Import verified skill archives

This commit is contained in:
tmk241
2026-08-11 17:04:37 +02:00
parent efc4b70e13
commit 8547d6ea33
4 changed files with 297 additions and 246 deletions
+32 -35
View File
@@ -7,61 +7,58 @@ This repository owns reusable Ink judgment. Ink owns runtime enforcement and
policy. [`toolset`](https://git.tmk241.com/tmk241/toolset) owns compiled external
executables. Skills never grant authority by themselves.
## Install
## Link local skills
Clone once, then symlink the skills you want:
Clone once, then link every skill shipped by this checkout:
```sh
git clone git@git.tmk241.com:tmk241/ink-skills.git
ink-skills/bin/ink-skills install
ink-skills/bin/ink-skills link
```
If the repository is already under `/opt/repositories`:
Link selected directories or target one project:
```sh
/opt/repositories/ink-skills/bin/ink-skills install
ink-skills link /opt/repositories/ink-skills/skills/audit-ink-cli
ink-skills link --project /path/to/project skills/configure-ink-agent
```
Install selected skills only:
`link` only creates absolute symlinks. It performs no network access, copies,
prompts, registry lookup, or policy mutation. Pulling a linked checkout changes
its bytes; restart Ink to freeze the updated skill snapshot.
## Import verified artifacts
Transport and authentication remain ordinary shell jobs:
```sh
ink-skills install audit-ink-cli configure-ink-agent
curl -fLo skills.tar https://example/skills.tar
git archive --format=tar HEAD >skills.tar
```
Install into one project instead of the user catalogue:
The publisher communicates the expected digest out of band. Import only after you
have that value:
```sh
ink-skills install --project /path/to/project configure-ink-agent
ink-skills import sha256:012345... skills.tar
ink-skills import --project /path/to/project sha256:012345... skills.tar skills/review-sql
```
Install from any Git repository your normal Git credentials can read:
`import` verifies the complete archive before extraction, accepts only regular
files and directories with safe relative paths, and rejects symlinks and special
files. It materializes the tree under
`$INK_SKILLS_STORE/sha256/HASH` (or the XDG/default data path), then links skills
from that immutable content-addressed location. `.ink-skills.tsv` records each
installed skill's archive digest and path without modifying `SKILL.md`.
```sh
ink-skills add --ref main git@git.example:team/skills.git
ink-skills add https://git.example/team/skills.git skills/review-sql
```
The same artifact works whether it arrived via curl, scp, USB, a browser download,
or `git archive`. `ink-skills` deliberately has no URL, Git, credential, branch,
release, or update logic.
`add` resolves the ref to one commit, exports it into a content-addressed store,
computes a SHA-256 over each selected skill tree, and symlinks that immutable
artifact. Provenance is recorded next to installed links in `.ink-skills.tsv`:
source, requested ref, resolved commit, path, and SHA-256. It deliberately does
not edit `SKILL.md` comments. A moved branch does not silently update an installed
skill; the existing pin causes a visible provenance collision.
Git SSH agents and credential helpers remain Git's job. Credential-bearing HTTP
URLs are refused so secrets do not enter manifests or process listings. Remote
skill trees containing symlinks are also refused.
The local `install` path is intentionally smaller than `npx skills`: no registry,
package manager, network access, copies, prompts, lockfile, or hidden state. It
creates absolute symlinks from `$HOME/.ink/skills` (or the installer-only
`$INK_SKILLS_HOME` target override) to this checkout. Pulling the repository
updates locally installed skills; restarting Ink freezes the new bytes into the
next startup snapshot. Ink itself discovers `$HOME/.ink/skills`,
`$CWD/.ink/skills`, and colon-separated `INK_SKILLS_DIRS`.
`ink-skills list` emits TSV. `ink-skills --help` is the complete command manual.
Existing paths and foreign symlinks are refused rather than overwritten.
Ink discovers `$HOME/.ink/skills`, `$CWD/.ink/skills`, and colon-separated
`INK_SKILLS_DIRS`. The installer-only `$INK_SKILLS_HOME` overrides the user link
target. `ink-skills list` emits TSV; `ink-skills --help` is the complete command
manual. Existing paths and foreign symlinks are refused rather than overwritten.
## Skills