Install
$ agentstack add skill-marchatton-agent-skills-wf-plan ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
wf-plan
Purpose
Turn a shaped packet (wf-shape dossier) into a commit-ready plan without re-litigating the shape.
Never implement production code. Only research and write the plan.
Inputs
Dossier folder path containing:
brief.mdbreadboard-pack.mdrisk-register.mdspike-investigation.md(if present)
Outputs
Inside the same dossier:
plan.md
Steps
0) Pickup (recommended if new thread)
- Invoke
pickupif repo/branch state is not fresh.
1) Ingest shaped packet (no idea refinement loop)
- Read brief → breadboard → risk register → spikes.
- If perimeter or top risks are missing: route back to wf-shape.
2) Create plan skeleton
- Create
plan.mdwith: - scope (in/out)
- key flows + key logic
- acceptance criteria + verification plan
- sequencing/phases + stop points
- rollout/rollback + observability
- dependencies + risks
3) Local research (always)
- Find similar patterns in repo.
- Pull institutional learnings (docs/solutions, docs/LEARNINGS.md).
- Record concrete file paths.
4) External research (conditional)
- Always external for: security/auth, payments, privacy, external APIs, migrations.
- Otherwise only if local context is thin.
5) Spec hardening (gap pass)
- Edge cases, failure modes, concurrency, performance, data integrity, security threats.
- Update acceptance criteria + verification.
6) Plan review passes
- Simplicity, risk, ops/release, data integrity, security/privacy, UX/product.
- Final mandatory pass: invoke
oracleon the whole plan and integrate findings (or mark out-of-bounds).
7) Commit gate
- GO only if:
- AC measurable
- verification per AC
- sequencing explicit
- rollout/rollback explicit
- no P1 unknowns remain
8) Handoff to build (recommended boundary)
- Invoke
handoffand include: - plan path + summary of phases
- how to verify
- rollout notes
- biggest remaining risks
- Recommend build in a fresh thread:
/newthenpickupthen run wf-develop or wf-ralph
Verification
- plan includes acceptance criteria + verification + rollout/rollback
- oracle pass integrated
Go/No-Go
- GO if the plan can be built without re-discovering the shape.
- NO-GO if it depends on “we’ll figure it out during implementation”.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: marchatton
- Source: marchatton/agent-skills
- License: MIT
- Homepage: https://www.marchatton.com
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.