delegate-skills
A skills package in which every coding-agent CLI gets its own delegation skill: the orchestrating agent writes a self-contained brief, a separate CLI edits a real working tree, and the human keeps the review and the commit.

What it is
A package of Agent Skills that each drive a different coding-agent CLI as an implementer while the orchestrating agent keeps the review and the commit. Every skill has the same shape: a brief written for a session that has no chat history, one scripts/relay.mjs that launches the CLI headlessly and polls it, four reference documents, and a result.json that speaks one shared contract — status, exit code, signal, the implementer’s own final report, the files it touched, and a session id where the CLI exposes one. Seventeen implementers ship today, from Claude Code, Codex and Cursor to Antigravity, Grok, Kimi, Qoder, Copilot, Warp and Command Code; a separate utility skill, delegate-setup, discovers which of those CLIs are installed and writes the fleet lanes. Nothing in the package commits, and where a CLI cannot be stopped from writing, that is stated in a footnote rather than smoothed over.
Who built itA personal account with a long contributor tail. The owner’s account carries 285 of the repository’s 390 commits — authored under two names, Ahmed Nagdy and Ahmed Mohammed, that share its verified emails — and 25 people have landed changes, the busiest with 23, 10 and 7 commits. Almost all of the work is co-signed: 99 commit trailers credit a model or a tool, most often Claude Fable 5, Claude Opus 5 and Cursor, and 377 of the 390 commits resolve to a GitHub account.
How it is put together
The parts · 6A skills package whose organising idea is one contract repeated seventeen times. Each implementer gets its own directory with the same four documents and one dispatch script, so an orchestrator learns one loop — brief, dispatch, poll, review, land — and swaps the CLI underneath it. Two consequences decide most of the code. The first is that a skill is installed as a single directory with no bundler, so every relay.mjs is self-contained and duplicates the shared helpers on purpose; drift between those copies is handled by a byte-parity test rather than by a shared source directory. The second is that the package refuses to own the commit: a relay stops at a diff and a structured result, and autonomy is described in each CLI’s own vocabulary, including the cases where a CLI cannot be restrained at all. delegate-setup is deliberately the only utility and it only writes configuration, so the orchestration policy users keep asking for stays outside the package.
- skills/<cli>-delegate/ ×17
- The implementer skills, each a
SKILL.mdwith a triggering description under 1,024 characters, exactly onescripts/relay.mjs, and the same four references — writing the brief, dispatch and poll, review and land, multi-task queues. The relays run from 25,706 bytes for Qoder to 58,241 for Command Code, and the directories from 44 KB to 105 KB. - skills/delegate-setup/
- The one utility skill:
discover.mjsprobes which implementer CLIs are installed,config.mjsvalidates and writes the lane map,lane.mjsresolves a lane for a relay and fails loud on a missing lane, an untrusted project config or an implementer mismatch, andimplementers.mjsholds the shared table of binaries and dials. It never dispatches coding work. - test/
- Twenty-six relay modules at 225 KB, plus the smoke, parity, isolated-install and event-scanner runners, and a harness that installs a shim and supplies a fake CLI in both CommonJS and native C# form. Registering a new skill in
test/harness/constants.mjsis what puts it into the timeout and abort matrix, and the suite fails if a skill directory is missing from it. - .github/ and .cursor/
- One workflow,
relays.yml, running parity, isolated-install, event-scanner and smoke on Ubuntu and Windows with Node 22, and validating the published package listing on Linux only. The issue template turns a claim into four required answers — non-interactive command, machine-readable output, autonomy, and a confirmation that no open claim covers the CLI — and a Cursor cloud environment file plus install script sit beside it. - AGENTS.md, CONTRIBUTING.md and docs/plans/
- The house rules: a controlled vocabulary table that fixes one word per concept and bans synonyms, a banned-on-sight list covering invented umbrella terms, references to the author’s local machine and unverifiable claims, the merge checklist and release ritual, and the 7,682-byte relay dedup plan kept with its superseded first version in an appendix.
- skills.sh.json and the two schema ids
- The package manifest groups the seventeen implementer skills under one heading and
delegate-setupunder Setup, and two JSON contracts carry the data between the parts:delegate-fleet.v1for the global or project lane map, whose project copy must match an approval hash or fail closed, anddelegate-relay.result.v1for every run’s result file.
Choices, and what they beat
One self-contained relay per implementer, with a byte-parity test over a generator, shared fragments or a bundler
A skill installs one directory at a time, so a cross-directory import would hard-crash a single-skill install. The adopted plan argues further that duplication which cannot drift is only disk, that the helpers have near-zero edit traffic, and that a sixty-line parity gate prevents the thing that actually hurt — so the machinery was refused and the gate was built instead.
The relay never commits; the reviewer lands the work over letting the implementer finish the job, commit included
Stated as an invariant rather than a preference, and enforced against the one implementer that disagrees: Aider commits by default and will commit a user’s pre-existing dirty work, so its relay always passes
--no-auto-commitsand--no-dirty-commitsand exposes neither as an option.One result contract and exactly four reference documents per skill over a result shape chosen per CLI
The checklist fixes the shape — four references, “not three, not five”, because the shape is the contract — and every relay writes
delegate-relay.result.v1. That is what lets an orchestrator learn the loop once and change implementer without relearning how results are read.Describe autonomy in each CLI’s own terms and publish what it cannot enforce over presenting one uniform read-only mode across the fleet
Some implementers have no enforced read-only mode and one cannot be stopped from writing headlessly. The rule is explicit that a CLI with no read-only mode is mergeable but a skill implying it has one is not, so those gaps are footnotes and tripwires rather than silence.
Keep orchestration policy outside the package over shipping a fleet orchestrator or a failover controller
Two proposals were closed with the same answer: this repository ships one delegate skill per CLI implementer plus
delegate-setup, and a second utility that dispatches across implementers, fails over and holds orchestration policy is out of scope. The design thread for that layer stays open as its own issue rather than being absorbed.Pin installs with annotated git tags over relying on
metadata.versionin the skill frontmatterThe Skills CLI installs by git ref, so the release ritual bumps every skill’s version for information and creates one annotated tag that users pin. The JSON contract ids are versioned independently and change only when a shape breaks, which keeps a documentation release from looking like a breaking one.
Read fromREADME.md (30,078 characters), CONTRIBUTING.md, AGENTS.md, docs/plans/relay-core-dedup.md, skills/delegate-setup/references/schema.md, skills.sh.json, .github/workflows/relays.yml, the issue and pull-request threads, and the complete 158-file tree with sizes.
Build log
6 stages- 01
One skill per implementer, and a claim rule written after two wasted builds
The repository was created on 2026-06-14 and its first commit added a single skill,
codex-delegate, with the package scaffolding around it. Three months later it ships seventeen implementer skills plusdelegate-setup, across 390 commits that thin out sharply at the end: 5 in June, 151 in July, 197 in August and 37 in September. The contribution record is wide for a personal repository — 102 pull requests of which 71 were merged, 38 issues of which 25 are closed, and 25 contributors, the busiest after the owner holding 23, 10 and 7 commits.CONTRIBUTING.mdopens by explaining why it has a rule at all: two people had independently built the same delegate skill, twice, and both times somebody’s work was wasted, so an implementer is claimed in an issue before it is written. The claim template makes the claimant state the CLI’s exact non-interactive command, what a relay can parse out of its output, and how its autonomy is set, and says plainly that a claim is “not an assignment, not exclusive”. The merge checklist then decides between competing pull requests: the one satisfying more of it merges, ties break on verification evidence and then on the earlier claim, and the losing pull request’s distinct improvements are pulled in and credited by number in the commit that lands them. - 02
Seven annotated tags in twelve days, and a unit of shipping that is one directory
Releases here are git tags, not GitHub releases: there are seven of them and none is a published release object. All seven fall inside twelve days —
v0.2.0on 2026-08-04 at 18:07,v0.3.0at 19:51,v0.3.1at 20:33 andv0.4.0at 21:55, four tag cuts in a single evening, thenv0.4.1the next morning,v0.4.2on 2026-08-08 andv0.5.0on 2026-08-16; September’s 37 commits produced none.CONTRIBUTING.mdprescribes the ritual: land onmaster, set every skill’smetadata.versionto the same semver, create an annotated tag and push it, because installers pin withnpx skills add amElnagdy/delegate-skills@v0.2.0rather than reading frontmatter. The two JSON contract ids,delegate-fleet.v1anddelegate-relay.result.v1, are versioned separately and bump only when a shape breaks. What makes the packaging decision load-bearing is that a skill is installed one directory at a time, with no bundler and no dependency graph, soskills/<name>-delegate/has to load standalone — a plain cross-directory import would hard-crash a single-skill install. That constraint is why each of the relays carries its own copy of the shared helpers, and why a byte-parity test exists to police the copies instead of a shared source directory. - 03
The relay never commits, and one implementer had to be stopped from doing it
The organising rule is a division of labour: the implementer edits a real working tree and writes a structured
result.json, then stops; the orchestrating agent re-runs the project’s own gates against the diff and makes the commit itself. The README states it as an invariant — the relay never commits, because committing belongs to the reviewer — and the same rigidity is applied to what a skill is allowed to claim. Three others sit beside it: a separate CLI must edit a real working tree so thatgit diffis the deliverable, the scripts use Node built-ins only with no dependencies, no network calls of their own, no credentials and no telemetry, and each CLI’s autonomy is described in that CLI’s own terms. The rule has a documented edge case that is not an exception to it: Aider commits by default, its--auto-commitsand--dirty-commitsboth default to true, and the second will commit a user’s pre-existing uncommitted work before it starts editing. The relay therefore always passes--no-auto-commitsand--no-dirty-commitsand exposes neither as an option. The framing that ties it together is in the README: this is a loop, not a forwarder — a forwarder hands over one task and returns the output, whereas here you dispatch, poll, review and land, across a single task or a queue. - 04
Seventeen CLIs, each described in its own terms, including where it cannot be restrained
Seventeen implementer CLIs do not offer the same safety primitives, and the documentation declines to pretend otherwise. Command Code’s headless mode has two states and nothing between them: a
-prun withholds the write, edit and shell tools, and--yoloallows every tool the process can reach, while--permission-mode auto-acceptand--tools-alldo not lift the write gate — so a brief’s list of paths is guidance rather than containment, and a container is the only real boundary. Kimi, Pi and Warp have no CLI-enforced read-only mode, sotouchedFilesand the diff are what the reviewer checks against, not a guarantee. Grok cannot be prevented from writing headlessly; the relay reports a tri-statereadOnlyViolationtripwire for detected Git-visible changes, and the footnote says it neither enforces nor attributes them. ZCode is stranger still: its CLI ships inside the desktop app, and of its four documented modes onlyplanandyolowork headlessly, becausebuildandeditblock every write tool and exit 0 having changed nothing — so the relay rejects those two rather than reporting a green run. Maintaining them individually is most of the work, and the disagreements are documented too: the OpenCode relay probes the installed CLI version before every dispatch, because 2.x passes a reasoning variant asmodel#variantwhile 1.x still takes--variant. - 05
Ten near-identical relays, and the sampling error that changed the plan
By early August the repository held ten
relay.mjsfiles sharing 80 to 90 percent near-verbatim code;docs/plans/relay-core-dedup.mdrecords how that was handled. Its own conclusion is that the problem is drift, not duplication: the shared helpers had quietly diverged, and a byte-check on 2026-08-04 found a null-guard inkillChildpresent only in the Claude relay while nine others would throw, and the duration parser on a BigInt variant in eight of ten, with Antigravity and Pi on the Number variant. The document also keeps the failure of its own first version: that version had diffed the Claude relay against the Codex one and assumed the other eight matched Claude, when they matched Codex — which turned its supposedly behaviour-free batch into a behaviour change in nine files. The adopted shape was to reconcile the divergent bodies once, carrying the strongest behaviour forward — only Vibe had bounded thegit statusprobe, and the canonical body now bounds it for all ten — then add a roughly sixty-line parity test asserting byte-equality, plus an isolated-install check that copies one skill directory alone into a temporary directory and runsrelay.mjs --helpthere. The plan explicitly refuses a generator and shared fragments, leaves the one-off atomic-write copy inlined, and gives its reasons for each refusal so they can be revisited rather than relitigated. - 06
What the failure reports produced, and what the project refuses to absorb
The issues are concrete about how delegation breaks. Number 126 describes an implementer that exits normally while leaving a detached grandchild holding the stdio pipes:
exitfires,closenever does, and because every relay settles onclose, the run produces noresult.jsonat all — and the wall-clock watchdog is no help, either hanging with no timeout set or reporting a timeout for a run that succeeded. Number 125 is a disagreement kept in the open: a claim that Codex’s version preflight costs about four seconds per dispatch on Windows, answered with 126 to 163 milliseconds measured across eight runs, and a request for the other machine’s setup. Scope is defended just as explicitly. A proposal for a persistent orchestration layer above the fleet was closed with the reply that this repository ships one skill per CLI implementer plusdelegate-setup, and that such a layer belongs in its own project; a second utility that would dispatch across implementers and fail over was closed the same way, citing the rule against inventing another utility; and issue 88 stays open as the design thread for that layer, where the proposer’s fleet of Claude, Codex, OpenCode and Antigravity lanes drew an answer from a companion project doing the same thing. The last commit is a merge on 2026-09-20; implementer pull requests for Devin, Kiro, Kilo and Muse are still open.
Adjacent records
All records →No. 061
Reticle
An MCP server and a dev-only SDK that let a coding agent read and drive a running web or desktop app from the inside, then answer with a verdict and the file and line to fix instead of a screenshot.
No. 070
OpenChatCut
A local-first video editor whose editing surface is a conversation: the built-in agent and external Codex or Claude Code sessions call the same editing tools the interface itself uses, so every change lands on a real multi-track timeline as a clip, transition, caption, effect or audio item that can still be dragged, undone and exported. Projects and media stay on the machine, and preview and final render both come out of Remotion.
No. 062
Ponytail
A ruleset and skill pack installed into a coding agent so that it stops at the first of seven rungs before writing code — it does not need to exist, it is already in the codebase, the standard library does it, a native platform feature does it, an installed dependency does it, or it is one line — with six commands for setting the level, reviewing a diff, auditing a repository, collecting deferred shortcuts into a ledger, printing the benchmark scoreboard and listing the commands.