Requested by the maintainer in Claude Code session session_018zT8d8NpiQ1ExhuNd5TxY6, 2026-10-06, verbatim: 「以后怎么避免在这类开发上耗资源,创建一张skills卡」.
What happened
#21840 (P2, readable only by platform administrators, and affecting only plugin drivers, of which the repository has none) was dispatched as a security fix. PR #21877 tried to decide, from key names and value shapes, which values in a plugin driver's config are credentials.
The cost came before any code was written: nobody asked whose problem it was, and nothing stopped the loop once it started.
Rules to add to .claude/skills/pm-dispatch/
-
Responsibility check before dispatch. Before dispatching a defect, the seat answers three questions in the claim or the dispatch:
- Whose code produces the risk?
- Does the platform already provide the right path, such as a bound secret, a declared contract or a documented boundary?
- Who can reach it, and does anyone use it today?
When the risk sits in third-party or user-authored code, a supported path exists, and only the highest privilege reaches it, the default is document, not defend. The seat proposes a docs change or a decision card, and does not dispatch a code fix.
-
No security boundary built on a heuristic. If the proposed fix decides security by guessing (key names, value shapes, pattern lists), the seat stops and opens a decision card that compares it with a declaration-based approach, before dispatch.
-
Circuit breaker on a PR. The seat pauses the PR and asks the maintainer, with a short summary and options, when any of these holds:
- the independent security review has failed two rounds in a row;
- the diff has grown past twice its first reviewed size;
- a review finds a new HIGH that was introduced by the previous round's fix.
No further development round is dispatched until the maintainer answers.
-
Price by reach, not by class. A finding with no current user, reachable only by the highest privilege, is graded at most low and may be recorded without a fix. The "security" label alone does not raise its priority.
Done when
- The four rules are in the pm-dispatch skill text, at the point where the seat claims or dispatches, and where it handles review rounds.
- The dispatch prompt template asks for the three answers in rule 1.
- The round-report shape has a line that records which circuit-breaker condition, if any, a PR has hit.
维护者速读
#21840 只影响仓库里不存在的插件驱动,而且只有平台管理员能看到,却被当成安全漏洞派了开发。#21877 靠猜字段名,复审 4 轮都没收住,代码长到 4000 行,最后作废,改成补一句文档。
要在派发规则里加四条:
- 派发前先判断责任归属和影响面。属于作者代码、平台已有正路、又只有最高权限能触及的,默认只补文档,不写防护代码。
- 方案靠"猜"来做安全判断的,先开决策卡。
- 熔断:安全复审连续 2 轮不过、改动超过最初规模的 2 倍、或者修复本身引出新的高危,满足任一条就暂停,来问你。
- 优先级按实际影响面定,不因为带了"安全"标签就自动拔高。
Generated by Claude Code
Requested by the maintainer in Claude Code session
session_018zT8d8NpiQ1ExhuNd5TxY6, 2026-10-06, verbatim: 「以后怎么避免在这类开发上耗资源,创建一张skills卡」.What happened
#21840 (P2, readable only by platform administrators, and affecting only plugin drivers, of which the repository has none) was dispatched as a security fix. PR #21877 tried to decide, from key names and value shapes, which values in a plugin driver's
configare credentials.configis its author's responsibility and that the platform does not guess. security(datasource): credential-shaped values in some datasource configurations are stored and served without the platform's secret handling — detail withheld pending maintainer #21840 was closed as not planned, fix(spec)!: credential-shaped datasource config values are refused at write and redacted on every read door for drivers with no shipped contract #21877 was closed unmerged, and one docs paragraph landed instead (docs(drivers): a plugin driver's config is its author's to keep free of credentials #21927).The cost came before any code was written: nobody asked whose problem it was, and nothing stopped the loop once it started.
Rules to add to
.claude/skills/pm-dispatch/Responsibility check before dispatch. Before dispatching a defect, the seat answers three questions in the claim or the dispatch:
When the risk sits in third-party or user-authored code, a supported path exists, and only the highest privilege reaches it, the default is document, not defend. The seat proposes a docs change or a decision card, and does not dispatch a code fix.
No security boundary built on a heuristic. If the proposed fix decides security by guessing (key names, value shapes, pattern lists), the seat stops and opens a decision card that compares it with a declaration-based approach, before dispatch.
Circuit breaker on a PR. The seat pauses the PR and asks the maintainer, with a short summary and options, when any of these holds:
No further development round is dispatched until the maintainer answers.
Price by reach, not by class. A finding with no current user, reachable only by the highest privilege, is graded at most low and may be recorded without a fix. The "security" label alone does not raise its priority.
Done when
维护者速读
#21840 只影响仓库里不存在的插件驱动,而且只有平台管理员能看到,却被当成安全漏洞派了开发。#21877 靠猜字段名,复审 4 轮都没收住,代码长到 4000 行,最后作废,改成补一句文档。
要在派发规则里加四条:
Generated by Claude Code