Claude was following a hotfix procedure that could put develop work into production. My first story was that the agent had forgotten a routine. The wrong story was that Claude lacked context. The right problem was an April copy of the hotfix steps inside /item, while the canonical ai/shared/workflow had moved twelve times in August.
At first, that looked like an agent-memory problem. The command had a procedure near at hand, and Claude had followed it. I went looking for a better reminder. That diagnosis made Claude the moving part and let the documents look settled.
The copy won because it was near the command
The documentation already named an authority order. Root guidance came first, then ai/shared/workflow, then everything else. The canonical file owned Git flow, including the branch model, sync, save, release, and hotfixes. It was maintained as the place where those rules changed.
The /item skill had its own hotfix release steps anyway. It had been written in April. The canonical workflow changed twelve times in August. A skill that embeds a procedure becomes another copy of it, carrying its own maintenance burden. I had treated proximity to the command as clarity. In practice, it made two files compete to define the same release path.
That distinction mattered because the hotfix path is narrow. A hotfix branch is cut from master, merged back to master, then carried from master to develop. The workflow blocks a hotfix branch that contains a commit reachable from develop but absent from master. If a fix actually needs in-progress code, it belongs on the staging path.
The branch check made the drift worse
The stale procedure was only the visible problem. During the investigation, the hotfix branch was re-cut from master to match the documented workflow. Then a more serious defect appeared in ai/scripts/verify-hotfix-branch.sh: the guard was reading stale local refs instead of origin refs. It could silently allow the exact develop-cut contamination it existed to stop.
That changed the incident. The copied instructions could send Claude down the wrong path. The branch-ancestry guard could also bless the path using an out-of-date view of the repository. I had trusted the existence of a verification step without asking what evidence it was reading. A check that compares the wrong refs does not fail closed. It only makes an old snapshot look deliberate.
The canonical workflow had already made the relevant invariant plain. The branch, not the ticket label, decides whether work is a hotfix or staging. A branch cut from develop is not safe for the hotfix release flow just because someone calls it a hotfix. The code had a guard for that condition. The guard had been looking in the wrong place.
The first guard was too weak
Deleting the embedded steps and pointing /item at canon addressed the ownership failure. The first CI guard for that rule did not hold. It was too weak and would have shipped undetected. The next commit made the rule stricter and added seven cases covering false positives. Both runs were green in CI.
The implementation moved the source of truth from an instruction blob to a direct reference. That does not make the workflow static. It makes future changes appear in one place. A change to the hotfix flow now updates the canonical file that the skill cites, instead of depending on someone to remember that /item carries a private transcription. The CI rule turns that ownership decision into a check at the moment a duplicate is added.
That revision was important because a guard against copied procedures can become a source of noise if it sees duplication where there is none. The seven cases put a boundary around the rule at the same time that the rule enforced one home for an operating procedure. The change added a concrete constraint on inlining a release procedure that already had an owner, nothing broader than that.
The completed change removed the April copy, made the skill cite the canonical workflow, and made CI reject another inline procedure. The branch-ancestry guard was corrected to use origin refs. The change then shipped in a release.
The later CI guard has seven cases. The ancestry check reads origin rather than stale local refs, and the April copy is gone.