bundled-skills/copilot-delegate/SKILL.md
Delegate coding tasks to the GitHub Copilot CLI (`copilot`) only when the user explicitly requests it, while the orchestrator retains review and landing responsibility.
npx skillsauth add FrancoStino/opencode-skills-antigravity copilot-delegateInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
copilot implementer (GitHub Copilot CLI) and then review its diff yourself.You are the orchestrator. Delegate a bounded coding task to a separate implementer — the GitHub Copilot CLI — then review what it produced and land it yourself. You write the brief and own the judgment; the implementer makes changes in its own session in a clean working tree; you verify and commit.
The loop needs only a shell command and file access, so any comparable orchestrator can drive it.
copilot CLI is not installed or authenticated./sandbox command and settings, disabled by default) — this relay
does not configure them. --read-only only disables edit tools (--mode plan); shell commands
still run. If project files must not change at all, dispatch against a clean or isolated worktree.copilot (npm install -g @github/copilot; the CLI requires Node 22+, the relay
itself runs on Node 18+ — the relay probes copilot version).copilot login (interactive web/device flow), or set
COPILOT_GITHUB_TOKEN / GH_TOKEN / GITHUB_TOKEN in the environment.copilot version succeeds.--cd at, the target git repository.Copilot picks a default model (auto). To choose another, pass --model <name>.
The relay accepts letters, digits, and . _ : / - only (the value reaches a shell on Windows).
Copilot supports a reasoning effort dial: --effort <level> with values
low, medium, high, xhigh, or max. The relay rejects any other value
before dispatch.
Run these five steps per task. Steps 1, 4, and 5 require judgment; 2 and 3 are mechanical.
Copilot sees only the text you send. It cannot read your conversation: the brief must stand alone
with the goal, current state, what to change, what to leave untouched, the project's real
gates, and a report contract. Keep each brief to a single task. Write it to a file and pass it as
the relay's --brief. See references/writing-the-brief.md.
Use the bundled relay. It runs copilot -p with --output-format json --no-color --stream off,
captures the JSONL event stream, and writes result.json.
node "<skill-dir>/scripts/relay.mjs" --brief brief.txt --cd /path/to/repo
# choose a model: add --model <name>
# set reasoning effort: add --effort <level>
# read-only planning pass: add --read-only (forces --mode plan)
# full tool autonomy: add --allow-all-tools
# hard time limit (watchdog): add --timeout 2h (the 30m default suits brief runs)
# resume a session: add --session <id> or --resume-last
# see all options: node .../relay.mjs --help
The child's cwd pins the workspace. The relay writes artifacts under the system temp dir by default and never commits. See references/dispatch-and-poll.md.
The relay blocks until copilot finishes. Run it with the orchestrator's background-command
facility, or background it in the shell and poll for result.json. A pre-run usage error exits 2
and writes no result; a missing copilot exits 127 and writes status: "copilot_unavailable".
Completion means the process exited and result.json exists — trust process state and the
working tree, not the progress display. Copilot's final assistant message is the finalMessage
field of result.json.
touchedFiles.See references/review-and-land.md.
If the work is good, commit it. The relay never commits — the diff and result.json are the
record; run git status and git diff first to confirm exactly what changed. If the group has a
PR flow, make the commit and push a branch; let human review happen. If the diff is wrong or
incomplete, re-dispatch a corrected brief in a fresh run and review again.
Without --allow-all-tools, copilot auto-denies tool calls in headless mode: the process exits 0
but the relay detects the denial events and reports status: "failed" with the CLI's own error
message and a hint to pass --allow-all-tools. This is the honest default — the orchestrator sees
the failure rather than a silent no-op.
--allow-all-tools explicitly grants full tool autonomy and requires explicit human authorization
for that run. A request to delegate to Copilot is not by itself consent to unrestricted tools.
--read-only selects --mode plan,
which disables edit tools so project files can't be changed by direct edits; it works without
--allow-all-tools. Shell commands still run in plan mode, so it guards against edits, not
against everything. The two flags are mutually exclusive.
Copilot also exposes sandbox controls, but they are upstream-experimental (MXC-based, controlled
via the /sandbox command and settings, disabled by default). This relay does not configure them.
Delegation is something the human opts into. Once briefed, copilot works as a tool you approved use of. The boundary is: do not accept conclusions from the self-report; verify everything on disk. For anything touching credentials, production data, or irreversible operations, stop and ask the human first instead of encoding it in a brief.
result.json, and failure recovery.scripts/relay.mjs not included; see upstream for full runtime. Requires copilot CLI, Node 18+, git.Adapted from amElnagdy/delegate-skills (MIT) — docs-only, runtime not bundled.
tools
Authorized security assessment of LLM applications and AI agents: prompt injection, tool abuse, RAG exposure, memory poisoning, system-prompt extraction, and agent-compliance engineering per OWASP LLM/ASI Top 10.
development
Builds two parameterized UI modes—流光溢彩白 (iridescent white) and 五彩斑斓黑 (colorful black)—with OKLCH, WebGL/CSS fallback, vision gating, screenshot QA, and total/per-color intensity reports. Use when a UI request names either mode or needs measured color parameters.
tools
Delegate coding tasks to the Kimi Code CLI (`kimi`) only when the user explicitly requests it, while the orchestrator retains review and landing responsibility.
development
Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output.