Files
2026-08-16 22:14:57 +02:00

4.0 KiB

ink-skills

Ink-native skills: small on-demand behavior patches for operating Ink, defining subagents, and creating permission-bearing external tools.

This repository owns reusable Ink judgment. Ink owns runtime enforcement and policy. toolset owns compiled external executables. Skills never grant authority by themselves.

Clone once, then link every skill shipped by this checkout:

git clone git@git.tmk241.com:tmk241/ink-skills.git
ink-skills/bin/ink-skills link

Link selected directories or target one project:

ink-skills link /opt/repositories/ink-skills/skills/audit-ink-cli
ink-skills link --project /path/to/project skills/configure-ink-agent

link only creates absolute symlinks. It performs no network access, copies, prompts, registry lookup, or policy mutation. Pulling a linked checkout changes its bytes; restart Ink to freeze the updated skill snapshot.

Import verified artifacts

Transport and authentication remain ordinary shell jobs:

curl -fLo skills.tar https://example/skills.tar
git archive --format=tar HEAD >skills.tar

The publisher communicates the expected digest out of band. Import only after you have that value:

ink-skills import sha256:012345... skills.tar
ink-skills import --project /path/to/project sha256:012345... skills.tar skills/review-sql

import verifies the complete archive before extraction, accepts only regular files and directories with safe relative paths, and rejects symlinks and special files. It materializes the tree under $INK_SKILLS_STORE/sha256/HASH (or the XDG/default data path), then links skills from that immutable content-addressed location. .ink-skills.tsv records each installed skill's archive digest and path without modifying SKILL.md.

The same artifact works whether it arrived via curl, scp, USB, a browser download, or git archive. ink-skills deliberately has no URL, Git, credential, branch, release, or update logic.

Ink discovers $HOME/.ink/skills, $CWD/.ink/skills, and colon-separated INK_SKILLS_DIRS. The installer-only $INK_SKILLS_HOME overrides the user link target. ink-skills list emits TSV; ink-skills --help is the complete command manual. Existing paths and foreign symlinks are refused rather than overwritten.

Skills

Skill Job
audit-ink-cli Audit and explain the Ink host without crossing the host/guest boundary.
configure-ink-agent Create or audit one Ink agent definition, access class, and effective-policy boundary.
create-ink-tool Build one inspectable permission-bearing executable suitable for Ink policy admission.

Agent definitions and policy

Agent definitions live in $HOME/.ink/agents or the exact current project's .ink/agents directory:

name: Frontend specialist
model: design
access: write
policy: frontend.policy

Implement the bounded frontend task and return proof.

access: read|write selects reader/writer scheduling; it does not grant commands or tools. Definitions are frozen at startup, so restart Ink after changing one.

Approved rows from $HOME/.ink/policy and ancestor project .ink/policy files are additive alternatives. A project file can introduce a command only through the normalized effective-policy digest approval; it is never trusted merely because it exists. Empty project policy adds nothing. Child/session policy and the immutable host floor may only narrow the approved durable rows.

Current caveat: Ink records policy: as frozen metadata but does not yet read the named relative file into the child effective policy. Do not treat it as enforced. Use the configure-ink-agent skill for the exact boundary and blocker.

Verify

sh -n bin/ink-skills
sh test/install-smoke.sh
sh test/skills-smoke.sh

Refusals

  • No npm package merely to create symlinks.
  • No skill registry, automatic updater, or network daemon.
  • No policy mutation during installation.
  • No bundled binaries; those belong in toolset.
  • No automatic installation by Ink itself.