Install
$ agentstack add skill-cbdreamer11-cb-loop-kit-claude-plugin-loop ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
The loop
Nothing is done until it has been observed working. A green build, "I read the code and it looks right", and "this should work" are not verification. The only valid signal is observed behaviour.
Run these six steps for every item. Do not skip 0 and do not skip 5.
0 · Locate yourself
- Read
.loop/STATE.md(what is done, what is next, what is parked) and
.loop/GOTCHAS.md (traps this project has already sprung).
git log --oneline -15andgit status. **Anything already committed is not
rebuilt.** A lot of what a document calls missing is already built and just not visible — confirm against the code before redoing it.
- Uncommitted files that are not yours may belong to a parallel session. Do not
touch them, and do not reuse a shared counter they may have taken (see the shared resource in .loop/VERIFY.md — read its true state with the command declared there).
- The next item is the first unchecked
[ ]in.loop/STATE.md. You do not need
new instructions to continue.
1 · Investigate
Open the real files you are about to change. Map what exists, what is editable, what is missing. Never work from memory of an API or a schema. If a question is genuinely open — or the item touches money, permissions, auth, or schema — run the loop-council skill before writing code, not after.
2 · Build, completely
One item at a time, finished. If completing it requires one more thing, that thing gets built too: it is not reported as a leftover and it is not offered as a question. An item is complete only if it would be safe to leave exactly as it is, forever — no dead end, no control that does not do what it says, no setting with no effect.
3 · Verify for real
Run the slots in .loop/VERIFY.md that apply. The rule for each: it must produce an artifact or an observation — a rendered page, a row, a file, a screenshot, a log line that only exists if the new code ran. Forbidden as evidence: an exit code, an HTTP 200, and "the build passed". Those prove the code compiled, not that it works.
4 · If it fails, fix it and verify again
Repeat 2 → 3 → 4 until it actually works. This is the loop. Do not move on with something unverified, and do not describe a failure as a partial success.
5 · Close
- Commit on the working branch, staging only your own files (never
git add -A
when someone else has uncommitted work). Never push to the protected branch.
- Update
.loop/STATE.md: mark the item[x]and add one line — *what you verified
and how*. Record anything you could not verify as GAP: .
- If you were blocked, write
PARKED: + exactly what is missingand move to
the next item. Park, never abandon, and never get stuck on one item.
- Add to
.loop/DECISIONS.mdif you chose between real alternatives, and to
.loop/GOTCHAS.md if something fooled you — the next session should not fall for it.
- Report the delta honestly: what is verified, what is a GAP, what is blocked on the
owner. Then continue with the next item. Do not ask "am I done, shall I continue?".
When to actually ask the owner
Only for what only they can unblock: a key or an access you do not have, moving real money, a business/legal/pricing decision, or publishing. Everything technical you decide yourself. "Do you want me to test it?" is never a valid question — if it matters, you already tested it.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: cbdreamer11
- Source: cbdreamer11/CB-loop-kit-claude-plugin
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.