Engineering · Tooling

Building the KXCO Skill Set for Claude

An organisation accumulates standards: how a figure gets sourced, what a plan must survive before it is built, which words never appear in published copy. Those standards usually live somewhere passive, and a standard in a document is advisory. It gets applied when the work is routine and skipped when it is urgent, which is precisely backwards. Here is the fifteen-skill set KXCO built to close that gap, what each part does, and the separation of method from estate that makes internal tooling safe to distribute at all.

By Shayne Heffernan 30 August 2026 ~15 min read Claude skillsProvenanceAI governanceRound Table

01 · Why a skill set at all

Claude supports skills. A skill is a folder holding one Markdown file. That file carries a name, a description, and a set of instructions. When the description matches what you are doing, or when you type the skill's name after a slash, the instructions load and Claude works differently for that task.

That is the whole mechanism. There is nothing clever underneath it, and that is exactly why it is worth taking seriously.

The problem it solves is specific. An organisation accumulates standards: how a figure gets sourced, what a plan must survive before it is built, which words never appear in published copy. Those standards usually live in three places, all of them weak. In someone's head. In a document nobody rereads. In a chat history that scrolls away.

A standard in any of those places is advisory. It gets applied when someone remembers to apply it, which is to say inconsistently, which is to say when the work is unimportant and never when it is urgent.

A skill is different in one respect that matters: it is loaded automatically at the moment the work happens. Not consulted. Loaded.

We audited our own position before building anything. Forty-one skills were installed on the primary development machine. Thirty of them were vendor documentation for a graph database. Not one encoded a KXCO standard. Every rule we actually operate by lived in notes.

That is the gap this work closes.

02 · What was built

Fifteen skills, in three installable packages, distributed through a private marketplace with access granted per person.

Thirteen were written at KXCO. Two are open source, included unchanged with their licences intact.

kxco-prompt

Nine skills that operate before Claude starts work.

The premise is unglamorous and correct: most poor output is a poor brief. Model capability has moved faster than the average request has improved, and the gap between what someone asks for and what they meant is now the dominant source of wasted work.

SkillWhat it does
/prompt-masterTakes an unstructured brain dump and returns one clean, runnable prompt. Identifies the target tool first, because a prompt for Claude is not a prompt for an image model.
/grill-meInterviews you in rounds. Each round asks every question whose prerequisites are already settled, and attaches a recommended answer to each. Your answers reshape the tree and the next round asks what they unblocked.
/how-toFor when you know the outcome but not the method or the vocabulary. Maps the route, names the terms you were missing, and hands you a prompt for step one.
/5Tunes a prompt for Claude Opus 5.
/fableTunes it for Claude Fable 5.
/personal-voiceEncodes a specific writing voice so output arrives in it on the first pass.
/anti-aiStrips the constructions that mark writing as machine generated.
/write-a-skillTurns a prompt you have retyped three times into a permanent skill.
/handoffCompresses a working session into the opening message of the next one.

Two of these deserve expansion.

/grill-me is the highest value skill in the package and the one people skip. It is not a code tool. It works on a hiring decision, a pricing model, or a partnership structure exactly as well as on an architecture. What it does is refuse to let an underspecified plan proceed by asking, one branch at a time, the questions whose answers you have been avoiding because you did not have them.

The discipline that makes it work is subtle. It asks the whole answerable frontier each round, not one question at a time and not everything at once. A question whose answer depends on another question still open belongs to a later round. That ordering is what stops the interview from asking you to guess.

/5 and /fable exist because the models genuinely differ, and the difference is counterintuitive.

Claude Opus 5 runs adaptive thinking by default. Instructions like "think step by step" and "take a deep breath" were useful on earlier models. They now cost tokens and buy nothing, and in some cases flatten output by constraining reasoning that would have gone further unprompted. The lever that replaced them is effort, which takes five levels. Persona padding is similarly dead weight: "you are a world-class expert with twenty years of experience" changes nothing. State the actual constraint instead, meaning the audience, the standard and the format.

Claude Fable 5 inverts something people assume is universal. A prescriptive step-by-step prompt makes Fable 5 perform worse. Opus 5 tolerates a tight recipe. Fable wants the goal, the constraints and the definition of done, and then wants you out of the way. Migrating a prompt between the two is not a copy, it is a rewrite in the opposite direction.

/anti-ai earns its place through one specific thing it catches. The em dash is the most reliable single tell of machine written copy, and a plain search for the character misses the HTML entity forms. —, — and — all render as an em dash and all survive a naive sweep. That is not hypothetical. It happened on a KXCO page that had already passed a manual check.

kxco-truth

Four skills. This is the package that is not for general distribution, and the reason the repository is private.

/evidence enforces the standard the Round Table already operates under, stated as it was agreed:

Every assertion carries a source that resolves and demonstrably supports it, and anything that fails is visibly marked.

Alongside it, always, the ceiling:

Verification proves we faithfully recorded what a credible source said. It does not prove the source was right.

The ceiling is not modesty. It is what makes the standard survive contact with someone hostile. A claim of absolute truth dies on its first counterexample. A claim about faithful recording is defensible indefinitely because it is accurate.

The skill sorts every citation into one of eight verdicts, and the separations matter more than the labels:

resolves · resolves-unsupported · moved · composed · gone · inconclusive · unsourced · derived

Three of those distinctions do real work.

inconclusive is not gone. A 401, 403, 429 or 503 means bot-walled or paywalled, not dead. On a real corpus this bucket has run to roughly one URL in seven, and whether it resolves depends on whose browser is logged in to what. Counting it as a failure understates the corpus. Counting it as a success overstates it. The honest move is a third bucket and a sentence saying that share is unenforceable by machine.

moved is not gone. Large outlets restructure. Triaging a moved article as a dead one generates work that fixes nothing.

composed is the one almost nobody checks for, and it is the finding this package exists because of.

A batch of URLs in one of our own records read as dead. Nearly every one that was checked resolved to a real article at a different address. The addresses had been rebuilt later from the outlet, the headline and a rough date, rather than retained from the original fetch.

The test that separates it from link rot is clean. Link rot deletes the page and leaves the address alone. Nothing that happens to a live article changes only its date segment. So an address whose slug is byte-identical to the real one but whose date is wrong was composed, not rotted. Equally, an address whose slug is the headline run through a slugifier, where the outlet uses an editorial slug, cannot have been derived from the real one in either direction.

This is not fabrication, and saying so precisely is part of the finding. The articles were real. The headlines were right. Every claim checked was supported by the piece it pointed at. The analysis could be trusted. Only the address field could not.

Getting that distinction backwards would have destroyed confidence in a body of work that was sound. That is why the skill states it in those terms rather than leaving it to the reader.

/lineage answers one question, as a chain: where did this number come from. Each hop named, ending at a document a person can open. If the chain breaks, it reports the hop that broke. A broken chain reported is a finding. A broken chain papered over is what destroys a standard.

It carries the query traps that produce silently wrong answers on our graphs. Magnitude is present on a minority of edges, so summing it produces a confident and wrong total. Direction is prose rather than structure, because the predicate is a sentence, so a dependency walk must be undirected and the result is blast radius rather than flow. Both of those return a plausible number if you get them wrong, which is the dangerous kind of error.

/resolve decides whether two records are the same entity. Its central rule is a refusal: never merge on a name. Not on a fuzzy match, not on high string similarity, not on the same name in the same country. A merge requires an identifier that a registry actually issued, meaning a CIK, an LEI, a company number, an ISIN, a domain, a tax identifier.

The trap it carries from experience is that street addresses lie about jurisdiction. A registered office, a trading address and a manufacturing site are three different places, and only one of them tells you the country. Reading country off the wrong one produces wrong jurisdictions at scale, quietly.

Every merge produces a record naming the survivor, what was absorbed, the identifier that carried it, the confidence, the evidence, the person who decided, the date, and the retained absorbed record. Reversible by construction. And negatives are recorded too, because a decision that two similar records are different entities is as valuable as a merge, and without it the same investigation runs again in six months.

/ingest exists to enforce one rule: retain, do not reconstruct. Nearly everything that later reads as decay began as something recorded loosely and rebuilt from memory afterwards. Keep the URL exactly as fetched. Hash the document on arrival. Record the fetch time separately from the time the fact was true. Snapshot anything bot-walled at the moment of assertion, because a citation that depends on a logged-in browser is unenforceable from then on.

kxco-council

Two skills.

/council runs the five planning seats as an enforced sequence rather than a document that gets read once: Strategist, Architect, Critic, owner approval, Reviewer, Scribe.

One change from the document is worth calling out, because it generalises well beyond us.

The Critic now runs from fresh context. It is dispatched with the plan and nothing else. No transcript, no reasoning, no history.

The reason is that a critic who watched the plan being built has already been persuaded by it. It sat through the argument. It will wave the plan through, and it will do so while producing critique-shaped output, which is worse than no critic at all because it manufactures false confidence. Self-verification misses what it wants to miss.

This is the same insight that shows up in adversarial verification for mathematical proofs, where fresh-context verifiers attack the proof and reliably catch what the prover's own check does not. It is not a KXCO invention. It is a KXCO application of something that was sitting in plain sight.

A second rule sits alongside it: an objection is closed by answering it, never by proceeding past it. Unanswered Critic objections stay listed on the plan. Our own truth standard plan currently carries five, openly.

/KXCOSKILLS is the master switch.

Here is what it honestly is, because the name promises more than any command can deliver. It cannot load fifteen sets of instructions simultaneously, and a version that tried would be worse than useless, because the instructions that matter would drown under database documentation.

What it does instead is the thing that was actually wanted. It turns on the house rules for the remainder of the session. It declares the full arsenal in one place so nothing is forgotten for being out of sight. It routes the task in hand to the skills that apply and says which and why. And it runs four standing chains without being asked again:

BUILD      grill the brief, council it, owner approves, build, review, record
PUBLISH    source every figure, put it in voice, strip the tells, then ship
KNOWLEDGE  collect, resolve the entity, ingest with provenance, verify, audit
DEFEND     someone challenges a number, walk it back, answer plainly

03 · Distribution, and the separation

The skills are distributed as a private plugin marketplace: a GitHub repository holding a manifest and three plugins. Access is granted per GitHub account.

claude plugin marketplace add KnightsbridgeAIQ/kxco-skills
claude plugin install kxco-prompt@kxco-skills
claude plugin install kxco-truth@kxco-skills
claude plugin install kxco-council@kxco-skills

Two commands and a restart. Improvements reach everyone through claude plugin update, which is the entire argument for a repository over a file that gets emailed around. A zip diverges the moment it is opened.

The design decision worth documenting is the split between method and estate.

A pre-distribution review of the skill files caught a database password sitting in a runnable command, alongside internal ports, container names, expected graph counts and an itemised defect list. All of it useful to the skill. None of it shippable. That review is why a private repository is safe to grant against, and it is the step most teams distributing internal tooling never run.

The separation:

  • The repository carries the method. How to decide, what to refuse, which distinction matters.
  • A local file carries the estate. Ports, container names, credentials by reference, expected counts, open defects.

Where a skill needs a specific, it names the local file. If that file is absent, the skill instructs the reader to establish the fact rather than guess it. /lineage does not say "use port 7688". It says probe first, identify the graph by its shape, and never trust a result whose node count you have not confirmed. That is better guidance anyway, and it happens to be portable.

The password became an environment variable, which it should always have been.

Three principles came out of that pass and are worth carrying into anything similar:

  1. A secret in a skill is a secret in every copy of that skill. There is no such thing as a private instruction file once it is distributed.
  2. An itemised defect list is not distributable, even privately. Our own publication rule is to fix quietly, publish the coverage percentage, and never itemise failures outside. A repository grant is a disclosure.
  3. Access is a one way door. Revoking someone stops future updates. It does not retrieve what they cloned. Treat every grant as permanent disclosure of everything in the repository at that moment.

That last point is why kxco-truth is a separate plugin from kxco-prompt. The nine prompt skills can be given to anyone. The provenance stack is the differentiator, and it can be withheld without withholding the rest.

04 · What this is worth

Every firm using Claude has the same model. What is not commodity is whether the output can be defended.

These skills remove the gap between the standard an organisation holds and the standard it actually applies under time pressure. That gap is where reputational damage lives. A figure published without a source that supports it, a plan built without surviving a real critic, a merge that quietly welded two companies into one node: none of those happen because anyone decided to be careless. They happen because the discipline was advisory and the deadline was not.

The /evidence skill is under seven thousand bytes, and that is the point. Behind it sits a set of decisions taken over months, each one paid for by a specific failure, now written down in the only place they will be read: at the moment the work is being done. Size is not the measure. Whether the rule is present when the deadline is not is the measure.

05 · The build queue

What is scheduled next, in order.

A coverage artefact on every provenance skill. /evidence demands that a verification stamp carries a verifier, a date and a method, or it is itself an unsourced claim. It should meet its own standard. Each run emits a record naming the corpus by hash, the claim count, the method, the date and the bucket counts, derived from the run rather than written by hand. That makes the control self-verifying: the artefact cannot exist without the work, and its absence is visible under a mandate. Same change for /lineage and /resolve.

The composed-address repair. The test found seventeen rebuilt addresses in the AI Sector record. Thirteen of the fourteen checked resolve to real articles at different addresses. Each gets its retained address recovered and verified against the claim it supports.

The wider sweep after it. Six of forty-seven CNBC links return 404 and CNBC is the largest source host, so moved gets triaged separately from gone. And the analyst summary strings have not been swept for the staleness found in one of them, where the prose ran years behind the claim data sitting beside it.

Finance connectors. The modelling skills run on supplied data today. The data-pull half needs vendor subscriptions, which is a commercial decision rather than an engineering one.

f:\Development under version control. Unrelated to this work and more urgent than any of it. The skills now live in a repository. A great deal else does not.

The companion piece on Live Trading News argues the position. This is the reference.

06 · Frequently asked questions

What is a Claude skill, in one sentence?

A folder containing one Markdown file that carries a name, a description and a set of instructions, which Claude loads automatically when the description matches the task or when you type the skill name after a slash.

Why not just write the standards in a document?

A document is read once on arrival and then competes with a deadline every day after. A skill is loaded at the moment the work happens, so skipping it requires a decision rather than a lapse.

Does a skill actually enforce anything, or is it advisory?

On its own it is an instruction layer. Under a mandate where use is verified at output, it is a control, because non-compliance becomes visible rather than silent. The coverage artefact on the build queue closes the remaining gap by making the record of a run derivable only from an actual run.

What is a composed address and how is it different from link rot?

Link rot deletes the page and leaves the address alone. A composed address was rebuilt after the fact from the outlet, headline and a rough date rather than retained from the original fetch, so the article is real and only the address string is wrong. An address whose slug is byte-identical to the real one but whose date segment differs was composed, because nothing that happens to a live article changes only its date.

Why is the repository private?

The prompt skills could be given to anyone. The provenance skills are the differentiator. Access is granted per GitHub account, and a grant is permanent disclosure of everything in the repository at that moment, because revoking access stops future updates but does not retrieve what was already cloned.

Can these skills be used outside KXCO?

The method is portable and deliberately so. The repository carries how to decide and what to refuse; a local file carries this estate's ports, credentials and counts. Where a skill needs a specific and the local file is absent, it instructs the reader to establish the fact rather than guess it.