Use for Agently runtime extensions: AgentExecution plugins and final review/artifact policies, Actions and MCP, Shell/BashExecutor and PowerShell permissions, ExecutionResource lifecycle, TaskWorkspace, RecordStore, auto_func and KeyWaiter, FastAPIHelper, or optional DevTools observation.
72
89%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Use this Skill after the request or workflow owner is known. Use
agently-triggerflow when branching, concurrency, pause/resume, retry, or
multi-stage progression must remain visible in the execution graph. Use
agently-stage only for process-local lifetime and sync/async bridging.
auto_func, KeyWaiter, FastAPIHelper, SSE, or WebSocket exposure:
helpers-and-services.md.| Owner | Responsibility |
|---|---|
ActionRuntime | Model-callable operation schema, planning/dispatch, policy, and Action results. |
ExecutionResource | Lifecycle of live clients, sandboxes, processes, browsers, databases, and MCP sessions. |
TaskWorkspace | One task's contained files, generated artifacts, readback, identity, and promotion. |
RecordStore | Durable records, links, retrieval, RuntimeEvents, checkpoints, snapshots, leases, and durable refs. |
TaskContext / ContextReader | Task information bindings and consumer-bound progressive disclosure. |
SkillLibrary | Installed immutable Skill revisions and resource reads; never execution permission. |
AgentExecution | One run's replaceable producer, task-scoped bindings, context, control, terminal policies, result and streams. |
Do not collapse these into a generic Workspace or runtime manager. File space is not record storage; records are not model-hot context; a Skill package is not an executor or permission grant.
@agent.action_func and agent.use_actions(...). The tool_* and
use_tool(s) names are compatibility surfaces.agent.create_execution() for multi-statement setup or an
unrelated new request. A completed revision is immutable; explicit producer
rework advances the same execution while old result readers retain their
revision. See the execution contract above.request, plan, long_content, or long_task through
create_execution(...). Final .validate(handler) is a hard output gate;
.review(..., on_fail="warn" | "block") is a soft assessment with an explicit
terminal policy. Review does not silently rework; rework belongs to the
producer. .artifact(...) requires verified TaskWorkspace readback.agent.create_task(...) only when the model should own bounded planning,
execution evidence, verification, and replan. create_task_loop(...) is a
compatibility spelling, not the recommended surface. Stable application
orchestration belongs to TriggerFlow.Reject unknown Skill revisions, resource refs, Action ids, selection keys, context block keys, recovery providers, and external-resume identities. Offer models one short host-issued selection key, validate it against the offered set, then reconstruct canonical records in host code.
Do not use keyword or regex matching as the semantic owner for intent, Skill relevance, route choice, evidence usefulness, or output quality. Do not fake model-owned success with canned outputs or deterministic business mappings.
b281fe2
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.