align skills with additive project policy
This commit is contained in:
@@ -40,9 +40,11 @@ changes belong to Ink's repository authority and implementation workflow.
|
||||
installed artifact identity and a demonstrably matching checkout's specification,
|
||||
tests, public help text, and source; label those findings as contract/source
|
||||
evidence rather than executed runtime proof.
|
||||
- Global and project policy files explain only their contribution. Effective
|
||||
authority also depends on all policy layers, pinned executable and contract
|
||||
bytes, startup freezing, and session decisions.
|
||||
- Approved global and ancestor-project rows are additive alternatives; each file
|
||||
explains only its contribution. Effective authority also depends on the approved
|
||||
normalized digest, restrictive child/session policy, the host floor, pinned
|
||||
executable and contract bytes, startup freezing, and session decisions. Never
|
||||
interpret a project file as automatically trusted.
|
||||
- Treat handovers, READMEs, examples, hidden source branches, and remembered argv
|
||||
as leads. Public help owns operator-facing commands; the specification owns intended
|
||||
behavior; tests and source establish current checkout behavior.
|
||||
|
||||
Reference in New Issue
Block a user