skill-intake-lifecycle
Skill Intake Lifecycle
Treat ~/.agents as the intake tier and authored package repositories as the promoted tier.
Installation is provisional: every third-party skill needs a rationale, a review date, and an
eventual evidence-backed verdict.
Preserve the two sources of truth
~/.agents/.skill-lock.json is owned by npx skills. Read it for mechanical installation facts,
but never edit, reformat, patch, or replace it. Only the CLI may write it.
~/.agents/skill-journal.jsonl is the append-only governance sidecar. Record rationale, review
dates, suite membership, and lifecycle events there. Do not copy lock-owned fields such as
installedAt, updatedAt, skillFolderHash, or localPatch into journal events.
MANDATORY: Before reading or writing journal state, read references/journal-protocol.md completely. It defines the v1 schema, append rules, and canonical queries. Do not invent fields or rewrite earlier lines.