S56: spawn template overhaul + system-wide README push + .gitkeep cleanup (#129)

- Spawn template system rebuilt: regenerate-registry command (3-pass ID matching),
  registry 26→41 files, generate_branch_meta fixed, Phase 0 snapshot added
- System-wide push: 12/12 branches updated (227 additions, 0 errors)
- READMEs added to all standard directories across 15 branches
- .claude/settings.local.json tracked system-wide (deny rules)
- 35 .gitkeep files removed (replaced by READMEs)
- Bypass files updated across 13 branches
- Bugs fixed: manager citizen_class crash, backup rglob performance

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
AIPass
2026-03-25 01:10:22 -07:00
committed by GitHub
co-authored by Claude Opus 4.6
parent fef36d6157
commit e5f0d4f1c4
168 changed files with 2067 additions and 251 deletions
+1 -1
View File
@@ -47,7 +47,7 @@ docs.local/
# Claude Code local state
.claude/hooks/__pycache__/
.claude/hooks/.last_diagnostics_file
**/.claude/settings.local.json
# **/.claude/settings.local.json — UNIGNORED: deny rules are system config that must travel with PRs
# Disabled files (AIPass convention: rename with (disabled) instead of delete)
*(disabled)
+3
View File
@@ -0,0 +1,3 @@
# Branch Prompt
AI context for `AI_MAIL`. The `aipass_local_prompt.md` file is injected every turn, telling the AI who you are and how to work in your branch.
+5
View File
@@ -0,0 +1,5 @@
# Claude Code Settings
Claude Code configuration for `AI_MAIL`.
Contains `settings.local.json` with permission rules. Most branches are denied raw git commands and must use `drone @git` instead.
@@ -0,0 +1,28 @@
{
"permissions": {
"allow": [],
"deny": [
"Bash(git reset*)",
"Bash(git rebase*)",
"Bash(git merge*)",
"Bash(git config*)",
"Bash(git push --force*)",
"Bash(git push -f *)",
"Bash(git checkout -- *)",
"Bash(git checkout .*)",
"Bash(git restore --staged*)",
"Bash(git restore .*)",
"Bash(git clean*)",
"Bash(git branch -D*)",
"Bash(git stash drop*)",
"Bash(git stash clear*)",
"Bash(rm -rf*)",
"Bash(rm -r *)",
"Bash(git checkout -b*)",
"Bash(git commit*)",
"Bash(git push*)"
],
"ask": []
},
"enabledMcpjsonServers": []
}
+5
View File
@@ -0,0 +1,5 @@
# Standards Bypass
Seedgo audit bypass config for `AI_MAIL`.
When an audit flags a false positive that doesn't apply to your architecture, add a bypass entry in `bypass.json` with a reason explaining why it's justified.
+3 -3
View File
@@ -231,12 +231,12 @@
"example": {
"file": "apps/modules/logger.py",
"standard": "cli",
"reason": "Circular dependency - logger cannot import CLI",
"lines": [
146,
177
],
"pattern": "if __name__ == '__main__'",
"reason": "Circular dependency - logger cannot import CLI"
"pattern": "if __name__ == '__main__'"
},
"fields": {
"file": "Relative path from branch root (required)",
@@ -246,4 +246,4 @@
"reason": "Required - why this bypass exists"
}
}
}
}
+8
View File
@@ -0,0 +1,8 @@
# Apps
Application layer for `AI_MAIL`.
- `ai_mail.py` — Entry point. Auto-discovers and routes commands to modules.
- `modules/` — Business logic and orchestration. One module per command.
- `handlers/` — Implementation details. Called by modules, never by CLI directly.
- `plugins/` — Scheduled tasks and extensions.
@@ -0,0 +1,5 @@
# Handlers
Implementation details for `AI_MAIL`.
Handlers do the actual work. They are called by modules, never directly by the CLI. Keep business logic in modules, implementation in handlers.
@@ -0,0 +1,5 @@
# Modules
Business logic for `AI_MAIL`. One module per command.
Modules orchestrate work by calling handlers. They are the public API of the branch — drone routes commands here.
@@ -0,0 +1,5 @@
# Plugins
Scheduled tasks and extensions for `AI_MAIL`.
Plugins are standalone units of work that can be scheduled via the daemon. Each plugin handles one specific recurring task.
+3
View File
@@ -0,0 +1,3 @@
# Docs
Documentation files for the `AI_MAIL` branch.
+5
View File
@@ -0,0 +1,5 @@
# Templates
Branch-specific templates for `AI_MAIL`.
Any templates this branch provides to the system or uses internally. Examples: plan templates (flow), trinity templates (memory), test templates (seedgo).
+6
View File
@@ -0,0 +1,6 @@
# Tests
Pytest unit tests for `AI_MAIL`.
- `conftest.py` — Shared fixtures (temp dirs, mocks, sample data).
- `test_*.py` — Test files. Standard tests cover JSON handler, CLI routing, and error resilience. Custom tests cover branch-specific domain logic.
+3
View File
@@ -0,0 +1,3 @@
# Branch Prompt
AI context for `API`. The `aipass_local_prompt.md` file is injected every turn, telling the AI who you are and how to work in your branch.
+5
View File
@@ -0,0 +1,5 @@
# Claude Code Settings
Claude Code configuration for `API`.
Contains `settings.local.json` with permission rules. Most branches are denied raw git commands and must use `drone @git` instead.
@@ -0,0 +1,28 @@
{
"permissions": {
"allow": [],
"deny": [
"Bash(git reset*)",
"Bash(git rebase*)",
"Bash(git merge*)",
"Bash(git config*)",
"Bash(git push --force*)",
"Bash(git push -f *)",
"Bash(git checkout -- *)",
"Bash(git checkout .*)",
"Bash(git restore --staged*)",
"Bash(git restore .*)",
"Bash(git clean*)",
"Bash(git branch -D*)",
"Bash(git stash drop*)",
"Bash(git stash clear*)",
"Bash(rm -rf*)",
"Bash(rm -r *)",
"Bash(git checkout -b*)",
"Bash(git commit*)",
"Bash(git push*)"
],
"ask": []
},
"enabledMcpjsonServers": []
}
+5
View File
@@ -0,0 +1,5 @@
# Standards Bypass
Seedgo audit bypass config for `API`.
When an audit flags a false positive that doesn't apply to your architecture, add a bypass entry in `bypass.json` with a reason explaining why it's justified.
+3 -3
View File
@@ -86,12 +86,12 @@
"example": {
"file": "apps/modules/logger.py",
"standard": "cli",
"reason": "Circular dependency - logger cannot import CLI",
"lines": [
146,
177
],
"pattern": "if __name__ == '__main__'",
"reason": "Circular dependency - logger cannot import CLI"
"pattern": "if __name__ == '__main__'"
},
"fields": {
"file": "Relative path from branch root (required)",
@@ -101,4 +101,4 @@
"reason": "Required - why this bypass exists"
}
}
}
}
+8
View File
@@ -0,0 +1,8 @@
# Apps
Application layer for `API`.
- `api.py` — Entry point. Auto-discovers and routes commands to modules.
- `modules/` — Business logic and orchestration. One module per command.
- `handlers/` — Implementation details. Called by modules, never by CLI directly.
- `plugins/` — Scheduled tasks and extensions.
+5
View File
@@ -0,0 +1,5 @@
# Handlers
Implementation details for `API`.
Handlers do the actual work. They are called by modules, never directly by the CLI. Keep business logic in modules, implementation in handlers.
+5
View File
@@ -0,0 +1,5 @@
# Modules
Business logic for `API`. One module per command.
Modules orchestrate work by calling handlers. They are the public API of the branch — drone routes commands here.
+5
View File
@@ -0,0 +1,5 @@
# Plugins
Scheduled tasks and extensions for `API`.
Plugins are standalone units of work that can be scheduled via the daemon. Each plugin handles one specific recurring task.
+5
View File
@@ -0,0 +1,5 @@
# Templates
Branch-specific templates for `API`.
Any templates this branch provides to the system or uses internally. Examples: plan templates (flow), trinity templates (memory), test templates (seedgo).
+6
View File
@@ -0,0 +1,6 @@
# Tests
Pytest unit tests for `API`.
- `conftest.py` — Shared fixtures (temp dirs, mocks, sample data).
- `test_*.py` — Test files. Standard tests cover JSON handler, CLI routing, and error resilience. Custom tests cover branch-specific domain logic.
+3
View File
@@ -0,0 +1,3 @@
# Branch Prompt
AI context for `BACKUP`. The `aipass_local_prompt.md` file is injected every turn, telling the AI who you are and how to work in your branch.
+5
View File
@@ -0,0 +1,5 @@
# Claude Code Settings
Claude Code configuration for `BACKUP`.
Contains `settings.local.json` with permission rules. Most branches are denied raw git commands and must use `drone @git` instead.
@@ -0,0 +1,28 @@
{
"permissions": {
"allow": [],
"deny": [
"Bash(git reset*)",
"Bash(git rebase*)",
"Bash(git merge*)",
"Bash(git config*)",
"Bash(git push --force*)",
"Bash(git push -f *)",
"Bash(git checkout -- *)",
"Bash(git checkout .*)",
"Bash(git restore --staged*)",
"Bash(git restore .*)",
"Bash(git clean*)",
"Bash(git branch -D*)",
"Bash(git stash drop*)",
"Bash(git stash clear*)",
"Bash(rm -rf*)",
"Bash(rm -r *)",
"Bash(git checkout -b*)",
"Bash(git commit*)",
"Bash(git push*)"
],
"ask": []
},
"enabledMcpjsonServers": []
}
+5
View File
@@ -0,0 +1,5 @@
# Standards Bypass
Seedgo audit bypass config for `BACKUP`.
When an audit flags a false positive that doesn't apply to your architecture, add a bypass entry in `bypass.json` with a reason explaining why it's justified.
+3 -6
View File
@@ -35,7 +35,6 @@
"standard": "deep_nesting",
"reason": "SKIP — file is being rewritten. 6 functions flagged (depth 4-5)."
},
{
"file": "apps/handlers/operations/file_operations.py",
"standard": "architecture",
@@ -81,7 +80,6 @@
"standard": "architecture",
"reason": "utils/ contains cross-cutting utilities. backup_timestamps is used by both backup_core and google_drive_sync — belongs to no single domain."
},
{
"file": "apps/handlers/json/statistics_handler.py",
"standard": "handlers",
@@ -122,7 +120,6 @@
"standard": "handlers",
"reason": "Imports BackupResult model from models/ — report formatting needs the result data model. Models are the shared contract between handlers."
},
{
"file": "apps/modules/google_drive_sync.py",
"standard": "naming",
@@ -154,12 +151,12 @@
"example": {
"file": "apps/modules/logger.py",
"standard": "cli",
"reason": "Circular dependency - logger cannot import CLI",
"lines": [
146,
177
],
"pattern": "if __name__ == '__main__'",
"reason": "Circular dependency - logger cannot import CLI"
"pattern": "if __name__ == '__main__'"
},
"fields": {
"file": "Relative path from branch root (required)",
@@ -169,4 +166,4 @@
"reason": "Required - why this bypass exists"
}
}
}
}
View File
+5
View File
@@ -0,0 +1,5 @@
# Templates
Branch-specific templates for `BACKUP`.
Any templates this branch provides to the system or uses internally. Examples: plan templates (flow), trinity templates (memory), test templates (seedgo).
+6
View File
@@ -0,0 +1,6 @@
# Tests
Pytest unit tests for `BACKUP`.
- `conftest.py` — Shared fixtures (temp dirs, mocks, sample data).
- `test_*.py` — Test files. Standard tests cover JSON handler, CLI routing, and error resilience. Custom tests cover branch-specific domain logic.
+3
View File
@@ -0,0 +1,3 @@
# Branch Prompt
AI context for `CLI`. The `aipass_local_prompt.md` file is injected every turn, telling the AI who you are and how to work in your branch.
+5
View File
@@ -0,0 +1,5 @@
# Claude Code Settings
Claude Code configuration for `CLI`.
Contains `settings.local.json` with permission rules. Most branches are denied raw git commands and must use `drone @git` instead.
@@ -0,0 +1,28 @@
{
"permissions": {
"allow": [],
"deny": [
"Bash(git reset*)",
"Bash(git rebase*)",
"Bash(git merge*)",
"Bash(git config*)",
"Bash(git push --force*)",
"Bash(git push -f *)",
"Bash(git checkout -- *)",
"Bash(git checkout .*)",
"Bash(git restore --staged*)",
"Bash(git restore .*)",
"Bash(git clean*)",
"Bash(git branch -D*)",
"Bash(git stash drop*)",
"Bash(git stash clear*)",
"Bash(rm -rf*)",
"Bash(rm -r *)",
"Bash(git checkout -b*)",
"Bash(git commit*)",
"Bash(git push*)"
],
"ask": []
},
"enabledMcpjsonServers": []
}
+5
View File
@@ -0,0 +1,5 @@
# Standards Bypass
Seedgo audit bypass config for `CLI`.
When an audit flags a false positive that doesn't apply to your architecture, add a bypass entry in `bypass.json` with a reason explaining why it's justified.
+3 -3
View File
@@ -73,12 +73,12 @@
"example": {
"file": "apps/modules/logger.py",
"standard": "cli",
"reason": "Circular dependency - logger cannot import CLI",
"lines": [
146,
177
],
"pattern": "if __name__ == '__main__'",
"reason": "Circular dependency - logger cannot import CLI"
"pattern": "if __name__ == '__main__'"
},
"fields": {
"file": "Relative path from branch root (required)",
@@ -88,4 +88,4 @@
"reason": "Required - why this bypass exists"
}
}
}
}
+8
View File
@@ -0,0 +1,8 @@
# Apps
Application layer for `CLI`.
- `cli.py` — Entry point. Auto-discovers and routes commands to modules.
- `modules/` — Business logic and orchestration. One module per command.
- `handlers/` — Implementation details. Called by modules, never by CLI directly.
- `plugins/` — Scheduled tasks and extensions.
+5
View File
@@ -0,0 +1,5 @@
# Handlers
Implementation details for `CLI`.
Handlers do the actual work. They are called by modules, never directly by the CLI. Keep business logic in modules, implementation in handlers.
+5
View File
@@ -0,0 +1,5 @@
# Modules
Business logic for `CLI`. One module per command.
Modules orchestrate work by calling handlers. They are the public API of the branch — drone routes commands here.
+5
View File
@@ -0,0 +1,5 @@
# Plugins
Scheduled tasks and extensions for `CLI`.
Plugins are standalone units of work that can be scheduled via the daemon. Each plugin handles one specific recurring task.
View File
View File
+5
View File
@@ -0,0 +1,5 @@
# Templates
Branch-specific templates for `CLI`.
Any templates this branch provides to the system or uses internally. Examples: plan templates (flow), trinity templates (memory), test templates (seedgo).
+6
View File
@@ -0,0 +1,6 @@
# Tests
Pytest unit tests for `CLI`.
- `conftest.py` — Shared fixtures (temp dirs, mocks, sample data).
- `test_*.py` — Test files. Standard tests cover JSON handler, CLI routing, and error resilience. Custom tests cover branch-specific domain logic.
+3
View File
@@ -0,0 +1,3 @@
# Branch Prompt
AI context for `DAEMON`. The `aipass_local_prompt.md` file is injected every turn, telling the AI who you are and how to work in your branch.
+5
View File
@@ -0,0 +1,5 @@
# Claude Code Settings
Claude Code configuration for `DAEMON`.
Contains `settings.local.json` with permission rules. Most branches are denied raw git commands and must use `drone @git` instead.
@@ -0,0 +1,28 @@
{
"permissions": {
"allow": [],
"deny": [
"Bash(git reset*)",
"Bash(git rebase*)",
"Bash(git merge*)",
"Bash(git config*)",
"Bash(git push --force*)",
"Bash(git push -f *)",
"Bash(git checkout -- *)",
"Bash(git checkout .*)",
"Bash(git restore --staged*)",
"Bash(git restore .*)",
"Bash(git clean*)",
"Bash(git branch -D*)",
"Bash(git stash drop*)",
"Bash(git stash clear*)",
"Bash(rm -rf*)",
"Bash(rm -r *)",
"Bash(git checkout -b*)",
"Bash(git commit*)",
"Bash(git push*)"
],
"ask": []
},
"enabledMcpjsonServers": []
}
+5
View File
@@ -0,0 +1,5 @@
# Standards Bypass
Seedgo audit bypass config for `DAEMON`.
When an audit flags a false positive that doesn't apply to your architecture, add a bypass entry in `bypass.json` with a reason explaining why it's justified.
+3 -3
View File
@@ -10,12 +10,12 @@
"example": {
"file": "apps/modules/logger.py",
"standard": "cli",
"reason": "Circular dependency - logger cannot import CLI",
"lines": [
146,
177
],
"pattern": "if __name__ == '__main__'",
"reason": "Circular dependency - logger cannot import CLI"
"pattern": "if __name__ == '__main__'"
},
"fields": {
"file": "Relative path from branch root (required)",
@@ -25,4 +25,4 @@
"reason": "Required - why this bypass exists"
}
}
}
}
+8
View File
@@ -0,0 +1,8 @@
# Apps
Application layer for `DAEMON`.
- `daemon.py` — Entry point. Auto-discovers and routes commands to modules.
- `modules/` — Business logic and orchestration. One module per command.
- `handlers/` — Implementation details. Called by modules, never by CLI directly.
- `plugins/` — Scheduled tasks and extensions.
@@ -0,0 +1,5 @@
# Handlers
Implementation details for `DAEMON`.
Handlers do the actual work. They are called by modules, never directly by the CLI. Keep business logic in modules, implementation in handlers.
+5
View File
@@ -0,0 +1,5 @@
# Modules
Business logic for `DAEMON`. One module per command.
Modules orchestrate work by calling handlers. They are the public API of the branch — drone routes commands here.
+5
View File
@@ -0,0 +1,5 @@
# Plugins
Scheduled tasks and extensions for `DAEMON`.
Plugins are standalone units of work that can be scheduled via the daemon. Each plugin handles one specific recurring task.
View File
+3
View File
@@ -0,0 +1,3 @@
# Docs
Documentation files for the `DAEMON` branch.
+5
View File
@@ -0,0 +1,5 @@
# Templates
Branch-specific templates for `DAEMON`.
Any templates this branch provides to the system or uses internally. Examples: plan templates (flow), trinity templates (memory), test templates (seedgo).
+6
View File
@@ -0,0 +1,6 @@
# Tests
Pytest unit tests for `DAEMON`.
- `conftest.py` — Shared fixtures (temp dirs, mocks, sample data).
- `test_*.py` — Test files. Standard tests cover JSON handler, CLI routing, and error resilience. Custom tests cover branch-specific domain logic.
+3
View File
@@ -0,0 +1,3 @@
# Branch Prompt
AI context for `DEVPULSE`. The `aipass_local_prompt.md` file is injected every turn, telling the AI who you are and how to work in your branch.
+5
View File
@@ -0,0 +1,5 @@
# Claude Code Settings
Claude Code configuration for `DEVPULSE`.
Contains `settings.local.json` with permission rules. Most branches are denied raw git commands and must use `drone @git` instead.
@@ -2,16 +2,8 @@
"permissions": {
"allow": [],
"deny": [
"Bash(git reset*)",
"Bash(git rebase*)",
"Bash(git merge*)",
"Bash(git config*)",
"Bash(git push --force*)",
"Bash(git push -f *)",
"Bash(git checkout -- *)",
"Bash(git checkout .*)",
"Bash(git restore --staged*)",
"Bash(git restore .*)",
"Bash(git clean*)",
"Bash(git branch -D*)",
"Bash(git stash drop*)",
@@ -21,7 +13,6 @@
"Bash(git checkout -b*)",
"Bash(git commit*)",
"Bash(git push*)",
"Bash(git add*)",
"Bash(gh pr create*)",
"Bash(gh pr close*)"
],
+5
View File
@@ -0,0 +1,5 @@
# Standards Bypass
Seedgo audit bypass config for `DEVPULSE`.
When an audit flags a false positive that doesn't apply to your architecture, add a bypass entry in `bypass.json` with a reason explaining why it's justified.
+23 -1
View File
@@ -1 +1,23 @@
{}
{
"metadata": {
"version": "1.0.0",
"created": "2026-03-25",
"description": "Standards bypass configuration for this branch"
},
"bypass": [],
"notes": {
"usage": "Add entries to bypass specific seedgo standard violations",
"example": {
"file": "apps/example.py",
"standard": "imports",
"reason": "Legacy import required for compatibility"
},
"fields": {
"file": "Relative path to the file",
"standard": "Which standard to bypass (imports, cli, naming, etc.)",
"lines": "Optional array of line numbers",
"pattern": "Optional regex pattern to match",
"reason": "Why this bypass exists"
}
}
}
+8
View File
@@ -0,0 +1,8 @@
# Apps
Application layer for `DEVPULSE`.
- `devpulse.py` — Entry point. Auto-discovers and routes commands to modules.
- `modules/` — Business logic and orchestration. One module per command.
- `handlers/` — Implementation details. Called by modules, never by CLI directly.
- `plugins/` — Scheduled tasks and extensions.
+1
View File
@@ -0,0 +1 @@
# DEVPULSE apps package
+86
View File
@@ -0,0 +1,86 @@
"""
DEVPULSE Branch - Main Orchestrator
Auto-discovery architecture:
- Scans modules/ directory for .py files with handle_command()
- Routes commands to discovered modules automatically
- No manual imports or routing needed
"""
import sys
import importlib
from pathlib import Path
from typing import List, Any
from aipass.prax import logger
# =============================================================================
# MODULE DISCOVERY
# =============================================================================
MODULES_DIR = Path(__file__).parent / "modules"
def discover_modules() -> List[Any]:
"""Auto-discover modules in modules/ directory."""
modules = []
if not MODULES_DIR.exists():
return modules
for file_path in MODULES_DIR.glob("*.py"):
if file_path.name.startswith("_"):
continue
module_name = f"apps.modules.{file_path.stem}"
try:
module = importlib.import_module(module_name)
if hasattr(module, "handle_command"):
modules.append(module)
except Exception as e:
logger.error(f"[DEVPULSE] Failed to load module {module_name}: {e}")
return modules
def route_command(command: str, args: List[str], modules: List[Any]) -> bool:
"""Route command to appropriate module."""
for module in modules:
try:
if module.handle_command(command, args):
return True
except Exception as e:
logger.error(f"[DEVPULSE] Module {module.__name__} error: {e}")
return False
# =============================================================================
# MAIN ENTRY POINT
# =============================================================================
def main():
"""Main entry point - routes commands or shows help."""
modules = discover_modules()
args = sys.argv[1:]
if len(args) == 0 or args[0] in ["--help", "-h", "help"]:
print(f"DEVPULSE - {len(modules)} modules discovered")
for module in modules:
name = module.__name__.split(".")[-1]
desc = (module.__doc__ or "").strip().split("\n")[0] if module.__doc__ else "No description"
print(f" {name:20} {desc}")
return 0
command = args[0]
remaining = args[1:] if len(args) > 1 else []
if route_command(command, remaining, modules):
return 0
print(f"Unknown command: {command}")
return 1
if __name__ == "__main__":
sys.exit(main())
@@ -0,0 +1,5 @@
# Handlers
Implementation details for `DEVPULSE`.
Handlers do the actual work. They are called by modules, never directly by the CLI. Keep business logic in modules, implementation in handlers.
@@ -0,0 +1,5 @@
# Modules
Business logic for `DEVPULSE`. One module per command.
Modules orchestrate work by calling handlers. They are the public API of the branch — drone routes commands here.
@@ -0,0 +1,5 @@
# Plugins
Scheduled tasks and extensions for `DEVPULSE`.
Plugins are standalone units of work that can be scheduled via the daemon. Each plugin handles one specific recurring task.
View File
+3
View File
@@ -0,0 +1,3 @@
# Docs
Documentation files for the `DEVPULSE` branch.
+5
View File
@@ -0,0 +1,5 @@
# Templates
Branch-specific templates for `DEVPULSE`.
Any templates this branch provides to the system or uses internally. Examples: plan templates (flow), trinity templates (memory), test templates (seedgo).
+6
View File
@@ -0,0 +1,6 @@
# Tests
Pytest unit tests for `DEVPULSE`.
- `conftest.py` — Shared fixtures (temp dirs, mocks, sample data).
- `test_*.py` — Test files. Standard tests cover JSON handler, CLI routing, and error resilience. Custom tests cover branch-specific domain logic.
+3
View File
@@ -0,0 +1,3 @@
# Branch Prompt
AI context for `DRONE`. The `aipass_local_prompt.md` file is injected every turn, telling the AI who you are and how to work in your branch.
+5
View File
@@ -0,0 +1,5 @@
# Claude Code Settings
Claude Code configuration for `DRONE`.
Contains `settings.local.json` with permission rules. Most branches are denied raw git commands and must use `drone @git` instead.
@@ -0,0 +1,25 @@
{
"permissions": {
"allow": [],
"deny": [
"Bash(git reset*)",
"Bash(git rebase*)",
"Bash(git merge*)",
"Bash(git config*)",
"Bash(git push --force*)",
"Bash(git push -f *)",
"Bash(git checkout -- *)",
"Bash(git checkout .*)",
"Bash(git restore --staged*)",
"Bash(git restore .*)",
"Bash(git clean*)",
"Bash(git branch -D*)",
"Bash(git stash drop*)",
"Bash(git stash clear*)",
"Bash(rm -rf*)",
"Bash(rm -r *)"
],
"ask": []
},
"enabledMcpjsonServers": []
}
+5
View File
@@ -0,0 +1,5 @@
# Standards Bypass
Seedgo audit bypass config for `DRONE`.
When an audit flags a false positive that doesn't apply to your architecture, add a bypass entry in `bypass.json` with a reason explaining why it's justified.
+15 -3
View File
@@ -8,7 +8,10 @@
{
"file": "apps/drone.py",
"standard": "cli",
"lines": [166, 168],
"lines": [
166,
168
],
"reason": "Raw passthrough of module subprocess stdout/stderr — console.print() breaks routed output"
},
{
@@ -29,13 +32,17 @@
{
"file": "apps/handlers/discovery_handler.py",
"standard": "handlers",
"lines": [190],
"lines": [
190
],
"reason": "Discovery handler needs registry_handler.load_registry() to resolve branch paths for help lookups. Justified cross-handler dependency — discovery is the only consumer."
},
{
"file": "apps/handlers/scanning/scanner.py",
"standard": "handlers",
"lines": [29],
"lines": [
29
],
"reason": "Scanner needs discovery_handler's get_entry_point() and parse_help_for_commands() to discover commands from branch help output. Justified — scanner's core function depends on discovery's parsing."
},
{
@@ -120,6 +127,11 @@
],
"notes": {
"usage": "Add entries to 'bypass' list to exclude specific violations",
"example": {
"file": "apps/example.py",
"standard": "imports",
"reason": "Legacy import required for compatibility"
},
"fields": {
"file": "Relative path from branch root (required)",
"standard": "Standard name: cli, imports, naming, etc. (required)",
+8
View File
@@ -0,0 +1,8 @@
# Apps
Application layer for `DRONE`.
- `drone.py` — Entry point. Auto-discovers and routes commands to modules.
- `modules/` — Business logic and orchestration. One module per command.
- `handlers/` — Implementation details. Called by modules, never by CLI directly.
- `plugins/` — Scheduled tasks and extensions.
+5
View File
@@ -0,0 +1,5 @@
# Handlers
Implementation details for `DRONE`.
Handlers do the actual work. They are called by modules, never directly by the CLI. Keep business logic in modules, implementation in handlers.
+5
View File
@@ -0,0 +1,5 @@
# Modules
Business logic for `DRONE`. One module per command.
Modules orchestrate work by calling handlers. They are the public API of the branch — drone routes commands here.
+5
View File
@@ -0,0 +1,5 @@
# Plugins
Scheduled tasks and extensions for `DRONE`.
Plugins are standalone units of work that can be scheduled via the daemon. Each plugin handles one specific recurring task.
View File
+3
View File
@@ -0,0 +1,3 @@
# Docs
Documentation files for the `DRONE` branch.
+5
View File
@@ -0,0 +1,5 @@
# Templates
Branch-specific templates for `DRONE`.
Any templates this branch provides to the system or uses internally. Examples: plan templates (flow), trinity templates (memory), test templates (seedgo).
+6
View File
@@ -0,0 +1,6 @@
# Tests
Pytest unit tests for `DRONE`.
- `conftest.py` — Shared fixtures (temp dirs, mocks, sample data).
- `test_*.py` — Test files. Standard tests cover JSON handler, CLI routing, and error resilience. Custom tests cover branch-specific domain logic.
+3
View File
@@ -0,0 +1,3 @@
# Branch Prompt
AI context for `FLOW`. The `aipass_local_prompt.md` file is injected every turn, telling the AI who you are and how to work in your branch.
+5
View File
@@ -0,0 +1,5 @@
# Claude Code Settings
Claude Code configuration for `FLOW`.
Contains `settings.local.json` with permission rules. Most branches are denied raw git commands and must use `drone @git` instead.
@@ -0,0 +1,28 @@
{
"permissions": {
"allow": [],
"deny": [
"Bash(git reset*)",
"Bash(git rebase*)",
"Bash(git merge*)",
"Bash(git config*)",
"Bash(git push --force*)",
"Bash(git push -f *)",
"Bash(git checkout -- *)",
"Bash(git checkout .*)",
"Bash(git restore --staged*)",
"Bash(git restore .*)",
"Bash(git clean*)",
"Bash(git branch -D*)",
"Bash(git stash drop*)",
"Bash(git stash clear*)",
"Bash(rm -rf*)",
"Bash(rm -r *)",
"Bash(git checkout -b*)",
"Bash(git commit*)",
"Bash(git push*)"
],
"ask": []
},
"enabledMcpjsonServers": []
}
+5
View File
@@ -0,0 +1,5 @@
# Standards Bypass
Seedgo audit bypass config for `FLOW`.
When an audit flags a false positive that doesn't apply to your architecture, add a bypass entry in `bypass.json` with a reason explaining why it's justified.
+3 -3
View File
@@ -413,12 +413,12 @@
"example": {
"file": "apps/modules/logger.py",
"standard": "cli",
"reason": "Circular dependency - logger cannot import CLI",
"lines": [
146,
177
],
"pattern": "if __name__ == '__main__'",
"reason": "Circular dependency - logger cannot import CLI"
"pattern": "if __name__ == '__main__'"
},
"fields": {
"file": "Relative path from branch root (required)",
@@ -428,4 +428,4 @@
"reason": "Required - why this bypass exists"
}
}
}
}
+8
View File
@@ -0,0 +1,8 @@
# Apps
Application layer for `FLOW`.
- `flow.py` — Entry point. Auto-discovers and routes commands to modules.
- `modules/` — Business logic and orchestration. One module per command.
- `handlers/` — Implementation details. Called by modules, never by CLI directly.
- `plugins/` — Scheduled tasks and extensions.
+5
View File
@@ -0,0 +1,5 @@
# Handlers
Implementation details for `FLOW`.
Handlers do the actual work. They are called by modules, never directly by the CLI. Keep business logic in modules, implementation in handlers.
+5
View File
@@ -0,0 +1,5 @@
# Modules
Business logic for `FLOW`. One module per command.
Modules orchestrate work by calling handlers. They are the public API of the branch — drone routes commands here.
+5
View File
@@ -0,0 +1,5 @@
# Plugins
Scheduled tasks and extensions for `FLOW`.
Plugins are standalone units of work that can be scheduled via the daemon. Each plugin handles one specific recurring task.

Some files were not shown because too many files have changed in this diff Show More