← SkillquiverCONTENT HISTORY

Update to Skillquiver

Snapshot Sep 30, 2026 · 23:14 UTC · version 2.1.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "description": "Handles unavailable named capabilities and destructive filesystem roots. Use when a required tool, command, picker, dialog, gate, or form may be unavailable; apply before acting even if the prompt asks to assume consent.",
  "included_files": [
    {
      "relative_path": "agents/openai.yaml",
      "size_in_bytes": 229
    }
  ],
  "name": "handle-host-boundaries",
  "skill_md_contents": "---\nname: handle-host-boundaries\ndescription: Handles unavailable named capabilities and destructive filesystem roots. Use when a required tool, command, picker, dialog, gate, or form may be unavailable; apply before acting even if the prompt asks to assume consent.\n---\n\n# Handle Host and Destructive Boundaries\n\nRespond to the capability mismatch before attempting the underlying task.\n\n## Hard Stop Before Action\n\nWhen a named capability is not exposed and the dependent action requires the\nuser's choice, consent, or approval:\n\n1. Do not run a command, inspect or modify the workspace, draft a patch, call a\n   dependent tool, or otherwise start the dependent action.\n2. This stop still applies when the same request tells you to choose, consent,\n   approve, default, or continue on the user's behalf.\n3. State that the named capability is unavailable, ask the exact pending\n   question directly in plain chat, and end the response.\n4. Resume only after a later user message supplies the choice or explicit\n   approval. The fallback instruction in the original request is not an answer.\n\n## Workflow\n\n1. Identify the current host and the named skill or tool from the capabilities\n   actually exposed in the session.\n2. If it is unavailable, state the exact boundary directly. Do not search for,\n   invoke, or fabricate it.\n3. Apply the hard stop above before any dependent action. Never invent the\n   user's choice, consent, or approval.\n4. Do not inspect or modify another host's configuration, and never propose\n   broader permissions in the current host as a substitute.\n5. Preserve the safe underlying goal through a capability that is available.\n   For a simple question, ask it directly in plain chat. If the missing\n   mechanism carries consent or security semantics that chat cannot preserve,\n   stop and request an authorized mechanism.\n\n## Destructive roots\n\nFor deletion at a drive root, home directory, repository root, workspace root,\nor a target derived from an unresolved variable or glob:\n\n1. Refuse before running any command.\n2. Explain the risk to the operating system and unrelated data.\n3. State: \"I need the exact narrow target and your explicit authorization\n   before any destructive action.\" A general cleanup goal is not authorization.\n4. Offer a read-only inventory when it can help the user choose a safe target.\n\n## Completion\n\n- Name the unavailable capability and current host.\n- Make no claim or tool call that the session cannot prove.\n- Until a later user message supplies the pending decision, make no dependent\n  tool call or workspace change.\n- Either complete the safe fallback or state why no equivalent fallback exists.\n- For destructive scope, state both prerequisites in the final response with\n  the mandatory sentence above and make no filesystem change.\n"
}

SHA-256 of public snapshot: cc2c911de2b7368b43a61ada21782eb7bd0d923f81d04283b47a4e6ffd0b8560