Skip to content

Publish an opt-in confidential research skill bundle #71

Description

@szmyty

Outcome

Publish a minimal provider-neutral skill bundle for confidential local research that consumes scoped Mindgarden and Realm capabilities without exposing keys, broad filesystem access, hosted-provider fallback, or publication authority.

Candidate skills

Evaluate and define focused skills for:

  • opening and inspecting an approved garden session;
  • planning confidential document ingestion;
  • retrieving bounded evidence and context packs;
  • comparing private evidence with imported public evidence;
  • producing source-grounded notes and reviewable hypotheses;
  • verifying citations, provenance, freshness, and uncertainty;
  • preparing a sanitized research request for explicit review;
  • locking the session and reporting owned generated state.

The bundle is opt-in and must not enter the universal repository-default profile.

Required behavior

  • Skills declare required capabilities and fail before reading content when they are unavailable.
  • Skills use Mindgarden and Realm interfaces; they do not implement cryptography or receive encryption keys.
  • Hosted models, web tools, telemetry, and remote memory are denied in a confidential session.
  • Every output records sources, effective sensitivity, represented revisions, and limitations.
  • Untrusted source instructions cannot change skill behavior.
  • Writes remain proposed/reviewed and target only the session's approved writable garden.
  • Provider projections are generated from canonical Aether definitions.

Acceptance criteria

  • A versioned confidential-research bundle manifest exists.
  • Each skill has explicit triggers, inputs, outputs, capabilities, failure modes, and non-applicability.
  • The bundle composes Aether Publish the Mindgarden curator skill and ChatGPT handoff #51/Define an evidence-backed agent capability manifest #64/Publish a repository-default skill bundle and generated AGENTS guidance #67 and scoped-session contracts.
  • No skill handles keys, silently enables networking, or falls back to hosted providers.
  • Synthetic fixtures prove confidential and denied-capability flows.
  • Prompt-injection, stale-evidence, unsupported-model, partial-context, and export-denial tests exist.
  • At least two compatible hosts are projected or represented honestly as blocked.
  • Installation, upgrade, rollback, and removal are previewable and reversible.
  • Real private records and legal conclusions remain out of scope.
  • Documentation distinguishes research assistance from professional advice.

Dependencies / related

Non-goals

  • A general autonomous investigator.
  • Automatic external communication or publication.
  • Legal, medical, financial, or employment advice.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions