VFS.md and SKILL.md
Both documents are optional. Nothing is added by default. Generate Markdown without a path, or pass an absolute virtual path to expose a live, read-only file there.- VFS.md describes visible mount paths, backend types, effective access modes, and available navigation guidance. It does not enumerate backend files or include credentials. Under restricted profiles it omits backend prose that could advertise hidden paths or commands.
- SKILL.md is one self-contained skill with frontmatter and help for visible registered CLIs: descriptions, subcommands, positional arguments, option value names, choices, defaults, and environment-variable names. A script that parses its own arguments has only its registered description; MIRAGE does not run arbitrary programs to discover help.
- Python
- TypeScript
/SKILL.md works at the root without a /skills mount. /skills/mirage/SKILL.md requires that parent directory to exist. MIRAGE does not install host skills or create missing directory trees. These are live bindings for the running workspace; recreate them after loading a snapshot or restarting the workspace. Their generated content is not persisted to backend storage.
The profile selector previews Markdown without changing a session or adding a file. To expose a document for a profile, create or select a session with that profile and call its method with a path.
CLI
The workspace commands call the daemon API. With no--path they print Markdown; with a path they expose the file inside MIRAGE.
--help; the default help style also supports -h when a CLI has not assigned it another meaning. man <cli> [subcommand...] uses the same help renderer. which <cli> and /usr/bin/<cli> refer to the registered executable. Group options go before the subcommand, as shown on the group’s help page. CLIs that imitate another program retain their declared help style and upstream license notices.
HTTP
Replacevfs-md with skill-md for the other document.
Document responses use
text/markdown. Missing sessions or parents return 404; collisions return 409; invalid paths or profile selectors return 422. Session creation accepts a named profile.
MCP, SSH, and FUSE
MCP reads these files with its normalread, ls and shell tools and adds no document tools. The endpoint serves the session its ?session_id= names (MCP), so an agent reads that session’s view and cannot pick another one; change its profile from the host with PATCH or mirage session update.
SSH uses the session its login key authorizes. FUSE and FSKit use their bound session. Each reads the files through ordinary file operations and needs no document API.