forked from bai/curriculum-project-hub
feat: make agent roles and skills dynamic
This commit is contained in:
@@ -37,6 +37,16 @@ that cursor is the `result.session_id`; store it in `AgentSession.metadata` as
|
||||
tool surfaces can differ even when the underlying model is the same; `/draft`
|
||||
and `/review` must not resume the same Claude runtime cursor by accident.
|
||||
|
||||
Role definitions are Organization-scoped runtime data. A role bundle selects
|
||||
its default model, system prompt, tool allowlist and installed Agent skill
|
||||
versions. PostgreSQL is authoritative for role composition and skill metadata;
|
||||
skill bytes live in a content-addressed persistent store selected only by the
|
||||
recorded SHA-256 digest. Updating a role or binding skills takes effect without
|
||||
a Hub release or process restart. A change to the role's execution surface
|
||||
(model, prompt, tools, selected skill content) archives its active sessions so
|
||||
the next run cannot resume a provider context created under stale instructions;
|
||||
label and ordering-only changes preserve conversational continuity.
|
||||
|
||||
Environment variables:
|
||||
```
|
||||
ANTHROPIC_BASE_URL=https://openrouter.ai/api
|
||||
|
||||
@@ -122,15 +122,16 @@ The boundary is enforced by the Claude Code SDK's built-in sandbox
|
||||
- `settingSources: []` and strict MCP configuration prevent an untrusted
|
||||
workspace or service-user config from widening tools, hooks, MCP servers, or
|
||||
sandbox paths.
|
||||
- Platform-curated Agent skills are immutable Hub release assets, loaded as a
|
||||
programmatic local plugin from a release-owned path. The sandbox exposes that
|
||||
path read-only, and the SDK receives only plugin-qualified allowlist names
|
||||
through its `skills` option; SDK-bundled skills are disabled. Filesystem
|
||||
setting sources remain disabled, so a
|
||||
project cannot register another skill or widen its tools through `.claude`
|
||||
settings. Requested skill ids are recorded on `run.created`; SDK
|
||||
initialization/results remain the authoritative evidence that loading
|
||||
actually succeeded.
|
||||
- Agent skills are Organization-scoped runtime configuration, not Hub release
|
||||
assets. A controlled host-console installer imports each version into a
|
||||
content-addressed persistent store and records its digest in PostgreSQL. A
|
||||
role selects enabled Organization skills alongside its model, system prompt
|
||||
and tool allowlist. Each run copies only those selected immutable versions
|
||||
into a run-scoped plugin outside the project workspace; the sandbox exposes
|
||||
that snapshot read-only and deletes it after the run. SDK-bundled skills and
|
||||
filesystem setting sources remain disabled, so project `.claude` content
|
||||
cannot register skills or widen tools. Requested skill versions are recorded
|
||||
on `run.created`; SDK initialization remains authoritative loading evidence.
|
||||
- Network: open (see Open Questions).
|
||||
|
||||
`bypassPermissions` is kept (headless server — no interactive prompts); the
|
||||
|
||||
Reference in New Issue
Block a user