Problem
Five skills in the marketplace set disable-model-invocation: true, so an agent can never start them.
The Skill tool refuses with "cannot be used with Skill tool due to disable-model-invocation", and it adds
"Do not replicate this skill's workflow by other means":
| plugin (0.14.17) |
skill |
| aep |
decompose, drive, review-plan, wave |
| worktree |
cleanup |
(aep:drive and aep:wave in 0.14.16 carry the flag too.)
In practice the operator asks an agent in words to do exactly what the skill does, for example "merge
all worktrees, then /worktree:cleanup". The agent cannot load the skill. It cannot follow the skill's
steps by hand either, because the refusal tells it not to. So it has to stop and ask the operator to type
the command, in the middle of work the operator already asked for. That is a hard stop in a headless or
orchestrated run, and friction everywhere else.
The safety the flag is meant to give is already built into the skills' own steps. worktree:cleanup, for
example, says to dry-run and apply only exact ids the operator approved. Those steps hold just as well
when an agent runs them.
Request
- Review every command and skill in the marketplace for agent invocability. The working assumption:
everything a plugin provides is eventually run by an agent.
- Drop
disable-model-invocation wherever the skill's own steps already gate the risky part: an
explicit dry-run, then an operator-approved list, or a proposal the operator approves before anything
is written.
- Where a gate is really needed, put it inside the skill, for example "ask the operator to approve
the table before --apply". Do not put it in the invocation. Then an agent can start the skill, prepare
the evidence, and stop only at the decision.
- Keep an operator-only skill only where there is a reason, and state that reason in its
description. The refusal text should then say what the agent may do instead.
- Add an eval that starts each skill from an agent turn ("the operator asked for X") and checks that
it either runs or stops at an explicit, documented approval gate, never at the invocation.
Problem
Five skills in the marketplace set
disable-model-invocation: true, so an agent can never start them.The Skill tool refuses with "cannot be used with Skill tool due to disable-model-invocation", and it adds
"Do not replicate this skill's workflow by other means":
decompose,drive,review-plan,wavecleanup(
aep:driveandaep:wavein 0.14.16 carry the flag too.)In practice the operator asks an agent in words to do exactly what the skill does, for example "merge
all worktrees, then /worktree:cleanup". The agent cannot load the skill. It cannot follow the skill's
steps by hand either, because the refusal tells it not to. So it has to stop and ask the operator to type
the command, in the middle of work the operator already asked for. That is a hard stop in a headless or
orchestrated run, and friction everywhere else.
The safety the flag is meant to give is already built into the skills' own steps.
worktree:cleanup, forexample, says to dry-run and apply only exact ids the operator approved. Those steps hold just as well
when an agent runs them.
Request
everything a plugin provides is eventually run by an agent.
disable-model-invocationwherever the skill's own steps already gate the risky part: anexplicit dry-run, then an operator-approved list, or a proposal the operator approves before anything
is written.
the table before
--apply". Do not put it in the invocation. Then an agent can start the skill, preparethe evidence, and stop only at the decision.
description. The refusal text should then say what the agent may do instead.
it either runs or stops at an explicit, documented approval gate, never at the invocation.