The tool described delete as "delete skills you created", which the code never
enforced and which does not fit how skills are made: most are written by the
user and the agent together, so who made the first call says nothing about
whether anyone minds the skill going. With the post-turn review gone there is
no case left for the agent deleting unasked, so the rule is simply: delete an
attached skill only when the user asks, whoever wrote it. Stated in the tool
description, the delete schema, and the manage-skills guidance (1.3; 1.2's
fingerprint recorded). No code gate: the request lives in the conversation, so
only the model can attest it either way.
Co-Authored-By: Claude <noreply@anthropic.com>
What
manage_skillsdescribed delete as "delete skills you created", but the code only checked that a skill was attached and not a core skill, so the agent could remove a skill on its own initiative.The first version of this PR gated delete on the
metadata.author: agentstamp, with auserRequestedflag to override it. That was dropped after discussion: skills are mostly made by the user and the agent together, so who made the first call says nothing about whether anyone minds the skill going. With the post-turn review removed (#532), there is also no case left for the agent deleting a skill unasked.The rule is now one sentence, whoever wrote the skill: delete an attached skill only when the user asks for it. It is stated in:
builtInToolDefaults.tsand the tool's own),namefield,manage-skillsguidance, bumped to 1.3, which also says never to delete on its own initiative, to tidy up or because a skill looks unused. 1.2's fingerprint (shipped in the 2.3.0 betas) is recorded as a literal so untouched copies upgrade silently.No code gate: the request lives in the conversation, so only the model can attest it, with or without a flag. Core skills stay undeletable, and a skill must still be attached. AGENTS.md is updated to match.
How I tested it
bun run check,format,lint, and the full unit suite (2004) pass, including the shipped-skill history test. The behaviour change is model-facing wording; Leo judges it live.AI assistance: Claude Code (Fable 5.1) wrote the change from Leo's brief (drop the agent/user skill distinction; the agent deletes a skill only when the user asks); Leo reviews and tests live.
Checklist
bun run check,bun run format,bun run lint, andbun run testpass locallymanifest.json: I noted that the docs site needs updating (see "Documentation" in CONTRIBUTING.md) — the skills page's delete sentence is updated in docs(skills): the agent deletes a skill only when you ask site#7