Milestone 419's acceptance, and it failed the first time it was run — which
is the only reason this commit exists.
THE MEASUREMENT. Ran the step-5 readout against this session's real traffic
instead of a fixture. It reported 19 rules named by an arm and none opened.
That is false: the session had called `get_rule` 45 times. Across six real
sessions on this instance: 208 opens, 3 surviving ledger entries. 1.4%.
THE CAUSE. `.opened.ids` was doing two jobs with opposite lifetimes.
- "this context HOLDS rule 156" — false after a compaction, and three hooks
read it to decide whether to stay quiet. Clearing it is correct.
- "rule 156 WAS OPENED" — which no compaction makes untrue, and which the
session-end readout is built on.
`scribe_clear_session_ledgers` sweeps every `<sid>*.ids` on SessionStart
source=compact. Right for the first claim, and it was deleting the second.
The TTL did the same thing more quietly: `scribe_rules_live` ages an
exclusion ledger, which is right, and would have eaten the early part of any
long session's evidence too.
So the readout was reporting only the stretch since the last compaction while
reading as though it had reported the session — a statistic that cannot vary
being mistaken for a finding (#3311), which is the shape this whole milestone
exists to stop producing. It ran AT the seam it was blind to.
THE SPLIT. `scribe_rules_append` now writes both: the exclusion ledger it
always wrote, and `<kind>.keep.ids`, an evidence twin that is never aged and
never swept. The readout reads twins; the three `held` readers are untouched.
DERIVED, NOT LISTED, because a list is what broke this before — the comment
above the sweep says so about its own history. Every ledger written through
the appender gets a twin, including the next one somebody adds; a new ledger
is born on the swept side unless its name opts out. `scribe_checkpoint_allowed`
writes its twin explicitly since it bypasses the appender, and there the split
lands right on both sides: the cap counts the swept file, so a compaction
honestly restores the budget to stop an act the context can no longer justify,
while the record that a stop happened stays.
Removed `scribe_ledger_ids`, orphaned by the change — a dead helper beside a
live one is a thing the next reader trusts.
test_session_ledger_clear.py asserted every ledger dies and could not have
caught this: its fixture never created a twin, so the sweep was one glob away
from either mistake with only one of them guarded. Both sides now asserted.
The slippage tests build their ledgers through the real writers rather than
by hand, for the same reason — a fixture that writes the bytes itself keeps
passing after the writer stops.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01821k5B3Ysecp9fNYs92Kuy
Scribe plugin for Claude Code
Turns a self-hosted Scribe instance into a first-class Claude Code extension:
- MCP tools over your notes, tasks, projects, milestones, systems, and
rulebook (the
scribeserver). - Session-start push channel — a
SessionStarthook injects the active project's live state (from the server) and this adapter's short Claude Code guidance, so Scribe surfaces without being asked. Rules are never preloaded; they arrive by retrieval when your work matches one. - Prior-art recall on writes — a
PreToolUsehook on Write/Edit checks the file about to be written against your recorded snippets (what's kept at that path, and what resembles the code) and offers them before the helper is rewritten. Titles only, never blocks the edit. - The shared Scribe skills — client-neutral Agent Skills, the same files any client's package would ship: using-scribe, writing-plans, reporting-back (reply to the operator in a shape that says where the work stands), systematic-debugging, verification, brainstorming, reusing-code (record and recall reusable code as snippets). Replaces superpowers.
- Your Scribe Processes as skills — saved Processes are synced into local
~/.claude/skills/scribe-proc-*stubs that auto-surface by relevance; the stub fetches the live procedure viaget_process. Refreshed each session and on demand with/scribe:sync.
It is designed so you can uninstall superpowers and depend on Scribe instead
of auto-memory — leave auto-memory at its default; Scribe replaces its job by
holding the one copy, not by switching it off.
How the pieces divide the work (decision #4027): the Scribe server orients
every MCP client and serves live state; the skills in skills/ state every
reflex in full and name no client; this plugin is the Claude Code adapter —
hooks that deliver at the right moment, /scribe:sync, and the few things only
Claude Code needs said (hooks/scribe_static_context.md). Packaging Scribe for
another client: see PACKAGING.md.
Install
The plugin ships inside the Scribe app repo, so the marketplace is that repo — you always get the plugin version that matches your Scribe instance.
/plugin marketplace add https://git.fabledsword.com/bvandeusen/FabledScribe.git
/plugin install scribe@scribe-plugin
On install you'll be asked for:
| Setting | What |
|---|---|
| Scribe base URL | e.g. https://scribe.example.com (no trailing slash) |
| Scribe API key | an fmcp_ key from Settings → API Keys (stored in your OS keychain) |
| Active project id | optional — numeric project id to scope the session-start context |
What gets wired
plugin.jsonmcpServers→ thescribeMCP server at<base URL>/mcp(Bearer auth).hooks/hooks.json→ SessionStart hook (hooks/scribe_session_context.sh), fail-open: if Scribe is unreachable it injects nothing and never blocks the session.hooks/hooks.json→ PreToolUse hook onWrite|Edit(hooks/scribe_prior_art.sh) →GET /api/plugin/prior-art. ReturnsadditionalContextwith no permission decision, so it can inform the write but never stop it; silent when nothing is recorded, which is most of the time. Two framings: a REUSE menu (similar/nearby records), and a SYNC nudge when a snippet records the exact file being edited — "updating the record is part of the edit" — each with its own once-per-session dedup. A third, ledger-fed line names a duplicate family (no canon) or a canon recorded elsewhere for the names being written (its own dedup channel,exclude_derive). Fail-open but not fail-silent: a configured instance that does not answer in time is said, once per outage ("Scribe did not answer … this write went UNCHECKED"), so a session can tell "checked, nothing there" from "never checked"; an answer clears the marker. The local by-name arm needs no server and always runs. Toggle in Settings → Knowledge auto-inject.hooks/hooks.json→ PostToolUse hook onBash(hooks/scribe_after_write.sh): code written through sed/heredocs/scripts never reaches the PreToolUse hook, so this one diffs the working tree after every Bash call (per-session path+blob snapshot; onegit statuswhen nothing changed) and runs the same arms on the definitions just written, through the same endpoint and the same dedup channels.additionalContextonly; never blocks, and shares the pre-write hook's once-per-outage "did not answer" line (8 s budget here — it runs after the tool, so it gates nothing). The extractor, the prose/data skip list, the local by-name duplicate arm and the outage line are shared inhooks/scribe_defs.sh.hooks/hooks.json→ Stop hook (hooks/scribe_report_check.sh): when the turn closed a Scribe task (update_task/create_taskwith status done), checks the reply that ends it for the completion sections — where the work sits, what needs you, what comes next — and reports the outcome toGET /api/plugin/report-check. If sections are missing it blocks once with the reason the server returns, and records how the rewrite came out; it never blocks twice, and never blocks when the instance did not record the check (unconfigured or unreachable). Outcomes land in the admin logs under categoryplugin, actionreport_check.skills/→ the universal process-skills, surfaced by description match.hooks/scribe_sync_processes.sh(a 2nd SessionStart hook) + the/scribe:synccommand → generate~/.claude/skills/scribe-proc-*stubs from your Scribe Processes (viaGET /api/plugin/processes); also fail-open, and pruned to match what exists in Scribe.
Notes
- Do not hand-edit
versionin.claude-plugin/plugin.json. It is minted from the clock — runpython3 scripts/mint_plugin_version.py(ormake mint-plugin, wheremakeis installed) after changing anything underplugin/, and commit the result. The installer decides whether to refresh the cache it executes from by comparing that string, so content that ships without a new version reaches the repo and stops there (#2209). CI fails the lane if you forget. - The session-start, auto-inject and prior-art hooks need only a read-scoped key; the MCP tools need write scope to create/update. Every hook is a GET for that reason — a read key cannot POST.