Surveyed the catalogue against the module's own rule: only a procedure with a consequence visible in recorded tool arguments or delivered files gets a check; a heuristic over prose is a number that looks like a measurement and is not one. Four qualify beyond the seven that had checks. postgres-migrations-forward-only — "applied once and never rolled back; undo with a NEW migration" and "renaming a column: don't". An Edit to a path under migrations/ is by construction a change to a file that already existed; a written migration containing RENAME COLUMN is the forbidden rename. criterion-benchmarking — "a missing black_box lets the optimiser delete the work". A written benches/*.rs that mentions criterion and never black_box. secret-scanning-gitleaks and cargo-audit-workflow — the procedure IS running the tool, so a recorded `gitleaks` / `cargo audit` command is the compliance (PassWith, naming the count) and its absence is NotApplicable, never a violation: the stream is capped and the mission may not have reached the step. The written text comes from the tool arguments (Write.content, Edit's new_string), not from reading files back. Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WZb5A2kfVfjpdwSochkuHz