Files
Rohit Ghumare ed6d0c0196 feat: add agent skills track and stateless MCP curriculum (#422)
* feat(phase-13/22): teach portable agent skill contracts

Agent skills need a portable contract before host-specific metadata and runtime policy can be reasoned about.

* fix(phase-13/23): make the ecosystem capstone accurate

The capstone should model current A2A operations, portable artifact metadata, and deterministic trace timing.

* feat(phase-13/24): teach skill discovery and disclosure

A useful skill catalog needs explicit scope precedence and bounded progressive disclosure before instructions are loaded.

* feat(phase-13/25): teach invocation policy and routing

Human, model, application, and skill activation need separate policy decisions before relevance ranking can be trusted.

* feat(phase-13/26): teach skill sandbox and trust boundaries

Skill instructions are untrusted input, so authority must remain host-owned and every filesystem, network, and command boundary must fail closed.

* feat(phase-13/27): add the skill release gate

A distributable skill needs adversarial structure, routing, safety, artifact, provenance, installation, and portability evidence before release.

* feat(skills): install and render complete skill bundles

Progressive-disclosure skills must keep companion references, scripts, assets, and evals intact across discovery, installation, and lesson rendering.

* docs(curriculum): index the agent skills mini-course

The expanded Phase 13 sequence needs consistent lesson links, durations, translations, and shared terminology across every learner entry point.

* feat(certification/11): teach stateless MCP integration

Certification learners need the same stateless wire model as the production curriculum.

* feat(phase-11/14): modernize MCP protocol contracts

The foundational MCP lesson must no longer teach the removed session lifecycle.

* fix(phase-13/01): align tool terms with stateless MCP

The tool interface introduction should point to the current protocol vocabulary.

* feat(phase-13/06): teach stateless MCP fundamentals

Learners need the current per-request contract before building clients or servers.

* feat(phase-13/07): build a stateless MCP server

The server lab should model the protocol that new implementations actually ship.

* feat(phase-13/08): build a stateless MCP client

The client lab must negotiate every request without relying on session state.

* feat(phase-13/09): teach current Streamable HTTP

Transport examples need the current POST-only lifecycle and notification behavior.

* feat(phase-13/10): teach stateless resources and prompts

Resource and prompt discovery must reflect stateless cache and result contracts.

* feat(phase-13/11): teach per-request sampling

Sampling calls must carry current capabilities and stateless response semantics.

* feat(phase-13/12): teach roots and elicitation retries

Elicitation retries and roots handling need current capability and MRTR boundaries.

* feat(phase-13/13): teach stateless MCP tasks

Task storage and subscriptions must survive cross-instance stateless requests.

* feat(phase-13/14): update MCP Apps contracts

Apps learners need current bridge, subscription, and discovery boundaries.

* feat(phase-13/15): update MCP threat boundaries

Threat modeling must cover current routing and MRTR state boundaries.

* feat(phase-13/16): update MCP OAuth contracts

OAuth examples must bind issuers and resources while using current errors.

* feat(phase-13/17): update gateway and registry contracts

Registry admission must separate publication identity from runtime discovery.

* feat(phase-13/18): teach production MCP authentication

Production auth should implement real PKCE, CIMD, and resource-bound caching.

* docs(phase-13/22): add a runnable skill quickstart

Beginners need an exact repository-root path from bundle inspection to host use.

* fix(phase-13/23): make the capstone stateless

The ecosystem capstone must compose the same current contracts taught upstream.

* docs(phase-13/24): clarify host discovery limits

Learners should distinguish known context budgets from host fallback behavior.

* docs(phase-13/26): clarify sandbox prerequisites

The safety lab needs explicit prerequisites and a viable conceptual fallback.

* docs(phase-13/27): add real-host release evidence

A production claim should require installed-host evidence beyond deterministic fixtures.

* docs(phase-16/02): update MCP legacy comparison

The interoperability comparison should use the current stateless MCP lifecycle.

* feat(phase-19/13): modernize the MCP registry capstone

The production capstone must separate Registry publication from stateless runtime discovery.

* docs(curriculum): index agent skills and stateless MCP

Learners need one coherent route through the skills track and current MCP sequence.

* feat(skills): add a focused agent skills learner path

A dedicated route removes placement and navigation friction for focused learners.

* feat(mcp): add production engineering track

* fix(cert-11): harden MCP integration contract

* fix(phase-11-14): classify MCP handler failures

* fix(mcp-07): validate JSON-RPC request identifiers

* fix(mcp-08): reuse strict response decoding

* fix(mcp-09): harden HTTP transport boundaries

* fix(mcp-11): isolate returned tool descriptors

* fix(mcp-12): make continuation state single-use

* fix(mcp-14): align lesson response metadata

* fix(mcp-15): expire and consume continuation state

* fix(mcp-16): bind OAuth enrollment and code exchange

* fix(mcp-18): enforce redirect and code lifetimes

* fix(mcp-23): validate task identifiers

* fix(skills-24): clarify discovery boundaries

* fix(skills-25): deny unknown invocation actors

* fix(skills-26): validate approval policy shape

* fix(mcp-28): terminate unsafe cursor pagination

* fix(mcp-29): preserve completed request state

* fix(mcp-30): require secure remote endpoints

* fix(mcp-31): strengthen conformance checks

* fix(agent-skills): align route prerequisites

* fix(scripts): harden skill bundle installation

* fix(site): validate learning and artifact boundaries

* fix(course): address review edge cases

* fix(mcp): tighten notification and redirect validation

* fix(mcp): secure reproducible lesson state

* fix(mcp): use required lesson header comments
2026-08-23 18:01:53 +01:00

138 lines
5.9 KiB
JSON

{
"schemaVersion": 1,
"id": "agent-skills",
"title": "Agent Skills Engineering",
"summary": "Build, route, secure, evaluate, package, and verify Agent Skills in real hosts.",
"estimatedMinutes": 570,
"stateFile": "AGENT-SKILLS-LEARNING.md",
"prerequisites": [
{
"type": "knowledge",
"required": true,
"title": "Files, Python, and the command line",
"description": "You can edit a text file, inspect a directory, and run a Python command. No agent framework experience is required."
},
{
"type": "software",
"required": true,
"title": "Node.js, npx, and Python 3 for real labs",
"description": "The install and bundled-script checkpoints require working node, npx, and python3 commands. The website and docs remain a conceptual fallback when these commands are unavailable."
},
{
"type": "host",
"required": true,
"title": "One selected skill-capable host and install scope",
"description": "Choose a supported agent host plus a writable project or user skill scope before installation. Record the exact host, scope, and installed path; do not infer discovery from installer success."
},
{
"type": "lesson",
"required": false,
"title": "The Tool Interface",
"path": "phases/13-tools-and-protocols/01-the-tool-interface",
"description": "Skim this first if tool schemas and side-effect boundaries are new to you."
},
{
"type": "lesson",
"required": false,
"title": "Tool Schema Design",
"path": "phases/13-tools-and-protocols/05-tool-schema-design",
"description": "Skim this first if you have not designed typed tool contracts."
},
{
"id": "tool-poisoning-and-untrusted-instructions",
"type": "knowledge",
"required": true,
"title": "Tool poisoning and untrusted instructions",
"description": "Before Lesson 26, explain why skill and tool metadata is untrusted input. Lesson 15 is an optional refresher outside this five-lesson route when this preflight is not yet confirmed."
}
],
"invocation": {
"codex": "learn-agent-skills, or choose it from /skills",
"claudeCode": "/learn-agent-skills",
"portableFallback": "Use learn-agent-skills to start or resume the Agent Skills Engineering path."
},
"conceptualFallback": "Read the website or each lesson's docs/en.md manually. Mark real-host discovery, invocation, script, update, and uninstall evidence pending until Node.js, npx, Python 3, a compatible host, and a writable install scope are available.",
"quickStart": {
"estimatedMinutes": 10,
"lessonPath": "phases/13-tools-and-protocols/22-skills-and-agent-sdks",
"goal": "Create a small skill, install the complete reviewer bundle into a real host, invoke it explicitly, verify its output, and remove it cleanly.",
"installCommand": "npx skills add rohitg00/ai-engineering-from-scratch --skill skill-contract-reviewer --full-depth",
"workingDirectory": "An empty learner workspace. Save its absolute path as TARGET_ROOT before installation.",
"expectedEvidence": [
"The installer reports the selected host and destination.",
"The host discovers skill-contract-reviewer after a rescan or new session.",
"An explicit invocation returns a validation report and primitive choice, plus the resolved script path, target path, cwd, argv, and exit code.",
"The uninstall command removes only skill-contract-reviewer from the selected host."
]
},
"lessons": [
{
"order": 1,
"phase": 13,
"lesson": 22,
"title": "Agent Skills: Portable Contract and Runtime Boundary",
"path": "phases/13-tools-and-protocols/22-skills-and-agent-sdks",
"minutes": 90,
"required": true,
"checkpoint": "Create, install, invoke, verify, and remove one complete skill bundle in a real host."
},
{
"order": 2,
"phase": 13,
"lesson": 24,
"title": "Skill Discovery and Progressive Disclosure",
"path": "phases/13-tools-and-protocols/24-skill-discovery-and-progressive-disclosure",
"minutes": 105,
"required": true,
"checkpoint": "Trace discovery, catalog publication, activation, and branch-specific resource loading separately."
},
{
"order": 3,
"phase": 13,
"lesson": 25,
"title": "Skill Invocation and Routing",
"path": "phases/13-tools-and-protocols/25-skill-invocation-and-routing",
"minutes": 105,
"required": true,
"checkpoint": "Exercise explicit invocation, implicit selection, abstention, and a near-miss request."
},
{
"order": 4,
"phase": 13,
"lesson": 26,
"title": "Skill Permissions, Sandboxes, and Trust",
"path": "phases/13-tools-and-protocols/26-skill-permissions-sandboxes-and-trust",
"minutes": 120,
"required": true,
"prerequisitePaths": [
"phases/13-tools-and-protocols/25-skill-invocation-and-routing"
],
"prerequisiteChecks": [
"tool-poisoning-and-untrusted-instructions"
],
"checkpoint": "Distinguish instructions, permission prompts, sandbox containment, and independent verification with observed evidence."
},
{
"order": 5,
"phase": 13,
"lesson": 27,
"title": "Skill Evals, Packaging, and Portability",
"path": "phases/13-tools-and-protocols/27-skill-evals-packaging-and-portability",
"minutes": 150,
"required": true,
"checkpoint": "Run the release gate in a real host, record routing and authority evidence, and verify upgrade and uninstall behavior."
}
],
"optionalLessons": [
{
"phase": 13,
"lesson": 23,
"title": "Capstone: Stateless Tool Ecosystem",
"path": "phases/13-tools-and-protocols/23-capstone-tool-ecosystem",
"minutes": 120,
"required": false,
"entryRule": "Complete the Agent Skills route and Phase 13 lessons 06 through 20 before starting this systems integration capstone."
}
]
}