bundled-skills/claude-delegate/SKILL.md
Delegate coding tasks to a separate Claude Code CLI process or Claude session only when the user explicitly requests it, while the orchestrator retains review and landing responsibility.
npx skillsauth add FrancoStino/opencode-skills-antigravity claude-delegateInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
claude implementer (Claude Code) and then review its diff yourself.You are the orchestrator. Delegate one bounded coding task to a separate implementer — a Claude Code CLI session — then review what it produced and land it yourself. You write the brief and own the judgment; the separate Claude session edits the working tree; you verify and commit.
This skill is not a signal for the current Claude to implement directly. Use it only after the human explicitly asks for delegation to another Claude Code process or session.
claude CLI is missing or unauthenticated (claude auth status).claude --version succeeds.claude auth status reports an authenticated session. On macOS the live credentials sit in the
login Keychain; when the orchestrator's own sandbox blocks Keychain access (Codex's sandbox
does), claude falls back to a possibly stale credentials file and reports loggedIn: false
even though the login is valid. Re-run the check — and the dispatch itself — with that sandbox
escalated or outside it before concluding the CLI is unauthenticated.--cd.The separate session has no orchestrator chat history. It receives the brief on stdin and can inspect the target working tree.
Claude Code automatically discovers the target project's CLAUDE.md and normal local Claude
configuration because the relay does not use --bare. It does not generically auto-load
AGENTS.md. Read AGENTS.md yourself and copy every load-bearing constraint and the real gate
commands into the brief. Tell the implementer not to commit. Keep one task per brief.
Template and details: references/writing-the-brief.md.
node "<skill-dir>/scripts/relay.mjs" --brief brief.txt --cd /path/to/repo
# review/diagnosis only: add --read-only
# continue the latest session: add --resume-last
# continue the recorded session: add --session <id>
# choose limits: add --max-turns 40 --max-budget-usd 10
# hard relay deadline: add --timeout 2h
# inspect every option: node .../relay.mjs --help
<skill-dir> is this installed skill directory, the folder containing this SKILL.md.
The relay runs claude -p --output-format stream-json --verbose, sends the brief through stdin, and
writes artifacts under the system temp directory by default. It never uses --bg or --bare, and it
never commits. See references/dispatch-and-poll.md.
The relay blocks until Claude exits. Use the orchestrator's background-command facility, or run it in
the foreground and wait. Completion means the process exited and result.json exists.
result.json.claude exits 127 and writes status: "claude_unavailable".Read finalMessage, touchedFiles, resultSubtype, and the raw artifact paths from result.json.
Treat the implementer's report and gate outcomes as claims:
touchedFiles.Full checklist: references/review-and-land.md.
The orchestrator commits only after the gates pass and the diff holds. For rework, resume the same Claude session with a delta brief:
echo "Keep the implementation, replace the mocked DB test with the migrated fixture, and remove the
unused import." | node "<skill-dir>/scripts/relay.mjs" --session <id> --cd /path/to/repo
Review a resumed run exactly like the first run.
The normal profile is deliberately explicit:
acceptEdits permission mode.CLAUDE.md, hooks,
normal authentication, session persistence, and other local settings still load.git commit, git push, and nested claude, plus
any command containing claude-delegate. Aliases, scripts, and wrappers can bypass them, so they
are only a speed bump; the brief's no-commit instruction and orchestrator review remain the boundary.Native Windows does not support Claude's shell sandbox. The relay restricts the tool surface and
pre-approves PowerShell so the run remains non-interactive, but that shell is not OS-isolated. Native
claude.exe and npm claude.cmd launch paths are implemented; Windows verification is pending.
--read-only uses plan mode with only Read, Glob, and Grep. It removes edit, write, and shell paths,
then compares parsed git porcelain and fingerprints the working-tree identity and index entries of
Git-visible paths that were already dirty.
readOnlyViolation is true when either signal proves a change, false when coverage is complete and
detects none, and null when coverage is incomplete. This is a reporting tripwire, not an OS boundary:
ignored paths and perfect restores are outside it, local hooks can write, and concurrent changes cannot
be attributed to Claude.
--dangerously-skip-permissions is an explicit opt-in to Claude's bypassPermissions mode. The
restricted tool surface, direct commit/push deny rules, and supported-platform shell sandbox remain,
but direct file tools can cross normal permission boundaries. Use it only with the human's explicit
acceptance.
Claude subagents, agent teams, and background sessions are useful when the current Claude environment is already the orchestrator and native coordination is the goal. This skill is complementary: it provides a cross-orchestrator contract — self-contained brief → dispatch → artifacts → review → land — and keeps the commit with the orchestrator.
CLAUDE.md versus
AGENTS.md, real gates, report contract, and delta briefs.result.json, polling, and failure recovery.scripts/relay.mjs not included; see upstream for full runtime. Requires claude CLI, Node 18+, git.Adapted from amElnagdy/delegate-skills (MIT) — docs-only, runtime not bundled.
tools
Authorized security assessment of LLM applications and AI agents: prompt injection, tool abuse, RAG exposure, memory poisoning, system-prompt extraction, and agent-compliance engineering per OWASP LLM/ASI Top 10.
development
Builds two parameterized UI modes—流光溢彩白 (iridescent white) and 五彩斑斓黑 (colorful black)—with OKLCH, WebGL/CSS fallback, vision gating, screenshot QA, and total/per-color intensity reports. Use when a UI request names either mode or needs measured color parameters.
tools
Delegate coding tasks to the Kimi Code CLI (`kimi`) only when the user explicitly requests it, while the orchestrator retains review and landing responsibility.
development
Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output.