Align skills with frozen Ink contracts

This commit is contained in:
tmk241
2026-08-11 16:42:45 +02:00
parent 284cf5ec90
commit 5552014329
5 changed files with 115 additions and 52 deletions
+14 -11
View File
@@ -36,9 +36,11 @@ ink-skills install --project /path/to/project configure-ink-agent
The installer is intentionally smaller than `npx skills`: no registry, package
manager, network access, copies, prompts, lockfile, or hidden state. It creates
absolute symlinks from `$HOME/.ink/skills` (or `$INK_SKILLS_HOME`) to this
checkout. Pulling the repository updates installed skills; restarting Ink freezes
the new bytes into the next startup snapshot.
absolute symlinks from `$HOME/.ink/skills` (or the installer-only
`$INK_SKILLS_HOME` target override) to this checkout. Pulling the repository
updates installed skills; restarting Ink freezes the new bytes into the next
startup snapshot. Ink itself discovers `$HOME/.ink/skills`, `$CWD/.ink/skills`,
and colon-separated `INK_SKILLS_DIRS`.
`ink-skills list` emits TSV. `ink-skills --help` is the complete command manual.
Existing paths and foreign symlinks are refused rather than overwritten.
@@ -48,13 +50,13 @@ Existing paths and foreign symlinks are refused rather than overwritten.
| Skill | Job |
|---|---|
| `ink-cli` | Audit and explain the Ink host without crossing the host/guest boundary. |
| `configure-ink-agent` | Create or audit one Ink agent definition, access class, and relative policy conjunct. |
| `configure-ink-agent` | Create or audit one Ink agent definition, access class, and effective-policy boundary. |
| `create-ink-agent-cli-tool` | Build one inspectable permission-bearing executable suitable for Ink policy admission. |
## Agent definitions and policy
Agent definitions live in `$INK_AGENT_HOME` (default `$HOME/.ink/agents`) or
project `.ink/agents` directories:
Agent definitions live in `$HOME/.ink/agents` or the exact current project's
`.ink/agents` directory:
```text
name: Frontend specialist
@@ -65,18 +67,19 @@ policy: frontend.policy
Implement the bounded frontend task and return proof.
```
The policy path is relative to the definition. It is a normal Ink policy file and
narrows the frozen parent snapshot conjunctively. `access: read|write` selects
reader/writer scheduling; it does not grant commands or tools. Definitions and
policy files are frozen at startup, so restart Ink after changing either.
`access: read|write` selects reader/writer scheduling; it does not grant commands
or tools. Definitions are frozen at startup, so restart Ink after changing one.
Use the `configure-ink-agent` skill for the complete decision boundary.
Current caveat: Ink records `policy:` as frozen metadata but does not yet read the
named relative file into the child effective policy. Do not treat it as enforced.
Use the `configure-ink-agent` skill for the exact boundary and blocker.
## Verify
```sh
sh -n bin/ink-skills
sh test/install-smoke.sh
sh test/skills-smoke.sh
```
## Refusals