Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
86 commits
Select commit Hold shift + click to select a range
b42d4fa
fix(bin): report a Lavish source armed only after its listener is run…
tiago-peixoto Sep 24, 2026
52e679b
fix(bin): stop repeating unknown-wake escalations that were already d…
tiago-peixoto Sep 25, 2026
c6e816f
fix(bin): keep a stated default-key retraction from cancelling a keyl…
tiago-peixoto Sep 25, 2026
a8572f6
fix(bin): terminate a remote job worker that lost ownership on TERM (…
tiago-peixoto Sep 25, 2026
4be8a40
docs: make configuration settings easier to find and understand (#5589)
tmchow Sep 25, 2026
b52d401
fix: limit project memory edits to factual corrections (#5636)
kunchenguid Sep 25, 2026
ca8c293
feat: permit gate lifecycle calls against disposable lab homes (#5635)
kunchenguid Sep 25, 2026
b575497
fix(bin): evict a watcher whose beacon stalls past a hard bound inste…
karotkriss Sep 25, 2026
5cec4e2
fix(pi): hide queued Firstmate inputs under Calm only when the sessio…
tiago-peixoto Sep 25, 2026
756f64e
fix(bin): refuse teardown when a required source disappears (#5548)
tiago-peixoto Sep 25, 2026
4e99de7
docs: make supervision-host easier to read (#5605)
tmchow Sep 25, 2026
660fa4a
docs: make the Herdr backend guide easier to read (#5606)
tmchow Sep 25, 2026
5323582
docs: make pi-supervision-branch easier to read (#5607)
tmchow Sep 25, 2026
d18a220
docs: make watcher-continuity easier to read (#5608)
tmchow Sep 25, 2026
70e41a8
docs: make sessionstart-nudge easier to read (#5609)
tmchow Sep 25, 2026
7c501a1
docs: make captain-hold-lifecycle easier to read (#5610)
tmchow Sep 25, 2026
c60f0ab
docs: make remote-secondmates easier to read (#5612)
tmchow Sep 25, 2026
683b3eb
fix(bin): bound the away digest and log why a delivery failed (#5554)
Sophylax Sep 25, 2026
dbe124d
test: add a gated harness seam and stabilize lifecycle fixtures (#5638)
kunchenguid Sep 25, 2026
1a814e4
fix(bin): refuse watchers from disposable checkouts and exit when the…
karotkriss Sep 25, 2026
84362f6
fix(bin): surface unrecognized status prefixes instead of reading the…
tiago-peixoto Sep 25, 2026
e97390a
fix(bin): report the failing item when remote inheritance fails (#5658)
karotkriss Sep 25, 2026
c643b57
fix(bin): stand down the Claude Stop auto-arm on pi-code-delivered pa…
karotkriss Sep 25, 2026
d1abcd6
fix(bin): match whole multi-word project names in the registry lookup…
karotkriss Sep 25, 2026
b805823
fix(bin): classify shell stdin payloads after -s operands (#5546)
coreldh Sep 25, 2026
83a4bbd
fix(bin): strip AI co-author trailers from fleet-launched commits (#5…
tiago-peixoto Sep 25, 2026
67f6c27
fix(bin): treat Pi's dollar-first cost footer as furniture (#5683)
tiago-peixoto Sep 25, 2026
8d2ee29
fix(bin): refuse merges with unreported required checks (#5534)
mremond Sep 25, 2026
0154324
fix: keep persistent secondmates out of landed-work cleanup (#5696)
kunchenguid Sep 25, 2026
f54aa00
fix: reject invalid X reply and follow-up arguments before posting (#…
kunchenguid Sep 25, 2026
3c14a54
fix: pause broken supervision-host sessions between engine probes (#5…
kunchenguid Sep 25, 2026
97365aa
fix(bin): absorb routine secondmate working and paused status appends…
karotkriss Sep 25, 2026
c4c9d63
fix(bin): use gh-axi for the ship DoD draft check (#5519)
karotkriss Sep 25, 2026
f1ea9ed
fix(bin): bind inactive-outcome receipt identity to structured fields…
karotkriss Sep 25, 2026
4299683
feat: record the Claude and Cursor dialog for the supervision host (#…
kunchenguid Sep 25, 2026
c33b3f6
fix(bin): retire check-row receipts on branch acknowledgement so away…
kunchenguid Sep 26, 2026
1fe1a67
fix(bin): deliver Claude-bound operational input as a record-backed d…
kunchenguid Sep 26, 2026
ef595d8
test: isolate lint fixture from tracked suite (#5727)
kunchenguid Sep 26, 2026
e789e52
fix(bin): republish parent metadata after a remote secondmate relaunc…
tiago-peixoto Sep 26, 2026
9a4cfbb
fix(bin): give slow watcher suites headroom under the changed-suite b…
karotkriss Sep 26, 2026
df4ae5d
fix(bin): stop nested steal-lock recursion and mid-steal watcher TERM…
kunchenguid Sep 26, 2026
873c923
test: make supervision-host park-boundary tests deterministic (#5710)
kunchenguid Sep 26, 2026
ea7c7f7
fix: stage remote home clones before publication (#5733)
kunchenguid Sep 26, 2026
920a7d9
fix: preserve Herdr status on Pi relaunch (#5161)
sdivanl Sep 26, 2026
65c53fb
Seed the relaunch-ordering PR poll fixture without fm-pr-check.sh (#5…
kunchenguid Sep 26, 2026
9b52cf5
feat: add attended supervision for Claude and Cursor hosts (#5748)
kunchenguid Sep 26, 2026
72b63ee
fix(bin): dedup directed source expansions in fm-pending-reply-lib (#…
kunchenguid Sep 26, 2026
d1a332c
fix(bin): avoid bash 5.2 sibling $() in recovery mint and delivery lo…
Lakescape Sep 26, 2026
3948170
fix(bin): name the recovery for a declined Claude imports dialog and …
karotkriss Sep 26, 2026
062d7a8
fix(bin): report the newest status event in the voice status reader (…
karotkriss Sep 26, 2026
e9a6675
fix(bin): gate a self-announcing tool's update-available report on a …
karotkriss Sep 26, 2026
cf20836
fix(bin): pass the dispatch profile effort to OpenCode workers throug…
karotkriss Sep 26, 2026
9d56cf6
fix: stop cancelled validation runs from reporting false failures (#5…
mremond Sep 26, 2026
bb69be6
fix: require declared waits for workers awaiting their own work (#5812)
mremond Sep 26, 2026
503ba82
fix: bound ShellCheck to one canonical root per process (#5770)
kunchenguid Sep 26, 2026
5700baa
fix: bound watcher cleanup wait on the downtime-marker lock (#5732)
kunchenguid Sep 26, 2026
62d643c
test: stop the remote secondmate e2e watcher before temp-root cleanup…
aminry Sep 26, 2026
30ef650
fix(bin): stop reporting untouched shared-captain copies as drift (#4…
tiago-peixoto Sep 26, 2026
f62a7d9
docs: restructure calm.md for readability (#5604)
tmchow Sep 27, 2026
3b68997
docs: restructure turnend-guard.md for readability (#5611)
tmchow Sep 27, 2026
49a218b
docs: move situational AGENTS.md sections into on-demand skills (#5872)
kunchenguid Sep 27, 2026
5a9880b
fix: route second-mate signal wakes by presented status span (#5879)
kunchenguid Sep 27, 2026
fd88ea0
fix(bin): take the source lock before the lifecycle lock in register-…
FocalFactotum Sep 27, 2026
b4561ad
fix: chain repository hooks under git -c overrides (#5877)
FocalFactotum Sep 27, 2026
fba81cb
fix(bin): withhold never-send values from dispatch resolver requests …
zachlandes Sep 27, 2026
6839202
feat(jev): add the guard framework contract and the memory RSS/swap t…
RooseveltAdvisors Sep 27, 2026
d051e6f
fix: prevent contribution poll starvation on slow GitHub reads (#5900)
0x7067 Sep 27, 2026
bff6454
feat(bin): add config/keep-ai-trailers opt-out to keep AI co-author t…
kiatng Sep 27, 2026
050a446
fix(bin): capture the full viewport for Herdr composer reads so a sla…
andrewesweet Sep 27, 2026
8a18fe2
fix(bin): isolate per-task endpoint reads in bounded children with a …
andrewesweet Sep 27, 2026
f93f0d3
fix: keep lab tmux sockets private and short under deep worktrees (#5…
kunchenguid Sep 27, 2026
ade7133
fix: silence routine no-change supervision outcomes (#5808)
jcpoyser Sep 27, 2026
8c5493a
feat: make /quiet a statement when attended supervision is ready (#5928)
kunchenguid Sep 27, 2026
c19c240
fix: grant Claude workers access to Firstmate task channels (#5884)
kunchenguid Sep 27, 2026
90e88d7
fix(bin): prevent idle recovery loops without stranding wakes (#4819)
jokim1 Sep 27, 2026
3d14792
fix: reduce remote worker and polling helper process churn (#5889)
kunchenguid Sep 27, 2026
022250d
fix: keep remote reply listeners and watcher cycles running (#5941)
kunchenguid Sep 27, 2026
3c2a91d
fix: make attended cutover outcome re-presentation check-first (#5925)
kunchenguid Sep 28, 2026
1b82b77
fix: restore primary rewakes after attended main-only closes (#5961)
kunchenguid Sep 28, 2026
df2e83a
Merge upstream Firstmate through 1b82b77a
ashkonmousavi Sep 28, 2026
838a897
Merge fork main Codex supervision repair
ashkonmousavi Sep 28, 2026
7cb6127
no-mistakes(review): Restore Codex quiet-mode refusal in quiet-check,…
ashkonmousavi Sep 28, 2026
b4c245d
no-mistakes(review): Restore fork AGENTS.md wording verbatim in moved…
ashkonmousavi Sep 28, 2026
4a3542e
no-mistakes(test): Widen Stop-hook retry wait to named timeout budgets
ashkonmousavi Sep 28, 2026
3fd790e
no-mistakes(document): Point landing refs to ship-landing; note Codex…
ashkonmousavi Sep 28, 2026
1046735
no-mistakes(ci): Fixed the Lint 1 failure by deleting 4 lines from bi…
ashkonmousavi Sep 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .agents/skills/afk/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ Hold-for-return is the default and the only reach profile this release records:
- **Claude, Cursor, OpenCode, omp, or Grok with `config/supervision-host`**: nothing to launch for `/afk`; go on to the announcement.
The supervision host (`docs/supervision-host.md`) is the away session there: it runs the branch's contract on a headless engine under the record while main is parked, and `bin/fm-afk-launch.sh start` and `start-native` refuse the away daemon on that home.
If `enter` printed a `Supervision host: no engine ...` line, every away wake reaches this conversation instead; say so in the announcement.
`/quiet` is unchanged there and still launches the daemon below.
`/quiet` enters nothing there where the attended host runs, and otherwise still launches the daemon below (the quiet skill's `quiet-check` decides).
- **Harness WITH a native in-pane tracked-background tool** (claude's and grok's, without the supervision host): run `bin/fm-afk-launch.sh start-native`, then run `FM_AFK_STATE_PREPARED=1 bin/fm-afk-start.sh` through that native tool.
This is a deliberate no-separate-terminal exception because the harness-hosted job creates no terminal or layout mutation, and a shell launcher cannot invoke a harness-native background tool.
If the native launch fails, run `bin/fm-afk-launch.sh stop` to roll back the prepared lifecycle.
Expand Down Expand Up @@ -83,7 +83,7 @@ No `/back` is needed. The first genuine message is the return signal:
Once the record is archived, resume full per-wake responsiveness through the emitted primary-harness supervision protocol while blocker handling proceeds, so the gate never creates a blind wait.
A Bearings request may be answered while the gate is open, and the digest surfaces the catch-up state as a Charted Next `(return-catchup)` warning row naming what still holds it.
Acting on the fleet - dispatching, steering, merging, or any other ordinary captain work - still waits until the check exits successfully.
Once it does, verify each task the brief lists under "Landed, cleanup due" the way `AGENTS.md` section 7 requires (the default-branch CI run the merge triggered when the project runs one, and the deploy or release workflow and the live version when the project has a deploy target), then close each verified task through ordinary teardown (`bin/fm-teardown.sh <task>`, never forced; a refusal is a stop-and-investigate result) and tell the captain those workers are closed, with the verification result, in outcome language.
Once it does, verify each task the brief lists under "Landed, cleanup due" the way `ship-landing` requires (the default-branch CI run the merge triggered when the project runs one, and the deploy or release workflow and the live version when the project has a deploy target), then close each verified task through ordinary teardown (`bin/fm-teardown.sh <task>`, never forced; a refusal is a stop-and-investigate result) and tell the captain those workers are closed, with the verification result, in outcome language.
A task whose verification is still running keeps its worker up until it passes, and a failed verification is reported to the captain instead of torn down.
- A message **with** the current operational prefix (`FM_OPERATIONAL_PREFIX`, U+2063 INVISIBLE SEPARATOR followed by `FIRSTMATE_OP: `), or a legacy bare `FM_INJECT_MARK` daemon escalation -> stay away and process it.
- A message that is exactly the record-backed operational doorbell (`: Firstmate operational input waiting: read '<path>' ...`) -> run `bin/fm-operational-input.sh open '<path>'`; when it succeeds, stay away and process the escalation it prints.
Expand Down
31 changes: 31 additions & 0 deletions .agents/skills/agent-skill-trigger-index/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
---
name: agent-skill-trigger-index
description: Load only when auditing or maintaining the complete agent-only skill trigger index.
user-invocable: false
metadata:
internal: true
---

# Agent-only reference skills

These skills are not captain-invocable; load them only at their precise triggers.

- `bootstrap-diagnostics` - load whenever the session-start digest's bootstrap or network-checks section prints an actionable diagnostic line (`MISSING:`, `MISSING_MANUAL:`, `PRESENTATION_UNAVAILABLE:`, `BACKEND_INVALID:`, `NEEDS_GH_AUTH`, `TANGLE:`, `STARTUP_MEMORY_BUDGET:`, `CREW_DISPATCH: invalid`, `FLEET_SYNC:`, `NETWORK_CHECKS:`, `HOME_SUMMARY:`, `BACKLOG_RECONCILE:`, `SECONDMATE_SYNC:`, `SECONDMATE_LIVENESS:`, `SECONDMATE_HANDOFF:`, `NUDGE_SECONDMATES:`, or `FMX:`), or when `BOOTSTRAP_INFO:` says an interrupted backlog cleanup may have left an endpoint or local copy; silence and other `BOOTSTRAP_INFO:` facts need no load.
- `diagnostic-reasoning` - load before scoping a reported bug and before acting on a diagnostic report.
- `research-first-decisions` - load before selecting a tool, library, framework, service, vendor, or approach from candidates, and before recording such a selection as decided; also load before adopting, configuring, upgrading, or integrating a library, SDK, API, CLI, framework, or service, or before debugging version-sensitive usage, where its Context7 version check is mandatory whether or not a candidate is being chosen.
- `wayfinding` - load before scoping work larger than one task, such as a stage, a release, a migration, or a campaign of related changes; before dispatching a task whose backlog dependency names a stage, a release, or a final acceptance; when work is blocked only at its final step or the queue looks fully gated; and whenever the ready frontier lists only umbrellas or nothing while holds still exist.
- `ask-user-authority` - load before deciding any ask-user finding.
- `quota-array-dispatch` - load before resolving an explicitly `quota-balanced` crew-dispatch rule.
- `harness-adapters` - load before spawning or recovering a crewmate or secondmate, handling a trust dialog, sending a harness-specific skill invocation, interrupting or exiting an agent, resuming an exited agent, or verifying a new harness adapter.
- `firstmate-orca` - load before switching to Orca, spawning or supervising Orca-backed work, smoke-testing Orca backend behavior, debugging Orca task state, or reconciling Orca-backed task metadata.
- `project-management` - load before adding, creating, removing, or initializing a project.
Cloning or registering a project is add intake and uses the same trigger.
- `stuck-crewmate-recovery` - load when the session-start digest reports an ordinary direct report's endpoint dead or its metadata has no window, after a stale wake, looping pane, repeated confusion, an answered-by-brief question, an unresponsive crewmate, or a failed steer, and whenever a live worker reports its no-mistakes pipeline dead, unreachable, or timed out.
- `secondmate-provisioning` - load before creating, seeding, validating, launching, handing backlog to, recovering, pushing inherited local material into, or retiring a secondmate home, and before editing `data/secondmates.md`.
- `captain-hold-lifecycle` - load before treating an investigation or visual review as complete, before ending a visual review that exposed a captain decision, when recording or routing the captain's answer, and on any `RECORD DIVERGENCE` line from the wake drain.
- `process-event-sources` - load before arming a long-polling source, before registering a deterministic condition->action watch (do X as soon as Y is true), on any `procevent <adapter> <source-id> <sequence>` check wake, and on any `process-event source stranded` or `process-event source failed to start` check wake.
Never run a registered source's blocking command yourself in a conversational turn.
- `fmx-respond` - load on an `x-mention <request_id>` `check:` wake to handle the mention, on an `x-mode-error ...` `check:` wake to report the Relay configuration blocker, on a `public-followup ...` `check:` wake or a startup-surfaced public commitment, and on any milestone or terminal wake for a Relay-linked task before posting its completion follow-up; relevant only when Relay is on.
- `firstmate-codexapp` - load before coordinating a visible Codex Desktop thread, evaluating a Codex App backend request, or reconciling Codex Desktop host-tool smoke evidence for Firstmate work.
- `firstmate-coding-guidelines` - load before changing firstmate's shared, tracked material, as defined by section 1's list, whether editing directly or briefing a crewmate for a firstmate-repo task.
- `journey-walk` - load before commissioning, scheduling, or supervising a live end-to-end journey walk, and when a walk blocker's fix is installed.
22 changes: 22 additions & 0 deletions .agents/skills/away-quiet-supervision/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
---
name: away-quiet-supervision
description: Load whenever /afk or /quiet is invoked, an away or quiet record exists, or a marked away-supervisor message arrives.
user-invocable: false
metadata:
internal: true
---

# Away and quiet supervision safety

The `/afk` and `/quiet` skills each own their daemon procedure, which is otherwise identical; these safety facts apply to both:

- Every current daemon injection uses the `away-supervisor` kind from `bin/fm-operational-input.sh` after `FM_OPERATIONAL_PREFIX` (U+2063 INVISIBLE SEPARATOR followed by `FIRSTMATE_OP: `), except that a Claude Code primary, which strips U+2063, receives that owner's record-backed doorbell and it counts as marked only when `bin/fm-operational-input.sh open <path>` verifies its record; the `/afk` skill owns legacy bare-marker compatibility.
- `state/.afk-contract` is the away posture, written in the same turn as `/afk` before any other work, because `/afk` is itself the go: no read-back gates entry or waits for a go; entry announces hold-for-return only, and the away session acts on those words by its own judgment through the guarded scripts under standing authority, holding for the return on doubt.
- While `state/.afk` exists, the daemon owns supervision; do not arm a separate watcher.
The daemon is never launched on Pi or Codex, where the ordinary supervision session continues under the record: Codex inside its foreground checkpoint loop, and Pi with main parked, where the branch takes every safe actionable wake it can and only a declined wake (including a broken branch or unsafe scan) or a watcher failure wakes main.
Away mode on a non-Pi home with `config/supervision-host` works the same way with the supervision host as the branch; a wake it hands back arrives through that harness's own wake path and is never the captain's return.
- A marked message while away or quiet mode is active is internal escalation and does not exit that mode.
- A message beginning `/afk` refreshes away mode; a message beginning `/quiet` refreshes quiet mode.
- Any other unmarked message means the captain returned in away mode (load `/afk`, run the return owner, and do not process that message as ordinary work until its durable catch-up gate clears), or, in quiet mode, is simply answered as ordinary work with the flag and daemon left untouched until an explicit `/quiet off`.
- Away and quiet mode never expand approval authority for merges, ask-user findings, destructive actions, irreversible actions, or security-sensitive choices.
- Bias ambiguous input toward exit because a present captain takes precedence.
2 changes: 1 addition & 1 deletion .agents/skills/bootstrap-diagnostics/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ metadata:

Handle each printed line as below, before dispatching work that depends on it.
The line formats themselves are owned by `bin/fm-bootstrap.sh`'s header; this playbook owns the response to actionable lines.
The inline rules in `AGENTS.md` section 3 still bind: detect, then consent, then install - never install anything the captain has not approved in this session - and no work is dispatched until the tools it needs are present and GitHub auth is good.
The session-start rules in `session-start-recovery` still bind: detect, then consent, then install - never install anything the captain has not approved in this session - and no work is dispatched until the tools it needs are present and GitHub auth is good.
When any diagnostic needs captain attention, report the plain consequence and requested action using `AGENTS.md` section 9's captain-facing translation contract; do not name the diagnostic label unless the captain needs to paste it into a command or issue.

- `MISSING: <tool> (install: <command>)` - list the missing tools to the captain with a one-line purpose each plus the printed install commands, wait for consent (one approval may cover the list), then run `bin/fm-bootstrap.sh install <approved tools...>`.
Expand Down
2 changes: 1 addition & 1 deletion .agents/skills/captain-hold-lifecycle/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ Only `answer` with the captain's words or an evidence-backed `reconcile close` m
Never close anything the captain owns without recording what he actually said: `bin/fm-captain-hold.sh answer` writes his exact words into the task and closes a question-shaped call, while `--release` frees a captain-gated work item to proceed.
A merge approval uses that existing release path because approval permits the merge to proceed; cleanup closes the work only after it lands and records what shipped.
Closing a held row at merge approval instead records completion before landing, so the backlog claims completion before the work actually ships.
When the answer changes what a task must build, follow `AGENTS.md` section 7's Validate contract to preserve the captain's words in the brief and steer the worker.
When the answer changes what a task must build, follow `AGENTS.md` section 7's mid-task ask rule to preserve the captain's words in the brief and steer the worker.
When the captain says "later", that is an answer too: re-hold with `bin/fm-captain-hold.sh hold <id> --reason "<reason>" --until <date>` so the item leaves the live Captain's Call and resurfaces on its date, instead of leaving a live-looking card or fabricating a closure; a bound board's dated `later` choice arrives already re-held this way through the keyed-answer intake.
"A keyed answer resolves its matching captain-held task" is one capability with one owner, `bin/fm-captain-hold.sh answers`, and every channel that carries a captain answer feeds it the same task id and answer; a channel never maps keys to tasks, records a decision, or resolves anything itself.
Chat already feeds it through `bin/fm-send.sh --resolve-key`, and a captured-answer source feeds it once bound with `bin/fm-captain-hold.sh bind <source-id>`; bind before arming the source, and key each structured question by the held task's id.
Expand Down
2 changes: 1 addition & 1 deletion .agents/skills/firstmate-codexapp/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,7 @@ For a Firstmate-managed task, include an explicit status instruction:
```text
Append supervisor-visible status lines to <absolute-firstmate-home>/state/<task-id>.status.
Use only these prefixes for status changes: working:, needs-decision:, blocked:, paused:, done:, failed:.
Use paused: only for a deliberate known external wait that should be rechecked later, never for a blocker that needs firstmate to act.
Follow the task brief's status-reporting rule for declaring and resolving waits; bin/fm-brief.sh owns that rule.
Before doing substantive work, append "working: Codex Desktop thread started".
```

Expand Down
7 changes: 4 additions & 3 deletions .agents/skills/firstmate-coding-guidelines/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ Before writing a new fact anywhere in this repo, ask where it belongs, in this o
1. Does the firstmate AGENT need this on every session or every turn to operate?
If yes: `AGENTS.md`, inline.
2. Does the agent need it only in a nameable situation - a spawn, a recovery, a specific wake type, a specific lifecycle step?
If yes: an agent-only skill under `.agents/skills/`, plus a one-line trigger pointer left inline in `AGENTS.md` (usually section 13).
If yes: an agent-only skill under `.agents/skills/`, whose description states its load trigger; leave a one-line inline pointer in `AGENTS.md` only when an always-loaded rule must name the skill.
3. Is it public product, setup, or user/operator reference?
If yes: the surface classified for that audience in [`docs/documentation-audiences.md`](../../../docs/documentation-audiences.md), limited to current behavior, setup, supported limits, stable invariants, concise rationale, and current verification entry points.
4. Is it contributor/maintainer architecture?
Expand Down Expand Up @@ -53,7 +53,7 @@ That is the trigger condition for loading the skill, plus any safety-critical fa
Everything else - the procedure, the mechanism, the surrounding detail - moves out completely.
Do not leave a partial restatement behind "just in case".
A partial copy is exactly the duplication the one-owner rule forbids.
The model to copy is `AGENTS.md` section 8's "Away-mode and quiet-mode stub": it keeps only the marker format, the ownership-transfer rule, and the exit condition inline, and points everything else at the `/afk` and `/quiet` skills.
The model to copy is `AGENTS.md` section 8's "Away-mode and quiet-mode stub": it keeps only the skill-invocation triggers inline and points everything else at the `/afk`, `/quiet`, and `away-quiet-supervision` skills.

## Size discipline

Expand All @@ -66,7 +66,7 @@ When in doubt, write the fact into the skill or doc first by patching that owner
## Trigger hygiene

A new skill is dead weight if nothing loads it.
Every new skill needs its load trigger declared inline: section 13 for agent-only reference skills, or the relevant operating section for anything else.
Every new skill needs its load trigger declared in its description, which is the always-loaded trigger index; add an inline `AGENTS.md` pointer only in the operating section whose always-loaded rule must name it.
State the trigger as a condition ("load before X", "load on Y wake"), never as a vague pointer.
Briefs for tasks that touch firstmate's own tracked material should tell the crewmate to load this skill.
`bin/fm-brief.sh`'s `REPO` argument is a caller-supplied string with no reliable signal that it names firstmate's own repo, unlike a project registered in `data/projects.md`, so there is no clean point inside the scaffold to detect this case automatically.
Expand Down Expand Up @@ -125,6 +125,7 @@ Firstmate PR #3644 demonstrated the cost: pinning a 75-162-script walk took 32.7
- Plain dash `-`, never an em dash.
- Never add an agent name as a commit co-author.
- `bin/*.sh` and `bin/backends/*.sh` must pass `shellcheck`.
- Run Firstmate production-library tests and commands that source `bin/` scripts under `bash` explicitly, never through the tool shell's default interpreter.
- Run `bin/fm-lint.sh` before treating a script change as done; it is the single owner of the lint definition that CI and the no-mistakes pre-push gate both invoke, its own header owns what that definition covers, and it refuses to run under any other version of either linter.
- When a task names a specific tool, implement the work with that tool, or explicitly flag the substitution and its new dependency footprint for review before shipping.
- Colocate tests with the existing pattern in `tests/`, name them `<subject>.test.sh`, and extend an existing script rather than inventing a new runner.
Expand Down
Loading
Loading