--- name: audit-ink-cli description: >- Use when the user explicitly asks an agent to audit, troubleshoot, or explain the Ink host CLI, its frozen policy, tools, skills, sessions, or context from available authority or user-provided output. Preserve the host/guest boundary: never launch Ink recursively or recommend admitting `ink` to its own run policy. Do not use for implementing Ink or creating an external executable for Ink. --- # Ink CLI ## One job Audit and explain the Ink host from inside an Ink-governed agent without granting the guest authority to invoke, resume, mutate, or recursively launch its host. This skill prevents one recurring failure: treating an operator CLI as an agent tool, then calling a command unavailable by design or broadening policy until the agent can recursively run Ink. ## Trigger boundary Load this skill for explicit questions about the `ink` command, `~/.ink/policy`, project `.ink/policy` files, visible tools or skills, session selection, context handover, startup snapshots, or gaps in those surfaces. Do not load it merely because ordinary work runs under Ink. External executables intended for Ink admission belong to `create-ink-tool`. Ink source changes belong to Ink's repository authority and implementation workflow. ## Host boundary and authority - Never invoke `ink` through the model's `run` surface, and never add or recommend a policy row that lets Ink launch itself. Its absence is intentional separation, not a missing command permission. - A human/operator may invoke Ink outside the governed agent. Give a copyable operator command only when the user asks and its public help contract is proven. - Use user-provided runtime output as runtime evidence. Otherwise inspect the installed artifact identity and a demonstrably matching checkout's specification, tests, public help text, and source; label those findings as contract/source evidence rather than executed runtime proof. - Approved global and ancestor-project rows are additive alternatives; each file explains only its contribution. Effective authority also depends on the approved normalized digest, restrictive child/session policy, the host floor, pinned executable and contract bytes, startup freezing, and session decisions. Never interpret a project file as automatically trusted. - Treat handovers, READMEs, examples, hidden source branches, and remembered argv as leads. Public help owns operator-facing commands; the specification owns intended behavior; tests and source establish current checkout behavior. Distinguish three surfaces explicitly: 1. **Operator CLI commands** such as top-level `ink sessions`, `ink skills`, `ink agent catalog`, and `ink policy help`. 2. **Model-callable Ink built-ins** exposed directly to the hosted agent. 3. **External executables** admitted through Ink's `run` policy. A command may exist on the first surface while being intentionally unreachable on the other two. Current source exposing flat `ink sessions`, `ink skills`, and `ink tools` does not imply invented nested verbs, and a policy rejection does not prove the operator command is absent. The current operator agent catalogue uses `ink agent catalog` and `ink agent resolve NAME`; role launch remains governed by the frozen `tool delegate` subject. ## Decision loop 1. Classify the request as contract audit, policy audit, operator instructions, session/context mutation, or Ink source work. 2. Establish the evidence class: user-observed runtime, installed artifact, matching checkout contract, or unverified note. 3. Compare the claim only across the relevant surface. Label it **observed**, **source-confirmed**, **missing**, **stale claim**, or **not proven**. 4. For an operator action, explain that the user—not the hosted agent—must run it. Do not inspect or mutate session state as a substitute. 5. For a missing capability, require Ink's specification authority before source implementation. Do not model it as a new external executable merely to bypass the host boundary. ## Refusals - Do not edit policy to admit `ink`, call Ink recursively, log in, approve a digest, resume or clear a session, or dump host context from the agent. - Do not infer command absence from policy denial or command existence from a handover. Challenge invented nested session or tool-verification verbs and verify current public help/source before suggesting operator argv. - Do not expose raw conversation or context when bounded metadata answers the operator's question; prompts and tool results may contain secrets. - Do not weaken path, origin, account, or repository selectors merely to make an unrelated external command run. ## Audit receipt ```text EVIDENCE: SURFACE: FINDING: ACTION: ``` Positive smoke: “Does Ink have a sessions command, and why can’t you run it?” loads this skill, confirms the operator/model boundary, and does not alter policy. Negative smoke: “Build a selector-aware GitHub reader for Ink” routes to `create-ink-tool`.