Split from #5214.
Problem
plugins/disk-hygiene/skills/clean/SKILL.md:5 sets disable-model-invocation: true, and the description says "manual-only". An orchestrator session or a subagent therefore cannot load the skill. The worker had to call scripts/hygiene.py scan directly, without the skill's instructions, and rebuild the flags from the worker brief.
Expected: the read-only audit (scan, classify, report) can be started by a model, so a session can delegate an audit. --execute and the removal lane stay user-only.
Suggested direction: split the read-only audit into a model-invocable skill or action, and keep the --execute path behind the existing user-only confirmation gate.
Additional evidence from #5214: even with a model-invocable audit, a delegated worker cannot build a valid command. The "disk-hygiene guard values" note (hook_python, data_root) comes from a UserPromptExpansion hook whose matcher is disk-hygiene:clean$, so it fires only when a person types the command and no orchestrator or subagent receives it. The fan-out brief's templates contain literal ${CLAUDE_PLUGIN_ROOT}, ${CLAUDE_PLUGIN_DATA}, ${CLAUDE_PROJECT_DIR} and <hook-python>, which a worker cannot expand because the guard rejects shell expansion. The bootstrap gap is tracked in the docs issue split from #5214 (item 4).
Decision
Manual-only was deliberate, and the guard and deletion safety are security-class. The owner decides after the evidence posted on #5214 (whether a read-only-only skill can be made unable to reach --execute).
Split from #5214.
Problem
plugins/disk-hygiene/skills/clean/SKILL.md:5setsdisable-model-invocation: true, and the description says "manual-only". An orchestrator session or a subagent therefore cannot load the skill. The worker had to callscripts/hygiene.py scandirectly, without the skill's instructions, and rebuild the flags from the worker brief.Expected: the read-only audit (scan, classify, report) can be started by a model, so a session can delegate an audit.
--executeand the removal lane stay user-only.Suggested direction: split the read-only audit into a model-invocable skill or action, and keep the
--executepath behind the existing user-only confirmation gate.Additional evidence from #5214: even with a model-invocable audit, a delegated worker cannot build a valid command. The "disk-hygiene guard values" note (
hook_python,data_root) comes from aUserPromptExpansionhook whose matcher isdisk-hygiene:clean$, so it fires only when a person types the command and no orchestrator or subagent receives it. The fan-out brief's templates contain literal${CLAUDE_PLUGIN_ROOT},${CLAUDE_PLUGIN_DATA},${CLAUDE_PROJECT_DIR}and<hook-python>, which a worker cannot expand because the guard rejects shell expansion. The bootstrap gap is tracked in the docs issue split from #5214 (item 4).Decision
Manual-only was deliberate, and the guard and deletion safety are security-class. The owner decides after the evidence posted on #5214 (whether a read-only-only skill can be made unable to reach
--execute).