Install
$ agentstack add skill-jukrap-ai-agent-playbook-forge-automation-control ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Forge Automation Control
Use this skill to make forge-backed work resumable, reviewable, and safe when no forge is available.
Workflow
- Inspect repository state, remotes, authentication, configured provider, and the current deny flags before proposing any remote write.
- Resolve the effective permission profile. Apply the most restrictive user instruction, project setting, CLI flag, and provider capability.
- Validate an approved structured plan. Keep fine-grained execution tasks in the local ledger and publish reviewable delivery groups as issues; task-per-issue mode is an explicit legacy choice.
- Run one idempotent tick at a time: claim one ready task, execute it within budget, rerun verification in the controller, record evidence, and checkpoint state.
- Synchronize only meaningful transitions, blockers, reconciliation requests, and final verification. Reuse managed issues, marker comments, branches, and draft pull requests.
- Pause when requirements change during execution, a lease or permission is uncertain, verification fails repeatedly, or a high-risk action needs approval.
- Fall back to the local ledger when remote access is unavailable or denied. Never treat remote synchronization as a prerequisite for local progress.
Safety Boundaries
- Keep merge, release, delete, force-push, and protected-branch writes approval-bound in every profile.
- Keep forge credentials out of configuration, prompts, worker environments, ledgers, evidence, and logs.
- Do not let a worker push or mutate forge state; the controller reviews files and verification before delivery.
- Preserve the user's working checkout. Use a managed isolated checkout for unattended execution.
- Do not invent a merge-first, release-first, or other gate that is absent from the approved plan. A merge approval may hold merge while branch implementation, verification, and a draft pull request continue.
- Pause before the first write when a configured GitHub Project requires a missing
projectscope. Showgh auth refresh -s projectand the status recheck command; never run authentication refresh automatically.
Related Skills
- Use
issue-planning-triageto shape a roadmap into a small set of independently reviewable delivery-group issues and to classify pre-existing ready-label work. Keep finer execution tasks in the local ledger. - Use
agent-orchestration-handoffwhen executor or review workers need bounded contracts, evidence ownership, and reconciliation handoff. - Use
git-worklog-guardrailsbefore controller staging, commit, push, draft pull request, or durable worklog updates.
References
Read references/provider-capabilities.md when detecting GitHub or Gitea, planning remote artifacts, or choosing a capability fallback.
Read references/state-and-permissions.md when resolving task transitions, queue labels, progress, permission profiles, deny flags, or approval gates.
Read references/scheduler-and-recovery.md when configuring ticks, supervisors, Actions, local schedulers, leases, crash recovery, or unattended Git delivery.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: jukrap
- Source: jukrap/ai-agent-playbook
- License: MIT
- Homepage: https://www.npmjs.com/package/ai-agent-playbook
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.