align skills with additive project policy

This commit is contained in:
tmk241
2026-08-16 22:14:57 +02:00
parent f6d0efdfc0
commit 92a2849376
5 changed files with 25 additions and 7 deletions
+6
View File
@@ -85,6 +85,12 @@ Implement the bounded frontend task and return proof.
`access: read|write` selects reader/writer scheduling; it does not grant commands
or tools. Definitions are frozen at startup, so restart Ink after changing one.
Approved rows from `$HOME/.ink/policy` and ancestor project `.ink/policy` files are
additive alternatives. A project file can introduce a command only through the
normalized effective-policy digest approval; it is never trusted merely because it
exists. Empty project policy adds nothing. Child/session policy and the immutable
host floor may only narrow the approved durable rows.
Current caveat: Ink records `policy:` as frozen metadata but does not yet read the
named relative file into the child effective policy. Do not treat it as enforced.
Use the `configure-ink-agent` skill for the exact boundary and blocker.
+5 -3
View File
@@ -40,9 +40,11 @@ changes belong to Ink's repository authority and implementation workflow.
installed artifact identity and a demonstrably matching checkout's specification,
tests, public help text, and source; label those findings as contract/source
evidence rather than executed runtime proof.
- Global and project policy files explain only their contribution. Effective
authority also depends on all policy layers, pinned executable and contract
bytes, startup freezing, and session decisions.
- Approved global and ancestor-project rows are additive alternatives; each file
explains only its contribution. Effective authority also depends on the approved
normalized digest, restrictive child/session policy, the host floor, pinned
executable and contract bytes, startup freezing, and session decisions. Never
interpret a project file as automatically trusted.
- Treat handovers, READMEs, examples, hidden source branches, and remembered argv
as leads. Public help owns operator-facing commands; the specification owns intended
behavior; tests and source establish current checkout behavior.
+4 -3
View File
@@ -83,7 +83,8 @@ policy. Therefore:
those are already sufficient.
This gate may be removed only after the provider launch path proves that the
referenced bytes are pinned and conjoined into the child effective policy.
referenced bytes are pinned and applied as a restriction to the child's inherited
approved durable policy.
## Decision loop
@@ -107,8 +108,8 @@ referenced bytes are pinned and conjoined into the child effective policy.
## Behavior smoke
Positive: “Create a frontend writer child with only formatter and file mutation
authority” loads this skill and blocks until the named policy is actually
conjoined or the parent frozen policy already supplies that exact boundary.
authority” loads this skill and blocks until the named restrictive policy is
actually enforced or the parent frozen policy already supplies that exact boundary.
Negative: “Ask the existing reviewer to inspect this diff” does not load this
skill; it is ordinary delegation.
+3 -1
View File
@@ -194,7 +194,9 @@ exits, environment/config precedence, credential timing, dependencies, pattern
semantics, and one realistic pipeline. Explicit help succeeds on stdout; usage
errors fail on stderr. Selector help gives value grammar, canonicalization, and a
least-authority policy row, including AND within one row and alternatives across
rows.
approved global and ancestor-project rows. Project rows are not automatically
trusted: Ink freezes the normalized effective policy and requires digest approval;
child/session policy and the host floor may only narrow it.
Keep argv unsurprising: options before operands, `--` ends options, `-` denotes a
natural stream, secrets never enter argv, and unknown, incompatible, or trailing
+7
View File
@@ -23,13 +23,20 @@ configure=$repo/skills/configure-ink-agent/SKILL.md
grep 'access.*read.*write' "$configure" >/dev/null
grep 'named agent policy is metadata-only' "$configure" >/dev/null
grep 'no `INK_AGENT_HOME` contract' "$configure" >/dev/null
grep 'applied as a restriction' "$configure" >/dev/null
audit_cli=$repo/skills/audit-ink-cli/SKILL.md
grep 'ink agent catalog' "$audit_cli" >/dev/null
grep 'frozen `tool delegate` subject' "$audit_cli" >/dev/null
grep 'additive alternatives' "$audit_cli" >/dev/null
grep 'automatically trusted' "$audit_cli" >/dev/null
create_tool=$repo/skills/create-ink-tool/SKILL.md
grep 'stage/match/apply' "$create_tool" >/dev/null
grep 'projection' "$create_tool" >/dev/null
grep 'approved global and ancestor-project rows' "$create_tool" >/dev/null
grep 'requires digest approval' "$create_tool" >/dev/null
grep 'Empty project policy adds nothing' "$repo/README.md" >/dev/null
printf 'ok\n'