Skip to content

feat(skills): adopt iii-skill-check render pipeline + per-worker docs/ - #109

Merged
anthonyiscoding merged 13 commits into
mainfrom
add/skills-rendering-and-validation
May 11, 2026
Merged

anthonyiscoding merged 13 commits into
mainfrom
add/skills-rendering-and-validation

Conversation

@anthonyiscoding

@anthonyiscoding anthonyiscoding commented May 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Wire the workers repo into the iii-hq/skills-and-validation render + verify pipeline (.skill-check.yaml + .github/workflows/skill-check.yml).
  • Refactor the seven workers that already shipped a skill.md (auth-credentials, llm-budget, models-catalog, session-tree, shell, subagent, turn-orchestrator) onto the canonical docs/ layout, mining the pre-migration skill.md and skills/*.md for content.
  • Each refactored worker now sources README.md, skill.md, and skills/*.md from docs/intro.md, docs/quickstart.md, docs/companions.md, docs/leaves/*.md, iii.worker.yaml, and config.yaml — rendering and verification handled by iii-skill-render and iii-skill-check.

Repo wiring

  • .skill-check.yaml — schema v1, anthropic AI provider, claude-opus-4-7 (v1 still supported by v0.2 of the action; implicitly mode: worker).
  • .github/workflows/skill-check.yml — runs on PR + push to main, uses iii-hq/skills-and-validation@v0.2 with write: true. The default workers-glob (*/iii.worker.yaml) is fine: the v0.2 action treats unmigrated workers (no docs/) as skipped (no docs/) rather than failing.
  • .gitignore — drop the blanket docs and config.yaml ignores so each worker keeps its source partials and runtime config in tree; ignore .skill-check/ so the action's install directory cannot be auto-committed back.

Per-worker

  • All 7 pass iii-skill-check verify --layers structure,vale,ai clean.
  • shell/ARCHITECTURE.md and turn-orchestrator/ARCHITECTURE.md preserve threat-model, full payload tables, CLI flags, streaming wire shapes, and the agent::events contract that don't fit canonical README slots.
  • shell/skills/fs/<leaf>.md flattened to shell/skills/<leaf>.md to match the renderer's flat leaf layout.

Content audit

After an initial draft, every claim in docs/intro.md, docs/quickstart.md, docs/companions.md, docs/leaves/*.md, and config.yaml for the 7 workers was audited against the pre-migration skill.md / skills/*.md, source code, and original README.md. Two minor invented additions were dropped:

  • auth-credentials/docs/leaves/get_token.md — removed an extraneous "use case" bullet.
  • session-tree/docs/leaves/append.md — removed a speculative claim about session-tree::messages reconstruction breaking when parent_id is omitted.

All other content is grounded in pre-migration docs or source.

Follow-up

  • Migrate the remaining 20 workers to canonical docs/ layout: acp, approval-gate, harness, hook-fanout, iii-database, iii-lsp, image-resize, mcp, oauth-anthropic, oauth-openai-codex, policy-denylist, proof, provider-anthropic, provider-openai, provider-router, session-inbox, skills, storage, todo-worker, todo-worker-python. harness/docs/ already exists but holds non-canonical files (iii-skill.md, sandbox-skill.md) — those will need to move or be renamed when harness migrates. No workflow change is needed as each worker migrates; the action picks new ones up on the next run.
  • Upstream action issue (handled by another agent): iii-hq/skills-and-validation's composite action installed binaries to \$WORKSPACE/.skill-check/ and its auto-fix commit step did not restrict the add-set to rendered worker artifacts. Earlier in this PR's history a bot commit shipped 4.6 MB of binaries before that was caught and .skill-check/ was added to .gitignore.

Test plan

  • iii-skill-check verify <worker> --layers structure,vale clean for all 7.
  • iii-skill-check verify <worker> --layers ai clean for all 7.
  • Content audit against pre-migration skill.md/skills/*.md and source.
  • CI skill-check job is green on this PR (now that the broken workers-glob override is removed).

🤖 Generated with Claude Code

Wire the workers repo into the iii-hq/skills-and-validation render +
verify pipeline, then refactor the seven workers that already shipped a
skill.md (auth-credentials, llm-budget, models-catalog, session-tree,
shell, subagent, turn-orchestrator) onto the canonical docs/ layout.

Each refactored worker now sources its README.md, skill.md, and
skills/*.md from docs/intro.md, docs/quickstart.md, docs/companions.md,
docs/leaves/*.md, iii.worker.yaml, and config.yaml, with rendering and
verification handled by iii-skill-render and iii-skill-check.

Repo wiring:
- .skill-check.yaml — schema v1, anthropic AI provider, claude-opus-4-7
- .github/workflows/skill-check.yml — runs on PR + push to main, uses
  iii-hq/skills-and-validation@v0.1 with write: true so drift is
  auto-rendered and committed back to the PR branch
- .gitignore — drop blanket `docs` and `config.yaml` ignores so each
  worker can keep its source partials and runtime config in tree

Per-worker:
- All 7 pass `iii-skill-check verify --layers structure,vale` clean
- shell/ and turn-orchestrator/ gained ARCHITECTURE.md to preserve the
  threat-model, payload tables, CLI flags, streaming wire shapes, and
  agent::events contract that don't fit the canonical README slots
- shell/skills/fs/<leaf>.md flattened to shell/skills/<leaf>.md to match
  the renderer's flat leaf layout

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented May 9, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 152 files, which is 2 over the limit of 150.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 1dad00f9-b1e0-4f17-8bbd-7a3edcdc79e2

📥 Commits

Reviewing files that changed from the base of the PR and between cca571f and b62a62c.

📒 Files selected for processing (152)
  • .github/workflows/skill-check.yml
  • .gitignore
  • .skill-check.yaml
  • approval-gate/tests/skill.rs
  • auth-credentials/README.md
  • auth-credentials/config.yaml
  • auth-credentials/docs/companions.md
  • auth-credentials/docs/intro.md
  • auth-credentials/docs/leaves/delete_token.md
  • auth-credentials/docs/leaves/get_token.md
  • auth-credentials/docs/leaves/list_providers.md
  • auth-credentials/docs/leaves/set_token.md
  • auth-credentials/docs/leaves/status.md
  • auth-credentials/docs/quickstart.md
  • auth-credentials/skill.md
  • auth-credentials/skills/delete_token.md
  • auth-credentials/skills/get_token.md
  • auth-credentials/skills/list_providers.md
  • auth-credentials/skills/set_token.md
  • auth-credentials/skills/status.md
  • auth-credentials/tests/skill.rs
  • llm-budget/README.md
  • llm-budget/docs/companions.md
  • llm-budget/docs/intro.md
  • llm-budget/docs/leaves/alert_set.md
  • llm-budget/docs/leaves/check.md
  • llm-budget/docs/leaves/create.md
  • llm-budget/docs/leaves/delete.md
  • llm-budget/docs/leaves/enforce.md
  • llm-budget/docs/leaves/exempt.md
  • llm-budget/docs/leaves/forecast.md
  • llm-budget/docs/leaves/get.md
  • llm-budget/docs/leaves/list.md
  • llm-budget/docs/leaves/pause.md
  • llm-budget/docs/leaves/record.md
  • llm-budget/docs/leaves/reset.md
  • llm-budget/docs/leaves/update.md
  • llm-budget/docs/leaves/usage.md
  • llm-budget/docs/quickstart.md
  • llm-budget/skill.md
  • llm-budget/skills/alert_set.md
  • llm-budget/skills/check.md
  • llm-budget/skills/create.md
  • llm-budget/skills/delete.md
  • llm-budget/skills/enforce.md
  • llm-budget/skills/exempt.md
  • llm-budget/skills/forecast.md
  • llm-budget/skills/get.md
  • llm-budget/skills/list.md
  • llm-budget/skills/pause.md
  • llm-budget/skills/record.md
  • llm-budget/skills/reset.md
  • llm-budget/skills/update.md
  • llm-budget/skills/usage.md
  • llm-budget/tests/skill.rs
  • models-catalog/README.md
  • models-catalog/config.yaml
  • models-catalog/docs/companions.md
  • models-catalog/docs/intro.md
  • models-catalog/docs/leaves/get.md
  • models-catalog/docs/leaves/list.md
  • models-catalog/docs/leaves/register.md
  • models-catalog/docs/leaves/supports.md
  • models-catalog/docs/quickstart.md
  • models-catalog/skill.md
  • models-catalog/skills/get.md
  • models-catalog/skills/list.md
  • models-catalog/skills/register.md
  • models-catalog/skills/supports.md
  • models-catalog/tests/skill.rs
  • session-tree/README.md
  • session-tree/config.yaml
  • session-tree/docs/companions.md
  • session-tree/docs/intro.md
  • session-tree/docs/leaves/append.md
  • session-tree/docs/leaves/clone.md
  • session-tree/docs/leaves/compact.md
  • session-tree/docs/leaves/create.md
  • session-tree/docs/leaves/export_html.md
  • session-tree/docs/leaves/fork.md
  • session-tree/docs/leaves/messages.md
  • session-tree/docs/leaves/tree.md
  • session-tree/docs/quickstart.md
  • session-tree/skill.md
  • session-tree/skills/append.md
  • session-tree/skills/clone.md
  • session-tree/skills/compact.md
  • session-tree/skills/create.md
  • session-tree/skills/export_html.md
  • session-tree/skills/fork.md
  • session-tree/skills/messages.md
  • session-tree/skills/tree.md
  • session-tree/tests/skill.rs
  • shell/ARCHITECTURE.md
  • shell/README.md
  • shell/docs/companions.md
  • shell/docs/intro.md
  • shell/docs/leaves/chmod.md
  • shell/docs/leaves/exec.md
  • shell/docs/leaves/exec_bg.md
  • shell/docs/leaves/grep.md
  • shell/docs/leaves/kill.md
  • shell/docs/leaves/list.md
  • shell/docs/leaves/ls.md
  • shell/docs/leaves/mkdir.md
  • shell/docs/leaves/mv.md
  • shell/docs/leaves/read.md
  • shell/docs/leaves/rm.md
  • shell/docs/leaves/sed.md
  • shell/docs/leaves/stat.md
  • shell/docs/leaves/status.md
  • shell/docs/leaves/write.md
  • shell/docs/quickstart.md
  • shell/skill.md
  • shell/skills/chmod.md
  • shell/skills/exec.md
  • shell/skills/exec_bg.md
  • shell/skills/fs/chmod.md
  • shell/skills/fs/grep.md
  • shell/skills/fs/ls.md
  • shell/skills/fs/mkdir.md
  • shell/skills/fs/mv.md
  • shell/skills/fs/read.md
  • shell/skills/fs/rm.md
  • shell/skills/fs/sed.md
  • shell/skills/fs/stat.md
  • shell/skills/fs/write.md
  • shell/skills/grep.md
  • shell/skills/kill.md
  • shell/skills/list.md
  • shell/skills/ls.md
  • shell/skills/mkdir.md
  • shell/skills/mv.md
  • shell/skills/read.md
  • shell/skills/rm.md
  • shell/skills/sed.md
  • shell/skills/stat.md
  • shell/skills/status.md
  • shell/skills/write.md
  • shell/src/lib.rs
  • shell/tests/skill.rs
  • turn-orchestrator/ARCHITECTURE.md
  • turn-orchestrator/README.md
  • turn-orchestrator/config.yaml
  • turn-orchestrator/docs/companions.md
  • turn-orchestrator/docs/intro.md
  • turn-orchestrator/docs/leaves/start.md
  • turn-orchestrator/docs/leaves/start_and_wait.md
  • turn-orchestrator/docs/quickstart.md
  • turn-orchestrator/skill.md
  • turn-orchestrator/skills/start.md
  • turn-orchestrator/skills/start_and_wait.md

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch add/skills-rendering-and-validation

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actions Bot commented May 9, 2026 •

Copy link
Copy Markdown
Contributor

skill-check

0 verified, 1 skipped (no docs/).

Layer Result
structure ✓
vale ✓
ai ✓

Three for three. Nicely done.

anthonyiscoding added a commit that referenced this pull request May 9, 2026
The composite action installs its binaries + bundled rules into
$GITHUB_WORKSPACE/.skill-check/ and then the auto-fix commit step
staged every dirty path in the workspace, including the install
directory itself. That landed 4.6 MB of binaries plus the rules
snapshot into the PR via the github-actions[bot] commit.

Untrack the directory and add it to .gitignore so subsequent action
runs cannot re-commit it. The action's auto-commit narrowing is a
separate upstream concern in iii-hq/skills-and-validation; flagged
in PR #109.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
anthonyiscoding added a commit that referenced this pull request May 9, 2026
The composite action installs its binaries + bundled rules into
$GITHUB_WORKSPACE/.skill-check/ and then the auto-fix commit step
staged every dirty path in the workspace, including the install
directory itself. That landed 4.6 MB of binaries plus the rules
snapshot into the PR via the github-actions[bot] commit.

Untrack the directory and add it to .gitignore so subsequent action
runs cannot re-commit it. The action's auto-commit narrowing is a
separate upstream concern in iii-hq/skills-and-validation; flagged
in PR #109.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@anthonyiscoding
anthonyiscoding force-pushed the add/skills-rendering-and-validation branch from cb1201a to 3504897 Compare May 9, 2026 19:42
anthonyiscoding and others added 2 commits May 9, 2026 14:45
The composite action installs its binaries and bundled rules into
$WORKSPACE/.skill-check/ when running on PRs. Without this ignore the
auto-fix step's commit-back stages the entire install directory. Keep
the install dir out of git so CI runs cannot accidentally land binaries
or vendored rules in this repo.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The default `*/iii.worker.yaml` glob runs the renderer against every
worker. The 20 workers that have not been migrated to the canonical
docs/ layout have no docs/intro.md and the action fails immediately on
them. Pin the glob to the 7 migrated workers; expand as each remaining
worker migrates.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@anthonyiscoding
anthonyiscoding force-pushed the add/skills-rendering-and-validation branch from 3504897 to b36a3ad Compare May 9, 2026 19:45
anthonyiscoding added a commit to iii-hq/skills-and-validation that referenced this pull request May 9, 2026
…-set

A consumer PR (iii-hq/workers#109) shipped 4.6 MB of bundled binaries
because the action installed iii-skill-{check,render} into
\$GITHUB_WORKSPACE/.skill-check and the auto-commit step did
\`git add -A\` — sweeping the install dir into the bot's "auto-render
worker docs" commit alongside the actual rendered output.

Two layered fixes:

1. Move the install dir to \$RUNNER_TEMP/skill-check so it can never
   appear in \`git status\` regardless of how the add-set is shaped.
   Updated all four references (download dest, render binary path,
   verify INSTALL_DIR env, ci-install.sh argument) to use runner.temp.

2. Tighten the auto-commit add-set: instead of \`git add -A\`, iterate
   the workers-glob and stage exactly the rendered artifacts —
   \`<dir>/README.md\`, \`<dir>/skill.md\`, and \`<dir>/skills/\` (the
   last with -A so stale-leaf cleanup deletions are also staged).
   Defense-in-depth so any future workspace pollution can't slip into
   bot commits either. If the scoped add finds nothing staged, the step
   exits clean instead of producing an empty commit.

Drift detection was also rescoped to those same paths so unrelated
untracked files in the consumer's workspace don't trigger the
auto-commit step on \`drift=present\`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
anthonyiscoding and others added 3 commits May 9, 2026 20:24
- auth-credentials/docs/leaves/get_token.md: remove a third "use case"
  bullet ("One-off debugging where a stored credential needs to be
  inspected directly") that did not appear in the pre-migration
  skill leaf or source.
- session-tree/docs/leaves/append.md: drop the speculative claim that
  omitting parent_id "creates a parent-less node and breaks
  session-tree::messages reconstruction"; restore the original phrasing
  about supplying the previous entry_id.

Audit of the other five migrated workers (llm-budget, models-catalog,
shell, subagent, turn-orchestrator) found no invented content.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented May 10, 2026 •

Copy link
Copy Markdown
Contributor

skill-check — worker

6 verified, 20 skipped (no docs/).

Layer Result
structure ✓
vale ✓
ai ✓

Three for three. Nicely done.

anthonyiscoding and others added 4 commits May 9, 2026 20:42
The brace-expansion glob `{auth-credentials,...}/iii.worker.yaml` was
treated as a literal directory name (the runner's `find` did not expand
braces), so the action skipped every worker with "no docs/ partials
yet". The v0.2 action already skips workers without `docs/` cleanly, so
the default `*/iii.worker.yaml` glob is the right choice — unmigrated
workers fall through as `skipped (no docs/)` rather than failing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The skills/* and skill.md files now begin with the iii-skill-render
generated banner — a single-line HTML comment — so the existing
`well_formed` check failed at "skill must start with an H1". Strip
single-line HTML comments in memory before the H1 check; the rendered
files themselves are not modified.

Canonical leaves go directly from the topical H1 to `## When to use`
with no summary paragraph in between. Gate the "summary not heading"
check on a `require_summary` flag and call it `false` for sub-skills
while keeping it `true` for the router skill (which still has the
intro.md paragraph after its H1).

Update shell/src/lib.rs include_str! paths to the flat skills/<leaf>.md
layout the renderer produces; the path-style iii://skills ids
("shell/fs/ls", …) are preserved.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Apply the suggested form `!(t.is_empty() || t.starts_with("<!--") && t.ends_with("-->"))`
across all six worker test files.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…and-validation

# Conflicts:
#	approval-gate/config.yaml
#	approval-gate/docs/companions.md
#	approval-gate/docs/intro.md
#	approval-gate/docs/leaves/start.md
#	approval-gate/docs/quickstart.md
#	approval-gate/tests/skill.rs
#	subagent/README.md
#	subagent/skill.md
#	subagent/skills/start.md
anthonyiscoding added a commit to iii-hq/skills-and-validation that referenced this pull request May 11, 2026
Workers like \`harness\` ship an \`iii.worker.yaml\` + a \`docs/\` dir
that holds skill bundles or hand-authored notes rather than the
renderer's partials. The action's existing \`[ -d "\$dir/docs" ] ||
continue\` skip gate didn't catch them — \`docs/\` exists, just without
\`docs/intro.md\` — so the renderer was invoked and failed loudly with
\`Error: reading <worker>/docs/intro.md\`.

\`docs/intro.md\` is the minimum required partial; a worker missing it
isn't using the renderer pattern. Move the skip gate from "no docs/
dir" to "no docs/intro.md" so opted-out workers don't break CI.

Symptom: iii-hq/workers#109's run on v0.2.4 failed at the harness
worker. The seven workers that DO carry docs/intro.md rendered and
verified cleanly; only harness needed the action to back off.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@anthonyiscoding
anthonyiscoding marked this pull request as ready for review May 11, 2026 15:01
@anthonyiscoding
anthonyiscoding merged commit ab1e650 into main May 11, 2026
1 check passed
@guibeira guibeira mentioned this pull request May 19, 2026
4 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants