a second model as Step 6./security-audit-staticgained an OWASP Top 10 coverage backstop: every surviving finding is mapped to a category, and any category with zero findings is flagged "not covered — double-check" rather than silently passing. It is a coverage check, not a mandate to invent findings.
v2.1.0 — 2026-07-03
pm-ai-shipping
/security-audit-staticfindings now carry a mandatory Evidence line (file:line+ verbatim snippet), and every citation is re-verified against the file before the final report ships.- Subagent fan-out has a concrete trigger (scope over ~30 files / ~5,000 lines) and a structured candidate-record contract, so parallel audit slices merge cleanly into one self-refute pass.
/performance-audit-staticnow hunts N+1 queries and request waterfalls — the most common perf failure in AI-generated code — alongside over-fetching, indexes, and caching, and gained a refute-before-reporting pass (dynamic field access, existing indexes, hot-path evidence).- Both audit commands pre-approve a read-only toolset (
allowed-tools): read, search, fan out, and write underreports/— never edit the code under audit. - The audited repo is treated as untrusted input across the kit: instructions embedded in code, comments, or docs are data to analyze — a steering attempt is itself a finding — never directives to follow.
/ship-checkruns the security and performance audits as parallel subagents once the docs exist.- Security reports gained severity anchors (what Critical/High/Medium/Low mean) and a consolidation rule (more than ~12 findings → lead with the worst, group the tail by root cause).
- Docs and reports now use repo-relative paths (
documentation/,reports/) — the old absolute forms (/documentation) could resolve to the filesystem root — and reports are always written, with the path announced, instead of "optionally".
Repo
- Added this
CHANGELOG.mdas the release source of truth with auto-tag-and-release on merge (adapted from claude-usage): pushing a new## vX.Y.Zheading tomaintags that version and publishes a GitHub Release with the section as notes — gated on the test suite and a version-sync check. - Added a test suite (
tests/) and a Tests workflow (every PR and push tomain): plugin-spec validation plus docs consistency — README skill/command counts vs. disk, marketplace plugin list vs. directories, version sync across all manifests, CHANGELOG format. - CONTRIBUTING now documents the changelog convention (every user-facing change gets a bullet; contributors credited inline) and the release procedure.
- Docs since v2.0.0: native Codex CLI install path; companion badges (burnstop, claude-usage).
v2.0.0 — 2026-06-05
- Added the pm-ai-shipping plugin (AI Shipping Kit):
/ship-check,/document-app,/derive-tests,/security-audit-static,/performance-audit-static, plus theshipping-artifactsandintended-vs-implementedskills. - Added the
strategy-red-teamskill and/red-team-prdcommand to pm-execution. - Refreshed the root README; added
CLAUDE.md/AGENTS.mdagent guidance.