delivery-loop CLAUDE.md

Repository instructions for maintaining Delivery Loop, a Claude Code plugin that turns written specifications into GitHub Issues and guides agents through implementation, review, fixes, and merging.

In plain words
What is it for?
Use it when editing the plugin, its configuration, or its scripts, especially when checking that changes remain repository-independent.
Why use it?
It explains the rules for keeping this shared plugin usable in many different repositories instead of accidentally tying it to one project.

Instructions file

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/blakemartz/delivery-loop/claude-md
Clone the repo
git clone --depth 1 https://github.com/blakemartz/delivery-loop
Per session 2,076 This file is loaded in full into every session.
When invoked 2,076 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.02076 $0.02076
Opus 5 $0.01038 $0.01038
Sonnet 5 $0.00415 $0.00415
Haiku 4.5 $0.00208 $0.00208

Measured 2d ago against content hash 2b4e53ea401d, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

delivery-loop CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

CLAUDE.md · 160 lines

How it starts

The opening of the file, as written. The whole thing — 160 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CLAUDE.md

Guidance for Claude Code working on this repository. This repo is the delivery-loop plugin — you are editing a shareable package. It also dogfoods the loop on itself (see "Dogfooding"), so you may additionally be running the loop here. For how the loop works and how a consumer uses it, read README.md; don't duplicate it here.

What this is

A self-contained agentic software-delivery loop for Claude Code, shipped as a plugin + marketplace. Consumers write specs; the loop files them as a GitHub-Issues backlog, then agents claim → implement → adversarially review → patch → merge each task in its own git worktree, behind one per-repo correctness gate. There is no server and no database — state is the consumer's repo, its Issues, and gh + git + jq.

The system was extracted and generalized from the Lineage monorepo, where it runs live. Lineage is upstream: most changes originate there and get ported here (see "Origin & sync"). This repo is the generic, redistributable copy.

The cardinal rule: everything must stay repo-agnostic

Every skill and script here runs inside someone else's repo. The single most common way to break this package is to leak specifics of one consumer.

  • No consumer-specific strings. No lineage, no hardcoded tool names (pnpm, uv, alembic, afplay), no assumed filenames (CLAUDE.md, a specific spec name). If you're tempted to write one, route it through config instead. Quick check: grep -ri lineage plugins/ must stay empty.
  • Per-repo behavior lives in exactly one place: .claude/delivery.conf in the consumer's repo, resolved by scripts/lib/config.sh. Skills read config keys (GATE_CMD, SPEC_SOURCES, …); they never name a concrete command.
  • Scripts self-reference via ${CLAUDE_PLUGIN_ROOT} so they resolve wherever the plugin is installed. Never use paths relative to a checkout.
  • Docs are cited by section number. Skills reference docs/agentic_delivery_spec.md §N. When editing those docs, preserve existing § numbers so the citations keep resolving.

Read the full file on GitHub · 160 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 160 lines · 2,076 tokens per session scan A 2b4e53ea401d

Subscribe to this mod's changes

delivery-loop CLAUDE.md is an instructions file published in the GitHub repository blakemartz/delivery-loop (4 stars, last pushed 1mo ago), licensed MIT. It adds 2,076 tokens to every session, about $0.0104 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.