Files
2026-08-16 22:14:57 +02:00

106 lines
5.2 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
name: audit-ink-cli
description: >-
Use when the user explicitly asks an agent to audit, troubleshoot, or explain
the Ink host CLI, its frozen policy, tools, skills, sessions, or context from
available authority or user-provided output. Preserve the host/guest boundary:
never launch Ink recursively or recommend admitting `ink` to its own run policy.
Do not use for implementing Ink or creating an external executable for Ink.
---
# Ink CLI
## One job
Audit and explain the Ink host from inside an Ink-governed agent without granting
the guest authority to invoke, resume, mutate, or recursively launch its host.
This skill prevents one recurring failure: treating an operator CLI as an agent
tool, then calling a command unavailable by design or broadening policy until the
agent can recursively run Ink.
## Trigger boundary
Load this skill for explicit questions about the `ink` command,
`~/.ink/policy`, project `.ink/policy` files, visible tools or skills, session
selection, context handover, startup snapshots, or gaps in those surfaces.
Do not load it merely because ordinary work runs under Ink. External executables
intended for Ink admission belong to `create-ink-tool`. Ink source
changes belong to Ink's repository authority and implementation workflow.
## Host boundary and authority
- Never invoke `ink` through the model's `run` surface, and never add or recommend
a policy row that lets Ink launch itself. Its absence is intentional separation,
not a missing command permission.
- A human/operator may invoke Ink outside the governed agent. Give a copyable
operator command only when the user asks and its public help contract is proven.
- Use user-provided runtime output as runtime evidence. Otherwise inspect the
installed artifact identity and a demonstrably matching checkout's specification,
tests, public help text, and source; label those findings as contract/source
evidence rather than executed runtime proof.
- Approved global and ancestor-project rows are additive alternatives; each file
explains only its contribution. Effective authority also depends on the approved
normalized digest, restrictive child/session policy, the host floor, pinned
executable and contract bytes, startup freezing, and session decisions. Never
interpret a project file as automatically trusted.
- Treat handovers, READMEs, examples, hidden source branches, and remembered argv
as leads. Public help owns operator-facing commands; the specification owns intended
behavior; tests and source establish current checkout behavior.
Distinguish three surfaces explicitly:
1. **Operator CLI commands** such as top-level `ink sessions`, `ink skills`,
`ink agent catalog`, and `ink policy help`.
2. **Model-callable Ink built-ins** exposed directly to the hosted agent.
3. **External executables** admitted through Ink's `run` policy.
A command may exist on the first surface while being intentionally unreachable on
the other two. Current source exposing flat `ink sessions`, `ink skills`, and
`ink tools` does not imply invented nested verbs, and a policy rejection does not
prove the operator command is absent. The current operator agent catalogue uses
`ink agent catalog` and `ink agent resolve NAME`; role launch remains governed by
the frozen `tool delegate` subject.
## Decision loop
1. Classify the request as contract audit, policy audit, operator instructions,
session/context mutation, or Ink source work.
2. Establish the evidence class: user-observed runtime, installed artifact,
matching checkout contract, or unverified note.
3. Compare the claim only across the relevant surface. Label it **observed**,
**source-confirmed**, **missing**, **stale claim**, or **not proven**.
4. For an operator action, explain that the user—not the hosted agent—must run it.
Do not inspect or mutate session state as a substitute.
5. For a missing capability, require Ink's specification authority before source
implementation. Do not model it as a new external executable merely to bypass
the host boundary.
## Refusals
- Do not edit policy to admit `ink`, call Ink recursively, log in, approve a
digest, resume or clear a session, or dump host context from the agent.
- Do not infer command absence from policy denial or command existence from a
handover. Challenge invented nested session or tool-verification verbs and
verify current public help/source before suggesting operator argv.
- Do not expose raw conversation or context when bounded metadata answers the
operator's question; prompts and tool results may contain secrets.
- Do not weaken path, origin, account, or repository selectors merely to make an
unrelated external command run.
## Audit receipt
```text
EVIDENCE: <runtime output, installed artifact, matching source, or limitation>
SURFACE: <operator CLI, model built-in, or admitted external command>
FINDING: <observed/source-confirmed/missing/stale/not proven>
ACTION: <operator step, specification step, or none>
```
Positive smoke: “Does Ink have a sessions command, and why can’t you run it?”
loads this skill, confirms the operator/model boundary, and does not alter policy.
Negative smoke: “Build a selector-aware GitHub reader for Ink” routes to
`create-ink-tool`.