The skill was dropped into `skills/` unregistered, so it had no manifest role, no routing row, and no gate. An agent found it with `ls`, could not invoke it (`Unknown skill: no-ai-slop`), read the body by hand, and applied it to the whole of `docs/ux-end-to-end-workflow.md` from the request "make it human read-able" — sweeping with `grep -nioE '<banned-words>'` and committing the result in 8a470ed8f. Nothing in the body said which files were drafts, so in a repo it meant every file with prose in it. That shape does not stop at one doc. The patterns it deletes on sight are the patterns Design Law is written in: binary contrasts, colon reveals, stated importance, and prose that tells an implementer how to weigh a rule. DIAGRAM.md carries 335 em dashes against the skill's cap of 1-2, the STELLAR chain is 40 AGENTS.md files of exactly those shapes, and the banned list contains `harness`, which is a crate name appearing in 422 tracked files and ~2,700 banned-word hits sit across 329 tracked source files. `SHRUNK_DOC_RATIO` guards AGENTS.md and nothing else, so `docs/`, `docs/mips/`, README.md and DIAGRAM.md were unguarded. The body now opens with a Scope contract that is not advisory: one named file or pasted draft per invocation, ambiguity routes to Detect rather than Edit, never sweep with a regex, prose only and not code fences or tables or marker blocks, propose a diff rather than write, stop at a quarter of the target's bytes, and require a clean baseline before any write. A refusal list names the contracts outright — AGENTS.md, DIAGRAM.md, docs/nips, docs/mips, docs/spec, migrations, gauntlet baselines, features, Beads, reference-code, CHANGELOG, LICENSE, marker blocks, skill bodies, and all source. Every "pattern to cut" gains a load-bearing exception, because a rule, invariant, refusal or silent-failure warning reads as slop precisely when it is doing its job. eval.md gains eight blocking Scope checks that run before the edit, and the frontmatter description now says what the skill is not for, so it stops matching "make this readable". Placement follows the convention skills/README.md already states: it is a generic utility, not a suite member, so it lives as identical copies in the three runtime trees beside `desktop-screenshot` and `meridian-cli` rather than in `skills/`. That also clears it from `just check-skills`, which fails any `skills/` directory without a manifest entry. The README records why it sits out there, and that it is a drafting aid and never a publication gate — `just check-external-copy` owns that boundary, and a blocklist over freeform prose fails open on the phrasing nobody predicted. Signed-off-by: Joshua Belke <joshua@innovationhub-act.org> |
||
|---|---|---|
| .. | ||
| add-meridian-nostr-capability | ||
| build-meridian-client | ||
| consult-council-approval | ||
| drive-meridian-maturity | ||
| evolve-meridian-relay | ||
| extend-meridian-agent-surface | ||
| measure-meridian-relay | ||
| nato-brand-kit | ||
| qa-meridian-projects | ||
| run-meridian-gauntlet | ||
| rust-coding | ||
| secure-meridian-boundaries | ||
| steward-stellar-docs | ||
| verify-meridian-change | ||
| manifest.json | ||
| README.md | ||
Meridian maturity skills
This directory is the canonical home of the project skill suite. Each agent
runtime discovers skills from its own tree — .claude/skills/,
.codex/skills/, and .agents/skills/ — so every suite skill is symlinked
into all three; edit only the copy here. A $name token inside any skill body
refers to a sibling skill in this suite. The standalone utility skills
(desktop-screenshot, meridian-cli, no-ai-slop) are generic tools rather
than suite members and live as identical copies directly in the runtime trees,
so they carry no manifest role and no routing row. just check-skills enforces
the symlinks, copy identity, manifest roles, and cross-references; a directory
left in skills/ without a manifest entry fails it.
no-ai-slop is a drafting aid for one named prose file, and its own Scope
contract is the reason it sits out here. It was dropped into skills/
unregistered, found by ls, and applied to a 1,212-line orientation guide via a
banned-word grep sweep from the request "make it human read-able" — a shape
that ends at the STELLAR chain, because the sentences it deletes on sight are
the sentences Design Law is written in. It now refuses AGENTS.md, DIAGRAM.md,
specs, migrations, gate evidence, marker blocks, skill bodies and all source, and
proposes a diff instead of writing. Never run it as a publication gate; the
paragraph below on outward-facing copy says why a blocklist over freeform prose
fails open, and just check-external-copy owns that boundary.
The suite assumes a frontier agent runtime — Claude Opus 5 class or newer:
parallel subagents carry the fan-out, seat-isolation, and fresh-context-critic
patterns the skill bodies name, and each pattern states its inline fallback so
a lesser runtime still works. Frontmatter stays exactly name and
description (enforced by just check-skills) because three runtimes read the
same file: runtime-specific invocation metadata belongs in
agents/<runtime>.yaml, and capability guidance belongs in the body, never in
frontmatter fields only one runtime understands.
Use the coordinator only when work begins from a Bead, feature spec, or portfolio question. Select exactly one primary implementation skill, add the security and performance overlays only when their risks apply, and finish with verification. The machine-readable roles live in manifest.json and are enforced by just check-skills.
| Task changes | Primary skill |
|---|---|
| Bead/spec selection, reconciliation, or maturity portfolio | drive-meridian-maturity (coordinator) |
| Event wire semantics, kinds, tags, replaceability, or NIP contract | add-meridian-nostr-capability |
| Relay/storage/config/mesh behavior with an unchanged wire contract | evolve-meridian-relay |
| A selected desktop, web, or mobile client surface | build-meridian-client |
| CLI, ACP, agent runtime, MCP, or workflow execution | extend-meridian-agent-surface |
Add secure-meridian-boundaries when standing, tenant, channel, repository, grant, proxy, or denial behavior matters. Add measure-meridian-relay when a performance claim or hot path matters. Add rust-coding when the slice writes or refactors Rust — it selects from the 265-rule rust-skills corpus in .settings/reference-code/rust-skills/ and records the deltas that make general Rust advice correct here, because that corpus targets edition 2024 against this workspace's edition 2021 and its unwrap, unsafe, profile, and dependency rules are all superseded by a repo gate. Add nato-brand-kit when the change produces or reviews an outward-facing visual artefact — a briefing deck, an onboarding or marketing screen, a report cover, a release graphic — or adds a colour or type token to any client surface. End implementation with verify-meridian-change; use it alone for review-only verification, contributor bootstrap diagnostics, or deploy/re-probe work.
steward-stellar-docs is the steward seat: it runs the STELLAR/DOX documentation pass as a delta against .settings/stellar/snapshot.json rather than a rewrite from memory, so a re-scan cannot quietly drop a contract a doc already recorded. Run it as the closeout of any change that moved structure, ownership, contracts, or workflow, and standalone when the snapshot is stale or missing. It also maintains .settings/stellar/reference-index.md, which keeps the gitignored .settings/reference-code/ checkouts findable — cloudflare-os and the rest — without pulling their upstream AGENTS.md files into this chain. It owns docs only; it never changes code.
Before selecting a primary, convene consult-council-approval (advisory) when the decision has real trade-offs — it touches a Design Law, introduces a new mechanism, is expensive to reverse, or contradicts a recorded call. The skill routes the decision to one of seven chartered councils (Protocol, Security & Identity, Architecture & Scale, Experience, Release & Operations, Agent & Automation, General), collects falsifiable seat positions, and records the chair's call with its reversal evidence in the Bead or PR. Councils advise and gate; they never implement.
Use the qa-meridian-projects campaign before implementation to collect lifecycle evidence for the active Projects epics. Route each authorized fix to exactly one primary based on what changes. If Nostr is primary, apply the client or agent skill's platform/runtime contract as a supplemental guide for consumers without selecting a second primary.
Preserve the user's mode. Review and diagnosis remain read-only. Implementation permits scoped code changes, but Beads/spec mutation still requires task-management scope. A broad request with no named target may produce a read-only portfolio or candidate list; it must not silently claim or close work.
qa-meridian-projects is a campaign skill. Retire it after Beads epics meridian-ssx and meridian-hmd close, moving any durable lifecycle procedure into crates/meridian-cli/TESTING.md.
run-meridian-gauntlet is the second campaign skill: the brownfield maturation loop for .settings/gauntlet/BUILD-GUANTLET-LOOP.md. One invocation advances one row of .settings/gauntlet/register.md by one state and stops, so it is driven repeatedly and resumes from the register rather than from a conversation. It selects and red-teams; it never implements — routing still goes through the coordinator to exactly one primary, and just check-gauntlet fails any row claiming a state its evidence cannot support. Retire it when every register row passes.
Internal narrative never leaves the repo
Every skill here records how a decision was reached — council seats, red-team rounds, subagent passes, model names — and the repo also carries the product identities it was renamed from (Codebase Chat, Buzz, Sprout). Both are correct internally and unpublishable externally.
The boundary is any text a customer reads: a GitLab ticket or wiki page, a briefing deck, a release note, a screenshot posted to a PR. Two rules bind every skill that produces such text:
- Build outward-facing copy from a statement of work, never by filtering
internal narrative down. A ticket says what to do and what done looks like.
A blocklist over freeform prose fails open on the phrasing nobody predicted —
that is precisely how "Council-approved (roster: Chairman, Contrarian, …)"
and
codebase_chat.*reached live customer tickets. just check-external-copyis the backstop, not the mechanism. It shares its pattern core withscripts/gitlab-export.py. When it fires, rewrite the copy; widening the pattern list is the wrong repair, because the next leak will use wording the list still does not have.
Bead text is not pre-cleared for publication. Treat .beads/, .settings/ and
council minutes as internal-only sources.