Diff
1diff --git a/dot_agents/skills/agents-md-cleanup/SKILL.md b/dot_agents/skills/agents-md-cleanup/SKILL.md
2index 2fb6393d884e3cedf1417d44c0eccd3b10473e41..12b332ae10031110ff51504330cca31f4bd6f5a2 100644
3--- a/dot_agents/skills/agents-md-cleanup/SKILL.md
4+++ b/dot_agents/skills/agents-md-cleanup/SKILL.md
5@@ -1,6 +1,7 @@
6 ---
7 name: agents-md-cleanup
8 description: Cleans and right-sizes repository AGENTS.md files while preserving generated-content contracts and human-owned guidance. Use when an agent guide is too long, repetitive, or overly detailed.
9+disable-model-invocation: true
10 ---
11
12 # AGENTS.md cleanup
13diff --git a/dot_agents/skills/deploying-production/SKILL.md b/dot_agents/skills/deploying-production/SKILL.md
14index 0dce3d8aa3ad90adf786f3cd43e959151a1edf9a..ec0e1fedd2f695a379f2f90e14979883530267da 100644
15--- a/dot_agents/skills/deploying-production/SKILL.md
16+++ b/dot_agents/skills/deploying-production/SKILL.md
17@@ -194,6 +194,15 @@ For the legacy production environment, either retain it in the tag workflow and
18 5. Retire reviewers or delete the legacy environment as chosen.
19 6. Without dispatching a helper, verify both environments select `main`; rollback has reviewers and no self-review; the ruleset is active with only App ID `4183494`; helpers use `tag-release@main` and the intended prefix.
20
21+## Required manual actions after the helper PR merges
22+
23+**Always include this callout in the completion response.** Do not say the conversion is complete until these actions are confirmed:
24+
25+1. Activate the active bot-only tag ruleset for `refs/tags/<tag-prefix>*.*.*`, allowing only App ID `4183494` to create, update, or delete matching tags.
26+2. Only after the ruleset is active, remove required reviewers from the retained legacy production environment, or delete it if every merged workflow reference is gone.
27+3. Verify both helper environments still select `main`; rollback requires a reviewer other than the initiator; the ruleset has no user, team, administrator, or deploy-key bypasses; and the helpers use the intended prefix.
28+4. Do not dispatch either helper as a test. It creates a production tag.
29+
30 ## After conversion: operating releases
31
32 **Forward:** merge and validate in dev; dispatch the forward helper from `main`; leave `commit` empty for current `main`, or provide a newer reviewed full SHA; confirm the tag starts deployment.
33diff --git a/dot_pi/private_agent/AGENTS.md b/dot_pi/private_agent/AGENTS.md
34index ef49465b388bcb2437003a17d2505bd990366eb3..d0782f7a61cb942716891ec730116fc23699c139 100644
35--- a/dot_pi/private_agent/AGENTS.md
36+++ b/dot_pi/private_agent/AGENTS.md
37@@ -14,10 +14,6 @@ When outputing text for human consumption (code comments, PR descriptions, docum
38 - Zero comments by default, only explain if it is truly complex or unexpected behaviour
39 - When in doubt, ask.
40
41-## Shell commands
42-
43-- Don't cd into a directory you're already in
44-
45 ## Security and access
46
47 - Zero Trust. Least privilege. Never leak secrets.