Skip to content
Back to skills

Adr

ASecurity

- Status: Proposed - Date: 2026-09-03 - Serves: manage skills, orchestrate remote MCP

  • 23 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
ai-agentsrustgoexpress

Works with

  • mcp

Security analysis

A100/100

Pro scans all 21 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add NimbleBrainInc/nimblebrain --skill adr --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Adr?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Adr
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/nimblebraininc-adr-nimblebrain/badge)](https://www.skillsdirectory.com/skills/nimblebraininc-adr-nimblebrain)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
# 0016. Where the connector↔skill binding lives

- Status: Proposed
- Date: 2026-09-03
- Serves: manage skills, orchestrate remote MCP

## Context

Three mechanisms currently associate guidance with a connector, and they bind in
three different places.

A **server-published skill** (ADR-0011) needs no binding at all: the skill is a
resource on the server, so the association is the fact of publication. Its
tool-affinity is scoped to the source's own name: the skill may declare
`tool-affinity` as bare names or globs of the server's own tools, which the
adapter prefixes with `<source>__` (`connectorToolAffinity`,
`src/skills/connector-skills.ts`), and one that declares none is bound to
`<source>__*`. The prefix is also the containment — matching is anchored, so a
declared pattern can only narrow within the server's own tools.

A **curated overlay** (ADR-0013) binds by *identity string*. The overlay repo is
keyed `<identity>/SKILL.md`, and the identity is derived at install by
`connectorSkillIdentity` (`src/connectors/catalog/server-detail.ts`) — the brokered
toolkit slug when the catalog entry names one, otherwise the last dotted segment
of the reverse-DNS server name's first path component. The materialized copy's
tool-affinity is bound to *that install's* namespace the same way: the overlay's
declared bare patterns under `<server>__`, or `<server>__*` when it declares none.

An **authored skill** binds by whatever `tool-affinity` globs its author typed.

So the same relationship — this guidance is about that connector — is expressed
as a derived string in one place, a namespace prefix in another, and an implicit
publication fact in a third. Which of the connector's tools a connector skill
governs is a separate question, answered by the skill's own declared patterns;
this ADR concerns only which connector it belongs to. The derivation is the fragile one: it is a formula
over a name, it can collide across unrelated connectors that happen to share a
last segment, and a connector whose name does not follow the shape it assumes
resolves to an identity no overlay is keyed under. The failure is a silent 404,
which is indistinguishable from "no overlay is curated for this connector."

## Options

**A. Keep the derived identity, and make the derivation the documented contract.**
Cheapest. The overlay repo stays keyed by a string the runtime computes, and the
rule becomes part of what a curated overlay author must know. Every miss is
still a silent no-op.

**B. Name the overlay on the operator-published catalog entry.** The entry
already carries operator-trusted, server-declared host metadata for
`ui`, `hooks`, and the notifications outbox (`src/connectors/catalog/projection.ts`).
An overlay reference would sit beside them, and the install would read a name
rather than compute one. Cost: one more hand-maintained field per entry, and a
second place a curated overlay's existence is recorded.

**C. Bind from the skill.** The overlay declares which connectors it applies to,
so the association lives with the guidance rather than with the connector. Cost:
the curated repo becomes the source of truth for a relationship the catalog also
describes, and the lookup direction inverts — the install can no longer ask for
one file by name.

**D. No binding field; make the referent visible.** Fold the guidance into the
catalog line the model already reads (ADR-0015) and let the model resolve which
guidance applies to what it is doing. Cost: guidance the model does not think to
ask for never arrives, and the surface-once delivery guarantee has nothing to key
on.

## What would decide it

- **How often the derived identity actually misses.** Count installs whose
  identity resolves to no curated overlay, split by whether an overlay for that
  connector exists under a different key. A derivation with no observed misses is
  not worth replacing; one that misses on a class of names is.
- **Whether collisions are reachable.** Two catalog entries whose derived
  identities are equal, one of which has an overlay. If the catalogue can produce
  that pair, the derivation is a correctness bug rather than an ergonomics one.
- **Whether the model resolves guidance from a visible referent.** Option D
  stands or falls on measurement: with the guidance named in the catalog and no
  binding metadata, does the model activate it on the turns where it helps? Only
  a negative result justifies adding a relationship field.
- **How many overlays exist.** Options B and C both add a hand-maintained copy of
  the relationship. At a handful of overlays that is nothing; at a hundred it is a
  second catalogue that drifts.

Until then, the derived identity stands and its failure mode — a silent 404
treated as "not curated" — is a known cost, not an accepted design.

Files in this skill

  • 0000-template.md1.2 KB
  • 0001-workspace-is-the-boundary-not-identity.md1.4 KB
  • 0002-files-resolve-by-bare-id.md1.8 KB
  • 0003-primitives-are-workspace-owned-and-path-authoritative.md1.6 KB
  • 0004-private-by-default-visibility-is-a-field.md1.9 KB
  • 0005-no-cross-workspace-reach-tool-shape-is-scope.md2.2 KB
  • 0006-personal-connector-use-requires-a-grant.md1.9 KB
  • 0007-offboarding-revokes-active-use.md4.3 KB
  • 0008-notifications-are-pulled-and-routed-by-the-operator.md6 KB
  • 0009-skills-are-the-agent-skills-standard-plus-a-nested-runtime-block.md4.5 KB
  • 0010-role-decides-the-channel.md5.6 KB
  • 0011-a-server-published-skill-is-a-peer-of-a-filesystem-skill.md5.3 KB
  • 0012-vendored-provenance-is-loader-stamped.md3.6 KB
  • 0013-connector-overlays-are-curated-pinned-and-reconciled-at-boot.md6 KB
  • 0014-skill-markers-are-host-owned-meta.md4.3 KB
  • 0015-the-catalog-lists-what-can-be-activated.md4 KB
  • 0016-binding-home-for-connector-and-skill.md4.1 KB
  • 0017-retiring-the-trigger-matcher.md3.9 KB
  • 0018-skill-channels-and-the-cache-breakpoints.md4.2 KB
  • 0019-scope-precedence-when-two-skills-share-a-name.md3.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…