checkpoint
Preserve and restore session state across compact and resume boundaries.
The 10 workflow definitions that travel with the signed policy bundle. Any session governed by that bundle can use them.
Read them before you install them — that is the point of this page. Each one shows the literal bytes that land on your machine and the SHA-256 your agent checks them against, so nothing here is a description of the artifact standing in for the artifact.
A skill is instruction text a model loads into its own context, which makes it
the supply chain into agent behavior: swapping one changes what every connected agent does,
with no code change anywhere. So they are graded for drift exactly like an enforcement hook,
they ship non-executable at 0644 with the execute bit refused at validation, and
replacing one locally makes your next attestation come back Drifted.
Preserve and restore session state across compact and resume boundaries.
Run the full commit ritual end to end — verify, stage with hygiene, conventional message + CHANGELOG, never bypass the pre-commit hook, commit as the…
Provide project-planning support without making this session the project manager of record.
Put a consequential set of choices to the human as an interactive HTML decision tree with a closed click-to-resume loop, not a chat wall of options.
Fan work out to sub-agents — auto-briefed, parallel, governed, goal-coupled.
Forge a crisp, hook-checkable session goal — inferring a draft from the conversation plus patterns from past sessions, and/or interviewing to pin the…
The detective's self-audit — put your OWN claims on trial before declaring work done.
Render a STANDALONE visual artifact to the visual-bar standard — interactive HTML (Plotly charts + vis-network graphs) PLUS a branded PNG companion…
Run the severity-tiered security linter over the codebase before committing.
Walk the verification ladder — a one-way ratchet — when delivering any component (invariant, feature, refactor, fix).
Fetch any of them without enrolling: GET /v1/bundle/stable for the
signed manifest, then GET /v1/blob/<sha256> for the bytes. Verifying the
bundle signature against the published publisher key needs nothing from
us but the key id.