Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions .agents/policy/unigetui-policy.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
{
"schemaVersion": 1,
"packId": "unigetui-policy",
"namespace": "unigetui",
"version": "1.0.0",
"displayName": "UniGetUI repository policy",
"description": "Deterministic presence checks for ACKit workflow, instructions, and localization guidance.",
"severity": "medium",
"rules": [
{
"id": "unigetui:ackit-config",
"type": "presence",
"glob": "ackit.yml",
"message": "ackit.yml must exist at repository root",
"remediation": "Restore ackit.yml and run ackit config check"
},
{
"id": "unigetui:agents-instructions",
"type": "presence",
"glob": "AGENTS.md",
"message": "AGENTS.md must exist at repository root",
"remediation": "Restore AGENTS.md canonical instructions"
},
{
"id": "unigetui:ackit-docs",
"type": "presence",
"glob": "docs/ACKIT.md",
"message": "docs/ACKIT.md must exist for contributor and agent guidance",
"remediation": "Restore docs/ACKIT.md"
}
]
}
23 changes: 23 additions & 0 deletions .agents/skills/ackit-context-optimization/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
---
name: ackit-context-optimization
description: Build budgeted context packs and trim instruction bloat for coding agents.
---

# Context Optimization

Activate when the user asks to prepare context for an agent session or reduce
token usage.

See [ranking signals](references/ranking.md) for deterministic ordering.

## Steps

1. `ackit pack --max-tokens <budget> [--format markdown|json] [--include <globs...>] [--changed] [--profile codex|claude|copilot|gemini|generic] [--task <id>] [--resume]` to generate a deterministic pack with a manifest of included/excluded files and reasons (`relativePath`, `action`, `reason`, `estimatedTokens`, `sha256`, `bytes`). Task-aware ranking (`--task`) and checkpoint resume (`--resume`) keep packs scoped; greedy fill excludes over-budget candidates with `budget exhausted`.
2. Review exclusions; add explicit includes only when the ranking missed real relevance (explicit include is the highest signal; no embeddings).
3. For bloated instructions, run `ackit optimize [--profile <name>] [--category <cat>] [--min-severity low|medium|high] [--explain] [--format terminal|json|markdown|sarif]` (read-only by default) and apply suggestions manually or with `ackit optimize --fix [--dry-run] [--diff]` — fixes apply ONLY to ACKit-managed surfaces.

## Notes

- Token counts are character-class estimates (~4 chars/token); treat budgets as soft targets.
- Safety gates run before scoring: secret-shaped content excluded, duplicate hashes deduped, machine-local paths scrubbed to `<local-path>`.
- Never paste repository content into external services.
19 changes: 19 additions & 0 deletions .agents/skills/ackit-context-optimization/references/ranking.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# Ranking signals

Precedence: explicit include > changed files > active-task references >
instruction scope > import proximity > README/architecture relevance >
file type, with a size penalty. Deterministic; no embeddings.

Weights: explicit include `+100`, git-changed `+60`, active-task reference
`+50`, instruction scope `+40`, import proximity `+30`,
README/architecture/docs `+20`, type base (md `10`, code `8`, config `6`,
other `2`), size penalty `-5` per 4KB capped `-40`. Ties break by ascending
repo-relative path.

Budget: greedy fill over the ranked list; over-budget candidates are excluded
with `budget exhausted`. Every manifest entry records `relativePath`,
`action` (`included`/`excluded`/`scrubbed`), `reason`, `estimatedTokens`,
`sha256`, `bytes`. Safety gates run before scoring: secret-shaped content
excluded, duplicate content-hash deduped, machine-local paths scrubbed.
`--task` boosts declared scope/refs/changed files; `--resume` embeds the
latest checkpoint resume section.
23 changes: 23 additions & 0 deletions .agents/skills/ackit-policy-authoring/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
---
name: ackit-policy-authoring
description: Author layered ackit policy files with deterministic merge, scoping and lockable rules.
---

# Policy Authoring

Activate when the user asks to codify scan thresholds or team-wide rule
overrides.

See [merge order](references/merge-order.md) for precedence and digest.

## Steps

1. Start from `ackit.yml`; add a policy layer with `schemaVersion: 1` and `extends` (local repo-relative files or `npm:<pkg>/<file>` for already-installed packages only — resolution is offline by construction, remote fetch is refused with `POL-OFFLINE-BLOCKED`).
2. Scope overrides with `org` / `repo` / `pathScopes`; lock security-relevant rules with `locked: true` so downstream layers cannot weaken them (`POL-LOCKED-CONFLICT`; deny is sticky across layers). Suppressions require `reason` and support `expiresAt`.
3. Verify with `ackit policy check` (chain plus digest plus autonomy plus review plus problems) and `ackit config check` (schema validation). Risk tiers (`tier0 allow` through `tier4 deny`) enforce ONLY at ACKit-owned boundaries (`task complete --force`, `checkpoint export`, `verification record`): explicit `deny` refuses with `POLICY-TIER-DENIED` (exit 4); explicit `ask` in a non-interactive context denies. Optional `review:` (`required` dimensions plus `blockingSeverity`) gates `PASS`-family verdicts via `VERDICT_BLOCKING`.

## Notes

- Remote URL auto-fetch is forbidden; dependencies must be pre-installed.
- Deterministic merge: defaults < `ackit.yml` < policy extends chain (declaration order) < CLI flags; arrays replace, objects merge; digest is sha256 over sorted-key JSON.
- Repositories without `autonomy:` / `review:` see zero behavior change.
12 changes: 12 additions & 0 deletions .agents/skills/ackit-policy-authoring/references/merge-order.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
# Merge order

defaults < ackit.yml < policy extends chain (in declaration order) < CLI
flags. Arrays replace; objects merge recursively. The effective policy digest
is sha256 over the canonical sorted-key JSON.

`extends` entries are local repo-relative files or `npm:<pkg>/<file>` for
already-installed packages only; remote fetch is refused
(`POL-OFFLINE-BLOCKED`), traversal outside the root is refused. Locked rules
(`locked: true`) cannot be weakened downstream (`POL-LOCKED-CONFLICT`); deny
is sticky across layers. `ackit policy check` prints chain, digest, autonomy,
review, and problems; `ackit config check` validates `ackit.yml` schema.
49 changes: 49 additions & 0 deletions .agents/skills/ackit-repo-workflow/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
---
name: ackit-repo-workflow
description: Run the UniGetUI ACKit start-of-task sequence, lifecycle gates, scans, readiness, packs, and evidence correctly. Use at task start, during work, and before completion.
---

# ackit repo workflow

Use for every UniGetUI task so ACKit gates stay green.

## Start of task

```powershell
ackit instructions --explain
ackit task list
ackit task show TASK-0001
ackit pack --profile codex --max-tokens 50000
```

Keep one active task with a single `[~]` item. Implementation lives under `docs/tasks/active/`; archive lives under `docs/tasks/archive/`.

## During work

```powershell
ackit scan --changed
ackit scan --staged
```

Boost or limit packs with `ackit pack --changed` and task-aware `ackit pack --task TASK-0001` when needed.

## Before done

```powershell
ackit config check
ackit policy check
ackit skills validate
ackit task doctor
ackit scan --ci
ackit readiness --strict
ackit optimize --explain
ackit diagnostics --json
```

Record exact outputs in task Completion notes. Complete only with verified evidence; archive with `ackit task archive <id>` after final proof.

## References

- Full contributor and agent guide is `docs/ACKIT.md`.
- Task lifecycle details are in the [ackit-workflow](../ackit-workflow/SKILL.md) builtin skill.
- Scan triage uses the [ackit-scan-and-fix](../ackit-scan-and-fix/SKILL.md) builtin skill.
23 changes: 23 additions & 0 deletions .agents/skills/ackit-scan-and-fix/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
---
name: ackit-scan-and-fix
description: Run ACKit scan, interpret findings by severity, and apply safe fixes with suppression hygiene.
---

# Scan and Fix

Activate when the user asks to scan, audit, or clean up the repository.

See [severity playbook](references/severity-playbook.md) for triage order.

## Steps

1. `ackit scan` (add `--ci` in CI contexts; `--format terminal|json|sarif|markdown|html`, `--baseline <file>` / `--write-baseline <file>`, `--changed` / `--staged` / `--since <ref>` / `--range <a..b>` for incremental sets) and read findings grouped by severity (`docs/reference/rules.md`).
2. Fix critical/high first: rotate exposed credentials out-of-band, remove keys, correct root-escape references. Values are never printed; do not paste findings into external services.
3. Suppress false positives ONLY inline with `# ackit-ignore:ACKITnnn <reason>` on the finding line or the line above (covers that line plus the next line); every applied bypass stays visible as a non-suppressible `ACKIT099` advisory. Policy-level suppressions require `reason` and support `expiresAt`; locked rules (`locked: true`) can never be weakened (`POL-LOCKED-CONFLICT`).
4. Re-scan (`ackit scan --ci`) and confirm exit 0 or an explicit accepted-risk list. Confirm offline policy with `ackit policy check` / `ackit config check` where thresholds or extends changed.

## Notes

- Unknown-extension files are always scanned; do not "fix" by renaming secrets away.
- Never weaken rules, thresholds, or baselines to make output green.
- Resolution is offline by construction; remote fetches never happen.
10 changes: 10 additions & 0 deletions .agents/skills/ackit-scan-and-fix/references/severity-playbook.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
# Severity playbook

- critical: credential/token exposure, private keys (`ACKIT001`, `ACKIT002`) — rotate first, then clean.
- high: connection strings, generic credential assignments, root escapes (`ACKIT003`, `ACKIT004`, instruction-graph escapes) — fix next.
- medium: entropy advisories (confirm before acting), config drift, path leaks (`ACKIT005`, `ACKIT010`, `ACKIT050`, `ACKIT070`, `ACKIT080`).
- low: hygiene markers, large context files, near-duplicates (`ACKIT020`, `ACKIT040`); every applied bypass emits `ACKIT099` (low/hygiene, not suppressible).

Inline suppression is `# ackit-ignore:ACKITnnn <reason>` on the finding line
or the line above (that line plus the next). File excludes come from config
`scan.exclude`; policy suppressions need `reason` and support `expiresAt`.
27 changes: 27 additions & 0 deletions .agents/skills/ackit-workflow/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
---
name: ackit-workflow
description: Enforce the ACKit docs-first, task-first workflow with one active checklist item and evidence-based completion.
---

# ACKit Workflow

Activate for any repository work session so tasks stay auditable.

See [task lifecycle](references/task-lifecycle.md) for statuses, gates, and archive rules.

## Steps

1. Discover work with `ackit task list` / `ackit task show <id>`; active work lives in `docs/tasks/active/` (completed work lives in `docs/tasks/archive/` and is resolved by ID, never treated as open). If none matches, create one with `ackit task create "<title>" [--intent INTENT-####] [--spec <path>] [--decision <path>] [--plan <path>]` (never invent IDs).
2. Keep exactly one `[~]` active checklist item; implement only that item; plan before code.
3. For workflow-enabled tasks, honor the declared profile: `ackit workflow set <id> --profile quick|standard|high-risk`, `ackit workflow show <id>`, `ackit workflow advance <id>`, `ackit workflow verify <id> --outcome pass|fail`. Provide `intentRef`/`specRefs`/`decisionRefs`/`planRef` when the stage requires them; referenced files must exist on disk.
4. Checkpoint long work: `ackit checkpoint create <id> --next-objective "<text>"`, `ackit checkpoint show <id>`, `ackit checkpoint validate <id>`, `ackit checkpoint export <id> [--out <file>]`; resume with `ackit task resume <id>`.
5. Link proof, do not assert it: `ackit evidence sync <id>`, `ackit evidence verify <id> --criterion AC-001 --type test --ref "<proof>"`, `ackit evidence validate <id>`; independent check via `ackit verification bundle <id>` then `ackit verification record <id> --verdict <file>` / `ackit verification show <id>`; watch drift with `ackit drift check <id>` (`ackit drift check-active` at the pre-commit gate).
6. Complete only through the composed gate: evidence complete, required verdict `PASS`/`PASS_WITH_WARNINGS` with zero blocking findings, stage complete, no unresolved `fail` attempt, no blocking drift. `VERIFY failed -> completed` is impossible without explicit `ackit task complete <id> --force` (tier2 boundary). Never mark `[x]` without command output in Completion notes.
7. Archive after final evidence: `ackit task archive <id>` (bulk `ackit task archive --completed [--dry-run]` moves completed-only; pending/active/blocked never move). `ackit task doctor` reports `TASK-COMPLETED-IN-ACTIVE` for completed work left in `active/`.
8. Gates before commit: `ackit doctor`, `ackit task doctor`, `ackit scan --ci`; run the task's own test plan and paste pass/fail counts into Completion notes; focused Conventional Commit, then immediately continue with the next dependency-ready task.

## Notes

- Unfinished work is never marked complete; checkpoint commits are fine.
- Out-of-scope requests become new tasks instead of scope creep.
- Tasks without workflow state keep pre-expansion behavior; workflow tasks enforce the gate.
18 changes: 18 additions & 0 deletions .agents/skills/ackit-workflow/references/task-lifecycle.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# Task lifecycle

Statuses: `[ ]` pending · `[~]` active · `[x]` completed+verified · `[!]` blocked.

Exactly one `[~]` item at a time. Never mark `[x]` without command output as
evidence in Completion notes. Blocked items stay visible with their blocker;
they are never silently skipped.

Active work lives in `docs/tasks/active/`; completed work lives in
`docs/tasks/archive/` and is resolved by ID (`ackit task show <id>`,
`ackit task list --all`). Archived completed tasks are not open work.

Workflow tasks complete only through the composed gate (evidence complete,
required verdict `PASS`/`PASS_WITH_WARNINGS`, stage complete, no unresolved
`fail`, no blocking drift). `ackit task doctor` reports
`TASK-COMPLETED-IN-ACTIVE` for completed work left in `active/`; archive it
with `ackit task archive <id>` (bulk `ackit task archive --completed
[--dry-run]` moves completed-only).
27 changes: 27 additions & 0 deletions .agents/skills/avalonia-ui/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
---
name: avalonia-ui
description: Implement UniGetUI Avalonia UI changes with correct View/ViewModel conventions, UI-thread dispatch, bindings, themes, and accessibility. Use when editing AXAML, controls, or app shell behavior.
---

# avalonia ui

Use for UniGetUI Avalonia work under `src/UniGetUI.Avalonia/`.

## Conventions

- Keep View/ViewModel separation; Views bind, ViewModels own state. Follow existing `Views/MainWindow.axaml` and `Program.cs` patterns.
- Dispatch UI updates on the UI thread; never touch visual state from background package-manager threads directly.
- Prefer compiled bindings and existing theme/resources; do not fork new theme dictionaries for one screen.
- Localize every user-facing string with `CoreTools.Translate`; in XAML use the `TranslatedTextBlock` control.

## Checks

- Keep Avalonia diagnostics gating intact: `EnableAvaloniaDiagnostics` in `src/Directory.Build.props`, compile gate `#if AVALONIA_DIAGNOSTICS_ENABLED` in `Program.cs`, runtime precedence CLI flags then `UNIGETUI_AVALONIA_DEVTOOLS` then `Auto`.
- Keep `Auto` WSL-safe (DevTools off by default on WSL); runtime toggle without build support logs a no-op warning.
- Verify XAML compiles via the relevant build in the [dotnet-build-test](../dotnet-build-test/SKILL.md) skill; run targeted tests before the full suite.
- Check keyboard navigation, contrast, and screen-reader names for new controls.

## Out of scope

- Package-manager logic belongs in the [package-manager-integration](../package-manager-integration/SKILL.md) skill.
- WinGet COM specifics belong in the [winget-native](../winget-native/SKILL.md) skill.
49 changes: 49 additions & 0 deletions .agents/skills/dotnet-build-test/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
---
name: dotnet-build-test
description: Build and test UniGetUI .NET/Avalonia solutions safely on Windows x64 with evidence-based failure classification. Use when building, testing, or validating formatting for UniGetUI C# changes.
---

# dotnet build test

Use for any UniGetUI C# build, test, or format check. Windows-first, x64, .NET 10.

## Solutions

- `src/UniGetUI.Windows.slnx` is the official Windows solution.
- `src/UniGetUI.Avalonia.slnx` is the cross-platform Avalonia solution.
- Target framework is `net10.0-windows10.0.26100.0` (min `10.0.19041`); tests use xUnit.

## Commands

Restore and test from `src/`:

```powershell
dotnet restore UniGetUI.Windows.slnx
dotnet test UniGetUI.Windows.slnx --verbosity q --nologo /p:Platform=x64
```

Read-only format gates (never mutate blindly):

```powershell
dotnet format whitespace src --folder --verify-no-changes
dotnet format style UniGetUI.Windows.slnx --no-restore --verify-no-changes
```

## Rules

- Do not run a broad mutating `dotnet format` across the solution. Use the verified whitespace/style verify commands and inspect the diff.
- Run the repo pre-commit hook setup once after cloning with `pwsh ./scripts/install-git-hooks.ps1`.
- Build affected projects first, then the full Windows solution; run targeted tests before the full suite.
- Treat every `IL2xxx` trim and `IL3xxx` AOT warning as a defect; do not blanket-suppress.

## Failure classification

- Baseline first: capture failing tests on clean `origin/main` before attributing failures to the change.
- Classify as pre-existing only with matching baseline output; otherwise treat as regression.
- Record exact commands plus pass/fail counts in task Completion notes.

## Completion gate

- Relevant whitespace/style verify passes.
- Relevant build passes on x64.
- Relevant tests pass; full suite pass or baseline-classified failures documented.
27 changes: 27 additions & 0 deletions .agents/skills/github-pr-ci/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
---
name: github-pr-ci
description: Keep UniGetUI branches clean, open focused PRs, and investigate CI without pushing local main. Use when branching, pushing to fork, or debugging dotnet-test and ACKit workflows.
---

# github pr ci

Use for branch hygiene, fork workflow, and CI triage. Upstream is `Devolutions/UniGetUI` as `origin`; fork is `Cynrath/UniGetUI` as `fork`.

## Branch hygiene

- Branch from clean `origin/main`; never merge local `main` or unrelated feature branches.
- Keep one logical change per branch; use the PR template and link issues without placeholders.
- Never push local `main` upstream. Push feature branches to `fork` for review.
- For rebased branches use `git push --force-with-lease`; never force-push `main`.

## CI triage

- `dotnet-test` runs whitespace/style verify, Windows x64 build, tests, full-trim and NativeAOT publish reports.
- ACKit workflow runs `ackit config check`, `ackit policy check`, `ackit skills validate`, `ackit task doctor`, `ackit scan --ci`, `ackit readiness --strict`.
- Pull logs first; classify as infra flake only with rerun evidence. Do not weaken thresholds to get green.
- Validate locally with the same commands before pushing.

## Approval boundary

- Fork workflow approval may be required before CI runs on new branches; request review rather than pushing workarounds.
- Do not open an upstream PR merely to create one; keep dogfooding branches on the fork with a written reason.
Loading
Loading