cc-changelog
CONTRIBUTOR TOOL - Track CC changelog, extract new versions since last check, analyze impact on plugin (breaking changes, opportunities, deprecations). Run…
Record a vetted Hex package version in hex_vet.exs after a security review
$ npx -y skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/phx-deps-vetContext preview
The summary Claude sees to decide when to auto-load this skill.
Record a vetted Hex package version in hex_vet.exs after a security review
name: phx-deps-vet description: Record a vetted Hex package version in hex_vet.exs after a security review — manages the audit ledger, not the scanner. Use to approve a dep after phx-deps-audit findings or to initialize hex_vet.exs.
Review a Hex package version, run Phase 1 supply-chain rules against it, prompt the user for a verdict, append the result to `hex_vet.exs` (project-root audit ledger). Vetted versions get downgraded to `INFO` on subsequent `phx-deps-audit` runs.
Run this AFTER `phx-deps-audit` to clear findings. Run this BEFORE merging a `mix.lock` PR to certify new versions.
phx-deps-vet phoenix 1.7.21 # vet a single package version phx-deps-vet --seed # import curated baseline seed (~30 pkgs) phx-deps-vet --list # show existing ledger entries phx-deps-vet --check # cross-check mix.lock vs ledger
1. **NEVER auto-approve.** Every entry MUST come from an `AskUserQuestion` confirmation. Drive-by trust ruins the ledger's value. 2. **Lock wins on disagreement.** If `mix.lock` has version X and the ledger vets X-1, emit INFO and treat X as unvetted. Don't silently trust the older entry. 3. **Ledger lives at project root.** `hex_vet.exs` is a first-class security artifact, visible in PR review. Don't move it into `.claude/`. 4. **Round-trip via `inspect/2`.** When appending, read the file with `Code.eval_file/1`, mutate the map, and write back via `inspect(term, pretty: true, limit: :infinity)`. Hand-rolled string appends drift over time. 5. **Always show findings before prompting.** The user must see what's being vetted. No silent `:safe_to_deploy` defaults. 6. **Confirmation counts are COMPUTED, never estimated.** Any number in an `AskUserQuestion` (criteria split, new/overwrite/no-op) MUST be derived from the loaded data *before* prompting — e.g. `Enum.frequencies_by(seed.audits, & &1.criteria)`. Eyeballing the file and approving on wrong numbers corrupts the consent.
If hex_vet.exs exists at project root:
Read it via Code.eval_file/1
Else:
Write the empty-ledger stub (see references/hex-vet.md §"Empty ledger")
Inform user: "Created hex_vet.exs at project root."`Code.eval_file/1` the seed and **compute** (Iron Law #6): the `criteria` split (`Enum.frequencies_by(seed.audits, & &1.criteria)`) and, against any existing ledger, exact new / overwrite / no-op counts. Put those computed numbers in the `AskUserQuestion`. Also state up front that the seed is a **provenance baseline, not certification of your current `mix.lock`** (per Iron Law #2, seed versions older than the locked ones stay unvetted). Ask before overwriting existing entries.
drift. Read the lock via `Code.eval_file("mix.lock")` with **`2>/dev/null`** — modern locks have quoted keys and emit a `found quoted keyword` warning per package (tens of KB of noise that gets persisted as an oversized tool result otherwise).
Run the deps-audit corpus loader. Cache lives at `~/.cache/phx-deps-audit/corpus/<pkg>/<version>/contents/`. Use:
bash ../phx-deps-audit/smoke-test/corpus.d/fetch.sh \
<pkg> <version>Source the rules from `../phx-deps-audit/references/rules-impl.md`. Run `run_all_rules` over the cached dir. Write findings to a temp `vet-findings.jsonl`. Set `FINDINGS_FILE` to override default path.
Print the findings table per `../phx-deps-audit/references/output-renderer.md`. On zero findings: say "No findings — vet from a clean baseline." On any finding: show severity, file, line, snippet inline.
Call `AskUserQuestion` with these 4 options:
If any finding is BLOCK severity: default-highlight `Skip`. Require explicit override before writing `:safe_to_deploy` over a BLOCK.
Read existing `hex_vet.exs` via `Code.eval_file/1`. Append the audit map below to `:audits`. Write back via `Code.format_string!(inspect(...))`.
%{
package: "<pkg>",
version: "<version>",
criteria: <verdict_atom>,
reviewer: "<git config user.email>",
notes: "<user-provided one-liner OR findings summary>",
reviewed_at: ~D[<today>]
}Write back via `Code.format_string!(inspect(term, pretty: true))`. Confirm to user: "Added `<pkg>` `<version>` to hex_vet.exs."
same rules `phx-deps-audit` runs
package `phx_deps_vet` for non-CC users.
that gates `mix deps.get`.
trust-chain semantics are designed.
Docs: phxagents.dev -- install guides per runtime, the runtime compatibility matrix, all 26 Iron Laws, and a browsable skill and agent catalog. Claude Code is great.
Repo: oliver-kriska/claude-elixir-phoenix
CONTRIBUTOR TOOL - Track CC changelog, extract new versions since last check, analyze impact on plugin (breaking changes, opportunities, deprecations). Run…
Run an A/B codex review experiment — holistic codex review vs 3 focused dimension passes (security, ecto, liveview) on the branch diff, classify findings,…
CONTRIBUTOR TOOL - Validate plugin against latest Claude Code documentation. Catches breaking changes, deprecations, discovers new features. Run before…
Guide plugin development workflow — editing skills, agents, hooks, or eval framework in this repo. Use when modifying files in plugins/elixir-phoenix/,…
Generate X/Twitter release promotion posts with ASCII tables and CodeSnap rendering. Use when writing release posts, promotion tweets, plugin announcements, or…
CONTRIBUTOR TOOL - Cut a plugin release: bump plugin.json version, finalize CHANGELOG, update README if needed, gate on make ci, commit, tag vX.Y.Z, and create…