Align Ink skills with frozen delegation contracts

This commit is contained in:
tmk241
2026-08-12 01:05:49 +02:00
parent 8547d6ea33
commit f6d0efdfc0
4 changed files with 24 additions and 24 deletions
+1 -1
View File
@@ -11,7 +11,7 @@
## Rules ## Rules
- A skill owns reusable judgment, never runtime policy or repeatable mechanics. - A skill owns reusable judgment, never runtime policy or repeatable mechanics.
- Ink source and `REQUIREMENTS.md` own host behavior; `toolset` owns external executables. - Ink source and `SPEC.md` own host behavior; `toolset` owns external executables.
- Keep skill names lowercase and hyphenated; directory and frontmatter name must match. - Keep skill names lowercase and hyphenated; directory and frontmatter name must match.
- `link` only creates symlinks. `import` may materialize only a caller-supplied, - `link` only creates symlinks. `import` may materialize only a caller-supplied,
SHA-256-verified local archive in the content-addressed store. Do not add URL, SHA-256-verified local archive in the content-addressed store. Do not add URL,
+4 -4
View File
@@ -37,14 +37,14 @@ changes belong to Ink's repository authority and implementation workflow.
- A human/operator may invoke Ink outside the governed agent. Give a copyable - A human/operator may invoke Ink outside the governed agent. Give a copyable
operator command only when the user asks and its public help contract is proven. operator command only when the user asks and its public help contract is proven.
- Use user-provided runtime output as runtime evidence. Otherwise inspect the - Use user-provided runtime output as runtime evidence. Otherwise inspect the
installed artifact identity and a demonstrably matching checkout's requirements, installed artifact identity and a demonstrably matching checkout's specification,
tests, public help text, and source; label those findings as contract/source tests, public help text, and source; label those findings as contract/source
evidence rather than executed runtime proof. evidence rather than executed runtime proof.
- Global and project policy files explain only their contribution. Effective - Global and project policy files explain only their contribution. Effective
authority also depends on all policy layers, pinned executable and contract authority also depends on all policy layers, pinned executable and contract
bytes, startup freezing, and session decisions. bytes, startup freezing, and session decisions.
- Treat handovers, READMEs, examples, hidden source branches, and remembered argv - Treat handovers, READMEs, examples, hidden source branches, and remembered argv
as leads. Public help owns operator-facing commands; requirements own intended as leads. Public help owns operator-facing commands; the specification owns intended
behavior; tests and source establish current checkout behavior. behavior; tests and source establish current checkout behavior.
Distinguish three surfaces explicitly: Distinguish three surfaces explicitly:
@@ -71,7 +71,7 @@ the frozen `tool delegate` subject.
**source-confirmed**, **missing**, **stale claim**, or **not proven**. **source-confirmed**, **missing**, **stale claim**, or **not proven**.
4. For an operator action, explain that the user—not the hosted agent—must run it. 4. For an operator action, explain that the user—not the hosted agent—must run it.
Do not inspect or mutate session state as a substitute. Do not inspect or mutate session state as a substitute.
5. For a missing capability, require Ink's requirements authority before source 5. For a missing capability, require Ink's specification authority before source
implementation. Do not model it as a new external executable merely to bypass implementation. Do not model it as a new external executable merely to bypass
the host boundary. the host boundary.
@@ -93,7 +93,7 @@ the frozen `tool delegate` subject.
EVIDENCE: <runtime output, installed artifact, matching source, or limitation> EVIDENCE: <runtime output, installed artifact, matching source, or limitation>
SURFACE: <operator CLI, model built-in, or admitted external command> SURFACE: <operator CLI, model built-in, or admitted external command>
FINDING: <observed/source-confirmed/missing/stale/not proven> FINDING: <observed/source-confirmed/missing/stale/not proven>
ACTION: <operator step, requirements step, or none> ACTION: <operator step, specification step, or none>
``` ```
Positive smoke: “Does Ink have a sessions command, and why can’t you run it?” Positive smoke: “Does Ink have a sessions command, and why can’t you run it?”
+2 -2
View File
@@ -63,7 +63,7 @@ no ancestor-chain project-agent discovery.
- `read` children may overlap and receive an immutable host floor with no command, - `read` children may overlap and receive an immutable host floor with no command,
file-mutation, lifecycle-mutation, or delegation authority. file-mutation, lifecycle-mutation, or delegation authority.
- `write` children are exclusive, operate in the canonical parent cwd, pause - `write` children are exclusive, operate in the canonical parent cwd, pause
parent effects, and still receive only their effective frozen policy. parent mutations, and still receive only their effective frozen policy.
Never infer effective authority from `access`, prompt text, or a `policy:` label. Never infer effective authority from `access`, prompt text, or a `policy:` label.
Use the child policy snapshot and a real allowed/denied smoke. Use the child policy snapshot and a real allowed/denied smoke.
@@ -87,7 +87,7 @@ referenced bytes are pinned and conjoined into the child effective policy.
## Decision loop ## Decision loop
1. Choose `read` unless the child must produce a real effect. 1. Choose `read` unless the child must perform a real mutation.
2. Choose the smallest model alias that fits the specialist job. 2. Choose the smallest model alias that fits the specialist job.
3. Put the definition in user scope or exact project cwd according to intended 3. Put the definition in user scope or exact project cwd according to intended
precedence. precedence.
+17 -17
View File
@@ -13,7 +13,7 @@ description: >-
## One job ## One job
Design a **permission-sized executable** whose name and argv expose its reachable Design a **permission-sized executable** whose name and argv expose its reachable
effects so Ink can discover, digest-pin, and grant it without granting a platform. reads and mutations so Ink can discover, digest-pin, and grant it without granting a platform.
One executable need not mean one source file: share private build-time modules One executable need not mean one source file: share private build-time modules
when that does not widen runtime authority. when that does not widen runtime authority.
@@ -21,26 +21,26 @@ when that does not widen runtime authority.
Read only what can change the boundary: Read only what can change the boundary:
- the exact job and every reachable side effect; - the exact job and every reachable mutation;
- Ink's current requirements, policy grammar, and mutation protocol; - Ink's current specification, policy grammar, and mutation protocol;
- neighboring tools and existing executables that may already satisfy the job; - neighboring tools and existing executables that may already satisfy the job;
- resource, credential, selector, target, packaging, and proof contracts; - resource, credential, selector, target, packaging, and proof contracts;
- repository requirements and tests. - repository specification and tests.
Project authority outranks this skill. Missing selector semantics, credentials, Project authority outranks this skill. Missing selector semantics, credentials,
recovery rules, or external contracts are blockers—not adapter opportunities. recovery rules, or external contracts are blockers—not adapter opportunities.
```text ```text
JOB -> REUSE? -> EFFECTS -> BOUNDARY -> CONTRACT -> ARTIFACT -> PROOF JOB -> REUSE? -> READS/MUTATIONS -> BOUNDARY -> CONTRACT -> ARTIFACT -> PROOF
``` ```
1. Reuse a directly inspectable executable only when granting its whole reachable 1. Reuse a directly inspectable executable only when granting its whole reachable
surface is honest; otherwise build the coherent missing boundary, not a wrapper. surface is honest; otherwise build the coherent missing boundary, not a wrapper.
2. Enumerate reads, mutations, network effects, secrets, state, children, and 2. Enumerate reads, mutations, network calls, secrets, state, children, and
config/plugin discovery; split where approval, blast radius, or recovery differ. config/plugin discovery; split where approval, blast radius, or recovery differ.
3. Define argv, selectors, streams, errors, dependencies, exhaustive versus 3. Define argv, selectors, streams, errors, dependencies, exhaustive versus
bounded output, and any tool-owned semantic presentation without recreating bounded output, and any tool-owned semantic presentation without recreating
shell grammar or a host-wide effect ontology. shell grammar or a host-wide mutation ontology.
4. State the runtime artifact honestly, then falsify its boundary, behavior, 4. State the runtime artifact honestly, then falsify its boundary, behavior,
presentation, and portability claims through Ink's real run entry point. presentation, and portability claims through Ink's real run entry point.
@@ -108,7 +108,7 @@ Shell globs, path filters, and content patterns are different contracts.
`find`/`fd` forms that execute or delete and `rg` forms that launch preprocessors `find`/`fd` forms that execute or delete and `rg` forms that launch preprocessors
are not read boundaries merely because one intended invocation only searches. A are not read boundaries merely because one intended invocation only searches. A
narrow native search tool is justified when it removes reachable effects, adds narrow native search tool is justified when it removes reachable mutations, adds
canonical path selectors, or supplies the required static portable artifact. canonical path selectors, or supplies the required static portable artifact.
Implement the coherent missing subset, not a compatibility facade or renamed Implement the coherent missing subset, not a compatibility facade or renamed
wrapper. wrapper.
@@ -125,8 +125,8 @@ tool apply <id> <hash> # revalidate; perform once
Required properties: Required properties:
- `stage` performs no external effect and resolves no secrets; - `stage` performs no mutation and resolves no secrets;
- the manifest pins executable identity, canonical effect, authority subject, - the manifest pins executable identity, canonical mutation, authority subject,
non-secret inputs, and drift-sensitive hashes; non-secret inputs, and drift-sensitive hashes;
- selectors are variable semantic facts, never argv prefixes, shell text, or - selectors are variable semantic facts, never argv prefixes, shell text, or
executable invariants; executable invariants;
@@ -149,7 +149,7 @@ layout; the tool owns meaning.
Use the repository's elected projection envelope and bounds exactly; never invent Use the repository's elected projection envelope and bounds exactly; never invent
per-tool presentation formats. Within that contract, use a small display per-tool presentation formats. Within that contract, use a small display
vocabulary rather than universal effect kinds: vocabulary rather than universal mutation kinds:
- headline and canonical target; - headline and canonical target;
- ordered key/value facts; - ordered key/value facts;
@@ -159,7 +159,7 @@ vocabulary rather than universal effect kinds:
Filesystem, HTTP, cloud, and infrastructure tools express their own semantics Filesystem, HTTP, cloud, and infrastructure tools express their own semantics
with those primitives. For example, an HTTP mutator supplies method, canonical with those primitives. For example, an HTTP mutator supplies method, canonical
origin/path, bounded body summary, status, and final URL as facts; it does not ask origin/path, bounded body summary, status, and final URL as facts; it does not ask
Ink to understand an `http` effect type. An infrastructure tool supplies account, Ink to understand an `http` mutation type. An infrastructure tool supplies account,
resource, region, and requested change as facts; it does not create a renderer resource, region, and requested change as facts; it does not create a renderer
branch for its provider. branch for its provider.
@@ -169,7 +169,7 @@ The projection is presentation evidence, never authority:
- derive projection records purely from that value and hash their exact semantic - derive projection records purely from that value and hash their exact semantic
bytes with the manifest; bytes with the manifest;
- render approval from the exact staged projection stored under that identity; - render approval from the exact staged projection stored under that identity;
- apply accepts only staged id plus hash, never replacement target, body, effect, - apply accepts only staged id plus hash, never replacement target, body, mutation,
or projection inputs; or projection inputs;
- the receipt identifies the exact staged manifest and may add only outcome and - the receipt identifies the exact staged manifest and may add only outcome and
evidence facts; it cannot rewrite approved records; evidence facts; it cannot rewrite approved records;
@@ -189,7 +189,7 @@ otherwise expose manifests, hashes, encoded payloads, or provider internals.
## CLI and stream contract ## CLI and stream contract
`tool --help` is the tested human contract: effects, argv, streams, ordering, `tool --help` is the tested human contract: mutations, argv, streams, ordering,
exits, environment/config precedence, credential timing, dependencies, pattern exits, environment/config precedence, credential timing, dependencies, pattern
semantics, and one realistic pipeline. Explicit help succeeds on stdout; usage semantics, and one realistic pipeline. Explicit help succeeds on stdout; usage
errors fail on stderr. Selector help gives value grammar, canonicalization, and a errors fail on stderr. Selector help gives value grammar, canonicalization, and a
@@ -250,7 +250,7 @@ interpreters, or generated-client machinery unless they are the named job.
Use the smallest matrix that can falsify the actual claims: Use the smallest matrix that can falsify the actual claims:
- help/contract agree with accepted argv and selectors; - help/contract agree with accepted argv and selectors;
- main path and one forbidden near miss with zero unintended effect; - main path and one forbidden near miss with zero unintended mutation;
- each reader selector has an adjacent no-match before access; - each reader selector has an adjacent no-match before access;
- each mutator has admitted, approval-required, refused, drift, duplicate, and - each mutator has admitted, approval-required, refused, drift, duplicate, and
indeterminate/recovery outcomes as applicable; indeterminate/recovery outcomes as applicable;
@@ -278,7 +278,7 @@ Do not:
- wrap or partially clone a utility whose whole admitted surface already fits; - wrap or partially clone a utility whose whole admitted surface already fits;
- combine read and mutation for code reuse; - combine read and mutation for code reuse;
- expose a generic request/admin/registry platform; - expose a generic request/admin/registry platform;
- invent invariant selectors, a universal effect ontology, or executable-name - invent invariant selectors, a universal mutation ontology, or executable-name
branches in Ink's renderer; branches in Ink's renderer;
- let tools choose terminal styling or let presentation metadata grant authority; - let tools choose terminal styling or let presentation metadata grant authority;
- treat argv prefixes, globs, or regexes as canonical path authority; - treat argv prefixes, globs, or regexes as canonical path authority;
@@ -312,7 +312,7 @@ Report only:
- **Presentation:** an HTTP mutator derives method, canonical target, and bounded - **Presentation:** an HTTP mutator derives method, canonical target, and bounded
body summary from one staged operation; Ink renders the exact stored projection body summary from one staged operation; Ink renders the exact stored projection
without an `httpsend` branch and overlays receipt-bound status/final URL only. without an `httpsend` branch and overlays receipt-bound status/final URL only.
- **Presentation sprawl:** “support AWS changes” does not add an AWS effect enum or - **Presentation sprawl:** “support AWS changes” does not add an AWS mutation enum or
renderer branch; the permission-sized infrastructure tool projects account, renderer branch; the permission-sized infrastructure tool projects account,
region, resource, requested change, outcome, and evidence through the elected region, resource, requested change, outcome, and evidence through the elected
generic vocabulary. generic vocabulary.