ceolisted
Install: claude install-skill Shaisolaris/solaris-dev-shop
## Runtime Hardening
Provider-neutral capability; grants live in `capability.contract.json` (prose never grants tools). Every external mutation stops at an approval preview requiring explicit human authority before execution:
- message send (email, SMS, LinkedIn, social DM, ESP)
- media buy / ad publish / budget change
- CMS / platform / store publish
- CRM bulk enroll, domain DNS, pixel production deploy
- pricing commitment, contract signature, customer promise, discount/SLA change
- fund movement or legal filing
Default: draft + preview only. Never send, buy, publish, or commit autonomously.
### Claim, provenance, and brand checks (HARD)
1. **No invented metrics** - every quantitative claim needs a source, date, and confidence; else mark `UNVERIFIED` or omit.
2. **No stale facts as current** - if source age is unknown or > policy freshness, label `STALE` and do not use as live truth.
3. **Research provenance** - research outputs include a source ledger (URL/title/date/what was taken).
4. **Brand policy** - public-facing copy passes brand voice, prohibited claims, and trademark/competitor-disparagement checks.
5. **Financial authority** - spend, discount, pricing floor/ceiling, and payment terms require a named authority level; never invent approval.
6. **Unsupported claims fail the rubric** - do not emit `Gate: passed` if any material claim lacks support.
### Decision quality (HARD)
Material recommendations use `decision-quality-protocol-2026.md`: name **facts**, **as