The bin/ toolbelt

August 29, 2026 ยท View on GitHub

The first mate drives these; interactive entrypoints work by hand too, while *-lib.sh files are sourced helpers. Each row is one purpose clause only: the script's own header comment is the authoritative description of its behavior, flags, and contracts, so read the header before first use. If you have changed away from the firstmate home in an interactive shell, invoke these scripts by absolute path through the repo's bin/ directory; the scripts self-locate internally after they start. The shared no-mistakes gate refusal for fleet lifecycle entrypoints is summarized in architecture.md, while docs/sessionstart-nudge.md covers the silent session-open hook use; fm-gate-refuse-lib.sh's header owns its exact contract.

ScriptPurpose
fm-session-start.shCompose lock, bootstrap, and wake drain into the single ordered session-start digest
fm-sessionstart-nudge.shPrint the native session-start hook nudge when the primary has not already run the digest
fm-sessionstart-run.shRoute a native session-open hook to the full digest, a context re-emit, or the nudge
fm-operational-input.shConstruct and parse the canonical cross-language operational-input protocol
fm-bootstrap.shDetect toolchain and fleet problems, run the locked session-start sweeps, and install approved tools
fm-startup-network.shRun session start's network checks off its blocking path, retaining every report while waking only for actionable results
fm-fleet-sync.shRefresh project clones with safe fast-forwards, self-heals, STUCK: reports, branch pruning, and bounded recovery from an orphaned .git/packed-refs.lock
fm-fleet-snapshot.shPrint the read-only structured fleet snapshot JSON (schema fm-fleet-snapshot.v1)
fm-home-summary-refresh.shAtomically publish this home's structured summary ledger
fm-fleet-view.shRender the fleet snapshot as a human Markdown view
fm-bearings-snapshot.shProject the fleet snapshot to the compact TOON bearings view; local-only unless --include-prs
fm-bearings-board.shBuild and arm the stable interactive /bearings lavish fleet board
fm-secondmate-reconcile.shAsk each secondmate to reconcile an inventory mismatch through its durable inbox, limited by a per-home cooldown
fm-update.shFast-forward-only self-update of firstmate and local or remote secondmate homes
fm-on.shExecute one tracked Firstmate command in a configured remote secondmate home, using its job worker except for the doctor bootstrap
fm-remote-job-lib.shShared bounded remote job queue, worker readiness, LaunchAgent contract, and filesystem-composed PATH
fm-remote-job-worker.shLong-lived remote queue worker for tracked fm-*.sh commands in the account runtime
fm-remote-job-reap-orphans.shStop remote job workers left running by a pruned code root, never one whose checkout still exists
fm-remote-doctor.shCheck, and with --fix repair, one remote account's second-mate readiness (remote job worker, Herdr, Aqua launch agents, PATH, and required tools)
fm-backlog-handoff.shMove queued backlog items into a secondmate home and durably wake its recorded receiver
fm-backlog-receive.shIdempotently ingest one confined remote handoff outbox through tasks-axi
fm-captain-hold.shHold tasks for the captain, record the captain's answers, gate investigation completion, and report record divergence between the status log and the backlog
fm-decision-hold.shOne-release compatibility shim mapping the retired decision commands onto fm-captain-hold.sh
fm-brief.shScaffold ship (explicit --mode), scout, secondmate-charter, and Herdr-lab briefs
fm-herdr-lab.shProvision and guardedly operate an isolated, never-default Herdr lab session
fm-install-herdr.shInstall CI's exact-version Herdr pin with official asset URL, SHA-256, and protocol checks
fm-install-treehouse.shInstall CI's exact-version Treehouse pin for real-Herdr E2E that needs spawn worktrees
fm-herdr-ci-cleanup.shSnapshot and tear down only job-owned fm-lab-* sessions in the Herdr CI lane
fm-test-run.shBehavior-test runner: selection, portable lanes, bounded concurrency, budgets, coverage guard, timing/JSON
fm-test-isolation-proof.shConcurrent isolation harness and portable candidate set owner
fm-ensure-agents-md.shEnsure a project's real AGENTS.md, its CLAUDE.md @AGENTS.md pointer, and the canonical self-governance section
fm-guard.shWarn on primary-checkout tangles, pending queued wakes, and unhealthy supervision
fm-primary-scope-lib.shShared marker-or-plain-checkout primary-home predicate for tracked hooks
fm-session-lock-lib.shShared session-lock harness identity (ancestry walk and holder liveness) for fm-lock.sh and the Claude Stop auto-arm
fm-claude-stop-autoarm.shClaude Stop asyncRewake hook owning tokenless watcher continuity with single-flight exit-2 rewake (docs/watcher-continuity.md)
fm-turnend-guard.shShared primary turn-end guard predicate so no turn ends blind (docs/turnend-guard.md)
fm-turnend-guard-grok.shGrok Stop-hook adapter for the primary turn-end guard
fm-kimi-turnend-hook.shSurgically install or remove Kimi's guarded global crew turn-end hook
fm-arm-pretool-check.shStable PreToolUse transport for the watcher-arm command policy (docs/arm-pretool-check.md)
fm-arm-command-policy.mjsSemantic owner of the watcher-arm PreToolUse policy (docs/arm-pretool-check.md)
fm-subagent-pretool-check.shPrimary-home delegation-shape PreToolUse guard (docs/subagent-guard.md)
fm-supervision-instructions.shRender the session-start primary-harness supervision block or the one-line repair instruction
fm-home-seed.shTransactionally provision a local secondmate home and maintain data/secondmates.md
fm-remote-home-seed.shRegister and provision a whole secondmate home on an SSH-reachable host
fm-remote-readiness-lib.shShared remote second-mate readiness gate: check and, when needed, repair then re-check through fm-remote-doctor.sh
fm-project-origin-lib.shAccepted origin-form owner shared by both remote provisioning boundaries
fm-spawn.shSpawn crewmates, scouts, id=repo batches, and secondmates on the resolved harness and runtime backend
fm-backend.shRuntime-backend selection, meta helpers, selector resolution, and operation dispatch
fm-backend-hometag-lib.shShared per-installation home-tag derivation for zellij tab and cmux workspace titles
fm-composer-lib.shSingle fleet-wide owner of composer shapes, capability-aware screen classification, and verdicts
backends/tmux.shVerified tmux session-provider adapter
backends/herdr.shExperimental herdr session-provider adapter
backends/zellij.shExperimental zellij session-provider adapter
backends/orca.shExperimental Orca backend adapter owning both worktree and terminal
backends/cmux.shExperimental cmux session-provider adapter
fm-config-push.shPush declared inherited local material to live local or remote secondmates and send the placement-specific config reread when changed
fm-project-mode.shResolve a project's registered delivery posture from data/projects.md for fleet sync and home seeding
fm-merge-local.shFast-forward a local-only project's local default branch after approval
fm-review-diff.shReview a crewmate branch or resolved PR head against the authoritative base
fm-marker-lib.shCompatibility entry point for the from-firstmate carrier owned by fm-operational-input.sh
fm-task-inbox-lib.shSingle owner of durable steering-inbox records, acknowledgement, doorbells, and the delivery-attempt ladder
fm-pending-reply-lib.shParent-owned secondmate pending-reply expectations, recovery, and keyed escalation lifecycle
fm-secondmate-report.shOptional helper to append a correlated parent status or document-pointer report
fm-procevent-remote-reply.shRelay the remote-secondmate status stream through non-destructive process-event deltas
fm-procevent-when.shFire a trust-bound deterministic action at most once when its registered condition holds, then wake with the outcome
fm-gate-refuse-lib.shShared no-mistakes gate-context refusal for fleet lifecycle entrypoints
fm-watch-arm.shVerified home-scoped watcher arm wrapper with loud cycle endings and bounded lifecycle ledger
fm-watch-checkpoint.shRun one bounded foreground watcher checkpoint for Codex-style supervision
fm-watch.shSingleton-safe watcher: absorb benign wakes, detect stalled local-secondmate wake queues, and exit on actionable ones
fm-inactive-reconcile.shReconcile long-inactive direct crewmate terminal outcomes without forge access
fm-afk-start.shRun the common sourceable away-mode daemon entry in the foreground
fm-afk-launch.shOwn away-mode entry, exit, rollback, and any backend terminal lifecycle
fm-afk-return.shOwn deterministic return shutdown, catch-up evidence, and the firstmate-actionable blocker gate
fm-supervisor-target-lib.shResolve the shared supervisor target and backend for the daemon and launcher
fm-supervise-daemon.shPresence-gated away-mode sub-supervisor: self-handle routine wakes, guard injection by the detected primary harness, escalate batched digests, alert on failed delivery
fm-crew-state.shPrint one deterministic current-state line for a crew
fm-nm-run-lib.shSingle owner of shared no-mistakes run-attribution primitives and rules
fm-tangle-lib.shShared default-branch resolution and primary-checkout tangle classification
fm-timeout-lib.shSingle owner of hard-bounded command execution and its fallback watchdog
fm-timing-lib.shSingle owner of the deferred network stage's per-step elapsed-time records, inert unless a run asks for them
fm-supervision-lib.shShared in-flight-work-without-fresh-watcher-beacon predicate
fm-ff-lib.shShared guarded fast-forward helper for origin pulls and local secondmate syncs
fm-lock-lib.shShared "is this git lock provably abandoned?" proof used by teardown and fleet-sync
fm-config-inherit-lib.shShared primary-to-secondmate inherited local-material propagation and config-reread delivery
fm-tasks-axi-lib.shShared backlog-backend selector and tasks-axi compatibility probe
fm-quota-axi-lib.shShared quota-axi compatibility floor for the bootstrap diagnostic
fm-vendor-auth-probe.shRun one hard-bounded, non-destructive authentication probe of a named vendor CLI and report the fact
fm-wake-drain.shPresent and acknowledge the current actor's claimed wake rows alongside status, decision, divergence, recovery, and supervision checks
fm-wake-grant.shSerialize Pi supervision-branch wake-row claim activation, publication, release, and deactivation
fm-wake-lib.shShared durable wake queue, recovery generations, portable locks, and watcher identity/health helpers
fm-classify-lib.shShared wake-classification vocabulary, durable keyed-decision folds and scans, and unread informational status-line selection
fm-send.shSteer a task via a durable inbox record plus doorbell, or send a supported key or typed harness invocation through the recorded backend
fm-branch-prompt.shEmit the Pi supervision branch's byte-stable system prompt (pi-supervision-branch.md)
fm-branch-outcome.shOwn the supervision branch's append-only outcome store, read cursor, and session-start replay
fm-lease.shClaim, release, inspect, and sweep per-task supervision leases
fm-lease-lib.shOne owner of the supervision lease contract and the main-only role-partition guards
fm-control.shAgent lifecycle control plane: allowlisted interrupt, exit, and transactional relaunch verbs for an exact task id (agent-control.md)
fm-control-lib.shOne executable owner of the control-plane verb allowlist, per-harness interrupt/exit mechanics, and per-backend capability
fm-busy-lib.shSingle owner of the semantic busy-state contract: verdicts, source attribution, and per-harness sources
fm-busy-event.shThe only writer of a task's semantic busy-state record; arms an incarnation and applies lifecycle events
fm-tmux-lib.shShared tmux pane primitives for composer capture, verified submit, and the submit-time busy check
fm-peek.shPrint a bounded tail of a crewmate endpoint
fm-check-register.shBind an intentional custom watcher check to its current bytes
fm-check-lib.shValidate custom-check registrations and prepare private execution snapshots
fm-tool-update-check.shReport watched tooling with an update available, and updates installed but left inert by PATH order
fm-pr-lib.shOwn canonical task and PR validation plus private atomic PR-poll publication, merge-notification identity, and retirement
fm-pr-poll.shProvide the byte-static watcher program for validated PR/MR-poll sidecars
fm-pr-check-migrate.shQuarantine older task polls without execution and rebuild only canonical polls
fm-pr-check.shRecord validated pr= and pr_head= values, then atomically arm a static merge poll
fm-pr-merge.shRecord PR metadata, merge a task's canonical full GitHub or GitLab URL, then refuse an outcome it cannot prove landed or queued
fm-merge-outcome-lib.shPublish a confirmed merge's durable, role-routed supervision outcome
fm-promote.shPromote a scout task in place to a protected ship task with an explicit delivery mode
fm-teardown.shFail-closed teardown: return landed ship worktrees, require completed scout deliverables, retire secondmate homes
fm-harness.shDetect the running harness and resolve crew or secondmate harness, model, and effort
fm-lock.shPer-home firstmate session lock
fm-x-lib.shShared Relay config, relay, and reply-threading helpers
fm-x-poll.shOne bounded Relay poll: stash newly offered mentions and emit their once-only wake
fm-x-reply.shPost or dry-run preview a composed Relay reply or follow-up
fm-x-dismiss.shDismiss a skipped Relay mention at the relay without replying
fm-x-link.shLink a spawned task to its originating Relay mention in task meta
fm-x-followup.shDetect, post, and cap completion follow-ups for a Relay-linked task
fm-public-followup-lib.shShared Relay gate, open-loop registry state, expiry classification, locking, and private transport paths
fm-public-followup.shReconcile and deliver typed public commitments, then rechain or explicitly retire their retained loops
fm-public-followup-emit.shReport one typed terminal work result into the home that owes the public reply
fm-inbox.shThe captain's out-of-band capture surface: queue a note, dictate one, read status, ask a side question
fm-voice-relay.pyHold the spoken conversation on this host, answer from the records, and hand real work to fm-inbox.sh (voice-relay.md)
fm-voice-client.pyThe laptop end of the spoken interface: capture, playback, and turn timing over SSH; audio devices unverified
fm_voice_frame.pyThe wire format both machines share, copied to the laptop beside the client
fm_voice_records.pyWhat a spoken answer may read, and the handover that queues real work