Centralize the user-confirmation gate inside security-scrub so every caller automatically pauses for review after a scan — auto-proceeding only when the result is a clean PASS with zero findings, and hard-stopping (no Continue option) on any BLOCKED result.
Read and implement all steps in the plan at docs/plans/add-security-scrub-user-gate.md — Add User Gate to security-scrub Skill. Verify against the plan's Tests, Verification, and Acceptance Criteria before reporting done. If everything passed, mark completion in docs/plans/add-security-scrub-user-gate.md — tick each step's [x] marker and each criterion's - [x], set status: completed — and re-render the HTML from the spec. If any check failed, leave status: in-progress and say which.
More ways to run this plan — goal & workflow prompts, file path
Achieve this goal: Add User Gate to security-scrub Skill. The plan at docs/plans/add-security-scrub-user-gate.md describes one approach — use it as reference, but optimize for the outcome. Verify against the plan's Tests, Verification, and Acceptance Criteria before reporting done. If everything passed, mark completion in docs/plans/add-security-scrub-user-gate.md — tick each step's [x] marker and each criterion's - [x], set status: completed — and re-render the HTML from the spec. If any check failed, leave status: in-progress and say which.
add-security-scrub-user-gate.html
docs/plans/add-security-scrub-user-gate.html
docs/plans/add-security-scrub-user-gate.md
Context
The story behind this plan — what prompted the work and why it matters now.
The security-scrub skill lives in kit/plugins/social-media-tools/skills/security-scrub/SKILL.md . It scans content for secrets and emits a structured SCRUB RESULT block, then stops. Five callers depend on it: share-session , share-github , share-selection , share-project , and share-scan .
In v2.3.2, a user-confirmation prompt was added directly inside share-session (lines 187–188). The other four callers have no gate at all, so a BLOCKED or WARN result silently allows sharing to continue. The fix was partial — every caller must now implement its own gate independently, leading to divergence and future drift.
Moving the gate into security-scrub itself enforces it uniformly for all callers. For the "auto-trigger" use case: when the result is a clean PASS (no findings whatsoever), the skill proceeds without prompting — this is the automatic continuation path. Any findings (LOW, MEDIUM, or HIGH) pause for explicit user input before returning.
Steps
The step-by-step work, in order — each step says what to do, why it matters, and how to check it worked.
Definition of done
The plan counts as done when every statement below is true — check each one off as you verify it.
Final check
One last pass to confirm the whole change works end to end.
Read kit/plugins/social-media-tools/skills/security-scrub/SKILL.md end-to-end and confirm Step 6 is present with all four branches (BLOCKED hard-stop, WARN gate, PASS-with-LOW gate, PASS-clean auto-continue). Confirm AskUserQuestion is in allowed-tools .
Read kit/plugins/social-media-tools/skills/share-session/SKILL.md Phase 2 and confirm the AskUserQuestion post-scrub instruction is removed.
Run the marketplace version check command from Step 4 and confirm it prints 2.4.0 . Check the CHANGELOG for the v2.4.0 entry. Run git log -1 --oneline and confirm a single clean commit contains all four changed files: security-scrub/SKILL.md , share-session/SKILL.md , marketplace.json , CHANGELOG.md , and this plan file.
Wrapping up
Three gates that must all pass before this plan is marked completed.
Completion Report
No items to report — all requirements met.