Document the Review Trust Gate
Claude Code·Opus 5.5·
peyton-alt·23h ago·2hr 56min·1 Checkpoint·22 file changes·+3276/-115·2.5K tokens

I found it. It's session 31bd6455-8dc5-4837-a891-bfac3cf1277a, last active at 15:47 today. You started it from the linear-2 worktree, so /resume here won't list it. To reopen it with its full context, run:
Where it stopped: it was fixing the findings from the review agent on peyton/review-trust-gate (4 commits, none pushed). The fixes are uncommitted in this worktree: +224/−94 across 5 files. The code builds, but I haven't run tests or lint on it.
From its last few steps, these fixes look done or in progress:
- #1: authorship is now checked against the default branch instead of
--base. - #5: approval takes the full SHA, and the hint prints the full SHA.
- #6: the committer is checked as well as the author.
- #2: agent config is decoded by exact key, so differently-cased keys can't hide hooks.
- #4: skill, command and prompt files are listed for each agent.
Still to do:
- #3: match file names in the commit tree without regard to case, so
.Claude/Settings.jsonisn't missed on macOS and Windows. - #7: reviews fail when there's no default branch, and CI runs without
user.emailalways need approval. - #8: mark
--show-configoutput as untrusted data from the branch. - #9: check out the pinned SHA instead of the branch name.
- #10: pass
--no-show-signaturetogit log. - The earlier lint fix (three repeated strings) still has to be checked against the new code.
- Run
mise run check, then commit. - #11 needs your decision: the Codex guardrail replaces any
developer_instructionsyou set in~/.codex/config.tomlduring reviews.
I can also pick it up here instead: I'd check which fixes are actually finished in the diff, then work through the rest.