Skip to content

feat: ship SKILL.md so a clone is actually an install - #8

Merged
MyAlterLego merged 1 commit into
mainfrom
feat/installable-skill
Jul 25, 2026
Merged

MyAlterLego merged 1 commit into
mainfrom
feat/installable-skill

Conversation

@MyAlterLego

Copy link
Copy Markdown
Contributor

Cloning this repo into a skills directory did not produce a working skill.

SKILL.md carries the frontmatter (name, description, effort) that registers and routes it, and it was deliberately kept out of the repo as the private entry point. The consequence had gone unnoticed: everything needed to run the toolkit shipped, and the one file needed to find it did not. A fresh clone gave you Tools/*.ts to invoke by hand.

The privacy rationale was about vendor terminology, not about the manifest — so this ships a vendor-neutral SKILL.md. Four couplings removed:

was now
frontmatter NOT-FOR naming a private skill library described generically
Customization section with an absolute private path optional, generic
"ISA Anti: criterion" the general form — a MUST NOT with a runnable probe, noting it maps onto any spec format with negative criteria
Integration cross-referencing named private skills same content in terms of what it complements: SAST, live testing, property-based probes, CAST

Nothing else changed — the routing table, method, tool reference, best practices and every gotcha were already vendor-neutral.

README now documents both install paths (skill and standalone CLI) and states the Bun prerequisite plainly. The shebangs are #!/usr/bin/env bun, so a box without Bun fails immediately; that was previously a single parenthetical, and it is the most common install failure.

Verified by cloning the branch into a clean directory, confirming the frontmatter parses and the CLI runs, and replicating the smoke suite locally.

Cloning this repo into a skills directory did NOT produce a working skill. `SKILL.md`
carries the frontmatter (name, description, effort) that registers and routes it, and
that file was deliberately kept out of the repo as the private, vendor-facing entry
point. The consequence went unnoticed: everything needed to RUN the toolkit shipped,
and the one file needed to FIND it did not. A fresh clone gave you `Tools/*.ts` to
invoke by hand.

The privacy rationale was about vendor terminology, not the manifest, so this ships a
vendor-neutral SKILL.md. Four couplings were removed:

  - frontmatter NOT-FOR clause naming a private skill library -> described generically
  - a Customization section pointing at an absolute private path -> optional, generic
  - "ISA `Anti:` criterion" -> the general form (a MUST NOT with a runnable probe),
    noting it maps onto any spec format with negative criteria
  - an Integration section cross-referencing named private skills -> the same content
    said in terms of what it complements: SAST and dependency audit, live/offensive
    testing, property-based probes, and CAST for retrospectives

Nothing else changed. The routing table, the method, the tool reference, the best
practices and all the gotchas were already vendor-neutral.

README also now documents both install paths and states the Bun prerequisite plainly,
because the shebangs are `#!/usr/bin/env bun` and a box without Bun fails immediately —
which is the most common install failure and was previously one parenthetical.

Verified by cloning the branch into a clean directory and checking the skill registers
and the CLI runs; smoke suite replicated locally.
@MyAlterLego
MyAlterLego merged commit 06896ea into main Jul 25, 2026
2 checks passed
@MyAlterLego
MyAlterLego deleted the feat/installable-skill branch July 25, 2026 23:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants