majiayu000/flowguard
Guard long, ambiguous, or stateful AI-agent work from drift. Use when the user asks to run or continue a multi-step task, autonomous loop, bug fix, repo change, PR readiness check, compaction handoff, resume from previous context, cost-control checkpoint, or any task likely to span many tool calls, files, sessions, agents, or verification gates.
npx skills add https://github.com/majiayu000/spellbook --skill flowguard
Use this skill as the single lifecycle entrypoint for agent work that can drift, lose context, or become expensive. It routes the task, verifies current state, runs bounded execution loops, and leaves a resumable handoff.
This skill coordinates other skills; it does not replace them. Use task-specific skills such as systematic-debugging, comprehensive-testing, codex-retrospective, or vibeguard only when their trigger is clearly met.
review-gate or produce the same review pack and wait for explicit human approval.Choose one route before editing files or running a long loop:
| Route | Use When | Action |
|---|---|---|
| execute_direct | Goal, context, constraints, and done-when are clear; scope is small or verification is cheap. | Work directly with short checkpoints. |
| plan_first | Work spans many files, sessions, agents, architecture decisions, migrations, or risky sequencing. | Create a brief execution plan or use the relevant planning skill before edits. |
| clarify_first | Goal, target files, constraints, done-when, destructive permission, production impact, or ownership is unclear. | Ask the smallest blocking question before continuing. |
Do not hide ambiguity inside assumptions. If a wrong assumption would cause large rewrites, production risk, data loss, credential exposure, or wasted long-loop cost, use clarify_first.
AGENTS.md for files that may be edited.# From the installed flowguard skill directory, the directory containing this SKILL.md:
scripts/workflow_state_snapshot.sh /path/to/target/repo
When already in the target repo, pass . as the target to the installed script, for example /path/to/installed/flowguard/scripts/workflow_state_snapshot.sh ..
Before substantial work, write or state the compact preflight:
route:
goal:
context:
constraints:
done_when:
out_of_scope:
verification_commands:
stop_conditions:
handoff_location:
objective_restatement:
plan_5_steps_or_less:
For short direct tasks, this can be one concise paragraph. For long tasks, make it explicit and keep it available for compaction or resume.
Use a step-test-update loop:
Stop and re-evaluate when any condition occurs:
execute_direct, but new evidence shows missing goal, constraints, or done-when. Stop and re-route.Do not claim completion from expectation or older output. Report fresh evidence from this session.
Pick checks from the repo, AGENTS.md, and changed surface. Common defaults:
| Stack | Before Completion | Before Submission |
|---|---|---|
| Rust | cargo check | cargo test |
| TypeScript | npx tsc --noEmit | project test command |
| Go | go build ./... | go test ./... |
| Python | focused import/type/lint check if present | pytest |
If a check cannot run, say why and name the nearest useful fallback that did run.
Before landing agent-generated changes, produce a concise review pack or use the
review-gate skill. The pack must include intent, diff summary, changed files,
risks, verification, open questions, and the exact action needing approval.
Human approval for one action does not automatically authorize a different
action such as merge.
Read references/state-contract.md when asked to create a handoff, resume after compaction, continue a previous task, or prepare automation.
Required handoff fields:
Resume must start by comparing the handoff with current local truth. If cwd, branch, files, tests, or user priority changed, update the plan before editing.
Use parallel agents only when file ownership is disjoint and merge ownership is explicit. A delegation must name:
If two agents need to write the same file, do not run them in parallel.
Skill workflows are manual first. Automate only after the workflow has been manually validated on real tasks. Scheduled automation should start as read-only: state scans, handoff drafts, stale-worktree reports, or verification summaries. Code edits, deploys, credential changes, or PR submissions require explicit user intent unless a separate trusted automation contract exists.
scripts/workflow_state_snapshot.sh <path>: read-only snapshot for cwd, git state, nearby agent instructions, dirty files, and likely verification commands.references/state-contract.md: templates for preflight, checkpoints, handoff, resume, loop guards, and automation readiness.review-gate: review pack and explicit human approval before landing agent-generated diffs.Take majiayu000/flowguard from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.
The instructions reference npx.
Without those the skill loads but fails at the first command.