agy-native · diff

git:20260715.cb2a7ac to git:20260716.2ff3bc2

12 added, 0 removed. Audit A to A.

---
name: agy-native
description: 'Use an explicitly selected AGY runtime for one provided packet or fresh validator context. Triggers: "agy", "antigravity", "AGY evidence".'
practices: [team-topologies, design-by-contract]
hexagonal_role: driving-adapter
consumes: [explicit-packet]
produces: [agy-run-evidence]
context_rel:
- kind: separate-ways
with: codex-exec
skill_api_version: 1
user-invocable: false
metadata:
tier: cross-vendor
dependencies: []
capabilities: [dispatch_explicit_packet, provide_fresh_context]
effects: [start_agy_session]
canonical_status: canonical
disposition: keep_optional_adapter
output_contract: AGY runtime evidence
---
# AGY Native
Use AGY only when the caller explicitly selects that runtime. Discover its live
command surface before acting and scope every session to the supplied workspace
and packet.
+ Discovering the live command surface before acting works because AGY's CLI
+ changes faster than any skill text: a remembered flag is a guess, while a
+ freshly listed one is evidence.
+
+ Named failure mode — **wrapper drift**: invoking AGY through remembered
+ syntax that silently changed, producing runs that look scoped but are not.
+
+ Anti-pattern: reusing one AGY session for both author and validator roles
+ because starting a second session is slower. Corrective: keep the identities
+ distinct; a shared session forfeits the fresh-judgment guarantee that makes
+ the validator's evidence usable.
+
- Keep author and validator sessions distinct when AGY supplies both roles.
- Persist the runtime conversation/context identity and artifact references.
- Validators remain read-only and hand judgment to Validate; they do not write
the core verdict directly.
- AGY plugin, memory, permission, retry, and session state remain substrate facts
and never become AgentOps phase, queue, or completion state.
- Never invoke `claude -p` through an AGY wrapper.
Return evidence to the caller and stop. Installation, plugin mutation, and
recurring scheduling require separate explicit authorization.