Problem
Intent policy is currently shared through package.json. A user cannot add worktree-local grants or denials without changing committed repository policy. Local state also needs strict Git safety rules so it cannot be silently tracked or hide .intent/hooks.
User outcome
A user can manually create a valid .intent/config.local.json beside the nearest owning package.json. Intent applies it automatically as personal worktree state: local skills can broaden shared defaults, local excludes can add denials, and shared excludes remain final.
Example:
{
"skills": [
"@acme/private-skill"
],
"exclude": [
"@acme/unsafe-skill"
]
}
In scope
- Add
.intent/config.local.json discovery beside the nearest owning package.json as the sole local policy source. Keep package.json as the sole shared committed source.
- Provide reusable guarded local resolver and storage behavior that future installer or review work may consume.
- Require local policy operations to run in a Git worktree. Use only the exact sidecar path in
$GIT_COMMON_DIR/info/exclude; do not ignore .intent/, and preserve .intent/hooks.
- Check that the exact local path is untracked on every local read and write. Reject tracked paths even when
info/exclude contains the path.
- Support a top-level JSON object with optional
skills and exclude fields, where at least one field is present. Parse present fields strictly as arrays of valid strings under the existing selector and exclusion grammars.
- Activate a manually created valid local file automatically. Fail closed when a present local file is tracked, unreadable, malformed, or not exactly ignored.
- Compile shared and local skill selectors independently. For declared shared policy, grant a candidate when either predicate matches. Preserve existing package, exact-skill, wildcard, npm, and workspace semantics.
- Preserve migration behavior when shared
intent.skills is absent and local skills is omitted or []. A non-empty local skills, including ["*"], ends that migration mode.
- Apply shared and local exclusions as final additive denials. Local policy must never restore a skill denied by shared policy.
- Make all policy consumers use the same effective-policy resolver: list, load, stale, support diagnostics, install
--map, and hooks.
Acceptance criteria
- A valid manual
.intent/config.local.json beside the nearest owning package.json is discovered and applied automatically in a Git worktree.
- The local file is accepted only when the exact path is untracked and exactly ignored through
$GIT_COMMON_DIR/info/exclude; the check applies to both reads and writes.
.intent/hooks remains usable, and the implementation never ignores .intent/ as a whole directory.
- A tracked, unreadable, malformed, or not-exactly-ignored present local file fails closed with actionable diagnostics.
- The local object rejects unknown top-level fields, accepts only optional
skills and exclude, requires at least one of them, and validates each present array under existing selector or exclusion rules.
- Shared and local selector sets are compiled independently. For declared shared policy, a candidate is granted when either set matches without changing package, exact-skill, wildcard, npm, or workspace semantics.
- Shared and local exclusions both deny matching candidates after grant selection. A shared exclusion cannot be bypassed locally.
- When shared
intent.skills is absent, omitted or empty local skills preserves current migration behavior. A non-empty local skills, including ["*"], ends it.
list, load, stale, support diagnostics, install --map, and hooks resolve the same effective policy and report local-source provenance where they already report policy diagnostics.
- The work introduces no
.intent/config.json, global local-policy store, new dependency, destination-selection UI, preview, confirmation, package writing, content delivery, locks, hashes, or Git skill-source support.
Related work
Blocked by: None. #219 is completed prior behavior. #220 and #221 may integrate local policy when available but can proceed independently with package.json-only behavior. #222 independent.
#220 owns interactive destination selection if and when it integrates local configuration. #221 owns repeat review if and when it integrates local configuration.
Problem
Intent policy is currently shared through
package.json. A user cannot add worktree-local grants or denials without changing committed repository policy. Local state also needs strict Git safety rules so it cannot be silently tracked or hide.intent/hooks.User outcome
A user can manually create a valid
.intent/config.local.jsonbeside the nearest owningpackage.json. Intent applies it automatically as personal worktree state: local skills can broaden shared defaults, local excludes can add denials, and shared excludes remain final.Example:
{ "skills": [ "@acme/private-skill" ], "exclude": [ "@acme/unsafe-skill" ] }In scope
.intent/config.local.jsondiscovery beside the nearest owningpackage.jsonas the sole local policy source. Keeppackage.jsonas the sole shared committed source.$GIT_COMMON_DIR/info/exclude; do not ignore.intent/, and preserve.intent/hooks.info/excludecontains the path.skillsandexcludefields, where at least one field is present. Parse present fields strictly as arrays of valid strings under the existing selector and exclusion grammars.intent.skillsis absent and localskillsis omitted or[]. A non-empty localskills, including["*"], ends that migration mode.--map, and hooks.Acceptance criteria
.intent/config.local.jsonbeside the nearest owningpackage.jsonis discovered and applied automatically in a Git worktree.$GIT_COMMON_DIR/info/exclude; the check applies to both reads and writes..intent/hooksremains usable, and the implementation never ignores.intent/as a whole directory.skillsandexclude, requires at least one of them, and validates each present array under existing selector or exclusion rules.intent.skillsis absent, omitted or empty localskillspreserves current migration behavior. A non-empty localskills, including["*"], ends it.list,load,stale, support diagnostics, install--map, and hooks resolve the same effective policy and report local-source provenance where they already report policy diagnostics..intent/config.json, global local-policy store, new dependency, destination-selection UI, preview, confirmation, package writing, content delivery, locks, hashes, or Git skill-source support.Related work
Blocked by: None. #219 is completed prior behavior. #220 and #221 may integrate local policy when available but can proceed independently with package.json-only behavior. #222 independent.
#220 owns interactive destination selection if and when it integrates local configuration. #221 owns repeat review if and when it integrates local configuration.