Components
The dashboard
Reads the vault broadly and writes to it narrowly. Binds to localhost only, because it can send as the user.

It reads almost everything and writes almost nothing. That asymmetry is the whole design, and it is deliberate rather than incidental.
What it may read is the vault broadly — tasks, notes, insights, activity, whatever a person wants to see in one place instead of in forty files. What it may write is a short, closed list: append a captured task, mark one finished, set a status on an outbox item, refresh its own derived cache.
It stopped being read-only, and that is worth saying out loud
The honest version of this component’s history is that it was read-only, and is not any more. It gained an outbox, and an outbox that cannot record that something was sent is a worse record than no outbox at all.
So it writes — and the list of what it may write stayed short on purpose. A surface that can display anything and change four specific things is a surface whose blast radius can be reasoned about. One that can change whatever it displays is not.
Localhost only, for one reason
It binds to the loopback interface and nowhere else, because through its dispatch surface it can send messages as the user. That is not a capability that belongs on a listening port. The constraint costs nothing — it runs on the machine the vault is on — and it removes an entire class of question.
One part of this is public, and it is old
A snapshot of this component was published in March and has not been touched since. The version described on this page is not that snapshot — it has moved on by dozens of contract revisions, and the public copy predates most of what is written here.
That is stated rather than left to be discovered. A reader who clones a six-month-old snapshot of a component whose current version is private has been sent somewhere by a page that looked current. A stale public copy is worse than no public copy, because it carries the authority of being official without the property of being true.
This part is not published
It is a local application and not in a public repository. The pattern transfers even though the code does not: read widely, write from a short enumerated list, and bind narrowly when the thing can act as a person.
Declared in the contract Not published
- Kind
- local web application
- Role
- Reads the vault and serves it: tasks, insights, activity, and the outbox where staged material is dispatched
- Reads
-
the vault broadly
- Writes
-
_inbox/_tasks.yaml — appends a captured task, marks one finished_inbox/_inbox.yaml — capture items_outbox/<item>/_manifest.md — the status, status-note, channel and contact fields only_outbox/<item>/_manifest.md — a new one where the folder has none, on confirmation (CR-115)<folder>/_summary.yaml — its own derived cache<folder>/_ops.yaml — one external_systems.chats entry, on explicit confirmation (CR-064)<folder>/_insights.yaml — the promotion_review block only, on explicit action (CR-100)
- Depends on
-
- messaging client (as a library, for the chat channel)
- Binds
- localhost only — it can send as the user
- Documentation belongs to
- the component's own repo
Worth knowing. Not read-only, and has not been since it gained the outbox. What it may write is deliberately narrower than what it may read
From ecosystem.yaml, contract 41 · core-skills 1.89.4 · read at build 2026-10-08