skills/core/stewardship/aoa-knowledge-stewardship/SKILL.md
Sanitize private technical material into a public-safe owner-bounded derivative, or resolve authority among authored, generated, runtime, and installed sources. Use for governed incidents, logs, configs, diagnostics, or conflicting source roles. Do not use for ordinary editing, memo/session work, direct publication, or durable-memory authority.
npx skillsauth add 8Dionysus/aoa-skills aoa-knowledge-stewardshipInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Keep knowledge useful without moving authority, custody, privacy policy, or durable memory into a generic skill.
Use this skill when:
Do not use this skill when:
If this package is nevertheless activated for direct publication without an
exact separately supplied publication workflow and its authority, return
blocked_missing_owner_workflow(owner-publication-workflow) with effect
none. Do this before reading any target input, including owner declarations,
policies, or raw material. Do not prepare a derivative as a side effect of the
blocked publication request; sanitization must be requested or planned as its
own preceding node.
Apply the front-door exclusions before opening target material. A direct
publication request without its exact owner workflow and authority stops at
blocked_missing_owner_workflow(owner-publication-workflow) even when the
task also supplies private material and sanitization policies.
Read references/contract.yaml and choose exactly one mode:
| Mode | Select when | Required procedure |
|---|---|---|
| authority-map | Authored, generated, cached, runtime, installed, or entrypoint sources overlap or disagree. | references/authority-map.md |
| sanitized-share | Private technical material must become useful for an explicit audience or disclosure class at an exact destination. | references/sanitized-share.md |
Read the selected reference completely. Do not blend source-role resolution with sanitization or publication.
Bind authority and destination only from declarations governing the target
material. A newer or nearby file cannot fill a missing owner edge.
In sanitized-share, establish the audience or disclosure class, permitted
abstraction, disclosure threshold, exact destination identifier, read/write
effect authority, publication posture, and review requirement from the
supplied governing declarations before opening the private raw material.
The task must supply an exact destination-contract reference; a pointer to
an unsupplied contract or a destination path mentioned by another file is
not the contract.
Require an explicit custody owner or destination owner before making an
owner-specific handoff, durable-placement claim, or publication claim. For
a strictly local derivative whose exact raw read, raw-preservation rule,
destination path, artifact write, and publication prohibition are already
explicit, an unnamed custody or destination owner remains unresolved and
is reported as residual ownership uncertainty; it does not erase the
concrete effect authority or block the bounded transformation. Never borrow
an owner from the skill, response channel, nearby repository, or raw
custodian. If a safety-critical transformation input or exact effect
authority is absent, return blocked_missing_input before reading raw.
Execute only the selected effect. Artifact creation, publication, and durable-memory admission remain separate task-local nodes.
Owners supply document-role law, sensitivity rules, destination thresholds, candidate schemas, builders, validators, and publication workflows.
tools
Diagnose a reviewed recurring session/workflow failure, or carry one bounded owner repair through checkpoint, rollback, and real health verification. Use for reviewed contamination, drift, repeated route/tool failure, or an established diagnosis ready for repair. Do not use on live evidence, for vague self-improvement, or to call a proposed or merely executed change verified.
tools
Use only when a literal ref to a closed/reviewed session packet is supplied, to extract, classify, propose promotion or branching, or identify an automation opportunity. Missing, live, or unreviewed evidence must fail closed without inventing a ref. Natural closeout preservation belongs to aoa-memo-writeback. Do not use for generic summaries, progression, direct owner writes, scheduling, mutation, or telemetry authority.
testing
Turn one stable technical truth into bounded evidence through contract, coverage-audit, or property mode. Use to define a named consumer seam, audit what existing checks really constrain, or express a broad invariant after manual cases establish meaning. Compose with aoa-eval when an evaluation surface must first be found or applied. Do not use for undefined behavior, generic test plans, or green checks as whole-system proof.
testing
Shape one software responsibility boundary through bounded-context, core-boundary, or port-adapter mode. Use when responsibilities, reusable rules, orchestration, or concrete dependencies are entangled and a small owner-aware boundary is needed before implementation. Do not use for source-authority lookup, ordinary edits, test design, or a boundary that is already clear.