Daily harness signal · September 25, 2026

Fix the whole
invocation chain.

One implementation lesson · Packaged skill helpers

A packaged skill can contain the right script bytes yet fail before doing work. Name the interpreter at every script boundary, then test the default path—not a shortcut that skips the broken helper.

Fresh · source September 19, 2026

Interpreter prefixes must reach nested helpers

Use when

An already-approved agent skill ships scripts through marketplace or archive packaging. Superpowers users reported readable helpers arriving without executable bits. Running the outer helper through Bash still failed when it directly executed its equally non-executable sibling.

Action

Require both repairs shipped in Superpowers 6.4.1, or a reviewed equivalent: interpreter-prefixed skill recipes and interpreter-prefixed nested calls. For an approved checkout, use:

bash "$SP_ROOT/skills/subagent-driven-development/scripts/task-brief" "$PLAN" 1
bash "$SP_ROOT/skills/subagent-driven-development/scripts/review-package" "$PLAN" "$BASE_SHA" "$HEAD_SHA"

Run from the intended repository with valid plan and commit endpoints. Omit OUTFILE during acceptance: that override bypasses the workspace helper and can hide the failure. Internally, both helpers now invoke sdd-workspace through "${BASH:-bash}". Match other bundled scripts to their actual interpreter; JavaScript needs Node, not Bash. Do not rewrite generated plugin caches or blindly retry permission errors.

Acceptance check

In an authorized disposable copy, remove execute bits while preserving read access. The old nested invocation must fail; the repaired documented commands must succeed without OUTFILE. Require the expected task sentinel and actual commit diff in the returned artifacts, not just exit zero. The real consumer must open those paths. Repeat with executable modes as a positive control. Retain source revision, file modes, arguments, statuses, and artifacts. Never alter the live cache for this fixture.

Evidence

Merged PRs 2301 and 2134, the September 19 release, and tagged source establish both changes. Issue 2040 contains multiple versioned reproductions. The tagged regression copies three helpers, removes execute bits, and checks that Bash-invoked task-brief creates its default artifact. It does not exercise review-package’s stripped-mode branch; our acceptance procedure adds that coverage.

Caveat

This fixes mode-loss compatibility, not trust, missing interpreters, unreadable files, or execution policy. Never use an interpreter to evade an intentional restriction. Windows/MSYS output-path compatibility is separate; its September 22 repair proposal remains open. The exact distribution stage that lost modes is not settled. Source and tests were inspected, not executed; no installation, skill edit, or runtime acceptance occurred today.

Compact source notes

  1. Superpowers 6.4.1, September 19, 2026; recipe repair 2301 and nested-call repair 2134, both merged September 17. Maintainer PRs report deterministic checks; no live-agent behavioral gain is inferred.
  2. Tagged skill recipes, task-brief, review-package and regression inspected. File history records the release integration.
  3. Original report and follow-ups, July 25–September 13; Codex report 45260, September 13, is the same reporter’s cross-post, not independent replication. Its distribution-stage attribution is qualified; the served bundle was not inspected. Windows report, September 16, and open path-normalization PR, September 22, limit portability claims.
  4. Anchor lens: exact nested calls, default-versus-explicit output branches and regression assertions. Unity lens: compatibility must hold across the whole invocation chain; proposed invariant. Shipped source semantics: confidence_confirmed; expanded acceptance procedure: confidence_likely. Failure to produce the expected readable artifacts falsifies acceptance. No new installation or evaluation is authorized by this issue.