# 01 — Concepts index: the skills thesis, mapped

25 dedicated briefs, 60,782 words. The core was written in **one four-day burst, 1–4 June 2026** — five briefs on the 1st, three on the 2nd, one on the 3rd, **six on the 4th** — with the identity extension on 18 June and the economy threads running into July. This index maps the clusters so the site does not publish 25 pages where 7 will do.

`[S]` shipped in some form · `[D]` designed, unbuilt · `[E]` economic/strategic position

---

## Cluster 1 — Skills are software packages `[D]` — the thesis

**Canonical:** `…/06/04/…skills-are-software-packages-intent-over-capability.md`

> *"Skills are a software package, that is the best analogy… the same way we have npm and pip for managing dependencies, we need a way to manage skills like that."*

With the full lifecycle demanded: *"vulnerabilities management, documentation, integration, wrappers, code reviews, deployment, CI pipelines, distribution reviews."* And the evolution claim: **skills describe intent, in English, not just capability** — which is why they are the *successor* to code packages, not a variant of them.

**Supporting:** the Tessl brief (a real registry, in real conversation), and the Feb 2026 threat-model trio — AppSec, DPO and GRC each reviewed the file-transfer skill, which is the lifecycle discipline actually happening.

## Cluster 2 — A skill is a graph `[D]` — the architecture

**Canonical:** `…/06/04/…skill-as-projection-of-graph-forking-ecosystem.md` + `…skills-as-graph-capturing-how-business-works.md` (3,244 w) + the 1 Jun semantic-graphs research (2,479 w)

> *"a skill is a projection of a semantic knowledge graph, where **today's skills are static photographs** of what they should be."*

Typed primitives — **principles, concepts, facts, knowledge, actions** — with meaning through connectivity, projection in the context of use, multiple graph types (control-flow, permission maps, identity graphs), and **the forking ecosystem**: *"forking a skill is good; sync back via pull-request-equivalents; edge customisation stays compatible with the top."*

**Deconflict:** "meaning through connectivity" is `graphs.sgit.ai`'s founding concept. This site owns its application to skills; that site owns the idea.

## Cluster 3 — Skills capture how a business works `[E→D]` — the purpose

**Canonical:** `…/06/02/…skills-as-business-knowledge-capture.md` + the finance cascade brief

The claim: skills *"finally give a business a scalable way to capture how it works."* The worked example is the finance team — expenses, invoicing, POs, NDAs, sign-offs — with the sharp observation of **why the existing 20-to-200-page finance document does not work**, and the **multi-level customisation cascade**: the corporate skill → the group version → the cybersecurity version → the ethics-response-team version.

That cascade is the same fractal instinct as the 10%-subset argument in the open-source pack and the subset method in the standards pack. Cross-link all three.

## Cluster 4 — The skill economy `[E]` — who gets paid

**Canonical:** the base-vault brief (2,966 w), the marketplace research (2,734 w), Tessl (2,678 w), opinionated expertise, OWASP expert skills (2,831 w)

The chain: an expert packages *"their opinionated view"* into a **base vault** → it forks into **branded / certified / customised** versions → *"the customised version… is fundamentally what you sell, you maintain it, and that is the one that has the intellectual property element"* → distribution rides aggregators (Tessl as the worked case) → scoring must be *"grounded in cryptographic provenance, evals, and an auditable graph, **rather than gameable popularity**."*

With one dated piece of external validation from a conference, and the OWASP angle: *"you do not have good revenue streams easily, apart from working for companies or doing consulting. That is where skills come into play."* **Shared with `open-source.sgit.ai`** — that site owns the OWASP monetisation thread.

## Cluster 5 — Skills, identity and permissions `[D]` — the security model

**Canonical:** `…/06/04/nhi-2.0/…skill-comes-with-identity.md` + `…/06/18/…skills-as-code-permission-granularity-oauth-not-enough….md`

`05__` in full. A skill must carry the identity and permission set needed to run it; every **unit of execution** — package, code, skill, agent, tool — should declare or have dynamically calculated its permissions; and OAuth fails because it *"grants in absolutes."*

## Cluster 6 — The lifecycle `[E]` — owned elsewhere

The Explorer → Product → Town Planner skill lifecycle, English-to-code as the maturity mechanism, and *"anybody who spends a lot of money on tokens has an engineering problem."* **Owned by `wardley-maps.sgit.ai`.** State in three lines, link out.

## Cluster 7 — The practice `[S]` — what actually exists

The 8 shipped skills and their conventions. `02__` in full. The only cluster that is `[S]`, and the site should lead with it.

---

## The reading order for the site

1. `02__` — what exists (catalogue + authoring conventions)
2. Cluster 1 — the thesis
3. Cluster 5 — identity and permissions (the most consequential design)
4. Cluster 2 — the graph architecture (label as design)
5. Clusters 3–4 — purpose and economy
6. Cluster 6 — three lines and a link

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
