← NaClCONTENT HISTORY

Update to NaCl

Snapshot Sep 30, 2026 · 23:13 UTC · version 0.2.2

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "description": "Inspect or initialize a NaCl project with a per-project Neo4j Community graph and project-local MCP. Use for first setup, bootstrap, and repair planning.",
  "included_files": [
    {
      "relative_path": "graph/migrations/001-gateway-foundation.json",
      "size_in_bytes": 510
    },
    {
      "relative_path": "graph/migrations/002-concurrency-foundation.json",
      "size_in_bytes": 1057
    },
    {
      "relative_path": "graph/migrations/003-schema-resource-identity.json",
      "size_in_bytes": 372
    },
    {
      "relative_path": "resources/bootstrap/apply-project-creation.mjs",
      "size_in_bytes": 4224
    },
    {
      "relative_path": "resources/bootstrap/apply-project-schema.mjs",
      "size_in_bytes": 2660
    },
    {
      "relative_path": "resources/bootstrap/codex-config-contract.mjs",
      "size_in_bytes": 2664
    },
    {
      "relative_path": "resources/bootstrap/codex-config-guard.mjs",
      "size_in_bytes": 2618
    },
    {
      "relative_path": "resources/bootstrap/graph-docker-compose.yml",
      "size_in_bytes": 1402
    },
    {
      "relative_path": "resources/bootstrap/install-pinned-neo4j-mcp.mjs",
      "size_in_bytes": 7920
    },
    {
      "relative_path": "resources/bootstrap/neo4j-image-PROVENANCE.md",
      "size_in_bytes": 1448
    },
    {
      "relative_path": "resources/bootstrap/neo4j-mcp-release-PROVENANCE.md",
      "size_in_bytes": 885
    },
    {
      "relative_path": "resources/bootstrap/neo4j-mcp-release.pin",
      "size_in_bytes": 1431
    },
    {
      "relative_path": "resources/bootstrap/neo4j-mcp-supply.mjs",
      "size_in_bytes": 4292
    },
    {
      "relative_path": "resources/bootstrap/plan-project-creation.mjs",
      "size_in_bytes": 8352
    },
    {
      "relative_path": "resources/bootstrap/plan-project-graph.mjs",
      "size_in_bytes": 19639
    },
    {
      "relative_path": "resources/bootstrap/preflight-project-graph.mjs",
      "size_in_bytes": 8434
    },
    {
      "relative_path": "resources/bootstrap/project-neo4j-launcher.mjs",
      "size_in_bytes": 4572
    },
    {
      "relative_path": "resources/bootstrap/protected-env.ps1",
      "size_in_bytes": 4143
    },
    {
      "relative_path": "resources/bootstrap/rollback-project-bootstrap.mjs",
      "size_in_bytes": 2959
    },
    {
      "relative_path": "resources/bootstrap/setup-project-graph.ps1",
      "size_in_bytes": 16099
    },
    {
      "relative_path": "resources/bootstrap/setup-project-graph.sh",
      "size_in_bytes": 14352
    },
    {
      "relative_path": "resources/bootstrap/vendor/PROVENANCE.md",
      "size_in_bytes": 1176
    },
    {
      "relative_path": "resources/bootstrap/vendor/smol-toml-1.7.0.cjs",
      "size_in_bytes": 22404
    },
    {
      "relative_path": "resources/bootstrap/vendor/smol-toml-LICENSE.txt",
      "size_in_bytes": 1499
    },
    {
      "relative_path": "resources/bootstrap/write-codex-mcp-config.mjs",
      "size_in_bytes": 2646
    },
    {
      "relative_path": "resources/graph-infra/queries/ba-queries.cypher",
      "size_in_bytes": 11527
    },
    {
      "relative_path": "resources/graph-infra/queries/handoff-queries.cypher",
      "size_in_bytes": 5287
    },
    {
      "relative_path": "resources/graph-infra/queries/sa-queries.cypher",
      "size_in_bytes": 29139
    },
    {
      "relative_path": "resources/graph-infra/queries/tl-queries.cypher",
      "size_in_bytes": 7858
    },
    {
      "relative_path": "resources/graph-infra/queries/validation-queries.cypher",
      "size_in_bytes": 7777
    },
    {
      "relative_path": "resources/graph-infra/schema/ba-schema.cypher",
      "size_in_bytes": 7805
    },
    {
      "relative_path": "resources/graph-infra/schema/sa-schema.cypher",
      "size_in_bytes": 37327
    },
    {
      "relative_path": "resources/graph-infra/schema/seed-data.cypher",
      "size_in_bytes": 46072
    },
    {
      "relative_path": "resources/graph-infra/schema/tl-schema.cypher",
      "size_in_bytes": 4526
    },
    {
      "relative_path": "resources/references/skills-only-runtime-contract.md",
      "size_in_bytes": 7181
    },
    {
      "relative_path": "runtime/graph-gateway/catalog.mjs",
      "size_in_bytes": 3558
    },
    {
      "relative_path": "runtime/graph-gateway/errors.mjs",
      "size_in_bytes": 1266
    },
    {
      "relative_path": "runtime/graph-gateway/migrations.mjs",
      "size_in_bytes": 8151
    },
    {
      "relative_path": "runtime/graph-gateway/neo4j-http.mjs",
      "size_in_bytes": 5806
    }
  ],
  "name": "nacl-init",
  "skill_md_contents": "---\nname: nacl-init\ndescription: Inspect or initialize a NaCl project with a per-project Neo4j Community graph and project-local MCP. Use for first setup, bootstrap, and repair planning.\n---\n\n# NaCl Init\n\nRead [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md).\n\nThis entry must work before any project MCP exists. Never call an installation\ndoctor, a package gateway, or a checkout-relative/global skill path.\n\nResolve one explicit absolute project root. For an empty new project without\n`config.yaml`, invoke the bundle-relative\n[project-creation planner](resources/bootstrap/plan-project-creation.mjs)\nwith the root, project name, optional one-line description, and optional stack.\nIt performs no writes. Present its exact `config.yaml`, `AGENTS.md`, Git action,\n`planHash`, and `CREATE_NACL_PROJECT:<sha256>` confirmation, then stop.\n\nAfter the user repeats that exact confirmation, invoke the bundle-relative\n[project-creation applier](resources/bootstrap/apply-project-creation.mjs)\nwith the same inputs, `plan-hash`, and confirmation. It recomputes the plan\nunder a create lock before writing. For a genuinely empty non-Git directory it\ncreates `config.yaml` and concise repository-specific `AGENTS.md`, initializes\nGit and commits only those initial artifacts. It preserves an existing\n`AGENTS.md` and never auto-adopts a non-Git directory containing files or a\nlinked worktree. Stop on any non-success result.\n\n`AGENTS.md` records durable project context, constraints, and verified commands;\nkeep it concise and use a closer nested `AGENTS.md` for directory-specific\nrules. Never put credentials in it. For an existing `config.yaml` without a\nstable `project.id`, present the exact add-only config change and stop for\nconfirmation before writing it; never derive identity during a read.\n\nBefore bootstrap, invoke the bundle-relative\n[plan runner](resources/bootstrap/plan-project-graph.mjs) with the\nexplicit root, ID, database, and chosen loopback Bolt/HTTP ports. This command\nis read-only: it performs no Docker call, network request, or mutation. Show\nits exact plan fields, `planHash`, and fresh\n`INIT_LOCAL_GRAPH:<project-id>:<sha256>` token, then stop. Never accept the old\nstatic token or reconstruct a token manually.\n\nAfter the user repeats that exact token, invoke the bundled POSIX or PowerShell\nrunner, respectively the\n[POSIX runner](resources/bootstrap/setup-project-graph.sh) or\n[PowerShell runner](resources/bootstrap/setup-project-graph.ps1), with\nthe same root, ID, database, ports, and token. Never pass a password. The\nrunner recomputes the plan immediately before its first mutation; stale or\nmismatched state is `BLOCKED/PLAN_TOKEN_STALE` with zero mutation.\n\nTreat the exact token as an execution request, not as a reason to re-plan,\ndiagnose, or ask for another confirmation. Run the selected runner exactly\nonce, capture its complete stdout and stderr, and do not infer project state\nwhile it is running. The runner's terminal machine-readable line is the sole\nauthority for the outcome:\n\n- `NACL_SKILLS_ONLY_BOOTSTRAP: status=... code=...` is the successful\n  bootstrap receipt.\n- `NACL_GRAPH_RESULT: status=... code=...` is a blocked, failed, or\n  partially verified bootstrap receipt.\n\nReport those fields verbatim. Never claim `PARTIAL_BOOTSTRAP_STATE`, missing\nfiles, or an incomplete bootstrap from an LLM inference, a directory name, or\na prior message. If the runner reports `FAILED` with `rollback=VERIFIED`,\nreport that failure and rollback; the graph bootstrap is not partial and no\nrecovery plan is needed. A retry requires a newly generated plan and fresh\nuser confirmation. Only if the runner reports `PARTIALLY_VERIFIED` with\n`rollback=INCOMPLETE`, invoke `plan-project-graph.mjs --diagnose-only` once,\nthen report the returned JSON evidence without embellishment. If no terminal\nreceipt is produced, report `RUNNER_RECEIPT_MISSING` and run that same\nread-only diagnosis; do not assert a state before its result.\n\nPreserve the runner's status/code. A successful runner returns\n`PARTIALLY_VERIFIED/RESTART_REQUIRED` with `bootstrap=VERIFIED` and\n`initialization=NOT_RUN`. Then stop and ask the user to open a new task in this\nproject so Codex loads the newly created project `.codex/config.toml`. The\ncurrent task must never report overall initialization `VERIFIED`.\n\nIn the new task, overall initialization is `VERIFIED` only after all of these\nsame-task gates succeed through the actual project `nacl_neo4j` MCP:\n\n1. Record real MCP `initialize` and `tools/list` discovery, requiring the exact\n   `read-cypher` and `write-cypher` tool names. Missing discovery is closed\n   non-success.\n2. Run graph connectivity health, read the complete\n   `nacl-graph-gateway` schema ledger, require versions 1–3 with their packaged\n   checksums, and read back every required constraint.\n3. Execute the bundled named read `sa_statistics_extensions` unchanged and\n   record its result. A generic `RETURN 1` alone is insufficient.\n4. Invoke the plan runner with `--verification-plan`, show its random\n   idempotency key, parameterized write/read-back statements, `planHash`, and\n   exact `VERIFY_NACL_INITIALIZATION:<project-id>:<sha256>` token, then stop.\n5. After the user freshly repeats that token, make exactly one parameterized\n   write-canary call with the plan's statement/parameters, followed by a\n   separate read call with the read-back statement. Require matching project\n   ID, idempotency key, and integer revision. Never accept a static, old, or\n   reconstructed verification token. Never automatically retry the write; any\n   failure requires a new verification plan, new idempotency key, and fresh\n   user confirmation.\n\nReturn these exact result fields: `status`, `code`, `initializationState`,\n`mcpServerKey`, `mcpInitialize`, `mcpToolsList`, `readTool`, `writeTool`,\n`graphHealth`, `schemaVersion`, `schemaChecksum`, `namedRead`, `writeCanary`,\nand `writeReadback`. Set `status=VERIFIED`, `code=INITIALIZATION_VERIFIED`, and\n`initializationState=VERIFIED` only when every field is verified; otherwise\npreserve the closed failing status/code.\n\nOptional agent profiles remain create-only and require a separate path-by-path\nplan and confirmation. On `AGENT_PROFILE_CONFLICT`, never overwrite: ask the\nuser to move or back up the conflicting file, then produce a fresh plan before\nany retry.\n"
}

SHA-256 of public snapshot: bc8bbbc4feebc37db4b7b257a0cc226ce3949ad54b4d1e20de49aef3572d511f