Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
4e699c8
chore(store): record approved resource refresh and release
b10x-bot[bot] Oct 5, 2026
92f498e
Update Connectors guidance and install current source releases
b10x-bot[bot] Oct 5, 2026
9ef9852
merge: refresh Connectors resources and source installation
b10x-bot[bot] Oct 5, 2026
96fe417
Verify current CLI contracts and maintained upstream pins
b10x-bot[bot] Oct 5, 2026
2960c45
merge: verify maintained release pins and executable examples
b10x-bot[bot] Oct 5, 2026
363ae4c
Refresh ESS capabilities and validate current Rust tutorials
b10x-bot[bot] Oct 5, 2026
debe330
merge: refresh ESS guidance and migrate runnable tutorials to Rust
b10x-bot[bot] Oct 5, 2026
a83926e
Clarify the admitted related-guard lifecycle combinations
b10x-bot[bot] Oct 5, 2026
e7f8860
Close command parsing and aborted Rust trial verification gaps
b10x-bot[bot] Oct 5, 2026
49d751b
merge: qualify related-guard compatibility with executable probes
b10x-bot[bot] Oct 5, 2026
d048af9
merge: close verifier false-green cases
b10x-bot[bot] Oct 5, 2026
b77158d
Keep ESS skill version claims in verification metadata
b10x-bot[bot] Oct 5, 2026
2c3c527
merge: keep release verification pins out of skill prose
b10x-bot[bot] Oct 5, 2026
6fb86a0
Resolve ESS trial ambiguities with validated modeling guidance
b10x-bot[bot] Oct 5, 2026
ac35d12
merge: clarify ESS limits and Rust tutorial setup from trials
b10x-bot[bot] Oct 5, 2026
7e92b1b
Match complete upstream pin identifiers
b10x-bot[bot] Oct 5, 2026
b7d22e7
merge: match complete eval version identifiers
b10x-bot[bot] Oct 5, 2026
81aee4e
feat: refresh current resources and repair frozen marketplace upgrades
b10x-bot[bot] Oct 5, 2026
92745de
Reuse setup release evidence and clarify ESS system prefixes
b10x-bot[bot] Oct 5, 2026
519f4b0
merge: reuse resolved ESS versions and clarify domain prefixes
b10x-bot[bot] Oct 5, 2026
29767c7
test: record current CLI verification and Rust trial baselines
b10x-bot[bot] Oct 5, 2026
76a18f4
Apply tutorial trial feedback and record release verification
b10x-bot[bot] Oct 5, 2026
fe26c80
Verify managed wave and preserve safe trial recovery
b10x-bot[bot] Oct 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
127 changes: 59 additions & 68 deletions .agents/skills/following-upstream/SKILL.md
Original file line number Diff line number Diff line change
@@ -1,87 +1,78 @@
---
name: following-upstream
description: Bring this repository up to date with everything it takes from other repositories — the aep, ess, worktree, metaharness and connectors releases its plugins drive, the workflows pinned by commit, and the issues its skills work around. Use when asked to check for upstream releases, sync or refresh agentplugins, follow a new release of aep or ess, or when the Tools check fails with "is newer than verified.json". Run it on a schedule.
description: Refresh Agentplugins against upstream CLI releases, workflow and package pins, and resolved issues. Use for an upstream review, a new dependency release, or a Tools check reporting an unverified release.
---

# Following upstream

This repository teaches agents to use CLIs it does not build. Every release of one of them can
rename a command, change a format, fix a bug a skill works around, or add something worth teaching.
This skill is the loop that finds those changes and carries them here: detect, read, update,
verify, release, then follow the change downstream.

## 1. Detect

```console
cargo run --locked --bin agentplugins-check -- upstream > ~/.cache/agentplugins-upstream.md
cargo run --locked --bin agentplugins-check -- upstream
```

The report has three sections, and ends with `<n> item(s) moved.` A run with 0 moved items ends
this skill: report that and stop.
Read every reported release, pin and cited issue. Use published releases for CLI compatibility;
a newer source commit alone does not establish a released capability. A zero-movement report still
requires any requested behaviour review: command existence cannot prove that a skill teaches the
current semantics.

| section | moved means | where the pin lives |
|---|---|---|
| Releases | a newer release than the pin, with its `CHANGELOG.md` sections since the pin | `verified.json` (aep, ess, worktree), `.github/workflows/eval.yml` (metaharness), the `integrating` skill (connectors) |
| Workflow pins | `main` of a `beyond10x/*` repository is past the commit a workflow uses | `.github/workflows/*.yml` |
| Cited issues | an issue a skill or page cites is closed | the file that cites it |
The maintained inputs include `verified.json`, the eval tool versions in `.github/workflows/eval.yml`,
the AEP protocol revision in `.engineering/project.yaml`, the Docs System dependency in
`website/package.json` and its lockfile, and hand-written workflow pins. Generated documentation
workflow pins belong to Atlas reconciliation; report their drift separately.

## 2. Read, and sort every change
## 2. Classify and update

Read each changelog section in full. Sort each entry into one row; an entry may land in two.
Work in a managed tree from `origin/main`, with an AEP artifact recording the scope and acceptance.
For every consumer-visible changelog entry, name the owning resource and the required change:

| kind | what to do here |
| Change | Resource and completion criterion |
|---|---|
| a command, flag or verb removed or renamed | fix every spelling in `plugins/` and `website/docs/`; `tools` names each one it no longer finds |
| a format, store or protocol version | the skills' version tables and upgrade paths (`aep:upgrade`, `ess:specifying` `later-formats.md`, the store section of `aep:planning`) |
| a new capability an agent would use | the skill that owns the activity (`ess:hardening`, `ess:testing-conformance`, `aep:implementing` …), one paragraph, with the command |
| a fix for something a skill works around | remove the workaround when the release carries the fix; cite the release |
| internal only (tests, refactors, CI) | nothing |

For a **closed cited issue**, read the closing change and remove or rewrite the text that cites it.
For a **moved workflow pin**: a file that starts `Generated by atlas docs reconcile` is not edited
here; it moves when Atlas reconciles. Report it. A hand-written workflow moves by one commit that
names the new pin and what changed.

For **connectors**, the `integrating` skill deliberately targets the v1 line (`v0.7.2`) while the
newest releases are the v2 lineage. A moved connectors release is a decision for the operator, not
an edit: report it with its changelog, once.

## 3. Update

In a managed worktree from `origin/main`. The rules of `AGENTS.md` hold: no CLI version in plugin
text (R5), grouped verbs, no retired names. Edit what § 2 sorted; do not move `verified.json` yet.
A store `protocols:` pin in `.engineering/project.yaml` moves to the new aep release commit.

## 4. Verify

1. `cargo run --locked --bin agentplugins-check -- tools` — every spelled command against the newest
releases, the ESS syntax example, and the ESS tutorial's specification, suite and `go test`.
2. A trial round per [`improving-by-trial`](../improving-by-trial/SKILL.md): the ESS trials and
`ess-tutorial` for a new release of ess, `aep-backlog` and `aep-tutorial` for a new release of aep. A run
worse than `trials/baseline.json` is triaged there; a defect in the other repository becomes a
`trial-finding` issue there, and a workaround here that cites it.
3. Then, and only then, `verified.json` moves to the new releases.
4. `task check` and `task site-build`.

## 5. Release

The release in `AGENTS.md` § Publishing: `CHANGELOG.md` names the releases verified against and what
changed for an agent; versions agree; bot commits, a pull request, merge on the required checks, a
bare annotated tag, then verify the release run, the GitHub Release, its assets and `SHA256SUMS`.

## 6. Downstream

- **The website's Start page** pins agentplugins, aep and ess releases
(`beyond10x/website` `data/experiences.json`, its validator and contract test). Move them in one
website pull request: lock only the `agentplugins` source beside `main`'s lock, commit it, render
`atlas docs snapshot` from a managed Atlas checkout at `origin/main`, and pass `npm run gate`.
- **Publication.** After the merge, the next Atlas "Publish unified documentation" run must pass.
One broken link anywhere fails every source's publication; read the failed run's log before
assuming the delay is Atlas's.
- Tell whoever asked for the release (a peer session, an issue) which version carries it.
| command, option or response changed | skills, examples and website instructions use the released contract |
| new source, suite or report format | syntax and conformance references explain its constructs and each target's actual limits |
| new capability | the owning activity links a validated example and its resulting observation |
| released fix | obsolete workaround removed; any still-relevant requirement retained |
| internal implementation only | record why no instruction changes |

A closed issue is a prompt to inspect its released fix, not evidence that the whole paragraph is
obsolete. Preserve dated transcripts as historical observations and add a current runnable path.

Connectors follows its current release lineage. Use the release's assets and source metadata to
select installation; a source-only release needs the catalog's Cargo route and its actual compiler
requirement. Validate the complete setup, metadata, acquisition and invocation contracts together.

Update the eval AEP and Metaharness pair together: the planning executable must match the AEP
library revision linked by the runner. A successful top-level `--help` cannot establish this.

Review a hand-written shared workflow pin's diff before updating it. A file headed `Generated by
atlas docs reconcile` is left to its owner. Changing a package pin also updates its lockfile and
runs the documentation build.

## 3. Verify

1. Run `agentplugins-check tools`. Repair every failure before treating a release as verified.
Distinguish executed release binaries from source-contract checks in the output and evidence.
2. Run the isolated trial round in [improving-by-trial](../improving-by-trial/SKILL.md), including
the current ESS tutorial. Reproduce reported defects, fix their owning resource, and rerun the
affected trial. Product defects become bot-owned `trial-finding` issues under that skill.
3. Record the exact releases in `verified.json` only after their required checks and trials pass.
4. Run `task check` and `task site-build` on the integrated candidate; record outputs against its
exact commit. Keep the source, README, AGENTS and public manifest consistent.

## 4. Release

Follow `AGENTS.md` Publishing: align workspace, plugin and skill versions and the changelog; publish
bot-authored commits and a reviewed PR; tag the green main commit; verify that exact tag's checks;
verify the retained archives, checksums and setup guide; publish through the bot and verify the
GitHub Release and its required assets. A pushed tag with unfinished checks or uploads is queued.

An ordinary source release ends there. Documentation publication proceeds through the existing
passive producer and reconciler. Report documentation as pending unless publication was actually
verified. Website source locks, consumer pins, shared rendering releases and facade deployments
belong to their own explicitly requested work.

## Report

Per moved item: what moved, what changed here (commit), or why nothing did. Then the trial numbers
against the baseline, the release and its verification, the issues filed, and anything left for the
operator (a connectors lineage decision, an Atlas-generated pin).
Name each changed resource and its release evidence, trial results against the baseline, the exact
published release and artifacts, and remaining owner-managed pin drift. Separate source release
completion from documentation publication.
38 changes: 32 additions & 6 deletions .agents/skills/improving-by-trial/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,10 @@ release. It also unsets `ANTHROPIC_API_KEY`, `TMPDIR` and `TMPPREFIX`. A defined
fixture it needs (a small service, a `TODO.md`, an OpenAPI document) under `work/`, and commit it
there with `git` when the trial needs history or a remote.

Setup refuses an existing sandbox: it may hold leased trees or the only recovery copy of trial
work. Use a fresh `NAME` for a rerun, for example `task trial:run TRIAL=ess-tutorial NAME=ess-tutorial-rerun`,
or complete the cleanup procedure below before reusing its name.

To trial the released version instead, remove `home/.local/bin/b10x` and unset `B10X_MARKETPLACE`
in `env`; the agent then follows `SETUP.md` from the release.

Expand Down Expand Up @@ -53,6 +57,9 @@ task trial:run NAME=<name> PROMPT='<the user sentence>' [DIR=<subdirectory of wo
The task copies the operator's credentials in (mode 600), runs `claude -p` with the sandbox's
`env`, `--strict-mcp-config` (no MCP server, including the account's claude.ai connectors) and
stream-json output into `run.jsonl`, and deletes the credentials when it finishes. The sandbox
root is passed as `--add-dir`, so managed worktrees below its isolated home are accessible as
working directories without granting access to the operator's home.
The sandbox
`PATH` has `cargo` and `go`, and `go` is an allowed tool, so a trial can build and test an
implementation.

Expand Down Expand Up @@ -102,7 +109,8 @@ agentplugins-check trial-report <sandbox>/run.jsonl --trial <name> [--baseline t
| `synthesis` | `N scenario(s) … M refusal(s)` in the last `ess verify conform synthesize` output |
| `unmapped` | `UNMAPPED:` markers in the YAML files the run wrote, read from disk, not from its prose |
| `outputs` | which of the definition's `outputs` exist (a directory counts when it is not empty) |
| `go_test` | passed, failed and skipped tests of the last `go test` (`-v` or `-json`); a package that does not build counts as a failure |
| `go_test` | historical Go trials: passed, failed and skipped tests of the last `go test` (`-v` or `-json`); a package that does not build counts as a failure |
| `cargo_test` | current Rust trials: passed, failed and ignored tests from the last `cargo test`; the implementation also reports executed conformance scenarios |

A trial reports the measures its definition lists; without `--trial`, an ad-hoc run gets every
measure but `outputs`. With `--baseline` it exits 1 when a measure got worse than the trial's entry:
Expand All @@ -120,6 +128,11 @@ The numbers say what happened, not why. From `run.jsonl`, also collect:
| waste | calls repeated, files read twice, commands that failed and were retried unchanged |
| the outcome | the verbatim `validate` / `generate` / plan output it pasted |

A zero process exit or a `success` result can still say the agent is waiting for background work.
Confirm that the requested workflow actually finished. If necessary, resume the same isolated
session after its task notification, preserve both transcripts and repeat the isolation check;
do not accept a waiting message or permissive metric summary as completion.

Before writing a finding into a skill, reproduce each claimed behaviour with the released CLI. A
trial agent's explanation of a refusal is a hypothesis.

Expand Down Expand Up @@ -154,27 +167,40 @@ and the fix is in a release, not when the issue closes.

Each round runs every trial in `trials/`: 4 ESS trials (`ess-new`, a new specification;
`ess-retrofit`, an existing service; `ess-pipeline`, generation plus a synthesized suite;
`ess-full-package`, every output plus a Go implementation held to the synthesized suite), and
`aep-backlog`, `worktree-onboarding` and `upgrade-seeded`. Change the domains and fixtures each
`ess-full-package`, every output plus a Rust implementation held to the suite), the current
`ess-tutorial`, and `aep-backlog`, `aep-tutorial`, `worktree-onboarding` and `upgrade-seeded`.
New executable fixtures use Rust. Change the domains and fixtures each
round so the agents cannot copy the previous answer from the skills; a changed trial starts a new
baseline entry.

### Every product release is re-verified

`verified.json` names, per CLI (`aep`, `ess`, `worktree`), the release the skills were last
`verified.json` names, per tracked CLI, the release the skills were last
verified against. The daily `agentplugins-check tools` run fails with one line per CLI whose newest
release is newer. Then:

1. Run `agentplugins-check tools` and fix every command it reports.
2. Run an ESS trial round (at least `ess-full-package`) against the new release.
2. Run the affected product's isolated trials against the new release. An ESS update includes
`ess-full-package` and `ess-tutorial`; an AEP update includes `aep-backlog` and `aep-tutorial`.
A complete resource refresh runs the whole round. Preserve historical baseline entries and
record changed Rust trials under their actual measurement keys.
3. Set the CLI to the new release in `verified.json` in the same pull request.

## 7. Clean up

`trial:run` deletes the credentials it copied. When the round is released, check that no
credentials are left in any sandbox and remove the sandboxes:
credentials are left in any sandbox. Retain its run logs and meaningful generated work. Inspect
each sandbox's own Worktree registry and Git linked trees, with that sandbox's environment; never
substitute the operator's registry. Follow the Worktree skill to archive unpublished work, end
each owner's leases, finish trees and apply GC only to exact reviewed IDs. Adopt legacy linked
trees through the CLI before retiring them. Copy recovery archives outside the sandbox and verify
them before deleting their original container.

Only after every linked tree is retired and recovery is retained may the sandbox itself be
removed. AEP's read-only protocol snapshots may require making that exact sandbox writable first:

```console
ls /var/tmp/b10x-trials-$USER/*/home/.claude/.credentials.json
chmod -R u+w /var/tmp/b10x-trials-$USER/<name>
rm -rf /var/tmp/b10x-trials-$USER/<name>
```
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"at": "2026-10-05T20:28:11Z",
"actor": "human:timo",
"artifact": "dependency-blocker:metaharness-links-aep-0-55",
"kind": "dependency-blocker",
"revision": 2,
"change": {
"change": "evidence",
"kind": "test_result",
"source": "Metaharness 0.9.1 published Cargo.toml links AEP 0.68.0; source-matched eval pair selected",
"reference": "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/beyond10x/metaharness/blob/0.9.1/crates/metaharness-aep/Cargo.toml"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"at": "2026-10-05T21:47:48Z",
"actor": "human:timo",
"artifact": "task:refresh-resources-release",
"kind": "task",
"revision": 6,
"change": {
"change": "evidence",
"kind": "test_result",
"source": "Agentplugins 0.20.0 local gates, isolated trials and independent adversarial verification",
"reference": "changes/0.20.0-verification.md"
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -2,11 +2,13 @@
format: aep.planning-md/3
id: dependency-blocker:metaharness-links-aep-0-55
kind: dependency-blocker
status: open
status: cleared
title: metaharness links aep 0.55.0, so no eval case can be recorded beside aep 0.64.0
relations:
- blocks: story:plugin-eval-cases
revision: 2
revision: 3
transitions:
- {from: "open", to: "cleared", at: "2026-10-05T20:28:11Z", actor: "human:timo", revision: 3, decided_on: {"recorded":{"test_result":1}}}
---
# Blocker: metaharness links aep 0.55.0

Expand Down
Loading
Loading