Skip to content
E. AguilarKeel Skillsdocs
Menu · Skills, command & hook

Reference

Skills, commands & hooks

Everything the plugin ships. Skills are model-invoked — they trigger themselves when the situation calls for it. Commands are things you run. Hooks run automatically, and one of them can stop a tool call outright.

Skills#

authorization-protocol#

skill model-invoked

Decides whether the agent may act or must stop and ask — goal / method / green light (only a green light means go), the four-step check, hot zones, the following-through rule, and the rule for unattended runs. Triggers before any action that writes, edits, commits, pushes, deploys, sends, publishes, or reconfigures, and whenever a request is a vague goal (“do whatever is needed”, “fix this”, “handle it”) with no specific scope.

Full write-up: the permission model.

model-delegation#

skill model-invoked

Picks the cheapest model that still preserves quality and risk control, and keeps delegation shallow — tiers by task type, max subagent depth, no self-escalation, and a cheapest-first tool ladder. Triggers on model selection, “delegate this”, “spawn a subagent”, agent depth, cost control, and tool choice.

Full write-up: model & delegation.

context-discipline#

skill model-invoked

Keeps the session anchored in files rather than chat, covers what to do at the two ends of a session, and signals when to end a long one and hand off cleanly. Triggers on long sessions, context bloat, “where did we leave off”, source of truth, session handoff, and wrapping up.

Full write-up: context discipline.

workspace-hygiene#

skill model-invoked new in 0.6

Keeps documents and state honest as they age, and catches the drift a written rule didn't prevent: separating state from history and when to cut, why a bootstrap carries no state, dated snapshots, checks that each exist because a real drift already got through, the three finding levels, ratchet budgets, and what a periodic sweep may never do. Triggers on “is this still true”, stale docs, a doc contradicting the code, drift, a state file growing, and maintenance routines.

Full write-up: the operating loop.

repeatable-work#

skill model-invoked new in 0.6

Turns repeated manual work into a script or documented procedure: the rule of three, counting occurrences without fooling yourself, the properties an agent-run tool needs, test banks with a negative control, and the capture → harvest → adopt loop. Triggers on “I keep doing this”, third time, “write a script”, automate, encapsulate, and improvement backlog.

Full write-up: the operating loop.

Commands#

/keel-skills:onboard#

command you run it new in 0.6

The initiation program — run this first. It inspects what is actually in the directory (a repo or not, one project or several, the stack, existing agent instructions, existing state files, or nothing at all), reports what it found and what it could not tell, then offers three sizes and builds only the one you pick: the brake alone, plus the session loop, or plus the maintenance loop.

Note

It ends by making the brake fire on a real command and showing you the audit line — because “it's set up” is a claim, not evidence. If the hook doesn't fire, that's a finding to chase, not something to gloss over.

/keel-skills:policy-init#

command you run it

Scaffolds your project's AGENT_POLICY.md by exploring the repo and interviewing you about your hot zones and sources of truth. Checks for an existing policy first and offers to extend rather than overwrite. onboard calls this for its policy step, so the interview lives in one place.

/keel-skills:session-start#

command you run it new in 0.6

Opens a session from files: rules, then state, then only the docs for the area you're touching — and runs the project's checks before the work, so drift from the last session surfaces while it is still cheap and clearly not yours.

/keel-skills:session-close#

command you run it new in 0.6

Reconciles the session into the files: resolved items move to history, verified facts land where they belong, gaps get recorded as gaps. One line of history. Re-runs the checks, reports what's uncommitted, and leaves a handoff a fresh session can resume from.

/keel-skills:hygiene#

command you run it schedulable new in 0.6

A read-only sweep: uncommitted work, secrets in tracked files, state drift, stale drafts. It never fixes, commits, or deletes — everything needing a change is reported with a recommendation, which is what makes it safe to run unattended.

/keel-skills:harvest#

command you run it new in 0.6

Reviews what repeated across recent sessions and drafts the tools worth building. It proposes; it never adopts. Run it in its own session when capacity is spare — it costs a lot and produces no product.

Hooks#

SessionStart — inject-policy.cjs#

hook automatic

If your project has an AGENT_POLICY.md, it's injected into context at the start of every session — so the policy no longer depends on the agent remembering to read it. If there's no policy it prints a two-line nudge pointing at onboard, since installed-but-unconfigured is the most common way this framework silently does nothing. Silence the nudge with a policy, or .keel/skip-onboarding.

PreToolUse — enforce-policy.cjs#

hook automatic can deny

The hard backstop. Inspects every tool call before it runs and returns allow / ask / deny against the spec's hot defaults plus your policy's concrete paths, commands and MCP tools. Ask is the request for a green light. In a non-interactive run (CI, KEEL_NONINTERACTIVE=1) a hot action is denied instead, because no human is there to approve it. Every decision lands in .keel/audit.jsonl.

Shell commands are matched per segment: a standing allowance clears only the command it matches, never what that command is chained to, so npm run build && git push stays hot.

Watch out

A backstop, not a sandbox. It catches accidents, drift and hallucinated actions — a large lift in assurance — but a determined or jailbroken agent with shell access can route around pattern matching. Scoped credentials and real isolation are complementary, not replaced.

Runnable templates#

Copy these into your project — onboard does it for you at the level you pick.

TemplateWhat it is
checks/keel_checks.pyDependency-free, read-only checks script: five universal checks, the FAIL/WARN/info split from git status, and a documented extension point
checks/test_keel_checks.pyIts test bank — ten cases, four of them negative controls that fail if the checks go quiet
PROJECT_STATE.template.mdWhat is true now and what is open, with the status labels
HISTORY.template.mdWhat happened, dated — and the one-line rule that keeps it readable
IMPROVEMENTS.template.mdThe capture file for the improvement loop
routines/weekly-hygiene.mdA ready-made prompt for an unattended weekly sweep
AGENT_POLICY.template.mdThe canonical policy template

Repository layout#

ComponentPath
Skillsplugins/keel-skills/skills/<name>/SKILL.md
Commandsplugins/keel-skills/commands/<name>.md
Hooksplugins/keel-skills/hooks/hooks.json + inject-policy.cjs + enforce-policy.cjs
Templatesplugins/keel-skills/templates/
Policy packspolicies/<stack>/AGENT_POLICY.md
This repo's own policyAGENT_POLICY.md — Keel Skills runs on Keel Skills