Dispatch independent tasks to parallel workers or subagents without write collisions. Use when: running or planning agents in parallel, even two; check scopes before any launch.
日本語の概要は準備中です。原文の説明を表示しています。
Freshly judge whether a finished change and its claims meet original acceptance: PASS, FAIL or NOT_PROVEN. Use when: asked for a go/no-go, sign-off or independent verdict.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Freshly judge one finished candidate against its original acceptance, return
PASS, FAIL, or NOT_PROVEN with criterion-level evidence, and stop.
Neighbours: advice or a second look is Review; whether a
stated claim holds is Reality Check. This file
carries every rule the judgment needs. Linked files, including
RPI boundaries and
mechanics, add depth only: if one cannot be read,
judge from this file and say which was unavailable.
not_checked and never counts toward PASS.Decide in this order:
not_checked is empty: PASS.An explicit request for Validate, an acceptance verdict or independent proof
that original acceptance is met selects this skill, even when phrased as
"review this". Generic checking or readiness questions, even with criteria
supplied, do not: ask once whether the caller wants advice or an acceptance
judgment, and wait. Issue no verdict or readiness approval meanwhile; missing
intent is not a NOT_PROVEN verdict. Shared routing:
advice or acceptance.
Spend validation where a mistake is costly. For an ordinary change the author's checks and CI are the gate, and no fresh judgment is owed. Use Validate when:
Judge once. Report NOT_PROVEN with its gaps and stop; do not request or wait for another round. After the author repairs findings, the affected checks confirm the repair; a second judgment happens only when the caller asks for one. Keep the judgment's cost a fraction of the cost of the work: when it approaches that cost, stop and return what is unchecked.
The subject is a nonempty implementation candidate, held unchanged after required checks and known repairs; plans, audits and reviews are subjects only when the caller requested document review. Supplied failed-acceptance evidence means FAIL on that subject; do not review a moving repair. Bind its identity at the start and again at the end of judgment:
ao provenance manifest --root "$REPO_ROOT" --include "$CHANGED_PATH",
one --include per changed path.git rev-parse HEAD) and the changed
paths (git diff --name-only <base>...HEAD); for uncommitted work, the
git status --porcelain listing and a shasum -a 256 of each changed file.A requested retrospective follows the code judgment and is not evidence for it. When intent bundles both, judge the code criteria separately and keep the overall request incomplete until the retrospective exists; issue no overall PASS early. An explicitly requested review of the retrospective judges that document on its own scope.
Author and validator identities must be explicit and distinct, and freshness must be attested by the runtime or the caller, naming the attester. An attestation is a declared trust fact, not cryptographic isolation. In ordinary use these count:
A role name, a persona switch inside the author's conversation, or the validator vouching for itself does not count. Never invent an identity. An identity gap makes the result NOT_PROVEN; keep every finding in the report.
Default to one fresh reviewer in the author's model family: Codex/OpenAI for Codex/OpenAI, Claude/Anthropic for Claude/Anthropic, on the runtime's configured capable model unless pinned. Supply task-specific intent, scope, exact subject and relevant evidence, without full author history, desired verdict or peer conclusions. Concise input must not omit necessary evidence; retrieve more source when a criterion requires it.
Cross-model review is opt-in: --cross-model [model] is a skill prompt
selection, not an AO flag, adding a fresh other-family reviewer through
model-dispatch. A required leg
that cannot run yields diversity_unsatisfied and NOT_PROVEN for the combined
request, even if another leg passed; optional diversity that is unavailable is
disclosed without erasing findings. Delivered FAILs and dissent stand; neither
voting nor model preference makes a split PASS, and agreement is not proof of
truth. No fixed ten-minute cap applies; respect real caller/native bounds
without renewing them. A timeout is missing judgment, not FAIL.
--force mutate the subject until proven otherwise; run them
only on a disposable copy or a committed subject, never the judged tree.Verdict: PASS | FAIL | NOT_PROVEN
Subject: <manifest digest, or commit SHA and changed paths>; unchanged start to end: yes | no
Criteria:
1. <criterion> - verified | failed | not verified - <evidence: file:line, receipt, observed output>
Findings: <class> - <what and where> - <consequence> (or "none")
Notes (optional, do not change the verdict): <...>
Checked: <what was inspected, and how>
Not checked: <in-scope acceptance not verified> (empty only for PASS)
Identity: author <id>; validator <id>; freshness attested by <runtime | caller>: <attester>
A finding fails an acceptance criterion or would mislead a user, break install
or the CLI, or remove protection for the product; anything else is an optional
note the author may ignore. Give each new finding a short stable class,
reused on recurrence, and say whether it is pre-existing, introduced or unknown
from before/after evidence; counts and timestamps alone do not establish cause.
Keep prior findings visible. not_checked holds in-scope acceptance that was
not verified; other limits stay in criterion reasoning, declared non-goals or
residual-risk prose, never hidden to obtain PASS. Delivery inside acceptance
stays unverified until its evidence exists; never remove that criterion to
reach PASS. Mechanics covers report proportion and
where each scope limit lives.
Validate is the sole semantic author of verdict.v2.
Only when the caller requests machine-readable evidence or a declared consumer
requires it, persist through ao provenance store-verdict
(mechanics); Go verifies structure and storage, not
truth. Otherwise return the result through the caller's existing channel,
without hidden machine artifacts. Validate owns no repair, retry, delivery or tracker transition:
known findings go back to the author for direct repair, and a causal stall uses
the RPI single-helper rule.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Dispatch independent tasks to parallel workers or subagents without write collisions. Use when: running or planning agents in parallel, even two; check scopes before any launch.
日本語の概要は準備中です。原文の説明を表示しています。
Run a supplied task in headless AGY (Antigravity, Gemini) and collect its result. Use when: AGY, Antigravity or Gemini is requested by name; never a fallback.
日本語の概要は準備中です。原文の説明を表示しています。
Run one prompt through headless Claude with scoped permissions and a time bound. Use when: scripting or automating a `claude -p` call, even a simple one.
日本語の概要は準備中です。原文の説明を表示しています。
Run one prompt through headless Codex and capture the result. Use when: wanting a one-shot `codex exec` run or CI step. Not for batches or retries.
日本語の概要は準備中です。原文の説明を表示しています。
Compare independent opinions from several models or contexts without inflating agreement. Use when: wanting a second opinion or debate, or summarizing several reviewers' results.
日本語の概要は準備中です。原文の説明を表示しています。
Draft or lint a bounded long-running goal prompt with a finish line and hard limits. Use when: selected by name; one change goes to Plan.
日本語の概要は準備中です。原文の説明を表示しています。