Align skill files with the product strategy

Add the missing siGit Code Cloud Agent skill (autonomous task -> PR, per the plan), reframe siGit Code Cloud as the hosted chat + Cloud Sessions (distinct from the agent), and add a consistent product-map pointer to every skill. Keep 'session' for chat and 'run' for the agent throughout. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

Seto Elkahfi committed Jun 26, 2026 at 21:44 UTC 6a2652c5232bb1cc70c8b74f204269d92806dc2e
8 files changed +173 -12
.agents/skills/deployment/SKILL.md
+3 -1
@@ -5,7 +5,9 @@ description: How to deploy, migrate, seed, and restart the sigit.si Rails app in
5
6 # Deploying sigit.si
7
8 -The Rails app behind `https://sigit.si` (the code + model hosting platform). Deploys happen by pushing `main` to a bare repo whose `post-receive` hook checks out the work tree and restarts Puma.
8 +> **Product map:** siGit Code (local agent) · siGit Code Cloud (hosted chat + Cloud Sessions) · siGit Code Cloud Agent (autonomous task → PR; planning). `sigit.si` is Git hosting; `code.sigit.si` is the home of siGit Code. Full taxonomy: [product-overview](../../../docs/product/product-overview.md).
9 +
10 +The Rails app behind `https://sigit.si` (Git hosting for the AI era; also serves the model library and the `/api/v1` surface the siGit Code Cloud products sign in to). Deploys happen by pushing `main` to a bare repo whose `post-receive` hook checks out the work tree and restarts Puma.
11
12 ## Server facts
13
.agents/skills/design-system/SKILL.md
+2
@@ -2,3 +2,5 @@
2 name: design-system
3 description: A skill for working with the sigit.si design system.
4 ---
5 +
6 +> **Product map:** siGit Code (local agent) · siGit Code Cloud (hosted chat + Cloud Sessions) · siGit Code Cloud Agent (autonomous task → PR; planning). `sigit.si` is Git hosting; `code.sigit.si` is the home of siGit Code. Full taxonomy: [product-overview](../../../docs/product/product-overview.md).
.agents/skills/local-environment/SKILL.md
+2
@@ -2,3 +2,5 @@
2 name: local-environment
3 description: A skill for working with the local environment for sigit.si
4 ---
5 +
6 +> **Product map:** siGit Code (local agent) · siGit Code Cloud (hosted chat + Cloud Sessions) · siGit Code Cloud Agent (autonomous task → PR; planning). `sigit.si` is Git hosting; `code.sigit.si` is the home of siGit Code. Full taxonomy: [product-overview](../../../docs/product/product-overview.md).
.agents/skills/sigit-app/SKILL.md
+2
@@ -5,6 +5,8 @@ description: Use when working on the "siGit Code & Deploy" Tauri desktop app (re
5
6 # siGit Code & Deploy desktop app (sigit-app)
7
8 +> **Product map:** siGit Code (local agent) · siGit Code Cloud (hosted chat + Cloud Sessions) · siGit Code Cloud Agent (autonomous task → PR; planning). `sigit.si` is Git hosting; `code.sigit.si` is the home of siGit Code. Full taxonomy: [product-overview](../../../docs/product/product-overview.md).
9 +
10 `sigit-app` is the **Tauri desktop client** for siGit (repo
11 `~/Repositories/sigit-app`). It is a **public client** (a shipped binary), so the
12 public-client security rules apply — see
.agents/skills/sigit-code-cloud-agent/SKILL.md new
+108
@@ -0,0 +1,108 @@
1 +---
2 +name: sigit-code-cloud-agent
3 +description: Reference for siGit Code Cloud Agent, the autonomous, sandboxed coding agent (task -> pull request) we are building. Use when working on the agent product surface: the AgentRun lifecycle, the AWS sandbox that runs siGit Code headless, per-run scoped tokens, the GitHostAdapter (sigit.si first, then GitHub/GitLab), or anything that turns a delegated task into a reviewed PR. Distinct from siGit Code Cloud (the hosted chat); see the sigit-code-cloud skill for that.
4 +---
5 +
6 +# siGit Code Cloud Agent
7 +
8 +**siGit Code Cloud Agent** is autonomous, sandboxed siGit Code that solves an
9 +issue or task in a Git repository and opens a pull request, working in the
10 +background like a human developer. The user delegates a task and walks away; the
11 +agent works on its own and comes back with a PR to review.
12 +
13 +Status: **planning**. The full strategy, architecture, pricing, and roadmap are in
14 +[`docs/product/sigit-code-cloud-agent-plan.md`](../../../docs/product/sigit-code-cloud-agent-plan.md).
15 +The product map (how this sits next to the other products) is in
16 +[`docs/product/product-overview.md`](../../../docs/product/product-overview.md).
17 +
18 +## Where it fits (and the naming that matters)
19 +
20 +- **siGit Code** — the local agent. The engine.
21 +- **siGit Code Cloud** — the hosted **chat** (interactive, synchronous). Its work
22 + unit is a **session**. See the `sigit-code-cloud` skill.
23 +- **siGit Code Cloud Agent** — this. Autonomous, asynchronous. Its work unit is an
24 + **agent run** (one delegated task -> autonomous work -> PR).
25 +
26 +Load-bearing: **"session" belongs to the chat product; the agent's unit is a
27 +"run".** Never call the agent or its runs "sessions". `/cloud/sessions` is chat
28 +history, not agent runs.
29 +
30 +## What it is and is not
31 +
32 +- **Engine:** siGit Code, run **headless** in an ephemeral **sandbox** (AWS), with
33 + hosted inference. The agent clones the repo, edits, runs build/test, iterates,
34 + and pushes a branch. The agent loop and tools already exist in `getsigit/sigit`;
35 + the new work is running it headless and the orchestration around it.
36 +- **Repo target:** **sigit.si first**, then **GitHub, GitLab, and other Git
37 + hosts**. Scope is **Git only** (no SVN, Mercurial, or other VCS). Keep clone /
38 + branch-push / PR-open behind a `GitHostAdapter` seam from day one so the agent
39 + is not welded to our own forge.
40 +- **Output:** a **pull request** on the target Git host (a pushed branch + review
41 + surface). A human reviews and merges. The agent never auto-merges.
42 +- **MVP trigger (decided):** from a repo on sigit.si, the user describes a task and
43 + the agent produces a PR. Formal issue-assignment is a fast-follow (needs an
44 + Issues feature and the host adapters).
45 +- **Copilot analog:** the Copilot coding agent (the cloud agent), not Copilot Chat.
46 +
47 +## Architecture (two planes; inference reused)
48 +
49 +```
50 +Control plane (Rails, sigit-si)
51 + AgentRun model (lifecycle) + controller + job
52 + Web "Run agent" UI, live run log (SSE), diff -> PR
53 + Mints per-run scoped tokens (git push + inference), enforces caps/metering
54 + | RunTask (aws-sdk) ^ SSE/webhook: logs, status, diff
55 + v |
56 +Execution plane (AWS)
57 + Ephemeral sandbox (Fargate task v1 -> Firecracker microVM at scale)
58 + clones repo (scoped git token) -> runs siGit Code headless
59 + OPENAI_BASE_URL = https://sigit.si/api/v1 (per-run inference token)
60 + edits / runs build+test -> pushes head branch -> PR via GitHostAdapter
61 + Private subnet, egress allowlist, hard caps (wall-clock, tokens, tool calls)
62 + | /v1/chat/completions (per-run token)
63 + v
64 +Inference (unchanged): Api::V1::ChatCompletionsController -> OndeCloudService -> Onde Cloud
65 + Existing entitlement gate, allowance metering, and identity masking all apply.
66 +```
67 +
68 +The agent is "just another client" of the inference endpoint siGit Code Cloud
69 +already operates, so the entitlement / metering / identity-masking path is reused
70 +unchanged. Because the agent's inference token is minted server-side per run with
71 +a budget, there is no public client holding credentials, which also closes the
72 +standing "inference token <-> Onde Cloud auth" gap for this path.
73 +
74 +## Safety (non-negotiable, because it runs code on our infra)
75 +
76 +- Per-run hard caps: wall-clock timeout, CPU/memory, inference token budget (tied
77 + to a new `AgentUsage`), max tool calls, max sandbox lifetime.
78 +- Network **egress allowlist** (sigit.si + package registries only). The single
79 + most important control.
80 +- Ephemeral, **scoped** credentials only; nothing long-lived in the sandbox.
81 +- Human-in-the-loop: the agent opens a PR, never auto-merges.
82 +- Per-plan concurrency caps; real cancellation tears down the sandbox.
83 +- Identity hygiene: run logs, PR titles/bodies, and errors stay neutral (same rule
84 + as chat); never disclose the upstream model or provider.
85 +
86 +## Pricing shape
87 +
88 +Runs cost sandbox compute (Fargate per-second) **plus** inference tokens, so
89 +metering captures both (`AgentUsage`: runs, agent-seconds, tokens). Sandbox time
90 +is rounding error; price on metered inference per run. Included-run bundles per
91 +plan, mirroring `Subscription::CLOUD_ALLOWANCE`. See the plan doc for the worked
92 +model and the `[FILL FROM PHASE 0]` inputs.
93 +
94 +## Dependencies / open items
95 +
96 +- **No PRs or Issues on sigit.si yet.** A minimal PR surface is on the critical
97 + path; v1 can ship as "pushed branch + compare view". Issues gate
98 + issue-assignment.
99 +- **AWS is net-new infra** (VPC/IAM/NAT/egress-allowlist). No `aws-sdk` in the app
100 + yet.
101 +- **siGit Code has no headless one-shot mode yet** (TUI or ACP only). Adding a
102 + headless runner that drives the existing loop non-interactively and exits is the
103 + first build step (do not start building until asked).
104 +
105 +## Status
106 +
107 +Spec and plan only. Nothing built. Do not start implementation without an explicit
108 +go-ahead; this skill is the reference for when we do.
.agents/skills/sigit-code-cloud/SKILL.md
+46 -10
@@ -1,14 +1,15 @@
1 ---
2 name: sigit-code-cloud
3 -description: Reference for siGit Code Cloud, the hosted inference offering for siGit Code. Use when working on the cloud product surface: the sigit login/logout/whoami account commands, the credential store, provider/backend selection (on-device vs siGit Code Cloud vs BYO endpoint), neutral quality tiers, or the onde-cloud API behind it. Covers the Copilot/Azure layering, the decoupled InferenceBackend engine, auth via sigit.si/api/v1, and what must never leak to the client.
3 +description: Reference for siGit Code Cloud, the hosted CHAT product for siGit Code (interactive, signed-in, no local model). Use when working on the cloud chat surface: the sigit login/logout/whoami account commands, the credential store, provider/backend selection (on-device vs siGit Code Cloud vs BYO endpoint), neutral quality tiers, the persisted Cloud Sessions API, or the onde-cloud API behind it. Covers the Copilot-Chat/Azure layering, the InferenceBackend engine, auth via sigit.si/api/v1, and what must never leak to the client. The autonomous task->PR product is siGit Code Cloud Agent; see the sigit-code-cloud-agent skill.
4 ---
5
6 # siGit Code Cloud
7
8 -**siGit Code Cloud** is the hosted inference offering for **siGit Code**. The
9 -product framing is deliberate:
8 +**siGit Code Cloud** is the hosted **chat** for **siGit Code**: interactive,
9 +signed-in, model in the cloud instead of on the device. The product framing is
10 +deliberate:
11
11 -- **siGit Code Cloud is the product**, like GitHub Copilot. The user signs in,
12 +- **siGit Code Cloud is the product**, like Copilot **Chat**. The user signs in,
13 picks a quality tier, and it works. They never see an API key, a base URL, or
14 the name of any model provider.
15 - **Onde Cloud is the infrastructure**, like Azure. It is the OpenAI-compatible
@@ -16,10 +17,18 @@ product framing is deliberate:
17 - **Onde Cloud, in turn, routes to upstream providers** (today Anthropic) and
18 hides them too, see the onde-cloud `router`/`anthropic` modules.
19
19 -Keep the names straight (see the `branding` skill): the product is `siGit Code`,
20 -the hosted tier is `siGit Code Cloud`, the CLI is `sigit`, the company is
21 -`smbCloud`, the inference infrastructure is `Onde Cloud` / `Onde Inference`, and
22 -the on-device Rust crate is `onde`.
20 +**This is the chat product, not the agent.** The autonomous, sandboxed
21 +task -> pull request product is **siGit Code Cloud Agent** (see the
22 +`sigit-code-cloud-agent` skill). Chat's work unit is a **session**; the agent's is
23 +a **run**. Keep them separate. Full product map:
24 +[`docs/product/product-overview.md`](../../../docs/product/product-overview.md).
25 +
26 +Keep the names straight (see the `branding` skill): the local agent is
27 +`siGit Code`, the hosted chat is `siGit Code Cloud`, the autonomous one is
28 +`siGit Code Cloud Agent`, the CLI is `sigit`, the company is `smbCloud`, the
29 +inference infrastructure is `Onde Cloud` / `Onde Inference`, and the on-device
30 +Rust crate is `onde`. `sigit.si` is Git hosting; `code.sigit.si` is the home of
31 +siGit Code.
32
33 ## The layering (why it's built this way)
34
@@ -113,6 +122,30 @@ model. To use the cloud after signing in, pick a tier in `/models`.
122 `~/.config/sigit/credentials.toml` (`$SIGIT_CONFIG_DIR` override), mode `0600`,
123 holding `access_token` (+ email for display).
124
125 +## Cloud Sessions (persisted chat) and the web app
126 +
127 +siGit Code Cloud chat conversations are saved as **Cloud Sessions** (short:
128 +sessions), so they sync across signed-in surfaces and can be resumed. "Session"
129 +means a chat conversation and belongs to this product only; the agent's unit is a
130 +"run" (see `sigit-code-cloud-agent`).
131 +
132 +- **Models (sigit-si):** `CloudSession` (UUID primary key, since it appears in a
133 + shareable URL) `has_many :cloud_messages`; `append_message!` auto-titles from
134 + the first user turn and tracks activity. `CloudMessage` roles are
135 + `user`/`assistant`/`system`.
136 +- **API:** `Api::V1::CloudSessionsController`, token-scoped to `current_user`, at
137 + `path: "sessions"` (kept distinct from the auth `SessionsController`):
138 + `GET/POST /api/v1/sessions`, `GET/PATCH/DELETE /api/v1/sessions/:id`, and
139 + `POST /api/v1/sessions/:id/messages`.
140 +- **Streaming is unchanged:** clients still stream from `/api/v1/chat/completions`;
141 + these endpoints only persist the transcript. The client appends the user message
142 + on send and the assistant message when the stream finishes.
143 +- **Web app:** `sigit-app/apps/code-cloud-web` is the SvelteKit client at
144 + **code.sigit.si**. `/cloud` is the chat; `/cloud/sessions` and
145 + `/cloud/sessions/<uuid>` are the saved history. Same `/api/v1` surface,
146 + same-origin in production. (Root `/` is the on-device dashboard for signed-in
147 + users and the marketing landing for signed-out ones.)
148 +
149 ## Onde Cloud side (the API the cloud tier calls)
150
151 Repo: `onde-cloud` (Rust/axum, OpenAI-compatible).
@@ -215,5 +248,8 @@ Onde Inference's — siGit pays Onde as a customer; here siGit charges its end u
248 `app_secret` in the `sigit` binary (public-client violation).
249 - Letting a persisted local model name show in the title while routing to the
250 cloud (guard with `InferenceBackend::is_remote()`).
218 -- Mixing the names: `siGit Code` (product), `siGit Code Cloud` (hosted tier),
219 - `sigit` (CLI), `smbCloud` (company), `Onde Cloud` (infrastructure).
251 +- Mixing the names: `siGit Code` (local agent), `siGit Code Cloud` (hosted chat),
252 + `siGit Code Cloud Agent` (autonomous, task -> PR), `sigit` (CLI), `smbCloud`
253 + (company), `Onde Cloud` (infrastructure).
254 +- Calling a chat conversation a "run", or the agent's work a "session". Chat has
255 + **sessions**; the agent has **runs**.
.agents/skills/sigit-code/SKILL.md
+8 -1
@@ -10,6 +10,12 @@ runs over ACP in editors like Zed and as an interactive terminal TUI. The repo i
10 **public**, keep secrets, provider names, and strategy out of it (see
11 `AGENTS.md`).
12
13 +It is the **engine** for the whole family: the hosted chat (**siGit Code Cloud**)
14 +runs the same agent against cloud inference, and the autonomous **siGit Code Cloud
15 +Agent** (planning) runs it headless in a sandbox to open pull requests. `sigit.si`
16 +is Git hosting; `code.sigit.si` is the home of siGit Code. Full product map:
17 +[`docs/product/product-overview.md`](../../../docs/product/product-overview.md).
18 +
19 ## Codebase map (`sigit/src`)
20
21 - `main.rs`: entry point. Routes to the account subcommands
@@ -63,7 +69,8 @@ private skill here, not in a public code comment. See `AGENTS.md`.
69
70 ## Cross-references
71
66 -- `sigit-code-cloud` (this repo): the hosted inference product.
72 +- `sigit-code-cloud` (this repo): the hosted chat product (siGit Code Cloud).
73 +- `sigit-code-cloud-agent` (this repo): the autonomous task -> PR product (planning).
74 - `smbcloud-auth` (this repo): the auth service.
75 - `ai-assisted-coding` (sigit repo): the `onde` `ChatEngine` API.
76 - `agent-client-protocol` (sigit repo): ACP.
.agents/skills/smbcloud-auth/SKILL.md
+2
@@ -5,6 +5,8 @@ description: Use when working on authentication in the sigit-si Rails app — si
5
6 # smbCloud Auth in sigit-si
7
8 +> **Product map:** siGit Code (local agent) · siGit Code Cloud (hosted chat + Cloud Sessions) · siGit Code Cloud Agent (autonomous task → PR; planning). `sigit.si` is Git hosting; `code.sigit.si` is the home of siGit Code. Full taxonomy: [product-overview](../../../docs/product/product-overview.md).
9 +
10 sigit-si does **not** own user identity. It is a **platform client** (client id
11 `sigit`) that authenticates against the shared **smbCloud Auth** service. Treat
12 smbCloud Auth as the source of truth for credentials; sigit-si keeps only a thin