agy-native
GitHub指定使用 AGY 运行时处理任务,强调事前通过 CLI 发现命令表面以确保准确性。严格区分作者与验证器角色,禁止隐式回退或复用会话,确保权限隔离与安全审计。
Trigger Scenarios
Install
npx skills add boshu2/agentops --skill agy-native -g -y
SKILL.md
Frontmatter
{
"name": "agy-native",
"consumes": [
"explicit-packet"
],
"metadata": {
"tier": "cross-vendor",
"effects": [
"start_agy_session"
],
"disposition": "keep_optional_adapter",
"capabilities": [
"dispatch_explicit_packet",
"provide_fresh_context"
],
"dependencies": [],
"canonical_status": "canonical"
},
"produces": [
"agy-run-evidence"
],
"practices": [
"team-topologies",
"design-by-contract"
],
"context_rel": [
{
"kind": "separate-ways",
"with": "codex-exec"
}
],
"description": "Use an explicitly selected AGY runtime for one provided packet or fresh validator context. Triggers: \"agy\", \"antigravity\", \"AGY evidence\".",
"hexagonal_role": "driving-adapter",
"user-invocable": false,
"output_contract": "AGY runtime evidence",
"skill_api_version": 1
}
AGY Native
Use AGY only when the caller explicitly selects that runtime. Discover its live
command surface with agy --help (and agy models for the current model set)
before acting, and scope every session to the supplied workspace and packet.
Discovering the live command surface before acting works because AGY's CLI changes faster than any skill text: a remembered flag is a guess, while a freshly listed one is evidence.
Permission posture (disclose it; never assume it)
The posture a run gets is chosen by flags, so name it explicitly:
- Default
agyruns interactively and prompts for each tool permission. --dangerously-skip-permissionsauto-approves every tool call — use it only when the packet's declared effects and the caller's authorization cover that blast radius.--sandboxrestricts the session's terminal access.- Print mode (
agy -p/--print) is the sanctioned headless path and carries a built-in--print-timeout(default 5m); a run that exceeds it is killed and reported as timed out, not as a result.
A reader who sets none of these gets AGY's interactive default, not a scoped run. Match the posture to the declared effects and disclose which one was used.
When AGY is unavailable
If agy is not installed or its command surface cannot be discovered, report the
absence as a disclosed fact and stop. Do not fall back to another runtime, do not
guess a command surface, and never route through claude -p.
Named failure mode — wrapper drift: invoking AGY through remembered syntax that silently changed, producing runs that look scoped but are not.
Anti-pattern: reusing one AGY session for both author and validator roles because starting a second session is slower. Corrective: keep the identities distinct; a shared session forfeits the fresh-judgment guarantee that makes the validator's evidence usable.
- Keep author and validator sessions distinct when AGY supplies both roles.
- Persist the runtime conversation/context identity and artifact references.
- Validators remain read-only and hand judgment to Validate; they do not write the core verdict directly.
- AGY plugin, memory, permission, retry, and session state remain substrate facts and never become AgentOps phase, queue, or completion state.
- Never invoke
claude -pthrough an AGY wrapper.
Return evidence to the caller and stop. Installation, plugin mutation, and recurring scheduling require separate explicit authorization.
Version History
-
7b07a7d
Current 2026-08-19 21:58
新增 AGY 运行时权限姿态说明(交互、沙箱、无头模式)及不可用时的失败处理规范;明确命令发现流程与角色隔离要求。
- 3f402e5 2026-07-24 22:06


