Project-Template/docs/architecture/scripts
null 734b6af828 feat(plan): six sections every plan must name, and the files an agent reads first
WORK_CYCLE.md covered only the end of the cycle. A cycle has two ends, and
the same six questions kept having to be asked out loud on every piece of
work. They are now mandatory in every plan, each justified by something this
household has actually paid for:

  unified code      eight copies of secrets.sh once existed here and five of
                    seven could not detect the most common secret shape --
                    INCLUDING THE TEMPLATE, so every project scaffolded from
                    it inherited a blind scanner
  error handling    the recurring fault is the silent pass, not the crash
  logging           an append-only log is unbounded by construction
  blind spots       named ones get fixed
  landmine fixes    the trap found while passing is cheapest to fix while
                    passing
  hardcode little   derive it, or justify the constant

GUARDS.md was five sections behind the project that has been learning; 11,
12 and 13 are backported, genericised to match the template's style. 13 is
the narrow form of the sixth rule, and WORK_CYCLE now cites it -- so
backporting it is what makes that citation true rather than a broken
reference.

Also adds the three files an agent reads BEFORE it reads docs/:

  CLAUDE.md             short, and it POINTS at DOC_TRUST_MAP rather than
                        repeating it -- a second copy of the map is the
                        failure that map exists to prevent. Carries the
                        exit-code table, the commit gates, and two standing
                        instructions: flag what looks wrong even when it is
                        not what you were asked about, and never print a
                        credential -- not from a file, not from a command's
                        output, not from a config subtree "with the secrets
                        filtered out", because that filter has failed before
                        by matching key NAMES while the secret sat inside an
                        object whose name was innocent
  .claudeignore         excludes artifacts and NEVER docs/. The Command
                        Center reads this repository's documents at a commit;
                        a generic ignore file that sweeps "documentation" or
                        "data" starves both the agent and the reconcile, and
                        everything still runs, just blind
  .claude/settings.json deny rules in the double-slash absolute form. A
                        tilde-style rule looks right in review and silently
                        matches nothing. It closes the Read TOOL only -- a
                        shell reads a file a hundred ways -- so it catches
                        the accidental read, not the determined one

scaffold.sh gains a ROOT array for the three, kept apart from DOCS so the
H1-plus-status-block check stays meaningful rather than being loosened into
a warning that is always wrong (GUARDS.md 5).

Verified: scaffold --dry-run into a scratch repo creates 22 files including
all three, with no HEADERLESS warning; doc-claims passes with 124 claimed
paths, all present.

Does not touch docs/architecture/scripts/secrets.sh, which carries someone
else's uncommitted improvement.
2026-09-01 21:44:00 -05:00
..
audit-gate.mjs chore(repo): put the template under version control 2026-08-17 22:44:26 -05:00
backup.sh chore(repo): put the template under version control 2026-08-17 22:44:26 -05:00
check-env.sh chore(repo): put the template under version control 2026-08-17 22:44:26 -05:00
commit-mine.sh chore(repo): put the template under version control 2026-08-17 22:44:26 -05:00
controls.sh feat(ops): controls.sh, which controls this project actually has 2026-08-17 23:11:52 -05:00
dead-code.py chore(repo): put the template under version control 2026-08-17 22:44:26 -05:00
deploy.py chore(repo): put the template under version control 2026-08-17 22:44:26 -05:00
dev.sh chore(repo): put the template under version control 2026-08-17 22:44:26 -05:00
doc-claims.sh fix(guards): a bare filename is a weaker claim than a path 2026-08-17 23:45:02 -05:00
doc-triggers.py fix(tools): doc-triggers could not see the documents at the repository root 2026-08-18 00:12:49 -05:00
duplication.py chore(repo): put the template under version control 2026-08-17 22:44:26 -05:00
forgejo-issue.py docs(tracker): an issue that produces a data shape names its surface 2026-08-22 14:05:11 -05:00
healthcheck.sh docs(template): the owner is _null 2026-08-17 22:47:56 -05:00
migrate.sh chore(repo): put the template under version control 2026-08-17 22:44:26 -05:00
preflight.sh feat(security): preflight.sh distinguishes present from in force 2026-08-17 23:30:37 -05:00
prove-guard.sh fix(guards): prove-guard rejected correct guards, and refused with the wrong code 2026-08-17 23:39:17 -05:00
release-notes.mjs chore(repo): put the template under version control 2026-08-17 22:44:26 -05:00
release.sh chore(repo): put the template under version control 2026-08-17 22:44:26 -05:00
restore-check.sh feat(ops): restore-check.sh, the other half of backup.sh 2026-08-17 23:07:36 -05:00
scaffold.sh feat(plan): six sections every plan must name, and the files an agent reads first 2026-09-01 21:44:00 -05:00
secrets.sh fix(secrets): the scanner printed the credential it found 2026-08-17 23:08:57 -05:00
status.sh chore(repo): put the template under version control 2026-08-17 22:44:26 -05:00
verify-before-done.sh feat(guards): gate the claim of being finished, not only the artifact 2026-08-29 08:42:00 -05:00
verify.sh chore(repo): put the template under version control 2026-08-17 22:44:26 -05:00