5.0 KiB
name, description
| name | description |
|---|---|
| audit-ink-cli | Use when the user explicitly asks an agent to audit, troubleshoot, or explain the Ink host CLI, its frozen policy, tools, skills, sessions, or context from available authority or user-provided output. Preserve the host/guest boundary: never launch Ink recursively or recommend admitting `ink` to its own run policy. Do not use for implementing Ink or creating an external executable for Ink. |
Ink CLI
One job
Audit and explain the Ink host from inside an Ink-governed agent without granting the guest authority to invoke, resume, mutate, or recursively launch its host.
This skill prevents one recurring failure: treating an operator CLI as an agent tool, then calling a command unavailable by design or broadening policy until the agent can recursively run Ink.
Trigger boundary
Load this skill for explicit questions about the ink command,
~/.ink/policy, project .ink/policy files, visible tools or skills, session
selection, context handover, startup snapshots, or gaps in those surfaces.
Do not load it merely because ordinary work runs under Ink. External executables
intended for Ink admission belong to create-ink-tool. Ink source
changes belong to Ink's repository authority and implementation workflow.
Host boundary and authority
- Never invoke
inkthrough the model'srunsurface, and never add or recommend a policy row that lets Ink launch itself. Its absence is intentional separation, not a missing command permission. - A human/operator may invoke Ink outside the governed agent. Give a copyable operator command only when the user asks and its public help contract is proven.
- Use user-provided runtime output as runtime evidence. Otherwise inspect the installed artifact identity and a demonstrably matching checkout's requirements, tests, public help text, and source; label those findings as contract/source evidence rather than executed runtime proof.
- Global and project policy files explain only their contribution. Effective authority also depends on all policy layers, pinned executable and contract bytes, startup freezing, and session decisions.
- Treat handovers, READMEs, examples, hidden source branches, and remembered argv as leads. Public help owns operator-facing commands; requirements own intended behavior; tests and source establish current checkout behavior.
Distinguish three surfaces explicitly:
- Operator CLI commands such as top-level
ink sessions,ink skills,ink agent catalog, andink policy help. - Model-callable Ink built-ins exposed directly to the hosted agent.
- External executables admitted through Ink's
runpolicy.
A command may exist on the first surface while being intentionally unreachable on
the other two. Current source exposing flat ink sessions, ink skills, and
ink tools does not imply invented nested verbs, and a policy rejection does not
prove the operator command is absent. The current operator agent catalogue uses
ink agent catalog and ink agent resolve NAME; role launch remains governed by
the frozen tool delegate subject.
Decision loop
- Classify the request as contract audit, policy audit, operator instructions, session/context mutation, or Ink source work.
- Establish the evidence class: user-observed runtime, installed artifact, matching checkout contract, or unverified note.
- Compare the claim only across the relevant surface. Label it observed, source-confirmed, missing, stale claim, or not proven.
- For an operator action, explain that the user—not the hosted agent—must run it. Do not inspect or mutate session state as a substitute.
- For a missing capability, require Ink's requirements authority before source implementation. Do not model it as a new external executable merely to bypass the host boundary.
Refusals
- Do not edit policy to admit
ink, call Ink recursively, log in, approve a digest, resume or clear a session, or dump host context from the agent. - Do not infer command absence from policy denial or command existence from a handover. Challenge invented nested session or tool-verification verbs and verify current public help/source before suggesting operator argv.
- Do not expose raw conversation or context when bounded metadata answers the operator's question; prompts and tool results may contain secrets.
- Do not weaken path, origin, account, or repository selectors merely to make an unrelated external command run.
Audit receipt
EVIDENCE: <runtime output, installed artifact, matching source, or limitation>
SURFACE: <operator CLI, model built-in, or admitted external command>
FINDING: <observed/source-confirmed/missing/stale/not proven>
ACTION: <operator step, requirements step, or none>
Positive smoke: “Does Ink have a sessions command, and why can’t you run it?” loads this skill, confirms the operator/model boundary, and does not alter policy.
Negative smoke: “Build a selector-aware GitHub reader for Ink” routes to
create-ink-tool.