SkillAtlasSkill 详情

dream

Stop approving everything your AI does. It's making you less safe.

审核状态:已审核Quality 80Security 92

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年8月8日

KERNEL

Stop approving everything your AI does. It's making you less safe.

Auto mode is the default now, and the data behind that decision is brutal: humans reviewing per-action permission prompts caught dangerous commands 13.6% of the time; automated checks caught 89%. People approve 97% of prompts. Attention decays to ~5% blocking after fifty prompts. Per-action approval is a leash held by someone who stopped looking. (Anthropic's numbers; the academic result is worse — 94% of developers miss deliberate agent sabotage, and 56% accept it even after a warning.)

KERNEL is the other model: fences. The agent runs free inside enforced boundaries — hooks that block destructive commands outright rather than warning about them, irreversible operations gated behind a one-time token only a human can open, independent verifier agents that never saw the builder's reasoning, and receipts for every claim. You review outcomes, not keystrokes.

And the fences learn: every mistake a session survives is written to a memory that outlives it, so yesterday's near-miss is tomorrow's blocked command.

For people running Claude Code in auto mode on real repositories. Not for you if you want an autonomous agent with no boundaries, or a replacement for tests, review, and reading the diff.

Install

claude plugin marketplace add ariaxhan/kernel-claude
claude plugin install kernel@kernel-marketplace
~/.claude/plugins/marketplaces/kernel-marketplace/scripts/kernel-setup.sh

Needs git, sqlite3, jq, python3, bash. Takes about ten seconds. Setup asks once before it writes, and never touches your shell config.

What you should see

Setup finishes by writing a real memory and reading it back by keyword:

## Recall: KERNEL installed machine

- [pattern] KERNEL 8.7.2 installed on this machine  ↳ kernel-setup.sh completed at 2026-08-04T23:51:39Z

KERNEL is set up.
  memory:  /Users/you/Documents/Vaults/_meta/agentdb/agent.db
  agentdb: /Users/you/Documents/Vaults/.local/bin/agentdb

That round trip is the proof, not a status message. There is now a SQLite database on your machine that every Claude Code session reads on start and writes on end. If setup could not write to it or could not read it back, it exits non-zero and tells you which half failed.

Now run claude and type /kernel:help.


Where things are

Full documentation covers install paths and verification, the daily loop, what KERNEL writes to disk, the safety model, troubleshooting, upgrading, and contributing.

Go to docs/install.md if the three commands above did not work, and docs/daily-use.md once they did.

What it actually does

Three things, in the order you notice them.

Memory. agentdb is a SQLite database in your Vaults directory. Sessions recall from it before acting and write learnings at the end, so a failure you hit last week does not cost you the same afternoon twice. Recall is FTS5 keyword search by default; local semantic search is opt-in and adds nothing to your network. See docs/data-and-memory.md.

Bounded resume. Handoffs, checkpoints, and retrospectives are validated JSON manifests, not prose summaries. A new session reconstructs exactly the state the manifest pins rather than inheriting a whole conversation. The manifest CLI is validate | latest | divergence | preflight | compile | resume | activate | deactivate.

Reversibility guards. Hooks classify commands and writes by how hard they are to undo. Recoverable mistakes get a warning the model can correct; genuinely destructive ones hard-block and surface to you, with a one-time approval token that a prompt-injected command cannot forge. These are a tripwire, not a sandbox, and docs/safety.md is explicit about where they stop working.

Underneath, KERNEL classifies each task by domain, work shape, and safety level, then loads one domain pack for the announced route. Ordinary work runs with no ceremony.

One honest limit on that, current as of 9.0.0: the model-routing and separate-builder-from-verifier rules are checked when receipt validation is run. They are not yet enforced on every request, and a request with no receipt at all proceeds normally. Treat them as a convention the tooling helps you keep, not as a sandbox.

On context cost, the number you will see quoted elsewhere is wrong and this is the corrected one. KERNEL's ambient cost to a plugin user is roughly 4,600 tokens: about 1,900 from the SessionStart hook and about 2,700 from skill frontmatter the host keeps visible so routing can happen. This repo's CLAUDE.md is not part of that; your host loads your own instruction file, not ours. An earlier target of "under 500 tokens" came from a measurement that charged our CLAUDE.md to everyone, and it is withdrawn. Detail and the ratchets that now enforce it: docs/kernel-9/INVENTORY.md.

Surfaces, and how Codex differs

Claude Code terminal, Desktop (local and SSH), and VS Code. Remote Claude Code sessions do not support plugins.

Codex CLI and the Codex app load the same package through their Claude-marketplace compatibility loader:

codex plugin marketplace add ariaxhan/kernel-claude
codex plugin add kernel@kernel-marketplace

Restart Codex afterwards, then invoke $kernel:init. Skills are namespaced on both hosts: Claude Code invokes /kernel:help, Codex invokes $kernel:help. Two real differences. Codex runs the supported synchronous hook events, including SessionEnd, but does not implement PostToolUseFailure. KERNEL's capture-error.sh is therefore not bound on that host, and tool-error recording degrades to what PostToolUse can observe. That degradation is silent at runtime, so the per-host matrix is worth reading before you rely on error history: docs/kernel-9/HOST-CAPABILITIES.md, generated from governance/hosts.json. And Codex does not register KERNEL's Claude Code agent definitions as native subagents; it maps the same roles onto its own during orchestration. Reasoning and detail: docs/install.md.

Updating

Claude Code:

/plugin marketplace update kernel-marketplace
/plugin update kernel@kernel-marketplace
/reload-plugins

Codex, where the marketplace upgrade also refreshes the installed cache:

codex plugin marketplace upgrade kernel-marketplace

Upgrading from 7.23, the breaking changes, and rolling back without losing data: docs/upgrading.md.

If update and reload both fail, reinstall. Claude Code takes /plugin uninstall kernel@kernel-marketplace --keep-data followed by a fresh install; Codex takes codex plugin remove kernel@kernel-marketplace then codex plugin add kernel@kernel-marketplace. Removing the marketplace or clearing the plugin cache is not routine maintenance.

Rolling back

Check out the verified 7.23 release commit and point the installed selector at it:

git clone https://github.com/ariaxhan/kernel-claude.git "$HOME/kernel-claude-7.23"
git -C "$HOME/kernel-claude-7.23" checkout 54a0053
V8_SELECTOR="$HOME/.claude/plugins/cache/kernel-marketplace/kernel/current/scripts/select-runtime.sh"
"$V8_SELECTOR" "$HOME/kernel-claude-7.23"
claude --plugin-dir "$HOME/kernel-claude-7.23"

To select a validated runtime explicitly, call a numbered selector directly, for example "$HOME/.claude/plugins/cache/kernel-marketplace/kernel/8.0.2/scripts/select-runtime.sh" /path/to/runtime. That moves current backward on purpose; ordinary old sessions cannot. It selects code only and does not convert state formats.

Where your data lives

Everything durable goes in the selected Vaults directory: _meta/agentdb/agent.db for memory, _meta/handoffs/ and _meta/checkpoints/ for JSON state, _meta/logs/ for runtime records. Detection order and the full list: docs/data-and-memory.md.

When the active project root exactly matches the Vaults root and a shared continuity engine with an executable host adapter is present, that service owns compaction checkpoints and restore injection, and KERNEL's compaction paths cleanly no-op rather than adding a second restore. Nested repositories retain KERNEL's deterministic generic fallback.

Contributing

git clone https://github.com/ariaxhan/kernel-claude.git
cd kernel-claude
./scripts/kernel-setup.sh
claude --plugin-dir ./
./tests/run-tests.sh

See docs/contributing.md. Fix defects here and release; do not edit an installed cache directory.

MIT licensed.

内容与创作

低风险

  • 来源需自行核对维护者身份。
  • 包含脚本或命令调用,安装前请复核。
  • 未检测到明显外部权限要求。
  • 未检测到高风险命令。
  • 扫描发现:0 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/ariaxhan/kernel-claude.git
  3. 将 "skills/dream" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/ariaxhan/kernel-claude.git
  3. 将 "skills/dream" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/ariaxhan/kernel-claude.git
  3. 将 "skills/dream" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/ariaxhan/kernel-claude.git
  3. 将 "skills/dream" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/ariaxhan/kernel-claude.git
  3. 将 "skills/dream" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: dream
description: "Deep creative exploration engine. Competing perspectives, stress-tested by a 4-persona council, scored by integrity. The approach that survives attack wins — not the one that sounds best."
user-invocable: true
allowed-tools: Agent, Bash, Read, Write, Grep, Glob, WebSearch
kernel:
  kind: workflow
  version: 1
  side_effects: writes_meta
  confirmation: none
Expand the solution space BEFORE committing.

Not "give me 3 options" — structured divergence: competing value systems + adversarial stress test + integrity scoring.

The winning approach is the one that SURVIVES attack, not the one that sounds best.

Use before any non-trivial decision. Use when the obvious answer feels too easy.

<on_start> agentdb read-start # prior dreams + learnings seed the perspectives; don't re-explore killed approaches </on_start>

<skill_load> always: skills/quality/SKILL.md, skills/architecture/SKILL.md on_domain: api: skills/api/SKILL.md, skills/backend/SKILL.md frontend: skills/frontend/SKILL.md backend: skills/backend/SKILL.md security: skills/security/SKILL.md </skill_load>

Before dreaming, understand what exists: 1. Glob/Grep affected areas in the codebase 2. Check _meta/research/ for prior work 3. Check agentdb for related learnings/failures 4. Map existing patterns, conventions, constraints

Dreams that ignore the codebase are fantasies, not proposals.

Goal: the SMALLEST possible solution. Question the premise itself. - Can we delete our way to the answer? - Does an existing tool/library already do this? - What if we just... don't build this? - What's the 20-line version?
Target: 90% code reduction. Must reference actual files that could be deleted.
Format: 3-8 lines. Effort estimate. Coverage percentage.
Goal: the version you'd be PROUD of in 6 months. - What does the ideal architecture look like? - What does this unlock beyond the immediate need? - What edge cases should be handled from day 1?
Target: complete solution. Must sketch actual architecture, not hand-wave.
Format: full description with component diagram. Effort estimate.
Goal: the 80/20 point. Ship this week. - What's the minimum that solves the real problem? - What can we defer without paying interest? - What's the upgrade path when we need more?
Target: 80% solution with clear upgrade path.
Must explicitly state what's deferred and the cost of deferral.
Format: concrete plan. Effort estimate. Tradeoff table.

Tier 1: generate all 3 inline. Tier 2+: spawn dreamer agent for codebase-grounded perspectives.

For EACH perspective, run through the council. Not voting — adversarial probing. Probes structural integrity. Coupling, single points of failure, migration nightmares. Breaks things by asking "what happens when..."
<persona id="user" concern="usability, complexity, does it solve MY problem?">
  Cuts through elegance. "Does it work for the person using this every day?"
</persona>

<persona id="adversary" concern="what breaks, worst case, what was missed">
  Pure attack mode. Edge cases, race conditions, security holes, wrong assumptions.
  If they can't find a flaw, the approach is strong.
</persona>

<persona id="operator" concern="can we ship it, can we maintain it, blast radius">
  Operational reality. Deployment, monitoring, rollback, on-call burden.
  Beautiful code that's hell to operate fails.
</persona>

Each persona: 2-3 lines per perspective. Specific concerns, not essays.

<ask_user> Use AskUserQuestion when: perspectives generated, before running council Ask: "Three perspectives ready. Which resonates, or run all through stress test?" Options: stress test all, lean toward {minimalist|maximalist|pragmatist}, rethink framing </ask_user>

For each perspective, score integrity based on council feedback:
  • How many council members raised critical (not fixable) concerns?
  • Did the perspective already account for the concerns?
  • Are the flaws structural or cosmetic?

= 0.8: ANTIFRAGILE — stronger because of the attacks. = 0.6: VIABLE — survives with minor fixes. < 0.6: SHATTERED — fundamental flaws. Don't pursue.

Rank surviving perspectives by score. If ALL shatter: the problem needs reframing (thermal shock).

# Dream: {topic}

Context

{codebase state, constraints, existing patterns}

Perspectives (ranked by integrity)

{emoji} {name} — integrity: {score}

{perspective content} Effort: {estimate} Council verdict: {1-line summary per persona} Survived because: {why it's robust} — {perspective name}

{repeat for each surviving perspective}

Shattered

{any that didn't survive, with reason}


Recommendation

{highest integrity + why. hybrid options if scores are close.}

Next: /kernel:forge {approach} or /kernel:ingest for guided execution. </output_format>

<ask_user> Use AskUserQuestion when: results presented with ranked perspectives Ask: "Proceed with {winner}, hybrid approach, or rethink the problem?" Options: proceed with winner, hybrid of top 2, rethink </ask_user>

Every approach failed the stress test. The problem needs reframing.
  1. Record why each shattered (agentdb learn failure)
  2. Ask: is the problem statement wrong? Solving the right thing?
  3. Generate 1-2 reframings of the original problem
  4. Return to diverge phase with reframed problem (max 1 reframe)
  5. If still shatters: STOP. "This needs human decomposition."

<github_integration> If gh authenticated and profile is github-oss or github-production: Post dream to GitHub Discussions (Decisions category). Otherwise: Write to _meta/dreams/{topic}.md only. </github_integration>

agentdb emit command "dream" "" '{"topic":"X","perspectives":3,"survived":N,"chosen":"pragmatist","integrity":0.85}'

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!