codex/skills/retrace/SKILL.md
Reconstruct and experimentally challenge decisions from prior Codex sessions. Use for `$retrace`, historical decision replay, counterfactual forks, alternative-route challenges, hindsight-separated retrospectives, workflow-governance audits, skill decision attribution, or 'why did that session choose this?'. `$seq` owns deterministic history and source-governance evidence; `$cas` owns safe thread/rollout replay and FIR lifecycle; `$retrace` owns bounded experiments and DRR synthesis. Never present fork output as the source model's hidden chain of thought.
npx skillsauth add tkersey/dotfiles retraceInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use a historical Codex session as an experimental branch point.
$seq freezes visible historical evidence
$cas creates controlled historical-context replays
$retrace compares bounded witnesses and synthesizes conclusions
Determine:
what was historically explicit
what the visible trace supports
whether the claimed workflow really governed the source
whether the route is stable under replay
which alternative is strongest
which fact flips the route
what hindsight changes
what remains unknowable
A replay is a new model execution, not access to the source model's private chain of thought.
Keep separate:
historically_explicit
trace_inferred
fork_consistent
counterfactual_stable
outcome_informed
unsupported
unknown
Allowed:
The source explicitly said...
Two pre-decision replays selected...
The route flipped when evidence E was withheld...
Forbidden:
The original model secretly thought...
The replay recovered the original chain of thought...
See epistemic-boundary.md.
$seqOwns:
source_governance_gate / SGG-v1
decision_context_packet / DCP-v2
$casOwns:
thread_fork or rollout_transcript lineage;fork_inquiry_receipt / FIR-v1
$retraceOwns:
retrace_inquiry_plan / RIP-v1
decision_reconstruction_record / DRR-v1
explain contemporaneous rationale reconstruction
replay pre-decision independent route selection
challenge strongest supported non-selected route
retrospective outcome-aware learning
compare staged baseline/intervention experiment
audit validate source and artifacts without replay
Do not begin with a large fork portfolio.
Prove the claimed workflow governed the source.
Run one outcome-blind lane and require one valid FIR.
Run:
historical-context baseline
policy/instruction intervention
Only when Stage 2 yields a material difference or unresolved ambiguity:
strongest-alternative challenge
one evidence/instruction ablation
one outcome-aware retrospective
Default maximum:
4 forks
1 turn per fork
read-only
ephemeral
network off
Resolve source, question, claimed workflow/skill, mode, lane portfolio, model policy, workspace policy, budgets, and persistence. Defaults:
mode = compare
workspace = transcript_only unless exact reconstruction is needed
permissions = read-only, network-off
persistence = receipts
Run this phase when:
review-compiler-audit.
Obtain the exact session-level row, not only aggregate counts.
For controller-backed review-closure workflows:seq review-compiler-audit \
--root ~/.codex/sessions \
--protocol <review-protocol> \
--repo <repo> \
--since <time> \
--until <time> \
--exclude-current \
--format json
Select the exact denominator.included_sessions row and preserve evidence for:
true workflow signal
required
entered
closed
closure compression
Classify workflow provenance:
controller_invocation
controller_event
controller_state
controller_receipt
explicit_workflow_declaration
artifact_under_repair
filename_or_path_mention
historical_reference
generic_prose
ambiguous
absent
Classify closure provenance separately:
controller_close
controller_receipt
campaign_bound_terminal
generic_delivery_closure
tool_success_only
ambiguous
absent
Create SGG-v1.
Verdicts:
authoritative
controller-grade governance evidence; replay allowed
declared_uncontrolled
explicit workflow declaration but controller governance unproven;
replay allowed with limitation
incidental
artifact/path/history mention only; stop before replay
ambiguous
deterministic investigation only
absent
stop before replay
A filename such as .step/review-workflow-plan.jsonl is not a workflow activation.
A generic merge/land/complete signal is not controller closure.
See source-governance.md.
Use the narrowest $seq surface:
skill-decision-audit
decision-capsule --mode candidates
turns
session-detail
artifact-search
When automatic candidates are absent, locate the visible route decision and use an exact one-based --turn-index.
seq decision-capsule \
--session-id <id> \
--turn-index <n> \
--anchor all \
--outcome-policy conservative \
--format json
Do not let replay models select the historical source episode.
The capsule must distinguish:
pre_decision
post_decision_pre_outcome
outcome_aware
Outcome blindness must be structural. Do not use a full-history replay plus an instruction to ignore later outcomes. See decision-capsule.md.
CAS supports two lineage modes.
thread_forkUse when source thread identity is available.
thread/fork
-> exact rollback
-> retained-anchor verification
Workspace may be exact, head-only, or transcript-only according to DCP evidence.
rollout_transcriptUse when the DCP has a verified rollout path but no source thread ID.
verify source rollout digest
-> verify retained anchor digest
-> fresh thread/start
-> bounded transcript-context turn/start
Requirements:
workspace_policy = transcript_only
no current-checkout tools
no live historical workspace claim
lineage_mode recorded in FIR
Rollout transcript replay is structurally anchored transcript replay, not live thread forking or workspace reconstruction. See workspace-reconstruction.md.
Require:
seq decision-capsule and DCP validation
cas session_inquiry and FIR support
at least one supported lineage mode
read-only inquiry
no-network policy
receipt persistence
When only deterministic analysis is available, fork-based claims are forbidden.
retrace_inquiry_plan:
plan_version: RIP-v1
inquiry_id:
source_capsule:
objective:
lanes:
- lane_id:
temporal_horizon:
inquiry_mode:
fork_count:
prompt_template:
evidence_allowed: []
evidence_withheld: []
model_policy:
workspace_policy:
permission_policy:
budgets:
cleanup:
Use different lane contracts; do not manufacture consensus through repeated leading prompts. See inquiry-lanes.md.
cas session_inquiry run \
--capsule capsule.json \
--plan plan.json \
--receipt-dir .ledger/retrace/<inquiry-id> \
--json
CAS must prove source lineage, retained anchor, model/provider, permission policy, workspace mode, turn state, and cleanup.
Detached lifecycle remains available through start, status, wait, interrupt, and cleanup.
Only complete, source-bound FIRs contribute to:
route distribution
consensus
stability
instruction effect
For rollout transcript receipts require:
lineage_mode = rollout_transcript
workspace_reconstruction.mode = transcript_only
verified source and anchor digests
See fork-inquiry.md.
Use decision_interrogation_adjudicator when:
source governance is declared_uncontrolled
forks disagree
hindsight leakage is plausible
lineage/workspace/model differs
skill effect is material
route stability will drive tuning or doctrine
The adjudicator is read-only.
DRR must preserve:
source-governance verdict
historical explicit facts
trace inference
valid/invalid receipts
baseline/intervention routes
strongest alternative
route-flip conditions
hindsight lessons
skill/instruction effects
contradictions
limitations
confidence
Consensus is never historical fact. See synthesis.md.
rationale:
post-decision/pre-outcome; reconstruct visible support and assumptions
counterfactual:
pre-decision; choose independently without predicting history
alternative challenge:
pre-decision; strongest evidence-consistent non-historical route
evidence ablation:
pre-decision; withhold/change one named item and re-decide
retrospective:
outcome-aware; label every lesson as hindsight-informed
Ask:
Did the source actually contain the skill/workflow?
Was governance authoritative, declared, incidental, or absent?
Did baseline and intervention choose different routes?
Did controlled ablation change the route?
Did the source explicitly attribute the decision?
Strongest evidence:
historical explicit attribution
+ authoritative source governance
+ exact pre-decision anchor
+ controlled intervention/ablation
+ route change
Fork self-report alone is weak.
DRR may inform $tune; it does not authorize edits.
Defaults:
ephemeral
read-only
network disabled
approvals denied
dynamic tools denied
one bounded turn
bounded excerpts and refs
Do not use thread/shellCommand.
Do not persist private reasoning.
Use .ledger/retrace/<inquiry-id>/ only when receipts are required, and local-exclude it by default.
A blocked replay does not erase deterministic source evidence.
Report:
source / decision / question
source-governance provenance and verdict
lineage and workspace mode
historical explicit / trace-inferred evidence
valid and invalid FIRs
baseline/intervention route distribution
strongest alternative and flip conditions
hindsight-separated lessons
skill/workflow effect
confidence and unsupported claims
cleanup and CLI gaps
$seq owns history and workflow provenance.$cas owns replay lifecycle.$retrace owns experiments and synthesis.tools
Invokes Apple's macOS 27 fm command-line tool from a local Mac to use the on-device system model or Private Cloud Compute, including instructions, image prompts, schema-constrained JSON, and noninteractive automation. Use when the user asks to run Apple Foundation Models through fm, compare system versus pcc, generate structured output, or automate fm without Swift or an app.
development
Compile historical Codex sessions into governed counterfactual evidence, evaluate an existing owner-applied candidate through blinded paired HCTP trials, and fold observable evidence into RUN, OBSERVE, or STOP. Use for `$hylo`, CRF extraction, counterfactual replay, source-governed direct or historical trials, sealed evidence, paired baseline/candidate evaluation, causal frontiers, or evidence-governed improvement.
testing
Ensure a `ledger` command is available on PATH; materialize, validate, record, replay, and project requested Actuating artifacts without taking semantic or execution authority; coordinate the shared Learnings/Synesthesia/Negative Ledger lifecycle checkpoint and repo-local source-memory reconciliation; address Universalist plans and receipts; and perform pure artifact validation.
testing
Classify and quotient review findings, failing tests, incidents, bug reports, migration failures, and other witnessed falsifiers against accepted intent and the current Construction. Author counterexample-set/v1 without selecting repairs, counting review credit, or granting mutation.