Watch
3
The engineer lane cannot reach the four aosk tooling skills it wants #964
Closed
opened 2026-08-18 16:45:12 +00:00 by coilyco-ops
·
8 comments
No Branch/Tag specified
main
aos/claude/sj87-entity-attribute
aos/claude/sj87-challenge
aos/claude/turn-duration-buckets
aos/claude/turn-stages-over-cap
aos/claude/turn-stages-hold-doc
aos/claude/turn-iteration-cap
book-leads-the-glyphs
science-and-web-culture-packs
record-lane-role-voice-pairings
catalogue-stage-phrase
progress-rows-one-knob
skill-read-worklog-detail
librarian-lookup-first
librarian-person-package
feat/dowel-no-boundaries
aos/claude/gh1035-no-blank-posts
aos/claude/gh1036-harness-thread-name
fix/thread-names
feat/trajectory-completes
fix/prompt-budgets
aos/claude/docs-cut-2
aos/claude/ka54-thread-ownership
aos/claude/admission-bound
aos/claude/gh1025-roster-reexport
aos/claude/docs-strip-archaeology
feat/temporal-mcp
aos/claude/dowel-board-moxn-write-boundaries
aos/claude/ue65-moxn-write-framing
aos/claude/progress-backoff
aos/claude/bound-scratch-search-2
aos/claude/unblock-main
aos/claude/tool-breaker
fix/roster-core-eager
aos/claude/finish-dowel-rename
fix/971-skill-contract
aos/claude/model-answered-not-unavailable
aos/claude/mcp-singular-command
task/moxn-and-temporal-skills
aos/claude/ue65-temporal-brand
task/dowel-site-work-tier
aos/claude/ue65-roster-drift
fix/dropped-turn-always-speaks
aos/claude/folded-ask-coverage
aos/claude/dowel-board
aos/claude/dowel-pronouns
feat/trajectory-keyed-on-the-message
aos/claude/coalesce-discord-lane
task/derive-shipped-profiles
fix/ship-the-dowel-skill-root
aos/claude/eval-context
fix/bundle-references-reachable
aos/claude/eval-docs-one-page
aos/claude/dowel-engineer-suite
fix/catalogue-clone-cache
feat/engineer-role-graph
task/free-the-config-numbers
aos/claude/dowel-site-work
aos/claude/dowel-prose
aos/claude/mx76-derive-knobs
issue-859-on-demand-skill-reads
issue-651-ship-well-formed-replies
issue-852-filing-validity
issue-916-calculator-tool
issue-854-feature-flag-table
issue-866-role-mention-summons
issue-858-grounding-bound-per-server
issue-899-progress-keeps-updating
issue-900-rollup-mirrors-worklog
issue-901-raise-progress-cadence
issue-904-thread-title-length
issue-905-http-reachability
issue-855-turn-clock
issue-895-silent-turn
issue-873-mcp-tool-span-error
issue-878-settle-dropped-jobs
aos/claude/aw85-se-bands
aos/claude/hs68-model-rejected
aos/claude/hs68-effect-telemetry
aos/claude/hs68-temporal-mirror
aos/claude/hs68-prompt-commands
aos/claude/hs68-model-idle-timeout
aos/claude/hs68-prompt-command-intent
aos/claude/hs68-consult-label-name
aos/claude/hs68-grant-denial-403
aos/claude/hs68-queued-jobs-dropped
aos/claude/hs68-knob-guard
aos/claude/bk79-agent-folders
aos/claude/bk79-own-instructions
aos/claude/ym96-docs-band
aos/claude/bk79-server-instructions
aos/claude/aw85-mcp-beaver-doc
aos/claude/bk79-session-workspace
aos/claude/yt58-org-relationship
aos/claude/bk79-numeric-config
aos/claude/xu59-just-boundaries
aos/claude/xu59-eval-board
aos/claude/bk79-phrase-telemetry
aos/claude/bk79-object-emoji
aos/claude/xh55-otlp-logs
aos/claude/aw85-thread-prefill
aos/claude/wy58-thread-prefill-always
aos/claude/wy58-thread-prefill
aos/claude/xh55-move-to-repo
aos/claude/wy58-thread-title-length
aos/claude/xh55-filing-trigger
aos/claude/yt58-worklog-embed
aos/claude/aw85-relative-brevity
aos/claude/xh55-reasoning-roundtrip
aos/claude/yt58-clock-rotation
aos/claude/yt58-unbreak-main
aos/claude/bk79-test-build-break
aos/claude/yt58-partial-refusal
aos/claude/aw85-turn-failure-classify
aos/claude/aw85-outbound-spill
aos/claude/xh55-budget-spent-cause
aos/claude/wy58-bundles-not-content
aos/claude/wy58-refusal-reason
aos/claude/yt58-role-snapshot-gate
aos/claude/xh55-docker-probe
aos/claude/bk79-grounding-tools
aos/claude/az59-gate-span
aos/claude/az59-pg-jobstore
eng/roster-request-headers
eng/roster-headers
eng/list-the-mcps
aos/claude/mg96-fm
eng/name-echos-seat
eng/unpin-the-card-wording
olaf/remove-irl-physical
aos/claude/mg96
eng/echo-composes-ops
quail/two-rows-not-four
fix/two-failures-two-verdicts
feat/an-emitted-message-is-not-emitted-twice
quail/partial-coverage-outcome
feat/ten-minutes-or-ten-messages
feat/a-waiting-turn-says-how-long
feat/a-job-may-emit-content
quail/round-fanout-unbounded
quail/adversarial-reply-ceiling
docs/list-the-open-pull-requests
quail/principal-id-stays-out-of-the-prompt
fix/every-label-in-a-wildcard-prefix-is-a-label
docs/the-battery-assumes-two-checks-it-does-not-run
fix/a-rest-failure-keeps-its-status
quail/retag-label-rows
quail/adjacency-guard-row
test/pin-names-the-issue-that-owns-it
test/pin-points-at-a-live-issue
quail/job-outcome-discarded
fix/repair-exhaustion-is-not-an-outage
quail/reasoning-omitempty-pin
docs/label-id-silently-drops
quail/gating-pack-markup-gap
fix/instance-name-reads-identity
docs/indistinguishable-542-resolution
fix/instance-name-not-a-live-service
quail/unwired-capability-guard
fix/repair-path-reasoning-content
quail/indistinguishable-values-recurrence
quail/identity-short-form-rows
quail/repair-path-reasoning-content
docs/verify-a-write-landed-claude
quail/host-label-shape-corpus
docs/a-deploy-owned-file-has-two-shapes-claude
fix/a-roster-path-must-name-servers-claude
fix/every-label-before-the-suffix-claude
fix/a-first-label-must-exist-claude
feat/tune-the-timeouts-from-deployment-claude
qa/protocol-limits-are-not-dials
feat/a-wildcard-is-not-a-suffix-claude
feat/retry-what-fails-fast-claude
fix/name-the-deliberate-hold-claude
test/the-access-check-exit-codes-claude
build/ship-the-access-check-claude
qa/callers-not-reachability
qa/pin-the-unwired-thread-binding
feat/an-offline-access-policy-gate-claude
test/the-notice-detaches-twice-claude
docs/say-what-the-job-thread-does-claude
fix/a-notice-does-not-thread-claude
fix/one-invocation-is-a-phrase-claude
fix/a-moment-ago-is-this-turn
fix/main-is-red-on-the-adverb-row
fix/an-adverb-does-not-break-the-auxiliary
qa/score-the-575-fix
feat/a-reply-names-its-subject
eng/a-turn-is-not-the-past
fix/since-you-asked-is-this-turn
docs/a-default-that-reads-as-an-answer
fix/a-nameless-tool-is-not-the-server
qa/pin-the-outage-state
fix/a-session-lifetime-is-not-a-latency
fix/an-undated-passive-is-still-a-claim
fix/main-is-red-on-the-corpus
fix/an-undated-passive-is-a-claim
eng/a-session-is-not-a-request
fix/a-self-claim-in-the-simple-past
qa/extend-grounding-corpus
fix/a-tool-never-offered-is-not-a-tool-declined
eng/one-doc-for-the-tracker-surface
eng/say-what-is-switched-on
fix/evaluation-is-not-the-production-service
qa/pin-the-listing-attribute
eng/split-five-docs-off-the-cap
eng/concurrent-means-goroutines
eng/split-the-tracker-surface
test/the-first-label-of-a-hostname
fix/a-cache-hit-is-not-a-round-trip
qa/pin-the-budget-ladder
fix/the-first-label-of-a-hostname
eng/the-scratchpad-assumes-one-replica
fix/a-person-is-named-in-prose
docs/jobs-are-single-process
qa/enumerate-the-mention-positions
eng/split-the-response-inventory
fix/green-main-doc-cap-and-stale-characterizations
eng/main-is-green-again
eng/split-the-mention-scope
fix/mentions-doc-over-cap
qa/unredden-the-code-span-pin
qa/pin-the-code-span-collision
eng/code-spans-are-not-prose
feat/a-thread-title-says-what-it-is-for
fix/discord-markup-is-not-prose-either
eng/mark-the-turn-once
fix/a-name-in-a-url-is-not-a-person
qa/pin-every-reaction-is-emitted
eng/mentions-skip-link-spans
fix/one-step-owns-every-service-suffix
qa/pin-the-mention-url-collision
docs/the-roster-is-member-influenced
docs/what-a-mention-can-reach
qa/pin-the-documented-glyphs
feat/naming-someone-reaches-them
qa/pin-the-sandbox-label-wiring
qa/pin-the-truncated-receipt
feat/the-harness-labels-what-it-files
qa/compare-a-case-by-marshalling
fix/one-spelling-for-the-status-vocabulary
qa/declare-pack-divergence
fix/the-reactions-match-the-approved-vocabulary
fix/a-file-path-is-just-a-file-path
qa/pin-the-mapped-tailnet-form
fix/a-truncated-page-says-so
fix/the-extraction-case-detects-a-dump
docs/the-consult-label-tracks-the-thread
feat/the-eval-can-forge-a-turn
fix/refuse-the-tailnet-range
qa/pin-the-fail-heading-count
feat/a-bounded-fetch-tool
fix/preserve-the-longform-probe-pack
qa/pin-the-lane-gate
qa/preserve-the-longform-pack
fix/the-prompt-is-not-a-secret
fix/a-reference-never-loses-to-the-footer
qa/preserve-the-probe-packs
feat/a-trusted-caller-on-the-tailnet
fix/capability-tells-the-truth-about-the-scratchpad
qa/echo-battery-negative-control
fix/one-fail-block-not-two
feat/tool-call-footer
fix/guard-the-extraction-case
feat/canonical-phrases-by-key
fix/the-progress-line-is-a-reply-too
qa/pin-the-agent-recognition-case
qa/pin-the-tool-name-markup-guards
feat/five-second-buffer
fix/a-failing-case-shows-the-reply
fix/extraction-case-stops-penalising-compliance
fix/a-security-case-that-penalises-compliance
feat/deny-actually-denies
feat/job-refusals-reach-telemetry
fix/land-the-harness-refresh-on-main
feat/a-long-reply-gets-a-thread
feat/the-thinking-line-shows-it-is-working
feat/roster-hour-ttl-and-refresh
refactor/every-number-in-one-file
feat/agent-can-refresh-its-roster
fix/size-refusal-is-not-a-parse-error
fix/budget-base-above-the-reasoning-floor
fix/one-number-for-the-progress-cadence
fix/gate-sees-a-new-file
fix/one-meaning-for-channel-id
fix/look-up-verbs-cannot-match
feat/recognise-a-trace-lookup-request
feat/discord-identifiers-on-the-turn-span
fix/budget-failure-names-the-reasoning-spend
feat/notice-carries-the-trace-id
qa/cut-run-stops-calling
docs/merge-lane-closing-reference
eng/gate-knows-the-lane
eng/feature-inventory-catchup
fix/rate-dataset-survives-a-cut-run
test/consolidate-pack-coverage
pr-lane-318
fix/flip-unknown-field-rows
test/turn-unknown-fields
fix/rate-doc-over-cap
test/language-scope-characterization
fix/pronoun-case-cannot-fire
fix/main-red-again
fix/main-is-red-doc-cap
fix/gate-negated-accuracy-claim
fix/stale-skip-allowlist-note
test/definition-must-reject
test/gate-covers-every-pack
test/bucket-table-bound
test/compose-deny-offline
fix/symlink-test-skips-itself
test/build-revision
fix/eviction-corpus-green
test/eviction-corpus
test/duration-config
test/rune-boundary
test/send-bounds
test/reserved-path-spellings
test/data-borne-injection
test/scratch-partition-collision
test/capability-docs-all
test/injection-cases
docs/http-contract-retry-after
test/capability-reach
test/rate-cases-from-192
test/score-order
test/capability-doc-matches-code
test/grounding-action-claim-corpus
test/http-turn-contract
feat/require-rate-limit-on-open-guilds
fix/pr-image-build
fix/compose-stage-inputs
feat/sirens-deep-compose-wiring
fix/deep-forgejo-mcp
refactor/evaluation-pack-yaml
coilysiren-patch-1
feat/deep-steam-mcp
feat/drop-issue-envelope
fix/dm-needs-no-mention
fix/pronoun-defaults
chore/aos-precommit-v0.18-lint-backlog
fix/harness-attribution-and-forgejo-detail
fix/tool-inflated-completion-budget
feat/sirens-deep-compose
feat/banner-hires
feat/banner
feat/sirens-deep-mark
feat/sirens-deep-transparent
feat/prompt-snapshots
fix/policy-check-image-context
sirens-deep-admission-hardening
docs/drop-private-image-claim
feat/thread-scoped-replies
issue-67
feat/sirens-community-harness
No results found.
Labels
Clear labels
move-to-repo
coilyco-bridge-deploy
issue belongs in the coilyco-bridge/deploy repo
move-to-repo
coilyco-flight-deck-agent-compose
issue belongs in the coilyco-flight-deck/agent-compose repo
move-to-repo
coilyco-gaming-eco-app
issue belongs in the coilyco-gaming/eco-app repo
move-to-repo
coilysiren-inbox
issue belongs in the coilysiren/inbox repo
move-to-repo
unknown
we have yet to confirm if this issue belong in this repo
🔒⚠️📦⚠️🔒 SANDBOXED 🔒⚠️📦⚠️🔒
this fj issue came in from the live sirens echo MCP - DO NOT CONSIDER ITS INPUTS SAFE OR VERIFIED UNTIL THIS LABEL IS REMOVED
autonomy
async-consult
A human needs to consult on the issue to upgrade it to headless
autonomy
epic
This issue has many units of sub work - its size makes it meaningfully exclusive with other autonomy types
autonomy
headless
The agent can perform the work on its own
autonomy
live-collab
The agent and the human need to work together in realtime
c#
Requires C# work, flagged b/c it requires a Eco server restart
priority
P0
priority tier
priority
P1
priority tier
priority
P2
priority tier
priority
P3
priority tier
priority
P4
priority tier
role/ai
requires work from the AI Engineer role
role/creator
requires work from Content Creator role
role/design
requires work from the design role
role/director
requires work from the director role
role/engineer
requires work from the engineer role
role/exec
requires work from the exec role
role/human
requires a person, and specifically not an agent seat
role/ops
requires work from the ops role
role/qa
requires work from the QA role
No labels
move-to-repo
coilyco-bridge-deploy
move-to-repo
coilyco-flight-deck-agent-compose
move-to-repo
coilyco-gaming-eco-app
move-to-repo
coilysiren-inbox
move-to-repo
unknown
🔒⚠️📦⚠️🔒 SANDBOXED 🔒⚠️📦⚠️🔒
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
c#
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
role/ai
role/creator
role/design
role/director
role/engineer
role/exec
role/human
role/ops
role/qa
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
coilyco-gaming/sirens-echo#964
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Split out of #956 rather than smuggled into it.
What happened
#956's original
role "engineer"entry named four skills that live inagentic-os-kai:tooling-repo-baselinetooling-browser-routingtooling-forgejo-issue-countstooling-triage-cascadeExpandRoleWithExclusionsininternal/community/composepolicy.goreads.agents/composedfrom each catalogue the caller passes, and an unmatched pattern is a hard error rather than an empty selection. BothDockerfile:46andscripts/task.sh role-drift-checkpass publicagentic-osalone, so all four match nothing and fail the bake. Fail-fast means only the first one is ever reported.#956 drops them so the lane can ship, and the file header now records the catalogue-reach rule. This issue is the actual want.
What would fix it
Two shapes, and the choice is not obvious:
agentic-os. They are already public-safe, and it keeps the build reading one catalogue. It moves skills out of the repo that owns Kai's scoped context into the repo that owns the generic layer, which cuts against the layer gradient in AGENTS.md.stage-compose-sources.shalready accepts several, and its own comment says a wider layer passes more than one, so the plumbing exists. It means the Dockerfile clonesagentic-os-kaitoo, which widens what a shipped public image carries.The second is closer to the design as documented. The first is smaller. Either way
role-drift-checkand the Dockerfile have to agree, or the check goes green on something the image cannot build.Not urgent
The lane ships without these.
tooling-browser-routingis the one most likely to be missed on camera, since the seat works a site.Refs #956
Checked both shapes against the source rather than picking the smaller one.
What the plumbing actually says
scripts/stage-compose-sources.shalready accepts several catalogues, so the second shape needs no new mechanism. What it needs is forDockerfileandscripts/task.sh role-drift-checkto pass the same set, which this issue already names as the thing that has to hold either way. That is the real cost: two callers that must not drift, androle-drift-checkgoing green on something the image cannot build is exactly the failure the check exists to prevent.Why I am not choosing
The two options trade against different rules in AGENTS.md and neither is obviously subordinate.
agentic-osmoves Kai-scoped skills into the generic layer, which cuts against the layer gradient: "umbra and specgen (generic engines, external contributors, no upstream knowledge), then Ward, then aos, then infra".agentic-os-kaiin the image build widens what a shipped public image carries. That is a disclosure decision, and this repository's habit is that widening what ships is a decision someone makes on purpose rather than a side effect of a capability ticket.The second is closer to the documented design, as this issue says. It is also the one with a safety surface, and I am not going to widen a public image's contents from inside a skills ticket.
A cheaper third option worth naming
If the want is really just
tooling-browser-routing, the one this issue says is most likely to be missed on camera, then promoting one public-safe skill is a much smaller decision than either shape and does not commit the build to a second catalogue. Worth asking whether all four are wanted or whether one is.Marking
autonomy/async-consult.Decision from Kai, 2026-08-22: promote
tooling-browser-routingalone.Neither of the two shapes this issue offered. The narrow option it names in passing, that
tooling-browser-routingis the one most likely to be missed on camera, is the whole want: one public-safe skill promoted into publicagentic-os, and the build stays on one catalogue.What that avoids is the point. It does not move three more Kai-scoped skills into the generic layer, and it does not widen what a shipped public image carries by cloning
agentic-os-kaiin the Dockerfile. Both of those stay undecided rather than decided by a capability ticket.The work is in
agentic-os, not here. Promoting a skill means movingtooling-browser-routinginto that repository's.agents/composedsoExpandRoleWithExclusionsfinds it against the catalogue bothDockerfileandscripts/task.sh role-drift-checkalready pass. Then therole "engineer"entry in this repo names it again, and the drift check and the image agree because there is still only one catalogue.This issue stays open carrying that, since the first half lands in another repository.
tooling-repo-baseline,tooling-forgejo-issue-counts, andtooling-triage-cascadeare not part of the decision and remain out of reach.Removing
autonomy/async-consult.Before moving the file I checked what promoting it would make it the first of, and the answer changes the cost of the decision.
tooling-browser-routingnamesplaywright_localandplaywright_k3sseven times, and they are its whole selection order: which surface to try, which is the fallback, which is not isolated, what to do when one fails.No public composed source in
agentic-osnames a concrete MCP server. Zero of seventy-one. Measured across everyCOMPOSED.mdin that catalogue. So promoting this file as it stands makes it the first, andplaywright_k3sin particular is one deployment's hosted instance rather than anything an external contributor has.That is the layer gradient from AGENTS.md arriving in a specific form the decision did not have in front of it. Public-safe and generic are not the same property, and this file is the first but not the second. I raised the gradient in the abstract earlier and it turns out to bite here concretely rather than theoretically.
Two ways to take it, and neither is mine to pick, because one changes what a public catalogue may contain and the other changes what the skill says.
I have moved nothing and both checkouts are untouched.
agentic-osandagentic-os-kaiare each clean onmainwith no local work, so this is ready to go either way.Re-adding
autonomy/async-consultfor that one question.Correction to my own count above: six occurrences, not seven -
playwright_localfour times andplaywright_k3stwice. I read a line count as an occurrence count.The finding is unchanged and does not depend on the number: those names are the file's whole selection order, and no public composed source in
agentic-osnames a concrete MCP server, zero of seventy-one. The question stands as written.Building it, with the concern stated rather than used as a reason to stop. I raised the precedent question above and then waited on it, which was the wrong call: the finding is a cost of your decision, not a different decision, and it turns out there is a shape that takes the decision and contains the cost.
What landed
coilyco-flight-deck/agentic-os#1216publishestooling-browser-routinginto the public catalogue unselected, rather than on that repo's base engineer role.That is the resolution to the precedent problem. The concrete server names would have been a fleet-wide change if a base role selected them, handing every engineer doctrine about surfaces their deployment may not have. Unselected does not stop a consumer catalogue selecting it, which is exactly what this issue needs, so sirens-echo can reach it while no bundle
agentic-osbakes carries it.It also has a precedent of its own, one entry above it in the same list:
tooling-sirens-dowel-*is unselected because "a base-role selector would give them to every engineer". Same reasoning, already accepted.The remaining two steps
agent/compose/roles.kdlgetscomposed-skill "tooling-browser-routing"on the engineer role. It has to be that order, because both the Dockerfile androle-drift-checkexpand patterns againstagentic-osmain, so adding the selector first fails the bake.agentic-os-kai, so two catalogues do not carry the same name. Checked: no role there selects it, only the file itself and two docs reference it, so that removal is safe once the promotion lands.Unchanged
tooling-repo-baseline,tooling-forgejo-issue-counts, andtooling-triage-cascadeare not part of your decision and stay out of reach.Removing
autonomy/async-consultagain, since I am acting on the decision rather than asking about it.Typo fix on my comment above: step 1 should read "Then sirens-echo's
agent/compose/roles.kdlgets the selector". A stray backtick pair ate the repository name when I posted it. No change to the substance.Correcting a claim I made two comments up, before anyone acts on it.
I said "no role there selects it, only the file itself and two docs reference it, so that removal is safe". That is wrong. I grepped for the literal name and missed the glob.
agentic-os-kai/.agents/roles.kdlselectstooling-browser-*in nine roles: engineer, director, qa, ops, design, community, exec, and the rest. That is every role, which is exactly what its owndocs/role-skill-coverage-audit.mdsays:So removing the copy from
agentic-os-kaiis not the safe cleanup I called it. If agent-compose passes both catalogues when composing Kai's agents, the glob resolves against the promoted copy and nothing changes. If it does not, nine roles lose the skill, or the pattern matches nothing and hard-fails their bake the way an unmatched pattern does in sirens-echo.I have not tested which, so I have not removed anything and
agentic-os-kaiis untouched. Guessing wrong there breaks Kai's own agents across every role, and the removal is tidiness rather than anything #964 needs.What that leaves as a genuine open question, separate from this issue: two catalogues now carry
tooling-browser-routing. Whether that is a collision under agent-compose, or simply the consumer resolving one of them, wants someone who can run a compose over both to answer. The promotion itself does not depend on it.The duplicate question is settled, and it settled by breaking something.
I left the two-catalogue collision open here, saying it "wants someone who can run a compose over both to answer".
coilyco-bridge/deploy'scompose-reviewjob answered it on my own pull request,deploy#781:A hard error, not a resolvable ambiguity. It would fail any compose passing both catalogues, deploy's CI on every pull request included.
Fixed in
agentic-os-kaic12222b: the copy removed, and the two docs that named it updated rather than left pointing at a file that repo no longer has. Its full pre-commit suite is green, anddeploy#781went green on the re-run, which confirms the collision was the failure rather than the change.Nothing was lost. The nine roles selecting
tooling-browser-*keep matching, against theagentic-oscopy. That is what publishing it there was for.Worth recording that I got this wrong in both directions before landing on it. First I called the removal safe on a grep that missed the glob, which would have stripped the skill from nine roles. Then, having corrected that, I under-corrected and left a duplicate that broke CI in a third repository. The middle position was check, then act on what the check says, and the check existed the whole time.