Design a deterministic, dry-run-first local workspace profile plan for .jm-adk.local.json covering runtime preferences, command policy, privacy boundaries, write safety, evidence tags, and offline validation; write only on explicit apply.
Produce a safe, deterministic plan for the local profile .jm-adk.local.json.
Default output is a dry-run preview; the skill validates runtime preferences,
command policy, privacy boundaries, write safety, and evidence, and writes the
file ONLY when an explicit apply mode is present and overwrite policy passes. [DOC]
Evidence tags in outputs use the Alfa core set (kit-facing audience):
[CODE] [CONFIG] [DOC] [INFERENCE] [ASSUMPTION]. One spelling per
document; never mix the Jarvis {...} family here. See
references/verification-tags.md. [CONFIG]
workspace-governance, a different skill. Do not touch it. [INFERENCE]Missing a required input is {VACIO_CRITICO}-equivalent: stop and ask rather
than auto-filling a security-relevant default (command policy, privacy). Cosmetic
defaults (output format) may be auto-filled and tagged [ASSUMPTION]. [INFERENCE]
.jm-adk.local.json unless mode=apply is explicit. [DOC]--apply is explicit AND overwrite policy
passes (no existing file, or --force). [DOC]Validate every plan against assets/workspace-setup-plan-contract.json with
scripts/validate_workspace_setup_plan.py. (Contract, validator, and fixtures
are planned deliverables of this skill, not yet present in-repo — treat their
paths as the build target.) [ASSUMPTION]
A valid plan MUST include:
target_file exactly .jm-adk.local.json. [DOC]mode ∈ {dry-run, apply}, with dry-run as the default. [DOC].gitignore coverage, --force for
overwrite. [DOC].jm-adk.local.json already exist?). [DOC]--apply and a
passing overwrite guard. [DOC]Reject and do not store inputs matching credential shapes, including: API keys /
tokens (sk-, ghp_, xox, long high-entropy strings), passwords, private
keys (BEGIN ... PRIVATE KEY), bearer/Authorization headers, raw email
addresses, and connection strings with embedded credentials. [INFERENCE]
On a hit: reject the input, name the category (not the value), and continue with
a redaction placeholder. Never echo the secret back. [DOC]
.jm-adk.local.json (require .gitignore coverage). [DOC]--force. [DOC]escalation-required. [DOC]Stop and re-plan if any holds: planning to write while mode=dry-run;
overwrite intended without --force; a secret reached the plan body; validation
checks are incomplete or the validator was skipped; command policy widened
without explicit escalation; profile would be writable into a git-tracked path.
[INFERENCE]
[CODE] instead of [ASSUMPTION]. [INFERENCE]{...} and Alfa [...] tag families in one output. [CONFIG]--apply. [DOC]--apply produces a profile that passes the contract validator. [DOC]--force was passed. [DOC]--force → block; return preview + the exact
--force command. [DOC]If a safe write is not possible, return the JSON preview plus the exact command for a later authorized apply. Never partial-write. [DOC]
# Validate a plan fixture offline (build target; see Deterministic Contract).
python3 skills/workspace-setup/scripts/validate_workspace_setup_plan.py \
skills/workspace-setup/scripts/fixtures/valid-dry-run-profile.json
bash skills/workspace-setup/scripts/check.sh.jm-adk.local.json, validator passes, nothing written. [DOC]--force): writes
the validated profile, then prints the setup summary. [DOC]--force: returns preview + the
--force command; no write. [DOC]fdad39c
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.