General-purpose coding policy for Baruch's AI agents
73
91%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Low
Low-risk findings worth noting
Process steps in order. Do not skip ahead.
Before any finish with enrolled work, reconcile the whole fleet under
references/supervision.md. Continue observation or persist an authorized pause
or handoff covering every active assignment. Keep user attention visible under
references/attention.md.
Before any team-round action, read the team-round contract in full. It is the
file rules/agent-team-operation.md points to, and it binds every step below.
Every worker brief names it as a required read.
skills/herdr-foreman/references/team-operation.mdYou run on the foreman's selected tier: the operator's coordination row,
resolved through select_tier and checked against the capability table
(skills/herdr-foreman/references/team-operation.md Foreman Seat).
Each command resolves CP to the local or home plugin, or to . in a
coding-policy clone; anywhere else it stops with an install instruction. Repeat its resolver in every call. Prose skills/... paths are relative to that root.
Before each decision, load its records and read every listed file:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" load-set --decision <plan|brief|gate|diagnose> --task <task>CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" load-set --decision wake --enrollment <enrollment-id>| Decision | Step | Target |
|---|---|---|
plan | Step 5 | --task |
brief | Step 7 | --task |
wake | Step 11, per wake event | --enrollment |
gate | Step 12 | --task |
diagnose | Step 13, diagnosis mode | --task |
It prints JSON whose files list is the floor for that decision; a file with
present: false is a gap to resolve, not one to skip. A non-zero exit names a
refused task, enrollment or unreconciled dispatch on stderr; resolve it first.
The contract is skills/herdr-foreman/references/working-memory.md "Load a
decision's records".
References:
skills/herdr-foreman/references/herdr.md
skills/herdr-foreman/references/round-flow.md
skills/herdr-foreman/references/round-setup.md
skills/herdr-foreman/references/task-ledger.md
skills/herdr-foreman/references/retrospectives.md
skills/herdr-foreman/references/working-memory.md
skills/herdr-foreman/references/attention.md
skills/herdr-foreman/references/supervision.md
skills/herdr-foreman/references/assignment-reasoning.md
skills/herdr-foreman/references/specialists.md
skills/herdr-foreman/references/judge-round.md
skills/herdr-foreman/state-schema.mdA refusal naming the legacy teamlead default home is a one-time operator
step, not a mode: record it as a
user-attention blocker naming foreman migrate-home (skills/herdr-foreman/state-schema.md Home
Migration), and run nothing else until the operator has stopped every foreman
and run it.
Four request kinds are answered offline, need no live Herdr, and finish here after the requested operation. Each reference carries its own owner commands and their contracts. Use the recorded state override or default, report any non-zero diagnostic, and never fabricate missing history. They grant no new task authority.
Catch-up or saved attention — references/attention.md. Read all
attention pages before claiming completeness.
Lesson curation, saved foreman context, or a foreman handoff —
references/working-memory.md.
A saved retrospective — references/retrospectives.md. Report the note's
date, coverage, conclusions, and path.
A task's cost or resource use — run the read-only report, omitting
--task for every task:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" cost-report --task <task>It prints JSON with a tasks list and an unrecorded list. Relay each
quantity separately, and every unknown value as unknown. Never total the
quantities or claim a saving. A non-zero exit writes its diagnostic to stderr
for an unusable state file or an unknown task; report it and stop. The output
contract is skills/herdr-foreman/state-schema.md (Writer / Reader Contract).
For every other request, read HERDR_ENV before running scripts.
One call answers every deterministic check a round start owes: Herdr and the roster, authority for the repo, measured headroom, the capability table's cadence, and worktree hygiene.
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/round-preflight.sh" \
--repo <owner/repo> --checkout <shared-checkout>Emits one JSON object: ready, the blocking reasons, the cadences that are
due, and each check's own payload under checks. Exit 1 is a verdict, not a
failure — something blocks the round. Exit 2 means the preflight could not
answer.
Before following any route below, report the worktree sweep to the operator:
When checks.worktrees.detail is present, relay its report verbatim
The sweep builds that report (skills/herdr-foreman/sweep-worktrees.sh,
report_text); never reshape or summarize it
When checks.worktrees has no detail, report its reason verbatim; a
status ok with no detail means the worktree root does not exist, and
there is nothing to report for it
On exit 2 there is no JSON; report the stderr diagnostic instead
Raise each dirty or unpushed item the report lists per
rules/hook-action-reporting.md Act on What It Names; the operator carries
out the resolution chosen, and the foreman runs none of it
Exit 0 — read due, satisfy any cadence it names, and proceed to Step 5.
A resumed foreman proceeds to the stow's continuation step instead (Step 17
Resume Route).
When due names the capability table, dispatch the refresh consultation under
references/model-tiers.md, then record its report and show the result:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" capability-record --record <report.json>CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" capability-showblocking reasons verbatim. Each names the command
that produced it; re-run that one, not the preflight. A foreman_tier block
beside a failed headroom check waits on that measurement; fix it first.
Otherwise it means this pane does not run the foreman's selected tier:
record a user-attention blocker naming start-foreman
(skills/herdr-foreman/references/model-tiers.md Foreman Seat) and finish here.On exit 0 or 1, a checks.foreman_tier status unconfigured blocks nothing:
relay its detail.warning verbatim before routing.
The blocker quotes the restart the operator runs from another shell, naming an empty Herdr shell pane; never run it from the foreman's own pane:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" start-foreman --pane <pane-id>Which checks run, and which exit codes they fold into blocking, are the
script's decision contract — see skills/herdr-foreman/round-preflight.sh, not
restated here (rules/script-as-black-box.md).
Steps 3 and 4 remain the individual commands, for a caller that needs one on its own. A round start runs this instead of all of them. The roster has no step of its own; inspect it directly when only the live workers are wanted:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/roster.sh"Emits the caller and live workers with kind, pane, and state. An empty roster on
exit 0 means unnamed panes: report them from herdr agent list with the
correcting herdr agent rename <pane-id> <name> command.
Record staffing gaps under references/round-setup.md. Leave unused specialist
profiles unlaunched. Never duplicate targets or fold verification onto a
contributor. Start workers in YOLO mode under references/model-tiers.md;
preserve it on relaunch. Verify live permission flags before dispatch, including
existing workers. Record task authorization and permitted actions under the
round-setup reference. Create or resume the stable ledger under
references/task-ledger.md; record its absolute path before dispatch. Apply the
round-setup accepted-behavior, resume and supervision binding requirements.
Run references/retrospectives.md on resume, before planning, or for an
explicit retrospective request. For an explicit request, complete a new
retrospective and finish here.
Proceed immediately to Step 5, or on a resume to the stow's continuation step.
Step 2 runs this. Use it alone when only the authority answer is wanted.
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/verify-authority.sh" <owner/repo>Record the emitted namespace ownership evidence using Step 3 of
references/round-setup.md. For a non-owned repo, reuse explicit per-action
operator permission; absent permission, remain read-only or finish here.
On non-zero, report the diagnostic and finish here.
Proceed immediately to Step 4.
Step 2 runs this. Use it alone to re-measure, which the judge round does.
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" measureEmits and saves headroom, windows, state, tier_billing, and failed_agents.
Busy workers are skipped. Unmeasured billing stays unknown. Report failed
measurements and obtain their readings before relying on those seats.
Usage and --trace contracts:
skills/herdr-foreman/references/round-setup.mdProceed immediately to Step 5 once the required readings are available.
Read the open tasks waiting for a seat, oldest first:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" foreman-queueIt prints {"schema_version": 1, "queue": [...]}. Each entry names task,
waiting_for (a list of developer, reviewer or tester),
dispatched_seats, since, developer and fix_round. A non-zero exit names
an unusable state file on stderr; restore it before planning. Tasks with an
active worker are omitted. A partitioned verifier stays listed with its
dispatched slices; check them against the validated partition. The order is a
default; choose another when the round needs it.
Choose the responsibilities needed next under references/specialists.md.
Supply its requirements file for specialized work. Schedule consultation and
verification as the task needs them. plan bars a developer reserved to
another task and a worker with an active enrollment, and names each bar in its
rationale; do not pass --exclude for either. apply re-reads the
reservations before sending. Reusing a reserved developer elsewhere requires
closing its task first.
The composition triggers decide part of that roster. Classify this round
against the repo's declaration first. For a pre-implementation round, pass
--planned naming the surfaces the work will touch. A round that writes no
repository content — an investigation, an architecture or advisory consultation
— declares writes_repository: false in that file instead
(references/specialists.md). A round with work already written classifies
that work:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" detect-triggers \
--repo <repo-path> --base <recorded-base> [--head <pushed-head>] \
--roles <role[,role...]> [--requirements <requirements.json>] \
[--planned <planned.json>] [--decisions <decisions.json>]Exit 0 means every fired trigger is staffed or answered. On exit 1, read the
stderr object: an absent declaration is written first (references/specialists.md),
and an unaddressed_trigger is staffed in the roles below or answered by a
recorded decision with its reason. Re-run the command with the updated
declaration, roles, requirements and decisions after every such change, and
plan only once it exits 0.
A round that will split its review surface validates the partition first, then
plans it with --partition:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" validate-partition \
--repo <repo-path> --base <recorded-base> [--head <pushed-head>] \
--partition <partition.json>Exit 1 names every unowned path, every overlap and every slice owning nothing,
in one run. Fix the partition and re-run; plan only once it exits 0. Save its
stdout — plan --partition takes that result, never the document
validate-partition read. Validate at the pushed head: the result's proof
records the repo, base and head it was proven against, and Step 12's gate
cannot check a working-tree proof. Format, ownership
payload and the seating it produces:
skills/herdr-foreman/references/review-partition.mdCP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" plan \
--roles <role[,role...]> [--requirements <requirements.json>] \
[--exclude <role>=<agent>[,<agent>...]]... [--partition <validated.json>] \
[--judge-mode adjudication|diagnosis] \
[--round <role>=<round-type>] [--round-context <evidence.json>] \
--task <task-id> [--fix-round <N>] [--correction-plan <id> --work <work.json>]Emits the role plan without worker contact; a partitioned role is seated once
per slice as <role>#<slice>, and Step 10 dispatches each seat with its own
brief. A judge seat declares its mode:
adjudication rules on a contested verdict, diagnosis on the investigator's
assessment at an exhausted allowance. Pass the same --judge-mode to apply.
On exit 1, resolve the diagnostic before continuing. Apply the Step 5 constraints in references/round-setup.md:
exclude contributors from verification, reserve the developer through early fixes,
preserve task identity and fix count, and reuse recorded correction bounds.
Tier contracts:
skills/herdr-foreman/references/model-tiers.md
skills/herdr-foreman/references/dispatch-recovery.mdSave the plan and rationale. Proceed immediately to Step 6.
For reviewer/tester briefs, run from a checkout holding the recorded commits:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/review-package.sh" \
<recorded-base-sha> <pushed-head-sha> <round-reports-dir>/review-<base7>..<head7>.diffApply the Step 6 base, range, and rebuild requirements in
references/round-setup.md. Success prints the absolute review-package path;
set it as REVIEW_PACKAGE. On non-zero, fix the diagnostic and retry before
composing verification briefs. Other roles need no package.
Proceed immediately to Step 7.
Resolve policy paths through the Step 7 reference first. Write its outputs in
shared within {"shared": {...}, "roles": {"<role>": {...}}} and run:
GATES is shared: Step 2's checks.gates.detail.brief, verbatim. On a
non-empty checks.gates.detail.missing, name those paths in the round's report.
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/compose-briefs.sh" \
"$CP/skills/herdr-foreman/templates" \
<values.json> <round-reports-dir>Emits common and role-brief paths. On non-zero, fix the diagnostic before dispatch. Validates composition inputs and review evidence before writing. Use a fresh absolute report path per role and attempt.
Follow references/round-setup.md Step 7 for shared and role-specific values,
authority, review evidence and brief completeness.
skills/herdr-foreman/references/team-operation.md Judgment
RoutesSPECIALIST_CONTEXT value to the absolute report path of
that consultation's assess-specialist recordProceed immediately to Step 8.
Step 2's preflight swept every repository with a worktree directory under
the root, every round, and Step 2 reported its outcomes. Route on its
checks.worktrees.status; the classification is
skills/herdr-foreman/round-preflight.sh's (the checks.worktrees comment
at the top of the file):
ok or degraded — provisionreason and detail,
repair what it names, then run Step 2's preflight again with
--no-measure and route on the new statusNever remove a worktree by hand; Step 15's removal of the merged task's own
worktree is the one exception. To re-sweep without provisioning (Step 15),
run the sweep alone and relay its report verbatim, as Step 2 does:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/sweep-worktrees.sh" "$HOME/.worktrees"Input is the worktree root. It removes the spent worktrees and local branches
of every repository with a worktree under that root. Stdout is one JSON
object whose report is the operator-facing summary; the full shape is the
script's top-of-file contract.
report, raise each
dirty or unpushed item it lists, and continue.report; its failure and error lines name each one.The removal predicates live in skills/herdr-foreman/prune-worktrees.sh
(top-of-file docstring).
Then run once per writing worker and every worktree named in a brief:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/provision-worktree.sh" \
<shared-checkout> <branch> <worktree-path> [base-ref]Emits path, branch, base, and created|attached|already-provisioned. On any
non-zero exit, fix the diagnostic and retry. Never dispatch a missing
worktree. Read-only consultations need none. Clean up after merge per
rules/agent-worktree-isolation.md. Proceed immediately to Step 9.
Optional, once per team; skip an already named sidebar.
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/label-workspaces.sh" \
<lead-label> [<agent>=<workspace-id>]...Emits per-target renamed|unchanged|failed; exit 3 names partial failures.
Report label failures and continue. Proceed immediately to Step 10.
Complete the retrospective reference's cadence and transition checks before live dispatch. Apply rechecks coverage before worker input. Dry runs prove no coverage.
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" apply \
--assignments <plan-file> \
--brief <role>=<path> [--brief <role>=<path>]... \
--report <role>=<report> [--report <role>=<report>]... \
--common <path-to-COMMON.md> --task <task-id> \
[--fix-round <N>] [--retain-context | --retain-specialist | --no-clear] \
[--correction-plan <id> --work <work.json>] [--dispatch-id <stable-id>]Emits dispatch JSON under state-schema.md. Supply each role's fresh absolute
report path from its brief. Apply enrolls before input; unknown sends remain
observation obligations. Apply refuses while an open decision or blocker on the
task is unanswered; see the attention reference's Dispatch gate.
Classify every brief against Step 3's authorization before sending it.
Apply refuses a consultation brief without a contiguous CRITERION 1..N block
under ## Acceptance Criteria. That block is the N its report answers.
Append the dispatch outcome to the task ledger; applied proves dispatch only.
Apply the recovery reference's Dispatch context requirements before sending.
Preserve task identity and cumulative fix count. Retained fixes dispatch
developer alone. Warm consultations use the recovery reference's
--retain-specialist path. Reconcile unknown outcomes
before retrying. Reuse existing correction authorization within its bounds.
Follow the Dispatch Results contract in references/round-flow.md for busy,
uncertain, failed, and dry-run outcomes. Preserve all already enrolled work.
Dispatch references:
skills/herdr-foreman/references/dispatch-recovery.md
skills/herdr-foreman/references/model-tiers.mdProceed to Step 11.
Run the bounded foreground watcher for all enrolled assignments:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" supervision-watch [--state <state-file>]Retain and await its real execution handle. The JSON result gives reason,
through, and durable events; a quiet deadline completes only that checkpoint.
Then ask which of those events need you:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" supervision-gate [--state <state-file>]It returns wake and suppressed, each event with its reason. Acknowledge
every suppressed event with that reason as its outcome, without reading
anything. Only named, information-poor cases are suppressed and every other
event wakes you, including a kind the gate has never seen; which cases, and
why, is the script's decision contract — see
skills/herdr-foreman/foreman/supervision_gate.py, not restated here
(rules/script-as-black-box.md).
For each wake event, verify report delivery for its enrollment:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" check-member --enrollment <enrollment-id> \
[--worktree <worker-checkout>]It reads the agent, report, recorded base and send time from the owner
records and runs wait-report.sh --once with them
(skills/herdr-foreman/foreman/members.py). Its JSON carries the
checkpoint's exit and delivery JSON as wait:
exit 0 confirms delivery, 1 remains pending, 3 confirms blocked, 4 lacks
confirmed delivery, and 5 proves terminal refusal; record it with
record-refusalwait_failed, carrying the
wait's own exit, 2 included); resolve the diagnostic stderr names, then run
it againThen act on the checkpoint:
--worktree when it has onereason: checkpoint_pending or a stall objectstall is classified only when --worktree names the checkoutskills/herdr-foreman/references/team-operation.md Stalled Workersreferences/attention.mdskills/herdr-foreman/references/supervision.md
skills/herdr-foreman/references/dispatch-recovery.mdSave each reviewer, tester and consultation report's successful delivery
receipt and record its contract lines with assess-specialist under
references/specialists.md before retiring its enrollment. A refusal names
the report's gap; what it saves is the assess-specialist contract in
references/dispatch-recovery.md. Record needs_work in Step 12 and
re-dispatch the same responsibility with that gap named. A reviewer or tester
re-dispatch spends no developer fix round.
Record user-facing obligations in the attention queue. Acknowledge only handled event IDs through the saved snapshot; schedule pending rechecks. Record no assessed outcome and close no enrollment here. Step 12 records acceptance after the round's gates exist. Complete due retrospectives between checkpoints without interrupting workers. Resume the fleet watch while any observation obligation remains; one blocked worker never hides another worker's report. Proceed to Step 12 when the required reports are delivered or their unavailability and recovery are recorded.
Classify every delivered report in one call, and save its stdout:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/classify/classify-reports.sh" <report>... > <labels.json>On exit 2 (usage error), fix the arguments stderr names and rerun before using
<labels.json>. A report in the output's unannotated list gets no gate and is
gated exactly as it would have been.
Read every report file in full, including a report whose worker exited cleanly.
A ## BLOCKED section can sit under a report that otherwise reads as finished.
A report's recorded VERDICT: and ACCEPTANCE lines decide it. Never accept,
reject or rate a finding on your own reading.
Then record the gates the labels earn, before gating any report:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" report-gate-record --labels <labels.json>recorded, replayed and no_gate listsclose-member and record-report refuse while a gate forbids the decisionassess-specialist and record-report record a verdict gate for every
VERDICT: blocking reportapply refuses a fresh release dispatch while the task carries an open
verdict gateblock gate clears only through report-gate-clearreread gate clears only through report-gate-rereadOutput fields, gate levels and the evidence each resolution cites are the owners' contract:
skills/herdr-foreman/references/report-classifier.mdGate the reports together in one turn, not one turn per report.
Before accepting a mechanical round, compare its whole result against the
oracle its plan declared. <result-file> is the pushed diff for a patch
oracle and the produced output otherwise:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" verify-oracle \
--plan <plan-file> --role <role> --result <result-file> --task <task>Exit 0 is a match. Exit 1 with "match": false is a blocking finding on the
round; exit 1 with no verdict is a usage error to resolve before gating,
including a plan whose oracle differs from the one the round's dispatch bound.
Before accepting a partitioned responsibility's pass, confirm its plan, as
dispatched, still covers exactly the task's diff at the tip under review:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" verify-partition \
--plan <plan.json> --repo <repo-path> --head <tip-under-review> --task <task>--taskOnly now, with every report's gates recorded, record each assignment's outcome in the task ledger from its recorded contract lines, citing the report:
accepted for a reviewer or tester needs a recorded valid VERDICT: at the
current report bytes, whatever its value; for a consultation it needs every
ACCEPTANCE line met. The verdict gates the round below, never acceptanceunmet criterion, is needs_workRecord the task's gate decision separately; a worker finishing its brief never completes the whole task. Once the ledger records an assignment's assessed outcome, close its enrollment in one call:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" close-member --enrollment <enrollment-id> \
--ledger <absolute-TASK-LEDGER.md>It refuses until the ledger's latest event for that worker and report carries
an assessed decision, and refuses accepted without the report's recorded
contract lines, checked before its classifier gates. It then acknowledges the
enrollment's pending events and resolves it, citing that ledger event; a repeat
replays. Resolution stays
separate from assignment acceptance and task completion.
Resume Step 11's fleet watch for any enrollment still observed.
Route correction-scope and bug-evidence assessment to a worker under
skills/herdr-foreman/references/team-operation.md Judgment Routes; never
assess them yourself.
Persist user-facing obligations under references/attention.md before presenting
them; record an actual answer or resolution separately from showing the item.
Every return to Step 4 is a round boundary: run Step 16 to log the round and Step 17 to reset first. Record the step this gate decision named as the stow's continuation step. The reset foreman takes Step 17's Resume Route.
After accepting a consultation, return to Step 4 for the next needed responsibility. For an investigation-only task, use the knowledge gate below.
For an investigation-only task, gate every assigned report on its recorded
ACCEPTANCE lines. Resolve a blocking verdict through the same bounded and
judge paths below. Once every criterion is met, present the findings and
preserve open user decisions; proceed to Step 15 if a task worktree needs cleanup, otherwise
Step 16. No implementation or release is inferred from the diagnostic result.
VERDICT: blocking from a reviewer,
tester, or security, ux-product or documentation consultation is a
blocking finding for the round. Apply the round-flow reference's Blocking
Gate contract and skills/herdr-foreman/references/team-operation.md Fix Loops. Return to
Step 4 for an authorized correction or Step 13 for a required judge ruling.uphold or amend)
decides it. A finding a weighing ruled defer or decline is settled only
by the next reviewer or tester report at the tip, marking it DECLINED with
the ruling and recording VERDICT: approved. Never match rulings to
findings yourself.VERDICT: approved, run report-gate-clear --report <blocking report> --evidence <re-check> --reason <what it settled> for each
blocking report.--decision.block gate on a VERDICT: approved
report goes to Step 13 for adjudication.MARGINAL:, or
one foreman finding-churn places on lines the previous fix round added,
goes to Step 13 for a weighing.references/dispatch-recovery.md, consult the investigator under
references/specialists.md with round context {"investigator": {"diagnosis_input": true}}, and take its assessed report to Step 13 for the
diagnosis.VERDICT: approved with advisory findings — record them in the round
log and fold them into the next round that is already happening. Never spend
a round on a lone advisory.Apply the release gate in this reference; obtain broad independent reviewer and tester passes against the current pushed tip before release:
skills/herdr-foreman/references/round-flow.mdWith its release criteria met, proceed immediately to Step 13.
Optional. No trigger — proceed to Step 14. A bot disagreement inside Step 14
returns here first. A weighing nomination from Step 12 is an adjudication
trigger. The judge's report is the ruling once foreman verify-ruling
binds it in the judge round's last step; until then no defer or decline
applies.
Run the round's seven steps in order — compose the brief, re-measure the shared window, plan the pinned seat, start its worker on the pinned tier, dispatch, wait, act on the ruling:
skills/herdr-foreman/references/judge-round.mdThe judge is read-only, so Step 8 is skipped for it. Never substitute a judge, lower its tier, or hand-write an assignment to bypass a refusal. Its last step names where to continue.
A judge round is a round: once its ruling is recorded, run Step 16 and Step
17 before continuing, whatever the ruling (insufficient and blocked
included). Record the step the ruling named as the stow's continuation step.
The reset foreman takes Step 17's Resume Route.
The release is one more assignment, never a prompt into the developer's
existing context. Return to Step 7 with the role release for
the developer's agent (template templates/brief-release.md, the same
WORKTREE and BRANCH, a fresh REPORT), run Step 8 (it reports
already-provisioned), dispatch through Step 10 so the context is cleared and
the brief is fresh, and wait on the report in Step 11. apply refuses the
release dispatch, dry run included, while the task carries an open verdict
gate: return to Step 12 and clear it first. A source-changing
release finding returns to Step 12 for the next counted developer assignment.
A blocking policy review returns there too, where its nominations go to a
weighing. Fill WEIGHING_RULING with the judge's report and the follow-up
issue once a weighing covers the findings, otherwise "none".
The worker merges after all gates pass. Proceed immediately to Step 15 only
after verifying its reported release against the live VCS and release gates.
Record that evidence in the task ledger.
Fast-forward the shared checkout, remove the merged task's own worktree with
git worktree remove, and delete the branch, in the post-merge order of
rules/agent-worktree-isolation.md Cleanup. This is the one removal the
foreman makes itself (skills/herdr-foreman/references/team-operation.md Writers and Checkouts,
the merged-task exception). Then run Step 8's sweep again for the round's other
worktrees. Proceed immediately to Step 16.
Finalize the task ledger with the round outcome and remaining obligations.
Mark the task completed only after its acceptance criteria and required
release and cleanup obligations are verified. When the task merged or was
abandoned, close it. The record is
{"task", "outcome": "merged" | "abandoned", "evidence"}:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" close-task --record <close.json>task_closed event JSON. Repeating the
same closure prints the existing event. Proceed.A task still in progress (a consultation or a fix round) is not closed; it continues to Step 17 open.
Preserve the ledger for resume and standup. Preserve retrospective notes and link them from the ledger. Save current progress through the attention owner and curate the round's lessons. Report outstanding attention first, followed by the outcome and saved paths. Proceed immediately to Step 17.
Stow the handoff under the working-memory reference, with a structured gap
for anything the stow could not capture. The stow's unresolved_work names
the continuation step, the step the round's outcome routes to:
foreman-queue seats remaining — Step 5Handle every pending supervision event, and save supervision-hold kind
handoff covering each active enrollment. Then schedule the reset:
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" foreman-reset --stow <stow-id> \
[--state <state-file>] [--config <config-file>] [--herdr-bin <path>]Pass the same --state, --config and --herdr-bin the stow was recorded
under.
pane_id, stow, deliverer pid
and log
replayed: true means this exact reset was already scheduled, and
nothing new startederror field:
reset_ended — this stow's one reset attempt failed or was
interrupted, including a deliverer that could not start
foreman-reset for this stowdetails.resume_prompt and
details.recordreset_record_newer — a newer build wrote the reset record
reset_record_unusable — the reset record is a link, unreadable or
malformed
details.recorderror — a refused precondition: an unready stow, the wrong
pane, supervision work still unheld, or an unreadable stow or state
foreman-resetcatch-up surfaces that outcome ahead of the attention queue
(foreman_resets)log named at exit 0
reset_ended there means the row shows failed or interruptedforeman-reset-reconcile command
catch-up prints for that row, before any recoveryResume Route — the next context follows one route:
foreman-queueforeman-queue lists seats only. Gating, release and closure return through
the continuation step, never through the queue.
Finish here.
For the daily standup, use
Skill(skill: "herdr-standup").
.tessl-plugin
hooks
rules
skills
adopt-fork-pr
herdr-foreman
classify
foreman
references
templates
tests
herdr-standup
migrate-to-plugin
onboard-repo
release
references
tests