Skills orchestration
📦

orchestration

Content revision r2 High Risk ⚙️ External commands📁 Filesystem access

Coordinate Tasks Across AI Coding Providers

Delegating work across AI providers requires consistent routing, execution, and result collection. This guide documents native Task delegation, provider selection, parallel workflows, and authentication recovery.

Supports: Claude Codex Code(CC)
⚠️ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "orchestration" from https://skillstore.io/skills/consiliency-orchestration.md and its manifest at https://skillstore.io/api/skills/consiliency-orchestration/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "orchestration". Select a provider for a review that requires filesystem write denial.

Expected outcome:

  • Recommended provider: Codex, based on the cookbook sandbox routing rule.
  • Prerequisites: installed CLI, authentication, current help output, and verified read-only controls.
  • Execution status: awaiting approval; no files changed.

Using "orchestration". Plan parallel architecture and security reviews without changing the repository.

Expected outcome:

  • Architecture review: Gemini, subject to provider consent and verified write restrictions.
  • Security review: Codex with verified read-only controls.
  • Collection plan: monitor both tasks, wait for completion, and compare findings.
  • Recovery plan: request interactive login if authentication fails, then retry the approved task.

Security Audit

High Risk
v11 • 10/4/2026 Open versioned report

All 65 static matches are false positives for Markdown formatting, fixed documentation references, or standard Git worktree examples. Semantic review identifies broad permissions with automatic approvals, incomplete read-only enforcement, and cleanup without explicit ownership verification. No evidence found of audit manipulation, credential theft, or malicious exfiltration in the reviewed files.

3
Files scanned
572
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (3)

High
Broad CLI Permissions Combined With Automatic Approval
The guide allows all arguments through 'Bash(codex:*)', 'Bash(gemini:*)', and 'Bash(cursor-agent:*)'. It also recommends '--yolo' and '--force', reducing approval barriers for delegated commands and file changes.
The permission patterns are explicit, and the Cursor write example is labeled 'auto-approves'. This is unsafe delegation guidance, not evidence of malicious author intent.
Medium
Read-Only Guidance Lacks Consistent Enforcement
The guide labels 'gemini --sandbox --yolo' and 'cursor-agent -p' as read-only, then relies on 'Do NOT modify any files' prompts. Sandboxing and approval behavior alone do not establish filesystem write denial; a Git worktree also does not confine an agent.
The read-only labels and prompt-only restriction are directly visible. The supplied guide provides no verification that Gemini or Cursor writes are actually denied.
Medium
Cleanup Guidance Lacks Explicit Artifact Ownership Checks
Default cleanup instructs readers to 'Delete agent-created files' and supplies broad patterns such as '*_analysis.json'. No explicit baseline or ownership record distinguishes agent artifacts from other new files, risking accidental deletion during concurrent work.
The prose requires new-file checks and reading before deletion, but it does not define how ownership is verified. The risk concerns following this guidance; no deletion implementation is supplied.

Risk Factors

⚙️ External commands (50)
native-invoke/SKILL.md:11 native-invoke/SKILL.md:36 native-invoke/SKILL.md:37-47 native-invoke/SKILL.md:47-49 native-invoke/SKILL.md:49-67 native-invoke/SKILL.md:67-68 native-invoke/SKILL.md:68-82 native-invoke/SKILL.md:82-83 native-invoke/SKILL.md:83-84 native-invoke/SKILL.md:84-92 native-invoke/SKILL.md:92-93 native-invoke/SKILL.md:93-96 native-invoke/SKILL.md:96-110 native-invoke/SKILL.md:110 native-invoke/SKILL.md:111 native-invoke/SKILL.md:112 native-invoke/SKILL.md:117-120 native-invoke/SKILL.md:120-126 native-invoke/SKILL.md:126-144 native-invoke/SKILL.md:144-168 native-invoke/SKILL.md:168 native-invoke/SKILL.md:171-179 native-invoke/SKILL.md:179-185 native-invoke/SKILL.md:185-187 native-invoke/SKILL.md:187-189 native-invoke/SKILL.md:189-191 native-invoke/SKILL.md:191-193 native-invoke/SKILL.md:193-195 native-invoke/SKILL.md:195-199 native-invoke/SKILL.md:199-201 native-invoke/SKILL.md:201-203 native-invoke/SKILL.md:203-205 native-invoke/SKILL.md:205-207 native-invoke/SKILL.md:207-208 native-invoke/SKILL.md:208-209 native-invoke/SKILL.md:209-213 native-invoke/SKILL.md:213-215 native-invoke/SKILL.md:215-217 native-invoke/SKILL.md:217-219 native-invoke/SKILL.md:219-221 native-invoke/SKILL.md:221-223 native-invoke/SKILL.md:223-234 native-invoke/SKILL.md:234-248 native-invoke/SKILL.md:248-254 native-invoke/SKILL.md:254-259 native-invoke/SKILL.md:259-262 native-invoke/SKILL.md:262-265 native-invoke/SKILL.md:265-273 native-invoke/SKILL.md:273-274 native-invoke/SKILL.md:274-275
📁 Filesystem access (8)
Audited by: codex View Audit History →
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/consiliency-orchestration/audits/11?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/consiliency-orchestration/security.svg)](https://skillstore.io/skills/consiliency-orchestration?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/consiliency-orchestration?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/consiliency-orchestration/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/consiliency-orchestration.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA · BibTeX · CFF)

APA citation

Consiliency. (2026). orchestration security audit report (audit version 11) [Author version unspecified]. Skillstore. https://skillstore.io/skills/consiliency-orchestration/audits/11

BibTeX citation

@techreport{consiliency-consiliency-orchestration-2026, author = {Consiliency}, title = {orchestration security audit report (audit version 11)}, institution = {Skillstore}, year = {2026}, number = {11}, url = {https://skillstore.io/skills/consiliency-orchestration/audits/11}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "orchestration security audit report (audit version 11)" version: "unspecified" type: report authors: - name: "Consiliency" date-released: "2026-10-04" url: "https://skillstore.io/skills/consiliency-orchestration/audits/11" identifiers: - type: other value: "skillstore:consiliency-orchestration:audit:11" description: "Skillstore immutable audit report identifier"

Compare variants

2 installable variants

Each author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.

Why this variant is first

Highest Skillstore Score
stablyai Recommended

stablyai-orchestration

Skillstore Score 77
Evidence Confidence High
Skillstore usage 25
Updated

2026-09-09

Consiliency Current

consiliency-orchestration

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 6
Updated

2026-10-05

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
73
Community
83
Spec Compliance

What You Can Build

Compare Independent Code Reviews

Plan parallel reviews with separate providers, collect their findings, and reconcile differences before making changes.

Route Architecture Analysis

Select providers according to reasoning complexity, context size, and budget while defining a fallback sequence.

Plan Controlled Agent Execution

Define authentication recovery, worktree separation, result collection, and approval checkpoints for delegated development tasks.

Try These Prompts

Choose a Provider
Recommend a provider for reviewing this function using the documented routing rules. Explain your choice and list prerequisites. Do not execute commands.
Prepare a Read-Only Review
Plan a Codex review of [files]. Verify installed CLI help and read-only enforcement. Request approval before invocation and return findings without file changes.
Coordinate Parallel Reviews
Plan parallel Codex and Gemini reviews of [component]. Confirm provider consent and write restrictions. After approval, collect results and summarize agreements and disagreements.
Design a Controlled Delegation Workflow
Design a delegation workflow for [task] with provider routing, fallback, authentication recovery, separate worktrees, artifact ownership tracking, and approval before writes or merges.

Best Practices

  • Verify installed CLI help, model availability, permissions, and authentication before constructing commands.
  • Obtain provider consent and enforce filesystem restrictions; do not rely on prompts or worktrees as security boundaries.
  • Review results before merging and delete only artifacts with verified ownership.

Avoid

  • Granting wildcard CLI permissions and automatic approval without defining permitted actions.
  • Treating a read-only prompt, generic sandbox, or Git worktree as proof that writes are impossible.
  • Deleting matching filenames without confirming that the current agent created them.

Frequently Asked Questions

Does this skill execute tasks automatically?
No. It provides documentation and examples for manual delegation through compatible tools.
Which providers have invocation examples?
The native invocation guide includes Codex, Gemini, and Cursor examples. The routing cookbook also discusses Claude.
Can I use every example directly in Codex?
No. Native Task and TaskOutput examples depend on Claude Code. Other environments require adapting the documented workflow.
Are all dependencies included?
No. Several referenced cookbooks, setup commands, provider tools, and terminal helpers are outside the reviewed package.
Does read-only mode guarantee that files cannot change?
No. Verify filesystem write denial for each provider. Prompt instructions and Git worktrees do not enforce it.
What happens when authentication fails?
The guide recommends opening an interactive terminal for provider login, waiting for completion, and retrying the task.

Developer Details

License

MIT

Skillstore revision

r2

Version notice

The author did not declare a version.

Ref

de4c0509741e39a47cd672fcf69fb415b8394eaf

Maintenance freshness

10/5/2026

Usage

6 downloads · 378 views

File structure