# ink-skills Ink-native skills: small on-demand behavior patches for operating Ink, defining subagents, and creating permission-bearing external tools. This repository owns reusable Ink judgment. Ink owns runtime enforcement and policy. [`toolset`](https://git.tmk241.com/tmk241/toolset) owns compiled external executables. Skills never grant authority by themselves. ## Link local skills Clone once, then link every skill shipped by this checkout: ```sh git clone git@git.tmk241.com:tmk241/ink-skills.git ink-skills/bin/ink-skills link ``` Link selected directories or target one project: ```sh ink-skills link /opt/repositories/ink-skills/skills/audit-ink-cli ink-skills link --project /path/to/project skills/configure-ink-agent ``` `link` only creates absolute symlinks. It performs no network access, copies, prompts, registry lookup, or policy mutation. Pulling a linked checkout changes its bytes; restart Ink to freeze the updated skill snapshot. ## Import verified artifacts Transport and authentication remain ordinary shell jobs: ```sh curl -fLo skills.tar https://example/skills.tar git archive --format=tar HEAD >skills.tar ``` The publisher communicates the expected digest out of band. Import only after you have that value: ```sh ink-skills import sha256:012345... skills.tar ink-skills import --project /path/to/project sha256:012345... skills.tar skills/review-sql ``` `import` verifies the complete archive before extraction, accepts only regular files and directories with safe relative paths, and rejects symlinks and special files. It materializes the tree under `$INK_SKILLS_STORE/sha256/HASH` (or the XDG/default data path), then links skills from that immutable content-addressed location. `.ink-skills.tsv` records each installed skill's archive digest and path without modifying `SKILL.md`. The same artifact works whether it arrived via curl, scp, USB, a browser download, or `git archive`. `ink-skills` deliberately has no URL, Git, credential, branch, release, or update logic. Ink discovers `$HOME/.ink/skills`, `$CWD/.ink/skills`, and colon-separated `INK_SKILLS_DIRS`. The installer-only `$INK_SKILLS_HOME` overrides the user link target. `ink-skills list` emits TSV; `ink-skills --help` is the complete command manual. Existing paths and foreign symlinks are refused rather than overwritten. ## Skills | Skill | Job | |---|---| | `audit-ink-cli` | Audit and explain the Ink host without crossing the host/guest boundary. | | `configure-ink-agent` | Create or audit one Ink agent definition, access class, and effective-policy boundary. | | `create-ink-tool` | Build one inspectable permission-bearing executable suitable for Ink policy admission. | ## Agent definitions and policy Agent definitions live in `$HOME/.ink/agents` or the exact current project's `.ink/agents` directory: ```text name: Frontend specialist model: design access: write policy: frontend.policy Implement the bounded frontend task and return proof. ``` `access: read|write` selects reader/writer scheduling; it does not grant commands or tools. Definitions are frozen at startup, so restart Ink after changing one. Current caveat: Ink records `policy:` as frozen metadata but does not yet read the named relative file into the child effective policy. Do not treat it as enforced. Use the `configure-ink-agent` skill for the exact boundary and blocker. ## Verify ```sh sh -n bin/ink-skills sh test/install-smoke.sh sh test/skills-smoke.sh ``` ## Refusals - No npm package merely to create symlinks. - No skill registry, automatic updater, or network daemon. - No policy mutation during installation. - No bundled binaries; those belong in `toolset`. - No automatic installation by Ink itself.