Document the Review Trust Gate

Claude Code·Opus 5.5·peyton-alt·23h ago·2hr 56min·1 Checkpoint·22 file changes·+3276/-115·2.5K tokens

can you find the sesssion we were working on in this worktree and resume it?

23h ago·33.3s

I found it. It's session 31bd6455-8dc5-4837-a891-bfac3cf1277a, last active at 15:47 today. You started it from the linear-2 worktree, so /resume here won't list it. To reopen it with its full context, run:

Where it stopped: it was fixing the findings from the review agent on peyton/review-trust-gate (4 commits, none pushed). The fixes are uncommitted in this worktree: +224/−94 across 5 files. The code builds, but I haven't run tests or lint on it.

From its last few steps, these fixes look done or in progress:

  • #1: authorship is now checked against the default branch instead of --base.
  • #5: approval takes the full SHA, and the hint prints the full SHA.
  • #6: the committer is checked as well as the author.
  • #2: agent config is decoded by exact key, so differently-cased keys can't hide hooks.
  • #4: skill, command and prompt files are listed for each agent.

Still to do:

  • #3: match file names in the commit tree without regard to case, so .Claude/Settings.json isn't missed on macOS and Windows.
  • #7: reviews fail when there's no default branch, and CI runs without user.email always need approval.
  • #8: mark --show-config output as untrusted data from the branch.
  • #9: check out the pinned SHA instead of the branch name.
  • #10: pass --no-show-signature to git log.
  • The earlier lint fix (three repeated strings) still has to be checked against the new code.
  • Run mise run check, then commit.
  • #11 needs your decision: the Codex guardrail replaces any developer_instructions you set in ~/.codex/config.toml during reviews.

I can also pick it up here instead: I'd check which fixes are actually finished in the diff, then work through the rest.

26863c4Ask before reviewing code someone else wrote A review loads the checkout's hooks, MCP servers, skills, and settings, so reviewing a teammate's branch runs whatever that branch configures. Reviews of your own commits (authored and committed by your user.email, counted from your default branch, never from --base) run as before. Anything else needs approval: a terminal confirm that lists what would run, or --trust-target <full sha> pinned to the head. Agents and non-terminal callers get a fixed refusal telling them to ask the user. --show-config lists what would run without running it. The inventory reads agent config with exact JSON keys (as the agents do) and matches the commit tree case-insensitively (as a macOS or Windows checkout loads it); symlinks and unparseable files count as unknown. With --target, the profile is chosen and the branch pinned in the caller's checkout, the pinned commit's tree is inspected, and only then is the worktree added (no checkout, no hooks), verified against the pin, and checked out: for someone else's branch with no git hooks, LFS smudge, or submodule recursion, and no .worktreeinclude copy. The re-run inside the worktree reads review settings from the caller's checkout and skips the gate only when the forwarded SHA matches its head. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Entire-Checkpoint: 01M473E034J2GNM6R18TH84MC3 Entire-Checkpoint: 01M47493FFMT3CG642S1JYEGYR Entire-Checkpoint: 01M474HXWPRC0WWMJBMZ892JY7 Entire-Checkpoint: 01M474JDBKTNMVGZDXJTNSHPB4 Entire-Checkpoint: 01M479ZDX6HB3GG7DRBR36G5DP+3215/-112