Let a package say which skills each coworker gets (#227)
Knowledge ships as one of three coworkers, described as answering company questions and citing sources, and the skills that would let it do that were seeded attached to nobody. So every clone started with the narrowing they exist for switched off, until somebody opened the Skills page and made the pairing by hand, in each deployment, again after each connector. The package wrote both files and knows which coworker it meant them for. This grants nothing, which is what makes seeding it safe. A skill is an instruction; what a Bot may call is its grants, and the offer each run is the intersection of the two, so a skill naming a tool its Bot does not hold loads nothing. MCP grants reach a person's own account and stay an administrator's decision, untouched. A redeploy takes back only what it gave: package grants carry a mark, and one an administrator made keeps their name and survives. A slug the package does not ship is refused at load rather than dropped, and a slug a person already owns is never granted, because the seed skips it and granting anyway would hand this Bot a stranger's instructions under a name the package expected to be its own.
D
David McKay committed
d293f2331bd5ff9ba4ad17af6ac94570a157d26d
Parent: 73ddf54
Committed by GitHub <noreply@github.com>
on 8/24/2026, 6:07:53 PM