creating-lenses — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited creating-lenses (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A lens is a window with characteristic salience, weighting, and vocabulary. The matrix stays 2D by default (reference × task); a lens optionally shapes a distillation at projection time. This skill produces the spec the lens-applicability gate consumes.
Dialogue skill, one lens per session, no subagents. Output feeds creating-distillations Pass G: see projection-protocol.md §Lens-as-optional-framing for the four-outcome applicability gate.
Three kinds of lens are first-class: personifiable-archetype, named-real-person, non-personifiable-frame.
creating-distillations.A lens spec at corpus.commons/{corpus}/lenses/{lens-slug}.md. Slug conventions:
{role-or-archetype}-{distinguishing-circumstance}.md, e.g. engineering-manager-post-incident.md.{first-last}-{role-or-distinguisher}.md, e.g. jane-doe-acme-cfo.md. The slug names the person; the circumstance is in the file.{frame-name}-lens.md, e.g. loss-aversion-lens.md, queue-physics-lens.md.The spec has six sections. Every kind fills the same six sections; what each section contains differs by kind, the standard does not.
Read aloud to the operator:
A lens spec has six sections. The first decision, kind of lens, changes what every answer that follows will contain, so we'll commit early and revisit only if the kind turns out wrong. The standard for rigour is the same across kinds: a job described in verbs and nouns, circumstance or condition spelled out, what gets displaced when the lens is hired, a grounding contract that says where the lens's intelligence comes from and what it refuses.
Confirm the operator wants to proceed.
Three diagnostic questions. The operator commits to a kind at the end of this phase; the rest of the skill branches accordingly.
a) Is there a real person you can point to in the chair when this lens is in use, with their own published material to draw from?
If yes, with citable material (LinkedIn page, published posts, talks, interviews), and the operator wants the lens grounded in that person specifically: named-real-person. This is its own kind. The extra discipline: the source material is cited and treated as a mini-reference; the lens reads as if Jane Doe were reading, given what her public material reveals about her stance, not as Jane Doe. Ventriloquism is the failure mode and the grounding contract guards against it.
The self-case is a sub-kind of named-real-person, where the named person is the operator running the skill. The same six sections, the same grounding-contract discipline, the same ventriloquism guard — sharpened: reads as if {operator}-at-time-T were reading; it is not {operator}-now, and {operator}-now is the seer choosing to look through it. When source material in the operator's own voice is thin (fewer than two or three citable artefacts), do not run this skill directly. Use gridmaker-interview instead — it runs a structured 10–15 minute interview that generates the source material, then renders the lens spec following the template below. gridmaker-interview defaults to writing into corpus.local/personal/lenses/.
b) Without a specific person, is there a role-in-circumstance you can point to?
Not "a CEO": that's an adjective. "A CEO 48 hours after a P0 incident, regulator calling Monday, board chair asking for a one-pager": that's a circumstance. If yes, personifiable-archetype. If the operator answers in role labels with no circumstance, push back. Christensen's jobs-to-be-done discipline (Competing Against Luck, 2016) is what stops a role label from masquerading as a lens: the situation makes the lens specific, not the title.
c) If you imagine the lens reading something, does it read with a person's voice, or is it more naturally a frame of attention the tool applies?
If frame of attention: non-personifiable-frame. The loss-aversion lens reads through one principle; it has no idioms or anxieties of its own. The queue-physics lens reads pipelines as networks of utilisation and variability; it doesn't speak. Forcing a frame into person-form makes the tool cuter and worse.
Commit the kind in one short paragraph: which kind, and why this and not another. The kind is provisional through Phase 2; if the job spec doesn't survive the chosen kind, revisit.
Before moving to content, ask:
"What's the visibility of this lens?open(safe for any audience),open-nc(open with non-commercial intent),copyrighted(third-party material),confidential(client/engagement-bound), orpersonal(operator only)?"
Record the answer as visibility: in the lens frontmatter. No silent default. Every new lens must carry the declaration; if the operator does not answer, ask again.
Spec-location gate. If the operator selects copyrighted, confidential, or personal while authoring into corpus.commons/, warn:
"Lenses with visibility{level}cannot live undercorpus.commons/. The build will fail if the file lands there. Would you like me to author it tocorpus.local/{corpus}/lenses/{lens-slug}.mdinstead?"
Wait for the operator's decision before writing any file. For open and open-nc, proceed to corpus.commons/ as normal.
The visibility level determines where the file lands and which profiles ship it. Settling it now prevents a build failure later.
Every lens has a job. The job is what the lens is hired to do when the tool reaches for it. The circumstance (or condition) is what determines when this is the right lens to reach for.
The verb-and-noun rule applies across kinds. If the operator answers in adjectives ("the strategic lens", "the careful lens"), the jobs discipline applies: ask the verb-and-noun follow-up. What does this lens read, under what condition, and what does its read produce that another lens's read does not?
a. Name the job in verbs and nouns. Not "make sense of incidents". "Read this outage report the way a board chair would, looking for what protects the company's reputation when the regulator calls on Monday." b. Spell the circumstance. Where, when, with whom, what just happened, what comes next, what social or commercial pressure is on them. Richer constraint produces a more useful lens. c. Alternatives from different categories. What might the user reach for instead? Do nothing, use another lens, talk to a person, consult a different reference. If every alternative is another lens of the same kind, the job is drawn too narrowly. d. Hire requires fire. What older frame, instinct, or template does adopting this lens displace? This is the half people skip. Fires the board-narrative reflex of attributing outages to a single individual. Fires the 'we communicated benefits clearly' instinct. Specifically named; not vague.
Same skeleton as archetype, plus:
a. Source material is cited. Pull in the operator's LinkedIn URL, the three posts, the talk transcript. Each is treated as a mini-reference the spec carries forward. If the material is thin (fewer than two or three citable artefacts in the person's own voice), flag the lens as YELLOW in Phase 6: the operator can ship, but the grounding contract carries a probationary status. b. The as-if clause is explicit. "The lens reads as if Jane Doe were reading, given what her public material reveals about her stance": not as Jane Doe. The job description names the as-if explicitly. c. Ventriloquism guard. The grounding contract (Phase 4) names it. If the named-real-person lens drifts into putting words in Jane Doe's mouth that her source material does not support, the lens has failed the trust bar.
a. Name the frame in verbs and nouns. Not "queue physics lens". "Read this delivery pipeline as a network of queues whose throughput is governed by utilisation and variability, and surface the queue most starved or most flooded." b. Spell the condition. When in the tool's flow does this frame get reached for? On what kind of input? At what step? Condition is to a frame what circumstance is to a persona: same discipline, different name. c. Alternative frames. What else could the tool reach for to read the same situation? Where does this frame outperform; where is it dominated? d. What the frame fires. Adopting a queue-physics lens displaces the "more people will fix it" instinct. Adopting a loss-aversion lens displaces the "we communicated benefits clearly" instinct. Naming what gets displaced is what makes the lens actionable; without it, the lens is decorative.
If no job survives the discipline (verb-and-noun, circumstance or condition richly spelled, alternatives that cross categories, something specific gets fired) the lens does not have a job. Either rewrite it or recognise it as a flavour of an existing lens and merge.
Phase 2(d) named what gets fired. Phase 3 makes the fire explicit and tests it.
a. Is the fired frame named, or vague? Vague doesn't count. "Old way of thinking" is not a fire. "Fires the board-narrative reflex of attributing outages to a single individual" is a fire.
b. *Is the fired frame active in current outputs?* If the operator can't show an example where the fired frame currently produces the wrong reading, the new lens may be solving an imagined problem. Push for the example. (For library lenses, the example is a real query the existing distillations answer poorly through the missing frame.)
c. Will the fired frame go quietly? Habits don't surrender on instruction. If the fired frame is entrenched, the lens needs a displacement plan: repeated reweighting at retrieval time, contrast with the old read explicitly, or pre-projection at Pass G into the distillations where the fire most needs to land.
If the fire test fails (nothing named, no example, no displacement plan), the lens does not have purchase. Mark YELLOW in Phase 6.
This is the load-bearing section. The contract is the spine of the spec, not an appendix.
a. Where does the lens's intelligence come from?
b. What does the lens refuse?
c. Anthropomorphism guard. Phrase the guard in the lens file itself. A lens does not need to be personified. Agent is a convenient label for software that mimes human behaviour, but the underlying mechanism is different: no human greps a book. A lens shapes what the assistant reads through; it does not pretend to be a self doing the reading. Configuring a lens as if it were an agent loads in scaffolding (voice, motivation, anxieties) the runtime does not use and cannot honour.
d. Three trust-breaking failure modes, named concretely. Examples:
Render the spec as a single document. Save to corpus.commons/{corpus}/lenses/{lens-slug}.md. Template:
---
name: {Lens name}
kind: archetype | real-person | frame
slug: {lens-slug}
visibility: open | open-nc | copyrighted | confidential | personal
---
# {Lens name}
**Kind:** archetype | real-person | frame
**Purpose:** {one sentence: what this lens reads, under what condition, and what its read produces that other lenses' reads do not}
## Job × circumstance (or frame × condition)
{The verb-and-noun job statement. The circumstance or condition richly spelled. The alternatives the lens displaces, across categories. The fire-list: what older frame this lens replaces when adopted. For named-real-person: the as-if clause and the source material cited.}
## What the lens fires
{The named, current, displaceable frame this lens replaces when adopted. The example where the fired frame currently produces the wrong reading. The displacement plan if the fired frame is entrenched.}
## Grounding contract
- **Intelligence source:** corpus / synthesis / model priors / cited external material
- **Refuses:** {what the lens does not do}
- **Anthropomorphism guard:** {the as-if clause; the structural-voice rule; the alarm signal for drift}
- **Trust-breaking failure modes:** {three, named concretely}
## Source material (named-real-person only)
- {citations: LinkedIn URL, post titles and URLs, talk transcripts, interviews}
## Author anchors
- Christensen, *Competing Against Luck*: for the jobs framework that grounds the job × circumstance / frame × condition discipline.
- {others as they apply to the lens's intelligence source}
## Salience and vocabulary
{What this lens notices first. What recedes. The lens's native vocabulary. Specific. This is what the retrieval-time fallback in `projection-protocol.md` reads to apply the lens cheaply at query time when no pre-projected distillation exists.}
## Response modulation (when the task axis carries field 2a)
{Optional. When the lens applies to a task axis whose spec carries field 2a (trigger→response tables), describe how this lens reshapes the *response unit*. The trigger unit (what the practitioner observes) does not change under a lens; the response unit may shift to foreground different sources, vocabulary, or framings. Example: a *board-chair* lens applied to the AAR axis doesn't change the trigger "team converges on X made a mistake" but reshapes the response from a Just-Culture decision-tree teach to a *narrative-protection* teach. If lens-neutral on task-spec triggers, write *"no response modulation; lens applies at retrieval-time fallback only"*.}Render in the operator's voice. Avoid stock phrases. The salience-and-vocabulary section is what the retrieval-time fallback uses; write it specifically enough to be useful when no pre-projected (source, task, lens) distillation exists. The response-modulation section tells creating-distillations how to reshape the teach-in-the-moment scripts at Pass G.
Apply the heuristics:
GO if:
NO-GO (rework):
YELLOW (ship with explicit caveat):
After GO, two index-update steps before the lens is reachable at runtime:
Kind, Slug (as a [slug](slug.md) link), Purpose (one sentence, copy the spec's **Purpose:** line), Reach for when (one sentence, when this lens fires), Native vocabulary & salience. The salience cell follows a strict three-part shape the JSON builder parses: Notices first: <comma-separated phrases>. Recedes: <comma-separated phrases>. Native: *<comma-separated italicised phrases>.* Break this shape and the build fails.python -m scripts.build_indexes.build_lens_index --corpus {corpus}. The builder parses the LENS-INDEX.md table, splits the salience cell into the structured salience block (notices_first, recedes, native_vocabulary as a phrase list), and writes corpus.commons/{corpus}/lens-index.json. The JSON is what answer-from-corpus's lens-applicability check reads at runtime; the markdown stays as the operator-inspection view.Then point the operator at creating-distillations with this lens named (standalone, or via creating-applications orchestration when the lens applies across multiple distillations). The lens spec feeds Pass G's per-distillation applicability evaluation; it is not a substitute for it. The lens may apply to many distillations, a few, or none: the per-distillation gate decides.
creating-distillations and the runtime.creating-distillations: per-distillation projection. Takes a lens spec and decides per (source, task, lens) distillation whether to pre-project. See projection-protocol.md §Lens-as-optional-framing.creating-applications: orchestrates creating-distillations across the source set when assembling a new application; lens spec flows through the orchestrator to each per-distillation invocation.ingesting-resources: if the lens's intelligence source includes references not yet in the library, ingest them first.matching-references: if the lens is corpus-grounded and the operator is unsure which references anchor it, run this first.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.