4.0 KiB
ink-skills
Ink-native skills: small on-demand behavior patches for operating Ink, defining subagents, and creating permission-bearing external tools.
This repository owns reusable Ink judgment. Ink owns runtime enforcement and
policy. toolset owns compiled external
executables. Skills never grant authority by themselves.
Link local skills
Clone once, then link every skill shipped by this checkout:
git clone git@git.tmk241.com:tmk241/ink-skills.git
ink-skills/bin/ink-skills link
Link selected directories or target one project:
ink-skills link /opt/repositories/ink-skills/skills/audit-ink-cli
ink-skills link --project /path/to/project skills/configure-ink-agent
link only creates absolute symlinks. It performs no network access, copies,
prompts, registry lookup, or policy mutation. Pulling a linked checkout changes
its bytes; restart Ink to freeze the updated skill snapshot.
Import verified artifacts
Transport and authentication remain ordinary shell jobs:
curl -fLo skills.tar https://example/skills.tar
git archive --format=tar HEAD >skills.tar
The publisher communicates the expected digest out of band. Import only after you have that value:
ink-skills import sha256:012345... skills.tar
ink-skills import --project /path/to/project sha256:012345... skills.tar skills/review-sql
import verifies the complete archive before extraction, accepts only regular
files and directories with safe relative paths, and rejects symlinks and special
files. It materializes the tree under
$INK_SKILLS_STORE/sha256/HASH (or the XDG/default data path), then links skills
from that immutable content-addressed location. .ink-skills.tsv records each
installed skill's archive digest and path without modifying SKILL.md.
The same artifact works whether it arrived via curl, scp, USB, a browser download,
or git archive. ink-skills deliberately has no URL, Git, credential, branch,
release, or update logic.
Ink discovers $HOME/.ink/skills, $CWD/.ink/skills, and colon-separated
INK_SKILLS_DIRS. The installer-only $INK_SKILLS_HOME overrides the user link
target. ink-skills list emits TSV; ink-skills --help is the complete command
manual. Existing paths and foreign symlinks are refused rather than overwritten.
Skills
| Skill | Job |
|---|---|
audit-ink-cli |
Audit and explain the Ink host without crossing the host/guest boundary. |
configure-ink-agent |
Create or audit one Ink agent definition, access class, and effective-policy boundary. |
create-ink-tool |
Build one inspectable permission-bearing executable suitable for Ink policy admission. |
Agent definitions and policy
Agent definitions live in $HOME/.ink/agents or the exact current project's
.ink/agents directory:
name: Frontend specialist
model: design
access: write
policy: frontend.policy
Implement the bounded frontend task and return proof.
access: read|write selects reader/writer scheduling; it does not grant commands
or tools. Definitions are frozen at startup, so restart Ink after changing one.
Approved rows from $HOME/.ink/policy and ancestor project .ink/policy files are
additive alternatives. A project file can introduce a command only through the
normalized effective-policy digest approval; it is never trusted merely because it
exists. Empty project policy adds nothing. Child/session policy and the immutable
host floor may only narrow the approved durable rows.
Current caveat: Ink records policy: as frozen metadata but does not yet read the
named relative file into the child effective policy. Do not treat it as enforced.
Use the configure-ink-agent skill for the exact boundary and blocker.
Verify
sh -n bin/ink-skills
sh test/install-smoke.sh
sh test/skills-smoke.sh
Refusals
- No npm package merely to create symlinks.
- No skill registry, automatic updater, or network daemon.
- No policy mutation during installation.
- No bundled binaries; those belong in
toolset. - No automatic installation by Ink itself.