align skills with additive project policy

This commit is contained in:
tmk241
2026-08-16 22:14:57 +02:00
parent f6d0efdfc0
commit 92a2849376
5 changed files with 25 additions and 7 deletions
+6
View File
@@ -85,6 +85,12 @@ Implement the bounded frontend task and return proof.
`access: read|write` selects reader/writer scheduling; it does not grant commands
or tools. Definitions are frozen at startup, so restart Ink after changing one.
Approved rows from `$HOME/.ink/policy` and ancestor project `.ink/policy` files are
additive alternatives. A project file can introduce a command only through the
normalized effective-policy digest approval; it is never trusted merely because it
exists. Empty project policy adds nothing. Child/session policy and the immutable
host floor may only narrow the approved durable rows.
Current caveat: Ink records `policy:` as frozen metadata but does not yet read the
named relative file into the child effective policy. Do not treat it as enforced.
Use the `configure-ink-agent` skill for the exact boundary and blocker.