phx-freeze · diff

git:20260723.d82e8e5 to git:20260724.918f809

30 added, 63 removed. Audit A to A.

---
name: phx-freeze
- description: Scope or freeze which files Claude can edit during debugging; Use when
- edits should stay in specific dirs…
+ description: Apply an advisory scope in this session. Use for read-only or directory-scoped
+ work; no enforcement hook is installed.
---
-
- # Freeze — scoped edit lock
-
- Toggle a project-local edit lock so Claude can only modify the files you intend
- during a focused task (debugging, a tight refactor, a review pass). Enforced by
- the `freeze-gate.sh` PreToolUse hook, which denies `Edit`/`Write`/`NotebookEdit`
- outside the allow-list. No sentinel = no lock; the hook stays dormant.
+ # Freeze — advisory edit scope
- The lock lives in `.claude/.freeze` — one allowed path prefix per line,
- project-relative. Empty file = freeze everything.
+ Apply a current-session instruction that limits which files this agent may edit.
+ This generated runtime does not install an enforcement hook, so the scope is
+ advisory rather than a technical lock. Never claim that edits are blocked by the
+ runtime.
## Usage
- `$elixir-phoenix:phx-freeze [args]` — resolve `$ARGUMENTS` and run the matching Bash branch.
-
- | Invocation | Effect |
- |------------|--------|
- | `$elixir-phoenix:phx-freeze` | Freeze ALL edits — read-only investigation mode |
- | `$elixir-phoenix:phx-freeze lib/app_web priv/repo` | Allow edits only under these dirs |
- | `$elixir-phoenix:phx-freeze status` | Show current lock state |
- | `$elixir-phoenix:phx-freeze off` | Lift the lock (delete the sentinel) |
-
- ### Freeze all edits (investigation mode)
-
- ```bash
- mkdir -p .claude && : > .claude/.freeze
- echo "Freeze ON — all edits blocked. Lift with $elixir-phoenix:phx-freeze off"
- ```
-
- ### Scope edits to specific directories
-
- ```bash
- mkdir -p .claude
- printf '%s\n' lib/app_web priv/repo > .claude/.freeze
- echo "Freeze ON — edits limited to: lib/app_web priv/repo"
+ ```text
+ $elixir-phoenix:phx-freeze
+ $elixir-phoenix:phx-freeze lib/app_web priv/repo
+ $elixir-phoenix:phx-freeze status
+ $elixir-phoenix:phx-freeze off
```
- Map `$ARGUMENTS` to the dirs the user named. Include any directory you still need
- to write to — e.g. add `.claude` if progress/scratchpad logging must continue.
-
- ### Show status
-
- ```bash
- if [ -f .claude/.freeze ]; then
- if [ -s .claude/.freeze ]; then echo "Freeze ON — limited to:"; cat .claude/.freeze
- else echo "Freeze ON — ALL edits blocked"; fi
- else echo "Freeze OFF — no edit lock"; fi
- ```
+ Treat the text after the skill invocation as follows:
- ### Lift the lock
+ | Invocation | Current-session behavior |
+ |---|---|
+ | No arguments | Do not edit files; investigation and reporting remain read-only. |
+ | Path prefixes | Edit only files under the listed project-relative prefixes. |
+ | `status` | Report the advisory scope currently established in this conversation. |
+ | `off` | Clear the advisory scope for subsequent work. |
- ```bash
- rm -f .claude/.freeze && echo "Freeze OFF — edits unlocked"
- ```
+ Do not create `.claude/.freeze`. That sentinel belongs to the canonical Claude
+ Code plugin and could affect a later Claude Code session even though this runtime
+ cannot enforce or clear it reliably.
## Iron Laws
- 1. **MANAGE the sentinel via Bash only** (`:>`, `printf`, `rm`) — NEVER via
- Edit/Write. The freeze hook gates Edit/Write and would block you from
- re-scoping or clearing the lock.
- 2. **NEVER leave a freeze active across unrelated tasks** — it persists until
- `$elixir-phoenix:phx-freeze off`, including into later sessions. Clear it when the task ends.
- 3. **PATHS ARE PROJECT-RELATIVE PREFIXES, one per line** — `lib/foo` allows
- `lib/foo` and everything under it; it does NOT allow `lib/foobar`.
-
- ## Notes
-
- - The hook denies with a reason and tells Claude not to retry, so a frozen edit
- surfaces clearly instead of failing silently.
- - Pairs with `$elixir-phoenix:phx-investigate` (freeze all while root-causing) and `$elixir-phoenix:phx-work`
- (scope to the plan's dirs). The lock is advisory tooling, not a security
- boundary — anyone can run `$elixir-phoenix:phx-freeze off`.
+ 1. **Never describe this scope as enforced** — it is a binding instruction for
+ the current agent, not a runtime or security boundary.
+ 2. **Never create or modify `.claude/.freeze` in a generated runtime** — no
+ matching enforcement component is installed here.
+ 3. **Honor the active scope until the user clears it or the focused task ends** —
+ ask before editing outside listed prefixes.
+ 4. **Keep paths project-relative** — `lib/foo` includes that directory and its
+ descendants, not a sibling such as `lib/foobar`.