Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 7 additions & 1 deletion .agents/skills/project-management/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ name: project-management
description: >-
Agent-only procedure for Firstmate project management.
Use before adding, creating, removing, or initializing a project.
Owns project add, create, clone, remove, initialization, registry, delivery-mode, autonomy, and outward-consent decisions.
Owns project add, create, clone, remove, initialization, registry, delivery-mode, autonomy, outward-consent decisions, and the secrets-intake handoff.
user-invocable: false
metadata:
internal: true
Expand Down Expand Up @@ -68,6 +68,12 @@ Initialization configures the local gate and does not vendor a no-mistakes skill
Do not create a commit merely because initialization ran.
If doctor reports an environment, authentication, or daemon problem, resolve that blocker before dispatching work and never restart the shared daemon from a project operation.

Load `secrets-management` during every project intake or initialization.
From the Firstmate root, run `bin/fm-secrets-check.sh inventory projects/<name>` after the gate check.
The inventory is read-only and value-safe, and it is not a substitute for the declared project classification.
If the project lacks `docs/secrets-policy.json`, assign its first ship task to copy and complete `docs/examples/project-secrets-policy.json` before any secret-bearing workflow or deployment change.
Firstmate never hand-writes that project file.

## Remove

Project removal is destructive and is not one of Firstmate's current direct-write exceptions under `projects/`.
Expand Down
237 changes: 237 additions & 0 deletions .agents/skills/secrets-management/SKILL.md

Large diffs are not rendered by default.

2 changes: 2 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,8 @@ jobs:
# Single owner of the lint definition (file set + config + version). Do not
# re-spell the shellcheck command here; keep CI and the pre-push gate on it.
- run: bin/fm-lint.sh
- name: Validate tracked secrets standard
run: bin/fm-secrets-check.sh

# Deterministic proof that portable parallel shards + portable serial + Herdr
# equal the complete tests/*.test.sh inventory with no missing or duplicates.
Expand Down
1 change: 1 addition & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -469,6 +469,7 @@ These skills are not captain-invocable; load them only at their precise triggers
- `harness-adapters` - load before spawning or recovering a crewmate or secondmate, handling a trust dialog, sending a harness-specific skill invocation, interrupting or exiting an agent, resuming an exited agent, or verifying a new harness adapter.
- `firstmate-orca` - load before switching to Orca, spawning or supervising Orca-backed work, smoke-testing Orca backend behavior, debugging Orca task state, or reconciling Orca-backed task metadata.
- `project-management` - load before adding, creating, removing, or initializing a project.
- `secrets-management` - load before project intake or initialization and before work that handles credentials or adds secret access to CI or deployment.
- `stuck-crewmate-recovery` - load when the session-start digest reports an ordinary direct report's endpoint dead or its metadata has no window, or after a stale wake, looping pane, repeated confusion, an answered-by-brief question, an unresponsive crewmate, or a failed steer.
- `secondmate-provisioning` - load before creating, seeding, validating, launching, handing backlog to, recovering, pushing inherited local material into, or retiring a secondmate home, and before editing `data/secondmates.md`.
- `decision-hold-lifecycle` - load before treating an investigation or visual review as complete, before ending a visual review that exposed a decision, and when recording or routing the captain's answer.
Expand Down
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,7 @@ Launching a supported harness inside it instantiates your first mate - and makes
- **Event-driven, zero-token supervision** - a bash watcher sleeps on the fleet and wakes the first mate only when something needs you; verified primary harnesses also get a turn-end backstop that blocks or follows up on a blind stop when work is under way and supervision is not live.
- **Optional X mode** - opt in with one local `.env` token so firstmate can answer your public `@myfirstmate` mentions, act on normal reversible mention requests through the same lifecycle as chat requests, acknowledge spawned work, and post up to three public-safe completion follow-ups within seven days for genuine milestones and the final outcome without changing non-X behavior; dry-run preview records would-be replies and dismissals locally before go-live.
- **Guarded by construction** - the first mate is read-only over your projects except for the guarded paths authorized by [hard rule 1](AGENTS.md#1-identity-and-prime-directives), with fleet sync's safe branch pruning remaining part of the fleet-sync exception; crewmates make every project change behind the configured merge authority.
- **Doppler by default** - the conditional [secrets-management policy](.agents/skills/secrets-management/SKILL.md) prefers secretless provider identity, otherwise scopes Doppler by project and environment, and validates declarations and rollout data through `bin/fm-secrets-check.sh`.
- **Restart-proof** - all state lives on disk and in the active session backend (tmux by hard default, herdr or cmux when selected or auto-detected, zellij/orca when explicitly selected); kill the session anytime and the next one reconciles, including confirmed-dead secondmate agents, and carries on.

Full detail on every feature lives in [docs/architecture.md](docs/architecture.md).
Expand Down
Loading