Skip to content

Tracking: codebase review findings (September 2026) #94

Description

@richardmhope

Umbrella issue for a full-codebase review of main at 759a34b. Baseline was healthy: ruff, ruff format, mypy (strict) and all 156 tests pass. Each finding is a sub-issue.

Suggested order

  1. Installer data-safety: uninstall deletes unmanaged and locally modified files #95 (uninstall deletes unmanaged or edited files), status reports the user's own files in shared directories as orphans #96 (status false orphans). Both are small.
  2. Release gating: Release workflow: any v* tag on any commit publishes to PyPI, and tests don't run #108 (any v* tag publishes; tests don't run).
  3. Wrong skill guidance: ci-workflow-review: GitLab script-injection guidance is wrong, and the eval fixture rewards it #101 (GitLab injection advice and fixture), Skills cite outdated or wrong OWASP/ASVS references #102 (outdated OWASP/ASVS references).
  4. Adapters: Codex adapter installs to a path Codex doesn't read; custom prompts are deprecated #99 (Codex project install is a no-op), Move adapters to native SKILL.md skill folders (Copilot, Cursor, Kiro, Codex) #100 (move to native SKILL.md skill folders).
  5. Evals: Eval scorer is too loose: wrong reports can pass #106 (loose scorer), Eval fixtures copy the skills' worked examples; add clean-diff and extra fixtures #107 (fixtures copy examples; clean-diff fixtures).
  6. Skill consistency and content: Align severity, classification and output format across skills #103 (severity alignment), Fill checklist coverage gaps in existing skills #104 (coverage gaps), New skills: LLM/agent-integration security, secrets, privacy/PII, frontend XSS/CSP, API authorization #105 (new skills).
  7. Release and CI: Release verification steps that can't fail usefully (post-publish gate, tamper test, identity check) #109 (verification steps), Release builds aren't locked or reproducible (unpinned hatchling, no --locked, SBOM from a fresh resolve) #110 (reproducible builds), Claude plugin users get the default branch, but the plugin version only changes at release #111 (plugin channel/version), CI gaps: Windows/macOS, minimum dependency versions, workflow linting, sdist install #112 (CI gaps), Proposal: simplify the release/provenance machinery #113 (simplification proposal), Release script and docs hygiene: version parsing, partial edits, tag parsing, bare uv run #114 (script/docs hygiene).
  8. Registry and CLI polish: Registry doesn't type-check meta.yaml; a numeric version like 1.10 becomes "1.1" #97 (meta.yaml type validation, version float), CLI robustness: update error handling, --agent all everywhere, config-dir env vars, atomic writes #98 (CLI robustness).

Related roadmap issues: #74, #75, #79, #80.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions