Align skill files with the product strategy
Add the missing siGit Code Cloud Agent skill (autonomous task -> PR, per the plan), reframe siGit Code Cloud as the hosted chat + Cloud Sessions (distinct from the agent), and add a consistent product-map pointer to every skill. Keep 'session' for chat and 'run' for the agent throughout. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Seto Elkahfi committed
Jun 26, 2026 at 21:44 UTC
6a2652c5232bb1cc70c8b74f204269d92806dc2e
8 files changed
+173
-12
.agents/skills/deployment/SKILL.md
+3
-1
@@ -5,7 +5,9 @@ description: How to deploy, migrate, seed, and restart the sigit.si Rails app in
5
6
# Deploying sigit.si
7
8
-The Rails app behind `https://sigit.si` (the code + model hosting platform). Deploys happen by pushing `main` to a bare repo whose `post-receive` hook checks out the work tree and restarts Puma.
8
+> **Product map:** siGit Code (local agent) · siGit Code Cloud (hosted chat + Cloud Sessions) · siGit Code Cloud Agent (autonomous task → PR; planning). `sigit.si` is Git hosting; `code.sigit.si` is the home of siGit Code. Full taxonomy: [product-overview](../../../docs/product/product-overview.md).
9
+
10
+The Rails app behind `https://sigit.si` (Git hosting for the AI era; also serves the model library and the `/api/v1` surface the siGit Code Cloud products sign in to). Deploys happen by pushing `main` to a bare repo whose `post-receive` hook checks out the work tree and restarts Puma.
11
12
## Server facts
13
.agents/skills/design-system/SKILL.md
+2
@@ -2,3 +2,5 @@
2
name: design-system
3
description: A skill for working with the sigit.si design system.
4
---
5
+
6
+> **Product map:** siGit Code (local agent) · siGit Code Cloud (hosted chat + Cloud Sessions) · siGit Code Cloud Agent (autonomous task → PR; planning). `sigit.si` is Git hosting; `code.sigit.si` is the home of siGit Code. Full taxonomy: [product-overview](../../../docs/product/product-overview.md).
.agents/skills/local-environment/SKILL.md
+2
@@ -2,3 +2,5 @@
2
name: local-environment
3
description: A skill for working with the local environment for sigit.si
4
---
5
+
6
+> **Product map:** siGit Code (local agent) · siGit Code Cloud (hosted chat + Cloud Sessions) · siGit Code Cloud Agent (autonomous task → PR; planning). `sigit.si` is Git hosting; `code.sigit.si` is the home of siGit Code. Full taxonomy: [product-overview](../../../docs/product/product-overview.md).
.agents/skills/sigit-app/SKILL.md
+2
@@ -5,6 +5,8 @@ description: Use when working on the "siGit Code & Deploy" Tauri desktop app (re
5
6
# siGit Code & Deploy desktop app (sigit-app)
7
8
+> **Product map:** siGit Code (local agent) · siGit Code Cloud (hosted chat + Cloud Sessions) · siGit Code Cloud Agent (autonomous task → PR; planning). `sigit.si` is Git hosting; `code.sigit.si` is the home of siGit Code. Full taxonomy: [product-overview](../../../docs/product/product-overview.md).
9
+
10
`sigit-app` is the **Tauri desktop client** for siGit (repo
11
`~/Repositories/sigit-app`). It is a **public client** (a shipped binary), so the
12
public-client security rules apply — see
.agents/skills/sigit-code-cloud-agent/SKILL.md
new
+108
@@ -0,0 +1,108 @@
1
+---
2
+name: sigit-code-cloud-agent
3
+description: Reference for siGit Code Cloud Agent, the autonomous, sandboxed coding agent (task -> pull request) we are building. Use when working on the agent product surface: the AgentRun lifecycle, the AWS sandbox that runs siGit Code headless, per-run scoped tokens, the GitHostAdapter (sigit.si first, then GitHub/GitLab), or anything that turns a delegated task into a reviewed PR. Distinct from siGit Code Cloud (the hosted chat); see the sigit-code-cloud skill for that.
4
+---
5
+
6
+# siGit Code Cloud Agent
7
+
8
+**siGit Code Cloud Agent** is autonomous, sandboxed siGit Code that solves an
9
+issue or task in a Git repository and opens a pull request, working in the
10
+background like a human developer. The user delegates a task and walks away; the
11
+agent works on its own and comes back with a PR to review.
12
+
13
+Status: **planning**. The full strategy, architecture, pricing, and roadmap are in
14
+[`docs/product/sigit-code-cloud-agent-plan.md`](../../../docs/product/sigit-code-cloud-agent-plan.md).
15
+The product map (how this sits next to the other products) is in
16
+[`docs/product/product-overview.md`](../../../docs/product/product-overview.md).
17
+
18
+## Where it fits (and the naming that matters)
19
+
20
+- **siGit Code** — the local agent. The engine.
21
+- **siGit Code Cloud** — the hosted **chat** (interactive, synchronous). Its work
22
+ unit is a **session**. See the `sigit-code-cloud` skill.
23
+- **siGit Code Cloud Agent** — this. Autonomous, asynchronous. Its work unit is an
24
+ **agent run** (one delegated task -> autonomous work -> PR).
25
+
26
+Load-bearing: **"session" belongs to the chat product; the agent's unit is a
27
+"run".** Never call the agent or its runs "sessions". `/cloud/sessions` is chat
28
+history, not agent runs.
29
+
30
+## What it is and is not
31
+
32
+- **Engine:** siGit Code, run **headless** in an ephemeral **sandbox** (AWS), with
33
+ hosted inference. The agent clones the repo, edits, runs build/test, iterates,
34
+ and pushes a branch. The agent loop and tools already exist in `getsigit/sigit`;
35
+ the new work is running it headless and the orchestration around it.
36
+- **Repo target:** **sigit.si first**, then **GitHub, GitLab, and other Git
37
+ hosts**. Scope is **Git only** (no SVN, Mercurial, or other VCS). Keep clone /
38
+ branch-push / PR-open behind a `GitHostAdapter` seam from day one so the agent
39
+ is not welded to our own forge.
40
+- **Output:** a **pull request** on the target Git host (a pushed branch + review
41
+ surface). A human reviews and merges. The agent never auto-merges.
42
+- **MVP trigger (decided):** from a repo on sigit.si, the user describes a task and
43
+ the agent produces a PR. Formal issue-assignment is a fast-follow (needs an
44
+ Issues feature and the host adapters).
45
+- **Copilot analog:** the Copilot coding agent (the cloud agent), not Copilot Chat.
46
+
47
+## Architecture (two planes; inference reused)
48
+
49
+```
50
+Control plane (Rails, sigit-si)
51
+ AgentRun model (lifecycle) + controller + job
52
+ Web "Run agent" UI, live run log (SSE), diff -> PR
53
+ Mints per-run scoped tokens (git push + inference), enforces caps/metering
54
+ | RunTask (aws-sdk) ^ SSE/webhook: logs, status, diff
55
+ v |
56
+Execution plane (AWS)
57
+ Ephemeral sandbox (Fargate task v1 -> Firecracker microVM at scale)
58
+ clones repo (scoped git token) -> runs siGit Code headless
59
+ OPENAI_BASE_URL = https://sigit.si/api/v1 (per-run inference token)
60
+ edits / runs build+test -> pushes head branch -> PR via GitHostAdapter
61
+ Private subnet, egress allowlist, hard caps (wall-clock, tokens, tool calls)
62
+ | /v1/chat/completions (per-run token)
63
+ v
64
+Inference (unchanged): Api::V1::ChatCompletionsController -> OndeCloudService -> Onde Cloud
65
+ Existing entitlement gate, allowance metering, and identity masking all apply.
66
+```
67
+
68
+The agent is "just another client" of the inference endpoint siGit Code Cloud
69
+already operates, so the entitlement / metering / identity-masking path is reused
70
+unchanged. Because the agent's inference token is minted server-side per run with
71
+a budget, there is no public client holding credentials, which also closes the
72
+standing "inference token <-> Onde Cloud auth" gap for this path.
73
+
74
+## Safety (non-negotiable, because it runs code on our infra)
75
+
76
+- Per-run hard caps: wall-clock timeout, CPU/memory, inference token budget (tied
77
+ to a new `AgentUsage`), max tool calls, max sandbox lifetime.
78
+- Network **egress allowlist** (sigit.si + package registries only). The single
79
+ most important control.
80
+- Ephemeral, **scoped** credentials only; nothing long-lived in the sandbox.
81
+- Human-in-the-loop: the agent opens a PR, never auto-merges.
82
+- Per-plan concurrency caps; real cancellation tears down the sandbox.
83
+- Identity hygiene: run logs, PR titles/bodies, and errors stay neutral (same rule
84
+ as chat); never disclose the upstream model or provider.
85
+
86
+## Pricing shape
87
+
88
+Runs cost sandbox compute (Fargate per-second) **plus** inference tokens, so
89
+metering captures both (`AgentUsage`: runs, agent-seconds, tokens). Sandbox time
90
+is rounding error; price on metered inference per run. Included-run bundles per
91
+plan, mirroring `Subscription::CLOUD_ALLOWANCE`. See the plan doc for the worked
92
+model and the `[FILL FROM PHASE 0]` inputs.
93
+
94
+## Dependencies / open items
95
+
96
+- **No PRs or Issues on sigit.si yet.** A minimal PR surface is on the critical
97
+ path; v1 can ship as "pushed branch + compare view". Issues gate
98
+ issue-assignment.
99
+- **AWS is net-new infra** (VPC/IAM/NAT/egress-allowlist). No `aws-sdk` in the app
100
+ yet.
101
+- **siGit Code has no headless one-shot mode yet** (TUI or ACP only). Adding a
102
+ headless runner that drives the existing loop non-interactively and exits is the
103
+ first build step (do not start building until asked).
104
+
105
+## Status
106
+
107
+Spec and plan only. Nothing built. Do not start implementation without an explicit
108
+go-ahead; this skill is the reference for when we do.
.agents/skills/sigit-code-cloud/SKILL.md
+46
-10
@@ -1,14 +1,15 @@
1
---
2
name: sigit-code-cloud
3
-description: Reference for siGit Code Cloud, the hosted inference offering for siGit Code. Use when working on the cloud product surface: the sigit login/logout/whoami account commands, the credential store, provider/backend selection (on-device vs siGit Code Cloud vs BYO endpoint), neutral quality tiers, or the onde-cloud API behind it. Covers the Copilot/Azure layering, the decoupled InferenceBackend engine, auth via sigit.si/api/v1, and what must never leak to the client.
3
+description: Reference for siGit Code Cloud, the hosted CHAT product for siGit Code (interactive, signed-in, no local model). Use when working on the cloud chat surface: the sigit login/logout/whoami account commands, the credential store, provider/backend selection (on-device vs siGit Code Cloud vs BYO endpoint), neutral quality tiers, the persisted Cloud Sessions API, or the onde-cloud API behind it. Covers the Copilot-Chat/Azure layering, the InferenceBackend engine, auth via sigit.si/api/v1, and what must never leak to the client. The autonomous task->PR product is siGit Code Cloud Agent; see the sigit-code-cloud-agent skill.
4
---
5
6
# siGit Code Cloud
7
8
-**siGit Code Cloud** is the hosted inference offering for **siGit Code**. The
9
-product framing is deliberate:
8
+**siGit Code Cloud** is the hosted **chat** for **siGit Code**: interactive,
9
+signed-in, model in the cloud instead of on the device. The product framing is
10
+deliberate:
11
11
-- **siGit Code Cloud is the product**, like GitHub Copilot. The user signs in,
12
+- **siGit Code Cloud is the product**, like Copilot **Chat**. The user signs in,
13
picks a quality tier, and it works. They never see an API key, a base URL, or
14
the name of any model provider.
15
- **Onde Cloud is the infrastructure**, like Azure. It is the OpenAI-compatible
@@ -16,10 +17,18 @@ product framing is deliberate:
17
- **Onde Cloud, in turn, routes to upstream providers** (today Anthropic) and
18
hides them too, see the onde-cloud `router`/`anthropic` modules.
19
19
-Keep the names straight (see the `branding` skill): the product is `siGit Code`,
20
-the hosted tier is `siGit Code Cloud`, the CLI is `sigit`, the company is
21
-`smbCloud`, the inference infrastructure is `Onde Cloud` / `Onde Inference`, and
22
-the on-device Rust crate is `onde`.
20
+**This is the chat product, not the agent.** The autonomous, sandboxed
21
+task -> pull request product is **siGit Code Cloud Agent** (see the
22
+`sigit-code-cloud-agent` skill). Chat's work unit is a **session**; the agent's is
23
+a **run**. Keep them separate. Full product map:
24
+[`docs/product/product-overview.md`](../../../docs/product/product-overview.md).
25
+
26
+Keep the names straight (see the `branding` skill): the local agent is
27
+`siGit Code`, the hosted chat is `siGit Code Cloud`, the autonomous one is
28
+`siGit Code Cloud Agent`, the CLI is `sigit`, the company is `smbCloud`, the
29
+inference infrastructure is `Onde Cloud` / `Onde Inference`, and the on-device
30
+Rust crate is `onde`. `sigit.si` is Git hosting; `code.sigit.si` is the home of
31
+siGit Code.
32
33
## The layering (why it's built this way)
34
@@ -113,6 +122,30 @@ model. To use the cloud after signing in, pick a tier in `/models`.
122
`~/.config/sigit/credentials.toml` (`$SIGIT_CONFIG_DIR` override), mode `0600`,
123
holding `access_token` (+ email for display).
124
125
+## Cloud Sessions (persisted chat) and the web app
126
+
127
+siGit Code Cloud chat conversations are saved as **Cloud Sessions** (short:
128
+sessions), so they sync across signed-in surfaces and can be resumed. "Session"
129
+means a chat conversation and belongs to this product only; the agent's unit is a
130
+"run" (see `sigit-code-cloud-agent`).
131
+
132
+- **Models (sigit-si):** `CloudSession` (UUID primary key, since it appears in a
133
+ shareable URL) `has_many :cloud_messages`; `append_message!` auto-titles from
134
+ the first user turn and tracks activity. `CloudMessage` roles are
135
+ `user`/`assistant`/`system`.
136
+- **API:** `Api::V1::CloudSessionsController`, token-scoped to `current_user`, at
137
+ `path: "sessions"` (kept distinct from the auth `SessionsController`):
138
+ `GET/POST /api/v1/sessions`, `GET/PATCH/DELETE /api/v1/sessions/:id`, and
139
+ `POST /api/v1/sessions/:id/messages`.
140
+- **Streaming is unchanged:** clients still stream from `/api/v1/chat/completions`;
141
+ these endpoints only persist the transcript. The client appends the user message
142
+ on send and the assistant message when the stream finishes.
143
+- **Web app:** `sigit-app/apps/code-cloud-web` is the SvelteKit client at
144
+ **code.sigit.si**. `/cloud` is the chat; `/cloud/sessions` and
145
+ `/cloud/sessions/<uuid>` are the saved history. Same `/api/v1` surface,
146
+ same-origin in production. (Root `/` is the on-device dashboard for signed-in
147
+ users and the marketing landing for signed-out ones.)
148
+
149
## Onde Cloud side (the API the cloud tier calls)
150
151
Repo: `onde-cloud` (Rust/axum, OpenAI-compatible).
@@ -215,5 +248,8 @@ Onde Inference's — siGit pays Onde as a customer; here siGit charges its end u
248
`app_secret` in the `sigit` binary (public-client violation).
249
- Letting a persisted local model name show in the title while routing to the
250
cloud (guard with `InferenceBackend::is_remote()`).
218
-- Mixing the names: `siGit Code` (product), `siGit Code Cloud` (hosted tier),
219
- `sigit` (CLI), `smbCloud` (company), `Onde Cloud` (infrastructure).
251
+- Mixing the names: `siGit Code` (local agent), `siGit Code Cloud` (hosted chat),
252
+ `siGit Code Cloud Agent` (autonomous, task -> PR), `sigit` (CLI), `smbCloud`
253
+ (company), `Onde Cloud` (infrastructure).
254
+- Calling a chat conversation a "run", or the agent's work a "session". Chat has
255
+ **sessions**; the agent has **runs**.
.agents/skills/sigit-code/SKILL.md
+8
-1
@@ -10,6 +10,12 @@ runs over ACP in editors like Zed and as an interactive terminal TUI. The repo i
10
**public**, keep secrets, provider names, and strategy out of it (see
11
`AGENTS.md`).
12
13
+It is the **engine** for the whole family: the hosted chat (**siGit Code Cloud**)
14
+runs the same agent against cloud inference, and the autonomous **siGit Code Cloud
15
+Agent** (planning) runs it headless in a sandbox to open pull requests. `sigit.si`
16
+is Git hosting; `code.sigit.si` is the home of siGit Code. Full product map:
17
+[`docs/product/product-overview.md`](../../../docs/product/product-overview.md).
18
+
19
## Codebase map (`sigit/src`)
20
21
- `main.rs`: entry point. Routes to the account subcommands
@@ -63,7 +69,8 @@ private skill here, not in a public code comment. See `AGENTS.md`.
69
70
## Cross-references
71
66
-- `sigit-code-cloud` (this repo): the hosted inference product.
72
+- `sigit-code-cloud` (this repo): the hosted chat product (siGit Code Cloud).
73
+- `sigit-code-cloud-agent` (this repo): the autonomous task -> PR product (planning).
74
- `smbcloud-auth` (this repo): the auth service.
75
- `ai-assisted-coding` (sigit repo): the `onde` `ChatEngine` API.
76
- `agent-client-protocol` (sigit repo): ACP.
.agents/skills/smbcloud-auth/SKILL.md
+2
@@ -5,6 +5,8 @@ description: Use when working on authentication in the sigit-si Rails app — si
5
6
# smbCloud Auth in sigit-si
7
8
+> **Product map:** siGit Code (local agent) · siGit Code Cloud (hosted chat + Cloud Sessions) · siGit Code Cloud Agent (autonomous task → PR; planning). `sigit.si` is Git hosting; `code.sigit.si` is the home of siGit Code. Full taxonomy: [product-overview](../../../docs/product/product-overview.md).
9
+
10
sigit-si does **not** own user identity. It is a **platform client** (client id
11
`sigit`) that authenticates against the shared **smbCloud Auth** service. Treat
12
smbCloud Auth as the source of truth for credentials; sigit-si keeps only a thin