# Zebrafish Production Kernel

Use this shared kernel for every Zebrafish production. It owns execution and
proof. A focused skill owns the judgment for its content or operational domain.
The current job owns its treatment.

## Three Layers

1. **Universal kernel:** live capability selection, provider-policy handling,
   budget control, provenance, deterministic probes, review evidence, admission,
   repair verification, and delivery binding.
2. **Content or operational skill:** domain-specific shape, craft, risk, and
   acceptance judgment. It compiles observable requirements for the kernel; it
   does not prescribe a provider or force every optional artifact.
3. **Task-local packet:** the brief, sources, treatment, script, storyboard,
   prompts, reference roles, claims, timing, budget, and revision decisions for
   this production. Keep these local to the work rather than turning them into
   permanent skill doctrine.

## Ground and Shape

Read the available Project context, supplied sources, and existing assets.
Separate supported facts from creative direction and unresolved assumptions.
Use the focused skill to shape the deliverable and identify the observable
states, actions, claims, landmarks, transitions, and risk windows that matter.

Compile only the acceptance units the artifact needs:

- A still uses spatial regions, visible landmarks, text or product states, and
  composition or anatomy risks.
- A social or poster layout adds intended viewing scale, crop or physical edge,
  exact-copy regions, output dimensions, and supplied platform, display, or
  print-production constraints.
- A video uses shots or beats, temporal windows, opening and closing states,
  identity or product landmarks, audio or copy claims, and transition risks.
- A pack uses per-asset roles plus cross-asset consistency and completeness.
- A long timeline adds sequence handoffs, continuity anchors, and coverage
  across the whole assembly.
- A web page uses content blocks, claims, headings, links, metadata, and
  rendered viewport or interaction states, plus page-level hierarchy and
  destination continuity.

Do not require a storyboard, script, reference image, or workflow merely because
the skill can use one. Require it only when the brief or the chosen execution
path needs it.

## Choose Live Execution

Inspect the operations and models available now. Select an operation by required
modality, duration, aspect ratio, language, reference support, output controls,
cost, latency, and policy compatibility. A direct operation and a workflow are
both valid when runtime validation accepts them.

Before spend:

- validate the exact operation inputs and reference roles;
- check identity consent and whether the provider accepts the proposed reference
  type, especially photorealistic human likenesses;
- reconcile opening states with requested first actions;
- estimate the chosen tier, variants, retries, and a repair reserve against the
  approved budget; and
- bind the dispatch to the selected operation and model tier.

Schema-valid input can still fail provider or partner policy. On failure, retain
the canonical response in protected operational evidence and surface only a safe
classification: provider, HTTP status, stable category, safe field path, safe
reason, and retryability. Never return a raw provider body, prompt, signed URL,
or private input. Do not spend on a materially equivalent retry after a
non-retryable content-policy or partner-validation rejection. Change the
reference strategy or operation only when the new path is genuinely compatible.

## Inspect and Admit

Review the actual returned bytes, not a prompt, plan, URL string, or metadata
record. Use the shared media-review contract and actual-artifact analyzer when
the modality is supported. For text, documents, HTML, and live pages, use
deterministic parsing plus source, DOM, link, and rendered-state evidence
appropriate to the domain. Do not imply that media admission inspected a
non-media artifact.

1. Observe the artifact blind before using the brief.
2. Run deterministic probes appropriate to the medium: decode and corruption,
   dimensions, duration, audio presence, frozen or black intervals, and safe-area
   geometry where applicable.
3. Distribute evidence across declared units and target high-risk windows.
4. Reconcile blind observations with the brief in a disposition ledger.
5. Report structured findings with strength, location or time, severity, cause,
   repair, and any unresolved blocker.
6. Let app-owned admission decide delivery eligibility from coverage, evidence,
   unresolved blockers, and receipt integrity when the artifact uses the media
   review runtime. For non-media work, bind the verdict to the exact reviewed
   revision and declared states through the available delivery workflow.

A technical pass is not creative approval. Extra anatomy, contradictory state,
identity or product drift, malformed visible text, broken continuity, inert
performance, or an unproved required claim can still block delivery.

## Repair and Bind

Repair the diagnosed cause while preserving named strengths. Re-run review on
the changed bytes and measure whether the target variable actually changed.
Different bytes alone do not prove a repair.

Bind delivery to the final reviewed generation and SHA-256. Failed, incomplete,
uninspected, degraded, mismatched, or superseded artifacts remain ineligible.
