← HarbormasterCONTENT HISTORY

Update to Harbormaster

Snapshot Sep 30, 2026 · 23:15 UTC · version 0.1.2

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "harbormaster",
  "description": "Diagnose local port collisions, identify the project or process holding a port, reserve ports, inspect service history, or safely free exactly one explicitly authorized local listener. Use for localhost conflicts, vanished dev servers, port ownership, reservations, and anti-killall process control.",
  "included_files": [],
  "skill_md_contents": "---\nname: harbormaster\ndescription: Diagnose local port collisions, identify the project or process holding a port, reserve ports, inspect service history, or safely free exactly one explicitly authorized local listener. Use for localhost conflicts, vanished dev servers, port ownership, reservations, and anti-killall process control.\n---\n\n# Harbormaster\n\nHarbormaster is the anti-killall. It inspects local listeners, attributes them to projects, records service appearances and disappearances, and can free exactly one explicitly selected port.\n\n## Surface gate\n\nBefore running any bundled command, confirm that this is a **local Codex task running on the computer whose ports the user wants to inspect**.\n\n- In a supported local Codex task, say that Harbormaster will inspect the current computer, then begin with the smallest read-only command that answers the request.\n- In ChatGPT, Codex cloud, or any other hosted or remote sandbox, do **not** run the bundled engine and do not describe sandbox listeners as the user's local ports.\n- On an unsupported surface, explain: \"Harbormaster inspects ports through a local Codex task on the computer you want to inspect. Hosted ChatGPT cannot see that computer's process table. Open Harbormaster in Codex on that machine and repeat your request.\"\n- If the execution surface is ambiguous, state the requirement and ask the user to open the request in local Codex. Never infer that zero sandbox listeners means the user's computer has no listening ports.\n\n## Locate the bundled engine\n\nUse the plugin's bundled `../../scripts/harbormaster.py` relative to this skill directory. Resolve it to an absolute path before running it. Do not assume a separately installed `ports` command exists.\n\n## Read first\n\nStart with the smallest read-only command that answers the request:\n\n- Harbor overview: `python3 <script> list`\n- Development listeners only: `python3 <script> list --dev`\n- Exact owner, agent-safe output: `python3 <script> who <port> --json --safe`\n- Reservations and collisions: `python3 <script> reservations`\n- Flight recorder: `python3 <script> history [port]`\n- Setup diagnosis: `python3 <script> doctor`\n\nPrefer `who <port> --json --safe` for Codex reasoning. Do not reveal full command lines or filesystem paths unless the user explicitly requests those details and they are necessary.\n\n## Mutations are explicit\n\n- Reserve only when the user asks: `python3 <script> reserve <port> <project> [--note ...]`.\n- Remove a reservation only when the user asks: `python3 <script> unreserve <port>`.\n- Before freeing a port, always run `who <port> --json --safe` and verify there is exactly one attributable holder.\n- Explain which project and process will stop, then require explicit authorization to free it.\n- Use interactive `free <port>` by default. Never add `-y` or `--force` unless the user explicitly asks for that exact override after seeing the owner evidence.\n- If ownership is unknown, multiple holders exist, or the target looks like a system service, stop. Never guess.\n- Never use `killall`, broad process-name termination, recursive cleanup, or unrelated service restarts.\n\n## Dashboard\n\nLaunch `serve` only when the user asks for the dashboard. Keep it loopback-only (`127.0.0.1`) and report the local URL. Do not expose it to the network.\n\n## Safety and privacy\n\n- Treat command arguments and filesystem paths as potentially sensitive.\n- Keep history and reservations local in `~/.harbormaster`.\n- Do not copy or publish local process inventories.\n- A vanished-service event is evidence that a listener disappeared, not proof of a crash.\n- Report observation, inference, and recommended action separately.\n"
}

SHA-256: 2404cf06a17269a7c565dca7f2df2c3e5aa6303877a99873b2f0cf7d88b24d9f