ink-skills
Ink-native skills: small on-demand behavior patches for operating Ink, defining subagents, and creating permission-bearing external tools.
This repository owns reusable Ink judgment. Ink owns runtime enforcement and
policy. toolset owns compiled external
executables. Skills never grant authority by themselves.
Install
Clone once, then symlink the skills you want:
git clone git@git.tmk241.com:tmk241/ink-skills.git
ink-skills/bin/ink-skills install
If the repository is already under /opt/repositories:
/opt/repositories/ink-skills/bin/ink-skills install
Install selected skills only:
ink-skills install audit-ink-cli configure-ink-agent
Install into one project instead of the user catalogue:
ink-skills install --project /path/to/project configure-ink-agent
Install from any Git repository your normal Git credentials can read:
ink-skills add --ref main git@git.example:team/skills.git
ink-skills add https://git.example/team/skills.git skills/review-sql
add resolves the ref to one commit, exports it into a content-addressed store,
computes a SHA-256 over each selected skill tree, and symlinks that immutable
artifact. Provenance is recorded next to installed links in .ink-skills.tsv:
source, requested ref, resolved commit, path, and SHA-256. It deliberately does
not edit SKILL.md comments. A moved branch does not silently update an installed
skill; the existing pin causes a visible provenance collision.
Git SSH agents and credential helpers remain Git's job. Credential-bearing HTTP URLs are refused so secrets do not enter manifests or process listings. Remote skill trees containing symlinks are also refused.
The local install path is intentionally smaller than npx skills: no registry,
package manager, network access, copies, prompts, lockfile, or hidden state. It
creates absolute symlinks from $HOME/.ink/skills (or the installer-only
$INK_SKILLS_HOME target override) to this checkout. Pulling the repository
updates locally installed skills; restarting Ink freezes the new bytes into the
next startup snapshot. Ink itself discovers $HOME/.ink/skills,
$CWD/.ink/skills, and colon-separated INK_SKILLS_DIRS.
ink-skills list emits TSV. ink-skills --help is the complete command manual.
Existing paths and foreign symlinks are refused rather than overwritten.
Skills
| Skill | Job |
|---|---|
audit-ink-cli |
Audit and explain the Ink host without crossing the host/guest boundary. |
configure-ink-agent |
Create or audit one Ink agent definition, access class, and effective-policy boundary. |
create-ink-tool |
Build one inspectable permission-bearing executable suitable for Ink policy admission. |
Agent definitions and policy
Agent definitions live in $HOME/.ink/agents or the exact current project's
.ink/agents directory:
name: Frontend specialist
model: design
access: write
policy: frontend.policy
Implement the bounded frontend task and return proof.
access: read|write selects reader/writer scheduling; it does not grant commands
or tools. Definitions are frozen at startup, so restart Ink after changing one.
Current caveat: Ink records policy: as frozen metadata but does not yet read the
named relative file into the child effective policy. Do not treat it as enforced.
Use the configure-ink-agent skill for the exact boundary and blocker.
Verify
sh -n bin/ink-skills
sh test/install-smoke.sh
sh test/skills-smoke.sh
Refusals
- No npm package merely to create symlinks.
- No skill registry, automatic updater, or network daemon.
- No policy mutation during installation.
- No bundled binaries; those belong in
toolset. - No automatic installation by Ink itself.