Harness Intelligence Wiki
SpecsCLIIssue 206 Skill Activation Boundaries

Implementation Notes: Skill Activation Boundaries

Implementation Notes: Skill Activation Boundaries

Result

Shared skill activation is now bounded at the installed provider seams. React Doctor activates automatically only for explicit Doctor requests or production changes overlapping React runtime APIs; every documented changed scan resolves the checked-out branch's configured upstream and passes it with --base. TDD discovery requires explicit TDD/test-first/RED-GREEN intent or unresolved behavior design. Verify Behavior retains a narrow orchestrator-facing description for Debugging Phase and Implement Spec, while its Codex policy disables implicit invocation.

Task Evidence

TaskEvidenceResult
T1Source commit cc042289af6ffa19775ef253f08fcc9404892651; focused and verifier lifecycle testsaccepted
T2Immutable-tag sync receipt cc04228; pin test 1/1; mirror/wiki checks; baseline classificationaccepted

RED/GREEN Evidence

  • RED: the non-Astra source worker created the cross-skill contract before skill edits; the pre-fix state failed on broad metadata, omitted explicit base authority, and directly discoverable Verify Behavior.
  • GREEN: the original focused suite passed 7/7. After comment repair, the focused suite passed 8/8 and the expanded verifier set passed 16/16.
  • Full shared suite: most tests passed; eight unrelated pre-existing Parallel Research/Wayfinder durable-report assertions failed outside issue #206 paths.

Skill Application Evidence

SkillStatusEvidence
writing-for-agentsappliedTrigger branches were narrowed in frontmatter, command authority was co-located, and explicit caller pointers were preserved.
tddappliedA focused public skill-contract test was introduced before guidance edits and driven RED to GREEN.
codebase-designappliedFrontmatter remains the discovery seam; Debugging Phase and Implement Spec remain explicit orchestration adapters without a new abstraction.

Validation

  • node --test tests/skill-activation-boundaries.contract.test.mjs tests/verify-behavior.contract.test.mjs: passed 7/7.
  • bun run --cwd apps/cli test -- src/scripts/sync-skills-repo.test.ts: passed 1/1.
  • bun run sync:skills: passed from immutable tag sync/issue-206-skill-activation-boundaries-cc04228 at exact source SHA cc042289af6ffa19775ef253f08fcc9404892651.
  • Cached immutable source and distributed skill mirror are byte-identical; wiki projection sync and check passed.
  • git diff --check: passed.
  • bun run release:classify -- --base origin/team/stefan/issue-205-effect-backend-structure --head HEAD: passed with releaseKind: baseline, baseline publication required, npm publication not required, and no classification error. The run used a workspace-local temporary directory to avoid the unrelated inode exhaustion in /tmp.

Review Repair 1

  • P1 command binding: strengthened the source test RED, then co-located upstream resolution and the no-upstream guard in the React Doctor command block.
  • P2 stale authority: replaced the historical Verify Behavior branch pin with the canonical e780042 main source identity in source and projected runbooks.
  • Focused source tests passed 7/7; Harness pin test passed 1/1; wiki sync tests passed 8/8.

Comment Repair

  • Removed Claude's human-only disable-model-invocation flag so Debugging Phase and Implement Spec can still invoke Verify Behavior.
  • Added agents/openai.yaml with policy.allow_implicit_invocation: false and narrowed the description to the two authorized orchestrator routes.
  • Published and pinned immutable shared-source tag sync/issue-206-skill-activation-boundaries-cc04228.
  • Corrected spec lifecycle/classification frontmatter, restored the 50-entry wiki-log cap, and retained T2 as incomplete until release classification passed.
  • Moved verify-behavior out of the planning pack and colocated it with create-verification-skill and update-verification-skill in the dedicated default verification pack.

Behavior Verification

No browser or application runtime behavior changed. The observable seam is static agent-consumed metadata, command examples, explicit caller text, and generated-source identity; contract tests and exact mirror comparison provide the applicable proof.

Not applicable: no user-visible UI changed.

Debt and Follow-up

Before PR closeout, rebase onto issue #205's final published Harness commit and prove ancestry.

On this page