All skills
cursor avatar

/orchestrate

@03192a5
by cursorcursor/plugins9.1k stars
857

Use only when the user explicitly types `/orchestrate <goal>` to decompose a large task, spawn a tree of parallel cloud-agent workers/subplanners/verifiers via the Cursor SDK, and collect structured handoffs; do not invoke autonomously.

Use this Skill: https://skilld.dev/gh/cursor/plugins/orchestrate

This session only. Nothing lands on disk.

scriptsadaptersREADME.md

≈306 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Adapters

Adapters are external IO shells. They do not own orchestration state.

SlackAdapter

SlackAdapter is the only adapter orchestrate ships. Slack is the human-visibility layer:

  • post the run kickoff message
  • post or edit one task message per task in the kickoff thread
  • upload files when an operator explicitly asks
  • read reactions for Andon
  • post free-form comments in the run thread

postRunKickoff is the only adapter method that writes to the channel root. The CLI resolves the channel once, then constructs the adapter with that channel. Every later Slack write takes a threadTs and stays in the same run thread.

Orchestrate owns Slack status mirrors, Andon, and the comment retry queue. Agents can still call MCPs directly for Linear, GitHub, Slack, Notion, and other ad-hoc external work. Those systems are not adapter destinations.

Comment retry queue

comment-retry-queue.json stores required comments by destination string. The valid Slack shape is slack:<channel>:<thread_ts>. Workspace calls validate the destination against plan.slackKickoffRef before posting or draining.

Routine lifecycle mirrors are best effort. Required comments retry with the queue's backoff schedule.

Source: SKILL.md on GitHub

2 warnings16d3 checks · Risk MEDIUM
  • Gen Agent Trust Hub16d

    The skill is a robust orchestration framework for parallel AI agents with significant built-in security controls, including automated redaction and environment isolation. However, it exposes a local command execution surface through its measurements feature and has a vulnerability surface for indirect prompt injection when interpolating agent handoffs.

  • Socket16d

    1 alert: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at 03192a5. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 5 months ago
disable-model-invocation
true

README badge

README badge for cursor/plugins/orchestrate