Skip to content

agent-skills updater cannot produce a green branch: desired-state digests are validated but never generatedΒ #179

Description

@devantler

πŸ€– Generated by the Agentic Engineer

Observed failure

#162 β€” the chore(deps): update agent skills PR β€” has been red on Validate manifests for days with a single error:

plugins/agentic-engineering/resources/provider-neutral.desired-state.json:
  agent-improvement skill digest must match the bundled skill

The updater syncs a changed plugins/agentic-engineering/skills/agent-improvement/SKILL.md but never refreshes spec.roles.agent-improver.skillSha256 in provider-neutral.desired-state.json, so the branch it produces cannot pass this repository's own required check.

It is a deadlock, and I measured it rather than inferring it

Those digests are only ever validated, never generated. grep -rl 'skillSha256\|definitionSha256' over the repository returns exactly three files: the desired-state JSON itself, scripts/validate-manifests.sh, and that script's test. There is no writer.

So the branch is only greenable by a hand edit β€” and a hand edit does not survive:

  1. 06:1xZ β€” I pushed 86281ec, refreshing the digest to the bundled skill's actual hash. Verified GREEN locally, with an ablation that restored the stale digest and made the validator fail again for the right reason. All 39 checks on that head passed, 0 failing.
  2. 06:20:09Z β€” the updater ran again and force-pushed 186d51ac, whose parent is cbc5958c, not my commit. The branches are diverged.
  3. The new head carries the same stale digest dccf7463… and Validate manifests fails again.

Whoever fixes it by hand next will have their fix discarded the same way, with no signal that it happened.

Why it matters

This is the conduit every reviewed agent-skills change reaches this marketplace through, so while it is stuck, no skill update ships β€” and the failure looks like an ordinary red check rather than a structural one, which is why it has sat.

What needs to happen

Give the digests a writer and run it where the branch is built, so the generated branch is self-consistent by construction. The caller workflow .github/workflows/update-agent-skills.yaml already checks out deps/agent-skills-update and pushes it, so it is the natural place to refresh before committing.

Acceptance criteria

  • A script recomputes every definitionSha256 / skillSha256 in provider-neutral.desired-state.json from the bundled files, using the same normalisation validate-manifests.sh uses (CRLFβ†’LF, then SHA-256) so the two cannot disagree.
  • The updater runs it before committing, so a synced skill change lands with its digest already correct.
  • A test proves the pair agrees: refresh, then validate, and assert clean β€” plus an ablation that perturbs one digest and asserts the validator fails.
  • chore(deps): update agent skillsΒ #162 (or its successor) reaches green on Validate manifests without a hand edit.

Size

Small. One script, one workflow step, one test.

Part of #38

Activity

added theissue type on Sep 1, 2026
moved this to πŸ“₯ Backlog in 🌊 Project Boardon Sep 1, 2026
self-assigned this
on Sep 1, 2026
added a commit that references this issue on Sep 1, 2026
moved this from πŸ“₯ Backlog to πŸ‘€ In Review in 🌊 Project Boardon Sep 1, 2026
moved this from πŸ‘€ In Review to βœ… Done in 🌊 Project Boardon Sep 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions