| name | model-first-function-flow |
| description | FlowGuard kernel for ordinary behavior/state modeling, unclear route selection, cross-route coordination, and kernel-owned internal gates. Use when no direct FlowGuard satellite clearly owns the risk or several routes must be coordinated; use the matching satellite directly when ownership is clear. |
FlowGuard Skill Kernel
Purpose
Select the smallest owning FlowGuard route and build the minimum valuable executable model for ordinary behavior/state work without becoming a monolith.
Entrypoint Scope
Route id: model_first_function_flow; role: kernel; native owner: model_first_function_flow. Decide use_flowguard, skip_with_reason, or needs_human_review through behavior_flow, argument_flow, or decision_flow.
Local Material Routing
Read references/route_index.md for the parity-checked route map and references/modeling_protocol.md as the core index; load references/modeling_core_protocol.md, references/modeling_evidence_protocol.md, references/skill_kernel_protocol.md, adoption, conformance, long-check, framework-upgrade, or invariant references only when that boundary is active.
Entrypoint Acceptance Map
- Accept ordinary modeling, unclear ownership, cross-route coordination, or kernel-owned
flowguard_self_maintenance, model_maturation_loop, risk_template_library, risk_evidence_ledger, and closure work.
- Route clear ownership directly to
flowguard-existing-model-preflight, flowguard-behavior-commitment-ledger, flowguard-architecture-reduction, flowguard-code-structure-recommendation, flowguard-contract-exhaustion-mesh, flowguard-development-process-flow, flowguard-field-lifecycle-mesh, flowguard-model-mesh, flowguard-model-miss-review, flowguard-model-test-alignment, flowguard-model-topology-hazard-review, flowguard-structure-mesh, flowguard-test-mesh, or flowguard-ui-flow-structure.
- Keep
flowguard-plan-detailing-compiler and flowguard-agent-workflow-rehearsal explicit/delegated modes owned by DevelopmentProcessFlow.
Use When
- Use when behavior/state/order/retry/side-effect risk needs
Input x State -> Set(Output x State) modeling, the correct satellite is unclear, or multiple route outputs must be coordinated.
Do Not Use When
- Do not force the kernel before a clear peer satellite, use it for trivial copy/format/direct-command work, or treat check-engine helpers as independently triggerable Codex skills.
Required Workflow
- Decide applicability/lens, verify adoption, run the lightweight commitment/model lookup for non-trivial existing-system work, select or report the primary behavior plane, and name the protected error class and claim boundary.
- Build/update the smallest faithful finite model with state, side effects, completion evidence, invariants, and a representative known-bad path.
- Run the formal check plan, inspect counterexamples, revise the model/architecture, and record template harvest closure.
- Route finite bad cases, commitments, fields, alignment, meshes, topology, UI, process freshness, conformance, and risk evidence only where triggered. Specification-provider task/evidence reconciliation belongs inside DevelopmentProcessFlow; do not invent another task engine or project provider fields into product UI rules.
- Preserve checked/unchecked/blocked/scoped evidence and close only at the requested current scope.
Hard Gates
- Model-purpose gate: before build/change, freeze this instance's task-specific failure(s) and boundary; then bind candidate plus native good/bad-per-failure/oracle/current evidence. Reusable types are not fixed-purpose; no mode/fallback; SkillGuard only supervises FlowGuard-declared checks.
- Verify the real FlowGuard check engine and AGENTS.md managed record; if import fails, connect the real toolchain or report blocked/partial and never create a fake mini-framework.
- Represent every modeled block as
Input x State -> Set(Output x State); do not replace executable modeling with prose or weaken hard invariants to pass.
- Default replacement disposes old fields/wrappers/aliases/alternate success paths; broad behavior needs a current Behavior Commitment Ledger and PPA for path-sensitive rows.
- The shared ledger has three owner planes (
product_runtime, agent_operation, development_process). Same-plane hits may guide the owning route; cross-plane rows remain typed context and never silently become instructions or merged owners.
- Do not impose a universal model execution gate on trivial actions. Escalate lightweight recall to route-native modeling when a non-trivial match, concrete Model Miss, recurring/high-risk operation, or broad claim makes it relevant.
- Broad model/code/test claims bind obligation ids, owner code contract ids, and current external-contract evidence for the same behavior.
- Missing, stale, skipped,
not_run, progress_only, scoped, or pass_with_gaps evidence cannot support broad done, full-governance, release, archive, or publication claims.
- Long-check progress is liveness only; UI/payload claims need real-surface proof; new/deepened models require template harvest closure.
- OpenSpec/Spec Kit retain native requirement, task, verification, and archive authority. FlowGuard may read one root-bounded work package, reconcile obligations, order dependency gates, and verify immutable receipts, but it cannot create a parallel provider state or treat a checkbox as evidence.
- FlowGuard diagram intent gate: preserve active model semantics. Do not flatten these into a generic flowchart; state/process/UI/SourceGuard/TraceGuard/WorldGuard/LogicGuard diagrams keep their own edge meanings, without LogicGuard being collapsed into FlowGuard control flow.
Output Requirements
- Return
evidence, failures, blockers, skipped_checks, residual_risk, claim_boundary, and typed_next_actions, plus route decision, model snapshot, counterexamples, and current validation status.
SkillGuard Maintenance
- Edit
.skillguard/contract-source.json, route registry, or direct references first, then regenerate derived contracts; SkillGuard validates native-integrated ownership and cannot define a parallel FlowGuard controller or manufacture evidence.