Skip to content
Back to skills

Decision Evaluate

ASecurity

Evaluate a pinned normalized decision ruleset through an explicitly configured Jev or LLM-subagent binding

  • 211 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 22, 2026
ai-agentsrustnodebackend

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 27, 2026

npx -y skills add jmagly/aiwg --skill decision-evaluate --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Decision Evaluate?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Decision Evaluate
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jmagly-decision-evaluate/badge)](https://www.skillsdirectory.com/skills/jmagly-decision-evaluate)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
namespace: aiwg
name: decision-evaluate
platforms: [all]
description: Evaluate a pinned normalized decision ruleset through an explicitly configured Jev or LLM-subagent binding
requires:
  - feature-enabled: AIWG_DECISION_ENABLED=1
  - request: dispatcher request JSON with authored artifact paths and runtime adapter configuration
ensures:
  - normalized-result: returns a decision.aiwg.io/v1alpha1 RulesetResult
  - backend-boundary: definitions and rulesets contain no vendor request payloads or credentials
script:
  entrypoint: scripts/decision-evaluate.mjs
  runtime: node
  cwd: project-root
  argsHint: "--request <dispatcher-request.json>"
---

# Decision Evaluate

Evaluate one pinned `DecisionRuleset` with one `DecisionBinding`. The dispatcher
validates pins, input, capabilities, typed outputs, retry/fallback budgets, and
composition before returning an outcome as data. It never authorizes or
executes the outcome.

The request document is runtime configuration, not a portable decision
artifact. It names `rulesetPath`, `bindingPath`, `definitionPaths`, `inputPath`,
`runId`, `invocationId`, optional `receiptDirectory` (which requires
`receiptIntegrityKeyRef`; see `docs/operations.md`), `credentials` mappings
from logical reference to environment-variable name, and optional
`adapterModules` for configured worker transports. Credential values are read
only at adapter call time and never written to results.

Network-capable adapters (including the packaged Jev adapter) require
`projectionPolicyPath`: a trusted projection policy file, or an array of
policies selected by exact adapter and model. Without it the dispatcher refuses
before any credential or transport use and exits `2`. Only adapters that declare
`egress: { mode: 'none' }` (for example the offline fixture worker) run without a
policy. `adapterOptions.jev` sets the Jev `endpoint`, `allowedOrigins` and the
operator-declared deployment `region`; the policy origin and region must match
them. There is no dispatcher setting that sends unprojected state to a network
adapter. See `agentic/code/addons/decision-engine/examples/dispatcher-request-jev.json`.

Set `AIWG_DECISION_ENABLED=1` explicitly. Existing workflows remain unchanged
when the flag is absent.

The deployed script loads the compiled runtime from the installed `aiwg`
package through `scripts/runtime-root.mjs`: `AIWG_ROOT` when it names a built
package, then a project `node_modules/aiwg`, then the `aiwg` executable on
`PATH`.

Files in this skill

  • SKILL.md1.4 KB
  • scripts/decision-convert-definition.mjs969 B
  • scripts/decision-evaluate.mjs2.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…