Repository navigation
chore(skills): load skills/ directly in Codex and delete the generated copy - #1188
Merged
Merged
Conversation
…d copy
The Codex plugin shipped skills-codex/, a generated second copy of skills/
with the frontmatter cut to name and description. The bodies were the source
bodies, all 28 catalog rows were parity_only, and `ao skills link` and
`npx skills` already hand Codex the source tree. .codex-plugin/plugin.json
now ships ./skills and the copy is gone, with the generator and everything
that only policed it.
Deleted: skills-codex/ (278 files), skills-codex-overrides/, scripts/lint/,
18 scripts (codex-sync, regen-codex-hashes, register-new-codex-skill,
append-codex-override-entry, mirror-codex-references,
refresh-codex-artifacts, audit-codex-parity.{py,sh},
check-codex-parity-drift, lint-codex-native, smoke-test-codex-skills,
export-claude-skills-to-codex and six validate-codex-* validators), their
tests, four gate-registry entries, and the doctor failure mode
fm-skills-stale-codex-sync.
Kept and reduced to what still has a subject:
- validate-codex-api-conformance.sh now checks skills/ against the facts the
Codex loader enforces (observed with skills/list on codex-cli 0.156.1) and
the explicit-only invocation policy. It stays in regen-all.sh --check.
- skill.runtime-formats, skill.runtime-parity, skill.manifests and
derived.changed-scope keep their skills/ halves.
- ao skills check, ao skills link and ao workflows link find the repo root by
skills/ plus registry.json and PRODUCT.md, not by the skills-codex/ sibling.
Carried over so nothing Codex relied on is lost:
- skills/interview/agents/openai.yaml. Codex reads the invocation policy from
that file, and the generator derived it from disable-model-invocation. It is
now source-owned and the conformance check fails without it.
- skills/_fixtures moved to tests/fixtures/skill-eval. Codex loads every
SKILL.md under the plugin skill tree; the fixtures loaded as a skill named
"Good Skill" and a load error.
prompt.md, .agentops-generated.json and .agentops-manifest.json had no Codex
consumer and are dropped without replacement. The CHANGELOG states what
plugin users lose.
Gate-Loosen-Reason: the generated Codex skill copy is deleted, so check-codex-parity-drift.sh and the four skill.codex-* registry entries that policed only that copy have no subject; every gate over skills/ is kept
Test-Removal-Reason: the removed Go tests covered Codex-copy parity, manifest-hash and plugin-cache sync code paths that are deleted with the copy
boshu2
added a commit
that referenced
this pull request
Oct 3, 2026
… gaps (#1189) Follows #1188, now merged; main was merged into this branch, so the diff is only this PR's changes. ## What changes The contract required a fresh author-distinct validation on every change, a PASS with nothing unchecked, and a re-validation after each repair. A reviewer asked to find problems always finds one, so that combination could not converge. In practice review cost exceeded the cost of the work. The contract and the skills that drive review now say: - **Default:** for an ordinary change the author's checks and CI are the gate. No fresh review is owed. - **One fresh read only when:** the caller asks; a mistake cannot be cheaply undone after it lands (a published release or instructions users will follow, a security boundary, destroying data or tracker state, deleting a check that protects the product); or no deterministic check covers the changed behavior. - **One round:** the reviewer gets the exact subject and one question, and does not re-run checks. - **Defects only:** what fails accepted behavior or would mislead a user, break install or the CLI, or remove protection for the product. Everything else is an optional note. - **No re-review:** a repair is confirmed by a check and does not start another review. `NOT_PROVEN` is reported with its gaps instead of being chased. - **Cost:** review stays a fraction of the cost of the work. A requested binding verdict keeps its existing PASS rule. ## Where - `AGENTS.md` (still within its 250-line budget, at 249). - Skills: `rpi`, `validate`, `implement`, `orchestrate`, `craft-goal`, `navigate`, and one example in `reverse-engineer`. `craft-goal` and `navigate` no longer give every bead its own validation. - References: `rpi/references/boundaries.md`, `outer-goal.md`, `bounded-adapter.md` (now says not to select it for ordinary work), and two `domain` standards pages. - Docs: `docs/agent-workflow-reference.md`, `docs/architecture/rpi-traversal.md`, CHANGELOG. - Two wording pins moved to the new rule: `tests/scripts/agents-operating-contract.bats` and `skills/rpi/scripts/validate.sh`. One now fails if "a repair does not start another review" disappears. ## Not changed - Council keeps its caller-set round limit and deadline; it is caller-selected and already bounded. - `skills/rpi/scripts/run_once.py`, the fixed-dispatch adapter with repeated review rounds, is untouched code. Deleting it belongs to the cleanup that follows. - README and other docs still describe the product as independently validated change. That wording is not touched here. ## Gap fixes (second commit) Found while checking release readiness; fixed here so the release has one clean pass. - **Docs:** `PRODUCT.md`, the docs index, how-it-works, architecture, philosophy, first-value path, migration, CI and scale pages now match the skills: checks and CI, plus one fresh read where a mistake is costly. - **Removed the fixed-dispatch RPI adapter** (`run_once.py`, its tests, reference page and `rpi.feature`) that modelled repeated review rounds, and `tests/e2e/rpi-phased-domain.sh`, a no-op tombstone kept only so that feature file's scenario link resolved. The conformance script keeps its Validate substrate probe. - **That probe was blind to in-process calls:** a Git call from the Validate helper reached the real binary unnoticed. It now intercepts them; shown by mutation. - **Skill Builder:** `heal.sh --check` exits 2 when `ao` cannot run instead of reporting a pass. A new test fails without the fix. - **Codex policy check:** rejects the `agents/openai.yaml` shapes Codex silently drops (non-object `interface`, `dependencies` without a `tools` list, a boolean spelled other than `true`/`false`). Any of them made an explicit-only skill implicitly selectable. - **Converter:** the Codex target no longer writes `prompt.md`. Checks at `2ae5bbb45`: `ao gate check --full` 66 of 66, bats 1,388 pass, `tests/skills/run-all.sh` pass, `regen-all.sh --check` current, doc release gate pass, Skill Builder integration tests 9 of 9. ## Checks `ao gate check --full` 66 of 66, bats 1,388 pass, `tests/skills/run-all.sh` pass, `regen-all.sh --check` current, doc release gate pass. No review round, per the rule this PR introduces: it changes instructions, not a release or a security boundary, and CI covers the rest.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes
The repo shipped a generated second copy of every skill under
skills-codex/for the Codex plugin. This deletes the copy and everything that existed only to generate or police it. The Codex plugin now readsskills/directly..codex-plugin/plugin.jsonpointsskillsat./skills.skills-codex/andskills-codex-overrides/are gone.regen-all.shno longer generates a second skill tree.scripts/(the generator, hash and parity tooling,scripts/lint/), 5 bats files, 10 other test scripts, 4 gate-registry entries (skill.codex-parity-drift,-runtime-sections,-override-coverage,-generated-artifacts), about 770 lines of non-test Go and the doctor failure modefm-skills-stale-codex-sync.Why it is safe
On
origin/mainthe copy was the source: the supporting files were byte-identical, all 28 names and descriptions matched, the 18 bodies that differed did so by one leading blank line, and all 28 catalog rows were generated. Linked installs andnpx skillsalready gave Codexskills/directly.What a Codex user gets now
skills/with 0 load errors in Codex 0.156.1, as a plugin install and as a linked install (checked throughcodex app-serverskills/listunder a temp home, no model session).craft-goal,interview,postmortem,rpi) stay hidden from implicit selection. Each carriesagents/openai.yaml; the one forinterviewused to be derived by the generator and is now a source file. A check fails when that file is missing, invalid YAML or lacks the policy.nameanddescription.prompt.mdis no longer shipped; Codex does not read it.Changes beyond a straight deletion
skills/_fixtures/moved totests/fixtures/skill-eval/. Codex walks the whole skill tree and was loading the fixture skills; the copy had hidden that.aousesskills/plusregistry.jsonandPRODUCT.mdinstead of theskills-codex/sibling.evals/skills-rpi/tasks/builder-recoverywas ported off the deleted projection.Evidence
1e846180e:go build,go vet,go test ./...(65 packages),check-go-lint.sh,ao gate check --full(66 pass), bats (1,388 pass, 2 skipped),regen-all.sh --check,validate-doc-release.shandci-local-release.sh --quickall pass. The second commit changes one paragraph of a contract doc.1e846180e: every deleted check had the copy as its only live subject, and the out-of-scope changes above were necessary and correct. Its one defect, an overclaim indocs/contracts/codex-skill-api.md, is fixed in the second commit.Not checked
evals/agentops-core/*.jsonsuite files still name the copy; nothing runs them.Gate-Loosen-Reason: the generated Codex skill copy is deleted, so check-codex-parity-drift.sh and the four skill.codex-* registry entries that policed only that copy have no subject; every gate over skills/ is kept
Test-Removal-Reason: the removed Go tests covered Codex-copy parity, manifest-hash and plugin-cache sync code paths that are deleted with the copy