Skill Composition
Compose existing capabilities through named inputs and outputs.
These examples and illustrative results are independently authored teaching materials, not measured model results.
Use case
Compose existing threat-model and security-review capabilities. Teaching threats.json must carry IDs, boundaries, threats and evidence; vague modeling does not form a usable handoff.
Mechanism
Verify available capabilities/invocation contracts and declare stage inputs/outputs/identity/failure. Model a permitted repository, validate artifacts/source evidence and retain untrusted provenance, then hand path/version/goal to review. Missing/invalid/unauthorized capabilities remain gaps without fabricated APIs or automatic installs. Outputs grant no new authority.
Bad example
Do some threat modeling, maybe another skill, then let the next stage guess from arbitrary prose.
Good example
Use verified modeling capability with teaching threats.json fields id/boundary/threat/evidence. Validate and inspect citations before security-review, labeling data origin. Invalid/missing output cannot become complete execution; actual API/authority follows the host.
Why the change matters
Contracts make composition inspectable and catch incomplete material at boundaries. Capability reuse avoids duplicate responsibility.
Observable expectation
Missing boundary fails structure; invented evidence remains unverified even with valid schema. Valid handoffs retain identity. Unavailable modeling is not claimed executed and composition does not enable extra tools.
Limits
No frozen source is confirmed; names/JSON are illustrative. Schema does not prove threat quality and context can be lost. Availability is not authorization; cycles need stop rules.
Sources and evidence
Source text has not been located. This method meets the editorial criteria; its examples are independent teaching constructions.
Read the editorial criteria