Skip to content

disk-hygiene: model-invocable read-only audit skill for orchestrators and subagents #5516

Description

@kyle-sexton

Split from #5214.

Problem

plugins/disk-hygiene/skills/clean/SKILL.md:5 sets disable-model-invocation: true, and the description says "manual-only". An orchestrator session or a subagent therefore cannot load the skill. The worker had to call scripts/hygiene.py scan directly, without the skill's instructions, and rebuild the flags from the worker brief.

Expected: the read-only audit (scan, classify, report) can be started by a model, so a session can delegate an audit. --execute and the removal lane stay user-only.

Suggested direction: split the read-only audit into a model-invocable skill or action, and keep the --execute path behind the existing user-only confirmation gate.

Additional evidence from #5214: even with a model-invocable audit, a delegated worker cannot build a valid command. The "disk-hygiene guard values" note (hook_python, data_root) comes from a UserPromptExpansion hook whose matcher is disk-hygiene:clean$, so it fires only when a person types the command and no orchestrator or subagent receives it. The fan-out brief's templates contain literal ${CLAUDE_PLUGIN_ROOT}, ${CLAUDE_PLUGIN_DATA}, ${CLAUDE_PROJECT_DIR} and <hook-python>, which a worker cannot expand because the guard rejects shell expansion. The bootstrap gap is tracked in the docs issue split from #5214 (item 4).

Decision

Manual-only was deliberate, and the guard and deletion safety are security-class. The owner decides after the evidence posted on #5214 (whether a read-only-only skill can be made unable to reach --execute).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent-readyFully specified and briefed; eligible for autonomous pickup from the frontier.priority: mediumReal value, no hard deadline; normal backlog flow.work-class: structuralRefactors, migrations, contract changes; cross-cutting and hard to reverse.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions