Operator Command
Inspect and safely mutate the independently installed hi-cli operator skill
hi operator manages the independently installed hi-cli operator skill. The CLI selects one immutable compatible target: version 2.0.0, revision dbfd199e89ab17f6241270ab1f23ea50c294926f, for CLI versions >=4.0.0 <5.0.0.
Commands
| Command | Purpose |
|---|---|
hi operator status | Inspect the canonical global and current-project records returned by Skills CLI. |
hi operator install | Let Skills CLI select the global harness target, then verify its canonical returned copy. |
hi operator update | Update each detected hi-cli scope and verify its canonical copy; use install when absent. |
hi operator migrate | Verify canonical replacement identity and legacy agent coverage before unscoped removal. |
Harness does not select an agent or harness target for these commands. It invokes Skills CLI without --agent; Skills CLI detects supported harnesses and presents its own selection when needed. HI_OPERATOR_AGENT is neither read nor required, including for plain, JSON, redirected, and recovery runs. Skills CLI aggregates the provider agents for a scope and skill into one canonical path, so Harness uses that path to byte-verify the returned copy rather than a separate copy for every harness. The path itself is not retained as verified identity.
Reading Status
Inside a matching project, the project-local copy is effective, whether verified or outdated. The global copy remains visible as shadowed and becomes the fallback outside that project. Status also reports incompatible copies and these explicit states:
outdated: a listed copy differs from the immutable content target. It remains unverified inventory, shadows lower-precedence copies, and produceshi operator updateguidance.absent: both scope inspections succeeded and no applicable copy exists.ambiguous: equally applicable copies have distinct identities, so no effective copy is invented.detection failed: an unsafe path, list failure, or missing, unreadable, or malformed result prevents safe inspection; partial observed evidence remains visible.
Verified records include source, version, revision, compatibility, aggregated provider agents, scope, and project root when applicable.
Verified Mutations
Install, update, and migration replace outdated inventory. After a write, reinspection uses Skills CLI's returned canonical path to byte-verify immutable content before recording the compatible range, aggregated provider agents, scope, and project root. A same-content path change is acceptable after re-verification because the path is not retained identity. Skills CLI owns target fan-out. A persistent mismatch remains unverified. Scopes remain independent: if one succeeds and another fails or cannot be verified, the command prints every outcome, retains the verified work, and exits nonzero.
Before unscoped legacy removal, migration requires the canonical replacement's provider-reported agents to cover every provider-reported dp-cli binding in that scope. Missing coverage, a mismatched replacement, or any other closed removal barrier preserves dp-cli and exits nonzero.
Failed and unverified write actions include a guarded retry. It preserves the target and operation context, then re-enters inspection and post-write verification.
An inspection failure prints a direct command rerun without a guarded write token. That rerun inspects the complete current lifecycle and may reconsider every scope now detected; the earlier unknown state never becomes an unconditional install.
Any observed successful write prints guidance to reload or reactivate $hi-cli, including partial-success cases.
hi skills rename remains a deprecated delegate to hi operator migrate; it has no separate lifecycle or rename policy.
See Operator-Skill State for the lifecycle trust model and its boundaries.