104 lines
5.0 KiB
Markdown
104 lines
5.0 KiB
Markdown
---
|
||
name: ink-cli
|
||
description: >-
|
||
Use when the user explicitly asks an agent to audit, troubleshoot, or explain
|
||
the Ink host CLI, its frozen policy, tools, skills, sessions, or context from
|
||
available authority or user-provided output. Preserve the host/guest boundary:
|
||
never launch Ink recursively or recommend admitting `ink` to its own run policy.
|
||
Do not use for implementing Ink or creating an external executable for Ink.
|
||
---
|
||
|
||
# Ink CLI
|
||
|
||
## One job
|
||
|
||
Audit and explain the Ink host from inside an Ink-governed agent without granting
|
||
the guest authority to invoke, resume, mutate, or recursively launch its host.
|
||
|
||
This skill prevents one recurring failure: treating an operator CLI as an agent
|
||
tool, then calling a command unavailable by design or broadening policy until the
|
||
agent can recursively run Ink.
|
||
|
||
## Trigger boundary
|
||
|
||
Load this skill for explicit questions about the `ink` command,
|
||
`~/.ink/policy`, project `.ink/policy` files, visible tools or skills, session
|
||
selection, context handover, startup snapshots, or gaps in those surfaces.
|
||
|
||
Do not load it merely because ordinary work runs under Ink. External executables
|
||
intended for Ink admission belong to `create-ink-agent-cli-tool`. Ink source
|
||
changes belong to Ink's repository authority and implementation workflow.
|
||
|
||
## Host boundary and authority
|
||
|
||
- Never invoke `ink` through the model's `run` surface, and never add or recommend
|
||
a policy row that lets Ink launch itself. Its absence is intentional separation,
|
||
not a missing command permission.
|
||
- A human/operator may invoke Ink outside the governed agent. Give a copyable
|
||
operator command only when the user asks and its public help contract is proven.
|
||
- Use user-provided runtime output as runtime evidence. Otherwise inspect the
|
||
installed artifact identity and a demonstrably matching checkout's requirements,
|
||
tests, public help text, and source; label those findings as contract/source
|
||
evidence rather than executed runtime proof.
|
||
- Global and project policy files explain only their contribution. Effective
|
||
authority also depends on all policy layers, pinned executable and contract
|
||
bytes, startup freezing, and session decisions.
|
||
- Treat handovers, READMEs, examples, hidden source branches, and remembered argv
|
||
as leads. Public help owns operator-facing commands; requirements own intended
|
||
behavior; tests and source establish current checkout behavior.
|
||
|
||
Distinguish three surfaces explicitly:
|
||
|
||
1. **Operator CLI commands** such as top-level `ink sessions`, `ink skills`,
|
||
`ink agent catalog`, and `ink policy help`.
|
||
2. **Model-callable Ink built-ins** exposed directly to the hosted agent.
|
||
3. **External executables** admitted through Ink's `run` policy.
|
||
|
||
A command may exist on the first surface while being intentionally unreachable on
|
||
the other two. Current source exposing flat `ink sessions`, `ink skills`, and
|
||
`ink tools` does not imply invented nested verbs, and a policy rejection does not
|
||
prove the operator command is absent. The current operator agent catalogue uses
|
||
`ink agent catalog` and `ink agent resolve NAME`; role launch remains governed by
|
||
the frozen `tool delegate` subject.
|
||
|
||
## Decision loop
|
||
|
||
1. Classify the request as contract audit, policy audit, operator instructions,
|
||
session/context mutation, or Ink source work.
|
||
2. Establish the evidence class: user-observed runtime, installed artifact,
|
||
matching checkout contract, or unverified note.
|
||
3. Compare the claim only across the relevant surface. Label it **observed**,
|
||
**source-confirmed**, **missing**, **stale claim**, or **not proven**.
|
||
4. For an operator action, explain that the user—not the hosted agent—must run it.
|
||
Do not inspect or mutate session state as a substitute.
|
||
5. For a missing capability, require Ink's requirements authority before source
|
||
implementation. Do not model it as a new external executable merely to bypass
|
||
the host boundary.
|
||
|
||
## Refusals
|
||
|
||
- Do not edit policy to admit `ink`, call Ink recursively, log in, approve a
|
||
digest, resume or clear a session, or dump host context from the agent.
|
||
- Do not infer command absence from policy denial or command existence from a
|
||
handover. Challenge invented nested session or tool-verification verbs and
|
||
verify current public help/source before suggesting operator argv.
|
||
- Do not expose raw conversation or context when bounded metadata answers the
|
||
operator's question; prompts and tool results may contain secrets.
|
||
- Do not weaken path, origin, account, or repository selectors merely to make an
|
||
unrelated external command run.
|
||
|
||
## Audit receipt
|
||
|
||
```text
|
||
EVIDENCE: <runtime output, installed artifact, matching source, or limitation>
|
||
SURFACE: <operator CLI, model built-in, or admitted external command>
|
||
FINDING: <observed/source-confirmed/missing/stale/not proven>
|
||
ACTION: <operator step, requirements step, or none>
|
||
```
|
||
|
||
Positive smoke: “Does Ink have a sessions command, and why can’t you run it?”
|
||
loads this skill, confirms the operator/model boundary, and does not alter policy.
|
||
|
||
Negative smoke: “Build a selector-aware GitHub reader for Ink” routes to
|
||
`create-ink-agent-cli-tool`.
|