vanillagreencom/kendex/skills/orch/SKILL.md
orch
PRIMARY AGENT ONLY — work-item orchestration for Linear or GitHub issues: prepare, delegate implementation, review, submit, merge, hand off, and oversee fleets of sessions.
- Source repository stars
- 64
- Declared platforms
- 0
- Static risk flags
- 1
- Last source update
- 2026-08-25
- Source checked
- 2026-08-25
Decision brief
What it does: where it fits
Problem with this skill? Run kendex report — it files to the owning repo automatically. Do not hand-file.
Not for
- Tasks that require unconfirmed production actions or broad system permissions.
- Environments where the pinned source and install steps cannot be inspected.
Compatibility matrix
Platform support, with evidence labels
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
Inspect first. Install second.
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/vanillagreencom/kendex --skill "skills/orch"Inspect the Agent Skill "orch" from https://github.com/vanillagreencom/kendex/blob/9606fe78419ef5bab0bc99d548569ec3790d8531/skills/orch/SKILL.md at commit 9606fe78419ef5bab0bc99d548569ec3790d8531. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
What the source asks the agent to do
- 01
Workflow Execution
Run exactly one simple command per tool call with explicit arguments. Rejected shapes and substitutes: references/codex-runtime.md. Normalize delegated command lists the same way before they enter a prompt: an env-assignment prefix becomes a precondition check plus the bare comm…
Sequential sections. Mark in-progress, execute every sub-section, mark completed, proceed. Never create tasks for sub-sections, never complete a parent before its children, never skip a step on a predicted outcome.Skip-if. Evaluate "Skip if [condition]" literally; when true, append "(SKIPPED)", mark completed.Nested workflows. Invoke ⤵-marked workflows through the harness mechanism, never inlined. Record the return point (→ § X) first. - 02
Review Pipeline
Finding schema. ../reviewer/schemas/review-finding.md, enforced by review-artifact-check. Routing reads verdict (actionrequired when blockers exist, else pass) and each suggestion's category ∈ {fix, issue}.
Finding schema. ../reviewer/schemas/review-finding.md, enforced by review-artifact-check. Routing reads verdict (actionrequired when blockers exist, else pass) and each suggestion's category ∈ {fix, issue}.Disposition. Classify each suggestion per references/finding-disposition.md: apply in-PR, file as a tracked issue, or decline with one line. The filing bar lives there.Issue audit pipeline. Collect every follow-up that clears the filing bar (category=issue suggestions, escalated blockers, dev "deliberately left out" lists, gaps noticed) into audit input (schema in project-management/s… - 03
The Cycle
Get the issue → dev implements → review → dev fixes blockers → re-review → push PR → review gate → shepherd to merge.
Bounded loops. A fix round addresses blockers only; re-review narrows to the fix diff and the domains it touched; two consecutive rounds with no new blocker end the review.No edge-case churn. A finding that cannot affect real usage is declined with a one-line reason — not fixed, not filed. File issues for critical follow-ups only.Review must converge. A defect class that recurs across rounds is fixed at its source — cut unrequired surface, fix the class structurally, or split — never patched per comment. A round whose only findings are scope, te… - 04
Commands
Route [args] to its workflow and follow Workflow Execution.
Route [args] to its workflow and follow Workflow Execution.start routing. github OWNER/REPON → TRACKER=github, ISSUEID=issue-N, keep OWNER/REPO for the API; otherwise Linear unless the id starts with issue-. A cwd whose git common dir differs from .git is a worktree → workflows… - 05
Scripts
The three waiters exit 3 on hard auth failure — references/gates.md.
The three waiters exit 3 on hard auth failure — references/gates.md.Multi-PR watching. Never hand-roll a monitor. When .agents/skills/review-gate/scripts/pr-watch.sh exists, run it (oversee: through oversee-watch); otherwise per-PR approval-wait/queue-wait. references/gates.md.workflow-state. Run it with no arguments for the action reference. State keys are normalized issue IDs — issue-N for GitHub, PROJ-123 for Linear; schemas/workflow-state.md.
Permission review
Static risk signals and limitations
Runs scripts
The documentation asks the agent to run terminal commands or scripts.
*Run exactly one simple command per tool call with explicit arguments.** Rejected shapes and substitutes: [references/codex-runtime.md](references/codex-runtime.md). Normalize delegated command lists the same way before they enter a prompt:Evidence record
Why each signal appears
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 92/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 64 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Provenance and original SKILL.md
- Repository
- vanillagreencom/kendex
- Skill path
- skills/orch/SKILL.md
- Commit
- 9606fe78419ef5bab0bc99d548569ec3790d8531
- License
- MIT
- Collected
- 2026-08-25
- Default branch
- main
View the original SKILL.md
Orchestration
Problem with this skill? Run
kendex report— it files to the owning repo automatically. Do not hand-file.
Load github and worktree before anything else; a Linear work item also needs linear. The dev and reviewer skills call orch scripts.
MODE SWITCH: you are the orchestrator. Delegate every implementation, review, and QA task to a specialist sub-agent. Never edit code unless the user explicitly asks.
The Cycle
Get the issue → dev implements → review → dev fixes blockers → re-review → push PR → review gate → shepherd to merge.
- Bounded loops. A fix round addresses blockers only; re-review narrows to the fix diff and the domains it touched; two consecutive rounds with no new blocker end the review.
- No edge-case churn. A finding that cannot affect real usage is declined with a one-line reason — not fixed, not filed. File issues for critical follow-ups only.
- Review must converge. A defect class that recurs across rounds is fixed at its source — cut unrequired surface, fix the class structurally, or split — never patched per comment. A round whose only findings are scope, test-coverage, or wording asks ends the review: reply, resolve, push nothing, merge through the gate. A finding that claims a defect — a failing state, a broken path, a dead end — is never one of those: declining it requires disproving its mechanism (name the passing state or the false premise); scope, age, or pre-existing never answers a defect the diff introduces or arms. Thread replies are exactly
Fixed in <sha>,Declined: <reason>, orTracked: KEN-<n>with the issue created first — the gate rejects a tracking claim naming no issue. Never--admin.- Ask the user only about product or experience. Scope expansion beyond the issue and revisiting a recorded decision always ask, whateverORCH_DECISION_MODEsays. Merge asks unlessORCH_MERGE_AUTONOMY=auto, which merges without asking only when every merge gate is green. - Acceptance is artifact-based. A round closes on a validated on-disk artifact plus git/tracker state, never on a return message.
Commands
Route <command> [args] to its workflow and follow Workflow Execution.
| Command | Arguments | Workflow | Purpose |
|---|---|---|---|
start | [ISSUE_ID] | github OWNER/REPO#N | workflows/start.md / workflows/start-worktree.md | Prepare one work item; from a worktree, run the full session |
start new | linear|github ... | workflows/start-new.md | Create one issue, then start it |
handoff | linear|github ... | workflows/handoff.md | Launch independent sessions |
plan-issues | PLAN_PATH linear|github | workflows/plan-issues.md | Convert plan items into issues |
dev-start | [ISSUE_ID] | workflows/dev-start.md | Delegate implementation |
dev-fix | [ISSUE_ID] | workflows/dev-fix.md | Delegate fix items |
ci-fix | PR_NUMBER | queue | workflows/ci-fix.md | Analyze and fix CI failures |
review | [all] | [last N] | [HASH] | workflows/review.md | On-demand review of local changes |
review-codebase | [PATH] | workflows/review-codebase.md | Whole-codebase fanout, findings only |
review-pr | [PR_NUMBER] | workflows/review-pr.md | Review cycle with fixes and QA |
review-pr-comments | PR_NUMBER | BRANCH | workflows/review-pr-comments.md | Triage PR review comments |
submit-pr | [PR_NUMBER] | workflows/submit-pr.md | Push, create PR, gates, merge |
merge-pr | PR_NUMBER | all | workflows/merge-pr.md | Verify conditions and merge |
post-summary | [ISSUE_ID] | workflows/post-summary.md | Post summary and handoff comments |
oversee | — | workflows/oversee.md | Fleet mode: one session per unblocked item, shepherd every PR to merge |
start routing. github OWNER/REPO#N → TRACKER=github, ISSUE_ID=issue-N, keep OWNER/REPO for the API; otherwise Linear unless the id starts with issue-. A cwd whose git common dir differs from .git is a worktree → workflows/start-worktree.md; otherwise workflows/start.md.
Scripts
.agents/skills/orch/scripts/<script> [args]
| Script | Intent |
|---|---|
workflow-state | Persistent state read/write/append — see below |
git-context | Git-derived values (branch, head, issue id, roots, timestamps) |
pr-view-json | PR view JSON; status=no_pr exits 0 and routes to PR creation, not an error |
resolve-base-branch | Print a worktree's base branch; exits 1 rather than guess |
base-freshness | Gate the review cycle on a current base; unverifiable = stale. --help |
review-artifact-check | Validate a reviewer's JSON artifact — the sole reviewer completion condition. --help + references/artifact-checks.md |
dev-return-write | Write a dev agent's round-scoped completion artifact; never hand-author the JSON. --help; schema schemas/dev-return.md |
worktree-claim | Take or verify this session's possession of an issue worktree; exits 75 when a foreign owner or lock holds it, or when the token it is bound to differs from the lease. --help |
worktree-push | Push an issue worktree via worktree push and reconcile rebased SHAs in workflow state (.rebase_map, fixed_items, pr_comment_review.fixes) in the same call. --help |
dev-round-write | Persist a fix round's delegated item set at stamp time. --help; schema schemas/dev-round.md |
dev-artifact-check | Validate a dev round's completion artifact by round id. --help + references/artifact-checks.md |
approval-wait | Poll the reviewer gate; --resolve-mode prints the effective gate mode. --help + references/gates.md |
ci-wait | Block until CI completes on a PR. --help + references/gates.md |
queue-wait | Block until a merge-queue / auto-merge outcome. --help + references/gates.md |
orch-env | Effective value of a kendex [env] setting (process env > kendex.settings.toml > default) |
spawn-adapter | Resolve Codex spawn parameters (spawn) and the runtime thread budget (slots) |
open-terminal | Terminal handoff; model, effort, and permission flags via --launch-flags. --help |
lanes | Enumerate harness auth lanes; pick prints the launch env prefix for the least-loaded qualifying lane, exit 3 when none qualifies. --help |
reconcile-work-items | Read-only tracker sweep (parked containers, items stale past RECONCILE_STALE_HOURS, Done items with unchecked boxes). Exit 1 on findings |
oversee-watch | Block until the fleet needs the overseer, then print one EVENT line. --help |
The three waiters exit 3 on hard auth failure — references/gates.md.
Multi-PR watching. Never hand-roll a monitor. When .agents/skills/review-gate/scripts/pr-watch.sh exists, run it (oversee: through oversee-watch); otherwise per-PR approval-wait/queue-wait. references/gates.md.
workflow-state. Run it with no arguments for the action reference. State keys are normalized issue IDs — issue-N for GitHub, PROJ-123 for Linear; schemas/workflow-state.md.
Review-gate modes. Read the effective gate mode (approval, review, or off) only through approval-wait --resolve-mode. references/gates.md.
Schemas
| Schema | Purpose |
|---|---|
schemas/workflow-state.md | State file |
schemas/dev-return.md | Dev completion artifact |
schemas/dev-round.md | Delegated fix-round item set |
../reviewer/schemas/review-finding.md | Review/QA finding JSON |
Configuration
Non-secret settings go in committed kendex.settings.toml under [env]; .env.local holds secrets and personal overrides. Keys: README.md § Configuration; review-gate keys in references/gates.md; lane keys in lanes --help and open-terminal --help.
System dependencies: jq; bash 4+; flock (util-linux).
Tests
bash skills/orch/tests/run-all.sh (append a name fragment to filter).
Runtime Notes
If you are running in Codex:
approval required by policy, but AskForApproval is set to Neverflags the command's SHAPE — never retry it, never wait for approval; rewrite it per references/codex-runtime.md. Polling loops → the orch waiters.agents/skills/orch/scripts/ci-wait,approval-wait,queue-wait— nevergithub.shsubcommands. Spawn generated agents throughscripts/spawn-adapterwithfork_context: false, thensend_inputaDELEGATION:-prefixed<delegation_format>.
If you are running in OpenCode: store the
task_idreturned byfunctions.taskin workflow state (child_sessions[agent].agent_id,review_agent_ids[reviewer-name]) and re-delegate withfunctions.task(task_id=<stored_id>). Spawn fresh only when no ID is stored, one resume attempt failed, or the task is confirmed dead.
If you are running in Pi with
pi-agents-tmux: delegation is onesubagentcall whosetaskargument is the filled<delegation_format>alone — never prepend role text. Store the returnedtaskIdin workflow state. references/pi-runtime.md.
Skill Rules
Workflow Execution
- Sequential sections. Mark in-progress, execute every sub-section, mark completed, proceed. Never create tasks for sub-sections, never complete a parent before its children, never skip a step on a predicted outcome.
- Skip-if. Evaluate "Skip if [condition]" literally; when true, append "(SKIPPED)", mark completed.
- Nested workflows. Invoke
⤵-marked workflows through the harness mechanism, never inlined. Record the return point (→ § X) first. - Worktree scope. Inside a worktree, never act on another worktree or branch. If the resolved
ISSUE_IDdiffers from the current branch, stop and ask: reuse, abort, or switch.
Harness-Safe Shell
Run exactly one simple command per tool call with explicit arguments. Rejected shapes and substitutes: references/codex-runtime.md. Normalize delegated command lists the same way before they enter a prompt: an env-assignment prefix becomes a precondition check plus the bare command.
Tracker Resolution
An ISSUE_ID starting with issue- is GitHub (TRACKER=github, issue number ${ISSUE_ID#issue-}, repo from caller context else gh repo view --json nameWithOwner); anything else is Linear. A caller-supplied tracker wins; resolve once per workflow into TRACKER and ISSUE_REF (#N for GitHub, the Linear identifier otherwise) — the only form a Closes line renders. Run Linear only / GitHub only steps only for that tracker; never run linear.sh against a GitHub item.
Delegation
| Pattern | When | Flow |
|---|---|---|
| Spawn + message | Fresh dev, QA, or review agents | Spawn → send delegation |
| Message only | Re-delegation to a live agent | Send delegation to the running agent |
| Self-create | No team context | Full instructions in the prompt |
No duplicate spawns. Never spawn a fresh agent while the same role is alive. Reuse by stored ID; respawn only after one recovery attempt or a confirmed stuck/closed status.
Format Tags Are Literal
<delegation_format> and <output_format> are exact: fill [PLACEHOLDERS], omit lines whose placeholder is empty, add nothing else, keep structure and field names verbatim. Placeholders hold schema fields only — never process prose. When a tagged block precedes an ask-user step, present the filled block first, then ask.
Single Return Message
An agent sends exactly one completion message. A second return is a violation: diff it against the first and flag unrequested commits.
Codex dual-channel completion. The Codex runtime delivers one completion over two channels — a send_input MESSAGE then a FINAL_ANSWER echoing it: treat the pair as one completion and deduplicate it. Still diff them; a new commit or extra changes is a genuine second return and is flagged.
Agent Lifecycle
SPAWN → DELEGATE → WORK → RETURN (single message) → IDLE / RE-DELEGATE.
Dev agents persist for the whole session, re-delegated for every fix round. Shut down only on explicit user request or a confirmed stall.
Reviewer persistence is budget-conditional. Available slots = budget (orch-env REVIEWER_SLOT_BUDGET 0; 0 = unlimited) − 1 − live child_sessions entries whose status is active (no status counts as active), minimum 1; recompute at every review-cycle start. Within budget, reuse reviewers by exact name and spawn only the missing subset. Over budget — or on a thread-limit spawn error — run waves: launch up to the available slots, retire each session on its validated artifact, persist the wave size as reviewer_slots_observed. Review state lives on disk, never in reviewer session memory.
QA agents spawn and shut down per agent.
Round Closure
The orchestrator owns round closure. Every dev/QA delegation carries three mechanics:
- Possession and round token — immediately before delegating:
worktree-claim --worktree [WORKTREE_PATH] --issue [ISSUE_ID]→ the delegation'sWorktree Lease:line; exit 75 aborts when a foreign holder has the worktree or the round's recorded lease generation differs from the lease. Thenworkflow-state new-round-id [ISSUE_ID] dev_round_id→ theRound ID:line, re-stampdev_delegated_at; a fix round also runsdev-round-write. - Arm a single-shot wall-clock watchdog at the same moment — one backgrounded
dev-artifact-check --wait 600 --worktree [WORKTREE] --issue [ISSUE_ID] --round-id [dev_round_id](fix rounds add--expect-items-from-round): returns when the artifact lands (accept/retry) or at the deadline (wait). Run A/B on its return; re-arm only on a new escalation step — never poll. references/artifact-checks.md. - Run the check on every wake and at the deadline — never classify from wording or elapsed time.
dev-artifact-check --worktree [WORKTREE] --issue [ISSUE_ID] --round-id [dev_round_id](fix rounds add--expect-items-from-round) printsverdict; act on it.
The acceptance table lives in the delegating workflow (dev-start.md § 3, dev-fix.md § 2, review-pr-comments.md § 6.1); the return message is display-only; tracker corroboration (B) applies only where that table names it. ci-fix.md (no dev-return artifact) is accepted by its return message plus the escalation ladder.
Escalation. Only after the 10-minute quiet window AND a confirmed stall (task status unchanged, no session-log entries for 10+ minutes, or the process exited): re-message once naming the missing step → wait 5 minutes → still inactive: shut down, re-create tasks, respawn, re-delegate.
State Management
Durable data lives in workflow state through the workflow-state CLI only (set-git-head/set-now, never inline substitution). Location: <state-dir>/workflow-state-[ID].json, where <state-dir> is the --state-dir flag, then $ORCH_STATE_DIR, then tmp/.
After compaction, resume from the step after the last completed one: read workflow state, re-send delegations by stored ID, respawn only an agent silent through one idle cycle. Never repeat completed actions.
Coordination
Containers. An issue with children or an agent:multi label and no (one PR) title marker is a CONTAINER. A container is never orchestrated and never gets a PR — each child is the PR unit, selection operates on unblocked children, and the container closes LAST when its final child merges.
Ancestor gate. Every selected issue walks its full parent_id chain. An enclosing (one PR) bundle REPLACES the selection. Dispatch requires the item's own state_type non-terminal AND the union of its blocked_by with every container ancestor's resolving terminal. Fetch blocker states in chunks of at most 50 ids, verify every id came back, keep the item blocked on a missing lookup. Mechanics: start, start-worktree, handoff, dev-start.
Sequencing. Order by data flow (Creates ↔ Consumes), never by agent ordering; existing blocking relations outrank inference. Cross-bundle relations go on the parent issues; dependent children of one container get child-blocks-child relations, which ARE the execution order; only an explicit (one PR) bundle leaves intra-bundle ordering to the delegated session.
Single-PR bundles. Exactly three opt-ins delegate all children as one session: a parent marked (one PR), a delegation carrying Audit Bundle: yes, or a leaf issue with an internal checklist. One composite task per sub-issue; multi-domain bundles process groups sequentially, collecting handoff notes between groups.
Tracked issue creation. Route every tracked issue through TPM (project-management) — never create one directly from an orchestration session, except where a workflow step specifies it with its label set (plan-issues, start-new, the merge-pr rebundle).
Review Pipeline
Finding schema. ../reviewer/schemas/review-finding.md, enforced by review-artifact-check. Routing reads verdict (action_required when blockers exist, else pass) and each suggestion's category ∈ {fix, issue}.
Disposition. Classify each suggestion per references/finding-disposition.md: apply in-PR, file as a tracked issue, or decline with one line. The filing bar lives there.
Issue audit pipeline. Collect every follow-up that clears the filing bar (category=issue suggestions, escalated blockers, dev "deliberately left out" lists, gaps noticed) into audit input (schema in project-management/schemas/) and delegate to TPM, with dependency fields populated when order is known. Never file directly.
Frequently asked questions
What to verify before installation and use
What does the orch source document cover?
Problem with this skill? Run kendex report — it files to the owning repo automatically. Do not hand-file.
How do I install orch?
The source record exposes this install command: npx skills add https://github.com/vanillagreencom/kendex --skill "skills/orch". Inspect the command and pinned source before running it.
Which permission-related actions were detected?
Static rules flagged exec-script in the source; the page lists the matching lines and excerpts.
Alternatives
Compare before choosing
garrytan/gbrain
bulk-ingestion
End-to-end discipline for turning any large data source (audio libraries, email takeouts, document corpora, chat exports, API dumps) into brain pages at scale. The lifecycle spine: SCHEMA → ACCESS → TRIAL → EVALUATE → IMPROVE → CODIFY → TEST → SKILLIFY → BULK → MONITOR. State is tracked in a durable JSON manifest (see MANIFEST-PATTERN.md) so any crash, session boundary, or subagent fan-out resumes from ground truth instead of memory.
alirezarezvani/claude-skills
app-store-optimization
App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist
wanshuiyin/Auto-claude-code-research-in-sleep
citation-audit
Use it for operations and research tasks; the detail page covers purpose, installation, and practical steps.
prowler-cloud/prowler
postgresql-indexing
PostgreSQL indexing best practices for Prowler: index design, partial indexes, partitioned table indexing, EXPLAIN ANALYZE validation, concurrent operations, monitoring, and maintenance. Trigger: When creating or modifying PostgreSQL indexes, analyzing query performance with EXPLAIN, debugging slow queries, reviewing index usage statistics, reindexing, dropping indexes, or working with partitioned table indexes. Also trigger when discussing index strategies, partial indexes, or index maintenance