About

Why the repository is public and the vault is not

This framework is developed against real data. Not a sample, not a fixture — an actual vault holding actual meetings with actual colleagues in it. That is deliberate, and it is the thing that requires the most explaining.

Why not develop against test data

Because almost every design decision recorded in this repository came from something going wrong in a way nobody would have invented. A status report that was true line by line and still missed the one fact that mattered. A field that sat at the wrong value for four releases because nothing read it back. A check that reported everything clean against a site with three missing pages.

Test data produces a framework that handles the situations you already thought of.

Which makes the boundary non-negotiable rather than careful

"Rewritten generically" is specific: an incident is described by its class, never its instance. Examples use invented names. The full specification of a change lives in the private vault; the public index carries a generic title row.

The inversion that makes it watchable

A guard runs before every push and scans every added line. The obvious design is a list of things that must never appear — and it does not work, because the set of real names cannot be enumerated. A colleague mentioned for the first time today is not on any denylist, and never was.

So the rule is inverted. Every name-like token in the repository must fully match a list of names known to be fictional. An unknown token blocks the push. The allow-list is public, because it contains only invented names — and adding a line to it is a conscious act: confirm the name is invented, never borrowed from someone real.

A denylist asks "is this one of the bad ones?" and fails open on everything it has not met. An allow-list asks "is this one of the ones I know are safe?" and fails closed. For a membrane, failing closed is the only acceptable direction.

What it caught

A history audit found three real contact identifiers sitting in example blocks that no denylist had ever heard of. They had been public. That is why there is now also a semantic review before each push — a person reading the added lines and answering three questions, because a pattern guard cannot judge meaning. A new customer name passes every regular expression ever written.

What this costs, and what it is worth

It costs a slower release. Every change is implemented generically, its evidence kept private, its public index row written separately, and its diff read by a human before it leaves.

What it buys is the only claim that matters here: a framework shaped by real failures, published without the failures themselves. Those are two different things, and keeping them apart is a mechanism rather than an intention.

From ecosystem.yaml, contract 41 · core-skills 1.89.4 · read at build 2026-10-08