跳到主要内容
知仓学习社ZHICANG

agent-hierarchy

Designs orchestrator-and-subagent hierarchies for a repository — splitting agents by exclusive write surface, pairing every producer with an indepen…

执行命令读凭据读文件严重 0 · 高危 4cbrock84/headcount

它会碰到什么

扫了多少5 个文本文件,50 KB
它会碰到什么执行命令读凭据读文件
命中总数7 处
命中统计严重 0 · 高 4 · 中 3 · 低 0
逐条看命中(4 条严重或高危)
  • scripts/agent-guard.mjs:19exec-spawn
    import { execFileSync } from 'node:child_process';
  • scripts/agent-guard.mjs:24cred-envread
    const MAP_FILE = process.env.AGENT_MAP ?? 'docs/AGENT-SURFACES.md';
  • scripts/agent-guard.mjs:25cred-envread
    const AGENT_DIR = process.env.AGENT_DIR ?? '.claude/agents';
  • scripts/agent-guard.mjs:26cred-envread
    const DECISION_LOG = process.env.AGENT_DECISIONS ?? 'docs/DECISION-LOG.md';

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Agent hierarchy

A method for standing up an orchestrator → specialist-subagent hierarchy, extracted from a

working implementation of ~24 agents over a 1,500-file monorepo, machine-checked on every PR.

The whole method in one paragraph

Split agents by write surface, not by topic. Two classes only: builders, which edit

inside exactly one exclusive surface and never commit, and reviewers, which are permanently

read-only and can always run in parallel. The orchestrator — the main chat — is the sole

committer. Write the surface map before any charters, keep it in one Markdown file, and

enforce it with a script that runs in CI. Each row also carries an authorityautonomous,

proposes, or escalates — which answers the separate question of whether that agent's work may

land without a decision; most rows are autonomous, and gating everything makes the gate

meaningless. Producer and auditor are never the same agent. For

each class of fact, exactly one file owns it and everyone else derives.

Why topic splits fail

"One agent on SEO, one on UI" is the intuitive split and it breaks immediately: both end up

editing tokens.css. Neither is wrong, and neither can be held responsible. A surface split

has no such overlap by construction — which is exactly what makes it checkable.

Order of operations

Do not start writing charters early; the order is the method.

  1. Inventory the real treegit ls-files | sed 's|/[^/]*$||' | sort -u. Report what is

actually there before proposing anything.

  1. Propose the roster — the smallest set where no two agents share a file. Each needs an

id, a class, a one-line remit, and its exact globs. An agent whose surface cannot be stated

in globs is not an agent; fold it in.

  1. Write the surface map — one Markdown file, one row per agent.
  2. Wire the guardscripts/agent-guard.mjs check proves the map is coherent (no path

claimed twice, no path unowned); agent-guard.mjs diff <agent> proves a given diff obeyed

it. Both are needed: once the orchestrator commits, the authorship that diff checks is

gone, so it has to run while the work is still attributable.

  1. Write charters last, in the format in the playbook: why the agent exists, what it must

never do, the verification its surface implies, and a six-section return contract.

Rules that carry a failure behind them

  • Producer and auditor are never the same agent. An agent that reviews its own output

reliably approves it.

  • The orchestrator is not one of the two classes. It is the sole committer, and giving it

a surface makes it a builder that can also merge.

  • One file owns each class of fact. Everything else derives from it, or the two copies

diverge and nobody notices which is stale.

  • Never remove a shared-core export because it looks unused. You cannot see the consumers

from inside the core. Deprecate, announce, then remove.

This repository's own log

docs/DECISION-LOG.md is the live instance of the decision log described in the playbook. When a

decision is raised, assign it the next number immediately — before it is answered — and give it

lettered options with an explicit recommendation. Never renumber, never reuse a number, and record

resolutions in place rather than deleting them.

Never

  • Add an agent before the surface it will own exists. The map comes first, the agent second.
  • Let two agents hold a write claim on the same path. Overlap resolves itself as a race.
  • Hand-edit a generated artifact instead of the source it derives from.
  • Skip the guard because the change is small. Small changes are how surfaces drift.

References

  • references/playbook.md — the full 415-line playbook: surface splitting, the guard, the

registry, the decision log, anti-patterns with their failure modes, sizing, multi-repo and

shared-core layouts, the charter format, and a day-one checklist.

  • references/starter-rosters.md — concrete rosters for a mobile-app portfolio, a game

portfolio, and a shared core, with producer/auditor pairings.

  • references/bootstrap-prompt.md — a fill-in-the-blanks prompt for standing this up in a

fresh session against a target repo.

  • scripts/agent-guard.mjs — the executable guard. No dependencies, Node 18+.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。