Umbrella issue for a full-codebase review of main at 759a34b . Baseline was healthy: ruff, ruff format, mypy (strict) and all 156 tests pass. Each finding is a sub-issue.
Suggested order
Installer data-safety: uninstall deletes unmanaged and locally modified files #95 (uninstall deletes unmanaged or edited files), status reports the user's own files in shared directories as orphans #96 (status false orphans). Both are small.
Release gating: Release workflow: any v* tag on any commit publishes to PyPI, and tests don't run #108 (any v* tag publishes; tests don't run).
Wrong skill guidance: ci-workflow-review: GitLab script-injection guidance is wrong, and the eval fixture rewards it #101 (GitLab injection advice and fixture), Skills cite outdated or wrong OWASP/ASVS references #102 (outdated OWASP/ASVS references).
Adapters: Codex adapter installs to a path Codex doesn't read; custom prompts are deprecated #99 (Codex project install is a no-op), Move adapters to native SKILL.md skill folders (Copilot, Cursor, Kiro, Codex) #100 (move to native SKILL.md skill folders).
Evals: Eval scorer is too loose: wrong reports can pass #106 (loose scorer), Eval fixtures copy the skills' worked examples; add clean-diff and extra fixtures #107 (fixtures copy examples; clean-diff fixtures).
Skill consistency and content: Align severity, classification and output format across skills #103 (severity alignment), Fill checklist coverage gaps in existing skills #104 (coverage gaps), New skills: LLM/agent-integration security, secrets, privacy/PII, frontend XSS/CSP, API authorization #105 (new skills).
Release and CI: Release verification steps that can't fail usefully (post-publish gate, tamper test, identity check) #109 (verification steps), Release builds aren't locked or reproducible (unpinned hatchling, no --locked, SBOM from a fresh resolve) #110 (reproducible builds), Claude plugin users get the default branch, but the plugin version only changes at release #111 (plugin channel/version), CI gaps: Windows/macOS, minimum dependency versions, workflow linting, sdist install #112 (CI gaps), Proposal: simplify the release/provenance machinery #113 (simplification proposal), Release script and docs hygiene: version parsing, partial edits, tag parsing, bare uv run #114 (script/docs hygiene).
Registry and CLI polish: Registry doesn't type-check meta.yaml; a numeric version like 1.10 becomes "1.1" #97 (meta.yaml type validation, version float), CLI robustness: update error handling, --agent all everywhere, config-dir env vars, atomic writes #98 (CLI robustness).
Related roadmap issues: #74 , #75 , #79 , #80 .
Umbrella issue for a full-codebase review of
mainat 759a34b. Baseline was healthy: ruff, ruff format, mypy (strict) and all 156 tests pass. Each finding is a sub-issue.Suggested order
uninstalldeletes unmanaged and locally modified files #95 (uninstalldeletes unmanaged or edited files),statusreports the user's own files in shared directories as orphans #96 (statusfalse orphans). Both are small.v*tag on any commit publishes to PyPI, and tests don't run #108 (anyv*tag publishes; tests don't run).SKILL.mdskill folders).--locked, SBOM from a fresh resolve) #110 (reproducible builds), Claude plugin users get the default branch, but the plugin version only changes at release #111 (plugin channel/version), CI gaps: Windows/macOS, minimum dependency versions, workflow linting, sdist install #112 (CI gaps), Proposal: simplify the release/provenance machinery #113 (simplification proposal), Release script and docs hygiene: version parsing, partial edits, tag parsing, bareuv run#114 (script/docs hygiene).versionlike 1.10 becomes "1.1" #97 (meta.yaml type validation, version float), CLI robustness: update error handling,--agent alleverywhere, config-dir env vars, atomic writes #98 (CLI robustness).Related roadmap issues: #74, #75, #79, #80.