Install pinned skills from Git repositories
This commit is contained in:
@@ -34,13 +34,31 @@ Install into one project instead of the user catalogue:
|
||||
ink-skills install --project /path/to/project configure-ink-agent
|
||||
```
|
||||
|
||||
The installer is intentionally smaller than `npx skills`: no registry, package
|
||||
manager, network access, copies, prompts, lockfile, or hidden state. It creates
|
||||
absolute symlinks from `$HOME/.ink/skills` (or the installer-only
|
||||
Install from any Git repository your normal Git credentials can read:
|
||||
|
||||
```sh
|
||||
ink-skills add --ref main git@git.example:team/skills.git
|
||||
ink-skills add https://git.example/team/skills.git skills/review-sql
|
||||
```
|
||||
|
||||
`add` resolves the ref to one commit, exports it into a content-addressed store,
|
||||
computes a SHA-256 over each selected skill tree, and symlinks that immutable
|
||||
artifact. Provenance is recorded next to installed links in `.ink-skills.tsv`:
|
||||
source, requested ref, resolved commit, path, and SHA-256. It deliberately does
|
||||
not edit `SKILL.md` comments. A moved branch does not silently update an installed
|
||||
skill; the existing pin causes a visible provenance collision.
|
||||
|
||||
Git SSH agents and credential helpers remain Git's job. Credential-bearing HTTP
|
||||
URLs are refused so secrets do not enter manifests or process listings. Remote
|
||||
skill trees containing symlinks are also refused.
|
||||
|
||||
The local `install` path is intentionally smaller than `npx skills`: no registry,
|
||||
package manager, network access, copies, prompts, lockfile, or hidden state. It
|
||||
creates absolute symlinks from `$HOME/.ink/skills` (or the installer-only
|
||||
`$INK_SKILLS_HOME` target override) to this checkout. Pulling the repository
|
||||
updates installed skills; restarting Ink freezes the new bytes into the next
|
||||
startup snapshot. Ink itself discovers `$HOME/.ink/skills`, `$CWD/.ink/skills`,
|
||||
and colon-separated `INK_SKILLS_DIRS`.
|
||||
updates locally installed skills; restarting Ink freezes the new bytes into the
|
||||
next startup snapshot. Ink itself discovers `$HOME/.ink/skills`,
|
||||
`$CWD/.ink/skills`, and colon-separated `INK_SKILLS_DIRS`.
|
||||
|
||||
`ink-skills list` emits TSV. `ink-skills --help` is the complete command manual.
|
||||
Existing paths and foreign symlinks are refused rather than overwritten.
|
||||
@@ -85,7 +103,7 @@ sh test/skills-smoke.sh
|
||||
## Refusals
|
||||
|
||||
- No npm package merely to create symlinks.
|
||||
- No skill registry or update daemon.
|
||||
- No skill registry, automatic updater, or network daemon.
|
||||
- No policy mutation during installation.
|
||||
- No bundled binaries; those belong in `toolset`.
|
||||
- No automatic installation by Ink itself.
|
||||
|
||||
Reference in New Issue
Block a user