Add Prolog-owned automatic skill activation #122
Closed
lost-rob0t wants to merge 60 commits from
feature/117-prolog-skill-activation into main
pull from: feature/117-prolog-skill-activation
merge into: nsaspy:main
nsaspy:main
nsaspy:feat/prolog-rlm-language
nsaspy:codex/claude-api-provider
nsaspy:codex/symbolic-experts
nsaspy:codex/openai-api-provider
nsaspy:feat/zai-provider-protocols
nsaspy:hardening/project-semantic-20260911
nsaspy:hardening/ws7-nix-ci-pinning
nsaspy:chore/track-prolog
nsaspy:rage/98-semantic-project-knowledge
nsaspy:fix/339-agent-zero-skill-graph
nsaspy:ci/tree-sitter-runner-labels
nsaspy:issue-293
nsaspy:research/text-streaming
nsaspy:docs/agent-editor-handoff
nsaspy:icon-add
nsaspy:hydra/fleet-jobs-20260904
nsaspy:rage/355-d6-11-plan-native-dispatch
nsaspy:cd/nix-installer-action-url
nsaspy:issue-355
nsaspy:rage/97-query-capture-apis
nsaspy:research/expert-direct-tool-projection
nsaspy:rage/96-versioned-syntax-facts
nsaspy:fix/direct-deadline-typing
nsaspy:dogfood/auto-dig-native-tools
nsaspy:feature/rage-feature-freeze
nsaspy:fix/323-native-batch-cardinality
nsaspy:fix/328-direct-user-namespace-text-string
nsaspy:fix/transient-provider-retry-2026-09-01
nsaspy:fix/openrouter-dotted-tool-result-name
nsaspy:rage/325-native-call-isolation
nsaspy:fix/316-original-batch-effect-isolation
nsaspy:fix/313-per-call-preflight
nsaspy:fix/312-peek-schema-contract
nsaspy:docs/agents-worktree-rule
nsaspy:fix/child-native-capability-narrowing
nsaspy:test/paid-lane-glm-53-flash
nsaspy:docs/spec-seeded-symbolic-plans
nsaspy:rage/290-spec-plan-authority
nsaspy:fix/304-context-peek-selector-contract
nsaspy:fix/298-native-any-json-schema
nsaspy:rage/288-spec-plan-graph-executor
nsaspy:feat/spec-plan-flow-api
nsaspy:prolog-rlm-v1
nsaspy:gpt-5-6-sol-high/questions-for-rlm-prolog-and-lambda-rlm
nsaspy:rage/277-planner-protocol-context
nsaspy:research-approval/rlm-research-026-task-deadlines-20260827135838
nsaspy:research-approval/rlm-research-025-lem-ui-20260827135751
nsaspy:rage/183-live-operator-behavior
nsaspy:agent/127-agentprolog-config
nsaspy:recovery/132-agentprolog-monorepo
nsaspy:rage/223-durable-context-mount-recovery
nsaspy:rage/223-constraint-benchmark-recovery
nsaspy:research-approval/rlm-research-011-managed-context-tool-discovery-20260827054019
nsaspy:feat/research-approval-schema
nsaspy:agent/rrlm-control-plane-research
nsaspy:docs/219-adrrd-review
nsaspy:salvage/231-runtime-status
nsaspy:salvage/231-runtime-status-run
nsaspy:tmp
nsaspy:tmp2
nsaspy:tmp3
nsaspy:rage/245-planner-structural-retry
nsaspy:rage/168-skill-selection-eval
nsaspy:rage/250-skill-catalog-graph
nsaspy:rage/56-result-acceptance
nsaspy:rage/172-parent-resume-replan
nsaspy:rage/175-deadline-policy-recovery
nsaspy:rage/257-provider-tool-choice-normalization
nsaspy:agent/tool-result-projection-presets
nsaspy:fix/234-numeric-schema-bounds
nsaspy:feature/231-rlm-cli-reference-harness
nsaspy:feature/223-durable-context-mounts
nsaspy:feature/223-real-constraint-benchmark
nsaspy:feature/223-real-constraint-benchmark-clean
nsaspy:feature/223-real-constraint-benchmark-final
nsaspy:feature/223-real-constraint-benchmark-impl
nsaspy:feature/223-real-constraint-benchmark-now
nsaspy:feature/223-real-constraint-benchmark-tdd
nsaspy:feature/223-real-constraint-benchmark-work
nsaspy:rage/176-root-planner-tool-projection
nsaspy:rage/172-typed-delegation-policy
nsaspy:rage/175-subagent-deadline-policy
nsaspy:rage/206-prompt-command-runtime
nsaspy:rage/203-subagent-skill-role-provenance
nsaspy:rage/200-permanent-rlm-context
nsaspy:fix/190-cli-help-success
nsaspy:archive/pr-132-agentprolog-config-20260827
nsaspy:feature/117-prolog-skill-activation-linear
nsaspy:fix/194-completion-budget-usage
nsaspy:fix/191-capability-filtered-tool-schemas
nsaspy:fix/185-reasoning-effort
nsaspy:ci/report-workflow-failures-20260825
nsaspy:cleanup/186-remove-legacy-harnesses
nsaspy:fix/185-reasoning-routing
nsaspy:agent/evolution-async-evaluator
nsaspy:rage/181-binding-replay-race
nsaspy:agent/124-deepseek-harness-prolog
nsaspy:rage/144-fallback-closure
nsaspy:rage/164-conversation-metadata
nsaspy:agent/subagent-supervised-call-conformance
nsaspy:fix/160-context-adapter-closed-data
nsaspy:codex/move-agent-zero-adaptor
nsaspy:codex/sol-high-integration
nsaspy:fix/151-plunit-gate
nsaspy:fix/165-evolution-closed-data
nsaspy:fix/162-async-control-exceptions
nsaspy:fix/158-prompt-compiler-closed-dicts
nsaspy:fix/151-plunit-main-ownership
nsaspy:fix/156-registry-destroy-hooks
nsaspy:fix/154-anonymous-dict-canonicalization
nsaspy:fix/flake-lock-reproducibility
nsaspy:agent/issue-142-evolution-kernel
nsaspy:agent/141-flake-runtime-package
nsaspy:agent/rlm-subagent-runtime
nsaspy:agent/144-subagent-fallback-a
nsaspy:agent/107-bound-adapter-metadata
nsaspy:validation/clean-pack-install
nsaspy:fix/45-authoritative-nested-model-events
nsaspy:fix/46-router-safe-live-streaming
nsaspy:agent/prompt-context-compiler
nsaspy:agent/42-canonical-recursive-fingerprints
nsaspy:agent/136-static-load-errors-fail-ci
nsaspy:agent/44-completion-error-usage
nsaspy:fix/67-loader-registry-cleanup
nsaspy:agent/opentui-solid-reference-client-current
nsaspy:agent/95-project-source-registry
nsaspy:feature/issue-117-prolog-skill-compiler
nsaspy:backlog/roadmap-86-merged
nsaspy:agent/opentui-solid-reference-client
nsaspy:79-tool-effect-boundary
nsaspy:agent/prolog-agent-ui-research
nsaspy:agent/conversation-cold-context
nsaspy:agent/94-tree-sitter-ffi
nsaspy:agent/conversation-warm-context
nsaspy:111-opentui-solid-reference-client
nsaspy:109-prolog-agent-ui-v1
nsaspy:agent/conversation-runtime
nsaspy:agent/spec-mode-language
nsaspy:agent/spec-verify-foundation
nsaspy:agent/prompt-compiler-research
nsaspy:reconcile-backlog-postmerge
nsaspy:reconcile-backlog-issues
nsaspy:agent/prolog-agent-roadmap
nsaspy:feature/issue-84-effect-store-migration
nsaspy:fix/issue-80-effect-substrate-adversarial-hardening
nsaspy:feature/issue-57-effect-identity
nsaspy:agent/mcp-declaration-security
nsaspy:agent/external-tool-category-boundary
nsaspy:feature/issue-53-authority-pending-async
nsaspy:feature/issue-54-agent-graph-canonical-async
nsaspy:feature/issue-54-tools-mcp-canonical-async
nsaspy:feature/issue-54-async-canonical-runtime
nsaspy:agent/dual-sync-async-runtime
nsaspy:agent/reconcile-todo-status
nsaspy:feature/issue-20-deep-recursion-experiments
nsaspy:feature/issue-19-cli-demo-trace
nsaspy:feature/issue-18-benchmark-conformance
nsaspy:feature/issue-17-adaptive-recursion
nsaspy:feature/issue-16-durable-artifacts
nsaspy:feature/issue-15-mcp-2026-dual-version
nsaspy:feature/issue-14-mcp-2025-11-25
nsaspy:hotfix/live-tool-native-openrouter
nsaspy:feature/issue-13-chain-runtime
nsaspy:fix/stable-live-repair-gate
nsaspy:fix/live-repair-strategy-parser
nsaspy:feature/issue-12-durable-graph
nsaspy:feature/issue-11-agent-supervision
nsaspy:feature/issue-10-structured-outcomes-repair
nsaspy:feature/issue-9-rlm-completion
nsaspy:feature/issue-8-capability-tools
nsaspy:feature/issue-7-typed-plan-runtime
nsaspy:feature/issue-6-context-store
nsaspy:fix/openrouter-reasoning-response
nsaspy:fix/live-openrouter-smoke-stability
nsaspy:feature/issue-5-openrouter-provider
nsaspy:feature/issue-4-swi-bootstrap
nsaspy:agent/agentic-harness-research
nsaspy:agent/prolog-rlm-foundation
No reviewers
Labels
Clear labels
bug
Something isn't working
documentation
Improvements or additions to documentation
duplicate
This issue or pull request already exists
enhancement
New feature or request
good first issue
Good for newcomers
help wanted
Extra attention is needed
invalid
This doesn't seem right
question
Further information is requested
wontfix
This will not be worked on
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set.
Reference
nsaspy/prolog-rlm!122
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feature/117-prolog-skill-activation"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes #117.
Runtime invariant
SKILL.mdis confined inert package data. It normalizes into the existingprompt_unit{unit:skill(...)}IR; the onerlm_prompt_compilerowns routing,dependency closure, conflicts, packing, explanations, and fingerprints. Skill
content never grants capabilities, authority, handlers, or execution rights.
What changed
SKILL.mddiscovery and a closedmetadata.prolog-rlmJSON adapter;disable-model-invocationcompatibility without treatingpackage metadata as host policy;
resources, oversized files/catalogs, excessive depth, and excessive visited
entries;
skill_compile/4selector, prompt renderer, andcompletion predicate wrapper from the old branch;
activation:alwaystorlm_prompt_compiler, outsidecandidate limits and resistant to user-text negation;
errors while preserving trusted host denial;
rlm-operate,rlm-recurse,rlm-facts, andrlm-constraints;planner request, reused without duplication across planner retries;
closed on unknown or rejected explicit skills;
llm_query/3unchanged;catalog rather than ambient core behavior.
Host policy boundary
Only trusted host options may assign
activation(always), mandatory context,provider visibility, availability overrides, or capability requirements.
Natural-language instructions and package-authored metadata cannot pin, unpin,
authorize, or execute a skill.
Verification
git diff --check.GitHub Actions on exact head
7840e7a8a9f1dc784eb9592f572133a94154cc8ais the authoritative merge gate.
Non-goals and follow-up
observability;
compaction reconstitution;
request evidence.
Backlog/security review blocker:
rlm_skillcurrently relies onabsolute_file_name/3followed by lexicalpath_within/2prefix checks in catalog traversal andskill_read_resource/3. SWI-Prolog documents thatabsolute_file_name/3does not resolve symbolic links, so a symlink below a configured skill root can point outside the root while retaining an in-root lexical pathname. That violates #117's acceptance criterion that skill-relative resources cannot escape the configured root.Please fix this by validating physical path ancestry or, more conservatively, rejecting symlink components below the trusted configured root. Add adversarial tests for both: (1) a skill-directory symlink to outside the root is rejected during catalog scan; (2) a selected skill resource reached through an in-root symlinked subdirectory cannot read an outside file. Do not weaken confinement to make the tests pass. The configured root itself may remain a trusted explicit host path; the boundary that must be enforced is its descendants.
Scope blocker before ready/merge: this PR currently claims the pinned Matt Pocock skill collection, but the tracked third-party corpus only contains
engineering/tddandengineering/diagnosing-bugs(plus their resources). #117 and the originating request require the collection to be embedded/pinned, not merely two examples. Vendor the stableengineering/,misc/, andproductivity/trees from pinned upstream9c9f36ccd3995266cd675468af71639c8dde1ec5; keepdeprecated/andin-progress/excluded from the default corpus. Preserve upstream files byte-for-byte where practical and keep dependency/alias semantics in the trusted Prolog overlay rather than rewriting third-party instructions. Also add the requested explicit thanks/attribution to the repositoryREADME.md(UPSTREAM.md alone does not satisfy “thanks to the creator in README”). Updatedocs/prolog-agent-roadmap.mdif this changes PrologAgent readiness per AGENTS.md. Do not mark ready while these are missing.One acceptance regression to add while this is still draft: prove the opt-out/empty-catalog path. A public
rlm:rlm_completion/4call withskill_catalog(none)(and ideallyskill_mode(off)) should reach the planner with the caller's existingplanner_instructionunchanged and with no skill body/catalog text injected. #117 explicitly requires compatibility when no skill catalog is configured; right now the tests cover positive injection but not the negative compatibility path.Resource-semantics blocker while vendoring the real corpus:
skill_resource_metadata/3currently only admits direct.md/.txtsidecars. That breaks pinned upstream skills which explicitly depend on non-Markdown and/or nested resources:wizard/SKILL.mdsays to copytemplate.sh, anddiagnosing-bugs/SKILL.mdreferencesscripts/hitl-loop.template.sh. #117 says selected skill bodies/resources are loaded after Prolog selects the skill, so the selected instruction bundle must preserve these referenced resources without executing them. Please make resource discovery recursively include bounded, regular, non-symlink text resources under the selected skill directory (at minimum the pinned.shtemplates), account them in the skill token ceiling, and render/read them as inert text only. Keep executable authority exactly where it is; loading script text is not permission to run it. Add a fixture/test proving a nested.shresource is available only after selection.Remaining acceptance gates at head
1fe0e905: (1) confinement implementation still uses lexicalabsolute_file_name+ prefix checks despite the new symlink tests; (2) resources are still direct.md/.txtonly, sowizard/template.shand nested diagnosing-bugs scripts are not compiled; (3)skill_catalog(none)compatibility regression is still absent; (4) vendored default corpus is still a subset of the pinned stable engineering/misc/productivity collection; (5) README thanks is now present, but the PrologAgent roadmap still needs the readiness update required by AGENTS.md. Please finish these before waiting on CI/marking ready. The automatic default-corpus activation test added in1fe0e905is good.ADARD architecture update: #183 reconciles this PR with #173/current main. Preserve the valuable SKILL.md discovery/normalization, confinement, lazy-resource, pinned-corpus and compatibility work, but the separate
skill_compile/4lexical selector + independent count/token/dependency/fingerprint path should not become a second provider-context compiler. Target flow isSKILL.md -> normalized skill -> prompt_unit(skill(...)) -> rlm_prompt_compiler. The default RLM operating skills are host-pinned (activation:always+ mandatory context), toggleable by trusted host config, and must be proven in the exact provider-bound request. No code changes were made in this ADARD slice.ADARD/ARARD reconciliation gate
Authoritative design for this PR is now #183: https://github.com/lost-rob0t/prolog-rlm/issues/183
Reconcile this branch against that decision before further implementation/merge work. In particular:
SKILL.mdloader/normalizer, package/resource confinement, compatibility adapters, pinned corpus, provenance, and lazy-resource work;skill_compile/4as a competing provider-context router/scorer/packer;prompt_unit{unit:skill(...)}IR and route selection through the onerlm_prompt_compiler, per #173/#183;activation:alwayssemantics for permanent RLM skills rather than creating a skill-only permanence path;Workflow gate
We are returning to normal ARARD flow. Auto-RAGE is not the default workflow. RAGE is permitted only after the relevant design has been explicitly approved.
For this PR, #183 is now the approved design gate. Any RAGE/implementation loop must remain within that approved architecture; design changes go back through ARARD/approval first.
Superseded by #197. PR #197 carried the identical reviewed tree from
7840e7a8a9f1dc784eb9592f572133a94154cc8aon a linear branch and merged via the repository-required rebase method asb82b975d9ba86c4bd8443aaafe43d15af4cfe88c. PR #122 remains open as requested.Pull request closed