efe41abde0
Tracker #79686 P3. Every skill mutation — curator, agent, or user — now appends one entry to the append-only JSONL ledger at ~/.hermes/skills/.curator_ledger.jsonl, with per-file before/after manifests whose contents are stored content-addressed (sha256-deduped) under ~/.hermes/.curator_backups/blobs/. - tools/skill_ledger.py: append/list/get, blob store, actor derivation (curator|agent|user), single-entry rollback that takes a pre-rollback safety entry first and FAILS CLOSED when that capture fails (consistent with the whole-run tarball rollback hardening from #63366). Path containment check so a hand-edited ledger can't write outside HERMES_HOME. - Hooked all three choke points: skill_manage() dispatch (all actors, delete intent recorded via absorbed_into/archived evidence), archive_skill()/restore_skill(), and curator auto-transitions (tagged actor=curator via a ContextVar override). - Ledger failures never block the mutation — telemetry, not a gate. Config gate skills.ledger (default true). - hermes curator ledger [--skill NAME] [--limit N] and hermes curator rollback <entry-id> (whole-tree snapshot rollback unchanged). - Optional TTL purge of skills/.archive/: curator.archive_ttl_days (default 0 = never) + explicit hermes curator purge, recorded in the ledger with before-blobs so purges stay recoverable. - Docs: curator.md sections on the ledger, single-edit rollback, and archive TTL purge. Curator invariants unchanged: only created_by:agent skills auto-transition, never hard-delete autonomously, pinned exempt; foreground user deletes stay hard-delete (and are now recoverable via the ledger). Closes #45778, #50875. Tests adapted from #50261 by @yu-xin-c.