cc-devflow-orchestrator
Route CC-DevFlow Workflows
Teams lose time choosing the next CC-DevFlow command during complex delivery work. This skill maps project status, phase gates, and user intent to the right Claude, Codex, or Claude Code workflow.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "cc-devflow-orchestrator" from https://skillstore.io/skills/dimon94-cc-devflow-orchestrator.md and its manifest at https://skillstore.io/api/skills/dimon94-cc-devflow-orchestrator/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "cc-devflow-orchestrator". I finished research and need to create product requirements.
Expected outcome:
Recommended next step: run the PRD workflow. Confirm the brainstorming document exists and aligns with the research notes first.
Using "cc-devflow-orchestrator". The status says development is complete. What comes next?
Expected outcome:
Recommended next step: run the two-stage review workflow. QA is an alternative only when review is intentionally skipped.
Using "cc-devflow-orchestrator". A phase gate failed because a required document is missing.
Expected outcome:
Recommended next step: check the orchestration status, identify the incomplete phase, and generate a status report after reviewing the local script.
Security Audit
SafeMost static findings are Markdown backtick false positives around slash-command documentation, not Ruby or shell execution. Three findings are confirmed because the skill tells users to run local shell scripts under .claude/scripts; these fixed-path commands require review before execution.
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (42)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/dimon94-cc-devflow-orchestrator/audits/10?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/dimon94-cc-devflow-orchestrator?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/dimon94-cc-devflow-orchestrator?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/dimon94-cc-devflow-orchestrator/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/dimon94-cc-devflow-orchestrator.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
Dimon94. (2026). cc-devflow-orchestrator security audit report (audit version 10) [Author version unspecified]. Skillstore. https://skillstore.io/skills/dimon94-cc-devflow-orchestrator/audits/10BibTeX citation
@techreport{dimon94-dimon94-cc-devflow-orchestrator-2026,
author = {Dimon94},
title = {cc-devflow-orchestrator security audit report (audit version 10)},
institution = {Skillstore},
year = {2026},
number = {10},
url = {https://skillstore.io/skills/dimon94-cc-devflow-orchestrator/audits/10},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "cc-devflow-orchestrator security audit report (audit version 10)"
version: "unspecified"
type: report
authors:
- name: "Dimon94"
date-released: "2026-07-09"
url: "https://skillstore.io/skills/dimon94-cc-devflow-orchestrator/audits/10"
identifiers:
- type: other
value: "skillstore:dimon94-cc-devflow-orchestrator:audit:10"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Start a new requirement workflow
Identify the right first command and expected documents for a new feature request.
Resume an interrupted delivery phase
Use the current orchestration status to select the next command without repeating completed work.
Route review and release checks
Choose the correct review, QA, verification, and release commands near the end of delivery.
Try These Prompts
Use cc-devflow-orchestrator to choose the first CC-DevFlow command for this requirement. Explain the expected document outputs.
Use cc-devflow-orchestrator with my current orchestration status. Recommend the next command and any optional alternatives.
Use cc-devflow-orchestrator to decide whether I should run review, QA, verification, or release next. Include the responsible agents.
Use cc-devflow-orchestrator to diagnose this blocked CC-DevFlow workflow. Recommend the recovery path and any files or scripts to inspect first.
Best Practices
- Confirm the current orchestration status before following any routing recommendation.
- Review referenced command, agent, and rule files when detailed standards matter.
- Ask for explicit approval before running any referenced local shell script.
Avoid
- Treating this orchestrator as the source of detailed implementation standards.
- Running suggested local scripts without inspecting their contents and trust boundary.
- Skipping phase gates because the next command appears obvious.