skill-authoring §6: name the deployment runtime before the review concludes#52
Merged
Merged
Conversation
…cludes A skill reviewed and finalized against the author's local macOS was rebuilt wholesale the same week when its real target — a sandboxed Linux VM — surfaced after sign-off: host identity, launcher mechanism, and machine-local MCP tool-name assumptions all failed there. §6's lenses check the file against the author's world; none asks where it will run. This adds that question as a review input plus the sweep list for machine-bound assumptions (absolute paths, OS launchers, host identity, clock/timezone, hard-coded MCP tool prefixes). Ships unprobed per the README covenant; Provenance records the probe shape as debt.
PR F-e-u-e-r#52 round-1 gate (grok-4.5 high: FIX 1,2; gpt-5.6-sol max: FIX 1-5). Reproduced and addressed: - unknown/unaskable runtime -> mark user-must-provide, conclude without a portability verdict, never default to the authoring host (grok F1) - MCP clause made executable and bounded to instance-specific identifiers: verified portable name, or a runtime/instance label; no invented discovery mechanism (grok F2 / codex F5) - Done now requires compatibility with every NAMED target - a labeled incompatibility blocks completion or explicitly shrinks the supported scope (codex F1, F4) - S2 citation restored to its qualified form: hard-coded machine-absolute paths (codex F2) - pos/neg pair added at the portable-vs-labeled boundary (codex F4 / grok n4); sweep categories glossed with concrete cues (grok n3); lead state-phrased (grok n5) - codex F3 rejected-with-reason: single-incident rules with unprobed markers are this repo's documented covenant and settled precedent (silent-clobber, fan-in, interactive-runtime all shipped on one observation); S4's two-strike governs fix-log promotion in consuming projects, not this pack's covenant-governed rule adoption - codex n6 (in-packet checks.py unverifiability): standing disposition, gate-runner re-runs it each round Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GhLu6NCGzM9HxnqNb87MAx
…eep, authoring-time ask, adoption block PR F-e-u-e-r#52 round-2 gate (grok-4.5 high: FIX 1,2,3,4; gpt-5.6-sol max: FIX 1,2,3,4,5,7). All reproduced and addressed: - the sweep now runs on every review; naming is a conditional first step, not the trigger - an already-named target no longer skips the whole rule (grok F1 / codex F2) - the runtime ASK moved to authoring start per the file's own gate-placement rule; this review verifies it landed (codex F1) - no-answer path: user-must-provide recorded, sweep still runs, adoption blocked until the owner resolves or explicitly defers (grok F2 / codex F4) - review record defined via S7's change-record shape; target runtime defined as execution environment + governing connector/tool instance (grok F3 / codex F7) - machine-absolute paths get S2's VCS-root remedy - a label never keeps one (grok F4) - scope shrink can only exclude an OPTIONAL target with the user's explicit say; labeled incompatibility with the actual deployment target blocks (codex F3) - pos example made concrete and verifiable: named replacement, run on the target image, instance named (codex F5 / grok n5) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GhLu6NCGzM9HxnqNb87MAx
PR F-e-u-e-r#52 round-3 gate (grok-4.5 high: FIX 1-5; gpt-5.6-sol max: FIX 1-8). All reproduced and addressed: - unknown-target semantics: requester supplies or records explicit risk-acceptance deferral; silence is neither; empty target list never satisfies Done vacuously (grok F1-analog / codex F1) - named-target attribution: obtained from the requester, not author-inferred presence of a string (grok r3 F1) - runtime-agnostic recorded outcome for doctrine-only files (grok F4) - compatibility judged per target over assumptions REACHABLE on it; verified target-scoped dispatch branches count compatible (codex F2) - S2 path remedy quoted verbatim incl. prefix verification, scoped to accidentally machine-local repo paths; target-defined absolute paths are ordinary machine-bound assumptions (codex F3, F6 / grok F2-analog) - S7 record-selection clause quoted verbatim (codex F7) - labels live IN the skill file beside the dependency, verified where reachable, marked unverified where not - a label records a limitation, never proves compatibility (codex F4, F8) - review-cannot-retro-place-the-ask stated; S6 is the blocking backstop, not a time machine (codex F5); target-image run dropped from the pos example (grok F3-analog) - optional-vs-required target pinned to the requester's explicit say (grok F5-analog) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GhLu6NCGzM9HxnqNb87MAx
PR F-e-u-e-r#52 round-4 gate (grok-4.5 high: FIX 1,2,3; gpt-5.6-sol max: FIX 1-6). Adjudication: - deferral terminal state unified: recorded risk acceptance by the deployment owner = alternate Done that still requires the sweep and in-file labels; no acceptance -> blocked; anti-vacuity clash removed (grok F1 / codex F1) - target-scoped dispatch satisfies a named target only when that target keeps a working path for every claimed capability - costume conditionals excluded (grok F2) - Done vocabulary unified on named-target-in-record (grok F3) - sweep list declared a floor; executable-dependency dimensions added (arch, interpreter/deps, versions, fs, permissions, network); runtime-agnostic restricted to pure instruction text (codex F2) - authoring-start requirement made answer-or-user-must-provide BEFORE first artifact-producing step; review = enforcement backstop (codex F4) - plugin branch narrowed to a plugin's instruction files, matching the frontmatter router (codex F6); repo-manifests-first discovery order (codex n7) - codex F3: this PR's own record gains its runtime line (body edit: runtime-agnostic, pure doctrine); codex n8: body Unicode claim corrected to include the arrow glyph - codex F5 rejected-with-reason (standing): single-incident rules with unprobed markers are this repo's covenant and precedent; S4 two-strike governs fix-log promotion in consuming projects Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GhLu6NCGzM9HxnqNb87MAx
F-e-u-e-r
added a commit
that referenced
this pull request
Jul 22, 2026
grok r3 F1: the labels rule's unverified-route block no longer bricks
wrappers with no attribution channel by design — channel present but
report missing/ambiguous/fallback-named blocks dispatch; no channel by
design yields a reachability-only pass with the limit recorded wherever
cited, never a verified-route claim.
grok r3 F2: pinned-string Done and pos example now carry the r2
route-attribution requirement (an unattributed probe never satisfies
the citation; the pos example shows the wrapper's route line).
grok r3 n3: hosted-behavior carve-out parenthetical now names both
duties (date-stamp the recorded claim; decision-time re-probe); the
writing imperative binds explicitly to tool-interface negatives.
grok r3 n4: check-name trigger broadened from 'safe' to any cited
property of a change (safe, correct, covered).
grok r3 n5: port recovery clause moved inside the address-in-use
branch; other bind errors stay terminal for that path.
grok r3 n6: ledger reference now cites the field by its actual title
('Recurring dispatches carry ledgers').
codex r3 F2 (scoped): attribution channel defined as reporting what
ANSWERED — a banner echoing the requested slug is configuration, not
attribution.
codex r3 F3 (scoped): the re-verify probe example now exercises the
claimed-absent capability; runtime-scoped verification remains S6's
deployment-runtime gate (no duplicate home).
codex r3 F4: ledger write-back gains the regressed-prior-fix
transition — re-flagging with evidence spawns a new OPEN finding, the
historical entry staying put with a pointer.
Rejected with counter-evidence (recorded in the PR trail): codex r3 F1
(mutate-and-restore on an unenforced copy is the exact case the
reference already rules — 'an unenforced reader can mutate and restore
without a trace; no endpoint comparison proves the read stayed clean'
-> provisional, never a clean gate pass); codex r3 F5 (re-raise of
PR #52's two-strike standing rejection — S1 placement already gates
authoring start, S6 is the named enforcement backstop, adjudicated in
that PR's own review; the frontmatter loader is pre-existing structure
outside this diff).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GhLu6NCGzM9HxnqNb87MAx
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds one rule to
skill-authoring§6: name the deployment runtime before the review concludes — ask where the skill/plugin will actually run as a review input, then sweep for machine-bound assumptions (absolute paths, OS-specific launchers, host identity, clock/timezone, hardcoded MCP tool-name prefixes). Done when the review names the target runtime(s) and each machine-bound assumption is portable or labeled.Why
§6's lenses (factual / doctrine / usability) all check the file against the author's world; none asks where it will run. A private incident showed the cost: a skill authored, reviewed, and finalized for the author's local macOS was rebuilt wholesale the same week when its real target — a sandboxed Linux VM — surfaced after sign-off; host identity, launcher mechanism, and machine-local MCP tool names all failed there. The question costs one sentence at review time and is a rework at deploy time.
Covenant status
Private incident cited as shape (contributor-verifiable, not linkable). Ships
unprobed; Provenance records the probe shape (machine-bound skill + named foreign runtime, observe whether the sweep fires) as debt.Checks
python3 .github/checks.py: all checks passed🤖 Generated with Claude Code