Daily harness signal · October 2, 2026

Prose edits.
Executable metadata.

One implementation lesson · Skill discovery integrity

A punctuation cleanup can remove skills from discovery without deleting their files. Validate embedded metadata through the actual consumer, then check which skill identities survived—not merely whether lint passed.

Evergreen · source August 19, 2026

Validate the metadata inside Markdown

Use when

A formatter, translation, prose sweep, or metadata edit touches SKILL.md. Pocock’s repository lost six discoverable skills after em-dash rewrites introduced unquoted colon-space sequences in descriptions. Generic YAML-file checks missed the YAML inside Markdown.

Action

Extend existing CI, not the installation workflow. Independently enumerate every intended published SKILL.md; parse its frontmatter using the pinned consumer’s parser and required-field/type checks. Compare discovered name/path pairs against an explicit expected set. Unexpected omissions, substitutions, or parse failures must block publication. For example, use description: "Draft a spec: preserve scope." rather than the unquoted form. Verify the decoded description is unchanged; quoting must not silently rewrite meaning. Keep intentional internal-skill exclusions explicit.

Acceptance check

In an authorized offline fixture, retain a valid sibling and remove the example’s quotes. The gate must identify the broken file and reject publication, even though another skill loads. Restore quoting: require the expected identity set and exact decoded text. Also test description: 17, which is valid YAML but the wrong type, and a wrong-path substitution that preserves the total count. Both must fail. Retain source revision, parser version, diagnostics, parsed metadata, and identity diff.

Evidence

Issue 907 provides Linux reproduction steps with skills CLI 1.5.22. Merged PR 911 quotes the six descriptions; pinned before/after source confirms the change. The installer’s tagged implementation uses npm’s yaml parser, warns on invalid frontmatter, and returns no skill for that file. The repair’s test plan reports PyYAML checks but leaves actual installer discovery unchecked—useful repair evidence, not consumer parity.

Caveat

Do not equate file count with catalog count: internal filtering, search scope, and name deduplication can legitimately differ. Reports disagree about warning visibility; the inspected version does warn. The source repair is merged, not proof that an installed copy contains it. Our acceptance fixture was not executed. Parsing and discovery do not prove correct routing, invocation authority, or behavior. This newsletter authorizes no installation, skill change, or evaluation.

Compact source notes

  1. Prose-sweep PR 905, August 19, 2026: checked JSON, script syntax and one YAML file, not embedded frontmatter. Versioned discovery failure; separate YAML report; count and warning-visibility report, same date.
  2. Merged repair and test checklist, August 19. Exact broken merge source and repaired source. Retrieved main retains quoting; that is not a deployed-version attestation. No added automated regression suite or end-to-end passing output inspected.
  3. Vercel skills 1.5.22 parser and discovery/type checks, retrieved today. Proposed adapter should exercise the actual approved consumer path; no package installation or public API export is assumed. Attempted frontmatter-test page was inaccessible.
  4. Agent Skills specification, undated, retrieved today: requires YAML frontmatter and describes reference validation. Format validation complements rather than replaces target-loader acceptance.
  5. Anchor lens: exact metadata failure, merged quoting repair, and parser/skip branches. Unity lens: preserve capability identity across text-to-catalog conversion; proposed invariant. Source semantics: confidence_confirmed; proposed control: confidence_likely. Accepting a missing expected skill or a same-count wrong-path substitution falsifies the gate.