Skip to content

feat: agent skill package, harness installer, and HD logo render - #1

Merged
Alot1z merged 2 commits into
mainfrom
feat/agent-skill-package
Sep 6, 2026
Merged

Alot1z merged 2 commits into
mainfrom
feat/agent-skill-package

Conversation

@Alot1z

@Alot1z Alot1z commented Sep 5, 2026

Copy link
Copy Markdown
Owner

Summary

Package toolscan for the agent ecosystem: a harness-agnostic agent skill, an installer that deploys it to every agent harness found on the machine, and a 2048px render of the radar mark for HD use.

What this ships

  • skills/toolscan/ — the skill package: SKILL.md (the real CLI surface and the fail-closed exit-code contract: exit 2 = truncated scan = no verdict, never "not found"), references/composition.md (how agents compose with it), and examples/agent-preflight.sh (a runnable preflight recipe). Machine-generic by construction — no personal paths, no machine-specific config.
  • scripts/install-skill.sh — installer with the same UX discipline as the Ix project's installer: --dry-run (previews, writes nothing), --json (machine-readable per-host report), [id] labels, unknown-id/unknown-option refusal with --help, and a refusal guard that never silently overwrites a foreign same-name skill without --force. Dry-run and real mode agree on exit codes (preview ≡ real parity).
  • assets/logo-2048.png — HD render of the radar mark.

Tests

tests/skill-package.test.ts (new) pins the contracts doctor-style with hermetic HOME fixtures — the suite never touches real harness directories:

  • skill package: parseable frontmatter, machine-generic (a walk asserts zero personal absolute paths), no secrets;
  • installer: --help lists all four harness ids; unknown id exits 1 listing them; dry-run writes nothing (byte-level directory comparison); refusal guard exits 1 in BOTH modes and leaves the foreign skill byte-identical; --force overwrites; real install lands in each present harness (cursor's skills-cursor convention pinned); re-install over its own output needs no --force; --json report is a single parseable document with honest per-host records (skip = dest: null).

Full suite: 68 passed / 3 skipped (71). Harness presence is tested through config-dir fixtures, never through command -v, so the suite is hermetic on any machine.

Validation

  • npm test — 5 files, 68 passed / 3 skipped.
  • Installer exercised in both modes against hermetic HOMEs on Windows (Git Bash), including the refusal and --force paths.
  • Skill package walked for personal paths and token material — zero hits.

Notes

  • The four harness conventions (claude, agents, codex, cursor — including cursor's skills-cursor path) mirror the Ix repo's verified harness registry; kept deliberately minimal until more harnesses are verified.
  • The JSON report's env key is TOOLSCAN_DRY_RUN (namespaced, not borrowed).

Packaging toolscan for the agent ecosystem: a harness-agnostic skill (SKILL.md + composition reference + preflight example) teaching the real CLI surface and the fail-closed exit-code contract; an installer that deploys it to the four verified harness conventions with the same UX discipline as the Ix installer (dry-run, --json report, [id] labels, refusal guard, --help, preview/real exit parity); and a 2048px render of the radar mark for HD use.
@Alot1z
Alot1z marked this pull request as ready for review September 6, 2026 00:14
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@Alot1z
Alot1z merged commit 86b0da0 into main Sep 6, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant