Agent Skillstrailofbits/skills › let-fate-decide

let-fate-decide

GitHub

通过塔罗牌抽取为模糊或随意指令提供决策灵感,辅助打破分析瘫痪并生成假设。适用于非精确需求的创意探索,但需结合工程证据验证,不用于安全关键决策。

plugins/let-fate-decide/skills/let-fate-decide/SKILL.md trailofbits/skills

Trigger Scenarios

用户表达犹豫、随意或委托决策(如'let fate decide', 'YOLO', 'whatever') 面临多个合理方案需随机选择时 提示词模糊不清且无明确偏好时

Install

npx skills add trailofbits/skills --skill let-fate-decide -g -y
More Options

Non-standard path

npx skills add https://github.com/trailofbits/skills/tree/main/plugins/let-fate-decide/skills/let-fate-decide -g -y

Use without installing

npx skills use trailofbits/skills@let-fate-decide

指定 Agent (Claude Code)

npx skills add trailofbits/skills --skill let-fate-decide -a claude-code -g -y

安装 repo 全部 skill

npx skills add trailofbits/skills --all -g -y

预览 repo 内 skill

npx skills add trailofbits/skills --list

SKILL.md

Frontmatter
{
    "name": "let-fate-decide",
    "description": "Draws the 12 Houses of the Zodiac Tarot spread to inject entropy into planning when prompts are vague, ambiguous, or casually delegated. Interprets the spread to guide next steps. Use when the user says 'let fate decide', 'YOLO', 'whatever', 'idk', or other nonchalant phrases, makes Yu-Gi-Oh references, or when you are about to arbitrarily pick between multiple reasonable approaches. Prefer over asking clarifying questions when the user's tone is casual or playful rather than precision-seeking.",
    "allowed-tools": "Bash Read Grep Glob"
}

Let Fate Decide

When the path forward is unclear, let the cards speak.

Quick Start

  1. Run the drawing script:

    uv run --no-config {baseDir}/scripts/draw_cards.py
    
  2. The script outputs JSON for the default 12 Houses of the Zodiac spread: 12 houses, each with 1 Major Arcana card and 2 Minor Arcana cards. Each house and card includes a file path relative to {baseDir}/

  3. Read each house file and each card's meaning file to understand the draw. For faster reads, use --content to include house and card text directly in the JSON:

    uv run --no-config {baseDir}/scripts/draw_cards.py --content
    
  4. Interpret the spread using the guide at {baseDir}/references/INTERPRETATION_GUIDE.md

  5. When the task belongs to a specialized technical workflow, use {baseDir}/references/TECHNICAL_CONTEXT_LENSES.md to translate the reading into an audit, verification, domain, failure-class, or stakeholder lens

  6. Apply the interpretation to the task at hand

When to Use

  • Vague prompts: The user's request is ambiguous and multiple reasonable approaches exist
  • Explicit invocations: "I'm feeling lucky", "let fate decide", "dealer's choice", "surprise me", "whatever you think", "YOLO"
  • Casual delegation: "whatever", "up to you", "your call", "idk", "just do something", "wing it", "I trust you", "doesn't matter", "do what you want", "I don't care", "any approach works", "you pick"
  • Yu-Gi-Oh energy: "Heart of the cards", "I believe in the heart of the cards", "you've activated my trap card", "it's time to duel"
  • Shrug-like brevity: Very short prompts that fully delegate the decision without expressing a preference
  • Redraw requests: "Try again" or "draw again" when no actual system changes occurred (this means draw new cards, not re-run the same approach)
  • Tie-breaking: When you are about to arbitrarily pick between 2+ valid approaches, draw cards instead of silently choosing one

When NOT to Use

  • The user has given clear, specific instructions
  • The task has a single obvious correct approach
  • As the deciding authority for safety-critical work (security, data integrity, production deployments, release approval, incident response)
  • The user explicitly asks you NOT to use Tarot
  • The user's tone is precision-seeking rather than casual -- ask clarifying questions instead to gather actual requirements

Security and Correctness Use

This skill may be used inside a security, audit, or correctness pipeline as a creative lens for discovery: choosing which angle to inspect next, breaking analysis paralysis, generating hypotheses, or surfacing blind spots.

It is never sufficient by itself. In security and correctness contexts, the reading must be followed by ordinary engineering evidence: source review, tests, proofs, traces, reproduction steps, exploitability analysis, or other domain-appropriate verification. Do not treat a favorable card as permission to ship, suppress a finding, skip validation, or overrule a concrete risk.

How It Works

The Draw

The script uses secrets for cryptographic randomness:

  1. Builds separate Major Arcana (22 cards) and Minor Arcana (56 cards) decks
  2. Performs Fisher-Yates shuffles via secrets.randbelow() (no modulo bias)
  3. Deals the default 12 Houses of the Zodiac spread
  4. Each house receives 1 Major Arcana card followed by 2 Minor Arcana cards
  5. Each of the 36 cards independently has a 50% chance of being reversed

The default spread records a conservative unordered-card entropy budget exceeding 100 bits: roughly log2(C(22,12)) bits from Major Arcana selection, log2(C(56,24)) bits from Minor Arcana selection (assuming secrets.randbelow() is cryptographically secure), plus 36 reversal bits. The exact values are computed and reported in the JSON output under entropy_bits. The actual ordered assignment of cards to houses contains more entropy.

The Spread

The default spread is 12 Houses of the Zodiac:

House Represents Question It Answers
1 Self How should this work begin?
2 Resources What values, assets, or constraints matter?
3 Communication What needs to be clarified or connected?
4 Foundations What context or dependency anchors the task?
5 Creativity Where should experimentation or delight shape the work?
6 Practice What quality, maintenance, or execution concern matters?
7 Partnership Who or what must this integrate with?
8 Transformation What risk, shared state, or deep change is present?
9 Exploration What principle or broader strategy guides the path?
10 Calling What delivery or long-term outcome is being served?
11 Community What system, network, or shared aspiration is involved?
12 The Hidden What blind spot, ending, or unconscious factor matters?

Within each house, the Major Arcana card sets the archetypal theme and the two Minor Arcana cards provide practical detail.

For compatibility with older workflows, draw_cards.py --legacy returns the previous 4-card hand, and draw_cards.py --legacy <count> returns a custom hand of 1-78 cards. A positional count without --legacy is rejected, because the new default spread has a fixed shape.

Reference Files

Each house's meaning is in its own markdown file under {baseDir}/houses/. House files describe how the house applies across technical contexts including building new projects, vulnerability discovery, correctness verification, and common audit, verification, domain, failure-class, and stakeholder workflows.

Each card's meaning is in its own markdown file under {baseDir}/cards/:

  • cards/major/ - 22 Major Arcana (archetypal forces)
  • cards/wands/ - 14 Wands (creativity, action, will)
  • cards/cups/ - 14 Cups (emotion, intuition, relationships)
  • cards/swords/ - 14 Swords (intellect, conflict, truth)
  • cards/pentacles/ - 14 Pentacles (material, practical, craft)

Interpretation

After drawing, read each house file and each card file, then synthesize meaning. See {baseDir}/references/INTERPRETATION_GUIDE.md for the full interpretation workflow. For cross-domain translation, see {baseDir}/references/TECHNICAL_CONTEXT_LENSES.md.

Key rules:

  • Reversed cards invert or complicate the upright meaning
  • Major Arcana cards carry more weight than Minor Arcana
  • The spread tells a story across all 12 houses; don't interpret cards in isolation
  • Map abstract meanings to concrete technical decisions
  • In security, audit, and correctness work, use the reading to choose an investigation path, then require evidence before accepting or dismissing any risk
  • Never output interpretation as a text-only turn. Include the interpretation alongside your next tool call (the action that implements the chosen option). Prefer --content so all 36 card meanings and all 12 house meanings are available from the draw output.

Example Session (House-Level Fragment)

A real reading synthesizes all 12 houses; the fragment below shows only what one house contributes so the format is clear. Do not stop after one house in actual use.

User: "I dunno, just make it work somehow"

[Draw cards]
1st House (Self): The Magician (upright), Five of Swords (reversed),
                  Ten of Pentacles (upright)

House contribution: The starting stance is resourceful and tool-rich
(Magician), but the practical details warn against combative edge-case work
(Five of Swords reversed) while still favoring maintainable craft
(Ten of Pentacles). This is one input into the overall reading; combine with
the remaining 11 houses before deciding on an approach.

The named draw agent returns a more compact form for portent questions: 3 concise bullets covering the dominant theme, the main risk or blind spot, and the recommended next action.

Error Handling

If the drawing script fails:

  • Script crashes with traceback: Report the error to the user and skip the reading. Do not invent cards or simulate a draw — the whole point is real entropy.
  • Card file not found: Note the missing file, interpret the card from its name and suit alone, and continue with the reading.
  • Never fake entropy: If the script cannot run, do not simulate a draw using your own "randomness." Tell the user the draw failed.

Rationalizations to Reject

Rationalization Why Wrong
"The cards said to, so I must" Cards inform direction, they don't override safety or correctness
"This reading justifies my pre-existing preference" Be honest if the reading challenges your instinct
"The reversed card means do nothing" Reversed means a different angle, not inaction
"Major Arcana overrides user requirements" User requirements always take priority over card readings
"I'll keep drawing until I get what I want" One draw per decision point; accept the reading
"The reading says the risk is fine" Cards can suggest what to inspect; only evidence can dismiss a security or correctness concern

Version History

  • 9b28133 Current 2026-08-20 09:17

Same Skill Collection

plugins/audit-context-building/skills/audit-context-building/SKILL.md
plugins/building-secure-contracts/skills/algorand-vulnerability-scanner/SKILL.md
plugins/building-secure-contracts/skills/cairo-vulnerability-scanner/SKILL.md
plugins/building-secure-contracts/skills/cosmos-vulnerability-scanner/SKILL.md
plugins/building-secure-contracts/skills/solana-vulnerability-scanner/SKILL.md
plugins/building-secure-contracts/skills/substrate-vulnerability-scanner/SKILL.md
plugins/building-secure-contracts/skills/ton-vulnerability-scanner/SKILL.md
plugins/burpsuite-project-parser/skills/burpsuite-project-parser/SKILL.md
plugins/c-review/skills/c-review/SKILL.md
plugins/claude-in-chrome-troubleshooting/skills/chrome-mcp-troubleshooting/SKILL.md
plugins/constant-time-analysis/skills/constant-time-analysis/SKILL.md
plugins/culture-index/skills/interpreting-culture-index/SKILL.md
plugins/devcontainer-setup/skills/devcontainer-setup/SKILL.md
plugins/differential-review/skills/differential-review/SKILL.md
plugins/dimensional-analysis/skills/dimensional-analysis/SKILL.md
plugins/dwarf-expert/skills/dwarf-expert/SKILL.md
plugins/firebase-apk-scanner/skills/firebase-apk-scanner/SKILL.md
plugins/fp-check/skills/fp-check/SKILL.md
plugins/gh-cli/skills/gh-cli/SKILL.md
plugins/git-cleanup/skills/git-cleanup/SKILL.md
plugins/goal-prompt/skills/goal-prompt/SKILL.md
plugins/modern-cpp/skills/modern-cpp/SKILL.md
plugins/modern-python/skills/modern-python/SKILL.md
plugins/mutation-testing/skills/mutation-testing/SKILL.md
plugins/open-sourcing/skills/open-sourcing/SKILL.md
plugins/rust-review/skills/rust-review/SKILL.md
plugins/second-opinion/skills/second-opinion/SKILL.md
plugins/semgrep-rule-creator/skills/semgrep-rule-creator/SKILL.md
plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator/SKILL.md
plugins/sharp-edges/skills/sharp-edges/SKILL.md
plugins/skill-improver/skills/skill-improver/SKILL.md
plugins/spec-to-code-compliance/skills/spec-to-code-compliance/SKILL.md
plugins/static-analysis/skills/sarif-parsing/SKILL.md
plugins/supply-chain-risk-auditor/skills/supply-chain-risk-auditor/SKILL.md
plugins/testing-handbook-skills/skills/address-sanitizer/SKILL.md
plugins/testing-handbook-skills/skills/aflpp/SKILL.md
plugins/testing-handbook-skills/skills/atheris/SKILL.md
plugins/testing-handbook-skills/skills/cargo-fuzz/SKILL.md
plugins/testing-handbook-skills/skills/coverage-analysis/SKILL.md
plugins/testing-handbook-skills/skills/fuzzing-dictionary/SKILL.md
plugins/testing-handbook-skills/skills/fuzzing-obstacles/SKILL.md
plugins/testing-handbook-skills/skills/harness-writing/SKILL.md
plugins/testing-handbook-skills/skills/libafl/SKILL.md
plugins/testing-handbook-skills/skills/libfuzzer/SKILL.md
plugins/testing-handbook-skills/skills/ossfuzz/SKILL.md
plugins/testing-handbook-skills/skills/ruzzy/SKILL.md
plugins/testing-handbook-skills/skills/testing-handbook-generator/SKILL.md
plugins/testing-handbook-skills/skills/wycheproof/SKILL.md
plugins/trailmark/skills/crypto-protocol-diagram/SKILL.md

Metadata

Files
0
Version
7dee682
Hash
ef51258f
Indexed
2026-08-20 09:17

ホーム - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-29 07:47
浙ICP备14020137号-1 $お客様$