Fix the non-skill plugin components: restore the intended tool scoping on the seven plan-reviewer-* agents (and two team-defaults agents), collapse the four plan-interview commands that have drifted from the skills they duplicate into thin delegators, and stop the four plan-agent hooks from spawning a process on every file edit in every session.
Seven plan-reviewer agents meant to be read-only run with full write access because they use the skills key allowed-tools instead of the agents key tools, and the marketplace proves the contrast — product-plans used the right key and is correctly scoped. This fixes that, plus four commands that have drifted from the skills they duplicate and four hooks that fire on every edit in every session.
Read and implement all steps in the plan at docs/plans/fix-plugin-component-defects.md — Fix the agent, command, and hook defects the skill-focused review missed. Verify against the plan's Tests, Verification, and Acceptance Criteria before reporting done. If everything passed, mark completion in docs/plans/fix-plugin-component-defects.md — tick each step's [x] marker and each criterion's - [x], set status: completed — and re-render the HTML from the spec. If any check failed, leave status: in-progress and say which.
More ways to run this plan — goal & workflow prompts, file path
Achieve this goal: Fix the agent, command, and hook defects the skill-focused review missed. The plan at docs/plans/fix-plugin-component-defects.md describes one approach — use it as reference, but optimize for the outcome. Fan out across parallel subagents where that serves the outcome. Verify against the plan's Tests, Verification, and Acceptance Criteria before reporting done. If everything passed, mark completion in docs/plans/fix-plugin-component-defects.md — tick each step's [x] marker and each criterion's - [x], set status: completed — and re-render the HTML from the spec. If any check failed, leave status: in-progress and say which.
Run a workflow to implement the plan at docs/plans/fix-plugin-component-defects.md — Fix the agent, command, and hook defects the skill-focused review missed. Brief subagents with the plan file at docs/plans/fix-plugin-component-defects.md. Reserve a final verification phase for the lead agent, not a subagent. Verify against the plan's Tests, Verification, and Acceptance Criteria before reporting done. If everything passed, mark completion in docs/plans/fix-plugin-component-defects.md — tick each step's [x] marker and each criterion's - [x], set status: completed — and re-render the HTML from the spec. If any check failed, leave status: in-progress and say which.
fix-plugin-component-defects.html
docs/plans/fix-plugin-component-defects.html
docs/plans/fix-plugin-component-defects.md
Context
The story behind this plan — what prompted the work and why it matters now.
A review on 2026-07-16 covered all 59 skills across the 13 marketplace plugins and produced three plans, but examined none of the 18 commands, 22 agents, or 6 hooks. This plan covers that gap. The findings are ranked below by blast radius, and the first is a live defect, not a style issue.
The agents key is tools:, not allowed-tools:. All seven plan-agent/agents/plan-reviewer-*.md files declare allowed-tools: Read, Glob, Grep, Bash, which is the skills key. On an agent it is not recognised, so the declaration is silently ignored and the agent inherits everything. The contrast is visible inside this very marketplace: product-plans/agents/product-reviewer-*.md declare tools: Read, Glob, Grep, Bash(git *) and are correctly scoped. Confirmed empirically from a live session's agent registry, where plan-agent:plan-reviewer-architecture lists as "(Tools: All tools)" while product-plans:product-reviewer-pm lists as "(Tools: Read, Glob, Grep, Bash(git *))". Both clusters intended the same restriction; only one got it. The consequence is seven agents whose whole job is to read a plan and report findings holding Write, Edit, and Bash against the repo.
A trap worth naming explicitly: the maintainer's memory records that allowed-tools is valid in skill files and that an IDE linter flagging it is wrong. That note is correct — for skills. It does not transfer to agents, and it is the single most likely reason this finding gets waved off. The key is valid in one component type and inert in the other.
Two team-defaults agents are misconfigured. css-generator.md declares MultiEdit, a tool that no longer exists in Claude Code, and has no model:. code-comments.md declares no tools: at all, so a JSDoc writer inherits Bash, WebFetch, and Agent; its description is a capability blurb with no trigger phrase, so it will not reliably activate; and its name: ts-commenter does not match its filename.
Four plan-interview commands have drifted from their own skills. deep-grill.md, plan-status.md, and documenting-plans.md do not invoke their same-named skills — they restate the whole workflow, and the copies are already 20, 153, and 383 lines apart from the skill they duplicate. The behaviours differ concretely: deep-grill's command resolves the plan from $ARGUMENTS, its skill from "a path in the user's message". plan-interview.md (397 lines) re-implements the router that also lives in its 594-line skill. Two behaviours, one name, no way for a user to know which they invoked. The repo already ships the correct shape: plan-to-html.md is frontmatter plus a single Skill(...) call.
Four hooks fire on every file edit. All four plan-agent/hooks.json PostToolUse entries match Write|Edit|MultiEdit, so every edit in every session spawns four processes to discover the file is not a plan. hooks/build-index.sh:36 compounds it: find_templates_dir() walks all of ~/.claude/plugins and the project root on each plan write, unbounded. Separately validate-plan-filename.py matches only Write|Edit, so MultiEdit bypasses the filename gate entirely — an inconsistency in the opposite direction.
Out of scope, deferred to Next Steps: consolidating plan-agent's 8 reviewer agents down to ~5 and delegating the ux/accessibility lenses to product-plans' equivalents. That removes agents users may reference and is a MAJOR-bump decision, consistent with the cleanup-first sequencing already agreed.
Files that change
Every file this plan touches, and what happens to each one.
- `kit/plugins/plan-agent/agents/
plan-reviewer-architecture.md`modifiedallowed-tools:becomestools:plan-reviewer-completeness.md`modified sameplan-reviewer-testability.md`modified sameplan-reviewer-risk.md`modified sameplan-reviewer-conventions.md`modified sameplan-reviewer-ux.md`modified sameplan-reviewer-accessibility.md`modified same
- `kit/plugins/team-defaults/agents/
css-generator.md`modified drop phantom MultiEdit, add modelcode-comments.md`modified add tools, rewrite description, rename file
- `kit/plugins/plan-interview/commands/
deep-grill.md`modified collapse to a Skill delegatorplan-status.md`modified collapse to a Skill delegatordocumenting-plans.md`modified collapse to a Skill delegatorplan-interview.md`modified collapse to a Skill delegator
`kit/plugins/social-media-tools/commands/digest.md`modified fix the reference to a command that does not exist- `kit/plugins/plan-agent/hooks/
hooks.json`modified gate on path before spawningbuild-index.sh`modified resolve templates via CLAUDE_PLUGIN_ROOT; bundled hook copy
`scripts/build-plans-index.sh`modified same change; the workflow copy, byte-identical today`docs/plans/build-index.sh`modified same change; the rebuild-hook fallback, byte-identical today`kit/plugins/plan-agent/hooks/validate-plan-filename.py`modified match MultiEdit- `tests/plugins/
test-agent-frontmatter.sh`new the objective-verification testtest-command-delegation.sh`new asserts commands delegate rather than restate
`.claude-plugin/marketplace.json`modified bumps for plan-agent, team-defaults, plan-interview, social-media-tools
Steps
The step-by-step work, in order — each step says what to do, why it matters, and how to check it worked.
allowed-tools: to tools: in all seven kit/plugins/plan-agent/agents/plan-reviewer-*.md files, keeping the declared value and tightening Bash to Bash(git *) to match the product-plans cluster.
allowed-tools: is not a recognised key, so the intended restriction is silently discarded and seven read-only plan reviewers currently hold Write, Edit, and unrestricted Bash against the repo — product-plans proves the correct key works, because its reviewers are scoped in the live registry while these list as "All tools".plan-agent:plan-reviewer-* with its scoped tool list rather than "(Tools: All tools)" — the registry, not the file, is the proof, since the file already looked correct while being ignored.kit/plugins/team-defaults/agents/css-generator.md by removing MultiEdit from its tool list, replacing it with Read, Write, Edit, Bash, WebFetch, and adding an explicit model:.
MultiEdit no longer exists in Claude Code, so the agent is granted a phantom tool and any behaviour depending on it silently degrades, while an absent model: leaves tier selection to inheritance rather than intent.MultiEdit, and grep -rn MultiEdit kit/plugins/ returns no agent frontmatter.kit/plugins/team-defaults/agents/code-comments.md by adding tools: Read, Edit, Glob, Grep, rewriting the description to lead with a trigger phrase such as "Use when the user asks to add or improve JSDoc on TypeScript files", and renaming the file to ts-commenter.md to match its name: field.
tools: a JSDoc writer inherits Bash, WebFetch, and Agent; a description that states capability without a trigger will not reliably activate, which is the difference between an agent that exists and one that gets used; and a filename that disagrees with name: makes the agent hard to locate.ts-commenter with exactly the four scoped tools, and its description reads as a WHEN rather than a WHAT.deep-grill.md, plan-status.md, documenting-plans.md, and plan-interview.md under kit/plugins/plan-interview/commands/ to the shape plan-to-html.md already uses — frontmatter plus a single Skill(skill: "plan-interview:<name>", args: "$ARGUMENTS") call — preserving each file's existing description and argument-hint.
Skill( call naming its own skill, and bash tests/plugins/test-command-delegation.sh passes.kit/plugins/social-media-tools/commands/digest.md:49, which tells the user to run /social-media-tools:share-code — a command that does not exist, since share-code is skill-only — by pointing at the skill or removing the line.
/social-media-tools:<name> string in the plugin's commands resolves to a real file under commands/.kit/plugins/plan-agent/hooks/hooks.json on the plans-directory path before spawning, or merge them into one dispatcher, and change validate-plan-filename.py's matcher to Write|Edit|MultiEdit.
Write|Edit, so MultiEdit slips past it, making the hook set simultaneously too eager and too narrow.MultiEdit is still blocked, and writing a well-named plan still triggers the render and index rebuild.find_templates_dir() with a direct resolution against $CLAUDE_PLUGIN_ROOT/templates in all three copies of the index builder in lockstep — kit/plugins/plan-agent/hooks/build-index.sh:36 (the bundled hook), scripts/build-plans-index.sh (the workflow copy), and docs/plans/build-index.sh (the rebuild-hook fallback) — confirming first that they are still byte-identical and treating any divergence as a finding to report rather than silently reconcile.
~/.claude/plugins and the project root on every plan write, which is unbounded work scaling with the user's installed-plugin count and repo size, and $CLAUDE_PLUGIN_ROOT is the supported way to resolve plugin-relative paths — but the three copies are byte-identical today (all md5 0258e397), so fixing only the bundled hook would leave CI and fallback installations running the defect while the copies silently diverge, which is worse than the original problem because divergence hides it.md5 kit/plugins/plan-agent/hooks/build-index.sh scripts/build-plans-index.sh docs/plans/build-index.sh reports one identical hash across all three, none contains find_templates_dir, the index still rebuilds on a plan write, and bash docs/plans/build-index.sh still succeeds standalone.tests/plugins/test-agent-frontmatter.sh and tests/plugins/test-command-delegation.sh, then bump version in .claude-plugin/marketplace.json for plan-agent, team-defaults, plan-interview, and social-media-tools with a matching CHANGELOG.md entry each, treating the agent tool-scoping fix as a PATCH and the ts-commenter rename as MINOR.
scripts/check-plugin-versions.mjs fails any PR that changes a plugin without raising its marketplace version.node scripts/check-plugin-versions.mjs exits 0.Tests
The tests that prove the change does what it promises.
allowed-tools: key, and every agent declares an explicit tools: — the exact defect this plan fixes, which was invisible because nothing asserted it. File: tests/plugins/test-agent-frontmatter.sh; Type: smoke; Asserts: for every kit/plugins/*/agents/*.md, frontmatter contains tools: and not allowed-tools:, declares a model:, and names no tool outside the known-valid set (catching phantom tools like MultiEdit); Run: bash tests/plugins/test-agent-frontmatter.shtests/plugins/test-command-delegation.sh; Targets: kit/plugins/plan-interview/commands/*.md; Key cases: each of the five collapsed commands is under 15 lines and contains exactly one Skill( call; a fixture command that restates a workflow fails/plugin:command string referenced anywhere in the marketplace resolves to a real file. File: tests/plugins/test-command-delegation.sh; Targets: cross-references in commands and skills; Key cases: digest.md's reference resolves, and a fixture naming a non-existent command failsDefinition of done
The plan counts as done when every statement below is true — check each one off as you verify it.
Final check
One last pass to confirm the whole change works end to end.
Start a session with the 13 marketplace plugins loaded and read the agent registry: every plan-agent:plan-reviewer-* must list its scoped tool set rather than "(Tools: All tools)". This is the plan's central proof and it cannot be done by reading the files, because the files already looked correct while being silently ignored — the registry is the only place the defect was visible and the only place the fix is. Then run bash tests/plugins/test-agent-frontmatter.sh and bash tests/plugins/test-command-delegation.sh, plus the full tests/plugins/ suite. Invoke /plan-interview:deep-grill <path> and the deep-grill skill on the same plan and confirm they now produce identical behaviour rather than resolving their argument differently. Edit a file outside docs/plans/ and confirm no plan hook fires; write a badly-named plan via MultiEdit and confirm the filename gate blocks it. Finally confirm node scripts/check-plugin-versions.mjs exits 0.
Wrapping up
Three gates that must all pass before this plan is marked completed.
Completion Report
No items to report — all requirements met.