CtrlK
BlogDocsLog inGet started
Tessl Logo

prompt-contract-operating-primitives

This skill should be used when the user provides a structured prompt contract, acceptance criteria, runbook, SPEC, or automation brief and asks which Claude primitive should own it: prompt, /goal, scheduled task, API tool runtime, agent loop, explicit command, reusable skill, static plan, dynamic workflow, hook, external event push, independent work, coordinated parallelism, cloud routine, headless run, CI, or human review. It normalizes a fail-closed v2.2 operating packet, selects exactly one primary primitive, and records composed primitives separately.

SKILL.md
Quality
Evals
Security

Prompt Contract Operating Primitives

Normalize a structured request into an operating packet, choose exactly one primary primitive, and route implementation to the existing owner skill. Keep all lower-precedence mechanisms in composed_primitives; never return two co-primary answers. This router decides and drafts only. [CONFIG]

SPEC is one accepted adapter alongside briefs, runbooks, issue templates, system/user pairs, and acceptance criteria. Preserve the caller's vocabulary; do not impose a methodology or brand. [CONFIG][INFERENCIA]

Inputs Expected

  • Observable outcome, milestones, evidence, and typed success/failure states. [CONFIG]
  • Runtime, explicit execution surface, structured runtime evidence, durability, trigger, continuation, orchestration, parallelism, invocation surface, and reuse. [CONFIG]
  • Effect, action policy, approval, policy gate, isolation, verifier, budget, cleanup, rollback, concurrency, and resource ownership. [CONFIG]
  • Stable contract_ref when work spans turns or runs. [CONFIG]
  • Durable-memory provenance, retention, approval, rollback, policy gate, and isolation when memory mutation is requested. [CONFIG]

If effect is absent, normalize it to unknown. If runtime or control evidence is absent, expose a coverage_gap; never infer authorization. [CONFIG]

Outputs Expected

  • One normalized v2.2 operating packet with milestones and all control policies. [CONFIG]
  • Exactly one primary_primitive, a reason, and its owner_skills. [CONFIG]
  • Zero or more composed_primitives, never alternate primary answers. [CONFIG]
  • ready, draft, blocked, policy_denied, or contract_changed plus typed gaps and enforcement requirements. [CONFIG]
  • A self-contained handoff, never an unapproved live action. [CONFIG]

Authority Contract

Resolve authority in this order: [CONFIG]

  1. platform or managed policy;
  2. explicit user authorization;
  3. project defaults;
  4. versioned contract.

Runtime observations are evidence. They may invalidate a precondition but never grant permission or elevate authority. A material scope, permission, or acceptance change returns contract_changed, supersedes the old reference, freezes pending work, and requires a new policy gate plus explicit reauthorization. [CONFIG]

Procedure

1. Normalize Fail-Closed

Validate JSON inputs against assets/operating-contract.schema.json and the stdlib compiler. Reject unknown fields and malformed nested structures. The schema and normalizer field sets must remain identical. [CONFIG][CODE]

Materialize structured runtime evidence as verified, source, provenance, observed_at, runtime, capabilities, and constraints. Accept runtime_verified only as a legacy adapter; it cannot make sensitive work ready because it lacks independently supplied provenance. [CONFIG]

Materialize authorization as decision, authority source, provenance, scope, evidence reference, and verification state. A boolean verification flag alone never grants authority. Evidence policy likewise requires named sources and provenance for sensitive work. [CONFIG]

Require execution_surface to distinguish claude_platform, agent_sdk, claude_code, generic, and unknown execution. Do not infer Agent SDK from runtime: sdk or cloud durability; an unresolved cloud surface blocks routing. [CONFIG]

Materialize conservative defaults for milestones, action/evidence/verifier policies, budget, stop states, composition, cleanup, rollback, concurrency, and resource ownership. Omitted effect becomes unknown and action default becomes deny. [CONFIG]

2. Gate Before Routing

  • Material contract drift routes to human_review with contract_changed. [CONFIG]
  • An external or irreversible effect without explicit approval routes to human_review with policy_denied. [CONFIG]
  • Repetition without an observable criterion or bounded stop rule routes to human_review with blocked. [CONFIG]
  • Conflicting write/exclusive resource owners return blocked. [CONFIG]

3. Select One Primary

Use the precedence in references/decision-model.md: [CONFIG]

  1. lifecycle hook;
  2. external event push;
  3. dynamic workflow;
  4. coordinated parallelism;
  5. independent parallel work;
  6. CI, Claude Platform API/tool runtime, headless, or cloud durability;
  7. generic tool, timed, or completion loop;
  8. explicit command;
  9. reusable skill;
  10. static plan;
  11. bounded prompt.

Distinguish the four commonly conflated surfaces: [CONFIG]

SurfaceRequired signalPrimary owner
explicit commandcaller requests a named/reusable invocation (explicit_command)claude-command-authoring
reusable skillinstructions should load on demand across tasks (reusable)claude-skill-authoring
static planone run owns a fixed phase map (orchestration: fixed)current run; no authoring owner
dynamic workflowruntime owns branches, fan-out, or state (orchestration: dynamic)dynamic-workflow-forge

4. Compose Without Co-Primary Answers

Record lower-precedence mechanisms in composed_primitives. Examples include a dynamic workflow behind event push, coordinated peers inside a dynamic workflow, a goal exposed through an explicit command, tool_permission_policy for unknown or write-capable effects, and worktree_isolation for worktree boundaries. [CONFIG]

Load only the primary owner next; load composed owners only when the handoff needs them. The complete primitive-to-owner matrix lives in references/decision-model.md. [CONFIG]

5. Gate Operating Controls

  • Read-only work may only allow read actions. Unknown effect remains draft. [CONFIG]
  • Write work requires an action allowlist, policy gate, isolation, required evidence, independent named verifier, cleanup, and rollback/compensation. [CONFIG]
  • External, destructive, credential, production, payment, or publishing effects require explicit approval at the point of action. [CONFIG]
  • Write, repeat, parallel, pushed external event, or external-effect work requires at least one finite budget limit before status can be ready. [CONFIG]
  • Sensitive runtime, authority, and result evidence requires explicit source and provenance; verified: true is never sufficient by itself. [CONFIG]
  • Coordinated work requires a coordination protocol and explicit resource ownership. Multiple write owners for one resource block execution. [CONFIG]
  • Stop states must include typed terminal outcomes; budget exhaustion cannot be treated as successful completion. [CONFIG]
  • Runtime evidence and model judgment cannot authorize actions. Deterministic evidence takes precedence. [CONFIG][INFERENCIA]
  • Memory mutation remains draft unless its dedicated policy and all general write controls are complete. [CONFIG]

6. Produce And Validate

Use templates/output.md. Validate JSON packets with scripts/compile_operating_contract.py; it uses only the Python standard library and checks schema-normalizer parity before classification. [CODE]

The executable quality criteria and adversarial cases live in scripts/tests/test_operating_contract.py; the detailed decision distinctions and anti-patterns live in references/decision-model.md. [CÓDIGO][CONFIG]

Contract

  • Acceptance: one normalized packet, one primary, explicit composition, [EXPLICIT] owner handoff, operating policies, evidence, budget, and typed stop states. [CONFIG]
  • Limits: decide and draft only; never launch live automation or approve an [EXPLICIT] effect. [CONFIG]
  • Edge cases: missing outcome is invalid; unknown effect is draft; hidden [EXPLICIT] criteria and ownership collisions block; material drift supersedes and reauthorizes; memory writes fail closed. [CONFIG]
  • Assumptions: owner skills remain authoritative for version-sensitive [SUPUESTO] runtime behavior. [SUPUESTO]
  • Trade-off: a larger packet makes control gaps explicit while the v1 field [EXPLICIT] adapter preserves reasonable input compatibility. [INFERENCIA]

Packet

Capas del packet, cargables bajo demanda (disciplina ICM: una capa por vez, nunca todas juntas): references/ guías de profundidad (cargar UNA por etapa) · templates/ plantilla de output · scripts/ automatización local · assets/ recursos estáticos.

Repository
JaviMontano/claude-plugins
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.