Skip to content

docs(agents): 治理審計 P1 — 結構收斂(薄鏡像納管 + skill 白名單 + workflow 殘留清理) - #275

Merged
monkey1sai merged 3 commits into
mainfrom
docs/agent-governance-audit-p1
Jul 2, 2026
Merged

monkey1sai merged 3 commits into
mainfrom
docs/agent-governance-audit-p1

Conversation

@monkey1sai

@monkey1sai monkey1sai commented Jul 2, 2026 •

Copy link
Copy Markdown
Owner

摘要

治理審計 P1(結構收斂):formal spec 見 docs/superpowers/specs/2026-07-02-agent-governance-doc-alignment.md(P0 = #274 已 merge)。純文件與 agent 資產收斂,無 runtime / code symbol 變更。

變更清單

  1. 兩份腐敗的 gitignored CLAUDE.md 收斂納管:bim-streaming-server/CLAUDE.md(142 行,含 8 處已刪服務 _bim-control/_s3_storage 引用與 101 行 GitNexus 樣板)與 web-viewer-sample/CLAUDE.md(149 行,同類問題)重寫為薄鏡像入口(各 ~13 行、指向 sibling AGENTS.md 與 repo-boundary §3.5/§3.6),並自兩個 sub .gitignore 移除 /CLAUDE.md 忽略規則——根因是這兩檔從不進 PR review 才腐敗至此。
  2. gitnexus×6 + repo-health skill 檔納入版控白名單(root .gitignore,.claude 與 .codex 兩側):修復「CLAUDE.md/AGENTS.md 的 MUST 級 GitNexus 規則指向從未進 git 的檔案」結構風險(新 clone / .claude 重建即消失)。
  3. 移除 10 個一次性 workflow 殘留(fu1/fu2/fu34/fullsystem-adversarial-verify、repo-wide-adversarial-round-1、bim-frontend-redesign-plan、fe-redesign-alignment-audit、ui-blueprint-a-vs-b-decision、spec-to-done-design、plan-next-spec-to-done 舊版):全部零現役引用、自 chore(agents): 追蹤 .claude 自製 agent 資產 #201 批次入庫後零編輯、部分綁死已消失的 worktree;-aware 新版與活管線(std-*、ship-item、fu-generic、repo-health-scan、routing.json)全數保留。git 歷史可回復。
  4. bim-review-coordinator:CLAUDE.md 三塊獨有內容(collaboration handler 退役狀態、ifc-cache carve-out、權威歸屬表)併回 AGENTS.md 後薄化為鏡像入口。
  5. root CLAUDE.md / AGENTS.md 收斂:四工具職責表+anti-patterns 下放 github-workflow.md 單一權威版(AGENTS.md 217→207 行);CLAUDE.md 修正舊工具名(gitnexus_impact→impact)、rebuild 詳規改指路、§2 表與 AGENTS.md 集合一致(124→123 行,兩檔均在預算內;「目標行數」需 GitNexus embedded block 支援單檔寫入才可再壓,本 PR 不動自動區塊)。
  6. repo-boundary-detail.md 補缺:governance-service 全檔零提及 → 補 §3.7 邊界段、兩份 mermaid + ASCII tree + 一句話定位補 governance-service/kit-manager 節點;新增 §3.8 kit-manager 簡段。
  7. sub-repo-verify-commands.md:補 governance-service 驗證段(host-native Python312)。
  8. web-viewer-sample/AGENTS.md:修正「npm run verify 等同 build」stale(實際 = build && test && test:struct-log)。
  9. spec-to-done SKILL 兩版同步:.codex 版修正與 P0 同源的 branch-protection stale 敘述+補維運注意事項段;.claude 版補 helper 一致性註記。

AI Coding Governance

Item Result
Linked issue none — 治理審計 P1(P0=#274);證據見 artifacts/2026-07-02-agent-governance-audit.md
Requirement source docs/superpowers/specs/2026-07-02-agent-governance-doc-alignment.md §P1
CODEOWNERS / owner review repo owner monkey1sai;main 僅需 CI 綠,走 buffered auto-merge
GitNexus evidence detect_changes(scope=staged):risk low、affected_processes=0、僅 markdown section touched、無 code symbol 變更
gstack evidence not applicable — docs / agent 資產收斂,無 user-facing runtime 變更
Agent workflow changed? yes — 移除 10 個一次性殘留 workflow(活管線 std-*/ship-item/fu-generic/routing.json 未動;git 歷史可回復)
Required checks expected 11 required checks(pr-review-agent、agent-governance、各 build/test、compose config、ps static、secret scan)

Frontend Verification

Item Result
Frontend route not applicable — web-viewer-sample 僅動 .gitignore/AGENTS.md/CLAUDE.md 文件,無 UI 變更
Main button(s) tested not applicable — 無 UI 變更
Fixture used not applicable — 無 UI 變更
Visible success state not applicable — 無 UI 變更
E2E command not applicable — 無 UI 變更(npm run verify 語意已在 AGENTS.md 修正為 build && test && test:struct-log)
Screenshot / trace not applicable — 無 UI 變更
Known gaps none — 本 PR 不改前端行為

Deploy Path Verification

Item Result
Affects runtime / docker / Kit / viewer / ports / env? no — bim-streaming-server 僅動 .gitignore 與 CLAUDE.md 文件
Canonical deploy path updated? not needed — docs-only
Deploy dry-run command not applicable — docs-only,無 deploy path 變更
Verify command 本地:check-pr-body-evidence.ps1 預跑 + gitnexus detect_changes(staged);CI:11 required checks

🤖 Generated with Claude Code

https://claude.ai/code/session_01CAswRmGWDHkrTUSmsq1vZy

Summary by CodeRabbit

  • New Features

    • Added GitNexus skill docs covering exploration, debugging, impact analysis, refactoring, and CLI usage.
    • Added new repo guidance for governance, boundary rules, and verification workflows across several projects.
  • Documentation

    • Expanded agent and CLAUDE guidance with clearer tool roles, repo boundaries, and validation steps.
    • Added/update verification instructions for server and web-viewer workflows.
  • Chores

    • Updated ignore rules to track selected CLAUDE files.
    • Removed several obsolete workflow definitions and related automation docs.

- 兩份 gitignored 腐敗 CLAUDE.md(streaming/viewer)重寫薄鏡像並 un-ignore 納管
- gitnexus×6 + repo-health skill 檔入版控白名單(修 MUST 規則指向未版控檔的結構風險)
- 移除 10 個一次性 workflow 殘留(零引用、綁死已消失 worktree;git 歷史可回復)
- coordinator CLAUDE.md 獨有內容併回 AGENTS.md 後薄化
- 四工具職責表下放 github-workflow.md 單一權威版(AGENTS.md 217→207)
- repo-boundary 補 governance-service §3.7 / kit-manager §3.8 + mermaid 節點
- sub-repo-verify 補 governance-service 段;viewer AGENTS verify 描述修正
- spec-to-done 兩版 adapter 同步(codex 版同源 stale + 維運段)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CAswRmGWDHkrTUSmsq1vZy
Copilot AI review requested due to automatic review settings July 2, 2026 05:18
@monkey1sai
monkey1sai enabled auto-merge (squash) July 2, 2026 05:18
@coderabbitai

coderabbitai Bot commented Jul 2, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Adds six new GitNexus SKILL.md documentation files and a new repo-health SKILL.md. Restructures root and sub-repo AGENTS.md/CLAUDE.md governance contracts, updates gitignore whitelisting for tracked skill directories, extends repo-boundary and verification docs, and removes multiple .claude/workflows/*.js adversarial-verification workflow scripts.

Changes

GitNexus and Repo-Health Skills

Layer / File(s) Summary
GitNexus CLI skill
.claude/skills/gitnexus/gitnexus-cli/SKILL.md
Documents CLI commands (analyze, status, clean, wiki, list), post-index steps, and troubleshooting.
GitNexus debugging skill
.claude/skills/gitnexus/gitnexus-debugging/SKILL.md
Documents investigation workflow using query, context, cypher, and trace.
GitNexus exploring skill
.claude/skills/gitnexus/gitnexus-exploring/SKILL.md
Documents codebase exploration workflow, checklist, resources, and a worked example.
GitNexus guide and tools reference
.claude/skills/gitnexus/gitnexus-guide/SKILL.md
Documents the central tool index and detailed contracts for list_repos, explain, pdg_query, trace, and graph schema.
GitNexus impact-analysis skill
.claude/skills/gitnexus/gitnexus-impact-analysis/SKILL.md
Documents impact/detect_changes workflow, checklist, and output interpretation.
GitNexus refactoring skill
.claude/skills/gitnexus/gitnexus-refactoring/SKILL.md
Documents rename/extract/split checklists, tool templates, risk rules, and a rename example.
Repo-health skill
.claude/skills/repo-health/SKILL.md
Defines a read-only health-check skill covering version drift, cleanup, .claude assets, doc sync, and its scan/report/fix workflow.

Governance Docs and Workflow Removal

Layer / File(s) Summary
Gitignore and root policy updates
.gitignore, AGENTS.md, docs/agents/github-workflow.md
Whitelists tracked skill directories and replaces inline tool-responsibility text with a pointer to a single-authority table plus updated local-artifact rules.
CLAUDE.md behavior alignment
CLAUDE.md
Updates rebuild directive wording, adds a plans lazy-load reference, and renames GitNexus tool references to impact/detect_changes().
Spec-to-done and alignment doc updates
.claude/skills/spec-to-done/SKILL.md, docs/superpowers/specs/2026-07-02-agent-governance-doc-alignment.md
Adds cross-host consistency note and expands the execution-record/acceptance sections.
Adversarial workflow removal
.claude/workflows/*.js
Removes multiple workflow scripts (bim-frontend-redesign-plan, fe-redesign-alignment-audit, fu1/fu2/fu34/fullsystem-adversarial-verify, plan-next-spec-to-done, repo-wide-adversarial-round-1, spec-to-done-design, ui-blueprint-a-vs-b-decision) including their meta exports and orchestration logic.

Sub-repo Boundary Documentation

Layer / File(s) Summary
bim-review-coordinator boundary updates
bim-review-coordinator/AGENTS.md, bim-review-coordinator/CLAUDE.md
Documents removed collaboration handlers, an IFC-ready caching carve-out, an ownership table, and a condensed CLAUDE mirror entry.
bim-streaming-server CLAUDE mirror
bim-streaming-server/.gitignore, bim-streaming-server/CLAUDE.md
Un-ignores CLAUDE.md and adds streaming/runtime and IFC→USDC conversion boundary documentation.
repo-boundary-detail.md governance-service/kit-manager
docs/agents/repo-boundary-detail.md
Adds governance-service and kit-manager to the folder listing, diagrams, and new boundary sections 3.7/3.8.
Sub-repo verify commands and web-viewer updates
docs/agents/sub-repo-verify-commands.md, web-viewer-sample/.gitignore, web-viewer-sample/AGENTS.md, web-viewer-sample/CLAUDE.md
Adds a governance-service verification section, un-ignores web-viewer CLAUDE.md, expands its verify command, and adds a CLAUDE mirror entry.

Estimated code review effort: 3 (Moderate) | ~30 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 標題準確概括了這次以治理審計 P1 為主的文件/技能收斂、skill 白名單與 workflow 清理變更。
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/agent-governance-audit-p1

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This is a docs-and-agent-assets-only PR implementing the "P1 structural convergence" phase of the 2026-07-02 agent-governance audit (P0 was #274). It contains no runtime or code-symbol changes. The goal is to make the repo's agent-facing governance docs consistent and tracked: converge two stale, gitignored sub-repo CLAUDE.md files into thin mirror entries, bring GitNexus/repo-health skill files under version control, remove one-off residual workflows, and add the missing governance-service/kit-manager boundary documentation.

Changes:

  • Rewrite bim-streaming-server/CLAUDE.md and web-viewer-sample/CLAUDE.md as thin mirror entries (and stop ignoring CLAUDE.md in both sub-repos); fold unique bim-review-coordinator content into its AGENTS.md.
  • Whitelist GitNexus CLI skills + repo-health skill in root .gitignore (both .claude and .codex); delete 10 unreferenced one-off workflows; dedup the four-tool table into github-workflow.md.
  • Add governance-service (§3.7) and kit-manager (§3.8) boundary sections, diagram nodes, and verify commands; correct the web-viewer npm run verify description and the GitNexus tool names (impact/detect_changes).

Reviewed changes

Copilot reviewed 38 out of 39 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
web-viewer-sample/CLAUDE.md New thin mirror entry pointing to sibling AGENTS.md and repo-boundary §3.6
web-viewer-sample/AGENTS.md Corrects stale npm run verify to build && test && test:struct-log (matches package.json)
web-viewer-sample/.gitignore Un-ignores /CLAUDE.md
docs/agents/sub-repo-verify-commands.md Adds governance-service host-native Python312 verify section
docs/agents/repo-boundary-detail.md Adds governance-service/kit-manager nodes, tree entries, §3.7/§3.8
docs/agents/github-workflow.md Single authoritative four-tool table + anti-patterns
CLAUDE.md Dedups pipeline/rebuild detail to pointers; fixes gitnexus_impact→impact
bim-streaming-server/CLAUDE.md New thin mirror entry
bim-streaming-server/.gitignore Un-ignores /CLAUDE.md
bim-review-coordinator/CLAUDE.md Thinned to mirror entry
bim-review-coordinator/AGENTS.md Absorbs collaboration-retirement note, ifc-cache carve-out, authority table
AGENTS.md Removes duplicated four-tool table, points to github-workflow.md
.gitignore Whitelists gitnexus/repo-health skills (.claude + .codex)
.codex/skills/spec-to-done/SKILL.md Syncs branch-protection narrative; cites .gitignore line numbers (now stale)
.codex/skills/repo-health/SKILL.md New tracked skill (references non-existent plans path)
.codex/skills/gitnexus/*/SKILL.md New tracked GitNexus CLI skill docs
.claude/skills/spec-to-done/SKILL.md Adds cross-host helper-consistency note
.claude/skills/repo-health/SKILL.md New tracked skill (references non-existent plans path)
.claude/skills/gitnexus/*/SKILL.md New tracked GitNexus CLI skill docs
.claude/workflows/*.js (10 files) Deletes one-off residual workflows (no active references)

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.


| 面向 | 抓什麼 | 性質 |
|---|---|---|
| **進度差異** | `docs/plans/開發軌跡與執行計畫.md` 的 A1–A10/M0–M8「計畫自報 vs 獨立查證」並列,標出計畫高估/低報 | 唯讀評估,**不納入「要修哪幾項」** |
Comment thread .codex/skills/repo-health/SKILL.md Outdated

| 面向 | 抓什麼 | 性質 |
|---|---|---|
| **進度差異** | `docs/plans/開發軌跡與執行計畫.md` 的 A1–A10/M0–M8「計畫自報 vs 獨立查證」並列,標出計畫高估/低報 | 唯讀評估,**不納入「要修哪幾項」** |
Comment thread .codex/skills/spec-to-done/SKILL.md Outdated
4. GitNexus detect-changes 在 linked worktree 看不到 staged(已知坑)→ implementer fallback `git diff --name-only --cached` 並記 `detectVerdict='fallback'`,PR body 揭露;完全失敗記 `fail`,同 run 3 次 → held。
5. pr-review-agent 兩種非內容故障:`missing_openspec`(P6 前置 a 預防)與`report generation failed`(工具整體故障,非 required check,由 ship-item 判斷層次處置)。
6. 本組檔案已 whitelist tracked(`.gitignore:37` `!.claude/skills/spec-to-done/`、`:42` `!.claude/workflows/`、`:55` `!.codex/skills/spec-to-done/`;含 SKILL.md、std-*.js、ship-item、本目錄 `ensure-host-native-ports-free.ps1`),隨 PR 進 git/CI。純動 `.claude/**` / `.codex/**` 的 PR 可能被 pr-review-agent paths-ignore 跳過 review(#202);main 無 branch protection 故此 check 非 required。
6. 本組檔案已 whitelist tracked(`.gitignore:37` `!.claude/skills/spec-to-done/`、`:42` `!.claude/workflows/`、`:55` `!.codex/skills/spec-to-done/`;含 SKILL.md、std-*.js、ship-item、本目錄 `ensure-host-native-ports-free.ps1`),隨 PR 進 git/CI。pr-review-agent 對所有 PR 都會跑(#202 的 paths-ignore 已移除,`pr-review-agent.yml` 現無 paths 過濾),且是 main branch protection 的 required check(11 項之一;2026-07-02 以 gh api 親查)——`.claude/**` / `.codex/**` 變更同樣受 review 與 AI Coding Governance body-evidence 表約束。
@github-actions

github-actions Bot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

PR Review Agent Summary

Field Value
Status blocked
Risk high
PR 275
Head docs/agent-governance-audit-p1 / 3085034bd7357c6c9939aba543b919df9a10c112
Base main / eea80d04de956928b241e1f395ca7f3b4d3a78da

Blockers

  • [high] .codex/skills/gitnexus/gitnexus-cli/SKILL.md Generated local tooling state must not be committed as product source.
  • [high] .codex/skills/gitnexus/gitnexus-debugging/SKILL.md Generated local tooling state must not be committed as product source.
  • [high] .codex/skills/gitnexus/gitnexus-exploring/SKILL.md Generated local tooling state must not be committed as product source.
  • [high] .codex/skills/gitnexus/gitnexus-guide/SKILL.md Generated local tooling state must not be committed as product source.
  • [high] .codex/skills/gitnexus/gitnexus-impact-analysis/SKILL.md Generated local tooling state must not be committed as product source.
  • [high] .codex/skills/gitnexus/gitnexus-refactoring/SKILL.md Generated local tooling state must not be committed as product source.
  • [high] .codex/skills/repo-health/SKILL.md Generated local tooling state must not be committed as product source.
  • [high] .codex/skills/spec-to-done/SKILL.md Generated local tooling state must not be committed as product source.
  • [high] Behavior, workflow, code, or repo-boundary changes require an OpenSpec change id or documented exception.

Warnings

  • None

Validation Commands

  • npm run verify
  • python -m pytest tests/test_conversion_authority_api.py -q
  • C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoProfile -ExecutionPolicy Bypass -File scripts/tests/test-stage-loading-contract.ps1
  • npm run verify

Checks

  • passed bim-review-coordinator verify (bim-review-coordinator)
  • passed bim-streaming-server conversion API tests (bim-streaming-server)
  • passed bim-streaming-server stage-loading contract (bim-streaming-server)
  • passed web-viewer-sample verify (web-viewer-sample)

Human Review Notes

  • Optional AI adapter is not required by policy and was skipped.

…spec 執行紀錄

pr-review-agent 對 .codex/skills 路徑是 hard blocker(pr-review-agent.ps1:343);
依「不由 agent 自行放寬 review gate」原則縮 PR 範圍:.claude 側 7 檔納管照舊,
.codex 側 git rm --cached + 還原 gitignore 白名單、工作樹鏡像保留。
spec 補執行紀錄(同時消 missing_openspec blocker)。

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CAswRmGWDHkrTUSmsq1vZy
@github-actions

github-actions Bot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

PR Review Agent Summary

Field Value
Status failed
Risk high
PR 275
Head docs/agent-governance-audit-p1 / 050f0b253ec0b7c179ef5c1e21d443126d305fc4
Base main / eea80d04de956928b241e1f395ca7f3b4d3a78da

Blockers

  • [high] D:\a\AI-BIM-governance\AI-BIM-governance\bim-review-coordinator Required validation failed: bim-review-coordinator verify.

Warnings

  • None

Validation Commands

  • npm run verify
  • python -m pytest tests/test_conversion_authority_api.py -q
  • C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoProfile -ExecutionPolicy Bypass -File scripts/tests/test-stage-loading-contract.ps1
  • npm run verify

Checks

  • failed bim-review-coordinator verify (bim-review-coordinator)
  • passed bim-streaming-server conversion API tests (bim-streaming-server)
  • passed bim-streaming-server stage-loading contract (bim-streaming-server)
  • passed web-viewer-sample verify (web-viewer-sample)

Human Review Notes

  • OpenSpec archive or formal spec evidence detected; active change-id validation was skipped.
  • Optional AI adapter is not required by policy and was skipped.

@github-actions

github-actions Bot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

PR Review Agent Summary

Field Value
Status passed
Risk low
PR 275
Head docs/agent-governance-audit-p1 / 050f0b253ec0b7c179ef5c1e21d443126d305fc4
Base main / eea80d04de956928b241e1f395ca7f3b4d3a78da

Blockers

  • None

Warnings

  • None

Validation Commands

  • npm run verify
  • python -m pytest tests/test_conversion_authority_api.py -q
  • C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoProfile -ExecutionPolicy Bypass -File scripts/tests/test-stage-loading-contract.ps1
  • npm run verify

Checks

  • passed bim-review-coordinator verify (bim-review-coordinator)
  • passed bim-streaming-server conversion API tests (bim-streaming-server)
  • passed bim-streaming-server stage-loading contract (bim-streaming-server)
  • passed web-viewer-sample verify (web-viewer-sample)

Human Review Notes

  • OpenSpec archive or formal spec evidence detected; active change-id validation was skipped.
  • Optional AI adapter is not required by policy and was skipped.

@github-actions

github-actions Bot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

PR Review Agent Summary

Field Value
Status passed
Risk low
PR 275
Head docs/agent-governance-audit-p1 / 41f0a3cf8157f91d17d86ab489992dbb55e2fe84
Base main / 2787c4f4ab1a7c1712709e8f176eaf37374b671f

Blockers

  • None

Warnings

  • None

Validation Commands

  • npm run verify
  • python -m pytest tests/test_conversion_authority_api.py -q
  • C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoProfile -ExecutionPolicy Bypass -File scripts/tests/test-stage-loading-contract.ps1
  • npm run verify

Checks

  • passed bim-review-coordinator verify (bim-review-coordinator)
  • passed bim-streaming-server conversion API tests (bim-streaming-server)
  • passed bim-streaming-server stage-loading contract (bim-streaming-server)
  • passed web-viewer-sample verify (web-viewer-sample)

Human Review Notes

  • OpenSpec archive or formal spec evidence detected; active change-id validation was skipped.
  • Optional AI adapter is not required by policy and was skipped.

@monkey1sai
monkey1sai merged commit 6f07f96 into main Jul 2, 2026
11 of 12 checks passed
@monkey1sai
monkey1sai deleted the docs/agent-governance-audit-p1 branch July 2, 2026 06:04

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🧹 Nitpick comments (1)
.claude/skills/gitnexus/gitnexus-guide/SKILL.md (1)

97-123: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Keep the trace contract and schema list aligned.

trace says class-rooted paths can traverse HAS_METHOD, but the Graph Schema section never lists that edge type. That makes the reference internally inconsistent and will mislead anyone writing Cypher against the documented schema. Please add HAS_METHOD to the edge list, or remove it from the trace description if it is intentionally unsupported.

Suggested patch
- **Edges (via CodeRelation.type):** CALLS, IMPORTS, EXTENDS, IMPLEMENTS, DEFINES, MEMBER_OF, STEP_IN_PROCESS
+ **Edges (via CodeRelation.type):** CALLS, HAS_METHOD, IMPORTS, EXTENDS, IMPLEMENTS, DEFINES, MEMBER_OF, STEP_IN_PROCESS
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/gitnexus/gitnexus-guide/SKILL.md around lines 97 - 123, The
`trace` documentation and the Graph Schema edge list are inconsistent: `trace`
mentions traversing `HAS_METHOD`, but the schema section omits that edge type.
Update the `trace` description and the Graph Schema block in `SKILL.md` so they
match by either adding `HAS_METHOD` to the documented `CodeRelation.type` edges
or removing it from `trace` if it is not actually supported.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.claude/skills/gitnexus/gitnexus-cli/SKILL.md:
- Around line 8-10: The recovery path in SKILL.md uses mutable runtime installs,
which makes `gitnexus analyze` non-reproducible. Update the fallback flow
referenced in the `node .gitnexus/run.cjs` and `npx gitnexus analyze` guidance
so it uses a pinned GitNexus version or a checked-in bootstrap instead of
floating `gitnexus@latest`/unversioned `npx`. Keep the existing runner-selection
guidance intact, but make the regeneration instructions deterministic for
fresh-clone and missing-runner recovery.

In @.claude/skills/repo-health/SKILL.md:
- Around line 3-9: The skill header and description in SKILL.md still say “four
dimensions,” but the workflow and body cover a fifth read-only progress
evaluation, so update the headline/description to match the actual contract.
Reword the `description`, title text, and the opening `# repo-health` summary so
they consistently say “4 個衛生面向 + 1 個進度面向,” keeping the rest of the skill content
aligned with the `/repo-health` flow.

In `@bim-review-coordinator/AGENTS.md`:
- Around line 7-11: The role summary still describes bim-review-coordinator as a
“Session / Collaboration Control Plane,” but the deprecation note in AGENTS.md
says the collaboration Socket.IO handlers have been removed. Update the
top-level description to reflect only the surviving session responsibilities in
the same document, keeping it aligned with the archive/retirement note and
avoiding any mention of collaboration control-plane behavior.

In `@docs/agents/sub-repo-verify-commands.md`:
- Around line 90-98: This section still reads like a generic index entry, so
mark it explicitly as a runbook/working note in the governance-service section
of docs/agents/sub-repo-verify-commands.md. Update the header or nearby prose
around the governance-service block to include a clear runbook marker, using the
existing governance-service and evidence-path text as the anchor, so readers
understand it is operational guidance rather than source-of-truth behavior.

---

Nitpick comments:
In @.claude/skills/gitnexus/gitnexus-guide/SKILL.md:
- Around line 97-123: The `trace` documentation and the Graph Schema edge list
are inconsistent: `trace` mentions traversing `HAS_METHOD`, but the schema
section omits that edge type. Update the `trace` description and the Graph
Schema block in `SKILL.md` so they match by either adding `HAS_METHOD` to the
documented `CodeRelation.type` edges or removing it from `trace` if it is not
actually supported.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 33fbd073-dfd3-4517-9d50-fc887703b7eb

📥 Commits

Reviewing files that changed from the base of the PR and between 2787c4f and 41f0a3c.

📒 Files selected for processing (32)
  • .claude/skills/gitnexus/gitnexus-cli/SKILL.md
  • .claude/skills/gitnexus/gitnexus-debugging/SKILL.md
  • .claude/skills/gitnexus/gitnexus-exploring/SKILL.md
  • .claude/skills/gitnexus/gitnexus-guide/SKILL.md
  • .claude/skills/gitnexus/gitnexus-impact-analysis/SKILL.md
  • .claude/skills/gitnexus/gitnexus-refactoring/SKILL.md
  • .claude/skills/repo-health/SKILL.md
  • .claude/skills/spec-to-done/SKILL.md
  • .claude/workflows/bim-frontend-redesign-plan.js
  • .claude/workflows/fe-redesign-alignment-audit.js
  • .claude/workflows/fu1-adversarial-verify.js
  • .claude/workflows/fu2-adversarial-verify.js
  • .claude/workflows/fu34-adversarial-verify.js
  • .claude/workflows/fullsystem-adversarial-verify.js
  • .claude/workflows/plan-next-spec-to-done.js
  • .claude/workflows/repo-wide-adversarial-round-1.js
  • .claude/workflows/spec-to-done-design.js
  • .claude/workflows/ui-blueprint-a-vs-b-decision.js
  • .gitignore
  • AGENTS.md
  • CLAUDE.md
  • bim-review-coordinator/AGENTS.md
  • bim-review-coordinator/CLAUDE.md
  • bim-streaming-server/.gitignore
  • bim-streaming-server/CLAUDE.md
  • docs/agents/github-workflow.md
  • docs/agents/repo-boundary-detail.md
  • docs/agents/sub-repo-verify-commands.md
  • docs/superpowers/specs/2026-07-02-agent-governance-doc-alignment.md
  • web-viewer-sample/.gitignore
  • web-viewer-sample/AGENTS.md
  • web-viewer-sample/CLAUDE.md
💤 Files with no reviewable changes (10)
  • .claude/workflows/fu34-adversarial-verify.js
  • .claude/workflows/repo-wide-adversarial-round-1.js
  • .claude/workflows/fu1-adversarial-verify.js
  • .claude/workflows/spec-to-done-design.js
  • .claude/workflows/plan-next-spec-to-done.js
  • .claude/workflows/ui-blueprint-a-vs-b-decision.js
  • .claude/workflows/fe-redesign-alignment-audit.js
  • .claude/workflows/fullsystem-adversarial-verify.js
  • .claude/workflows/fu2-adversarial-verify.js
  • .claude/workflows/bim-frontend-redesign-plan.js

Comment on lines +8 to +10
Commands below use `node .gitnexus/run.cjs <command>` — the project-local runner `gitnexus analyze` drops next to the index. It auto-selects an available runner at call time (global `gitnexus`, else `pnpm dlx`, else `npx`), so no package-manager assumption and no global install is required.

> **Not analyzed yet, or `node .gitnexus/run.cjs` reports `Cannot find module`** (the gitignored runner is absent — e.g. a fresh clone or `git clean`)? (Re)generate it with `npx gitnexus analyze` from the project root. On **npm 11.x**, if `npx` crashes during install (`node.target is null`), install once with `npm i -g gitnexus` (then `gitnexus analyze`) or use `pnpm --allow-build=@ladybugdb/core --allow-build=gitnexus --allow-build=tree-sitter dlx gitnexus@latest analyze`. See [#1939](https://github.com/abhigyanpatwari/GitNexus/issues/1939).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '%s\n' '--- file: .claude/skills/gitnexus/gitnexus-cli/SKILL.md ---'
cat -n .claude/skills/gitnexus/gitnexus-cli/SKILL.md | sed -n '1,80p'

printf '%s\n' '\n--- search for related bootstrap/version guidance ---'
rg -n --hidden --glob '.claude/**' --glob '!**/node_modules/**' \
  'gitnexus analyze|gitnexus@latest|npx gitnexus|pnpm .*dlx gitnexus|pinned-version|version' \
  .claude

Repository: monkey1sai/AI-BIM-governance

Length of output: 50387


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '%s\n' '--- gitnexus references and version pins ---'
rg -n --hidden --glob '!**/node_modules/**' --glob '!**/.git/**' \
  'gitnexus(`@latest`)?|npx gitnexus|pnpm .*dlx gitnexus|npm i -g gitnexus|gitnexus analyze|version:' \
  .claude package.json pnpm-lock.yaml package-lock.json yarn.lock 2>/dev/null | sed -n '1,220p'

printf '%s\n' '\n--- nearby gitnexus skill docs ---'
for f in \
  .claude/skills/gitnexus/gitnexus-cli/SKILL.md \
  .claude/skills/gitnexus/gitnexus-guide/SKILL.md \
  .claude/skills/gitnexus/README.md
do
  if [ -f "$f" ]; then
    echo "### $f"
    cat -n "$f" | sed -n '1,140p'
  fi
done

Repository: monkey1sai/AI-BIM-governance

Length of output: 23078


Pin the recovery install path

npx gitnexus analyze and pnpm ... dlx gitnexus@latest analyze still pull mutable upstream packages at runtime. Pin the GitNexus version here, or route the fallback through a checked-in bootstrap, so recovery stays reproducible and doesn’t depend on floating releases.

🧰 Tools
🪛 SkillSpector (2.3.7)

[warning] 10: [RP1] null: npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Remediation: Pin the version: npx @scope/server@1.2.3

(MCP Rug Pull (RP1))


[warning] 22: [MP2] Context Window Stuffing: Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Remediation: Implement context-window management that detects and rejects padding or stuffing attempts. Prioritize system instructions over user-injected content.

(Memory Poisoning (MP2))


[warning] 46: [MP2] Context Window Stuffing: Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Remediation: Implement context-window management that detects and rejects padding or stuffing attempts. Prioritize system instructions over user-injected content.

(Memory Poisoning (MP2))

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/gitnexus/gitnexus-cli/SKILL.md around lines 8 - 10, The
recovery path in SKILL.md uses mutable runtime installs, which makes `gitnexus
analyze` non-reproducible. Update the fallback flow referenced in the `node
.gitnexus/run.cjs` and `npx gitnexus analyze` guidance so it uses a pinned
GitNexus version or a checked-in bootstrap instead of floating
`gitnexus@latest`/unversioned `npx`. Keep the existing runner-selection guidance
intact, but make the regeneration instructions deterministic for fresh-clone and
missing-runner recovery.

Source: Linters/SAST tools

Comment on lines +3 to +9
description: Use when the user wants to check or clean up the AI-BIM-governance repo's health — version/dependency drift across services, branch/worktree/temp cleanup, .claude asset hygiene, and doc/config sync. Scans read-only across four dimensions, reports, then fixes only what the user confirms.
argument-hint: "(選填)只想看某面向:version / cleanup / assets / docs"
---

# repo-health — AI-BIM repo 四面向健檢

對 `AI-BIM-governance` 跑唯讀健檢,回報問題,**只修使用者確認的項目**。

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Align the headline with the actual 5-step contract.

The front matter and title advertise “four dimensions,” but the body already includes a fifth, read-only progress evaluation, and the /repo-health workflow scans all five. Please reword this to “4 個衛生面向 + 1 個進度面向” so the skill contract matches the implementation.

🧰 Tools
🪛 SkillSpector (2.3.7)

[error] 15: [PE3] Credential Access: Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Remediation: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths.

(Privilege Escalation (PE3))

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/repo-health/SKILL.md around lines 3 - 9, The skill header and
description in SKILL.md still say “four dimensions,” but the workflow and body
cover a fifth read-only progress evaluation, so update the headline/description
to match the actual contract. Reword the `description`, title text, and the
opening `# repo-health` summary so they consistently say “4 個衛生面向 + 1 個進度面向,”
keeping the rest of the skill content aligned with the `/repo-health` flow.

Comment on lines +7 to +11
`bim-review-coordinator` 是外部 IFC-ready intake、metadata-only callback outbox 與 Session / Collaboration Control Plane。它負責建立 review session、協調 viewer 與 streaming server 的連線資訊、廣播 presence 等基本 session 事件,並保存最小 local shadow metadata。

服務埠口:`127.0.0.1:8004`
服務埠口:`127.0.0.1:8004`(含 Socket.IO)

> **退役狀態(2026-05-21,change `remove-conflict-review-from-fast-mvp`)**:`highlightRequest` / `selectionUpdate` / `annotationCreate` 等 collaboration Socket.IO event handlers 已自本 service 移除(`src/socket/reviewNamespace.ts`);`getReviewIssues` / `createAnnotation` / `/api/model-versions/:id/review-bootstrap` 也已刪。`/api/review-sessions/:id/events` 與 `/lifecycle-events` 仍保留;lifecycle endpoint 排除 collaboration event 的 wording 保留作 archive compatibility(舊 event log 仍可能含這些 type)——不要把這些已刪 handler 當 regression 加回來。

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟠 Major | ⚡ Quick win

Drop the stale collaboration label from the role summary.

Line 11 already says the collaboration Socket.IO handlers were removed, so line 7 should not still describe this service as a "Session / Collaboration Control Plane". Please narrow it to the surviving session surface so the mirror stays aligned with the deprecation note.

Proposed wording
-`bim-review-coordinator` 是外部 IFC-ready intake、metadata-only callback outbox 與 Session / Collaboration Control Plane。
+`bim-review-coordinator` 是外部 IFC-ready intake、metadata-only callback outbox 與 Session Control Plane。
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
`bim-review-coordinator` 是外部 IFC-ready intake、metadata-only callback outbox 與 Session / Collaboration Control Plane。它負責建立 review session、協調 viewer 與 streaming server 的連線資訊、廣播 presence 等基本 session 事件,並保存最小 local shadow metadata。
服務埠口:`127.0.0.1:8004`
服務埠口:`127.0.0.1:8004`(含 Socket.IO)
> **退役狀態(2026-05-21,change `remove-conflict-review-from-fast-mvp`)**:`highlightRequest` / `selectionUpdate` / `annotationCreate` 等 collaboration Socket.IO event handlers 已自本 service 移除(`src/socket/reviewNamespace.ts`);`getReviewIssues` / `createAnnotation` / `/api/model-versions/:id/review-bootstrap` 也已刪。`/api/review-sessions/:id/events` 與 `/lifecycle-events` 仍保留;lifecycle endpoint 排除 collaboration event 的 wording 保留作 archive compatibility(舊 event log 仍可能含這些 type)——不要把這些已刪 handler 當 regression 加回來。
`bim-review-coordinator` 是外部 IFC-ready intake、metadata-only callback outbox 與 Session Control Plane。它負責建立 review session、協調 viewer 與 streaming server 的連線資訊、廣播 presence 等基本 session 事件,並保存最小 local shadow metadata。
服務埠口:`127.0.0.1:8004`(含 Socket.IO)
> **退役狀態(2026-05-21,change `remove-conflict-review-from-fast-mvp`)**:`highlightRequest` / `selectionUpdate` / `annotationCreate` 等 collaboration Socket.IO event handlers 已自本 service 移除(`src/socket/reviewNamespace.ts`);`getReviewIssues` / `createAnnotation` / `/api/model-versions/:id/review-bootstrap` 也已刪。`/api/review-sessions/:id/events` 與 `/lifecycle-events` 仍保留;lifecycle endpoint 排除 collaboration event 的 wording 保留作 archive compatibility(舊 event log 仍可能含這些 type)——不要把這些已刪 handler 當 regression 加回來。
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@bim-review-coordinator/AGENTS.md` around lines 7 - 11, The role summary still
describes bim-review-coordinator as a “Session / Collaboration Control Plane,”
but the deprecation note in AGENTS.md says the collaboration Socket.IO handlers
have been removed. Update the top-level description to reflect only the
surviving session responsibilities in the same document, keeping it aligned with
the archive/retirement note and avoiding any mention of collaboration
control-plane behavior.

Comment on lines +90 to +98
## governance-service (Python host-native, port 49102)

```powershell
cd governance-service
& "C:\Program Files\Python312\python.exe" -m pytest tests/ -v
& "C:\Program Files\Python312\python.exe" scripts/run_governance_evidence.py
```

須走 host-native `C:\Program Files\Python312\python.exe`(具 ifcopenshell 0.8.5 + ifctester);勿用 WSL / Docker(本服務 CPU-only,無 GPU 需求)。真實 IFC evidence 落 `docs/evidence/governance-rule-run-pass/`。

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Mark this file as a runbook.

docs/**/*.md must explicitly declare the document nature, but this section still reads like a generic index page. Please add a clear runbook/working note marker so readers do not treat it as source-of-truth behavior.

Suggested header tweak
-# Sub-repo 驗證入口
+# Runbook: Sub-repo 驗證入口
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/agents/sub-repo-verify-commands.md` around lines 90 - 98, This section
still reads like a generic index entry, so mark it explicitly as a
runbook/working note in the governance-service section of
docs/agents/sub-repo-verify-commands.md. Update the header or nearby prose
around the governance-service block to include a clear runbook marker, using the
existing governance-service and evidence-path text as the anchor, so readers
understand it is operational guidance rather than source-of-truth behavior.

Source: Coding guidelines

monkey1sai added a commit that referenced this pull request Jul 2, 2026
* feat(pr-review-agent): generated_tooling_path 只擋新增、放行已追蹤鏡像檔修改

解「.codex 373 檔被追蹤(#212)卻永遠改不動」結構矛盾(#275 撞過,
adapter 同步 diff 因此遺失)。使用者 2026-07-02 拍板放寬。

- 新增 Test-PrReviewPathExistsAtBase: git cat-file -e 查 merge-base
  是否已追蹤;Base/Head 缺失一律 false (fail-closed)
- guard 分支: tracked 修改降 generated_tooling_path_modified warning;
  新增路徑或無 base 可判定維持 hard blocker
- Test 3c: tracked 修改=warning / 新增=blocker / 無 base=全 blocker

驗證: pwsh scripts/tests/test-pr-review-agent.ps1 baseline 與改後全綠。
spec: docs/superpowers/specs/2026-07-02-pr-review-agent-tracked-tooling-mirror-modify.md

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CiKNHW9BqXbP7p674tWUwa

* fix(pr-review-agent): ExistsAtBase 改 ls-tree,修 CI PowerShell 5.1 NativeCommandError

cat-file -e 對不存在路徑寫 stderr,CI 用 powershell.exe 5.1 (EAP=Stop)
會包成 NativeCommandError 拋出 → Test 3c 在 CI 紅、本機 pwsh 7 綠。
ls-tree --name-only 對不存在路徑靜默回空(exit 0、無 stderr),語意等價。

驗證: 本機 powershell.exe 5.1 與 pwsh 7 各跑 scripts/tests/test-pr-review-agent.ps1 全綠。

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CiKNHW9BqXbP7p674tWUwa

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants