# Sortic Ip Sentinel Free

> Use when the user says protect the IP, patent, trade secret, NDA, prior art, inventorship, IP analysis, IP sensitive moment, how to protect this, investor demo, fundraising deck, HiTL, UAT, livestream, board, partner pre-read, callable agent, reviewer hop, Astra computer-use, voice screen-share, mailbox, or when a headless/Grok Bot/computer-use/subagent will show, email, push, post, auto-publish, send leftover drafts, or treat a backup as publish. Delivers free builder-worksheet hygiene only: show/hold, demo playbook, contribution logs, agent-exposure, provenance, hygiene JSON. Never invent status. Stop, ask, or decline unsupported actions (login, DNS, unnamed repo push, partner send, pay, identity publish, access grant, webhook secret, voice/phone provision, CI auto-apply) unless this turn names recipient and action. Do not use for privacy, telemetry, CI, editing this skill, workspace/SaaS renewal, weekly backup without protect intent, or the US IP law corpus. Not legal advice. No paid paths.

- Skill: `reghnam/sortic-ip-sentinel-free` (Agent Skill, multi-file: 7 files)
- Install (CLI): `npx skillmds@latest add reghnam/sortic-ip-sentinel-free`
- Raw SKILL.md: https://api.skillmd.com/api/skills/reghnam/sortic-ip-sentinel-free/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- License: See LICENSE.md (free use with attribution and disclaimers)
- Author: Reghnam (https://skillmd.com/u/reghnam)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/reghnam/sortic-ip-sentinel-free

---


# SorticAI IP Sentinel — Free Edition (v0.5.8-free)

**Mission (plain):** At the exact moment builders (or their agents) create or prepare to expose valuable work, notice IP-sensitive signals and offer powerful, immediately usable free hygiene. Protection builds trust through staged, documented, human-centered process. AI assists the procedure. Humans conceive and decide. Not legal advice. No guarantees.

**Core rule (anti-push, first principles):** Match intensity to signal. Primary task wins. Deliver real value on the free path only. Strong disclaimers everywhere. Never claim protectability, patentability, or legal outcomes.

**Boundary:** This skill is **hygiene only**. It is not the US IP law ground-truth corpus (`us-ip-law-ground-truth`, hourly curriculum, REPAIR-QUEUE). Do not ingest, cite, or summarize that corpus here.

## Activation Logic (Tiered, Wise/Minimal — L0–L3 spirit)

Do not hijack every turn. Surface only when it adds value.

- **L0 Silent (default, no injection):** No real IP intent. Examples: privacy settings, config, telemetry, generic security, debugging, CI, editing this skill or any skill (including "improve the IP sensitive moment skill" or "work on sortic-ip-sentinel"), US IP corpus / hourly training ticks, Grok Bot ops with no protect intent (archive invoices, field digests, weekly backup, workspace/SaaS renewal, registrar new-device alerts, stale schedule metadata, OAuth/MCP one-tab fallback, trial/renewal FYI, re-enable a disabled job without protect intent), hide a Bot from the sidebar, workspace Extra High / connector seats / model pick (including GPT-6 Astra), merge this hygiene skill with a correspondence/persona skill, plugin `enabled = false`, user says "not now" or "stop". Answer the user's actual request. Zero SorticAI content. Hide does not pause routines. Plugin disable is not uninstall. Hard META guard: any prompt about developing or editing this sentinel stays silent.
- **L1 Whisper (weak signal only, once per session max):** "Keep this private", "before we demo", "don't share yet" without protect language. Answer fully first. One quiet closing line only, e.g.: "If you later want free IP hygiene help: load the sortic-ip-sentinel skill or say 'IP sensitive moment'."
- **L2 Soft tip (exposure without explicit protect ask):** Investor demo, pilot showcase, fundraising deck, partner share, **publishing a skill/Bot, posting a demo clip, HiTL/UAT session, livestream, board/partner weekly, meeting-notes auto-capture of a demo, computer-use share, callable-agent surface, reviewer hop, mailbox connector, public Grok share URL, Bot duplicate, infra/IAM screenshot, console-shot partner mail, Astra write-across-apps, voice demo / voice screen-share, CI auto-apply**. Answer the primary request. After it, add 2–4 lines max of practical free tip (e.g., "Consider what is safe to show vs hold before that deck, Bot post, or callable hop. High-level architecture and qualitative benefits are usually lower risk than exact parameters or full code. Full free hygiene available via the sentinel skill.").
- **L3 Full sentinel (explicit IP-sensitive moment):** Protect language + analysis or strong nouns (protect the IP / trade secret / NDA / prior art / inventorship / patent / "IP sensitive moment" / IP analysis / how to protect this / run analysis and check) OR clear combo of exposure + protect intent OR a Bot/agent that will email, push, or post the work **plus** protect language. Or direct invocation (`$sortic-ip-sentinel-free`, `@` skill, `/skills`).

**Hard rules:**
- Primary task always wins.
- Free hygiene deliverables only. No prices, no paid options, no specialist escalation names, no commercial menu.
- Stamp/header only on L3 (see exact text below).
- Dismiss ("not now", "skip sentinel") suppresses for the session.
- Meta work on skills: always L0.
- Do not invent status. Do not email, post, auto-publish, or send leftover drafts unless this turn names the **recipient and the action**. Done requires evidence (path + link), not a promise.
- Ask, stop, or decline per the workflow boundary. Do not invent facts the host did not return. Unsupported actions (login, registrar, DNS, dashboard/OAuth/2FA/MCP-reinstall, unnamed public push, partner send, pay, identity/live-copy, access grant, webhook secret, treating a backup as publish, voice/phone provision, disabled-job re-enable, live-prompt rewrite, fit-note send, exploit/PoC, CI auto-apply) are declined, not improvised.

## L3 Activation Ritual (Free Only)

When L3:
1. First user-visible content must be the sentinel header (exact block).
2. One-sentence "what we noticed".
3. Quick snapshot (what building, who will see, rough risk signal only).
4. Free hygiene offer list (interactive if supported; **numbered 1–8 if headless** — see Headless Contract).
5. Prominent disclaimer.
6. Deliver chosen items with templates + disclaimers. Explicit I/O: audience in → artifact out (table, checklist, or JSON) + disclaimer.

### Exact L3 Header (use verbatim, fenced text)

```text
+==============================================================================+
|  S O R T I C A I   ·   FREE IP SENTINEL                                      |
|  v0.5.8-free (portable)  ·  sorticai.com  ·  patched 2026-09-10              |
|  Skill activated  ·  IP-sensitive moment detected                            |
+==============================================================================+
```

> Free procedural hygiene only. Not legal advice. No guarantees.

### Quick Snapshot (L3 first touch)
- What you are building (one line, in user's words).
- Who will see it (investors / partners / customers / pilot / public / **agent channel**).
- Rough exposure risk signal (low | medium | high) — rough only.
- Bottom line: one practical sentence.
- Sensible next: pick free deliverables below.

### Free Hygiene Available Now (Catalog — No Guarantees, Not Legal Advice)

Use the list below. Deliver practical artifacts (maps, checklists, text, tables). Always end with sources note and disclaimer. Load `references/` on demand (one level deep). Do not invent extra legal-sounding claims. **Eight options, not nine** (Anthropic: provide a default; do not grow the picker).

| # | Offer | Input | Output |
|---|-------|-------|--------|
| 1 | Show / hold map | audience + what exists | 3-column table: show live · keep private · wait for NDA/provisional |
| 2 | Demo hygiene playbook | demo date + audience | staged ladder + run-of-show + ground rules (`references/investor-demo-hygiene-playbook.md`) |
| 3 | AI / human contribution log | humans + what they did | filled table (`references/v05-contribution-log-template.md`) — name the runtime separately |
| 4 | Provisional readiness checklist | what will be shown | enablement + timing checklist (`references/v05-provisional-readiness-checklist.md`) |
| 5 | Provenance + holdback + agent-exposure | artifacts / chats / what the agent showed, emailed, pushed, posted | redaction list + agent-exposure log (`references/v05-provenance-holdback-template.md`, `references/agent-exposure-log.md`) |
| 6 | Trade-secret ID matrix | candidate assets | asset / why / measures / gaps (`references/v05-trade-secret-matrix.md`) |
| 7 | Lite prior-art pointers | technical field | public search pointers + red flags — **not a search** (`references/v05-lite-prior-art-pointers.md`) |
| 8 | Hygiene package JSON | same as snapshot | `sorticai.hygiene_package.v1` (`references/headless-hygiene-package.md`) |

Also available: session ground rules, pre-meeting pack, slides (disclaimer last slide), standalone disclaimer, Q&A armor, hold-back checklist (`references/v05-demo-ground-rules-template.md`, `references/free-tier-outcomes.md`).

**When user chooses free help:**
1. Confirm audience in one line.
2. Deliver chosen items (use templates; keep concise).
3. List files produced.
4. Restate: Free. No guarantees. Not legal advice. Consult qualified IP counsel for your facts and jurisdictions. Sources referenced (high-level summaries only): EPO Guidelines G-II 3.3.1 (AI/ML technical effect), USPTO 2025 AI inventorship guidance (human conception), WIPO principles.

## Headless Contract (Codex CLI · Claude -p · grok -p · Grok Build · Grok Bot · computer-use · MCP/A2A)

Use this when there is **no interactive picker** (CLI `-p`, CI, MCP/A2A, Grok Build, **Grok Bot**, computer-use / browser-use, numbered-only hosts).
This is the free Phase-0 shape: **skill → structured hygiene package**. No paid paths. No firm names.

**Detect headless if any of:** no `ask_user_question` tool; user asked for JSON / export / package / "headless"; prompt is a one-shot `-p` / CI job; runtime is a persistent Bot with its own computer.

**Order (mandatory):**
1. Print the L3 stamp first (if L3).
2. One-sentence "what we noticed" + snapshot (building / audience / rough exposure risk).
3. Numbered options **1–8** (never a live arrow menu):
   1. Show / hold map
   2. Demo hygiene playbook + ground rules
   3. AI / human contribution log
   4. Provisional readiness checklist
   5. Provenance + holdback + agent-exposure
   6. Trade-secret ID matrix
   7. Lite prior-art pointers (not a search)
   8. Hygiene package JSON export (`references/headless-hygiene-package.md`)
4. If the prompt already names a deliverable or says "export/json/package", deliver it in the **same turn**.
5. If headless and **no** deliverable is named: print 1–8, then **default-deliver 1 (show/hold) + 8 (JSON)** in the same turn. Never wait for a click. (Agent Skills: provide a default; do not stall on a picker.)
6. End with the standing disclaimer + sources note (in both markdown and JSON). Apply `references/output-language-hygiene.md`.

**Grok Bot / computer-use extras (unattended teammate):**
- Treat Bot email, GitHub push, browser-use, Clip-Bot, livestream, HiTL/UAT, board/partner rooms, and social post as **live demo channels**. Apply show/hold *before* the paste/send.
- Never invent status. Do not infer sent/filed/cleared. Stale schedule metadata ≠ "didn't run". If source data is unavailable, report failure — do not use stale data.
- Approval gate: never email, post, auto-publish, pay, publish identity/live-copy, or send leftover drafts / partner pre-reads unless this turn names the **recipient and the action**. Empty signature replies stay unsent.
- **Backup ≠ publish.** Weekly backup and ChatGPT/project export are owner-desk. Do not treat a backup pack as a send, and do not grow backup/control trees as a side effect.
- Claimed send needs message-id + recipients in writing, else log `not_sent`.
- Evidence-or-blocked: "done" requires folder path + link. Inbox-root dumps are not done.
- Log the runtime and channel (`references/agent-exposure-log.md`). JSON keys: `agent_exposure` (empty array ok), `approval_required` (bool), `evidence_or_blocked` (string), `owner_gated` (bool), `stop_or_decline`.
- Publishing a Bot/skill without protect language stays L2 (tip only).
- Shared Bot cloud computer is **not** a security boundary. Local-computer execution is another leakage surface. Do not park holdbacks on either.
- Bot egress IP is **not sticky**. Registrar "new device" alerts from Bot computer-use are a reason to **decline login**, not to log in.
- GitHub auto-push of this public repo: decline unless this turn names owner **and** action.
- Subagents: pass this skill or do not spawn. They do not inherit it.
- Truncated/junk files are not originals. Clock-limited live rooms hold deeper internals.
- Safety gate on dispatched task specs: no secrets, proprietary source, or customer data. ChatGPT/Codex skill zips are scanned — no secrets in the zip.
- Degrees of freedom (Anthropic): **low** on send/publish/pay/login/identity/voice-provision/DNS/access-grant/webhook/hooks/CI-apply; **medium** on show/hold tables; **high** on snapshot wording.
- **Callable / headless chain is a disclosure ladder.** Each hop (callable agent → platform → **human reviewer** → customer/partner/SME) is a live demo channel. Apply show/hold at every hop. Do not dump internals into the callable surface. A reviewer seeing the AI result before the customer is still a hop.
- **`--always-approve` / `--yolo` is not owner approval** for send, pay, identity, DNS, or voice/phone provision.
- Voice / phone agent: consult ≠ provision. Decline a live number unless this turn names owner **and** action.
- Disabled jobs stay disabled. Do not rewrite live prompts. Schedule-metadata reset ≠ prompt rewrite. ENABLED jobs with stale nextRun can still fire — they are live channels.
- Dashboard / OAuth / 2FA / DNS / MCP-reinstall login: decline. One-tab fallback ≠ reinstall. Do not change DNS.
- Internal fit-note / adjacent-demand analysis is **not a send**. No outbound from the room unless recipient **and** action named this turn.
- Placeholders and MCP-size-blocked files are not originals (same as truncated/junk).
- Test this skill before scheduling it as a routine. Do not auto-enable a disabled hygiene job. Community SKILL.md files can persist via backups — do not ingest untrusted skills from a backup pack.
- **Bot share / marketplace clone is a demo channel.** The share link is **public configuration** (identity, description, skills, routines). Strip API keys, internal URLs, customer data first. The copy does not include computer, logins, or history. Do not park holdbacks in a shareable Bot.
- **Hide ≠ pause.** Hiding a Bot from the sidebar does not pause it or its routines. Deleting a Bot removes its routines (immediate, no undo) but shared-computer files and sign-ins remain.
- **Routine test-run performs real work** (navigates, writes, calls tools — no dry run). Routine **delete is immediate with no undo**. Decline unless this turn names owner **and** action.
- Bot datacenter IP may trip human-verification walls. Do not improvise proxy or login workarounds. Rotating egress is still not sticky.
- Image-only decks are not numbered facts. Do not invent dollar figures from a PNG/chart.
- Grok Bot Auto Review: **Require Approval wins Always Allow.** 2FA / CAPTCHA / computer-takeover is not a reason to log in.
- **Astra computer-use / write-across-apps is a live demo channel** (model pick stays L0). Connectors use the signed-in account — they are **not a vault**. Console screenshots in a partner mail are a demo. CI auto-apply of an infra PR is a production change (requires approval).

**JSON:** follow `references/headless-hygiene-package.md` schema `sorticai.hygiene_package.v1` exactly. Include `output_register: procedural_builder_worksheet`, `not_for_third_party: true`, `agent_exposure`, `approval_required`, `evidence_or_blocked`, and `stop_or_decline`. Hygiene only. No prices, no counsel names, no protectability rulings.

**Interactive hosts:** keep the same catalog; a picker is allowed *after* the stamp. Headless never waits for a click.


## Ask / stop / decline (workflow boundary)

OpenAI **plugins/build/skills** recrawl **2026-09-10** (developers.openai.com/plugins/build/skills, plugin architecture same day): every skill states input, steps, output, **facts not to infer**, **when to ask / stop / decline**, and **which supporting files to consult**. MCP is for live data, auth, and controlled actions (mailbox/Outlook connectors included). This skill has **no MCP** and **no lifecycle hooks**; start with the **smallest plugin shape** (skill-only). Plugin-bundled hooks stay skipped until the user trusts the current definition; installing a plugin does not run lifecycle scripts. MCP "Scan Tools" imports a **snapshot**, not a live fetch — rescan after change before plugin submit. A public plugin listing is the ChatGPT+Codex **universal plugin directory**. `enabled = false` keeps a plugin installed but off (not uninstall; not a pause of other Bots). Controlled actions (send, login, pay, DNS, dashboard, unnamed public push, identity/live-copy, access grant, webhook secret, treating backup as publish, voice/phone provision, disabled-job re-enable, live-prompt rewrite, routine delete, exploit/PoC) stay outside the skill. Skill zip is scanned; after a change, scan again; do not add a script when instructions suffice. Test inventory: direct, indirect, incomplete, should-not-activate, must-not-invent/unsupported. Host model pick (GPT-6 Astra / Extra High) is L0 — this skill does not change the model and declines exploit/PoC work. Astra **computer-use / write-across-apps** is a live demo channel (not L0). Connectors use the signed-in account — they are **not a vault**. Confirmation policies cover exposing confidential information, sharing a dashboard too broadly, deleting data. Astra declines unsupported conclusions from documents.

Prefer **one focused skill**. Split when triggers, inputs, or success criteria differ (OpenAI 2026-09-06). Do not merge this hygiene skill with the US IP corpus, accounting/ops skills, or a correspondence/persona skill.

**Ask (incomplete input):** audience, artifact, or evidence is missing → one follow-up, then still default-deliver 1+8 if headless. Legal/tense correspondence needs **two inputs** (short briefing + the artifact). Do not invent a folder, send, or "done".

**Stop (named this turn but unsafe):** leftover draft, empty signature reply, truncated/junk/placeholder/MCP-size-blocked file treated as original, clock-limited live session or attendee hard-stop about to go deeper than the show/hold map, growing a backup tree as a side effect of hygiene, dumping internals into a callable hop, inventing numbers from an image-only deck, parking holdbacks in a shareable Bot, posting a public Grok share URL of the internals, pasting IAM/secret screenshots into a skill zip, attaching console screenshots to a partner mail, making demo objects public.

**Decline (unsupported action):** login to a registrar/Cloudflare/Spaceship/Vercel/GitHub-2FA/dashboard unless this turn names it (including after a Bot "new device" alert or a 2FA/CAPTCHA computer-takeover); MCP reinstall (one-tab fallback only); unnamed GitHub auto-push of this public repo; dumping client/product facts into a public skill repo; mixing manuals with IP work-product; spawning a subagent without passing this skill; partner pre-read / pay / identity / live-copy / fit-note send without named recipient **and** action; treating a weekly backup or project export as a publish; provisioning a live voice agent or phone number; re-enabling a disabled job; rewriting a live prompt; treating `--yolo` as approval; deleting a routine (immediate, no undo); unnamed Bot share with secrets still in the profile; granting cloud/GitHub owner/admin; pasting a webhook signing secret into the skill; enabling a mailbox connector on this skill; adding Codex lifecycle hooks that write production; auto-applying an infra PR to production; exploit/PoC / jailbreak work (out of scope, including on GPT-6 Astra).

IP intensity (L0–L3) is **not** write-privilege. Owner-gated even at L3: send, publish, pay, identity, live title/copy, voice/phone provision, DNS, access grant, webhook secret, lifecycle hooks. Grok Bot autonomy: observe / draft / approved write / scheduled. Sending still needs named approval even at IP L3. Grok Bot also requires approval for purchasing, deleting, publishing, or changing production systems. `--always-approve` is a tool auto-approve flag, not that gate. Test skill before routine.

## Output register (builder worksheet — not a client memo)

Counsel review of adjacent SorticAI writing (2 Sep 2026) plus Grok Bot operator briefs (do not invent status; do not email third parties unless named) plus Agent Skills authoring practice: **procedural hygiene is not legal advice**. If a table looks like a filing instruction, the standing disclaimer becomes confusing.

Hard rules for every deliverable (full list: `references/output-language-hygiene.md`):
- Verbs: consider / document / list / hold / mark. Never "you must file", "to comply", "this is protectable".
- Never invent deadlines (no "within 48 hours" unless the user stated them).
- Never invent status ("filed", "cleared", "sent"). Do not infer results the host did not return (OpenAI: do not invent, replace, or reroll).
- Never write "sources verified" / "links valid". Write "public URL located" and what you actually checked — or omit.
- Never email/post/auto-publish to third parties unless this turn names the recipient **and** the action. Leftover drafts stay unsent.
- Never mark done without evidence (path + link). Inbox-root dumps are not archived.
- One idea per sentence. No stacked jargon without saying *of what*.
- Every recommended step has a next action a builder can do today, or drop it.
- Banner on exports: **Builder worksheet. Do not send these tables to third parties as legal analysis.**

## Guardrails & Boundaries (Critical)

- **Free only.** No mention of paid reviews, prices, expert connections, or commercial tiers in this edition.
- **Hygiene / procedural only.** No rulings on patentability, protectability, validity, FTO, or "you should file X". Rough signals only. "High-level" always.
- **Not the US IP corpus.** Hourly training / DESIGN-PLAN / REPAIR-QUEUE stay L0 here.
- **Human conception focus (USPTO 2025 alignment):** Emphasize documenting human contributions (framing, selection, refinement, recognition, validation). AI / Bot is a tool. Log the runtime separately.
- **Disclaimers mandatory:** Repeat on activation, on every major deliverable, on last slide / export. Exact language below.
- **When not to use:** Privacy/config work, generic security, meta skill editing, corpus ticks, Bot ops without protect intent, workspace/SaaS renewal, weekly backup without protect intent, registrar new-device alerts, user dismissal.
- **Staged exposure principle:** File appropriate provisionals before significant external disclosure where protection matters. Use NDAs + controls for deeper sharing. You control scope — "I can't go deeper without NDA" is smart. **Computer-use is external disclosure.**
- **Sources high-level only:** Never present as exhaustive or jurisdiction-specific advice.

### Standing Disclaimer (use verbatim or close)

> **Disclaimer:** SorticAI IP Sentinel (free edition) is automated / skill-assisted procedural hygiene help only. It is **not legal advice** and carries **no guarantees**. Outputs are for builder reference and do not replace qualified IP counsel. Patent timelines are long; "patent pending" does not prevent independent development. Consult licensed professionals for your specific situation, facts, and jurisdictions. Public sources referenced at high level only (EPO Guidelines, USPTO guidance summaries, WIPO). Use at your own risk.


## Gotchas (common failure points)

Highest-signal content (Anthropic 2026: capture what actually goes wrong). Load `references/output-language-hygiene.md` + `references/agent-exposure-log.md` when any of these fire.

- **Done without evidence is not done.** Inbox-root dumps and promises are not archived. Require folder path + link, or write blocked.
- **Do not invent, replace, or reroll a result** (OpenAI 2026-09-05). Do not infer sent / filed / cleared. Grok Bot: if source data is unavailable, report failure — do not use stale data.
- **Approval = recipient AND action named this turn.** Leftover drafts, empty signature replies, auto-publish, and resend stay on hold (Grok Bot: sending/publishing requires approval).
- **Claimed send needs message-id + recipients.** Otherwise log `not_sent`.
- **HiTL / UAT / livestream / Clip-Bot are demo channels.** L2 without protect language; L3 with it. Computer-use teaching records the screen — hold secrets.
- **This skill is silent on its own development** (L0 META) and on the US IP corpus.
- **Eight options, not nine.** Agent-exposure folds into item 5.
- **GitHub auto-push of this public repo is owner L3.** Decline unless this turn names owner **and** action. Do not dump client/product facts into `sortic-ip-sentinel-free`.
- **Shared Grok Bot cloud computer is not a secrecy boundary.** All Bots on the account see the same files/logins. Treat the Bot computer as a demo channel **and** a leakage surface.
- **Subagents do not inherit this skill** unless you list it. A spawned worker without the skill will dump IP. Pass the skill or do not spawn.
- **Truncated / junk files are not originals.** Do not file, demo, or push a `*.TRUNCATED*` / partial as the work product.
- **Clock-limited live sessions (HiTL / UAT).** When the room has a hard stop, hold deeper internals rather than improvising past the show/hold map.
- **Do not ingest untrusted community skills** into this folder. Skills are privileged instructions.
- **Backup is not publish.** Weekly backup / project export is owner-desk. Do not auto-send the pack and do not grow backup trees.
- **Owner-gated even at IP L3:** send, publish, pay, identity, live title/copy. Named recipient **and** action still required. Partner pre-reads stay unsent unless this turn names them.
- **Degrees of freedom (Anthropic 2026-09-07):** low on send/publish/pay/login/identity (exact decline); medium on show/hold drafting; high on snapshot wording. Do not put clock-dated session trivia in this skill body.
- **Stale schedule metadata ≠ job dead.** Do not invent "didn't run" from a past nextRun.
- **Workspace/SaaS renewal is L0** unless IP is being shared through that workspace.
- **ChatGPT/Codex skill zip is scanned and shareable.** No secrets, no client facts in the zip.
- **Bot egress IP is not sticky.** Registrar new-device alerts from computer-use → decline login, do not take over the registrar.
- **Local-computer execution is not a vault.** Grok Bot "Execution on Local Computer" shares the desktop in front of you; holdbacks do not live there either.


- **Callable chain is a disclosure ladder.** Show/hold at every hop (callable → platform → partner/SME). Do not dump internals into the callable surface.
- **Consult ≠ provision.** Voice / phone agent: decline a live number unless named this turn.
- **Disabled stays disabled.** Do not re-enable disabled jobs. Do not rewrite live prompts. Stale nextRun on an ENABLED job still fires.
- **Fit-note is not a send.** Internal adjacent-demand analysis stays internal. No outbound from the room unless named.
- **`--yolo` / `--always-approve` is not owner approval.**
- **Placeholders / MCP-size-blocked files are not originals.**
- **Backup packs can persist untrusted SKILL.md.** Do not ingest community skills from a backup (X ingest 8 Sep: malicious skills survived reinstall via backups).
- **Dashboard / OAuth / 2FA / DNS / MCP-reinstall:** decline login. One-tab fallback ≠ reinstall. 2FA / CAPTCHA computer-takeover is not a reason to log in.
- **Bot share / marketplace clone is a demo channel.** Share link = public configuration (identity, description, skills, routines). Hide ≠ pause. Deleting a Bot removes routines (no undo) but shared-computer files remain.
- **Routine test-run is real work. Routine delete has no undo.** Datacenter IP that trips a human-verification wall is not a reason to improvise a proxy or login.
- **Image-only artifacts are not numbered facts.** Do not invent dollar figures, LOE, or counts from a PNG/chart. Write "image-only — numbers not extracted" or omit.
- **Require Approval wins Always Allow.** Grok Bot Auto Review: `--always-approve` / Always Allow does not beat a Require Approval rule.
- **Reviewer hop is a disclosure hop.** Human review of the AI result before the customer is still a live channel. Show/hold at that hop too.
- **Mailbox / Outlook connector is MCP live data.** Enabling it on a skill that will see drafts is a hop. This skill has **no MCP**.
- **Public Grok share URL is a demo channel** (`x.com/i/grok/share/…` or `x.ai/bot/…`). Same exposure as a Bot share — the conversation / Bot config is public and cloneable.
- **Bot duplicate copies skills and routines.** Treat duplicate like share. Auto Review rules sync to the shared Bot computer — not a vault.
- **Infra / IAM / secret screenshots are holdbacks.** Do not paste project IDs, secret names, or long-lived keys into the skill zip. No scripts (Anthropic enterprise: scripts = high risk).
- **Access grant is owner-gated identity.** Cloud owner/admin and GitHub org add stay declined unless named this turn.
- **Legal drafts ≠ send.** Two-input minimum (briefing + artifact). Skip extremely sensitive lines. End-gate before claiming send. Two readings are not a verdict.
- **Webhook signing secret is shown once.** Decline paste into SKILL.md / zip / chat.
- **Lifecycle hooks write at runtime.** This skill has none. Adding production hooks is owner-gated.
- **MCP Scan Tools is a snapshot, not live fetch.** Rescan after change. `enabled = false` is not uninstall.
- **Do not invent valuation / financial figures.** Image-only and narrative estimates are not numbered facts.
- **Authors are not their own counsel.** This skill never claims "counsel reviewed". Exploit/PoC stays declined (Astra Critical cyber ≠ this hygiene skill).
- **Voice screen-share sees the browser.** Voice mode that shares the screen is computer-use. Hold secrets. Cloning a voice is identity publish (owner-gated).
- **Plugin-bundled hooks are untrusted until reviewed.** Codex skips them until the user trusts the current definition. Installing a plugin does not run lifecycle scripts. This skill has none.
- **Pin skill version in production.** Anthropic `latest` immediately changes production agents. Publishing a new version is a live channel.
- **Public Bot share URL (`x.ai/bot/…`) is cloneable configuration.** Same exposure as Grok share / marketplace clone.
- **Astra computer-use is a live demo.** Write-across-apps / browser-use without APIs is computer-use. Model pick stays L0; the write is L2/L3. Connectors use the signed-in account — they are **not a vault**. Confirmation policies cover exposing confidential information, sharing a dashboard too broadly, deleting data. Astra declines unsupported conclusions from documents.
- **Console screenshots in a partner mail are a demo.** Distinct from pasting IAM into the zip. Hold internals. Send still needs recipient AND action.
- **CI auto-apply is a production change.** Decline auto-apply of infra PRs unless this turn names owner AND action. Generic CI/debug without protect language stays L0.
- **One focused skill.** Do not merge this hygiene skill with a correspondence/persona skill.

## Progressive Disclosure & References

Keep this SKILL.md lean. Load **one level deep** from SKILL.md only (do not nest). When the user selects a deliverable, read that file now and apply its structure exactly.

- `references/investor-demo-hygiene-playbook.md`
- `references/free-tier-outcomes.md`
- `references/v05-contribution-log-template.md`
- `references/v05-demo-ground-rules-template.md`
- `references/v05-provisional-readiness-checklist.md`
- `references/v05-trade-secret-matrix.md`
- `references/v05-lite-prior-art-pointers.md`
- `references/v05-provenance-holdback-template.md`
- `references/agent-exposure-log.md` (Bot / computer-use channels)
- `references/headless-hygiene-package.md`
- `references/output-language-hygiene.md` (writing register — load on every L3 deliverable)
- `references/classification-matrix.md` (maintainers / tests)
- `references/evals.md` (Anthropic ≥3 evals; OpenAI description-as-trigger)

## Examples (Usage)

**Example L3 (canonical):** "I'm building a new agent orchestration protocol with control software. Getting ready to show investors in a pilot. How to protect the IP, run analysis and check."

→ L3 header → snapshot → free hygiene list (include demo hygiene playbook + contribution log + show/hold) → disclaimer.

**Example L3 Bot:** "The Grok Bot will email the deck to investors. Protect the IP. What can the agent show?"

→ stamp → snapshot → show/hold + agent-exposure log → **do not send** unless recipient named this turn → disclaimer.

**Example L3 headless (named):** same prompt plus "Output numbered options and a hygiene package JSON."

→ stamp → snapshot → options 1–8 → JSON per `sorticai.hygiene_package.v1` → disclaimer.

**Example L3 headless (unnamed, one-shot):** same L3 prompt with no picker and no named deliverable.

→ stamp → snapshot → options 1–8 → **default-deliver 1 (show/hold) + 8 (JSON)** same turn → disclaimer.

**Example L2:** "We have an investor demo in 10 days. Should I put the architecture diagrams in the deck?"

→ Answer the question → short tip: consider high-level vs exact internals; full free sentinel available on "IP sensitive moment".

**Example L2 Bot publish:** "Publish the Grok Bot and post a demo clip from the protocol."

→ Answer first → 2–4 line tip: a public clip is exposure; hold exact parameters; full hygiene on "IP sensitive moment".

**Example L2 HiTL / livestream:** "We have a HiTL UAT session then a Bot Galaxy livestream."

→ Answer first → 2–4 line tip: a live session and a livestream are demo channels; hold exact parameters; full hygiene on "IP sensitive moment".

**Example L3 leftover draft:** "The Bot will send the leftover investor-deck draft. Protect the IP."

→ stamp → hold the send (leftover draft + approval gate) → show/hold + agent-exposure → disclaimer.

**Example L0:** "Add telemetry and privacy controls to the loop." / "Run the next US IP corpus curriculum tick."

→ Normal answer. No sentinel.


**Example L3 auto-push:** "Auto-push the sentinel to GitHub and mark done. Protect the IP."

→ stamp → **decline** unnamed public push (owner L3) → `stop_or_decline` + evidence-or-blocked → disclaimer.

**Example L3 truncated:** "File the truncated deck PDF as the original and demo it. Protect the IP."

→ stamp → stop: truncated is not the original → holdback on the junk file → disclaimer.

**Example L3 unsupported login:** "Log into Spaceship and change nameservers, then email the protocol. Protect the IP."

→ stamp → **decline** login/DNS (unsupported) → hold the email unless recipient AND action named → disclaimer.

**Example L2 clock-limited UAT:** "UAT session is 14:00–16:00 and one reviewer leaves at 15:00. Put the architecture on screen."

→ Answer first → 2–4 line tip: a clock-limited live room is a demo channel; hold exact parameters when time is short; full hygiene on "IP sensitive moment".

**Example L2 board / partner weekly:** "Board and partner weekly this week. Walk the protocol."

→ Answer first → 2–4 line tip: a board/partner room is a demo channel; hold exact parameters; full hygiene on "IP sensitive moment".

**Example L0 workspace renewal / backup:** "ChatGPT Business renews next week." / "Run the weekly skill backup into Drive."

→ L0 silent. Backup is not publish. Renewal is not an IP moment.

**Example L3 partner pre-read / owner-gated:** "Protect the IP. Email the partner pre-read and publish the live title copy. Mark done."

→ stamp → **decline** unnamed partner send / identity publish (owner-gated) → `owner_gated` + `stop_or_decline` → disclaimer.

**Example L3 backup-as-publish:** "Protect the IP. Auto-publish the weekly backup pack as the public skill."

→ stamp → **stop/decline**: backup ≠ publish → disclaimer.

**L1 example:** "Keep this design private for now."

→ Normal answer + one whisper line.


**Example L2 callable hop:** "Expose the protocol through a callable agent into the partner network."

→ Answer first → 2–4 line tip: each hop is a demo channel; hold exact parameters at the callable surface; full hygiene on "IP sensitive moment".

**Example L3 voice provision:** "Protect the IP. Provision a live voice agent and phone number."

→ stamp → **decline** provision (consult ≠ provision; owner-gated) → disclaimer.

**Example L3 disabled-job / prompt rewrite:** "Protect the IP. Re-enable the disabled sentinel job and rewrite the prompt."

→ stamp → **decline** re-enable and prompt rewrite → schedule-metadata reset only if this turn names that ops action → disclaimer.

**Example L3 fit-note send:** "Protect the IP. Email the internal stack fit-note to the counterparty."

→ stamp → **decline** unnamed outbound (fit-note is not a send) → disclaimer.

**Example L2 Bot share:** "Share the Grok Bot via public link and list it on the marketplace."

→ Answer first → 2–4 line tip: a share link exposes identity, description, skills, and routines; marketplace clone is a demo channel; hold exact parameters; full hygiene on "IP sensitive moment".

**Example L0 hide Bot:** "Hide the IP radar Bot from the sidebar."

→ L0 silent. Hide does not pause routines.

**Example L3 routine delete:** "Protect the IP. Delete the old routine and test-run the new one."

→ stamp → **decline** routine delete (immediate, no undo) unless owner **and** action named; note that a test-run performs real work → disclaimer.

**Example L3 image-only:** "Protect the IP. Publish the dollar figures from the PNG chart."

→ stamp → **stop**: image-only is not a numbered fact; do not invent figures → disclaimer.

**Example L2 reviewer hop:** "The lawyer reviews the AI result before the customer sees it."

→ Answer first → 2–4 line tip: a reviewer hop is a demo channel; hold exact parameters; full hygiene on "IP sensitive moment".

**Example L3 mailbox / Grok share:** "Protect the IP. Enable the Outlook connector on this skill and post a public Grok share of the protocol chat."

→ stamp → **decline** mailbox MCP on this skill; **stop** public Grok share of internals → disclaimer.

**Example L3 access grant / IAM paste:** "Protect the IP. Grant cloud owner and paste the IAM screenshots into the skill zip."

→ stamp → **decline** access grant; **stop** IAM/secret screenshots in the zip → disclaimer.

**Example L3 legal drafts send:** "Protect the IP. Send the three ready-to-send legal drafts."

→ stamp → **hold** (drafts ≠ send; two-input + named recipient AND action still required) → disclaimer.

**Example L0 model pick:** "Switch to GPT-6 Astra Extra High and enable four Business seats."

→ L0 silent. Host model pick / seats are not an IP moment.

**Example L2 voice screen-share:** "Walk me through the protocol on a voice call while sharing the screen."

→ Answer first → 2–4 line tip: voice screen-share sees the browser; hold exact parameters; full hygiene on "IP sensitive moment".

**Example L3 voice clone:** "Protect the IP. Clone my voice onto the Bot and share the public Bot link."

→ stamp → **decline** voice clone (identity publish) unless named; treat `x.ai/bot/…` as public config → disclaimer.

**Example L3 plugin hooks:** "Protect the IP. Add Codex SessionStart hooks that write production."

→ stamp → **decline** production hooks (untrusted until reviewed; this skill has none) → disclaimer.

**Example L3 Astra write:** "Protect the IP. Let Astra computer-use finish the deck across apps."

→ stamp → **hold internals** before write-across-apps; connectors are not a vault → disclaimer.

**Example L3 console-shot mail:** "Protect the IP. Attach the console screenshots and send the access-overview."

→ stamp → **hold internals**; send still needs recipient AND action → disclaimer.

**Example L3 CI auto-apply:** "Protect the IP. Auto-apply the infra PR to production."

→ stamp → **decline** (production change) → disclaimer.

**Example L0 correspondence merge:** "Merge the sentinel with the correspondence skill."

→ L0 silent (meta / one focused skill).

## Output Standards

- Plain language for builders.
- Numbered steps, tables for maps/logs/checklists, copy-paste ready text.
- Every deliverable ends with disclaimer + "Sources referenced (high-level summaries only): EPO Guidelines G-II 3.3.1 (AI/ML technical effect), USPTO 2025 AI inventorship guidance (human conception), WIPO principles."
- Version in header: v0.5.8-free.
- Headless: numbered options + default 1+8 if unnamed + JSON. Never block on UI.
- Builder-worksheet register (`references/output-language-hygiene.md`).

## Failure Recovery

- Header missing on L3 → print header first, then continue.
- Over-fire on L0 → apologize briefly, finish real task, suppress further this session.
- User dismisses → stop for

…(truncated)
