Files
ink-skills/README.md
T
2026-08-11 16:54:17 +02:00

110 lines
3.7 KiB
Markdown

# ink-skills
Ink-native skills: small on-demand behavior patches for operating Ink, defining
subagents, and creating permission-bearing external tools.
This repository owns reusable Ink judgment. Ink owns runtime enforcement and
policy. [`toolset`](https://git.tmk241.com/tmk241/toolset) owns compiled external
executables. Skills never grant authority by themselves.
## Install
Clone once, then symlink the skills you want:
```sh
git clone git@git.tmk241.com:tmk241/ink-skills.git
ink-skills/bin/ink-skills install
```
If the repository is already under `/opt/repositories`:
```sh
/opt/repositories/ink-skills/bin/ink-skills install
```
Install selected skills only:
```sh
ink-skills install audit-ink-cli configure-ink-agent
```
Install into one project instead of the user catalogue:
```sh
ink-skills install --project /path/to/project configure-ink-agent
```
Install from any Git repository your normal Git credentials can read:
```sh
ink-skills add --ref main git@git.example:team/skills.git
ink-skills add https://git.example/team/skills.git skills/review-sql
```
`add` resolves the ref to one commit, exports it into a content-addressed store,
computes a SHA-256 over each selected skill tree, and symlinks that immutable
artifact. Provenance is recorded next to installed links in `.ink-skills.tsv`:
source, requested ref, resolved commit, path, and SHA-256. It deliberately does
not edit `SKILL.md` comments. A moved branch does not silently update an installed
skill; the existing pin causes a visible provenance collision.
Git SSH agents and credential helpers remain Git's job. Credential-bearing HTTP
URLs are refused so secrets do not enter manifests or process listings. Remote
skill trees containing symlinks are also refused.
The local `install` path is intentionally smaller than `npx skills`: no registry,
package manager, network access, copies, prompts, lockfile, or hidden state. It
creates absolute symlinks from `$HOME/.ink/skills` (or the installer-only
`$INK_SKILLS_HOME` target override) to this checkout. Pulling the repository
updates locally installed skills; restarting Ink freezes the new bytes into the
next startup snapshot. Ink itself discovers `$HOME/.ink/skills`,
`$CWD/.ink/skills`, and colon-separated `INK_SKILLS_DIRS`.
`ink-skills list` emits TSV. `ink-skills --help` is the complete command manual.
Existing paths and foreign symlinks are refused rather than overwritten.
## Skills
| Skill | Job |
|---|---|
| `audit-ink-cli` | Audit and explain the Ink host without crossing the host/guest boundary. |
| `configure-ink-agent` | Create or audit one Ink agent definition, access class, and effective-policy boundary. |
| `create-ink-tool` | Build one inspectable permission-bearing executable suitable for Ink policy admission. |
## Agent definitions and policy
Agent definitions live in `$HOME/.ink/agents` or the exact current project's
`.ink/agents` directory:
```text
name: Frontend specialist
model: design
access: write
policy: frontend.policy
Implement the bounded frontend task and return proof.
```
`access: read|write` selects reader/writer scheduling; it does not grant commands
or tools. Definitions are frozen at startup, so restart Ink after changing one.
Current caveat: Ink records `policy:` as frozen metadata but does not yet read the
named relative file into the child effective policy. Do not treat it as enforced.
Use the `configure-ink-agent` skill for the exact boundary and blocker.
## Verify
```sh
sh -n bin/ink-skills
sh test/install-smoke.sh
sh test/skills-smoke.sh
```
## Refusals
- No npm package merely to create symlinks.
- No skill registry, automatic updater, or network daemon.
- No policy mutation during installation.
- No bundled binaries; those belong in `toolset`.
- No automatic installation by Ink itself.