Idea to implementation
job-to-be-done → prototype → spec-pipeline → gauntlet-loop
It does not prove production fitness or authorize release.
Island Dev Crew / Forge 50
IDC Skills · The Forge
Velocity, welded to proof.
Fifty fused agent skills for building, researching, operating, verifying, and shipping—designed to increase velocity without loosening quality, control, or security boundaries.

Identity artwork — not evidence of release status. The proof is below.
The immutable tag and versioned external witnesses bind the exact release identity. "Signed · 5/5" means contentReady, not readyToRun=true. A sidecar is byte distribution; it does not prove cross-harness invocation semantics — see the five evidence layers.
Island Development Crew · Huntsville, Alabama — No authority without evidence.
How fifty islands compose
50 islands· 13 user-only· 3 loops
Forge 50 is a navigable system of independent agent skills. Use one island for a focused job or connect several into an inspectable loop. The shared law is simple: no authority without evidence. A claim is not complete until a red-capable check produces something another person can inspect.
Skills compose at runtime — one concern per island, loops over menus. Don't bundle; don't duplicate meaning across islands; keep every reference one level deep.
A loop is a coordinated set of skills forming a loop (align → spec → build → verify → ship → compound), not an unrelated catalog.
job-to-be-done → prototype → spec-pipeline → gauntlet-loop
It does not prove production fitness or authorize release.
computer-use-smoke → evidence-packet → cross-family-review → transport-complete
A successful transport check does not expand the scope of the reviewer's verdict.
arch-survey → deep-modules → folder-workspace → archipelago
It does not make architecture quality automatic; the chosen seam and evidence still need judgment.
binds a full SHA, names author + reviewer seats, and voids on move
is U-<n> + head + a recomputable command
answers who / where / from-what-head / since-when
is state-not-instructions … its receiver runs the wake protocol
The fleet names its seats by model family, always: OpenAI Codex, Claude Fable 5, Jon Isaac.
Why a naked skill pack is dangerous
619 egress· 395 git-guard· 5 checks· seq 4
Adopting one is a trust decision, and the IDC rule governs it: no authority without evidence. Stars, a familiar name, or "it's just a prompt" are not evidence.
scan: advisoryinstall hook: enforced
skill-supply-chain-review/SKILL.md · CHANGELOG.mdmachinery: implementedproduction: deferred
integrity/README.md · CHANGELOG.md · docs/2.0.5-release-scope.mdThe signed manifest binds tracked bytes, declared control files, POSIX-mode intent, external-reference observations, and reviewed fetch/execute exceptions. It does not certify benevolent intent, sandbox an agent, prevent same-user post-check mutation, or turn a repository-controlled verifier into an external freshness root.
Inspect the proof
tag 2.0.5· seq 4· 280 tests
Forge 50 2.0.5 is a limited-trust, public content-authenticated release. Its front door is new; its assurance boundary remains deliberately narrower than full freshness authority.
Assets: manifest.json and manifest.json.sig.
Served over HTTPS at a versioned path; carries the detached-signature digest.
DNSSEC validation requires an authenticated validating resolver or tool such as delv; seeing a TXT string with plain DNS lookup is not cryptographic validation.
What each check establishes — and what it does not. The two columns carry equal weight on purpose.
| Check | Establishes | Does not establish |
|---|---|---|
| validate_skills.py | Registry/frontmatter structure and named compatibility diagnostics | Signed identity, security, installation, or runtime behavior |
| verify_forge_50.py | Registry, validation-record, provenance, and vendored protocol closure | That every skill succeeds on every real task |
| skill_integrity.py verify | Signed tracked-byte and policy closure under the independently anchored Forge key | Freshness, benevolent intent, sandboxing, or readyToRun=true |
| Harness probe | The exact loader/invocation behavior exercised on one named harness/version | Other harnesses, versions, or policies |
| External freshness launcher | Newest authorized release plus content integrity under protected external state | Protection from a compromised operating system or trusted runtime |
| Independent exact-head review | A reviewer's verdict on one immutable commit/tree and stated matrix | Merge, tag, release, or broader authority |
RUN — you can recompute this from the checkout; the commands are in Install safely. REPO — declared in the repository; the release index lives on the trust-index branch, which is outside the release tree but not outside the repository. The two genuinely out-of-repository channels are the HTTPS and DNSSEC witnesses above.
If the tag, commit, tree, manifest, signature, fingerprint, or witness differs, stop. Preserve the exact bytes and command output, then follow SECURITY.md. Do not "repair" an immutable release or accept a close-looking fingerprint.
The hardening arc
2.0.1 → 2.0.5· 28→37· 300→395· 589→619· seq 1→2→4
git fixtures 28 → 3750 machine-readable records150 cases
100 unit tests + 20 subtestsguard 300/300egress 589/589
guard 395/395egress 619/61931 preserved Kimi records
tests 280manifestSequence 4
fixtures 28 → 37guard 300 → 395egress 589 → 619manifestSequence 1 → 2 → 4tests 100(+20) → 280
Promotion required the owner-held content signature, clean-clone reproduction, protected macOS/Linux CI, fresh exact-head independent acceptance, new versioned HTTPS and DNSSEC witnesses, an immutable annotated tag, exact release assets, and post-publication comparison of all channels.
The HTTPS witness and the DNSSEC TXT record for 2.0.5 were both published on 2026-09-09; the release identity is confirmed by two out-of-repository channels.
Choose your outcome
50 rows· 25 starting points· 25 unrouted· 13 user / 37 model
Choose the outcome. Bring the right discipline. These five routes are editorial starting points—not popularity rankings or blanket certifications. Every listed skill is independently addressable; successful execution remains task-, dependency-, platform-, and harness-specific. Each loop is a recommended composition.
Route key
buildresearchoperateverify & shiparchitect
Turn an idea into a scoped, testable implementation without confusing motion with progress.
job-to-be-done → prototype → spec-pipeline → gauntlet-loop
Replace plausible answers with sourced findings and context that survives the session.
grill → research/video-analysis → data-source-map → productionize-opinion
Coordinate agents and recurring work without losing ownership or control-plane history.
console-as-code → lane-claim → worktree-fleet/model-routing → agent-schedule
Turn "it works" into recomputable evidence, independent review, and exact-revision transport proof.
computer-use-smoke → evidence-packet → cross-family-review → self-contained-ship → transport-complete
Shape repository, domain, and module boundaries so agents navigate an explicit system.
arch-survey → deep-modules → folder-workspace/workspace-scaffold → archipelago
The catalog is ordered deliberately: authoring and review foundations come first, the ICM workspace cluster occupies 22–28, and shipping/governance skills close the chain. Invocation values come from the registry.
A new skill does not expand the fixed fifty by assertion; it must displace an incumbent under the repository's governance.
50 of 50 islands shown — the registry holds 37 model · 13 user · 25 start-here tags
All 50 registered islands at release 2.0.5, in registry order.
| # | Island | Invocation | Route (start here) | Job |
|---|---|---|---|---|
| 01 | idc-skill-authoring | model | Build | The skill layer of the canon — folder anatomy, progressive disclosure, invocation and router skills, the Codex openai.yaml sidecar, fleet distribution, and the evidence discipline. Points to writing-for-agents for the universal levers. |
| 02 | writing-for-agents | model | — | The universal levers for any document an agent reads — context pointers, the two loads, information hierarchy, completion criteria, leading words, pruning, and failure modes. Fires when editing AGENTS.md / CLAUDE.md / rules files. |
| 03 | cross-family-review | model | Verify & Ship | The crown ceremony: an independent reviewer from a different model family reviews a diff at an exact head along Standards and Spec axes and returns a named-seat verdict that voids on move. The author never reviews their own work. |
| 04 | worktree-fleet | user | Operate | Git worktrees for same-machine parallel agents, with the IDC boundary: adopted for drafts, forbidden for evidence. Worktree artifacts are inadmissible as gate evidence until re-derived from a fresh clone. |
| 05 | grill | model | Research | Relentless interview to reach shared understanding before building, in three modes (ambush, drill, batch), emitting settled decisions as ADRs. Facts are looked up; only decisions are asked. |
| 06 | wayfinder | user | — | Plan a chunk of work too big for one agent session — chart it as a shared map of decision tickets on the issue tracker, then resolve them one at a time until the way to the destination is clear. Plans across sessions by resolving decisions, not slices of a build. |
| 07 | agent-guardrails | model | — | Four mechanical layers under an AI fleet — shell denylist, git block, pre-commit gate, read-only data role — mechanizing the covenants beneath the prompts. |
| 08 | handoff | user | — | Compact a session into a state-based handoff a fresh agent resumes from with zero memory, plus the wake protocol the receiver runs — re-reading verdicts and register state from the tree before trusting the summary. |
| 09 | lane-claim | model | Operate | Declare-and-halt coordination for agents working one repo across many machines: claim a lane before touching it, halt if already claimed, release when done. Cures the cross-machine collisions worktrees cannot. |
| 10 | transport-complete | model | Verify & Ship | Ship a change and babysit it until verifiably live — commit, push, watch CI, confirm the deploy promoted the exact SHA, prove production serves it. Done means a health check for the exact SHA, not a successful push. |
| 11 | spec-pipeline | model | Build | One pipeline from a discussed feature to shipped code: spec (synthesis) then tracer-bullet tickets with blocking edges, implement at pre-agreed seams with TDD, then an optional persistent goal loop. |
| 12 | prototype | model | Build | Build a throwaway prototype to answer one design question — a single shareable HTML file for a logic/state question, or several switchable UI variants for a look question — then capture the answer and discard the code. |
| 13 | research | model | Research | Investigate a question against high-trust primary sources and capture findings as a cited Markdown file — every claim sourced or explicitly flagged unverified. DeepAPI is an optional backend. |
| 14 | finding-register | model | — | A durable register of findings each enumerated at an exact SHA (not a running count), provenance-marked in both directions, and given a collision-free id swept before allocation. |
| 15 | deep-modules | model | Architect | Shared vocabulary and enforcement for deep modules — a lot of behaviour behind a small interface at a clean seam — with the dependency-cruiser rules that make entry points the only way in. |
| 16 | domain-modeling | model | — | Actively build and sharpen a project's domain model — challenge terms, invent edge-case scenarios, and write the glossary and term-derived decisions down when they crystallise. The active discipline that changes the model, distinct from reading CONTEXT.md. |
| 17 | diagnose | model | — | A disciplined loop for hard bugs: build a tight red-capable feedback loop first, reproduce and minimise, hypothesise, instrument, fix with a regression test, post-mortem. Performance is judged by operation counts, not wall-clock. |
| 18 | archipelago | model | Architect | The full-cycle, evidence-gated build protocol — typed contracts at every seam, gates that must be able to fail, loopback routing, a tamper-evident ledger, and band caps you cannot talk your way past. |
| 19 | domain-wire | model | — | Wire a domain the IDC way — the three-lane model (story / product / AI-native), one canonical per venture with siblings 308-redirecting to it, automatic graduation when a brand deed exists, and canonicals moving in the same commit. |
| 20 | console-as-code | model | Operate | Assemble an agent's operating prompt from versioned in-repo blocks (BOOT, covenants, lanes, seats), stamped with the assembly SHA, so every prompt is an auditable artifact and the same console assembles identically on every seat. |
| 21 | evidence-packet | model | Verify & Ship | Assemble a byte-verifiable evidence packet — the diff, the verification-ladder commands, and their captured outputs — so a reviewer recomputes every claim instead of trusting the author. A weak and a frontier author are equally mergeable when both can run the ladder. |
| 22 | job-to-be-done | model | Build | The pre-build triage that asks whether a thing should be built or automated at all, and where the human stays in the loop — delegation/complexity/outcome, the 90/10 rule. Its best outcome is often 'don't build it'. |
| 23 | folder-workspace | model | Architect | Structure a repo as an ICM workspace — folders and markdown as agent architecture, routed by a three-layer map (map/rooms/workspace) so one agent becomes the agent each task needs, without agent swarms. The map is an auditable routing contract. |
| 24 | workspace-scaffold | model | Architect | Scaffold a new ICM workspace for a domain — generate the root map, the rooms, the naming conventions — then prove a fresh agent routes through it before declaring done. |
| 25 | data-source-map | model | Research | Wire an external data source into a workspace with a markdown descriptor — describe where a SQL/BigQuery/Drive/Oracle store lives, what it holds, and what to ask it, so an agent queries it on demand instead of ingesting it into a vector store. The descriptor is a map to live data, not a copy. |
| 26 | productionize-opinion | model | Research | Distill an operator's own raw material — transcripts, notes, decisions, chat history — into durable workspace context that carries their voice and process. Mines you, not external sources; inferences are marked as inferences. |
| 27 | skill-tune | model | — | Empirically improve a skill or context file — run it on representative tasks, judge each output, edit, re-run, and keep an edit only when a measured score rises. The most efficient files are small (500-800 tokens); a tuned file is usually a shorter file. |
| 28 | workspace-audit | model | — | Audit an ICM workspace for drift — check every path the map claims exists in the tree, and that no live room is missing from the map. The map is a claim; the tree is the evidence; drift is a claim the evidence contradicts. |
| 29 | wizard | model | — | Generate an interactive bash wizard that walks a human through steps only they can perform — opening each URL, saying what to click, capturing values, and writing them into .env files and GitHub Actions secrets. Ships a fixed template.sh UX library. |
| 30 | to-questionnaire | user | — | Turn a decision you can't answer alone into a Markdown questionnaire for the one person who can — filled in async or worked through together. Grills you about the send (who it goes to, what you need back), not the subject. |
| 31 | wait-what | user | — | Stop — that last message did not land. Re-pitch it with the missing context, in ASD-STE100 Simplified Technical English, grounded in the project's own CONTEXT.md ubiquitous language. |
| 32 | short | user | — | Compress the current answer — strip filler, simplify wording, cut length while keeping substance. |
| 33 | teach | user | — | A stateful multi-session teaching workspace — mission-grounded lessons from high-trust sources, delivered as beautiful self-contained HTML with tight feedback loops and learning records. |
| 34 | gauntlet-loop | user | Build | Convert any task into a fan-out of builder sub-agents each shadowed by a blind critic, looped against a falsifiable bar. The lightweight cousin of archipelago — wow-grade prototypes fast; graduate to archipelago when the bar must be a real gate. Ships build-prompt.sh, the deterministic task-to-prompt converter. |
| 35 | video-analysis | model | Research | Turn a video URL into a grounded analysis from two channels — the transcript (what was said) and frames sampled at a chosen cadence (what was shown); every claim cited to a transcript line or a frame number. Ships grab.sh. |
| 36 | arch-survey | model | Architect | Proactively survey a whole codebase for architectural refactor opportunities — mine change-history hot-spots, gate each through the deep-module deletion test, and rank them as a before/after report. The discovery scan that runs before deep-modules designs one chosen module. |
| 37 | merge-resolve | model | — | Resolve an in-progress git merge or rebase by tracing every conflicting hunk to the intent that authored it (commit/PR/issue), keeping both intents where they compose and recording the trade-off where they collide, never aborting, and running the project checks before finishing. |
| 38 | issue-triage | model | — | Move a queue of issues you did NOT create (bug reports, incoming requests, external PRs) through a triage state machine, grill for missing info, and emit durable agent-ready briefs — every AI note carrying an honesty disclaimer. The inbound on-ramp job-to-be-done and grill don't cover. |
| 39 | agent-schedule | model | Operate | Schedule an unattended agent on a recurring wall-clock (cron/systemd/heartbeat/while-sleep vs a built-in scheduler), then verify the schedule actually fired before trusting it. The only island triggered by time; every loop sibling is condition-driven. |
| 40 | prose-craft | user | — | Author original prose (article, essay, explainer) in two phases: EXPLORE mines fragments and coins the load-bearing leading word; EXPLOIT builds grounded beats where no beat leans on an ungrounded concept, optionally shaping each block's form. Distinct from short/wait-what/teach/writing-for-agents. |
| 41 | delegated-authority-prompt | user | — | Compose a minimum-question, maximum-authority delegation prompt in five slots (objective + definition of done, context pack, decision rights, stop conditions, evidence contract) so a delegated agent runs far without check-ins, made safe by the tripwires that bound it. The mirror of grill: grill front-loads the questions, this front-loads the answers. |
| 42 | model-routing | model | Operate | Route one task to the cheapest model or tool that still clears its cognitive-demand floor (vision-native / deep-reasoning / cheap-bulk), and record why the pick clears the bar. The only island that selects the model a step runs on. |
| 43 | batch-sample-curate | user | — | Draw N candidates from a probabilistic-output tool (image/video/design/copy) and curate to the best against a scored keep/cut ledger, recording why each was kept or cut. Distinct from gauntlet-loop (refine one to a bar) and prototype. |
| 44 | self-contained-ship | model | Verify & Ship | Prove a deliverable phones home to nobody before it ships — a static egress scanner (schemes wss/ws/ftp + fetch/WebSocket/XHR/EventSource/import/@import/url/src/href, per-hit bounded egress-ok waiver) paired with a sealed offline load asserting zero outbound. The containment gate; transport-complete proves liveness, not containment. |
| 45 | computer-use-smoke | model | Verify & Ship | Drive a real UI through a scripted smoke path and assert observable outcomes (Playwright/browser-use/computer-use) — the runtime primitive that produces the band-4 evidence archipelago demands but nothing else makes. A verdict is an assertion; a screenshot is triage. |
| 46 | skill-supply-chain-review | model | — | Audit a third-party agent skill before adopting it — provenance, hidden/implicit invocation, dangerous instructions, prompt-injection surface, unresolved pointers — and emit a trust verdict bound to a pinned version. No authority without evidence, applied to the supply chain. |
| 47 | ai-humanizer | model | — | Detect and SCORE AI-writing tells in prose — a bundled statistical + pattern scorer emitting a deterministic 0-100 AI-likeness number — so a de-slop pass yields byte-verifiable before/after evidence (the score dropped), not a claim. The prose cluster's failing check. |
| 48 | exposure-audit | model | — | Read-only exposure audit of any target machine or repo against a NAMED advisory (CVE/breach/malicious-package/supply-chain) — enumerate what is installed and reachable, decide affected-or-not on captured evidence, write a structured report. Read-only; never remediate. |
| 49 | skill-duel | user | — | Run an incumbent skill against a challenger through ONE identical gauntlet (same executor cases, same defect-tied critic, same seat) and return a swap/no-swap verdict welded to the scores — a challenger displaces only by strictly beating the incumbent; a tie keeps the seat. The mechanical governor of the capped pack. |
| 50 | connected-fix-prompt | user | — | Compose ONE dependency-ordered refinement prompt from a set of findings — rank N interdependent defects root-cause-before-symptom and by impact, each carrying recomputable evidence, so a fixer clears them in a single correct-order pass instead of thrashing. The composer between finding-register and the fixer. |
Read the full catalog in the 2.0.5 tree →
Forge 50 fuses public work from David Ondrej, Matt Pocock, and Jake Van Clief with IDC-authored islands and field discipline. IDC's contribution is not a claim to other people's work; it is the weld. THIRD-PARTY-NOTICES.md
Install safely
6 steps· 5 evidence layers
The safe path begins outside the checkout: compare the tag, commit, tree, manifest digest, and signing fingerprint with the immutable release and both external witnesses. Do not execute repository code until that identity comparison agrees.
Forge 50 separates four decisions that ordinary install guides often collapse:
git clone https://github.com/Island-Dev-Crew/idc-skills.git
cd idc-skills
git checkout --detach 2.0.5
git rev-parse HEAD
git rev-parse HEAD^{tree}Expected
68ce34a032484529104b570d417e29ac8156b080
ec2ee9b600aba60c46ca1a1f793484018ff78ea3
Do not take the expected commit and tree from the tracked README or from the checkout you are trying to authenticate. Stop on any mismatch. Do not substitute a branch, fork, mirror, archive repost, or similarly named tag.
DNSSEC validation requires an authenticated validating resolver or tool such as delv; seeing a TXT string with plain DNS lookup is not cryptographic validation.
python3 -I -B scripts/validate_skills.py --json
python3 -I -B scripts/verify_forge_50.py --json
python3 -I -B scripts/verify_harness_support.py
python3 -I -B scripts/verify_runtime_requirements.py \
--contract runtime-requirements.json
# the three remaining RUN receipts in the strip above
python3 -B -m unittest discover -s tests -p 'test_*.py'
skills/agent-guardrails/scripts/test-block-dangerous-git.sh
skills/self-contained-ship/scripts/test-scan-egress.shExpected
valid: true … errors: 0 … warnings: 13
pass: true … skills: 50 … compatibilityAdvisories: 13
Ran 280 tests
RESULT pass=395 fail=0
RESULT pass=619 fail=0
The 13 warnings and 13 compatibility advisories are expected: they name the thirteen user-only islands that carry the Claude-family disable-model-invocation extension. Errors, not warnings, are the stop condition. These commands execute repository-controlled Python. They prove their named repository facts for the identified checkout; they are not a sandbox, do not independently authenticate the checkout, and do not prove successful invocation in a live harness.
python3 -I -B scripts/skill_integrity.py verify \
--ssh-keygen /independently/selected/ssh-keygen \
--ssh-keygen-sha256 sha256:<independently-computed-executable-digest> \
--jsonProceed only on
contentReady: true, score: 5/5
SHA256:LBkF4ekX2Z1XQ08gjjExnku92wAgmyFA04YJqPiczbA
This gate authenticates the scoped signed bytes and policies. It is not freshness authority, a sandbox, or proof that every signed instruction is safe for every environment.
These paths are deployment templates, not values to copy literally. The production threshold/freshness ceremony is not activated for 2.0.5, so 2.0.5 cannot honestly complete this route as readyToRun=true.
An operator may adopt content after a valid contentReady result under an explicit local policy that accepts the missing external freshness guarantee. That choice is outside the 2.0.5 release authority. The repository intentionally provides no flag that relabels it readyToRun=true and no direct-install bypass for the launcher.
The harness matrix is a dated 2026-08-11 contract covering 15 surfaces with mixed evidence states; not a universal support promise.
The five evidence layers
1. byte distribution; 2. loader discovery; 3. explicit invocation; 4. implicit-invocation policy; 5. successful execution. A green result at one layer is not evidence that the next layer passed.
Use GitHub's private “Report a vulnerability” flow → Do not place exploit details, credentials, private keys, or unredacted host evidence in a public issue.
Questions about Forge 50: hello@islanddevcrew.com
Island Development Crew · Huntsville, Alabama
Contributions are welcome, but a persuasive description is not acceptance evidence.
MIT — see LICENSE and THIRD-PARTY-NOTICES.md.
No authority without evidence.