allowed-stack-guardrail skillA
allowed-stack-guardrail is agent-read markdown (skill) from devantler-tech/agent-skills: Before agreeing to build anything for a non-technical user, check the need against the consuming deployment's "## Stack map" section: in-stack needs proceed; out-of-stack or unmatched needs get a friendly, jargon-free decline plus an offer to file a well-formed issue on the block's owning repo (or the map's default intake repo). Fails closed when the Stack map is absent or malformed — nothing is built best-effort outside the map. Use in a vibe-coding setting whenever a build request is about to .
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Allowed-stack guardrail
A deployment that lets people build conversationally still has a hard boundary: only the building
blocks the deployment actually operates are buildable. This skill is that boundary check. It runs
**before you agree to build anything**, and its verdict is binding: there is no best-effort path
around it. Declines are delivered in the register of the `jargon-free-voice` skill.
## The Stack map contract
The allowed stack is **deployment-owned configuration** — it never ships inside this skill. The
consuming deployment's canonical instructions file (`AGENTS.md`) defines it in a section titled
exactly **`## Stack map`**, containing:
- **A table** whose rows each carry three required fields:
- **Building block** — the block's plain-language name;
- **Good for** — the needs it serves, written in the user's vocabulary (this is the matching
surface);
- **Owning repo** — `owner/repo`, where a suggested issue for that block is filed.
- **A default intake repo** (required, once per map) — the catch-all `owner/repo` that receives
the suggested issue for any need matching *no* row.
…Read the whole file at its exact version.
How to install
mdr add devantler-tech/agent-skills/allowed-stack-guardrail@git:20260712.7b9904emdr add devantler-tech/agent-skills/allowed-stack-guardrail@sha256:441dcd44093994fbPin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_khzsfckgeedn6ewi)
1 badge views in 30 days
Versions
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (4618 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
devantler-tech/agent-skills · 3 stars · license Apache-2.0 · pushed 2026-09-24 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_khzsfckgeedn6ewi GET https://markdownregistry.com/api/v1/resolve?ref=devantler-tech/agent-skills/allowed-stack-guardrail GET https://markdownregistry.com/api/v1/blob/441dcd44093994fb2f6173091818f714725ee8f6f99ba2d833489d19de44ab95
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.