Skip to content

Harden skill contracts and portfolio integrity - #22

Merged
mosobande merged 1 commit into
orifrom
feature/lightweight-skill-contracts
Aug 22, 2026
Merged

Harden skill contracts and portfolio integrity#22
mosobande merged 1 commit into
orifrom
feature/lightweight-skill-contracts

Conversation

@mosobande

@mosobande mosobande commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

Summary

This change tightens the Engineering and Productivity skill portfolio while preserving deliberately lightweight skills instead of expanding them into workflow-heavy contracts.

Skill behavior

  • teach ko-skill to classify skills as lightweight or workflow before judging instruction depth;
  • apply the same control-shape rule during portfolio audits;
  • keep iwadi lightweight while reporting material primary-source conflicts and limiting evidence gaps;
  • make se-triage complete its current assessment before asking permission for an unapproved relevant external/provider mutation;
  • keep Irinṣẹ tool selection lean by moving operational lifecycle behind a conditional reference;
  • keep Àyẹ̀wò Ìgbà Iṣẹ́ single-session analysis lean by moving corpus-only mechanics behind a conditional reference;
  • remove the implicit technical-writing authority to edit yo-slop;
  • retain ro-wo, salaye, and Alága without speculative workflow expansion or extraction.

Provider safety

  • separate provider host trust from ambient credential authority in seda-pr and wo-pr;
  • strip generic provider tokens for trusted custom hosts;
  • disable GitLab CI auto-login for these provider operations;
  • update provider tests to assert credential isolation;
  • declare complete runtime compatibility for the provider workflows.

Release ownership

  • keep Changesets as the package-version owner;
  • let npm regenerate package-lock.json during npm run version instead of editing it with a custom synchronizer;
  • remove the duplicate VERSION file and hard-coded README version marker;
  • link README to GitHub's stable /releases/latest endpoint;
  • remove the custom release-state and catalog scripts;
  • keep PR validation limited to native package-lock verification (npm ci) and the two provider test suites;
  • keep semantic portfolio/catalog reconciliation with ko-skill and review rather than a second permanent registry checker.

Design decisions

Broad applicability does not by itself justify workflow state, phases, retries, or recovery machinery. A lightweight skill may still produce one composed artifact when that native result closes its outcome.

Cross-skill dependency metadata remains absent because the current Agent Skills metadata surface provides no dependency semantics.

Verification

Final parent candidate: 688810c1dfa8cb40b9af647a493d667edf7e3522.

The release simplification removes custom generated-state machinery rather than replacing it: npm ci is the package/lock consistency gate, Changesets updates the package version, and npm owns lockfile regeneration. Provider unit tests remain unchanged from the previously accepted candidate.

The se-triage permission rule preserves its existing authority model and provider-write safeguards. Irinṣẹ and Àyẹ̀wò Ìgbà Iṣẹ́ remain behavior-preserving progressive-disclosure changes. The proposed Alága extraction remains rejected because candidate, proof, documentation, and review gates are too coupled to the core delivery path.

Stack

This PR is the non-design parent for design PR #9. PR #9 is based directly on this parent head; design-specific ownership and routing changes remain in the child.

Review focus

  1. provider token isolation for GitHub/GitLab public and custom hosts;
  2. the se-triage end-of-assessment mutation-permission boundary;
  3. behavior preservation across the Irinṣẹ and Àyẹ̀wò Ìgbà Iṣẹ́ conditional extractions;
  4. the lightweight/workflow classification in ko-skill;
  5. native Changesets/npm release ownership without custom synchronizers.

Contributor: @mosobande

@mosobande
mosobande force-pushed the feature/lightweight-skill-contracts branch from 0beab25 to 181cf7a Compare August 22, 2026 15:37
@mosobande
mosobande force-pushed the feature/lightweight-skill-contracts branch 2 times, most recently from 4bf4d6e to ff421f3 Compare August 22, 2026 17:29
@mosobande
mosobande force-pushed the feature/lightweight-skill-contracts branch from 5e9c26e to 688810c Compare August 22, 2026 18:03
@mosobande
mosobande requested a review from atunwo August 22, 2026 18:08

@atunwo atunwo Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Alátùńwò AI review · 📄 Diff-only

Reviewed from the pull request diff only (no surrounding files).

This PR hardens provider credential isolation, simplifies release ownership, and refines skill contracts. No blocking issues found; runtime behavior could not be independently verified from the supplied diff.

@atunwo
atunwo Bot removed the request for review from atunwo August 22, 2026 18:09
@mosobande
mosobande merged commit a2f8c0c into ori Aug 22, 2026
4 checks passed
@github-actions github-actions Bot mentioned this pull request Aug 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant