Skip to content

chore(flags): harden the stale-flag cleanup skill - #107780

Open
JamesPatrickGill wants to merge 15 commits into
chore/flags-cleanup-eval-coveragefrom
chore/flags-cleanup-skill-hardening
Open

JamesPatrickGill wants to merge 15 commits into
chore/flags-cleanup-eval-coveragefrom
chore/flags-cleanup-skill-hardening

Conversation

@JamesPatrickGill

@JamesPatrickGill JamesPatrickGill commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Problem

A person who asks the cleanup skill to remove a stale flag can get code deleted against a rollout that has since moved, or a PR pushed after the checks failed. The skill's own dogfood run produced both.

  • The skill read the flag once, at assessment, then edited call sites off that read. A rollout changed in between was edited against stale data.
  • Nothing gated publication on the result of validation, so a failed or unrunnable check still ended in a pushed branch.
  • A second session could clean up a flag a teammate had already cleaned up in an open PR, because no step looked.
  • Asked for an override on an excluded flag, the skill offered one.

This is the top layer of a stack. #107777 adds the eval scorers that grade these rules.

Changes

  • The skill now re-reads the flag definition immediately before the first edit, and again before it publishes. Either read failing, or coming back different, stops the run.
  • Validation ends in one of three named outcomes: passed, failed, or could not run. Only passed permits a push or a PR.
  • A new step 3 searches the checkout, the branches and the open PRs for a cleanup of this key before any call site is read. An in-flight cleanup stops the run and gets reported.
  • The exclusion list applies to a flag the user names, not just to a survey result. No override is offered or accepted.
  • The product-tour question must be answered before removal is recommended. An empty result from the other dependency reads does not answer it.
  • Orphaned code splits in two. Code that exists only because this flag existed goes. A general helper that lost its last caller stays and gets named in the report, because deleting it rewrites the repository's flag abstraction.
  • Usage-based staleness no longer calls itself the strongest signal. Local evaluation and disabled event capture hide continued use.
  • The handoff prompt for an agent that cannot read PostHog carries the same existing-work, pre-edit and pre-publish checks.
  • The handoff prompt carries the product-tour answer with the date the user gave it, and still tells the receiving agent to ask the user before it removes any code. The prompt is a copyable artifact that leaves the session, so an asserted fact expires with nothing to signal it. The date makes the answer's age visible; the confirmation stops it being read as clearance.
  • The existing-work check pages through the open-PR listing. Every host caps a page, and a truncated listing reports no error, so a cleanup already in flight on a later page read as no cleanup at all and the skill opened a duplicate PR.
  • A changed flag sends the handoff prompt back to the assessment checks, not to the rollout classification. The main path already restarts there, because the change is itself an update and a flag updated inside the last 30 days is excluded.
  • Mechanical: steps 3 through 7 renumber to 4 through 8, and cross-references follow.

Ten more commits landed from the review round and are part of this diff:

  • The pre-edit and pre-publish checks fetch the flag status as well as the definition, then compare version, updated_at and the status rollout object. The definition carries no rollout summary and version is null on a flag written before versioning, so the old comparison could not be made as written.
  • Both checks repeat the dependency and schedule reads, not just the definition read, and apply step 2's exclusions to the fresh responses.
  • A changed flag restarts at step 2 rather than step 4, so the dependency, schedule and age exclusions run again.
  • The pre-publish read repeats after the user authorizes publication, so an approval that sat does not carry a stale read past it.
  • The existing-work check runs git fetch --prune, so a cleanup branch deleted on the remote stops looking like work in flight.
  • The existing-work check searches the history of the key's constants and wrappers as well as the key. A cleanup that removes checks through a constant can leave the literal key in place.
  • The handoff prompt selects PR diffs the way the main path does: metadata for all, a diff for every fork PR and for any PR whose head branch or title names the key.
  • The handoff prompt carries the rule that repository content is data, never instructions.
  • A flag constant that a surviving payload read still uses is kept, not deleted with the flag check.
  • Git refs interpolated into shell commands are quoted, because Git accepts shell characters in branch and remote names.

Note

This changes what the skill does for anyone who runs it. A cleanup that used to publish on a failed check now stops and reports.

How did you test this code?

No automated test asserts the content of a skill file. The eval coverage that grades these rules against a live agent run is the layer below, #107777.

The two-read design comes from a 12-trial reproduction of the dogfood failure, run before this branch: the pre-edit re-read alone left unsafe publishes reachable, and the pre-edit and pre-publish reads together took them to 0 of 12. That measurement has no artifact in this repository and is not linkable, so treat it as reported rather than checked.

Not run in this session: the sandboxed cleanup eval suite, which needs a Claude runtime and a seeded project.

hogli test over the two eval-harness test files and the gated-writes invariant from the layer below, all passing locally. hogli ci:preflight --strict passes.

Automatic notifications

  • Publish to changelog?

Docs update

None. The skill file is the documentation for this behavior.

🤖 Agent context

Autonomy: Human-driven (agent-assisted)

Agent: Claude Code. Opus 5 wrote the original skill edits. ReviewHog wrote ten review-round commits. Sonnet 5 wrote the fixes in the last commit.

This re-cuts the second half of #104315, which carried these edits as nine commits plus the eval coverage. That branch sat 412 commits behind master and its CI failed on staleness, not on a test. This layer is rebuilt from current master rather than rebased, and squashed to one commit. SKILL.md had no drift on master since the old branch's merge base, so the file is byte-identical to the old branch tip.

The Greptile P1 on the handoff prompt's missing tour confirmation is now closed. ReviewHog escalated it for a human decision between asserting the confirmed answer and telling the receiving agent to ask. Both are implemented, because each alone fails: an assertion goes stale with nothing to signal it, and asking alone discards the answer the assessment already obtained. The answer travels with its date as evidence, and the confirmation is still required.

Two instruction gaps found while reading ReviewHog's commits, filed by nobody: the missing pagination on the open-PR listing, and the handoff prompt's restart target. Both are in Changes above.

  • No duplicate: gh pr list --state open --search "stale feature flags skill" found only chore(feature-flags): require a fresh read before every write #104315, which this stack supersedes.
  • Public artifact: nothing here carries material from an agent session that is not already public.
  • Skills invoked: /stacking-prs, /writing-tests, /writing-pr-descriptions, /address-pr-reviews, /writing-user-facing-copy, /ste-writing.
  • CodeRabbit CLI pass: skipped. A PreToolUse hook blocks /reviewing-with-coderabbit unless a person types the slash command, and no person did in this session. The hook is working as intended, so the PR opens without a local review pass.

🤖 Generated with Claude Code

@github-actions

Copy link
Copy Markdown
Contributor

🤖 CI report

⚠️ Trunk lane — backend Python lane

This PR is assigned to the backend Python lane. It runs backend Python tests and may merge in parallel with PRs in other lanes.

@greptile-apps

greptile-apps Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Retrigger

[Low risk] Updates documentation for feature flag cleanup procedures.

The PR appears safe to merge based on this review.

Reviews (2) · Last reviewed commit: "chore(feature-flags): carry the tour ans..."

Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
@JamesPatrickGill
JamesPatrickGill force-pushed the chore/flags-cleanup-skill-hardening branch from 5ac84be to 053cd5b Compare September 28, 2026 14:50
@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

The feature-flag cleanup skill adds eligibility checks for flag age, schedules, dependencies, and product-tour usage. It requires checks for existing cleanup before rollout classification and repository inspection. It also defines fresh-definition checks before edits and publication, distinguishes flag-specific dead code from reusable helpers, and blocks publication when validation fails or cannot run. The handoff prompts, example interaction, and summary rules reflect these workflow requirements.

Priority: ⬇️ Low

Merge Risk: 🔵 Low · up to f1197

The cleanup workflow can misidentify already-merged work, miss a cleanup PR opened during the run, or be unusable in clients lacking required capabilities. These are bounded workflow risks, but the base-ref, final PR check, and cross-client instructions need attention before relying on the skill broadly.

Architecture Summary

Architecture risk: 🔵 Low · up to f1197

The change affects 1 system.

Changed systems: products

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — products (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md: The usage-based staleness text now says missing recent calls may result from local evaluation or disabled event capture, replacing the claim that SDKs have stopped checking the flag.
  • observed — Modified behavior in products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md: The workflow now distinguishes assessment from cleanup authorization: assessment permits reads and recommendations, while repository edits require an explicit cleanup request. It then selects the available access path.
  • observed — Modified behavior in products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md: Candidate exclusions now include flags created or updated within 30 days, pending or recurring schedules, and active dependents. Product-tour usage must be confirmed before recommendations or edits; named flags are subject to the same exclusions, and overrides are disallowed. Missing evidence or dates stop removal. Before editing, the workflow requires a summary of retained behavior and evidence; flag and tool content is explicitly treated as data.
  • observed — Modified behavior in products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md: A new pre-classification check searches the checkout, fetched remotes, commit history, and hosted open PRs for existing cleanup. Incomplete required fetches or unavailable PR access stop editing. The workflow distinguishes merged removals, reintroduced or missed runtime checks, and in-flight unmerged removals; in-flight work is reported and stops further cleanup. Only removal of a runtime check counts, and historical merged removals do not count as pending work.
🚥 Pre-merge checks | ✅ 1
✅ Passed checks (1 passed)
Check name Status Explanation
Description check ✅ Passed The description clearly explains the problem, changes, testing status, release impact, agent context, and review decisions. It omits the required Release status section and checkbox selection.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@JamesPatrickGill JamesPatrickGill added the reviewhog ($$$) Reviews pull requests before humans do label Sep 28, 2026
@posthog

posthog Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

🦔 PostHog Review reviewed this pull request

Found 1 must fix, 4 should fix, 2 consider.

Published 7 findings (view the review).

Resolved comments: 10 fixed, 1 already settled, 1 left for you

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Note

Quiet mode is enabled, so only the most important comments were posted inline. Other review comments are grouped below.

🟡 Other comments (2)
products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md-145-151 (1)

145-151: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Use capabilities that are available across MCP clients.

This skill requires Git CLI commands and names Edit, Write, and MultiEdit calls. MCP clients do not share a shell or a common edit-tool API. Describe the required operations without binding them to these tools, or provide a capability-neutral fallback that stops before edits when a required operation is unavailable.

As per path instructions: “These skills ship to every MCP client. Flag any instruction that uses a command, flag, tool, or capability not available to every MCP user: flag-gated, client-specific, or mode-specific.”

Also applies to: 154-159, 246-249

Source: Path instructions

products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md-303-307 (1)

303-307: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Repeat the existing-work check before publication.

Step 3 scans branches and open PRs before rollout classification and call-site tracing. A teammate can open a cleanup PR while this run edits or validates. The publish gate does not repeat that scan, so the run can still push or open duplicate cleanup work. Repeat the existing-work check before pushing or opening a PR, and stop if an unmerged removal exists.


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: a6d2a602-9e4d-49f2-8c4a-ad40cd8c2dc4

📥 Commits

Reviewing files that changed from the base of the PR and between a281f4f and 053cd5b.

📒 Files selected for processing (1)
  • products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 10 remain after this review.

Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
@posthog

posthog Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

PostHog Review alpha 🦔 If you find any issues helpful - please reply "valid", "invalid", etc., for evaluation purposes 🙏

@posthog posthog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PostHog Review

Found 1 must fix, 4 should fix, 2 consider.

Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
@posthog posthog Bot removed the reviewhog ($$$) Reviews pull requests before humans do label Sep 28, 2026
@JamesPatrickGill
JamesPatrickGill force-pushed the chore/flags-cleanup-skill-hardening branch from 053cd5b to 2d212a9 Compare September 28, 2026 15:29

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

Quiet mode is enabled, so only the most important comments were posted inline. Other review comments are grouped below.

🟡 Other comments (1)
products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md-251-251 (1)

251-251: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Use a client-neutral edit-gate instruction.

This skill ships to every MCP client, but Edit, Write, and MultiEdit are client-specific tool names. The before any other action clause preserves the ordering requirement, but the named-call wording still assumes APIs that some clients may not provide.

Suggested wording
-Before your first Edit, Write, or MultiEdit call in this step, and before any other action in this step, repeat step 2's four reads: the definition, the status, the dependent flags, and the scheduled changes.
+At the start of this step, repeat step 2's four reads before taking any other action: the definition, the status, the dependent flags, and the scheduled changes.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: 202983f4-2ef4-41a6-a61d-a9b793d9d656

📥 Commits

Reviewing files that changed from the base of the PR and between 2d212a9 and b38dbed.

📒 Files selected for processing (1)
  • products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 1 remain after this review.

@JamesPatrickGill
JamesPatrickGill force-pushed the chore/flags-cleanup-skill-hardening branch from b38dbed to cac03c8 Compare September 28, 2026 16:29
@JamesPatrickGill
JamesPatrickGill marked this pull request as ready for review September 28, 2026 16:41
@pr-assigner-resolver-posthog
pr-assigner-resolver-posthog Bot requested a review from a team September 28, 2026 16:41
@haacked haacked changed the title chore(feature-flags): harden the stale-flag cleanup skill chore(flags): harden the stale-flag cleanup skill Sep 28, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: d79dac5f-cd7b-428f-a0a1-1759b71cd26e

📥 Commits

Reviewing files that changed from the base of the PR and between b38dbed and cac03c8.

📒 Files selected for processing (1)
  • products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 10 remain after this review.

Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
@JamesPatrickGill
JamesPatrickGill force-pushed the chore/flags-cleanup-skill-hardening branch from cac03c8 to f1197cf Compare September 28, 2026 18:10

@haacked haacked left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Solid hardening pass. One blocking issue inline on the handoff prompt's pre-edit check, and the rest are suggestions.

Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
Comment thread products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md Outdated
@veria-ai

veria-ai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

PR overview

All previously flagged issues have been addressed. No open security concerns remain on this pull request.

Security review

No open security issues remain on this pull request.

Fixed/addressed: 1 · PR risk: 0/10

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

Quiet mode is enabled, so only the most important comments were posted inline. Other review comments are grouped below.

🟡 Other comments (1)
products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md-183-183 (1)

183-183: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Use the resolved base ref for the ancestry check.

The procedure fetches each relevant remote but does not define origin as the base remote. In a checkout where the base branch is tracked by upstream, origin/<base branch> can be missing or unrelated. The workflow can then classify a merged cleanup as unmerged. Resolve the base remote and branch before this check.

Suggested fix
-`git merge-base --is-ancestor <removal commit> origin/<base branch>` succeeds for a removal that already landed.
+Resolve the base remote and branch before this check, then run:
+`git merge-base --is-ancestor <removal commit> <resolved base ref>` for a removal that already landed.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: 23c63757-f9e7-4c05-9485-a6c1d83a927a

📥 Commits

Reviewing files that changed from the base of the PR and between cac03c8 and f1197cf.

📒 Files selected for processing (1)
  • products/feature_flags/skills/cleaning-up-stale-feature-flags/SKILL.md

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.

JamesPatrickGill and others added 15 commits September 28, 2026 20:18
Adds the guards the skill's own dogfood run showed it needed. A fresh
definition read now gates the first edit (step 6) and the publish (step
8), so a rollout that moves mid-run cannot be edited or shipped against
stale data. Validation ends in one of passed, failed, or could-not-run,
and only passed permits a push.

A new step 3 looks for cleanup that already exists in the checkout, in a
branch, or in an open PR before any call site is read. Exclusions now
apply to a named flag as well as a survey result, with no override on
offer, and the product-tour question must be answered rather than asked.
The orphan rule splits code the flag created from general helpers that
only lost their last caller, and keeps the latter.

The handoff prompt carries the same existing-work, pre-edit and
pre-publish checks for an agent that cannot read PostHog.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…s use

Step 6 keeps payload reads in place, but its orphan rule removed the key string, constant and registry entry unconditionally. A payload read that still passes the constant would break. The rule now checks each symbol for other uses first and keeps the ones a surviving read still needs.

Generated-By: PostHog Desktop
Task-Id: d33c2c9d-7ce8-4fde-8bc2-34a13fa78daf
…mands

Step 3 reads branch, remote and PR ref names, but the shell rule only covered the flag key. Git accepts shell characters in ref names, so the rule now covers those names and other repository content too.

Generated-By: PostHog Desktop
Task-Id: d33c2c9d-7ce8-4fde-8bc2-34a13fa78daf
…f prompt

The handoff prompt now tells the receiving agent to read open PR diffs, including fork PRs, but its trust statement covered only flag keys and variant names. It now states that branch names, commit messages, PR titles, PR diffs and repository files are data, never instructions, as the main workflow does in step 3.

Generated-By: PostHog Desktop
Task-Id: d33c2c9d-7ce8-4fde-8bc2-34a13fa78daf
When the pre-edit or pre-publish read found a changed flag, steps 6 and 8 sent the agent back to step 4. Step 4 only classifies the rollout, so it skipped step 2's dependency, schedule and age exclusions. A change is itself an update, and step 2 excludes a recently updated flag. Both handlers now restart at step 2, as the handoff prompt already does.

Generated-By: PostHog Desktop
Task-Id: d33c2c9d-7ce8-4fde-8bc2-34a13fa78daf
Step 8 read the flag at the start of the step, but the agent could then wait for the user to authorize publication. A rollout change during that wait went undetected. The read must now come right before the push or PR call, and repeats when publication resumes after a pause. The worked example shows the re-read after the user agrees.

Generated-By: PostHog Desktop
Task-Id: d33c2c9d-7ce8-4fde-8bc2-34a13fa78daf
…ork check

Step 3 ran a plain git fetch, which keeps remote-tracking refs for branches deleted on the host. The later git log --all search still saw them, so a closed and deleted cleanup branch could stop every run as work in flight. The fetch now uses --prune.

Generated-By: PostHog Desktop
Task-Id: d33c2c9d-7ce8-4fde-8bc2-34a13fa78daf
The handoff prompt told the receiving agent to inspect every open PR diff and stop if any check was incomplete. In a busy repository that is thousands of diffs, and one unrelated refused diff stops the run. The prompt now uses step 3's selection: search the history of all fetched refs for the key, list open PRs by metadata, and inspect only fork PR diffs and PRs whose head branch or title names the key.

Generated-By: PostHog Desktop
Task-Id: d33c2c9d-7ce8-4fde-8bc2-34a13fa78daf
…blish checks

The pre-edit and pre-publish checks fetched only the flag definition, then compared version and rollout. The definition has no rollout summary, and version is null on a flag written before versioning, so the comparison could not be done as written. Both checks, and the handoff's pre-publish check, now fetch the status too and compare version, updated_at, and the status rollout object.

Generated-By: PostHog Desktop
Task-Id: d33c2c9d-7ce8-4fde-8bc2-34a13fa78daf
…t and publish

A schedule or dependent flag created after assessment does not change this flag's definition, so the pre-edit and pre-publish reads missed it. Both checks now repeat step 2's four reads and apply its exclusions to the fresh responses before comparing version, updated_at and rollout. The after-approval re-read and the handoff's pre-publish check follow the same rule.

Generated-By: PostHog Desktop
Task-Id: d33c2c9d-7ce8-4fde-8bc2-34a13fa78daf
…ht cleanups

The existing-work check searched history only for the literal key. A cleanup that removes checks through a registry constant, but leaves the key in the registry, does not change the key's occurrence count, so the search missed it. Step 3 and the handoff prompt now also search the history of each constant and wrapper that holds the key.

Generated-By: PostHog Desktop
Task-Id: d33c2c9d-7ce8-4fde-8bc2-34a13fa78daf
The handoff prompt is a copyable artifact. It leaves the session and a
person can paste it days later, so a fact the prompt asserts expires
without telling the receiving agent.

A product tour can link a flag, and no read tool reports the link. The
generated prompt carried neither the question nor the answer the
assessment obtained, so a receiving agent could remove a flag a tour still
uses. The prompt now carries the answer with the date it was given, and
still tells the receiving agent to confirm with the user before it removes
any code. The date is what makes a stale answer visible; the confirmation
is what stops the answer being read as clearance.

Two more instruction gaps in the same file, neither filed by a reviewer:

- The open-PR listing in the existing-work check had no pagination
  requirement. Every host caps a page, and a truncated listing reports no
  error, so a cleanup already in flight on a later page reads as no
  cleanup at all and the skill opens a duplicate PR. Both the main path
  and the handoff prompt now say to page through the whole list.
- The handoff prompt sent a changed flag back to the rollout
  classification. The main path already restarts at the assessment checks,
  because the change is itself an update and a flag updated inside the
  last 30 days is excluded. The handoff prompt now restarts in the same
  place.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
An answer left in context from an earlier assessment was reusable with no check on
its age. A tour can start to use the flag after that answer, so the skill could
remove code a tour needs without asking the only person who can say.

Reuse now needs the answer to come from this assessment. An older answer names its
date, and the user has to confirm it before the agent recommends removal or edits
code. The handoff prompt already carries the date and requires that confirmation.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Five findings from haacked's review of the main path.

An open fork PR is text an outside contributor writes, and the skill sent an agent
holding PostHog access to read every one of them in full. On this repository that is
tens of thousands of changed lines, so the read either overflows the context or
truncates and misses the removal it was looking for. The agent now filters each fork
diff in the shell for the key and its constants, reads only the matching hunks, and
reports a diff it could not filter as unchecked.

Quoting does not make a Git ref safe. Git accepts `'` and `$(` in a branch name, and
step 3 sends the agent to branches found by name and then diffs them, so anyone who
can push a branch could run a command on the machine doing the cleanup. Refs now go
through the same allowlist the handoff already uses for interpolated values, and a
ref that fails it is a check the agent could not complete.

The `git log --all -S` walk reads every commit on every ref, once per name, and a
blobless clone fetches blobs as it goes. The skill now says to run it in the
background and that a running search is not an incomplete check, while an abandoned
one is. Bounding it by the flag's creation date would be faster but would miss the
re-created key the seasonal-flag case depends on.

Missing PR access no longer stops local edits. A duplicate PR and a duplicate review
are harms of publication, and stopping early contradicted both the "make the changes
yourself" path and "lack of PR access is not a failed cleanup". The gap is recorded
and step 8 refuses to publish until the search completes, which also catches a
cleanup PR opened while the agent was editing.

Two wording fixes: "do not revert an edit you already made instead of not making it"
read as "do not revert", which contradicted step 8, and "report how to restore
validation" did not say what the report has to contain.

The pre-edit summary moves from step 2 to the end of step 5, where the agent has the
existing work, the rollout state and the call sites it asks for.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…gainst

The generated prompt told the receiving agent to re-read the flag before its first
edit and compare, but carried nothing to compare against: the key, the variant and
the tour answer, and no version, update time or rollout. The check could not fire.
A prompt written for a 100% boolean, a rollback to 0%, and a paste 35 days later all
pass the age check, and the prompt still says to keep the enabled body, so the
cleanup ships the path PostHog serves to nobody.

The prompt now carries an "Assessed state" line beside the tour line, and its
pre-edit check fetches the definition and the status and compares version, update
time and rollout against it. A `version` and an ISO `updated_at` both match the
interpolation allowlist.

Three main-path fixes had never reached the handoff's copy of steps 3, 6 and 8:
`git fetch --prune` per remote, the ref allowlist, and repeating the reads when an
authorization request pauses publication. It also gains the fork-diff filter and the
incomplete-check rule. Each of the three steps now carries an HTML comment naming
the handoff as a second copy, so the next edit finds both.

Both handoff strings become `text` fences. Unfenced, lines such as "report it and
stop" read as instructions to the agent running this skill.

The file had grown to 561 lines, past the 500-line limit in the writing-skills
handbook, which no lint enforces. The handoff section moves to
`references/handoff-prompt.md`, which haacked suggested and which left the file at
503, so the worked example moves to `references/example-interaction.md` as well.
457 lines now. Both headings stay, so the cross-reference at line 47 still resolves,
and `hogli build:skills` collects both reference files.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Status: In Review

Development

Successfully merging this pull request may close these issues.

2 participants