← Corpus / lossless-monorepo / agent-skill

New skill (gh-cli-projects-tasks-conventions), new credibility-ingest routine, and three skill updates from real-world incidents

A premature-on-purpose new skill for gh project task creation — codifying just two conventions (compose with pseudomonorepos to find the right repo, link to context-v files via clickable GitHub URLs) so they don't drift while the rest emerge. Plus a company-anchored credibility-ingest routine that inverts the crawl-fetch-ingest cascade so a fundraising deck can render its backers legibly. Plus three updates born from real incidents: an Astro Knots prerender-vs-auth rule (calmstorm-decks shipped a silent production bypass before we caught it), an audience-cascade cross-reference in git-conventions, and a full rewrite of the content-rollup reference now that two production splashes have implemented it.

Path
agent-skills/changelog/2026-06-05_01.md
Authors
Michael Staton
Augmented with
Claude Opus 4.7 (1M context)
Tags
Skills · GitHub-Projects · GH-CLI · Crawl-Fetch-Ingest · Credibility-Ingest · Astro-Knots · Prerender-Auth-Gap · Content-Rollup · Pseudomonorepos

New skill, new routine, and three skill updates from real-world incidents

Why Care?

Three different threads of work converged into a single coherent batch this week, and the common shape is worth naming up front: every change here came from a concrete moment where the skills tree was either missing a rule (so an agent made the wrong call) or had a rule whose framing didn’t match what we’d actually learned. Nothing here is speculative codification. Each addition has a real incident or a real workflow behind it.

If you’re loading this tree from any sibling repo, the new rules that bite hardest:

  • Auth-gated Astro routes must not be prerender = true. This is now codified in [[astro-knots]] with the production-bypass mechanics drawn out. calmstorm-decks shipped this hole; the fix is one-line per route, but the rule is “always false unless the route is in the middleware’s public allowlist.”
  • gh project item-create bodies that reference context-v files must use the file’s own repo URL, not the parent monorepo path. New skill: [[gh-cli-projects-tasks-conventions]]. The submodule trap is a 404, not a redirect.
  • crawl-fetch-ingest now has two anchor types. Firm-anchored (the original) and company-anchored (the new one, used for credibility cards on a fundraise deck). Same cascade, different entry point and stop condition.

What’s New?

New skill — gh-cli-projects-tasks-conventions/

A new first-party skill at gh-cli-projects-tasks-conventions/. Premature on purpose — we don’t have many gh project conventions yet, but the two that exist matter enough to record now so they don’t drift while we figure out the rest.

The two behavioral conventions:

  1. Compose with [[pseudomonorepos]] to figure out which repo a local context-v path actually lives in. A file at lossless-monorepo/ai-labs/context-v/explorations/X.md does NOT live in the lossless-monorepo repo on GitHub — it lives in ai-labs, which is submoduled. Tasks that point at parent-monorepo paths produce 404s.
  2. Task bodies are, primarily, the clickable GitHub URL(s) to the context-v files the task references. Not a prose summary. The link is the point — collaborators may not have the full tree cloned; the click has to work.

The skill ships a shell recipe for building the URL correctly (cd into the file’s directory, git rev-parse --show-toplevel for the right repo root, git remote get-url origin for the right GitHub URL, git rev-parse --abbrev-ref HEAD for the right branch tier per [[pseudomonorepos]]‘s development / main / master model), plus practical gh project item-create and item-edit recipes including bulk task creation from spec sections via anchor links.

Open seams listed in the skill (so future-us doesn’t have to rediscover what was deferred): status discipline, priority discipline, project layout (per-app vs per-engagement vs per-quarter), custom field conventions, iteration / sprint conventions, cross-app project rollups, auto-archival rules.

New routine — crawl-fetch-ingest/routines/investor-credibility-ingest.md

The crawl-fetch-ingest skill grew a second anchor type. The original walk is firm-anchored: one VC firm → its team → its portfolio → those portcos’ CEOs. The new walk is company-anchored: one operating company → its list of backer firms → each backer’s team + portfolio, stopping there.

Why the inversion: when an operating company is fundraising and its deck names backers most readers haven’t heard of, the rendering layer needs cheap-to-fetch credibility signals per backer — partner photos that say “real people, not a brand,” and portfolio logos that say “if those companies trust this firm, this round is in good company.” Walking down to portco CEOs at credibility-card distance adds nothing; logos do the work.

The routine writes to data/investors/{firm-slug}/ so it can coexist with data/team/ (the operating company’s own employees) and data/firms/{firm-slug}/ (if the project ALSO ran the firm-anchored walk on a specific VC). All three directories living in the same project is the expected fundraise-repo shape.

The skill’s main SKILL.md picked up a “Two anchor types” section that names both walks as first-class and points at the routine for the new one. Description was updated to surface the new triggers (“ingest our backers”, “credibility ingest”, “make these investors legible to readers”).

Update — astro-knots/SKILL.md — auth-gated routes must not be prerendered

A new section codifying a hole calmstorm-decks shipped: /play/variant/[variant].astro and /play/section/[slot].astro were prerender = true with getStaticPaths() enumerating variants. Under output: "server" with middleware-based auth, prerendered routes go around the SSR runtime entirely — the CDN serves static HTML, middleware never runs, the auth gate is invisible, anyone with the URL gets in.

The dev-mode symptom was sneakier than the production hole: prerendered routes in dev with output: "server" do run through middleware, but the request context Astro hands to that middleware doesn’t surface the inbound Cookie header reliably. The middleware reads cookies.get("session") → undefined → bounces to /access, even though the browser is correctly sending the cookie. We saw “login works once, then loops” — looks like a cookie bug, is actually a prerender bug.

The section ships:

  • An ASCII diagram of where the gate runs (and doesn’t) in each mode
  • A table mapping route type to required prerender value
  • A sweep instruction: grep every export const prerender = true and cross-reference against the middleware’s PUBLIC_PREFIXES; anything prerendered AND gated is a silent production bypass
  • A pointer to the realized example in dididecks-ai/changelog/2026-05-17_02.md for the full debugging trace

The skill’s “Default behavior” table also picked up a new row: “Add prerender = true to a route” → refuse unless the route is in the middleware’s public allowlist.

Update — git-conventions/SKILL.md — commit messages serve four audiences

A new section ties commit messages to the same four-audience cascade [[changelog-conventions]] codifies for README, changelog entries, and release narratives. Commit messages surface publicly via the GitHub commits view, push-time release notes, the parent pseudomonorepo’s rolled-up changelog feed, and search engines — they carry the same discipline: header lands in two seconds for the general audience, first body paragraph explains what and why for nerds passing by, subsequent paragraphs name files and edge cases for nerds paying close attention, the tail carries SHAs and Co-Authored-By for the internal team.

The pre-commit checklist (§5) and body-structure conventions (§4) already encoded much of this in mechanics; the new section adds the framing that makes the mechanics legible — what the cascade is for, not just what shape it takes.

Update — pseudomonorepos/references/content-rollup.md — now implemented, two variants

The content-rollup reference was previously aspirational (“first splash renders local-only content, roll-up is the documented next step, not yet implemented”). It’s now implemented in two production variants as of 2026-05-17, and the reference document was largely rewritten to match.

The two variants:

VariantWhen to useReference impl
GitHub Content APIChildren are git submodules that may NOT be locally checked outcontent-farm/splash (8 plugin submodules)
Local filesystemChildren are always-checked-out workspace siblingsai-labs/splash (4 children, two with apps/ sub-children)

Both produce the same splash/src/rollup/ output shape, so the content-collection setup and page templates are identical downstream.

The other big architectural shift: the original draft assumed live API calls at build time. The current model is deliberate-sync, not live-fetch — pnpm rollup:sync is an explicit step, pnpm build and pnpm dev are pure file IO. The shift eliminated ~60 API calls per build, removed the GITHUB_TOKEN plumbing from CI, and made builds reproducible. The rollup output lives under version control at splash/src/rollup/.

The reference now documents the actual output layout (with provenance frontmatter and the auto-injected “edit at the source” HTML comment), the recursive walk that picks up changelog/releases/<version>.md, the union-loader pattern in src/content.config.ts with lenient zod preprocessors so author-written frontmatter never breaks the build, and the cron-based auto-refresh path.

Update — CANDIDATES.md — maintain-design-systems candidate

A new candidate landed in the future-skills queue: maintain-design-systems — the design-system + component-library view per project. Sibling-in-shape to [[maintain-splash-pages]] and broader than [[maintain-design-md]] (DESIGN.md is one ingredient of this broader practice, not the whole thing).

The candidate codifies a two-surface contract (DESIGN.md for chosen tokens, /dev/* workbench for candidates + current state), the component-library-view discipline (context-v/sitemap/components/ mini-specs with composes: / composed_by: cross-references), the alternates-as-design-history convention (alternates/ directories preserving unchosen candidates), and the multi-audience legibility argument (developer / agent / end client seeing the same surface).

Stubbed in at ai-labs/dididecks-ai/context-v/sitemap/routes/dev-icons.md; promotion to a cross-project skill is deferred until a second project validates the pattern.

Files Changed

context-v/skills/
├── CANDIDATES.md                                          (new candidate: maintain-design-systems)
├── changelog/
│   ├── 2026-05-22_01.md                                   (companion entry for da20229)
│   └── 2026-06-05_01.md                                   (this file)
├── gh-cli-projects-tasks-conventions/                     (new skill)
│   └── SKILL.md
├── crawl-fetch-ingest/
│   ├── SKILL.md                                           (added "Anchor types" section, expanded description, expanded output-layout note)
│   └── routines/
│       └── investor-credibility-ingest.md                 (new routine — company-anchored walk)
├── astro-knots/SKILL.md                                   (added "Auth-gated routes must not be prerendered" section + default-behavior table row)
├── git-conventions/SKILL.md                               (added "Commit messages also serve four audiences" section)
└── pseudomonorepos/
    └── references/
        └── content-rollup.md                              (rewritten — now implemented in two variants, deliberate-sync architecture)

What’s Next

  • Sweep every Astro Knots site with output: "server" and grep prerender = true against the middleware’s public allowlist. calmstorm-decks is fixed; the others need a pass.
  • Promote maintain-design-systems when a second Astro Knots project validates the /dev/* workbench + alternates archive pattern beyond dididecks-ai.
  • Build out the gh-cli-projects-tasks-conventions open seams as conventions emerge — status discipline, priority discipline, project layout. Don’t pre-empt; let real use cases write them.
  • Document a third content-rollup variant if a future splash needs one (e.g., a fully-static no-script fallback for repos with neither submodules nor workspace siblings). The current two-variant model covers everything in the tree today.

Reference

  • [[pseudomonorepos]] — the tree-walking discipline that makes the gh project URL convention correct and that the content-rollup reference document slots inside
  • [[changelog-conventions]] — the four-audience cascade now cross-referenced from [[git-conventions]]
  • [[maintain-splash-pages]] — sibling in shape to the maintain-design-systems candidate; same “every important project benefits from the discipline” framing
  • [[crawl-fetch-ingest]] — parent skill of the new investor-credibility-ingest routine; the two anchor types share the same fetch cascade
  • content-farm/splash and ai-labs/splash — the two production reference implementations of the content-rollup pattern documented this week
  • dididecks-ai/changelog/2026-05-17_02.md — full debugging trace of the calmstorm-decks auth-loop incident that produced the prerender rule