Skills executor-planning
๐Ÿ“ฆ

executor-planning

Content revision r1 Medium Risk โš™๏ธ External commands๐Ÿ“ Filesystem access

Turn Approved Specifications into Implementation Plans

Incomplete implementation plans leave developers guessing about interfaces, dependencies, and acceptance criteria. This skill structures approved specifications into traceable tasks with explicit tests and execution gates.

Supports: Claude Codex Code(CC)
๐Ÿ“Š 68 Adequate

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "executor-planning" from https://skillstore.io/skills/atri10-executor-planning.md and its manifest at https://skillstore.io/api/skills/atri10-executor-planning/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "executor-planning". Plan an approved feature that adds scoring and routing through documented interfaces.

Expected outcome:

  • Draft plan: scoring and routing, with requirement coverage and exact interface contracts.
  • Task sequence: define shared types, implement scoring, then integrate routing.
  • Dependency map: routing consumes shared types and scoring results.
  • Acceptance checks: explicit expected values, negative-input tests, and repeatable test commands.
  • Handoff: complete plan regression before asking the human to select an execution mode.

Using "executor-planning". Review a draft plan whose final task contains a dependency section and omits an expected test failure.

Expected outcome:

  • Extraction defect: move the dependency section above the first task heading.
  • Test defect: name the exact expected failure before implementation exists.
  • Coverage check: associate every requirement with at least one task.
  • Verification status: rerun task extraction and plan linting with the companion tools before claiming the gate passed.

Security Audit

Medium Risk
v1 โ€ข 10/5/2026 Open versioned report

Most of the 221 static findings are Markdown formatting, legitimate companion references, or routine planning commands. Two temporary-file findings remain confirmed, and a semantic finding identifies overly broad Git staging. No evidence found of prompt injection or exfiltration; companion script implementations are outside the reviewed package.

1
Files scanned
773
Lines analyzed
2
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Broad Git Staging Can Include Unrelated Changes
The handoff runs 'git add docs/executor/INIT-0004-cloud-tenant-cells' before committing. Directory-wide staging can include unrelated or sensitive initiative files beyond the intended plan, index, and specification updates.
The example explicitly stages the entire initiative directory instead of the three intended document updates. Actual exposure depends on other changes in that directory.
Capability review items (2)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Temp directory access
"$n" /tmp/brief-check.md >/dev/null || echo "TASK $n FAILS"
The example writes each brief to a predictable shared temporary pathname without showing exclusive creation. Concurrent runs or precreated links could corrupt or redirect output.
Medium
Temp directory access
grep -m1 '^\*\*Task:\*\*' /tmp/brief-check.md
The loop reads the same shared temporary file even after extraction failure. Stale output or another concurrent run could substitute the task identity being verified.
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/atri10-executor-planning/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/atri10-executor-planning/security.svg)](https://skillstore.io/skills/atri10-executor-planning?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/atri10-executor-planning?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/atri10-executor-planning/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/atri10-executor-planning.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

atri10. (2026). executor-planning security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/atri10-executor-planning/audits/1

BibTeX citation

@techreport{atri10-atri10-executor-planning-2026, author = {atri10}, title = {executor-planning security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/atri10-executor-planning/audits/1}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "executor-planning security audit report (audit version 1)" version: "unspecified" type: report authors: - name: "atri10" date-released: "2026-10-05" url: "https://skillstore.io/skills/atri10-executor-planning/audits/1" identifiers: - type: other value: "skillstore:atri10-executor-planning:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
65
Community
74
Spec Compliance

What You Can Build

Prepare a Reviewable Delivery Plan

Convert an approved feature specification into traceable tasks with explicit file ownership, interfaces, and acceptance tests.

Create Self-Contained Agent Briefs

Prepare tasks that isolated coding agents can implement without access to the surrounding conversation or complete plan.

Repair a Multi-Plan Handoff

Find missing requirement coverage, interface mismatches, dependency cycles, and incomplete test steps before implementation begins.

Try These Prompts

Create a First Plan
Create a draft implementation plan from [approved specification] and [interface document]. Check prerequisites and identify missing inputs before drafting tasks.
Define Testable Tasks
Refine [draft plan] into self-contained tasks. Include requirement IDs, exact interfaces, file lists, failing tests, expected results, and refactoring steps.
Split an Approved Specification
Use [decided decomposition session] to split [approved specification] into independently testable plans. Document coverage, predecessor assumptions, execution order, and dependency maps.
Audit and Repair the Plan Set
Audit [plan set] against [specification] and [interface contracts]. Repair coverage gaps, dependency cycles, and extraction defects. Report unavailable validation tools without claiming success.

Best Practices

  • Confirm specification approval, interface contracts, and the human-selected decomposition before drafting tasks.
  • Make each task independently understandable with exact requirements, interfaces, tests, and dependency references.
  • Verify companion tools, use private temporary files, and inspect explicitly staged changes before the execution handoff.

Avoid

  • Inventing interfaces or architectural decisions inside an implementation plan.
  • Using placeholders, implicit constraints, or references to another task instead of a complete acceptance contract.
  • Starting implementation before regression clears and the human selects an execution mode.

Frequently Asked Questions

Which AI tools are listed as supported?
The report lists Claude, Codex, and Claude Code. The workflow still requires the companion Executor resources and project documents.
What inputs are required before planning?
Provide an approved specification, relevant architecture decisions, and a decided decomposition session. Work spanning components also requires interface documents.
Does this package include the validation scripts?
No. This package contains only the planning instructions. The referenced scripts and supporting documents belong to the companion Executor package.
Can the skill invent missing interfaces?
No. Missing interfaces require an architecture decision before planning resumes. Task signatures must match the approved interface document.
When does implementation begin?
Implementation begins after plan regression clears and the human chooses subagent or inline execution. Planning does not authorize implementation by itself.
What security precautions apply to the examples?
Replace the shared temporary pathname with a private temporary directory. Stage only reviewed files and inspect staged changes before committing.

Developer Details

Author

atri10

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

6d0b11444384184b7ae743742a7e233a9a705cd9

Maintenance freshness

10/6/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“„ SKILL.md

More from atri10

View all
View all