skills.sgit.ai / shipped
S — what is actually shipped, unsoftened

What is actually shipped

Every sibling site publishes this page, and the rule is the same everywhere: this is the honest version, not the encouraging one.

The lifecycle table, unsoftened

Lifecycle stageFor codeFor skills
Version controleverywherein git, no versions of their own
Dependency managementpip / npmnone
Vulnerability managementpartiallyone review, Feb 2026, never repeated
Code reviewstandardno process
CIextensiveno skill is tested
DistributionPyPI, Docker Hubno registry
Documentationstandardthe one stage where skills lead

One green cell out of seven. Full context on the thesis page.

The duplicate

use-sg-playwright exists in two repositories, 43 words apart, and one copy carries an auth claim the service code contradicts. The full exhibit, measured on every build →

Zero declared permissions, zero evals, no registry

The security precedent, and the lapse

In February 2026 — before any of the June theory — the file-transfer skill got a full review trio: an AppSec threat model, a DPO data-flow analysis, and a GRC risk register, all dated 26–27 Feb. That is the “every analogy we have with code, we need with skills” discipline actually practised: a skill treated as software, reviewed as software.

Once. No skill since has had the same treatment. It belongs here as both the precedent that proves the discipline is possible, and the lapse that shows it was not repeated.

Every current skill is a static photograph

The graph projection theory criticises exactly the shape every shipped skill has today: a fixed markdown file rather than a projection of an underlying graph. Publishing that criticism against the estate’s own artefacts is the credible move; resolving it is a research programme, not a sprint.