Skip to content
Back to skills

Reflect

ASecurity

Review conversation lessons and propose scoped Skill improvements.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 1, 2026
ai-agents

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 6, 2026

npx -y skills add williamwue/oh-my-stack --skill reflect --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Reflect?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Reflect
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/williamwue-reflect-oh-my-stack/badge)](https://www.skillsdirectory.com/skills/williamwue-reflect-oh-my-stack)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: reflect
description: "Review conversation lessons and propose scoped Skill improvements."
---

# Reflect

## Codex delegation binding

For every delegated worker in this workflow, derive the exact `model`,
`reasoning_effort`, and complete role-plus-task `message` with
`../../scripts/codex-delegation.mjs prepare` relative to this Skill. It resolves
the nearest project manifest first, then the user manifest. Supply the named
route/panel entry where configured; otherwise supply the canonical role
and the observed parent model and effort. Pass
the returned `task_name`, `fork_turns=none`, model, effort, and message
explicitly to the spawn call. Do not use a generated custom-role name as a selector or
claim its TOML was activated. After the worker finishes, run the helper's
`verify` mode on the persisted parent and child records when available; it
checks the spawn metadata, parent link, and child `turn_context`.
The persisted spawn message may be encrypted; disclose when its exact
role/task text cannot be audited. If records are unavailable, state that
runtime model resolution is unverified.

## Child session handoff

Read [the handoff contract](../poteto-mode/references/subagent-handoff.md).
New tasks, repair rounds, retries, and queue items use fresh child sessions
with the original brief, every later directive, prior findings and responses,
and unresolved objections. Reuse only for required costly live state, and
only when the host allows it. Stop and fence active writers before replacement.
A host-owned orchestrator's model catalog, workspace binding, child tools,
and review-round rules take precedence over the native binding above.
Keep its task handles and attribution receipts. Do not use a backing child
conversation as a new delegated review, or claim native-record verification
for a host-owned child. Report attribution evidence gaps explicitly.

Use only when the user asks to reflect on an actual conversation or work run.
Trivial exchanges and one-off preferences do not justify durable Skill edits.
Identify the active task transcript through the runtime's task history or the
workspace-scoped transcript path. Do not search unrelated projects or private
history. When no full transcript is accessible, create a bounded digest from
visible context and disclose the loss of tool evidence.

Run three independent read-only reviews when delegation is available: judgment
(wrong decisions and missed evidence), tooling (friction and repeatable checks),
and divergent alternatives. Give each the same frozen task record and require
precise citations, counterexamples, and proposed destination. When available,
use `reflect.tooling`, `reflect.judgment`, and `reflect.divergent` for
the respective lenses; keep all three sessions independent. Use
`reflect.synthesizer` for the later synthesis pass. Use configured routes,
not assumed model identities. With fewer workers, preserve separate
lenses and label reduced independence.

Synthesize Accepted, Rejected, and Backlog findings. Root rechecks each accepted
claim against the transcript and target Skill. Move a finding to Backlog when
a type, schema, lint rule, test, or runtime check enforces it more reliably than
prose. Reject duplicated guidance, subjective one-offs, and changes outside the
user's workspace or intended scope.

Show the proposed edit set with exact paths and the evidence before altering
shared or personal Skills. Apply only changes the user requested or approved;
otherwise return a reviewable proposal. For approved changes, use
[authoring-a-skill](../authoring-a-skill/SKILL.md), validate references and
frontmatter, and test behavioral changes when warranted. Do not assume a team
tracker exists or file external backlog items without authorization. Return
applied edits, proposed edits, rejected findings, and open structural work.

Files in this skill

  • SKILL.md3 KB
  • agents/openai.yaml226 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…