agents: vendor the engineering skills and carry their license #6

Merged
pit merged 1 commit from hermes/vendor-skills into main 2026-10-09 08:40:22 +00:00
Owner

Summary

 AGENTS.md                    # pr skill path -> vendored copy
 .gitignore                   # + .hermes/
+.agents/skills/             # 27 skills, verbatim from mattpocock/skills @ main
+├── <name>/SKILL.md         #   plus each skill's reference files
+├── LICENSE                 # MIT, (c) 2026 Matt Pocock
+└── NOTICE                  # provenance + humanlayer/skills credit
+skills-lock.json            # source path + content hash per skill

Vendors the engineering-skill set into the repo so any agent that reads
.agents/skills/ finds them, independent of this machine's global profile.
hermes skills list now tags them Source: project; anything not vendored
(such as diagnose-crash) stays local.

Evidence

  • Before: .agents/ was untracked, the repo was untrusted, and the whole
    skill set resolved as local only (hermes skills list).
    After: hermes skills trust recorded the repo
    (skills.trusted_project_dirs: /home/pit/Projects/infra-tracker), and the
    vendored skills load as project-sourced:

    $ hermes skills list   # tail
    ...  31 enabled, 0 disabled   (27 tagged Source: project)
    
    $ git show --stat --format=%h HEAD
    1190746 agents: vendor the engineering skills and carry their license
     84 files changed, 3790 insertions(+), 1 deletion(-)
    
  • License carried: .agents/skills/LICENSE (upstream MIT, verbatim) +
    .agents/skills/NOTICE (mattpocock/skills provenance; humanlayer/skills credit
    for the pr skill's show-me-derived layout, already documented in the
    vendored pr/CREDITS.md).

Merge Danger

Door: two-way

git revert 1190746 restores the tree. The vendored files are a fork of
upstream, pinned by skills-lock.json; nothing consumes them until a session
runs inside a trusted clone.

Blast Radius: public-repo publishing

These skills are MIT-licensed and the repo is public, so this publishes
third-party content; provenance and license are pinned to keep it compliant.
No secrets, no provisioning. One operational note: a fresh clone on another
machine needs a one-time hermes skills trust before the skills load.

## Summary ```diff AGENTS.md # pr skill path -> vendored copy .gitignore # + .hermes/ +.agents/skills/ # 27 skills, verbatim from mattpocock/skills @ main +├── <name>/SKILL.md # plus each skill's reference files +├── LICENSE # MIT, (c) 2026 Matt Pocock +└── NOTICE # provenance + humanlayer/skills credit +skills-lock.json # source path + content hash per skill ``` Vendors the engineering-skill set into the repo so any agent that reads `.agents/skills/` finds them, independent of this machine's global profile. `hermes skills list` now tags them `Source: project`; anything not vendored (such as `diagnose-crash`) stays local. ## Evidence - **Before:** `.agents/` was untracked, the repo was untrusted, and the whole skill set resolved as `local` only (`hermes skills list`). **After:** `hermes skills trust` recorded the repo (`skills.trusted_project_dirs: /home/pit/Projects/infra-tracker`), and the vendored skills load as project-sourced: ```text $ hermes skills list # tail ... 31 enabled, 0 disabled (27 tagged Source: project) ``` ```text $ git show --stat --format=%h HEAD 1190746 agents: vendor the engineering skills and carry their license 84 files changed, 3790 insertions(+), 1 deletion(-) ``` - License carried: `.agents/skills/LICENSE` (upstream MIT, verbatim) + `.agents/skills/NOTICE` (mattpocock/skills provenance; humanlayer/skills credit for the `pr` skill's `show-me`-derived layout, already documented in the vendored `pr/CREDITS.md`). ## Merge Danger **Door:** two-way `git revert 1190746` restores the tree. The vendored files are a fork of upstream, pinned by `skills-lock.json`; nothing consumes them until a session runs inside a trusted clone. **Blast Radius:** public-repo publishing These skills are MIT-licensed and the repo is public, so this publishes third-party content; provenance and license are pinned to keep it compliant. No secrets, no provisioning. One operational note: a fresh clone on another machine needs a one-time `hermes skills trust` before the skills load.
Copy the mattpocock/skills set into .agents/skills/ so every agent working in
this repo finds them, pin the exact revision in skills-lock.json, and ship the
upstream MIT license and notice alongside.

- .agents/skills/: 27 skills from mattpocock/skills @ main, verbatim
- skills-lock.json: per-skill source path and content hash
- .agents/skills/LICENSE + NOTICE: upstream MIT (c) 2026 Matt Pocock, plus the
  humanlayer/skills credit for the pr skill's show-me-derived layout
- .gitignore: ignore .hermes/
- AGENTS.md: point at the vendored pr skill instead of the global one
pit merged commit 89ab05c840 into main 2026-10-09 08:40:22 +00:00
pit deleted branch hermes/vendor-skills 2026-10-09 08:40:23 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
olympus/infra-tracker!6
No description provided.