Autopilot-stack
You own the stack, never the landing. Build and verify the queue with full autonomy, then hand the operator one linear base-branch stack to review and land. The sibling of Autopilot-full.
- Run the owner loop unchanged. Resolve the forge once for the program. GitHub CLI (
gh) is the default. Ifcommand -v originsucceeds and Origin can resolve the repository, useorigin pr ...for PR create, edit, view, watch, and merge operations. Otherwise stay onghand record the fallback. Never require Graphite (gt). One Cursor cloud agent per PR owns its change end to end: build, first push, a ready PR opened before self-proof, self-proof (gates, CI, receipts), skeptical Bugbot triage per../references/bugbot-triage.md, a slop-strip (thedeslopskill from thecursor-team-kitplugin (/deslop)), /no-comments (the no-comments skill), and babysit to green perplaybooks/babysit.md. Owners parallelize when the work is self-contained. Within about 15 minutes, every owner starts adecisions.tsvtrail per the show-me-your-work skill, pushes its first branch snapshot, and opens the PR ready, never draft. Keep the trail uncommitted and return it in the report. Owners also keep thechildren.tsvof Autopilot-full step 2. - Audit on the wake chain. The root runs an audit tick roughly every 30 minutes. A local root arms each tick as a real terminal
/loop. The loop uses a monitored-shell 30-minute sleep and emits an output-notification sentinel. A cloud root uses the existing cloud-sleeper wake chain instead. Never leave the cadence to memory or lossy completion notifications. At each tick, re-read this playbook from trunk withgit show origin/main:pstack/skills/poteto-mode/playbooks/autopilot-stack.md, then re-read the armed/goal. Audit the operation against both. Fix drift during that tick. Probe each owner with a generic liveness or status check. Count only side effects as progress: commits, pushes, PR or check deltas, and store reports. Treat a lane that passes its expected runtime without a side effect as stuck. Stand it down and dispatch a replacement at once. Do not wait for a polite return. Probe all subagents and end the tick per Autopilot-full step 6. - Hold the operator gates. State-then-wait, so a request to state the plan is not a go. On the operator's explicit go, arm a
/goalwith the full program objective. The goal continues across turns until the chain is done. On the operator's stop, every owner takes an immediate zero-writes hold. - Verify each round. The owner reports its code-ready head SHA once the shipped code is final, and STACK-READY with the exact head SHA when its loop is green. The root verifies each round per Autopilot-full step 4, with STACK-READY in place of merge-ready. Nothing enters the stack unverified.
- Append on a clean verdict, never ship. No owner merges, arms auto-merge, or closes. A clean verdict appends the PR to the one linear base-branch stack, in verified order or an order the operator specified.
- Single writer on topology, parallel writers on builds. Owners push only their own branches and report the tip, current base, and intended parent. The root is the only topology writer. To append a PR, fetch the intended parent, rebase the child branch onto that exact parent tip, push with
--force-with-leaseonly after anls-remotecheck, and set the PR base to the parent branch. Create it withorigin pr create --status open --base <parent-branch>orgh pr create --base <parent-branch>according to the resolved forge. Retarget an existing PR withorigin pr edit <pr> --base <parent-branch>orgh pr edit <pr> --base <parent-branch>. Only the root PR targets trunk. Never submit or register the chain throughgt. - Absorb drift at the root, then re-verify what moved. The root fetches current trunk and rebases the chain from bottom to top. When a rebase surfaces conflicts in an owner's files, that owner fixes its own slice and the root pushes the result. A rebase rewrites every SHA above it and voids verdicts at the old SHAs. Apply the patch-id rule in
playbooks/shipping.mdat each verdict SHA. Anything that is no longer valid goes back through this playbook's step 4 before delivery. Re-run mergeability and CI after every rewritten push even when the patch-id is unchanged. The countersign rule is unchanged from Autopilot-full. A genuinely new pin raises a stop for the root's fresh countersign. Absorbing drift of landed values is not a raise. - Deliver the chain. The deliverable is one linear chain of verified PRs, reviewable bottom-up in the resolved forge, every link carrying its verifier verdict in the PR body or a comment. The operator reviews and lands it, with their own clicks or by arming merge-when-ready.
Choosing between the autopilots. Autopilot-full when the PRs are independent and landing authority is granted. Autopilot-stack when the operator wants review before landing, the work is sequenced or coupled, or merge authority is withheld.
Reply: links to the stack root and tip, a one-line verdict summary per link, and anything parked or excluded with the reason.