# iii-directory

> Engine introspection, workers registry proxy, filesystem-backed skills, system prompts, and agent profiles, plus lexical function search with a conditional pre-generate hint.

| field | value |
|-------|-------|
| version | 1.2.15 |
| type | binary |
| license | Apache-2.0 |
| repo | https://github.com/iii-hq/workers |
| supported_targets | aarch64-apple-darwin, x86_64-pc-windows-msvc, aarch64-pc-windows-msvc, x86_64-unknown-linux-gnu, aarch64-unknown-linux-gnu, x86_64-unknown-linux-musl, armv7-unknown-linux-gnueabihf |
| author | iii |

## installation

```sh
iii trigger compose::add worker=iii-directory@1.2.15
```

## dependencies

- `configuration` @ `0.x`

## readme

# iii-directory

Workers registry HTTP proxy and filesystem-backed skills, system prompts,
and agent profiles for the [iii engine](https://github.com/iii-hq/iii). Every
public function sits under a single `directory::*` namespace, split
into five surfaces (all MCP-agnostic):

| Surface | What clients see | When to use it |
|---|---|---|
| **Skills** (`directory::skills::*`) | Enriched listing via `directory::skills::list` (`{ id, title, type, function_id, disable_model_invocation, description, bytes, modified_at }` per row), a single-skill reader `directory::skills::get { id }` returning `{ id, title, type, function_id, disable_model_invocation, path, body, modified_at }` (the full body instead of the list teaser), and `directory::skills::index` which renders a short per-worker overview document (one `## <title>` + first paragraph + `read more` link per `type: index` skill). Authored by `create`, edited by `update`, removed by `delete`. `title` prefers the YAML frontmatter `title:` (then `name:`) over the body H1; `type` is lifted from frontmatter `type:` (e.g. `index`, `how-to`, `reference`) and serialised as `null` when absent. System-installed agent skills under the read-only `agents_skills_folder` are served too (see [On-disk layout](#on-disk-layout)). | Orientation: "when and why to use my worker's tools" |
| **System prompts** (`directory::system-prompts::*`) | Identity prompts listed by `list`, read by `get`, authored by `create`, edited by `update`, and removed by `delete`. The list response keeps its `prompts` field name. Stored under any `system-prompts/` path segment; `create` writes `<skills_folder>/system-prompts/<name>.md`. | What the chat's system-prompt picker offers as an identity prompt (enrich or replace) |
| **Agent Profiles** (`directory::agents::*`) | Reusable session identities whose file body is the system prompt, with display `name`, emoji `logo`, preloaded `skills` and `functions` (bodies and contracts the harness freezes into every session's prompt), and optional `model` + `reasoning_effort` in required frontmatter. `list` rows carry the display/configuration metadata and `get` adds `system_prompt` and `unknown_skills`. Stored as direct `<agents_folder>/<id>.md` files. See [Agent profile storage](../docs/architecture/agent-profile-storage.md). | A named identity selected with `harness::send { options: { agent } }` |
| **Search** (`directory::search_functions`) | One to six external capabilities → compact function-id candidates (installed, plus registry workers under `installable`), with a conditional pre-generate hint pointing agents at it. | "Which functions do I call for this task?" |
| **Registry** (`directory::registry::*`) | HTTP proxy over `api.workers.iii.dev` with `workers::{list,info}`. Rows share the core `name` / `description` / `version` fields with the engine's `engine::workers::list` and add publication metadata (`type`, `config`, `supported_targets`, `total_downloads`, `dependencies`, optional `image`). `workers::list` is cursor-paginated with a server-authored page size. | "What's published in the public registry?" |

Engine introspection (functions / triggers / registered triggers /
workers) is served by the engine natively at
`engine::functions::*`, `engine::triggers::*`,
`engine::registered-triggers::*`, and `engine::workers::*`. Call the
engine ids directly. One wrapper survives for callers that can only
reach the `directory::` namespace: `directory::engine::functions::info`
proxies a single function's schema (see its row below).

This worker is where an agent's identity text LIVES. `skills/system-prompts/iii-runtime.md`
ships here and is the one copy of "how to work against a live iii engine" —
`claude-code` and `pi` fetch it with `directory::system-prompts::get
name=iii-runtime` (plus `directory::skills::index`) for both their headless
turns and their console terminals, rather than compiling a prompt of their own.
Edit that file and every agent reads the edit; no worker release involved.

Skills and system prompts are sourced from `skills_folder`; agent profiles
use the dedicated `agents_folder`. Writes are the
**`directory::skills::download*`** functions, which pull markdown from either
the [workers registry](https://workers.iii.dev) or a GitHub repo and route each
supported family to its configured root, plus the
per-kind single-file editors — `directory::skills::{create,update,delete}`,
`directory::system-prompts::{create,update,delete}` and
`directory::agents::{create,update,delete}`. Once downloaded, files
belong to the developer — edit them however you want, in the editor of
your choice: a change made directly on disk fires the matching
`on-change` with `op: "external"` (see [Custom trigger
types](#custom-trigger-types)).

`directory::registry::workers::*` and the engine's `engine::workers::*`
share the core `name` / `description` / `version` fields so a parser
that touches only those keys works against either surface; the
registry view also surfaces publication metadata (`type`, `config`,
`supported_targets`, `total_downloads`, `dependencies`, optional
`image`) and the engine view adds runtime / connection state.

## Table of contents

1. [Install](#install)
2. [Configuration](#configuration)
3. [Quickstart: download some skills](#quickstart-download-some-skills)
4. [On-disk layout](#on-disk-layout)
5. [Skill ids](#skill-ids)
6. [Functions](#functions)
7. [Function search & pre-generate hint](#function-search--pre-generate-hint)
8. [Custom trigger types](#custom-trigger-types)
9. [Local development & testing](#local-development--testing)
10. [Migration from skills v0.2.x](#migration-from-skills-v02x)

---

## Install

```bash
iii trigger compose::add worker=iii-directory
```

`iii trigger compose::add` resolves the worker and its dependencies, writes
exact declarations to `worker-compose.yaml`, and reconciles the Compose project.

For container settings, fetch `compose::schema { function_id: "compose::add" }` and use
its `workers` list. For example, after registering the completion wake described below:

```json
{
  "operation_id": "<operation-id>",
  "workers": [
    "state",
    {
      "worker": "iii-directory",
      "start_after": ["state"],
      "config_override": { "registry_search": true }
    }
  ]
}
```

The list can mix worker names and objects. Each object accepts `scripts`, `config_name`,
`config_override`, `working_dir`, `environment`, `env_file`, `startup_timeout`, and
package `version` as well as `worker` and `start_after`. `scripts.run` is for local
workers only. Supplied maps replace the whole field; omitted settings are retained.

The returned `install.payload` from function search is a minimal shorthand. If the worker
needs settings, replace its singular `worker` with an object in `workers`.
Register a one-shot `compose-operation` wake before calling `compose::add`, use the same
`operation_id` in both calls, and wait for terminal success before using the new functions.
An acceptance response does not mean the worker is ready. See the
[container settings example and completion flow](https://github.com/iii-hq/workers/blob/main/harness/README.md#adding-workers-with-container-settings)
for field behavior, path resolution, and recovery.

---

## Skills

Install the `iii-directory` agent skill for Claude Code, Cursor, and 30+ other agents:

```bash
npx skills add iii-hq/workers --skill iii-directory
```

Browse or install every worker skill at once:

```bash
npx skills add iii-hq/workers --list
npx skills add iii-hq/workers --all
```

---

## Configuration

Runtime settings live in the **`configuration` worker** under id
**`iii-directory`** (the same pattern `database` and `storage` use). At boot
the worker registers its JSON Schema, reads the live value via
`configuration::get` (the configuration worker env-expands `${VAR}`), and binds
a `configuration` trigger so it re-fetches on change.

Persisted values default to `./data/configuration/iii-directory.yaml` (fs
adapter). Edit that file directly, call `configuration::set id=iii-directory`,
or use the Console's global Settings modal — all three propagate without a redeploy.

### Fields

```yaml
# TOPOLOGY — changing any of these requires a worker restart.
skills_folder: skills                  # under III_COMPOSE_DIR, or the process cwd standalone
local_skills_folder: skills/iii        # project-scoped overrides (whole-namespace local-wins)
agents_folder: agents                  # direct <id>.md agent profiles
agents_skills_folder: .agents/skills   # READ-ONLY agent skills, with the same relative-path base
auto_download: true                   # subscribe to worker-add + run the boot reconcile

# TUNABLE — hot-reload live on `configuration:updated`.
registry_url: https://api.workers.iii.dev   # workers registry base URL
download_timeout_ms: 60000                   # per git-clone / HTTP request timeout (ms)
registry_cache_ttl_ms: 60000                 # in-process TTL for registry::workers::* responses
filter_unregistered: true                    # hide skills whose namespace isn't an installed worker
inject_hint: false                           # bind the directory::pre-generate search-hint hook (off: the harness identity prompt already teaches directory-first discovery)
hint_min_workers: 2                          # minimum surface width before the hint fires (0 = always)
registry_search: true                        # include installable registry workers in every search
```

The writable `skills_folder` and `agents_folder` roots are created when needed.

### Zero-config default + seed

With no seed and no stored value the worker uses built-in defaults. Relative
folder paths use `III_COMPOSE_DIR` when set and the process current directory
otherwise (`skills_folder: skills`, `agents_folder: agents`,
`registry_url: https://api.workers.iii.dev`).
Pass `--config <path>` to supply a YAML seed: when present and no value is
stored yet, its contents become `initial_value` on `configuration::register`
(see [`config.yaml.example`](config.yaml.example)). Engine-managed deployments
inline the config under the worker entry; the engine delivers it via `--config`.

### Hot reload

On `configuration::set` (or an external edit to the persisted file), the worker
re-fetches the authoritative value. Tunable changes apply in place and the
registry caches are cleared so a repointed `registry_url` takes effect
immediately. Topology changes (`skills_folder` / `local_skills_folder` /
`agents_folder` / `agents_skills_folder` / `auto_download`) are refused with a "restart
required" log; the previous configuration is kept until the worker restarts.

The writable `skills_folder`, `local_skills_folder`, and `agents_folder` are
watch roots, and the watcher creates each one at boot if it is missing.
Direct `<id>.md` edits under `agents_folder` fire
`directory::agents::on-change` with `op: "external"`; nested files are ignored.
`agents_skills_folder` is a watch root too,
but only when it already exists — the worker never creates (or writes)
anything under it. Install your first agents skill while the worker is
running and that root stays unwatched until the next restart: reads still
serve it, since every read re-scans disk, but the live `external` doorbell
is missing until then. `local_skills_folder` defaults to `skills/iii` under
`III_COMPOSE_DIR`, or under the process current directory when the worker runs
standalone. An empty local root shadows nothing. Because the roots are
restart-required, the watch
roots are fixed for the process lifetime.

---

## Quickstart: download some skills

```bash
# Pull a specific worker's directory bundle at a fixed semver from
# the registry. Files land under `<skills_folder>/agent-memory/`.
iii trigger --function-id=directory::skills::download \
  --payload='{"worker": "agent-memory", "version": "1.2.3"}'

# Same, but always fetch whatever's tagged `latest` (also the default
# when neither version nor tag is given).
iii trigger --function-id=directory::skills::download \
  --payload='{"worker": "agent-memory"}'

# Pull a single subfolder out of a public GitHub repo via
# `git clone --depth 1 --branch main`. Files land under
# `<skills_folder>/frontend-design/`. The `branch` field defaults to
# `main`; pass `"master"` for older repos that haven't migrated.
iii trigger --function-id=directory::skills::download \
  --payload='{
    "repo": "https://github.com/anthropics/skills",
    "skill": "frontend-design"
  }'
```

The response is
`{ namespace, skills_written, system_prompts_written, agents_written, source }`.
The three `*_written` fields list the files materialised in this run.
Registry entries shaped exactly as `agents/<id>.md` land in
`<agents_folder>/<id>.md`; repo downloads do not install agent profiles.

After every successful download the worker fires the
`directory::skills::on-change`, `directory::system-prompts::on-change`,
and/or `directory::agents::on-change` trigger types so that
subscribers like the [`mcp`](https://github.com/iii-hq/workers/tree/main/mcp) worker can
forward MCP `notifications/list_changed` to their clients.

---

## On-disk layout

The worker uses separate roots for directory content and agent profiles:

```text
skills_folder/
  <namespace>/                 # one folder per `directory::skills::download` namespace
    index.md                   # → iii://<namespace>/index
    contacts.md                # → iii://<namespace>/contacts
    emails/send-email.md       # → iii://<namespace>/emails/send-email
    system-prompts/            # ← magic marker for system prompts
      reviewer.md              # ← identity prompt (needs YAML frontmatter)
  system-prompts/              # ← where system-prompts::create writes
    pirate.md

agents_folder/                 # ← where agents::create writes
  release-captain.md           # ← agent profile (needs YAML frontmatter)
  frontend-design.md           # ← `extends: iii` builds on the bundled base
```

Two base agent profiles ship inside the worker binary: `iii` (the harness
default identity, verbatim) and `iii-minimal` (the minimal directory-first
identity — the same text as the bundled system prompt of that name). Each is
always listed (`builtin: true`), a local `agents_folder/<id>.md` shadows it,
`update` on it copy-on-writes that local file, and deleting the file falls
back to the bundled copy. No file is ever seeded on disk.

A second, READ-ONLY root — `agents_skills_folder` (default `.agents/skills`
under the same Compose or standalone base) — serves agent skills. It is
scanned **shallowly**: only `<skill-dir>/SKILL.md` becomes an entry
(id `<skill-dir>/index`, displayed as `<skill-dir>`); a skill's
`reference/`, `scripts/`, or other support payload is never listed. A
missing directory is silently empty. These skills bypass
`filter_unregistered` (their namespaces are skills, not workers), stay
out of `directory::skills::index` (a per-WORKER surface), and are
refused by `update`/`delete` — edit them with their owning tool, or
copy one into `skills_folder` on disk to fork it. Precedence is
`local_skills_folder` > `skills_folder` > `agents_skills_folder`,
namespace-wise: a top-level namespace directory in a higher root
shadows the same namespace below.

A few rules:

- **Skill ids** are the relative path under `skills_folder` with `.md`
  stripped. Each segment must satisfy `[a-z0-9_-]{1,64}`.
- **Skill frontmatter is optional.** When present, the reader recognises
  `title:` (preferred title), `name:` (title fallback), `type:` (free-form
  classifier), `function_id:` (canonical bus function id surfaced by `list`
  and `get`), `description:` (preferred `list` teaser), and
  `disable-model-invocation:` (boolean, default `false`, surfaced as
  `disable_model_invocation` by both responses). The body H1 and first
  paragraph are the title and list-description fallbacks, respectively.
  Disabled skills remain visible to ordinary directory clients; model
  index consumers decide whether to filter them. Any other YAML keys are ignored.
- **System prompts** live under any `*/system-prompts/*.md` path, with
  YAML frontmatter (`description` required, `name` optional). A path carrying
  both a `prompts` and a `system-prompts` segment is a system prompt because
  `system-prompts` is classified first. Other paths containing a `prompts`
  segment are ignored by scans and downloads.
- **What a system prompt can do, by design.** The console's chat picker
  can send a selected system prompt with
  `system_prompt_strategy: "override"`, which replaces the harness's
  built-in identity prompt with that file's body verbatim. Files reach
  `system-prompts/` either by local authoring or via
  `directory::skills::download` from a git repo or the registry, so a
  downloaded bundle can supply one. This is an accepted property, not a
  hole: it takes a deliberate selection in the UI, the same UI already
  accepts arbitrary typed text, and the operator owns `skills_folder`.
  Worth knowing before you point `skills_folder` at a directory other
  people can write to.
- **Agent profiles** are direct `<agents_folder>/<id>.md` files (unrelated to
  the read-only `agents_skills_folder` above, which holds external tools'
  *skills*). Nested profiles and the former
  `<skills_folder>/**/agents/*.md` layout are ignored. Frontmatter is required
  and must declare a non-empty `name`
  (the display name — the id is always the file stem); `description` may
  be empty, `logo` is emoji-only (≤16 bytes, no path characters),
  `skills:` filters the skill index (absent/empty = every skill), and
  `model:` names a model id for sessions using this profile (absent = the
  send decides), and optional `reasoning_effort:` names its provider-native
  effort. Both are stored verbatim and resolved against the live model
  catalog where they are used. The body is the
  system prompt, verbatim, and may be empty — a profile with no prompt of
  its own contributes only its parent chain (if any) and its non-prompt
  settings. Unknown `skills` ids are
  warnings surfaced by `get`, never load failures.
- **Agent profiles declare preloaded functions.** `functions:` lists engine
  function ids (`coder::tree`, `coder::search`, …) the profile uses
  routinely. The harness resolves their contracts once, when a session
  starts as this profile, and freezes them into the system prompt as a
  `<preloaded_functions>` block (id, description, compacted request schema), so
  the model calls them on the first step instead of spending a
  `directory::search_functions` + `engine::functions::info` round-trip per
  session; everything else still goes through discovery. Ids are stored
  verbatim (non-empty, no whitespace; duplicates collapse, order kept);
  `get` reports ids the engine does not currently know in
  `unknown_functions` (a warning — the harness renders them as unavailable),
  `list` carries `function_count`. `directory::agents::functions::add` /
  `::remove { id, functions }` edit only that frontmatter field — the rest
  of the file stays byte-identical — and fan out `on-change` as an update.
  The console's profile editor picks them from the live registry with the
  same keyboard-first search + Selected/Available lists as skills.
- **Agent profiles inherit.** `extends: <id>` names one parent profile
  (chains allowed, at most 8 hops). The resolved system prompt served by
  `get` is the parent's resolved prompt followed by a blank line and this
  file's body — a blank body contributes nothing, so a profile with no
  prompt of its own serves its parent chain unchanged; `model` and
  `reasoning_effort` fall back to the nearest ancestor that sets them when
  omitted, while `skills` and `functions` inherit ADDITIVELY (the union of
  the chain's lists, root first, no duplicates — a child adds to what its
  parents allow / preload, it cannot remove); `name`, `description`, `logo`,
  `icon` and `color` are always the profile's own. A chain that does not resolve
  (unknown parent, loop, too deep) is reported by `list`/`get` as
  `inheritance_error` (`D415` text) while the profile still serves its own
  file (so the editor can fix it); the harness refuses to run it.
- Under a skills root, files outside `prompts/`, `system-prompts/`, and
  reserved `agents/` segments are skills.

The download function namespaces by source:

| Source | Destination |
|---|---|
| `repo=URL skill=NAME branch?=main` | `<skills_folder>/<NAME>/...` |
| `worker=NAME version=…` | Skills/prompts under `<skills_folder>/<NAME>/...`; exact `agents/<id>.md` entries under `<agents_folder>/<id>.md` |
| `worker=NAME tag=…` (default `tag=latest`) | Same routing as the version form |

Re-pulling the same source overwrites files **file-by-file** —
existing siblings outside the response set are preserved (so
hand-edited additions survive a re-pull).

---

## Skill ids

Skills are addressed by their relative path under `skills_folder` with
`.md` stripped — e.g. `<skills_folder>/agent-memory/observe.md` →
id `"agent-memory/observe"`. The same string is what
`directory::skills::list` returns and what `directory::skills::get`
expects in `{ "id": ... }`. The legacy `iii://{id}` link form is still
accepted on `get` (the prefix is auto-stripped), but the worker no
longer parses any other `iii://` URI shape — bodies are read solely by
id, and the auto-rendered tree-shaped index that previous releases
served at `iii://directory/skills` is gone. Consumers that want a
tree-shaped picker iterate `list` rows themselves and indent by
`id.matches('/').count()`.

---

## Functions

Functions sit under `directory::*`. All registrations are
namespace-clean; this worker is intentionally agnostic to MCP and any
other adapter.

### `directory::skills::*` (filesystem reader + editor)

| Function ID | Description |
|---|---|
| `directory::skills::download` | Download directory content. Flexible alias accepting either source set: `{repo, skill, branch?}` (defaults `branch=main`) or `{worker, version?\|tag?}` (defaults `tag=latest`). Prefer the two explicit forms below so the source is unambiguous. |
| `directory::skills::download_from_repo` | Repo-only form: `{repo, skill, branch?}`. Copies one skill folder out of a GitHub repo; paths under `prompts/` and `agents/` are ignored. |
| `directory::skills::download_from_registry` | Registry-only form: `{worker, version?\|tag?}`. Installs a published worker's bundle from `api.workers.iii.dev`, routing exact `agents/<id>.md` entries to `agents_folder`. |
| `directory::skills::list` | Enriched listing of every fs-backed skill: `{ id, title, type, function_id, disable_model_invocation, description, bytes, modified_at }` per row. `title` prefers the YAML frontmatter `title:` over the body H1, `type` is lifted from frontmatter `type:` (`null` when absent), `function_id` identifies the documented bus function when present, and `description` is the frontmatter description or first body paragraph — so consumers can render a picker without a follow-up `get` per row. |
| `directory::skills::get` | Fetch one skill by id. Returns `{ id, title, type, function_id, disable_model_invocation, path, body, modified_at }`. It shares the list row's identity, classification, function, and invocation metadata, but returns the raw markdown `body` and absolute on-disk `path` instead of the teaser and byte count; there is no `description` field. The path's parent directory is the skill's base directory, where payload like `scripts/` and `reference/` lives, and is meaningful only to callers on this worker's machine. Accepts a bare id or the same id prefixed with `iii://`. Pass `raw: true` to additionally get the FULL on-disk file (frontmatter included) as `raw` — the round-trip form `update` takes. |
| `directory::skills::update` | Overwrite one EXISTING skill file with new full-file content: `{ id, content }` where `content` is the edited `raw` from `get { raw: true }`. Validated against the read invariants (size cap, non-empty body after frontmatter); atomic write; fans out `directory::skills::on-change` with `op: "update"`. Never creates files (use `create`). Refuses read-only system-installed skills under `agents_skills_folder` (`D116`). |
| `directory::skills::create` | Create a NEW skill file at `<skills_folder>/<id>.md` from full-file content: `{ id, content }`. Frontmatter is optional (same rules as `update`: size cap, non-empty body). Refuses an `id` that already resolves in the visible set — including the `<id>` → `<id>/index` overview alias and system-installed agents skills — or a target path that already exists on disk (`D114`); an `id` in a namespace reserved by a system-installed agents skill (`D115`); and, while `filter_unregistered` is on, an `id` the visibility filter would immediately hide (`D115`). Atomic write; fans out `directory::skills::on-change` with `op: "create"`. Returns the same shape as `update`. |
| `directory::skills::delete` | Permanently remove one EXISTING skill file by `{ id }` (same id forms as `get`). Resolves against the same visible set as `list`/`get`, refuses read-only system-installed skills under `agents_skills_folder` (`D116`), removes the file plus any parent directories left empty (so a deleted namespace can't keep shadowing a lower-precedence root), and fans out `directory::skills::on-change` with `op: "delete"`. Returns `{ id }` (the resolved on-disk id). |
| `directory::skills::index` | Render one short markdown entry per installed worker (skills with frontmatter `type: index`). Returns `{ body, workers_count }` where `body` is a ready-to-paste page: `# Skills index`, then one `## <worker title>` heading + the worker's first overview paragraph + a `Read iii://<ns>/index` pointer the agent can follow with `directory::skills::get`. Token-light by design; use `directory::skills::list` for per-skill rows. |

### `directory::system-prompts::*` (filesystem reader + editor)

| Function ID | Description |
|---|---|
| `directory::system-prompts::list` | Metadata-only listing of every fs-backed system prompt. |
| `directory::system-prompts::get` | Fetch one system prompt's body + `{name, description, modified_at}`. Plain shape, no envelope. Pass `raw: true` to additionally get the FULL on-disk file (frontmatter included) as `raw`. |
| `directory::system-prompts::update` | Overwrite one EXISTING system prompt file with new full-file content: `{ name, content }`. The frontmatter must keep a non-empty `description` (and a valid `name` when declared) — the same rules the scanner enforces. Atomic write; fans out `directory::system-prompts::on-change` with `op: "update"`. Returns the system prompt's effective name after the write. |
| `directory::system-prompts::create` | Create a NEW system prompt file at `<skills_folder>/system-prompts/<name>.md` from full-file content: `{ name, content }`, where `content` is the FULL file including frontmatter. The frontmatter must carry a non-empty `description` (and a `name` matching the request, when declared) — the same rules `update` enforces. Refuses a `name` that already exists anywhere in the merged system-prompt scan, and a target path that already exists on disk even if the scanner would skip it. Atomic write; fans out `directory::system-prompts::on-change` with `op: "create"`. Returns `{ name, description, bytes, modified_at }`. |
| `directory::system-prompts::delete` | Permanently remove one EXISTING system prompt file by `{ name }`. Resolves against the same merged scan as `list`/`get`, fans out `directory::system-prompts::on-change` with `op: "delete"`, and returns `{ name }`. |

### Agent Profiles — `directory::agents::*` (filesystem reader + editor)

| Function ID | Description |
|---|---|
| `directory::agents::list` | Metadata-only listing of every agent profile — fs-backed plus the bundled `iii` / `iii-minimal` bases (`builtin: true` until a local file shadows one): `{ id, name, description, logo, skill_count, model, reasoning_effort, icon, color, extends, modified_at }` per row, `skill_count`/`model`/`reasoning_effort` resolved through `extends` (`skill_count: null` = every skill; `model: null` = the send decides). A row whose chain does not resolve carries `inheritance_error`. |
| `directory::agents::get` | Fetch one agent profile by `{ id }`: the RESOLVED `system_prompt` (each ancestor's body root-first, then this file's body), `skills` + `unknown_skills` (filter entries matching no visible skill — warnings), `model` (`null` = the send decides), provider-native `reasoning_effort`, display `icon`/`color`, `extends`, `builtin`, `modified_at`, and `inheritance_error` when the chain does not resolve (own file served meanwhile). Pass `raw: true` to additionally get this profile's FULL on-disk file as `raw`. |
| `directory::agents::update` | Overwrite one EXISTING agent profile file with new full-file content: `{ id, content }`. Same rules the scanner enforces (required frontmatter with non-empty `name`, emoji-only `logo`; the body — the system prompt — may be empty); the id stays the file stem. Updating a bundled profile creates the local file that shadows it. Atomic write; fans out `directory::agents::on-change` with `op: "update"`. |
| `directory::agents::create` | Create a NEW agent profile at `<agents_folder>/<id>.md` from full-file content: `{ id, content }`. Refuses an `id` that already exists in the configured agent-profile root, and a target path that already exists on disk even if the scanner would skip it; creating a bundled id shadows the bundled copy. Atomic write; fans out `directory::agents::on-change` with `op: "create"`. Returns `{ id, name, description, logo, bytes, modified_at }`. |
| `directory::agents::delete` | Permanently remove one EXISTING agent profile file by `{ id }`. Resolves against the same configured root as `list`/`get`, fans out `directory::agents::on-change` with `op: "delete"`, and returns `{ id }`. Deleting the local shadow of a bundled profile falls back to the bundled copy; a bundled profile with no local file has nothing to delete (`D414`). Sessions already using the profile are unaffected; profiles extending it stop resolving until fixed. |
| `directory::agents::functions::add` | `{ id, functions: ["coder::tree", …] }` — append engine function ids to one EXISTING profile's OWN `functions:` list (its *preloaded* functions: the contracts the harness pre-loads into the system prompt of every new session running as the profile). Ids already present are kept once; only that frontmatter field is rewritten (block style), every other byte of the file is untouched; writes atomically, copy-on-writes a bundled profile's shadow, fans out `on-change` with `op: "update"`. Returns `{ id, functions, added, unchanged?, bytes, modified_at }` — `unchanged: true` means nothing was written. `D416` for a request with no valid ids (entries must be non-empty and whitespace-free). |
| `directory::agents::functions::remove` | `{ id, functions }` — drop ids from one EXISTING profile's OWN `functions:` list (absent ids are ignored; the field disappears when the list empties). Same write semantics and `D416`; returns `{ id, functions, removed, unchanged?, bytes, modified_at }`. Neither verb touches ids inherited through `extends` — those stay in the resolved union and are removed on the parent that declares them. |

### Engine introspection (native, plus one wrapper)

Engine introspection is served natively; call these ids directly — every
one takes the same filters (`prefix`, `search`, `worker`,
`include_internal` where applicable). One wrapper is kept for callers
whose policy only admits the `directory::` namespace:

| Function ID | Description |
|---|---|
| `directory::engine::functions::info` | Thin proxy to `engine::functions::info` for a single `function_id`: request/response schemas, metadata, and registered triggers. The one `directory::engine::*` helper that still exists — reach for it only when you cannot call `engine::*` directly. |

The native ids:

| Function ID | Description |
|---|---|
| `engine::functions::list` | List functions registered with the engine. |
| `engine::functions::info` | Single-function detail: schemas, owning worker. |
| `engine::triggers::list` | List trigger TYPES (the providers, e.g. `http`, `cron`). |
| `engine::triggers::info` | Single trigger-type detail: configuration schema, return schema. |
| `engine::registered-triggers::list` | List trigger INSTANCES (subscriber rows). |
| `engine::registered-triggers::info` | Single registered-trigger detail. |
| `engine::workers::list` | List workers with an open engine WS connection. Daemon-managed providers (`http`, `cron`, `state`) won't appear — call `worker::list` from the supervisor to see those. |
| `engine::workers::info` | One worker's detail by `name`. |

### `directory::registry::*` (workers registry HTTP proxy)

| Function ID | Description |
|---|---|
| `directory::registry::workers::list` | Browse / search published workers in `api.workers.iii.dev`. Optional free-text `search` (matched fuzzy by `pg_trgm`) and opaque `cursor` for pagination; page size is server-authored. Response is `{ workers: [...], pagination: { next_cursor, has_more, page_size } }`. Shares the core `name` / `description` / `version` fields with the engine's `engine::workers::list`. |
| `directory::registry::workers::info` | Pre-install card for one worker. Fans out two parallel registry calls — `GET /w/{slug}` for the worker envelope (publication metadata + readme + functions + triggers) and `GET /w/{slug}/skills` for the skills tree — and merges them into `{ worker, api_reference, skills_tree, readme? }`. The card keeps public function/trigger names and descriptions only: request/response schemas, metadata, internal and search-excluded functions are dropped (browser's schemas alone ran 65 KB; the contract is `engine::functions::info` after installing), and `readme` (10–25 KB) is included only with `readme: true`. The full record stays cached in-process for `directory::search_functions`. Input still accepts `version:` (semver) or `tag:` (e.g. `latest`); both go on the wire as `?version=…`. |

Both `directory::registry::*` responses are cached in-process for
`registry_cache_ttl_ms` (default 60s).

There is **no** `directory::skills::register` — see
[Migration](#migration-from-skills-v02x) below.

---

## Function search & pre-generate hint

One-shot function search over the live engine catalog (hybrid by default:
BM25 fused with the local MiniLM model, reranked; `function_search_mode:
lexical` for BM25 only), absorbed from the former `discovery` worker. It returns only compact `{ function_id,
description }` candidates, grouped by worker in rank order. The model chooses
the candidates it needs, then fetches their contracts in one
`engine::functions::info { function_ids: [...] }` call instead of walking the
catalog with `engine::functions::list`.

| Function | Kind | What it does |
|---|---|---|
| `directory::search_functions` | public | `{ capabilities }` → `{ guidance, workers[], installable[]?, latency_ms }`: hybrid rank over the live engine catalog in batches of six capabilities (12 candidates per batch across at most max(6, 2 × capabilities) workers, up to 3 batches) plus matching NOT-installed registry workers under `installable`. `capabilities` is a required list of non-empty unmet external capability searches (one to six is the norm); entries past the 18th are not searched and are named in `guidance`. Requests to summarize provided text/content are ignored. |
| `directory::pre-generate` | internal hook | Injects the conditional search hint into a harness generation (at most once per turn). |
| `directory::on-functions-change` | internal | Refreshes the search catalog on the engine's functions-available push. |
| `directory::hint-preview` | internal | The exact hint text per exposure mode, for the configuration UI. |

Ranking pipeline:

1. **Corpus**: the live engine catalog (boot snapshot + push refresh),
   slimmed to name + first description sentence + argument names. `engine::`
   ids, functions published with `metadata.internal`, and the search itself
   never participate — the worker's own public `directory::*` functions are
   searchable like any other capability.
2. **Scoring**: Okapi BM25 (k1 1.2, b 0.75) with the function name indexed at
   3× weight, camelCase segmentation (`presignUrl` → presign + url), a
   22-word grammatical stoplist, conservative plural folding, JSON-key
   stripping from capability text, and a two-distinct-terms minimum match.
3. **Capability queries**: each `capabilities` entry is ranked independently
   against its own leader and is authoritative. Include every currently unmet
   external capability once in the same call. Write every capability in
   English, translating non-English requests while preserving proper names,
   URLs, and function ids. Requests to summarize provided text or content are
   ignored. Results merge round-robin so every capability gets a candidate
   before any gets a rider.
4. **Pruning**: coverage-aware function floor (≥50% of the leader AND full
   term coverage or ≥85% score) drops same-worker family riders; a
   namespace-level floor (40% of the leader) drops trailing workers.
5. **Registry search** (`registry_search`, default on): every call also
   consults the private workers registry in-process with the same capability
   queries plus informative-term retries (all concurrent; every listed worker
   is a candidate — the registry is team-authored). Candidates merge
   round-robin across search variants; their API references are pooled and
   ranked per capability with BM25 fused with the MiniLM dense lane (same
   0.30 admission floor as the installed catalog), so a capability sharing no
   vocabulary with a contract ("retrieve web news articles" → `web::fetch`)
   still surfaces. Returns up to 2 workers / 6 candidates per batch of six
   capabilities (so up to 6 workers / 18 candidates across three batches; a
   worker two batches both surface keeps one entry with its functions merged)
   that WOULD match if installed, with `compose::add` guidance.
6. **Session memory** (keyed by caller-supplied OTel baggage, fail-open):
   repeat queries omit candidates already delivered.

The pre-generate hook appends one `<discovery_assist>` block pointing the
model at `search_functions`, telling it to derive capabilities from the goal
and current execution state and to batch selected ids through
`engine::functions::info` — at most once per turn, and only when every gate
clears: the function is callable in the surface, no search result is in the
current task window yet, the surface spans at least `hint_min_workers` distinct
workers, the current task (from the latest user message) has no real function
results yet, and it does not already name a callable function id. Measured on
26 pre-existing e2e scenarios: an unconditional hint *induces* redundant
discovery on guided tasks (up to +110% tokens). The hook ships OFF by default
(`inject_hint: false`): the harness identity prompt already teaches
`directory::search_functions` as the default discovery path, so the hint is
for deployments running a custom identity prompt without that doctrine. The
hook's transcript annotations (`origin.directory`) carry only coarse
outcome/reason and counts.

Knobs (`inject_hint`, `hint_min_workers`, `registry_search`) live in the
`iii-directory` configuration entry and hot-apply — see Configuration.

## Custom trigger types

| Trigger type | Fires when | Payload to subscribers |
|---|---|---|
| `directory::skills::on-change` | After a `directory::skills::download` that wrote at least one skill markdown file, a `directory::skills::update`, `create`, or `delete`, or external (file pasted/edited/deleted directly on disk — including under `agents_skills_folder`) | download: `{ "op": "download", "namespace": "<ns>", "source": "repo" \| "registry" }`; update/create/delete: `{ "op": "<operation>", "namespace": "<ns>", "id": "<id>" }`; external (file pasted/edited/deleted directly on disk): `{ "op": "external" }` |
| `directory::system-prompts::on-change` | After a `directory::skills::download` that wrote at least one system prompt markdown file, a `directory::system-prompts::update`, `create`, `delete`, or external file change | download: `{ "op": "download", "namespace": "<ns>", "source": "repo" \| "registry" }`; update/create/delete: `{ "op": "<operation>", "name": "<name>" }`; external: `{ "op": "external" }` |
| `directory::agents::on-change` | After a `directory::skills::download` that wrote at least one agent profile, a `directory::agents::update`, `create`, `delete`, or external file change | download: `{ "op": "download", "namespace": "<ns>", "source": "repo" \| "registry" }`; update/create/delete: `{ "op": "<operation>", "name": "<id>" }`; external: `{ "op": "external" }` |

Dispatches are fire-and-forget (Void), so the write path doesn't
block on downstream latency.

The `external` op comes from a filesystem watch over `skills_folder`,
`local_skills_folder`, and (when it already exists) the read-only
`agents_skills_folder`. It is a doorbell, not a ledger: every read re-scans
disk, so a missed event costs a stale open view until the next call, never
data. A burst coalesces into one event per kind, and this worker's own writes
are suppressed — a `create` or `update` sends its precise op and never an
extra `external`.

**Loop hazard for subscribers.** Suppression covers writes made *through this
worker*. A subscriber that reacts to `{ "op": "external" }` by writing `.md`
files under `skills_folder` by some other route — a shell or coder worker, a
script — is not suppressed and will re-trigger itself. Either write through
`directory::*::update` / `create`, or make the reaction idempotent and gated.

---

## Local development & testing

### Run from source

On targets with a pinned static ONNX Runtime (Linux glibc x86_64/aarch64,
Apple Silicon macOS, Windows MSVC) every build links it and MiniLM retrieval
and reranking are compiled in. With no `ORT_LIB_PATH`, `ort-sys` downloads the
runtime for the build target at build time (SHA-256-verified). For offline or
cached x86_64 Linux builds, provision it once and export the path it prints:

```bash
export ORT_LIB_PATH="$(scripts/provision-onnxruntime.sh)"   # idempotent, SHA-256 verified
export ORT_PREFER_DYNAMIC_LINK=0
```

Other targets (musl, armv7, Intel macOS) build the BM25-only worker and need
nothing extra.

```bash
# --config is an optional YAML seed (see config.yaml.example); omit it to
# rely on the value stored in the `configuration` worker (or built-in defaults).
cargo run --release -- --url ws://127.0.0.1:49134 --config ./config.yaml.example
```

### Tests

```bash
# Fast, offline — exercises the pure helpers (markdown / id validators
# / fs source) without needing an iii engine.
cargo test --lib

# Full BDD suite — requires an iii engine on ws://127.0.0.1:49134
# (or III_ENGINE_WS_URL). The git-backed download scenarios spin up
# a local fixture repo via `git init`; the registry-backed scenarios
# point a wiremock server at the worker's `registry_url` config.
cargo test

# One feature group at a time. Available tags:
#   @engine  @read  @download  @download_repo  @download_registry
cargo test --test bdd -- --tags @download
```

The BDD harness lives under [tests/](tests/). Feature files mirror the
modules in [src/functions/](src/functions/). Step definitions under
[tests/steps/](tests/steps/) drive each feature through the same
`iii.trigger` path the production binary uses.

## api reference

```json
{
  "functions": [
    {
      "description": "Internal: auto-download skills on worker add event.",
      "metadata": {
        "internal": true
      },
      "name": "directory::__on_worker_added",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "description": "`worker` trigger payload for `directory::__on_worker_added`. Only `worker` is read; declared as a struct so the function publishes a typed schema.",
        "properties": {
          "worker": {
            "default": null,
            "type": [
              "string",
              "null"
            ]
          }
        },
        "title": "WorkerAddedEvent",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "ok": {
            "type": "boolean"
          }
        },
        "required": [
          "ok"
        ],
        "title": "WorkerAddedAck",
        "type": "object"
      }
    },
    {
      "description": "Create a new agent profile at <agents_folder>/<id>.md from full-file markdown (frontmatter with a non-empty `name`, emoji-only `logo`, optional `skills:` filter and `functions:` list of engine function ids to pre-load into sessions; the body is the system prompt and may be empty). Rejects ids or paths that already exist; a bundled id is shadowed.",
      "metadata": {
        "tool": {
          "label": "Create agent profile"
        }
      },
      "name": "directory::agents::create",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "content": {
            "description": "Full file content, frontmatter included; `name` is required, the body is the system prompt and may be empty.",
            "type": "string"
          },
          "id": {
            "description": "New profile id, used as the file stem; lowercase ASCII, digits, `-` and `_` only, and not already taken.",
            "type": "string"
          }
        },
        "required": [
          "content",
          "id"
        ],
        "title": "AgentCreateInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "bytes": {
            "description": "Bytes written.",
            "format": "uint",
            "minimum": 0,
            "type": "integer"
          },
          "description": {
            "type": "string"
          },
          "id": {
            "type": "string"
          },
          "logo": {
            "type": [
              "string",
              "null"
            ]
          },
          "modified_at": {
            "description": "File mtime after the write, RFC 3339.",
            "type": "string"
          },
          "name": {
            "description": "Display name parsed from the (new) frontmatter.",
            "type": "string"
          }
        },
        "required": [
          "bytes",
          "description",
          "id",
          "modified_at",
          "name"
        ],
        "title": "AgentWriteOutput",
        "type": "object"
      }
    },
    {
      "description": "Delete one existing agent profile's markdown file by id. Deleting the local shadow of a bundled profile falls back to the bundled copy; profiles that extend it stop resolving until fixed.",
      "metadata": {
        "tool": {
          "label": "Delete agent profile"
        }
      },
      "name": "directory::agents::delete",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "id": {
            "description": "Existing agent profile id, as returned by `directory::agents::list`.",
            "type": "string"
          }
        },
        "required": [
          "id"
        ],
        "title": "AgentDeleteInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "id": {
            "type": "string"
          }
        },
        "required": [
          "id"
        ],
        "title": "AgentDeleteOutput",
        "type": "object"
      }
    },
    {
      "description": "Add preloaded functions to one existing agent profile: appends the given engine function ids (e.g. `coder::tree`) to the profile's own `functions:` list — the contracts the harness pre-loads into the system prompt of every new session running as this profile. Ids already present are kept once; the rest of the file is untouched. Editing a bundled profile creates the local file that shadows it.",
      "metadata": {
        "tool": {
          "label": "Add agent profile functions"
        }
      },
      "name": "directory::agents::functions::add",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "functions": {
            "description": "Engine function ids (e.g. `coder::tree`), verbatim, one per entry.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "id": {
            "description": "Existing agent profile id, as returned by `directory::agents::list`.",
            "type": "string"
          }
        },
        "required": [
          "functions",
          "id"
        ],
        "title": "AgentFunctionsInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "added": {
            "description": "Ids this call actually added (already-present ids are not repeated).",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "bytes": {
            "description": "Bytes on disk after the call.",
            "format": "uint",
            "minimum": 0,
            "type": "integer"
          },
          "functions": {
            "description": "The profile's OWN `functions:` list after the write (not resolved through `extends`), in file order.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "id": {
            "type": "string"
          },
          "modified_at": {
            "description": "File mtime after the call, RFC 3339.",
            "type": "string"
          },
          "removed": {
            "description": "Ids this call actually removed (absent ids are ignored).",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "unchanged": {
            "description": "True when the request changed nothing; the file was not rewritten.",
            "type": "boolean"
          }
        },
        "required": [
          "added",
          "bytes",
          "functions",
          "id",
          "modified_at",
          "removed",
          "unchanged"
        ],
        "title": "AgentFunctionsOutput",
        "type": "object"
      }
    },
    {
      "description": "Remove preloaded functions from one existing agent profile: drops the given engine function ids from the profile's own `functions:` list (ids not present are ignored); the rest of the file is untouched. Only the profile's OWN list is edited; ids inherited through `extends` stay (the resolved list is the union of the chain) and are removed on the parent.",
      "metadata": {
        "tool": {
          "label": "Remove agent profile functions"
        }
      },
      "name": "directory::agents::functions::remove",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "functions": {
            "description": "Engine function ids (e.g. `coder::tree`), verbatim, one per entry.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "id": {
            "description": "Existing agent profile id, as returned by `directory::agents::list`.",
            "type": "string"
          }
        },
        "required": [
          "functions",
          "id"
        ],
        "title": "AgentFunctionsInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "added": {
            "description": "Ids this call actually added (already-present ids are not repeated).",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "bytes": {
            "description": "Bytes on disk after the call.",
            "format": "uint",
            "minimum": 0,
            "type": "integer"
          },
          "functions": {
            "description": "The profile's OWN `functions:` list after the write (not resolved through `extends`), in file order.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "id": {
            "type": "string"
          },
          "modified_at": {
            "description": "File mtime after the call, RFC 3339.",
            "type": "string"
          },
          "removed": {
            "description": "Ids this call actually removed (absent ids are ignored).",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "unchanged": {
            "description": "True when the request changed nothing; the file was not rewritten.",
            "type": "boolean"
          }
        },
        "required": [
          "added",
          "bytes",
          "functions",
          "id",
          "modified_at",
          "removed",
          "unchanged"
        ],
        "title": "AgentFunctionsOutput",
        "type": "object"
      }
    },
    {
      "description": "Fetch one agent profile by id: the system prompt resolved through its `extends` chain, display fields, preloaded `skills` (skill ids whose bodies the harness pre-loads into the session prompt) plus `unknown_skills`, preloaded `functions` (engine function ids the harness pre-loads into the session prompt) plus `unknown_functions`, model, reasoning_effort, and `inheritance_error` when the chain does not resolve. Pass raw: true for the exact on-disk file to edit with directory::agents::update.",
      "metadata": {},
      "name": "directory::agents::get",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "id": {
            "type": "string"
          },
          "raw": {
            "default": null,
            "description": "When true, also return the exact on-disk file (frontmatter included) as `raw`, ready for directory::agents::update.",
            "type": [
              "boolean",
              "null"
            ]
          }
        },
        "required": [
          "id"
        ],
        "title": "AgentGetInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "builtin": {
            "description": "Bundled with the worker, no file behind it (see `list`).",
            "type": "boolean"
          },
          "color": {
            "description": "Harness subagent color token (closed set, validated at write time); `null` = neutral.",
            "type": [
              "string",
              "null"
            ]
          },
          "description": {
            "type": "string"
          },
          "extends": {
            "description": "Parent profile id (`extends:`), as declared; `null` = none.",
            "type": [
              "string",
              "null"
            ]
          },
          "functions": {
            "description": "Preloaded functions, resolved through `extends` (the nearest profile with a non-empty list): engine function ids whose contracts the harness pre-loads into the system prompt of every session running as this profile, so the model calls them without discovery or a contract lookup. Empty = none.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "icon": {
            "description": "Harness subagent icon token (closed set, validated at write time); `null` = caller picks.",
            "type": [
              "string",
              "null"
            ]
          },
          "id": {
            "type": "string"
          },
          "inheritance_error": {
            "description": "Set when the `extends` chain does not resolve (unknown parent, loop, deeper than 8): `system_prompt` and the inherited fields then come from this file alone, `raw` still round-trips so the chain can be fixed, and the harness refuses to run the profile meanwhile.",
            "type": [
              "string",
              "null"
            ]
          },
          "logo": {
            "type": [
              "string",
              "null"
            ]
          },
          "model": {
            "description": "Model id for sessions using this profile, resolved through `extends`; `null` = the send decides. Served verbatim — resolution against the live model catalog happens where it is used.",
            "type": [
              "string",
              "null"
            ]
          },
          "modified_at": {
            "description": "File mtime as RFC 3339; empty for a bundled profile.",
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "raw": {
            "description": "FULL on-disk file content (this profile's own file, ancestors excluded). Present only when the request set `raw: true`.",
            "type": [
              "string",
              "null"
            ]
          },
          "reasoning_effort": {
            "description": "Provider-native reasoning effort paired with `model`, resolved through `extends`; `null` = the model/provider default. Served verbatim and validated at use time.",
            "type": [
              "string",
              "null"
            ]
          },
          "skills": {
            "description": "Preloaded skills, resolved through `extends` (the union of the chain's lists, root first): skill ids whose bodies the harness pre-loads into the system prompt of every session running as this profile. Empty = none. Never a filter on the skills index.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "system_prompt": {
            "description": "The RESOLVED identity: every ancestor's body root-first, then this file's body, frontmatter stripped, joined by a blank line; blank bodies are skipped, so a profile with no prompt of its own serves its parent chain unchanged and a prompt-less profile without `extends` serves `\"\"`. A profile that has a body and no `extends` serves that body verbatim.",
            "type": "string"
          },
          "unknown_functions": {
            "description": "`functions` entries the engine does not currently know (not registered right now, or a typo). Warnings — the profile still loads and the harness skips them; an empty list also results when the engine could not be asked.",
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "unknown_skills": {
            "description": "`skills` entries that resolve to no currently visible skill. Warnings — the agent profile still loads and the harness renders them as unavailable.",
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "builtin",
          "description",
          "functions",
          "id",
          "modified_at",
          "name",
          "skills",
          "system_prompt",
          "unknown_functions",
          "unknown_skills"
        ],
        "title": "AgentGetOutput",
        "type": "object"
      }
    },
    {
      "description": "List agent profiles (id, name, description, logo, icon, color, model, reasoning_effort, skill_count, function_count, extends, modified_at) from the agents folder plus the bundled ones (`builtin: true`). Inherited fields resolve through `extends`; skill_count null means no preloaded skills, function_count counts the preloaded functions (contracts injected into new sessions).",
      "metadata": {},
      "name": "directory::agents::list",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "title": "ListAgentsInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "definitions": {
          "AgentEntry": {
            "properties": {
              "builtin": {
                "description": "Bundled with the worker, no file behind it: editing it creates the local file (which then shadows this entry); there is nothing to delete.",
                "type": "boolean"
              },
              "color": {
                "description": "Harness subagent color token for display identities; `null` = neutral.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "description": {
                "type": "string"
              },
              "extends": {
                "description": "Parent profile id (`extends:`), as declared; `null` = none.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "function_count": {
                "description": "Number of preloaded functions (contracts the harness pre-loads into the session prompt), resolved through `extends`; `0` = none.",
                "format": "uint",
                "minimum": 0,
                "type": "integer"
              },
              "icon": {
                "description": "Harness subagent icon token for spawn display identities; `null` = caller picks.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "id": {
                "description": "Flat agent profile id (the file stem) — what `harness::send { options: { agent } }` will take.",
                "type": "string"
              },
              "inheritance_error": {
                "description": "Set when the `extends` chain does not resolve (unknown parent, loop, too deep): the row carries the profile's own fields only, and the harness refuses to run it until the chain is fixed.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "logo": {
                "description": "Emoji logo, `null` when the agent profile has none.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "model": {
                "description": "Model id for sessions using this profile, resolved through `extends`; `null` = the send decides.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "modified_at": {
                "description": "File mtime as RFC 3339; empty for a bundled profile.",
                "type": "string"
              },
              "name": {
                "description": "Display name from frontmatter (`name:`).",
                "type": "string"
              },
              "reasoning_effort": {
                "description": "Provider-native reasoning effort paired with `model`, resolved through `extends`; `null` = the model/provider default.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "skill_count": {
                "description": "Number of preloaded skills (bodies the harness pre-loads into the session prompt), resolved through `extends`; `null` = none.",
                "format": "uint",
                "minimum": 0,
                "type": [
                  "integer",
                  "null"
                ]
              }
            },
            "required": [
              "builtin",
              "description",
              "function_count",
              "id",
              "modified_at",
              "name"
            ],
            "type": "object"
          }
        },
        "properties": {
          "agents": {
            "items": {
              "$ref": "#/definitions/AgentEntry"
            },
            "type": "array"
          }
        },
        "required": [
          "agents"
        ],
        "title": "ListAgentsOutput",
        "type": "object"
      }
    },
    {
      "description": "Overwrite one existing agent profile with full-file markdown (frontmatter with a non-empty `name`, emoji-only `logo`, optional `skills:` and `functions:` lists; the body is the system prompt and may be empty). Updating a bundled profile creates a local file that shadows it. To change only the preloaded functions, prefer directory::agents::functions::add / remove.",
      "metadata": {
        "tool": {
          "label": "Update agent profile"
        }
      },
      "name": "directory::agents::update",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "content": {
            "description": "FULL new file content, frontmatter block included — the string `directory::agents::get { raw: true }` returns, edited.",
            "type": "string"
          },
          "id": {
            "description": "Existing agent profile id, as returned by `directory::agents::list`.",
            "type": "string"
          }
        },
        "required": [
          "content",
          "id"
        ],
        "title": "AgentUpdateInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "bytes": {
            "description": "Bytes written.",
            "format": "uint",
            "minimum": 0,
            "type": "integer"
          },
          "description": {
            "type": "string"
          },
          "id": {
            "type": "string"
          },
          "logo": {
            "type": [
              "string",
              "null"
            ]
          },
          "modified_at": {
            "description": "File mtime after the write, RFC 3339.",
            "type": "string"
          },
          "name": {
            "description": "Display name parsed from the (new) frontmatter.",
            "type": "string"
          }
        },
        "required": [
          "bytes",
          "description",
          "id",
          "modified_at",
          "name"
        ],
        "title": "AgentWriteOutput",
        "type": "object"
      }
    },
    {
      "description": "Read full detail for one engine function: schemas, owning worker, and registered triggers that target it. Proxies to the engine's native engine::functions::info.",
      "metadata": {},
      "name": "directory::engine::functions::info",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "function_id": {
            "description": "Fully-qualified function id on the bus (e.g. `sandbox::create`).",
            "type": "string"
          }
        },
        "required": [
          "function_id"
        ],
        "title": "FunctionInfoInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "definitions": {
          "RegisteredTriggerSummary": {
            "description": "Trigger instance summary for the response envelope.",
            "properties": {
              "config": true,
              "id": {
                "type": "string"
              },
              "trigger_type": {
                "type": "string"
              }
            },
            "required": [
              "config",
              "id",
              "trigger_type"
            ],
            "type": "object"
          }
        },
        "description": "Response shape for `directory::engine::functions::info`.\n\nMirrors the shape of the old `directory::engine::functions::info` but WITHOUT the `how_guide` and `related_skills` fields.",
        "properties": {
          "description": {
            "type": [
              "string",
              "null"
            ]
          },
          "function_id": {
            "type": "string"
          },
          "metadata": true,
          "registered_triggers": {
            "items": {
              "$ref": "#/definitions/RegisteredTriggerSummary"
            },
            "type": "array"
          },
          "request_schema": true,
          "response_schema": true,
          "worker_name": {
            "type": [
              "string",
              "null"
            ]
          }
        },
        "required": [
          "function_id",
          "registered_triggers"
        ],
        "title": "FunctionInfoOutput",
        "type": "object"
      }
    },
    {
      "description": "Internal: the exact search-hint text per exposure mode, for the configuration UI.",
      "metadata": {
        "internal": true,
        "trace_hidden": true
      },
      "name": "directory::hint-preview",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "title": "HintPreviewRequest",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "description": "The exact hint text per exposure mode, for the configuration UI. The live block's `functions_generation` attribute varies per generation; the preview renders it as 0.",
        "properties": {
          "agent_trigger": {
            "type": "string"
          },
          "native": {
            "type": "string"
          }
        },
        "required": [
          "agent_trigger",
          "native"
        ],
        "title": "HintPreviewResponse",
        "type": "object"
      }
    },
    {
      "description": "Internal: reload tunable iii-directory settings from the authoritative configuration when it changes.",
      "metadata": {
        "internal": true
      },
      "name": "directory::on-config-change",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "description": "Trigger payload for `directory::on-config-change`. The handler ignores it (it re-fetches from the authoritative configuration); the empty struct exists so the function publishes a typed request schema rather than AnyValue.",
        "title": "OnConfigChangeRequest",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "ok": {
            "type": "boolean"
          }
        },
        "required": [
          "ok"
        ],
        "title": "OnConfigChangeResponse",
        "type": "object"
      }
    },
    {
      "description": "Internal: refresh the search catalog after the engine function set changes.",
      "metadata": {
        "internal": true,
        "trace_hidden": true
      },
      "name": "directory::on-functions-change",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "event": {
            "type": [
              "string",
              "null"
            ]
          }
        },
        "title": "OnFunctionsChangeEvent",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "ok": {
            "type": "boolean"
          }
        },
        "required": [
          "ok"
        ],
        "title": "AckResponse",
        "type": "object"
      }
    },
    {
      "description": "Internal: inject the conditional search hint into one harness generation.",
      "metadata": {
        "internal": true,
        "trace_hidden": true
      },
      "name": "directory::pre-generate",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "definitions": {
          "ExposeKind": {
            "oneOf": [
              {
                "enum": [
                  "agent_trigger",
                  "native"
                ],
                "type": "string"
              },
              {
                "description": "Forward compatibility: an exposure mode this build does not know gets the mode-neutral call instruction rather than a deserialization error.",
                "enum": [
                  "other"
                ],
                "type": "string"
              }
            ]
          },
          "GeneratePayload": {
            "properties": {
              "expose": {
                "allOf": [
                  {
                    "$ref": "#/definitions/ExposeKind"
                  }
                ],
                "description": "How the harness exposes functions to the model for this generation. Absent on harnesses that predate the field, which only ever exposed through agent_trigger by default."
              },
              "functions_generation": {
                "format": "uint64",
                "minimum": 0,
                "type": "integer"
              },
              "messages": {
                "items": true,
                "type": "array"
              },
              "system_prompt": {
                "type": "string"
              },
              "tools": {
                "items": {
                  "$ref": "#/definitions/ToolSchema"
                },
                "type": "array"
              }
            },
            "required": [
              "functions_generation",
              "messages",
              "system_prompt",
              "tools"
            ],
            "type": "object"
          },
          "ToolSchema": {
            "description": "One catalog entry: the contract fields search runs on.",
            "properties": {
              "description": {
                "type": "string"
              },
              "name": {
                "type": "string"
              },
              "parameters": true
            },
            "required": [
              "description",
              "name",
              "parameters"
            ],
            "type": "object"
          }
        },
        "properties": {
          "depth": {
            "format": "uint32",
            "minimum": 0,
            "type": "integer"
          },
          "generate": {
            "$ref": "#/definitions/GeneratePayload"
          },
          "session_id": {
            "type": "string"
          },
          "step": {
            "format": "uint64",
            "minimum": 0,
            "type": "integer"
          },
          "turn_id": {
            "type": "string"
          }
        },
        "required": [
          "depth",
          "generate",
          "session_id",
          "step",
          "turn_id"
        ],
        "title": "PreGenerateHookRequest",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "definitions": {
          "DiscoveryOutcome": {
            "enum": [
              "hint_injected",
              "skipped"
            ],
            "type": "string"
          },
          "DiscoveryPassV1": {
            "description": "The durable transcript row for one hook pass. Coarse by design: outcome, reason, and counts only — no prompts, messages, tool contracts, session ids, or timings ever leave the hook.",
            "properties": {
              "allowed_functions": {
                "format": "uint64",
                "minimum": 0,
                "type": "integer"
              },
              "functions_generation": {
                "format": "uint64",
                "minimum": 0,
                "type": "integer"
              },
              "outcome": {
                "$ref": "#/definitions/DiscoveryOutcome"
              },
              "reason": {
                "anyOf": [
                  {
                    "$ref": "#/definitions/DiscoveryReason"
                  },
                  {
                    "type": "null"
                  }
                ]
              }
            },
            "required": [
              "allowed_functions",
              "functions_generation",
              "outcome"
            ],
            "type": "object"
          },
          "DiscoveryReason": {
            "enum": [
              "search_unavailable",
              "already_searched",
              "narrow_surface",
              "already_operating",
              "task_guided",
              "hint_already_sent"
            ],
            "type": "string"
          },
          "DiscoveryTranscriptAnnotation": {
            "properties": {
              "data": {
                "$ref": "#/definitions/DiscoveryPassV1"
              },
              "summary": {
                "type": "string"
              },
              "type": {
                "type": "string"
              },
              "version": {
                "format": "uint8",
                "minimum": 0,
                "type": "integer"
              }
            },
            "required": [
              "data",
              "summary",
              "type",
              "version"
            ],
            "type": "object"
          },
          "PreGenerateAnnotations": {
            "properties": {
              "directory": {
                "$ref": "#/definitions/DiscoveryTranscriptAnnotation"
              }
            },
            "required": [
              "directory"
            ],
            "type": "object"
          },
          "PreGenerateMutations": {
            "properties": {
              "append_messages": {
                "description": "Ephemeral tail messages for this generation only. The hint rides here rather than as a system-prompt mutation: the system prompt is the provider's first input item, and a once-per-turn append there invalidated the entire prompt-cache prefix twice per turn.",
                "items": true,
                "type": "array"
              }
            },
            "required": [
              "append_messages"
            ],
            "type": "object"
          }
        },
        "properties": {
          "annotations": {
            "$ref": "#/definitions/PreGenerateAnnotations"
          },
          "decision": {
            "type": "string"
          },
          "mutations": {
            "anyOf": [
              {
                "$ref": "#/definitions/PreGenerateMutations"
              },
              {
                "type": "null"
              }
            ]
          }
        },
        "required": [
          "annotations",
          "decision"
        ],
        "title": "PreGenerateHookResponse",
        "type": "object"
      }
    },
    {
      "description": "Preview one registry worker before installing: envelope (version, kind, dependencies, config), its public function and trigger names with descriptions, and skill file paths. Schemas are omitted — install, then read contracts with engine::functions::info. Pass `readme: true` for the README prose; `version` or `tag` (default tag \"latest\").",
      "metadata": {},
      "name": "directory::registry::workers::info",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "description": "`directory::registry::workers::info` input. Pass either `version` or `tag`; if neither is provided we fall back to `tag: \"latest\"`.",
        "properties": {
          "name": {
            "description": "Worker name in the registry (e.g. `\"resend\"`).",
            "type": "string"
          },
          "readme": {
            "default": false,
            "description": "Include the README markdown (10–25 KB for most workers). Off by default: the card is for judging fit before `compose::add`; the README is for setup prose and examples.",
            "type": "boolean"
          },
          "tag": {
            "default": null,
            "type": [
              "string",
              "null"
            ]
          },
          "version": {
            "default": null,
            "description": "Mutually exclusive with `tag`. If neither is provided we fall back to `tag: \"latest\"`.",
            "type": [
              "string",
              "null"
            ]
          }
        },
        "required": [
          "name"
        ],
        "title": "WorkerInfoInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "definitions": {
          "ApiReference": {
            "properties": {
              "functions": {
                "default": [],
                "items": {
                  "$ref": "#/definitions/ApiReferenceFunction"
                },
                "type": "array"
              },
              "triggers": {
                "default": [],
                "items": {
                  "$ref": "#/definitions/ApiReferenceTrigger"
                },
                "type": "array"
              }
            },
            "type": "object"
          },
          "ApiReferenceFunction": {
            "properties": {
              "description": {
                "type": [
                  "string",
                  "null"
                ]
              },
              "metadata": true,
              "name": {
                "type": "string"
              },
              "request_schema": true,
              "response_schema": true
            },
            "required": [
              "name"
            ],
            "type": "object"
          },
          "ApiReferenceTrigger": {
            "properties": {
              "description": {
                "type": [
                  "string",
                  "null"
                ]
              },
              "invocation_schema": true,
              "metadata": true,
              "name": {
                "type": "string"
              },
              "return_schema": true
            },
            "required": [
              "name"
            ],
            "type": "object"
          },
          "Dependency": {
            "description": "Worker dependency entry. Mirrors the `Dependency` schema in `openapi.yaml`.",
            "properties": {
              "name": {
                "type": "string"
              },
              "version": {
                "type": "string"
              }
            },
            "required": [
              "name",
              "version"
            ],
            "type": "object"
          },
          "SkillsTree": {
            "properties": {
              "skills": {
                "default": [],
                "items": {
                  "$ref": "#/definitions/SkillsTreeSkill"
                },
                "type": "array"
              }
            },
            "type": "object"
          },
          "SkillsTreeSkill": {
            "properties": {
              "path": {
                "type": "string"
              }
            },
            "required": [
              "path"
            ],
            "type": "object"
          },
          "Worker": {
            "description": "Shared worker envelope used by both `directory::registry::workers::list` rows and the `worker` field of `directory::registry::workers::info`. Field names match the OpenAPI `WorkerListItem` schema. The shared core fields (`name`, `description`, `version`) line up with the engine's `engine::workers::list` row shape so callers learn one envelope across local + registry surfaces.",
            "properties": {
              "author": {
                "anyOf": [
                  {
                    "$ref": "#/definitions/WorkerAuthor"
                  },
                  {
                    "type": "null"
                  }
                ],
                "default": null
              },
              "config": {
                "default": {},
                "description": "Free-form runtime configuration block from the publish payload."
              },
              "dependencies": {
                "default": [],
                "items": {
                  "$ref": "#/definitions/Dependency"
                },
                "type": "array"
              },
              "description": {
                "default": null,
                "type": [
                  "string",
                  "null"
                ]
              },
              "image": {
                "description": "Container image tag, populated only for `type=image` workers.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "name": {
                "type": "string"
              },
              "repo": {
                "default": null,
                "type": [
                  "string",
                  "null"
                ]
              },
              "supported_targets": {
                "default": [],
                "items": {
                  "type": "string"
                },
                "type": "array"
              },
              "total_downloads": {
                "default": 0,
                "format": "uint64",
                "minimum": 0,
                "type": "integer"
              },
              "type": {
                "default": null,
                "description": "Worker kind — `binary`, `image`, or `engine`.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "version": {
                "default": null,
                "description": "Latest published version (worker-list) or the resolved version (worker-info, when called with `version` / `tag`).",
                "type": [
                  "string",
                  "null"
                ]
              }
            },
            "required": [
              "name"
            ],
            "type": "object"
          },
          "WorkerAuthor": {
            "description": "Author block for a published worker. Field names match the `WorkerAuthor` schema in `openapi.yaml` (`pfp`, `verified`).",
            "properties": {
              "name": {
                "type": [
                  "string",
                  "null"
                ]
              },
              "pfp": {
                "default": null,
                "description": "Profile picture URL. `null` when the author hasn't uploaded one.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "verified": {
                "default": false,
                "type": "boolean"
              }
            },
            "type": "object"
          }
        },
        "properties": {
          "api_reference": {
            "$ref": "#/definitions/ApiReference"
          },
          "readme": {
            "type": [
              "string",
              "null"
            ]
          },
          "skills_tree": {
            "$ref": "#/definitions/SkillsTree"
          },
          "worker": {
            "allOf": [
              {
                "$ref": "#/definitions/Worker"
              }
            ],
            "description": "Same shape as `directory::registry::workers::list` rows (and the engine's `engine::workers::list` rows for the shared core fields)."
          }
        },
        "required": [
          "api_reference",
          "skills_tree",
          "worker"
        ],
        "title": "WorkerInfoOutput",
        "type": "object"
      }
    },
    {
      "description": "List workers from the public registry, optionally filtered by fuzzy `search` (default order: downloads). Cursor-paginated: pass back `pagination.next_cursor` as `cursor`.",
      "metadata": {},
      "name": "directory::registry::workers::list",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "description": "`directory::registry::workers::list` input. Mirrors the engine's `engine::workers::list` search input so callers can switch between local and registry surfaces without re-learning the API. Adds `cursor` for paging because the registry is paged (server-authored page size — the client cannot override it).",
        "properties": {
          "cursor": {
            "default": null,
            "description": "Cursor from a previous call's `pagination.next_cursor`; omit for the first page.",
            "type": [
              "string",
              "null"
            ]
          },
          "search": {
            "default": null,
            "description": "Optional free-text query, fuzzy-matched by the registry; omitted means ordered by downloads.",
            "type": [
              "string",
              "null"
            ]
          }
        },
        "title": "WorkerListInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "definitions": {
          "Dependency": {
            "description": "Worker dependency entry. Mirrors the `Dependency` schema in `openapi.yaml`.",
            "properties": {
              "name": {
                "type": "string"
              },
              "version": {
                "type": "string"
              }
            },
            "required": [
              "name",
              "version"
            ],
            "type": "object"
          },
          "Pagination": {
            "description": "Pagination envelope returned alongside a worker-list page. Mirrors the OpenAPI `Pagination` schema.",
            "properties": {
              "has_more": {
                "default": false,
                "type": "boolean"
              },
              "next_cursor": {
                "default": null,
                "description": "Opaque cursor for the next page. `null` on the last page.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "page_size": {
                "default": 0,
                "description": "Server-authored page size. The client cannot override this.",
                "format": "uint32",
                "minimum": 0,
                "type": "integer"
              }
            },
            "type": "object"
          },
          "Worker": {
            "description": "Shared worker envelope used by both `directory::registry::workers::list` rows and the `worker` field of `directory::registry::workers::info`. Field names match the OpenAPI `WorkerListItem` schema. The shared core fields (`name`, `description`, `version`) line up with the engine's `engine::workers::list` row shape so callers learn one envelope across local + registry surfaces.",
            "properties": {
              "author": {
                "anyOf": [
                  {
                    "$ref": "#/definitions/WorkerAuthor"
                  },
                  {
                    "type": "null"
                  }
                ],
                "default": null
              },
              "config": {
                "default": {},
                "description": "Free-form runtime configuration block from the publish payload."
              },
              "dependencies": {
                "default": [],
                "items": {
                  "$ref": "#/definitions/Dependency"
                },
                "type": "array"
              },
              "description": {
                "default": null,
                "type": [
                  "string",
                  "null"
                ]
              },
              "image": {
                "description": "Container image tag, populated only for `type=image` workers.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "name": {
                "type": "string"
              },
              "repo": {
                "default": null,
                "type": [
                  "string",
                  "null"
                ]
              },
              "supported_targets": {
                "default": [],
                "items": {
                  "type": "string"
                },
                "type": "array"
              },
              "total_downloads": {
                "default": 0,
                "format": "uint64",
                "minimum": 0,
                "type": "integer"
              },
              "type": {
                "default": null,
                "description": "Worker kind — `binary`, `image`, or `engine`.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "version": {
                "default": null,
                "description": "Latest published version (worker-list) or the resolved version (worker-info, when called with `version` / `tag`).",
                "type": [
                  "string",
                  "null"
                ]
              }
            },
            "required": [
              "name"
            ],
            "type": "object"
          },
          "WorkerAuthor": {
            "description": "Author block for a published worker. Field names match the `WorkerAuthor` schema in `openapi.yaml` (`pfp`, `verified`).",
            "properties": {
              "name": {
                "type": [
                  "string",
                  "null"
                ]
              },
              "pfp": {
                "default": null,
                "description": "Profile picture URL. `null` when the author hasn't uploaded one.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "verified": {
                "default": false,
                "type": "boolean"
              }
            },
            "type": "object"
          }
        },
        "properties": {
          "pagination": {
            "$ref": "#/definitions/Pagination"
          },
          "workers": {
            "items": {
              "$ref": "#/definitions/Worker"
            },
            "type": "array"
          }
        },
        "required": [
          "pagination",
          "workers"
        ],
        "title": "WorkerListOutput",
        "type": "object"
      }
    },
    {
      "description": "Search available functions for the unmet external capabilities of a step (usually one to six, at most eighteen per call); returns compact function-id candidates grouped by worker.",
      "metadata": {},
      "name": "directory::search_functions",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "capabilities": {
            "description": "Non-empty capability searches derived from the goal and current execution state, usually one to six and at most eighteen per call (searched in batches of six). For one search at each decision point, include all unmet external capabilities once. Exclude intrinsic reasoning, summarization, planning, or formatting, and do not repeat needs already represented or satisfied. Requests to summarize provided text or content are ignored. Write every entry in English, translating non-English user requests while preserving proper names, URLs, and function IDs.",
            "items": {
              "minLength": 1,
              "type": "string"
            },
            "minItems": 1,
            "type": "array",
            "uniqueItems": true
          }
        },
        "required": [
          "capabilities"
        ],
        "title": "SearchFunctionsRequest",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "definitions": {
          "FunctionCandidate": {
            "properties": {
              "description": {
                "description": "First description sentence, capped at 160 bytes.",
                "type": "string"
              },
              "function_id": {
                "type": "string"
              }
            },
            "required": [
              "description",
              "function_id"
            ],
            "type": "object"
          },
          "InstallCall": {
            "description": "A ready-made `compose::add` target and payload. Under agent-trigger exposure, the caller still supplies the wrapper's user-facing `description`.",
            "properties": {
              "function": {
                "type": "string"
              },
              "payload": true
            },
            "required": [
              "function",
              "payload"
            ],
            "type": "object"
          },
          "InstallableWorker": {
            "description": "A registry worker that is NOT installed but carries functions matching the requested capabilities. `name` is the registry slug `compose::add` installs.",
            "properties": {
              "description": {
                "type": "string"
              },
              "functions": {
                "description": "Compact candidates only. If the remaining task needs these functions, reuse their IDs and fetch the required contracts through `engine::functions::info`.",
                "items": {
                  "$ref": "#/definitions/FunctionCandidate"
                },
                "type": "array"
              },
              "install": {
                "allOf": [
                  {
                    "$ref": "#/definitions/InstallCall"
                  }
                ],
                "description": "The `compose::add` target and payload; agent-trigger callers add `description`."
              },
              "name": {
                "type": "string"
              },
              "version": {
                "type": "string"
              }
            },
            "required": [
              "description",
              "functions",
              "install",
              "name",
              "version"
            ],
            "type": "object"
          },
          "SearchWorker": {
            "properties": {
              "functions": {
                "items": {
                  "$ref": "#/definitions/FunctionCandidate"
                },
                "type": "array"
              },
              "namespace": {
                "type": "string"
              }
            },
            "required": [
              "functions",
              "namespace"
            ],
            "type": "object"
          }
        },
        "properties": {
          "guidance": {
            "type": "string"
          },
          "installable": {
            "description": "Matching workers from the private registry. Their functions are NOT callable until the worker is installed.",
            "items": {
              "$ref": "#/definitions/InstallableWorker"
            },
            "type": "array"
          },
          "latency_ms": {
            "format": "double",
            "type": "number"
          },
          "workers": {
            "items": {
              "$ref": "#/definitions/SearchWorker"
            },
            "type": "array"
          }
        },
        "required": [
          "guidance",
          "installable",
          "latency_ms",
          "workers"
        ],
        "title": "SearchFunctionsResponse",
        "type": "object"
      }
    },
    {
      "description": "Create a new skill at <skills_folder>/<id>.md from full-file markdown (frontmatter optional, non-empty body). Rejects ids or paths that already exist, including system-installed skills. Use directory::skills::update to edit existing skills.",
      "metadata": {
        "tool": {
          "label": "Create skill"
        }
      },
      "name": "directory::skills::create",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "content": {
            "description": "Full file content, frontmatter optional; only the size cap and a non-empty body are enforced.",
            "type": "string"
          },
          "id": {
            "description": "New skill id, used as the file path under skills_folder (`/`-separated segments of `[a-z0-9_-]`), not already taken.",
            "type": "string"
          }
        },
        "required": [
          "content",
          "id"
        ],
        "title": "SkillCreateInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "bytes": {
            "description": "Bytes written.",
            "format": "uint",
            "minimum": 0,
            "type": "integer"
          },
          "function_id": {
            "description": "Frontmatter `function_id:` of the content, `null` when absent.",
            "type": [
              "string",
              "null"
            ]
          },
          "id": {
            "description": "The created skill's id (normalized form of the input id).",
            "type": "string"
          },
          "modified_at": {
            "description": "File mtime after the write, RFC 3339.",
            "type": "string"
          },
          "title": {
            "description": "Title resolved from the content (frontmatter `title:`, then `name:`, then body H1, then the id) — what `list` rows will show.",
            "type": "string"
          },
          "type": {
            "description": "Frontmatter `type:` of the content, `null` when absent.",
            "type": [
              "string",
              "null"
            ]
          }
        },
        "required": [
          "bytes",
          "id",
          "modified_at",
          "title"
        ],
        "title": "SkillCreateOutput",
        "type": "object"
      }
    },
    {
      "description": "Delete one existing skill's markdown file by id (same id forms as directory::skills::get); refuses read-only system-installed skills.",
      "metadata": {
        "tool": {
          "label": "Delete skill"
        }
      },
      "name": "directory::skills::delete",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "id": {
            "description": "Existing skill id — the same forms `directory::skills::get` accepts (bare id, `<id>.md`, `SKILL(S).md`, `iii://<id>`).",
            "type": "string"
          }
        },
        "required": [
          "id"
        ],
        "title": "SkillDeleteInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "id": {
            "description": "Id of the skill whose file was removed — the RESOLVED on-disk id (e.g. `ns/index` for input `ns`), not the input form.",
            "type": "string"
          }
        },
        "required": [
          "id"
        ],
        "title": "SkillDeleteOutput",
        "type": "object"
      }
    },
    {
      "description": "Download skills into skills_folder from exactly one source: {repo, skill, branch?} clones a GitHub skill folder; {worker, version?|tag?} pulls from the workers registry. Prefer the explicit download_from_registry / download_from_repo.",
      "metadata": {
        "tool": {
          "label": "Download skills"
        }
      },
      "name": "directory::skills::download",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "branch": {
            "default": null,
            "description": "Source A: branch to clone. Defaults to `\"main\"`. Pass `\"master\"` (or any other branch name) for repos whose default branch is not `main`.",
            "type": [
              "string",
              "null"
            ]
          },
          "repo": {
            "default": null,
            "description": "Source A: GitHub repo URL. Pair with `skill`.",
            "type": [
              "string",
              "null"
            ]
          },
          "skill": {
            "default": null,
            "description": "Source A: subfolder under `skills/` inside the repo. Doubles as the destination namespace inside `skills_folder`.",
            "type": [
              "string",
              "null"
            ]
          },
          "tag": {
            "default": null,
            "description": "Registry tag to pull (default `latest`); mutually exclusive with `version`.",
            "type": [
              "string",
              "null"
            ]
          },
          "version": {
            "default": null,
            "description": "Source B: explicit semver to pull. Mutually exclusive with `tag`.",
            "type": [
              "string",
              "null"
            ]
          },
          "worker": {
            "default": null,
            "description": "Source B: workers registry name. Pair with exactly one of `version` / `tag`.",
            "type": [
              "string",
              "null"
            ]
          }
        },
        "title": "DownloadInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "agents_written": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "namespace": {
            "type": "string"
          },
          "skills_written": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "source": true,
          "system_prompts_written": {
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "agents_written",
          "namespace",
          "skills_written",
          "source",
          "system_prompts_written"
        ],
        "title": "DownloadOutput",
        "type": "object"
      }
    },
    {
      "description": "Download one worker's directory bundle from the workers registry into skills_folder. `worker` is required; pass `version` (exact semver) or `tag` (default \"latest\"), not both. Files are overwritten file-by-file.",
      "metadata": {
        "tool": {
          "label": "Download skills (registry)"
        }
      },
      "name": "directory::skills::download_from_registry",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "description": "Input for `directory::skills::download_from_registry`. The required `worker` field is what makes this function's source unambiguous at the schema level.",
        "properties": {
          "tag": {
            "default": null,
            "description": "Registry tag to pull (e.g. `\"latest\"`). Mutually exclusive with `version`. Defaults to `\"latest\"` when neither is provided.",
            "type": [
              "string",
              "null"
            ]
          },
          "version": {
            "default": null,
            "description": "Explicit semver to pull. Mutually exclusive with `tag`.",
            "type": [
              "string",
              "null"
            ]
          },
          "worker": {
            "description": "Worker name in the registry (e.g. `\"shell\"`).",
            "type": "string"
          }
        },
        "required": [
          "worker"
        ],
        "title": "RegistryDownloadInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "agents_written": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "namespace": {
            "type": "string"
          },
          "skills_written": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "source": true,
          "system_prompts_written": {
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "agents_written",
          "namespace",
          "skills_written",
          "source",
          "system_prompts_written"
        ],
        "title": "DownloadOutput",
        "type": "object"
      }
    },
    {
      "description": "Download one skill folder from a GitHub repo into skills_folder: `repo` (https/ssh/git@ URL) and `skill` (subfolder under `skills/`, also the destination namespace) are required; `branch` defaults to \"main\".",
      "metadata": {
        "tool": {
          "label": "Download skills (repo)"
        }
      },
      "name": "directory::skills::download_from_repo",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "description": "Input for `directory::skills::download_from_repo`. The required `repo` + `skill` fields make this function's source unambiguous at the schema level.",
        "properties": {
          "branch": {
            "default": null,
            "description": "Branch to clone. Defaults to `\"main\"`.",
            "type": [
              "string",
              "null"
            ]
          },
          "repo": {
            "description": "GitHub repo URL (validated: https / ssh / git@ only).",
            "type": "string"
          },
          "skill": {
            "description": "Subfolder under `skills/` inside the repo. Doubles as the destination namespace inside `skills_folder`.",
            "type": "string"
          }
        },
        "required": [
          "repo",
          "skill"
        ],
        "title": "RepoDownloadInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "agents_written": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "namespace": {
            "type": "string"
          },
          "skills_written": {
            "items": {
              "type": "string"
            },
            "type": "array"
          },
          "source": true,
          "system_prompts_written": {
            "items": {
              "type": "string"
            },
            "type": "array"
          }
        },
        "required": [
          "agents_written",
          "namespace",
          "skills_written",
          "source",
          "system_prompts_written"
        ],
        "title": "DownloadOutput",
        "type": "object"
      }
    },
    {
      "description": "Fetch one skill by id and return its raw markdown body plus id, title, type, function_id, and modified_at. A worker overview is addressed by the bare worker name; `<id>.md` and `iii://<id>` forms are accepted. On a miss, D110 names the closest ids.",
      "metadata": {
        "tool": {
          "label": "Get skill"
        }
      },
      "name": "directory::skills::get",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "id": {
            "description": "Skill id as returned by directory::skills::list (e.g. `directory/skills/list`); `<id>.md` and `iii://<id>` forms are accepted.",
            "type": "string"
          },
          "raw": {
            "default": null,
            "description": "When true, also return the exact on-disk file (frontmatter included) as `raw`, ready for directory::skills::update.",
            "type": [
              "boolean",
              "null"
            ]
          }
        },
        "required": [
          "id"
        ],
        "title": "SkillGetInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "body": {
            "description": "Raw markdown body (post-frontmatter) from disk.\n\nNote: there is no `description` field. `description` is the body's first paragraph, which is already inside `body` — every caller asking for the body would otherwise pay for the prefix twice. Use `directory::skills::list` rows when you want the teaser without the full body.",
            "type": "string"
          },
          "disable_model_invocation": {
            "description": "Whether model-facing indexes should omit this skill from invocation candidates.",
            "type": "boolean"
          },
          "function_id": {
            "description": "Frontmatter `function_id:` when present — the canonical bus function id this skill documents (e.g. `sandbox::create`). The response's `id` field is the SKILL path on disk; `function_id` is what the agent should pass to `agent_trigger`. `null` when the skill isn't 1:1 with a single function.",
            "type": [
              "string",
              "null"
            ]
          },
          "id": {
            "type": "string"
          },
          "modified_at": {
            "description": "File mtime as RFC 3339.",
            "type": "string"
          },
          "path": {
            "description": "Absolute on-disk path of the skill file. Its parent directory is the skill's base directory — where payload the body references by relative path (`scripts/`, `reference/`, agent-skills convention) lives. Only meaningful to callers sharing this worker's filesystem (shell/file tools on the same machine).",
            "type": "string"
          },
          "raw": {
            "description": "FULL on-disk file content (frontmatter block included). Present only when the request set `raw: true`. This is the exact string to hand back to `directory::skills::update`; fallback notes that `get` may prepend to `body` are never added here.",
            "type": [
              "string",
              "null"
            ]
          },
          "title": {
            "description": "Frontmatter `title:` when present and non-empty, otherwise the first `# H1` line in the body, otherwise the bare `id`.",
            "type": "string"
          },
          "type": {
            "description": "Frontmatter `type:` (e.g. `index`, `how-to`, `reference`). `null` when the file has no frontmatter or omits the key.",
            "type": [
              "string",
              "null"
            ]
          }
        },
        "required": [
          "body",
          "disable_model_invocation",
          "id",
          "modified_at",
          "path",
          "title"
        ],
        "title": "SkillGetOutput",
        "type": "object"
      }
    },
    {
      "description": "Read a per-worker overview: one markdown block per installed worker (title, first paragraph, and the directory::skills::get call for the reference). For per-skill rows use directory::skills::list.",
      "metadata": {},
      "name": "directory::skills::index",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "title": "IndexSkillsInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "body": {
            "description": "Rendered markdown document — one short `## <title>` block per installed worker (each worker's root overview doc, whether or not it declares frontmatter `type: index`), carrying the worker's first-paragraph overview and a `directory::skills::get` call to read the full reference. Sorted lex by id.",
            "type": "string"
          },
          "workers_count": {
            "description": "Number of worker entries rendered (i.e. the count of worker overview rows that survived the filter). Cheap sanity check that doesn't require re-parsing the body.",
            "format": "uint",
            "minimum": 0,
            "type": "integer"
          }
        },
        "required": [
          "body",
          "workers_count"
        ],
        "title": "IndexSkillsOutput",
        "type": "object"
      }
    },
    {
      "description": "List skills, one row per skill (id, title, type, function_id, description, bytes, modified_at). Filters: `search` (substring on id/title/description), `prefix` (worker namespace), `type`; `include_description: false` for lighter rows. Pass a row's `function_id`, not its `id`, to agent_trigger.",
      "metadata": {},
      "name": "directory::skills::list",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "include_description": {
            "default": null,
            "description": "When `false`, the response omits the first-paragraph `description` field on every row. Useful for token-light pickers that only need `id` + `title` + `type`. Default `true`.",
            "type": [
              "boolean",
              "null"
            ]
          },
          "prefix": {
            "default": null,
            "description": "Exact prefix match against `id`. Combine with `search` to scope a fuzzy match to one worker namespace, e.g. `prefix: \"sandbox/\"`.",
            "type": [
              "string",
              "null"
            ]
          },
          "search": {
            "default": null,
            "description": "Case-insensitive substring match against `id`, `title`, and (when `include_description` is true) the first body paragraph. Omitted rows are filtered out cheaply on the FsSkill { id } pass before the per-file frontmatter read, so a narrowed list is dramatically cheaper for the caller than the unfiltered one.",
            "type": [
              "string",
              "null"
            ]
          },
          "type": {
            "default": null,
            "description": "Exact match against the frontmatter `type:` field (`index`, `how-to`, `reference`, ...). `null` for entries with no frontmatter `type:`.",
            "type": [
              "string",
              "null"
            ]
          }
        },
        "title": "ListSkillsInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "definitions": {
          "SkillEntry": {
            "properties": {
              "bytes": {
                "format": "uint",
                "minimum": 0,
                "type": "integer"
              },
              "description": {
                "description": "First paragraph of the body, empty when the file has only headings. Also empty when the caller passed `list { include_description: false }` for a token-light row.",
                "type": "string"
              },
              "disable_model_invocation": {
                "description": "Whether model-facing indexes should omit this skill from invocation candidates.",
                "type": "boolean"
              },
              "function_id": {
                "description": "Frontmatter `function_id:` when present — the canonical bus function id this skill documents (e.g. `sandbox::create`). The row's `id` field is the SKILL path on disk (e.g. `sandbox/skills/sandbox/create`); `function_id` is what an agent should pass to `agent_trigger`. `null` for skills that aren't 1:1 with a single function (index/reference).",
                "type": [
                  "string",
                  "null"
                ]
              },
              "id": {
                "type": "string"
              },
              "modified_at": {
                "description": "File mtime as RFC 3339 (best effort; empty if unavailable).",
                "type": "string"
              },
              "title": {
                "description": "Frontmatter `title:` when present and non-empty, otherwise the first `# H1` line in the body, otherwise the bare `id`.",
                "type": "string"
              },
              "type": {
                "description": "Frontmatter `type:` (e.g. `index`, `how-to`, `reference`). `null` when the file has no frontmatter or omits the key.",
                "type": [
                  "string",
                  "null"
                ]
              }
            },
            "required": [
              "bytes",
              "description",
              "disable_model_invocation",
              "id",
              "modified_at",
              "title"
            ],
            "type": "object"
          }
        },
        "properties": {
          "skills": {
            "items": {
              "$ref": "#/definitions/SkillEntry"
            },
            "type": "array"
          }
        },
        "required": [
          "skills"
        ],
        "title": "ListSkillsOutput",
        "type": "object"
      }
    },
    {
      "description": "Overwrite one existing skill with full-file markdown (pass back the `raw` from directory::skills::get { raw: true }, edited). Never creates files; refuses read-only system-installed skills.",
      "metadata": {
        "tool": {
          "label": "Update skill"
        }
      },
      "name": "directory::skills::update",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "content": {
            "description": "FULL new file content, frontmatter block included — the string `directory::skills::get { raw: true }` returns, edited.",
            "type": "string"
          },
          "id": {
            "description": "Skill id to overwrite (same forms directory::skills::get accepts); the file must already exist.",
            "type": "string"
          }
        },
        "required": [
          "content",
          "id"
        ],
        "title": "SkillUpdateInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "bytes": {
            "description": "Bytes written.",
            "format": "uint",
            "minimum": 0,
            "type": "integer"
          },
          "function_id": {
            "description": "Frontmatter `function_id:` of the new content, `null` when absent.",
            "type": [
              "string",
              "null"
            ]
          },
          "id": {
            "description": "The id that was updated (normalized form of the input id).",
            "type": "string"
          },
          "modified_at": {
            "description": "File mtime after the write, RFC 3339.",
            "type": "string"
          },
          "title": {
            "description": "Title resolved from the NEW content (frontmatter `title:`, then body H1, then the id) — what `list` rows will now show.",
            "type": "string"
          },
          "type": {
            "description": "Frontmatter `type:` of the new content, `null` when absent.",
            "type": [
              "string",
              "null"
            ]
          }
        },
        "required": [
          "bytes",
          "id",
          "modified_at",
          "title"
        ],
        "title": "SkillUpdateOutput",
        "type": "object"
      }
    },
    {
      "description": "Create a new system prompt at <skills_folder>/system-prompts/<name>.md from full-file markdown (non-empty frontmatter `description` required; a declared `name` must match). Rejects names or paths that already exist.",
      "metadata": {
        "tool": {
          "label": "Create system prompt"
        }
      },
      "name": "directory::system-prompts::create",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "content": {
            "description": "Full file content, frontmatter included; `description` is required and a declared `name` must match.",
            "type": "string"
          },
          "name": {
            "description": "New system prompt name, used as the file stem; same charset as listed names and not already taken.",
            "type": "string"
          }
        },
        "required": [
          "content",
          "name"
        ],
        "title": "SystemPromptCreateInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "bytes": {
            "description": "Bytes written.",
            "format": "uint",
            "minimum": 0,
            "type": "integer"
          },
          "description": {
            "description": "Description parsed from the frontmatter.",
            "type": "string"
          },
          "modified_at": {
            "description": "File mtime after the write, RFC 3339.",
            "type": "string"
          },
          "name": {
            "description": "The created system prompt's name (as requested).",
            "type": "string"
          }
        },
        "required": [
          "bytes",
          "description",
          "modified_at",
          "name"
        ],
        "title": "SystemPromptCreateOutput",
        "type": "object"
      }
    },
    {
      "description": "Permanently delete one EXISTING filesystem-backed system prompt by name. Resolves against the same merged scan as directory::system-prompts::list, removes only that prompt's markdown file, and fans out directory::system-prompts::on-change with { op: \"delete\" }.",
      "metadata": {
        "tool": {
          "label": "Delete system prompt"
        }
      },
      "name": "directory::system-prompts::delete",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "name": {
            "description": "Existing system prompt name, as returned by `directory::system-prompts::list`.",
            "type": "string"
          }
        },
        "required": [
          "name"
        ],
        "title": "SystemPromptDeleteInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "name": {
            "description": "Name of the system prompt whose file was removed.",
            "type": "string"
          }
        },
        "required": [
          "name"
        ],
        "title": "SystemPromptDeleteOutput",
        "type": "object"
      }
    },
    {
      "description": "Fetch one system prompt by name — a filesystem-backed entry, or a worker-bundled one (`builtin: true`) when no local file shadows it. Returns the raw markdown body plus name, description, and modified_at — no envelope, no templating.",
      "metadata": {},
      "name": "directory::system-prompts::get",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "name": {
            "type": "string"
          },
          "raw": {
            "default": null,
            "description": "When `true`, the response includes the full on-disk file content (frontmatter included) as `raw`, ready for `directory::system-prompts::update`.",
            "type": [
              "boolean",
              "null"
            ]
          }
        },
        "required": [
          "name"
        ],
        "title": "SystemPromptGetInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "body": {
            "type": "string"
          },
          "builtin": {
            "description": "Served from the copy bundled with the worker (no local file yet): an update creates the local file.",
            "type": "boolean"
          },
          "description": {
            "type": "string"
          },
          "modified_at": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "raw": {
            "type": [
              "string",
              "null"
            ]
          }
        },
        "required": [
          "body",
          "builtin",
          "description",
          "modified_at",
          "name"
        ],
        "title": "SystemPromptGetOutput",
        "type": "object"
      }
    },
    {
      "description": "List system prompts (name, description, modified_at) from skills_folder's `system-prompts/` plus the ones bundled with this worker (`builtin: true` until a local file shadows one).",
      "metadata": {},
      "name": "directory::system-prompts::list",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "title": "ListSystemPromptsInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "definitions": {
          "SystemPromptEntry": {
            "properties": {
              "builtin": {
                "description": "Bundled with the worker, no file behind it: editing it creates the local file (which then shadows this entry); there is nothing to delete.",
                "type": "boolean"
              },
              "description": {
                "type": "string"
              },
              "modified_at": {
                "type": "string"
              },
              "name": {
                "type": "string"
              }
            },
            "required": [
              "builtin",
              "description",
              "modified_at",
              "name"
            ],
            "type": "object"
          }
        },
        "properties": {
          "prompts": {
            "items": {
              "$ref": "#/definitions/SystemPromptEntry"
            },
            "type": "array"
          }
        },
        "required": [
          "prompts"
        ],
        "title": "ListSystemPromptsOutput",
        "type": "object"
      }
    },
    {
      "description": "Overwrite one existing system prompt with full-file markdown; the frontmatter must keep a non-empty `description`. Updating a bundled prompt (`builtin: true`) creates a local file that shadows it. Returns the effective name (frontmatter `name:` wins over the file stem).",
      "metadata": {
        "tool": {
          "label": "Update system prompt"
        }
      },
      "name": "directory::system-prompts::update",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "content": {
            "description": "Full file content, frontmatter included; `description` must stay non-empty.",
            "type": "string"
          },
          "name": {
            "description": "System prompt name to overwrite, as listed; a bundled prompt (`builtin: true`) is copied to a local file first.",
            "type": "string"
          }
        },
        "required": [
          "content",
          "name"
        ],
        "title": "SystemPromptUpdateInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "properties": {
          "bytes": {
            "description": "Bytes written.",
            "format": "uint",
            "minimum": 0,
            "type": "integer"
          },
          "description": {
            "description": "Description parsed from the new frontmatter.",
            "type": "string"
          },
          "modified_at": {
            "description": "File mtime after the write, RFC 3339.",
            "type": "string"
          },
          "name": {
            "description": "The system prompt's EFFECTIVE name after the write: the new frontmatter `name:` when declared, otherwise the file stem. Differs from the input name when the update renames the system prompt.",
            "type": "string"
          }
        },
        "required": [
          "bytes",
          "description",
          "modified_at",
          "name"
        ],
        "title": "SystemPromptUpdateOutput",
        "type": "object"
      }
    },
    {
      "description": "Serve the iii-directory worker's injected console UI assets (content function for its console:script / console:style triggers).",
      "metadata": {
        "internal": true
      },
      "name": "iii-directory::ui-content",
      "request_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "description": "Input of the content function: the console asks for one asset by path.",
        "properties": {
          "path": {
            "description": "The asset path from the trigger config (e.g. `state/page.js`).",
            "type": "string"
          }
        },
        "required": [
          "path"
        ],
        "title": "UiContentInput",
        "type": "object"
      },
      "response_schema": {
        "$schema": "http://json-schema.org/draft-07/schema#",
        "description": "Output of the content function.",
        "properties": {
          "content": {
            "description": "The asset source, verbatim.",
            "type": "string"
          },
          "content_type": {
            "description": "MIME type the console should serve the asset with.",
            "type": "string"
          }
        },
        "required": [
          "content",
          "content_type"
        ],
        "title": "UiContentResult",
        "type": "object"
      }
    }
  ],
  "triggers": [
    {
      "description": "Fires after a directory::skills::download that wrote at least one agent profile, or a directory::agents::update, create, or delete. Also fires with { op: \"external\" } when a watched agents file changes on disk outside this worker.",
      "invocation_schema": {},
      "metadata": {},
      "name": "directory::agents::on-change",
      "return_schema": {}
    },
    {
      "description": "Fires after a directory::skills::download that wrote at least one skill markdown file, or a directory::skills::update, create, or delete. Also fires with { op: \"external\" } when a watched skills root changes on disk outside this worker — including the read-only agents skills root, when that root exists at startup.",
      "invocation_schema": {},
      "metadata": {},
      "name": "directory::skills::on-change",
      "return_schema": {}
    },
    {
      "description": "Fires after a directory::skills::download that wrote at least one system prompt, or a directory::system-prompts::update, create, or delete. Also fires with { op: \"external\" } when a watched system-prompts root changes on disk outside this worker.",
      "invocation_schema": {},
      "metadata": {},
      "name": "directory::system-prompts::on-change",
      "return_schema": {}
    }
  ]
}
```
