Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .claude/commands/audit.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,9 +29,9 @@ the claims live in the documents themselves and are harvested at run time. (The

## Process

### 0. Sync
### 0. Isolate and orient

Run `bash setup.sh` from the workspace root. Stale git state invalidates findings.
Run `node scripts/workspace-start.mjs --session <stable-key> [needed-component-repos…]` before edits; use the returned workspace and component worktrees, read its reorientation report and changed guidance. `bash setup.sh` is installation/explicit maintenance, not session startup. If an anchor needs a component that is absent, request that component with the same session key or report it as unverified; never turn a missing checkout into a false drift finding. A read-only request is not permission to run this fix-executing command.

### 1. Mechanical pass (always full, always first)

Expand Down
49 changes: 4 additions & 45 deletions .claude/rules/youcoded-toolkit.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,57 +4,16 @@ paths:
# root, never inside a session worktree — same bug as registries.md. See
# .claude/rules/README.md.
- "**/youcoded-core/**"
last_verified: 2026-07-15
last_verified: 2026-09-27
verify:
- path: youcoded-core/plugin.json
- path: youcoded-core/hooks/hooks-manifest.json
- path: youcoded-core/hooks/write-guard.sh
- path: youcoded-core/hooks/worktree-guard.sh
---

# youcoded-core Plugin Rules
# Archived youcoded-core — read-only historical reference

You are editing the `youcoded-core` Claude Code plugin — a BUNDLED first-party plugin (alongside `wecoded-themes-plugin` + `wecoded-marketplace-publisher`), NOT a separate toolkit layer. Read workspace `docs/toolkit-structure.md` for full context.
**The GitHub repository was archived 2026-09-20.** Do not edit, version, tag, release, or push this repository. Its clone is retained for historical inspection and for older v1.2.4 installations; it is not a release target. A release or hook fix belongs in the app's bundled copies (`youcoded/desktop/hook-scripts/` and `youcoded/app/src/main/assets/`), which the app's tests pin to each other. Never change the running app's installed hooks or `~/.claude/settings.json` as a workaround.

## Status

**Being deprecated.** `docs/active/plans/2026-04-21-deprecate-youcoded-core.md` is the active deprecation plan — `write-guard.sh` is moving into the app natively, and the repo will eventually be archived. Prefer fixing bugs over adding features here. New functionality belongs in the app or in a separate marketplace plugin.

## Structure

Single plugin with one manifest at the root: `youcoded-core/plugin.json` (currently v1.2.1). Phase 3 flattened the former three-layer decomposition — there is no `core/`, `life/`, or `productivity/` subdirectory.

Top-level directories:
- `hooks/` — `hooks-manifest.json` + hook shell scripts
- `skills/` — only `setup-wizard/` and `remote-setup/` remain in-plugin
- `commands/` — `/update`, `/health`, `/diagnose`
- `bootstrap/` — historical manual-install script
- `scripts/` — post-update, migrations, security sweep

Other skills (journal, encyclopedia, task inbox, theme-builder, skill-creator, google services) moved out during Phase 3 and now ship as independent marketplace plugins.

## Hard rules

- **Never edit hooks in `~/.claude/settings.json` directly.** Update `youcoded-core/hooks/hooks-manifest.json` — the desktop app's `HookReconciler` merges it in on launch. Direct edits get overwritten.
- **`.sh` files MUST have execute bit set.** Git on Windows doesn't set this automatically. After creating or renaming a script: `git update-index --chmod=+x path/to/file.sh`. Missing execute bit is the #1 cause of "hook does nothing" bugs.
- **`config.json` is portable; `config.local.json` is machine-specific.** `config.local.json` is rebuilt every session by `session-start.sh` — don't commit or sync it.
- **Feature work uses `git worktree add`**, not branch creation in the main plugin dir. `worktree-guard.sh` blocks branch switches here.

## Skills

Directories with `SKILL.md` files. YAML frontmatter `description` is how Claude discovers them. Be specific and concrete in descriptions — they're always in context.

Currently in-plugin:
- `skills/setup-wizard/` — conversational first-run helper
- `skills/remote-setup/` — remote-access pairing flow

## Hooks

Declared in `youcoded-core/hooks/hooks-manifest.json`. Five hooks across three types. Guards to know about:
- `write-guard.sh` — PreToolUse, blocks writes when another session recently modified the file (being absorbed into the app natively per the deprecation plan)
- `worktree-guard.sh` — PreToolUse for Bash, blocks branch switches in the plugin dir
- `session-start.sh` — runs at session start, injects encyclopedia context, runs version migrations

## Version bumping

Bump `plugin.json` `version` on master. `.github/workflows/auto-tag.yml` detects the change vs `HEAD~1` and creates a `vX.Y.Z` tag automatically.
Why this rule is still path-scoped here: opening archived files for reference should not turn an old instruction into authorization to write them. See `docs/active/plans/2026-04-21-deprecate-youcoded-core.md` for remaining app-side retirement and `youcoded-admin/skills/release/SKILL.md` for the current app-only release.
38 changes: 16 additions & 22 deletions .claude/skills/wrap-up/SKILL.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: wrap-up
description: End-of-session workspace retrospective — replay what this session actually did (context loaded, searches forced by missing docs, tooling used, wrong turns, what Destin said he wants), turn that friction into durable workspace improvements, then push and ask about merging. Use whenever Destin says "wrap up", "wrap this up", "close out this session", "let's finish up", "we're done", "anything to improve?", or asks what this session taught us about the workspace. Every finding ends the session applied, filed as a dated roadmap entry, or explicitly dropped.
description: Use when Destin says "wrap up", "wrap this up", "close out this session", "let's finish up", "we're done", "anything to improve?", or asks what this session taught us about the workspace.
---

# /wrap-up — turn this session into a better workspace
Expand All @@ -9,12 +9,14 @@ A session is the only thing that knows where the workspace failed it; once the t
closes, that knowledge is gone. Two prior retrospectives proved the failure mode: findings
written down, never closed, rediscovered twice.

**This is a PROCESS, not a report generator.** Every recommendation ends this session
**applied**, **a dated roadmap entry** (`docs/roadmap/<area>.md` — `ROADMAP.md` → "Filing
an item"), or **dropped with a reason**.
**This is a PROCESS, not a report generator.** Within an authorized editing session,
every recommendation ends **applied**, **a dated roadmap entry** (`docs/roadmap/<area>.md`
— `ROADMAP.md` → "Filing an item"), or **dropped with a reason**. For a read-only session,
report the recommendation and ask before recording or applying it; wrap-up does not widen
what Destin authorized.

Retrospective first, while the session is fresh. Pushing and closing out (Step 6) is a
checklist that survives a tired session; honest self-replay is not.
Retrospective first, while the session is fresh. Branch-state reporting and close-out
(Step 6) are a checklist that survives a tired session; honest self-replay is not.

## What "better" means here

Expand Down Expand Up @@ -100,7 +102,7 @@ poisons the ones that matter. A short session can end here.

## Step 5 — land them, on the session's branch

Retrospective edits ship WITH the work, so everything pushes and merges together:
When edits are authorized, retrospective changes stay on the same session branches as the work; neither this step nor wrap-up itself authorizes a push or merge:

- Sub-repo edits (a pinning test, an ast-grep rule, a WHY comment) → the session's feature
branch in that repo.
Expand All @@ -117,15 +119,11 @@ Then:
- **Roadmap:** the area file whose `Filing test:` says yes; **dedupe by file or symbol name,
not by symptom** — searching `flaky` instead of `sync-spaces-engine` filed a duplicate.
- **Dropped:** say so in your reply, with the reason. An unrecorded rejection gets re-argued.
- **Always:** append this session's entry to `docs/wrap-ups.md` — its header explains the
format. That file is Step 1 for the next session; skipping it is how the same friction
gets rediscovered.
- **When editing is authorized:** append this session's entry to `docs/wrap-ups.md` — its header explains the format. In a read-only session, give the retrospective in chat and ask before recording it. The ledger is Step 1 for the next editing session.

## Step 6 — push everything, then ask about merging
## Step 6 — identify local-only work and report the boundary

**Push every branch this session touched. Do not ask.** A push is a backup, not a release:
it ships nothing, and `git push -d` undoes it. An unpushed branch is the only state where
work can actually be lost.
**Inspect this session's branches; publish only within the authorization for this task.** A push backs up commits but also publishes them to the remote, and a later branch deletion does not erase copies others fetched. If Destin asked to push, verify the branch and scan public-repo commits for secrets first. Otherwise report the commits that exist only on this machine; do not silently push them. A read-only session must not become an editing or shipping session because it is ending.

Then sweep for anything else local-only — other sessions leave branches behind, and one
sweep found seven across four repos:
Expand Down Expand Up @@ -164,8 +162,7 @@ done

For a fuller inventory across every OLD worktree, not just this session's own, `node scripts/prune-worktrees.mjs` reports which are actually safe to delete (clean, merged, unused) — dry run only; never run its `--apply` without Destin naming the exact ones.

**Secrets-scan any branch before its first push to a PUBLIC repo — including swept ones you
never read.** `youcoded` and `youcoded-dev` are public; `youcoded-admin` is not.
**Secrets-scan any branch before its first authorized push to a PUBLIC repo.** For other sessions' branches, report local-only work rather than publishing it under this session's authority. `youcoded` and `youcoded-dev` are public; `youcoded-admin` is not.

Then run the close-out check per branch — read-only, always exits 0, and it detects whether
the branch landed and checks accordingly:
Expand All @@ -174,17 +171,14 @@ the branch landed and checks accordingly:
bash scripts/close-out.sh <branch> [<repo>] # repo: a sub-repo name, or `workspace`
```

**Finish every line it reports.** A `TODO` is yours to do now. A `--` line is a judgement it
deliberately refuses to make — make it: close the roadmap item **if the work actually
**Address every line within the authorized scope; report the rest.** A `TODO` is not permission to edit or ship beyond the task. A `--` line is a judgement it
deliberately refuses to make — make it only with evidence: close the roadmap item **if the work actually
shipped** (`node scripts/roadmap-check.mjs --close <area>:<text> --ref "<commit or PR>"`, then archive its
report); give the subsystem a `docs/MAP.md` row
("no rule" is an answer, "no row" is not); move `status: shipped` docs to `docs/archive/`
and repoint cross-links — but a doc describing work still in review stays in `docs/active/`,
or it goes invisible to the reviewing session.

**Then ask Destin one question: "Ready to merge?"** With a recommendation and, per branch,
what is actually proven — did `scripts/verify.sh` pass, has any of it run for real, what is
unverified. **Default to NOT merging** unless he says yes; he decides. Never end a turn
suggesting a merge (`CLAUDE.md` → iteration mode), and do not open a PR unless he asks.
**End with the state of each branch and what was actually proven** — did `scripts/verify.sh` pass, has any of it run for real, what is unverified or only saved locally. Do not propose a merge, open a PR, or merge as a routine wrap-up step. If Destin expressly asks whether to merge, present the evidence and wait for his instruction; merging and pushing require explicit authorization (`CLAUDE.md` → Git, worktrees, and shipping).

**You run the commands, not Destin.** Never end a turn handing him something to type.
2 changes: 1 addition & 1 deletion CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -77,7 +77,7 @@ Never invent an error cause. Use `<ErrorState>`: specific accurate detail + Retr

## Development Workflow

Load only the procedure needed. Existing approval gates still apply; moving their recipes out of this file does not waive them.
Choose the route by request (read-only review, edit, UI feature, fix-executing audit, wrap-up, or release) in `docs/workspace-workflows.md` → Choosing a workflow. Load only the procedure needed. Existing approval gates still apply; moving their recipes out of this file does not waive them.

### New Features & UI/UX Changes

Expand Down
2 changes: 1 addition & 1 deletion ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -71,7 +71,7 @@ Target: `v1.3.1`
## Backlogs
| Area | Open | Needs verify | Decisions | Parked |
|---|---|---|---|---|
| [dev-workspace](docs/roadmap/dev-workspace.md) — building the app, not the app | 101 | 32 | 4 | 9 |
| [dev-workspace](docs/roadmap/dev-workspace.md) — building the app, not the app | 101 | 31 | 4 | 9 |
| [native-harness](docs/roadmap/native-harness.md) — the app's own agent doing work | 57 | 10 | 5 | 25 |
| [user-interface](docs/roadmap/user-interface.md) — shared primitives, chrome, layout, copy | 40 | 16 | 2 | 6 |
| [remote-access](docs/roadmap/remote-access.md) — reaching the app from another device | 30 | 7 | 1 | 4 |
Expand Down
4 changes: 2 additions & 2 deletions docs/MAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -75,8 +75,8 @@ Rules live in `.claude/rules/`; depth docs are read-on-demand (`youcoded/docs/`,
| Marketplace worker | `wecoded-marketplace/worker/src/lib/analytics.ts`<br>`wecoded-marketplace/worker/src/lib/admin-filter.ts` | worker-backend | `wecoded-marketplace/docs/worker-backend.md` | `wecoded-marketplace/worker/test/analytics-lib.test.ts`<br>`wecoded-marketplace/worker/test/admin-filter.test.ts`<br>`wecoded-marketplace/.github/workflows/worker-ci.yml` (pre-merge typecheck+test) |
| Marketplace catalog (serve + hourly ingest) | `wecoded-marketplace/worker/src/catalog/routes.ts`<br>`wecoded-marketplace/worker/src/catalog/publish.ts`<br>`wecoded-marketplace/worker/src/catalog/auth.ts`<br>`wecoded-marketplace/worker/migrations/0006_catalog.sql`<br>`wecoded-marketplace/scripts/catalog/build.mjs`<br>`wecoded-marketplace/scripts/catalog/lib/capabilities.mjs`<br>`wecoded-marketplace/scripts/catalog/sources/` (wecoded · docker · awesome-copilot · cursorrules)<br>`youcoded/desktop/src/main/skill-provider.ts` (`fetchIndex` reads it)<br>`youcoded/app/src/main/kotlin/com/youcoded/app/skills/MarketplaceFetcher.kt` | catalog<br>registries (client side) | `wecoded-marketplace/docs/catalog.md` | `wecoded-marketplace/worker/test/catalog.test.ts`<br>`wecoded-marketplace/worker/test/catalog-publish.test.ts`<br>`wecoded-marketplace/scripts/catalog/test/` (`node --test scripts/catalog/test/*.test.mjs`)<br>`youcoded/desktop/tests/skill-provider-catalog.test.ts`<br>`wecoded-marketplace/.github/workflows/catalog-ingest.yml` (hourly; red run IS the alarm) |
| Claude Code hooks the app registers (`~/.claude/settings.json`) | `youcoded/desktop/src/main/hook-reconciler.ts` (adds required hooks, enforces MAX timeout, **prunes dead ones — ownership is decided by `listInstalledPluginDirs()`, which only walks dirs that EXIST**)<br>`youcoded/desktop/src/main/legacy-cleanup.ts` (deletes the retired `~/.claude/plugins/youcoded-core/` clone at launch — deleting it is what makes its leftover entries look user-added, so the reconciler carries an owned-legacy-root list)<br>`youcoded/desktop/src/main/claude-code-registry.ts` (`listInstalledPluginDirs`)<br>`youcoded/desktop/src/main/hook-relay.ts` (the named pipe hooks talk back through — `HookOwnerGate` drops hooks from a `claude` nested inside a session, an ask for a session this app does not own is handed straight back undecided, and a held ask gets the app's 2 h hold; Android: `EventBridge.kt`, see the Claude Code prompts row)<br>`youcoded/desktop/scripts/install-hooks.js` (the app's OWN hooks — deliberately separate from the plugin reconciler)<br>`youcoded/desktop/src/main/claude-settings.ts` (**the ONE reader/writer of the file** — read once, compare before write under the lock; a corrupt file becomes a timestamped backup and a fresh file)<br>`youcoded/desktop/src/main/launch-settings-chores.ts` (the boot chores — reconcile, prompt-suggestion off, retention default — in one locked cycle)<br>`youcoded/app/src/main/kotlin/com/youcoded/app/runtime/Bootstrap.kt` (~L900 — Android's own prune; it drops the legacy prefix unconditionally, desktop only when the file is missing) | (no rule) | `docs/toolkit-structure.md` | `youcoded/desktop/tests/hook-reconciler-prune.test.ts`<br>`youcoded/desktop/tests/hook-relay.test.ts` (owner gate, pass-through, the hold)<br>`youcoded/desktop/tests/permission-timeout-margins.test.ts` (app 2 h < relay 2 h 30 m < Claude Code 3 h — never tidy them equal)<br>`youcoded/desktop/tests/legacy-cleanup.test.ts`<br>`youcoded/desktop/tests/claude-settings.test.ts`<br>`youcoded/desktop/tests/launch-settings-chores.test.ts` |
| youcoded-core plugin | `youcoded-core/hooks/hooks-manifest.json`<br>`youcoded-core/plugin.json` | youcoded-toolkit | `docs/toolkit-structure.md` | manual (hook runtime) |
| Build & release | `youcoded/app/build.gradle.kts`<br>`youcoded/scripts/build-web-ui.sh`<br>`youcoded/.github/workflows/desktop-test-build.yml` (beta builds)<br>`youcoded/desktop/src/shared/version-line.ts` | — | `docs/build-and-release.md` | `youcoded/.github/workflows/desktop-release.yml`<br>`youcoded/desktop/tests/version-line.test.ts` |
| Archived youcoded-core plugin (read-only history; not a release target) | `youcoded-core/hooks/hooks-manifest.json`<br>`youcoded-core/plugin.json` | youcoded-toolkit | `docs/toolkit-structure.md` (historical) | no new releases; app hook parity: `youcoded/desktop/tests/write-guard-contract.test.ts` |
| Build & release | `youcoded-admin/skills/release/SKILL.md` (app-only procedure)<br>`youcoded/app/build.gradle.kts`<br>`youcoded/scripts/build-web-ui.sh`<br>`youcoded/.github/workflows/desktop-test-build.yml` (beta builds)<br>`youcoded/desktop/src/shared/version-line.ts` | — | `docs/build-and-release.md` | `youcoded-admin/skills/release/release-skill.test.mjs`<br>`youcoded/.github/workflows/desktop-release.yml`<br>`youcoded/.github/workflows/android-release.yml`<br>`youcoded/desktop/tests/version-line.test.ts` |

## Hot paths — the exact file, without a search

Expand Down
Loading
Loading