align skills with additive project policy
This commit is contained in:
@@ -85,6 +85,12 @@ Implement the bounded frontend task and return proof.
|
||||
`access: read|write` selects reader/writer scheduling; it does not grant commands
|
||||
or tools. Definitions are frozen at startup, so restart Ink after changing one.
|
||||
|
||||
Approved rows from `$HOME/.ink/policy` and ancestor project `.ink/policy` files are
|
||||
additive alternatives. A project file can introduce a command only through the
|
||||
normalized effective-policy digest approval; it is never trusted merely because it
|
||||
exists. Empty project policy adds nothing. Child/session policy and the immutable
|
||||
host floor may only narrow the approved durable rows.
|
||||
|
||||
Current caveat: Ink records `policy:` as frozen metadata but does not yet read the
|
||||
named relative file into the child effective policy. Do not treat it as enforced.
|
||||
Use the `configure-ink-agent` skill for the exact boundary and blocker.
|
||||
|
||||
@@ -40,9 +40,11 @@ changes belong to Ink's repository authority and implementation workflow.
|
||||
installed artifact identity and a demonstrably matching checkout's specification,
|
||||
tests, public help text, and source; label those findings as contract/source
|
||||
evidence rather than executed runtime proof.
|
||||
- Global and project policy files explain only their contribution. Effective
|
||||
authority also depends on all policy layers, pinned executable and contract
|
||||
bytes, startup freezing, and session decisions.
|
||||
- Approved global and ancestor-project rows are additive alternatives; each file
|
||||
explains only its contribution. Effective authority also depends on the approved
|
||||
normalized digest, restrictive child/session policy, the host floor, pinned
|
||||
executable and contract bytes, startup freezing, and session decisions. Never
|
||||
interpret a project file as automatically trusted.
|
||||
- Treat handovers, READMEs, examples, hidden source branches, and remembered argv
|
||||
as leads. Public help owns operator-facing commands; the specification owns intended
|
||||
behavior; tests and source establish current checkout behavior.
|
||||
|
||||
@@ -83,7 +83,8 @@ policy. Therefore:
|
||||
those are already sufficient.
|
||||
|
||||
This gate may be removed only after the provider launch path proves that the
|
||||
referenced bytes are pinned and conjoined into the child effective policy.
|
||||
referenced bytes are pinned and applied as a restriction to the child's inherited
|
||||
approved durable policy.
|
||||
|
||||
## Decision loop
|
||||
|
||||
@@ -107,8 +108,8 @@ referenced bytes are pinned and conjoined into the child effective policy.
|
||||
## Behavior smoke
|
||||
|
||||
Positive: “Create a frontend writer child with only formatter and file mutation
|
||||
authority” loads this skill and blocks until the named policy is actually
|
||||
conjoined or the parent frozen policy already supplies that exact boundary.
|
||||
authority” loads this skill and blocks until the named restrictive policy is
|
||||
actually enforced or the parent frozen policy already supplies that exact boundary.
|
||||
|
||||
Negative: “Ask the existing reviewer to inspect this diff” does not load this
|
||||
skill; it is ordinary delegation.
|
||||
|
||||
@@ -194,7 +194,9 @@ exits, environment/config precedence, credential timing, dependencies, pattern
|
||||
semantics, and one realistic pipeline. Explicit help succeeds on stdout; usage
|
||||
errors fail on stderr. Selector help gives value grammar, canonicalization, and a
|
||||
least-authority policy row, including AND within one row and alternatives across
|
||||
rows.
|
||||
approved global and ancestor-project rows. Project rows are not automatically
|
||||
trusted: Ink freezes the normalized effective policy and requires digest approval;
|
||||
child/session policy and the host floor may only narrow it.
|
||||
|
||||
Keep argv unsurprising: options before operands, `--` ends options, `-` denotes a
|
||||
natural stream, secrets never enter argv, and unknown, incompatible, or trailing
|
||||
|
||||
@@ -23,13 +23,20 @@ configure=$repo/skills/configure-ink-agent/SKILL.md
|
||||
grep 'access.*read.*write' "$configure" >/dev/null
|
||||
grep 'named agent policy is metadata-only' "$configure" >/dev/null
|
||||
grep 'no `INK_AGENT_HOME` contract' "$configure" >/dev/null
|
||||
grep 'applied as a restriction' "$configure" >/dev/null
|
||||
|
||||
audit_cli=$repo/skills/audit-ink-cli/SKILL.md
|
||||
grep 'ink agent catalog' "$audit_cli" >/dev/null
|
||||
grep 'frozen `tool delegate` subject' "$audit_cli" >/dev/null
|
||||
grep 'additive alternatives' "$audit_cli" >/dev/null
|
||||
grep 'automatically trusted' "$audit_cli" >/dev/null
|
||||
|
||||
create_tool=$repo/skills/create-ink-tool/SKILL.md
|
||||
grep 'stage/match/apply' "$create_tool" >/dev/null
|
||||
grep 'projection' "$create_tool" >/dev/null
|
||||
grep 'approved global and ancestor-project rows' "$create_tool" >/dev/null
|
||||
grep 'requires digest approval' "$create_tool" >/dev/null
|
||||
|
||||
grep 'Empty project policy adds nothing' "$repo/README.md" >/dev/null
|
||||
|
||||
printf 'ok\n'
|
||||
|
||||
Reference in New Issue
Block a user