- skills are found at any depth under the skills dir, so category-nested
layouts (skills/<category>/<id>/SKILL.md) vendor correctly; the folder
basename is the upstream id and the outermost SKILL.md wins over anything
nested inside a skill folder
- web-tree urls pointing directly at a type directory (.../tree/main/skills)
now map that directory as the type root instead of nesting it under the
default layout
- verified against the real github.com/mattpocock/skills repository
(36 skills across categories; include-selection by basename)
- admin-protected client config (flag > AGENT_LIB_CONFIG > platform default),
token used for basic auth only, redacted from all errors and files
- work-repo pull via go-git (bare cache clone + fetch, remote re-pointed on
config change), clean failure keeps previous state
- inventory: own items + external areas from lockfile; MCP inventoried but
never deployed
- manifest v1 records name/type/origin/revision/content-hash per item,
deterministic bytes; folder hashes over sorted relpath+filehash lines so
tree and disk hashes agree
- shared deploy package (atomic temp+rename, exec-bit preserving) now backs
both curator materialization and client deployment
- sync validates and hashes everything before the first mutation; second run
is a byte-level no-op