KeiSeiKit-1.0/hooks/no-hand-edit-agents.sh
Parfii-bot d155afc554 fix(audit-m): tomd cache path-salt; bridges respects rollback; rollback rm-rf guard; placeholder URLs; research skill role-tag note; stack frontend-gap doc
- M1 (RULE 0.4): replace fabricated URLs 'https://example.invalid/PROJECT-D'
  and 'https://…/PROJECT-D' with plain text ('user's personal CLI predecessor').
- M2: tomd-preread cache key = basename + mtime + 8-char shasum of full path,
  so two files with the same basename+mtime at different paths no longer
  collide. Portable shasum shim; falls back to 'nohash' if shasum absent.
- M3: install.sh --with-bridges gated on ROLLED_BACK=0 so bridges are NOT
  emitted into $PWD after an ERR-trap rollback.
- M4: rollback() guards rm -rf "$orig" behind an existence check.
- M5: skills/research/SKILL.md front-matter note — role tags like
  'web-researcher' / 'meta-critic' are ad-hoc prompt labels for the generic
  kei-researcher subagent, NOT separate manifests. Prevents fruitless
  grep in _manifests/.
- M6: README adds a 'Frontend-stack coverage gap' callout listing the
  planned-but-not-shipped frameworks (React-Vite, Vue-Nuxt, SvelteKit,
  Astro, Angular, plain-web).
- M7: no-hand-edit-agents.sh documents at case block that the GENERATED
  marker is the SOLE source of truth — legacy unmarked .md files pass
  silently by design; re-run the assembler to adopt them.
2026-04-21 20:09:24 +08:00

53 lines
1.9 KiB
Bash
Executable file

#!/bin/sh
# PreToolUse(Edit|Write) — block hand-editing generated agent .md files.
#
# Generated files start with: <!-- GENERATED by _assembler ...
# Edit the manifest at _manifests/<name>.toml instead.
#
# Override: set AGENT_MIGRATION=1 in env to allow hand edits (migration / emergency).
#
# Stdin: JSON with tool_input.file_path
# Silent fall-through if jq is absent; otherwise `set -eu` would abort and
# Claude Code would refuse Edit/Write system-wide.
command -v jq >/dev/null 2>&1 || exit 0
set -eu
[ "${AGENT_MIGRATION:-0}" = "1" ] && exit 0
FILE=$(jq -r '.tool_input.file_path // empty')
[ -n "$FILE" ] || exit 0
# Only care about files directly under ~/.claude/agents/*.md
# (not blocks/, manifests/, assembler/, template, generated preview)
#
# NOTE on staleness: we use the `<!-- GENERATED by _assembler -->` marker
# on line 1 as the SOLE SOURCE OF TRUTH for "is this file generated?".
# Legacy agent .md files that were produced before the assembler existed
# (and therefore lack the marker) will pass this hook silently. That is
# intentional — the marker is how the assembler self-declares ownership,
# and any file without it is assumed hand-authored. Re-run the assembler
# to adopt an older file into the managed set.
case "$FILE" in
"$HOME/.claude/agents/_"*) exit 0 ;;
"$HOME/.claude/agents/"*.md) ;;
*) exit 0 ;;
esac
# Detect generated marker in the first 10 lines (sole truth — see NOTE above)
if [ -f "$FILE" ] && head -10 "$FILE" | grep -q 'GENERATED by _assembler'; then
NAME=$(basename "$FILE" .md)
echo "[no-hand-edit-agents] BLOCKED: $FILE is generated." >&2
echo "" >&2
echo "Edit the manifest instead:" >&2
echo " ~/.claude/agents/_manifests/$NAME.toml" >&2
echo "" >&2
echo "Or edit a shared block:" >&2
echo " ~/.claude/agents/_blocks/<block>.md" >&2
echo "" >&2
echo "Override (emergency only): export AGENT_MIGRATION=1" >&2
exit 1
fi
exit 0