SKILL.md
wiki-remove
When This Skill Activates
- User wants to permanently remove a maintained vault path (not archive-for-reference).
- User explicitly requests permanent disposal of one exact raw object.
- Cleanup of stale pages that should not return via snapshot resurrection.
- User says hard delete, remove for real, stop resurrecting.
Output language
If skillwiki is available: run skillwiki lang at the start. Otherwise default to English log prose.
Pre-orientation
Read SCHEMA/index only as needed. Confirm the full vault-relative path. First classify the target as maintained content or raw/** evidence.
Probe (required)
command -v skillwiki && skillwiki remove --helpgit -C <vault> rev-parse --is-inside-work-treeandgit remote get-url origin(expect privatekarlorz/wiki/ fleetvault_remote)- Auth:
gh auth statusorgit ls-remote origin HEAD
| Result | Mode |
|---|---|
| skillwiki OK | PRIMARY |
| skillwiki fail, git/gh + private repo OK | FAILSAFE-GIT |
| neither | FAIL CLOSED — stop; never bare rm for fleet effect |
Do not auto npm install -g skillwiki in headless/goal/satellite sessions.
PRIMARY — maintained pages
- Resolve vault:
skillwiki path. - Confirm path with user.
- On a vault-sync leaf when S3 prune is intentional:
skillwiki remove <page> [vault] --remote seaweed-wiki:cloud/wiki --remote-delete --max-remote-deletes 1 --reason "<text>" Otherwise: skillwiki remove <page> [vault] --reason "<text>"
- Read JSON: expect
tombstone_pathundermeta/delete-intents/,removedset. - Commit + push via normal wiki-sync / git (tombstone + deletion must reach private
mainfor durability). - Report MODE=primary, paths, and whether remote-delete ran.
skillwiki remove must refuse every raw/** target. Do not bypass that refusal.
PRIMARY — exact raw disposal
Permanent raw disposal is exceptional and never inferred from cleanup, dedup, stale, archive, or reingest intent.
- Require an explicit user request naming one exact raw file and a reason. Refuse basenames, globs, directories, symlinks, batches, and inferred targets.
- Run
skillwiki sources dispose <exact-raw-path> [vault] --reason "<text>". - Present the preview: complete-file SHA-256, byte size, typed/other/asset inbound references, delete-intent path, recoverability statement, operation ID, and approval token.
- Only in the same attended session, after the user approves that exact preview, run the identical command with
--write --approve <token>. - The command revalidates bytes and inbound references under the managed lock, writes append-only approval/completion events plus durable delete intent, then removes the exact object.
- Scheduled/headless disposal is always refused. A stale token never authorizes changed state.
FAILSAFE-GIT steps (no skillwiki CLI)
Agent must have git (and preferably gh) access to private vault remote. This fallback is for maintained pages only. If the target is under raw/, fail closed until skillwiki sources dispose is available; never reproduce raw disposal by hand.
- Confirm path with user. Set
PATH_REL(vault-relative, no..). - Write tombstone
meta/delete-intents/<slug>.jsonwhere slug is path with/→, e.g.summaries/foo.md→summariesfoo.md.json:
{
"schema": "vault-delete-intent/v1",
"path": "PATH_REL",
"action": "remove",
"created": "ISO-8601-UTC",
"host": "SKILLWIKI_HOST_ID-or-unknown",
"actor": "agent-failsafe-git",
"reason": "user requested remove; skillwiki CLI unavailable",
"source": "failsafe-git",
"expires": null
}
- Delete local file at
PATH_REL(and index line for[[slug]]if typed page). git addtombstone + path change; commit with trailers:
Delete-Intent: PATH_REL
Delete-Source: failsafe-git
git pull --rebase origin main(or merge fallback per vault-sync ADR) thengit push origin HEAD:main. Require successful push before claiming durable success.- Optional: if
rcloneandWIKIREMOTEexist:rclone deletefile "$WIKIREMOTE/PATH_REL"(single path only). - Report
MODE=failsafe-git, commit SHA,S3_PRUNE=done|deferred.
Stop conditions
- User declines.
- FAIL CLOSED (no CLI and no private git access).
- Push to private wiki fails.
- Path invalid or under
_archive/without explicit restore/remove policy. - Raw target cannot be processed by the attended exact-target CLI flow.
Forbidden
- Bare
rm/ baregit rmwithout tombstone. - Force-push.
- Unbounded
rclone sync/ mass remote delete. - Claiming fleet delete complete without tombstone on
origin/main(and push success). - Passing raw paths to ordinary
skillwiki remove, or using FAILSAFE-GIT/bare filesystem deletion for raw evidence. - Scheduled, headless, batch, glob, directory, basename-inferred, or stale-token raw disposal.
Reversibility
Hard remove is not locally reversible from _archive. Restore requires re-authoring content and deleting the tombstone file under meta/delete-intents/, then normal push.