P19 · Skill authoring

Skill Composition

Compose existing capabilities through named inputs and outputs.

Editorially reviewedSource unconfirmed

These examples and illustrative results are independently authored teaching materials, not measured model results.

Use case

Compose existing threat-model and security-review capabilities. Teaching threats.json must carry IDs, boundaries, threats and evidence; vague modeling does not form a usable handoff.

Mechanism

Verify available capabilities/invocation contracts and declare stage inputs/outputs/identity/failure. Model a permitted repository, validate artifacts/source evidence and retain untrusted provenance, then hand path/version/goal to review. Missing/invalid/unauthorized capabilities remain gaps without fabricated APIs or automatic installs. Outputs grant no new authority.

Bad example

Do some threat modeling, maybe another skill, then let the next stage guess from arbitrary prose.

Good example

Use verified modeling capability with teaching threats.json fields id/boundary/threat/evidence. Validate and inspect citations before security-review, labeling data origin. Invalid/missing output cannot become complete execution; actual API/authority follows the host.

Why the change matters

Contracts make composition inspectable and catch incomplete material at boundaries. Capability reuse avoids duplicate responsibility.

Observable expectation

Missing boundary fails structure; invented evidence remains unverified even with valid schema. Valid handoffs retain identity. Unavailable modeling is not claimed executed and composition does not enable extra tools.

Limits

No frozen source is confirmed; names/JSON are illustrative. Schema does not prove threat quality and context can be lost. Availability is not authorization; cycles need stop rules.

Sources and evidence

Source text has not been located. This method meets the editorial criteria; its examples are independent teaching constructions.

Read the editorial criteria