All skills
simota avatar

/nexus

@c805268
by shingo imotasimota/agent-skills85 stars
15

Orchestrating multi-specialist task chains and scope-adaptive product delivery: classifies intent, selects and executes the minimum viable chain, aggregates results, and verifies acceptance criteria. For multi-domain tasks, build-first delivery, and product lifecycle execution.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/nexus

This session only. Nothing lands on disk.

referencerecipes-detail.md

≈17k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Recipes — Detail

Extended descriptions for verbose Recipe rows, and the canonical home for the family taxonomy. reference/recipes-index.md carries the canonical name / subcommand / chain template / Read pointer, and SKILL.md ### Recipe Families keeps a compact grouping + one-line axis; this file expands the "When to Use" prose and the full within-family axes that do not fit on one row. The Recipes table is flat; the families below group it and name the axis that separates confusable siblings. When an input fits a family but not a specific recipe, use the axis to pick — or, for an overloaded anchor, run the one-question REDIRECT (reference/intent-clarification.md).


Recipe Families (mental model + within-family disambiguation)

Family Recipes Distinguishing axis within the family
Fix bug · security fault class: defect vs vulnerability
Improve (existing code) refactor · optimize · kaizen · anneal · restyle scope of the change: known restructure / a perf number on correct code / one feature vs a target / discovered design weaknesses / the visible design. Per-recipe axes → §§ anneal · restyle below. improve/polish/enhance and improve the design are overloaded across the family → REDIRECT (code-vs-visual: architecture/code → anneal, UI/look-and-feel → restyle; one feature vs a target → kaizen; known single restructure → refactor; iterate to a quality bar → converge in Loop). Prove vs fix: assay (Quality-Max) proves or refutes stated design claims by experiment and hands anneal a pre-evidenced slate; a plain "it drifted, clean it up" stays on anneal, the cheaper default.
Loop (autonomous / iterative execution) goal · converge · quell · burnish · whet within-family axis = what the completion oracle is: goal = native /goal setup only (no run) · converge = in-session rubric Generator-Evaluator quality loop (score per dimension) · quell = an external review engine's finding count reaching zero (Codex by default; the reviewer is the evaluator, so maker≠checker is structural) · burnish = the same external-reviewer oracle applied to a rendered UI surface, split in two (hard findings to zero, soft axes to ≥ 2 — see § burnish below) · whet = a mutation engine's surviving-mutant set driven to a per-partition threshold contract (see § whet below). These three differ only by the object — code diff · rendered surface · surviving mutants — and all fill the five declaration slots of _common/FINDING_LEDGER.md; newsroom is a fourth member on the claim axis, kept in Grounded content because its deliverable is an article. Before proposing a fifth, read that file's §1 (C1-C5) and § When a finding loop is the wrong shape. Every loop passes _common/LOOP_PRECONDITIONS.md first — its § Shape resolution classifies an underspecified make a loop/automate with a loop/run until done to the right owner, gating on the loop-engineering preconditions (verifiable oracle · external hard-stop · maker≠checker · persistent memory · drift-aware). The unattended runner is the orbit skill — never re-implemented here; discovery→ship loop → apex. An explicit shape → the sibling direct.
Build (new) feature · deliver · apex scope and investment: feature = one bounded capability · deliver = scope-adaptive product/MVP delivery using the minimum viable chain · apex = high-investment discovery→ship one-shot.
Discover → build pairs spec→feature/deliver/apex · charter→enact · layer→sigil-authoring spec = one feature spec (dialogue) · charter = whole-repo team + work plan · layer = whole-repo reusable operating layer (project skills + recipes + workflows + routing map). All stop at a design; the pair runs it. layer vs charter: charter plans what work to do + who does it (one delivery); layer designs what reusable tooling the repo should have (persists). layer vs sigil: Sigil[blueprint] designs the coordinated set; Sigil's artifact modes implement one artifact at a time.
Reason (no code) gedanken · delve output = insight, not a build. gedanken = abstract thought-experiment about a claim/hypothesis (construct→reason→perturb→refute→conclude); delve = grounded deep-dive into a shipped feature → evolution directions (deepen/broaden/reframe). Axis: abstract-hypothetical vs grounded-existing-feature. Both orchestrate magi/flux; trivial "what if" → flux/magi, trivial "what could we do with X" → flux/spark direct. gedanken vs magi (intent-anchored, not keyword-anchored — "worth it" alone doesn't decide it): verdict-seeking (wants a final go/no-go delivered) → magi direct; process-oriented (wants the reasoning walked through — e.g. "think through whether microservices are worth it here, no code") → gedanken. delve vs kaizen (discover directions vs execute vs a target): evolve/improve a feature is overloaded → REDIRECT.
Comprehend (reverse-engineer existing code → understanding artifact, no code) cartograph · chronicle · verity · abide output = a grounded documentation artifact of what exists, not insight/evolution and not a build. Within-family axis: space vs time vs standing coherence vs change conformance — cartograph = multi-repo structure, how it works today (code citations); chronicle = commit history, how it got here & what it believes (commit SHAs); verity = where the repo's account of itself fails to hold — contradictions, stale record, unexplained artifacts, triaged and routed (both-direction sweeps at a pinned HEAD). The first two document what is; the last two document what does not add up, and are the members whose deliverable is a defect register. verity vs abide splits on the anchor, not the subject — both audit record-vs-reality, but verity freezes an artifact inventory at a pinned HEAD (no change anchor), while abide freezes a change set and judges it against the standing decision record including records the change never touched. verity since=<tag> narrows verity's inventory to touched artifacts and therefore cannot see abide's core case — the code moved and the ADR did not. "where does our record disagree with our code" → verity; "did this change / this PR / this release walk away from a decision" → abide (→ atlas to author the superseding record; → verity when the docket sprawls repo-wide). Axis vs the Reason family: document-what-exists (backward) vs reason/evolve (forward); axis vs Improve: verity reports and never edits, anneal fixes (audit→fix pair). Full prose + the route-out list → §§ cartograph · chronicle · verity below.
Verdict (which feature) essential · killer · trim essential = THE must-have · killer = THE differentiator · trim = remove dead-weight (inverse). Shared gate: reference/verdict-gate.md.
Reproduce, Synthesize & Invent clone · fuse · graft · transmute · migrate · eureka source count/fidelity: clone = 1 source faithful · fuse = ≥2 sources synthesized · graft = host+donor concept (rejects surface copy) · transmute = own-source cross-language · migrate = own-system change-completeness · eureka = zero sources — originates a mechanism and proves it novel against a Prior-Art Ledger; a collision with an existing source kills the candidate rather than feeding it. Shared discipline: _common/DIFFERENTIAL_PARITY.md. differential parity alone is ambiguous → REDIRECT.
Quality-Max (expensive, confirm) acceptance · growth-acceptance · summit · podium · wish · runway · crucible · silhouette · lattice · chorus · assay · hallmark · rebrand · marquee axis = what is being maximized, and each member owns exactly one question with one oracle. Merge/lifecycle: acceptance (proof-carrying merge) → growth-acceptance (post-launch). Artifact: summit (strategic code, engine triangulation) · podium (content/slides) · wish (the single most important ask, no second delivery — vs converge in Loop, which iterates to a standard bar with revisions expected). Design/brand wing — one question each: best? → runway · works at all? → crucible (the floor; orthogonal to runway and commonly sequential — ceiling first, floor proven after) · recognizably ours? → silhouette · one system? → lattice · one product across platforms? → chorus · what is the brand? → hallmark · landed everywhere? → rebrand · acquisition LP → marquee. Code-design wing: are the design claims true? → assay; assay(prove) → anneal(fix) is a measure→fix pair spanning this family and Improve, with anneal the cheaper default for "find what's wrong". Per-recipe oracles, cost, confirm tier and sibling axes → the §§ below.
Grounded content newsroom output = an article whose every factual claim is provenance-proven. newsroom = claim-grounding maximization for a single written artifact: Evidence Ledger (per reference/research-grounding.md, primary-source-authoritative) built before writing (compose) or against an existing draft (audit) → producer≠verifier claim audit with citation-support re-open → adversarial refutation of load-bearing claims (≥2 independent T1–T3 sources) + staleness check → remediation ≤2 cycles → named Provenance Report; unresolvable claims marked [UNVERIFIED], never silently kept or deleted. Axis vs neighbors: podium = package polish across formats (grounding is one Phase 4 branch there — newsroom inverts the weighting: grounding IS the deliverable); tome direct = authoring with no grounding requirement; attest = impl-vs-spec (newsroom is prose-vs-world); canon = named-standards compliance.
Document package package (incl. venture) 12-domain preset registry
Meta / control pack skill-profile switch; CLASSIFY is an internal phase and proactive is a no-args invocation mode, not Recipes

kaizen

Existing-feature continuous improvement covering perf / UX / code-quality / feature-extension. PDCA loop, not single-pass: improves against a quantified target and stops on target-met or diminishing-returns. Differs from refactor (internal-only), optimize (perf-only), and feature (new addition). Scale: 4-8 agents (× ≤3 cycles).

The ⟲{…}⟲ block loops until target-met OR diminishing-returns OR iteration cap. Full phase contract (DIAGNOSE+BASELINE / PROPOSE+TARGET / IMPROVE / VERIFY+LOOP / SHIP) → reference/inline-recipes.md.


anneal

Codebase design audit → prioritized behavior-preserving brush-up. The corrective, execution-bearing member of the Improve family: where kaizen improves one feature against a target you already chose, anneal discovers undiagnosed design weaknesses across a scope you have not pre-diagnosed, then brushes up the prioritized slate. Surface design issues from six independent dimensions (architecture / code-smell / standards / over-engineering / under-specified design = edge cases & invariants / specification = spec↔code conformance & drift, AC traceability, undocumented behavior), prioritize by value × risk, and fix the slate with real code that preserves behavior (refactor-grade discipline) — gated by a dual VERIFY (no-regression + Before/After design-metric proof). The metallurgical metaphor: relieve accumulated internal design stress and leave the structure tougher, not cosmetic polish. <target> scopes the audit; no target → whole-codebase sweep (confirm-before-launch, slate capped to top-N by value × risk, long-tail recorded). Default Mode AUTORUN with the Phase 3 slate gate (Ask First on 10+ files / PUBLIC_API / DATA / any behavior-changing fix). Named Design Ledger; checkpoint-resume (anneal resume). Engine routing follows summit principles (Codex code-gen / Claude judgment). Distinct from refactor (known restructure, known scope), optimize (perf number), kaizen (one feature vs known target), delve (no code — evolution directions), trim (remove features), summit/acceptance (PR-gated), and the spec-axis neighbors spec (author a new spec) / attest·pdm (report-only conformance) / acceptance (PR gate). 6-16 agents × ≤3 cycles, medium-to-high cost (cost scales with slate size, not codebase size — PRIORITIZE is the governor).

Full phase contract (MAP / CRITIQUE / PRIORITIZE / BRUSH-UP / VERIFY / SHIP), Failure Modes Prevented, and boundaries → reference/anneal-recipe.md. Wrap in a rubric-graded loop via converge anneal.


restyle

UI/visual design improvement of an existing surface — the UI/visual-design member of the Improve family: where anneal improves code design and kaizen improves one feature against a quantified metric, restyle improves the visible design itself (look · feel · motion · hierarchy · consistency) of a screen / component / flow. Audit the current design (Echo persona walkthrough + friction baseline ‖ Palette heuristics + a11y baseline), have Vision set a design direction + Design Brief (rubric axes with current→target scores + explicit non-goals), confirm at the ✓direction-gate, then loop implement↔verify against the Brief — verified by Echo re-walkthrough, a11y ≥ baseline, and a Radar no-regression gate (restyle changes presentation, never contracts). Muse's token-first rule (tokenize before ad-hoc styles) makes each restyle strengthen the design system instead of eroding it. <target> scopes the audit; no target → whole-UI sweep (Confirm-before-launch; slate capped to top-N by friction × visibility, long-tail recorded). Default Mode AUTORUN with the ✓direction-gate (Confirm-before-launch on no-target / full-surface / brand-token / 10+ files). Named Lookbook; checkpoint-resume (restyle resume). Engine routing follows summit principles (Codex code-gen: Artisan/Flow/Muse-apply/Ink; Claude judgment: Echo/Palette/Vision/Guardian). Distinct from kaizen (one feature vs a metric target — a kaizen UX axis that grows into a redesign hands off here), anneal (code/architecture design), feature (new capability), vision direct (direction only, no execution), palette/flow/muse direct (one named fix — minimum viable chain), the atelier skill (full design-to-impl pipeline incl. prototypes/assets/persistent design system — hand off when scope becomes pipeline-wide), funnel premium (LP studio). 5-12 agents × ≤3 cycles, medium cost (slate cap is the governor).

Full phase contract, Failure Modes Prevented, boundaries + Decision Tree → reference/restyle-recipe.md. Loop discipline per reference/evaluator-loop-protocol.md (Brief = rubric; Echo/Palette = independent Evaluators).


charter

Repo-wide analysis → self-driving Charter, team design included — stops at the document. Document-first planning recipe; the execution half is enact. Where apex discovers a feature and ships it in one shot, charter reads the whole repository, distills a durable Charter artifact (docs/CHARTER.md + CHARTER.roster.yaml) that designs the team (§5 roster + §6 orchestration plan) and §10 checklists (pre-flight / per-package Definition-of-Done / progress tracker / final delivery) without building or running it. The team becomes a pure function of the document, so enact (or a future session) reconstructs the identical team and gates each boundary on the checklists. Distinct from apex (feature-centric, one-shot), goal (loop config only), package (docs only). The §5/§6 design is multi-engine by default (engines=claude+codex): Claude Code for plan/design/review, Codex CLI (model the supported authorized model, C3.0 variant tiering) for build loops + high-volume parallel coding (Orbit sub-hub pinned to Codex, per-engine prereqs + fallback_engine recorded for enact). Modes: autonomous (no-args) / objective-supplied / scope= / out= / engines=. 5-15 agents (analysis + authoring only). No execution → no Confirm Gate.

Read: reference/charter-recipe.md.


enact

Execute a Charter end-to-end. The execution half of the charter → enact pair: reads an existing Charter, constructs the team from §5 roster (bind role→skill→spawn + verify prereqs), orchestrates §4 work breakdown via the §6 plan (spawn per package; Orbit sub-loop for build iterations; checkpoints + guardrails; hub-spoke aggregate), then verifies §7 and ships. Updates §9 Execution Log so the Charter stays the living source of truth; resume restarts from the last checkpoint. No analysis/planning — the Charter is the complete contract; a missing/invalid section stops at Phase 1 rather than improvising. Runs to completion (enforced under AUTORUN_FULL): no mid-run stops for progress, recoverable failures (retry→fallback_engine→Scout+Builder→alt owner→SKIPPED(blocked)+continue), or cost; loops until every §4 package is terminal (SUCCESS/PARTIAL/SKIPPED). Only intentional stops = §8 safety red lines (L4/destructive/out-of-scope) + no-valid-Charter precondition. Honesty preserved: §7 failures delivered truthfully, not masked. The orchestrator streams every progress event to an append-only run-log file (docs/CHARTER.run.log.md, override log=); Charter §9 holds only a pointer + summary, and resume restarts from the run-log tail. ★ Gate is announce-and-proceed (no objection window); GUIDED/INTERACTIVE re-introduce stops. Modes: enact <path> (default docs/CHARTER.md) / dry-run (construct + verify only) / resume. 6-30+ agents.

Read: reference/enact-recipe.md.


layer

Design + stand up a repo's operating layer — Sigil blueprints and authors, Nexus registers. Where charter designs a team + work plan to deliver a body of work, layer designs the reusable operating layer a repository should carry: which project-local skills encode its conventions, which repo-tailored recipes chain them, which skill-and-agent workflows coordinate project outcomes, and a routing map (single-owner per task domain; ecosystem-owned tasks deferred, never duplicated). Sigil[blueprint] designs the system; Sigil's artifact modes author each body (9+/12); Nexus registers recipes/workflows/routing map; Hone/Orbit take hooks/loops. Mechanism choice per task uses _common/MECHANISM_SELECTION.md for hook/rule/subagent/skill. Each designed workflow carries a formal topology + ≤ 5 phases (no Bag-of-Agents). Distinct from charter (team+work plan, one delivery), sigil artifact authoring (one skill body), and spec (one feature spec). Modes: whole-repo (no-args) / <scope> / design-only (stop at the blueprint, charter-style) / resume / engines=. Confirm-before-launch (DELEGATE writes files + changes routing); ≥10 skills or established-routing changes → Ask First. Named report: Operating-Layer Blueprint (+ Layer Report tail in full mode). Checkpoint-resume (layer resume). 5-15 agents (design-only 3-6); Low-Medium cost.

Read: reference/layer-recipe.md.


spec

Interactive feature-proposal → locked specification through deep human-in-the-loop dialogue. Takes a rough idea and refines it conversationally into a sign-off-ready spec carrying mandatory testable, traceable acceptance criteria, then stops at the spec — writes no code. The discovery half of spec → feature/apex, mirroring charter → enact. Defaults to INTERACTIVE (with delve; the dialogue is the deliverable); its phase-boundary checkpoints are contract-level, so even AUTORUN cannot skip them. +Lens reuse-scan grounds it in the existing codebase; draft-persisted & resumable (spec resume [<slug>]); locks only when all lock preconditions pass — testable L3 ACs + the Spec Quality Gate (ambiguity/completeness/consistency/testability/scope/provenance) + a refute-polarity skeptic panel on the four load-bearing claims (problem-real / direction-beats-rejected / ACs-entail-REQs / scope-separable, _common/ADVERSARIAL_REFUTATION.md) — and writes docs/specs/<slug>.md per a standard template; the dialogue itself is conducted per reference/dialogue-protocol.md (question craft, Assumption Ledger, Provenance Gate). Depth-scaled (depth=light|standard|deep — scales turns and panel size, never the lock preconditions) and emits a Spec Handoff Packet (ACs + non-goals + assumption ledger + refutation flags + reuse findings) the build recipes consume without re-deriving. Distinct from essential/killer (which-feature verdict, minimal dialogue), feature/apex (build code), charter (whole-repo team design), converge (automated grading loop), and flux (single-agent brainstorm, no artifact). 3-12 agents × dialogue turns (light 3-5 / standard 5-9 / deep 8-12).

Full phase contract (FRAME / EXPAND / CHALLENGE / SHAPE / SPECIFY / LOCK), boundaries, and anti-patterns → reference/spec-recipe.md.


gedanken

Structured thought-experiment reasoning — take a question / hypothesis / premise / design tension and reason about it rigorously inside a constructed hypothetical, under controlled variation, to surface hidden assumptions, derive non-obvious implications, and establish what would falsify the conclusion. Writes no code. The disciplined analog of a classic Gedankenexperiment (Galileo's falling bodies, Einstein's elevator, Rawls' veil of ignorance). The general-purpose exploratory-reasoning recipe: distinct from magi (which delivers a decision — gedanken is often its upstream), flux (diverges; gedanken converges under variation), omen (failure-mode-only; a special case gedanken uses in PERTURB), flux (a single reframing move; gedanken orchestrates it into a protocol), helm (business-scenario simulation; gedanken is domain-agnostic), and spec/charter (which produce buildable artifacts; gedanken produces an insight). Default Mode AUTORUN_FULL (INTERACTIVE for Socratic dialogue); no confirm gate (no code). 3-9 agents × variation depth. A trivial one-off "what if" routes to flux/magi direct (minimum viable chain).

The variation bound and the adversarial REFUTE are contract-level; resumable per phase. Optional handoff at CONCLUDE → magi (decision) / spec (if it resolved what to build) / verdict recipes. Full phase contract, archetype menu, Failure Modes Prevented, and boundaries → reference/gedanken-recipe.md.


delve

Existing-feature deep-dive → evolution-direction dialogue — take an already-shipped feature, excavate it through dialogue past what it does to what is really going on, surface non-obvious insights, and chart evolution directions (deepen / broaden / reframe). Writes no code — stops at a named Evolution Map and hands off to spec/kaizen/feature/apex. The grounded-existing-feature member of the Reason family (where gedanken is the abstract-hypothetical member) and the discovery upstream of kaizen. Distinct from kaizen (executes improvement against a fixed quantified target — delve discovers what to improve and is its upstream), spec (shapes a new idea into a buildable spec — delve excavates an existing feature), gedanken (reasons about an abstract hypothetical — delve is grounded in real code/usage), and the verdict recipes essential/killer/trim (which-feature verdict — delve maps directions for one feature). Default Mode INTERACTIVE (with spec, the two dialogue recipes); its three dialogue checkpoints (confirm-feature-as-is / validate-insights / pick-direction) are contract-level, so even AUTORUN cannot skip them. No confirm/safety gate (no code). Draft-persisted & resumable (delve resume [<slug>]); writes docs/evolution/<feature-slug>.md; the dialogue itself is conducted per reference/dialogue-protocol.md (question craft, Assumption Ledger, Provenance check at CHART). 3-9 agents × dive depth. A trivial one-off "what could we do with X?" routes to flux/spark direct (minimum viable chain).

The three dialogue checkpoints and the EXCAVATE↔SURFACE deepening bound are contract-level; resumable via delve resume [<slug>]. Full phase contract (GROUND / EXCAVATE / SURFACE / DIVERGE / REFUTE / CHART), Failure Modes Prevented, and boundaries → reference/delve-recipe.md.


cartograph

Multi-repo reverse-engineering → bird's-eye diagrams + design document — reverse-engineers a feature/system spanning multiple repos from the code (white-box) into one cross-repo model + a design doc; writes no product code, grounded-by-construction (UNKNOWN over fabrication). Named Cartography Map; checkpoint-resume (cartograph resume). Distinct from delve (one feature, dialogue, evolution), charter (team+work plan), pdm (plan-vs-code), clone (black-box rebuild in code), migrate, package, and chronicle (temporal arc vs this spatial snapshot); single-repo → lens/atlas/canvas direct. 5-16 agents × ≤3 grounding cycles.

The SCOPE gate and the grounding/coverage bound are contract-level; resumable via cartograph resume. Full phase contract (SCOPE / MAP / CORRELATE / SYNTHESIZE / DIAGRAM / DOCUMENT / VERIFY), Failure Modes Prevented, and boundaries → reference/cartograph-recipe.md.


chronicle

Commit-history reverse-engineering → era timeline + narrative storylines + lens deep-dives + inferred ethos + repository history document set — reconstructs how a repo evolved along two axes: time (named eras) and theme (storylines: feature-lineage/defect-&-resilience/improvement/decisions → an ADR-style decision log), then a DEEPEN phase (security/domain-design/architecture/performance/design-ux/issues, one file per lens) and a DISTILL phase infers the project's pattern-grounded, refutation-gated, people-neutral ethos. Writes no product code — grounded to commit SHA/tag/PR at a pinned HEAD, UNKNOWN over fabrication. Named Chronicle; checkpoint-resume (chronicle resume). Distinct from cartograph (spatial snapshot vs this temporal arc), launch (one period's report), tome (one diff), trail (one regression question), atlas (forward ADR), magi (live decision vs this descriptive ethos), delve, charter, pdm. 4-21 agents × ≤3 grounding cycles.

The SCOPE gate and the grounding/coverage bound are contract-level; resumable via chronicle resume. Full phase contract (SCOPE / SURVEY / SEGMENT / EXCAVATE / SYNTHESIZE / DEEPEN / DISTILL / DIAGRAM / DOCUMENT / VERIFY), Failure Modes Prevented, and boundaries → reference/chronicle-recipe.md.


verity

Codebase × documentation coherence audit → a triaged discrepancy register — audits a repo's record (docs, comments, config, CI, specs) against its reality (the code as it runs) in both directions and reports exactly three finding classes: CONTRADICTION (two artifacts assert incompatible things), STALE (true once, no longer), UNEXPLAINED (exists with no recorded reason). Report-only by contract — writes only under docs/audit/, fixes nothing, routes every finding to the recipe that would close it. Named Verity Register (README.md + per-class files + a machine-readable register.yaml + a rejected-candidate annex); checkpoint-resume (verity resume). 7-24 agents × ≤3 coverage/grounding cycles.

Four load-bearing pieces, none optional. (1) Two asymmetric sweeps — CORRELATE-FORWARD verifies extracted claims against the code (finds CONTRADICTION + STALE); CORRELATE-REVERSE traces provenance from code back to the record (the only source of UNEXPLAINED). Either sweep alone reads as a complete audit while missing a whole class. (2) Authority adjudication — which side of a contradiction governs is a separate decision made against a declared authority table; UNDECIDED is a first-class outcome and the code is never the default winner, because filing a code regression as a stale doc converts a bug into a documentation chore. (3) The Provenance Search Record — an UNEXPLAINED entry is a claim about the record's silence, so it is inadmissible without an enumerated search (comments · docs · ADRs · git log/blame · PR body · issues · CHANGELOG), each marked searched: miss or not-available: <reason>; otherwise "I did not look" ships as "nobody knows". (4) Frozen inventory + root-cause clustering — the denominator is fixed at INVENTORY so coverage is falsifiable, and findings are grouped by the change that produced them, so an abandoned migration routes to migrate once instead of to fourteen doc edits.

Not a _common/FINDING_LEDGER.md member: it emits a finding set but has no fix cycle, so it fails C6 exactly as compliance findings do — closure belongs to the routed recipes and to humans. It takes that file's tracker shape (§1a), borrowing assigned identity (§4) and nothing-silently-dropped (§5), and adds no loop machinery; re-running at a later HEAD and diffing register.yaml is the re-check.

Distinct from cartograph (spatial structure) and chronicle (temporal arc) — the family's third axis is coherence; from anneal (verity→anneal is the audit→fix pair; bare spec-code drift splits register-vs-fix), pdm (planned-vs-shipped scope), attest (conformance to one privileged spec), canon (external standards), lattice (design-system token denominator), newsroom (claims vs the world — same discipline, opposite direction), and sweep/trail/lens (each one question, each a verity engine).

The SCOPE gate and the coverage/grounding bound are contract-level; resumable via verity resume. Full phase contract (SCOPE / INVENTORY / EXTRACT / CORRELATE-FORWARD / CORRELATE-REVERSE / CORROBORATE / TRIAGE / REGISTER / GATE), the finding-class taxonomy, the authority table, the route table, Failure Modes Prevented, and boundaries → reference/verity-recipe.md.


essential

Must-have feature verdict + conditional implementation. Converges on THE ONE feature without which the product cannot exist. Subtraction-oriented (MVP, core feature, scope reduction).

Full sequential funnel + verdict + conditional implementation → reference/inline-recipes.md.


killer

Killer-feature verdict + conditional implementation with feature flag. Converges on THE ONE decisive differentiator via cross-engine triangulation, then gates the verdict on defensibility (moat) + adversarial refutation before any build. Default baseline: Claude + Codex (dual-engine) — perspective diversity via different prompt frames + WebSearch tool usage. agy optional third axis when AVAILABLE. Addition-and-leap-oriented.

Full cross-engine triangulation + moat/refutation gate + verdict + flagged implementation (with differentiation KPI & kill criterion) → reference/inline-recipes.md.


trim

Dead-weight feature removal verdict + conditional excision — the inverse of essential/killer. Applies the essential axis (must-have for the core job?) and killer axis (defensible differentiator?) as a 2×2 filter over the existing feature set: a feature survives if essential OR killer; only one that is neither and carries real cost (CoK ≥ 7) becomes a removal candidate. Core engine is void (YAGNI / Feature Sunset / CoK / blast radius); trim adds the dual-axis judgment + multi-agent execution void's propose-only recipes lack. Subtraction-and-removal-oriented. trim with no target → whole-project auto-scan (PDM full inventory + Void carrying-cost rank → top-N-by-CoK slate; defaults to GUIDED). Confirm before Phase 5 excision (semi-destructive; PUBLIC_API/DATA blast radius → Ask First).

Full inventory + dual-axis gate + safety/must-stay refutation + verdict + phased excision → reference/inline-recipes.md.


newsroom

Grounded article production / audit — claim-grounding maximization for a single written artifact: every factual claim traces to a cited, trust-tiered source; speculation/inference/opinion explicitly labeled or removed; wrong views hunted adversarially. Two modes: compose (evidence-first — the Evidence Ledger per reference/research-grounding.md is built before writing and the writer is ledger-bound) and audit (existing article → claim-driven sweep → correction). Core guarantees: citation-support over citation-existence (the auditor re-opens every cited source and confirms it states the claim), producer ≠ verifier (auditor/skeptics never the writer, Q9), corroboration (load-bearing facts need ≥2 independent T1–T3 sources; T4 never sufficient alone), staleness check vs publication date, and never-silent (unresolvable claims ship marked [UNVERIFIED] or are deleted with a log — silent keep and silent delete both forbidden). A member of the external-reviewer-to-zero family (_common/FINDING_LEDGER.md) on the claim axis: the Evidence Ledger + claim_audit.json are that protocol's ledger with claims as findings, identity is assigned (claim_id carried through rewrites, because remediation rewrites sentences), and DOWNGRADED / DELETED (logged) are its self-dismissal analogue. C4 holds — the claim set is the article's own assertions — so no split oracle is needed, which is why ≤2 cycles suffice where quell needs 6. The prose craft axis is not in scope (it fails C4 and lives in reference/doc-quality-protocol.md W7-W11 as a single-pass gate). Named Provenance Report; checkpoint-resume (newsroom resume). 6-16 agents × ≤2 remediation cycles, 2-5× cost. Confirm release-critical (conditional — intentional parity with podium). Distinct from podium (package polish across formats — grounding is one branch there; newsroom inverts the weighting), tome direct (authoring, no grounding requirement), attest (impl-vs-spec; newsroom is prose-vs-world), canon (named-standards compliance), clone/fuse/graft sweeps (same ledger machinery, capture-authoritative vs newsroom's primary-source-authoritative).

Read: reference/newsroom-recipe.md, reference/research-grounding.md.


wish

Once-in-a-lifetime request — scarcity-gated one-shot quality-ceiling delivery, deliverable-agnostic (code / document / design / content / plan). Seven identity elements no sibling carries together: Scarcity Gate (usage journaled in .agents/nexus.md; routine invocations challenged — anti-inflation is contract-level), Benchmark Anchor (score-3 descriptors sourced from best-in-class exemplars via a cited Evidence Ledger, user-ratified before the rubric freezes — a ceiling invented by the system that must reach it is not a ceiling), Ceiling ACCEPT (all rubric dims = 3, raised from converge's ≥ 2), calibrated evaluation (two-point calibration against the exemplar and a routine-quality control; an uncalibrated evaluator cannot produce a ceiling ACCEPT), Wish Crystallization (contract-level dialogue excavating the true wish + disappointment criteria + the named recipients), cross-engine blind tournament (3-5 candidates distributed across model families, one per (engine, angle), provenance stripped until scores are recorded; dual-lineage carry on L/XL), and a two-part exit gate — One-Shot Gate (fresh-context verifier: "would a redo be materially better?" with cited evidence) + Comparative Gate (blind head-to-head vs the exemplar and vs our own retained runner-up; a loss to the runner-up means convergence destroyed value). Also carries a Reception Simulation (named recipients meet the artifact cold), a bounded rubric amendment (once, user-ratified), a budget envelope (budget-reached delivers best-so-far, never a silent overrun), and an Unexplored-Space Ledger (what was deliberately not pursued). 27-102 agents × ≤5 cycles (+1 bonus), 10-28× cost. Always confirm (the Scarcity Gate is the confirmation; intentional parity with summit's unconditional gate). Distinct from summit (multi-engine tournament for strategic code), converge (standard bar, revisions expected), apex (build lifecycle), podium (content pipeline).

Read: reference/wish-recipe.md, reference/evaluator-loop-protocol.md, reference/dialogue-protocol.md.


runway

Flagship UI design tournament — parallel design directions → persona-panel judging → ceiling convergence (all rubric dims = 3) for the surfaces that define the product. The design-axis member of the Quality-Max family: where summit runs an engine tournament for strategic code and podium maximizes content, runway maximizes the visible design of an in-product flagship surface (top page, core product screen, first-run onboarding). Where restyle (Improve family) iterates a single Vision direction to a standard bar (dims ≥ 2), runway competes 3 orthogonal directions (brand-led / usability-led / trend-led) prototyped in parallel, judges them with a persona panel (Echo×personas ‖ Palette ‖ Magi brand-fit), then converges the winner — salvaging the losers' best ideas — to the ceiling (all dims = 3). restyle's ✓direction-gate escalates here when directions tie or the surface is product-defining. Named Runway Board (per-direction score comparison + salvage record + score trajectory); checkpoint-resume (runway resume). Distinct from marquee (conversion-driven acquisition LP — runway surfaces live inside the product), wish (deliverable-agnostic + Scarcity Gate), vision direct (direction only), atelier skill (design-to-impl pipeline), kaizen (one feature vs a metric). 12-30 agents × ≤3 cycles, 4-10× cost. Always confirm (intentional parity with summit/wish).

Read: reference/runway-recipe.md, reference/evaluator-loop-protocol.md.


hallmark

Brand identity package quality-max — brand-core dialogue → identity tournament → persona-resonance + adversarial gauntlet → proof-carrying Brand Book + design tokens. Creates the brand identity itself (values / voice / prohibitions → visual identity → guidelines) with verification gates no document generator carries: a persona-resonance panel (Cast+Echo[demand]+Echo) and a differentiation refutation per _common/ADVERSARIAL_REFUTATION.md ("does it still hold with a competitor's logo swapped in?"). Fills the gap upstream of growth-acceptance, which verifies brand tone at ship time (G14) but never creates the identity — hallmark's output feeds its Brand Compiler. Phase 2 Brand Core is a contract-level dialogue; AUTORUN cannot skip (per reference/dialogue-protocol.md). Mostly no code (token definitions only). Named Hallmark Charter; draft-resume (hallmark resume — the dialogue draft + identity drafts are the state). Distinct from compete skill (personal branding — hallmark is product/org brand), package (doc generation without verification gates), rebrand (propagates a settled brand — hallmark→rebrand is a create→propagate pair), marquee (acquisition LP that consumes the brand), vision/muse direct (one direction / token work — minimum viable chain), BRAND_EQUITY (Compete — research only). 10-24 agents, 3-8× cost. Confirm-before-launch (Phase 0 Scope Gate: new / rebrand / partial refresh).

Read: reference/hallmark-recipe.md, reference/dialogue-protocol.md, _common/ADVERSARIAL_REFUTATION.md.


rebrand

All-surface brand propagation with a proven-complete guarantee — migrate's RESIDUE-GATE discipline × a brand-consistency rubric; old-brand decommission gated on the completeness proof. Takes a settled brand (a hallmark output or an existing Brand Book) and propagates it across every brand touchpoint — UI, LP, docs, emails, error messages, OGP, README — the identity failure mode being brand-specific: a partial rebrand is brand damage (a stale logo or the old voice surviving in an overlooked surface is worse than no rebrand). INVENTORY freezes the baseline denominator; per-surface batches loop under Echo+Palette brand-rubric + Radar no-regression checks; the RESIDUE-GATE (grep + visual scan for old tokens/old voice, independent re-scan 2× zero) closes the outer loop; DECOMMISSION of old assets is gated on the ATTEST proof. The old→new brand mapping table is the parity oracle per _common/DIFFERENTIAL_PARITY.md. Named Consistency Attestation (surface × rubric matrix + zero-residue proof); checkpoint-resume (rebrand resume). Distinct from migrate (technical change-completeness — brand-case routes here), restyle (single-surface improvement, no completeness guarantee), hallmark (creates the identity — no settled Brand Book yet → hallmark first), muse direct (one token change), growth-acceptance (post-ship verification — downstream). 8-20 agents, 3-6× cost. Ask First on big-bang / 10+ files (intentional parity with migrate).

Read: reference/rebrand-recipe.md, reference/migrate-recipe.md, _common/DIFFERENTIAL_PARITY.md.


marquee (= wish domain=lp)

Wish-grade one-shot landing-page production — crystallization dialogue → GROUND (competitor teardown doubling as the exemplar/control anchor set) → 3-direction cross-engine blind tournament → calibrated adversarial gauntlet + ceiling convergence with machine oracles (Lighthouse / CWV / WCAG) → cold reception pass → One-Shot + Comparative exit gates; ACCEPT = all rubric dims = 3. The LP specialization of wish: it keeps wish's quality machinery but carries no Scarcity Gate — an intentional difference (LP production is a legitimately repeatable demand per product); the objectivity anchor is instead a fixed 5-dim Ceiling Rubric whose Performance dim is machine-checkable (Lighthouse Perf/SEO/Best-Practices ≥ 95, all CWV green, WCAG AA) — one corner of the ceiling is not a judgment call. The other dims: Message (every Echo persona articulates the value from the hero alone), Craft (multi-engine judge + Vision bar), Conversion (Growth audit yields zero improvement proposals), Trust (Evidence Ledger-backed claims + Canon[legal]? legal alignment). LP-specific refutation angles per _common/ADVERSARIAL_REFUTATION.md: bounce-reason enumeration + "does it still hold with a competitor's logo swapped in?". Production runs on funnel premium's craft axes; the ship records an A/B handoff to growth-acceptance. Named Marquee Dossier; checkpoint-resume (marquee resume). Distinct from wish (deliverable-agnostic + Scarcity Gate), funnel premium skill (standard-to-premium single-direction LP studio — routine LP → funnel premium direct), funnel skill (one LP/section direct), runway (in-product flagship surface, not an acquisition device), podium (docs/slides), kaizen/restyle (improve an existing LP). Bare landing page is overloaded → REDIRECT (routine build → funnel premium/funnel). 26-55 agents × ≤4 cycles (3 + ≤1 exit-gate bonus), 10-24× cost. Always confirm + Phase 1 Crystallize is contract-level dialogue.

Read: reference/marquee-recipe.md, reference/wish-recipe.md, reference/research-grounding.md, reference/evaluator-loop-protocol.md.


crucible

Operability proof under adversarial conditions — the floor member of the Quality-Max design wing, and the only design recipe whose oracle is binary rather than scored: every cell of a (critical task × condition) matrix is PASS (the task completed) or FAIL, because a rubric score can average away a condition in which the product is unusable and a completion ledger cannot. Four identity elements no sibling carries together: a declared denominator (the Critical Task Set + Condition Set are ratified before the run, and the pairwise-reduced matrix records its dropped cells — coverage chosen after seeing results is not coverage), adversarial conditions rather than personas (runway/restyle ask how a surface feels; crucible asks whether the task finishes under a degraded environment), content reality as a first-class axis (empty state · 10k-row overflow · missing asset · maximum-length label · RTL · longest localized string, driven by generated radar fixtures), and an independent full-matrix re-run at the gate — not just the remediated cells, because a remediation that trades one condition for another has moved the hole, not the floor. A task that fails under ideal conditions exits at Phase 2 to bug by contract. Named Operability Proof; every open cell is named with wont-fix/needs-redesign/needs-platform-support and an owner — a pass rate without its failing-cell list is forbidden by §2 and §7. Checkpoint-resume (crucible resume). _common/ADVERSARIAL_REFUTATION.md is deliberately N/A: the oracle is binary and reproducible, so the fresh-executor re-run is the refutation. 16-34 agents × ≤3 cycles, 5-11× cost. Always confirm (intentional parity with runway/summit). Distinct from runway (ceiling), restyle (standard bar), canon skill (standards conformance is one axis here), siege skill (the system, not the interface), palette/voyager direct (one fix / suite authoring).

Read: reference/crucible-recipe.md, _common/PROPORTION_AND_SPACING.md, reference/evaluator-loop-protocol.md.


silhouette

Distinction proof for a product surface — strips branding and measures via a pre-committed Sameness Ledger + inverted-polarity sweep + a Blind Recognition Test (attribution vs K≥3 competitors against a pre-declared, immutable chance threshold) whether the surface is still recognizably ours — under a hard constraint that distinctiveness must be free (a11y ≥ baseline ∧ friction ≤ baseline). BLOCK (convention-locked) is a legitimate exit, handed off to hallmark/prose/flow/eureka. Named Distinction Dossier; checkpoint-resume (silhouette resume). Distinct from hallmark (creates the identity), runway (craft ceiling — Phase 2 can run inside it), restyle (standard bar), compete skill (research only), eureka (same pre-commit discipline, mechanism novelty), crucible (operability). 14-30 agents × ≤3 cycles, 5-9× cost. Always confirm.

Read: reference/silhouette-recipe.md, reference/research-grounding.md, _common/ADVERSARIAL_REFUTATION.md.


lattice

Design-system coherence proof (steady state) — proves the completeness of system conformance with no identity change: inherits migrate's freeze-denominator/prove-residue/delete-after-proof discipline and adds a three-way deviation classification (residue/gap/justified, model-judged) + appearance parity as the safety oracle (a conformance fix that changes what renders is reverted and re-classified as a gap). Precondition: a system of record must exist — none → muse/vitrine first. Closes with a Drift Sentinel hone CI handoff. Named Coherence Proof; checkpoint-resume (lattice resume). Distinct from rebrand (identity migration), muse/vitrine direct, restyle/runway (how it looks), anneal (code design), sweep (dead code), migrate (technical change), chorus (between platforms). 10-22 agents, 3-7× cost. Ask First on big-bang / 10+ files.

Read: reference/lattice-recipe.md, reference/migrate-recipe.md, reference/rebrand-recipe.md, _common/DIFFERENTIAL_PARITY.md.


chorus

Cross-platform coherence proof — proves each platform build is idiomatic to its own platform and recognizably the same product, simultaneously, via a ratified Invariant/Variant Contract and a two-sided gate over one oracle: the Idiom Gate (per-platform conformance vs published HIG/Material systems, cited) and the Kinship Gate (blind same-product attribution + first-try learned transfer A↔B). A fix raising one gate while lowering the other is rejected and escalated to the contract. Reported per platform, never aggregated. Named Chorus Attestation; checkpoint-resume (chorus resume). Precondition: ≥2 platforms with a shared surface. Distinct from port skill (plan→prove pair), native/MOBILE_NATIVE (one platform), lattice (within one platform's system), rebrand, crucible, runway. 14-30 agents × ≤3 cycles, 5-10× cost. Always confirm.

Read: reference/chorus-recipe.md, _common/PROPORTION_AND_SPACING.md, _common/PARALLEL.md.


assay

Experimental proof of design claims (code / architecture) — answers "is this a good design?" by running the experiment instead of trusting proxies: harvests load-bearing claims (ADRs, docs, conventions, what the code implicitly claims, the roadmap) into a Design Claim Ledger, resolves each via one of four instruments assigned mechanically (ADD/SUBTRACT/REWRITE/ASSERT), gated by an Adequacy Gate (the suite is every instrument's sensor — no coverage on an element means untested, not unnecessary). Oracle = zero UNPROVEN load-bearing claims; REFUTED counts as resolved (refuted-is-a-success). apply=true is opt-in, applying only experiment-proven-safe changes. Named Design Proof; checkpoint-resume (assay resume). Distinct from anneal (discover+fix — measure→fix pair), refactor, acceptance/summit, ripple, void/trim (judged vs experimented), siege/radar (assay's sensors), attest/pdm, lattice (same ASSERT shape). 24-55 agents, 8-16× cost. Always confirm with a budget envelope.

Read: reference/assay-recipe.md, _common/DIFFERENTIAL_PARITY.md, reference/anneal-recipe.md, _common/ADVERSARIAL_REFUTATION.md.


converge

Quality-convergence loop — the invocable entry point for the Generator-Evaluator pattern (reference/evaluator-loop-protocol.md). A Generator produces/revises; independent Evaluators score against a Rubric tied to a Sprint Contract; the loop runs until ACCEPT or a hard bound. Execution-control, not a task shape (exposed as a subcommand because it carries a Contract/Rubric/bounds args the Mode table can't). Two forms: converge (standalone) and converge <recipe> (inner recipe as Generator). Mandatory termination bounds: max_cycles (3) / token_budget / diminishing-returns ε / BLOCK escalation — no unbounded run. Flatten rule: wrapping a loop-recipe (kaizen/apex/summit) uses its generator agents, not its loop, so converge owns the single termination oracle (avoids loop-on-loop blowup + dueling oracles). 4-10 agents × ≤3 cycles. Distinct from kaizen (metric-PDCA on existing features) and goal (unattended setup).

Read: reference/converge-recipe.md, reference/evaluator-loop-protocol.md.


quell

Review-to-zero fix loop — fix code, re-run an external review engine over the same frozen scope, repeat until the reviewer returns zero open findings at or above a severity floor (floor=medium default). The Loop-family member whose oracle is a finding count, not a rubric score: the reviewer is a separate engine (codex review via Judge, engines=codex|codex+claude|tri), so maker ≠ checker is structural. Three mechanisms make "until zero" reachable and honest rather than an infinite loop: a Finding Ledger keyed by a line-number-free fingerprint (so a shifted finding is not counted as new) where every finding carries exactly one disposition (OPEN / FIXED-VERIFIED / FALSE-POSITIVE-RATIFIED / WONTFIX-RATIFIED / DEFERRED / BELOW-FLOOR / FROZEN); disposition integrity (the cycle-N fixer may never dismiss its own findings, dismissal uses refute polarity per _common/ADVERSARIAL_REFUTATION.md, WONTFIX on CRITICAL/HIGH is Ask First, FIXED-VERIFIED requires absence from a fresh review); and oscillation detection (a fingerprint re-emerging after being fixed twice → FROZEN + BLOCK). A mandatory per-cycle Green Gate (tests/build/typecheck) prevents "zero findings on broken code". Profiles specialize the green gate, the fixer roster, and the out-of-bounds rule — never the termination contract: profile=refactor (alias quell refactor) swaps in an Equivalence Gate (the same suite passes identically), freezes test files (a test edit is a TEST-EDITED blocker the fixer may not ratify — the refactor-loop analog of self-dismissal), makes behavior-changing fixes DEFERRED with a route to bug/feature/security (Builder and Sentinel are off the roster; Zen leads), treats behavior-drift findings as blocking at any severity, and requires the SAFETY-NET behavior pin as a launch precondition (un-pinnable scope → BLOCK). That discipline is cited from routing-matrix.md § REFACTOR Phase Contract + _common/DIFFERENTIAL_PARITY.md, not re-derived. Runs uninterrupted — announce-and-proceed after one launch-time blast-radius acknowledgement at BASELINE — but is bounded externally: loop ≤ N cycles (default N=6) + token budget + a diminishing-returns stop on net open count. Named Quell Ledger; checkpoint-resume (quell resume). Distinct from converge (rubric bar), acceptance (merge decision with proof obligations — the natural next step: quell → acceptance), judge direct (one review, no fixing), judge pair (conversational per-finding), anneal (self-generated design slate), bug (single defect RCA), and the orbit skill (unattended, survives session end). 4-11 agents per cycle × ≤6 cycles, medium-to-high cost.

Read: reference/quell-recipe.md, judge/reference/codex-review-usage.md.


burnish

Design review-to-zero loop — quell's machinery with the object swapped from a code diff to a rendered UI surface: capture the frozen surface × breakpoint × state matrix, run an external multimodal review engine (codex / agy via Judge) over it, fix, re-capture, re-review. The swap forces exactly one structural change — a split oracle, because design findings do not all reduce to a defect count. HARD findings (WCAG/contrast/touch target/focus order/overflow/missing empty-loading-error state/token residue/perf budget) are machine-checkable and go to zero at or above floor; SOFT axes (hierarchy, rhythm, typographic scale, motion, density, brand fit) are judgment and go to ≥ 2 on evaluator-loop-protocol.md's 0-3 scale. Reaching for literal zero on the soft half is the failure mode the recipe exists to prevent. Three further mechanisms keep it convergent and honest: a Finding Charter frozen at BASELINE (hard classes + soft axes + the matrix), so a finding invented after seeing the surface is OUT-OF-CHARTER and non-blocking rather than a new fix cycle; a grounding requirement (locus + expected/observed, else NEEDS-INFO and still OPEN — "feels cluttered" is not a finding); and a fingerprint that excludes pixel coordinates, screenshot hashes, and DOM indices (the transposition of quell's line-number exclusion — otherwise a 1px change reports every finding as new). The per-cycle Appearance Gate replaces quell's Green Gate: render · a11y non-regression vs baseline · behavior non-regression · SPILL (a visual diff on a surface outside the frozen set blocks at any severity). Identity is out of bounds in both profiles — IA, copy meaning, and brand-token changes are always DEFERRED (identity-changing) with a route, and Vision sits on no roster, because a polish loop that can re-direct the design is bounded by nothing. profile=faithful adds reference conformance against a declared source of truth (Figma frame / design system) with REFERENCE-DRIFT blocking at any severity; no reference of record ⇒ BLOCK, never a silent fall-back. Bounded externally: loop ≤ N cycles (default N=4) + token budget + a diminishing-returns stop that requires both halves of the oracle to stall. Named Burnish Ledger; checkpoint-resume (burnish resume). Distinct from restyle (sets the direction and scores it with internal evaluators — restyle → burnish is the pair), quell (code diff), crucible (task completion under degraded conditions), silhouette (blind attribution), lattice (system conformance with a frozen denominator), runway (craft ceiling by tournament), and the orbit skill (unattended). 5-13 agents per cycle × ≤4 cycles (+4 at BASELINE), medium-to-high cost.

Read: reference/burnish-recipe.md, reference/quell-recipe.md.


whet

Mutation-survivor loop — run a mutation engine over the frozen scope, kill the survivors, re-run, repeat until every declared partition meets its bar. The Loop-family member whose oracle is a deterministic tool's finding set: Siege runs and classifies, Radar writes tests, so maker ≠ checker is structural without needing a second engine. It exists because the loop had no owner — siege's MUTATE runs mutations and recommends, radar authors, nobody drives the set to a threshold. C4 holds (the mutant set is finite and each mutant has a right answer), so there is no split oracle; instead the floor is a threshold contract — a frozen partition set where must-kill-all partitions allow zero survivors and every other partition needs corrected score ≥ its bar, because chasing 100% is siege's MA-02 Score Obsession. The domain's distinguishing problem is that two of its three cheats improve the number arithmetically: corrected score is Killed / (Total − Equivalent), so declaring a survivor EQUIVALENT raises the score with no test written — hence EQUIVALENT-RATIFIED requires a failed attempt to construct a distinguishing test plus a cited equivalence pattern, may never be ratified by the test author, and the equivalence rate is reported per cycle so a score that moved by shrinking the denominator is visible; and a survivor can always be killed by asserting on the mutated expression itself, which raises TAUTOLOGICAL-KILL (blocking at any severity — the TEST-EDITED analogue). Deleting the host code is legitimate per MA-07 but closes as CLOSED-BY-REMOVAL with Void/Sweep dead-code evidence and never counts as a kill. The per-cycle Suite-Integrity Gate (green on unmutated code · no flake · within the tier= runtime budget · coverage non-regression) prevents a mutation run on a suite that cannot host one; un-stabilizable flake at BASELINE is BLOCK. Bounded by loop ≤ N cycles (default N=3) + budget + diminishing-returns. Named Whet Ledger; checkpoint-resume (whet resume). Distinct from siege skill (one measurement, no loop), radar (coverage, and flaky repair — whet BLOCKs on flake), quell/burnish (reviewer oracle on a diff / a surface), and the orbit skill (unattended). 4-8 agents per cycle × ≤3 cycles (+2 at BASELINE); the governor is engine runtime, not agent count.

Read: reference/whet-recipe.md, siege/reference/mutation-testing-advanced.md.


migrate

Change-completeness migration — propagate a wholesale change across the codebase with a proven-complete guarantee (no omission). Cases: arch (layered→hexagonal, monolith→modular), framework (Express→Fastify, Vue2→Vue3), middleware (REST→gRPC, RabbitMQ→Kafka, store swap), mock-to-prod (stub/in-memory→real service). case=lang forwards to transmute. Double-loop: per-batch PLAN→EXECUTE→VERIFY inside an outer completeness loop closed by a RESIDUE-GATE (forward counter + independent loop-until-dry re-scan + matrix axis-coverage), then a DECOMMISSION phase that removes old code gated on the completeness proof. Strategy: strangler-fig (default) ‖ parallel-run ‖ big-bang. 6-20 agents. Confirm whole-system arch / big-bang.

Read: reference/migrate-recipe.md.


clone

Faithful product reproduction — reverse-engineers an existing product's observable surface and rebuilds it as a complete copy, verified by differential parity against a captured baseline across six dimensions (visual · behavioral · feature · data/API · asset · performance). Platform-agnostic (target_type ∈ live-web/desktop/mobile/has-source/api). Four integrity gates: Rights (Ask First), Capture Completeness, Provenance & Drift, Differential Parity engine. Opens with a contract-level Stack Dialogue (AUTORUN cannot skip) locking the rebuild stack. Emits a Clone Handoff Packet. Distinct from transmute (own-source rewrite), migrate (own-system completeness), PORTING (web→native), pixel (single mockup), feature (net-new). 9-27 agents. Ask First at the Rights Gate; confirm before big-bang full clone.

Read: reference/clone-recipe.md.


fuse

Multi-source product synthesis — the synthesis extension of clone. Where clone reproduces one product faithfully against a single baseline, fuse captures two or more products (clone's full capture/provenance/parity machinery, run per source) and synthesizes them into one new product: adopting selected elements from each source, merging overlapping ones, and adding net-new connective tissue. The deliverable is intentionally not a faithful copy of any single source, so clone's single-baseline oracle no longer applies — fuse adds the three things clone cannot express: a Fusion Map (assigns every element of the new product a provenance {adopt-A|adopt-B|merge|net-new|drop} + resolution rationale + oracle), a dual/selective oracle (adopted elements → differential parity vs that source's baseline; merged/net-new → spec+AC conformance — never confused), and a Coherence Gate (proves the result is one product — one visual language / interaction grammar / terminology / data model — not a Frankenstein patchwork). Conflicts between sources (two nav models, two schemas for "the same" entity) are resolved in a Conflict Ledger (Magi-arbitrated against the Fusion Thesis). Multi-source IP/trade-dress posture is recorded per adopted element. sources=2..N, mixed target_type allowed. Distinct from clone (one source, fidelity is the goal), feature/apex (net-new, only inspired — no captured baselines), migrate (own-system consolidation), transmute (own-source rewrite). Pair spec → fuse when which elements to take from each source is itself unsettled. 12-32 agents, high cost. Confirm before big-bang full fusion OR sources ≥ 3.

Read: reference/fuse-recipe.md.


graft

Concept transplant for innovation — the extension of fuse and the inverse of clone on the fidelity axis. Where clone/fuse reproduce observable surfaces by parity, graft takes your current owned product as the host (white-box, mapped from source — not captured) and extracts a specific reference product's (the donor) important concepts — its load-bearing principles/mechanisms, abstracted away from the donor's surface — then transplants and adapts them onto the host to produce a genuinely innovative product. It explicitly rejects surface copying (the opposite of clone): a graft that copies the donor's chrome while missing the idea that made it work has failed. Verified by a triple oracle held on every graft: concept-fidelity (the donor concept's mechanism/effect reproduced, re-expressed originally in the host's surface — Attest+judge, high donor-resemblance is a smell) ∧ host-integrity (the living product's existing-behavior regression net stays 100% green + declared invariants hold — Radar+Ripple) ∧ Innovation Gate (emergent novelty neither host nor donor had, surviving adversarial "this is just a bolt-on/gimmick" refutation + felt-novelty via Echo + defensibility via Compete — borrowing killer's moat/refutation discipline). A graft that is concept-faithful and host-safe but fails the Innovation Gate is delivered honestly as "a feature, not an innovation." Core artifact: Graft Map (per donor concept → adapt|hybridize|invert|reject + host attachment point + adaptation + per-graft innovation thesis + invariants respected); plus a Host-Invariant Contract (value-path/workflow/data/contract non-negotiables) and a per-graft originality posture (default: re-implement the idea originally — concept-level transplant is structurally lower IP-risk than surface reproduction). Flux is core (concept distillation + hybridize/invert novelty moves), not optional. Ships behind a feature flag with adoption KPI + kill criterion (killer-style) unless waived at Phase 0. host=1, donors=1..N. Distinct from fuse (peer external sources, surface synthesis, no owned host), clone (surface reproduction), kaizen (metric PDCA, no external concept/novelty bar), feature (additive, no concept extraction/innovation gate), killer (verdict only — pair killer → graft). 10-28 agents. Confirm when invasive to host core OR shipping without a flag.

Read: reference/graft-recipe.md.


eureka

Novelty-proven invention — the only recipe whose oracle is absence: extracts a named domain contradiction, sweeps prior art with inverted polarity (research to avoid) into a Prior-Art Ledger + failure archaeology, diverges six cross-engine generators, and gates candidates through the Novelty Gate (COLLISION/OBVIOUS killed with citation) → Tetrad Gate (novelty·value·feasibility·defensibility) → Sacrifice Ledger (the trade-off must be gone, not relocated — DISPLACED-HIDDEN kills, DISPLACED-DECLARED passes) → falsification-first Reduction to Practice. Rights/licensing are out of scope (→ canon[legal]). Salvage Routing is contract-level: every kill/non-ACCEPT exit carries route:<recipe> (e.g. COLLISION→graft/feature, OBVIOUS→kaizen/optimize) rather than a silent discard. depth=scout prices the novelty-only question separately (Phases 1→1.5→2′→3, mutually exclusive with ship=true); ship=true continues to spec→apex under a Novelty Invariant + a final non-builder regression check. Named Invention Dossier; checkpoint-resume. Distinct from graft (transplants a proven mechanism — one of eureka's six generators, not the whole recipe), fuse, killer (picks from candidates in hand, no novelty proof), spark, gedanken (no falsifiable artifact), wish (known deliverable). 32-62 agents × ≤3 cycles (+1 re-ideation), 9-24× cost; +ship=true 43-92 agents, 13-33× cost. Always confirm; Ask First on any spike touching real systems.

Read: reference/eureka-recipe.md, reference/research-grounding.md.


package (includes legacy venture as domain=startup)

Generalized document-package generator — 12-domain preset registry: startup (the legacy venture blueprint) / generic / research / ai-adoption / legal* / saas / media / growth / career / learning / hiring* / local-gov*. Per-domain swap: directories, role→skill map, traceability anchor (F-/H-/UC-/R-/P-/E-/T-/LO-/I-), risk gates (*=mandatory). Single Phase 0-6 engine. Depth 5-28 agents (startup tiers: lite 6-8, mvp(default) 14-18, raise 16-20, full 24-28). Confirm full depth.

Read: reference/package-recipe.md. Startup-preset deep blueprint: reference/venture-recipe.md.

Source: SKILL.md on GitHub

3 warnings13d5 checks · Risk MEDIUM
  • Gen Agent Trust Hub13d

    The 'nexus' skill is a comprehensive multi-agent orchestration framework that manages complex task chains. While it incorporates extensive internal guardrails and verification protocols, it explicitly mandates the use of high-risk flags that bypass security permissions to achieve autonomy. It also provides instructions for establishing persistent tasks via cron and GitHub Actions, and utilizes external research tools to fetch content from the web.

  • Socket13d

    1 alert: gptSecurity

  • Snyk13d

    Risk: LOW · No issues

  • Runlayer6mo

    6/22 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at c805268. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for simota/agent-skills/nexus