diff --git a/README.md b/README.md index f352b3a..453d4e1 100644 --- a/README.md +++ b/README.md @@ -85,6 +85,12 @@ Implement the bounded frontend task and return proof. `access: read|write` selects reader/writer scheduling; it does not grant commands or tools. Definitions are frozen at startup, so restart Ink after changing one. +Approved rows from `$HOME/.ink/policy` and ancestor project `.ink/policy` files are +additive alternatives. A project file can introduce a command only through the +normalized effective-policy digest approval; it is never trusted merely because it +exists. Empty project policy adds nothing. Child/session policy and the immutable +host floor may only narrow the approved durable rows. + Current caveat: Ink records `policy:` as frozen metadata but does not yet read the named relative file into the child effective policy. Do not treat it as enforced. Use the `configure-ink-agent` skill for the exact boundary and blocker. diff --git a/skills/audit-ink-cli/SKILL.md b/skills/audit-ink-cli/SKILL.md index faf6953..cad14f5 100644 --- a/skills/audit-ink-cli/SKILL.md +++ b/skills/audit-ink-cli/SKILL.md @@ -40,9 +40,11 @@ changes belong to Ink's repository authority and implementation workflow. installed artifact identity and a demonstrably matching checkout's specification, tests, public help text, and source; label those findings as contract/source evidence rather than executed runtime proof. -- Global and project policy files explain only their contribution. Effective - authority also depends on all policy layers, pinned executable and contract - bytes, startup freezing, and session decisions. +- Approved global and ancestor-project rows are additive alternatives; each file + explains only its contribution. Effective authority also depends on the approved + normalized digest, restrictive child/session policy, the host floor, pinned + executable and contract bytes, startup freezing, and session decisions. Never + interpret a project file as automatically trusted. - Treat handovers, READMEs, examples, hidden source branches, and remembered argv as leads. Public help owns operator-facing commands; the specification owns intended behavior; tests and source establish current checkout behavior. diff --git a/skills/configure-ink-agent/SKILL.md b/skills/configure-ink-agent/SKILL.md index 48dd3eb..883e0b9 100644 --- a/skills/configure-ink-agent/SKILL.md +++ b/skills/configure-ink-agent/SKILL.md @@ -83,7 +83,8 @@ policy. Therefore: those are already sufficient. This gate may be removed only after the provider launch path proves that the -referenced bytes are pinned and conjoined into the child effective policy. +referenced bytes are pinned and applied as a restriction to the child's inherited +approved durable policy. ## Decision loop @@ -107,8 +108,8 @@ referenced bytes are pinned and conjoined into the child effective policy. ## Behavior smoke Positive: “Create a frontend writer child with only formatter and file mutation -authority” loads this skill and blocks until the named policy is actually -conjoined or the parent frozen policy already supplies that exact boundary. +authority” loads this skill and blocks until the named restrictive policy is +actually enforced or the parent frozen policy already supplies that exact boundary. Negative: “Ask the existing reviewer to inspect this diff” does not load this skill; it is ordinary delegation. diff --git a/skills/create-ink-tool/SKILL.md b/skills/create-ink-tool/SKILL.md index b9a269f..af1915f 100644 --- a/skills/create-ink-tool/SKILL.md +++ b/skills/create-ink-tool/SKILL.md @@ -194,7 +194,9 @@ exits, environment/config precedence, credential timing, dependencies, pattern semantics, and one realistic pipeline. Explicit help succeeds on stdout; usage errors fail on stderr. Selector help gives value grammar, canonicalization, and a least-authority policy row, including AND within one row and alternatives across -rows. +approved global and ancestor-project rows. Project rows are not automatically +trusted: Ink freezes the normalized effective policy and requires digest approval; +child/session policy and the host floor may only narrow it. Keep argv unsurprising: options before operands, `--` ends options, `-` denotes a natural stream, secrets never enter argv, and unknown, incompatible, or trailing diff --git a/test/skills-smoke.sh b/test/skills-smoke.sh index c09356a..ca437ae 100755 --- a/test/skills-smoke.sh +++ b/test/skills-smoke.sh @@ -23,13 +23,20 @@ configure=$repo/skills/configure-ink-agent/SKILL.md grep 'access.*read.*write' "$configure" >/dev/null grep 'named agent policy is metadata-only' "$configure" >/dev/null grep 'no `INK_AGENT_HOME` contract' "$configure" >/dev/null +grep 'applied as a restriction' "$configure" >/dev/null audit_cli=$repo/skills/audit-ink-cli/SKILL.md grep 'ink agent catalog' "$audit_cli" >/dev/null grep 'frozen `tool delegate` subject' "$audit_cli" >/dev/null +grep 'additive alternatives' "$audit_cli" >/dev/null +grep 'automatically trusted' "$audit_cli" >/dev/null create_tool=$repo/skills/create-ink-tool/SKILL.md grep 'stage/match/apply' "$create_tool" >/dev/null grep 'projection' "$create_tool" >/dev/null +grep 'approved global and ancestor-project rows' "$create_tool" >/dev/null +grep 'requires digest approval' "$create_tool" >/dev/null + +grep 'Empty project policy adds nothing' "$repo/README.md" >/dev/null printf 'ok\n'