A
Three-lens skeleton + IA rebuild
living——
- Design the three-lens skeleton + plan model (this workflow)S08
- Add the
data-lens axis to the .entry grammar + brain.js facetS08
- Extract tokens →
theme.css; de-hardcode the fontsS09
- Write
product/ + engineering/ lens prose (brain = source of truth)S09
- Generated 3-lens portal cover + persistent shell/footerS09
- Liberal cross-lens links — every page reaches related lenses (multiple paths to the same place)S09
B
Plan board + derived progress
living——
- Design the initiative → task → session modelS08
- Progress derivation in brain.js (counts task status, fills bars)S08
- Seed this build's backlog as the first planS08
- Wire the plan into the cover (progress spine + Tier-1 pill)S08
C
Hands — direct manipulation
hands——
- Edit text in place (
contenteditable) → file write, no AIS09
- Drag-to-reorder & delete a block → file writeS10
- Keyboard path for reorder/delete (drag is mouse-only) — a11y
D
Theme consolidation + /theme
reach——
- One overridable
theme.css — brain imports it, the toolbar reads its tokens at runtime · docs stay self-contained (archival) · flipped in the S28 auditS28
- /theme command (presets + interactive, derive from a brand hex) · shipped in the skill · flipped in the S28 auditS28
E
CLAUDE.md contract + manifest
reach——
- Delimited, regenerable contract + the 4 plan ops + lens rules · lives in CLAUDE.md + SKILL.md + /plan; 13 marker regions on the cover · flipped in the S28 auditS28
.sandpaper/manifest.json (books, cid-prefixes, id-counters, theme path) — written by sandpaper initS10
F
The skill — /init, /theme, /plan, /decide, /sync…
reach——
- /init — harvest repo → interview → generate the first brainS10
- Capture commands: /plan /decide /learn /log /stamp /serve /themeS10
- /sync — the drift immune system (brain ↔ code reconcile)S10
- Auto-update hooks (SessionStart inject + Stop stamp-check) +
SKILL.md — brain stays current, no proddingS10
- /help (the command index) + /open (launch the dashboard) commandsS10
- Smarter
/init — wide artifact discovery (specs/logs/docs, not just code) + an interactive wizard (fill gaps + shape the brain)S10
G
Sidecar publish + npm packaging
reach——
- Always-publishable brain — out-link resolver (source meta · name-checked probe · click-time rewrite) + doctor lint + deploy guideS28
- sandpaper.sh landing page (site/) — judged pitch lab · self-stamping hero demo · 4-critic review · OG card · was t-0029, renumbered (id collision)S28
- SHIP: sandpaper.sh + brain.sandpaper.sh live — two Vercel projects, domains attached, resolver verified in productionS28
- PUBLISHED —
@nynb/sandpaper@0.1.0 live on npm; verified via registry + a real npx smoke test · D-017S28
- Vercel git integration wired + verified —
sandpaper-site → site/, sandpaper-brain → brain/; w-0205's plain push auto-deployed both, confirmed by the ownerS28
- Publish preflight —
doctor --publish scans brain/ for secrets · emails · internal URLs before a deploy · from q-privacy
bin/verify-publish.js + CI (.github/workflows/ci.yml) — the tarball-safety checks (no site/, no secrets, size envelope) now run on every push/PR, Node 18/20/22 · D-018S28
- Release workflow (
.github/workflows/release.yml) — a version tag runs tests → verify-publish → npm publish --provenance → a GitHub Release; plus .github/dependabot.yml for Actions/dep hygiene · D-018S28
/sandpaper:release — versioning as a Sandpaper feature, not a side process: drafts notes + a semver bump from brain/log.html, runs npm version + push · D-018S28
- PIPELINE VERIFIED —
v0.2.0 published for real with provenance (SLSA attestation confirmed) via release.yml + the new NPM_TOKEN; found + fixed a changelog-extraction awk bug along the way · l-awk-v-escapingS28
- The blueprint identity (D-015) — landing + brain reskin, the owner's logomark, SANDPAPER titling · added in the S28 audit; shipped without a taskS28
- npx sandpaper install-skill / init / doctor / open (tested e2e on a fresh repo)S10
- Brain-aware Sand contract (respect entry grammar / link-never-copy)
- Cold-repo
/init — partial-scaffold (dimmed deferred chrome) + no-spec data-ref contract · from validation
- Self-deriving cover counts — brain.js fills them from the board (retire hand-typed
data-count) · verified from canonical pages in ChromiumS32
I
v0.2.1 — truth + safety sweep
reach——
- Design and approve the risk-based
v0.2.1 stabilization sweepS29
- Implement verified server, trust-boundary, concurrency, session, and reload hardeningS30
- Make toolbar/direct/undo state truthful and fix the verified UI regressionsS31
- Reconcile brain/docs/resolver/doctor and complete self-derived cover state (
t-0028)S33
- Add regression integration coverage for server, SSE, setup, undo, and fixed failure pathsS32
- Verify, stamp, version, and release
v0.2.1S37
J
v0.3.0 — Claude + Codex, first-class
reach——
- Design and approve the provider-neutral Claude + Codex contractS39
- Implement provider choice, runners, install/hooks, toolbar identity, and documentationS40
- Verify both providers, stamp, version, and release
v0.3.0S43
✓
Spine — the bridge
spine——
- Bridge: claude -p stream-json → status chip + change cards
- Undo / snapshots · live reload · click-to-scope
- Adversarial review — 8 bugs fixed
✓
Brain v1 — service manual + action bar
brain——
- Scaffold the brain + the manual aesthetic redesign
- Serve the folder with the Sand / Sling action bar
- Markdown replies · git baseline