Skip to content
Back to skills

Attach

ASecurity

Routes classifier judgment requests to the cli-jev (hosted Jev) or cli-deem (local Deem) transport through mode-registry.json. Holds no packet-local logic.

  • 36 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 1, 2026
documentationshellbashnodetestingbackend

Works with

  • cli
  • mcp

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add MichelKerkmeester/opencode--spec-kit-skilled-agent-orchestration --skill attach --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Attach?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Attach
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/michelkerkmeester-attach/badge)](https://www.skillsdirectory.com/skills/michelkerkmeester-attach)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cli-classifier
description: "Routes classifier judgment requests to the cli-jev (hosted Jev) or cli-deem (local Deem) transport through mode-registry.json. Holds no packet-local logic."
allowed-tools: [Read, Bash, Grep, Glob]
version: 1.1.0.0
---

<!-- Keywords: cli-classifier, cli-jev, cli-usage, cli-deem, jev, typed judgment, jev-mcp, local classifier, deem, deem model, deem judgment, deem health, noul, choice, score, local deem server -->

# cli-classifier - Classifier Transport Hub

One public skill identity for classifier models that return typed judgments: the hosted Jev service and the Deem model served on this machine. This hub holds no packet-local logic. It routes by `workflowMode` through `mode-registry.json` and uses `hub-router.json` for router policy, signals and outcomes.

---

## 1. WHEN TO USE

Use this skill when a request needs a typed judgment from a classifier or needs to know whether one is usable.

| Mode | Packet | Kind | Use it for | Tool posture |
|------|--------|------|------------|--------------|
| `cli-jev` | `cli-usage` | transport | A hosted Jev judgment through the `jev` CLI or its MCP surface: a probability, one option key, an ordered score position or a batch of keyed answers | Read and Bash only, mutates nothing |
| `cli-deem` | `cli-deem` | transport | A Deem availability check, a probability, one option key, an ordered level or a batch of keyed answers from the local Deem server | Read and Bash only, mutates nothing |

A caller names its backend. The two transports answer the same judgment types and never fail over to each other silently.

### When NOT to Use

- Work that needs an edit, a review or a multi-step process. Dispatch the judgment to a transport and pair it with a workflow mode.
- Running `jev-mcp` from a shell. Its stdio carries MCP frames, so it belongs in an MCP host configuration.
- Starting, stopping or updating the Deem server. That is the operator's step with `deem-ctl`.

---

## 2. SMART ROUTING

Routing is registry-driven. `mode-registry.json` lists every packet. `hub-router.json` decides whether the result is one transport, both transports in order or a defer.

> **Compiled routing (default-on, flag-gated, additive).** Resolve the mode via the compiled router contract first:
> ```bash
> node .skilled/bin/compiled-route.cjs --hub cli-classifier --prompt "<task>"
> ```
> Follow the returned decision: `route` (use its `targets`), `clarify`/`defer` (disambiguate), `reject` (refuse). On a `{"servingAuthority":"legacy"}` sentinel or any error, use the routing below. The front door self-gates on serving-authority. Compiled routing is now the default for `cli-classifier`. Set `SPECKIT_COMPILED_ROUTING=0` to force legacy routing fleet-wide. That is the explicit kill-switch.

### Two-Axis Model

- `packetKind: "transport"` marks a bridge to an external tool. It selects a value and never mutates this workspace.
- A transport declares `mutatesWorkspace: false`, forbids `Write`, `Edit` and `Task` and is registered under the `transport-axis` extension.
- The advisor resolves the hub identity and stays blind to the transports (`routingClass: "metadata"`). The hub owns the resolution.
- Mode `cli-jev` runs over the packet folder `cli-usage`, as mode `research` of `system-deep-loop` runs over `deep-research`.

### Routing Rule

```text
read hub-router.json
  -> score routerSignals and vocabularyClasses
  -> apply routerPolicy.tieBreak (cli-jev, then cli-deem)
  -> read mode-registry.json for packetKind, backendKind, toolSurface and advisorRouting
  -> load the selected packet
```

### Outcomes

- `single`: one dominant judgment intent routes to its transport. A Jev request routes to `cli-jev`, a Deem request to `cli-deem`.
- `orderedBundle`: a request that names both backends by their aliases, such as a jev judgment checked against a deem judgment, routes to both transports in `tieBreak` order, `cli-jev` first.
- `defer`: unclear intent asks for disambiguation rather than guessing a value. A request that names only the hub defers, because the hub name does not choose a backend.

---

## 3. HOW IT WORKS

### Layout

```text
cli-classifier/
  SKILL.md
  README.md
  mode-registry.json
  hub-router.json
  ROUTER.md                     # stage-two control, stage1-only
  description.json
  graph-metadata.json
  leaf-manifest.json
  changelog/
  manual-testing-playbook/
  benchmark/
  shared/
  cli-usage/                    # mode cli-jev
    SKILL.md
    README.md
    references/
    assets/
    feature-catalog/
    manual-testing-playbook/
    benchmark/
    changelog/
  cli-deem/                     # mode cli-deem
    SKILL.md
    README.md
    references/
    feature-catalog/
    scripts/
    changelog/
```

### Companion Metadata

- `mode-registry.json` owns `workflowMode`, `packetKind`, `backendKind`, `toolSurface`, packet folder identity, aliases and `advisorRouting`. Its `transport-axis` extension lists the transports.
- `hub-router.json` owns `routerPolicy`, `routerSignals`, `vocabularyClasses` and outcomes.
- `ROUTER.md` is the stage-two control document, `router_state: stage1-only` until an author promotes it with a concrete leaf map.
- `description.json` owns hub-doctor metadata.
- `graph-metadata.json` is the one skill-graph identity node for the hub.

### Extensions

- `transport-axis`: declares `transports: ["cli-deem", "cli-jev"]`. The per-hub gate enforces the whole transport contract: routingClass `metadata`, `mutatesWorkspace: false`, the forbidden tool set and membership in the axis.

---

## 4. RULES

### ALWAYS

- Resolve the packet through `mode-registry.json`. Never hardcode a transport's path in prose-only logic.
- Keep `SKILL.md` thin: routing, invariants and navigation only.
- Keep both transports non-mutating. A transport returns a value and selects. A workflow mode acts.
- Keep every transport `routingClass: "metadata"`. The hub resolves it and the advisor stays blind to the axis.
- Keep exactly one `graph-metadata.json`, at the hub root.

### NEVER

- Never grant `Write`, `Edit` or `Task` to a transport.
- Never add a second packet array or a packet-local `graph-metadata.json`.
- Never let a transport complete a task on its own.
- Never fail over from one backend to the other without the caller asking for it.
- Never start `jev-mcp` from a shell, and never start the Deem server from this hub or its packets.

### ESCALATE IF

- A request needs a judgment and an edit but no workflow mode is selected. Report the gap instead of mutating from a transport.
- `command -v jev` fails. Mode `cli-jev` is not routable on this machine, and the hub says so rather than inventing a judgment.
- `cli-deem health` exits non-zero. Deem is not usable for this run, and the hub says so rather than inventing a judgment.

---

## 5. REFERENCES

- Registry: [`mode-registry.json`](./mode-registry.json).
- Router: [`hub-router.json`](./hub-router.json).
- Root router: [`ROUTER.md`](./ROUTER.md).
- Mode `cli-jev`: [`cli-usage/SKILL.md`](./cli-usage/SKILL.md), [`cli-usage/references/cli-reference.md`](./cli-usage/references/cli-reference.md), [`cli-usage/references/providers-and-models.md`](./cli-usage/references/providers-and-models.md), [`cli-usage/references/integration-patterns.md`](./cli-usage/references/integration-patterns.md), [`cli-usage/references/mcp-server.md`](./cli-usage/references/mcp-server.md).
- Mode `cli-deem`: [`cli-deem/SKILL.md`](./cli-deem/SKILL.md), [`cli-deem/references/wire-contract.md`](./cli-deem/references/wire-contract.md), [`cli-deem/references/deem-ctl-lifecycle.md`](./cli-deem/references/deem-ctl-lifecycle.md), [`cli-deem/references/model-pin.md`](./cli-deem/references/model-pin.md).
- Hub metadata: [`description.json`](./description.json), [`graph-metadata.json`](./graph-metadata.json), [`leaf-manifest.json`](./leaf-manifest.json).
- Hub changelog: [`changelog/v1.1.0.0.md`](./changelog/v1.1.0.0.md).

---

## RELATED RESOURCES

- `manual-testing-playbook/manual-testing-playbook.md` - the hub's operator-facing scenario index.
- `cli-usage/manual-testing-playbook/manual-testing-playbook.md` - the `cli-jev` transport's own scenario index.
- `.skilled/skills/sk-doc/sk-create-skill/references/parent-skill/parent-skills-nested-packets.md` - the parent-hub pattern this hub follows.

Files in this skill

  • README.md4.9 KB
  • ROUTER.md3.5 KB
  • SKILL.md8.1 KB
  • benchmark/README.md1.7 KB
  • benchmark/reports/README.md1.9 KB
  • canary-cases.v1.json3.4 KB
  • changelog/v1.1.0.0.md2.4 KB
  • description.json1.4 KB
  • graph-metadata.json5.1 KB
  • hub-router.json2.1 KB
  • manifest.cli-classifier.json195 B
  • mode-registry.json4.2 KB
  • playbook-v2/hub-routing/alias-still-resolves.md6.3 KB
  • playbook-v2/hub-routing/judgment-request-routes-to-transport.md8 KB
  • playbook/hub-routing/alias-still-resolves.md5.8 KB
  • playbook/hub-routing/deem-request-routes-to-transport.md4.9 KB
  • playbook/hub-routing/jev-request-stays-with-cli-jev.md4.6 KB
  • playbook/hub-routing/judgment-request-routes-to-transport.md7.5 KB
  • playbook/hub-routing/out-of-domain-resolves-nothing.md4.9 KB
  • playbook/manual-testing-playbook.md7.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…