feat: ship SKILL.md so a clone is actually an install - #8
Merged
Merged
Conversation
Cloning this repo into a skills directory did NOT produce a working skill. `SKILL.md`
carries the frontmatter (name, description, effort) that registers and routes it, and
that file was deliberately kept out of the repo as the private, vendor-facing entry
point. The consequence went unnoticed: everything needed to RUN the toolkit shipped,
and the one file needed to FIND it did not. A fresh clone gave you `Tools/*.ts` to
invoke by hand.
The privacy rationale was about vendor terminology, not the manifest, so this ships a
vendor-neutral SKILL.md. Four couplings were removed:
- frontmatter NOT-FOR clause naming a private skill library -> described generically
- a Customization section pointing at an absolute private path -> optional, generic
- "ISA `Anti:` criterion" -> the general form (a MUST NOT with a runnable probe),
noting it maps onto any spec format with negative criteria
- an Integration section cross-referencing named private skills -> the same content
said in terms of what it complements: SAST and dependency audit, live/offensive
testing, property-based probes, and CAST for retrospectives
Nothing else changed. The routing table, the method, the tool reference, the best
practices and all the gotchas were already vendor-neutral.
README also now documents both install paths and states the Bun prerequisite plainly,
because the shebangs are `#!/usr/bin/env bun` and a box without Bun fails immediately —
which is the most common install failure and was previously one parenthetical.
Verified by cloning the branch into a clean directory and checking the skill registers
and the CLI runs; smoke suite replicated locally.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Cloning this repo into a skills directory did not produce a working skill.
SKILL.mdcarries the frontmatter (name,description,effort) that registers and routes it, and it was deliberately kept out of the repo as the private entry point. The consequence had gone unnoticed: everything needed to run the toolkit shipped, and the one file needed to find it did not. A fresh clone gave youTools/*.tsto invoke by hand.The privacy rationale was about vendor terminology, not about the manifest — so this ships a vendor-neutral
SKILL.md. Four couplings removed:Anti:criterion"MUST NOTwith a runnable probe, noting it maps onto any spec format with negative criteriaNothing else changed — the routing table, method, tool reference, best practices and every gotcha were already vendor-neutral.
README now documents both install paths (skill and standalone CLI) and states the Bun prerequisite plainly. The shebangs are
#!/usr/bin/env bun, so a box without Bun fails immediately; that was previously a single parenthetical, and it is the most common install failure.Verified by cloning the branch into a clean directory, confirming the frontmatter parses and the CLI runs, and replicating the smoke suite locally.