ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      zlc000190

      Safety Report

      Subagent Driven Development

      @zlc000190

      Use when executing implementation plans with independent tasks in the current session

      2,944Downloads
      39Installs
      2Stars
      1Versions
      Project Management1,537

      Security Analysis

      medium confidence
      Suspicious0.04 risk

      The skill's instructions expect the agent to read and modify project files, run tests, commit, and update external task trackers, but it declares no required tools, credentials, or boundaries — the capabilities don't match the declared requirements.

      Feb 10, 20264 files4 concerns
      Purpose & Capabilityconcern

      The description says this is a workflow for executing implementation plans, which plausibly requires repository access, git, test runners, and integration with a task tracker (TodoWrite). However, the skill declares no required binaries, env vars, or config paths. It references actions like 'commit', 'get git SHAs', 'Mark task complete in TodoWrite', and 'Use superpowers:finishing-a-development-branch' that imply access to system tools and external services. The lack of declared capabilities/credentials is an incoherence.

      Instruction Scopeconcern

      SKILL.md explicitly instructs the agent to read plan files, extract tasks, dispatch fresh implementer/spec/quality-reviewer subagents per task, run implementations, tests, commits, and mark tasks complete in TodoWrite. Those instructions permit reading and modifying repository files and interacting with external systems, but they don't constrain what files can be read or what data may be transmitted. The prompts reference follow-up actions (commits, tests, pushes) that are broad in scope.

      Install Mechanismok

      This is an instruction-only skill with no install spec and no code files, which minimizes the risk of arbitrary code being written to disk as part of installation.

      Credentialsconcern

      No environment variables or credentials are declared, yet the workflow clearly implies needing credentials or tokens for git remote pushes and for TodoWrite (or other task-tracking APIs). Required tools like git, the project's test runner, or CI credentials are not listed. This omission makes it unclear what secrets the skill will need at runtime.

      Persistence & Privilegenote

      The skill does not set always:true and does not disable model invocation, so it will behave like a normal, invokable skill. However, because the instructions enable autonomous subagent dispatching that can modify repo state, you should be cautious about allowing model-initiated runs that perform commits or external updates without explicit user confirmation.

      Guidance

      This skill's instructions require repository read/write, running tests, committing, and updating an external task tracker, but the package declares no required tools or credentials. Before installing: 1) Ask the publisher to list required binaries (git, test runner), exact external integrations (what is TodoWrite and how it authenticates), and any environment variables or tokens. 2) Ask how commits/pushes are performed (local only vs. push to remote) and whether the skill will prompt for approval before making changes. 3) Prefer the skill explicitly limit which paths it may read/modify and require explicit user approval for destructive actions. 4) Consider disabling autonomous model invocation (disableModelInvocation:true) or ensuring human confirmation is required for commits and external API calls. If the author cannot clarify these points, treat the skill as risky to enable on sensitive repositories.

      Latest Release

      v0.1.0

      Initial release: 子代理驱动开发

      More by @zlc000190

      Writing Skills

      4 stars

      Dispatching Parallel Agents

      2 stars

      Requesting Code Review

      2 stars

      Writing Plans

      2 stars

      Brainstorming

      1 stars

      Using Superpowers

      1 stars

      Published by @zlc000190 on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]