← Corpus / lossless-monorepo / agent-skill
New skill (gh-cli-projects-tasks-conventions), new credibility-ingest routine, and three skill updates from real-world incidents
A premature-on-purpose new skill for gh project task creation — codifying just two conventions (compose with pseudomonorepos to find the right repo, link to context-v files via clickable GitHub URLs) so they don't drift while the rest emerge. Plus a company-anchored credibility-ingest routine that inverts the crawl-fetch-ingest cascade so a fundraising deck can render its backers legibly. Plus three updates born from real incidents: an Astro Knots prerender-vs-auth rule (calmstorm-decks shipped a silent production bypass before we caught it), an audience-cascade cross-reference in git-conventions, and a full rewrite of the content-rollup reference now that two production splashes have implemented it.
- Path
- agent-skills/changelog/2026-06-05_01.md
- Authors
- Michael Staton
- Augmented with
- Claude Opus 4.7 (1M context)
- Tags
- Skills · GitHub-Projects · GH-CLI · Crawl-Fetch-Ingest · Credibility-Ingest · Astro-Knots · Prerender-Auth-Gap · Content-Rollup · Pseudomonorepos
New skill, new routine, and three skill updates from real-world incidents
Why Care?
Three different threads of work converged into a single coherent batch this week, and the common shape is worth naming up front: every change here came from a concrete moment where the skills tree was either missing a rule (so an agent made the wrong call) or had a rule whose framing didn’t match what we’d actually learned. Nothing here is speculative codification. Each addition has a real incident or a real workflow behind it.
If you’re loading this tree from any sibling repo, the new rules that bite hardest:
- Auth-gated Astro routes must not be
prerender = true. This is now codified in [[astro-knots]] with the production-bypass mechanics drawn out.calmstorm-decksshipped this hole; the fix is one-line per route, but the rule is “alwaysfalseunless the route is in the middleware’s public allowlist.” gh project item-createbodies that reference context-v files must use the file’s own repo URL, not the parent monorepo path. New skill: [[gh-cli-projects-tasks-conventions]]. The submodule trap is a 404, not a redirect.crawl-fetch-ingestnow has two anchor types. Firm-anchored (the original) and company-anchored (the new one, used for credibility cards on a fundraise deck). Same cascade, different entry point and stop condition.
What’s New?
New skill — gh-cli-projects-tasks-conventions/
A new first-party skill at gh-cli-projects-tasks-conventions/. Premature on purpose — we don’t have many gh project conventions yet, but the two that exist matter enough to record now so they don’t drift while we figure out the rest.
The two behavioral conventions:
- Compose with [[pseudomonorepos]] to figure out which repo a local context-v path actually lives in. A file at
lossless-monorepo/ai-labs/context-v/explorations/X.mddoes NOT live in thelossless-monoreporepo on GitHub — it lives inai-labs, which is submoduled. Tasks that point at parent-monorepo paths produce 404s. - Task bodies are, primarily, the clickable GitHub URL(s) to the context-v files the task references. Not a prose summary. The link is the point — collaborators may not have the full tree cloned; the click has to work.
The skill ships a shell recipe for building the URL correctly (cd into the file’s directory, git rev-parse --show-toplevel for the right repo root, git remote get-url origin for the right GitHub URL, git rev-parse --abbrev-ref HEAD for the right branch tier per [[pseudomonorepos]]‘s development / main / master model), plus practical gh project item-create and item-edit recipes including bulk task creation from spec sections via anchor links.
Open seams listed in the skill (so future-us doesn’t have to rediscover what was deferred): status discipline, priority discipline, project layout (per-app vs per-engagement vs per-quarter), custom field conventions, iteration / sprint conventions, cross-app project rollups, auto-archival rules.
New routine — crawl-fetch-ingest/routines/investor-credibility-ingest.md
The crawl-fetch-ingest skill grew a second anchor type. The original walk is firm-anchored: one VC firm → its team → its portfolio → those portcos’ CEOs. The new walk is company-anchored: one operating company → its list of backer firms → each backer’s team + portfolio, stopping there.
Why the inversion: when an operating company is fundraising and its deck names backers most readers haven’t heard of, the rendering layer needs cheap-to-fetch credibility signals per backer — partner photos that say “real people, not a brand,” and portfolio logos that say “if those companies trust this firm, this round is in good company.” Walking down to portco CEOs at credibility-card distance adds nothing; logos do the work.
The routine writes to data/investors/{firm-slug}/ so it can coexist with data/team/ (the operating company’s own employees) and data/firms/{firm-slug}/ (if the project ALSO ran the firm-anchored walk on a specific VC). All three directories living in the same project is the expected fundraise-repo shape.
The skill’s main SKILL.md picked up a “Two anchor types” section that names both walks as first-class and points at the routine for the new one. Description was updated to surface the new triggers (“ingest our backers”, “credibility ingest”, “make these investors legible to readers”).
Update — astro-knots/SKILL.md — auth-gated routes must not be prerendered
A new section codifying a hole calmstorm-decks shipped: /play/variant/[variant].astro and /play/section/[slot].astro were prerender = true with getStaticPaths() enumerating variants. Under output: "server" with middleware-based auth, prerendered routes go around the SSR runtime entirely — the CDN serves static HTML, middleware never runs, the auth gate is invisible, anyone with the URL gets in.
The dev-mode symptom was sneakier than the production hole: prerendered routes in dev with output: "server" do run through middleware, but the request context Astro hands to that middleware doesn’t surface the inbound Cookie header reliably. The middleware reads cookies.get("session") → undefined → bounces to /access, even though the browser is correctly sending the cookie. We saw “login works once, then loops” — looks like a cookie bug, is actually a prerender bug.
The section ships:
- An ASCII diagram of where the gate runs (and doesn’t) in each mode
- A table mapping route type to required
prerendervalue - A sweep instruction: grep every
export const prerender = trueand cross-reference against the middleware’sPUBLIC_PREFIXES; anything prerendered AND gated is a silent production bypass - A pointer to the realized example in
dididecks-ai/changelog/2026-05-17_02.mdfor the full debugging trace
The skill’s “Default behavior” table also picked up a new row: “Add prerender = true to a route” → refuse unless the route is in the middleware’s public allowlist.
Update — git-conventions/SKILL.md — commit messages serve four audiences
A new section ties commit messages to the same four-audience cascade [[changelog-conventions]] codifies for README, changelog entries, and release narratives. Commit messages surface publicly via the GitHub commits view, push-time release notes, the parent pseudomonorepo’s rolled-up changelog feed, and search engines — they carry the same discipline: header lands in two seconds for the general audience, first body paragraph explains what and why for nerds passing by, subsequent paragraphs name files and edge cases for nerds paying close attention, the tail carries SHAs and Co-Authored-By for the internal team.
The pre-commit checklist (§5) and body-structure conventions (§4) already encoded much of this in mechanics; the new section adds the framing that makes the mechanics legible — what the cascade is for, not just what shape it takes.
Update — pseudomonorepos/references/content-rollup.md — now implemented, two variants
The content-rollup reference was previously aspirational (“first splash renders local-only content, roll-up is the documented next step, not yet implemented”). It’s now implemented in two production variants as of 2026-05-17, and the reference document was largely rewritten to match.
The two variants:
| Variant | When to use | Reference impl |
|---|---|---|
| GitHub Content API | Children are git submodules that may NOT be locally checked out | content-farm/splash (8 plugin submodules) |
| Local filesystem | Children are always-checked-out workspace siblings | ai-labs/splash (4 children, two with apps/ sub-children) |
Both produce the same splash/src/rollup/ output shape, so the content-collection setup and page templates are identical downstream.
The other big architectural shift: the original draft assumed live API calls at build time. The current model is deliberate-sync, not live-fetch — pnpm rollup:sync is an explicit step, pnpm build and pnpm dev are pure file IO. The shift eliminated ~60 API calls per build, removed the GITHUB_TOKEN plumbing from CI, and made builds reproducible. The rollup output lives under version control at splash/src/rollup/.
The reference now documents the actual output layout (with provenance frontmatter and the auto-injected “edit at the source” HTML comment), the recursive walk that picks up changelog/releases/<version>.md, the union-loader pattern in src/content.config.ts with lenient zod preprocessors so author-written frontmatter never breaks the build, and the cron-based auto-refresh path.
Update — CANDIDATES.md — maintain-design-systems candidate
A new candidate landed in the future-skills queue: maintain-design-systems — the design-system + component-library view per project. Sibling-in-shape to [[maintain-splash-pages]] and broader than [[maintain-design-md]] (DESIGN.md is one ingredient of this broader practice, not the whole thing).
The candidate codifies a two-surface contract (DESIGN.md for chosen tokens, /dev/* workbench for candidates + current state), the component-library-view discipline (context-v/sitemap/components/ mini-specs with composes: / composed_by: cross-references), the alternates-as-design-history convention (alternates/ directories preserving unchosen candidates), and the multi-audience legibility argument (developer / agent / end client seeing the same surface).
Stubbed in at ai-labs/dididecks-ai/context-v/sitemap/routes/dev-icons.md; promotion to a cross-project skill is deferred until a second project validates the pattern.
Files Changed
context-v/skills/
├── CANDIDATES.md (new candidate: maintain-design-systems)
├── changelog/
│ ├── 2026-05-22_01.md (companion entry for da20229)
│ └── 2026-06-05_01.md (this file)
├── gh-cli-projects-tasks-conventions/ (new skill)
│ └── SKILL.md
├── crawl-fetch-ingest/
│ ├── SKILL.md (added "Anchor types" section, expanded description, expanded output-layout note)
│ └── routines/
│ └── investor-credibility-ingest.md (new routine — company-anchored walk)
├── astro-knots/SKILL.md (added "Auth-gated routes must not be prerendered" section + default-behavior table row)
├── git-conventions/SKILL.md (added "Commit messages also serve four audiences" section)
└── pseudomonorepos/
└── references/
└── content-rollup.md (rewritten — now implemented in two variants, deliberate-sync architecture)
What’s Next
- Sweep every Astro Knots site with
output: "server"and grepprerender = trueagainst the middleware’s public allowlist.calmstorm-decksis fixed; the others need a pass. - Promote
maintain-design-systemswhen a second Astro Knots project validates the/dev/*workbench + alternates archive pattern beyonddididecks-ai. - Build out the
gh-cli-projects-tasks-conventionsopen seams as conventions emerge — status discipline, priority discipline, project layout. Don’t pre-empt; let real use cases write them. - Document a third content-rollup variant if a future splash needs one (e.g., a fully-static no-script fallback for repos with neither submodules nor workspace siblings). The current two-variant model covers everything in the tree today.
Reference
- [[pseudomonorepos]] — the tree-walking discipline that makes the
gh projectURL convention correct and that the content-rollup reference document slots inside - [[changelog-conventions]] — the four-audience cascade now cross-referenced from [[git-conventions]]
- [[maintain-splash-pages]] — sibling in shape to the
maintain-design-systemscandidate; same “every important project benefits from the discipline” framing - [[crawl-fetch-ingest]] — parent skill of the new
investor-credibility-ingestroutine; the two anchor types share the same fetch cascade content-farm/splashandai-labs/splash— the two production reference implementations of the content-rollup pattern documented this weekdididecks-ai/changelog/2026-05-17_02.md— full debugging trace of thecalmstorm-decksauth-loop incident that produced the prerender rule