Skip to content

Add the dev-workflow:sparring advisory skill (0.14.0) - #32

Merged
dsnger merged 4 commits into
mainfrom
sparring-skill
Sep 30, 2026
Merged

dsnger merged 4 commits into
mainfrom
sparring-skill

Conversation

@dsnger

@dsnger dsnger commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

What

A new user-invoked skill, dev-workflow:sparring: an advisory session in a chat you open for that purpose. It investigates read-only, checks agent reports against the current files, and drafts bounded prompts for a coding agent to run elsewhere. It does not implement, commit, or run review gates. The read-only posture is an instruction, not a sandbox.

  • plugins/dev-workflow/skills/sparring/SKILL.md: new, copied verbatim from spec §5, no manifest key (invariant 6)
  • docs/sparring-briefing.md: the closing section said "not a plugin feature" and is replaced by spec §6
  • README.md, AGENTS.md, docs/architecture.md: the skill is named in each inventory
  • dev-workflow 0.13.3 → 0.14.0, with a CHANGELOG entry

Spec: docs/superpowers/specs/2026-09-17-sparring-skill-design.md · Story: docs/superpowers/stories/2026-09-17-sparring-skill-story.md · Plan: docs/superpowers/plans/2026-09-30-sparring-skill.md

Review record

  • Gate A spec: cycle at71dccpoc, 3 passes, closed (commit 01a511d).
  • Gate A plan: cycle vl584i4v7j, 5 passes. Findings 15,10,6,4,2 and Majors 6,6,1,1,0. Closed (commit dc44dd5).
  • Gate B: cycle 73tpkveiel, pass 1. Both the spec and the quality branch returned NO FINDINGS, so the cycle closed on the zero-finding exit.
  • The quality battery exited 0 at the reviewed commit and again before closing.

What no check covers

What the skill does in a session is prompt text. No harness runs it, so its behaviour was checked by reading only: 12 walkthrough scenarios plus the 12 prompt-standards items, and none of it was executed.

Summary by CodeRabbit

  • New Features
    • Added the dev-workflow:sparring skill for repository investigation, checking reports against current files, weighing options, and drafting bounded prompts for a coding agent.
    • The skill is invoked by name and provides advice without making implementation changes. It can optionally use a project’s local docs/SPARRING-PARTNER.md.
  • Documentation
    • Updated the plugin inventories and briefing to describe the skill and distinguish it from this repository’s sparring document.

Gate-A spec cycle closed. Final pass clean at the derived floor: 0 Blockers
and 0 Majors at pass 3, every earlier Blocker and Major resolved, Minor and
Nit findings collected without iteration. No product file is written by this
commit; implementation is not authorized.

Docs-only change (docs/**.md) — Gate B is N/A per CLAUDE.md §5, and no plugin
path is touched, so invariant 12 does not apply.

cycle at71dccpoc; floor 3 per {docs/superpowers/stories/2026-09-17-sparring-skill-story.md (level 1)}; hook reminder threshold absent
cycle at71dccpoc; Gate-A spec (passes 1-3, gpt-6-astra): Findings 18,10,3. Blockers 0,0,0. Majors 6,4,0.
Gate-A plan cycle closed. Pass 5 is clean at or above the derived floor:
0 Blockers and 0 Majors; every earlier Major was repaired in the plan and
confirmed resolved by the following pass. Pass 5's two Minors are
collected, not iterated. The committed plan is byte-identical to the text
pass 5 reviewed (sha256 f1e84f110f899ecd8de03022eb2aa466978973966413bcee67d24adac45c46d1).

Docs-only change (docs/**.md) — Gate B is N/A per CLAUDE.md §5.

cycle vl584i4v7j; floor 3 per {docs/superpowers/stories/2026-09-17-sparring-skill-story.md (level 1)}; hook reminder threshold absent
cycle vl584i4v7j; Gate-A plan (passes 1-5, gpt-6-astra): Findings 15,10,6,4,2. Blockers 0,0,0,0,0. Majors 6,6,1,1,0.
New skill plugins/dev-workflow/skills/sparring/SKILL.md, copied verbatim from
the spec's §5: an explicitly invoked advisory session (read-only by
instruction, not a sandbox) for investigating, checking agent reports
against the current files, and drafting bounded prompts for a coding agent
to run elsewhere. disable-model-invocation: true stops the model invoking
it on its own; it restricts nothing once running. Loaded by convention, no
manifest key (invariant 6).

docs/sparring-briefing.md's closing section said the pattern was "not a
plugin feature"; this change made that false, so it is replaced with the
spec's §6 text, which records that the promotion happened by decision, not
by a trigger. The skill is named in README.md, AGENTS.md and
docs/architecture.md. dev-workflow 0.13.3 -> 0.14.0.

Evidence — docs/superpowers/stories/2026-09-17-sparring-skill-story.md
Battery: AGENTS.md quality row, exit 0 at fcfef04cd30789a4eb3a6c680babae0a1fdda53d.
Check (counterfactual, spec §7 row 7): grep -c 'Not a plugin feature' and
'trigger, not a reflex' in docs/sparring-briefing.md read 1 and 1 before the change,
0 and 0 after.

cycle 73tpkveiel; floor 3 per {docs/superpowers/stories/2026-09-17-sparring-skill-story.md (level 1)}; hook reminder threshold absent
cycle 73tpkveiel; Gate B (passes 1, gpt-6-astra): Findings 0. Blockers 0. Majors 0.

Gate B pass 1 was one logical pass run as two calls (reviewType spec and
quality, same baseSha dc44dd5 and headSha
fcfef04cd30789a4eb3a6c680babae0a1fdda53d); both returned NO FINDINGS, so the
cycle closed on the zero-finding exit below the floor.
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 31 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 8f91c230-d1a7-4b2d-bec2-0985779c014a

📥 Commits

Reviewing files that changed from the base of the PR and between ae2b254 and 4eb273a.

📒 Files selected for processing (2)
  • docs/hardening-log.md
  • docs/superpowers/specs/2026-09-17-sparring-skill-design.md

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 009be97c-a5cd-45e5-9282-5c577658f56f

📥 Commits

Reviewing files that changed from the base of the PR and between 85faa49 and ae2b254.

📒 Files selected for processing (10)
  • AGENTS.md
  • README.md
  • docs/architecture.md
  • docs/sparring-briefing.md
  • docs/superpowers/plans/2026-09-30-sparring-skill.md
  • docs/superpowers/specs/2026-09-17-sparring-skill-design.md
  • docs/superpowers/stories/2026-09-17-sparring-skill-story.md
  • plugins/dev-workflow/.claude-plugin/plugin.json
  • plugins/dev-workflow/CHANGELOG.md
  • plugins/dev-workflow/skills/sparring/SKILL.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The pull request adds the explicitly invoked dev-workflow:sparring advisory skill. It defines read-only-by-instruction repository investigation, evidence-based advice, and bounded coding-agent prompts. It also updates the plugin version, changelog, skill inventories, briefing, and design and delivery records.

Changes

Sparring Skill

Layer / File(s) Summary
Skill design and delivery plan
docs/superpowers/specs/2026-09-17-sparring-skill-design.md, docs/superpowers/stories/2026-09-17-sparring-skill-story.md, docs/superpowers/plans/2026-09-30-sparring-skill.md
The design, story, and plan define the skill’s scope, behavior, acceptance criteria, verification scenarios, and delivery procedures.
Advisory skill workflow
plugins/dev-workflow/skills/sparring/SKILL.md, docs/superpowers/specs/2026-09-17-sparring-skill-design.md
The skill directs repository investigation and report checks, distinguishes evidence from inference, limits permitted actions, and defines the contents and response format for bounded coding-agent prompts.
Plugin release and inventories
plugins/dev-workflow/.claude-plugin/plugin.json, plugins/dev-workflow/CHANGELOG.md, AGENTS.md, README.md, docs/architecture.md, docs/sparring-briefing.md, docs/superpowers/specs/2026-09-17-sparring-skill-design.md
The plugin version changes to 0.14.0; the changelog and skill inventories include sparring. The briefing now describes the skill as shipped and explicitly invoked, while remaining a hand-written, unscaffolded document.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant User
  participant SparringSkill
  participant Repository
  participant CodingAgent
  User->>SparringSkill: Request investigation or advice
  SparringSkill->>Repository: Read project guidance and current artifacts
  Repository-->>SparringSkill: Provide repository evidence
  SparringSkill-->>User: Return findings and, if requested, a bounded prompt
  User->>CodingAgent: Provide prompt in a separate coding session
Loading

Merge Risk: ⚪ Minimal · up to ae2b2

The advisory skill and its release documentation are consistent, with no concrete merge-blocking issue identified. Its read-only limits are instructions, not a sandbox. Mergeable subject to normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to ae2b2

The advisory workflow clearly limits intended actions and separates advice from implementation. Those limits are instructions rather than enforced restrictions. No concrete security defect was established, but execution behavior and exceptional document-write recovery remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The advisory label does not technically limit access to the named document or repository. If its instructions are violated, effective exposure depends on the host's existing tool permissions; credential, network, tenant, and environment reach are not established by the inspected source.

Trust Boundaries and Controls

  • observed — Pasted reports and other-session material are advisory inputs rather than evidence of this session implementing. Local project guidance cannot expand implementation authority, and report claims must be verified before advice is based on them. These are textual controls, not demonstrated resistance to malicious instructions.

Resilience and Maintainability Implications

  • observed — The authorized document save remains excluded from the implementation-session redirect in later turns, but writes outside that permission do not. Downstream edits require snapshot revalidation and preservation of unrelated work; the direct-save exception does not specify conflict detection, atomicity, or partial-write recovery.

Hardening Proposals

  • proposed — If advisory mode is later intended to provide an enforceable security guarantee, restrict host tool authority and provide a narrowly scoped document-save operation with conflict detection and explicit failure reporting. This would strengthen the stated contract rather than repair a verified vulnerability.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the main change: adding the dev-workflow:sparring advisory skill and its 0.14.0 release.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit reads the files with care,
It checks each claim against what’s there.
It drafts a prompt, concise and clear,
For another agent elsewhere to hear.
No commits hop from this review,
Just facts and guidance, neatly due.

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Low risk] Documentation and plugin metadata for a new advisory skill.

The PR appears safe to merge; no outstanding findings remain.

Summary

The PR adds an explicitly invoked, advisory-only dev-workflow:sparring skill, updates the briefing and component inventories, and releases it as version 0.14.0. The post-review change corrects the spec’s walkthrough count and records the correction in the hardening log.

Reviews (2) · Last reviewed commit: "docs: correct the spec's walkthrough cou..."

Comment thread docs/superpowers/specs/2026-09-17-sparring-skill-design.md Outdated
…urrence

The sparring-skill spec introduced its walkthrough list as "the eight
walkthrough scenarios … the last two were added by pass 1" while the list
numbers twelve; the second Gate-A repair round added 9-12 without updating
the sentence (PR #32, Greptile P2). The sentence now says twelve and which
round added which. docs/hardening-log.md records it as the eighth docs-drift
occurrence, at 1 prose with no new text.

Docs-only change (docs/**.md): Gate B is N/A per CLAUDE.md §5's prose
exemption, so there is no Gate-B cycle and no provenance line or skip record.
@dsnger
dsnger merged commit 81787b7 into main Sep 30, 2026
3 checks passed
@dsnger
dsnger deleted the sparring-skill branch September 30, 2026 14:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant