feat(design): ask once before downloading impeccable's engine

When the probe prints DESIGN_DETECTOR_INSTALL_OFFER the design skills ask the
user one AskUserQuestion, in interactive sessions only (spawned or headless
runs never install and never ask; Conductor gets the prose brief), before
any other step: install the engine now, not now, never ask again
(design_detector_install_prompted), or turn the detector off. A yes runs the
receipted, checksum-pinned install and the skill continues with a READY probe.
The brief says what impeccable is, what the one file is, where it goes, how
it is verified and logged, and that no skill or hook comes with it; users who
want the /impeccable skill run npx impeccable install themselves.

design-review carries the brief inline (it is not carved). design-html keeps
its skeleton small: the probe block points at a new read-on-demand section,
sections/detector-install-offer.md, registered in its manifest and carve
guard; its skeleton ceiling is re-measured (55,262) and its eager ceiling
set to the measured 13,767. The review and ship passes state that they never
offer an install. NOTICE.md, README, docs/skills.md, the interop design doc,
and the CHANGELOG describe the new posture: gstack still never runs
impeccable's installer or launcher; the one download is consented, pinned,
and receipted. Ship goldens refreshed for the review-pass wording.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Garry Tan
2026-09-09 04:51:14 +00:00
co-authored by Claude Fable 5.1
parent 3b7a2775ee
commit 92f85f1ba8
19 changed files with 168 additions and 24 deletions
+7 -3
View File
@@ -21,9 +21,13 @@ Unmodified copy:
- `test/fixtures/impeccable-antipatterns.json`: `crates/live/assets/antipatterns.json` at commit 87d8f6d6 (engine-v0.1.3), wrapped in a `_source` provenance object.
Not distributed: `bin/gstack-design-detect.ts` invokes an impeccable engine the
user installed. gstack does not ship, download, or install that engine, and does
not audit its network behavior; the wrapper refuses URL targets so gstack never
asks it to touch the network.
user installed. gstack does not ship or mirror that engine and never runs impeccable's
installer or launcher. The one download gstack can make is the engine binary
itself, only after the user accepts a design skill's one-time offer: fetched from
impeccable's own GitHub release into `~/.impeccable/bin/<version>/`, verified
against the checksum pinned in `lib/design-detect-contract.ts`, and recorded in
the egress ledger first. gstack does not audit the engine's network behavior; the
wrapper refuses URL targets so gstack never asks it to touch the network.
## DESIGN.md specification — Copyright Google LLC — Apache License 2.0