跳到主要内容
知仓学习社ZHICANG

agy-native

Run a supplied task in AGY Antigravity and collect its result. Use when: the caller selects AGY; never a fallback for native coding.

不碰外部(只输出文字)无严重或高危命中hashgraph-online/awesome-codex-plugins

它会碰到什么

扫了多少3 个文本文件,3 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

AGY Native

Use AGY only when the caller explicitly selects that runtime. Discover its live

command surface with agy --help (and agy models for the current model set)

before acting, and scope every session to the supplied workspace and packet.

Discovering the live command surface before acting works because AGY's CLI

changes faster than any skill text: a remembered flag is a guess, while a

freshly listed one is evidence.

Permission posture (disclose it; never assume it)

The posture a run gets is chosen by flags, so name it explicitly:

  • Default agy runs interactively and prompts for each tool permission.
  • --dangerously-skip-permissions auto-approves every tool call — use it only

when the packet's declared effects and the caller's authorization cover that

blast radius.

  • --sandbox restricts the session's terminal access.
  • Print mode (agy -p / --print) is the sanctioned headless path and carries

a built-in --print-timeout (default 5m); a run that exceeds it is killed and

reported as timed out, not as a result.

A reader who sets none of these gets AGY's interactive default, not a scoped

run. Match the posture to the declared effects and disclose which one was used.

When AGY is unavailable

If agy is not installed or its command surface cannot be discovered, report the

absence as a disclosed fact and stop. Do not fall back to another runtime, do not

guess a command surface, and never route through claude -p.

Named failure mode — wrapper drift: invoking AGY through remembered

syntax that silently changed, producing runs that look scoped but are not.

Anti-pattern: reusing one AGY session for both author and validator roles

because starting a second session is slower. Corrective: keep the identities

distinct; a shared session forfeits the fresh-judgment guarantee that makes

the validator's evidence usable.

  • Keep author and validator sessions distinct when AGY supplies both roles.
  • Persist the runtime conversation/context identity and artifact references.
  • Validators remain read-only and hand judgment to Validate; they do not write

the core verdict directly.

  • AGY plugin, memory, permission, retry, and session state remain substrate facts

and never become AgentOps phase, queue, or completion state.

  • Never invoke claude -p through an AGY wrapper.

Return evidence to the caller and stop. Installation, plugin mutation, and

recurring scheduling require separate explicit authorization.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。