Work / AI Systems
Nova
An AI workspace: one versioned repository that defines how every AI harness works for Brian. Skills, delegation agents, guardrail hooks and budget gates, shared live between Claude Code and Codex.
- Status
- Live, in daily use
- Stack
- Node · PowerShell · Claude Code + Codex · skills · agents · hooks
- Started
- July 2026
- Source
- Private repo
What it is
Every AI coding tool keeps its own configuration: rules, reusable playbooks, agent definitions, event hooks. Kept as copies, they drift apart, and every rule written into an always-loaded file is paid for in tokens on every session and every subagent.
Nova is the answer to both. The repository is the live configuration directory itself, so an edit takes effect immediately and git is the only history. There is no copy step and no release shelf. Codex reads the same skill files through generated links, and a drift check fails when the two sides disagree.
It works in layers. A short global rules file holds what applies everywhere. Hooks fire on harness events to block dangerous operations and re-inject the per-turn habits. Skills load their full method only when their trigger fires. Agent definitions form the delegation tiers, and two multi-agent engines run audits and research. A doctor script and a generated atlas keep all of it honest.
Every other project on this site is built through it. The repository stays private because it sits beside personal configuration; this page describes the system, not what it holds.
What it does
- Skill stack33 playbooks, from planning and test-first work to audits, research and session recovery, each under a size budget.
- Delegation tiersAssistant, developer and investigator agents, with model and effort chosen per task; a dispatched agent does not re-delegate unless its brief allows it.
- Audit and research enginesMulti-agent runs whose findings are refuted by default and confirmed only with evidence, and which survive a usage-limit stop.
- Guardrail hooksBlock irreversible git operations, commits carrying secrets, and making a repository public before it passes a history scan.
- Budget gatesMeasure session context and prompt a clean wrap-up with a written handoff before a limit ends the session.
- Codex bridgeExposes the same skills, agents and guards to Codex, generated from this repository and checked for drift.
Build log
From a plugin shelf to a live workspace
The record of how Nova was built, from the first commit on 1 July 2026 to today: what was added, what was retired, and why. Dated, oldest first.
- 165commits
- 95days from first commit, with work on 38 of them
- 33skills
- 10agent definitions
- 11hooks wired into the harness
As of 4 Oct 2026, counted from the repository.
- Era I · 1 – 9 JulGit becomes the release
- Era II · 11 – 27 JulBudgets and guardrails
- Era III · 4 – 26 AugMeasured, not estimated
- Era IV · 31 Aug – 4 SepCutting the always-loaded cost
- Era V · 2 – 4 OctNothing leaks
Era I · 1 – 9 Jul 2026
Git becomes the release
An existing set of skills and agents was put under git, its plugin release shelf was retired the same day, and the first guardrails, engines and adopted skills went in.
-
A snapshot, then the shelf retired
The first commit captured the stack as it already stood: a global rules file, 10 skills, 11 agents, one git guardrail hook and a plugin release shelf. The next commit retired the shelf. It needed a version bump and an app restart for every change, and it had drifted a full generation behind, missing five newer skills. From then on the repository was the live configuration and git was the versioning.
-
A doctor for drift, and a smaller always-on surface
A read-only check script, the doctor, began failing on mismatched names, dangling references and missing hook scripts; its first run caught two example names that pointed at nothing. The same day three documentation skills were folded into one, and the global rules file went from 8.8 KB to 3.1 KB, because every session and every spawned agent pays for it.
Brian's call The top agent tier became the ceiling for any dispatched agent; the managing session itself is never dispatched as an agent.
-
Dispatched agents never dispatch
An agent read the manager's delegation rules from a project briefing and handed its own job to a child agent, which died silently; the task produced nothing. A hard line went into the agent definitions: a dispatched agent escalates when it is stuck instead of re-delegating, and the top tier may delegate only when its brief explicitly allows it.
-
Guardrail hooks
A commit guard began scanning staged changes for token shapes and blocking the commit, and the git guard closed gaps for force-pushes in refspec form and unrecoverable stash deletion, then began blocking blanket staging. The guard blocked its own commit because the message mentioned a dangerous command, so quoted text is now ignored before matching.
-
The engines degrade instead of dying
The multi-agent audit and research engines were hardened so a rate limit or a single agent's death degrades the run rather than losing it. Any stop now produces a partial report, findings a dead verifier could not judge are marked unverified instead of dropped, and a resume replays finished work from the run journal.
Method Eleven simulated failure scenarios across both engines, then a live run forced into the budget floor and resumed.
-
A per-turn reflex hook
Moving the delegation playbook out of the always-loaded rules and behind a skill trigger had cost the habit of delegating unprompted. A hook began re-injecting a short set of per-turn reflexes: consider delegation and settle decisions with a picker mid-run; the next day it added collecting everything addressed to Brian in one footer.
-
What a 57-agent run taught
A large run hit no rate limits; its only deaths were the account's usage window. Its resume did hit one: cached stages returned instantly and fired the next phase as a single burst that killed 36 agents. The rules became halving concurrency on a resume and having heavy agents write their work to disk, which let all 40 part-files survive.
-
The adoption wave
Fourteen skills and a set of hooks were adopted from six MIT- and BSD-licensed open-source repositories, each distilled into the house format or vendored with its licence notice. A Codex adversarial review found three major problems before landing, all fixed. The same day the distilled skills were renamed into the house namespace and every adopted hook was wired.
Brian's call Rename them to "make them our own", and wire everything.
-
The first hook retired
One adopted hook forced the agent to gather facts before every edit or command. It produced 20 denials in a single documentation session and was unwired the next day; git keeps the code.
Brian's call Pure friction; retire it.
-
Byte budgets and one lineage file
A session-start hook began warning when the always-loaded rules files passed a byte budget, routing the fix to the documentation skill's archival pass. Licence attributions scattered across skill folders were consolidated into one lineage file, and a copyright line carried in the wrong form was corrected to match the upstream licence.
Era II · 11 – 27 Jul 2026
Budgets and guardrails
Size budgets became checks, a gate that checked the wrong tree was fixed, the stack began working across two machines, and several guards were loosened where they cost more than they caught.
-
Branch deletion unblocked
The git guard stopped blocking branch deletion: it is recoverable from the reflog, and the agent checks merge status before cleaning up a branch. The operations that destroy uncommitted work or rewrite history stay blocked.
Brian's call The block was only friction on routine cleanup.
-
The compression floor
Crucible's project briefing hit a hard floor at about 12.9 KB after six archival passes; every further byte cut was load-bearing. The project budget was raised from 12 to 14 KB with the reasoning recorded: a budget set at the floor fires on every new term, and a guard that always warns trains people to ignore it.
-
Unattended runs
A posture skill for runs Brian is not watching: no blocking pop-ups, decisions logged to a run ledger, irreversible actions queued instead of taken, checkpoints at green gates and a report at the end. On 27 July it was changed to read the project before asking its one opening question, and to always ask it.
Brian's call Orient first, so the one moment he is at the keyboard is worth it.
-
Size budgets become a check
The doctor gained a size ledger: 10 KB per skill body, 600 characters per description, a combined description budget, and a cap on the per-turn reflex, which fell from 2.4 KB to 1.0 KB per prompt. Oversized skills moved detail into reference files that load only when needed, and thirteen descriptions were trimmed without losing a trigger phrase.
-
Two more hooks retired
Two adopted hooks spawned a process on every tool call. Half of their output was permanently inert, the harness now reported context pressure itself, and their loop detector flagged legitimate repeated calls. They were removed; the useful one beside them stayed.
-
The doctor checked the wrong tree
Run from a worktree, the doctor reported clean while two skills in that worktree were over budget, because it always validated the main copy. It now checks the tree it lives in and prints which tree it checked, since a check that can run against the wrong tree has to say so.
Method Reproduced by padding a skill to 18.3 KB in a worktree: the old script passed it, the fixed one flagged it.
-
A file and folder discipline
A read-only Codex audit found seven skills still telling agents to create purpose-built folders or leave temporary files in projects. All seven were fixed, scratch work moved to the session scratchpad, and the rule got one canonical home in the documentation skill. The planning skill was rebuilt the same day as the replacement for plan mode, with a small and a whole-project scope.
Method Codex audited and implemented a trim pass; Claude reviewed before merge.
-
Read by section, not by permission
The documentation method had required asking before reading the large history files. The ask was ignored in practice and its real purpose was context discipline, so the rule became: read freely, but only the section needed, found by its heading.
Brian's call Retire the read gate.
-
One stack, two machines
Hook paths became machine-independent so one settings file works on both of Brian's computers. Session-start behaviour was consolidated into a single wake hook that warns when a repository is behind its remote, and from the next day fast-forwards it automatically when the tree is clean and strictly behind.
-
New skills, scanned before ingest
Design-craft, content, server-building and browser-testing skills joined the stack, sources pinned to exact upstream commits. An automated skill security scanner became a standing step before anything external is ingested, and its high-severity flags were triaged one by one.
-
Parallel-session detection reworked
The guard for two sessions working in one repository relied on claim files, and stale claims from closed sessions reported three live sessions where there were none. The claims were deleted; every session instead took its own worktree, with a pop-up deciding the merge back.
Brian's call The tooling stops guessing what is live.
Era III · 4 – 26 Aug 2026
Measured, not estimated
Session budgets moved from the model's own guesses to measurement, the Codex bridge went live, the stack gained its three invariants, and several skills were built from real failures.
-
Session budget gates
A session declared itself out of context at about half its window by estimating instead of reading the measurement, and deferred work it could have finished. Sessions cut off by the usage limit also resumed carrying a heavy context. A gate began measuring context and usage and prompting a clean wrap-up first, covered by 14 sandboxed tests.
Brian's call The usage gate fires on tokens used, never on elapsed time.
-
Retired, then re-armed the same day
The context gate was retired in favour of the harness's native countdown. Within the day a live session crossed the checkpoint unnoticed, so the gate came back as a one-line reminder at the crossing. The global rules file was cut again, from 4.6 KB to 2.3 KB.
-
The Codex bridge goes live
A deterministic adapter linked 27 skills raw into Codex, generated its global instructions and ten agent definitions, and shared the guard hooks, with a sync script whose check mode is the drift gate. Claude stays primary and this repository stays the only editable source.
-
Three invariants
Three rules were set for every skill, hook and agent: every always-loaded byte must earn its output; no component may make the model do worse than it would unaided; and the stack must work under any capable model, with anything Claude-specific marked as such. The agent tiers were reshaped into assistant, developer and investigator specialties, and the skill-management skill widened to cover agents and hooks.
Brian's call The three invariants.
-
Recovering a dead session
A skill for picking up a session that died at the usage limit without reloading its context: a reader agent distills the old transcript into a handoff. Real recoveries added its rules within a day: a dead session's dev server was still serving old code eighteen hours later and made a test look like a regression, and a saved handoff claimed a release tag that did not exist.
-
Measure the stack, do not list it
The quarterly health-check prompt still named a retired hook and a renamed skill, so a script now discovers the stack from disk and joins it against real usage. Only actual skill invocations count, because every name appears in every session's prompt. Even then, skills followed inline undercount: two core ones looked dead until measured properly.
-
A guard that could never fire
The reworked parallel-session guard had fired zero times across 36 sessions that included 8 real overlaps. Three stacked defects meant it recorded a process that died seconds later, timed out, and then silently erased its own lock. All three were fixed and checked against five synthetic scenarios.
-
nova-workflow becomes Nova
The repository was renamed as its scope grew from Claude workflow to every AI tool Brian uses. The AI tooling's own working data moved under it as a separate private repository, written only by a scripted backup lane.
-
Parallel sessions handed back
The parallel-session skill and its guard were retired; worktree know-how was kept as a reference. The budget gate was simplified to one prompt at 500k tokens used. Two skills were added for tidying a repository and building agent-callable command-line tools, the latter defaulting to a CLI over an MCP server for local tools, on published benchmarks of token cost.
Brian's call The live-session prompt cost more than it saved; he coordinates parallel sessions himself.
-
Memory folded into the method
Twenty-six standing notes that had accumulated in the assistant's automatic memory were moved into the skills and docs where they belonged. Automatic memory was narrowed to a few directives and a staging area, so lessons live in versioned files every session and every harness can read.
-
The skill two others pointed at
Two skills drew their boundary against a verify skill that had never existed. It was built after a feature passed all 31 of its fixture tests and returned nothing against real data. The rule: run the change on real data on its real surface and observe the result, with numbers rather than adjectives.
-
Lessons from the art batches
Codex image batches for Crucible fed a dated ledger of dispatch rules, binding on every later dispatch. One lane converted its own files and reported them verified when one was wrong, so a foreign model's self-report never replaces a check. A 47-image batch came back about half as bright as the shipped set while every image passed on its own, so batch-level properties get a batch-level gate.
-
The backup net catches one
The backup lane's first run on the second machine stopped before committing because its fail-closed filename net found a runtime credential file swept into the mirror. The folder holding it was excluded outright, and the net was left unchanged, since catching that is its job.
Era IV · 31 Aug – 4 Sep 2026
Cutting the always-loaded cost
A census of real sessions showed where the stack was paying for the same text again and again. The fixes cut the reflex, the descriptions, the atlas and an estimator that could not see enough to be right.
-
Verify the fix, then the test
An audit-fix campaign on Pantheon added dispatch rules: adversarial checking of fixes found three bypasses in code that had already passed its own tests. On 3 September the companion rule followed: revert the fix and watch the new regression test fail, because a test written after a fix can pass against the broken code.
-
The reflex, rationed
A census of 308 sessions found the per-turn reflex reached 28 copies per session at the 90th percentile and 210 at the most, about 84k tokens of identical text in one context. It now sends the full text on the first turn and every sixth, with a one-line pointer between. A prompt guard with 33 advisories and no catches was unwired, and a handoff from the previous session is now injected at start.
-
Two shelves, and a generated atlas
Fifteen skills with no invocations since July moved to a library shelf with trigger-only descriptions, cutting descriptions from 15,905 to 12,472 characters in every session and subagent. The atlas's per-skill prose, which had drifted in four places, became a generated index, taking it from 120 KB to 55 KB, and the doctor now fails when it is stale.
-
The usage estimator retired
The usage gate had estimated the account's window from local transcripts, which cannot see parallel or remote sessions, and it fired at 82% while two other sessions were running. It now arms only from a configured limit. A global rule on code comments was added the same day: state the why in a few lines, never the history.
Brian's call Every estimate it produced was a false gate; retire it.
-
A floor moves both ways
Crucible's eighth archival pass found that part of its briefing's "floor" was dated status filed as essence. Removing it took the file from about 18 KB to about 15.6 KB with every invariant intact, and the project budget came down from 18 KB to 16.5 KB.
Era V · 2 – 4 Oct 2026
Nothing leaks
After four weeks without commits, work resumed on what can leave the machine: secret values in backups, private details in repositories about to go public, and the commits made to public ones.
-
Backups check known secrets
The backup lane's net knew only token shapes, so a secret value an agent had printed into a session log could pass it. A fail-closed step now compares every staged file against the machine's own known secret values and aborts the commit on a match, reporting only where, never the value.
Method Red-green: a planted fake secret aborted the lane with nothing committed; a real run over 1,248 staged files passed clean.
-
A gate before going public
A new skill with an executable gate scans a repository's full history for secrets, machine identifiers and stray files before it can go public. A hook blocks any command that makes a repository public unless a recent passing result matches the exact commit. Tested against a real repository, it failed the original and passed the history-scrubbed copy.
-
Public repos ship placeholders
A second guard scans commits and pushes in repositories that are already public, and blocks on any machine identifier or secret value. A gap surfaced the same day in live use: a command that changed directory and then committed was checked against the wrong repository. Both public-facing guards now follow directory changes, with 17 and 14 test cases passing.
-
Chat organizing handed to the app
The desktop app began exposing its own tools for grouping, renaming and archiving chats, so the skill that had done this by editing records handed it over and kept only the one job the app still cannot do: carrying chats and their settings across a project folder rename. Its body fell from 10.0 KB to 7.8 KB.