跳到主要内容
知仓学习社ZHICANG

agent-spec

Specify an autonomous or tool-using AI agent before building it. Use when asked to design an AI agent, define an agent's tools and guardrails, scope…

不碰外部(只输出文字)无严重或高危命中mohitagw15856/pm-claude-skills

它会碰到什么

扫了多少1 个文本文件,4 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Agent Spec Skill

An agent is a model plus tools plus a loop — and the danger lives in the tools and the loop, not the

model. This skill specifies an agent so its authority is explicit: what it can do, what needs a human

yes, and what happens when it's wrong. Scope and guardrails first; cleverness second.

Required Inputs

Ask for these only if they aren't already provided:

  • Job to be done — the outcome the agent owns, and the boundary of its authority.
  • Tools/actions — what it can call (read APIs, write actions, code execution), and which are irreversible.
  • Autonomy level — fully autonomous, propose-then-approve, or co-pilot.
  • Risk surface — what's the worst thing a wrong action could do (spend money, send a message, delete data)?
  • Success definition & escalation — how "done" is judged, and when it must hand off to a human.

Output Format

Agent Spec: [name]

1. Goal & scope — the job in one sentence; explicit non-goals and authority limits.

2. Tools / actions — a table; mark each action's reversibility and required permission.

| Tool | Purpose | Reversible? | Gate |

|---|---|---|---|

| search_kb | read context | yes | none |

| send_email | notify | no | human approval |

3. Control loop — plan → act → observe → reflect; the stopping condition; and a hard max-steps / max-cost budget so it can't loop forever.

4. Guardrails & approval gates — which actions require a human yes (default: anything irreversible, outbound, or spending), input/output validation, and allow/deny lists. Pair irreversible actions with a dry-run preview (see [action-runner](../action-runner/SKILL.md)).

5. Memory & state — what it remembers within a task vs. across tasks, and where (link a [professional-brain](../professional-brain/SKILL.md) for durable memory).

6. Escalation & handoff — the triggers that stop the agent and route to a human (low confidence, repeated failure, out-of-scope request, high-risk action).

7. Evaluation — task success rate, action correctness, and safety (false-action rate). Define with an [ai-eval-plan](../ai-eval-plan/SKILL.md), and test on adversarial/trap tasks.

8. Failure handling — timeouts, tool errors, hallucinated tool calls, and the safe default (stop and ask, never guess on a high-risk action).

Quality Checks

  • [ ] Every tool is marked reversible/irreversible, and every irreversible action has a human gate
  • [ ] There is a hard max-steps and max-cost budget — the loop cannot run unbounded
  • [ ] Escalation triggers are explicit (confidence, repeated failure, out-of-scope, high-risk)
  • [ ] The safe default on uncertainty is "stop and ask", not "guess and act"
  • [ ] Evaluation includes a safety metric (wrong/unauthorised actions), not just task success
  • [ ] Non-goals and authority limits are stated, not implied

Anti-Patterns

  • [ ] Do not give an agent irreversible actions without an approval gate — autonomy and irreversibility together is how agents cause real damage
  • [ ] Do not omit a step/cost budget — an agent that can loop is an agent that can rack up cost or thrash forever
  • [ ] Do not measure only task success — an agent that completes the task by taking a wrong action has failed
  • [ ] Do not let the agent invent tool calls or arguments — validate against the schema and fail safe
  • [ ] Do not skip the "what's the worst case" analysis — the risk surface determines how many guardrails you need

Based On

Tool-using / agentic design practice — bounded control loops, least-privilege tools, human-in-the-loop approval, and safety evaluation.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

同名技能的其他版本

有 3 个不同仓库或目录里都有叫 agent-spec 的技能。它们内容并不相同,别混用: