workspace-taskboard
Workspace Taskboard
Boundary
Bind one controller to one verified saved local Codex project through
canonical_project_root and versioned host-readback allowed_roots[]. Manage a local
Codex task only when its resolved canonical cwd equals or is a component-aware descendant
of an allowed root. Accept symlinks that resolve inside; reject escapes, parents,
siblings, prefix collisions, projectless tasks, remote/ChatGPT tasks, and unverified
attached folders. Never infer membership from a common ancestor, repository remote, or
title. A different project gets a different controller and control_id.
This Skill is the controller and in-conversation projection. It does not create a Web or Tauri product, modify Codex, inject a sidebar, run a database/service, or manage Claude Code, ZCode, AGY, or other provider sessions. Those providers remain worker-internal run evidence owned by their adapters.