← Back to catalogue
Published

Agent Skill / Instruction

vr.wm-knw-005 · wm-knw-005-agent-skill-instruction

Represent a governed, versioned and portable reusable instruction package that tells an AI agent when and how to perform a bounded capability, with explicit contracts, resources, authority, safety and evaluation semantics.

World Models Information and virtual systems INF.KNW.SKL

Bundle → Layer → Finding → Questions Filled

7 bundles · 16 layers · 32 findings · 96 questions

Identity, discovery and stewardship Establishes which reusable skill exists, how it is found and who governs each immutable release.

Skill identity, class and release

Stable semantic identity, package identity and immutable version.

Skill master identity, name, class and alias

Identifies the reusable skill, governed namespace, canonical lowercase package name, semantic class, aliases and collision history independently of installation path.

  1. What governed skill assertion is recorded for skill master identity, name, class and alias, for which skill identity, release, task context, agent environment and lifecycle state? identity
  2. Which source, steward, standard, validation or evaluation establishes skill master identity, name, class and alias, with what evidence, confidence, freshness and limitations? provenance
  3. Which authority, safety, compatibility or change rule governs skill master identity, name, class and alias, and how are permissions, predecessors, successors and external bindings preserved? validation

Release version, status, compatibility and predecessor

Records immutable release identity, semantic version, publication status, compatibility range, predecessor, supersession and change classification.

  1. What governed skill assertion is recorded for release version, status, compatibility and predecessor, for which skill identity, release, task context, agent environment and lifecycle state? lifecycle
  2. Which source, steward, standard, validation or evaluation establishes release version, status, compatibility and predecessor, with what evidence, confidence, freshness and limitations? ownership
  3. Which authority, safety, compatibility or change rule governs release version, status, compatibility and predecessor, and how are permissions, predecessors, successors and external bindings preserved? security

Purpose, discovery and stewardship

Intent metadata, ownership, licensing and source authority.

Purpose, description, capability, tags and discovery keywords

Explains what the skill helps an agent do, when to use it, supported capability class, domain tags, synonyms and search or matching hints.

  1. What governed skill assertion is recorded for purpose, description, capability, tags and discovery keywords, for which skill identity, release, task context, agent environment and lifecycle state? definition
  2. Which source, steward, standard, validation or evaluation establishes purpose, description, capability, tags and discovery keywords, with what evidence, confidence, freshness and limitations? authority
  3. Which authority, safety, compatibility or change rule governs purpose, description, capability, tags and discovery keywords, and how are permissions, predecessors, successors and external bindings preserved? privacy

Author, steward, publisher, source, license and attribution

Binds creator, current steward, publisher, repository and release source, supplier, license, copyright, attribution and contact or disclosure channels.

  1. What governed skill assertion is recorded for author, steward, publisher, source, license and attribution, for which skill identity, release, task context, agent environment and lifecycle state? ownership
  2. Which source, steward, standard, validation or evaluation establishes author, steward, publisher, source, license and attribution, with what evidence, confidence, freshness and limitations? requirement
  3. Which authority, safety, compatibility or change rule governs author, steward, publisher, source, license and attribution, and how are permissions, predecessors, successors and external bindings preserved? retention
Applicability, activation and context Defines when a skill is relevant, when it must not be selected and which environment and context make activation valid.

Triggers, matching and exclusions

Task-to-skill selection and negative applicability.

Use-when trigger, intent, object and evidence

Defines explicit request, artifact type, task intent, domain concept, environment signal and evidence sufficient to rank the skill as relevant.

  1. What governed skill assertion is recorded for use-when trigger, intent, object and evidence, for which skill identity, release, task context, agent environment and lifecycle state? requirement
  2. Which source, steward, standard, validation or evaluation establishes use-when trigger, intent, object and evidence, with what evidence, confidence, freshness and limitations? constraint
  3. Which authority, safety, compatibility or change rule governs use-when trigger, intent, object and evidence, and how are permissions, predecessors, successors and external bindings preserved? access

Do-not-use exclusion, overlap, conflict and selection priority

Defines negative triggers, adjacent skill boundary, incompatible task, ambiguity, priority, tie-breaking and fallback when no safe match exists.

  1. What governed skill assertion is recorded for do-not-use exclusion, overlap, conflict and selection priority, for which skill identity, release, task context, agent environment and lifecycle state? constraint
  2. Which source, steward, standard, validation or evaluation establishes do-not-use exclusion, overlap, conflict and selection priority, with what evidence, confidence, freshness and limitations? process
  3. Which authority, safety, compatibility or change rule governs do-not-use exclusion, overlap, conflict and selection priority, and how are permissions, predecessors, successors and external bindings preserved? exception

Preconditions, environment and context budget

Operational compatibility and minimum context required before loading.

Agent runtime, platform, package, network and storage compatibility

Declares supported agent interface, operating system, runtime, packages, filesystem, database, network, locale and resource constraints with version ranges.

  1. What governed skill assertion is recorded for agent runtime, platform, package, network and storage compatibility, for which skill identity, release, task context, agent environment and lifecycle state? interoperability
  2. Which source, steward, standard, validation or evaluation establishes agent runtime, platform, package, network and storage compatibility, with what evidence, confidence, freshness and limitations? event
  3. Which authority, safety, compatibility or change rule governs agent runtime, platform, package, network and storage compatibility, and how are permissions, predecessors, successors and external bindings preserved? interoperability

Task context, input availability, token budget and freshness

Specifies required user intent, active Dimension, files or records, policies, model context, context budget, freshness and unresolved prerequisites before activation.

  1. What governed skill assertion is recorded for task context, input availability, token budget and freshness, for which skill identity, release, task context, agent environment and lifecycle state? state
  2. Which source, steward, standard, validation or evaluation establishes task context, input availability, token budget and freshness, with what evidence, confidence, freshness and limitations? measurement
  3. Which authority, safety, compatibility or change rule governs task context, input availability, token budget and freshness, and how are permissions, predecessors, successors and external bindings preserved? decision
Contracts and instructions Defines typed inputs and outputs, success and failure evidence, and the decision procedure communicated to the agent.

Input and argument contract

Typed invocation data, defaults, validation and sensitive fields.

Input name, schema, type, cardinality, default and example

Defines each input or argument, machine schema dialect, type, requiredness, multiplicity, default, examples, units, allowed values and reference resolution.

  1. What governed skill assertion is recorded for input name, schema, type, cardinality, default and example, for which skill identity, release, task context, agent environment and lifecycle state? composition
  2. Which source, steward, standard, validation or evaluation establishes input name, schema, type, cardinality, default and example, with what evidence, confidence, freshness and limitations? evidence
  3. Which authority, safety, compatibility or change rule governs input name, schema, type, cardinality, default and example, and how are permissions, predecessors, successors and external bindings preserved? identity

Input source, validation, trust, sensitivity and redaction

Declares source authority, trust boundary, validation, normalization, secrets or personal-data handling, redaction, freshness and rejection behavior.

  1. What governed skill assertion is recorded for input source, validation, trust, sensitivity and redaction, for which skill identity, release, task context, agent environment and lifecycle state? validation
  2. Which source, steward, standard, validation or evaluation establishes input source, validation, trust, sensitivity and redaction, with what evidence, confidence, freshness and limitations? quality
  3. Which authority, safety, compatibility or change rule governs input source, validation, trust, sensitivity and redaction, and how are permissions, predecessors, successors and external bindings preserved? definition

Output, result and evidence contract

Expected products, completion criteria and failure semantics.

Output schema, artifact, state and evidence

Defines structured and unstructured outputs, artifacts, state changes, references, validation report, provenance, audience and evidence of completion.

  1. What governed skill assertion is recorded for output schema, artifact, state and evidence, for which skill identity, release, task context, agent environment and lifecycle state? composition
  2. Which source, steward, standard, validation or evaluation establishes output schema, artifact, state and evidence, with what evidence, confidence, freshness and limitations? validation
  3. Which authority, safety, compatibility or change rule governs output schema, artifact, state and evidence, and how are permissions, predecessors, successors and external bindings preserved? classification

Success, partial success, error, postcondition and acceptance

Defines success, partial, no-op, blocked, cancelled and error outcomes, postconditions, acceptance checks, residual risks and escalation evidence.

  1. What governed skill assertion is recorded for success, partial success, error, postcondition and acceptance, for which skill identity, release, task context, agent environment and lifecycle state? state
  2. Which source, steward, standard, validation or evaluation establishes success, partial success, error, postcondition and acceptance, with what evidence, confidence, freshness and limitations? security
  3. Which authority, safety, compatibility or change rule governs success, partial success, error, postcondition and acceptance, and how are permissions, predecessors, successors and external bindings preserved? composition

Instruction, procedure and decision logic

Authoritative steps, branches, examples and edge cases.

Instruction goal, sequence, checkpoint, branch and stop condition

Structures goal, ordered or conditional steps, checkpoints, branch predicates, loops, stop conditions, escalation and handoff without owning the task run.

  1. What governed skill assertion is recorded for instruction goal, sequence, checkpoint, branch and stop condition, for which skill identity, release, task context, agent environment and lifecycle state? process
  2. Which source, steward, standard, validation or evaluation establishes instruction goal, sequence, checkpoint, branch and stop condition, with what evidence, confidence, freshness and limitations? privacy
  3. Which authority, safety, compatibility or change rule governs instruction goal, sequence, checkpoint, branch and stop condition, and how are permissions, predecessors, successors and external bindings preserved? relationship

Example, counterexample, edge case, ambiguity and fallback

Provides representative inputs and outputs, invalid cases, boundary examples, common failure modes, ambiguity resolution and safe fallback behavior.

  1. What governed skill assertion is recorded for example, counterexample, edge case, ambiguity and fallback, for which skill identity, release, task context, agent environment and lifecycle state? evidence
  2. Which source, steward, standard, validation or evaluation establishes example, counterexample, edge case, ambiguity and fallback, with what evidence, confidence, freshness and limitations? retention
  3. Which authority, safety, compatibility or change rule governs example, counterexample, edge case, ambiguity and fallback, and how are permissions, predecessors, successors and external bindings preserved? state
Resources, tools and dependencies Organizes progressive disclosure and binds scripts, tools, APIs, references and assets without importing their lifecycles.

Progressive disclosure and bundled resources

Layered loading, context cost and safe reference traversal.

Bootstrap metadata, instruction body and load order

Defines always-visible metadata, activation-loaded instructions, on-demand resources, read order, context cost, maximum depth and cache or invalidation behavior.

  1. What governed skill assertion is recorded for bootstrap metadata, instruction body and load order, for which skill identity, release, task context, agent environment and lifecycle state? process
  2. Which source, steward, standard, validation or evaluation establishes bootstrap metadata, instruction body and load order, with what evidence, confidence, freshness and limitations? access
  3. Which authority, safety, compatibility or change rule governs bootstrap metadata, instruction body and load order, and how are permissions, predecessors, successors and external bindings preserved? lifecycle

Reference, template, example, asset and data resource

Catalogues non-executable documentation, templates, examples, schemas, lookup data and media by purpose, path or URI, digest, media type and load condition.

  1. What governed skill assertion is recorded for reference, template, example, asset and data resource, for which skill identity, release, task context, agent environment and lifecycle state? composition
  2. Which source, steward, standard, validation or evaluation establishes reference, template, example, asset and data resource, with what evidence, confidence, freshness and limitations? exception
  3. Which authority, safety, compatibility or change rule governs reference, template, example, asset and data resource, and how are permissions, predecessors, successors and external bindings preserved? temporal

Scripts, tools, APIs and software dependencies

Executable bindings, interface schemas and dependency resolution.

Script, command, entry point, runtime and integrity

Binds executable files or commands to entry points, runtime, arguments, dependencies, digest, provenance, isolation, expected exit and error behavior.

  1. What governed skill assertion is recorded for script, command, entry point, runtime and integrity, for which skill identity, release, task context, agent environment and lifecycle state? interoperability
  2. Which source, steward, standard, validation or evaluation establishes script, command, entry point, runtime and integrity, with what evidence, confidence, freshness and limitations? interoperability
  3. Which authority, safety, compatibility or change rule governs script, command, entry point, runtime and integrity, and how are permissions, predecessors, successors and external bindings preserved? spatial

Tool, API, resource, capability and dependency binding

References tools or APIs by authority and version with input and output schema, side-effect declaration, credentials, availability, alternatives and compatibility range.

  1. What governed skill assertion is recorded for tool, api, resource, capability and dependency binding, for which skill identity, release, task context, agent environment and lifecycle state? relationship
  2. Which source, steward, standard, validation or evaluation establishes tool, api, resource, capability and dependency binding, with what evidence, confidence, freshness and limitations? decision
  3. Which authority, safety, compatibility or change rule governs tool, api, resource, capability and dependency binding, and how are permissions, predecessors, successors and external bindings preserved? provenance
Authority, safety and trust Separates technical capability from permission, controls consequential actions and defends instruction and package supply chains.

Permission, delegation and secret boundary

Requested access versus effective authority and least privilege.

Requested tool, file, network, database and data access

Declares required and optional access scopes, purpose, target, duration, sensitivity, read or write effect and least-privilege alternative.

  1. What governed skill assertion is recorded for requested tool, file, network, database and data access, for which skill identity, release, task context, agent environment and lifecycle state? access
  2. Which source, steward, standard, validation or evaluation establishes requested tool, file, network, database and data access, with what evidence, confidence, freshness and limitations? identity
  3. Which authority, safety, compatibility or change rule governs requested tool, file, network, database and data access, and how are permissions, predecessors, successors and external bindings preserved? ownership

Effective policy, delegation, confirmation, credential and audit

Binds active Dimension policy, role, delegated authority, confirmation threshold, credential reference, expiration and external audit record without embedding secrets.

  1. What governed skill assertion is recorded for effective policy, delegation, confirmation, credential and audit, for which skill identity, release, task context, agent environment and lifecycle state? authority
  2. Which source, steward, standard, validation or evaluation establishes effective policy, delegation, confirmation, credential and audit, with what evidence, confidence, freshness and limitations? definition
  3. Which authority, safety, compatibility or change rule governs effective policy, delegation, confirmation, credential and audit, and how are permissions, predecessors, successors and external bindings preserved? authority

Action risk, reversibility and failure

Consequences, safeguards, compensation and prohibited behavior.

Side effect, hazard, severity, reversibility and compensation

Classifies read-only, reversible, destructive, external or consequential effects, affected subjects, hazards, severity, reversibility and compensation plan.

  1. What governed skill assertion is recorded for side effect, hazard, severity, reversibility and compensation, for which skill identity, release, task context, agent environment and lifecycle state? quality
  2. Which source, steward, standard, validation or evaluation establishes side effect, hazard, severity, reversibility and compensation, with what evidence, confidence, freshness and limitations? classification
  3. Which authority, safety, compatibility or change rule governs side effect, hazard, severity, reversibility and compensation, and how are permissions, predecessors, successors and external bindings preserved? requirement

Pre-write check, confirmation, post-write verification and prohibition

Defines preconditions, approval or confirmation, dry-run and preview, write boundary, readback verification, rollback, escalation and forbidden actions.

  1. What governed skill assertion is recorded for pre-write check, confirmation, post-write verification and prohibition, for which skill identity, release, task context, agent environment and lifecycle state? constraint
  2. Which source, steward, standard, validation or evaluation establishes pre-write check, confirmation, post-write verification and prohibition, with what evidence, confidence, freshness and limitations? composition
  3. Which authority, safety, compatibility or change rule governs pre-write check, confirmation, post-write verification and prohibition, and how are permissions, predecessors, successors and external bindings preserved? constraint

Trust, injection and supply-chain security

Origin verification, instruction hierarchy and executable isolation.

Instruction authority, untrusted content, injection and isolation

Classifies instruction sources by authority, treats retrieved content and tool output as data, defines conflict behavior, sanitization, sandboxing and exfiltration boundaries.

  1. What governed skill assertion is recorded for instruction authority, untrusted content, injection and isolation, for which skill identity, release, task context, agent environment and lifecycle state? security
  2. Which source, steward, standard, validation or evaluation establishes instruction authority, untrusted content, injection and isolation, with what evidence, confidence, freshness and limitations? relationship
  3. Which authority, safety, compatibility or change rule governs instruction authority, untrusted content, injection and isolation, and how are permissions, predecessors, successors and external bindings preserved? process

Package source, digest, signature, attestation and vulnerability

Records source and build provenance, digest, signature, attestation, supplier, dependency inventory, vulnerability evidence, review and trust decision.

  1. What governed skill assertion is recorded for package source, digest, signature, attestation and vulnerability, for which skill identity, release, task context, agent environment and lifecycle state? provenance
  2. Which source, steward, standard, validation or evaluation establishes package source, digest, signature, attestation and vulnerability, with what evidence, confidence, freshness and limitations? state
  3. Which authority, safety, compatibility or change rule governs package source, digest, signature, attestation and vulnerability, and how are permissions, predecessors, successors and external bindings preserved? event
Execution, evaluation and observability Binds skill activation to external runs and records validation, evaluation, regression and privacy-aware evidence.

Activation and run binding

Instantiation, state, idempotency, retry and cancellation references.

Activation selection, version, context and run reference

Records why a release was selected, resolver and policy versions, task context digest, arguments, activation time and external agent, task or workflow run identifier.

  1. What governed skill assertion is recorded for activation selection, version, context and run reference, for which skill identity, release, task context, agent environment and lifecycle state? event
  2. Which source, steward, standard, validation or evaluation establishes activation selection, version, context and run reference, with what evidence, confidence, freshness and limitations? lifecycle
  3. Which authority, safety, compatibility or change rule governs activation selection, version, context and run reference, and how are permissions, predecessors, successors and external bindings preserved? measurement

Run state, tool-call result, idempotency, retry, cancel and recovery

References execution states, tool calls, outputs, errors, idempotency keys, retry policy, cancellation, compensation and recovery evidence without owning the execution engine.

  1. What governed skill assertion is recorded for run state, tool-call result, idempotency, retry, cancel and recovery, for which skill identity, release, task context, agent environment and lifecycle state? lifecycle
  2. Which source, steward, standard, validation or evaluation establishes run state, tool-call result, idempotency, retry, cancel and recovery, with what evidence, confidence, freshness and limitations? temporal
  3. Which authority, safety, compatibility or change rule governs run state, tool-call result, idempotency, retry, cancel and recovery, and how are permissions, predecessors, successors and external bindings preserved? evidence

Validation, tests, evaluations and telemetry

Conformance, behavioral evidence, regression and monitored use.

Format, link, schema, dependency, permission and security validation

Runs structural, reference, schema, dependency, compatibility, permission, integrity, injection and prohibited-action checks against pinned rules.

  1. What governed skill assertion is recorded for format, link, schema, dependency, permission and security validation, for which skill identity, release, task context, agent environment and lifecycle state? validation
  2. Which source, steward, standard, validation or evaluation establishes format, link, schema, dependency, permission and security validation, with what evidence, confidence, freshness and limitations? spatial
  3. Which authority, safety, compatibility or change rule governs format, link, schema, dependency, permission and security validation, and how are permissions, predecessors, successors and external bindings preserved? quality

Test, evaluation, baseline, metric, regression, telemetry and privacy

Versions test cases, evaluators, datasets, baselines, metrics, thresholds, results, variance, regressions, monitored outcomes, sampling and privacy controls.

  1. What governed skill assertion is recorded for test, evaluation, baseline, metric, regression, telemetry and privacy, for which skill identity, release, task context, agent environment and lifecycle state? measurement
  2. Which source, steward, standard, validation or evaluation establishes test, evaluation, baseline, metric, regression, telemetry and privacy, with what evidence, confidence, freshness and limitations? provenance
  3. Which authority, safety, compatibility or change rule governs test, evaluation, baseline, metric, regression, telemetry and privacy, and how are permissions, predecessors, successors and external bindings preserved? validation
Distribution, lifecycle and interoperability Governs registries, resolution, installation, enablement, update, rollback, deprecation, removal and portable projections.

Registry, resolution, installation and local state

Discovery sources, dependency solving and governed local adoption.

Registry, channel, release resolution, dependency lock and mirror

Identifies registries and channels, resolves immutable release and dependencies, records lock, mirror, availability, revocation and offline or federated source behavior.

  1. What governed skill assertion is recorded for registry, channel, release resolution, dependency lock and mirror, for which skill identity, release, task context, agent environment and lifecycle state? interoperability
  2. Which source, steward, standard, validation or evaluation establishes registry, channel, release resolution, dependency lock and mirror, with what evidence, confidence, freshness and limitations? ownership
  3. Which authority, safety, compatibility or change rule governs registry, channel, release resolution, dependency lock and mirror, and how are permissions, predecessors, successors and external bindings preserved? security

Install, enable, disable, scope, precedence, conflict and local delta

Separates package installation from enablement and activation, records system, user, project or Dimension scope, precedence, conflicts, approved local extensions and effective state.

  1. What governed skill assertion is recorded for install, enable, disable, scope, precedence, conflict and local delta, for which skill identity, release, task context, agent environment and lifecycle state? state
  2. Which source, steward, standard, validation or evaluation establishes install, enable, disable, scope, precedence, conflict and local delta, with what evidence, confidence, freshness and limitations? authority
  3. Which authority, safety, compatibility or change rule governs install, enable, disable, scope, precedence, conflict and local delta, and how are permissions, predecessors, successors and external bindings preserved? privacy

Update, deprecation, migration and portability

Compatible evolution, rollback, retirement and standards projections.

Update, compatibility, migration, rollback, deprecation and removal

Evaluates version constraints, applies migration or rollback, communicates deprecation and end of support, disables or removes copies and preserves required evidence.

  1. What governed skill assertion is recorded for update, compatibility, migration, rollback, deprecation and removal, for which skill identity, release, task context, agent environment and lifecycle state? lifecycle
  2. Which source, steward, standard, validation or evaluation establishes update, compatibility, migration, rollback, deprecation and removal, with what evidence, confidence, freshness and limitations? requirement
  3. Which authority, safety, compatibility or change rule governs update, compatibility, migration, rollback, deprecation and removal, and how are permissions, predecessors, successors and external bindings preserved? retention

Agent Skills, MCP, JSON Schema, SPDX and SLSA crosswalk and loss

Pins source and target versions, maps metadata, arguments, tools, resources, packages and attestations, validates projections and declares omitted or non-round-trippable meaning.

  1. What governed skill assertion is recorded for agent skills, mcp, json schema, spdx and slsa crosswalk and loss, for which skill identity, release, task context, agent environment and lifecycle state? interoperability
  2. Which source, steward, standard, validation or evaluation establishes agent skills, mcp, json schema, spdx and slsa crosswalk and loss, with what evidence, confidence, freshness and limitations? constraint
  3. Which authority, safety, compatibility or change rule governs agent skills, mcp, json schema, spdx and slsa crosswalk and loss, and how are permissions, predecessors, successors and external bindings preserved? access

Classifiers Filled

Family
World Models
Category
Information and virtual systems
Entry kind
aggregate
Navigation path
NAV.INF.KNW.SKL
Domain
INF.KNW.SKL
Industry
Cross-industry
Tags
agentskillinstructioninf.knw.skl

What it is Filled

Owns skill semantic identity, immutable releases, purpose, discovery, applicability, activation conditions, input and output contracts, instruction procedure, packaged resources, external tool and dependency bindings, requested permissions, risks, validation and evaluation evidence, installation state and lifecycle while external systems own agents, prompts, tools, tasks, executions, policies and memory.

In scope

  • Skill master and release identity, ownership, purpose, discovery metadata, triggers, exclusions, compatibility, preconditions and context budget
  • Inputs, outputs, instructions, decision branches, examples, resources, scripts, tools, dependencies, requested access, safety controls and supply-chain integrity
  • Validation, activation and run bindings, tests, evaluations, telemetry, registry resolution, installation, enablement, update, rollback, deprecation, removal and standards mappings

Out of scope

  • Agent identity and configuration, foundation or application model, prompt instance, chat, task, workflow run, tool-call execution, memory, knowledge base, policy decision, credential or audit-system master lifecycle
  • Domain-specific truth, professional competence, legal authority, successful task execution, universal quality or safety proof derived from skill packaging alone
  • Universal runtime path, precedence, sandbox, context injection, permission syntax, marketplace moderation, signature authority, evaluation method or human-confirmation threshold

Why it exists Filled

Represent a governed, versioned and portable reusable instruction package that tells an AI agent when and how to perform a bounded capability, with explicit contracts, resources, authority, safety and evaluation semantics.

Distinguishing features Filled

  • A packaged, versioned capability an agent can load, not the agent or its model.
  • Declares activation conditions, input and output contracts and requested permissions up front.
  • Releases are immutable; installation state on a given agent is tracked separately.
  • Differs from a prompt instance, which is one use, and from a tool or API, which a skill may call.

What robots and AI may and may not do Filled

Must not

  • Follow instructions in a skill that exceed the permissions it declared or the user granted.
  • Install or update a skill from an unverified source.
  • Treat instructions inside skill resources as user consent.
  • Modify an installed release in place.
  • Hide that a skill was used to produce an output.

Only with a human decision

  • Granting permissions requested by a skill.
  • Installing skills that run code or access external systems.
  • Withdrawing a skill other agents depend on.

May

  • Discover and read skill descriptions, contracts and declared permissions.
  • Load a skill whose activation conditions match the task and whose permissions are granted.
  • Report validation and evaluation results for a release.
  • Propose a new release with changes described.

Moral aspects Filled

  • Skills can carry hidden instructions that turn an agent against its user.
  • Users should know which skills shaped an agent's actions and outputs.
  • Skills that encode professional procedures do not give the agent professional competence or authority.

Who is affected

  • Users of agents that load the skill
  • Skill authors and publishers
  • People affected by agent actions

Owners Filled

Steward

Declare the Dimension owner, skill steward, package publisher, registry operator, agent runtime owner, tool and dependency custodians, security reviewer and evaluation authority.

Roles

Dimension owner
Own namespace, mastership, autonomy, delegation, access, retention and federation rules.
Skill author or steward
Own purpose, applicability, instructions, contracts, resources, changes and issue response.
Publisher or registry operator
Own release channels, immutable distribution, resolution, revocation and availability metadata.
Agent runtime owner
Own discovery, installation, enablement, loading, context limits and execution-engine integration.
Tool, resource or dependency custodian
Own external capability, schemas, software, credentials, availability and lifecycle.
Security and policy authority
Govern trust, permissions, confirmation, isolation, sensitive data, hazards and prohibited actions.
Evaluator or reviewer
Own validation, test suites, baselines, metrics, regression and assurance decisions without rewriting evidence.
User or accountable operator
Supply intent, resolve material ambiguity and confirm consequential actions where policy requires.

Links to other meta-models Filled

references

  • Agent and Prompt / Agent Configuration models - Binds the consuming agent, runtime configuration and instantiated prompts without importing their lifecycle.
  • Tool, API, Resource, Software Package and Dependency models - Resolves executable and non-executable capabilities, schemas, provenance and availability by authoritative identity.
  • Task, Workflow, Execution, Policy, Credential, Memory, Evidence and Audit models - Connects activation, authority, operational effects, context and evidence while retaining external mastership.

aligned

  • Agent Skills Specification - Supports portable SKILL.md packages, metadata and progressive disclosure while identifying Vercy governance extensions.
  • Model Context Protocol 2025-11-25 - Supports prompt, tool and resource projections without collapsing a skill into an MCP server feature.
  • JSON Schema Draft 2020-12 and Semantic Versioning 2.0.0 - Supports machine contracts and release compatibility with pinned dialect and declared limits.
  • SPDX 3.0.1 and SLSA 1.2 - Supports package, dependency, license, provenance, attestation and verification projections without proving instruction safety.

neighbor

  • Prompt and Agent Configuration - A skill is reusable procedural knowledge selected for a context; a prompt is an instantiated message or template and agent configuration governs the agent's persistent setup.
  • Tool, API and Resource - The skill declares required capability and interface bindings, but tools and resources own discovery, invocation, schema, authorization, availability and result lifecycles.
  • Task, Workflow and Execution - The skill defines a reusable procedure and can bind activation or outcome evidence; the instantiated task and execution engine own run state, tool calls, cancellation and operational effects.
  • Policy, Permission, Credential and Audit - Requested permissions and safeguards are local declarations; the active Dimension policy grants authority, credential masters supply secrets by reference and audit systems own immutable access trails.
  • Software Package and Supply Chain - Bundled scripts and dependencies are software artifacts referenced with SPDX and SLSA evidence; this model specializes their role inside a skill but does not own build or vulnerability lifecycle.
  • Memory, Knowledge, Document and Dataset - References and examples may load contextual content on demand, while source documents, datasets, memory records and truth claims remain governed externally.

What else AI and robots need to interact with it Filled

Identity and identifiers required Filled

  • Authoritative skill registry or master-system identifier and immutable release identifier.
  • Governed globally resolvable skill and release IRI or package coordinate.
  • Adopting-Dimension UUID or ULID when no authoritative external identifier exists.

Direct properties not applicable Not applicable

Not applicable

Institutional or informational subject: no invented physical properties.

Recognition optional Filled

  • A skill has a name, a release version, a purpose, activation conditions, an instruction body and declared permissions.
  • It is confused with a system prompt, a tool definition and a software library.

Capabilities and actions required Filled

  • Register skill: Create a governed semantic identity, purpose, steward, source, license and initial release lineage.
  • Assemble and publish release: Package instructions, metadata, resources and dependency declarations as an immutable release.
  • Discover and rank skill: Match a task and environment against use-when, exclusion, compatibility and confidence evidence.
  • Validate skill and bindings: Validate package form, references, schemas, dependencies, permissions, integrity and prohibited actions.
  • Resolve and install release: Resolve immutable release and dependency lock, verify provenance and create a scoped installed copy.
  • Enable, disable or prioritize skill: Change effective availability and precedence for a governed scope without changing package content.
  • Activate and load skill: Select a validated release, load instructions and minimum resources, and create an external run binding.
  • Authorize and propose action plan: Translate instructions into a policy-checked plan with tool requests, confirmations, safeguards and expected evidence.
  • Record run outcome: Bind external task, workflow and tool-call results to the skill release and activation context.
  • Evaluate and regression-test skill: Run pinned structural, behavioral, safety and compatibility evaluations and compare with baselines.
  • Update, migrate or rollback skill: Evaluate compatibility, install a successor, migrate local deltas or restore a prior verified release.
  • Deprecate, remove or export skill: Publish retirement state, remove eligible local copies or create a standards-aligned projection with loss declaration.

Hazards and failure modes required Filled

  • Prompt injection hidden in skill resources.
  • Supply-chain compromise of a published skill.
  • Permission creep across releases.
  • Outdated instructions applied to changed tools.

Standards and interfaces required Filled

  • Model Context Protocol (MCP) for tool and resource bindings.
  • Semantic Versioning 2.0.0 for releases.
  • SLSA supply-chain levels for build provenance.
  • JSON Schema for input and output contracts.

Context of use required Filled

  • NIST AI RMF is a voluntary United States public-authority framework with broad international usefulness, not binding universal law.
  • Agent Skills and MCP are evolving specifications; adopting Dimensions must pin exact retrieved versions and experimental-field support.
  • SPDX and SLSA mappings support package and provenance assurance but do not independently prove instruction safety or domain correctness.

Sources Filled

  1. Agent Skills Specification - Agent Skills
  2. Prompts - Model Context Protocol
  3. Tools - Model Context Protocol
  4. JSON Schema Draft 2020-12 - JSON Schema
  5. Semantic Versioning 2.0.0 - Semantic Versioning
  6. SPDX Specification - SPDX Project
  7. SLSA Specification - Supply-chain Levels for Software Artifacts
  8. AI Risk Management Framework - National Institute of Standards and Technology
  9. PROV-O: The PROV Ontology - World Wide Web Consortium
  10. RFC 3339: Date and Time on the Internet: Timestamps - Internet Engineering Task Force

Open questions

  • Validate profiles for Codex, Claude, Gemini, GitHub Copilot and other agent runtimes, including discovery paths, activation precedence and context-loading behavior.
  • Develop permission, secret, network, filesystem, database, sandbox, confirmation and destructive-action policy recipes for personal and organizational Dimensions.
  • Create signing, revocation, dependency-lock, vulnerability, provenance and evaluation fixtures for registry installation, update and rollback.
  • Approve sibling model identifiers and relation cardinalities for agents, prompts, tools, APIs, tasks, workflows, policies, software packages, knowledge resources, executions and evaluations.
  • Runtime-specific discovery paths, precedence, context injection, permission syntax, tool naming, sandboxes and installation policy require pinned agent profiles.
  • Agent, model, prompt, tool, API, task, workflow, execution, policy, credential, memory, knowledge-base, software, evidence and audit lifecycles remain in neighboring masters.
  • Certified cross-runtime portability fixtures, domain task benchmarks, vulnerability feeds, signature roots, marketplace moderation and revocation federation remain future work.

Machine files

Provenance

world-models research · reviewable-draft

Built from: models/wm-knw-005-agent-skill-instruction/spec.yaml, ver-cy/world-models/card-supplements/wm-knw-005-agent-skill-instruction.json