plugin agent twins — compliance-verifier, living-docs-auditor, review-sidecar (I8)
Three plugin/agents/*.md files byte-identical to their in-repo agents/ sources, generated by scripts/generate-plugin-twins.sh under a no-marker, no-header contract enforced by principle 24(d) — the marketplace audience gets the same reviewers the clone repo ships.
plugin agent twins — compliance-verifier, living-docs-auditor, review-sidecar (I8)
Status: shipped-beta (generated artifacts — do not hand-edit; regenerate from sources) · Ships to: plugin (marketplace install of getff@getff) · Fires at: when the consuming harness loads the plugin's agents — the same review/audit moments their in-repo sources fire at
What it is
The plugin's agent trio: compliance-verifier (PR-description evidence review), living-docs-auditor (backward Living-Documentation drift audit via scripts/audit-ai-docs.sh), and review-sidecar (external-perspective diff review). Each plugin/agents/<name>.md is a BYTE-IDENTICAL copy of its agents/<name>.md source — no header, no rewrite — so a plugin consumer runs exactly the agents the framework repo's own sessions run.
How it works
- Generation is mechanical:
scripts/generate-plugin-twins.shmaintains two populations with two contracts — plugin/hooks twins get a copy plus an AUTO-GENERATED header (with optional per-source@plugin-transformmodes), while plugin/agents twins are byte-identical copies with NO marker support and NO header. - The no-marker contract is deliberate and gate-enforced: principle 24(d) requires EVERY
plugin/agents/*.mdto be byte-identical to its source, sosedandmanualmodes are unreachable by construction — a marker there would be dead code whose only effect is a red gate. The header is omitted because these files' YAML frontmatter must open on line 1; injecting a comment would corrupt them and break byte-identity anyway. - The twin-depth consequence is recorded at the generator: a twin sits one directory deeper, so a relative link that resolves from
agents/lands one level short inside the twin — byte-identity forbids rewriting links, so the depth is documented rather than patched. - Lane honesty: plugin-path only. The in-repo sources fire inside the framework clone; a consumer who installed via the clone/npm path gets the agents through
.claude/agents/delivery (A11) instead — same content, different channel, and only the marketplace audience meets the twins.
Satellites & companions
Sources are the in-repo agents (the C-family rows for these three agents); generated by the same script that twins the plugin hooks (the D-family plugin wiring). Part of the plugin manifest surface (I1/I2); consumed under the host-wins ladder (I5).
Anchors
At framework pin aa87d0a47a6d8502f983cc9fe7284bd5dcb3d650:
plugin/agents/compliance-verifier.md:2— «name: compliance-verifier»plugin/agents/living-docs-auditor.md:2— «name: living-docs-auditor»plugin/agents/review-sidecar.md:2— «name: review-sidecar»scripts/generate-plugin-twins.sh:4-5— «# (1) plugin/hooks/ ← .claude/hooks/.sh — copy + AUTO-GENERATED header» «# (2) plugin/agents/.md ← agents/.md — byte-identical copy, no header»scripts/generate-plugin-twins.sh:15-16— «# requires EVERY plugin/agents/*.md to be byte-identical to its agents/ source, sosedand» «#manualmodes are unreachable by construction — a marker would be dead code whose only»scripts/generate-plugin-twins.sh:21-23— «# Population (2) consequence — TWIN DEPTH (record it here; nothing else states it): a twin sits» «# one directory deeper than its source, so a relative link that resolves from agents/ resolves»
plugin skill tool-bootstrapping — extended trigger surface (I7)
The plugin twin of the shipped tool-bootstrapping discipline skill: the same 6-rule MCP/skill proposal protocol for consumer projects, with an extended trigger list including Russian-language triggers.
plugin/install/fetch-and-wire.sh — the hybrid seam (I9)
The bridge behind /getff:install-enforcement: fetches the project's OWN official installer instead of bundling ~2MB into the plugin, runs it dry-run by default, and never wires anything on its own — --apply plus the command's consent does the real run.