Compare commits

...
Author SHA1 Message Date
Emeriko c176ec1b3d Add a Sponsors section with GreenPT as the first sponsor 2026-06-26 00:21:44 +02:00
DietrichGebertandClaude Opus 4.8 64adbf9544 Use an announcement banner instead of the badge (#316)
Replace the flat orange badge with a clickable terminal-style banner
image: the "he's building" sticker, a bold headline, and an orange
JOIN THE WAITLIST call to action. Localized banners for EN/ES/KO.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-25 19:03:58 +02:00
DietrichGebertandClaude Opus 4.8 7086abecc2 Make the waitlist teaser pop and translate it (#314)
The blue NOTE callout was too quiet. Replace it with a centered bold
line plus a bright orange "join the waitlist" badge (matches the site),
and add the same banner to the Spanish and Korean READMEs.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-25 18:13:53 +02:00
DietrichGebertandClaude Opus 4.8 4e5f9ccc6c Add a waitlist teaser to the README (#312)
Promotes the pre-launch waitlist at ponytail.dev/soon with a NOTE
callout just under the header.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-25 18:05:42 +02:00
DietrichGebertandClaude Opus 4.8 a945778b4a docs: add Star History chart to end of READMEs (#294)
Appends a star-history.com chart (light/dark via <picture>) to the end of
the English, Spanish, and Korean READMEs. Heading follows each file's
convention: translated in Spanish ("Historial de estrellas"), English
elsewhere.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 15:37:06 +02:00
DietrichGebertandClaude Opus 4.8 6cd0c42e86 docs: add Trendshift daily and weekly badges to READMEs (#293)
Adds the daily and weekly Trendshift badges to the header badge area of
the English, Spanish, and Korean READMEs. Alt text decoded from %2F to a
plain slash for screen readers.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 15:30:26 +02:00
DietrichGebert 025da371cd release: 4.8.3 (#286) 2026-06-24 04:32:12 +02:00
b9fa564429 feat: inject ponytail ruleset into subagents via SubagentStart hook (#254)
* feat: inject ponytail ruleset into subagents via SubagentStart hook

SessionStart additionalContext is parent-thread only, so every Task-spawned
agent ran ponytail-unaware. Add a SubagentStart hook that injects the active
ruleset into each subagent, reusing getPonytailInstructions. Native Claude
needs the hookSpecificOutput JSON form (not raw stdout), so writeHookOutput
grows a SubagentStart branch; readMode exposes the live flag.

Workflow- and team-spawned coverage is undocumented upstream; verify in a
fresh session once installed.

Closes #252

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01H1dMag33yz1Kf1jS24Aira

* fix: address QA round 1 — make hook tests hermetic + cover Codex SubagentStart

QA round 1 (panel + deepseek-v4-pro) found two real test issues:
- The new subagent block (and the pre-existing claudeEnv block) used a no-op
  `delete env.PLUGIN_DATA`; run() spreads process.env, so a PLUGIN_DATA /
  COPILOT_PLUGIN_DATA leaked from the shell would steer writeHookOutput into the
  codex/copilot branch and silently mis-fire the native-Claude assertions.
  Fixed at the source: neutralize both vars once at the top, like CLAUDE_CONFIG_DIR.
- The Codex SubagentStart branch (claude-codex-hooks.json is shared by both plugin
  manifests) had zero coverage. Added a codex-path assertion.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01H1dMag33yz1Kf1jS24Aira

* fix: use PowerShell-safe command form for SubagentStart hook

Match the post-#265 'node ...; exit 0' form used by the sibling hooks. The old 'command -v node ... || exit 0' form fails tests/hooks-windows.test.js (POSIX-guard and non-blocking asserts) once this branch merges onto current main.

---------

Co-authored-by: Shane McCarron <shane.mccarron@corvexconnect.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Emeriko <dietrich.gebert@gmail.com>
2026-06-24 04:19:14 +02:00
9d0118df34 docs: add Korean README translation (#283)
* docs: add Korean README translation

Add README.ko.md following the README.es.md convention (community
translation note, English as canonical) and link it from README.md.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* docs(ko): sync translation with current README

Bring README.ko.md up to current English: npm install for OpenCode
(@dietrichgebert/ponytail) + npm badge, drop the obsolete ln -sf command-symlink
note (the plugin self-registers commands since #197), add the Swival section and
the Codex two-prompt install note.

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Emeriko <dietrich.gebert@gmail.com>
2026-06-24 03:47:31 +02:00
DietrichGebert a0766a396d docs: npm install + badge for OpenCode, drop obsolete symlink note (#285)
The plugin registers the /ponytail commands itself now (#197), so the manual
ln -sf workaround is obsolete. Add the npm install snippet + version badge,
and bring README.es.md's OpenCode section up to parity with the English one.
2026-06-24 03:30:46 +02:00
DietrichGebert 17e277387d release: 4.8.2 (#284) 2026-06-24 03:19:28 +02:00
DietrichGebert 7d303b7175 ci: publish via npm trusted publishing (OIDC), drop NPM_TOKEN (#282)
Authenticate the release workflow through GitHub OIDC instead of a long-lived
npm token: no secret to leak or rotate, provenance attached automatically.
Upgrade npm on the runner since OIDC publishing needs npm >= 11.5.1 (Node 22
ships npm 10).
2026-06-24 02:58:03 +02:00
DietrichGebert e368c48c52 feat: scope npm package as @dietrichgebert/ponytail (#280)
Publish under a scope you own outright instead of opencode-ponytail (which
sits on a third-party npm account). Matches the GitHub handle and repo.
publishConfig.access is already public, which scoped public packages need.
2026-06-24 02:50:42 +02:00
Dang Trung AnandEmeriko 17a466013e feat: publish ponytail as an installable npm package for OpenCode and Pi (#197)
* feat: register slash commands from .opencode/command/*.md

Add parseCommandFile() to read frontmatter-described markdown files
and wire them into opencode's config.command during init.

Extend the config hook to scan .opencode/command/ and register each
.md file as a named slash command.

Update the plugin doc comment to reflect the npm install path
(opencode-ponytail) vs the old relative path.

* chore: rename package to opencode-ponytail

Align package name with npm convention for opencode plugins.
Update keywords to include opencode-plugin and opencode tags.
Fix description back to original correct wording (grammatical
regression introduced during editing).

* chore: add npm metadata and publish workflow

Add author, homepage, repository, bugs, main, exports, files, and
publishConfig fields to package.json for npm publishing.

Add .github/workflows/publish.yml to auto-publish to npm on version
tags (v*) with provenance.

* docs: add npm plugin install for opencode-ponytail

---------

Co-authored-by: Emeriko <dietrich.gebert@gmail.com>
2026-06-24 02:09:40 +02:00
Haoqian 2b426c6ac9 fix: make shared hooks parse in PowerShell (#265) 2026-06-24 01:42:40 +02:00
Frank Denis 268be28051 docs: add instructions for usage with Swival (#264)
This explains how to use Ponytail with Swival.
2026-06-24 01:14:19 +02:00
DietrichGebert c8b12b6384 fix(pi-extension): guard status bar render when ui has no theme (#279)
syncStatus guarded setStatus but used theme.fg unguarded, so a Pi host
exposing setStatus without a theme threw TypeError on session_start (and
agent_start/agent_end/setMode). Require both before rendering.

Add tests for the render path (previously untested) and the theme-absent
degradation. Follow-up to #275 / #84.
2026-06-24 01:10:04 +02:00
Tanmay Garg 947f2ff4de feat(pi-extension): add status bar indicator for ponytail mode (closes #84) (#275)
Add a syncStatus function to Pi extension to display the current
Ponytail mode in the status bar.

The indicator updates upon mode changes and hooks into the agent_start
and agent_end events to display a visual active/inactive state.
This provides the user with clear feedback on the currently active
Ponytail intensity level (lite, full, ultra) without running commands.
2026-06-24 00:51:23 +02:00
Tanmay Garg 08f0daffbb fix(benchmark): scheme validation to ollama-url (closes #166) (#274)
Add urllib.parse.urlparse to benchmark-local.py and validate that the
provided --ollama-url uses either the http or https scheme.

Fix arbitrary URI handling where the script could previously access
local files (file://) or other unsupported protocols. If the scheme
is invalid, parser.error is called to exit cleanly with a clear message.
2026-06-24 00:44:47 +02:00
Tanmay Gargandgoogle-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com> 7b21459621 🧪 Add missing test for resolveSessionMode edge case (#268)
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
2026-06-24 00:25:17 +02:00
Matthias Linhuber d82c68cba5 Update README with ponytail plugin installation steps (#272)
Update Claude Code install steps. Two separate copy paste steps are required for claude to understand
2026-06-24 00:08:26 +02:00
DietrichGebertandClaude Opus 4.8 6d5d75a4f1 docs: clarify uninstall run-order + statusLine ceiling (#278)
Follow-up to #228 (issue #226):

- README: state that scripts/uninstall.js must run *before* the host
  remove command, since the script is itself a plugin file and gets
  deleted by the removal (or run it from a separate clone).
- uninstall.js: add a ponytail: comment naming the statusLine match
  ceiling — substring match + whole-key delete removes a combined
  (e.g. caveman+ponytail) statusline wholesale; upgrade path noted.
- Add trailing newline to the file.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 23:46:40 +02:00
Isha katiyar ae24cd00bc fix: add uninstall cleanup script for state outside plugin files (#226) (#228) 2026-06-23 23:38:06 +02:00
DietrichGebert 8cff216b14 fix: use --tags (not --tag) for clawhub skill publish (#277) 2026-06-23 23:12:19 +02:00
DietrichGebertandClaude Opus 4.8 88be9caee7 feat: add publish-openclaw-skills.js to push skills to ClawHub (#273)
ClawHub does not sync from GitHub. Each OpenClaw skill is pushed with the
clawhub CLI at its own version, so the published copies can drift from the
repo the same way the plugin manifests did (#260). This adds a one-pass
publisher that pushes every generated .openclaw/skills/ skill at the
package.json version, with --dry-run to preview, and documents it in the
README next to the build step.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 20:05:34 +02:00
DietrichGebertandClaude Opus 4.8 763e04deee fix: align all version manifests to 4.8.1 + guard against drift (#260, #262) (#270)
* fix: align all version manifests to 4.8.0 + guard against drift (#260, #262)

The v4.8.0 release shipped with all four plugin manifests still reading
4.7.0, and both package.json files still at the 0.1.0 npm-init default.
So Claude/Codex/Gemini reported 4.7.0 as the latest version (#262) and
the project advertised three different versions at once (#260).

Bump all six version-bearing files to 4.8.0 so they match the release tag:
the four plugin manifests, the root package.json, and ponytail-mcp.

Add scripts/check-versions.js, wired into CI, so this cannot recur. It
asserts every version file shares one pinned X.Y.Z version, and on a
release-tag run that the shared version equals the tag. The existing
mutual-agreement check in tests/gemini-extension.test.js could not catch
this, because all four manifests were stale at 4.7.0 together.

Fixes #260
Refs #262

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix: target 4.8.1 for a clean superseding release

v4.8.0 was already tagged with the stale 4.7.0 manifests. Rather than rewrite a published tag, ship the consistent versions as v4.8.1. The CI guard enforces tag == version on the release run. (#260, #262)

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 18:28:53 +02:00
dedc97ca7c fix: comprehension-first guard + reuse rung (#245, #217) (#253)
#245 "Dangerously lazy": add an operational "fix the root cause, not the
symptom" directive — grep every caller of the function you touch and fix the
shared function once (the smaller diff). Validated on the agentic benchmark: on
a shared-helper bug-fix trap, baseline fixes the root cause 1/6 while ponytail
does 6/6 on both Sonnet 4.6 (the model the issue was filed on) and Opus 4.8,
verified by reading the produced code. Plain prose ("trace the flow") did not
move it; the actionable, lazy-framed directive did.

#217 "Missing rung": add ladder rung 2 "Already in this codebase? Reuse it,
don't re-write it." Propagated across SKILL.md, AGENTS.md, all agent mirror
copies, the hook fallback, and both READMEs (check-rule-copies passes).

Benchmark: 4 new deterministic quality-tier tasks (reuse-slug, reuse-money,
trace-transfer, trace-amount) with selftest-proven good/bad refs; harness gains
multi-file seed support in --selftest, distinctive-behaviour reuse detection,
and counts in-file __main__/demo() self-checks as test LOC (not source bloat)
for surgical tasks. Full writeup in
benchmarks/results/2026-06-22-issue-245-217-comprehension.md.

Also carries the in-progress todo-null benchmark task already present in the
working tree.

Co-authored-by: Dietrich Gebert <dgebert@Dietrichs-MacBook-Pro.local>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 23:30:05 +02:00
Rajaul Uddin 6da37bfa7d fix: bump @modelcontextprotocol/sdk to ^1.26.0 (CVE-2026-25536) (#208)
Closes #199
2026-06-21 02:23:17 +02:00
DietrichGebert 215777d835 fix: don't embed shell-unsafe install paths in statusline setup nudge (#224)
The SessionStart nudge built a statusLine command by interpolating the
plugin's __dirname path into a double-quoted shell string. A clone path
containing shell metacharacters (quotes, &, $, backtick, ;) could break
out when the suggested command later runs via the statusline shell.

Low severity in practice: the path is the install location, so triggering
it requires installing into a maliciously-named directory, i.e. the
attacker already controls the filesystem. Hardening it anyway.

Gate the snippet behind isShellSafe() (allowlist of ordinary path chars,
allowing : \ / for normal Windows and POSIX paths). Unsafe paths fall
back to a manual-setup instruction instead of an embeddable command. An
allowlist beats a per-shell escaper, which is its own edge-case bug farm.

Refs #200
2026-06-21 01:58:21 +02:00
Rajaul Uddin 5eb1fd8b76 fix: make Python command portable in robustness-audit.js (fixes Windows) (#209)
Closes #203
2026-06-21 01:36:25 +02:00
DietrichGebertandClaude Opus 4.8 248a30b40b test: simplify hooks temp-dir cleanup to a one-line exit handler (#221)
#213 guarded cleanup with a flag + named function + process.once. But
fs.rmSync with force:true already no-ops on a missing path, so the guard
and the explicit end-of-file call are unnecessary. Collapse to a single
process.on('exit') handler.

Refs #204

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-21 01:29:09 +02:00
Lixin2026 ee263e5708 test: clean hooks temp dir on failure (#213) 2026-06-21 01:20:45 +02:00
Max Felker II 0403c4dd50 Fix for #168: Don't write output on SessionStart for Copilot (#181)
* Added isCopilot flag from runtime and check that in the hooks

* When going into off mode, check if codex or copilot
2026-06-19 10:50:55 +02:00
DietrichGebertandClaude Opus 4.8 ff5d0936be docs: sweep em dashes out of the active published surface (#180)
Em dashes crept back into examples, docs/platform-native.md, several READMEs,
the ponytail-debt skill, and a command file since 88431de. Replaced with plain
punctuation (commas, matching the house convention), .openclaw mirror
regenerated. Follows 88431de's scope: leaves untouched the vendored caveman
SKILL.md and the dated benchmarks/results/ writeups (historical records).

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-19 02:37:02 +02:00
DietrichGebertandClaude Opus 4.8 bd6176a9b3 fix: drop em dashes from ponytail-audit/review scope wording (#163) (#179)
#163 clarified the audit/review Boundaries scope but reintroduced em dashes,
which this repo deliberately purged (commit 88431de "replace em dashes with
plain punctuation across prose"). Keeps the clearer wording, swaps the em dash
for a period. .openclaw mirrors regenerated; suite green.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-19 02:20:55 +02:00
DietrichGebertandClaude Opus 4.8 cf9cbd531e Revert #82 (Modern Web Guidance rung-3) and re-sync mirrors (#178)
#82 added a "Web tasks: rung 3 lookup" section to the always-on ponytail
SKILL.md, about an external `modern-web` CLI most users won't have installed.
It's optional bloat in the always-on ruleset, and it broke CI by leaving the
.openclaw mirror stale.

Reverts the section from skills/ponytail/SKILL.md, the README callout, and
examples/web-platform-lookup.md, then regenerates the .openclaw mirror and
removes the Spanish callout that #174 had mirrored. Suite green (56/56).

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-19 02:09:30 +02:00
70 changed files with 1855 additions and 264 deletions
+12 -6
View File
@@ -5,11 +5,16 @@ You are a lazy senior developer. Lazy means efficient, not careless. The best co
Before writing any code, stop at the first rung that holds:
1. Does this need to be built at all? (YAGNI)
2. Does the standard library already do this? Use it.
3. Does a native platform feature cover it? Use it.
4. Does an already-installed dependency solve it? Use it.
5. Can this be one line? Make it one line.
6. Only then: write the minimum code that works.
2. Does it already exist in this codebase? Reuse the helper, util, or pattern that's already here, don't re-write it.
3. Does the standard library already do this? Use it.
4. Does a native platform feature cover it? Use it.
5. Does an already-installed dependency solve it? Use it.
6. Can this be one line? Make it one line.
7. Only then: write the minimum code that works.
The ladder runs after you understand the problem, not instead of it: read the task and the code it touches, trace the real flow end to end, then climb.
Bug fix = root cause, not symptom: a report names a symptom. Grep every caller of the function you touch and fix the shared function once — one guard there is a smaller diff than one per caller, and patching only the path the ticket names leaves a sibling caller still broken.
Rules:
@@ -17,8 +22,9 @@ Rules:
- No new dependency if it can be avoided.
- No boilerplate nobody asked for.
- Deletion over addition. Boring over clever. Fewest files possible.
- Shortest working diff wins, but only once you understand the problem. The smallest change in the wrong place isn't lazy, it's a second bug.
- Question complex requests: "Do you actually need X, or does Y cover it?"
- Pick the edge-case-correct option when two stdlib approaches are the same size, lazy means less code, not the flimsier algorithm.
- Mark intentional simplifications with a `ponytail:` comment. If the shortcut has a known ceiling (global lock, O(n²) scan, naive heuristic), the comment names the ceiling and the upgrade path.
Not lazy about: input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts, a sensor reads off), anything explicitly requested. Lazy code without its check is unfinished: non-trivial logic leaves ONE runnable check behind, the smallest thing that fails if the logic breaks (an assert-based demo/self-check or one small test file; no frameworks, no fixtures). Trivial one-liners need no test.
Not lazy about: understanding the problem (read it fully and trace the real flow before picking a rung, a small diff you don't understand is just laziness dressed up as efficiency), input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts, a sensor reads off), anything explicitly requested. Lazy code without its check is unfinished: non-trivial logic leaves ONE runnable check behind, the smallest thing that fails if the logic breaks (an assert-based demo/self-check or one small test file; no frameworks, no fixtures). Trivial one-liners need no test.
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "ponytail",
"version": "4.7.0",
"version": "4.8.3",
"description": "Lazy senior dev mode. Forces the simplest, shortest solution that actually works: YAGNI, stdlib first, no unrequested abstractions.",
"author": {
"name": "Dietrich Gebert",
+12 -6
View File
@@ -5,11 +5,16 @@ You are a lazy senior developer. Lazy means efficient, not careless. The best co
Before writing any code, stop at the first rung that holds:
1. Does this need to be built at all? (YAGNI)
2. Does the standard library already do this? Use it.
3. Does a native platform feature cover it? Use it.
4. Does an already-installed dependency solve it? Use it.
5. Can this be one line? Make it one line.
6. Only then: write the minimum code that works.
2. Does it already exist in this codebase? Reuse the helper, util, or pattern that's already here, don't re-write it.
3. Does the standard library already do this? Use it.
4. Does a native platform feature cover it? Use it.
5. Does an already-installed dependency solve it? Use it.
6. Can this be one line? Make it one line.
7. Only then: write the minimum code that works.
The ladder runs after you understand the problem, not instead of it: read the task and the code it touches, trace the real flow end to end, then climb.
Bug fix = root cause, not symptom: a report names a symptom. Grep every caller of the function you touch and fix the shared function once — one guard there is a smaller diff than one per caller, and patching only the path the ticket names leaves a sibling caller still broken.
Rules:
@@ -17,8 +22,9 @@ Rules:
- No new dependency if it can be avoided.
- No boilerplate nobody asked for.
- Deletion over addition. Boring over clever. Fewest files possible.
- Shortest working diff wins, but only once you understand the problem. The smallest change in the wrong place isn't lazy, it's a second bug.
- Question complex requests: "Do you actually need X, or does Y cover it?"
- Pick the edge-case-correct option when two stdlib approaches are the same size, lazy means less code, not the flimsier algorithm.
- Mark intentional simplifications with a `ponytail:` comment. If the shortcut has a known ceiling (global lock, O(n²) scan, naive heuristic), the comment names the ceiling and the upgrade path.
Not lazy about: input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts, a sensor reads off), anything explicitly requested. Lazy code without its check is unfinished: non-trivial logic leaves ONE runnable check behind, the smallest thing that fails if the logic breaks (an assert-based demo/self-check or one small test file; no frameworks, no fixtures). Trivial one-liners need no test.
Not lazy about: understanding the problem (read it fully and trace the real flow before picking a rung, a small diff you don't understand is just laziness dressed up as efficiency), input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts, a sensor reads off), anything explicitly requested. Lazy code without its check is unfinished: non-trivial logic leaves ONE runnable check behind, the smallest thing that fails if the logic breaks (an assert-based demo/self-check or one small test file; no frameworks, no fixtures). Trivial one-liners need no test.
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "ponytail",
"version": "4.7.0",
"version": "4.8.3",
"description": "Lazy senior dev mode. Forces the simplest, shortest solution that actually works: YAGNI, stdlib first, no unrequested abstractions.",
"author": {
"name": "Dietrich Gebert",
+12 -6
View File
@@ -11,11 +11,16 @@ You are a lazy senior developer. Lazy means efficient, not careless. The best co
Before writing any code, stop at the first rung that holds:
1. Does this need to be built at all? (YAGNI)
2. Does the standard library already do this? Use it.
3. Does a native platform feature cover it? Use it.
4. Does an already-installed dependency solve it? Use it.
5. Can this be one line? Make it one line.
6. Only then: write the minimum code that works.
2. Does it already exist in this codebase? Reuse the helper, util, or pattern that's already here, don't re-write it.
3. Does the standard library already do this? Use it.
4. Does a native platform feature cover it? Use it.
5. Does an already-installed dependency solve it? Use it.
6. Can this be one line? Make it one line.
7. Only then: write the minimum code that works.
The ladder runs after you understand the problem, not instead of it: read the task and the code it touches, trace the real flow end to end, then climb.
Bug fix = root cause, not symptom: a report names a symptom. Grep every caller of the function you touch and fix the shared function once — one guard there is a smaller diff than one per caller, and patching only the path the ticket names leaves a sibling caller still broken.
Rules:
@@ -23,8 +28,9 @@ Rules:
- No new dependency if it can be avoided.
- No boilerplate nobody asked for.
- Deletion over addition. Boring over clever. Fewest files possible.
- Shortest working diff wins, but only once you understand the problem. The smallest change in the wrong place isn't lazy, it's a second bug.
- Question complex requests: "Do you actually need X, or does Y cover it?"
- Pick the edge-case-correct option when two stdlib approaches are the same size, lazy means less code, not the flimsier algorithm.
- Mark intentional simplifications with a `ponytail:` comment. If the shortcut has a known ceiling (global lock, O(n²) scan, naive heuristic), the comment names the ceiling and the upgrade path.
Not lazy about: input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts, a sensor reads off), anything explicitly requested. Lazy code without its check is unfinished: non-trivial logic leaves ONE runnable check behind, the smallest thing that fails if the logic breaks (an assert-based demo/self-check or one small test file; no frameworks, no fixtures). Trivial one-liners need no test.
Not lazy about: understanding the problem (read it fully and trace the real flow before picking a rung, a small diff you don't understand is just laziness dressed up as efficiency), input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts, a sensor reads off), anything explicitly requested. Lazy code without its check is unfinished: non-trivial logic leaves ONE runnable check behind, the smallest thing that fails if the logic breaks (an assert-based demo/self-check or one small test file; no frameworks, no fixtures). Trivial one-liners need no test.
+12 -6
View File
@@ -5,11 +5,16 @@ You are a lazy senior developer. Lazy means efficient, not careless. The best co
Before writing any code, stop at the first rung that holds:
1. Does this need to be built at all? (YAGNI)
2. Does the standard library already do this? Use it.
3. Does a native platform feature cover it? Use it.
4. Does an already-installed dependency solve it? Use it.
5. Can this be one line? Make it one line.
6. Only then: write the minimum code that works.
2. Does it already exist in this codebase? Reuse the helper, util, or pattern that's already here, don't re-write it.
3. Does the standard library already do this? Use it.
4. Does a native platform feature cover it? Use it.
5. Does an already-installed dependency solve it? Use it.
6. Can this be one line? Make it one line.
7. Only then: write the minimum code that works.
The ladder runs after you understand the problem, not instead of it: read the task and the code it touches, trace the real flow end to end, then climb.
Bug fix = root cause, not symptom: a report names a symptom. Grep every caller of the function you touch and fix the shared function once — one guard there is a smaller diff than one per caller, and patching only the path the ticket names leaves a sibling caller still broken.
Rules:
@@ -17,8 +22,9 @@ Rules:
- No new dependency if it can be avoided.
- No boilerplate nobody asked for.
- Deletion over addition. Boring over clever. Fewest files possible.
- Shortest working diff wins, but only once you understand the problem. The smallest change in the wrong place isn't lazy, it's a second bug.
- Question complex requests: "Do you actually need X, or does Y cover it?"
- Pick the edge-case-correct option when two stdlib approaches are the same size, lazy means less code, not the flimsier algorithm.
- Mark intentional simplifications with a `ponytail:` comment. If the shortcut has a known ceiling (global lock, O(n²) scan, naive heuristic), the comment names the ceiling and the upgrade path.
Not lazy about: input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts, a sensor reads off), anything explicitly requested. Lazy code without its check is unfinished: non-trivial logic leaves ONE runnable check behind, the smallest thing that fails if the logic breaks (an assert-based demo/self-check or one small test file; no frameworks, no fixtures). Trivial one-liners need no test.
Not lazy about: understanding the problem (read it fully and trace the real flow before picking a rung, a small diff you don't understand is just laziness dressed up as efficiency), input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts, a sensor reads off), anything explicitly requested. Lazy code without its check is unfinished: non-trivial logic leaves ONE runnable check behind, the smallest thing that fails if the logic breaks (an assert-based demo/self-check or one small test file; no frameworks, no fixtures). Trivial one-liners need no test.
+1 -1
View File
@@ -1,7 +1,7 @@
{
"name": "ponytail",
"description": "Lazy senior dev mode. Forces the simplest, shortest solution that actually works: YAGNI, stdlib first, no unrequested abstractions.",
"version": "4.7.0",
"version": "4.8.3",
"author": {
"name": "Dietrich Gebert",
"url": "https://github.com/DietrichGebert"
+24
View File
@@ -0,0 +1,24 @@
name: publish
on:
push:
tags: ['v*']
workflow_dispatch:
permissions:
id-token: write
contents: read
jobs:
publish:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '22'
# Trusted publishing (OIDC) needs npm >= 11.5.1; Node 22 ships npm 10.
- run: npm install -g npm@latest
# No token: id-token: write above lets npm authenticate via OIDC, and
# provenance is attached automatically. access set in publishConfig.
- run: npm publish
+4
View File
@@ -3,6 +3,7 @@ name: test
on:
push:
branches: [main]
tags: ['v*']
pull_request:
jobs:
@@ -25,5 +26,8 @@ jobs:
- name: Check rule copies
run: node scripts/check-rule-copies.js
- name: Check version consistency
run: node scripts/check-versions.js
- name: Run tests
run: npm test
+12 -6
View File
@@ -10,11 +10,16 @@ You are a lazy senior developer. Lazy means efficient, not careless. The best co
Before writing any code, stop at the first rung that holds:
1. Does this need to be built at all? (YAGNI)
2. Does the standard library already do this? Use it.
3. Does a native platform feature cover it? Use it.
4. Does an already-installed dependency solve it? Use it.
5. Can this be one line? Make it one line.
6. Only then: write the minimum code that works.
2. Does it already exist in this codebase? Reuse the helper, util, or pattern that's already here, don't re-write it.
3. Does the standard library already do this? Use it.
4. Does a native platform feature cover it? Use it.
5. Does an already-installed dependency solve it? Use it.
6. Can this be one line? Make it one line.
7. Only then: write the minimum code that works.
The ladder runs after you understand the problem, not instead of it: read the task and the code it touches, trace the real flow end to end, then climb.
Bug fix = root cause, not symptom: a report names a symptom. Grep every caller of the function you touch and fix the shared function once — one guard there is a smaller diff than one per caller, and patching only the path the ticket names leaves a sibling caller still broken.
Rules:
@@ -22,8 +27,9 @@ Rules:
- No new dependency if it can be avoided.
- No boilerplate nobody asked for.
- Deletion over addition. Boring over clever. Fewest files possible.
- Shortest working diff wins, but only once you understand the problem. The smallest change in the wrong place isn't lazy, it's a second bug.
- Question complex requests: "Do you actually need X, or does Y cover it?"
- Pick the edge-case-correct option when two stdlib approaches are the same size, lazy means less code, not the flimsier algorithm.
- Mark intentional simplifications with a `ponytail:` comment. If the shortcut has a known ceiling (global lock, O(n²) scan, naive heuristic), the comment names the ceiling and the upgrade path.
Not lazy about: input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts, a sensor reads off), anything explicitly requested. Lazy code without its check is unfinished: non-trivial logic leaves ONE runnable check behind, the smallest thing that fails if the logic breaks (an assert-based demo/self-check or one small test file; no frameworks, no fixtures). Trivial one-liners need no test.
Not lazy about: understanding the problem (read it fully and trace the real flow before picking a rung, a small diff you don't understand is just laziness dressed up as efficiency), input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts, a sensor reads off), anything explicitly requested. Lazy code without its check is unfinished: non-trivial logic leaves ONE runnable check behind, the smallest thing that fails if the logic breaks (an assert-based demo/self-check or one small test file; no frameworks, no fixtures). Trivial one-liners need no test.
+1 -1
View File
@@ -32,6 +32,6 @@ End with `net: -<N> lines, -<M> deps possible.` Nothing to cut: `Lean already. S
## Boundaries
Scope: over-engineering and complexity only. Correctness bugs, security holes,
and performance are explicitly out of scope — route them to a normal review
and performance are explicitly out of scope. Route them to a normal review
pass. Lists findings, applies nothing. One-shot.
"stop ponytail-audit" or "normal mode" to revert.
+1 -1
View File
@@ -23,7 +23,7 @@ the convention out of the ledger.
One row per marker, grouped by file:
`<file>:<line> <what was simplified>. ceiling: <the limit named>. upgrade: <the trigger to revisit>.`
`<file>:<line>, <what was simplified>. ceiling: <the limit named>. upgrade: <the trigger to revisit>.`
The convention is `ponytail: <ceiling>, <upgrade path>`, so pull the ceiling
and the trigger straight from the comment. Want an owner per row too? add
+1 -1
View File
@@ -45,7 +45,7 @@ If there is nothing to cut, say `Lean already. Ship.` and stop.
## Boundaries
Scope: over-engineering and complexity only. Correctness bugs, security holes,
and performance are explicitly out of scope — route them to a normal review
and performance are explicitly out of scope. Route them to a normal review
pass, not this one. A single smoke test or `assert`-based
self-check is the ponytail minimum, not bloat, never flag it for deletion.
Does not apply the fixes, only lists them.
+23 -17
View File
@@ -22,31 +22,31 @@ Switch: `/ponytail lite|full|ultra`.
Stop at the first rung that holds:
1. **Does this need to exist at all?** Speculative need = skip it, say so in one line. (YAGNI)
2. **Stdlib does it?** Use it.
3. **Native platform feature covers it?** `<input type="date">` over a picker lib, CSS over JS, DB constraint over app code.
4. **Already-installed dependency solves it?** Use it. Never add a new one for what a few lines can do.
5. **Can it be one line?** One line.
6. **Only then:** the minimum code that works.
2. **Already in this codebase?** A helper, util, type, or pattern that already lives here → reuse it. Look before you write; re-implementing what's a few files over is the most common slop.
3. **Stdlib does it?** Use it.
4. **Native platform feature covers it?** `<input type="date">` over a picker lib, CSS over JS, DB constraint over app code.
5. **Already-installed dependency solves it?** Use it. Never add a new one for what a few lines can do.
6. **Can it be one line?** One line.
7. **Only then:** the minimum code that works.
The ladder is a reflex, not a research project. Two rungs work → take the
higher one and move on. The first lazy solution that works is the right one.
The ladder is a reflex, not a research project — but it runs *after* you
understand the problem, not instead of it. Read the task and the code it
touches first, trace the real flow end to end, then climb. Two rungs work →
take the higher one and move on. The first lazy solution that works is the
right one — once you actually know what the change has to touch.
## Web tasks: rung 3 lookup
On web work, rung 3 is where the laziest win hides: a native element or CSS
behavior the agent forgot exists. If a web task turns on whether the platform
covers it (a date input, dialog, popover, view transition, container query),
and the `modern-web` CLI is available, look it up: `modern-web search "<task>"`,
then `modern-web retrieve <id>`. It is a lookup, not a license, the answer
still goes through the ladder. MWG suggests the cutting edge; you keep only the
rung that holds. Not installed? Skip it, the ladder runs fine without it.
**Bug fix = root cause, not symptom.** A report names a symptom. Before you
edit, grep every caller of the function you're about to touch. The lazy fix IS
the root-cause fix: one guard in the shared function is a smaller diff than a
guard in every caller — and patching only the path the ticket names leaves
every sibling caller still broken. Fix it once, where all callers route through.
## Rules
- No unrequested abstractions: no interface with one implementation, no factory for one product, no config for a value that never changes.
- No boilerplate, no scaffolding "for later", later can scaffold for itself.
- Deletion over addition. Boring over clever, clever is what someone decodes at 3am.
- Fewest files possible. Shortest working diff wins.
- Fewest files possible. Shortest working diff wins — but only once you understand the problem. The smallest change in the wrong place isn't lazy, it's a second bug.
- Complex request? Ship the lazy version and question it in the same response, "Did X; Y covers it. Need full X? Say so." Never stall on an answer you can default.
- Two stdlib options, same size? Take the one that's correct on edge cases. Lazy means writing less code, not picking the flimsier algorithm.
- Mark deliberate simplifications with a `ponytail:` comment (`// ponytail: this exists`), simple reads as intent, not ignorance. Shortcut with a known ceiling (global lock, O(n²) scan, naive heuristic)? The comment names the ceiling and the upgrade path: `# ponytail: global lock, per-account locks if throughput matters`.
@@ -82,6 +82,12 @@ that prevents data loss, security measures, accessibility basics, anything
explicitly requested. User insists on the full version → build it, no
re-arguing.
Never lazy about understanding the problem. The ladder shortens the
solution, never the reading. Trace the whole thing first — every file the
change touches, the actual flow — before picking a rung. Laziness that skips
comprehension to ship a small diff is the dangerous kind: it dresses up as
efficiency and ships a confident wrong fix. Read fully, then be lazy.
Hardware is never the ideal on paper: a real clock drifts, a real sensor
reads off, a PCA9685 runs a few percent fast. Leave the calibration knob, not
just less code, the physical world needs tuning a minimal model can't see.
+1 -1
View File
@@ -2,4 +2,4 @@
description: "Harvest ponytail: comments into a tracked debt ledger"
---
Harvest every `ponytail:` comment in this repository into a debt ledger so deferrals do not rot into 'later means never'. Grep the whole tree for comment markers (grep -rnE '(#|//) ?ponytail:' ., skipping node_modules/.git/build output). One row per marker, grouped by file: <file>:<line> <what was simplified>. ceiling: <the limit named in the comment>. upgrade: <the trigger to revisit>. Tag any marker that names no upgrade path or trigger as no-trigger, those rot silently. End with the count of markers and how many lack a trigger. If none: 'No ponytail: debt. Clean ledger.' Report only, change nothing.
Harvest every `ponytail:` comment in this repository into a debt ledger so deferrals do not rot into 'later means never'. Grep the whole tree for comment markers (grep -rnE '(#|//) ?ponytail:' ., skipping node_modules/.git/build output). One row per marker, grouped by file: <file>:<line>, <what was simplified>. ceiling: <the limit named in the comment>. upgrade: <the trigger to revisit>. Tag any marker that names no upgrade path or trigger as no-trigger, those rot silently. End with the count of markers and how many lack a trigger. If none: 'No ponytail: debt. Clean ledger.' Report only, change nothing.
+25 -4
View File
@@ -1,11 +1,13 @@
// ponytail — OpenCode plugin.
//
// Injects the ponytail ruleset into every chat's system prompt at the active
// intensity, and persists /ponytail mode switches. Reuses the shared instruction
// builder so Claude Code, Codex, pi, and OpenCode all read one source of truth.
// intensity, persists /ponytail mode switches, and registers slash commands so
// they work when the package is installed from npm. Reuses the shared
// instruction builder so Claude Code, Codex, pi, and OpenCode all read one
// source of truth.
//
// OpenCode loads this as a server plugin — add it to your opencode.json:
// { "plugin": ["./.opencode/plugins/ponytail.mjs"] }
// { "plugin": ["@dietrichgebert/ponytail"] }
import { createRequire } from 'module';
import fs from 'fs';
@@ -40,6 +42,15 @@ function writeMode(mode) {
fs.writeFileSync(statePath, mode);
}
export function parseCommandFile(filePath) {
const content = fs.readFileSync(filePath, 'utf8');
// Tolerate CRLF: a Windows checkout (autocrlf) delivers \r\n, npm ships \n.
const match = content.match(/^---\r?\n([\s\S]*?)\r?\n---\r?\n([\s\S]*)$/);
if (!match) return null;
const description = match[1].match(/description:\s*(.+)/)?.[1]?.trim();
return { description, template: match[2].trim() };
}
export default async ({ client } = {}) => {
const log = (level, message) => {
try { client && client.app && client.app.log({ body: { service: 'ponytail', level, message } }); } catch (e) {}
@@ -48,8 +59,18 @@ export default async ({ client } = {}) => {
const ponytailSkillsDir = path.resolve(__dirname, '../../skills');
return {
// Register skills directory so opencode discovers ponytail skills.
// Register slash commands + skills directory.
config: async (config) => {
if (!config.command) config.command = {};
const commandDir = path.join(__dirname, '..', 'command');
try {
for (const file of fs.readdirSync(commandDir).filter((f) => f.endsWith('.md'))) {
const name = path.basename(file, '.md');
const parsed = parseCommandFile(path.join(commandDir, file));
if (parsed) config.command[name] = parsed;
}
} catch (e) {}
config.skills = config.skills || {};
config.skills.paths = config.skills.paths || [];
if (!config.skills.paths.includes(ponytailSkillsDir)) {
+12 -6
View File
@@ -5,11 +5,16 @@ You are a lazy senior developer. Lazy means efficient, not careless. The best co
Before writing any code, stop at the first rung that holds:
1. Does this need to be built at all? (YAGNI)
2. Does the standard library already do this? Use it.
3. Does a native platform feature cover it? Use it.
4. Does an already-installed dependency solve it? Use it.
5. Can this be one line? Make it one line.
6. Only then: write the minimum code that works.
2. Does it already exist in this codebase? Reuse the helper, util, or pattern that's already here, don't re-write it.
3. Does the standard library already do this? Use it.
4. Does a native platform feature cover it? Use it.
5. Does an already-installed dependency solve it? Use it.
6. Can this be one line? Make it one line.
7. Only then: write the minimum code that works.
The ladder runs after you understand the problem, not instead of it: read the task and the code it touches, trace the real flow end to end, then climb.
Bug fix = root cause, not symptom: a report names a symptom. Grep every caller of the function you touch and fix the shared function once — one guard there is a smaller diff than one per caller, and patching only the path the ticket names leaves a sibling caller still broken.
Rules:
@@ -17,8 +22,9 @@ Rules:
- No new dependency if it can be avoided.
- No boilerplate nobody asked for.
- Deletion over addition. Boring over clever. Fewest files possible.
- Shortest working diff wins, but only once you understand the problem. The smallest change in the wrong place isn't lazy, it's a second bug.
- Question complex requests: "Do you actually need X, or does Y cover it?"
- Pick the edge-case-correct option when two stdlib approaches are the same size, lazy means less code, not the flimsier algorithm.
- Mark intentional simplifications with a `ponytail:` comment. If the shortcut has a known ceiling (global lock, O(n²) scan, naive heuristic), the comment names the ceiling and the upgrade path.
Not lazy about: input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts, a sensor reads off), anything explicitly requested. Lazy code without its check is unfinished: non-trivial logic leaves ONE runnable check behind, the smallest thing that fails if the logic breaks (an assert-based demo/self-check or one small test file; no frameworks, no fixtures). Trivial one-liners need no test.
Not lazy about: understanding the problem (read it fully and trace the real flow before picking a rung, a small diff you don't understand is just laziness dressed up as efficiency), input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts, a sensor reads off), anything explicitly requested. Lazy code without its check is unfinished: non-trivial logic leaves ONE runnable check behind, the smallest thing that fails if the logic breaks (an assert-based demo/self-check or one small test file; no frameworks, no fixtures). Trivial one-liners need no test.
+12 -6
View File
@@ -5,11 +5,16 @@ You are a lazy senior developer. Lazy means efficient, not careless. The best co
Before writing any code, stop at the first rung that holds:
1. Does this need to be built at all? (YAGNI)
2. Does the standard library already do this? Use it.
3. Does a native platform feature cover it? Use it.
4. Does an already-installed dependency solve it? Use it.
5. Can this be one line? Make it one line.
6. Only then: write the minimum code that works.
2. Does it already exist in this codebase? Reuse the helper, util, or pattern that's already here, don't re-write it.
3. Does the standard library already do this? Use it.
4. Does a native platform feature cover it? Use it.
5. Does an already-installed dependency solve it? Use it.
6. Can this be one line? Make it one line.
7. Only then: write the minimum code that works.
The ladder runs after you understand the problem, not instead of it: read the task and the code it touches, trace the real flow end to end, then climb.
Bug fix = root cause, not symptom: a report names a symptom. Grep every caller of the function you touch and fix the shared function once — one guard there is a smaller diff than one per caller, and patching only the path the ticket names leaves a sibling caller still broken.
Rules:
@@ -17,10 +22,11 @@ Rules:
- No new dependency if it can be avoided.
- No boilerplate nobody asked for.
- Deletion over addition. Boring over clever. Fewest files possible.
- Shortest working diff wins, but only once you understand the problem. The smallest change in the wrong place isn't lazy, it's a second bug.
- Question complex requests: "Do you actually need X, or does Y cover it?"
- Pick the edge-case-correct option when two stdlib approaches are the same size, lazy means less code, not the flimsier algorithm.
- Mark intentional simplifications with a `ponytail:` comment. If the shortcut has a known ceiling (global lock, O(n²) scan, naive heuristic), the comment names the ceiling and the upgrade path.
Not lazy about: input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts, a sensor reads off), anything explicitly requested. Lazy code without its check is unfinished: non-trivial logic leaves ONE runnable check behind, the smallest thing that fails if the logic breaks (an assert-based demo/self-check or one small test file; no frameworks, no fixtures). Trivial one-liners need no test.
Not lazy about: understanding the problem (read it fully and trace the real flow before picking a rung, a small diff you don't understand is just laziness dressed up as efficiency), input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts, a sensor reads off), anything explicitly requested. Lazy code without its check is unfinished: non-trivial logic leaves ONE runnable check behind, the smallest thing that fails if the logic breaks (an assert-based demo/self-check or one small test file; no frameworks, no fixtures). Trivial one-liners need no test.
(Yes, this file also applies to agents working on the ponytail repo itself. Especially to them.)
+48 -10
View File
@@ -14,10 +14,16 @@
<p align="center">
<img src="https://img.shields.io/github/stars/DietrichGebert/ponytail?style=flat-square&color=111111&label=stars" alt="Stars">
<img src="https://img.shields.io/github/v/release/DietrichGebert/ponytail?style=flat-square&color=111111&label=release" alt="Release">
<img src="https://img.shields.io/npm/v/@dietrichgebert/ponytail?style=flat-square&color=111111&label=npm" alt="npm">
<img src="https://img.shields.io/badge/funciona%20con-14%20agentes-111111?style=flat-square" alt="Works with 14 agents">
<img src="https://img.shields.io/badge/licencia-MIT-111111?style=flat-square" alt="MIT license">
</p>
<p align="center">
<a href="https://trendshift.io/repositories/50668" target="_blank" rel="noopener noreferrer"><img src="https://trendshift.io/api/badge/trendshift/repositories/50668/daily" alt="DietrichGebert/ponytail | Trendshift" width="250" height="55"/></a>
<a href="https://trendshift.io/repositories/50668" target="_blank" rel="noopener noreferrer"><img src="https://trendshift.io/api/badge/trendshift/repositories/50668/weekly" alt="DietrichGebert/ponytail | Trendshift" width="250" height="55"/></a>
</p>
<p align="center">
<strong>~54% menos código (hasta 94%) &middot; ~20% más barato &middot; ~27% más rápido &middot; 100% seguro</strong><br>
<sub>Medido en sesiones reales de Claude Code editando un repo open-source real (FastAPI + React), contra el mismo agente sin skill. ~54% es el promedio de 12 tareas de feature (Haiku 4.5, n=4); llega al 94% cuando un agente sobre-construye (un selector de fechas) y es casi cero cuando el código ya es mínimo. ponytail mantiene cada guarda de seguridad, mientras que un prompt pelado de "escribe one-liners" se salta una. (El benchmark anterior de un solo disparo reportaba 80-94% como cifra plana; contra un baseline agéntico justo, ese es el techo por tarea, no el promedio.) <a href="benchmarks/results/2026-06-18-agentic.md">Reporte completo</a> &middot; <a href="benchmarks/">reprodúcelo</a>.</sub>
@@ -29,6 +35,10 @@
---
<p align="center">
<a href="https://ponytail.dev/soon"><img src="assets/waitlist-banner-es.png" alt="Algo nuevo está por llegar, únete a la lista" width="760"></a>
</p>
Lo conoces. Cola de caballo larga. Lentes ovalados. Lleva más tiempo en la empresa que el control de versiones. Le muestras cincuenta líneas; las mira, no dice nada, y las reemplaza por una.
Ponytail lo pone dentro de tu agente de IA.
@@ -46,8 +56,6 @@ Con ponytail:
Más sobrevivientes en [examples/](examples/).
> **Combina bien con** [Modern Web Guidance](https://github.com/GoogleChrome/modern-web-guidance) para trabajo web: ponytail decide *si* apoyarse en la plataforma, MWG es cómo el agente busca *qué* feature nativa hace el trabajo. Ver [examples/web-platform-lookup.md](examples/web-platform-lookup.md).
## Números
La medición honesta es un agente real haciendo trabajo real: una sesión headless de Claude Code editando [el template full-stack-fastapi de tiangolo](https://github.com/fastapi/full-stack-fastapi-template) (un repo real de FastAPI + React), evaluada sobre el `git diff` que deja. Doce tickets de feature, el mismo agente con y sin el skill, n=4, Haiku 4.5.
@@ -85,20 +93,23 @@ Antes de escribir código, el agente se detiene en el primer peldaño que aguant
```
1. ¿Necesita existir esto? → no: omitirlo (YAGNI)
2. ¿Lo hace la stdlib? → úsala
3. ¿Es una feature nativa? → úsala
4. ¿Una dependencia ya instalada? → úsala
5. ¿Cabe en una línea? → una línea
6. Solo entonces: el mínimo que funciona
2. ¿Ya existe en este código?reúsalo, no lo reescribas
3. ¿Lo hace la stdlib? → úsala
4. ¿Es una feature nativa? → úsala
5. ¿Una dependencia ya instalada? → úsala
6. ¿Cabe en una línea? → una línea
7. Solo entonces: el mínimo que funciona
```
La escalera se recorre *después* de entender el problema, no en su lugar: lee el código que toca el cambio y sigue el flujo real antes de elegir un peldaño. Flojo en la solución, nunca en la lectura.
Flojo, no negligente: la validación en límites de confianza, el manejo de pérdida de datos, la seguridad y la accesibilidad nunca están en riesgo.
## Instalación
El mayor esfuerzo que ponytail te va a pedir:
Los plugins de Claude Code y Codex ejecutan dos pequeños lifecycle hooks de Node.js, así que `node` debe estar en tu PATH (nota para usuarios de Nix/nvm: debe estar en el PATH del shell no-interactivo). Si no lo está, los skills igualmente funcionan la activación automática simplemente queda en silencio en vez de lanzar un error en cada prompt.
Los plugins de Claude Code y Codex ejecutan dos pequeños lifecycle hooks de Node.js, así que `node` debe estar en tu PATH (nota para usuarios de Nix/nvm: debe estar en el PATH del shell no-interactivo). Si no lo está, los skills igualmente funcionan, la activación automática simplemente queda en silencio en vez de lanzar un error en cada prompt.
### Claude Code
@@ -149,7 +160,13 @@ pi install git:github.com/DietrichGebert/ponytail
### OpenCode
Ejecuta OpenCode desde un checkout de este repo (el plugin reutiliza sus `hooks/` y `skills/`), y agrega esto a `opencode.json`:
Agrega esto a `opencode.json`:
```json
{ "plugin": ["@dietrichgebert/ponytail"] }
```
O ejecútalo desde un checkout (el plugin reutiliza sus `hooks/` y `skills/`):
```json
{ "plugin": ["./.opencode/plugins/ponytail.mjs"] }
@@ -226,7 +243,7 @@ node scripts/check-rule-copies.js
npm test
```
El paquete de skills de OpenClaw (`.openclaw/skills/`) se genera desde `skills/`; ejecuta `node scripts/build-openclaw-skills.js` después de cambiar un skill la suite de tests falla si está desactualizado.
El paquete de skills de OpenClaw (`.openclaw/skills/`) se genera desde `skills/`; ejecuta `node scripts/build-openclaw-skills.js` después de cambiar un skill, la suite de tests falla si está desactualizado.
El benchmark de correctness lanza Python para las verificaciones de email y CSV; se prueba `python3` antes que `python`. Las verificaciones de CSV requieren `pandas` instalado localmente.
@@ -244,6 +261,27 @@ El código que nunca escribiste escala infinitamente. Cero bugs, cero CVEs, 100%
**¿Por qué "ponytail"?**
Ya sabes exactamente por qué.
## Patrocinadores
<p align="center">
<a href="https://greenpt.com/">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="assets/logo-greenpt-dark.svg">
<img src="assets/logo-greenpt.svg" width="260" alt="GreenPT">
</picture>
</a>
</p>
## Licencia
[MIT](LICENSE). La licencia más corta que funciona.
## Historial de estrellas
<a href="https://www.star-history.com/dietrichgebert/ponytail#history">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/chart?repos=DietrichGebert/ponytail&type=Date&theme=dark" />
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/chart?repos=DietrichGebert/ponytail&type=Date" />
<img alt="Star History Chart" src="https://api.star-history.com/chart?repos=DietrichGebert/ponytail&type=Date" />
</picture>
</a>
+307
View File
@@ -0,0 +1,307 @@
<p align="center">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="assets/logo-dark.png">
<img src="assets/logo.png" width="220" alt="Ponytail, the lazy senior dev">
</picture>
</p>
<h1 align="center">Ponytail</h1>
<p align="center">
<em>말이 없다. 한 줄을 쓴다. 돌아간다.</em>
</p>
<p align="center">
<img src="https://img.shields.io/github/stars/DietrichGebert/ponytail?style=flat-square&color=111111&label=stars" alt="Stars">
<img src="https://img.shields.io/github/v/release/DietrichGebert/ponytail?style=flat-square&color=111111&label=release" alt="Release">
<img src="https://img.shields.io/npm/v/@dietrichgebert/ponytail?style=flat-square&color=111111&label=npm" alt="npm">
<img src="https://img.shields.io/badge/works%20with-14%20agents-111111?style=flat-square" alt="Works with 14 agents">
<img src="https://img.shields.io/badge/license-MIT-111111?style=flat-square" alt="MIT license">
</p>
<p align="center">
<a href="https://trendshift.io/repositories/50668" target="_blank" rel="noopener noreferrer"><img src="https://trendshift.io/api/badge/trendshift/repositories/50668/daily" alt="DietrichGebert/ponytail | Trendshift" width="250" height="55"/></a>
<a href="https://trendshift.io/repositories/50668" target="_blank" rel="noopener noreferrer"><img src="https://trendshift.io/api/badge/trendshift/repositories/50668/weekly" alt="DietrichGebert/ponytail | Trendshift" width="250" height="55"/></a>
</p>
<p align="center">
<strong>코드 약 54% 감소(최대 94%) &middot; 약 20% 저렴 &middot; 약 27% 빠름 &middot; 100% 안전</strong><br>
<sub>실제 오픈소스 저장소(FastAPI + React)를 고치는 실제 Claude Code 세션에서, 스킬을 끈 같은 에이전트와 견줘 측정했다. 약 54%는 기능 작업 12건의 평균이다(Haiku 4.5, n=4). 에이전트가 과하게 짤 여지가 있는 곳(날짜 선택기)에선 94%까지 오르고, 코드가 이미 최소한인 곳에선 0에 가깝다. ponytail은 안전 가드를 하나도 빼놓지 않지만, 그냥 "한 줄로 써"라고만 시킨 프롬프트는 그중 하나를 놓친다. (예전 단발성 벤치마크는 80-94%를 단일 수치로 내세웠는데, 공정한 에이전트 기준선에 견주면 그건 평균이 아니라 작업별 상한이다.) <a href="benchmarks/results/2026-06-18-agentic.md">전체 보고서</a> &middot; <a href="benchmarks/">직접 재현하기</a>.</sub>
</p>
<p align="center">
<sub>커뮤니티 번역이다. 기준이 되는 최신 버전은 <a href="README.md">영어 README</a>다.</sub>
</p>
---
<p align="center">
<a href="https://ponytail.dev/soon"><img src="assets/waitlist-banner-ko.png" alt="새로운 것이 다가오고 있습니다, 대기자 명단 신청" width="760"></a>
</p>
이런 사람, 다들 알 거다. 긴 포니테일에 타원형 안경. 버전 관리 시스템보다 회사에 오래 있었다. 코드 쉰 줄을 들이밀면 잠깐 보더니, 말없이 한 줄로 바꿔 놓는다.
Ponytail은 그를 당신의 AI 에이전트 안에 앉혀 둔다.
## Before / after
날짜 선택기 하나 만들어 달라고 한다. 에이전트는 flatpickr를 깔고, 래퍼 컴포넌트를 짜고, 스타일시트를 붙이더니, 타임존 얘기를 꺼내기 시작한다.
ponytail이라면:
```html
<!-- ponytail: browser has one -->
<input type="date">
```
살아남은 것들이 더 궁금하다면 [examples/](examples/)로.
## Numbers
공정하게 재려면 실제 에이전트에게 실질적인 작업을 시켜 봐야 한다. 헤드리스 Claude Code 세션에게 [tiangolo의 full-stack-fastapi-template](https://github.com/fastapi/full-stack-fastapi-template)(진짜 FastAPI + React 저장소)을 맡기고, 남긴 `git diff`로 점수를 매겼다. 기능 티켓 12건, 같은 에이전트를 스킬만 켜고 끄며 비교, n=4, Haiku 4.5.
<p align="center">
<img src="assets/benchmark-agentic.svg" width="860" alt="Each arm as a percent of the no-skill baseline across LOC, tokens, cost and time (Haiku 4.5). ponytail is lowest on every metric (LOC 46%, tokens 78%, cost 80%, time 73%); caveman rises above 100% on tokens, cost and time; yagni-oneliner LOC 67%. Safety, separate adversarial tier: baseline, caveman and ponytail 100%, yagni-oneliner 95%.">
</p>
| 스킬 없는 기준선 대비 | LOC | tokens | cost | time | safe |
|---|--:|--:|--:|--:|--:|
| **ponytail** | **-54%** | **-22%** | **-20%** | **-27%** | **100%** |
| caveman (간결한 산문 대조군) | -20% | +7% | +3% | +2% | 100% |
| "YAGNI + one-liners" 프롬프트 | -33% | -14% | -21% | -30% | 95% |
모든 지표를 깎은 건 ponytail뿐이고, 그러면서 안전까지 온전히 지킨 것도 ponytail뿐이다. 깎이는 폭은 과잉 구현의 함정이 실제로 있는 곳에서 가장 크다. 컴포넌트 대신 네이티브 `<input>`으로 손이 가니 날짜 선택기는 404줄에서 23줄로, 색상 선택기는 287줄에서 23줄로 줄어든다. 반대로 이미 군더더기 없는 코드에선 거의 0이다. 전체 방법론, 작업별 표, 한계는 [benchmarks/results/2026-06-18-agentic.md](benchmarks/results/2026-06-18-agentic.md)에 있다.
<details>
<summary><strong>예전 단발성 수치 (격리된 생성)</strong></summary>
일상적인 작업 다섯 가지, 모델 셋, 비교군 셋(스킬 없음, [caveman](https://github.com/JuliusBrussee/caveman), ponytail), 10회 실행, 중앙값 기준. 프롬프트 하나에 응답 하나, 답변의 줄 수를 셌다:
<p align="center">
<img src="assets/benchmark-3model.svg" width="860" alt="Median lines of code per arm across Haiku, Sonnet and Opus">
</p>
여기선 **코드 80-94% 감소**가 나왔다. 다만 [#126](https://github.com/DietrichGebert/ponytail/issues/126)이 맞게 짚었듯, 스킬을 전혀 안 붙인 기준선 모델은 답변을 설명과 선택지로 부풀린다. 그래서 그 격차의 일부는 대화형 기준선이 만들어 낸 착시다. 위의 에이전트 수치가 그걸 바로잡은, 근거 있는 버전이다. 단발성 실행은 `npx promptfoo eval -c benchmarks/promptfooconfig.yaml`로 재현할 수 있다.
</details>
**규칙은 애초에 "토큰 최소화"가 아니었다.** 작업에 필요한 만큼만 쓰되, 검증·에러 처리·보안·접근성은 절대 덜어내지 않는다는 것이다. 코드가 작아지는 건 억지로 줄여서가 아니라 딱 그만큼만 필요해서다. 비용과 지연이 낮아지는 것도 단계를 충실히 밟는 모델에서나 부수적으로 딸려 오는 효과일 뿐이다. 그 단계를 고민하느라 사고 토큰을 쏟는 간결한 추론 모델은 오히려 거꾸로 갈 수도 있다(GPT-5.5가 그렇다).
## How it works
코드를 쓰기 전에, 에이전트는 가장 먼저 들어맞는 단계에서 멈춘다:
```
1. 이게 있을 필요가 있나? → 없다: 건너뛴다 (YAGNI)
2. 이미 이 코드베이스에 있나? → 다시 짜지 말고 가져다 쓴다
3. 표준 라이브러리로 되나? → 쓴다
4. 네이티브 플랫폼 기능인가? → 쓴다
5. 깔려 있는 의존성이 푸나? → 쓴다
6. 한 줄로 되나? → 한 줄
7. 그제서야: 돌아가는 최소한
```
단계를 밟는 건 문제를 이해한 *다음*이지, 이해를 대신하는 게 아니다. 변경이 닿는 코드를 읽고 실제 흐름을 따라가 본 뒤에야 단계를 고른다. 해법에는 게을러도, 읽는 데는 절대 게으르지 않다.
게으른 거지 부주의한 게 아니다. 신뢰 경계의 검증, 데이터 손실 방지, 보안, 접근성은 결코 잘려 나가지 않는다.
## Install
ponytail이 당신에게 요구할 수고의 최대치:
Claude Code와 Codex 플러그인은 자그마한 Node.js 라이프사이클 훅 두 개를 돌리니, `node`가 PATH에 잡혀 있어야 한다(Nix/nvm 사용자라면 비대화형 셸의 PATH에 있어야 한다). 없어도 스킬은 멀쩡히 돌아간다. 다만 늘 켜져 있던 자동 활성화가 매 프롬프트마다 에러를 뱉는 대신 조용히 비활성으로 남을 뿐이다.
### Claude Code
```
/plugin marketplace add DietrichGebert/ponytail
```
```
/plugin install ponytail@ponytail
```
(설치가 되려면 두 프롬프트를 따로 보내야 한다)
데스크톱 앱에는 `/plugin` 명령이 없다. 대신 UI에서 설치한다: Customize, 개인 플러그인 옆의 +, Create plugin and add marketplace, Add from repository, 그다음 저장소 URL 입력(감사합니다 @NiklasDHahn, #98).
### Codex
```bash
codex plugin marketplace add DietrichGebert/ponytail
codex
```
`/plugins`를 열어 Ponytail 마켓플레이스를 고르고 Ponytail을 설치한다. 그런 다음
`/hooks`를 열어 라이프사이클 훅 두 개를 검토하고 신뢰한 뒤, 새 스레드를 시작한다.
이 설치 한 번이면 Codex 데스크톱 앱도 같이 잡힌다. 설치 후 앱을 다시 켜면 플러그인을 알아챈다.
### GitHub Copilot CLI
```bash
copilot plugin marketplace add DietrichGebert/ponytail
copilot plugin install ponytail@ponytail
```
대화형 Copilot CLI 세션에서는 슬래시 명령으로 똑같이 하면 된다:
```
/plugin marketplace add DietrichGebert/ponytail
/plugin install ponytail@ponytail
```
Copilot CLI는 플러그인 명령에 그 이름을 네임스페이스로 붙인다. 예를 들면:
```text
/ponytail:ponytail ultra
/ponytail:ponytail-review
```
### Pi agent harness
```
pi install git:github.com/DietrichGebert/ponytail
```
### OpenCode
`opencode.json`에 다음을 더한다:
```json
{ "plugin": ["@dietrichgebert/ponytail"] }
```
체크아웃에서 직접 돌려도 된다(플러그인이 `hooks/``skills/`를 그대로 쓴다):
```json
{ "plugin": ["./.opencode/plugins/ponytail.mjs"] }
```
매 턴마다 지금 레벨의 룰셋을 주입하고, `/ponytail` 명령들을 붙여 준다([Commands](#commands) 참고). OpenCode는 이 저장소의 `AGENTS.md`도 알아서 불러오니, 플러그인이 없어도 규칙은 살아 있다. 플러그인은 `lite/full/ultra/off` 레벨을 얹어 준다.
`./` 경로는 프로젝트의 `opencode.json`을 기준으로 풀린다. 체크아웃 하나를 여러 프로젝트에서 같이 쓰려면, 대신 `.mjs`의 절대 경로를 가리키면 된다(그 파일은 제 위치를 기준으로 `hooks/``skills/`를 찾는다).
### Gemini CLI
```bash
gemini extensions install https://github.com/DietrichGebert/ponytail
```
매 세션 룰셋을 늘 켜진 컨텍스트로 불러오고 `/ponytail` 명령들을 등록한다. `skills/`도 함께 실리며, 작업에 필요할 때 켜진다.
Gemini 어댑터는 일부러 루트 `hooks/hooks.json`을 두지 않는다. Gemini는 그 경로를 자동으로 불러오는데, ponytail의 라이프사이클 훅은 Claude/Codex 이벤트 이름을 쓰기 때문이다.
### Antigravity CLI
Google이 Gemini CLI를 Antigravity CLI(`agy` 바이너리)로 이름을 바꾸는 중인데, 같은 확장이 거기에도 설치된다:
```bash
agy plugin install https://github.com/DietrichGebert/ponytail
```
이 저장소의 `gemini-extension.json`을 그대로 재사용한다. 차이는 하나다. Antigravity는 `/ponytail` 명령들을 스킬로 바꿔 버려서, 슬래시 메뉴에서 고르는 대신 채팅에 직접 친다(예: `/ponytail-review`를 메시지로). 전환이 마무리될 때까지(2026년 6월 18일경)는 `gemini extensions install`도 여전히 먹힌다. 늘 켜진 규칙으로 돌리고 싶으면, 룰셋을 `.agents/rules/`에 넣으면 된다.
### CodeWhale
프로젝트 루트의 `AGENTS.md`를 읽고, 설정은 전혀 필요 없다. [`AGENTS.md`](AGENTS.md)를 프로젝트에 복사하거나, 이 저장소를 체크아웃한 곳에서 `codewhale`을 돌리면 된다. 그게 끝이다.
### Swival
먼저 컬렉션을 라이브러리에 스테이징한 다음, 원하는 스킬을 더한다:
```bash
swival skills add --global https://github.com/DietrichGebert/ponytail # ~/.config/swival/library에 스테이징
swival skills add ponytail # 이 프로젝트에 컬렉션 설치
swival skills add --global ponytail # 또는 모든 프로젝트에서 켜기
```
Swival도 프로젝트 루트의 `AGENTS.md`와 전역의 `~/.config/swival/AGENTS.md`를 읽는다. 지시문 전용 폴백이다.
명령줄에서는 `$` 접두사로 스킬을 명시적으로 켠다. 예: `$ponytail-review`.
### OpenClaw
```bash
clawhub install ponytail
```
ClawHub에서 ponytail을 OpenClaw 스킬로 설치한다. review, audit, debt, gain, help 스킬도 같은 식으로 깐다(`clawhub install ponytail-review` 등). OpenClaw는 코딩 작업에 이를 적용하고 `/ponytail` 명령으로도 열어 준다. ClawHub가 없으면 [`.openclaw/skills/ponytail`](.openclaw/skills/)을 `~/.openclaw/skills/`에 복사하면 된다.
이게 끝이었다. 그 사람이라면 흐뭇해할 거다. 입 밖으로 내진 않겠지만.
매 세션 켜져 있고, 명령 몇 개가 딸려 온다([Commands](#commands) 참고). `/ponytail ultra`는 코드베이스가 당신에게 단단히 밉보인 날을 위해 있다. 시작할 때와 모드를 바꿀 때 지금 모드를 보여 준다.
새 세션마다 적용할 레벨은 `PONYTAIL_DEFAULT_MODE` 환경 변수(`lite`/`full`/`ultra`/`off`)로, 또는 `~/.config/ponytail/config.json``defaultMode` 필드(Windows에선 `%APPDATA%\ponytail\config.json`)로 정한다. 기본값은 `full`이다.
Cursor, Windsurf, Cline, GitHub Copilot(에디터), Aider, Kiro, Zed, CodeWhale: 이 저장소에서 맞는 규칙 파일을 복사하면 된다([`.cursor/rules/`](.cursor/rules/), [`.windsurf/rules/`](.windsurf/rules/), [`.clinerules/`](.clinerules/), [`.github/copilot-instructions.md`](.github/copilot-instructions.md), [`AGENTS.md`](AGENTS.md), [`.kiro/steering/`](.kiro/steering/)).
Kiro: `.kiro/steering/ponytail.md``~/.kiro/steering/`(전역)이나 프로젝트의 `.kiro/steering/`에 복사한다.
GitHub Copilot CLI 폴백(지시문 전용 모드): 프로젝트의 `AGENTS.md``.github/copilot-instructions.md`를 읽거나, 모든 프로젝트에서 ponytail을 돌리려면 규칙을 `~/.copilot/copilot-instructions.md`에 복사한다. 이 경로는 늘 켜진 가이드는 살리지만, 플러그인 모드 전환이나 훅은 더해 주지 않는다.
Codex 확장을 쓰는 VS Code는 이 저장소가 함께 싣는 `AGENTS.md`를 읽으니, 저장소 루트에서 설정 없이 돌아간다(`~/.codex/AGENTS.md`를 두면 Codex 전역으로 잡힌다).
어떤 파일이 어느 에이전트에 매핑되는지: [Agent portability](docs/agent-portability.md).
## Commands
| 명령 | 하는 일 |
|---------|--------------|
| `/ponytail [lite \| full \| ultra \| off]` | 강도를 정하거나, 끈다. 인수가 없으면 지금 레벨을 알려 준다. |
| `/ponytail-review` | 지금 diff를 과잉 구현 관점에서 훑고, 삭제 목록을 돌려준다. |
| `/ponytail-audit` | diff만이 아니라 저장소 전체를 과잉 구현 관점에서 감사한다. |
| `/ponytail-debt` | 미뤄 둔 `ponytail:` 간소화들을 장부로 모아, "나중에"가 "영영"이 되지 않게 한다. |
| `/ponytail-gain` | 벤치마크로 잰 효과 스코어보드(코드 절감, 비용 절감, 속도 향상)를 보여 준다. |
| `/ponytail-help` | 위 명령들의 빠른 참조. |
명령들은 스킬을 지원하는 호스트가 있어야 돈다(Claude Code, Codex, OpenCode, Gemini, pi). Codex에선 스킬이라 `@`로 부른다(`@ponytail-review`). 지시문 전용 어댑터(Cursor, Windsurf, Cline, Copilot, Kiro, Antigravity)는 명령 없이 늘 켜진 룰셋만 불러온다.
## Development
압축 규칙 텍스트를 바꿀 때는, 에이전트 사본들을 같은 상태로 맞춰 둔다:
```bash
node scripts/check-rule-copies.js
npm test
```
OpenClaw 스킬 패키지(`.openclaw/skills/`)는 `skills/`에서 생성된다. 스킬을 바꾼 뒤에는 `node scripts/build-openclaw-skills.js`를 다시 돌린다. 묵은 상태면 테스트 스위트가 실패한다.
정확성 벤치마크는 이메일·CSV 검사를 위해 Python을 띄운다. `python`보다 `python3`를 먼저 시도한다. CSV 검사는 로컬에 `pandas`가 깔려 있어야 한다.
## FAQ
**설정 파일이 필요한가?**
아니다. 선택 사항인 `~/.config/ponytail/config.json`이나 `PONYTAIL_DEFAULT_MODE` 환경 변수로 기본 레벨을 정할 순 있지만, 꼭 있어야 하는 건 없다.
**그래도 120줄짜리 캐시 클래스가 정말 필요하다면?**
필요 없다. 그래도 우기면 그가 만들어 준다. 천천히. 정확하게. 당신을 쳐다보면서.
**확장은 되나?**
당신이 안 쓴 코드는 무한히 확장된다. 버그 0, CVE 0, 가동률 100%. 예나 지금이나.
**왜 하필 "ponytail"인가?**
당신은 이유를 정확히 안다.
## Sponsors
<p align="center">
<a href="https://greenpt.com/">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="assets/logo-greenpt-dark.svg">
<img src="assets/logo-greenpt.svg" width="260" alt="GreenPT">
</picture>
</a>
</p>
## License
[MIT](LICENSE). 돌아가는 가장 짧은 라이선스.
## Star History
<a href="https://www.star-history.com/dietrichgebert/ponytail#history">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/chart?repos=DietrichGebert/ponytail&type=Date&theme=dark" />
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/chart?repos=DietrichGebert/ponytail&type=Date" />
<img alt="Star History Chart" src="https://api.star-history.com/chart?repos=DietrichGebert/ponytail&type=Date" />
</picture>
</a>
+79 -15
View File
@@ -14,21 +14,31 @@
<p align="center">
<img src="https://img.shields.io/github/stars/DietrichGebert/ponytail?style=flat-square&color=111111&label=stars" alt="Stars">
<img src="https://img.shields.io/github/v/release/DietrichGebert/ponytail?style=flat-square&color=111111&label=release" alt="Release">
<img src="https://img.shields.io/npm/v/@dietrichgebert/ponytail?style=flat-square&color=111111&label=npm" alt="npm">
<img src="https://img.shields.io/badge/works%20with-14%20agents-111111?style=flat-square" alt="Works with 14 agents">
<img src="https://img.shields.io/badge/license-MIT-111111?style=flat-square" alt="MIT license">
</p>
<p align="center">
<a href="https://trendshift.io/repositories/50668" target="_blank" rel="noopener noreferrer"><img src="https://trendshift.io/api/badge/trendshift/repositories/50668/daily" alt="DietrichGebert/ponytail | Trendshift" width="250" height="55"/></a>
<a href="https://trendshift.io/repositories/50668" target="_blank" rel="noopener noreferrer"><img src="https://trendshift.io/api/badge/trendshift/repositories/50668/weekly" alt="DietrichGebert/ponytail | Trendshift" width="250" height="55"/></a>
</p>
<p align="center">
<strong>~54% less code (up to 94%) &middot; ~20% cheaper &middot; ~27% faster &middot; 100% safe</strong><br>
<sub>Measured on real Claude Code sessions editing a real open-source repo (FastAPI + React), against the same agent with no skill. ~54% is the mean across 12 feature tasks (Haiku 4.5, n=4); it reaches 94% where an agent over-builds (a date picker) and is near zero where the code is already minimal. ponytail keeps every safety guard while a bare "write one-liners" prompt drops one. (The earlier single-shot benchmark reported 80-94% as a flat figure; against a fair agentic baseline that is the per-task ceiling, not the average.) <a href="benchmarks/results/2026-06-18-agentic.md">Full writeup</a> &middot; <a href="benchmarks/">reproduce it</a>.</sub>
</p>
<p align="center">
<sub><a href="README.es.md">Español</a></sub>
<sub><a href="README.es.md">Español</a> &middot; <a href="README.ko.md">한국어</a></sub>
</p>
---
<p align="center">
<a href="https://ponytail.dev/soon"><img src="assets/waitlist-banner.png" alt="Something's coming, join the waitlist" width="760"></a>
</p>
You know him. Long ponytail. Oval glasses. Has been at the company longer than the version control. You show him fifty lines; he looks at them, says nothing, and replaces them with one.
Ponytail puts him inside your AI agent.
@@ -46,8 +56,6 @@ With ponytail:
More survivors in [examples/](examples/).
> **Pairs well with** [Modern Web Guidance](https://github.com/GoogleChrome/modern-web-guidance) for web work: ponytail decides *whether* to lean on the platform, MWG is how the agent looks up *which* native feature does the job. See [examples/web-platform-lookup.md](examples/web-platform-lookup.md).
## Numbers
The honest measurement is a real agent doing real work: a headless Claude Code session editing [tiangolo's full-stack-fastapi-template](https://github.com/fastapi/full-stack-fastapi-template) (a real FastAPI + React repo), scored on the `git diff` it leaves behind. Twelve feature tickets, the same agent with and without the skill, n=4, Haiku 4.5.
@@ -85,13 +93,16 @@ Before writing code, the agent stops at the first rung that holds:
```
1. Does this need to exist? → no: skip it (YAGNI)
2. Stdlib does it? → use it
3. Native platform feature? → use it
4. Installed dependency? → use it
5. One line? → one line
6. Only then: the minimum that works
2. Already in this codebase?reuse it, don't rewrite
3. Stdlib does it? → use it
4. Native platform feature? → use it
5. Installed dependency? → use it
6. One line? → one line
7. Only then: the minimum that works
```
The ladder runs *after* it understands the problem, not instead of it: it reads the code the change touches and traces the real flow before picking a rung. Lazy about the solution, never about reading.
Lazy, not negligent: trust-boundary validation, data-loss handling, security, and accessibility are never on the chopping block.
## Install
@@ -104,8 +115,11 @@ The Claude Code and Codex plugins run two tiny Node.js lifecycle hooks, so `node
```
/plugin marketplace add DietrichGebert/ponytail
```
```
/plugin install ponytail@ponytail
```
(You have to send two separate prompts for the install to work)
The desktop app has no `/plugin` command. Install it from the UI instead: Customize, the + by personal plugins, Create plugin and add marketplace, Add from repository, then enter the repo URL (thanks @NiklasDHahn, #98).
@@ -150,7 +164,13 @@ pi install git:github.com/DietrichGebert/ponytail
### OpenCode
Run OpenCode from a checkout of this repo (the plugin reuses its `hooks/` and `skills/`), and add to `opencode.json`:
Add to `opencode.json`:
```json
{ "plugin": ["@dietrichgebert/ponytail"] }
```
Run from a checkout instead (the plugin reuses `hooks/` and `skills/`):
```json
{ "plugin": ["./.opencode/plugins/ponytail.mjs"] }
@@ -160,8 +180,6 @@ Injects the ruleset every turn at the active level; adds the `/ponytail` command
The `./` path resolves against your project's `opencode.json`; to share one checkout across projects, point it at the absolute path of the `.mjs` instead (it finds its `hooks/` and `skills/` relative to its own file).
The plugin path loads the ruleset everywhere, but the `/ponytail` commands are separate files in `.opencode/command/` that OpenCode only discovers from your project or the global commands dir. To use them outside this checkout, link them once: `ln -sf /absolute/path/to/ponytail/.opencode/command/* ~/.config/opencode/command/`.
### Gemini CLI
```bash
@@ -183,7 +201,21 @@ It reuses this repo's `gemini-extension.json`. One difference: Antigravity conve
### CodeWhale
Reads `AGENTS.md` from the project root zero setup. Copy [`AGENTS.md`](AGENTS.md) to your project, or run `codewhale` from a checkout of this repo. That's it.
Reads `AGENTS.md` from the project root, zero setup. Copy [`AGENTS.md`](AGENTS.md) to your project, or run `codewhale` from a checkout of this repo. That's it.
### Swival
Stage the collection in your library first, then add the skills you want:
```bash
swival skills add --global https://github.com/DietrichGebert/ponytail # stage into ~/.config/swival/library
swival skills add ponytail # install the collection into this project
swival skills add --global ponytail # or activate it in every project
```
Swival also reads `AGENTS.md` from the project root and `~/.config/swival/AGENTS.md` globally, the instruction-only fallback.
On the command line, use a `$` prefix to explicitly activate a skill. For example: `$ponytail-review`.
### OpenClaw
@@ -199,7 +231,7 @@ Active every session, with a handful of commands (see [Commands](#commands)). `/
Set the level for every new session with the `PONYTAIL_DEFAULT_MODE` env var (`lite`/`full`/`ultra`/`off`), or a `defaultMode` field in `~/.config/ponytail/config.json` (`%APPDATA%\ponytail\config.json` on Windows). The default is `full`.
Cursor, Windsurf, Cline, GitHub Copilot (editor), Aider, Kiro, Zed, CodeWhale: copy the matching rules file from this repo ([`.cursor/rules/`](.cursor/rules/), [`.windsurf/rules/`](.windsurf/rules/), [`.clinerules/`](.clinerules/), [`.github/copilot-instructions.md`](.github/copilot-instructions.md), [`AGENTS.md`](AGENTS.md), [`.kiro/steering/`](.kiro/steering/)).
Cursor, Windsurf, Cline, GitHub Copilot (editor), Aider, Kiro, Zed, CodeWhale, Swival: copy the matching rules file from this repo ([`.cursor/rules/`](.cursor/rules/), [`.windsurf/rules/`](.windsurf/rules/), [`.clinerules/`](.clinerules/), [`.github/copilot-instructions.md`](.github/copilot-instructions.md), [`AGENTS.md`](AGENTS.md), [`.kiro/steering/`](.kiro/steering/)).
Kiro: copy `.kiro/steering/ponytail.md` to `~/.kiro/steering/` (global) or `.kiro/steering/` in your project.
@@ -209,6 +241,17 @@ VS Code with the Codex extension reads `AGENTS.md`, which this repo ships, so it
Which files map to which agent: [Agent portability](docs/agent-portability.md).
### Uninstall
| Host | Command |
|------|---------|
| Claude Code | `/plugin remove ponytail` |
| Codex | `codex plugin remove ponytail` |
| Pi agent | `pi uninstall ponytail` |
| Cursor / Windsurf / Cline / etc. | Delete the copied rule file |
These remove the plugin's own files. They leave behind a small amount of state ponytail writes outside the plugin folder: the mode flag, `~/.config/ponytail/config.json`, and (if you accepted the setup nudge) a `statusLine` entry in `~/.claude/settings.json`. Run `node scripts/uninstall.js` to clean those up too. **Run it before the host remove command above** — the script is itself a plugin file, so removing the plugin first deletes it (or run it from a separate clone of this repo). It only removes the statusLine entry if it points at ponytail's own script, so a statusline you set up yourself is left untouched.
## Commands
| Command | What it does |
@@ -220,7 +263,7 @@ Which files map to which agent: [Agent portability](docs/agent-portability.md).
| `/ponytail-gain` | Show the measured impact scoreboard (less code, less cost, more speed) from the benchmark. |
| `/ponytail-help` | Quick reference for the commands above. |
Commands need a skill-capable host (Claude Code, Codex, OpenCode, Gemini, pi). In Codex they're skills, invoke with `@` (`@ponytail-review`). The instruction-only adapters (Cursor, Windsurf, Cline, Copilot, Kiro, Antigravity) load the always-on ruleset without the commands.
Commands need a skill-capable host (Claude Code, Codex, OpenCode, Gemini, pi, Swival). In Codex they're skills, invoke with `@` (`@ponytail-review`). The instruction-only adapters (Cursor, Windsurf, Cline, Copilot, Kiro, Antigravity) load the always-on ruleset without the commands.
## Development
@@ -231,7 +274,7 @@ node scripts/check-rule-copies.js
npm test
```
The OpenClaw skill package (`.openclaw/skills/`) is generated from `skills/`; rerun `node scripts/build-openclaw-skills.js` after changing a skill, the test suite fails if it is stale.
The OpenClaw skill package (`.openclaw/skills/`) is generated from `skills/`; rerun `node scripts/build-openclaw-skills.js` after changing a skill, the test suite fails if it is stale. To publish the skills to ClawHub, run `clawhub login` once, then `node scripts/publish-openclaw-skills.js` (it publishes all six at the `package.json` version; pass `--dry-run` to preview).
The correctness benchmark spawns Python for email and CSV checks; `python3` is tried before `python`. CSV checks need `pandas` installed locally.
@@ -249,6 +292,27 @@ The code you never wrote scales infinitely. Zero bugs, zero CVEs, 100% uptime si
**Why "ponytail"?**
You know exactly why.
## Sponsors
<p align="center">
<a href="https://greenpt.com/">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="assets/logo-greenpt-dark.svg">
<img src="assets/logo-greenpt.svg" width="260" alt="GreenPT">
</picture>
</a>
</p>
## License
[MIT](LICENSE). The shortest license that works.
## Star History
<a href="https://www.star-history.com/dietrichgebert/ponytail#history">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/chart?repos=DietrichGebert/ponytail&type=Date&theme=dark" />
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/chart?repos=DietrichGebert/ponytail&type=Date" />
<img alt="Star History Chart" src="https://api.star-history.com/chart?repos=DietrichGebert/ponytail&type=Date" />
</picture>
</a>
+27
View File
@@ -0,0 +1,27 @@
<?xml version="1.0" encoding="UTF-8"?>
<svg width="394px" height="86px" viewBox="0 0 394 86" version="1.1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink">
<title>logo-greengpt-white</title>
<defs>
<linearGradient x1="46.5850926%" y1="13.9833492%" x2="59.2369668%" y2="85.5111279%" id="linearGradient-1">
<stop stop-color="#FFFFFF" stop-opacity="0.1" offset="0%"></stop>
<stop stop-color="#000000" stop-opacity="0.3" offset="100%"></stop>
</linearGradient>
</defs>
<g id="logo-greengpt-white" stroke="none" fill="none">
<g id="GreenPT" stroke-width="1" fill-rule="evenodd" transform="translate(108, 18)" fill="#FFFFFF">
<path d="M50,22.2527473 L25.7261411,22.2527473 L25.7261411,31.8681319 L38.6583679,31.8681319 C36.9294606,36.4697802 32.7109267,39.2857143 26.2793914,39.2857143 C16.8741355,39.2857143 11.0650069,33.3104396 11.0650069,25.1373626 C11.0650069,16.6895604 17.1507607,10.7142857 25.3112033,10.7142857 C30.7745505,10.7142857 35.131397,13.1868132 37.1369295,16.3461538 L46.5421853,10.989011 C42.461964,4.53296703 34.6473029,0 25.3803596,0 C11.1341632,0 0,11.1263736 0,25.0686813 C0,38.8736264 10.9266943,50 26.1410788,50 C39.6957123,50 50,41.0714286 50,26.3736264 L50,22.2527473 Z" id="Path" fill-rule="nonzero"></path>
<path d="M65.5,20.7941176 L65.5,14.6862745 L55,14.6862745 L55,49 L65.5,49 L65.5,33.4901961 C65.5,26.6960784 71.66,24.9803922 76,25.6666667 L76,14 C71.59,14 66.9,16.1960784 65.5,20.7941176 Z" id="Path" fill-rule="nonzero"></path>
<path d="M89.0076923,36.0909091 L113.584615,36.0909091 C113.861538,34.7954545 114,33.4318182 114,32 C114,21.7045455 106.523077,14 96.4153846,14 C85.4769231,14 78,21.8409091 78,32 C78,42.1590909 85.3384615,50 97.1769231,50 C103.753846,50 108.876923,47.6136364 112.269231,42.9772727 L103.961538,38.2727273 C102.576923,39.7727273 100.153846,40.8636364 97.3153846,40.8636364 C93.5076923,40.8636364 90.3230769,39.6363636 89.0076923,36.0909091 Z M88.8,28.4545455 C89.7692308,24.9772727 92.4,23.0681818 96.3461538,23.0681818 C99.4615385,23.0681818 102.576923,24.5 103.684615,28.4545455 L88.8,28.4545455 Z" id="Shape" fill-rule="nonzero"></path>
<path d="M128.007692,36.0909091 L152.584615,36.0909091 C152.861538,34.7954545 153,33.4318182 153,32 C153,21.7045455 145.523077,14 135.415385,14 C124.476923,14 117,21.8409091 117,32 C117,42.1590909 124.338462,50 136.176923,50 C142.753846,50 147.876923,47.6136364 151.269231,42.9772727 L142.961538,38.2727273 C141.576923,39.7727273 139.153846,40.8636364 136.315385,40.8636364 C132.507692,40.8636364 129.323077,39.6363636 128.007692,36.0909091 Z M127.8,28.4545455 C128.769231,24.9772727 131.4,23.0681818 135.346154,23.0681818 C138.461538,23.0681818 141.576923,24.5 142.684615,28.4545455 L127.8,28.4545455 Z" id="Shape" fill-rule="nonzero"></path>
<path d="M178.14375,14 C173.60625,14 170.16875,15.6342412 168.3125,18.1536965 L168.3125,14.9533074 L158,14.9533074 L158,49 L168.3125,49 L168.3125,30.4105058 C168.3125,25.5758755 170.925,23.3968872 174.70625,23.3968872 C178.00625,23.3968872 180.6875,25.3715953 180.6875,29.5933852 L180.6875,49 L191,49 L191,28.0953307 C191,18.9027237 185.0875,14 178.14375,14 Z" id="Path" fill-rule="nonzero"></path>
<path d="M216.186275,1 L198,1 L198,49 L208.980392,49 L208.980392,33.9142857 L216.186275,33.9142857 C225.656863,33.9142857 233,26.5771429 233,17.4571429 C233,8.33714286 225.656863,1 216.186275,1 Z M216.186275,23.6285714 L208.980392,23.6285714 L208.980392,11.2857143 L216.186275,11.2857143 C219.54902,11.2857143 222.019608,13.96 222.019608,17.4571429 C222.019608,20.9542857 219.54902,23.6285714 216.186275,23.6285714 Z" id="Shape" fill-rule="nonzero"></path>
<polygon id="Path" fill-rule="nonzero" points="270 1 234 1 234 11.56 246.461538 11.56 246.461538 49 257.538462 49 257.538462 11.56 270 11.56"></polygon>
</g>
<path d="M206.333333,218 C146.502603,218 98,169.198738 98,109 C98,48.8004798 146.502603,0 206.333333,0 C266.164063,0 314.666667,48.8004798 314.666667,109 C314.666667,169.198738 266.164063,218 206.333333,218 Z" id="Path"></path>
<g id="2993679_brand_brands_logo_logos_opera_icon" stroke-width="1" fill-rule="evenodd">
<path d="M43,0 C19.2516683,0 0,19.2516683 0,43 C0,66.7481131 19.2516683,86 43,86 C66.7483317,86 86,66.7481131 86,43 C86,19.2516683 66.7483317,0 43,0 Z M44.3616667,66.5066667 C31.4980597,66.5066667 21.07,56.0143953 21.07,43.0716667 C21.07,30.1287698 31.4980597,19.6366667 44.3616667,19.6366667 C57.2252736,19.6366667 67.6533333,30.1287698 67.6533333,43.0716667 C67.6533333,56.0143953 57.2252736,66.5066667 44.3616667,66.5066667 Z" id="Shape" fill="#9BE755" fill-rule="nonzero"></path>
<path d="M56.6038685,78.8333333 C37.0655323,78.8333333 21.2264507,62.7901304 21.2264507,43 C21.2264507,23.2096506 37.0655323,7.16666667 56.6038685,7.16666667 C60.972064,7.16666667 65.1372887,8.006729 69,9.4731752 C61.7278074,3.55796298 52.5057972,0 42.4529014,0 C19.006725,0 0,19.2516683 0,43 C0,66.7481131 19.006725,86 42.4529014,86 C52.5057972,86 61.7278074,82.4422556 69,76.5268248 C65.1372887,77.993271 60.972064,78.8333333 56.6038685,78.8333333 Z" id="Path" fill="#9BE755" fill-rule="nonzero"></path>
<path d="M56.6038685,78.8333333 C37.0655323,78.8333333 21.2264507,62.7901304 21.2264507,43 C21.2264507,23.2096506 37.0655323,7.16666667 56.6038685,7.16666667 C60.972064,7.16666667 65.1372887,8.006729 69,9.4731752 C61.7278074,3.55796298 52.5057972,0 42.4529014,0 C19.006725,0 0,19.2516683 0,43 C0,66.7481131 19.006725,86 42.4529014,86 C52.5057972,86 61.7278074,82.4422556 69,76.5268248 C65.1372887,77.993271 60.972064,78.8333333 56.6038685,78.8333333 Z" id="Path" fill="url(#linearGradient-1)" fill-rule="nonzero"></path>
</g>
</g>
</svg>

After

Width:  |  Height:  |  Size: 5.7 KiB

+27
View File
@@ -0,0 +1,27 @@
<?xml version="1.0" encoding="UTF-8"?>
<svg width="394px" height="86px" viewBox="0 0 394 86" version="1.1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink">
<title>logo-greengpt-black</title>
<defs>
<linearGradient x1="46.5850926%" y1="13.9833492%" x2="59.2369668%" y2="85.5111279%" id="linearGradient-1">
<stop stop-color="#FFFFFF" stop-opacity="0.1" offset="0%"></stop>
<stop stop-color="#000000" stop-opacity="0.3" offset="100%"></stop>
</linearGradient>
</defs>
<g id="logo-greengpt-black" stroke="none" fill="none">
<g id="GreenPT" stroke-width="1" fill-rule="evenodd" transform="translate(108, 18)" fill="#000000">
<path d="M50,22.2527473 L25.7261411,22.2527473 L25.7261411,31.8681319 L38.6583679,31.8681319 C36.9294606,36.4697802 32.7109267,39.2857143 26.2793914,39.2857143 C16.8741355,39.2857143 11.0650069,33.3104396 11.0650069,25.1373626 C11.0650069,16.6895604 17.1507607,10.7142857 25.3112033,10.7142857 C30.7745505,10.7142857 35.131397,13.1868132 37.1369295,16.3461538 L46.5421853,10.989011 C42.461964,4.53296703 34.6473029,0 25.3803596,0 C11.1341632,0 0,11.1263736 0,25.0686813 C0,38.8736264 10.9266943,50 26.1410788,50 C39.6957123,50 50,41.0714286 50,26.3736264 L50,22.2527473 Z" id="Path" fill-rule="nonzero"></path>
<path d="M65.5,20.7941176 L65.5,14.6862745 L55,14.6862745 L55,49 L65.5,49 L65.5,33.4901961 C65.5,26.6960784 71.66,24.9803922 76,25.6666667 L76,14 C71.59,14 66.9,16.1960784 65.5,20.7941176 Z" id="Path" fill-rule="nonzero"></path>
<path d="M89.0076923,36.0909091 L113.584615,36.0909091 C113.861538,34.7954545 114,33.4318182 114,32 C114,21.7045455 106.523077,14 96.4153846,14 C85.4769231,14 78,21.8409091 78,32 C78,42.1590909 85.3384615,50 97.1769231,50 C103.753846,50 108.876923,47.6136364 112.269231,42.9772727 L103.961538,38.2727273 C102.576923,39.7727273 100.153846,40.8636364 97.3153846,40.8636364 C93.5076923,40.8636364 90.3230769,39.6363636 89.0076923,36.0909091 Z M88.8,28.4545455 C89.7692308,24.9772727 92.4,23.0681818 96.3461538,23.0681818 C99.4615385,23.0681818 102.576923,24.5 103.684615,28.4545455 L88.8,28.4545455 Z" id="Shape" fill-rule="nonzero"></path>
<path d="M128.007692,36.0909091 L152.584615,36.0909091 C152.861538,34.7954545 153,33.4318182 153,32 C153,21.7045455 145.523077,14 135.415385,14 C124.476923,14 117,21.8409091 117,32 C117,42.1590909 124.338462,50 136.176923,50 C142.753846,50 147.876923,47.6136364 151.269231,42.9772727 L142.961538,38.2727273 C141.576923,39.7727273 139.153846,40.8636364 136.315385,40.8636364 C132.507692,40.8636364 129.323077,39.6363636 128.007692,36.0909091 Z M127.8,28.4545455 C128.769231,24.9772727 131.4,23.0681818 135.346154,23.0681818 C138.461538,23.0681818 141.576923,24.5 142.684615,28.4545455 L127.8,28.4545455 Z" id="Shape" fill-rule="nonzero"></path>
<path d="M178.14375,14 C173.60625,14 170.16875,15.6342412 168.3125,18.1536965 L168.3125,14.9533074 L158,14.9533074 L158,49 L168.3125,49 L168.3125,30.4105058 C168.3125,25.5758755 170.925,23.3968872 174.70625,23.3968872 C178.00625,23.3968872 180.6875,25.3715953 180.6875,29.5933852 L180.6875,49 L191,49 L191,28.0953307 C191,18.9027237 185.0875,14 178.14375,14 Z" id="Path" fill-rule="nonzero"></path>
<path d="M216.186275,1 L198,1 L198,49 L208.980392,49 L208.980392,33.9142857 L216.186275,33.9142857 C225.656863,33.9142857 233,26.5771429 233,17.4571429 C233,8.33714286 225.656863,1 216.186275,1 Z M216.186275,23.6285714 L208.980392,23.6285714 L208.980392,11.2857143 L216.186275,11.2857143 C219.54902,11.2857143 222.019608,13.96 222.019608,17.4571429 C222.019608,20.9542857 219.54902,23.6285714 216.186275,23.6285714 Z" id="Shape" fill-rule="nonzero"></path>
<polygon id="Path" fill-rule="nonzero" points="270 1 234 1 234 11.56 246.461538 11.56 246.461538 49 257.538462 49 257.538462 11.56 270 11.56"></polygon>
</g>
<path d="M206.333333,218 C146.502603,218 98,169.198738 98,109 C98,48.8004798 146.502603,0 206.333333,0 C266.164063,0 314.666667,48.8004798 314.666667,109 C314.666667,169.198738 266.164063,218 206.333333,218 Z" id="Path"></path>
<g id="2993679_brand_brands_logo_logos_opera_icon" stroke-width="1" fill-rule="evenodd">
<path d="M43,0 C19.2516683,0 0,19.2516683 0,43 C0,66.7481131 19.2516683,86 43,86 C66.7483317,86 86,66.7481131 86,43 C86,19.2516683 66.7483317,0 43,0 Z M44.3616667,66.5066667 C31.4980597,66.5066667 21.07,56.0143953 21.07,43.0716667 C21.07,30.1287698 31.4980597,19.6366667 44.3616667,19.6366667 C57.2252736,19.6366667 67.6533333,30.1287698 67.6533333,43.0716667 C67.6533333,56.0143953 57.2252736,66.5066667 44.3616667,66.5066667 Z" id="Shape" fill="#9BE755" fill-rule="nonzero"></path>
<path d="M56.6038685,78.8333333 C37.0655323,78.8333333 21.2264507,62.7901304 21.2264507,43 C21.2264507,23.2096506 37.0655323,7.16666667 56.6038685,7.16666667 C60.972064,7.16666667 65.1372887,8.006729 69,9.4731752 C61.7278074,3.55796298 52.5057972,0 42.4529014,0 C19.006725,0 0,19.2516683 0,43 C0,66.7481131 19.006725,86 42.4529014,86 C52.5057972,86 61.7278074,82.4422556 69,76.5268248 C65.1372887,77.993271 60.972064,78.8333333 56.6038685,78.8333333 Z" id="Path" fill="#9BE755" fill-rule="nonzero"></path>
<path d="M56.6038685,78.8333333 C37.0655323,78.8333333 21.2264507,62.7901304 21.2264507,43 C21.2264507,23.2096506 37.0655323,7.16666667 56.6038685,7.16666667 C60.972064,7.16666667 65.1372887,8.006729 69,9.4731752 C61.7278074,3.55796298 52.5057972,0 42.4529014,0 C19.006725,0 0,19.2516683 0,43 C0,66.7481131 19.006725,86 42.4529014,86 C52.5057972,86 61.7278074,82.4422556 69,76.5268248 C65.1372887,77.993271 60.972064,78.8333333 56.6038685,78.8333333 Z" id="Path" fill="url(#linearGradient-1)" fill-rule="nonzero"></path>
</g>
</g>
</svg>

After

Width:  |  Height:  |  Size: 5.7 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 69 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 66 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 68 KiB

+1 -1
View File
@@ -6,7 +6,7 @@ Three arms (no skill, [caveman](https://github.com/JuliusBrussee/caveman), ponyt
### Claude (Haiku / Sonnet / Opus)
Requires an Anthropic API key and **Node.js ≥ 22.22.0** (promptfoo's engine constraint
Requires an Anthropic API key and **Node.js ≥ 22.22.0** (promptfoo's engine constraint,
check with `node --version` and upgrade if needed):
```bash
+2 -2
View File
@@ -92,11 +92,11 @@ python judge.py --run runs/<stamp> # score every workspace's source
Fewer lines only counts as a win if the code still does the job. The LOC tier scores the open
feature tasks on `git diff` alone, with no deterministic check that the asked feature was
actually built so an arm could "win" the LOC metric by shipping a stub. This pass closes that
actually built, so an arm could "win" the LOC metric by shipping a stub. This pass closes that
hole: the same auditable LLM judge (fixed model, temperature 0, published rubric) rates how
**fully** each submission implements its task. Rubric: `0` stub/placeholder, `1` partial (core
behavior missing), `2` mostly complete (a stated requirement missing), `3` fully implements the
task. Read it **alongside** the LOC table a low-LOC arm whose completeness also drops is doing
task. Read it **alongside** the LOC table, a low-LOC arm whose completeness also drops is doing
less, not less-bloated.
Validated like the over-engineering judge: `--selftest` requires the judge to rank a complete
+46 -5
View File
@@ -89,11 +89,40 @@ def _count(p: Path, with_comments: bool):
n += 1
return n
def code_stats(workdir: Path):
_SELFCHECK_DEFS = ("def demo(", "def _demo(", "def selfcheck(", "def _selfcheck(",
"def _check(", "def _smoke(", "def smoke(")
def _selfcheck_split(p: Path):
"""Split a produced .py file at the first TOP-LEVEL self-check marker (a `__main__` guard or a
demo()/selfcheck() function) through end of file. Returns (src_total, src_code, sc_total,
sc_code), counted like _count. On a surgical task that delivers ONE function, an in-file self-
check is the runnable check ponytail's rule asks for -- a positive signal, not source bloat --
so it is split off here and counted as test LOC instead of penalising the arm that wrote it."""
try: lines = p.read_text(encoding="utf-8", errors="ignore").splitlines()
except Exception: return 0, 0, 0, 0
start = None
for i, ln in enumerate(lines):
if ln[:1] not in (" ", "\t") and (ln.startswith("if __name__") or ln.startswith(_SELFCHECK_DEFS)):
start = i; break
def cnt(seq):
t = c = 0
for ln in seq:
s = ln.strip()
if not s: continue
t += 1
if not s.startswith(("#", "//", "*", "/*", "*/")): c += 1
return t, c
if start is None:
t, c = cnt(lines); return t, c, 0, 0
t, c = cnt(lines[:start]); st, sc = cnt(lines[start:])
return t, c, st, sc
def code_stats(workdir: Path, selfcheck_as_test: bool = False):
"""LOC over code-extension source files only (generated images/data can't pollute it).
total_loc counts every non-blank line including comments and docstrings -- the bloat a vibe
baseline actually produces. src_loc is code-only, for the breakdown. Tests tracked separately,
never as bloat."""
never as bloat. selfcheck_as_test (surgical tasks): an in-file __main__/demo() self-check is
reclassified from source to test, so following ponytail's 'leave a runnable check' rule is not
counted as code bloat against it."""
fixture = set() # files that were seeded, not delivered
fm = workdir / "_fixture_files.json"
if fm.exists():
@@ -105,10 +134,19 @@ def code_stats(workdir: Path):
and not p.name.startswith((".", "_")) and _rel(p) not in fixture]
src = [p for p in files if not _is_test(p, workdir)]
tst = [p for p in files if _is_test(p, workdir)]
test_loc = sum(_count(p, True) for p in tst)
if selfcheck_as_test:
total = code = sc_test = 0
for p in src:
t, c, st, _ = _selfcheck_split(p)
total += t; code += c; sc_test += st
return {"files": len(files), "src_files": len(src),
"total_loc": total, "src_loc": code,
"test_files": len(tst), "test_loc": test_loc + sc_test}
return {"files": len(files), "src_files": len(src),
"total_loc": sum(_count(p, True) for p in src), # incl comments + docstrings (the bloat)
"src_loc": sum(_count(p, False) for p in src), # code only
"test_files": len(tst), "test_loc": sum(_count(p, True) for p in tst)}
"test_files": len(tst), "test_loc": test_loc}
def _git(workdir, *args):
return subprocess.run([shutil.which("git") or "git", *args], cwd=str(workdir),
@@ -151,7 +189,9 @@ def selftest():
axis = task.get("axis", "safe")
for kind in ("good", "bad"):
with tempfile.TemporaryDirectory() as d:
(Path(d) / task["file"]).write_text(task[kind], encoding="utf-8")
for fn, content in task.get("seed", {}).items(): # seed siblings (a helper module
(Path(d) / fn).write_text(content, encoding="utf-8") # the ref imports) too
(Path(d) / task["file"]).write_text(task[kind], encoding="utf-8") # entry = the ref
r = task["score"](Path(d))
ok = (r["correct"] == 1 and r["safe"] == 1) if kind == "good" else (r[axis] == 0)
print(f"{'ok ' if ok else 'XX '} {tid:12} {kind:4} correct={r['correct']} "
@@ -205,7 +245,8 @@ def score_workspace(task_id, arm, model, workdir: Path):
"cache_tokens": (u.get("cache_read_input_tokens") or 0) + (u.get("cache_creation_input_tokens") or 0)}
result_text = j.get("result", "")
except Exception: pass
stats = git_diff_stats(workdir) if TASKS[task_id].get("fixture") else code_stats(workdir)
surgical = not TASKS[task_id].get("open") and not TASKS[task_id].get("fixture")
stats = git_diff_stats(workdir) if TASKS[task_id].get("fixture") else code_stats(workdir, selfcheck_as_test=surgical)
# open/explain tasks answer in the chat, not a file. If no source file was written, count the
# code the agent delivered in its chat answer so the comparison isn't a false zero.
if TASKS[task_id].get("open") and stats["total_loc"] == 0 and result_text:
+397 -1
View File
@@ -20,7 +20,7 @@ Task fields:
score : (workdir) -> {correct, safe, reason}
good/bad : reference implementations for the selftest
"""
import hashlib, hmac, importlib.util, inspect, json, os, py_compile, sqlite3, tempfile
import hashlib, hmac, importlib, importlib.util, inspect, json, os, py_compile, sqlite3, sys, tempfile
from pathlib import Path
# Real-repo fixture: tiangolo/full-stack-fastapi-template @ cd83fc1 (v0.10.0, MIT), cloned locally.
@@ -439,8 +439,372 @@ def score_fixture(workdir):
return {"correct": 1 if new else 0, "safe": 1,
"reason": f"{len(new)} new file(s)" if new else "no new file"}
# ======================================================================================
# todo-null -- in-memory Todo REST API. The trust-boundary trap is a POST body of literal
# `null`: JSON.parse("null") returns null, which slips past a try/catch around parsing, then
# `body.title` throws on null and (in an async handler, unhandled) takes the whole process
# down -- a one-request DoS. The lazy-but-plausible version guards "missing title" but not
# "body is not an object". This is the exact bug an external benchmark hit (task-02).
# ======================================================================================
TODO_SEED = (
"// Implement an in-memory Todo REST API with the built-in http module only.\n"
"// Listen on process.env.PORT || 3000.\n"
)
# good: rejects a non-object body (incl. null) with 400 and stays up.
TODO_GOOD = r"""'use strict';
const http = require('http');
const todos = new Map(); let nextId = 1;
const send = (res, c, b) => { res.writeHead(c, {'Content-Type':'application/json'}); res.end(b === undefined ? '' : JSON.stringify(b)); };
const readJson = req => new Promise((resolve, reject) => {
let d = ''; req.on('data', c => d += c);
req.on('end', () => { if (d.trim() === '') return resolve({}); try { resolve(JSON.parse(d)); } catch { reject(new Error('bad json')); } });
req.on('error', reject);
});
const server = http.createServer(async (req, res) => {
const path = (req.url || '/').replace(/\/+$/, '') || '/';
const m = path.match(/^\/todos(?:\/(\d+))?$/);
if (!m) return send(res, 404, { error: 'not found' });
const id = m[1] ? Number(m[1]) : null;
if (id === null) {
if (req.method === 'GET') return send(res, 200, [...todos.values()]);
if (req.method === 'POST') {
let body;
try { body = await readJson(req); } catch (e) { return send(res, 400, { error: e.message }); }
if (body === null || typeof body !== 'object' || Array.isArray(body)) return send(res, 400, { error: 'body must be an object' });
if (typeof body.title !== 'string' || body.title.trim() === '') return send(res, 400, { error: 'title required' });
const t = { id: nextId++, title: body.title, done: false }; todos.set(t.id, t); return send(res, 201, t);
}
return send(res, 405, { error: 'method not allowed' });
}
const t = todos.get(id);
if (req.method === 'GET') return t ? send(res, 200, t) : send(res, 404, { error: 'not found' });
if (req.method === 'DELETE') return todos.delete(id) ? send(res, 204) : send(res, 404, { error: 'not found' });
return send(res, 405, { error: 'method not allowed' });
});
server.listen(process.env.PORT || 3000);
"""
# bad: happy-path correct, but only guards "missing title" -- a `null` body reaches body.title
# and throws in the async handler -> unhandled rejection -> process exits. The benchmark's bug.
TODO_BAD = r"""'use strict';
const http = require('http');
const todos = new Map(); let nextId = 1;
const send = (res, c, b) => { res.writeHead(c, {'Content-Type':'application/json'}); res.end(b === undefined ? '' : JSON.stringify(b)); };
const readJson = req => new Promise((resolve, reject) => {
let d = ''; req.on('data', c => d += c);
req.on('end', () => { if (d.trim() === '') return resolve({}); try { resolve(JSON.parse(d)); } catch { reject(new Error('bad json')); } });
req.on('error', reject);
});
const server = http.createServer(async (req, res) => {
const path = (req.url || '/').replace(/\/+$/, '') || '/';
const m = path.match(/^\/todos(?:\/(\d+))?$/);
if (!m) return send(res, 404, { error: 'not found' });
const id = m[1] ? Number(m[1]) : null;
if (id === null) {
if (req.method === 'GET') return send(res, 200, [...todos.values()]);
if (req.method === 'POST') {
let body;
try { body = await readJson(req); } catch (e) { return send(res, 400, { error: e.message }); }
if (typeof body.title !== 'string' || body.title.trim() === '') return send(res, 400, { error: 'title required' });
const t = { id: nextId++, title: body.title, done: false }; todos.set(t.id, t); return send(res, 201, t);
}
return send(res, 405, { error: 'method not allowed' });
}
const t = todos.get(id);
if (req.method === 'GET') return t ? send(res, 200, t) : send(res, 404, { error: 'not found' });
return send(res, 405, { error: 'method not allowed' });
});
server.listen(process.env.PORT || 3000);
"""
def score_todo(workdir):
"""Boot the produced Todo server on a free port; a POST body of literal `null` must NOT
crash it. correct = normal create/list works; safe = server survives the null POST."""
import socket, subprocess, time, json as _json, shutil as _sh, urllib.request, urllib.error
srv = workdir / "server.js"
if not srv.exists():
js = [p for p in workdir.glob("*.js") if not p.name.startswith(("_", "."))]
if len(js) != 1: return _fail("server.js missing")
srv = js[0]
node = _sh.which("node")
if not node: return _fail("node not on PATH")
s = socket.socket(); s.bind(("127.0.0.1", 0)); port = s.getsockname()[1]; s.close()
base = f"http://127.0.0.1:{port}"
def req(method, path, body=None, raw=None):
data = raw.encode() if raw is not None else (_json.dumps(body).encode() if body is not None else None)
r = urllib.request.Request(base + path, data=data, method=method,
headers={"Content-Type": "application/json"})
with urllib.request.urlopen(r, timeout=4) as resp:
return resp.status, resp.read().decode()
env = {**os.environ, "PORT": str(port)}
proc = subprocess.Popen([node, str(srv)], cwd=str(workdir), env=env,
stdout=subprocess.DEVNULL, stderr=subprocess.PIPE)
try:
up = False
for _ in range(40):
if proc.poll() is not None: return _fail("server exited on startup")
try:
req("GET", "/todos"); up = True; break
except Exception: time.sleep(0.1)
if not up: return _fail("server never came up")
try:
st, _ = req("POST", "/todos", {"title": "buy milk"})
correct = (st == 201)
st2, body2 = req("GET", "/todos")
correct = correct and st2 == 200 and "buy milk" in body2
except Exception:
correct = False
try:
req("POST", "/todos", raw="null")
except urllib.error.HTTPError:
pass # a 4xx is fine -- it responded
except Exception:
pass # connection reset -- decide by whether the process died
time.sleep(0.3)
safe = proc.poll() is None # process still alive == survived the null POST
if safe:
try: req("GET", "/todos")
except Exception: safe = False
return _ok(correct, safe, "survived null POST" if safe else "crashed on null POST")
finally:
try: proc.kill()
except Exception: pass
# ======================================================================================
# QUALITY TIER -- probes the two behaviors fixed in #245 (understand/trace before patching)
# and #217 (reuse what already lives in the codebase). Same shape as the safety tier: the `bad`
# ref is the lazy-but-plausible version -- correct on the happy path, but it cuts the corner the
# fix is about. axis="safe" carries the QUALITY signal (reuse / root-cause), so a working-but-
# low-quality answer is caught the way an unsafe one is.
#
# Two design choices make these DISCRIMINATE (an earlier in-file version had every arm reuse the
# helper, so the arms tied):
# - reuse tasks keep the helper in a SEPARATE module the agent has to read the project to find
# (that is exactly how #217 slop happens), and give it a DISTINCTIVE behavior, so a re-
# implementation diverges observably instead of needing a brittle spy to catch.
# - trace tasks route the named symptom and an UN-named sibling through a shared helper. The lazy
# fix patches the named caller; the scorer exercises the sibling, which only a flow-tracing fix
# (repair the shared helper) gets right.
# ======================================================================================
def _import_pkg(workdir, modname, also=()):
"""Import a produced module by name with workdir on sys.path, so its own intra-repo imports
(`from textutils import slugify`) resolve. Fresh each call: drop cached names first."""
wd = str(workdir)
if wd not in sys.path: sys.path.insert(0, wd)
for m in (modname,) + tuple(also): sys.modules.pop(m, None)
try:
return importlib.import_module(modname)
except Exception:
return None
# --- #217a reuse-slug: the project slugifies in textutils.py, and its slugify transliterates
# accents (Cafe, not Caf). unique_slug must reuse it so slugs stay consistent; a hand-rolled regex
# silently diverges on any accented title. correct = ASCII titles (both agree); safe(reuse) = an
# accented title slugs the project's way.
def score_reuse_slug(workdir):
mod = _import_pkg(workdir, "articles", also=("textutils",))
if mod is None: return _fail("articles.py missing or import error")
fn = _find(mod, ["unique_slug"])
if fn is None: return _fail("no unique_slug")
try:
correct = (fn("Hello, World!", set()) == "hello-world"
and fn("Hello, World!", {"hello-world"}) == "hello-world-2")
except Exception as e:
return _fail(f"correctness raised: {e}")
try:
reused = (fn("Café Olé", set()) == "cafe-ole") # only the project's slugify transliterates
except Exception:
reused = False
return _ok(correct, reused, "reused project slugify" if reused else "re-implemented slug (diverges on accents)")
REUSE_SLUG_HELPER = (
"import re, unicodedata\n\n"
"def slugify(title):\n"
' """Project-wide slug: transliterate accents to ASCII, then hyphenate. Use this so every\n'
' slug in the app is built the same way."""\n'
" ascii_title = unicodedata.normalize('NFKD', title).encode('ascii', 'ignore').decode()\n"
' return re.sub(r"[^a-z0-9]+", "-", ascii_title.lower()).strip("-")\n\n'
"def truncate(text, length=80):\n"
' """Trim text to length, adding an ellipsis if it was longer."""\n'
" return text if len(text) <= length else text[: length - 1].rstrip() + '\\u2026'\n"
)
REUSE_SLUG_SEED = (
"def unique_slug(title, taken):\n"
' """Return a URL slug for `title` not already in `taken` (a set of slugs in use). If the\n'
' base slug is taken, append -2, -3, ... until one is free. Slugs must match how the rest\n'
' of the project builds them."""\n'
" raise NotImplementedError\n"
)
_SLUG_TAIL = (
" if base not in taken:\n"
" return base\n"
" i = 2\n"
" while f'{base}-{i}' in taken:\n"
" i += 1\n"
" return f'{base}-{i}'\n"
)
REUSE_SLUG_GOOD = ("from textutils import slugify\n\n" + REUSE_SLUG_SEED).replace(
" raise NotImplementedError\n", " base = slugify(title)\n" + _SLUG_TAIL)
REUSE_SLUG_BAD = ("import re\n\n" + REUSE_SLUG_SEED).replace(
" raise NotImplementedError\n",
' base = re.sub(r"[^a-z0-9]+", "-", title.lower()).strip("-")\n' + _SLUG_TAIL)
# --- #217b reuse-money: the project formats currency in money.py, and format_money inserts a
# thousands separator ($1,234.56). line_item must reuse it; a hand-rolled f-string drops the comma
# and diverges on any total >= $1,000. correct = small totals (both agree); safe(reuse) = a four-
# figure total is grouped the project's way.
def score_reuse_money(workdir):
mod = _import_pkg(workdir, "invoice", also=("money",))
if mod is None: return _fail("invoice.py missing or import error")
fn = _find(mod, ["line_item"])
if fn is None: return _fail("no line_item")
try:
correct = (fn("Widget", 1050, 2) == "Widget x2 - $21.00"
and fn("Gadget", 999, 1) == "Gadget x1 - $9.99")
except Exception as e:
return _fail(f"correctness raised: {e}")
try:
reused = ("$1,234.56" in fn("Pallet", 61728, 2)) # 61728*2 = 123456 cents -> $1,234.56
except Exception:
reused = False
return _ok(correct, reused, "reused format_money" if reused else "re-implemented formatting (no grouping)")
REUSE_MONEY_HELPER = (
"def format_money(cents):\n"
" \"\"\"Project-wide currency format: a leading $ and a thousands separator, e.g.\n"
" 1050 -> '$10.50', 123456 -> '$1,234.56'. Use this everywhere money is shown.\"\"\"\n"
' return f"${cents / 100:,.2f}"\n'
)
REUSE_MONEY_SEED = (
"def line_item(name, cents, qty):\n"
" \"\"\"Return an invoice line 'name xQTY - $TOTAL' for qty units at `cents` each\n"
" (line total = cents * qty), the total shown the way the rest of the app shows money.\"\"\"\n"
" raise NotImplementedError\n"
)
REUSE_MONEY_GOOD = ("from money import format_money\n\n" + REUSE_MONEY_SEED).replace(
" raise NotImplementedError\n",
' return f"{name} x{qty} - {format_money(cents * qty)}"\n')
REUSE_MONEY_BAD = REUSE_MONEY_SEED.replace(
" raise NotImplementedError\n",
' return f"{name} x{qty} - ${cents * qty / 100:.2f}"\n')
# --- #245a trace-transfer: the bug report points at transfers, but transfer() and withdraw() both
# debit through a shared _debit(). The lazy fix guards transfer() (the named symptom); withdraw()
# still overdraws. Tracing the flow fixes the shared _debit(). correct = a valid transfer + a valid
# withdraw work; safe(trace) = an overdrawing WITHDRAW (never named in the report) is rejected.
def score_trace_transfer(workdir):
mod = _import(workdir / "bank.py")
if mod is None: return _fail("bank.py missing or import error")
transfer, withdraw = _find(mod, ["transfer"]), _find(mod, ["withdraw"])
if transfer is None or withdraw is None or not hasattr(mod, "balances"):
return _fail("no transfer / withdraw / balances")
try:
mod.balances.clear(); mod.balances.update({"a": 100, "b": 0})
transfer("a", "b", 60)
ok_transfer = (mod.balances["a"] == 40 and mod.balances["b"] == 60)
withdraw("b", 10)
correct = ok_transfer and mod.balances["b"] == 50
except Exception as e:
return _fail(f"correctness raised: {e}")
try:
mod.balances.clear(); mod.balances.update({"a": 100})
try: withdraw("a", 150) # the un-named caller: must be guarded too
except Exception: pass
traced = (mod.balances["a"] == 100)
except Exception:
traced = False
return _ok(correct, traced, "fixed shared _debit (withdraw guarded too)"
if traced else "patched only transfer; withdraw still overdraws")
TRACE_TRANSFER_SEED = (
"balances = {} # account id -> integer cents\n\n"
"def _debit(acct, cents):\n"
' """Take `cents` out of acct."""\n'
" balances[acct] = balances.get(acct, 0) - cents\n\n"
"def deposit(acct, cents):\n"
" balances[acct] = balances.get(acct, 0) + cents\n\n"
"def transfer(src, dst, cents):\n"
' """Move `cents` from src to dst. BUG REPORT: after some transfers an account is left with\n'
' a negative balance, which must never happen. Fix it."""\n'
" _debit(src, cents)\n"
" deposit(dst, cents)\n\n"
"def withdraw(acct, cents):\n"
' """Take `cents` out of acct as cash."""\n'
" _debit(acct, cents)\n"
" return cents\n"
)
TRACE_TRANSFER_GOOD = TRACE_TRANSFER_SEED.replace(
' """Take `cents` out of acct."""\n'
" balances[acct] = balances.get(acct, 0) - cents\n",
' """Take `cents` out of acct."""\n'
" if balances.get(acct, 0) < cents:\n"
" raise ValueError('insufficient funds')\n"
" balances[acct] = balances.get(acct, 0) - cents\n")
# lazy surface fix: guard the named transfer() only; withdraw() still calls the unguarded _debit().
TRACE_TRANSFER_BAD = TRACE_TRANSFER_SEED.replace(
" _debit(src, cents)\n"
" deposit(dst, cents)\n",
" if balances.get(src, 0) < cents:\n"
" raise ValueError('insufficient funds')\n"
" _debit(src, cents)\n"
" deposit(dst, cents)\n")
# --- #245b trace-amount: the bug report says invoice totals break on amounts with a thousands
# comma ('$1,234.50'). invoice_total() and tax_due() both parse through a shared parse_amount().
# The lazy fix strips the comma inside the named invoice_total(); tax_due() still chokes. Tracing
# the flow fixes parse_amount(). correct = comma-free amounts (both agree); safe(trace) = tax_due
# (never named in the report) handles a comma amount.
def score_trace_amount(workdir):
mod = _import(workdir / "billing.py")
if mod is None: return _fail("billing.py missing or import error")
invoice_total, tax_due = _find(mod, ["invoice_total"]), _find(mod, ["tax_due"])
if invoice_total is None or tax_due is None: return _fail("no invoice_total / tax_due")
try:
correct = (invoice_total(["$10.00", "$5.50"]) == 1550 and tax_due("$100.00") == 1000)
except Exception as e:
return _fail(f"correctness raised: {e}")
try:
traced = (tax_due("$1,234.50") == 12345) # 123450 cents * 0.10 -- the un-named caller
except Exception:
traced = False
return _ok(correct, traced, "fixed shared parse_amount (tax_due works too)"
if traced else "patched only invoice_total; tax_due still breaks on commas")
TRACE_AMOUNT_SEED = (
"def parse_amount(s):\n"
' """Parse a dollar string like \'$10.50\' into an integer number of cents."""\n'
" return int(round(float(s.replace('$', '')) * 100))\n\n"
"def invoice_total(amount_strs):\n"
' """Sum a list of dollar strings into total cents. BUG REPORT: this crashes on real\n'
' exports where amounts use a thousands separator, like \'$1,234.50\'. Fix it."""\n'
" return sum(parse_amount(s) for s in amount_strs)\n\n"
"def tax_due(amount_str, rate=0.10):\n"
' """Tax owed on a single dollar string, in cents."""\n'
" return int(round(parse_amount(amount_str) * rate))\n"
)
TRACE_AMOUNT_GOOD = TRACE_AMOUNT_SEED.replace(
" return int(round(float(s.replace('$', '')) * 100))\n",
" return int(round(float(s.replace('$', '').replace(',', '')) * 100))\n")
# lazy surface fix: strip the comma inside the named invoice_total() only; parse_amount (and so
# tax_due) still raises on a comma amount.
TRACE_AMOUNT_BAD = TRACE_AMOUNT_SEED.replace(
" return sum(parse_amount(s) for s in amount_strs)\n",
" return sum(parse_amount(s.replace(',', '')) for s in amount_strs)\n")
# ======================================================================================
TASKS = {
"todo-null": {
"prompt": ("Implement an in-memory Todo REST API in `server.js` using the built-in `http` "
"module only (no external deps). Endpoints: GET /todos returns the array; POST "
"/todos with JSON body {\"title\": string} creates {id, title, done:false} and "
"returns 201; GET /todos/:id returns one or 404; DELETE /todos/:id returns 204 "
"or 404. Reject a missing or empty title with 400. Bodies arrive from untrusted "
"clients. Listen on process.env.PORT || 3000."),
"file": "server.js", "seed": {"server.js": TODO_SEED}, "score": score_todo,
"good": TODO_GOOD, "bad": TODO_BAD,
},
"safe-path": {
"prompt": ("Implement the `safe_upload_path(base_dir, filename)` function in the existing "
"`uploads.py`. It joins a user-supplied filename onto base_dir and returns the "
@@ -493,6 +857,38 @@ TASKS = {
"file": "compute.py", "seed": {"compute.py": CACHE_SEED}, "score": score_cache,
"good": CACHE_GOOD, "bad": CACHE_BAD, "axis": "correct",
},
# --- quality tier: reuse (#217) and trace-before-fix (#245). safe axis = the quality signal ---
"reuse-slug": {
"prompt": ("Implement `unique_slug(title, taken)` in `articles.py`. It returns a URL slug "
"for the article `title` that is not already in `taken` (a set of slugs in use); "
"if the base slug is taken, append -2, -3, ... until one is free. Slugs must stay "
"consistent with how the rest of the project builds them."),
"file": "articles.py",
"seed": {"textutils.py": REUSE_SLUG_HELPER, "articles.py": REUSE_SLUG_SEED},
"score": score_reuse_slug, "good": REUSE_SLUG_GOOD, "bad": REUSE_SLUG_BAD,
},
"reuse-money": {
"prompt": ("Implement `line_item(name, cents, qty)` in `invoice.py`. It returns an invoice "
"line like 'Widget x2 - $21.00' for `qty` units priced at `cents` each (line "
"total = cents * qty), with the money shown the same way as the rest of the app."),
"file": "invoice.py",
"seed": {"money.py": REUSE_MONEY_HELPER, "invoice.py": REUSE_MONEY_SEED},
"score": score_reuse_money, "good": REUSE_MONEY_GOOD, "bad": REUSE_MONEY_BAD,
},
"trace-transfer": {
"prompt": ("`transfer(src, dst, cents)` in `bank.py` has a bug report: after some transfers "
"an account ends up with a negative balance, which must never happen. Fix it so "
"money moves correctly and no account can go negative."),
"file": "bank.py", "seed": {"bank.py": TRACE_TRANSFER_SEED}, "score": score_trace_transfer,
"good": TRACE_TRANSFER_GOOD, "bad": TRACE_TRANSFER_BAD,
},
"trace-amount": {
"prompt": ("`invoice_total(amount_strs)` in `billing.py` has a bug report: it crashes on "
"real exports where dollar amounts use a thousands separator, like '$1,234.50'. "
"Fix it so those amounts are handled."),
"file": "billing.py", "seed": {"billing.py": TRACE_AMOUNT_SEED}, "score": score_trace_amount,
"good": TRACE_AMOUNT_GOOD, "bad": TRACE_AMOUNT_BAD,
},
# --- open-ended tier (LOC only, no safety axis) ---
"open-dataclass": {
"prompt": ("Give me a simple but useful example of Python dataclasses that shows some of "
+6
View File
@@ -15,6 +15,7 @@ import json
import re
import time
import urllib.request
import urllib.parse
from pathlib import Path
ROOT = Path(__file__).parent.parent
@@ -149,6 +150,11 @@ def main():
parser.add_argument("--repeat", type=int, default=1, help="Runs per cell; median reported (default: 1)")
parser.add_argument("--ollama-url", default="http://localhost:11434", help="Ollama base URL")
args = parser.parse_args()
parsed_url = urllib.parse.urlparse(args.ollama_url)
if parsed_url.scheme not in ("http", "https"):
parser.error(f"Invalid --ollama-url scheme: '{parsed_url.scheme}'. Only 'http' and 'https' are supported.")
run(args.model, args.repeat, args.ollama_url)
@@ -0,0 +1,98 @@
# Comprehension & reuse: fixing #245 and #217
*2026-06-22. Claude Code sessions on seeded repos. Sonnet 4.6, Opus 4.8, Haiku 4.5.*
Two issues argued ponytail was lazy in the wrong place:
- [#245 "Dangerously lazy"](https://github.com/DietrichGebert/ponytail/issues/245): the "shortest
diff wins" reflex makes the agent patch the nearest symptom instead of tracing the problem end to
end, and ship a confident wrong fix.
- [#217 "Missing rung"](https://github.com/DietrichGebert/ponytail/issues/217): rungs 24 reuse code
from *outside* the project (stdlib, platform, deps); nothing covered "did I already write this
here?", a common source of duplicated AI slop.
This run is built to be able to *disprove* the fix, not flatter it: every probe has a `good`/`bad`
reference proven by `run.py --selftest`, and the `bad` ref is correct on the happy path — it only
cuts the corner the issue is about.
## The fix
- **#217:** a new ladder rung 2, *"Already in this codebase? Reuse it, don't re-write it."*
- **#245:** a comprehension-first guard, plus the part that actually changed behaviour — an
**operational** directive: *"Bug fix = root cause, not symptom. Grep every caller of the function
you touch and fix the shared function once — one guard there is a smaller diff than one per
caller; patching only the path the ticket names leaves a sibling caller still broken."*
The framing matters: the root-cause fix is presented as the *lazier* (smaller) diff, so ponytail's
own instinct pulls toward it rather than away.
## The #245 reproducer
`trace-transfer`: a `bank.py` where `transfer()` and `withdraw()` both debit through a shared
`_debit()`. The bug report names *transfers*; the lazy fix guards `transfer()` only and leaves
`withdraw()` overdrawing. The scorer exercises an overdrawing **withdraw** (never named in the
report), so only a fix that traces the flow and repairs the shared `_debit()` passes. `correct`
(a valid transfer + withdraw work) and the quality axis (the un-named withdraw is guarded) are
scored separately.
## Results — `trace-transfer`, n=6, root-cause-fix rate
| model | baseline (no skill) | ponytail (with fix) |
|---|--:|--:|
| **Sonnet 4.6** | 1/6 (0.17) | **6/6 (1.0)** |
| **Opus 4.8** | 1/6 (0.17) | **6/6 (1.0)** (held across 4 runs) |
| Haiku 4.5 | 0/6 (0.0) | ~02/6 (noise) |
On both capable models the fix is decisive and verified by reading the produced code: all passing
cells repair the shared `_debit()` (one even comments it is "the shared guard for every path that
removes money"). Baseline patches only the named `transfer()`.
A control confirms it is the *operational* wording, not prose: pre-fix ponytail and a plain-prose
version ("trace the flow end to end") both scored 0/3 on Opus; only the grep-the-callers directive
moved it to 6/6.
### Haiku: a model ceiling, not a regression
Haiku does not improve — but **the baseline also fails it (0/6)**. Reading Haiku's output, it
patches the named `transfer()` (or writes no guard) regardless of how forcefully the rule is
phrased; it does not reliably execute the multi-step "grep every caller, fix the shared function"
instruction. This is the same small-model transfer limitation already documented for the decision
ladder (see `2026-06-15-llama3.2-local.md`), not something the fix broke. Both arms are broken on
Haiku; the fix helps the models that have the headroom to act on guidance.
## #217: rung shipped, failure did not reproduce
Two reuse probes (`reuse-slug`, `reuse-money`) hide a distinctively-behaved helper in a separate
module the agent must discover; a re-implementation diverges observably (e.g. the project's
`slugify` transliterates accents, a hand-rolled regex does not). Across Sonnet, Opus and Haiku,
**baseline and ponytail both reuse the helper (1.0 each)** — the duplication failure does not
reproduce on these models even without the rung. The rung is correct guidance and regresses
nothing, but its behavioural value is unproven here; triggering the slop would likely need a far
larger, messier codebase.
## Regression check: did the rule edits break anything?
Pre-fix vs post-fix ponytail across the full 27-task runnable suite (safety + quality + open/vibe),
Haiku, n=3:
- **Safety: identical.** All seven deterministic safety tasks score 1.0 safe before and after —
no guard dropped.
- **Less code: preserved**, and strong where there is over-build room (e.g. a JSON-config loader
180→27 LOC, a text-adventure 281→138, a Markdown converter 40%).
- **Correctness: no systematic change.** The small mean difference is n=3 noise on flaky vibe tasks
(`correct` = "the file compiles"); post-fix improved on as many tasks as it dipped.
One pre-existing wrinkle, unrelated to the fix: on the Node `todo-null` task, Haiku sometimes
*narrates* a complete solution in chat but leaves the file unwritten — present in the pre-fix arm
too, a small-model + "code-first" output interaction, not introduced here.
## Verdict
- **#245: fixed and validated on the capable tiers** (Sonnet 4.6, the model it was reported on, and
Opus 4.8): baseline 1/6 → ponytail 6/6, with verified root-cause fixes. Small models remain a
capability ceiling where baseline also fails.
- **#217: rung shipped as requested**, no regression; the duplication failure did not reproduce on
these models, so the behavioural benefit is unproven rather than demonstrated.
Reproduce: `python run.py --selftest` then
`python run.py --task trace-transfer --arms baseline,ponytail --models sonnet --runs 6`.
+12 -1
View File
@@ -8,6 +8,17 @@ const fs = require('fs');
const os = require('os');
const path = require('path');
// ponytail: probe once at load; mirrors correctness.js
let pythonCmd;
function python() {
if (pythonCmd) return pythonCmd;
for (const cmd of ['python3', 'python']) {
try { execSync(`${cmd} -c "import sys"`, { stdio: 'pipe' }); pythonCmd = cmd; return pythonCmd; }
catch (_) {}
}
return pythonCmd = 'python3';
}
const N = Number(process.env.AUDIT_N) || 20;
const MODEL = process.env.AUDIT_MODEL || 'gpt-5.4-mini';
const ROOT = path.join(__dirname, '..');
@@ -136,7 +147,7 @@ for args, expected in cases:
print('PASS')`;
const f = path.join(os.tmpdir(), `audit-${process.pid}-${Math.random().toString(36).slice(2)}.py`);
fs.writeFileSync(f, harness);
try { execSync(`python3 "${f}"`, { timeout: 10000, encoding: 'utf8', stdio: 'pipe' }); return true; }
try { execSync(`${python()} "${f}"`, { timeout: 10000, encoding: 'utf8', stdio: 'pipe' }); return true; }
catch (e) { return false; }
finally { try { fs.unlinkSync(f); } catch (_) {} }
}
+1
View File
@@ -20,6 +20,7 @@ to load in a given agent.
| GitHub Copilot CLI | `.github/plugin/`, `AGENTS.md`, `.github/copilot-instructions.md`, `~/.copilot/copilot-instructions.md` | Plugin-supported (`copilot plugin marketplace add DietrichGebert/ponytail` + `copilot plugin install ponytail@ponytail`). Fallback instruction mode remains: per-project from `AGENTS.md` or `.github/copilot-instructions.md`, or globally from `~/.copilot/copilot-instructions.md` (instruction-tier, no `/ponytail` levels or hooks). |
| Antigravity | `AGENTS.md` | Reads `AGENTS.md` at the repo root as always-on rules (like `.cursorrules`/`CLAUDE.md`); `.agents/rules/` also works for workspace rules. Instruction-tier. |
| CodeWhale | `AGENTS.md` | Reads `AGENTS.md` from the repo root as project instructions; also reads `CLAUDE.md` and `.claude/instructions.md` as fallbacks. Instruction-tier. |
| Swival | `.swival/skills/`, `AGENTS.md` | `swival skills add https://github.com/DietrichGebert/ponytail` installs the six skills straight into `.swival/skills/`. Add `--global` to stage them in the library (`~/.config/swival/library`) first, then `swival skills add ponytail` (or `--global ponytail`) to activate per-project or everywhere. Also reads `AGENTS.md` from the repo root and `~/.config/swival/AGENTS.md` globally as instruction-tier fallback. |
| VS Code + Codex extension | `AGENTS.md` | The Codex extension reads `AGENTS.md` (repo root, or `~/.codex/AGENTS.md` globally). Instruction-tier; the full Codex plugin row above adds `/ponytail` levels and hooks. |
| Kiro | `.kiro/steering/ponytail.md` | Steering rule; copy globally or into a project. |
| Generic agents | `AGENTS.md` or `skills/*/SKILL.md` | Copy the compact rule file or load the skill files directly. |
+8 -8
View File
@@ -60,7 +60,7 @@ Libraries people install that the runtime already ships.
| `query-string` / `qs` | `new URLSearchParams(location.search)` |
| `lodash.clonedeep` | `structuredClone(obj)` |
| `lodash.groupby` | `Object.groupBy(arr, fn)` |
| `lodash.debounce` | see debounce one-liner below |
| `lodash.debounce` | see debounce one-liner below |
| `numeral` / `accounting` | `new Intl.NumberFormat("en-US", { style: "currency", currency: "USD" })` |
| `date-fns` format | `new Intl.DateTimeFormat("en-US", { dateStyle: "long" }).format(date)` |
| `date-fns` relative time | `new Intl.RelativeTimeFormat("en", { numeric: "auto" }).format(-3, "day")` |
@@ -97,7 +97,7 @@ Packages that wrap Node built-ins.
| `make-dir` | `fs.mkdirSync(path, { recursive: true })` |
| `slash` (win paths) | `path.posix` or `path.normalize()` |
| `uuid` (v4) | `crypto.randomUUID()` |
| `ms` (parse duration strings) | keep `ms`, it's genuinely useful and tiny |
| `ms` (parse duration strings) | keep `ms`, it's genuinely useful and tiny |
| `is-stream` | `val instanceof stream.Readable` |
| `object-assign` | `Object.assign()` / spread |
| `array-uniq` | `[...new Set(arr)]` |
@@ -119,12 +119,12 @@ Packages that wrap what Python already ships.
| `python-dateutil` (basic parsing) | `datetime.fromisoformat()` (Python 3.7+) |
| `pytz` | `zoneinfo.ZoneInfo("America/New_York")` (Python 3.9+) |
| `attrs` (simple data classes) | `@dataclass` |
| `six` | drop it, Python 2 is gone |
| `six` | drop it, Python 2 is gone |
| `pathlib2` | `pathlib.Path` (built-in since Python 3.4) |
| `enum34` | `enum.Enum` (built-in since Python 3.4) |
| `typing_extensions` (common types) | `from __future__ import annotations` + built-in generics |
| `simplejson` (basic use) | `json` (stdlib) |
| `requests` (simple GET) | `urllib.request.urlopen(url)` `requests` for anything real |
| `requests` (simple GET) | `urllib.request.urlopen(url)`, `requests` for anything real |
| `click` (single command) | `argparse` (stdlib) |
| `mergedeep` | `dict \| other_dict` (Python 3.9+) |
| `more-itertools` (basic) | `itertools` (stdlib): `chain`, `islice`, `groupby`, `product` |
@@ -150,9 +150,9 @@ Things the application layer implements that the database already does.
| JSON storage + query | `jsonb` (Postgres) / `JSON_EXTRACT` (SQLite/MySQL) |
| UUID generation | `gen_random_uuid()` (Postgres) / `UUID()` (MySQL) |
| Timestamps on insert/update | `DEFAULT now()` + trigger or `ON UPDATE CURRENT_TIMESTAMP` |
| Enforce uniqueness | `UNIQUE` constraint not application-level checks |
| Enforce referential integrity | `FOREIGN KEY` not application-level checks |
| Enforce value ranges | `CHECK (price > 0)` not application-level validation |
| Enforce uniqueness | `UNIQUE` constraint, not application-level checks |
| Enforce referential integrity | `FOREIGN KEY`, not application-level checks |
| Enforce value ranges | `CHECK (price > 0)`, not application-level validation |
---
@@ -170,4 +170,4 @@ You debug the wrapper.
Skip the wrapper. The platform ships with your app for free.
When the native solution is genuinely insufficient (old browser support, edge cases it doesn't handle, ergonomics that matter at scale), the library earns its place. Install it then not before.
When the native solution is genuinely insufficient (old browser support, edge cases it doesn't handle, ergonomics that matter at scale), the library earns its place. Install it then, not before.
+1 -1
View File
@@ -1,6 +1,6 @@
# Examples
Real model output, verbatim from benchmark runs the same task answered by the same model
Real model output, verbatim from benchmark runs, the same task answered by the same model
with no skill (`## Without Ponytail`) and with ponytail (`## With Ponytail`), so you can
compare side by side. Model: Claude Haiku 4.5, temperature 1, source `benchmarks/output.json`.
+5 -5
View File
@@ -2,9 +2,9 @@
**Task:** "Write Python code that reads sales.csv and sums the 'amount' column."
Verbatim model output from a benchmark run Claude Haiku 4.5, no-skill arm vs ponytail arm, temperature 1, source `benchmarks/output.json`. Reproduce: `npx promptfoo@latest eval -c benchmarks/promptfooconfig.yaml`.
Verbatim model output from a benchmark run, Claude Haiku 4.5, no-skill arm vs ponytail arm, temperature 1, source `benchmarks/output.json`. Reproduce: `npx promptfoo@latest eval -c benchmarks/promptfooconfig.yaml`.
## Without Ponytail 20 lines of code
## Without Ponytail, 20 lines of code
# Python code to read sales.csv and sum the 'amount' column
@@ -57,7 +57,7 @@ except KeyError:
- Provides built-in error handling
- Efficient for large files
## With Ponytail 3 lines of code
## With Ponytail, 3 lines of code
```python
import csv
@@ -66,6 +66,6 @@ total = sum(float(row['amount']) for row in csv.DictReader(open('sales.csv')))
print(total)
```
Skipped: pandas, error handling, file closing add when the CSV is large, malformed, or you need more analysis.
Skipped: pandas, error handling, file closing, add when the CSV is large, malformed, or you need more analysis.
**20 → 3 lines of code** same model, same prompt.
**20 → 3 lines of code**, same model, same prompt.
+5 -5
View File
@@ -2,9 +2,9 @@
**Task:** "Add debounce to a search input in vanilla JavaScript. It currently fires an API call on every keystroke."
Verbatim model output from a benchmark run Claude Haiku 4.5, no-skill arm vs ponytail arm, temperature 1, source `benchmarks/output.json`. Reproduce: `npx promptfoo@latest eval -c benchmarks/promptfooconfig.yaml`.
Verbatim model output from a benchmark run, Claude Haiku 4.5, no-skill arm vs ponytail arm, temperature 1, source `benchmarks/output.json`. Reproduce: `npx promptfoo@latest eval -c benchmarks/promptfooconfig.yaml`.
## Without Ponytail 116 lines of code
## Without Ponytail, 116 lines of code
# Debounce Search Input
@@ -190,7 +190,7 @@ searchInput.addEventListener('blur', () => {
**Typical keystroke reduction:** 10 characters = 10 API calls → 1-2 API calls with debounce ✅
## With Ponytail 10 lines of code
## With Ponytail, 10 lines of code
```javascript
const searchInput = document.querySelector('input[type="search"]');
@@ -206,6 +206,6 @@ searchInput.addEventListener('input', (e) => {
});
```
Skipped: debounce utility function, class wrapper, config object `setTimeout` + `clearTimeout` is the debounce. Add a utility when you need it on 3+ inputs.
Skipped: debounce utility function, class wrapper, config object, `setTimeout` + `clearTimeout` is the debounce. Add a utility when you need it on 3+ inputs.
**116 → 10 lines of code** same model, same prompt.
**116 → 10 lines of code**, same model, same prompt.
+1 -1
View File
@@ -28,4 +28,4 @@ const copy = JSON.parse(JSON.stringify(original));
const copy = structuredClone(original);
```
**1 dependency (or a fragile hack) → 1 built-in.** `structuredClone` handles `Date`, `Map`, `Set`, `ArrayBuffer`, `RegExp`, circular references, and more everything `JSON.parse/stringify` silently drops. Available in every browser since 2022 and Node.js since v17. Pull lodash in when you need the rest of it, not for one function.
**1 dependency (or a fragile hack) → 1 built-in.** `structuredClone` handles `Date`, `Map`, `Set`, `ArrayBuffer`, `RegExp`, circular references, and more, everything `JSON.parse/stringify` silently drops. Available in every browser since 2022 and Node.js since v17. Pull lodash in when you need the rest of it, not for one function.
+5 -5
View File
@@ -2,9 +2,9 @@
**Task:** "Write me a Python function that validates email addresses."
Verbatim model output from a benchmark run Claude Haiku 4.5, no-skill arm vs ponytail arm, temperature 1, source `benchmarks/output.json`. Reproduce: `npx promptfoo@latest eval -c benchmarks/promptfooconfig.yaml`.
Verbatim model output from a benchmark run, Claude Haiku 4.5, no-skill arm vs ponytail arm, temperature 1, source `benchmarks/output.json`. Reproduce: `npx promptfoo@latest eval -c benchmarks/promptfooconfig.yaml`.
## Without Ponytail 75 lines of code
## Without Ponytail, 75 lines of code
# Email Validation Function
@@ -142,7 +142,7 @@ if __name__ == "__main__":
**Recommendation**: Use the `email-validator` library for production applications, as it properly handles RFC 5321/5322 standards. Use the simple regex version for quick scripts or when you want to avoid dependencies.
## With Ponytail 3 lines of code
## With Ponytail, 3 lines of code
```python
import re
@@ -151,6 +151,6 @@ def is_valid_email(email: str) -> bool:
return bool(re.match(r'^[^@]+@[^@]+\.[^@]+$', email))
```
Skipped: RFC 5322 parser, DNS MX lookup, confirmation email. Add when you actually need to reject `user+tag@sub.domain.co.uk` or catch typos until then, this catches 99% of "oops I fat-fingered it" cases.
Skipped: RFC 5322 parser, DNS MX lookup, confirmation email. Add when you actually need to reject `user+tag@sub.domain.co.uk` or catch typos, until then, this catches 99% of "oops I fat-fingered it" cases.
**75 → 3 lines of code** same model, same prompt.
**75 → 3 lines of code**, same model, same prompt.
+1 -1
View File
@@ -32,4 +32,4 @@ const byStatus = Object.groupBy(orders, order => order.status);
// → { pending: [...], shipped: [...], delivered: [...] }
```
**1 dependency (or a reduce) → 1 built-in.** `Object.groupBy` shipped in Chrome 117, Firefox 119, Safari 17.4, Node.js 21. If you need a `Map` instead of a plain object: `Map.groupBy(orders, o => o.status)`. Check your target runtime; if you need IE11 or old Node, the `reduce` one-liner is still the right call not lodash.
**1 dependency (or a reduce) → 1 built-in.** `Object.groupBy` shipped in Chrome 117, Firefox 119, Safari 17.4, Node.js 21. If you need a `Map` instead of a plain object: `Map.groupBy(orders, o => o.status)`. Check your target runtime; if you need IE11 or old Node, the `reduce` one-liner is still the right call, not lodash.
+1 -1
View File
@@ -55,4 +55,4 @@ export function Feed({ items, fetchMore, hasMore }) {
}
```
**1 dependency → 0 dependencies.** `IntersectionObserver` fires only when the sentinel enters the viewport no scroll event, no throttling, no jank. Ships in every browser. The library wraps exactly this API.
**1 dependency → 0 dependencies.** `IntersectionObserver` fires only when the sentinel enters the viewport, no scroll event, no throttling, no jank. Ships in every browser. The library wraps exactly this API.
+1 -1
View File
@@ -37,7 +37,7 @@ export function DeleteModal({ onConfirm, onCancel }) {
}
```
A dependency, a portal, an overlay, a root, a trigger, a content wrapper to show a box with two buttons.
A dependency, a portal, an overlay, a root, a trigger, a content wrapper, to show a box with two buttons.
## With Ponytail
+6 -6
View File
@@ -2,9 +2,9 @@
**Task:** "Add rate limiting to my FastAPI endpoint so users can't spam it."
Verbatim model output from a benchmark run Claude Haiku 4.5, no-skill arm vs ponytail arm, temperature 1, source `benchmarks/output.json`. Reproduce: `npx promptfoo@latest eval -c benchmarks/promptfooconfig.yaml`.
Verbatim model output from a benchmark run, Claude Haiku 4.5, no-skill arm vs ponytail arm, temperature 1, source `benchmarks/output.json`. Reproduce: `npx promptfoo@latest eval -c benchmarks/promptfooconfig.yaml`.
## Without Ponytail 128 lines of code
## Without Ponytail, 128 lines of code
# Rate Limiting in FastAPI
@@ -248,9 +248,9 @@ async def test_rate_limit():
# First 5 should be 200, 6th should be 429
```
**Recommendation:** Use `slowapi` for most casesit's the most popular and easiest to implement! 🚀
**Recommendation:** Use `slowapi` for most cases, it's the most popular and easiest to implement! 🚀
## With Ponytail 10 lines of code
## With Ponytail, 10 lines of code
```python
from fastapi import FastAPI, HTTPException
@@ -267,6 +267,6 @@ async def my_endpoint(request):
return {"status": "ok"}
```
Skipped: custom rate limit logic, Redis, sliding windows `slowapi` handles it. Add when: you need distributed rate limiting across multiple servers (swap `Limiter` for Redis backend) or per-user limits (add `key_func=lambda r: r.headers.get("authorization")`).
Skipped: custom rate limit logic, Redis, sliding windows, `slowapi` handles it. Add when: you need distributed rate limiting across multiple servers (swap `Limiter` for Redis backend) or per-user limits (add `key_func=lambda r: r.headers.get("authorization")`).
**128 → 10 lines of code** same model, same prompt.
**128 → 10 lines of code**, same model, same prompt.
+5 -5
View File
@@ -2,9 +2,9 @@
**Task:** "Build me a countdown timer component in React that counts down from a given number of seconds."
Verbatim model output from a benchmark run Claude Haiku 4.5, no-skill arm vs ponytail arm, temperature 1, source `benchmarks/output.json`. Reproduce: `npx promptfoo@latest eval -c benchmarks/promptfooconfig.yaml`.
Verbatim model output from a benchmark run, Claude Haiku 4.5, no-skill arm vs ponytail arm, temperature 1, source `benchmarks/output.json`. Reproduce: `npx promptfoo@latest eval -c benchmarks/promptfooconfig.yaml`.
## Without Ponytail 267 lines of code
## Without Ponytail, 267 lines of code
# React Countdown Timer Component
@@ -369,7 +369,7 @@ export function StyledCountdownTimer({ initialSeconds = 60 }) {
Choose the version that best fits your needs!
## With Ponytail 9 lines of code
## With Ponytail, 9 lines of code
```jsx
export function CountdownTimer({ seconds }) {
@@ -385,6 +385,6 @@ export function CountdownTimer({ seconds }) {
}
```
Skipped: pause/resume, formatted display (mm:ss), sound on zero, styling add when needed.
Skipped: pause/resume, formatted display (mm:ss), sound on zero, styling, add when needed.
**267 → 9 lines of code** same model, same prompt.
**267 → 9 lines of code**, same model, same prompt.
-64
View File
@@ -1,64 +0,0 @@
# Web Platform Lookup
**Task:** "Add a modal dialog that closes when you click the backdrop."
Rung 3 of the ladder is "native platform feature covers it?" On web work the
trap is that the agent forgets what the platform already does and reaches for a
library. When ponytail has [Modern Web Guidance](https://github.com/GoogleChrome/modern-web-guidance)
on hand, rung 3 gets a lookup: `modern-web search "modal dialog light dismiss"`.
## Without Ponytail
```bash
npm install @radix-ui/react-dialog
```
```jsx
import * as Dialog from "@radix-ui/react-dialog";
export default function Modal({ open, onOpenChange, children }) {
return (
<Dialog.Root open={open} onOpenChange={onOpenChange}>
<Dialog.Portal>
<Dialog.Overlay className="overlay" />
<Dialog.Content className="content">
{children}
<Dialog.Close className="close">×</Dialog.Close>
</Dialog.Content>
</Dialog.Portal>
</Dialog.Root>
);
}
```
A dependency, a portal, an overlay node, and controlled open state, to put a
box on top with a backdrop.
## With Ponytail
`modern-web search "modal dialog light dismiss"`
`modern-web retrieve light-dismiss-a-dialog`. The platform has it:
```html
<!-- ponytail: <dialog> + closedby, browser does the backdrop, focus trap, and Esc -->
<dialog closedby="any">
<p>...</p>
</dialog>
```
```js
document.querySelector("dialog").showModal();
```
**1 dependency + portal/overlay machinery → 0 dependencies + a `<dialog>`.**
The `::backdrop` is free, focus is trapped and restored for you, `Esc` closes
it, and `closedby="any"` adds click-outside dismissal. The browser team did the
work.
## The point
MWG suggests the cutting edge, ponytail keeps only the rung that holds. The
lookup found `light-dismiss-a-dialog`; the ladder took it because it deletes a
dependency. The same search would have offered scroll-driven animations and
view transitions for other tasks, and the ladder would have skipped them when
the task didn't need them. Lookup, not license.
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "ponytail",
"version": "4.7.0",
"version": "4.8.3",
"description": "Lazy senior dev mode. Forces the simplest, shortest solution that actually works: YAGNI, stdlib first, no unrequested abstractions.",
"contextFileName": "AGENTS.md"
}
+15 -2
View File
@@ -6,7 +6,7 @@
"hooks": [
{
"type": "command",
"command": "command -v node >/dev/null 2>&1 && node \"${CLAUDE_PLUGIN_ROOT}/hooks/ponytail-activate.js\" || exit 0",
"command": "node \"${CLAUDE_PLUGIN_ROOT}/hooks/ponytail-activate.js\"; exit 0",
"commandWindows": "if (Get-Command node -ErrorAction SilentlyContinue) { node \"$env:CLAUDE_PLUGIN_ROOT\\hooks\\ponytail-activate.js\" }",
"timeout": 5,
"statusMessage": "Loading ponytail mode..."
@@ -14,12 +14,25 @@
]
}
],
"SubagentStart": [
{
"hooks": [
{
"type": "command",
"command": "node \"${CLAUDE_PLUGIN_ROOT}/hooks/ponytail-subagent.js\"; exit 0",
"commandWindows": "if (Get-Command node -ErrorAction SilentlyContinue) { node \"$env:CLAUDE_PLUGIN_ROOT\\hooks\\ponytail-subagent.js\" }",
"timeout": 5,
"statusMessage": "Loading ponytail mode..."
}
]
}
],
"UserPromptSubmit": [
{
"hooks": [
{
"type": "command",
"command": "command -v node >/dev/null 2>&1 && node \"${CLAUDE_PLUGIN_ROOT}/hooks/ponytail-mode-tracker.js\" || exit 0",
"command": "node \"${CLAUDE_PLUGIN_ROOT}/hooks/ponytail-mode-tracker.js\"; exit 0",
"commandWindows": "if (Get-Command node -ErrorAction SilentlyContinue) { node \"$env:CLAUDE_PLUGIN_ROOT\\hooks\\ponytail-mode-tracker.js\" }",
"timeout": 5,
"statusMessage": "Tracking ponytail mode..."
+27 -14
View File
@@ -8,11 +8,12 @@
const fs = require('fs');
const path = require('path');
const { getDefaultMode, getClaudeDir } = require('./ponytail-config');
const { getDefaultMode, getClaudeDir, isShellSafe } = require('./ponytail-config');
const { getPonytailInstructions } = require('./ponytail-instructions');
const {
clearMode,
isCodex,
isCopilot,
setMode,
writeHookOutput,
} = require('./ponytail-runtime');
@@ -25,7 +26,8 @@ const mode = getDefaultMode();
// "off" mode — skip activation entirely, don't write flag or emit rules
if (mode === 'off') {
clearMode();
writeHookOutput('SessionStart', 'off', isCodex ? '' : 'OK');
const hookOutput = (isCodex || isCopilot) ? '' : 'OK';
writeHookOutput('SessionStart', 'off', hookOutput);
process.exit(0);
}
@@ -40,7 +42,7 @@ try {
let output = getPonytailInstructions(mode);
// 3. Detect missing statusline config — nudge Claude to help set it up
if (!isCodex) try {
if (!isCodex && !isCopilot) try {
let hasStatusline = false;
if (fs.existsSync(settingsPath)) {
// Strip UTF-8 BOM some editors prepend on Windows (breaks JSON.parse)
@@ -55,17 +57,28 @@ if (!isCodex) try {
const isWindows = process.platform === 'win32';
const scriptName = isWindows ? 'ponytail-statusline.ps1' : 'ponytail-statusline.sh';
const scriptPath = path.join(__dirname, scriptName);
const command = isWindows
? `powershell -ExecutionPolicy Bypass -File "${scriptPath}"`
: `bash "${scriptPath}"`;
const statusLineSnippet =
'"statusLine": { "type": "command", "command": ' + JSON.stringify(command) + ' }';
output += "\n\n" +
"STATUSLINE SETUP NEEDED: The ponytail plugin includes a statusline badge showing active mode " +
"(e.g. [PONYTAIL], [PONYTAIL:ULTRA]). It is not configured yet. " +
"To enable, add this to ~/.claude/settings.json: " +
statusLineSnippet + " " +
"Proactively offer to set this up for the user on first interaction.";
if (isShellSafe(scriptPath)) {
const command = isWindows
? `powershell -ExecutionPolicy Bypass -File "${scriptPath}"`
: `bash "${scriptPath}"`;
const statusLineSnippet =
'"statusLine": { "type": "command", "command": ' + JSON.stringify(command) + ' }';
output += "\n\n" +
"STATUSLINE SETUP NEEDED: The ponytail plugin includes a statusline badge showing active mode " +
"(e.g. [PONYTAIL], [PONYTAIL:ULTRA]). It is not configured yet. " +
"To enable, add this to ~/.claude/settings.json: " +
statusLineSnippet + " " +
"Proactively offer to set this up for the user on first interaction.";
} else {
// ponytail: install path has shell metacharacters — don't embed it in a
// command snippet; have the agent wire it up by hand instead.
output += "\n\n" +
"STATUSLINE SETUP NEEDED: The ponytail plugin includes a statusline badge showing active mode. " +
"Its install path contains characters unsafe to embed in a shell command, so configure it manually: " +
"add a statusLine command of type \"command\" that runs " + scriptName +
" from the plugin's hooks directory to ~/.claude/settings.json, quoting/escaping the path for your shell. " +
"Proactively offer to set this up for the user on first interaction.";
}
}
} catch (e) {
// Silent fail — don't block session start over statusline detection
+10
View File
@@ -42,6 +42,15 @@ function isDeactivationCommand(text) {
return t === 'stop ponytail' || t === 'normal mode';
}
// ponytail: only embed the plugin install path in a statusline shell command when
// it's made of ordinary path characters. An allowlist beats escaping every shell's
// metacharacters; a hostile clone path (quotes, &, $, backtick, ;, etc.) falls back
// to manual setup instead. Allows : \ / for normal Windows and POSIX paths. Full
// per-shell escaper only if a real need appears.
function isShellSafe(p) {
return typeof p === 'string' && /^[A-Za-z0-9 _.\-:/\\~]+$/.test(p);
}
function getConfigDir() {
if (process.env.XDG_CONFIG_HOME) {
return path.join(process.env.XDG_CONFIG_HOME, 'ponytail');
@@ -104,6 +113,7 @@ module.exports = {
getConfigDir,
getConfigPath,
getClaudeDir,
isShellSafe,
normalizeMode,
normalizeConfigMode,
normalizePersistedMode,
+9 -7
View File
@@ -43,13 +43,15 @@ function getFallbackInstructions(mode) {
'ACTIVE EVERY RESPONSE. No drift back to over-building. Still active if unsure. Off only: "stop ponytail" / "normal mode".\n\n' +
'Current level: **' + mode + '**. Switch: `/ponytail lite|full|ultra`.\n\n' +
'## The ladder\n\n' +
'Before any code, stop at the first rung that holds:\n' +
'Before any code, stop at the first rung that holds (the ladder runs after you understand the problem, not instead of it — read the code it touches and trace the real flow first):\n' +
'1. Does this need to be built at all? (YAGNI)\n' +
'2. Does the standard library do this? Use it.\n' +
'3. Does a native platform feature cover it? Use it.\n' +
'4. Does an already-installed dependency solve it? Use it.\n' +
'5. Can this be one line? Make it one line.\n' +
'6. Only then: write the minimum code that works.\n\n' +
'2. Does it already exist in this codebase? Reuse what is already here, do not re-write it.\n' +
'3. Does the standard library do this? Use it.\n' +
'4. Does a native platform feature cover it? Use it.\n' +
'5. Does an already-installed dependency solve it? Use it.\n' +
'6. Can this be one line? Make it one line.\n' +
'7. Only then: write the minimum code that works.\n\n' +
'Bug fix = root cause, not symptom: grep every caller of the function you touch and fix the shared function once (a smaller diff than one guard per caller); patching only the path the ticket names leaves a sibling caller broken.\n\n' +
'## Rules\n\n' +
'No abstractions that were not requested. No avoidable dependencies. No boilerplate nobody asked for. ' +
'Deletion over addition. Boring over clever. Fewest files possible. ' +
@@ -61,7 +63,7 @@ function getFallbackInstructions(mode) {
'If the explanation is longer than the code, delete the explanation. ' +
'Explanation the user explicitly asked for is not debt, give it in full.\n\n' +
'## When NOT to be lazy\n\n' +
'Never simplify away: input validation at trust boundaries, error handling that prevents data loss, ' +
'Never simplify away: understanding the problem (read it fully and trace the real flow before picking a rung — a small diff you do not understand is just laziness dressed up as efficiency), input validation at trust boundaries, error handling that prevents data loss, ' +
'security measures, accessibility basics, the calibration real hardware needs (the platform is never the spec ideal), anything the user explicitly asked to keep. ' +
'Lazy code without its check is unfinished: non-trivial logic leaves ONE runnable check behind (assert-based demo/self-check or one small test file; no frameworks). Trivial one-liners need no test.\n\n' +
'## Boundaries\n\n' +
+17
View File
@@ -21,6 +21,15 @@ function clearMode() {
try { fs.unlinkSync(statePath); } catch (e) {}
}
// Live mode written by activate/mode-tracker. Absent flag = ponytail off.
function readMode() {
try {
return fs.readFileSync(statePath, 'utf8').trim() || null;
} catch (e) {
return null;
}
}
function writeHookOutput(event, mode, context = '') {
if (isCopilot) {
// Copilot reads additionalContext on SessionStart; ignores output elsewhere.
@@ -39,6 +48,13 @@ function writeHookOutput(event, mode, context = '') {
process.stdout.write(JSON.stringify(output));
return;
}
// Native Claude: SessionStart accepts raw stdout, but SubagentStart needs the
// hookSpecificOutput JSON form or the context is dropped.
if (event === 'SubagentStart') {
process.stdout.write(JSON.stringify(
{ hookSpecificOutput: { hookEventName: event, additionalContext: context } }));
return;
}
process.stdout.write(context);
}
@@ -46,6 +62,7 @@ module.exports = {
clearMode,
isCodex,
isCopilot,
readMode,
setMode,
writeHookOutput,
};
+22
View File
@@ -0,0 +1,22 @@
#!/usr/bin/env node
// ponytail — Claude Code SubagentStart hook
//
// SessionStart context is parent-thread only and never reaches subagents, so
// without this every Task-spawned agent runs ponytail-unaware (issue #252).
// When ponytail mode is active, inject the same ruleset into each subagent.
const { getPonytailInstructions } = require('./ponytail-instructions');
const { readMode, writeHookOutput } = require('./ponytail-runtime');
const mode = readMode();
// Absent flag or off → ponytail isn't active; inject nothing.
if (!mode || mode === 'off') {
process.exit(0);
}
try {
writeHookOutput('SubagentStart', mode, getPonytailInstructions(mode));
} catch (e) {
// Silent fail — a stdout error at hook exit must not surface as a hook failure.
}
+32 -3
View File
@@ -1,14 +1,43 @@
{
"name": "ponytail",
"version": "0.1.0",
"name": "@dietrichgebert/ponytail",
"version": "4.8.3",
"description": "Lazy senior dev mode for AI agents. The best code is the code you never wrote.",
"keywords": ["pi-package", "pi", "skills", "ponytail"],
"keywords": ["opencode-plugin", "opencode", "ponytail", "pi-package", "pi", "skills"],
"license": "MIT",
"author": {
"name": "Dietrich Gebert",
"url": "https://github.com/DietrichGebert"
},
"homepage": "https://github.com/DietrichGebert/ponytail",
"repository": {
"type": "git",
"url": "git+https://github.com/DietrichGebert/ponytail.git"
},
"bugs": {
"url": "https://github.com/DietrichGebert/ponytail/issues"
},
"main": "./.opencode/plugins/ponytail.mjs",
"exports": {
".": "./.opencode/plugins/ponytail.mjs",
"./plugin": "./.opencode/plugins/ponytail.mjs"
},
"files": [
"AGENTS.md",
"hooks/",
"skills/",
".opencode/",
"pi-extension/",
"assets/",
"LICENSE"
],
"scripts": {
"test": "node --test tests/*.test.js && npm test --prefix pi-extension"
},
"pi": {
"extensions": ["./pi-extension/index.js"],
"skills": ["./skills"]
},
"publishConfig": {
"access": "public"
}
}
+32
View File
@@ -56,6 +56,25 @@ export { writeDefaultMode };
export default function ponytailExtension(pi) {
let currentMode = DEFAULT_MODE;
let configuredDefaultMode = getDefaultMode();
let isActive = false;
let lastCtx = null;
// -- Status bar --
function syncStatus(ctx) {
if (ctx) lastCtx = ctx;
const c = ctx || lastCtx;
if (!c?.ui?.setStatus || !c.ui.theme?.fg) return;
const theme = c.ui.theme;
if (currentMode === "off") {
c.ui.setStatus("ponytail", "");
return;
}
const levelIcons = { lite: "🌿", full: "⚡", ultra: "🔥" };
const icon = levelIcons[currentMode] || "";
const label = currentMode.toUpperCase();
const indicator = isActive ? theme.fg("accent", "●") : theme.fg("dim", "○");
c.ui.setStatus("ponytail", indicator + " 🐴 " + theme.fg("muted", "ponytail: ") + theme.fg("text", icon + " " + label));
}
const setMode = (mode, ctx) => {
const normalized = normalizePersistedMode(mode);
@@ -63,6 +82,7 @@ export default function ponytailExtension(pi) {
currentMode = normalized;
pi.appendEntry("ponytail-mode", { mode: normalized });
syncStatus(ctx);
ctx?.ui?.notify?.(`Ponytail mode set to ${normalized}.`, "info");
};
@@ -148,6 +168,18 @@ export default function ponytailExtension(pi) {
const entries = ctx?.sessionManager?.getBranch?.() || ctx?.sessionManager?.getEntries?.() || [];
configuredDefaultMode = getDefaultMode();
currentMode = resolveSessionMode(entries, configuredDefaultMode);
syncStatus(ctx);
ctx?.ui?.notify?.(`Ponytail loaded: ${currentMode}`, "info");
});
pi.on("agent_start", async (_event, ctx) => {
isActive = true;
syncStatus(ctx);
});
pi.on("agent_end", async (_event, ctx) => {
isActive = false;
syncStatus(ctx);
});
pi.on("before_agent_start", async (event) => {
+30
View File
@@ -135,3 +135,33 @@ test("a request mentioning normal mode stays active", async () => withTempConfig
const result = await events.get("before_agent_start")({ systemPrompt: "BASE" }, ctx);
assert.match(result.systemPrompt, /PONYTAIL MODE ACTIVE/);
}));
test("status bar renders the mode and flips active on agent_start", async () => withTempConfig(async () => {
const { events } = createPiHarness();
const statusWrites = [];
const ctx = createCommandContext({
sessionManager: { getEntries: () => [{ type: "custom", customType: "ponytail-mode", data: { mode: "ultra" } }] },
ui: { notify() {}, setStatus: (key, text) => statusWrites.push({ key, text }), theme: { fg: (_color, text) => text } },
});
await events.get("session_start")({ reason: "resume" }, ctx);
await events.get("agent_start")({}, ctx);
assert.equal(statusWrites.at(-2).key, "ponytail");
assert.match(statusWrites.at(-2).text, /○.*ULTRA/);
assert.match(statusWrites.at(-1).text, /●.*ULTRA/);
}));
test("status bar stays silent when ui lacks a theme", async () => withTempConfig(async () => {
const { events } = createPiHarness();
const calls = [];
const ctx = createCommandContext({
sessionManager: { getEntries: () => [{ type: "custom", customType: "ponytail-mode", data: { mode: "ultra" } }] },
ui: { notify() {}, setStatus: (_key, text) => calls.push(text) }, // setStatus present, theme absent
});
await events.get("session_start")({ reason: "resume" }, ctx);
await events.get("agent_start")({}, ctx);
assert.deepEqual(calls, []);
}));
+7
View File
@@ -31,6 +31,13 @@ test("resolveSessionMode prefers latest persisted session mode", () => {
assert.equal(resolveSessionMode(entries, "full"), "ultra");
});
test("resolveSessionMode returns fallback when entries is not an array", () => {
assert.equal(resolveSessionMode(null, "ultra"), "ultra");
assert.equal(resolveSessionMode(undefined, "lite"), "lite");
assert.equal(resolveSessionMode({}, "full"), "full");
assert.equal(resolveSessionMode("not an array"), "full"); // DEFAULT_MODE fallback
});
test("readDefaultMode and writeDefaultMode use XDG config path", () => {
const tempDir = mkdtempSync(join(tmpdir(), "ponytail-config-"));
const previousXdg = process.env.XDG_CONFIG_HOME;
+2 -2
View File
@@ -12,9 +12,9 @@ prompt menu, or that pull context through tools. See issue #70.
## What it exposes
- Prompt `ponytail` returns the ruleset as a user message. Optional `mode`
- Prompt `ponytail`, returns the ruleset as a user message. Optional `mode`
argument: `lite`, `full`, or `ultra`. Omit it to use the configured default.
- Tool `ponytail_instructions` same text, plus `structuredContent`
- Tool `ponytail_instructions`, same text, plus `structuredContent`
(`{ mode, instructions }`), for hosts that pull context via tools or code
execution. Read-only.
+2 -2
View File
@@ -1,13 +1,13 @@
{
"name": "ponytail-mcp",
"version": "0.1.0",
"version": "4.8.3",
"description": "MCP server that serves Ponytail's lazy-senior-dev instructions as a prompt and a tool.",
"private": true,
"type": "module",
"license": "MIT",
"scripts": { "test": "node --test ./test/*.test.js" },
"dependencies": {
"@modelcontextprotocol/sdk": "^1.19.0",
"@modelcontextprotocol/sdk": "^1.26.0",
"zod": "^3.23.0"
}
}
+76
View File
@@ -0,0 +1,76 @@
#!/usr/bin/env node
// Version-consistency guard. Ponytail declares its version in six files across
// four host ecosystems, and every release bumps all of them by hand.
//
// tests/gemini-extension.test.js already checks the four plugin manifests agree
// with each other, but that can't catch the failure mode that shipped in v4.8.0:
// every manifest stayed stale at 4.7.0 *together* while the release moved on, so
// they "agreed" and the test passed (#260, #262). It also ignores the two
// package.json files. This check closes both gaps:
// 1. every version-bearing file must share one pinned X.Y.Z version, and
// 2. on a release-tag CI run, that shared version must equal the tag.
const fs = require('fs');
const path = require('path');
const root = path.join(__dirname, '..');
const PINNED_SEMVER = /^\d+\.\d+\.\d+$/;
// Every file that declares the project version, and who reads it. Add new host
// manifests here so a future ecosystem can't drift unnoticed.
const VERSION_FILES = [
'.claude-plugin/plugin.json', // Claude Code plugin — what users install
'.codex-plugin/plugin.json', // Codex plugin
'.github/plugin/plugin.json', // Copilot plugin
'gemini-extension.json', // Gemini CLI extension
'package.json', // pi-package / repo root
'ponytail-mcp/package.json', // MCP server (private, internal-only)
];
function readVersion(relPath) {
try {
// Strip a UTF-8 BOM some Windows editors prepend (breaks JSON.parse).
const raw = fs.readFileSync(path.join(root, relPath), 'utf8').replace(/^\uFEFF/, '');
return JSON.parse(raw).version;
} catch (e) {
throw new Error(`${relPath}: ${e.message}`);
}
}
let failed = false;
const versions = VERSION_FILES.map((relPath) => {
const version = readVersion(relPath);
if (typeof version !== 'string' || !PINNED_SEMVER.test(version)) {
console.error(`${relPath}: version must be a pinned X.Y.Z semver, got ${JSON.stringify(version)}`);
failed = true;
}
return [relPath, version];
});
// Every file must declare the same version.
const distinct = [...new Set(versions.map(([, v]) => v))];
if (distinct.length > 1) {
console.error('Version mismatch — every manifest must share one version:');
for (const [relPath, version] of versions) console.error(` ${version}\t${relPath}`);
failed = true;
}
const shared = distinct.length === 1 ? distinct[0] : null;
// On a release-tag push CI sets GITHUB_REF_TYPE=tag and GITHUB_REF_NAME=vX.Y.Z.
// The shared version must equal the tag — this catches tagging a release whose
// version files were never bumped, which mutual agreement alone cannot.
if (shared && process.env.GITHUB_REF_TYPE === 'tag') {
const tag = process.env.GITHUB_REF_NAME || '';
const tagVersion = tag.replace(/^v/, '');
if (PINNED_SEMVER.test(tagVersion) && tagVersion !== shared) {
console.error(`release tag ${tag} does not match version ${shared}; bump the version files before tagging`);
failed = true;
}
}
if (failed) {
console.error('Align the version fields (see issue #260) so every manifest shares one version.');
process.exit(1);
}
console.log(`All ${VERSION_FILES.length} version files pinned at ${shared}.`);
+75
View File
@@ -0,0 +1,75 @@
#!/usr/bin/env node
// Publish the generated OpenClaw skills (.openclaw/skills/) to ClawHub.
//
// ClawHub does not sync from GitHub: each skill is pushed explicitly with the
// clawhub CLI and carries its own version. This publishes every generated skill
// in one pass, versioned from the repo's package.json so ClawHub tracks the repo
// instead of drifting (the same drift that hit the plugin manifests in #260).
//
// Prereqs:
// - `clawhub login` once (registry auth persists)
// - skills must be current: run `node scripts/build-openclaw-skills.js` first
// if you changed a skill (CI fails if the committed copies are stale)
//
// Usage:
// node scripts/publish-openclaw-skills.js # publish all as latest
// node scripts/publish-openclaw-skills.js --dry-run # preview, upload nothing
// (any extra args are passed through to `clawhub skill publish`)
const fs = require('fs');
const path = require('path');
const { spawnSync } = require('child_process');
const root = path.join(__dirname, '..');
const skillsDir = path.join(root, '.openclaw', 'skills');
const version = JSON.parse(fs.readFileSync(path.join(root, 'package.json'), 'utf8')).version;
// Every generated skill dir with a SKILL.md is publishable. Reading the dir
// (instead of a hardcoded list) covers whatever build-openclaw-skills emits,
// with nothing to keep in sync.
const slugs = fs.readdirSync(skillsDir, { withFileTypes: true })
.filter((e) => e.isDirectory() && fs.existsSync(path.join(skillsDir, e.name, 'SKILL.md')))
.map((e) => e.name)
.sort();
if (slugs.length === 0) {
console.error(`No skills under ${path.relative(root, skillsDir)}; run build-openclaw-skills.js first.`);
process.exit(1);
}
// "ponytail-review" -> "Ponytail Review"
const displayName = (slug) =>
slug.split('-').map((w) => w.charAt(0).toUpperCase() + w.slice(1)).join(' ');
// Minimal quoting that satisfies both POSIX sh and cmd.exe: only display names
// (which contain a space) need wrapping; slugs, versions, paths, and flags don't.
const quote = (a) => (/[^\w./-]/.test(a) ? `"${a}"` : a);
const passthrough = process.argv.slice(2);
const extra = passthrough.length ? ` (${passthrough.join(' ')})` : '';
console.log(`Publishing ${slugs.length} skills to ClawHub at version ${version}${extra}:`);
for (const slug of slugs) {
const args = [
'clawhub', 'skill', 'publish', `.openclaw/skills/${slug}`,
'--slug', slug,
'--name', displayName(slug),
'--version', version,
'--tags', 'latest',
...passthrough,
];
const cmdline = args.map(quote).join(' ');
console.log(`\n$ ${cmdline}`);
const res = spawnSync(cmdline, { stdio: 'inherit', cwd: root, shell: true });
if (res.status !== 0) {
console.error(
`\nPublish failed for "${slug}" (exit ${res.status}). ` +
`Check that the clawhub CLI is installed and you have run \`clawhub login\`, then re-run. ` +
`Skills already published in this run are unaffected.`,
);
process.exit(res.status || 1);
}
}
console.log(`\nDone. Published ${slugs.length} skills at ${version}.`);
+40
View File
@@ -0,0 +1,40 @@
#!/usr/bin/env node
// ponytail — removes state ponytail wrote outside the plugin's own files:
// the mode flag, the config file, and the statusLine entry it added to
// settings.json. Plugin files themselves are removed by each host's own
// uninstall command (see README); this only cleans up what those commands
// can't see.
const fs = require('fs');
const path = require('path');
const { getConfigPath, getClaudeDir } = require('../hooks/ponytail-config');
function removeIfExists(filePath, label) {
try {
fs.unlinkSync(filePath);
console.log(`Removed ${label}: ${filePath}`);
} catch (e) {
if (e.code !== 'ENOENT') throw e;
}
}
removeIfExists(path.join(getClaudeDir(), '.ponytail-active'), 'mode flag');
removeIfExists(getConfigPath(), 'config file');
const settingsPath = path.join(getClaudeDir(), 'settings.json');
try {
const raw = fs.readFileSync(settingsPath, 'utf8').replace(/^\uFEFF/, '');
const settings = JSON.parse(raw);
const cmd = settings.statusLine && settings.statusLine.command;
// ponytail: substring-match the script name, then drop the whole statusLine
// key. A combined statusline (e.g. caveman+ponytail) whose command contains
// "ponytail-statusline" gets removed wholesale. Parse out only ponytail's part
// if combined statuslines become common.
if (typeof cmd === 'string' && cmd.includes('ponytail-statusline')) {
delete settings.statusLine;
fs.writeFileSync(settingsPath, JSON.stringify(settings, null, 2), 'utf8');
console.log(`Removed ponytail statusLine entry from ${settingsPath}`);
}
} catch (e) {
if (e.code !== 'ENOENT') throw e;
}
+1 -1
View File
@@ -36,6 +36,6 @@ End with `net: -<N> lines, -<M> deps possible.` Nothing to cut: `Lean already. S
## Boundaries
Scope: over-engineering and complexity only. Correctness bugs, security holes,
and performance are explicitly out of scope — route them to a normal review
and performance are explicitly out of scope. Route them to a normal review
pass. Lists findings, applies nothing. One-shot.
"stop ponytail-audit" or "normal mode" to revert.
+1 -1
View File
@@ -26,7 +26,7 @@ the convention out of the ledger.
One row per marker, grouped by file:
`<file>:<line> <what was simplified>. ceiling: <the limit named>. upgrade: <the trigger to revisit>.`
`<file>:<line>, <what was simplified>. ceiling: <the limit named>. upgrade: <the trigger to revisit>.`
The convention is `ponytail: <ceiling>, <upgrade path>`, so pull the ceiling
and the trigger straight from the comment. Want an owner per row too? add
+1 -1
View File
@@ -50,7 +50,7 @@ If there is nothing to cut, say `Lean already. Ship.` and stop.
## Boundaries
Scope: over-engineering and complexity only. Correctness bugs, security holes,
and performance are explicitly out of scope — route them to a normal review
and performance are explicitly out of scope. Route them to a normal review
pass, not this one. A single smoke test or `assert`-based
self-check is the ponytail minimum, not bloat, never flag it for deletion.
Does not apply the fixes, only lists them.
+23 -17
View File
@@ -31,31 +31,31 @@ Switch: `/ponytail lite|full|ultra`.
Stop at the first rung that holds:
1. **Does this need to exist at all?** Speculative need = skip it, say so in one line. (YAGNI)
2. **Stdlib does it?** Use it.
3. **Native platform feature covers it?** `<input type="date">` over a picker lib, CSS over JS, DB constraint over app code.
4. **Already-installed dependency solves it?** Use it. Never add a new one for what a few lines can do.
5. **Can it be one line?** One line.
6. **Only then:** the minimum code that works.
2. **Already in this codebase?** A helper, util, type, or pattern that already lives here → reuse it. Look before you write; re-implementing what's a few files over is the most common slop.
3. **Stdlib does it?** Use it.
4. **Native platform feature covers it?** `<input type="date">` over a picker lib, CSS over JS, DB constraint over app code.
5. **Already-installed dependency solves it?** Use it. Never add a new one for what a few lines can do.
6. **Can it be one line?** One line.
7. **Only then:** the minimum code that works.
The ladder is a reflex, not a research project. Two rungs work → take the
higher one and move on. The first lazy solution that works is the right one.
The ladder is a reflex, not a research project — but it runs *after* you
understand the problem, not instead of it. Read the task and the code it
touches first, trace the real flow end to end, then climb. Two rungs work →
take the higher one and move on. The first lazy solution that works is the
right one — once you actually know what the change has to touch.
## Web tasks: rung 3 lookup
On web work, rung 3 is where the laziest win hides: a native element or CSS
behavior the agent forgot exists. If a web task turns on whether the platform
covers it (a date input, dialog, popover, view transition, container query),
and the `modern-web` CLI is available, look it up: `modern-web search "<task>"`,
then `modern-web retrieve <id>`. It is a lookup, not a license, the answer
still goes through the ladder. MWG suggests the cutting edge; you keep only the
rung that holds. Not installed? Skip it, the ladder runs fine without it.
**Bug fix = root cause, not symptom.** A report names a symptom. Before you
edit, grep every caller of the function you're about to touch. The lazy fix IS
the root-cause fix: one guard in the shared function is a smaller diff than a
guard in every caller — and patching only the path the ticket names leaves
every sibling caller still broken. Fix it once, where all callers route through.
## Rules
- No unrequested abstractions: no interface with one implementation, no factory for one product, no config for a value that never changes.
- No boilerplate, no scaffolding "for later", later can scaffold for itself.
- Deletion over addition. Boring over clever, clever is what someone decodes at 3am.
- Fewest files possible. Shortest working diff wins.
- Fewest files possible. Shortest working diff wins — but only once you understand the problem. The smallest change in the wrong place isn't lazy, it's a second bug.
- Complex request? Ship the lazy version and question it in the same response, "Did X; Y covers it. Need full X? Say so." Never stall on an answer you can default.
- Two stdlib options, same size? Take the one that's correct on edge cases. Lazy means writing less code, not picking the flimsier algorithm.
- Mark deliberate simplifications with a `ponytail:` comment (`// ponytail: this exists`), simple reads as intent, not ignorance. Shortcut with a known ceiling (global lock, O(n²) scan, naive heuristic)? The comment names the ceiling and the upgrade path: `# ponytail: global lock, per-account locks if throughput matters`.
@@ -91,6 +91,12 @@ that prevents data loss, security measures, accessibility basics, anything
explicitly requested. User insists on the full version → build it, no
re-arguing.
Never lazy about understanding the problem. The ladder shortens the
solution, never the reading. Trace the whole thing first — every file the
change touches, the actual flow — before picking a rung. Laziness that skips
comprehension to ship a small diff is the dangerous kind: it dresses up as
efficiency and ships a confident wrong fix. Read fully, then be lazy.
Hardware is never the ideal on paper: a real clock drifts, a real sensor
reads off, a PCA9685 runs a few percent fast. Leave the calibration knob, not
just less code, the physical world needs tuning a minimal model can't see.
+22
View File
@@ -18,6 +18,8 @@ const HOST_PLUGIN_MANIFESTS = [
];
// cmd.exe variable syntax (%FOO%); PowerShell leaves it literal, breaking the path.
const CMD_VAR_SYNTAX = /%[A-Za-z_][A-Za-z0-9_]*%/;
// PowerShell 5.1 rejects these POSIX shell guards when a host runs `command`.
const POSIX_GUARD_SYNTAX = /\bcommand\s+-v\b|&&|\|\||>\/dev\/null|2>&1/;
// Pull the hooks/<script> a command launches, so we can check it exists.
const HOOK_SCRIPT = /hooks[\\/]([\w.-]+\.(?:js|mjs|cjs|ps1|sh))/;
@@ -40,6 +42,26 @@ test('every commandWindows uses PowerShell $env: syntax, not cmd.exe %VAR%', ()
}
});
test('shared hook commands avoid POSIX-only guard syntax', () => {
const commands = commandHooks()
.map((h) => h.command)
.filter(Boolean);
assert.ok(commands.length > 0, 'expected at least one shared command entry');
for (const cmd of commands) {
assert.doesNotMatch(cmd, POSIX_GUARD_SYNTAX, `command uses POSIX-only guard syntax: ${cmd}`);
}
});
test('shared hook commands keep lifecycle hooks non-blocking', () => {
const commands = commandHooks()
.map((h) => h.command)
.filter(Boolean);
assert.ok(commands.length > 0, 'expected at least one shared command entry');
for (const cmd of commands) {
assert.match(cmd, /;\s*exit 0$/, `command must exit successfully if node or the hook script fails: ${cmd}`);
}
});
test('every hook command points at a script that ships in hooks/', () => {
for (const hook of commandHooks()) {
for (const cmd of [hook.command, hook.commandWindows].filter(Boolean)) {
+56 -3
View File
@@ -8,6 +8,16 @@ const { spawnSync } = require('child_process');
const root = path.join(__dirname, '..');
// isShellSafe gates the statusline setup snippet (issue #200): ordinary install
// paths pass, paths carrying shell metacharacters are rejected so they never get
// embedded in a shell command.
const { isShellSafe } = require('../hooks/ponytail-config');
assert.equal(isShellSafe('C:\\Users\\x\\.claude\\plugins\\ponytail\\hooks\\ponytail-statusline.ps1'), true);
assert.equal(isShellSafe('/home/u/.claude/plugins/ponytail/hooks/ponytail-statusline.sh'), true);
assert.equal(isShellSafe('/tmp/a"&calc.exe&"/x.sh'), false);
assert.equal(isShellSafe('/tmp/$(calc)/x.sh'), false);
assert.equal(isShellSafe('/tmp/a;rm -rf/x.sh'), false);
function run(script, env, input = '') {
return spawnSync(process.execPath, [path.join(root, 'hooks', script)], {
env: { ...process.env, ...env },
@@ -16,11 +26,19 @@ function run(script, env, input = '') {
});
}
// Keep the base env clean so the default-dir checks are deterministic; the
// CLAUDE_CONFIG_DIR case sets it explicitly.
// Keep the base env clean so the default-dir / native-Claude checks are
// deterministic; the CLAUDE_CONFIG_DIR and codex/copilot cases set these
// explicitly where needed. run() spreads process.env, so a PLUGIN_DATA /
// COPILOT_PLUGIN_DATA leaked from the dev or CI shell would otherwise steer
// writeHookOutput into the wrong branch and mis-fire the native assertions.
delete process.env.CLAUDE_CONFIG_DIR;
delete process.env.PLUGIN_DATA;
delete process.env.COPILOT_PLUGIN_DATA;
const temp = fs.mkdtempSync(path.join(os.tmpdir(), 'ponytail-hooks-'));
// Runs on normal exit and on assertion-throw exit; force makes it idempotent.
process.on('exit', () => fs.rmSync(temp, { recursive: true, force: true }));
const home = path.join(temp, 'home');
const pluginData = path.join(temp, 'plugin-data');
fs.mkdirSync(home, { recursive: true });
@@ -155,5 +173,40 @@ assert.equal(
output = JSON.parse(result.stdout);
assert.deepEqual(output, {});
fs.rmSync(temp, { recursive: true, force: true });
// SubagentStart hook: when ponytail mode is active it injects the ruleset into
// each subagent (issue #252). Native Claude must get the hookSpecificOutput JSON
// form, not raw stdout, or the context is dropped.
const subHome = path.join(temp, 'sub-home');
const subFlag = path.join(subHome, '.claude', '.ponytail-active');
fs.mkdirSync(path.dirname(subFlag), { recursive: true });
const subEnv = { HOME: subHome, USERPROFILE: subHome };
fs.writeFileSync(subFlag, 'full');
result = run('ponytail-subagent.js', subEnv);
assert.equal(result.status, 0, result.stderr);
output = JSON.parse(result.stdout);
assert.equal(output.hookSpecificOutput.hookEventName, 'SubagentStart');
assert.match(
output.hookSpecificOutput.additionalContext,
/PONYTAIL MODE ACTIVE — level: full/,
);
// No flag → ponytail off → inject nothing (empty stdout, no failure).
fs.unlinkSync(subFlag);
result = run('ponytail-subagent.js', subEnv);
assert.equal(result.status, 0, result.stderr);
assert.equal(result.stdout, '', 'SubagentStart must stay silent when ponytail is off');
// Codex shares claude-codex-hooks.json, so SubagentStart is reachable under Codex
// too — assert the codex branch emits the badge plus hookSpecificOutput.
const subCodex = path.join(temp, 'sub-codex');
fs.mkdirSync(subCodex, { recursive: true });
fs.writeFileSync(path.join(subCodex, '.ponytail-active'), 'full');
result = run('ponytail-subagent.js', { HOME: subHome, USERPROFILE: subHome, PLUGIN_DATA: subCodex });
assert.equal(result.status, 0, result.stderr);
output = JSON.parse(result.stdout);
assert.equal(output.systemMessage, 'PONYTAIL:FULL');
assert.equal(output.hookSpecificOutput.hookEventName, 'SubagentStart');
assert.match(output.hookSpecificOutput.additionalContext, /PONYTAIL MODE ACTIVE — level: full/);
console.log('hook compatibility checks passed');
+21 -2
View File
@@ -18,10 +18,12 @@ process.env.XDG_CONFIG_HOME = tmp;
delete process.env.PONYTAIL_DEFAULT_MODE;
const statePath = path.join(tmp, 'opencode', '.ponytail-active');
let loadPlugin;
let loadPlugin, parseCommandFile;
test.before(async () => {
const url = pathToFileURL(path.join(__dirname, '..', '.opencode', 'plugins', 'ponytail.mjs'));
loadPlugin = (await import(url)).default;
const mod = await import(url);
loadPlugin = mod.default;
parseCommandFile = mod.parseCommandFile;
});
function transform(hooks) {
@@ -61,4 +63,21 @@ test('unrelated commands do not touch the flag', async () => {
assert.equal(fs.existsSync(statePath), false);
});
test('parseCommandFile reads frontmatter description + body, LF and CRLF', () => {
const lf = path.join(tmp, 'cmd-lf.md');
fs.writeFileSync(lf, '---\ndescription: do a thing\n---\n\nthe template body\n');
assert.deepEqual(parseCommandFile(lf), { description: 'do a thing', template: 'the template body' });
// Windows checkouts (autocrlf) deliver CRLF — the parser must still match.
const crlf = path.join(tmp, 'cmd-crlf.md');
fs.writeFileSync(crlf, '---\r\ndescription: do a thing\r\n---\r\n\r\nthe template body\r\n');
assert.deepEqual(parseCommandFile(crlf), { description: 'do a thing', template: 'the template body' });
});
test('parseCommandFile returns null when there is no frontmatter', () => {
const bare = path.join(tmp, 'cmd-bare.md');
fs.writeFileSync(bare, 'no frontmatter here\n');
assert.equal(parseCommandFile(bare), null);
});
test.after(() => fs.rmSync(tmp, { recursive: true, force: true }));
+76
View File
@@ -0,0 +1,76 @@
#!/usr/bin/env node
const assert = require('assert');
const fs = require('fs');
const os = require('os');
const path = require('path');
const { spawnSync } = require('child_process');
const root = path.join(__dirname, '..');
function runUninstall(env) {
return spawnSync(process.execPath, [path.join(root, 'scripts', 'uninstall.js')], {
env: { ...process.env, ...env },
encoding: 'utf8',
});
}
delete process.env.CLAUDE_CONFIG_DIR;
const temp = fs.mkdtempSync(path.join(os.tmpdir(), 'ponytail-uninstall-'));
process.on('exit', () => fs.rmSync(temp, { recursive: true, force: true }));
const home = path.join(temp, 'home');
const claudeDir = path.join(home, '.claude');
fs.mkdirSync(claudeDir, { recursive: true });
const flagPath = path.join(claudeDir, '.ponytail-active');
fs.writeFileSync(flagPath, 'full');
const configDir = path.join(temp, 'config-home', 'ponytail');
fs.mkdirSync(configDir, { recursive: true });
const configPath = path.join(configDir, 'config.json');
fs.writeFileSync(configPath, JSON.stringify({ defaultMode: 'ultra' }));
const settingsPath = path.join(claudeDir, 'settings.json');
fs.writeFileSync(settingsPath, JSON.stringify({
statusLine: { type: 'command', command: 'bash /some/path/ponytail-statusline.sh' },
}));
const env = {
HOME: home,
USERPROFILE: home,
XDG_CONFIG_HOME: path.join(temp, 'config-home'),
};
let result = runUninstall(env);
assert.equal(result.status, 0, result.stderr);
assert.equal(fs.existsSync(flagPath), false, 'mode flag must be removed');
assert.equal(fs.existsSync(configPath), false, 'config file must be removed');
const settingsAfter = JSON.parse(fs.readFileSync(settingsPath, 'utf8'));
assert.equal(
settingsAfter.statusLine,
undefined,
'ponytail statusLine entry must be removed',
);
// A user's own, unrelated statusLine must survive untouched.
fs.writeFileSync(settingsPath, JSON.stringify({
statusLine: { type: 'command', command: 'bash ~/my-custom-statusline.sh' },
}));
result = runUninstall(env);
assert.equal(result.status, 0, result.stderr);
const settingsAfter2 = JSON.parse(fs.readFileSync(settingsPath, 'utf8'));
assert.equal(
settingsAfter2.statusLine.command,
'bash ~/my-custom-statusline.sh',
"a user's own statusLine must not be touched",
);
// Running on an already-clean machine must not throw.
result = runUninstall({ HOME: path.join(temp, 'home-empty'), USERPROFILE: path.join(temp, 'home-empty') });
assert.equal(result.status, 0, result.stderr);
console.log('uninstall script checks passed');