The pipeline had never been run against an actual repository — every test in
the suite is either a prose-grep over SKILL.md or a unit test that asserts key
presence. Running it against scratch repos (private remote, and public `open/`
remote with and without a gitignored STATE.md) found two defects living under
a 42/42-green suite.
1. dirty_files truncated the first path. gitOk() trims every command's output,
but `git status --porcelain` puts the worktree status in column 2, so a
modified-but-unstaged file is " M path". The trim ate the leading space and
the fixed slice(3) then ate the first character: app.js was reported as
pp.js. Only the first line is affected, which is why it survived — no test
asserted dirty_files VALUES, only that the key existed. Porcelain now goes
through a non-trimming gitOkRaw().
2. The commit message claimed a STATE.md update it did not contain. The
message was hardcoded to "oppdater STATE.md" regardless of what was staged.
On every `open/` repo STATE.md is gitignored, so the handoff commit carries
only the --also paths. Git history is the regime's long-term log; it was
systematically wrong about its own contents.
Also promotes the leak condition from advisory to hard gate. A public remote
whose STATE.md is not yet gitignored is the state a FRESH open/ repo starts
in, and should_commit_state was true there — the ritual only mentioned
leak_warning, then committed. It now lands in errors[] (step 2 stops on a
non-empty errors[]), should_commit_state is false, and --commit refuses to
stage STATE.md. Explicit --also paths are still honoured: the gate protects
STATE.md, not the commit as a whole.
And corrects SKILL.md's justification for the single-line rule. It claimed a
wrapped rationale= replaces the board's next step with garbage; board.sh in
repo-mailbox 0.20.3 tracks a comment to its closer, so that no longer follows.
The rule stands, restated with the risk that is still real: a rationale
containing the closer sequence ends its own comment early.
Tests 42 -> 48, all six written failing first.
Still unverified: that /graceful-handoff loads as a user command (#26251), and
that a cross-plugin Skill invocation of repo-mailbox:route passes from a
sub-scoped skill. Both need the catalog ref bumped so the version is installed.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RvLY4FwbzY157oVqwnkHD8