Tried and abandoned — the scope-guard hypothesis
"New PreToolUse hook + destructive-command skill" was a tidier story than a version pin, and
wrong. Worth knowing the guard's real blast radius: repo-wide
--write/--fix formatter runs, and
git stash pop|apply with no ref. Nothing else.
Tried and abandoned — the systemic loader bug read
Five git-agent skills were missing from the listing. Four carry
disable-model-invocation: true and are user-invocable only, so their absence is
correct; only post-merge-cleanup was signal. Checking frontmatter across all
skills first would have skipped it.
Tried and abandoned — "just run the update everywhere"
Probing it updated devbox/513/.claude/worktrees/wire-dashboard-impact-grid-d56c80
(4.14.4 → 4.19.0), an
already-deleted worktree in an unrelated repo. Practical harm nil, but it is an unrequested
change to another project, and it killed the simple design.
Gotcha — a correct user-scoped install is not evidence a skill is available
User scope was 4.19.0 with the file on disk the entire time. Scope shadowing is silent: no
warning that a project row overrides a newer user row.
Gotcha — no working-tree file tells you the current plugin version
Different worktrees sit on different refs, so marketplace.json read from one of
them is whatever branch it happens to be on.
Gotcha — macOS bash 3.2 has no mapfile
The first driver died on it before running anything, so no partial state.
Gotcha — installed_plugins.json rows are never reaped
Deleting a worktree leaves its pin forever; 2 of 7 agentics rows and 9 of 15 in
devbox/513 are orphans.
Gotcha — a chat "yes" cannot lift a permission-layer denial
rm is denied outright by the user's global rules; re-asking in conversation
does not reach that layer.