Import verified skill archives
This commit is contained in:
@@ -7,61 +7,58 @@ This repository owns reusable Ink judgment. Ink owns runtime enforcement and
|
||||
policy. [`toolset`](https://git.tmk241.com/tmk241/toolset) owns compiled external
|
||||
executables. Skills never grant authority by themselves.
|
||||
|
||||
## Install
|
||||
## Link local skills
|
||||
|
||||
Clone once, then symlink the skills you want:
|
||||
Clone once, then link every skill shipped by this checkout:
|
||||
|
||||
```sh
|
||||
git clone git@git.tmk241.com:tmk241/ink-skills.git
|
||||
ink-skills/bin/ink-skills install
|
||||
ink-skills/bin/ink-skills link
|
||||
```
|
||||
|
||||
If the repository is already under `/opt/repositories`:
|
||||
Link selected directories or target one project:
|
||||
|
||||
```sh
|
||||
/opt/repositories/ink-skills/bin/ink-skills install
|
||||
ink-skills link /opt/repositories/ink-skills/skills/audit-ink-cli
|
||||
ink-skills link --project /path/to/project skills/configure-ink-agent
|
||||
```
|
||||
|
||||
Install selected skills only:
|
||||
`link` only creates absolute symlinks. It performs no network access, copies,
|
||||
prompts, registry lookup, or policy mutation. Pulling a linked checkout changes
|
||||
its bytes; restart Ink to freeze the updated skill snapshot.
|
||||
|
||||
## Import verified artifacts
|
||||
|
||||
Transport and authentication remain ordinary shell jobs:
|
||||
|
||||
```sh
|
||||
ink-skills install audit-ink-cli configure-ink-agent
|
||||
curl -fLo skills.tar https://example/skills.tar
|
||||
git archive --format=tar HEAD >skills.tar
|
||||
```
|
||||
|
||||
Install into one project instead of the user catalogue:
|
||||
The publisher communicates the expected digest out of band. Import only after you
|
||||
have that value:
|
||||
|
||||
```sh
|
||||
ink-skills install --project /path/to/project configure-ink-agent
|
||||
ink-skills import sha256:012345... skills.tar
|
||||
ink-skills import --project /path/to/project sha256:012345... skills.tar skills/review-sql
|
||||
```
|
||||
|
||||
Install from any Git repository your normal Git credentials can read:
|
||||
`import` verifies the complete archive before extraction, accepts only regular
|
||||
files and directories with safe relative paths, and rejects symlinks and special
|
||||
files. It materializes the tree under
|
||||
`$INK_SKILLS_STORE/sha256/HASH` (or the XDG/default data path), then links skills
|
||||
from that immutable content-addressed location. `.ink-skills.tsv` records each
|
||||
installed skill's archive digest and path without modifying `SKILL.md`.
|
||||
|
||||
```sh
|
||||
ink-skills add --ref main git@git.example:team/skills.git
|
||||
ink-skills add https://git.example/team/skills.git skills/review-sql
|
||||
```
|
||||
The same artifact works whether it arrived via curl, scp, USB, a browser download,
|
||||
or `git archive`. `ink-skills` deliberately has no URL, Git, credential, branch,
|
||||
release, or update logic.
|
||||
|
||||
`add` resolves the ref to one commit, exports it into a content-addressed store,
|
||||
computes a SHA-256 over each selected skill tree, and symlinks that immutable
|
||||
artifact. Provenance is recorded next to installed links in `.ink-skills.tsv`:
|
||||
source, requested ref, resolved commit, path, and SHA-256. It deliberately does
|
||||
not edit `SKILL.md` comments. A moved branch does not silently update an installed
|
||||
skill; the existing pin causes a visible provenance collision.
|
||||
|
||||
Git SSH agents and credential helpers remain Git's job. Credential-bearing HTTP
|
||||
URLs are refused so secrets do not enter manifests or process listings. Remote
|
||||
skill trees containing symlinks are also refused.
|
||||
|
||||
The local `install` path is intentionally smaller than `npx skills`: no registry,
|
||||
package manager, network access, copies, prompts, lockfile, or hidden state. It
|
||||
creates absolute symlinks from `$HOME/.ink/skills` (or the installer-only
|
||||
`$INK_SKILLS_HOME` target override) to this checkout. Pulling the repository
|
||||
updates locally installed skills; restarting Ink freezes the new bytes into the
|
||||
next startup snapshot. Ink itself discovers `$HOME/.ink/skills`,
|
||||
`$CWD/.ink/skills`, and colon-separated `INK_SKILLS_DIRS`.
|
||||
|
||||
`ink-skills list` emits TSV. `ink-skills --help` is the complete command manual.
|
||||
Existing paths and foreign symlinks are refused rather than overwritten.
|
||||
Ink discovers `$HOME/.ink/skills`, `$CWD/.ink/skills`, and colon-separated
|
||||
`INK_SKILLS_DIRS`. The installer-only `$INK_SKILLS_HOME` overrides the user link
|
||||
target. `ink-skills list` emits TSV; `ink-skills --help` is the complete command
|
||||
manual. Existing paths and foreign symlinks are refused rather than overwritten.
|
||||
|
||||
## Skills
|
||||
|
||||
|
||||
Reference in New Issue
Block a user