#643 Add update-jira-ticket pre-flight validator and rework recovery protocol - #654
Merged
Conversation
Pure validator library that flags the known failure classes for Jira's HTML→ADF conversion: composition violations (`<code>` nested with inline marks), named entities outside `&`/`<`/`>`, Confluence storage-format constructs, multi-line `<pre>`, and any element outside the allowlist. The validator is split into a minimal tag tokenizer, one function per rule class, a pure orchestrator, and a stdin/stdout CLI returning a discriminated-union JSON payload (`ok: true` or `ok: false` with findings). The skill body and build-pipeline wiring follow in subsequent commits.
Registers the validator as a third bundle target so `nmr --filter agents build` produces `content/skills/update-jira-ticket/update-jira-ticket.mjs`. Extends `BundleTarget` with an optional `smokeTest` clause that pipes a payload to the bundle and asserts on its parsed result; the new target uses it to verify the built bundle returns a `composition-code-inline-mark` finding for `<strong><code>x</code></strong>`. Existing targets keep the empty-argv default. Adds the new `.mjs` path to the root `.gitignore`, the package's `.prettierignore`, and the eslint config's bundle-ignore list, matching the existing convention for kb-add and kb-retrieve. Drops the unused `--check` flag from the CLI; there's only one mode today.
…t checker Shifts the skill body from "rules the agent must remember" to "rules the validator enforces; here's how to run it and act on findings." Adds a new Pre-flight checker section documenting the helper's stdin/stdout contract, the rule IDs, and how to act on findings. The composition-rules and character-handling sections shrink to the rationale only (the checker is the source of truth). Rewrites the recovery protocol so probe-ticket creation requires explicit user opt-in via a three-option recommendation-gradient prompt; the bisection, retry-cap, and JSONL-log machinery only run if the user picks "probe and bisect." Documents the probe-ticket tagging contract (label `mcp-probe`, deterministic title, description prefix) and a JQL sweep for cleanup. The doc-only `version_message` and file-path-mode rules remain as one-line don't-do-this constraints under the correct-path checklist (the validator only sees the HTML payload, not the MCP call args).
The CLI's entry-point gate compared `import.meta.url` to `process.argv[1]` directly, which fails when the helper is installed via `codeassembly-agents install --link`: the SKILL.md invocation expands `$(dirname "$SKILL_PATH")` to the symlink path, while `import.meta.url` resolves to the real source path. The two never match and `main()` silently does not run. Adds an `isEntryPoint()` helper matching the pattern in `src/kb-add/cli.ts` and `src/kb-retrieve/cli.ts` — both sides go through `realpathSync`, and a `realpathSync` failure emits a stderr warning so silent skips do not hide environment problems.
…ket rules
The `export type { OpenTagToken } from './parser.ts';` line in `rules.ts` was unused: the only consumers (`check.ts`, the tests) import the type directly from `parser.ts` or `types.ts`. The re-export added a maintenance signal that did not reflect any actual coupling.
…e-jira-ticket The plan's Risks section flagged `<a title="X<Y>Z">` as a known landmine for naive tokenizers and committed to testing it explicitly. The original test used `<` (an entity), which did not exercise the tokenizer's quote-awareness against a raw `<`. Adds a sibling test asserting the parser does not tokenize literal `<Y>` inside a quoted attribute value as a `disallowed-element`.
…ry section
The recovery-protocol step pointed at `_data/recommendation-gradient.md` for the option format. That path is relative to the codeassembly-agents source tree, not the installed `{platform_home_dir}/skills/update-jira-ticket/` layout, so the agent reading the skill at runtime cannot follow it. The inline example below already shows the format. Replaces the broken pointer with a self-contained orienting phrase that names the markers and tradeoff lines directly.
Adds a header note to `parser.ts` calling out two intentional tokenizer behaviors at the edges: HTML comments / CDATA / DOCTYPE declarations are not recognized, so tag-shaped content inside them is tokenized as real tags; and `walkTokens` does not auto-balance unclosed tags, so a sibling after an unclosed ancestor registers as nested under that ancestor. Adds two locking tests under a `documented parser limitations` describe block so a future change that "fixes" either behavior fails loudly and forces a conscious doctrine change rather than a silent behavior shift.
…ct relative path
The previous commit dropped this reference on the premise that `_data/recommendation-gradient.md` was not available in installed layouts. That premise was wrong — the install script copies `content/skills/_data/` to `{platform_home_dir}/skills/_data/`, and sibling skills (`collaboration`, `refine-plan`) reference it as `../_data/recommendation-gradient.md` from their own directory. Restores the link using the correct relative path so future doctrine updates flow through to this skill without needing to keep the inline summary in sync.
Dependency auditProduction dependency audit passed. |
williamthorsen
marked this pull request as ready for review
May 25, 2026 08:14
williamthorsen
added a commit
that referenced
this pull request
Jul 18, 2026
…0.2.1 agents-v0.3.0 - #1019 feat: Add a personal rulebook with em-dash usage rule (#1024) - #1005 internal: Emit session-lifecycle events via harness hooks (#1021) - #1014 fix: Rebuild post-review next steps on the reviewer/author role model (#1020) - #1008 feat: Add a managed event-hook utility for Rovo config.yml (#1017) - #1004 feat: Add an implement-plan skill for the implementation phase (#1016) - #1009 fix: Sweep ticket and plan for missed decisions before saving (#1015) - #1007 internal: Add a managed hook-entry utility for Claude Code settings.json (#1011) - #1000 feat!: Rename and generalize the upgrade-dependencies skill (#1003) - #881 tooling: Migrate build to nmr-compile and give mcp an entry point (#1001) - #987 internal: Instrument review-branch, respond-to-review, and create-pr with lifecycle events (#999) - #986 internal: Add an emit-event skill helper and lifecycle event envelope v0 (#998) - deps: Upgrade all deps to latest minor version - #991 refactor: Remove client-side event-immutability enforcement (#997) - #993 refactor: Separate the smoke-test code from the bundle build tooling (#996) - #994 fix: Remove the visualization hooks that logged an error on every prompt (#995) - #740 fix: Recommend refine-plan only when decisions remain unsettled (#990) - #989 refactor: Give the store's on-disk layout a single owner (#992) - #973 fix: Carry comment discipline in every agent that writes comments (#983) - #978 feat: Add an action-items convention that separates asks from prose (#982) - #972 fix: Support events from a harness that exposes no session id (#981) - #971 fix: Inline output-shaping specs so skills cannot improvise them (#980) - #976 feat!: Disambiguate the memory-store selector and accept its displayed label (#979) - #927 feat: Frame agent-guidance changes as instructions, not accomplished behavior (#970) - #964 feat: Default to folding discovered work into the current change (#969) - #962 feat: Standardize ticket-authoring doctrine across the emitting skills (#968) - #958 refactor: Route the capture-event add path through KbEvent (#966) - #853 refactor: Replace rule engine with a type-blind vault-integrity layer (#961) - #852 refactor: Route the assertion write commands through KbAssertion (#959) - #907 fix: Render self-referential and cross-skill invocations per harness (#957) - #953 feat: Resolve the PR URL from a PR-based branch identity (#956) - #914 feat: Add spike mode to the ticket and plan authoring skills (#955) - #950 feat: Support a PR number as a branch and artifact identifier (#954) - #938 feat: Support collections from user-declared content sources (#951) - #939 fix: Dedup migrated memories by topic, not session id alone (#949) - #919 feat: Keep implementation detail out of ticket drafts (#948) - #933 feat: Report the source each deployed artifact resolved from (#947) - #940 feat: Add a feedback-memories list command and rename the toolbox (#946) - #932 feat: Support skills and subagents from user-declared content sources (#945) - #936 fix: Attribute migrated feedback events to their origin project (#942) - #934 refactor: Narrow resolveClosure to SourceResolver only (#941) - #924 feat: Resolve rulebooks from user-declared content sources (#935) - #859 feat: Scope feedback-memory migration per store and ground triage in each project (#931) - #650 feat: Add migrate-feedback-memories skill to route memories home (#930) - fix: Special-case the # prefix in create-ticket id construction - #721 feat: Route generalizable feedback to capture-feedback, not memory (#929) - #847 fix: Prevent create-ticket from mis-associating backlog tickets (#928) - #922 feat: Default interactive chat to concise with deep-dive opt-in (#926) - #921 feat: Extend compose-time concision to plans, devlogs, summaries (#925) - docs: Add ambient-hosts to guidance README - #920 feat: Establish the concision spine and wire the ticket and review-comment gates (#923) - #883 tests: Run real-install tests only as a deliberate integration step (#917) - #751 refactor: Set the shell-conventions rulebook to skill-only delivery (#916) - #886 feat!: Deploy harness-specific skills via the declarative mechanism (#912) - #877 feat: Generate project-scoped Rovo Dev prompts.yml on sync (#911) - #904 feat: Make events editable until pushed to the remote (#910) - #879 fix: Declare cross-artifact runtime dependencies (#908) - #897 feat: Surface event impact in recall and filter by it (#906) - #898 feat: Add `{skill:}` and `{subagent:}` invocation tokens (#905) - #899 fix: Skip support directories with no installable files (#903) - #821 feat: Add a mutable impact rating to events (#901) - #895 fix: Deploy a subagent's injected skills with sync (#900) - fmt: Auto-format - #880 feat: Add authoring-guidance rulebook for agents (#896) - #878 feat!: Retire unconditional install (#894) - #892 feat: Apply skill transforms when sync deploys declared skills (#893) - #888 feat: Resolve and persist ticket URLs for bare or omitted references (#890) - #887 feat: Add collection members key with computed @library membership (#889) - #857 feat: Add a user-global deployment domain via sync --global (#884) - #871 feat: Add capture-feedback skill (#882) - #856 feat: Add collections and transitive dependency resolution (#876) - #855 feat: Make subagents declarable and deployable via codeassembly.yaml (#875) - #854 feat!: Make skills declarable & deployable via codeassembly.yaml (#873) - #851 feat: Add kb-retrieve-events for event recall (#872) - #865 tests: Rationalize install-command tests onto fixtures to remove timeout flakes (#870) - #860 feat: Add library list command to enumerate artifacts (#868) - #850 feat: Add kb-update-events for batch event editing (#867) - #733 feat!: Introduce the codeassembly.yaml rulebook declaration format (#866) - #843 fix: Wire comment-discipline into respond-to-review (#845) - #834 fix: Remove dangling owned symlinks during uninstall (#844) - #830 feat: Name skill-delivered rulebooks with a consult- prefix (#839) - #833 fix: Make a no-findings review a valid, full-score result (#838) - #827 feat: Rename collaboration skill to collaborate and make it user-invocable (#837) - #828 fix: Prune stale files on install (#836) - #820 feat!: Rename platform to harness (runtime) and scm (VCS host) (#832) - #824 fix: Scope kb-retrieve recall to the configured note set (#829) - #818 tests: Use full timestamps in test fixtures, not bare dates (#826) - #816 fix: Write kb-add assertions under content/assertions (#819) - #813 fix: Stop --retag from bumping updated for curatorial tag edits (#823) - #817 feat: Record the agent harness in captured events (#822) - #802 fix: Gate kb-add's registry default behind an explicit @default sentinel (#814) - #775 feat: Default ticket-emitting skills to concise tickets (#811) - #785 feat: Add a kb-edit operation to append addressed-by references (#808) - #784 fix: Stop reviewers emitting self-disqualifying findings (#804) - #800 fix: Require an explicit --store on every capture-event call (#806) - #803 fix: Repair collaboration skill's mistake-recording step (#805) - #796 refactor: Rename PlatformConfig dir-name fields to *DirName (#801) - #791 fix: Expand templated script paths in installed subagents (#797) - #783 feat: Store and reuse resolved ticket and PR URLs in the branch manifest (#789) - #780 fix: Exclude top-level skills/_partials/ from skill installation (#788) - #763 feat: Add an addressed-by/addresses relation linking problems to their responses (#787) - #779 feat!: Designate the default KB with a top-level default_kb pointer (#786) - #774 feat: Unify plan and design-and-plan on a shared plan template (#782) - #771 refactor: Consolidate duplicated parseTagList and readAll helpers (#781) - #766 feat!: Adopt explicit-UTC second-precision timestamps for KB date fields (#773) - tests: Drop the removed immutable field from a kb-retrieve helper - #749 feat: Honor the schema recall policy in kb-retrieve (#764) - #748 refactor: Remove the unused immutable record-type schema flag (#765) - #756 feat: Rename the Diátaxis --type flag to --diataxis (#757) - #720 feat: Add a kb create command to provision new KB stores (#755) - #732 feat: Add skill delivery mode for rulebooks (#754) - #741 fix: Resolve review spec source by recency with an explicit override (#753) - #734 refactor: Replace js-yaml with the yaml library (#743) - #727 refactor: Redesign the record taxonomy around a stored recordType discriminant (#742) - #731 feat: Add init and sync commands for the project rulebook library (#738) - #718 feat: Add a config-driven kb check CLI and library export (#735) - #724 refactor: Rename @codeassembly/kb-core to @codeassembly/kb (#726) - #715 fix: Drop branch-cleanup advice and deletion-status fields from merge output (#722) - #716 feat: Relocate event records to content/events/ and document the fix-tag convention (#719) - #714 feat: Add event capture and a kind-aware record-store core (#717) - deps: Upgrade all deps to latest minor version - #706 fix: Reframe legacy finding-ID rule to prevent ID collisions (#712) - #709 feat: Skip HTML sanitization for the markdown Jira-update tool (#710) - #704 fix: Give the lede pipeline authority to cut supplied mechanism (#708) - #702 refactor: Deduplicate the isRecord type guard across factory and run-core (#707) - #661 fix: Self-anchor agents helpers at the git repo root (#703) - #690 refactor: Deduplicate filesystem-existence and type-guard helpers (#700) - #684 test: Pin --kb resolution for a single-entry default registry (#698) - #689 feat: Consolidate the kb.yaml loader and surface registry defects in kb-retrieve (#695) - #683 fix: Forbid interactive UI controls when prompting the user (#692) - #685 refactor: Consolidate acceptance-criteria scaffold into a partial (#691) - #670 fix: Keep change-summary ledes outcome-shaped (#688) - #671 feat: Treat suppression directives as reviewable design signals (#686) - #678 fix: Stop resolving the pr field at artifact-write time; set it only in PR-aware skills (#687) - #638 feat: Add kb-curate skill for vault-wide KB hygiene (#681) - #662 feat: Add /revise-comments to audit and edit existing comments (#680) - #674 fix: Tighten review-finding thresholds for genuine improvements (#679) - #673 feat: Add kb-edit skill for post-creation note maintenance (#676) - #672 fix: Move user-global KB config to `~/.agents/kb.yaml` (#675) - #657 feat: Add test-structure discipline to agent guidance and review pipeline (#669) - #658 fix: Fix `&` corruption in rendered titles on bash 5.2+ (#667) - #664 fix: Tolerate unknown keys in `.agents/preferences.yaml` (#666) - #653 fix: Replace `get-session-context` skill with a bundled TS deriver (#663) - #642 feat: Add comment discipline to agent guidance and review pipeline (#659) - #643 fix: Add update-jira-ticket pre-flight validator and rework recovery protocol (#654) - #637 feat: Add kb-add skill for capturing knowledge-base notes (#652) - #636 feat: Add kb-retrieve skill for querying the knowledge base (#645) - #629 fix: Skip .DS_Store and stray entries during rovodev install (#633) - #631 fix: Make installable content paths resolve outside the monorepo (#632) - #567 feat: Surface ticket-vs-PR-description divergence in /review-pr (#628) - #624 fix: Make resolve-frontmatter work from any subdirectory (#627) - #621 fix: Codify dispatch precondition for resolve-frontmatter (#626) - #592 feat: Apply recommendation gradient to all substantive option choices (#625) - #558 feat: Add changelog-writer subagent (#620) - #617 fix: Make skill tool-name references platform-portable (#619) - #603 tests: Add edge-case tests for artifact-frontmatter YAML emission (#618) - #599 feat: Decouple review dispositions from reviewer framing (#616) - #611 feat: Stop reporting "behavior unchanged" in changelog entries (#615) - #608 feat: Discourage code-level detail in design-and-plan tickets (#614) - #607 fix: Use {platform_home_dir} for helper-script invocations (#613) - feat: Add guidance about capitalization after a colon - deps: Upgrade all deps to latest minor version - #606 tooling: Allow test:sh to run selected shellspec tests (#610) - #605 fix: Fix shellspec test suite hangs in agents package (#609) - #595 refactor: Emit complete YAML frontmatter from resolve-frontmatter.sh (#604) - #593 feat: Add change-narrating voice and jargon to lede-voice (#602) - #597 feat: Make subagent tool-name references platform-portable (#601) - refactor: Fix capitalization in subagent definitions - #572 feat: Revise `respond-to-review` to be less deferential to reviewer recommendations (#600) - #589 feat: Guide agents to prefer partials over duplicated content (#598) - #537 feat: Unify artifact frontmatter under a canonical metadata schema (#596) - #583 feat: Require repo-relative paths in review finding locations (#594) - #581 feat: Redefine 👍🏼👎🏼 as a confirmation contract (#586) - #584 fix: Remove `<pre>` from update-jira-ticket allowlist (#585) - feat: Strengthen type-safety guidance - #580 fix: Restore gradient usage with skill-local pointers (#582) - #578 fix: Prohibit `version_message` argument in update-jira-ticket (#579) - #555 feat: Restructure voice and format rules to enforce inline at point-of-use (#573) - #522 feat: Support partials in skills and subagent definitions (#571) - #553 feat: Replace /review-change with /review-branch and /review-pr (#570) - #515 feat: Auto-retry interrupted reviewer dispatches (#566) - #519 fix: Raise reviewer max_turns defaults (#564) - #560 feat: Treat tickets as requests; design as if from the beginning (#562) - #544 fix: Stop under-recommending direct implementation (#557) - #548 feat: Add work-type emojis and breaking tag to PR descriptions (#554) - #542 refactor: Stop duplicating work-type tiers in commit/SKILL.md (#551) - #545 feat: Add critical-evaluation guidance to collaboration skill (#550) - #538 feat: Extract release-notes voice into shared rules (#549) - #540 refactor: Remove duplicated rules from shared AGENTS.md (#547) - #536 fix: Treat menu omission as drop in /wrap-up (#541) - #535 feat: Inline shared guidance into platform files at install time (#539) - #524 feat: Document code+mark restriction in update-jira-ticket (#534) - #531 feat: Delimit publishable content in merge approval prompt (#533) - #526 feat: Make recommendation-gradient the interactive default (#532) - #469 internal: Migrate label-map schema reference to release-kit (#530) - ## tooling: Exclude generated files from Prettier formatting - #527 refactor: Unify Jira-style ticket ID extraction across skills (#529) factory-v0.2.1 - deps: Upgrade all deps to latest minor version - #943 docs: Remove local-only references from design docs (#944) - fmt: Auto-format - deps: Upgrade all deps to latest minor version - #818 tests: Use full timestamps in test fixtures, not bare dates (#826) - deps: Upgrade jsdom to patch vuln in undici - deps: Upgrade all deps to latest minor version - deps: Upgrade all deps to latest minor version - #702 refactor: Deduplicate the isRecord type guard across factory and run-core (#707) - deps: Upgrade all deps to latest minor version - deps: Upgrade all deps to latest minor version - deps: Upgrade dependencies - ## tooling: Exclude generated files from Prettier formatting kb-v0.2.0 - #881 tooling: Migrate build to nmr-compile and give mcp an entry point (#1001) - deps: Upgrade all deps to latest minor version - #989 refactor: Give the store's on-disk layout a single owner (#992) - #972 fix: Support events from a harness that exposes no session id (#981) - #965 tooling: Fix type resolution in the published kb and run-core packages (#975) - #853 refactor: Replace rule engine with a type-blind vault-integrity layer (#961) - #852 refactor: Route the assertion write commands through KbAssertion (#959) - #821 feat: Add a mutable impact rating to events (#901) - fmt: Auto-format - #851 feat: Add kb-retrieve-events for event recall (#872) - #850 feat: Add kb-update-events for batch event editing (#867) - #849 internal: Add type-blind note I/O and declared per-type record modules (#858) - #824 fix: Scope kb-retrieve recall to the configured note set (#829) - #818 tests: Use full timestamps in test fixtures, not bare dates (#826) - #817 feat: Record the agent harness in captured events (#822) - #800 fix: Require an explicit --store on every capture-event call (#806) - #792 feat: Set the default knowledge base when creating one (#799) - #793 feat: Add a kb set-default command for the default knowledge base (#798) - #763 feat: Add an addressed-by/addresses relation linking problems to their responses (#787) - #779 feat!: Designate the default KB with a top-level default_kb pointer (#786) - #766 feat!: Adopt explicit-UTC second-precision timestamps for KB date fields (#773) - #767 refactor: Normalize declaration ordering across the kb package (#770) - #761 feat: Add note targeting to kb check via paths and --vs (#769) - #748 refactor: Remove the unused immutable record-type schema flag (#765) - #759 feat: Alphabetize the default schema's field lists and add diataxis to assertion (#760) - #752 refactor: Consolidate duplicated kb test helpers into a shared module (#758) - #720 feat: Add a kb create command to provision new KB stores (#755) - #727 refactor: Redesign the record taxonomy around a stored recordType discriminant (#742) - kb: Fix executable bit of kb script - #718 feat: Add a config-driven kb check CLI and library export (#735) - #724 refactor: Rename @codeassembly/kb-core to @codeassembly/kb (#726) mcp-v0.2.1 - #881 tooling: Migrate build to nmr-compile and give mcp an entry point (#1001) - ## tooling: Exclude generated files from Prettier formatting run-core-v0.2.1 - #881 tooling: Migrate build to nmr-compile and give mcp an entry point (#1001) - #965 tooling: Fix type resolution in the published kb and run-core packages (#975) - #818 tests: Use full timestamps in test fixtures, not bare dates (#826) - #734 refactor: Replace js-yaml with the yaml library (#743) - deps: Upgrade all deps to latest minor version - #702 refactor: Deduplicate the isRecord type guard across factory and run-core (#707) - ## tooling: Exclude generated files from Prettier formatting
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds a pre-flight check that catches malformed Jira HTML in the
update-jira-ticketskill before the request is sent, so failures now surface as specific, actionable findings instead of opaque API rejections. When the skill needs to send a diagnostic probe ticket to isolate a formatting problem, it now prompts before doing so rather than creating one silently. Opt-in probe tickets are tagged consistently so they can be cleared from the backlog in a single sweep later.Why
Before this change, the skill leaned on agent memory to avoid a list of HTML composition rules, named-entity restrictions, and forbidden element classes that the MCP tool's HTML→ADF converter rejects with an opaque
INVALID_INPUT. Agents forgot the rules mid-generation, and the documented recovery protocol silently created a real "PROBE delete me" ticket in the user's Jira backlog to bisect the failing payload — these tickets accumulated indefinitely with no way to distinguish them from real work. The user described the workflow as "ABSURDLY fragile" and called out the leaked probe tickets as the most visible symptom. Encoding the rule list as a deterministic checker eliminates the memory failure mode, and moving probe creation behind a user prompt with a recognizable tag ends the backlog pollution.Details
🎉 Features
update-jira-ticket.mjsvalidates the rendered HTML against five rule classes (composition violations between<code>and inline marks, named entities outside the safe trio, Confluence<ac:*>/<ri:*>constructs, multi-line<pre>, any element outside the allowlist) and emits structured findings naming the rule, snippet, and a suggested fix.mcp-probelabel, deterministic title, and a description prefix marking them as auto-created and safe to delete — and the skill documents the JQL sweep for cleanup.🐛 Bug fixes
realpathSync, matching the kb-add/kb-retrieve pattern. The previous direct equality check would silently no-op oncodeassembly-agents install --linkinstalls, where the SKILL.md invocation path is a symlink to the real bundle.🧪 Tests
check.test.tsincluding reverse-nesting symmetry for the composition rule, literal-angle-bracket guard in quoted attribute values (closing a gap from the plan's own risk register), and locking tests for two intentional parser tolerance behaviors (comments and unclosed tags) so a future contributor doesn't quietly "fix" them.BundleTargetwith an optional per-bundle invocation clause; the new target pipes a known-bad payload through the built.mjsand asserts the right rule fires, catching esbuild-config regressions the source-level unit tests cannot.📚 Documentation
parser.tsheader documents the tokenizer's intentional limitations (HTML comments / CDATA / DOCTYPE tokenized as tag soup;walkTokensdoes not auto-balance unclosed tags) so future contributors understand the design choices.Closes #643