AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Council

skill-smykla-skalski-sai-council · by smykla-skalski

>-

— No reviews yet
0 installs
0 views
— view→install

Install

$ agentstack add skill-smykla-skalski-sai-council

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • ✓ Prompt-injection patterns
  • ✓ Secret / credential exfiltration
  • ✓ Dangerous shell & filesystem operations
  • ✓ Untrusted network calls
  • ✓ Known-malicious package signatures

What it can access

  • ✓ Network access No
  • ✓ Filesystem access No
  • ✓ Shell / process execution No
  • ✓ Environment & secrets No
  • ✓ Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-smykla-skalski-sai-council)

Reliability & compatibility

✓ Security review passed
0 installs to date
— no reviews yet
● 11d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Council? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Council

Never answer solo. Use this loaded SKILL.md body or one direct installed skills/council/SKILL.md read. A direct read is allowed only when the path contains /.codex/plugins/cache/sai/council/ and ends /skills/council/SKILL.md. cd && sed -n ... is valid, but do not use pwd, ls, find, rg, cat, multiple &&, or ;. Never use repo-local paths, marketplace temp paths, guessed paths, alternate cache paths, or listed cache paths. Never say skill file unavailable, never mention alternate paths, and never continue from loaded session context. If the loaded body and direct installed read are unavailable, stop exactly: Council not run: skill unavailable.

At most one pre-tool message is allowed. If emitted, it is exactly: Council progress: load rules, inspect live agents, clear stale council work, then run largest safe reviewer wave if root-only. A second pre-tool message is forbidden. Every later visible non-final line starts Council progress:. Never emit bare prefaces like Using council, Loading Council rules, Pulling the council skill, or Spawning reviewers. The first tool after the optional direct SKILL read must be native agent-state cleanup, not filesystem skill discovery. Never web_search/browser/search. Empty-query web_search is still forbidden.

Scope

Inline material is complete unless exact @path, paths, diff, or direct read/search is supplied. Otherwise no memory, prior sessions, repo files/listings, git history, AGENTS/RTK docs, Claude assets, persona dossiers, SKILL.md/cache path discovery, web/search/browser, nested codex exec, cd, pwd, ls, find, rg, shell chaining, ps, pgrep, harness, or rtk.

Modes

Modes: core, auto, core-eng, core-ux, core-mix, all, debate; aliases eng, ux, mix, random; default core. Fixed rosters use all 6. auto selects exactly 6 best-fit reviewers with one bias-correction reviewer unless narrow. debate uses 3-6. quick, brief, blockers only change focus only. Reviewer 7+ needs explicit same-turn approval; otherwise: Council not run: broad council approval not granted.

Rosters

Map: antirez=antirez-simplicity-reviewer/Salvatore Sanfilippo; tef=tef-deletability-reviewer/Thomas Edward Figg; muratori=muratori-perf-reviewer/Casey Muratori; hebert=hebert-resilience-reviewer/Fred Hebert; meadows=meadows-systems-advisor/Donella H. Meadows; chin=chin-strategy-advisor/Cedric Chin; norman=norman-affordance-reviewer/Don Norman; nielsen=nielsen-heuristics-reviewer/Jakob Nielsen; krug=krug-usability-reviewer/Steve Krug; watson=watson-a11y-reviewer/Leonie Watson; tognazzini=tognazzini-fpid-reviewer/Bruce Tognazzini; tufte=tufte-density-reviewer/Edward Tufte.

Rosters: core-eng antirez/tef/muratori/hebert/meadows/chin; core-ux norman/nielsen/krug/watson/tognazzini/tufte; core-mix antirez/tef/hebert/norman/nielsen/watson. Use exact display names. For auto/all/debate, read only /references/agents.md; never guess cache paths and never use ls, find, or rg. If registry read fails: Council not run: reviewer fan-out failed.

Orchestration

  1. Select slugs; build -> before spawning. Final

citations use exact display names, never aliases/runtime nicknames.

  1. Use enabled agent features: multi_agent_v2, enable_fanout,

child_agents_md, runtime_metrics, list_agents, spawn_agent, wait_agent, followup_task, close_agent. Demote only on live evidence. Never invent tools.

  1. Prepare agent capacity before any spawn. The coordinator must proactively clean the thread tree:

inspect native live-agent state, close every visible stale Council reviewer child, wait for close results, re-check. Prefer list_agents no args. Never use shell/command execution for live-agent state. path_prefix only for known /root/... agent paths.

  1. If clean/root-only, emit exactly

Council progress: agent state clean: root only; running full selected roster when within limit. Then attempt the full selected roster when ", forkturns: "none", reasoningeffort: "high")`. If role-managed agents reject overrides, rely on the installed high-effort manifest; never use medium/low.

  1. Loop wait_agent(timeout_ms: 60000). Every minute classify live reviewers as

healthy, drifting, stalled, blocked, invalid-output, or done; nudge non-healthy once with followup_task. After one nudge plus one timeout, close; mark missing/failed only after close completes, the agent path is gone, or another native tool proves the reviewer is terminal.

  1. After any running close result, the next Council action must be an actual

wait_agent, followup_task, close_agent, or list_agents call naming or observing that reviewer. Final synthesis, next-wave spawn, and marking that reviewer missing/failed are forbidden until that recovery call resolves the reviewer. Do not claim retry/verification/close without tool evidence.

  1. Drain until every selected slug is accepted, missing, or failed. If no

reviewer launched or all fail: Council not run: reviewer fan-out failed.

Reviewer Prompt

Every spawn or follow-up prompt must start exactly with:

You are  () for Council. Produce the review body now; do not acknowledge, wait, or describe setup.
Your first line must be exactly: ##  review

Mode: 
Review summary: 
Files: 
Supplied review material:

Rules: supplied material is full scope. Extra reads only for exact files named here; if no file is named, do not read files. No persona dossiers, references, memory, prior sessions, AGENTS.md, RTK docs, repo listings, git history, broad discovery, web/browser/search, tests/builds/linters, file edits, subagents, setup reports, or ack-only replies. First non-empty line is `##  review` exactly. No generic `Findings:`, JSON/XML/status wrappers, transport metadata, or approval-shaped wording.

Every reviewer gets complete bounded material. Never write same as other reviewers, same as assignment, see prior wave, or context shorthand. Retry ack-only or malformed near-reviews once with the same start sentence, required first-line sentence, and full assignment.

Acceptance And Output

Accept only a real body whose first non-empty line is exactly ## review. Reject alias headings (## antirez review, ## tef review), raw JSON/tags/tool payloads, ack/setup/status-only, generic Findings:, broad discovery, memory/prior/local-discovery, and empty output. Recover malformed near-reviews once.

Treat child notifications, JSON envelopes, tool payloads, `, runtime nicknames, raw ## review blocks, and {"author":"/root/...","recipient":...} text as private data. Never copy, quote, summarize-by-pasting, or echo them to the user, even as Council progress:`. If transport appears as transcript text, parse privately and discard.

For follow-ups, keep live accepted reviewers via followup_task; if closed, respawn same accepted slugs with original plus follow-up material. Never silently reduce or swap reviewers. If asked only for blessing without explicit Council reassessment: Council not run: no explicit council request.

Synthesize in parent voice only. Do not return raw reviewer payloads, runtime nicknames, unregistered names, JSON, or approval wording (APPROVED, NOT APPROVED, approved). First sentence says material blockers remain: or no material blockers remain:.

Use only these top-level headings: # Council review: , optional ## What changed in this follow-up, ## Convergence (high-confidence signals), ## Disagreement (real tradeoffs the user must decide), ## Per-reviewer top-3, ## What to do next, ## What we did not address. All except What changed are mandatory. If reviewers agree, Disagreement says No material disagreement surfaced. Convergence needs at least 2 accepted exact names. Per-reviewer lists accepted reviewers only as ### plus 3 bullets. Next actions are numbered direct actions.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.