dxkit-gatelisted
Install: claude install-skill vyuh-labs/dxkit
# dxkit-gate
This skill runs the embeddable tree gate: one call in, one machine-readable
verdict out. It is the same engine as the repo guardrail pointed at a bare
directory, so the verdicts and fingerprints match what an onboarded repo
would see.
## Choosing the prior
- **Fresh tree** (default): `vyuh-dxkit gate <dir> --policy <policy.json>`.
Everything found is net-new by construction. Right for a freshly
generated or converted package.
- **Edited tree**: add `--baseline <original-dir>` to diff against the
generated original. Only findings the edit introduced can block;
pre-existing ones are grandfathered exactly like repo-mode debt.
- **Workspace / wave**: `vyuh-dxkit gate <dir> --workspace --flows <flowsDir>`
judges every immediate subdirectory as a member tree AND the composition:
unresolved cross-member calls block, routes nobody consumes warn, and a
declared flow (`*.flow.json`, flow.v1) with an unserved step blocks.
Always pass `--json` when a program (including you) reads the result; parse
the `verdict.v1` document, not the human text.
## Trust: decide it deliberately
The gate treats the tree as untrusted by default: it scans bytes but never
executes the tree's code, and the correctness floor (compile + tests) plus
command checks are skipped with a disclosed cause. Pass `--trusted` ONLY
when the user is prepared to execute the tree's own code. Ask if unclear;
do not silently add `--trusted` to make skips go away.
## Reading the verdict
- Exit 0