New:Socket for Asana Is Now Available.Learn more
Get Started

arkgate

Package Overview
Dependencies
Maintainers
1
Versions
77
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

arkgate - npm Package Compare versions

Comparing version
4.8.1
to
4.8.2
dist/diagnosticCatalog-CPzH-MLN.d.ts

Sorry, the diff of this file is too big to display

+11
-0

@@ -6,2 +6,13 @@ # Changelog

## 4.8.2 — 2026-08-30
**Patch** over **4.8.1**. Frozen 13 skills match four-plane honesty: ArkOrder on
adopt / place / autopilot; ArkRun `kernelRoots`; kernel import `arkgate/runtime`.
No `/ark-order` / `/ark-run`. Does not close `K01` / `Z09`. **No required config migration.**
**Status: published** (on npm `latest`; see `docs/releases/4.8.2.md`).
### Changed
- **Skills four-plane honesty:** existing 13 names teach Layers, ArkRules, ArkRun, and ArkOrder. Adopt (session-0: schema `1.3+`, `planeRoots`, `maxXiKeys`) and Autopilot (grind) name ArkOrder; Place hands ArkOrder grind to Autopilot. ArkRun `kernelRoots` is preferred (`compositionRoots` alias). Kernel import is `arkgate/runtime` (companion deprecated). Skills never enforce.
## 4.8.1 — 2026-08-30

@@ -8,0 +19,0 @@

+1
-1

@@ -1,2 +0,2 @@

export { k as AICodeGate, l as AICodeGateContext, m as AICodeGateOptions, n as AICodeGateResult, o as AICodeGateViolation, p as AIGateExtension, q as ANALYSIS_IR_SCHEMA_VERSION, r as ARK_ANALYSIS_RESULT_SCHEMA, s as ARK_ANALYSIS_RESULT_SCHEMA_VERSION, t as ARK_DESIGN_DELTA_SCHEMA_VERSION, u as ARK_ENFORCEMENT_STATE_SCHEMA_VERSION, v as AdapterCompletenessReason, w as AdapterDiagnostic, x as AdapterResult, y as AdapterSeverity, z as AdapterViolationInput, B as AnalysisCapabilityUse, C as AnalysisCompilerOptions, D as AnalysisCompleteness, F as AnalysisContract, G as AnalysisEvidence, H as AnalysisFile, I as AnalysisFileChange, J as AnalysisFileInput, K as AnalysisImportEdge, L as AnalysisIr, M as AnalysisMode, N as AnalysisResult, O as AnalysisViolation, P as AnalyzeArchitectureConvergenceInput, Q as AnalyzeChangeInput, S as AnalyzePolicyDeltaInput, T as AnalyzeProjectInput, U as AnalyzeResolvedProjectInput, V as ArchitectureActualChange, W as ArchitectureChangeMap, X as ArchitectureChangeMapContract, Y as ArchitectureChangeMapDependency, Z as ArchitectureChangeMapFile, _ as ArchitectureChangeOperation, $ as ArchitectureConvergenceClassification, a0 as ArchitectureConvergenceFinding, a1 as ArchitectureConvergenceResult, a2 as ArchitectureDependency, a3 as ArchitectureEngineEdge, a4 as ArchitectureEngineResult, a5 as ArchitectureEngineViolation, a6 as ArkDesignDeltaResult, a7 as ArkEnforcementHost, a8 as ArkEnforcementState, aa as ChangePreflightResult, ac as CollectAnalysisConfigWarningsInput, ad as DIAGNOSTIC_CATALOG, ae as DIAGNOSTIC_CATALOG_SCHEMA_VERSION, af as DIAGNOSTIC_DOCS_RELATIVE_PATH, ag as DIAGNOSTIC_RULE_IDS, ah as DesignDeltaChange, ai as DesignDeltaEnforcementScope, aj as DesignDeltaIdentity, ak as DesignSmellEvidence, al as DesignSmellFinding, am as DesignSmellId, an as DiagnosticCatalogEntry, ao as DiagnosticCategory, ap as EnforcementBoundaryState, aq as EnforcementEvidence, ar as EnforcementEvidenceField, as as EnforcementVerification, at as EvaluateArchitectureGraphInput, au as ForbiddenCapabilityUse, aw as POLICY_DELTA_SCHEMA_VERSION, ax as PolicyDelta, ay as PolicyDeltaAcknowledgement, az as PolicyDeltaAnalysis, aA as PolicyDeltaClassification, aB as PolicyDeltaFinding, aC as PreflightResolvedChangeInput, aD as PreparedChangeFile, aE as RESOLVED_CANDIDATE_FACTS_SCHEMA, aF as RESOLVED_CANDIDATE_FACTS_SCHEMA_VERSION, aG as ResolvedAmbientFact, aH as ResolvedAnalysisFile, aI as ResolvedAnalysisIr, aJ as ResolvedAnalysisResult, e as ResolvedArkRunCompositionRootHitFact, a as ResolvedArkRunDeclarationFact, b as ResolvedArkRunKernelCallFact, R as ResolvedArkRunKernelCallKind, c as ResolvedArkRunManagedNewFact, aK as ResolvedCandidateFacts, aL as ResolvedCandidateFactsInput, aM as ResolvedCapability, aN as ResolvedCapabilityFact, aO as ResolvedChangePreflightResult, d as ResolvedDependencyFact, aP as ResolvedDependencyKind, aQ as ResolvedDependencyState, aR as ResolvedFactsCompleteness, f as ResolvedFactsReason, aS as ResolvedFileFact, aT as ResolvedIntentReferenceFact, aU as ResolvedPublishFact, aV as ResolvedSafetyFact, aW as ResolvedSafetyKind, aX as ResolvedSafetyReport, aY as SemanticDependency, aZ as SemanticDependencyKind, b2 as analyzeArchitectureConvergence, b3 as analyzeChange, b4 as analyzePolicyDelta, b5 as analyzeProject, b6 as analyzeResolvedProject, b9 as catalogFixForRuleId, ba as catalogWhyForRuleId, bb as classifyArkPolicyDelta, bc as collectAnalysisConfigWarnings, be as collectForbiddenCapabilityUses, bf as createAICodeGate, bg as createAdapterResult, bh as createArchitectureProfile, bi as createArchitectureProfileFromArkConfig, bj as createElevenLayerArkConfig, bk as createResolvedCandidateFacts, bm as detectArchitectureCycles, bn as deterministicHash, bo as diagnosticDocsFragment, bp as diagnosticDocsPath, bq as elevenLayerProfile, br as evaluateArchitectureGraph, bu as explainViolation, bw as extractSemanticDependencies, bx as getDiagnosticCatalogEntry, by as isCataloguedOrArkRuleFamily, bz as isKnownDiagnosticCode, bA as loadContract, bB as loadResolvedCandidateFacts, bC as policyDeltaAcknowledgementMatches, bD as preflightChange, bE as preflightResolvedChange, bF as resolvedFactsEvidenceRequirementsHash, bG as serializeDiagnosticCatalog, bH as stableSerialize, bI as toAdapterDiagnostic, bJ as version } from '../diagnosticCatalog-CSF4N3w8.js';
export { k as AICodeGate, l as AICodeGateContext, m as AICodeGateOptions, n as AICodeGateResult, o as AICodeGateViolation, p as AIGateExtension, q as ANALYSIS_IR_SCHEMA_VERSION, r as ARK_ANALYSIS_RESULT_SCHEMA, s as ARK_ANALYSIS_RESULT_SCHEMA_VERSION, t as ARK_DESIGN_DELTA_SCHEMA_VERSION, u as ARK_ENFORCEMENT_STATE_SCHEMA_VERSION, v as AdapterCompletenessReason, w as AdapterDiagnostic, x as AdapterResult, y as AdapterSeverity, z as AdapterViolationInput, B as AnalysisCapabilityUse, C as AnalysisCompilerOptions, D as AnalysisCompleteness, F as AnalysisContract, G as AnalysisEvidence, H as AnalysisFile, I as AnalysisFileChange, J as AnalysisFileInput, K as AnalysisImportEdge, L as AnalysisIr, M as AnalysisMode, N as AnalysisResult, O as AnalysisViolation, P as AnalyzeArchitectureConvergenceInput, Q as AnalyzeChangeInput, S as AnalyzePolicyDeltaInput, T as AnalyzeProjectInput, U as AnalyzeResolvedProjectInput, V as ArchitectureActualChange, W as ArchitectureChangeMap, X as ArchitectureChangeMapContract, Y as ArchitectureChangeMapDependency, Z as ArchitectureChangeMapFile, _ as ArchitectureChangeOperation, $ as ArchitectureConvergenceClassification, a0 as ArchitectureConvergenceFinding, a1 as ArchitectureConvergenceResult, a2 as ArchitectureDependency, a3 as ArchitectureEngineEdge, a4 as ArchitectureEngineResult, a5 as ArchitectureEngineViolation, a6 as ArkDesignDeltaResult, a7 as ArkEnforcementHost, a8 as ArkEnforcementState, aa as ChangePreflightResult, ac as CollectAnalysisConfigWarningsInput, ad as DIAGNOSTIC_CATALOG, ae as DIAGNOSTIC_CATALOG_SCHEMA_VERSION, af as DIAGNOSTIC_DOCS_RELATIVE_PATH, ag as DIAGNOSTIC_RULE_IDS, ah as DesignDeltaChange, ai as DesignDeltaEnforcementScope, aj as DesignDeltaIdentity, ak as DesignSmellEvidence, al as DesignSmellFinding, am as DesignSmellId, an as DiagnosticCatalogEntry, ao as DiagnosticCategory, ap as EnforcementBoundaryState, aq as EnforcementEvidence, ar as EnforcementEvidenceField, as as EnforcementVerification, at as EvaluateArchitectureGraphInput, au as ForbiddenCapabilityUse, aw as POLICY_DELTA_SCHEMA_VERSION, ax as PolicyDelta, ay as PolicyDeltaAcknowledgement, az as PolicyDeltaAnalysis, aA as PolicyDeltaClassification, aB as PolicyDeltaFinding, aC as PreflightResolvedChangeInput, aD as PreparedChangeFile, aE as RESOLVED_CANDIDATE_FACTS_SCHEMA, aF as RESOLVED_CANDIDATE_FACTS_SCHEMA_VERSION, aG as ResolvedAmbientFact, aH as ResolvedAnalysisFile, aI as ResolvedAnalysisIr, aJ as ResolvedAnalysisResult, e as ResolvedArkRunCompositionRootHitFact, a as ResolvedArkRunDeclarationFact, b as ResolvedArkRunKernelCallFact, R as ResolvedArkRunKernelCallKind, c as ResolvedArkRunManagedNewFact, aK as ResolvedCandidateFacts, aL as ResolvedCandidateFactsInput, aM as ResolvedCapability, aN as ResolvedCapabilityFact, aO as ResolvedChangePreflightResult, d as ResolvedDependencyFact, aP as ResolvedDependencyKind, aQ as ResolvedDependencyState, aR as ResolvedFactsCompleteness, f as ResolvedFactsReason, aS as ResolvedFileFact, aT as ResolvedIntentReferenceFact, aU as ResolvedPublishFact, aV as ResolvedSafetyFact, aW as ResolvedSafetyKind, aX as ResolvedSafetyReport, aY as SemanticDependency, aZ as SemanticDependencyKind, b2 as analyzeArchitectureConvergence, b3 as analyzeChange, b4 as analyzePolicyDelta, b5 as analyzeProject, b6 as analyzeResolvedProject, b9 as catalogFixForRuleId, ba as catalogWhyForRuleId, bb as classifyArkPolicyDelta, bc as collectAnalysisConfigWarnings, be as collectForbiddenCapabilityUses, bf as createAICodeGate, bg as createAdapterResult, bh as createArchitectureProfile, bi as createArchitectureProfileFromArkConfig, bj as createElevenLayerArkConfig, bk as createResolvedCandidateFacts, bm as detectArchitectureCycles, bn as deterministicHash, bo as diagnosticDocsFragment, bp as diagnosticDocsPath, bq as elevenLayerProfile, br as evaluateArchitectureGraph, bu as explainViolation, bw as extractSemanticDependencies, bx as getDiagnosticCatalogEntry, by as isCataloguedOrArkRuleFamily, bz as isKnownDiagnosticCode, bA as loadContract, bB as loadResolvedCandidateFacts, bC as policyDeltaAcknowledgementMatches, bD as preflightChange, bE as preflightResolvedChange, bF as resolvedFactsEvidenceRequirementsHash, bG as serializeDiagnosticCatalog, bH as stableSerialize, bI as toAdapterDiagnostic, bJ as version } from '../diagnosticCatalog-CPzH-MLN.js';
import { P as PolicyViolation, g as PolicySeverity, h as PolicyEnforcementMode, i as Policy, I as IntentName, j as IntentCreator, k as IntentRelationship, b as ArchitectureProfile, D as DomainEvent } from '../types-DCSlrRnV.js';

@@ -3,0 +3,0 @@ export { A as ArchitectureLayer, a as ArchitectureLayerConfig, c as ArchitectureRule, d as ArkCheckConfig, l as CorrelationId, C as CreateArchitectureProfileFromArkConfigOptions, e as CreateArchitectureProfileOptions, f as CreateElevenLayerArkConfigOptions, E as EventMetadata, m as IntentRelationshipKind } from '../types-DCSlrRnV.js';

@@ -221,3 +221,5 @@ # ArkGate package surface policy

Ship notes for a version live under [releases/](https://github.com/pedroknigge/arkgate/tree/main/docs/releases)
(current published: [4.8.1.md](https://github.com/pedroknigge/arkgate/blob/main/docs/releases/4.8.1.md);
(current published: [4.8.2.md](https://github.com/pedroknigge/arkgate/blob/main/docs/releases/4.8.2.md);
prior published: [4.8.1.md](https://github.com/pedroknigge/arkgate/blob/main/docs/releases/4.8.1.md);
prior published: [4.8.0.md](https://github.com/pedroknigge/arkgate/blob/main/docs/releases/4.8.0.md);
prior published: [4.7.6.md](https://github.com/pedroknigge/arkgate/blob/main/docs/releases/4.7.6.md);

@@ -224,0 +226,0 @@ prior published: [4.7.5.md](https://github.com/pedroknigge/arkgate/blob/main/docs/releases/4.7.5.md);

@@ -65,4 +65,4 @@ # ArkGate documentation

Current published: [releases/4.8.1.md](releases/4.8.1.md) (`arkgate@4.8.1` on npm `latest`; does not close `K01`).
Prior: [releases/4.7.6.md](releases/4.7.6.md) · [4.7.5](releases/4.7.5.md) · [4.7.4](releases/4.7.4.md) · [4.7.3](releases/4.7.3.md) · [4.7.2](releases/4.7.2.md) · [4.7.1](releases/4.7.1.md) · [4.7.0](releases/4.7.0.md) · [4.6.7](releases/4.6.7.md) · [4.6.6](releases/4.6.6.md) · [4.6.5](releases/4.6.5.md) · [4.6.4](releases/4.6.4.md) · [4.6.3](releases/4.6.3.md) · [4.6.2](releases/4.6.2.md) · [4.6.1](releases/4.6.1.md) · [4.6.0](releases/4.6.0.md).
Current published: [releases/4.8.2.md](releases/4.8.2.md) (`arkgate@4.8.2` on npm `latest`; does not close `K01`).
Prior: [releases/4.8.1.md](releases/4.8.1.md) · [4.8.0](releases/4.8.0.md) · [4.7.6](releases/4.7.6.md) · [4.7.5](releases/4.7.5.md) · [4.7.4](releases/4.7.4.md) · [4.7.3](releases/4.7.3.md) · [4.7.2](releases/4.7.2.md) · [4.7.1](releases/4.7.1.md) · [4.7.0](releases/4.7.0.md) · [4.6.7](releases/4.6.7.md) · [4.6.6](releases/4.6.6.md) · [4.6.5](releases/4.6.5.md) · [4.6.4](releases/4.6.4.md) · [4.6.3](releases/4.6.3.md) · [4.6.2](releases/4.6.2.md) · [4.6.1](releases/4.6.1.md) · [4.6.0](releases/4.6.0.md).
Older notes: [releases/](releases/). Config: [configuration.md](configuration.md).

@@ -69,0 +69,0 @@

{
"name": "arkgate",
"version": "4.8.1",
"version": "4.8.2",
"description": "When the agent writes a bad import, the write doesn’t land. The same check fails the pull request.",

@@ -5,0 +5,0 @@ "type": "module",

@@ -32,7 +32,7 @@ <div align="center">

> **ArkGate 4.8.1** is on npm `latest`. Write. Check. Ship. Adopted = required GitHub
> **ArkGate 4.8.2** is on npm `latest`. Write. Check. Ship. Adopted = required GitHub
> status running `arkgate-check --strict-merge`, or an explicit `advisory-only` stance.
> Status is compact (`arkgate-check --doctor`; `--all` for Details). Optional **ArkRun**
> (`arkgate/runtime`) is an in-memory runtime — not Postgres. `@arkgate/runtime` is deprecated.
> [4.8.1](docs/releases/4.8.1.md) · [4.8.0](docs/releases/4.8.0.md) · [4.7.6](docs/releases/4.7.6.md) · [Docs hub](docs/README.md) · [Voice](docs/product-voice.md)
> [4.8.2](docs/releases/4.8.2.md) · [4.8.1](docs/releases/4.8.1.md) · [4.8.0](docs/releases/4.8.0.md) · [Docs hub](docs/README.md) · [Voice](docs/product-voice.md)

@@ -270,3 +270,5 @@ ---

| Security | [SECURITY.md](SECURITY.md) |
| Current published (4.8.1 on npm `latest`) | [docs/releases/4.8.1.md](docs/releases/4.8.1.md) · [CHANGELOG](CHANGELOG.md) |
| Current published (4.8.2 on npm `latest`) | [docs/releases/4.8.2.md](docs/releases/4.8.2.md) · [CHANGELOG](CHANGELOG.md) |
| Prior published (4.8.1) | [docs/releases/4.8.1.md](docs/releases/4.8.1.md) |
| Prior published (4.8.0) | [docs/releases/4.8.0.md](docs/releases/4.8.0.md) |
| Prior published (4.7.6) | [docs/releases/4.7.6.md](docs/releases/4.7.6.md) |

@@ -273,0 +275,0 @@ | Prior published (4.7.5) | [docs/releases/4.7.5.md](docs/releases/4.7.5.md) |

@@ -9,3 +9,3 @@ {

},
"version": "4.8.1",
"version": "4.8.2",
"packages": [

@@ -15,3 +15,3 @@ {

"identifier": "arkgate",
"version": "4.8.1",
"version": "4.8.2",
"runtimeHint": "npx",

@@ -18,0 +18,0 @@ "transport": {

@@ -23,4 +23,5 @@ ---

- CLI-first: if `arkgate-check` already resolved the root, do not wait on MCP.
- Do not add `arkRun` unless the user wants the extra. When they do, write **advisory** `arkRun`
(schema `1.2+`) in this turn. Absence is silent and valid. Skills never enforce.
- Do not add `arkRun` or `arkOrder` unless the user wants that extra. When they do, write
**advisory** extra in this turn (`arkRun` schema `1.2+`; `arkOrder` schema `1.3+`).
Absence is silent and valid. Compact starter stays extras-off. Skills never enforce.

@@ -100,3 +101,4 @@ Invoking this skill **is** the approval. Write the architecture config in this turn.

| Freeze **real** debt after the config is honest | User said map only |
| Turn **advisory** ArkRun on (`arkRun` extra, schema `1.2+`) | Evaluate / wire a hand-rolled bus → `/ark-runtime`; new kernel-managed file → `/ark-place` |
| Turn **advisory** ArkRun on (`arkRun` extra, schema `1.2+`; **`kernelRoots` preferred**) | Evaluate / wire a hand-rolled bus → `/ark-runtime`; new kernel-managed file → `/ark-place` |
| Turn **advisory** ArkOrder on (`arkOrder` extra, schema `1.3+`, `planeRoots`) | New plane-root file after extra is on → `/ark-place`; grind skip clusters → `/ark-autopilot` |

@@ -121,5 +123,5 @@ ## Dual engine (mandatory)

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
ArkGate has **two opt-in planes**. The user chooses which to use; you **always label** findings so they never blur.
ArkGate has **always-on Layers** plus opt-in extras. The user chooses extras; you **always label** findings so they never blur. Absence of an extra is silent and valid. Skills never enforce. ArkOrder is an extra **inside** the `arkgate` package (`arkgate/order`), not a second install.

@@ -130,6 +132,7 @@ | Plane | What it protects | Where it lives | Sensors / tools |

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime` | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |
**Rules for every report / answer:**
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** (or a two-column table with those headers).
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** or **`[ArkOrder]`** (or a table with those headers).
2. Never call an import-edge violation an “invariant” or an aggregate sensor a “layer deny.”

@@ -140,2 +143,3 @@ 3. Absence of `arkRules` is **valid** — do not force ArkRules unless the user wants them or residual inventory clearly wants a pilot.

6. Absence of `arkRun` is **valid**. Write it only when the user wants the extra. Skills never enforce.
7. Absence of `arkOrder` is **valid**. Write it only when the user wants the extra. Do not invent `/ark-order`. Skills never enforce.

@@ -150,3 +154,3 @@

- User asked to turn the extra on: write **advisory** `arkRun` on `ark.config.json` (`schemaVersion` `1.2+`) **in this turn**. Default `"mode": "advisory"`.
- Required shape: `compositionRoots` (real files; empty + enforced fails closed), `managedLayers` (existing `layers[].name` only), `requireDeclarations` (default true).
- Required shape: **`kernelRoots` preferred** (real files; empty + enforced fails closed). `compositionRoots` is a legacy alias — still valid. `managedLayers` (existing `layers[].name` only), `requireDeclarations` (default true).
- Do **not** put `arkRun` on the compact starter / `ark start` scaffold. Brownfield stays advisory until the team promotes.

@@ -159,2 +163,24 @@ - Absence is valid and **silent** — never force the extra. Never force the kernel over existing Nest/DI. Do not invent `/ark-run`.

### Adopt + ArkOrder
- User asked to turn the extra on: write **advisory** `arkOrder` on `ark.config.json` (`schemaVersion` `1.3+`) **in this turn**. Default `"mode": "advisory"` — never session-0 default `enforced`.
- Required shape: `planeRoots` (real files; empty + enforced = `ARKORDER_MISSING_PLANE`), `managedLayers` (existing `layers[].name` only), `maxXiKeys` (default 7).
- Example (consumer trees — not this library's 4-layer compact):
```json
{
"schemaVersion": "1.3",
"arkOrder": {
"mode": "advisory",
"planeRoots": ["src/main.ts"],
"managedLayers": ["Application"],
"maxXiKeys": 7
}
}
```
- Do **not** put `arkOrder` on the compact starter / `ark start` scaffold. Domain stays plane-free. Import `createOrderPlane` from `arkgate/order` (same npm package).
- Absence is valid and **silent** — never force the extra. Do not invent `/ark-order`.
- Demoting enforced → advisory or deleting the extra is policy-delta **weakening**.
- After the extra is honest: handoff `/ark-place` for new plane-root files; grind skip via `/ark-autopilot`. Skills never enforce.
## Subagent fan-out (optional, host-dependent)

@@ -210,4 +236,6 @@

User wants the ArkRun extra → write **advisory** `arkRun` (schema `1.2+`, real
`compositionRoots`, existing `managedLayers`) **in this turn**. Do not add it to a compact
starter. Do not promote to enforced as the session-0 default.
`kernelRoots` preferred — `compositionRoots` alias, existing `managedLayers`) **in this turn**.
User wants the ArkOrder extra → write **advisory** `arkOrder` (schema `1.3+`, real
`planeRoots`, existing `managedLayers`, `maxXiKeys` 7) **in this turn**. Do not add extras
to a compact starter. Do not promote to enforced as the session-0 default.
2. **Check + diagnose** — `summary.concentrated` / dominant edge → fix contract first, don’t freeze.

@@ -255,5 +283,5 @@ Cross-slice / cross-context `peerIsolation` hits are judgment: extract shared or events.

- Force runtime kernel over existing Nest/DI.
- Put `arkRun` on the compact starter / `ark start` scaffold.
- Put `arkRun` or `arkOrder` on the compact starter / `ark start` scaffold.
- Claim in-memory kernel stores are production durability.
- Invent `/ark-run`.
- Invent `/ark-run` or `/ark-order`.
- Claim Enforce while governed% is low, cores empty with I/O in Application, or core bags ungoverned.

@@ -270,3 +298,3 @@ - End adopt with only “baseline written” when design-weak residual is visible in files you opened.

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`

@@ -273,0 +301,0 @@ - **Done axes:** architecture residual (status/doctor/compass) | feature/ticket residual (outside package). Enforce green ≠ feature done

@@ -43,5 +43,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
Label findings **`[Layer]`** vs **`[ArkRules]`**. Absence of `arkRules` is valid.
Label findings **`[Layer]`** vs **`[ArkRules]`** vs **`[ArkRun]`** vs **`[ArkOrder]`**. Absence of extras is valid and silent. Session-0 extras (advisory `arkRun` / advisory `arkOrder`) live on **`/ark-adopt`**. Do not invent `/ark-run` or `/ark-order`. Skills never enforce.

@@ -61,3 +61,3 @@ ## Subagent fan-out (optional, host-dependent)

1. Bind MCP (`ark_identity` then `ark_recommend`) or run `ark-check --recommend`.
2. Execute **`/ark-adopt`** autonomy: write the config, dirs, optional advisory ArkRules, gates.
2. Execute **`/ark-adopt`** autonomy: write the config, dirs, optional advisory ArkRules, optional advisory ArkRun / ArkOrder when asked, gates.
3. `ark-check --strict-config`. Handoff `/ark-place` for new files.

@@ -73,5 +73,5 @@

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`
- **Handoff:** `/ark-adopt` / `/ark-place` / `none`
- **Incomplete?** `no` | `yes — <what is missing>`

@@ -63,2 +63,3 @@ ---

| **Apply** leftover design (one Shape refactor) | User said map only |
| Extra skip cluster (`ARKRUN_*` / `ARKORDER_*`) after extra is on | Extra off → `/ark-adopt` (advisory); evaluate one bus → `/ark-runtime` |
| Spaghetti under ENFORCE: Shape work (invoke = apply one pilot) | — |

@@ -114,5 +115,5 @@

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
ArkGate has **two opt-in planes**. The user chooses which to use; you **always label** findings so they never blur.
ArkGate has **always-on Layers** plus opt-in extras. The user chooses extras; you **always label** findings so they never blur. Absence of an extra is silent and valid. Skills never enforce. ArkOrder is an extra **inside** the `arkgate` package (`arkgate/order`), not a second install.

@@ -123,5 +124,7 @@ | Plane | What it protects | Where it lives | Sensors / tools |

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |
**Rules for every report / answer:**
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** (or a two-column table with those headers).
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** or **`[ArkOrder]`** (or a table with those headers).
2. Never call an import-edge violation an “invariant” or an aggregate sensor a “layer deny.”

@@ -131,2 +134,3 @@ 3. Absence of `arkRules` is **valid** — do not force ArkRules unless the user wants them or residual inventory clearly wants a pilot.

5. CLI helpers: `ark-check --rules-inventory --json`, doctor JSON `rulesUnderContract`, sensors emit `ARKRULE_*` / `INVARIANT_UNCOVERED` with `evidence.arkruleId`.
6. Absence of extras is **valid**. Extra skip clusters grind **here** after the extra is on. Do not invent `/ark-run` or `/ark-order`. Skills never enforce.

@@ -141,2 +145,15 @@

### Autopilot + ArkRun
When `arkRun` is present:
- Grind skip clusters with judgment: `ARKRUN_DIRECT_NEW` / `ARKRUN_TRANSPORT_BYPASS` / `ARKRUN_KERNEL_IN_DOMAIN` / `ARKRUN_MISSING_ROOT`. Never invent `mechanical-safe` for new emits / homemade buses.
- Factory only inside `arkRun.kernelRoots` (`compositionRoots` alias). Import `arkgate/runtime`. Doctor `arkRun` is `notAScore`.
- Extra off → `/ark-adopt` (advisory) or `/ark-runtime` (evaluate one candidate). Do not invent `/ark-run`.
- Skills never enforce.
### Autopilot + ArkOrder
When `arkOrder` is present:
- Grind skip clusters with judgment: `ARKORDER_MISSING_PLANE` / `ARKORDER_KERNEL_IN_DOMAIN` / `ARKORDER_GENERIC_UPDATE` / `ARKORDER_TOO_MANY_PARAMS` / `ARKORDER_INGEST_WRITES_XI`. Freeze ξ with `release()`; never `update`/`patch`/`set`.
- Extra off → `/ark-adopt` (advisory). Do not invent `/ark-order`.
- Skills never enforce.
## Subagent fan-out (optional, host-dependent)

@@ -257,2 +274,3 @@

- Replace host Nest/DI with the runtime kernel unasked.
- Invent `/ark-run` or `/ark-order`.
- Auto-apply pattern (B) bets as if they were mechanical-safe.

@@ -279,3 +297,3 @@ - Create origin only after a long cleanup (freezes a polished “before” that never was).

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`

@@ -282,0 +300,0 @@ - **Handoff:** `/ark-…` / CLI / `none`

@@ -20,3 +20,3 @@ ---

|------------------------------|----------------|
| Layers / include / ArkRules / **ArkRun extra** need an edit | **`/ark-adopt`** (path, first `arkRun`) or **`/ark-autopilot`** (tighten) |
| Layers / include / ArkRules / **ArkRun extra** / **ArkOrder extra** need an edit | **`/ark-adopt`** (path, first `arkRun` / first `arkOrder`) or **`/ark-autopilot`** (tighten) |
| False-green / concentrated edge | **`/ark-adopt`** — write the honest config |

@@ -43,5 +43,5 @@ | Kernel extra / one kernel candidate | **`/ark-runtime`** — leftover name; wires `arkgate/runtime`, not a second package |

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
Label findings **`[Layer]`** vs **`[ArkRules]`** vs **`[ArkRun]`**. Absence of `arkRules` or `arkRun` is valid. First-time extra is **`/ark-adopt`** (advisory). Wire one candidate with **`/ark-runtime`**. New kernel-managed file with **`/ark-place`**. Do not invent `/ark-run`.
Label findings **`[Layer]`** vs **`[ArkRules]`** vs **`[ArkRun]`** vs **`[ArkOrder]`**. Absence of extras is valid and silent. First-time extra is **`/ark-adopt`** (advisory). Wire one kernel candidate with **`/ark-runtime`**. New kernel-managed / plane-root file with **`/ark-place`**. Grind skip clusters with **`/ark-autopilot`**. Do not invent `/ark-run` or `/ark-order`. Skills never enforce.

@@ -60,5 +60,5 @@ ## Subagent fan-out (optional, host-dependent)

1. If the path is missing or lying → execute **`/ark-adopt`** (including first advisory `arkRun`).
2. If the path is honest and you are tightening rules or the ArkRun extra → execute **`/ark-autopilot`**.
3. Companion / one candidate → **`/ark-runtime`**. `ark-check --strict-config`.
1. If the path is missing or lying → execute **`/ark-adopt`** (including first advisory `arkRun` / first advisory `arkOrder`).
2. If the path is honest and you are tightening rules or extras (`arkRun` / `arkOrder`) → execute **`/ark-autopilot`**.
3. One kernel candidate (extra already on) → **`/ark-runtime`**. `ark-check --strict-config`.

@@ -73,5 +73,5 @@ ## Completion contract (skill incomplete if missing)

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`
- **Handoff:** `/ark-adopt` / `/ark-autopilot` / `none`
- **Incomplete?** `no` | `yes — <what is missing>`

@@ -78,5 +78,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
ArkGate has **two opt-in planes**. The user chooses which to use; you **always label** findings so they never blur.
ArkGate has **always-on Layers** plus opt-in extras. The user chooses extras; you **always label** findings so they never blur. Absence of an extra is silent and valid. Skills never enforce. ArkOrder is an extra **inside** the `arkgate` package (`arkgate/order`), not a second install.

@@ -87,9 +87,12 @@ | Plane | What it protects | Where it lives | Sensors / tools |

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |
**Rules for every report / answer:**
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** (or a two-column table with those headers).
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** or **`[ArkOrder]`** (or a table with those headers).
2. Never call an import-edge violation an “invariant” or an aggregate sensor a “layer deny.”
3. Absence of `arkRules` is **valid** — do not force ArkRules unless the user wants them or residual inventory clearly wants a pilot.
4. Editing `arkrules/*` or promoting modes is **`/ark-contract`**; fixing code under a structure sensor is **`/ark-fix`** / **`/ark-loop`** (judgment, never invent mechanical-safe).
4. Editing `arkrules/*` or promoting modes is **`/ark-adopt`** / leftover **`/ark-contract`**; fixing code under a structure sensor is leftover **`/ark-fix`** / **`/ark-loop`** or **`/ark-autopilot`** (judgment, never invent mechanical-safe).
5. CLI helpers: `ark-check --rules-inventory --json`, doctor JSON `rulesUnderContract`, sensors emit `ARKRULE_*` / `INVARIANT_UNCOVERED` with `evidence.arkruleId`.
6. Extras silent when off. Doctor `arkRun` is `notAScore`. Do not force extras. Do not invent `/ark-run` or `/ark-order`.

@@ -101,2 +104,5 @@

### Coverage + extras
- Extras silent when off. Doctor `arkRun` is `notAScore`. “No arkRun / arkOrder” is not a failed gate. Do not force extras.
## Subagent fan-out (optional, host-dependent)

@@ -189,3 +195,3 @@

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`

@@ -192,0 +198,0 @@ - **Handoff:** `/ark-…` / CLI / `none`

@@ -62,5 +62,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
ArkGate has **two opt-in planes**. The user chooses which to use; you **always label** findings so they never blur.
ArkGate has **always-on Layers** plus opt-in extras. The user chooses extras; you **always label** findings so they never blur. Absence of an extra is silent and valid. Skills never enforce. ArkOrder is an extra **inside** the `arkgate` package (`arkgate/order`), not a second install.

@@ -71,5 +71,7 @@ | Plane | What it protects | Where it lives | Sensors / tools |

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |
**Rules for every report / answer:**
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** (or a two-column table with those headers).
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** or **`[ArkOrder]`** (or a table with those headers).
2. Never call an import-edge violation an “invariant” or an aggregate sensor a “layer deny.”

@@ -79,2 +81,3 @@ 3. Absence of `arkRules` is **valid** — do not force ArkRules unless the user wants them or residual inventory clearly wants a pilot.

5. CLI helpers: `ark-check --rules-inventory --json`, doctor JSON `rulesUnderContract`, sensors emit `ARKRULE_*` / `INVARIANT_UNCOVERED` with `evidence.arkruleId`.
6. Extras silent when off. Doctor `arkRun` is `notAScore`. Do not force extras. Do not invent `/ark-run` or `/ark-order`.

@@ -98,2 +101,5 @@

### Explain + extras
- Extras silent when off. If `arkRun` is on, doctor `arkRun` is `notAScore` — never a tour score. Do not force extras.
## Subagent fan-out (optional, host-dependent)

@@ -229,3 +235,3 @@

- **Result:** one-line outcome (include `ark-report.html` path; note if browser open was attempted)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`

@@ -232,0 +238,0 @@ - **Handoff:** `/ark-…` / CLI / `none`

@@ -142,5 +142,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
ArkGate has **two opt-in planes**. The user chooses which to use; you **always label** findings so they never blur.
ArkGate has **always-on Layers** plus opt-in extras. The user chooses extras; you **always label** findings so they never blur. Absence of an extra is silent and valid. Skills never enforce. ArkOrder is an extra **inside** the `arkgate` package (`arkgate/order`), not a second install.

@@ -151,5 +151,7 @@ | Plane | What it protects | Where it lives | Sensors / tools |

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |
**Rules for every report / answer:**
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** (or a two-column table with those headers).
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** or **`[ArkOrder]`** (or a table with those headers).
2. Never call an import-edge violation an “invariant” or an aggregate sensor a “layer deny.”

@@ -159,2 +161,3 @@ 3. Absence of `arkRules` is **valid** — do not force ArkRules unless the user wants them or residual inventory clearly wants a pilot.

5. CLI helpers: `ark-check --rules-inventory --json`, doctor JSON `rulesUnderContract`, sensors emit `ARKRULE_*` / `INVARIANT_UNCOVERED` with `evidence.arkruleId`.
6. Never write `arkRun` or `arkOrder` from this skill. When extras are present, label residual **`[ArkRun]`** / **`[ArkOrder]`**. Do not invent `/ark-run` or `/ark-order`.

@@ -168,2 +171,6 @@

### Explore + extras
- Map extras when present; never write `arkRun` / `arkOrder`. Extra off → residual `n/a` / silent.
- Field path may name `examples/arkorder-billing/` (ArkOrder fixture — map only). First extra write is `/ark-adopt`; grind is `/ark-autopilot`.
## Output mode (pick one — do not invent a fourth)

@@ -296,2 +303,3 @@

5. Flag **false promises**: demo fails under its own check, or green with a hollow contract.
6. When extras are on, label residual `[ArkRun]` / `[ArkOrder]`. Field path may name `examples/arkorder-billing/`. Never write extras from this skill.

@@ -439,3 +447,3 @@ If the repo is a **pure app** (no examples): state **Field path: internal** and do one of:

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`

@@ -442,0 +450,0 @@ - **Done axes:** architecture residual (status/doctor/compass) | feature/ticket residual (outside package). Enforce green ≠ feature done

@@ -49,5 +49,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
Label findings **`[Layer]`** vs **`[ArkRules]`**. Structure sensor fixes are judgment.
Label findings **`[Layer]`** vs **`[ArkRules]`** vs **`[ArkRun]`** vs **`[ArkOrder]`**. Absence of extras is valid and silent. Extra skip clusters (`ARKRUN_*` / `ARKORDER_*`) are **`/ark-autopilot`**. Do not invent `/ark-run` or `/ark-order`. Skills never enforce.

@@ -87,5 +87,5 @@ ## Subagent fan-out (optional, host-dependent)

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`
- **Handoff:** `/ark-autopilot` / `/ark-adopt` / `none`
- **Incomplete?** `no` | `yes — <what is missing>`

@@ -44,5 +44,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
Label findings **`[Layer]`** vs **`[ArkRules]`**. Never invent `mechanical-safe` kinds.
Label findings **`[Layer]`** vs **`[ArkRules]`** vs **`[ArkRun]`** vs **`[ArkOrder]`**. Absence of extras is valid and silent. Extra skip clusters (`ARKRUN_*` / `ARKORDER_*`) are **`/ark-autopilot`**. Never invent `mechanical-safe` kinds. Do not invent `/ark-run` or `/ark-order`. Skills never enforce.

@@ -83,5 +83,5 @@ ## Subagent fan-out (optional, host-dependent)

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`
- **Handoff:** `/ark-autopilot` / `/ark-explore` / `none`
- **Incomplete?** `no` | `yes — <what is missing>`

@@ -23,4 +23,8 @@ ---

- When `arkRun` is on: scaffold through the kernel (no `new` of managed types; declare
`uses` / `reactsTo` / `raises` / `sends`). Extra off → do not introduce the kernel. Enable it
`uses` / `reactsTo` / `raises` / `sends`; factory only in `arkRun.kernelRoots`,
`compositionRoots` alias). Extra off → do not introduce the kernel. Enable it
via `/ark-adopt`. Skills never enforce.
- When `arkOrder` is on: factory only in `arkOrder.planeRoots`; Domain stays plane-free;
freeze ξ with `release()`. Extra off → do not introduce the plane. Enable it via
`/ark-adopt`. Skills never enforce.

@@ -70,2 +74,3 @@ ## Autonomy contract

| Kernel-managed artifact when `arkRun` is already on | Extra not chosen yet → `/ark-adopt` (advisory `arkRun`); evaluate / migrate a hand-rolled bus → `/ark-runtime` |
| Plane-root artifact when `arkOrder` is already on | Extra not chosen yet → `/ark-adopt` (advisory `arkOrder`); skip cluster grind → `/ark-autopilot` |

@@ -113,3 +118,3 @@ The user describes something they need to build (a saga, a background job, an

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime` | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |

@@ -134,3 +139,3 @@

- Scaffold kernel-managed artifacts **through the kernel**, not `new` of an admitted type (`ARKRUN_DIRECT_NEW`).
- Call `createStrictArkKernel` (or an admission sibling) only inside `arkRun.compositionRoots`. Each call is a new instance — no process-wide `getKernel()`.
- Call `createStrictArkKernel` (or an admission sibling) only inside `arkRun.kernelRoots` (`compositionRoots` is a legacy alias — still valid). Each call is a new instance — no process-wide `getKernel()`.
- Domain-role files stay kernel-free (`ARKRUN_KERNEL_IN_DOMAIN`). Import from `arkgate/runtime` (or `arkgate/nestjs`). `@arkgate/runtime` is deprecated.

@@ -148,2 +153,3 @@ - List `uses` / `reactsTo` / `raises` / `sends` when `requireDeclarations` is on. Adding an existing call-site literal to the declaration list is the only mechanical-safe ArkRun edit; inventing a new emit / handle / depend is judgment.

- Call the factory only inside `arkOrder.planeRoots`. Empty roots in `enforced` mode is `ARKORDER_MISSING_PLANE`.
- Skip clusters (`ARKORDER_MISSING_PLANE` / `ARKORDER_KERNEL_IN_DOMAIN` / `ARKORDER_GENERIC_UPDATE` / `ARKORDER_TOO_MANY_PARAMS` / `ARKORDER_INGEST_WRITES_XI`): place this artifact, then grind via `/ark-autopilot`. Extra not on → `/ark-adopt`. Do not invent `/ark-order`.
- Absence of the extra is valid. Do not invent `/ark-order`. Skills never enforce.

@@ -216,2 +222,5 @@

`/ark-autopilot`. Extra not on → `/ark-adopt` (advisory) or `/ark-runtime` (evaluate).
- If `arkOrder` is on and the user is grinding skip violations (`ARKORDER_*`) across many files:
place this artifact on a plane root, then leftover `/ark-fix` / `/ark-autopilot`. Extra not on
→ `/ark-adopt` (advisory). Do not invent `/ark-order`.

@@ -218,0 +227,0 @@ ## Operating rules

@@ -14,3 +14,3 @@ ---

**When:** evaluate a hand-rolled bus / outbox / saga / projection / policy / Nest adapter against
the kernel, or wire an extra that is already on (composition root, declarations, transport).
the kernel, or wire an extra that is already on (kernel root, declarations, transport).
**Not when:** session 0 / extra not chosen (`/ark-adopt`); one new file (`/ark-place`); skip-violation

@@ -54,5 +54,5 @@ grind (`/ark-autopilot` / leftover `/ark-fix`).

## Out of scope for ArkRules
## Out of scope for ArkRules and ArkOrder
This skill is **runtime-kernel only**. Do not mix ArkRules structure/invariants here; hand off to `/ark-contract` / `/ark-adopt` / `/ark-explore` for static contract planes. Label kernel-usage residual **`[ArkRun]`** so it never blurs with **`[Layer]`** or **`[ArkRules]`**.
This skill is **runtime-kernel only**. Do not mix ArkRules structure/invariants here; do **not** turn this skill into an ArkOrder skill. Hand off first extras to `/ark-adopt`, new files to `/ark-place`, skip clusters to `/ark-autopilot`. Label kernel-usage residual **`[ArkRun]`** so it never blurs with **`[Layer]`**, **`[ArkRules]`**, or **`[ArkOrder]`**.

@@ -80,5 +80,6 @@ ## Subagent fan-out (optional, host-dependent)

**STOP — do not continue this skill as complete.** Handoff **`/ark-adopt`** to write **advisory**
`arkRun` (schema `1.2+`; `compositionRoots`, `managedLayers`, `requireDeclarations`). Do not
invent the extra here. If the extra is present, note `mode`, roots, managed layers, and
`requireDeclarations`; doctor `arkRun` is `notAScore`.
`arkRun` (schema `1.2+`; **`kernelRoots` preferred**, `compositionRoots` alias, `managedLayers`,
`requireDeclarations`). Do not invent the extra here. If the extra is present, note `mode`,
`kernelRoots` (or alias `compositionRoots`), managed layers, and `requireDeclarations`; doctor
`arkRun` is `notAScore`.
3. **Pick ONE target** — the smallest, most self-contained candidate (fewest

@@ -90,7 +91,8 @@ call sites). Migrating everything at once is how adoptions die. List the

5. **Wire through the kernel** — read the
[runtime package guide](https://github.com/pedroknigge/arkgate/blob/main/packages/runtime/README.md)
plus the [experimental surface policy](https://github.com/pedroknigge/arkgate/blob/main/docs/package-surface.md#experimental-opt-in-surfaces) before
writing code.
[experimental opt-in surfaces](https://github.com/pedroknigge/arkgate/blob/main/docs/package-surface.md#experimental-opt-in-surfaces)
(primary kernel guide; import `arkgate/runtime` from the same `arkgate` tarball). Optional
durability non-claim: [production-hardening.md](https://github.com/pedroknigge/arkgate/blob/main/docs/production-hardening.md).
Do **not** treat `packages/runtime/README.md` (deprecated companion leftover) as the kernel guide.
- Call `createStrictArkKernel` (or an admission sibling: `createArkKernel`, `*FromConfig`) **only**
inside `arkRun.compositionRoots`. Each call is a new instance — no process-wide singleton.
inside `arkRun.kernelRoots` (`compositionRoots` is a legacy alias — still valid). Each call is a new instance — no process-wide singleton.
- Keep Domain-role layers kernel-free (`ARKRUN_KERNEL_IN_DOMAIN`).

@@ -162,3 +164,3 @@ - Resolve managed types from the kernel; do not construct admitted types with `new`

- **Result:** one-line outcome
- **Planes:** **`[ArkRun]`** residual (or `n/a` if extra absent) — do not mix with `[Layer]` / `[ArkRules]`
- **Planes:** **`[ArkRun]`** residual (or `n/a` if extra absent) — do not mix with `[Layer]` / `[ArkRules]` / `[ArkOrder]`
- **Compass:** `n/a` (runtime skill; static residual → explore/fix) | top residual if doctor was run

@@ -165,0 +167,0 @@ - **Handoff:** `/ark-…` / CLI / `none`

@@ -72,5 +72,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
ArkGate has **two opt-in planes**. The user chooses which to use; you **always label** findings so they never blur.
ArkGate has **always-on Layers** plus opt-in extras. The user chooses extras; you **always label** findings so they never blur. Absence of an extra is silent and valid. Skills never enforce. ArkOrder is an extra **inside** the `arkgate` package (`arkgate/order`), not a second install.

@@ -81,8 +81,10 @@ | Plane | What it protects | Where it lives | Sensors / tools |

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |
**Rules for every report / answer:**
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** (or a two-column table with those headers).
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** or **`[ArkOrder]`** (or a table with those headers).
2. Never call an import-edge violation an “invariant” or an aggregate sensor a “layer deny.”
3. Absence of `arkRules` is **valid** — do not force ArkRules unless the user wants them or residual inventory clearly wants a pilot.
4. Editing `arkrules/*` or promoting modes is **`/ark-contract`**; fixing code under a structure sensor is **`/ark-fix`** / **`/ark-loop`** (judgment, never invent mechanical-safe).
4. Editing `arkrules/*` or promoting modes is **`/ark-adopt`** / leftover **`/ark-contract`**; fixing code under a structure sensor is leftover **`/ark-fix`** / **`/ark-loop`** or **`/ark-autopilot`** (judgment, never invent mechanical-safe). Extra decisions stay on existing doors. Do not invent `/ark-run` or `/ark-order`.
5. CLI helpers: `ark-check --rules-inventory --json`, doctor JSON `rulesUnderContract`, sensors emit `ARKRULE_*` / `INVARIANT_UNCOVERED` with `evidence.arkruleId`.

@@ -95,2 +97,5 @@

### Think + extras
- Extra decisions stay enforceable on existing doors (`/ark-adopt` session 0, `/ark-place` new file, `/ark-autopilot` grind, `/ark-runtime` one kernel candidate). No new skill name. Do not invent `/ark-run` or `/ark-order`.
## Subagent fan-out (optional, host-dependent)

@@ -132,4 +137,5 @@

judgment auto-apply, codemod engines, or skipping write-gate/CI.
8. **Hand off** — placement `/ark-place`; config `/ark-contract`; bulk debt `/ark-loop` /
`/ark-autopilot`; map-only `/ark-explore`; violations `/ark-fix`.
8. **Hand off** — placement `/ark-place`; first extra `/ark-adopt`; grind `/ark-autopilot`;
map-only `/ark-explore`; leftover config `/ark-contract`; leftover cluster `/ark-fix` /
`/ark-loop`. Extra decisions stay on those doors. Do not invent `/ark-run` or `/ark-order`.
When the user needs action not advice: **STOP — do not continue this skill as complete** — invoke the handoff skill.

@@ -161,3 +167,3 @@

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`

@@ -164,0 +170,0 @@ - **Done axes:** architecture residual (status/doctor/compass) | feature/ticket residual (outside package). Enforce green ≠ feature done

@@ -119,5 +119,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
ArkGate has **two opt-in planes**. The user chooses which to use; you **always label** findings so they never blur.
ArkGate has **always-on Layers** plus opt-in extras. The user chooses extras; you **always label** findings so they never blur. Absence of an extra is silent and valid. Skills never enforce. ArkOrder is an extra **inside** the `arkgate` package (`arkgate/order`), not a second install.

@@ -128,5 +128,7 @@ | Plane | What it protects | Where it lives | Sensors / tools |

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |
**Rules for every report / answer:**
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** (or a two-column table with those headers).
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** or **`[ArkOrder]`** (or a table with those headers).
2. Never call an import-edge violation an “invariant” or an aggregate sensor a “layer deny.”

@@ -136,2 +138,3 @@ 3. Absence of `arkRules` is **valid** — do not force ArkRules unless the user wants them or residual inventory clearly wants a pilot.

5. CLI helpers: `ark-check --rules-inventory --json`, doctor JSON `rulesUnderContract`, sensors emit `ARKRULE_*` / `INVARIANT_UNCOVERED` with `evidence.arkruleId`.
6. Schema `1.3` extras stay off unless already on. Pin teaches `arkgate/runtime` (same tarball), not the deprecated companion. Do not invent `/ark-run` or `/ark-order`.

@@ -143,2 +146,7 @@

### Upgrade + extras
- Schema `1.3` extras (`arkRun` / `arkOrder`) stay off unless already on. Do not turn extras on during upgrade.
- Pin teaches `arkgate/runtime` (same tarball). `@arkgate/runtime` is deprecated. Do not send agents to `packages/runtime/README.md` as the kernel guide.
- After 4.8.2, customized skills may lag — opt-in `--refresh-skills` with consent so the frozen 13 names pick up four-plane deepen. No new skill names.
## Safety contract

@@ -312,3 +320,3 @@

- **Result:** old → new version and managed-upgrade outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`

@@ -315,0 +323,0 @@ - **Handoff:** `/ark-…`, CLI action, or `none`

@@ -10,3 +10,3 @@ # ArkGate Agent Skills package

Package version when last generated context: **arkgate@4.8.0**
Package version when last generated context: **arkgate@4.8.1**
Schema: agent-skills package contract `1.0`

@@ -13,0 +13,0 @@

@@ -23,4 +23,5 @@ ---

- CLI-first: if `arkgate-check` already resolved the root, do not wait on MCP.
- Do not add `arkRun` unless the user wants the extra. When they do, write **advisory** `arkRun`
(schema `1.2+`) in this turn. Absence is silent and valid. Skills never enforce.
- Do not add `arkRun` or `arkOrder` unless the user wants that extra. When they do, write
**advisory** extra in this turn (`arkRun` schema `1.2+`; `arkOrder` schema `1.3+`).
Absence is silent and valid. Compact starter stays extras-off. Skills never enforce.

@@ -100,3 +101,4 @@ Invoking this skill **is** the approval. Write the architecture config in this turn.

| Freeze **real** debt after the config is honest | User said map only |
| Turn **advisory** ArkRun on (`arkRun` extra, schema `1.2+`) | Evaluate / wire a hand-rolled bus → `/ark-runtime`; new kernel-managed file → `/ark-place` |
| Turn **advisory** ArkRun on (`arkRun` extra, schema `1.2+`; **`kernelRoots` preferred**) | Evaluate / wire a hand-rolled bus → `/ark-runtime`; new kernel-managed file → `/ark-place` |
| Turn **advisory** ArkOrder on (`arkOrder` extra, schema `1.3+`, `planeRoots`) | New plane-root file after extra is on → `/ark-place`; grind skip clusters → `/ark-autopilot` |

@@ -121,5 +123,5 @@ ## Dual engine (mandatory)

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
ArkGate has **two opt-in planes**. The user chooses which to use; you **always label** findings so they never blur.
ArkGate has **always-on Layers** plus opt-in extras. The user chooses extras; you **always label** findings so they never blur. Absence of an extra is silent and valid. Skills never enforce. ArkOrder is an extra **inside** the `arkgate` package (`arkgate/order`), not a second install.

@@ -130,6 +132,7 @@ | Plane | What it protects | Where it lives | Sensors / tools |

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime` | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |
**Rules for every report / answer:**
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** (or a two-column table with those headers).
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** or **`[ArkOrder]`** (or a table with those headers).
2. Never call an import-edge violation an “invariant” or an aggregate sensor a “layer deny.”

@@ -140,2 +143,3 @@ 3. Absence of `arkRules` is **valid** — do not force ArkRules unless the user wants them or residual inventory clearly wants a pilot.

6. Absence of `arkRun` is **valid**. Write it only when the user wants the extra. Skills never enforce.
7. Absence of `arkOrder` is **valid**. Write it only when the user wants the extra. Do not invent `/ark-order`. Skills never enforce.

@@ -150,3 +154,3 @@

- User asked to turn the extra on: write **advisory** `arkRun` on `ark.config.json` (`schemaVersion` `1.2+`) **in this turn**. Default `"mode": "advisory"`.
- Required shape: `compositionRoots` (real files; empty + enforced fails closed), `managedLayers` (existing `layers[].name` only), `requireDeclarations` (default true).
- Required shape: **`kernelRoots` preferred** (real files; empty + enforced fails closed). `compositionRoots` is a legacy alias — still valid. `managedLayers` (existing `layers[].name` only), `requireDeclarations` (default true).
- Do **not** put `arkRun` on the compact starter / `ark start` scaffold. Brownfield stays advisory until the team promotes.

@@ -159,2 +163,24 @@ - Absence is valid and **silent** — never force the extra. Never force the kernel over existing Nest/DI. Do not invent `/ark-run`.

### Adopt + ArkOrder
- User asked to turn the extra on: write **advisory** `arkOrder` on `ark.config.json` (`schemaVersion` `1.3+`) **in this turn**. Default `"mode": "advisory"` — never session-0 default `enforced`.
- Required shape: `planeRoots` (real files; empty + enforced = `ARKORDER_MISSING_PLANE`), `managedLayers` (existing `layers[].name` only), `maxXiKeys` (default 7).
- Example (consumer trees — not this library's 4-layer compact):
```json
{
"schemaVersion": "1.3",
"arkOrder": {
"mode": "advisory",
"planeRoots": ["src/main.ts"],
"managedLayers": ["Application"],
"maxXiKeys": 7
}
}
```
- Do **not** put `arkOrder` on the compact starter / `ark start` scaffold. Domain stays plane-free. Import `createOrderPlane` from `arkgate/order` (same npm package).
- Absence is valid and **silent** — never force the extra. Do not invent `/ark-order`.
- Demoting enforced → advisory or deleting the extra is policy-delta **weakening**.
- After the extra is honest: handoff `/ark-place` for new plane-root files; grind skip via `/ark-autopilot`. Skills never enforce.
## Subagent fan-out (optional, host-dependent)

@@ -210,4 +236,6 @@

User wants the ArkRun extra → write **advisory** `arkRun` (schema `1.2+`, real
`compositionRoots`, existing `managedLayers`) **in this turn**. Do not add it to a compact
starter. Do not promote to enforced as the session-0 default.
`kernelRoots` preferred — `compositionRoots` alias, existing `managedLayers`) **in this turn**.
User wants the ArkOrder extra → write **advisory** `arkOrder` (schema `1.3+`, real
`planeRoots`, existing `managedLayers`, `maxXiKeys` 7) **in this turn**. Do not add extras
to a compact starter. Do not promote to enforced as the session-0 default.
2. **Check + diagnose** — `summary.concentrated` / dominant edge → fix contract first, don’t freeze.

@@ -255,5 +283,5 @@ Cross-slice / cross-context `peerIsolation` hits are judgment: extract shared or events.

- Force runtime kernel over existing Nest/DI.
- Put `arkRun` on the compact starter / `ark start` scaffold.
- Put `arkRun` or `arkOrder` on the compact starter / `ark start` scaffold.
- Claim in-memory kernel stores are production durability.
- Invent `/ark-run`.
- Invent `/ark-run` or `/ark-order`.
- Claim Enforce while governed% is low, cores empty with I/O in Application, or core bags ungoverned.

@@ -270,3 +298,3 @@ - End adopt with only “baseline written” when design-weak residual is visible in files you opened.

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`

@@ -273,0 +301,0 @@ - **Done axes:** architecture residual (status/doctor/compass) | feature/ticket residual (outside package). Enforce green ≠ feature done

@@ -43,5 +43,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
Label findings **`[Layer]`** vs **`[ArkRules]`**. Absence of `arkRules` is valid.
Label findings **`[Layer]`** vs **`[ArkRules]`** vs **`[ArkRun]`** vs **`[ArkOrder]`**. Absence of extras is valid and silent. Session-0 extras (advisory `arkRun` / advisory `arkOrder`) live on **`/ark-adopt`**. Do not invent `/ark-run` or `/ark-order`. Skills never enforce.

@@ -61,3 +61,3 @@ ## Subagent fan-out (optional, host-dependent)

1. Bind MCP (`ark_identity` then `ark_recommend`) or run `ark-check --recommend`.
2. Execute **`/ark-adopt`** autonomy: write the config, dirs, optional advisory ArkRules, gates.
2. Execute **`/ark-adopt`** autonomy: write the config, dirs, optional advisory ArkRules, optional advisory ArkRun / ArkOrder when asked, gates.
3. `ark-check --strict-config`. Handoff `/ark-place` for new files.

@@ -73,5 +73,5 @@

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`
- **Handoff:** `/ark-adopt` / `/ark-place` / `none`
- **Incomplete?** `no` | `yes — <what is missing>`

@@ -63,2 +63,3 @@ ---

| **Apply** leftover design (one Shape refactor) | User said map only |
| Extra skip cluster (`ARKRUN_*` / `ARKORDER_*`) after extra is on | Extra off → `/ark-adopt` (advisory); evaluate one bus → `/ark-runtime` |
| Spaghetti under ENFORCE: Shape work (invoke = apply one pilot) | — |

@@ -114,5 +115,5 @@

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
ArkGate has **two opt-in planes**. The user chooses which to use; you **always label** findings so they never blur.
ArkGate has **always-on Layers** plus opt-in extras. The user chooses extras; you **always label** findings so they never blur. Absence of an extra is silent and valid. Skills never enforce. ArkOrder is an extra **inside** the `arkgate` package (`arkgate/order`), not a second install.

@@ -123,5 +124,7 @@ | Plane | What it protects | Where it lives | Sensors / tools |

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |
**Rules for every report / answer:**
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** (or a two-column table with those headers).
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** or **`[ArkOrder]`** (or a table with those headers).
2. Never call an import-edge violation an “invariant” or an aggregate sensor a “layer deny.”

@@ -131,2 +134,3 @@ 3. Absence of `arkRules` is **valid** — do not force ArkRules unless the user wants them or residual inventory clearly wants a pilot.

5. CLI helpers: `ark-check --rules-inventory --json`, doctor JSON `rulesUnderContract`, sensors emit `ARKRULE_*` / `INVARIANT_UNCOVERED` with `evidence.arkruleId`.
6. Absence of extras is **valid**. Extra skip clusters grind **here** after the extra is on. Do not invent `/ark-run` or `/ark-order`. Skills never enforce.

@@ -141,2 +145,15 @@

### Autopilot + ArkRun
When `arkRun` is present:
- Grind skip clusters with judgment: `ARKRUN_DIRECT_NEW` / `ARKRUN_TRANSPORT_BYPASS` / `ARKRUN_KERNEL_IN_DOMAIN` / `ARKRUN_MISSING_ROOT`. Never invent `mechanical-safe` for new emits / homemade buses.
- Factory only inside `arkRun.kernelRoots` (`compositionRoots` alias). Import `arkgate/runtime`. Doctor `arkRun` is `notAScore`.
- Extra off → `/ark-adopt` (advisory) or `/ark-runtime` (evaluate one candidate). Do not invent `/ark-run`.
- Skills never enforce.
### Autopilot + ArkOrder
When `arkOrder` is present:
- Grind skip clusters with judgment: `ARKORDER_MISSING_PLANE` / `ARKORDER_KERNEL_IN_DOMAIN` / `ARKORDER_GENERIC_UPDATE` / `ARKORDER_TOO_MANY_PARAMS` / `ARKORDER_INGEST_WRITES_XI`. Freeze ξ with `release()`; never `update`/`patch`/`set`.
- Extra off → `/ark-adopt` (advisory). Do not invent `/ark-order`.
- Skills never enforce.
## Subagent fan-out (optional, host-dependent)

@@ -257,2 +274,3 @@

- Replace host Nest/DI with the runtime kernel unasked.
- Invent `/ark-run` or `/ark-order`.
- Auto-apply pattern (B) bets as if they were mechanical-safe.

@@ -279,3 +297,3 @@ - Create origin only after a long cleanup (freezes a polished “before” that never was).

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`

@@ -282,0 +300,0 @@ - **Handoff:** `/ark-…` / CLI / `none`

@@ -20,3 +20,3 @@ ---

|------------------------------|----------------|
| Layers / include / ArkRules / **ArkRun extra** need an edit | **`/ark-adopt`** (path, first `arkRun`) or **`/ark-autopilot`** (tighten) |
| Layers / include / ArkRules / **ArkRun extra** / **ArkOrder extra** need an edit | **`/ark-adopt`** (path, first `arkRun` / first `arkOrder`) or **`/ark-autopilot`** (tighten) |
| False-green / concentrated edge | **`/ark-adopt`** — write the honest config |

@@ -43,5 +43,5 @@ | Kernel extra / one kernel candidate | **`/ark-runtime`** — leftover name; wires `arkgate/runtime`, not a second package |

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
Label findings **`[Layer]`** vs **`[ArkRules]`** vs **`[ArkRun]`**. Absence of `arkRules` or `arkRun` is valid. First-time extra is **`/ark-adopt`** (advisory). Wire one candidate with **`/ark-runtime`**. New kernel-managed file with **`/ark-place`**. Do not invent `/ark-run`.
Label findings **`[Layer]`** vs **`[ArkRules]`** vs **`[ArkRun]`** vs **`[ArkOrder]`**. Absence of extras is valid and silent. First-time extra is **`/ark-adopt`** (advisory). Wire one kernel candidate with **`/ark-runtime`**. New kernel-managed / plane-root file with **`/ark-place`**. Grind skip clusters with **`/ark-autopilot`**. Do not invent `/ark-run` or `/ark-order`. Skills never enforce.

@@ -60,5 +60,5 @@ ## Subagent fan-out (optional, host-dependent)

1. If the path is missing or lying → execute **`/ark-adopt`** (including first advisory `arkRun`).
2. If the path is honest and you are tightening rules or the ArkRun extra → execute **`/ark-autopilot`**.
3. Companion / one candidate → **`/ark-runtime`**. `ark-check --strict-config`.
1. If the path is missing or lying → execute **`/ark-adopt`** (including first advisory `arkRun` / first advisory `arkOrder`).
2. If the path is honest and you are tightening rules or extras (`arkRun` / `arkOrder`) → execute **`/ark-autopilot`**.
3. One kernel candidate (extra already on) → **`/ark-runtime`**. `ark-check --strict-config`.

@@ -73,5 +73,5 @@ ## Completion contract (skill incomplete if missing)

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`
- **Handoff:** `/ark-adopt` / `/ark-autopilot` / `none`
- **Incomplete?** `no` | `yes — <what is missing>`

@@ -78,5 +78,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
ArkGate has **two opt-in planes**. The user chooses which to use; you **always label** findings so they never blur.
ArkGate has **always-on Layers** plus opt-in extras. The user chooses extras; you **always label** findings so they never blur. Absence of an extra is silent and valid. Skills never enforce. ArkOrder is an extra **inside** the `arkgate` package (`arkgate/order`), not a second install.

@@ -87,9 +87,12 @@ | Plane | What it protects | Where it lives | Sensors / tools |

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |
**Rules for every report / answer:**
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** (or a two-column table with those headers).
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** or **`[ArkOrder]`** (or a table with those headers).
2. Never call an import-edge violation an “invariant” or an aggregate sensor a “layer deny.”
3. Absence of `arkRules` is **valid** — do not force ArkRules unless the user wants them or residual inventory clearly wants a pilot.
4. Editing `arkrules/*` or promoting modes is **`/ark-contract`**; fixing code under a structure sensor is **`/ark-fix`** / **`/ark-loop`** (judgment, never invent mechanical-safe).
4. Editing `arkrules/*` or promoting modes is **`/ark-adopt`** / leftover **`/ark-contract`**; fixing code under a structure sensor is leftover **`/ark-fix`** / **`/ark-loop`** or **`/ark-autopilot`** (judgment, never invent mechanical-safe).
5. CLI helpers: `ark-check --rules-inventory --json`, doctor JSON `rulesUnderContract`, sensors emit `ARKRULE_*` / `INVARIANT_UNCOVERED` with `evidence.arkruleId`.
6. Extras silent when off. Doctor `arkRun` is `notAScore`. Do not force extras. Do not invent `/ark-run` or `/ark-order`.

@@ -101,2 +104,5 @@

### Coverage + extras
- Extras silent when off. Doctor `arkRun` is `notAScore`. “No arkRun / arkOrder” is not a failed gate. Do not force extras.
## Subagent fan-out (optional, host-dependent)

@@ -189,3 +195,3 @@

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`

@@ -192,0 +198,0 @@ - **Handoff:** `/ark-…` / CLI / `none`

@@ -62,5 +62,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
ArkGate has **two opt-in planes**. The user chooses which to use; you **always label** findings so they never blur.
ArkGate has **always-on Layers** plus opt-in extras. The user chooses extras; you **always label** findings so they never blur. Absence of an extra is silent and valid. Skills never enforce. ArkOrder is an extra **inside** the `arkgate` package (`arkgate/order`), not a second install.

@@ -71,5 +71,7 @@ | Plane | What it protects | Where it lives | Sensors / tools |

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |
**Rules for every report / answer:**
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** (or a two-column table with those headers).
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** or **`[ArkOrder]`** (or a table with those headers).
2. Never call an import-edge violation an “invariant” or an aggregate sensor a “layer deny.”

@@ -79,2 +81,3 @@ 3. Absence of `arkRules` is **valid** — do not force ArkRules unless the user wants them or residual inventory clearly wants a pilot.

5. CLI helpers: `ark-check --rules-inventory --json`, doctor JSON `rulesUnderContract`, sensors emit `ARKRULE_*` / `INVARIANT_UNCOVERED` with `evidence.arkruleId`.
6. Extras silent when off. Doctor `arkRun` is `notAScore`. Do not force extras. Do not invent `/ark-run` or `/ark-order`.

@@ -98,2 +101,5 @@

### Explain + extras
- Extras silent when off. If `arkRun` is on, doctor `arkRun` is `notAScore` — never a tour score. Do not force extras.
## Subagent fan-out (optional, host-dependent)

@@ -229,3 +235,3 @@

- **Result:** one-line outcome (include `ark-report.html` path; note if browser open was attempted)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`

@@ -232,0 +238,0 @@ - **Handoff:** `/ark-…` / CLI / `none`

@@ -142,5 +142,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
ArkGate has **two opt-in planes**. The user chooses which to use; you **always label** findings so they never blur.
ArkGate has **always-on Layers** plus opt-in extras. The user chooses extras; you **always label** findings so they never blur. Absence of an extra is silent and valid. Skills never enforce. ArkOrder is an extra **inside** the `arkgate` package (`arkgate/order`), not a second install.

@@ -151,5 +151,7 @@ | Plane | What it protects | Where it lives | Sensors / tools |

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |
**Rules for every report / answer:**
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** (or a two-column table with those headers).
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** or **`[ArkOrder]`** (or a table with those headers).
2. Never call an import-edge violation an “invariant” or an aggregate sensor a “layer deny.”

@@ -159,2 +161,3 @@ 3. Absence of `arkRules` is **valid** — do not force ArkRules unless the user wants them or residual inventory clearly wants a pilot.

5. CLI helpers: `ark-check --rules-inventory --json`, doctor JSON `rulesUnderContract`, sensors emit `ARKRULE_*` / `INVARIANT_UNCOVERED` with `evidence.arkruleId`.
6. Never write `arkRun` or `arkOrder` from this skill. When extras are present, label residual **`[ArkRun]`** / **`[ArkOrder]`**. Do not invent `/ark-run` or `/ark-order`.

@@ -168,2 +171,6 @@

### Explore + extras
- Map extras when present; never write `arkRun` / `arkOrder`. Extra off → residual `n/a` / silent.
- Field path may name `examples/arkorder-billing/` (ArkOrder fixture — map only). First extra write is `/ark-adopt`; grind is `/ark-autopilot`.
## Output mode (pick one — do not invent a fourth)

@@ -296,2 +303,3 @@

5. Flag **false promises**: demo fails under its own check, or green with a hollow contract.
6. When extras are on, label residual `[ArkRun]` / `[ArkOrder]`. Field path may name `examples/arkorder-billing/`. Never write extras from this skill.

@@ -439,3 +447,3 @@ If the repo is a **pure app** (no examples): state **Field path: internal** and do one of:

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`

@@ -442,0 +450,0 @@ - **Done axes:** architecture residual (status/doctor/compass) | feature/ticket residual (outside package). Enforce green ≠ feature done

@@ -49,5 +49,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
Label findings **`[Layer]`** vs **`[ArkRules]`**. Structure sensor fixes are judgment.
Label findings **`[Layer]`** vs **`[ArkRules]`** vs **`[ArkRun]`** vs **`[ArkOrder]`**. Absence of extras is valid and silent. Extra skip clusters (`ARKRUN_*` / `ARKORDER_*`) are **`/ark-autopilot`**. Do not invent `/ark-run` or `/ark-order`. Skills never enforce.

@@ -87,5 +87,5 @@ ## Subagent fan-out (optional, host-dependent)

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`
- **Handoff:** `/ark-autopilot` / `/ark-adopt` / `none`
- **Incomplete?** `no` | `yes — <what is missing>`

@@ -44,5 +44,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
Label findings **`[Layer]`** vs **`[ArkRules]`**. Never invent `mechanical-safe` kinds.
Label findings **`[Layer]`** vs **`[ArkRules]`** vs **`[ArkRun]`** vs **`[ArkOrder]`**. Absence of extras is valid and silent. Extra skip clusters (`ARKRUN_*` / `ARKORDER_*`) are **`/ark-autopilot`**. Never invent `mechanical-safe` kinds. Do not invent `/ark-run` or `/ark-order`. Skills never enforce.

@@ -83,5 +83,5 @@ ## Subagent fan-out (optional, host-dependent)

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`
- **Handoff:** `/ark-autopilot` / `/ark-explore` / `none`
- **Incomplete?** `no` | `yes — <what is missing>`

@@ -23,4 +23,8 @@ ---

- When `arkRun` is on: scaffold through the kernel (no `new` of managed types; declare
`uses` / `reactsTo` / `raises` / `sends`). Extra off → do not introduce the kernel. Enable it
`uses` / `reactsTo` / `raises` / `sends`; factory only in `arkRun.kernelRoots`,
`compositionRoots` alias). Extra off → do not introduce the kernel. Enable it
via `/ark-adopt`. Skills never enforce.
- When `arkOrder` is on: factory only in `arkOrder.planeRoots`; Domain stays plane-free;
freeze ξ with `release()`. Extra off → do not introduce the plane. Enable it via
`/ark-adopt`. Skills never enforce.

@@ -70,2 +74,3 @@ ## Autonomy contract

| Kernel-managed artifact when `arkRun` is already on | Extra not chosen yet → `/ark-adopt` (advisory `arkRun`); evaluate / migrate a hand-rolled bus → `/ark-runtime` |
| Plane-root artifact when `arkOrder` is already on | Extra not chosen yet → `/ark-adopt` (advisory `arkOrder`); skip cluster grind → `/ark-autopilot` |

@@ -113,3 +118,3 @@ The user describes something they need to build (a saga, a background job, an

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime` | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |

@@ -134,3 +139,3 @@

- Scaffold kernel-managed artifacts **through the kernel**, not `new` of an admitted type (`ARKRUN_DIRECT_NEW`).
- Call `createStrictArkKernel` (or an admission sibling) only inside `arkRun.compositionRoots`. Each call is a new instance — no process-wide `getKernel()`.
- Call `createStrictArkKernel` (or an admission sibling) only inside `arkRun.kernelRoots` (`compositionRoots` is a legacy alias — still valid). Each call is a new instance — no process-wide `getKernel()`.
- Domain-role files stay kernel-free (`ARKRUN_KERNEL_IN_DOMAIN`). Import from `arkgate/runtime` (or `arkgate/nestjs`). `@arkgate/runtime` is deprecated.

@@ -148,2 +153,3 @@ - List `uses` / `reactsTo` / `raises` / `sends` when `requireDeclarations` is on. Adding an existing call-site literal to the declaration list is the only mechanical-safe ArkRun edit; inventing a new emit / handle / depend is judgment.

- Call the factory only inside `arkOrder.planeRoots`. Empty roots in `enforced` mode is `ARKORDER_MISSING_PLANE`.
- Skip clusters (`ARKORDER_MISSING_PLANE` / `ARKORDER_KERNEL_IN_DOMAIN` / `ARKORDER_GENERIC_UPDATE` / `ARKORDER_TOO_MANY_PARAMS` / `ARKORDER_INGEST_WRITES_XI`): place this artifact, then grind via `/ark-autopilot`. Extra not on → `/ark-adopt`. Do not invent `/ark-order`.
- Absence of the extra is valid. Do not invent `/ark-order`. Skills never enforce.

@@ -216,2 +222,5 @@

`/ark-autopilot`. Extra not on → `/ark-adopt` (advisory) or `/ark-runtime` (evaluate).
- If `arkOrder` is on and the user is grinding skip violations (`ARKORDER_*`) across many files:
place this artifact on a plane root, then leftover `/ark-fix` / `/ark-autopilot`. Extra not on
→ `/ark-adopt` (advisory). Do not invent `/ark-order`.

@@ -218,0 +227,0 @@ ## Operating rules

@@ -14,3 +14,3 @@ ---

**When:** evaluate a hand-rolled bus / outbox / saga / projection / policy / Nest adapter against
the kernel, or wire an extra that is already on (composition root, declarations, transport).
the kernel, or wire an extra that is already on (kernel root, declarations, transport).
**Not when:** session 0 / extra not chosen (`/ark-adopt`); one new file (`/ark-place`); skip-violation

@@ -54,5 +54,5 @@ grind (`/ark-autopilot` / leftover `/ark-fix`).

## Out of scope for ArkRules
## Out of scope for ArkRules and ArkOrder
This skill is **runtime-kernel only**. Do not mix ArkRules structure/invariants here; hand off to `/ark-contract` / `/ark-adopt` / `/ark-explore` for static contract planes. Label kernel-usage residual **`[ArkRun]`** so it never blurs with **`[Layer]`** or **`[ArkRules]`**.
This skill is **runtime-kernel only**. Do not mix ArkRules structure/invariants here; do **not** turn this skill into an ArkOrder skill. Hand off first extras to `/ark-adopt`, new files to `/ark-place`, skip clusters to `/ark-autopilot`. Label kernel-usage residual **`[ArkRun]`** so it never blurs with **`[Layer]`**, **`[ArkRules]`**, or **`[ArkOrder]`**.

@@ -80,5 +80,6 @@ ## Subagent fan-out (optional, host-dependent)

**STOP — do not continue this skill as complete.** Handoff **`/ark-adopt`** to write **advisory**
`arkRun` (schema `1.2+`; `compositionRoots`, `managedLayers`, `requireDeclarations`). Do not
invent the extra here. If the extra is present, note `mode`, roots, managed layers, and
`requireDeclarations`; doctor `arkRun` is `notAScore`.
`arkRun` (schema `1.2+`; **`kernelRoots` preferred**, `compositionRoots` alias, `managedLayers`,
`requireDeclarations`). Do not invent the extra here. If the extra is present, note `mode`,
`kernelRoots` (or alias `compositionRoots`), managed layers, and `requireDeclarations`; doctor
`arkRun` is `notAScore`.
3. **Pick ONE target** — the smallest, most self-contained candidate (fewest

@@ -90,7 +91,8 @@ call sites). Migrating everything at once is how adoptions die. List the

5. **Wire through the kernel** — read the
[runtime package guide](https://github.com/pedroknigge/arkgate/blob/main/packages/runtime/README.md)
plus the [experimental surface policy](https://github.com/pedroknigge/arkgate/blob/main/docs/package-surface.md#experimental-opt-in-surfaces) before
writing code.
[experimental opt-in surfaces](https://github.com/pedroknigge/arkgate/blob/main/docs/package-surface.md#experimental-opt-in-surfaces)
(primary kernel guide; import `arkgate/runtime` from the same `arkgate` tarball). Optional
durability non-claim: [production-hardening.md](https://github.com/pedroknigge/arkgate/blob/main/docs/production-hardening.md).
Do **not** treat `packages/runtime/README.md` (deprecated companion leftover) as the kernel guide.
- Call `createStrictArkKernel` (or an admission sibling: `createArkKernel`, `*FromConfig`) **only**
inside `arkRun.compositionRoots`. Each call is a new instance — no process-wide singleton.
inside `arkRun.kernelRoots` (`compositionRoots` is a legacy alias — still valid). Each call is a new instance — no process-wide singleton.
- Keep Domain-role layers kernel-free (`ARKRUN_KERNEL_IN_DOMAIN`).

@@ -162,3 +164,3 @@ - Resolve managed types from the kernel; do not construct admitted types with `new`

- **Result:** one-line outcome
- **Planes:** **`[ArkRun]`** residual (or `n/a` if extra absent) — do not mix with `[Layer]` / `[ArkRules]`
- **Planes:** **`[ArkRun]`** residual (or `n/a` if extra absent) — do not mix with `[Layer]` / `[ArkRules]` / `[ArkOrder]`
- **Compass:** `n/a` (runtime skill; static residual → explore/fix) | top residual if doctor was run

@@ -165,0 +167,0 @@ - **Handoff:** `/ark-…` / CLI / `none`

@@ -72,5 +72,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
ArkGate has **two opt-in planes**. The user chooses which to use; you **always label** findings so they never blur.
ArkGate has **always-on Layers** plus opt-in extras. The user chooses extras; you **always label** findings so they never blur. Absence of an extra is silent and valid. Skills never enforce. ArkOrder is an extra **inside** the `arkgate` package (`arkgate/order`), not a second install.

@@ -81,8 +81,10 @@ | Plane | What it protects | Where it lives | Sensors / tools |

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |
**Rules for every report / answer:**
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** (or a two-column table with those headers).
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** or **`[ArkOrder]`** (or a table with those headers).
2. Never call an import-edge violation an “invariant” or an aggregate sensor a “layer deny.”
3. Absence of `arkRules` is **valid** — do not force ArkRules unless the user wants them or residual inventory clearly wants a pilot.
4. Editing `arkrules/*` or promoting modes is **`/ark-contract`**; fixing code under a structure sensor is **`/ark-fix`** / **`/ark-loop`** (judgment, never invent mechanical-safe).
4. Editing `arkrules/*` or promoting modes is **`/ark-adopt`** / leftover **`/ark-contract`**; fixing code under a structure sensor is leftover **`/ark-fix`** / **`/ark-loop`** or **`/ark-autopilot`** (judgment, never invent mechanical-safe). Extra decisions stay on existing doors. Do not invent `/ark-run` or `/ark-order`.
5. CLI helpers: `ark-check --rules-inventory --json`, doctor JSON `rulesUnderContract`, sensors emit `ARKRULE_*` / `INVARIANT_UNCOVERED` with `evidence.arkruleId`.

@@ -95,2 +97,5 @@

### Think + extras
- Extra decisions stay enforceable on existing doors (`/ark-adopt` session 0, `/ark-place` new file, `/ark-autopilot` grind, `/ark-runtime` one kernel candidate). No new skill name. Do not invent `/ark-run` or `/ark-order`.
## Subagent fan-out (optional, host-dependent)

@@ -132,4 +137,5 @@

judgment auto-apply, codemod engines, or skipping write-gate/CI.
8. **Hand off** — placement `/ark-place`; config `/ark-contract`; bulk debt `/ark-loop` /
`/ark-autopilot`; map-only `/ark-explore`; violations `/ark-fix`.
8. **Hand off** — placement `/ark-place`; first extra `/ark-adopt`; grind `/ark-autopilot`;
map-only `/ark-explore`; leftover config `/ark-contract`; leftover cluster `/ark-fix` /
`/ark-loop`. Extra decisions stay on those doors. Do not invent `/ark-run` or `/ark-order`.
When the user needs action not advice: **STOP — do not continue this skill as complete** — invoke the handoff skill.

@@ -161,3 +167,3 @@

- **Result:** one-line outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`

@@ -164,0 +170,0 @@ - **Done axes:** architecture residual (status/doctor/compass) | feature/ticket residual (outside package). Enforce green ≠ feature done

@@ -119,5 +119,5 @@ ---

## Dual plane — layers + ArkRules (mandatory, except /ark-runtime)
## Dual plane — layers + extras (mandatory, except /ark-runtime)
ArkGate has **two opt-in planes**. The user chooses which to use; you **always label** findings so they never blur.
ArkGate has **always-on Layers** plus opt-in extras. The user chooses extras; you **always label** findings so they never blur. Absence of an extra is silent and valid. Skills never enforce. ArkOrder is an extra **inside** the `arkgate` package (`arkgate/order`), not a second install.

@@ -128,5 +128,7 @@ | Plane | What it protects | Where it lives | Sensors / tools |

| **ArkRules** (intra-layer) | Structure inside a layer + domain invariants as data | `arkRules` map + `arkrules/<ExactLayerName>.json` | structure sensors, invariant coverage, `--rules-inventory`, doctor `rulesUnderContract` |
| **ArkRun** (extra) | Kernel usage + complete declarations | `arkRun` on `ark.config.json` (schema `1.2+`); factory `arkgate/runtime`; **`kernelRoots` preferred**, `compositionRoots` alias | `ARKRUN_*`, doctor `arkRun` (`notAScore`) |
| **ArkOrder** (extra) | Operational pattern (ξ vs s) | `arkOrder` on `ark.config.json` (schema `1.3+`); factory `arkgate/order` | `ARKORDER_*` |
**Rules for every report / answer:**
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** (or a two-column table with those headers).
1. Prefix each finding or next step with **`[Layer]`** or **`[ArkRules]`** or **`[ArkRun]`** or **`[ArkOrder]`** (or a table with those headers).
2. Never call an import-edge violation an “invariant” or an aggregate sensor a “layer deny.”

@@ -136,2 +138,3 @@ 3. Absence of `arkRules` is **valid** — do not force ArkRules unless the user wants them or residual inventory clearly wants a pilot.

5. CLI helpers: `ark-check --rules-inventory --json`, doctor JSON `rulesUnderContract`, sensors emit `ARKRULE_*` / `INVARIANT_UNCOVERED` with `evidence.arkruleId`.
6. Schema `1.3` extras stay off unless already on. Pin teaches `arkgate/runtime` (same tarball), not the deprecated companion. Do not invent `/ark-run` or `/ark-order`.

@@ -143,2 +146,7 @@

### Upgrade + extras
- Schema `1.3` extras (`arkRun` / `arkOrder`) stay off unless already on. Do not turn extras on during upgrade.
- Pin teaches `arkgate/runtime` (same tarball). `@arkgate/runtime` is deprecated. Do not send agents to `packages/runtime/README.md` as the kernel guide.
- After 4.8.2, customized skills may lag — opt-in `--refresh-skills` with consent so the frozen 13 names pick up four-plane deepen. No new skill names.
## Safety contract

@@ -312,3 +320,3 @@

- **Result:** old → new version and managed-upgrade outcome
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** (or `n/a` if unused)
- **Planes:** one-line split of residual **[Layer]** vs **[ArkRules]** vs **[ArkRun]** vs **[ArkOrder]** (or `n/a` if unused)
- **Compass:** top residual lenses | `n/a`

@@ -315,0 +323,0 @@ - **Handoff:** `/ark-…`, CLI action, or `none`

Sorry, the diff of this file is too big to display

Sorry, the diff of this file is too big to display

Sorry, the diff of this file is too big to display

Sorry, the diff of this file is too big to display

Sorry, the diff of this file is too big to display

Sorry, the diff of this file is too big to display

Sorry, the diff of this file is too big to display

Sorry, the diff of this file is too big to display

Sorry, the diff of this file is too big to display