agy-worker
Delegate Repository Work Safely
Repository delegation can consume time and make verification inconsistent. This skill sends bounded work to agy, then keeps review, checks, repair, and acceptance with Codex.
ΠΡΡΠ°Π½ΠΎΠ²ΠΈΡΠ΅ΡΡ ΠΈ Π·Π°ΠΏΡΠΎΡΠΈΡΠ΅ ΠΏΠΎΠ΄ΡΠ²Π΅ΡΠΆΠ΄Π΅Π½ΠΈΠ΅ ΠΏΠ΅ΡΠ΅Π΄ ΡΡΡΠ°Π½ΠΎΠ²ΠΊΠΎΠΉ.
ΠΡΠΎΠ²Π΅ΡΡΡΠ΅ ΠΏΠ»Π°Π½ ΠΈ ΠΏΠΎΠ»ΡΡΠΈΡΠ΅ ΡΠ²Π½ΠΎΠ΅ ΡΠΎΠ³Π»Π°ΡΠΈΠ΅ ΠΏΠΎΠ»ΡΠ·ΠΎΠ²Π°ΡΠ΅Π»Ρ ΠΏΠ΅ΡΠ΅Π΄ ΠΈΠ·ΠΌΠ΅Π½Π΅Π½ΠΈΠ΅ΠΌ ΡΠ°ΠΉΠ»ΠΎΠ².
Π£ΡΡΠ°Π½ΠΎΠ²ΠΈΡΡ Ρ ΠΏΠΎΠΌΠΎΡΡΡ ΠΌΠΎΠ΅Π³ΠΎ ΠΠ³Π΅Π½ΡΠ°
Π‘ΠΊΠΎΠΏΠΈΡΡΠΉΡΠ΅ ΡΡΠΎΡ Π·Π°ΠΏΡΠΎΡ Π² ΡΠ²ΠΎΠ΅Π³ΠΎ ΠΠ³Π΅Π½ΡΠ°. ΠΠ½ ΡΠΎΠ΄Π΅ΡΠΆΠΈΡ ΠΊΠ°Π½ΠΎΠ½ΠΈΡΠ΅ΡΠΊΡΡ ΡΡΡΠ°Π½ΠΈΡΡ Skill ΠΈ ΠΌΠ°Π½ΠΈΡΠ΅ΡΡ.
Review the Skillstore skill "agy-worker" from https://skillstore.io/skills/cagdasyurekli-agy-worker.md and its manifest at https://skillstore.io/api/skills/cagdasyurekli-agy-worker/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.ΠΠ°Ρ ΠΠ³Π΅Π½Ρ ΠΏΠΎ-ΠΏΡΠ΅ΠΆΠ½Π΅ΠΌΡ Π΄ΠΎΠ»ΠΆΠ΅Π½ ΠΏΠΎΠΊΠ°Π·Π°ΡΡ ΠΏΠ»Π°Π½ ΠΈ Π·Π°ΠΏΡΠΎΡΠΈΡΡ Π²ΡΠ΅ ΠΏΠΎΠ΄ΡΠ²Π΅ΡΠΆΠ΄Π΅Π½ΠΈΡ, ΡΡΠ΅Π±ΡΠ΅ΠΌΡΠ΅ ΠΏΠΎΠ»ΠΈΡΠΈΠΊΠΎΠΉ Π±Π΅Π·ΠΎΠΏΠ°ΡΠ½ΠΎΡΡΠΈ.
Π Π΅ΡΡΡΡΡ Π΄Π»Ρ AI-Π°Π³Π΅Π½ΡΠΎΠ²
ΠΡΠΏΠΎΠ»ΡΠ·ΡΠΉΡΠ΅ ΡΡΠΈ ΡΡΡΠ»ΠΊΠΈ, ΠΊΠΎΠ³Π΄Π° AI-Π°Π³Π΅Π½ΡΡ, crawler ΠΈΠ»ΠΈ script Π½ΡΠΆΠ΅Π½ ΡΠΈΡΡΡΠΉ ΠΊΠΎΠ½ΡΠ΅ΠΊΡΡ Π²ΠΌΠ΅ΡΡΠΎ ΠΏΠΎΠ»Π½ΠΎΠΉ ΡΡΡΠ°Π½ΠΈΡΡ.
ΠΡΠΎΡΠ΅ΡΡΠΈΡΠΎΠ²Π°ΡΡ
ΠΡΠΏΠΎΠ»ΡΠ·ΠΎΠ²Π°Π½ΠΈΠ΅ Β«agy-workerΒ». Explore the authentication flow and identify the files that handle token validation.
ΠΠΆΠΈΠ΄Π°Π΅ΠΌΡΠΉ ΡΠ΅Π·ΡΠ»ΡΡΠ°Ρ:
- Mapped the authentication entry points and token validation path.
- Listed evidence files and marked unverified assumptions for Codex review.
ΠΡΠΏΠΎΠ»ΡΠ·ΠΎΠ²Π°Π½ΠΈΠ΅ Β«agy-workerΒ». Add parser error-path tests under tests/parser and verify the change.
ΠΠΆΠΈΠ΄Π°Π΅ΠΌΡΠΉ ΡΠ΅Π·ΡΠ»ΡΡΠ°Ρ:
- Implemented the focused tests within the approved path.
- Ran the relevant test command and reported the final candidate status.
ΠΡΠΏΠΎΠ»ΡΠ·ΠΎΠ²Π°Π½ΠΈΠ΅ Β«agy-workerΒ». Audit the repository workflow and repair bounded failures.
ΠΠΆΠΈΠ΄Π°Π΅ΠΌΡΠΉ ΡΠ΅Π·ΡΠ»ΡΡΠ°Ρ:
Returned a structured project result with the candidate diff, verification evidence, remaining limits, and delivery recommendation.
ΠΡΠ΄ΠΈΡ Π±Π΅Π·ΠΎΠΏΠ°ΡΠ½ΠΎΡΡΠΈ
ΠΡΡΠΎΠΊΠΈΠΉ ΡΠΈΡΠΊMost static matches are benign implementation, validation, documentation, schema, or control-character checks. Confirmed risks include provider and verifier execution, environment inheritance, keychain handling, settings access, and non-sandboxed provider authority. Static review was capped at 400/991 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
ΠΠΎΠ΄ΡΠ²Π΅ΡΠΆΠ΄ΡΠ½Π½ΡΠ΅ ΠΏΡΠΎΠ±Π»Π΅ΠΌΡ Π±Π΅Π·ΠΎΠΏΠ°ΡΠ½ΠΎΡΡΠΈ (7)
ΠΡΠ½ΠΊΡΡ ΠΏΡΠΎΠ²Π΅ΡΠΊΠΈ Π²ΠΎΠ·ΠΌΠΎΠΆΠ½ΠΎΡΡΠ΅ΠΉ (50)
ΠΡΠΎ ΡΠ΅Π°Π»ΡΠ½ΡΠ΅ Π»ΠΎΠΊΠ°Π»ΡΠ½ΡΠ΅ Π²ΠΎΠ·ΠΌΠΎΠΆΠ½ΠΎΡΡΠΈ, ΠΊΠΎΡΠΎΡΡΠ΅ ΠΌΠΎΠ³ΡΡ ΠΎΠΆΠΈΠ΄Π°ΡΡΡΡ Π΄Π»Ρ ΡΡΠΎΠ³ΠΎ Π½Π°Π²ΡΠΊΠ°, ΠΏΠΎΡΡΠΎΠΌΡ ΠΎΠ½ΠΈ ΡΡΠ΅Π±ΡΡΡ ΠΏΡΠΎΠ²Π΅ΡΠΊΠΈ, Π½ΠΎ Π½Π΅ ΡΡΠΈΡΠ°ΡΡΡΡ ΠΏΠΎΠ΄ΡΠ²Π΅ΡΠΆΠ΄ΡΠ½Π½ΡΠΌ Π²ΡΠ΅Π΄ΠΎΠ½ΠΎΡΠ½ΡΠΌ ΠΏΠΎΠ²Π΅Π΄Π΅Π½ΠΈΠ΅ΠΌ.
Π€Π°ΠΊΡΠΎΡΡ ΡΠΈΡΠΊΠ°
βοΈ ΠΠ½Π΅ΡΠ½ΠΈΠ΅ ΠΊΠΎΠΌΠ°Π½Π΄Ρ (50)
π ΠΠΎΡΡΡΠΏ ΠΊ ΡΠ΅ΡΠΈ (43)
π ΠΠΎΡΡΡΠΏ ΠΊ ΡΠ°ΠΉΠ»ΠΎΠ²ΠΎΠΉ ΡΠΈΡΡΠ΅ΠΌΠ΅ (50)
β‘ Π‘ΠΎΠ΄Π΅ΡΠΆΠΈΡ ΡΠΊΡΠΈΠΏΡΡ (22)
π ΠΠ΅ΡΠ΅ΠΌΠ΅Π½Π½ΡΠ΅ ΠΎΠΊΡΡΠΆΠ΅Π½ΠΈΡ (15)
ΠΠΎΠ΄Π΅Π»ΠΈΡΡΡΡ ΠΈ ΡΠΈΡΠΈΡΠΎΠ²Π°ΡΡ ΡΡΠΎΡ ΠΎΡΡΠ΅Ρ
ΠΠ΅Π»ΠΈΡΠ΅ΡΡ Π²Π΅ΡΡΠΈΠΎΠ½Π½ΡΠΌ ΠΎΡΡΠ΅ΡΠΎΠΌ ΠΎΠ± ΠΎΡΠ΅Π½ΠΊΠ΅, Π½Π΅ΠΉΡΡΠ°Π»ΡΠ½ΡΠΌ Π·Π½Π°ΡΠΊΠΎΠΌ, Π²ΡΡΡΠ°ΠΈΠ²Π°Π΅ΠΌΠΎΠΉ ΠΊΠ°ΡΡΠΎΡΠΊΠΎΠΉ ΠΈ ΡΠΈΡΠ°ΡΠ°ΠΌΠΈ. Skillstore ΠΏΡΠ±Π»ΠΈΠΊΡΠ΅Ρ Π΄ΠΎΠΊΠ°Π·Π°ΡΠ΅Π»ΡΡΡΠ²Π°, Π½Π΅ ΡΠ΅ΡΠ°Ρ, Π±Π΅Π·ΠΎΠΏΠ°ΡΠ΅Π½ Π»ΠΈ ΡΡΠΎΡ Skill.
ΠΠΎΠΏΠΈΡΠΎΠ²Π°ΡΡ ΡΡΡΠ»ΠΊΡ Π½Π° ΠΎΡΡΡΡ
https://skillstore.io/skills/cagdasyurekli-agy-worker/audits/8?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportΠΠ½Π°ΡΠΎΠΊ Markdown
[](https://skillstore.io/skills/cagdasyurekli-agy-worker?utm_source=security_passport_badge)ΠΠ½Π°ΡΠΎΠΊ HTML
<a href="https://skillstore.io/skills/cagdasyurekli-agy-worker?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/cagdasyurekli-agy-worker/security.svg" alt="Skillstore security assessment" loading="lazy"></a>ΠΡΡΡΠ°ΠΈΠ²Π°Π΅ΠΌΠ°Ρ ΠΊΠ°ΡΡΠΎΡΠΊΠ°
<iframe src="https://skillstore.io/embed/skills/cagdasyurekli-agy-worker.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>ΠΠΊΠ°Π΄Π΅ΠΌΠΈΡΠ΅ΡΠΊΠΈΠ΅ ΡΡΡΠ»ΠΊΠΈ (APA Β· BibTeX Β· CFF)
Π¦ΠΈΡΠ°ΡΠ° APA
cagdasyurekli. (2026). agy-worker security audit report (audit version 8) [Author version 0.21.0]. Skillstore. https://skillstore.io/skills/cagdasyurekli-agy-worker/audits/8Π¦ΠΈΡΠ°ΡΠ° BibTeX
@techreport{cagdasyurekli-cagdasyurekli-agy-worker-2026,
author = {cagdasyurekli},
title = {agy-worker security audit report (audit version 8)},
institution = {Skillstore},
year = {2026},
number = {8},
url = {https://skillstore.io/skills/cagdasyurekli-agy-worker/audits/8},
note = {Author version 0.21.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "agy-worker security audit report (audit version 8)"
version: "0.21.0"
type: report
authors:
- name: "cagdasyurekli"
date-released: "2026-09-20"
url: "https://skillstore.io/skills/cagdasyurekli-agy-worker/audits/8"
identifiers:
- type: other
value: "skillstore:cagdasyurekli-agy-worker:audit:8"
description: "Skillstore immutable audit report identifier"
ΠΡΠ΅Π½ΠΊΠ° Skillstore
ΠΠΎΡΠ΅ΠΌΡ ΡΠ°ΠΊΠ°Ρ ΠΎΡΠ΅Π½ΠΊΠ° ΠΠΎΡΡΠΎΠ²Π΅ΡΠ½ΠΎΡΡΡ Π΄ΠΎΠΊΠ°Π·Π°ΡΠ΅Π»ΡΡΡΠ²: Π‘ΡΠ΅Π΄Π½ΠΈΠΉΠ§ΡΠΎ Π²Ρ ΠΌΠΎΠΆΠ΅ΡΠ΅ ΠΏΠΎΡΡΡΠΎΠΈΡΡ
Explore an unfamiliar repository
Ask agy to map code paths or investigate a focused question, then review the evidence with Codex.
Implement a bounded change
Delegate a feature, refactor, or test change within an approved scope and verify the resulting diff independently.
Run a broad project workflow
Use project mode for larger audits or repairs while preserving review, checks, and delivery decisions with Codex.
ΠΠΎΠΏΡΠΎΠ±ΡΠΉΡΠ΅ ΡΡΠΈ ΠΏΡΠΎΠΌΠΏΡΡ
Use agy-worker to inspect the repository and explain the code paths related to [topic]. Read only the approved scope and report evidence.
Use agy-worker to implement [change] under [paths]. Preserve existing behavior, run relevant checks, and summarize the final diff.
Use agy-worker to review the candidate for [task]. Run independent checks, identify gaps, and repair only within the approved scope.
Use agy-worker project mode for [objective]. Require approved provider scope, explicit model and budget, independent verification, and an evidence-based delivery decision.
ΠΡΡΡΠΈΠ΅ ΠΏΡΠ°ΠΊΡΠΈΠΊΠΈ
- Approve the exact provider-readable content, model, budget, and isolation mode before launch.
- Prefer provider scopes and argv verification, then inspect the final diff independently.
- Keep secrets, raw logs, controller state, and unrelated private files outside approved content.
ΠΠ·Π±Π΅Π³Π°ΡΡ
- Do not treat installation as permission to transmit repository content.
- Do not trust worker envelopes, reported tests, or provider claims without independent checks.
- Do not use whole-worktree or shell verification modes without explicit scope and risk approval.
Π§Π°ΡΡΠΎ Π·Π°Π΄Π°Π²Π°Π΅ΠΌΡΠ΅ Π²ΠΎΠΏΡΠΎΡΡ
What does agy-worker delegate?
What remains with Codex?
Does the skill transmit repository files?
Is the provider session a sandbox?
Which hosts are supported?
How should I verify results?
Π‘Π²Π΅Π΄Π΅Π½ΠΈΡ Π΄Π»Ρ ΡΠ°Π·ΡΠ°Π±ΠΎΡΡΠΈΠΊΠΎΠ²
ΠΠ²ΡΠΎΡ
cagdasyurekliΠΠΈΡΠ΅Π½Π·ΠΈΡ
MIT
ΠΠ΅ΡΡΠΈΡ Π°Π²ΡΠΎΡΠ°
v0.21.0
Π Π΅Π²ΠΈΠ·ΠΈΡ Skillstore
r8
Π Π΅ΠΏΠΎΠ·ΠΈΡΠΎΡΠΈΠΉ
https://github.com/cagdasyurekli/codex-agy-worker/tree/3da9a50afaa66492dd77f23f92c6ed4f84be4ada/skills/agy-workerΠ‘ΡΡΠ»ΠΊΠ°
73b58aaf0aa4d29844f1b4c2acf4f530fc1ae7b9
ΠΠΊΡΡΠ°Π»ΡΠ½ΠΎΡΡΡ ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΠΈ
20.09.2026
ΠΡΠΏΠΎΠ»ΡΠ·ΠΎΠ²Π°Π½ΠΈΠ΅
6 Π·Π°Π³ΡΡΠ·ΠΎΠΊ Β· 18 ΠΏΡΠΎΡΠΌΠΎΡΡΠΎΠ²
Π‘ΡΡΡΠΊΡΡΡΠ° ΡΠ°ΠΉΠ»ΠΎΠ²
π agents/
π openai.yaml
π README.md
π references/
π PROJECT_LIFECYCLE_AND_VERIFICATION.md
π SECURITY_AND_COMPATIBILITY.md
π TROUBLESHOOTING.md
π runtime/
π agents/
π bulk-test-writer.md
π diff-reviewer.md
π repo-inventory.md
π agy-worker.sh
π benchmark.sh
π benchmarks/
π v1/
π manifest.json
π portable-source.json
π tasks/
π exact-edit/
π candidate.txt
π envelope.json
π initial.txt
π variants/
π bulk.json
π compat/
π agy-model-effort-matrix.json
π agy-model-effort-matrix.sha256
π agy-models-inventory-binding.json
π agy-models-inventory-binding.sha256
π agy-version-manifest.json
π agy-version-manifest.sha256
π model-effort-matrix.schema.json
π model-intelligence/
π dataset.v1.json
π version-manifest.schema.json
π delegation-policy.sh
π doctor.sh
π evidence-report.sh
π feedback-triage.sh
π ground-truth.sh
π job.sh
π model-evidence-campaign.sh
π model-selection.sh
π qa-gate.sh
π schemas/
π benchmark-plan.schema.json
π benchmark-result.schema.json
π delegation-policy.schema.json
π evidence-receipt.schema.json
π model-evidence-campaign-advisory-preview.schema.json
π model-evidence-campaign-advisory-summary.schema.json
π model-evidence-campaign-aggregate-preview.schema.json
π model-evidence-campaign-aggregate.schema.json
π model-evidence-campaign-evaluation.schema.json
π model-evidence-campaign-plan.schema.json
π model-evidence-campaign-record.schema.json
π model-intelligence-advisory.schema.json
π model-intelligence-evidence.schema.json
π model-recommendation.schema.json
π model-selection.schema.json
π swebench-workflow-study-advisory.schema.json
π swebench-workflow-study-plan.schema.json
π swebench-workflow-study-report.schema.json
π worker-result.provider.schema.json
π worker-result.schema.json
π workflow-state.schema.json
π scripts/
π agy_dispatch_containment.py
π agy_dispatch_verification.py
π agy_dispatch.py
π benchmark.py
π candidate_state.py
π compatibility.py
π delegation_policy.py
π doctor-metadata.py
π evidence_receipt.py
π evidence_report.py
π feedback-triage.py
π job_lifecycle.py
π model_evidence_campaign.py
π model_selection.py
π swebench_workflow_study.py
π validate-envelope.py
π version_manifest_engine.py
π workflow.py
π swebench-workflow-study.sh
π verify-job.sh
π workflow.sh
π scripts/
π resolve-pipeline.sh
π SKILL.md