Files
gstack/plan-devex-review/SKILL.md.tmpl
T
01593aa67c v1.91.2.0 fix: consolidate gstack reliability wave (#2959)
* fix(memory-ingest): --scan-secrets scans the rendered page and fails closed

--scan-secrets ran gitleaks on the raw transcript .jsonl, then imported a
page rendered from it. gitleaks' assignment rules don't match across a
JSON-escaped quote (KEY=\"v\" on disk), so a secret the rendered page
shows as KEY="v" was imported unflagged. And the gate skipped a file only
on scanner "gitleaks" with findings, so a scan that errored (non-zero
exit, 16MB maxBuffer overflow on a file with many findings, unparseable
report) or could not run (gitleaks missing, slow-probe cooldown) imported
the file unscanned.

Scan the rendered page body, the exact bytes writeStaged() writes, via a
new secretScanText() helper, and skip the file whenever the scan did not
complete. Skipped files stay out of the state file, so the next run
retries them. Reword the helper warnings and setup-gbrain/memory.md,
which described the fail-open as intended.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(test): reconcile Bun failure markers and footer counts

* fix(sync-gbrain): verify source-scoped reads without mutation

* fix(test): recognize grounded TTHW target choices structurally

* fix(aside): make the readiness probe work under zsh and report why it failed

The probe built its deadline into `_T` and expanded it unquoted, so
`$_T aside repl …` only worked in a shell that word-splits. zsh does not: it
looked for a command literally named "gtimeout 30", the probe answered
ASIDE_NOT_RUNNING with Aside installed and ready, and every browsing skill
fell back to the bundled Chromium in silence. zsh is the macOS default and
Aside is macOS-only, so on a stock Mac the probe could never report READY.

The deadline becomes a function, `_gs_d`. It receives the command as "$@",
already split, so sh, bash and zsh all behave the same, and the gtimeout →
timeout → perl alarm chain is unchanged. A 4th arm runs the call unbounded
when none of the three is present, which is what the empty `_T` did before.
Not `eval`: it re-parses the string, so the parens and `;` of the perl arm
become syntax and that arm dies in bash *and* zsh — on a stock Mac, the arm
that actually runs.

On failure the probe now prints the CLI's reason after ASIDE_NOT_RUNNING:,
the shape gstack-render already uses: the first line that starts with a
capital letter, i.e. the CLI's own sentence or Node's `Error:` line below its
loader frame. "Not running" covers states with different fixes — no window
open for the profile, a NODE_OPTIONS preload that kills the CLI — and a bare
verdict sent all of them to "open the Aside app". The BROWSER SETUP prose
quotes that reason before asking the user to open the app.

The text pin asserted the broken invocation verbatim, so it now pins the
function and asserts neither `$_T aside repl` nor an eval form comes back. A
second test executes the rendered probe in sh, bash and zsh on each of the
four deadline arms with stubbed binaries on a narrowed PATH, plus two failing
CLIs: one that prints its own sentence, one that crashes like Node with the
useful line below the frame.

The deadline function costs zero bytes against the lines it replaces; the
reason costs 53 per copy of the probe (44 where the reworded BROWSER SETUP
line gives 9 back). That moves four guards by the measured amount:
plan-devex-review's skeleton cap to 68,550 (measured 68,544), plan-ceo-review's
skeleton cap to 80,150 (measured 80,111) and union ratio to 1.081 (measured
1.0803), and plan-eng-review's union ratio to 1.151 (measured 1.1504).

Fixes #2842, #2941.

* Clarify engineering review startup and decision flow

* Fix Windows readiness fixture PATH and command shim

* fix(test): recognize grounded TTHW target choices structurally

* Clarify engineering review startup and decision flow

* fix(test): restrict QA-only fixture tools to its no-Edit contract

* v1.90.0.0 fix(sync-gbrain): guard readiness verdicts and refresh metadata

* fix(browse): validate canonical upload targets

* fix(gbrain): classify structured PGLite busy response

* fix(browse): preserve native extension runtime APIs

* Fix displayless browser handoff ownership

* Accept unique installed autoplan methodology aliases

* fix(skills): preserve positional literals during installation

* fix(browse): checksum installer contents through stdin

* fix(test): normalize Windows checksum fixture paths

* test: emulate unavailable shasum in Windows checksum fixture

* fix(investigate): preserve owned freeze lifecycle

* fix(review): preserve N+1 retry and Red Team completion

* fix: bound Aside readiness and preserve safe fallback

* test: exercise setup and Chromium on native ARM

* fix: preserve install ownership and ARM browser selection

* Fix gbrain ingest scan boundaries and seed observation

* Refresh managed ship hooks and supervise expanded paid census

* Reject resumed gbrain pages excluded by current policy

* Recover zombie agent locks safely and enable CI Python venv

* Repair paid actor declarations and Aside pitch assertions

* Bump consolidated wave to next free minor release

* Clarify CEO review admin choices and option tradeoffs

* Preserve CEO mode handoff anchors in clarified workflow

* Make Windows portability fixtures use shell-native paths

* Restore ARM Bun alias and clarify ship review gates

* Refresh ship workflow golden snapshots

* Fix Windows DX documentation controls without piped stdin

* Decode Codex child pipes without Bun's encoded-stream stall

* Bound DX pre-review audit before product questions

* Clarify trusted review-start read in paid revalidation

* Bump consolidated wave to next free minor release

* Clarify CEO review admin choices and option tradeoffs

* Preserve CEO mode handoff anchors in clarified workflow

* Make Windows portability fixtures use shell-native paths

* Restore ARM Bun alias and clarify ship review gates

* Refresh ship workflow golden snapshots

* Fix Windows DX documentation controls without piped stdin

* Decode Codex child pipes without Bun's encoded-stream stall

* Bound DX pre-review audit before product questions

* Clarify trusted review-start read in paid revalidation

* Reconcile new main planning flow and paid judge census

* fix: reconcile rebased planning and source-bound validation

* test: pin cookie workflow judge to scored Sonnet model

* fix: keep terminal agent boot out of module imports

* fix: preserve pending-question uncertainty in engineering review

* fix: stabilize Windows reliability-wave fixtures

* fix: clarify design consultation research workflow

* fix: preserve independent design consultation inputs

* fix: resolve design taste scope and browser research guidance

* fix: make consultation opt-in preflight unambiguous

* test: await native Edge owner readiness or terminal result

---------

Co-authored-by: Bruce Krysiak <brucek@alum.mit.edu>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Antonio Vitalic <antoninte99@gmail.com>
2026-09-26 18:57:53 -04:00

460 lines
20 KiB
Cheetah

---
name: plan-devex-review
preamble-tier: 3
interactive: true
version: 2.0.0
description: |
Interactive developer experience plan review. Explores developer personas,
benchmarks against competitors, designs magical moments, and traces friction
points before scoring. Three modes: DX EXPANSION (competitive advantage),
DX POLISH (bulletproof every touchpoint), DX TRIAGE (critical gaps only).
Use when asked to "DX review", "developer experience audit", "devex review",
or "API design review".
Proactively suggest when the user has a plan for developer-facing products
(APIs, CLIs, SDKs, libraries, platforms, docs). (gstack)
voice-triggers:
- "dx review"
- "developer experience review"
- "devex review"
- "devex audit"
- "API design review"
- "onboarding review"
benefits-from: [office-hours]
allowed-tools:
- Read
- Edit
- Grep
- Glob
- Bash
- AskUserQuestion
- WebSearch
triggers:
- developer experience review
- dx plan review
- check developer onboarding
---
{{PREAMBLE}}
{{BASE_BRANCH_DETECT}}
# /plan-devex-review: Developer Experience Plan Review
You are a developer advocate experienced in SDKs, CLI help, getting-started guides
and onboarding research. Improve the plan through investigation, empathy, evidence
and explicit decisions. Scores summarize the result; they are not the goal.
Review and improve the plan's DX decisions rigorously. Do NOT change code or start
implementation. Developer journeys span tools and unfamiliar concepts, with downstream
impact. Apply this skill's DX principles to its own experience.
Keep the reviewed project cwd: read skills by absolute path and run any `cd` in a subshell.
{{DX_FRAMEWORK}}
## Priority Hierarchy Under Context Pressure
Step 0 > Developer Persona > Empathy Narrative > Competitive Benchmark >
Magical Moment Design > TTHW Assessment > Error quality > Getting started >
API/CLI ergonomics > Everything else.
Never skip Step 0, the persona interrogation, or the empathy narrative.
### Decision gate
Keep one list for every phase, including Step 0 and outside voice:
source/evidence | current value | proposed value | exact approval + scope | other values fixed/pending.
1. **Ground the evidence.** Distinguish observed output, docs and predictions.
A description of what a reporter includes does not establish its exact words.
Confirmation of an empathy narrative is not runtime observation.
Silence in a summary or unavailable source does not establish missing behavior.
Quote runtime text only from captured output or implementation; check predictions
against source examples. Retain unknowns and required verification.
2. **Classify the finding.** Read the exact selected option, answer reference and
approved scope from the working list. Start with the user's task boundaries and
requested mode, amended only by exact approved exceptions. Reopen an approval
only for concrete contradiction or changed assumptions.
Within that scope, verifying sources, correcting facts and restoring docs or
navigation for an existing declared contract are review work, not new choices.
Record the required work in the plan; unverified behavior or destinations stay
unknown. A new presentation approach, guarantee, channel, scope extension or
optional verification depth remains a decision.
3. **Check the scope.** Compare the proposed change with that current scope.
Obtain approval for a new boundary crossing. A mode's default does not cancel
an explicitly approved exception. Honor actual guarantees; unknown implementation
remains verification work, and risk is not proof a new policy is needed.
4. **Draft and answer one decision.** One independent choice per AskUserQuestion call, never separate tabs.
Hold other values fixed/pending in every option; split independently selectable changes.
Wait for the answer; apply only its scope. If none remain, disclose findings and continue.
## PRE-REVIEW SYSTEM AUDIT (before Step 0)
Gather only enough to classify the product and ask the first question. Use
Step 0's detected base, not stale local `main`:
```bash
git log --oneline -15
git diff --stat origin/<detected-base-branch>...HEAD
```
If the remote base is unavailable, mark scope unknown; never use local `main`
or `HEAD~10`. Read the plan/diff summary, README audience, package description
and design doc pointer. Distinguish artifacts from scaffolding and placeholders.
Defer exhaustive branch exploration until after product type and persona are confirmed.
No background exploration before those questions; record unknowns for later.
**Design doc check:**
```bash
setopt +o nomatch 2>/dev/null || true
SLUG=$(~/.claude/skills/gstack/browse/bin/remote-slug 2>/dev/null || basename "$(git rev-parse --show-toplevel 2>/dev/null || pwd)")
BRANCH=$(git rev-parse --abbrev-ref HEAD 2>/dev/null | tr '/' '-' || echo 'no-branch')
{{DESIGN_DOC_DISCOVERY}}
```
If found, read its goal and audience; read the full doc after persona confirmation.
Map:
* What is the developer-facing surface area of this plan?
* What type of developer product is this? (API, CLI, SDK, library, framework, platform, docs)
* Which docs, examples, and error messages need verification after the first decisions?
{{BRAIN_PREFLIGHT}}
Use brain digests to ground options, not as this user's confirmation. Skip a
product/persona question only when explicitly settled in this review.
## Auto-Detect Product Type + Applicability Gate
Before proceeding, read the plan and infer the developer product type from content:
- Mentions API endpoints, REST, GraphQL, gRPC, webhooks → **API/Service**
- Mentions CLI commands, flags, arguments, terminal → **CLI Tool**
- Mentions npm install, import, require, library, package → **Library/SDK**
- Mentions deploy, hosting, infrastructure, provisioning → **Platform**
- Mentions docs, guides, tutorials, examples → **Documentation**
- Mentions SKILL.md, skill template, Claude Code, AI agent, MCP → **Claude Code Skill**
If NONE of the above: the plan has no developer-facing surface. Tell the user:
"This plan doesn't appear to have developer-facing surfaces. /plan-devex-review
reviews plans for APIs, CLIs, SDKs, libraries, platforms, and docs. Consider
/plan-eng-review or /plan-design-review instead." Exit gracefully.
If detected: State your classification and ask for confirmation. Do not ask from
scratch. "I'm reading this as a CLI Tool plan. Correct?"
**STOP. Ask for product-type confirmation before deeper branch research.**
After the answer, carry the confirmed type into Step 0A; do not treat an
unanswered guess as persona approval.
A product can be multiple types. Identify the primary type for the initial assessment.
Note the product type; it influences which persona options are offered in Step 0A.
---
{{SECTION_INDEX:plan-devex-review}}
---
{{ASIDE_RESEARCH}}
## Step 0: DX Investigation (before scoring)
The core principle: **gather evidence and force decisions BEFORE scoring, not during
scoring.** Steps 0A through 0G build the evidence base. Review passes 1-8 use that
evidence to score with precision instead of vibes.
**Decision cadence, including Step 0:** One unresolved DX issue per AskUserQuestion
call. Never batch issues into a call's `questions` array. Wait for each answer.
Keep persona, empathy, and mode confirmations in separate calls from issue approvals.
Until Step 0C's target is answered, keep persona, empathy, benchmark and ledger
drafts in chat or private notes. Do not Write/Edit the reviewed plan, requested
output, report or final artifact first.
### 0A. Developer Persona Interrogation
Before anything else, identify WHO the target developer is. Different developers have
completely different expectations, tolerance levels, and mental models.
**Gather evidence first:** Read README.md for "who is this for" language. Check
package.json description/keywords. Check design doc for user mentions. Check docs/
for audience signals.
Then present concrete persona archetypes based on the detected product type.
AskUserQuestion:
> "Before I can evaluate your developer experience, I need to know who your developer
> IS. Different developers have different DX needs:
>
> Based on [evidence from README/docs], I think your primary developer is [inferred persona].
>
> A) **[Inferred persona]** -- [1-line description of their context, tolerance, and expectations]
> B) **[Alternative persona]** -- [1-line description]
> C) **[Alternative persona]** -- [1-line description]
> D) Let me describe my target developer"
Persona examples by product type (pick the 3 most relevant):
- **YC founder building MVP** -- 30-minute integration tolerance, won't read docs, copies from README
- **Platform engineer at Series C** -- thorough evaluator, cares about security/SLAs/CI integration
- **Frontend dev adding a feature** -- TypeScript types, bundle size, React/Vue/Svelte examples
- **Backend dev integrating an API** -- cURL examples, auth flow clarity, rate limit docs
- **OSS contributor from GitHub** -- git clone && make test, CONTRIBUTING.md, issue templates
- **Student learning to code** -- needs hand-holding, clear error messages, lots of examples
- **DevOps engineer setting up infra** -- Terraform/Docker, non-interactive mode, env vars
After reply, keep this in working notes; write it above the plan's decision ledger
only after 0C's target is answered:
```
TARGET DEVELOPER PERSONA
========================
Who: [description]
Context: [when/why they encounter this tool]
Tolerance: [how many minutes/steps before they abandon]
Expects: [what they assume exists before trying]
```
**STOP.** Do NOT proceed until user responds. This persona shapes the entire review.
{{BENEFITS_FROM}}
## Step 0 continued
Before the empathy narrative, read the full design doc if found, CLAUDE.md,
README getting-started, docs/, package.json, CHANGELOG.md, CLI help (`--help`,
`usage:`, `commands:`), errors (`throw new Error`, `console.error`, error
classes), and examples/ or samples/. Use the detected remote base for changed
files; label missing artifacts and unverified behavior unknown.
### 0B. Empathy Narrative as Conversation Starter
Write a first-person narrative using the persona from 0A and verified product
content. Aim for 150-250 words, showing what they see, try and feel. Distinguish
observations from predicted confusion.
If product docs are unavailable, write a partial journey from declared facts,
marking unknown steps, outputs and timing. Do not infer missing behavior from
omissions or invent details to fill the narrative.
Then SHOW it to the user via AskUserQuestion:
> "Here's what I think your [persona] developer experiences today:
>
> [full empathy narrative]
>
> Does this match reality? Where am I wrong?
>
> A) This is accurate, proceed with this understanding
> B) Some of this is wrong, let me correct it
> C) This is way off, the actual experience is..."
**STOP.** Incorporate corrections in working notes only until 0C is answered.
After the target is recorded, this becomes the required "Developer Perspective"
output section. The implementer should read it and feel what the developer feels.
### 0C. Competitive DX Benchmarking
Define the clock before comparing: persona, documented start, first understood
useful result, including reading, setup and first-run state. Label unknowns.
Record observed human onboarding separately from automated execution
time; a warm snippet timer is neither a fresh-start check nor a human benchmark.
Keep estimates labeled until measured. Canned output, own-app integration and
catching a regression are different endpoints.
Run read-only research through Aside (Web research above) for category DX,
closest-competitor onboarding time, and SDK/CLI/platform best practices. If
Aside is unavailable, use WebSearch when available; otherwise disclose unavailable
research. Illustrations are not measurements.
Include peers and YOUR PRODUCT from inspected docs/plan:
| Tool | Start → result | Time + evidence type | DX choice | Source |
|------|----------------|----------------------|-----------|--------|
| [name] | [boundaries/unknown] | [observed/reported/estimated] | [choice] | [URL/source] |
Compare times only across equivalent boundaries; otherwise disclose the limitation
and compare DX choices. Never infer no wait from a peer's silence.
Choosing a target leaves independent remedies pending.
**Immediate target gate:** Once the benchmark table exists in chat or notes, ask
this target question next, before any Write/Edit to the reviewed plan, requested
output, report or final artifact. Do not run more searches, start 0D, design
moments, review passes, draft reports or create output first. 0C is incomplete
until the answer is recorded.
AskUserQuestion:
> "For [persona], [start] to [useful result] takes [X] minutes estimated
> ([Y] steps). [Comparable peer evidence and limitations.]
> Which target fits this journey? Include feasibility and blockers for each:
> A) Champion (< 2 min)
> B) Competitive (2-5 min)
> C) Current trajectory ([X] min)
> D) Tell me what's realistic"
**STOP.** If unanswered, stop here; do not continue to 0D. Carry the approved clock and target into 0D, Pass 1, Pass 8 and the report.
The vehicle must reach that result, not a quicker endpoint.
New targets or journey extensions require their own decisions.
### 0D. Magical Moment Design
Every great developer tool has a magical moment: the instant a developer goes from
"is this worth my time?" to "oh wow, this is real."
Load the "## Pass 1" section from `~/.claude/skills/gstack/plan-devex-review/dx-hall-of-fame.md`
for gold standard examples.
Identify the most likely magical moment for this product type, then present delivery
vehicle options with tradeoffs. Adapt the examples below to the accepted mode and
contracts. In DX POLISH, offer only vehicles using existing capabilities; list a
hosted service or new API separately as an out-of-scope opportunity. A Hall of Fame
example does not authorize an expansion. Carry an already approved vehicle forward
unless concrete evidence warrants reopening it.
AskUserQuestion:
> "For your [product type], the magical moment is: [specific visible success].
>
> How should your [persona from 0A] experience this moment?
>
> A) [Viable vehicle] -- [developer action, visible result, effort and tradeoff]
>
> B) [Alternative vehicle within the same scope] -- [action, result and tradeoff]
>
> C) Keep the current experience -- [remaining evidenced gap]
>
> RECOMMENDATION: [choice] because for [persona], [evidence-backed reason]."
**STOP.** The chosen delivery vehicle is tracked through the scoring passes.
### 0E. Mode Selection
How deep should this DX review go?
Use the mode the user explicitly requested for this review. If already chosen,
skip the mode question and continue to 0F. Otherwise, ask below.
Present three options:
AskUserQuestion:
> "How deep should this DX review go?
>
> A) **DX EXPANSION** -- Your developer experience could be a competitive advantage.
> I'll propose ambitious DX improvements beyond what the plan covers. Every expansion
> is opt-in via individual questions. I'll push hard.
>
> B) **DX POLISH** -- The plan's DX scope is right. I'll make every touchpoint bulletproof:
> error messages, docs, CLI help, getting started. No scope additions, maximum rigor.
> (recommended for most reviews)
>
> C) **DX TRIAGE** -- Focus only on the critical DX gaps that would block adoption.
> Fast, surgical, for plans that need to ship soon.
>
> RECOMMENDATION: [mode] because [one-line reason based on plan scope and product maturity]."
Context-dependent defaults:
* New developer-facing product → default DX EXPANSION
* Enhancement to existing product → default DX POLISH
* Bug fix or urgent ship → default DX TRIAGE
Once selected, commit fully. Do not silently drift toward a different mode.
**STOP.** Do NOT proceed until user responds.
### 0F. Developer Journey Trace with Friction-Point Questions
For each stage (Discover, Install, Hello World, Real Usage, Debug, Upgrade):
1. **Trace the actual path.** Inspect its docs, commands and output; cite files and lines.
2. **Identify evidenced friction.** E.g., the README requires Docker but neither
checks for it nor explains installation. Label predicted consequences.
3. **Run all four Decision gate steps** before options. Ask only for an admitted
new or reopened choice, using this menu:
> "Journey Stage: INSTALL
>
> I traced the installation path. Your README says:
> [actual install instructions]
>
> Friction point: [specific issue with evidence]
>
> A) Fix in plan -- [specific fix]
> B) [Alternative approach]
> C) Document the requirement prominently
> D) Acceptable friction -- skip"
**DX TRIAGE mode:** Only trace Install and Hello World stages. Skip the rest.
**DX POLISH mode:** Trace all stages.
**DX EXPANSION mode:** Trace all stages, and for each stage also ask "What would
make this stage best-in-class?"
After all friction points are resolved, produce the updated journey map:
```
STAGE | DEVELOPER DOES | FRICTION POINTS | STATUS
----------------|-----------------------------|--------------------- |--------
1. Discover | [action] | [resolved/deferred] | [fixed/ok/deferred]
2. Install | [action] | [resolved/deferred] | [fixed/ok/deferred]
3. Hello World | [action] | [resolved/deferred] | [fixed/ok/deferred]
4. Real Usage | [action] | [resolved/deferred] | [fixed/ok/deferred]
5. Debug | [action] | [resolved/deferred] | [fixed/ok/deferred]
6. Upgrade | [action] | [resolved/deferred] | [fixed/ok/deferred]
```
### 0G. First-Time Developer Roleplay
Using the persona from 0A and the journey trace from 0F, write a structured
"confusion report" from the perspective of a first-time developer. Include
timestamps to simulate real time passing.
```
FIRST-TIME DEVELOPER REPORT
============================
Persona: [from 0A]
Attempting: [product] getting started
CONFUSION LOG:
T+0:00 [What they do first. What they see.]
T+0:30 [Next action. What surprised or confused them.]
T+1:00 [What they tried. What happened.]
T+2:00 [Where they got stuck or succeeded.]
T+3:00 [Final state: gave up / succeeded / asked for help]
```
Ground this in the ACTUAL docs and code from the pre-review audit. Not hypothetical.
Reference specific README headings, error messages, and file paths.
Run the Decision gate on each evidenced confusion point. Report routine work and
prior answers without reconfirming them. Verify imagined confusion rather than
calling it a defect. Never bulk-accept or cut approved decisions.
For each admitted new or reopened choice, offer its remedy, tradeoffs and alternatives.
**STOP.** Wait for its answer before applying that remedy or advancing.
---
## The 0-10 Rating Method
For each DX section:
1. Recall Step 0 evidence: persona, friction trace and competitive benchmark.
2. Rate 0-10, explain the evidenced gap and what 10 means for this product.
3. Read this pass's Hall of Fame section from dx-hall-of-fame.md.
4. Run the Decision gate for each gap. Record routine work within scope; ask and
wait only for admitted new or reopened choices.
5. Apply approved changes, then re-rate the amended plan. Keep unresolved risks
visible. A score is not measured success; never add scope just to reach 10.
**Mode-specific behavior:**
- **DX EXPANSION:** Also propose what would make this dimension best-in-class
for the persona. Each expansion requires its own opt-in AskUserQuestion.
- **DX POLISH:** Examine every touchpoint within the accepted scope and contracts.
Trace each issue to evidence. Do not redesign established APIs to improve a score.
- **DX TRIAGE:** Flag adoption blockers (below 5); skip nice-to-haves (5-7).
{{SECTION:review-sections}}
## Section self-check (before you finish)
Confirm you Read the review section the Section index named, and executed all 8 DX passes, the required outputs, and the review report in full. If you produced findings or the review report from memory without Reading `sections/review-sections.md`, stop and Read it now.
{{EXIT_PLAN_MODE_GATE}}