All skills
oaustegard avatar

/agent-routing

@576f2c8

Decide which model, effort level, and cascade shape each subagent gets, and how to keep improvement loops safe (evaluator-as-selector, stop on regression). Routes on measured cost-per-completed-task rather than per-token price, because a tier's token count varies more by task shape than price varies across tiers. Covers per-model effort semantics, the concision lever, cascade preconditions, context handoff, and watching a subagent fan-out live. Use when spawning subagents via the Agent or Workflow tools, when choosing how to escalate a failed attempt, when fanning out more than a handful of agents, or when asked which model or effort a task should get. Grounded in measured calibration (references/calibration-2026-07-15.md), a 2026-08 coding-cost study, and a 2026-09 agentic-repair battery that measured the cascade rungs directly; Managed Agents API specifics are operational, not calibrated.

Use this Skill: https://skilld.dev/gh/oaustegard/claude-skills/agent-routing

This session only. Nothing lands on disk.

SKILL.md

β‰ˆ230 tokens always: the name and description. β‰ˆ5.6k when used: this file. β‰ˆ2.3k more on demand in 3 files.

Agent Routing β€” model, effort, and cascade selection

The rule that decides everything

Cost is output tokens Γ— output price. Prices span ~5Γ— across tiers. Token counts span up to 7Γ— within a single tier depending on task shape. The shape therefore decides more than the tier does, and routing on the per-token discount gets the answer backwards.

Measured 2026-08-17, 14 spec-dense Python modules graded by hidden tests, all tiers at equal quality where noted:

arm tok/task pass $/task vs opus
haiku-solo 20,051 14/14 $0.1007 1.30Γ—
haiku + concision 13,342 12/14 $0.0672 1.01Γ—
opus-solo 3,001 14/14 $0.0774 1.00Γ—
sonnet-base 4,687 14/14 $0.0478 0.62Γ—
sonnet + concision 2,951 13/14 $0.0305 0.42Γ—
sonnet cascade (below) β€” 14/14 $0.0315 0.41Γ—

Haiku is 5Γ— cheaper per token and cost 30% more per solved task than Opus, because it emitted 6.7Γ— the tokens. Prices: Haiku 4.5 $1/$5, Sonnet 5 $2/$10, Opus 5 $5/$25 per MTok.

Two questions before spawning

  1. Is the output short or long? Short = a schema instance, a label, an answer, a small patch. Long = a module, a document, a plan, a review.
  2. Is it mechanically checkable, or does it need judgment?
short output long output
checkable haiku + verifier sonnet @ medium + concision + verifier
judgment sonnet @ medium sonnet/opus @ high

Output length is the discriminator because it is what the verbosity multiplier multiplies. Haiku's premium is invisible on a 200-token JSON object and ruinous on a 700-token module that costs it 13,000 tokens of thinking to produce.

Routing table

Task shape Model Effort Verify with
Extraction, classification, format transforms, schema-bound output haiku n/a schema / spot-check
Closed-form computation, state tracking, multi-hop lookup haiku n/a deterministic check
Constraint-bound generation (exact counts, required tokens, lipograms) haiku n/a mechanical checker
Bulk scans/greps, per-file summaries, fan-out reads haiku n/a sample audit
Code generation from a spec; any long structured artifact sonnet medium run the tests
Code edits with tests available sonnet medium run the tests
Judging / scoring another model's output sonnet+ medium β€” (judge β‰  worker)
Ambiguity resolution, novel synthesis, architecture, taste sonnet/opus high human or panel
Long-horizon multi-step agentic work, cross-file reasoning sonnet/opus high/xhigh milestone checks

Haiku holds the top four rows on merit: 240/240 measured across nested modular arithmetic, 30-hop chains, 25-operation state tracking, trap-laden word math, and 5-constraint generation, some with CoT suppressed (references/calibration-2026-07-15.md). Those runs requested effort: low; Haiku ignores effort, so the column says n/a (see below). Do not up-tier short checkable work "to be safe"; there is no measured benefit and it costs 3–5Γ—. The burden of proof is on routing up.

Haiku loses the generation rows on cost alone, not capability β€” it scored 14/14 on the same suite Opus swept.

Effort is model-specific β€” verify per model before reusing a level

Measured 2026-08-17 via per-message output_tokens_details.thinking_tokens, thinking as a share of output on identical prompts:

model low medium
Sonnet 5 2.9% 47.7% (61.7% without concision)
Haiku 4.5 88–91% 88–91%

low was a near kill-switch on Sonnet 5: it dropped 14/14 β†’ 10/14. Sonnet 5.5 is different. On the 14-repo seeded-bug battery (2026-09-29, two replicates, temporal-routing-headroom):

arm solved (r1, r2) output tokens, 14 tasks $/completed
Sonnet 5 @ low (2026-09-03) 9/14 16,779 β€”
Sonnet 5.5 @ low 10, 11 11,466 $0.0104
Sonnet 5.5 @ medium 11, 12 10,853 $0.0090
Sonnet 5.5 @ high 12, 12 14,488 $0.0121
Opus 5.5 @ high 11, 13 18,464 $0.0284
Opus 5 @ high (2026-09-03) 10/14 55,674 $0.1392
  • low and medium cost the same on Sonnet 5.5 for this work, and low missed only trap tasks. Claude Code's <reasoning_effort> tag agrees: 4 at low, 5 at medium.
  • high bought the paired traps: lru_ttl and wrap_text went from 0 of 2 at low to 2 of 2 and 1 of 2.
  • Sonnet 5.5 @ high matched Opus 5.5 @ high at 24 of 28 each, for 0.43Γ— the cost per completed task. Seeded repair does not separate tiers, so this says the two are close on this family and nothing about harder work.
  • The token counts are one replicate (budget deltas from r2); thinking share could not be measured, because Claude Code omits thinking text.

Effort does not reach Haiku 4.5. The Messages API rejects effort on it; Claude Code's Workflow agent() accepts the option and drops it (0 of 12 Haiku probes carried an effort tag or a transcript effort field). The identical 88–91% thinking share at low and medium above is that fact seen from the token side, and the ~26% token drop once attributed to low sits inside the 23% run-to-run gap measured below. Tune Haiku with the prompt; the routing table lists its effort as n/a.

  • Tune Sonnet with the prompt as well as the knob. On Sonnet 5, medium was the working floor and low overshot into thinking-off; on Sonnet 5.5 low is a usable rung 1 and high is the rung that caught the traps.
  • Buy depth only for judgment-heavy roles; drop triage and formatting roles to low without touching the expensive role's budget.

Setting effort β€” which channel reaches which agent

Measured in Claude Code on 2026-09-28 (muninn.austegard.com/blog/effort-levels-in-claude-code-subagents.html):

channel reaches notes
Workflow agent(prompt, {effort}) one subagent 24/24 Sonnet and Opus probes ran at the requested level while the session sat elsewhere. The only way a parent sets a subagent's effort.
Agent tool, SendMessage nothing No effort parameter. The subagent runs at the session's level when it starts or resumes.
Session setting (/effort) main loop, and every subagent at its next turn A resumed subagent picks up the new level. The model cannot change this itself; it recommends a level and the human sets it.
Managed Agents agent config Set on the agent, not per session: an effort inside a per-session model override is silently ignored. If the create response echoes effort: None, the org's beta header (managed-agents-2026-04-01) doesn't carry the feature and the field was dropped.

A Workflow run needs the user's opt-in (ultracode, an explicit request, or a user-invoked skill that names it). Without one, a subagent spawned through the Agent tool gets the session's level, and the routing table's effort column is advisory.

The concision lever, and its limit

Adding one instruction β€” this is routine work; do not deliberate at length, do not enumerate test cases or weigh alternative designs; write it directly β€” cut output 37% on Sonnet and 27% on Haiku, at no quality cost. It composes with effort. Use it on every long-output generation spawn.

It does not reach work whose output is small. On agentic bug repair β€” a patch plus a paragraph β€” the same instruction cut Sonnet output 2.9%, at no quality change either way. The lever acts on deliberation the model would have written down, so a task that emits little has little to cut. Measure before carrying it to a new task family; "every long-output generation spawn" is the scope, and repair work is not in it.

Then stop. Thinking below a model's natural level is load-bearing, and cutting into it buys tokens with correctness:

  • An engineered suppression prompt (positive framing, bounded budget, n-shot exemplar) cut Haiku 35% and halved its pass rate, 8/9 β†’ 4/9. Within that arm, passing runs thought 1.9Γ— more than failing runs.
  • Sonnet at low (2.9% thinking) fell 14/14 β†’ 10/14.
  • Priced per passing result the suppressed arms were more expensive: 22,143 tokens vs 17,126 for the un-engineered prompt.

A targeted checklist ("enumerate the spec's rejection rules first") helps only when it names the actual failure mode: it took one validation-heavy task from 15,220 to 9,634 tokens at equal quality, and took a semantics-heavy task from 3/3 to 0/3. Misnaming the failure mode is worse than not intervening.

Cascade

Precondition, checked first: is the cheap tier actually cheaper per task? The first rung is never free, so a cascade pays only when the cheap tier's measured cost per completed task is below the destination's. Verbosity can erase a price discount outright β€” Haiku at $0.067/task against Sonnet's $0.031 made haiku β†’ sonnet worse than Sonnet alone regardless of p_fail: the attempt cost 2Γ— the destination's entire job. Compute this before designing the ladder.

Second precondition: no verifier β‡’ no cascade. Route by the table instead; silent cheap-tier errors compound with nothing to catch them.

The verifier's holder makes the escalation call. Never the worker. A subagent asked whether it finished says yes: across 58 graded runs carrying an explicit "did you finish" field, 58 said yes and 44 had passed the held-out suite. Every one of the 14 failures self-reported success. The workers were not lying β€” they had passed the tests they could see, and those tests stay satisfiable while the task is unfinished. "Try it, and ask for help if you fail" therefore fails on exactly the tasks that need escalation. Put the decision wherever the stronger check lives; in a fan-out that is the orchestrator.

The shape that worked (measured, 14/14 at 0.41Γ— Opus):

result = sonnet(task, effort=low, concise)          # rung 1: 10/14, $0.0155
if verify(result) fails:
    result = sonnet(task, effort=medium, concise,   # rung 2: fixed 12/12
                    prior=result, failure=test_output)

Rung 2 is the same model one effort step up. A tier jump is the exception you justify. Measured twice. On a second battery (14 seeded-bug repos, 2026-09-03) rung 2 ran from an identical failed attempt at both settings: sonnet @ medium and opus @ high rescued the same 4 of 5 tasks and both missed the same fifth, at 11,691 against 32,504 output tokens. Composed over the same rung 1, the same-model cascade cost 0.31Γ— always-opus and the tier jump 0.76Γ—. The tier jump costs 2.5Γ— and buys nothing.

Those rungs are Sonnet 5. On Sonnet 5.5, low and medium solved the same tasks at the same cost, so the step that changes anything is low β†’ high: high is where the paired traps started getting caught (see the effort table above). The cascade itself has not been run on 5.5.

A cascade can beat the frontier solo arm on correctness, not only on cost. In that run the sonnet→sonnet cascade solved 13/14 where always-opus solved 10/14. opus starting from the issue text fell into the same stop-early trap as sonnet on three tasks; opus starting from the failed patch and the failing assertions fixed all three.

How to run rung 2 in Claude Code. For a subagent, launch a fresh Workflow agent() one effort step up and pass it the diff and the test output; Agent and SendMessage cannot change a subagent's effort. For the main loop, recommend the next level and let the human set /effort; the session keeps its cache and carries on.

Caching pushes the same way. Caches are model-scoped, so a tier jump discards rung 1's prefix. An effort change does not: in Claude Code on 2026-09-28, five subagent resumes across a level change (Lowβ†’Medium, Highβ†’Extra, Extraβ†’Max) all read their full prefix from cache, and the parent read 97,839 tokens from cache on its first request after a change. On the API the per-message effort message ({"role": "system", "content": [], "output_config": {"effort": …}}, beta mid-conversation-output-config-2026-07-01) keeps the cache on Fable 5.1, Mythos 5.1, Opus 5, Opus 5.5 and Sonnet 5.5 with thinking on; a change to the top-level effort still invalidates the messages cache.

The TTL is what misses. Every miss in that experiment followed a gap longer than five minutes. Subagents write only to the 5-minute tier and the parent to the 1-hour tier, so a subagent resumed after five idle minutes rebuilds its whole prefix (about 54k tokens for a bare general-purpose agent). Resume a subagent for a quick retry; after a longer gap, start a fresh one, since same-model agents share a cached prefix (32 of 36 fresh probes read from cache on their first request).

Every figure in this skill prices output tokens only; input and cache effects sit outside its cost model.

Carry the prior attempt and the raw failure output into the retry. Informed retry fixed 12/12; a blind re-attempt fixed 9/12 and failed one task identically across all three replicates β€” a systematic blind spot re-rolling never escapes. The extra input averaged 866 tokens, 5.9% of the retry's cost. Input is 1/5 the price of output, so context is nearly free relative to thinking.

The artifacts, not the prior model's account of itself. Adding rung 1's stated diagnosis on top of the patch and the assertions did nothing: 13/15 against 12/15 over three replicates, 1% fewer output tokens, and the whole difference was one replicate of one unstable task. It does not help and it does not anchor β€” SWE-Router (arXiv 2607.00053) restarts its strong model from the task description to avoid an anchoring effect that is not there. Pass the diff and the test output; skip the rationale.

Don't pay a frontier model to write guidance. An Opus diagnosis added zero over raw test output in two independent tests, at ~$0.15/task. The failing test already says what the orchestrator would say.

Verify content, not envelope. Strip fences, preambles, and trailing commentary before checking; hard-fail only on semantic content and log envelope deviations as soft. Two Haiku runs returned 7/7 and 6/6 correct fields while both wrapping output in a markdown fence the prompt forbade β€” a verifier keying on raw.startswith('{') would have escalated both for zero content error. Spurious escalation is a cascade failure mode, not a safety margin.

Judgment tasks fail in a shape checkers miss. Asked to rebut a stakeholder's "spend is down 66%" off a partial-month extract, Haiku killed the bad conclusion but normalized per calendar day across a 40%-weekend window and missed a model-mix confound β€” while passing every mechanical check available (word count, prose form, internal arithmetic consistency). The cheap tier fails as right headline, missed confound. This is why judgment rows route up rather than cascade.

Context handoff β€” routing picks the tier; the prompt carries the context

Subagents inherit nothing: not the conversation, not loaded skills, not the existence of artifacts already on disk. Every index, scan output, artifact path, or tool recipe must be serialized into the prompt (or a file the prompt points at). Otherwise the agent falls back to blind rediscovery and the tier premium is spent on crawling. A Sonnet with no handoff wastes more than a Haiku with a good procedure.

Per spawn: (1) artifact paths + how to query them, (2) tool commands verbatim, interpreter path included β€” subagents don't know your venv, (3) explicit anti-patterns ("no ls/glob discovery"), (4) an output spec.

Evidence: 2026-07-16, four Sonnet Explore agents launched onto a 2,300-file repo without the handoff opened with ls crawls despite a full tree-sitter symbol index sitting on disk; relaunched with per-agent index slices, the verbatim command, and anti-crawl rules, discovery cost dropped to ~zero.

To convert a judgment-shaped task into a cheap-tier-executable one (explicit procedures, n-shot examples), use the sibling down-skilling skill. This skill decides the routing; that one engineers the prompt.

Shared-prefix caching cuts the fan-out multiplier (unmeasured, conditional). When N subagents share a byte-stable prefix β€” the fixed handoff, not the per-agent slices β€” prefix caching can pull that portion toward a read-discount rate where the orchestration surface exposes it. Keep per-agent content at the tail. Verify your surface caches subagent prefixes before relying on it.

Loop discipline

Never blind-loop. Re-applying a prompt to a model's own output is the identity at best β€” an LLM call already unrolls its reasoning internally β€” and regression-then-freeze at worst: a re-looped haiku broke its own middle line on iteration 2 and froze on the broken text for every iteration after.

  1. Loop only with an out-of-band evaluator β€” ground truth, mechanical checker, or an up-tier judge scoring every iteration.
  2. Select, don't trust the last: final = argmax_r eval(answer_r).
  3. Stop on first regression. If eval(r) < eval(r-1), stop; loops froze on degraded output rather than recovering.
  4. Loop for diversity, not depth. Vary the angle per iteration; identical re-application converges instantly.
  5. "Improve this" with no headroom is the danger zone. It pressures the model to change something; without a selector, that change ships.

Judge rules

  • Judge model β‰  worker model; judge at least one tier up. Same-model self-assessment is untested.
  • Prefer mechanical checkers wherever a spec can be executed (counts, schemas, tests, regex): free, deterministic, zero judge tokens.
  • Judges are for rubric quality, not arithmetic β€” don't ask a model to verify a sum a Python one-liner can check.

Escalation triggers (route up despite the table)

  • The verifier fails twice at the same tier. Route up for capability, not for thoroughness β€” opus @ high fell into the same stop-early trap as sonnet @ low on three of four tasks built to reward a second look. A verifier catches that; a bigger model does not.
  • The task requires weighing trade-offs with no checkable ground truth.
  • Output ships verbatim to a human without review.
  • The subagent must plan its own multi-step tool strategy over many turns.
  • The task spans multiple sources that may disagree and must be reconciled.

Observing the fan-out β€” you can't govern what you can't watch

Stop-on-regression and "verifier failed twice" assume you can see a subagent's work while it runs. By default you can't: the session stream previews only the primary thread, and a subagent's output lands only after its whole turn buffers.

Attach one stream per thread. Read the session stream for the coordinator; on every session.thread_created (carrying session_thread_id and agent_name), attach a watcher to GET /v1/sessions/{id}/threads/{thread_id}/stream with event_deltas.

  • Preview is a scratch buffer; the buffered event is the record. Deltas are best-effort and shed under load, so concatenated deltas are a prefix of the final text. Reconcile by a single replace when the buffered agent.message arrives; the SDK's accumulate_managed_agents_event folds start/delta/record into one snapshot. One accumulator per connection. (The same trap appears offline: per-message usage records in transcripts include streaming partials β€” take the max per message id, or you undercount tokens ~2Γ—.)
  • No replay. A stream opened after a request started gets no deltas for it, and reconnects never replay β€” attach on thread_created or miss the first response.
  • Coordination events live on the primary thread β€” session.thread_created, agent.thread_message_sent, agent.thread_message_received. Child tool calls cross-posted to the primary carry session_thread_id; skip them.
  • Terminate cleanly. Watchers exit on session.thread_status_idle; the main loop on session.status_idle β€” print the stop reason when it isn't end_turn, and break on terminated-status events.

Operational, not calibrated. Source: Anthropic Managed Agents notebook CMA_watch_subagents_live (beta managed-agents-2026-04-01); contract in events and streaming.

Measure before trusting this

Everything above is measured on three batteries: a 300-call deterministic calibration (references/calibration-2026-07-15.md), a 14-task hidden-test coding suite (2026-08-17, ~190 subagent runs), and a 14-repo seeded-bug agentic battery (2026-09-03, ~120 subagent runs, oaustegard/experiments β†’ temporal-routing-headroom) that measured the cascade rungs, the escalation signal, and the tier gap against each other. Re-measure when:

  • A model or price revision lands. Both the verbosity multipliers and the cost table above invert on either. Sonnet 5.5 (2026-09-29) is such a revision. Its effort levels are measured above on the seeded-bug battery only; the other Sonnet figures in this skill are Sonnet 5 data, and the verbosity multipliers and the generation-suite costs have not been re-run on the 5.5 generation.
  • The task family is off all three batteries. No deterministic task has made Haiku fail on correctness yet, so the capability cliff is past what's been probed. Seeded-bug repair in a small module is now measured as not tier-separating: three probe shapes aimed at thoroughness, at ambiguity the tests underdetermine, and at a repo with no test suite at all, and sonnet @ low solved all six cells against opus @ high.
  • Output length differs materially from what was measured. The whole cost model keys on token volume; a 10Γ— longer artifact re-opens the tier question.
  • You need pass-rate differences of 1–2 tasks. Run-to-run variance swamps them: two runs of the same model on the same 14 tasks produced disjoint failure sets and a 23% token gap. Token deltas are trustworthy; small pass-rate deltas are not.

Source: SKILL.md on GitHub

No alerts11d3 checks Β· Risk SAFE
  • Gen Agent Trust Hub11d

    The skill provides technical guidelines for routing tasks between different AI models and managing subagent orchestration. It is generally safe; however, it encourages a workflow where untrusted data, such as file scan outputs, is passed directly into subagent prompts, which creates a surface for indirect prompt injection.

  • Socket11d

    No alerts

  • Snyk11d

    Risk: LOW Β· No issues

Signed by skilld at 576f2c8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 days ago
metadata
{
  "author": "Oskar Austegard and Claude",
  "version": "2.3.0"
}
Other metadata
compatibility
Designed for Claude Code / Claude Code on the Web β€” assumes an orchestrator with Agent/Workflow subagent tools. Only the Workflow tool sets a subagent's effort; the Agent tool sets its model. Not applicable to claude.ai chat use.

README badge

README badge for oaustegard/claude-skills/agent-routing