All skills
cat-xierluo avatar

/multi-agent-orchestration

@41268aa

编排两个以上边界独立的本地 worker,使用 Orca Run/Task/Dispatch、独立 worktree/session 或 tmux 回退,由 PM 负责拆解、派发、巡检、429 停滞恢复、独立验收、PR 收口与临时资源清理;也用于用户明确要求“并行推进”“多个 worker”“PM 总控”“Wave Autopilot”或防止 PM 直接实现逃逸。不要用于单个短任务、纯状态同步,或仅需 Git 分支、提交、PR、merge 规则的工作。

Use this Skill: https://skilld.dev/gh/cat-xierluo/legal-skills/multi-agent-orchestration

This session only. Nothing lands on disk.

templatespm-spawn-postflight.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

PM spawn 后 postflight cheatsheet

配套 SKILL.md §2、§3.3、§4 与 §7。先识别控制模式,再选择对应核验;不要把 tmux、terminal-managed 和 supervised 的完成信号混用。

Wave 准备屏障

supervised Wave 必须先完成:

  1. 写 manifest,确认 Task 相互独立且 key 唯一。
  2. 运行 orca-wave-prepare.sh --manifest ... --receipt ...。
  3. 核对 receipt 同时含 run_id、coordinator_handle 和全部 task_id。
  4. receipt 成功后才并行启动 worker,并同时传 --orca-run-id、--orca-coordinator-handle 与对应 --orca-task-id。

不得并发执行 run-create/run-use/task-create。单 worker 可以跳过 manifest,让 helper 自建 Run/Task。

通用即时核验

每个 spawn-worker.sh 返回后立即核验,不等待业务完成:

test -f "$WORKTREE/.claude/agent-sessions/$SESSION/METADATA.json"
jq '{worktree,branch,session,runtime,verification,execution_authority}' \
  "$WORKTREE/.claude/agent-sessions/$SESSION/METADATA.json"
git -C "$WORKTREE" status --short --branch

确认 cwd/worktree/branch/session、Harness authority、安装门禁、provider lease 与允许文件范围符合任务卡。核验失败就停止派发,不由 PM 静默接管业务实现。

同时核对 SPAWN_WORKER_VERIFY_PREFLIGHT、METADATA .verification、.execution_authority.allowed_shell_commands 与 Git common-dir authority receipt:任务合同中的每条命令必须保持同一完整字符串。实现/可复用验证任务优先传 --verification-contract ... --verification-task-id ...;没有 JSON 合同时逐条传 --verify-cmd 并加 --require-verification。嵌套项目使用项目配置 verification.by_worker_type,不得把 cd <subdir> && <verify> 拆成两条或改成泛化 Shell 授权。

存量 supervised Worker 已冻结进程快照,不能靠手改 JSON 生效。命令漏传时使用 pm-orchestrate.sh reauthorize --allow-cmd '<exact command>' 重建并重绑 Worker;对尚未启动的派发则修正合同后重新 spawn。

Orca supervised

即时核验真实 Dispatch,而不是 tmux session:

bash scripts/pm-orchestrate.sh show --worktree "$WORKTREE" --session "$SESSION"
bash scripts/pm-orchestrate.sh read --worktree "$WORKTREE" --session "$SESSION" --lines 80

必须看到 METADATA 的 run_id/coordinator_handle/task_id/dispatch_id 与 worker-show 对应。后续用 bounded wait:

bash scripts/pm-orchestrate.sh wait --worktree "$WORKTREE" --session "$SESSION" --timeout 900
  • worker_done → Delivery 才是 lifecycle 完成;STATUS、commit、tests、heartbeat、idle 都不是。
  • Delivery 要逐条处理,settled worker 选择 reuse/release/retain,最后才 ack。
  • worker-show/dispatch-show 与 diff/tests 可以用于业务验收,但不能替代 lifecycle settlement。
  • worker 仍存活但漏发 worker_done:用结构化 send 提醒它执行 live preamble 中的精确命令。
  • worker 已死:满足严格 liveness gate 后才用 pm-orchestrate settle --reason ...;stop 失败不得 destroy。

不要给 supervised terminal 再发完整 task prompt,也不要用 Sentinel/pm-monitor 判完成。

Orca terminal-managed

没有 supervised.dispatch_id 时只使用 terminal 控制面:

bash scripts/pm-orchestrate.sh read --worktree "$WORKTREE" --session "$SESSION" --lines 5000 --cursor 0
bash scripts/pm-orchestrate.sh wait --worktree "$WORKTREE" --session "$SESSION" --timeout 30

保存 nextCursor 后增量读取。tui-idle 仅表示当前可交互,不证明业务完成;最终以 STATUS/RESULT、真实 diff/tests/artifacts 和 PM 验收为准。terminal-managed 没有 worker_done 义务。

tmux 回退

只有 METADATA 不含 Orca terminal/Dispatch 时才核验 tmux:

tmux has-session -t "$SESSION" 2>/dev/null
tmux display-message -p -t "$SESSION" '#{pane_current_path}'
tmux capture-pane -t "$SESSION" -p | tail -20

STATUS/RESULT 用于 checkpoint;Sentinel/pm-monitor 可作事件与低频观察器,但仍需真实产物验收。不要 attach,不要无界轮询,不要让 PM 因等待 STATUS 阻塞下一次派发。

并发纪律

Wave receipt 是准备屏障;屏障之后,文件域正交的 worker 启动与 postflight 可并行。共享 schema、锁文件、迁移或同一任务源的写入必须按依赖顺序执行。spawn 返回后立即回到 PM 主循环,使用 bounded wait/事件巡检,不做 while ... sleep 无界等待。

Source: SKILL.md on GitHub

1 alert10d3 checks · Risk HIGH
  • Gen Agent Trust Hub10d

    The skill is a comprehensive multi-agent orchestration framework designed to manage multiple AI agents across isolated git worktrees and terminal sessions. It incorporates robust internal security controls such as an installation guard and a scope guard to limit the actions of sub-agents. It uses pinned executables and cryptographic hashes to verify script integrity. A potential risk of indirect prompt injection exists because the manager agent processes output from worker agents, but this is inherent to its function and mitigated by instructional boundaries and secret redaction.

  • Socket10d

    2 alerts: gptSecurity, gptAnomaly

  • Snyk10d

    Risk: LOW · No issues

Signed by skilld at 41268aa. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated yesterday
Other metadata
metadata
{
  "version": "2.31.1",
  "homepage": "https://github.com/cat-xierluo/legal-skills",
  "author": "杨卫薪律师(微信ywxlaw)"
}

README badge

README badge for cat-xierluo/legal-skills/multi-agent-orchestration