Skip to content

Composition installer release

This directory records the immutable publication identities for the installable Composition Agent Skill. It is a release-publication surface, not the installed skill's runtime authority.

Provider release record versus consumer use

This record serves two related but distinct purposes. For Composition authority maintainers, it identifies the provider release: the immutable installer bytes, the distributed Skill source, and the selected Composer toolchain. For consumers, it supplies the verified bootstrap material for installing or replacing the Composition Skill. It does not define a consumer product release, and it does not replace the consumer Composition guide, the product release guide, or Composer update/upgrade behavior.

composition-installer.json remains the machine-readable authority. This README explains that descriptor and the verification boundary; it must not become a second descriptor or a mutable release channel.

The stable publication deliberately separates three full-SHA identities:

  • installer script revision c328fbe2bf733cf32cea54c1054570a94afa693a — the remotely executed stdlib-only bootstrap script;
  • skill source revision 745ccc6e00a96c602f9edbb6edc4bca530429539 — the skills/composition/ tree downloaded and atomically installed by that bootstrap script; and
  • stable Composition toolchain revision f46595bcee2b0cdbc204fca052b2b431eefae3b5 — the exact Composer source selected by the installed skill's runtime-manifest.json.

The published installer bytes are additionally pinned by SHA-256: d5422e28b29aaf015c14ffe4d17ae4a0478e0d108a98c951f978f7016f90e607.

composition-installer.json is the machine-readable authority for these identities and the installer digest. scripts/verify_composition_skill_installer_release.py verifies the descriptor against repository history, the pinned installer bytes, the complete runnable Skill distribution, the complete snapshot-aware toolchain surface, the runtime-lock digest, and strict ancestry between the three immutable revisions.

The stable toolchain now includes every first-class recipe published by this Composition authority, including skill, website, and webapp. Stable consumers therefore use the normal runner path for all three product identities; a Website does not require a walkthrough-specific revision override.

This skill-source release includes the read-only doctor command. For normal consumers, doctor reports CPython support, the selected immutable revision, Git as not required, ephemeral full-SHA source acquisition, and persistent validated runtime-cache readiness without acquiring source/runtime state from the network. doctor is diagnostic only and does not replace Composition validation or guarantee later GitHub/package-source availability.

Agent bootstrap

A coding agent should treat composition-installer.json as data rather than assuming a particular download utility. It may use any available HTTPS transport to fetch the installer at the descriptor's immutable repository/revision/path, but it must verify the downloaded bytes against installer.sha256 before execution. Save the verified installer to a temporary file, execute it with the supported CPython interpreter in isolated mode (python -I <installer> <target>), and remove the temporary installer afterward. A digest mismatch must terminate before the installer bytes are written or executed. Neither curl nor wget nor a templates clone is required by this contract.

The target may be a persistent Agent Skills directory when the host exposes one, or an OS temporary directory for a transient invocation. In either case the installed Composition Skill remains the repository-facing interface and owns doctor, provenance, inspect, plan, apply, and validate.

Verified installation

For interactive users, use the same verify-before-execute invariant. The following POSIX-shell command needs only a supported CPython interpreter. It downloads the immutable installer, verifies the published SHA-256 in memory, prints the verified digest as audit evidence, and only then writes and executes a temporary installer in isolated mode:

python -I -c '
import hashlib
import pathlib
import subprocess
import sys
import tempfile
import urllib.request

url = "https://raw.githubusercontent.com/TakashiSasaki/templates/c328fbe2bf733cf32cea54c1054570a94afa693a/scripts/install_composition_skill.py"
expected = "d5422e28b29aaf015c14ffe4d17ae4a0478e0d108a98c951f978f7016f90e607"
data = urllib.request.urlopen(url, timeout=30).read()
actual = hashlib.sha256(data).hexdigest()
if actual != expected:
    raise SystemExit(f"installer SHA-256 mismatch: expected {expected}, got {actual}")
print(f"Verified Composition installer SHA-256: {actual}")
with tempfile.NamedTemporaryFile(suffix=".py", delete=False) as handle:
    handle.write(data)
    installer = pathlib.Path(handle.name)
try:
    subprocess.run([sys.executable, "-I", str(installer), *sys.argv[1:]], check=True)
finally:
    installer.unlink(missing_ok=True)
' /path/to/agent-skills/composition

For an existing Composition skill installation, append --replace. Replacement remains guarded by the local skill installer and is accepted only when the destination is already identified as this skill. Do not replace this command with exec(urlopen(...).read()): pinning a URL to a full commit SHA does not by itself verify that the bytes received match the published installer digest.

The commands and bootstrap protocol above never execute the mutable composition branch or a tag and do not require a templates clone. Normal Composer invocations obtain the selected full-SHA GitHub archive into an OS temporary directory, verify the snapshot inventory while executing, and remove the source snapshot afterward. The validated Python runtime cache remains a separate persistent performance optimization.