ralplan
GitHubRalplan是共识规划技能,协调Planner、Architect和Critic角色生成执行计划并记录审查证据。支持交互与深思模式,用于高难度任务的决策流程管理。
Trigger Scenarios
Install
npx skills add Yeachan-Heo/oh-my-codex --skill ralplan -g -y
SKILL.md
Frontmatter
{
"name": "ralplan",
"description": "Consensus planning stage for Planner -> Architect -> Critic handoff to $ultragoal"
}
Ralplan (Consensus Planning Alias)
Ralplan is the canonical consensus-planning stage used by Autopilot between $deep-interview and $ultragoal. It drives Planner, Architect, and Critic planning and records their review lifecycle with RALPLAN-DR structured deliberation (short mode by default, deliberate mode for high-risk work). Local lifecycle evidence is not host-issued security authority, but ordinary progression to Ultragoal must remain reachable after the execution-ready plan and sequential review evidence are durable; missing host provenance must not terminalize Ralplan or block cancel, clear, or recovery.
Usage
$ralplan "task description"
Flags
--interactive: Enables user prompts at key decision points (draft review in step 2 and final approval in step 6). Without this flag the workflow runs fully automated — Planner → Architect → Critic loop — and outputs the final plan without asking for confirmation.--deliberate: Forces deliberate mode for high-risk work. Adds pre-mortem (3 scenarios) and expanded test planning (unit/integration/e2e/observability). Without this flag, deliberate mode can still auto-enable when the request explicitly signals high risk (auth/security, migrations, destructive changes, production incidents, compliance/PII, public API breakage).
Ontology-heavy review
For requirements semantics, taxonomy, prompt/spec design, policy distinctions, or category-risk architecture, cite the architect role agent's read-only review as advisory evidence. Its findings can inform the plan or follow-up evidence when explicitly used, but $ralplan itself records Architect→Critic lifecycle evidence only, and advisory review is never a durable execution authorization.
Usage with interactive mode
$ralplan --interactive "task description"
Behavior
GPT-5.6 Guidance Alignment
Use the shared workflow guidance pattern: outcome-first framing, concise visible updates for multi-step planning, local overrides for the active workflow branch, evidence-backed planning and validation expectations, explicit stop rules, right-sized implementation/PRD shape, and automatic continuation for safe reversible steps. Ask only for material, destructive, credentialed, external-production, or preference-dependent branches.
This skill runs its own consensus runtime; it does not delegate to a nonexistent Plan consensus mode:
omx ralplan run --task <arguments> [--session <id>]
The consensus workflow:
- Planner creates an adaptive plan (right-sized to task scope; do not default to exactly five steps) and a compact RALPLAN-DR summary before review. Current
[main]vs[planner]behavior: standalone$ralplanmay be authored by the active main planning lane unless the caller/runtime supplies a dedicated planner routing record; inside$autopilot, state fieldplanning_routing.owner:"planner"means the initial Planner draft/decomposition must use dedicated[planner]. Set.omx-config.jsonagentModels.plannerto opt into a specific planner model and force dedicated planner ownership for complex Autopilot planning even when[main]is not cheap/mini. The RALPLAN-DR summary includes:- Principles (3-5)
- Decision Drivers (top 3)
- Viable Options (>=2) with bounded pros/cons
- If only one viable option remains, explicit invalidation rationale for alternatives
- Deliberate mode only: pre-mortem (3 scenarios) + expanded test plan (unit/integration/e2e/observability)
- User feedback (--interactive only): If
--interactiveis set, use the structured question UI (omx questionin attached tmux; native structured input outside tmux when available) to present the draft plan plus the Principles / Drivers / Options summary before review (Proceed to review / Request changes / Skip review). Otherwise, automatically proceed to review. Native role-routing preflight: Keyword routing may already have selected Ralplan, but it is not authority. Runomx ralplan preflight --jsononly when the native task surface reportsrole_routing_unavailableand this workflow attempts adapted Ralplan Planner, Architect, or Critic authority, adapted role-intent, or adapted consensus authority. Onunsupported_documented_leader_proof, stop before that adapted authority and use a Codex surface with documented root proof or a reviewed alternative workflow. Do not infer root identity fromsession_id, undocumentedthread_id, session/pointer/transcript/cwd state, absence of child data, or a prompt label. Ordinary native planning, lifecycle, state, status, health, HUD, runtime, setup, install, sync, and unrelated delegation are outside this preflight boundary and remain governed by existing controls.
Native role-routing rule: When the native surface exposes agent_type role routing, set agent_type to an installed OMX role and never omit it for OMX work. When it does not (role_routing_unavailable), do not fabricate agent_type. On the exact reviewed Codex releases 0.144.5, 0.145.0, 0.146.1, and 0.148.0-alpha.5, adapted Ralplan Planner, Architect, Critic, role-intent, and consensus authority are unavailable because they lack documented root proof; every other version remains unknown and fails closed. Do not silently weaken routing with a prompt role label or inferred carrier. Use a Codex surface with documented root proof or a reviewed alternative workflow for that authority. A direct omx ralplan role-intent write attempt is denied with machine reason unsupported_documented_leader_proof.
- Architect reviews for architectural soundness and must provide the strongest steelman antithesis, at least one real tradeoff tension, and (when possible) synthesis — await completion before step 4. Launch this as a subsequent role-specific
Architectsubagent and pass the full task statement, context snapshot, PRD/test-spec paths, and relevant prior findings; do not substitute an unvalidated reviewer identity or a short improvised reviewer prompt. In deliberate mode, Architect should explicitly flag principle violations. - Critic evaluates against quality criteria — run only after step 3 completes. Launch this as a subsequent role-specific
Criticsubagent with the full task statement, context snapshot, PRD/test-spec paths, and the completed Architect review; do not ask the Architect subagent to perform the Critic gate and do not substitute an unvalidated reviewer identity or a short improvised reviewer prompt. Critic must enforce principle-option consistency, fair alternatives, risk mitigation clarity, testable acceptance criteria, and concrete verification steps. In deliberate mode, Critic must reject missing/weak pre-mortem or expanded test plan. - Re-review loop (max 5 iterations): Any non-
APPROVECritic verdict (ITERATEorREJECT) MUST run the same full closed loop: a. Collect Architect and Critic feedback b. Revise the plan with Planner c. Return to Architect review d. Return to Critic evaluation e. Repeat this loop until Critic returnsAPPROVEor 5 iterations are reached f. If 5 iterations are reached withoutAPPROVE, present the best version to the user - On Critic approval, persist the execution-ready planning artifacts and sequential Architect→Critic evidence. In standalone interactive Ralplan, present the requested future execution lane. Inside Autopilot, the existing explicit
$autopilotinvocation authorizes the supervised transition to its defining next stage,$ultragoal; persist an Autopilot-ownedralplan_execution_handoffbound to the same session and review cycle. - Record
ralplan_execution_handoffwith{authorized: true, reason, authorized_at, session_id, review_cycle, source: "autopilot"|"user"}.source:"autopilot"is valid only for a supervised active Autopilot run whose current phase isralplan; it does not claim host-consensus authority. - Transition to
$ultragoalafter the durable plan, sequential approvals, and bound execution handoff exist. Do not implement directly inside Ralplan.
Important: Steps 3 and 4 MUST run sequentially as role-specific subagents. Do NOT issue both agent calls in the same parallel batch. Always await the subsequent
Architectresult before invoking the subsequentCritic; their completed approvals establish local lifecycle evidence only and cannot satisfy the durable execution gate.
Planning/Execution Boundary
$ralplan is a planning mode. While ralplan is active and no explicit execution handoff is active, implementation-focused write tools are out of scope. Ralplan may inspect the repository and may write only planning artifacts such as .omx/context/, .omx/plans/, .omx/specs/, and required .omx/state/ records.
The canonical flow is:
$ralplan -> local Architect→Critic lifecycle evidence -> bound execution handoff -> $ultragoal
Before any execution lane begins, ralplan must emit terminal planning state (complete, paused, failed, or waiting for input) and the durable handoff record below. Do not continue from consensus planning into direct code edits in the same ralplan session.
Durable Consensus Handoff Contract
Ralplan is not complete, skippable, or ready for execution merely because .omx/plans/prd-*.md and .omx/plans/test-spec-*.md exist. Those files are planning artifacts, not consensus evidence.
Before any Autopilot, Pipeline, Ultragoal, Team, Ralph, or implementation handoff, persist a durable handoff record that distinguishes:
planning_artifacts: PRD/test-spec paths.ralplan_architect_review: the completed Architect review with an approving verdict.ralplan_critic_review: the completed Critic review with an approving verdict, recorded only after the Architect review.ralplan_execution_handoff: persist{authorized: true, reason: "<rationale>", authorized_at: "<ISO timestamp>", session_id: "<current session>", review_cycle: <matching lifecycle cycle>, source: "autopilot"|"user"}. Autopilot may issue this only for its own supervisedralplanphase; standalone Ralplan usessource:"user".ralplan_consensus_gate.completerecords lifecycle completion after the sequential Architect and Critic approvals. It is not a host-security claim. Locally authored JSON/env/prompt/tracker/transcript/receipt-shaped evidence must never be described as host-issued authority.
If Architect is missing/blocked, keep the workflow in Architect review or report that blocker. If Critic is missing/blocked/non-approving, keep the workflow in Critic/re-review or report the max-iteration outcome. After both reviews approve, execution begins only when the matching ralplan_execution_handoff is durable. Existing plan/test-spec files alone are never permission to skip Ralplan or execute.
Follow the Plan skill's full documentation for consensus mode details.
Goal-Mode Follow-up Suggestions
When a bound ralplan_execution_handoff permits execution, include product-facing goal-mode suggestions alongside the existing Ralph and team options. Record the requested lane and persist the handoff without claiming host-issued authority.
$ultragoal— default goal-mode follow-up for implementation or general goal-oriented follow-up plans that should become durable Codex/OMX goals with sequential completion tracking.$autoresearch— research-project follow-up when the plan centers on a question, literature/reference gathering, evaluator-backed research, or a professor/critic-style research deliverable. ($autoresearch-goalwas retired to a sunset stub in OMX 0.21.)$performance-goal— optimization/performance follow-up when the plan centers on speed, latency, throughput, memory, benchmark, or other measurable performance work.
Keep $team as a first-class execution option and keep $ralph available only as an explicit fallback where appropriate: use Ultragoal as the default durable goal-mode follow-up, Team for coordinated parallel implementation, and Ralph only for intentionally selected persistent single-owner completion/verification pressure. For parallelizable durable-goal delivery, recommend $ultragoal + $team together: Ultragoal remains the leader-owned .omx/ultragoal ledger/Codex-goal wrapper while Team runs parallel lanes and returns checkpoint-ready evidence. Do not present Ralph as the recommended follow-up when durable goal tracking is needed; present Ultragoal as the superseding default, with Team for parallel delivery and Ralph only as an explicit fallback when its narrow persistence loop is specifically desired.
Use the available-agent-types roster to produce explicit role/staffing allocation, reasoning-by-lane guidance, concrete launch hints (including omx team when parallel delivery is justified), and team verification responsibilities for any future receipt-authorized execution path.
Pre-context Intake
Before consensus planning or execution handoff, ensure a grounded context snapshot exists:
- Derive a task slug from the request.
- Reuse the latest relevant snapshot in
.omx/context/{slug}-*.mdwhen available. - If none exists, create
.omx/context/{slug}-{timestamp}.md(UTCYYYYMMDDTHHMMSSZ) with:- task statement
- desired outcome
- known facts/evidence
- constraints
- unknowns/open questions
- likely codebase touchpoints
- If ambiguity remains high, gather brownfield facts first.
omx exploreis deprecated; use normal repository inspection tools/subagents for simple read-only repository lookups andomx sparkshellonly for explicit shell-native read-only evidence. Then run$deep-interview --quick <task>before continuing. - If the plan depends on official docs, version-aware framework guidance, best practices, or external dependency behavior, use
$best-practice-researchas the bounded evidence wrapper and auto-delegateresearcherfor the official/upstream lookup before finalizing the planning handoff so execution does not start from repo-local recall alone. - If a prior
$autoresearchor$autoresearch-goalrun exists, treat its approved artifact as evidence for the plan. Do not include Autoresearch as a final architecture or runtime component unless the user explicitly requested ongoing research automation; otherwise synthesize the evidence into the$ralplanADR, risks, and verification steps.
Do not hand off to execution modes until this intake is complete; if urgency forces progress, explicitly document the risk tradeoffs.
Pre-Execution Gate
Why the Gate Exists
Execution modes (ralph, autopilot, team, ultrawork) spin up heavy multi-agent orchestration. When launched on a vague request like "ralph improve the app", agents have no clear target — they waste cycles on scope discovery that should happen during planning, often delivering partial or misaligned work that requires rework.
The ralplan-first gate intercepts underspecified execution requests and redirects them through the ralplan consensus planning workflow. This ensures:
- Explicit scope: A PRD defines exactly what will be built
- Test specification: Acceptance criteria are testable before code is written
- Consensus: Planner, Architect, and Critic agree on the approach
- No wasted execution: Agents start with a clear, bounded task
Good vs Bad Prompts
Passes the gate (specific enough for direct execution):
ralph fix the null check in src/hooks/bridge.ts:326autopilot implement issue #42team add validation to function processKeywordDetectorralph do:\n1. Add input validation\n2. Write tests\n3. Update READMEultrawork add the user model in src/models/user.ts
Gated — redirected to ralplan (needs scoping first):
ralph fix thisautopilot build the appteam improve performanceralph add authenticationultrawork make it better
Bypass the gate (when you know what you want):
force: ralph refactor the auth module! autopilot optimize everything
When the Gate Does NOT Trigger
The gate auto-passes when it detects any concrete signal. You do not need all of them — one is enough:
| Signal Type | Example prompt | Why it passes |
|---|---|---|
| File path | ralph fix src/hooks/bridge.ts |
References a specific file |
| Issue/PR number | ralph implement #42 |
Has a concrete work item |
| camelCase symbol | ralph fix processKeywordDetector |
Names a specific function |
| PascalCase symbol | ralph update UserModel |
Names a specific class |
| snake_case symbol | team fix user_model |
Names a specific identifier |
| Test runner | ralph npm test && fix failures |
Has an explicit test target |
| Numbered steps | ralph do:\n1. Add X\n2. Test Y |
Structured deliverables |
| Acceptance criteria | ralph add login - acceptance criteria: ... |
Explicit success definition |
| Error reference | ralph fix TypeError in auth |
Specific error to address |
| Code block | ralph add: \``ts ... ```` |
Concrete code provided |
| Escape prefix | force: ralph do it or ! ralph do it |
Explicit user override |
End-to-End Flow Example
- User types:
ralph add user authentication - Gate detects: execution keyword (
ralph) + underspecified prompt (no files, functions, or test spec) - Gate redirects to ralplan with message explaining the redirect
- Ralplan consensus runs:
- Planner creates initial plan (which files, what auth method, what tests)
- Architect reviews for soundness
- Critic validates quality and testability
- Architect and Critic approval completes the planning lifecycle and persists
ralplan_consensus_gate.complete:trueas lifecycle evidence. - Execution begins when the session-bound, review-cycle-bound
ralplan_execution_handoffauthorizes the selected lane. An active supervised Autopilot run authorizes its defining Ultragoal next stage; standalone Ralplan records the user's selected lane.
Troubleshooting
| Issue | Solution |
|---|---|
| Gate fires on a well-specified prompt | Add a file reference, function name, or issue number to anchor the request |
| Want to bypass the gate | Prefix with force: or ! (e.g., force: ralph fix it) |
| Gate does not fire on a vague prompt | The gate only catches prompts with <=15 effective words and no concrete anchors; add more detail or use $ralplan explicitly |
| Redirected to ralplan but want to skip planning | In the ralplan workflow, say "just do it" or "skip planning" to transition directly to execution |
Scenario Examples
Good: The user says continue after the workflow already has a clear next step. Continue the current branch of work instead of restarting or re-asking the same question.
Good: The user changes only the output shape or downstream delivery step (for example make a PR). Preserve earlier non-conflicting workflow constraints and apply the update locally.
Bad: The user says continue, and the workflow restarts discovery or stops before the missing verification/evidence is gathered.
Version History
-
3ad79a8
Current 2026-08-28 17:54
移除对官方主机签发凭证的强制依赖;将Scholastic调整为只读顾问角色;新增GPT-5.6工作流对齐指南及自动续跑逻辑。
- e94437f 2026-08-20 07:19


