github rebelytics/one-skill-to-rule-them-all v3.5.0
v3.5.0: test-week merge, this week's reports folded in, v3.6.0 opens

3 hours ago

v3.5.0 merges the release/v3.5.0 test branch after its test week, folds in every report from the past week that could ship without a test period, and opens release/v3.6.0 for the rest. Every change merged here had evidence: either the test week exercised it in real sessions, or a written synthetic check ran and passed. Four branch changes had neither and stay on release/v3.6.0.

From the test branch

  • Session start creates the workspace with one asserting command and records what it created in checkpoints.log.
  • The id snippet lists ids without ls, guards the listing and writes the id floor last; the scan and the archival sweep run as one awk pass instead of a process per file.
  • The session-start scan lists every observation log beside the pinned one, flags more invalid header shapes (including a colon in an unquoted list entry) and covers archive/; a refused scan has a flat command ladder.
  • Step 6 runs the staging gate on any non-empty staging root.
  • A scheduled review writes a started marker, and a run that died after its first call is reported as such.
  • Every observation carries commands_verified:.
  • Review Steps 1 and 6 keep the file list on disk and compare it with comm; Step 1 counts headers that parse but do not conform.
  • A stop hook can run the per-task backstop on a harness event.
  • Caller-owned sessions skip the reporting steps and never run the review; a dispatched subagent writes nothing.
  • Session start names the installed version, and the validator holds the field.
  • Staging resolves a symlinked live path; the review ends with three next steps in chat and the full decision list in a record.
  • The activation block and the hook name the only observation write path; the sibling check runs a bounded project-scope sweep before claiming absence.
  • Attribution moves into the frontmatter and a one-line footer, the network rule is scoped to two user-started exceptions, and the README explains the name.

Review rounds since the branch was cut

  • The validator fails when the core line ceiling sits more than three lines above the core, quotes an unquoted name: when packing, and skips fenced code at any indentation.
  • One canonical frontmatter normaliser for comparing staged and installed copies.
  • Compile checks use PYTHONPYCACHEPREFIX; subagent briefs carry an explicit delete scope and the parent snapshots the staging tree.
  • Starter principles 28 and 29; several wording fixes ("silently", "maintained by someone else", staged copies).

This week's reports

  • Pre-flight reads closing comments before judging PR acceptance, and compares cited upstream text with HEAD every time.
  • Skill names are written as the skill listing shows them; an actioned resolution names where the fix lives; a summary names only ids a create printed.
  • new-observation.sh is run with bash and committed executable; the release workflow runs the repository checks before packing.
  • Validator: a quoted name with a trailing comment reads like PyYAML; script paths in command position are checked; an unquoted description may not contain a space before #; a verdict is reached when the console cannot encode the output.
  • Under a write allowlist, the workspace roots are created at install; a re-anchor moves the whole workspace root.
  • The instrument guard questions a populated result too; extending an entry re-checks its title.
  • Shipped scripts are verified with hostile tests; Step 4's starter-set writes are the maintainer's; the missing-reference-file rule is stated in the core.
  • Hand-over fences carry no info string; installs and process state do not cross the package boundary; a Windows note on what reaches the shell; entries are UTF-8 without a byte order mark.
  • A barrier counts once it is armed; the authoring load triggers on the file being written; an approved step the tool layer refuses is handed over, not retried; a draft's claims are checked against the record.
  • Activation states the per-session cost of loading the skill and the adopter's trade.
  • Fix: a zero-byte observation file no longer blocks every later write.
  • README: how the skill differs from project memory, a quick install with the activation step, the skills CLI named and installs stated as a lower bound, where a scheduled review's changes go. Markdown now counts in the repository's language statistics.

On release/v3.6.0 for a test week

The read-only mode path, the skipped-start-up-step report, the fresh-install evidence pass and the "not installed" probe; the starter-set and upstream-issue offers; denial and classifier-objection handling; untrusted issue and PR text; pack-last with a round-trip check; atomic id claims; numbered-file guards and lost-entry reporting; a pre-tool hook for the write path; routing before the presence check; version-control metadata in a staged skill; Windows drive-letter paths; folderless sessions; the drift audit; principle headings at session start; missing bundle files; the clipboard route; the far-side recipe; a write gate for skill files; byte-order-mark stripping; staging hooks like skills; and the session-start scan shipped as scripts/session-start-scan.sh instead of an inline block.

Thank you

This release credits 26 people as co-authors: @tldah4558-prog, @minorum, @dispather, @qveys, @notbucki, @bonatoriccardo, @psycoban, @juniordurant, @jnrod03-rgb, @chibuzorokoh, @agerescue, @LorisBaeriswyl, @Akki-97, @zulafcb2808-png, @xgboosted, @willdarbey123-netizen, @voodoohop, @thobi1987-prog, @rikiyanai, @moshopping, @lechnir3, @itsdaniik, @Zoukki, @Spealy, @MiltonSilvaJr and @Bob426.

Don't miss a new one-skill-to-rule-them-all release

NewReleases is sending notifications on new releases.