{"_id":"@agenttool/skills-yutabase","name":"@agenttool/skills-yutabase","dist-tags":{"next":"0.1.0-dev.0","latest":"0.1.0-dev.0"},"versions":{"0.1.0-dev.0":{"name":"@agenttool/skills-yutabase","version":"0.1.0-dev.0","description":"Pure deterministic YUTABASE plans from minimized Agent Skills inspection snapshots","license":"Apache-2.0","author":{"name":"AgentTool contributors"},"type":"module","sideEffects":false,"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./input.schema.json":{"default":"./schema/skills-yutabase-input-v0.1.schema.json"}},"publishConfig":{"access":"public","tag":"next"},"engines":{"node":">=20.19.0","bun":">=1.3.5"},"scripts":{"clean":"node --eval \"require('node:fs').rmSync('dist', { recursive: true, force: true })\"","build":"bun run clean && tsc","typecheck":"tsc --noEmit && tsc --noEmit -p tsconfig.contract.json","test":"bun test","check:package":"bun run build && bun test ./tests/package.check.ts","smoke:node":"node scripts/smoke-node.mjs","ci":"bun run typecheck && bun test && bun run check:package && bun run smoke:node","prepack":"bun run ci"},"devDependencies":{"@types/bun":"1.3.14","@types/node":"20.19.43","ajv":"8.20.0","typescript":"5.9.3"},"keywords":["agents","skills","yutabase","provenance","projection","uuidv5"],"repository":{"type":"git","url":"git+https://github.com/cambridgetcg/agenttool.git","directory":"packages/skills-yutabase"},"_id":"@agenttool/skills-yutabase@0.1.0-dev.0","bugs":{"url":"https://github.com/cambridgetcg/agenttool/issues"},"homepage":"https://github.com/cambridgetcg/agenttool#readme","_integrity":"sha512-hGxCVqGznTadfxU11hCrzRhmzuH+LJ6bQpPYvsgDAWattooFCCoM25RcjcvyfkXMAtVQpWDR09kqPUxalO/uyA==","_resolved":"/home/runner/work/_temp/agenttool-npm-release/agenttool-skills-yutabase-0.1.0-dev.0.tgz","_from":"file:/home/runner/work/_temp/agenttool-npm-release/agenttool-skills-yutabase-0.1.0-dev.0.tgz","_nodeVersion":"24.18.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-hGxCVqGznTadfxU11hCrzRhmzuH+LJ6bQpPYvsgDAWattooFCCoM25RcjcvyfkXMAtVQpWDR09kqPUxalO/uyA==","shasum":"36ccc921d7131b79fd1f9f40a1e2eef1c68b5f27","tarball":"https://registry.npmjs.org/@agenttool/skills-yutabase/-/skills-yutabase-0.1.0-dev.0.tgz","fileCount":31,"unpackedSize":99184,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agenttool%2fskills-yutabase@0.1.0-dev.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIA0r70cTIIiL4TkIPvpUJsr870JgYgMiQOnYaoYUkeKWAiEAmalSwJq88syxPmtJ9vALnNZLvjylaw5iRNBm6qRUP8Q="}]},"_npmUser":{"name":"agenttool","email":"contact@cambridgetcg.com"},"directories":{},"maintainers":[{"name":"agenttool","email":"contact@cambridgetcg.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/skills-yutabase_0.1.0-dev.0_1785617726220_0.15000356472031195"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-01T20:55:26.065Z","0.1.0-dev.0":"2026-08-01T20:55:26.348Z","modified":"2026-08-01T20:55:26.728Z"},"maintainers":[{"name":"agenttool","email":"contact@cambridgetcg.com"}],"description":"Pure deterministic YUTABASE plans from minimized Agent Skills inspection snapshots","homepage":"https://github.com/cambridgetcg/agenttool#readme","keywords":["agents","skills","yutabase","provenance","projection","uuidv5"],"repository":{"type":"git","url":"git+https://github.com/cambridgetcg/agenttool.git","directory":"packages/skills-yutabase"},"author":{"name":"AgentTool contributors"},"bugs":{"url":"https://github.com/cambridgetcg/agenttool/issues"},"license":"Apache-2.0","readme":"# @agenttool/skills-yutabase\n\nPure, deterministic plans from minimized Agent Skills inspection metadata to a\nseparate YUTABASE `skills` book. The v0.1 profile has two decks,\n`inspections` and `skill_snapshots`, joined only by\n`lists_skill_snapshot`.\n\nThis is the safe first seam for Nen skills: an exact `@agenttool/skills`\ninspection report stays outside YUTABASE, while its digest, caller-supplied\ninspector revision, bounded counts, and each selected skill name/content digest\ncan be cached as rebuildable provenance. The planner computes a\ndomain-separated digest of the minimized selection so two subsets of one\nreport cannot collide on an inspection-card identity. The supplied revision\nvalue is also bound into that identity because it is external to the canonical\nreport bytes. It remains unverified and is not a Git observation. The same\nmechanism can catalog a separately reviewed Hugging Face skill bundle only\nafter it is inspected locally through `@agenttool/skills`; Hugging Face or\nproposal digests cannot substitute for the inspection digest.\n\n## Boundary\n\nThe caller must first validate the full report against\n`@agenttool/skills/report.schema.json`, retain canonical report bytes, verify\nthe report and skill digests, supply the claimed inspector revision, and\nminimize the result into this package's closed `./input.schema.json` contract.\nThe report digest recipe is frozen as\n`agenttool.skills/report-stable-json-sha256-v1`: SHA-256 of the UTF-8 bytes\nreturned by `@agenttool/skills` `stableStringify(report)` with its default\nrecursive key ordering, two-space indentation, and trailing LF. The exported\n`skillsInspectionReportDigestFromCanonicalBytes()` helper hashes those bytes;\nit does not canonicalize or validate them. This planner checks only the\nminimized fields it consumes. Its explicit `not_performed` results are not\nsuccessful validations.\n\nThe JavaScript boundary snapshots inert data rather than retaining the\ncaller's objects. Every listed object field and array element must be an own,\nenumerable data property. Objects must use `Object.prototype` or `null`;\narrays must be dense and use the standard array prototype. Accessors,\ninherited or sparse values, symbols, custom prototypes, custom array fields,\nand values recognized by Node/Bun as `Proxy` objects are rejected before\nproperty reflection. `assertSkillsYutabaseInput()` accepts `unknown` and\nnarrows it only after these checks. `planSkillsInspection()` and the direct\n`skillsSelectionDigest()` helper compute exclusively from detached snapshots,\nso caller code cannot rotate a value between validation, identity, and output.\n\nJSON Schema success is only the portable structural gate. Runtime validation\nalso checks a real exact UTC instant, unique skill names, skill-array/summary\nagreement, per-skill category equality, aggregate file/script/resource totals,\nand redacted-alias coverage. The root schema comment lists these runtime-only\nrules.\n\nEvery selected skill names its source lane explicitly:\n\n- `name_kind: \"reported\"` accepts only a portable lowercase hyphenated name.\n- `name_kind: \"redacted_alias\"` accepts only the exact `<redacted-N>`\n  placeholder emitted by the upstream inspector, with `N` bounded to\n  `1..4096` and covered by the report redaction count.\n\nNever recover or substitute the concealed original. The kind is bound into\nselection, skill-snapshot, relation, and evidence identity.\n\n`source.inspector_revision` accepts only a 40- or 64-character lowercase hex\nshape. It is identity-bearing caller input, not proof that a Git object exists\nor that an `@agenttool/skills` artifact was built from it. Plans therefore\nproject `inspector_revision_provenance: \"caller_supplied_unverified\"` and report\n`limitations.inspector_revision_verification: \"not_performed\"`.\n\nIt accepts no skill bodies, descriptions, prompts, paths, issue messages,\nrequirement names, identities, model output, scores, ranks, XP, credentials,\nor permission grants. It does not inspect files, interpret Nen vows or\nabilities, authenticate a publisher, evaluate safety or truth, persist data,\nrun embeddings/models, call a network, or authorize an action. A content\ndigest identifies inspected bytes; it is not a signature or approval.\n\nKAKIN-native Nen ability manifests remain a separate, non-substitutable\nevidence lane. DeepSeek and Hugging Face inference belong in an optional\nsanitizing proposal sidecar; their output must never become canonical\nYUTABASE truth, and raw/private skill content should not be sent remotely.\n\n## Example\n\n```ts\nimport { planSkillsInspection } from \"@agenttool/skills-yutabase\";\n\nconst plan = planSkillsInspection(\n  {\n    $schema: \"https://agenttool.dev/schemas/skills-yutabase-input-v0.1.schema.json\",\n    protocol: \"agenttool.skills-yutabase-input/v0.1\",\n    project_id: \"11111111-2222-4333-8444-555555555555\",\n    recorded_at: \"2026-08-01T12:00:00.000Z\",\n    source: {\n      kind: \"agenttool.skills.inspection\",\n      report_schema: \"urn:agenttool:skills:inspection:v0.1\",\n      report_schema_version: \"agenttool.skills/inspect-v0.1\",\n      report_digest: \"sha256:\" + \"a\".repeat(64),\n      report_digest_semantics: \"agenttool.skills/report-stable-json-sha256-v1\",\n      report_valid: true,\n      inspector_name: \"@agenttool/skills\",\n      inspector_version: \"0.3.0\",\n      inspector_revision: \"b\".repeat(40),\n      mode: \"read-only\",\n    },\n    selection_summary: {\n      skills: 1,\n      files: 2,\n      scripts: 0,\n      resources: 1,\n      errors: 0,\n      warnings: 0,\n      redactions: 0,\n    },\n    skills: [{\n      name_kind: \"reported\",\n      name: \"nen-vow-forge\",\n      content_digest: \"sha256:\" + \"c\".repeat(64),\n      file_count: 2,\n      script_count: 0,\n      resource_count: 1,\n    }],\n    authority: { automatic_action: \"never\", grants: [] },\n  },\n  { claimant: \"urn:example:private-skills-projector\" },\n);\n```\n\nThe plan contains intentions only. The existing Correspondence projector does\nnot apply this book. See `PERSISTENCE-CONTRACT.md` before designing a durable\nprivate sidecar. `recorded_at` and the claimant are claim metadata only: they\ndo not participate in IDs or immutable card fields. The caller-supplied\ninspector revision does participate in inspection identity, without becoming\nverified provenance.\n\n## Development\n\n```sh\nbun install --frozen-lockfile\nbun run ci\nnpm pack --dry-run --ignore-scripts\n```\n\nZero runtime dependencies. Apache-2.0. Publishing is a separately authorized\nprotected workflow; importing or testing this package does not publish it.\n","readmeFilename":"README.md","_rev":"1-ae733de6edf1792f4f36866f1109d7a7"}