AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Workflow Agent Spectrum Classifier

skill-anthonyalcaraz-agentic-graph-rag-skills-workflow-agent-spectrum-classifier · by AnthonyAlcaraz

|

No reviews yet
0 installs
34 views
0.0% view→install

Install

$ agentstack add skill-anthonyalcaraz-agentic-graph-rag-skills-workflow-agent-spectrum-classifier

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-anthonyalcaraz-agentic-graph-rag-skills-workflow-agent-spectrum-classifier)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Workflow Agent Spectrum Classifier? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Workflow-Agent Spectrum Classifier

Overview

Ch1 rejects "is it an agent or not" as the wrong question. Following Andrew Ng ("systems can be agent-like to different degrees") and Anthropic's workflow-vs-agent distinction, it places systems on a continuous spectrum:

  • Workflow end — "predefined execution paths: orchestrated sequences that

follow explicit instructions." Reliable and deterministic, limited adaptability. Chapter examples: a FAQ generator, a fund-analysis app.

  • Agent end — systems that "determine processes dynamically, providing

flexibility at the cost of predictability." Chapter examples: coding agents, deep research agents.

  • Blended middle — "deterministic workflows with nondeterministic LLMs

inserted at key points," with humans in the loop where judgment is required. Chapter example: an investment firm's market-commentary report — the LLM retrieves, analyzes, and submits; humans review for compliance and submit to regulators.

The placement is grounded in the three dimensions of agency, which "exist on sliding scales, not as binary attributes":

  • Autonomy — degree of independent decision-making without external

direction.

  • Action — ability to execute decisions that affect the environment.

"Without this capability to effect change, you have an assistant or advisor, not an agent."

  • Authority — scope and limitations of permitted actions. (Ch1's

real-estate-agent example: high autonomy to market a property, little authority over price.)

When a system operates across these dimensions, four capabilities emerge: autonomous decision-making, contextual understanding, strategic tool utilization, and memory persistence. The skill reports them alongside the band.

When to Use

  • Right-sizing an architecture: deterministic workflow vs blended

human-in-the-loop vs full agent

  • Settling a "is this really an agent?" debate with a shared rubric
  • Auditing whether a "read-only advisor" is being over-sold as an agent (the

action test)

  • Teaching the three agency dimensions with concrete placements

Phrases: "is this a workflow or an agent", "where on the spectrum", "classify this system", "is it agentic", "workflow vs agent", "does this count as an agent".

When NOT to Use

  • Ranking model quality — the spectrum is about system design, not the

underlying model.

  • Non-LLM systems with no autonomy/action to speak of — placement is

trivially WORKFLOW and uninformative.

  • As an authority control. This reports the authority dimension; it does

not enforce permissions. Use capability-authorization-gate (Ch3) for that.

Process

| Step | Input | Action | Output | Verification | |------|-------|--------|--------|--------------| | 1 | autonomy / action / authority / determinism (0..1) | lib.classify(...) | spectrum position + band | position in 0..1; band matches cutoffs | | 2 | autonomy + path_determinism | lib.spectrum_position(...) | 0..1 position | rises with autonomy, falls with determinism | | 3 | action value | read is_agent_by_action_test | agent-vs-advisor gate | false when action not WORKFLOW; scripted text -> not AGENT | | 6 | list of systems | CLI batch | per-system placement | each system carries a band + notes |

Rationalizations

| Agent rationalization | Documented rebuttal | |------------------------|--------------------| | "It uses an LLM, so it's an agent." | Ch1: agency is a spectrum, not a label. A FAQ generator uses an LLM on a predefined path — it sits at the WORKFLOW end. Score autonomy and path determinism, don't assume. | | "It reasons brilliantly, so it's a top-tier agent." | Ch1's action test: "Without this capability to effect change, you have an assistant or advisor, not an agent." A read-only diagnostic with high autonomy still fails the action test. | | "This complex process must be a full agent." | Ch1: the most complex enterprise processes are BLENDED — "deterministic workflows with nondeterministic LLMs inserted at key points," humans in the loop. Full-agent framing removes the human judgment the process requires. | | "Give it maximum autonomy and authority — more agentic is better." | Ch1: the dimensions are calibrated, not maximized (the real-estate agent has high autonomy, low pricing authority). Miscalibrated authority is a safety problem, not an agency win. | | "The band is just cosmetic labeling." | The band drives the architecture in later chapters: WORKFLOW -> explicit deterministic edges, AGENT -> conditional adaptive edges (Ch1 GraphRAG Flexibility section). Misplacing the band mis-designs the graph. |

Red Flags

  • A system scores AGENT but fails the action test. It is an advisor sold as

an agent; either grant it (bounded) action or stop calling it an agent.

  • Everything lands BLENDED. Either the dimensions are all set near 0.5

(under-specified) or the free-text description is too vague — supply concrete autonomy/action signals.

  • High autonomy paired with high authority and no human-in-the-loop note.

Verify this is intended; unbounded authority under high autonomy is the configuration Ch1 warns to calibrate.

  • classify_text disagrees with your intuition. It is best-effort keyword

inference; read estimated_dimensions, correct them, and re-run classify with the numeric values.

Non-Negotiable Verification

  1. Run the benchmark battery. python cli.py benchmark must report 8/8:
  • FAQ generator -> WORKFLOW, DevOps agent -> AGENT, market-commentary ->

BLENDED

  • the read-only advisor fails the action test and carries the advisor note
  • position is monotonic in autonomy and determinism
  • emergent-capability flags reflect the supplied signals
  • free-text dynamic-agent text is not WORKFLOW; scripted text is not AGENT
  1. Verify CLI help. python cli.py --help exits 0 and prints the SKILL.md

description.

  1. Inspect the scenario. python cli.py scenario devops should show the

four DevOps systems spread across all three bands.

Security Posture

  • Prompt injection. Numeric classify has no text surface. classify_text

and the describe subcommand read a free-text description with regex keyword matching only — no eval, no instruction execution — so a crafted description can at worst bias the estimated dimensions, which are returned transparently under estimated_dimensions for the caller to correct.

  • Data exfiltration. No network calls; the only file read is the systems

JSON path the caller supplies (default: the bundled sample). --json output goes to stdout.

  • Privilege escalation. No shell invocation, no dynamic import, no file

writes. Placement is advisory and must not be wired to real permission grants — the action/authority scores describe intent, they do not enforce it.

Source Attribution

Distilled from Agentic GraphRAG (O'Reilly, by Anthony Alcaraz and Sam Julien), Chapter 1 — Defining Agentic AI, "Classifying Agentic Systems: The Workflow-Agent Spectrum" and the "three dimensions of agency" definition. The spectrum framing follows Andrew Ng ("agent-like to different degrees") and Anthropic's workflow-vs-agent distinction, both named in the chapter; the workflow / blended / agent examples (FAQ generator, market-commentary report, coding & deep-research agents) and the action test are the chapter's.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.