cline-delegate
>-
它会碰到什么
逐条看命中(10 条严重或高危)
- 高
scripts/relay.mjs:33exec-shell-true* with shell:true. Provider and model values therefore accept only shell-safe
- 高
scripts/relay.mjs:75exec-spawnimport { spawn, execFileSync, spawnSync } from "node:child_process"; - 高
scripts/relay.mjs:75exec-spawnimport { spawn, execFileSync, spawnSync } from "node:child_process"; - 高
scripts/relay.mjs:96exec-shell-true// --model and --provider values reach a shell on win32 (shell:true for the .cmd
- 高
scripts/relay.mjs:108exec-spawnconst r = spawnSync(
- 高
scripts/relay.mjs:301exec-shell-true// shell:true resolves cline.cmd, but a missing command is only an exit 1 from
- 高
scripts/relay.mjs:304cred-envreadconst wherePath = join(process.env.SystemRoot || process.env.WINDIR || "C:\\Windows", "System32", "where.exe");
- 高
scripts/relay.mjs:304cred-envreadconst wherePath = join(process.env.SystemRoot || process.env.WINDIR || "C:\\Windows", "System32", "where.exe");
- 高
scripts/relay.mjs:314exec-shell-true? await runProbe("cline --version", [], { shell: true, detached: false }) - 高
scripts/relay.mjs:549exec-shell-true// shell:true on win32 so the cline.cmd shim resolves. Safe on both
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Cline Delegate
You are the orchestrator. Delegate a bounded coding task to a separate implementer - the Cline
coding agent CLI - then review what it produced and land it yourself. You write the brief and own
the judgment; the implementer makes changes in its own session in a clean working tree; you verify
and commit.
The loop needs only a shell command and file access, so any comparable orchestrator can drive it.
When NOT to use this
- The task is small enough to do inline; delegation overhead is not worth it.
- The
clineCLI is not installed or authenticated. - You require the relay to configure a sandbox. Cline exposes sandbox controls, but this relay
leaves them to the CLI environment; use --plan when the run must be read-only.
Prerequisites (check once)
- Install
cline(npm or bundled binary; the relay probescline --version). - Authenticate: run
cline auth(interactive sign-in), or configure
ANTHROPIC_API_KEY / an OpenAI-compatible base URL.
- Confirm
cline --versionsucceeds. - Work in, or point
--cdat, the target git repository.
Choose the model (optional)
Cline picks a default model. To choose another, pass the separate --model <id> or --provider <name>
(e.g. anthropic, openai-native, openrouter). The relay accepts letters, digits,
and . _ : / - only (the value reaches a shell on Windows).
The loop
Run these five steps per task. Steps 1, 4, and 5 require judgment; 2 and 3 are mechanical.
1. Write a brief
Cline sees only the text you send. It cannot read your conversation: the brief must stand alone
with the goal, current state, what to change, what to leave untouched, the project's real
gates, and a report contract. Keep each brief to a single task. Write it to a file and pass it as
the relay's --brief. See [references/writing-the-brief.md](references/writing-the-brief.md).
2. Dispatch
Use the bundled relay. It runs cline --json -v, streams the brief on stdin behind a fixed
positional instruction, captures the JSON event stream, and writes result.json.
node "<skill-dir>/scripts/relay.mjs" --brief brief.txt --cd /path/to/repo
# choose a model / provider: add --model <id> --provider <name>
# read-only planning pass: add --plan (forces --auto-approve false)
# deny approval-required tools: add --auto-approve false
# hard time limit (watchdog): add --timeout 2h (the 30m default suits brief runs; most implementation briefs should be 1-2h)
# see all options: node .../relay.mjs --help
The child's cwd pins the workspace. The relay writes artifacts under the system temp dir by
default and never commits. See [references/dispatch-and-poll.md](references/dispatch-and-poll.md).
3. Wait for completion
The relay blocks until cline finishes. Run it with the orchestrator's background-command
facility, or background it in the shell and poll for result.json. A pre-run usage error exits 2
and writes no result; a missing cline exits 127 and writes status: "cline_unavailable".
Completion means the process exited and result.json exists - trust process state and the
working tree, not the progress display. Cline's final message is the finalMessage field of
result.json.
4. Review - do not trust the self-report
- Re-run the project's gates yourself.
- Read the diff against the brief, starting with
touchedFiles. - Run relevant guard skills if installed.
See [references/review-and-land.md](references/review-and-land.md).
5. Land it
If the work is good, commit it. The relay never commits - the diff and result.json are the
record; run git status and git diff first to confirm exactly what changed. If the group has a
PR flow, make the commit and push a branch; let human review happen. If the diff is wrong or
incomplete, re-dispatch a corrected brief in a fresh run and review again.
Autonomy and permissions
The relay explicitly passes Cline's --auto-approve, defaulting to true in act mode. Cline
plan mode can request a switch to act mode, so --plan forces --auto-approve false; the relay
rejects --plan --auto-approve true. That pair is the read-only gate. Cline also exposes sandbox
through --data-dir / CLINE_SANDBOX, but the relay does not configure or override it. Plan-first
for anything risky, then review the plan before a separate act-mode dispatch. Malformed or malicious
briefs remain dangerous in act mode because commands run as the current user.
Authorization model
Delegation is something the human opts into. Once briefed, cline works as a tool you approved use
of. The boundary is: do not accept conclusions from the self-report; verify everything on
disk. For anything touching credentials, production data, or irreversible operations, stop and ask
the human first instead of encoding it in a brief.
References
- [references/writing-the-brief.md](references/writing-the-brief.md) - structure, scope, gates,
brief delivery.
- [references/dispatch-and-poll.md](references/dispatch-and-poll.md) - flags, artifacts,
result.json, and failure recovery.
- [references/review-and-land.md](references/review-and-land.md) - what to verify before calling
the diff done, at the end of a run.
- [references/multi-task-queues.md](references/multi-task-queues.md) - sequential queues,
constraint carry-forward, progress tracking, and the final coherence pass.
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。