Skip to content
Back to skills

Flow Delegate

ASecurity

Delegate a bounded repository task to an allowlisted external coding CLI through the guarded Flow runner. Use for automatic provider selection or explicit Codex, OpenCode, Kimi, Gemini, or Kiro delegation that requires timeout handling and independent local review.

  • 3 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 9, 2026
ai-agentsbashgit

Works with

  • cli

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 9, 2026

npx -y skills add pwdev-solucoes/pwdev-claude-marketplace --skill flow-delegate --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Flow Delegate?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Flow Delegate
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/pwdev-solucoes-flow-delegate/badge)](https://www.skillsdirectory.com/skills/pwdev-solucoes-flow-delegate)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: flow-delegate
description: Delegate a bounded repository task to an allowlisted external coding CLI through the guarded Flow runner. Use for automatic provider selection or explicit Codex, OpenCode, Kimi, Gemini, or Kiro delegation that requires timeout handling and independent local review.
---

# Delegate Through Flow

Read [delegation](../../references/delegation.md), [safety](../../references/safety.md), and [collaboration](../../references/collaboration.md) before acting.

## Select

Accept `auto` or one explicit provider: `codex`, `opencode`, `kimi`, `gemini`, or `kiro`. For `auto`, select from the provider matrix in [delegation](../../references/delegation.md), announce the provider, mode, and reason, and use `read` only for analysis-only work.

Standalone delegation inherits no fleet authorization, so never add either fleet bypass vector: `--dangerously-bypass-approvals-and-sandbox` (Codex) or `--dangerously-skip-permissions` (Claude). An acknowledgement given for a fleet launch never covers a delegated run.

## Run

1. Inspect repository status, resolve `../../scripts/run-agent.sh` from this installed skill, check the selected binary, and determine its configured `timeout_s` without reading secret files.
2. Run the packaged preview and display both its exact expanded provider vector and confirmation token:

   ```text
   bash <packaged-run-agent.sh> --preview <provider> <read|write> <task>
   ```

3. Require explicit confirmation of that exact expanded vector. Treat the displayed token as bound to its provider, repository, mode, typed model, arguments, standardized prompt, and task; do not reuse it after any change.
4. Execute the identical packaged runner invocation without `--preview`, setting `FLOW_DELEGATION_CONFIRM_TOKEN` to the confirmed token. Execute only the packaged runner. Set the host execution timeout to at least `timeout_s + 60` seconds so the runner can report its own timeout first.
5. Report the runner exit code and captured output path. Do not treat a delegated summary as proof of completion.

## Review Independently

After every run, including failures, inspect Git status and the full unstaged and staged diff, inspect relevant untracked files, reconcile scope against the task, and run the relevant tests in the primary session. Return an independent `APPROVED`, `CAVEATS`, or `REJECTED` verdict with evidence and concerns.

Files in this skill

  • SKILL.md2.3 KB
  • agents/openai.yaml193 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…