π€ Generated by the Agentic Engineer
Observed failure
#162 β the chore(deps): update agent skills PR β has been red on Validate manifests for days with a single error:
plugins/agentic-engineering/resources/provider-neutral.desired-state.json:
agent-improvement skill digest must match the bundled skill
The updater syncs a changed plugins/agentic-engineering/skills/agent-improvement/SKILL.md but never refreshes spec.roles.agent-improver.skillSha256 in provider-neutral.desired-state.json, so the branch it produces cannot pass this repository's own required check.
It is a deadlock, and I measured it rather than inferring it
Those digests are only ever validated, never generated. grep -rl 'skillSha256\|definitionSha256' over the repository returns exactly three files: the desired-state JSON itself, scripts/validate-manifests.sh, and that script's test. There is no writer.
So the branch is only greenable by a hand edit β and a hand edit does not survive:
- 06:1xZ β I pushed
86281ec, refreshing the digest to the bundled skill's actual hash. Verified GREEN locally, with an ablation that restored the stale digest and made the validator fail again for the right reason. All 39 checks on that head passed, 0 failing.
- 06:20:09Z β the updater ran again and force-pushed
186d51ac, whose parent is cbc5958c, not my commit. The branches are diverged.
- The new head carries the same stale digest
dccf7463β¦ and Validate manifests fails again.
Whoever fixes it by hand next will have their fix discarded the same way, with no signal that it happened.
Why it matters
This is the conduit every reviewed agent-skills change reaches this marketplace through, so while it is stuck, no skill update ships β and the failure looks like an ordinary red check rather than a structural one, which is why it has sat.
What needs to happen
Give the digests a writer and run it where the branch is built, so the generated branch is self-consistent by construction. The caller workflow .github/workflows/update-agent-skills.yaml already checks out deps/agent-skills-update and pushes it, so it is the natural place to refresh before committing.
Acceptance criteria
Size
Small. One script, one workflow step, one test.
Part of #38
Observed failure
#162 β the
chore(deps): update agent skillsPR β has been red onValidate manifestsfor days with a single error:The updater syncs a changed
plugins/agentic-engineering/skills/agent-improvement/SKILL.mdbut never refreshesspec.roles.agent-improver.skillSha256inprovider-neutral.desired-state.json, so the branch it produces cannot pass this repository's own required check.It is a deadlock, and I measured it rather than inferring it
Those digests are only ever validated, never generated.
grep -rl 'skillSha256\|definitionSha256'over the repository returns exactly three files: the desired-state JSON itself,scripts/validate-manifests.sh, and that script's test. There is no writer.So the branch is only greenable by a hand edit β and a hand edit does not survive:
86281ec, refreshing the digest to the bundled skill's actual hash. Verified GREEN locally, with an ablation that restored the stale digest and made the validator fail again for the right reason. All 39 checks on that head passed, 0 failing.186d51ac, whose parent iscbc5958c, not my commit. The branches arediverged.dccf7463β¦andValidate manifestsfails again.Whoever fixes it by hand next will have their fix discarded the same way, with no signal that it happened.
Why it matters
This is the conduit every reviewed agent-skills change reaches this marketplace through, so while it is stuck, no skill update ships β and the failure looks like an ordinary red check rather than a structural one, which is why it has sat.
What needs to happen
Give the digests a writer and run it where the branch is built, so the generated branch is self-consistent by construction. The caller workflow
.github/workflows/update-agent-skills.yamlalready checks outdeps/agent-skills-updateand pushes it, so it is the natural place to refresh before committing.Acceptance criteria
definitionSha256/skillSha256inprovider-neutral.desired-state.jsonfrom the bundled files, using the same normalisationvalidate-manifests.shuses (CRLFβLF, then SHA-256) so the two cannot disagree.Validate manifestswithout a hand edit.Size
Small. One script, one workflow step, one test.
Part of #38