Daily harness signal · September 26, 2026

Which review
actually ran?

One implementation lesson · Skill routing

A familiar command name does not identify the procedure you intended. Qualify completion-critical skill references, then verify the loaded source through the actual caller—not just the slash-command menu.

Evergreen · source August 7, 2026

Bind the review step to its intended implementation

Use when

A Claude Code workflow requires a specific plugin review, but a bundled or installed skill shares its bare name. Pocock’s code-review checks Standards and Spec; substituting another review changes the acceptance procedure, even when both produce plausible findings.

Action

For an already-approved mattpocock-skills plugin, replace ambiguous caller guidance with:

Invoke the Skill tool with skill=mattpocock-skills:code-review. Use the agreed base and spec. If unavailable or denied, stop and report that exact target; do not substitute the bundled review.

Confirm the installed namespace, source, and revision. Keep this host-specific binding in the caller’s adapter: a plain skills installation does not automatically acquire a plugin namespace. Do not disable built-ins or weaken invocation policy to silence a routing failure.

Acceptance check

In an authorized disposable fixture containing both review surfaces, exercise the real parent-to-review and, where used, child-to-review path. Require the recorded Skill argument and loaded source to identify the intended plugin, plus separate Standards and Spec outputs. Headings alone are not provenance. An unavailable or policy-denied target must produce an explicitly blocked review, no fallback, and no completion claim. Retain host/plugin versions, installation mode, resolved path, and transcript. Repeat affected paths after upgrades; keep independent task checks.

Evidence

Issue 809 records Claude Code 2.1.224, plugin 1.2.3, and the exact refusal. Tagged source confirms the plugin namespace, bare caller reference, and model-invocable reviewer. Official documentation defines qualified plugin names. Counterevidence matters: issue 78235 reports correct coexistence and internal routing on 2.1.220. These reports justify checking your installed path, not claiming every current installation is broken.

Caveat

Issue 809 was closed as Duplicate, not with a verified repair. Versions, installation modes, and caller contexts differ; a deterministic regression is unproven. Later releases also changed bundled-review invocation, so the historical refusal is not a permanent policy contract. Qualification selects identity; it does not grant authority or establish review quality. This adapter and fixture are proposed, not executed. No skill, plugin, or configuration was changed today.

Compact source notes

  1. DavidGhetto’s versioned report, August 7, 2026; maintainer closure says “Duplicate.” Earlier multi-install discussion, July 9–23, describes opposite shadowing directions and update-sensitive local renames. Neither supplies a controlled current-version test.
  2. Inspected 1.2.3 manifest, caller, and reviewer, plus caller history. Retrieved main retains the bare reference; history is not deployed-version attestation. The source’s separate implement invocation restriction remains intact.
  3. Official plugin namespace contract and skill precedence reference, undated, retrieved today. Neostar’s July 30 recovery report qualifies older collision claims. August 25 release expands autonomous bundled review, conflicting with the skills page’s blanket user-only wording. Do not infer present permissions from the older error.
  4. Anchor lens: exact caller, manifest, frontmatter and differing field receipts. Unity lens: preserve procedure identity across invocation boundaries; proposed invariant. Static source semantics: confidence_confirmed; operational adaptation: confidence_likely. Loading another target or accepting a denied review falsifies the proposed gate. This issue authorizes no installation, skill edit, or evaluation.