# Why variant, break, and explain-interface Skills Are Disabled for Model Invocation

> Discover why variant, break, and explain-interface skills are disabled for model invocation. Learn how this protects against automated triggers and ensures human control over exploratory workflows.

- Repository: [Jakub Krehel/skills](https://github.com/jakubkrehel/skills)
- Tags: internals
- Published: 2026-09-12

---

**The `variant`, `break`, and `explain-interface` skills carry `disable-model-invocation: true` in their front-matter and `policy.allow_implicit_invocation: false` in their [`agents/openai.yaml`](https://github.com/jakubkrehel/skills/blob/main/agents/openai.yaml) configuration to ensure only human users—not automated models—can trigger these exploratory workflows.**

The jakubkrehel/skills repository maintains a strict architectural boundary between user-invoked and model-invoked capabilities. While many skills operate autonomously within AI-driven pipelines, these three specific skills are intentionally gated to prevent automatic execution of operations that generate experimental artifacts or require explicit human judgment.

## The Dual-Flag Policy in AGENTS.md

According to [`AGENTS.md`](https://github.com/jakubkrehel/skills/blob/main/AGENTS.md) at line 47, the repository implements a synchronized locking mechanism using two complementary flags across different AI harnesses:

> "`interface-review`, `variant`, `break` and `explain-interface` are the user-invoked skills. Each carries `disable-model-invocation: true` in its front-matter **and** `policy.allow_implicit_invocation: false` in its [`agents/openai.yaml`](https://github.com/jakubkrehel/skills/blob/main/agents/openai.yaml). Those are the Claude Code and Codex halves of the same switch, and must be set together, or the skill behaves differently per harness."

This dual-configuration ensures consistent behavior across both the Claude Code and Codex execution environments. The `disable-model-invocation` flag controls the Claude Code harness, while `policy.allow_implicit_invocation` governs the Codex side—together they create an exclusive user-invocation gate that is enforced regardless of which AI system processes the request.

## Architectural Rationale for Disabling Model Invocation

### Preventing Unwanted Exploratory Artifacts

The **`variant`**, **`break`**, and **`explain-interface`** skills generate exploratory or experimental outputs: design variants, robustness harnesses, or UI explanations. If models could invoke these automatically, they would spawn unwanted pages, temporary files, or noisy output without human supervision. Disabling model invocation ensures a human decides when these potentially voluminous artifacts are actually needed.

### Preserving the Orchestrator Hand-Off

The repository uses **`better-interface`** as a top-level orchestrator that aggregates findings from domain-specific skills and delivers a final verdict. If lower-level skills like `variant` or `break` could be invoked directly by models, they might bypass this orchestration layer, breaking the intended review pipeline. Restricting invocation to manual CLI commands forces all exploratory work to flow through the proper orchestration hierarchy.

### Maintaining Cross-Harness Policy Consistency

The jakubkrehel/skills repository supports multiple AI harnesses (Claude Code and Codex). Setting both `disable-model-invocation: true` in the skill's front-matter and `policy.allow_implicit_invocation: false` in [`agents/openai.yaml`](https://github.com/jakubkrehel/skills/blob/main/agents/openai.yaml) guarantees that the skill behaves identically across environments. Setting only one flag would create inconsistent behavior where a skill might be blocked in Claude Code but available to Codex, or vice versa.

### Avoiding Automatic Side Effects

These skills perform operations with side effects: writing temporary files, opening browser windows, or generating network traffic. Model-initiated runs could trigger these actions without explicit user consent, creating unpredictable system states. The restriction ensures that side-effect-heavy operations occur only after deliberate human initiation.

## Technical Implementation Details

Each restricted skill implements the policy through specific configuration files:

- **[`skills/variant/agents/openai.yaml`](https://github.com/jakubkrehel/skills/blob/main/skills/variant/agents/openai.yaml)** – Sets `disable-model-invocation: true`
- **[`skills/break/agents/openai.yaml`](https://github.com/jakubkrehel/skills/blob/main/skills/break/agents/openai.yaml)** – Sets `disable-model-invocation: true`
- **[`skills/explain-interface/agents/openai.yaml`](https://github.com/jakubkrehel/skills/blob/main/skills/explain-interface/agents/openai.yaml)** – Sets `disable-model-invocation: true`

Additionally, each contains the Codex-side restriction: `policy.allow_implicit_invocation: false`.

The central policy documentation in **[`AGENTS.md`](https://github.com/jakubkrehel/skills/blob/main/AGENTS.md)** explicitly lists these skills alongside `interface-review` as the exclusive user-invoked set, distinguishing them from the model-invoked skills that operate automatically within the pipeline.

## Manual Invocation Examples

Because these skills are excluded from model invocation, users must trigger them explicitly via CLI:

```bash

# Generate design variants (user-invoked only)

npx skills add jakubkrehel/skills
skills variant --count 5 --output ./variants

# Create robustness break tests (user-invoked only)

skills break --scenario network-failure --output ./break-tests

# Explain a UI interface (user-invoked only)

skills explain-interface https://example.com/login

```

Attempts to invoke these skills programmatically from other skills or automated pipelines will fail, ensuring the human-in-the-loop requirement is enforced at the configuration level.

## Summary

- **`variant`**, **`break`**, and **`explain-interface`** are exclusively user-invoked skills that cannot be triggered by AI models.
- The restriction relies on two synchronized flags: `disable-model-invocation: true` (Claude Code) and `policy.allow_implicit_invocation: false` (Codex).
- These skills generate experimental artifacts that would create noise if executed automatically.
- The restriction preserves the **`better-interface`** orchestrator's role as the central aggregation point.
- All three skills require manual CLI invocation to execute their side-effect-heavy operations.

## Frequently Asked Questions

### What happens if only one of the two restriction flags is set?

If a developer sets `disable-model-invocation: true` but forgets `policy.allow_implicit_invocation: false` in [`agents/openai.yaml`](https://github.com/jakubkrehel/skills/blob/main/agents/openai.yaml), the skill will behave inconsistently across harnesses. Claude Code will block model invocation while Codex might still allow it, creating unpredictable behavior depending on which AI system processes the request.

### Can models indirectly trigger these skills through the better-interface orchestrator?

No. The **`better-interface`** orchestrator aggregates findings from other skills but does not invoke `variant`, `break`, or `explain-interface` automatically. These skills must be triggered manually via CLI commands, ensuring the orchestrator's output remains focused on synthesis rather than initiating exploratory side-workflows.

### Are there other skills in the repository with these restrictions?

Yes. According to [`AGENTS.md`](https://github.com/jakubkrehel/skills/blob/main/AGENTS.md), **`interface-review`** shares the same restriction flags as `variant`, `break`, and `explain-interface`. These four skills constitute the complete set of user-invoked skills in the jakubkrehel/skills repository, while all other skills are available for model-driven invocation.

### Why are temporary file operations considered risky enough to require manual invocation?

Skills like `break` and `variant` write files to specified output directories and may open browsers or initiate network requests. In automated pipelines, these side effects could clutter file systems, overwrite existing work, or trigger external services without oversight. Restricting them to manual invocation ensures users explicitly specify output locations and consent to the operations.