Fix #35: Relax hook allowlist for reviewer and release smoke gaps - #36
Conversation
Internal tester reportResult: PASS P0/P1/P2/P3: none remaining. Confirmed:
Validation seen:
No blocking findings remain. |
Owner delivery noteRun id: Scope:
Hook doctor:
Validation:
Hold:
|
Internal security reviewer reportResult: PASS P0/P1/P2: none remaining. Resolved findings:
P3 residual:
No unresolved P0/P1/P2 remains. |
Live hook validation updateRun: Result
Verification after follow-up
Claude ACP review status
Current state: hook validation gate passed; Claude ACP review remains incomplete due provider availability, not hook policy. |
Claude ACP code/security reviewReviewer: Claude ACP P0/P1/P2 findingsNone. P3 / follow-upNone identified. Evidence checked
Commander next stepNo blockers. Proceed to merge when merge policy is satisfied. |
Claude ACP re-review for latest deltaReviewer: Claude ACP Conclusion: PASS P0/P1/P2 findingsNone. Notes
Latest CI: Node 22 and Node 24 passed. |
Summary
Fixes #35.
This PR fills the HOLO PreToolUse allowlist gaps found while preparing the v0.1.3 release PR #34. It is intentionally kept separate from #34 and should stay open until the real PreToolUse hook is reattached and validated against this branch build/dist.
Changes
$HOME/.codex/skills/**and$HOME/.agents/skills/**for normal skill protocol use.which/command -vfor known tools,claude --help,claude acp --help, and trusted wrapper--help.agent-loop ... --help/pnpm agent-loop ... --help.npm packonly into safe system tempholo-*dirs and safe temp read checks.sed -i,find -exec/-delete, non-skill HOME reads,npm publish, unsafe Claude/AGY wrapper args.Validation
pnpm exec vitest run plugins/autonomous-pr-loop/tests/hook-policy.test.ts: passed, 18 tests.pnpm build:hooks: passed; pre-tool-use dist updated.pnpm lint: passed.pnpm test: passed, 36 files and 417 tests.npx gitnexus detect_changes --repo HOLO-Codex: completed, HIGH risk expected for hook policy flow; changed files are scoped to hook policy, pre-tool-use dist, and hook-policy tests.git diff --check: clean.Internal review
SKILL.md,references/**, andscripts/*.mjsif needed.Hold before merge
Do not merge yet. Next gate is real hook validation after the user reattaches the real PreToolUse hook:
pnpm agent-loop install-hooks --repo /Users/mac-mini/projects/HOLO-Codex --jsonpnpm agent-loop hooks doctor --jsondispatch-claude-acp/SKILL.md,claude --help,claude acp --help, trusted Claude ACP dispatch, non-dry-run tarball pack/install smoke.sed -i, non-skill HOME read,npm publish, unsafe Claude command.Run id:
6a10cd46-45ed-4b79-92d5-6b0dafcad15d.