Align skills with frozen Ink contracts

This commit is contained in:
tmk241
2026-08-11 16:42:45 +02:00
parent 284cf5ec90
commit 5552014329
5 changed files with 115 additions and 52 deletions
+9 -5
View File
@@ -49,14 +49,17 @@ changes belong to Ink's repository authority and implementation workflow.
Distinguish three surfaces explicitly:
1. **Operator CLI commands** such as top-level `ink sessions` or `ink context`.
1. **Operator CLI commands** such as top-level `ink sessions`, `ink skills`,
`ink agent catalog`, and `ink policy help`.
2. **Model-callable Ink built-ins** exposed directly to the hosted agent.
3. **External executables** admitted through Ink's `run` policy.
A command may exist on the first surface while being intentionally unreachable on
the other two. Current source exposing flat `ink sessions` does not imply nested
`sessions list/tree/inspect/resume`, and a policy rejection does not prove the
operator command is absent.
the other two. Current source exposing flat `ink sessions`, `ink skills`, and
`ink tools` does not imply invented nested verbs, and a policy rejection does not
prove the operator command is absent. The current operator agent catalogue uses
`ink agent catalog` and `ink agent resolve NAME`; role launch remains governed by
the frozen `tool delegate` subject.
## Decision loop
@@ -77,7 +80,8 @@ operator command is absent.
- Do not edit policy to admit `ink`, call Ink recursively, log in, approve a
digest, resume or clear a session, or dump host context from the agent.
- Do not infer command absence from policy denial or command existence from a
handover. In particular, challenge invented nested session verbs.
handover. Challenge invented nested session or tool-verification verbs and
verify current public help/source before suggesting operator argv.
- Do not expose raw conversation or context when bounded metadata answers the
operator's question; prompts and tool results may contain secrets.
- Do not weaken path, origin, account, or repository selectors merely to make an