SKILLS/acceptance-orchestrator/SKILL.md
Use when a coding task should be driven end-to-end from issue intake through implementation, review, deployment, and acceptance verification with minimal human re-intervention.
npx skillsauth add pinkpixel-dev/skills-collection-1 acceptance-orchestratorInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Orchestrate coding work as a state machine that ends only when acceptance criteria are verified with evidence or the task is explicitly escalated.
Core rule: do not optimize for "code changed"; optimize for "DoD proven".
create-issue-gateclosed-loop-deliveryverification-before-completionOptional supporting skills:
deploy-devpr-watchpr-review-autopilotgit-shipRequire these inputs:
dev default)Fixed defaults:
23m -> 6m -> 10mintakeissue-gatedexecutingreview-loopdeploy-verifyacceptedescalatedIntake
Issue gate
create-issue-gate logic.ready or execution gate is not allowed, stop immediately.draft.Execute
closed-loop-delivery for implementation and local verification.Review loop
3m6m10m10m round, stop waiting and process all visible comments together.Deploy and runtime verification
dev by default.Completion gate
verification-before-completion.Move to accepted only when every acceptance criterion has matching evidence.
Move to escalated when any of these happen:
2 full roundsAlways stop for human confirmation on:
When reporting status, always include:
Status: intake / executing / accepted / escalatedAcceptance Criteria: pass/fail checklistEvidence: commands, logs, API results, or runtime proofOpen Risks: anything still uncertainNeed Human Input: smallest next decision, if blockedDo not report "done" unless status is accepted.
development
Build a systematic threat hunt hypothesis framework that transforms threat intelligence, attack patterns, and environmental data into testable hunting hypotheses.
development
Deploy MISP (Malware Information Sharing Platform) to aggregate, correlate, and distribute threat intelligence feeds from multiple sources for centralized IOC management and automated SIEM integration.
development
Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary motivations, capabilities, infrastructure, and TTPs for proactive defense.
development
Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees. Use when SOC teams need formalized response procedures for ransomware incidents aligned to NIST SP 800-61 and MITRE ATT&CK ransomware techniques.