bundled-skills/aider-delegate/SKILL.md
Delegate coding tasks to Aider (`aider`) only when the user explicitly requests it, while the orchestrator retains review and landing responsibility.
npx skillsauth add FrancoStino/opencode-skills-antigravity aider-delegateInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
aider implementer (Aider) and then review its diff yourself.You are the orchestrator. Hand a bounded coding task to a separate implementer - Aider - then review what it produced and land it yourself. You write the brief and own the judgment; Aider does the typing in its own run; you verify and commit.
The loop needs only a shell command and file access, so any comparable orchestrator can drive it.
Aider commits by default. Two of its defaults would destroy the reviewable diff this skill exists to produce:
--auto-commits (default True) - Aider commits its own edits after each exchange.--dirty-commits (default True) - Aider commits your pre-existing uncommitted work before it
starts editing.The relay always passes --no-auto-commits and --no-dirty-commits, and neither is configurable
through it. If you ever drive aider by hand instead of through the relay, pass both yourself, or the
work lands as commits you never reviewed. The relay also passes --no-gitignore, because Aider
otherwise writes .aider* into .gitignore on startup and dirties the tree you are about to read.
aider CLI is not installed, or no model is configured for it.python -m pip install aider-chat, or the standalone installer from the
Aider install docs.OPENAI_API_KEY,
ANTHROPIC_API_KEY, …) or its own config; see Aider's model docs.aider --version succeeds.--cd at, the target git repository.Aider uses its own configured model when --model is omitted. Pass --model <name> to pick another.
Aider talks to any OpenAI-compatible endpoint, so this is also the skill for delegating to a model
running on the user's own hardware - llama.cpp's server, Ollama, vLLM, LM Studio, or anything else
that serves the same API. Pair --model with --api-base:
node "<skill-dir>/scripts/relay.mjs" --brief brief.txt --cd /path/to/repo \
--model openai/<served-model-name> --api-base http://127.0.0.1:<port>/v1
Three things differ from a hosted provider:
openai/ prefix is required. It tells Aider to speak the OpenAI protocol to your endpoint;
the part after it is whatever name your server reports, not a provider catalog name.OPENAI_API_KEY. The client library
requires the header even when the server ignores its value.diff format, which
requires exact search/replace blocks. --edit-format whole trades tokens for reliability; keep the
brief's scope tight with --file so whole-file rewrites stay cheap.A local endpoint that is not running looks like a hang, not an error: Aider retries the connection
until the relay's --timeout watchdog fires and reports status: "timeout". Confirm the server is up
before dispatching a long brief.
No account or provider registration is involved: Aider is a pip install, the endpoint is yours, and
OPENAI_API_KEY only has to be non-empty. The relay pins the flags that would otherwise reach the
network on their own - --no-check-update, --no-analytics (Aider's own default is random, which
opts some sessions in by itself), and --no-detect-urls, without which Aider offers to scrape any URL
in the brief and --yes-always accepts that offer silently.
--no-suggest-shell-commands closes the remaining path by which a run could reach the network without
being asked to. What stays outside the relay's control is the brief itself: instructions that tell
Aider to install a package or call an API will still be carried out, and --auto-lint runs the
repository's own tooling. Offline here means nothing in the dispatch path reaches out on its own - not
that a sandbox is stopping it.
Run these five steps per task. Steps 1, 4, and 5 require judgment; 2 and 3 are mechanical.
Aider sees only the text you send plus the files in its editing scope - no chat history or shared context. Include the goal, current state, what to change, what to leave untouched, the project's actual gates, and a report contract. Keep one task per brief. See references/writing-the-brief.md.
Use the bundled helper. It wraps Aider's headless --message-file mode, captures the run, and writes
result.json. (<skill-dir> is the installed folder containing this SKILL.md.)
node "<skill-dir>/scripts/relay.mjs" --brief brief.txt --cd /path/to/repo
# choose a model: add --model <name>
# point at an OpenAI-compatible server: add --api-base <url>
# scope the edit surface: add --file <path> (repeatable), --read <path> for context only
# dry run, no files modified: add --read-only
# continue the previous chat: add --resume-last (delta brief only)
# hard time limit (watchdog): add --timeout 2h (the 30m default suits short runs; implementation briefs routinely need 1-2h)
# see all options: node .../relay.mjs --help
The child process's cwd pins the workspace. The brief is delivered with --message-file, so it never
rides argv: it stays out of the host process list and clear of the OS argument size cap. The relay
writes artifacts under the system temp dir by default and never commits. See
references/dispatch-and-poll.md.
The helper blocks until Aider finishes. Run it with the orchestrator's background-command facility, or
background it in the shell and poll for result.json. A pre-run usage error exits 2 and writes no
result; a missing aider exits 127 and writes status: "aider_unavailable".
Trust process state and the working tree over a progress display. Completion means the process exited
and result.json exists. Aider's report is the finalMessage field in result.json (also printed in
full on stdout between the report markers).
Aider exits 0 even when it never reached a model, so the relay scans the run for Aider's own endpoint
and authentication errors and reports status: "failed" when it finds one. Treat a failed status
with an error mentioning the endpoint as a configuration problem, not a coding failure.
Treat Aider's final message and gate claims as claims:
touchedFiles.Aider's --auto-lint is on by default, so it may have already run a linter and fixed its own
complaints. That is Aider's lint, not your gates - run yours anyway. See
references/review-and-land.md.
The implementer edits the working tree; the orchestrator commits. Commit only after the gates pass
and the diff holds. If rework is needed, send a delta brief with --resume-last, then review again.
The relay passes --yes-always, Aider's own term for auto-confirming every prompt, because a headless
run cannot answer one. Understand what that consents to in advance. Auto-confirmation applies to
every prompt Aider would otherwise raise, and Aider's prompts are not limited to file edits: left at
its defaults it also offers to run shell commands it has suggested, and --yes-always would accept
those with nobody reading them. The relay therefore pins --no-suggest-shell-commands, which removes
that path.
What remains is not a sandbox, and nothing here pretends otherwise. Aider has no permission modes and
no isolation: within its file scope it edits freely, and --auto-lint (on by default) runs whatever
linter the repository configures. A brief that tells Aider to run a command still gets a command run.
Delegation is the authorization; if a run must not be able to touch the host, run it in a container or
a throwaway worktree, because no flag in this relay will give you that.
File selection is not a security boundary. --file, --read, and --subtree-only set what Aider
puts in its chat context, which is a scoping and token-cost decision. They do not confine what it can
reach. See references/writing-the-brief.md.
--read-only maps to Aider's --dry-run, which performs the run without modifying files. The relay
does not independently verify that claim - it reports what git status --porcelain shows and warns if
a --read-only run left the tree changed. touchedFiles and the diff, not a flag, are the guarantee.
Aider has no session ids. Its resume unit is the chat history file it keeps in the repository
(.aider.chat.history.md), so --resume-last maps to Aider's --restore-chat-history and
--history-file pins a specific one. Because that history lives in the repo, resume is per-worktree,
not per-user: two clones of the same project do not share it.
Delegation is something the human opts into. Once they have ("run this queue", "proceed"), committing verified, gate-passing work is the agreed contract. Two limits remain: surface, don't absorb (report Aider's design decisions, defensible-but-unasked turns, and non-blocking nitpicks) and stop for scope changes (if correct completion needs going beyond the brief, ask instead of expanding the mandate). See references/review-and-land.md.
result.json, polling, and failure recovery.scripts/relay.mjs not included; see upstream for full runtime. Requires aider CLI, Node 18+, git.Adapted from amElnagdy/delegate-skills (MIT) — docs-only, runtime not bundled.
tools
Authorized security assessment of LLM applications and AI agents: prompt injection, tool abuse, RAG exposure, memory poisoning, system-prompt extraction, and agent-compliance engineering per OWASP LLM/ASI Top 10.
development
Builds two parameterized UI modes—流光溢彩白 (iridescent white) and 五彩斑斓黑 (colorful black)—with OKLCH, WebGL/CSS fallback, vision gating, screenshot QA, and total/per-color intensity reports. Use when a UI request names either mode or needs measured color parameters.
tools
Delegate coding tasks to the Kimi Code CLI (`kimi`) only when the user explicitly requests it, while the orchestrator retains review and landing responsibility.
development
Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output.