--- name: ink-cli description: >- Use when the user explicitly asks an agent to audit, troubleshoot, or explain the Ink host CLI, its frozen policy, tools, skills, sessions, or context from available authority or user-provided output. Preserve the host/guest boundary: never launch Ink recursively or recommend admitting `ink` to its own run policy. Do not use for implementing Ink or creating an external executable for Ink. --- # Ink CLI ## One job Audit and explain the Ink host from inside an Ink-governed agent without granting the guest authority to invoke, resume, mutate, or recursively launch its host. This skill prevents one recurring failure: treating an operator CLI as an agent tool, then calling a command unavailable by design or broadening policy until the agent can recursively run Ink. ## Trigger boundary Load this skill for explicit questions about the `ink` command, `~/.ink/policy`, project `.ink/policy` files, visible tools or skills, session selection, context handover, startup snapshots, or gaps in those surfaces. Do not load it merely because ordinary work runs under Ink. External executables intended for Ink admission belong to `create-ink-agent-cli-tool`. Ink source changes belong to Ink's repository authority and implementation workflow. ## Host boundary and authority - Never invoke `ink` through the model's `run` surface, and never add or recommend a policy row that lets Ink launch itself. Its absence is intentional separation, not a missing command permission. - A human/operator may invoke Ink outside the governed agent. Give a copyable operator command only when the user asks and its public help contract is proven. - Use user-provided runtime output as runtime evidence. Otherwise inspect the installed artifact identity and a demonstrably matching checkout's requirements, tests, public help text, and source; label those findings as contract/source evidence rather than executed runtime proof. - Global and project policy files explain only their contribution. Effective authority also depends on all policy layers, pinned executable and contract bytes, startup freezing, and session decisions. - Treat handovers, READMEs, examples, hidden source branches, and remembered argv as leads. Public help owns operator-facing commands; requirements own intended behavior; tests and source establish current checkout behavior. Distinguish three surfaces explicitly: 1. **Operator CLI commands** such as top-level `ink sessions` or `ink context`. 2. **Model-callable Ink built-ins** exposed directly to the hosted agent. 3. **External executables** admitted through Ink's `run` policy. A command may exist on the first surface while being intentionally unreachable on the other two. Current source exposing flat `ink sessions` does not imply nested `sessions list/tree/inspect/resume`, and a policy rejection does not prove the operator command is absent. ## Decision loop 1. Classify the request as contract audit, policy audit, operator instructions, session/context mutation, or Ink source work. 2. Establish the evidence class: user-observed runtime, installed artifact, matching checkout contract, or unverified note. 3. Compare the claim only across the relevant surface. Label it **observed**, **source-confirmed**, **missing**, **stale claim**, or **not proven**. 4. For an operator action, explain that the user—not the hosted agent—must run it. Do not inspect or mutate session state as a substitute. 5. For a missing capability, require Ink's requirements authority before source implementation. Do not model it as a new external executable merely to bypass the host boundary. ## Refusals - Do not edit policy to admit `ink`, call Ink recursively, log in, approve a digest, resume or clear a session, or dump host context from the agent. - Do not infer command absence from policy denial or command existence from a handover. In particular, challenge invented nested session verbs. - Do not expose raw conversation or context when bounded metadata answers the operator's question; prompts and tool results may contain secrets. - Do not weaken path, origin, account, or repository selectors merely to make an unrelated external command run. ## Audit receipt ```text EVIDENCE: SURFACE: FINDING: ACTION: ``` Positive smoke: “Does Ink have a sessions command, and why can’t you run it?” loads this skill, confirms the operator/model boundary, and does not alter policy. Negative smoke: “Build a selector-aware GitHub reader for Ink” routes to `create-ink-agent-cli-tool`.