invoking-agents
Orchestrate Issues Through Review and QA
Multi-agent issue delivery can lose state, mix roles, and skip safeguards. This skill coordinates implementation, review, QA, escalation, and pull request creation through agent-flow.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "invoking-agents" from https://skillstore.io/skills/drix10-invoking-agents.md and its manifest at https://skillstore.io/api/skills/drix10-invoking-agents/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "invoking-agents". Implement issue #42 and open a pull request.
Expected outcome:
Issue #42 completed. Implementation, review, and QA passed. Pull request #108 was opened from the issue branch.
Using "invoking-agents". Run issue #57 through the pipeline.
Expected outcome:
Issue #57 needs a human decision because the acceptance criteria conflict. The decision brief includes the exact ambiguity and attempted resolution.
Using "invoking-agents". Process issues #60 and #61 in parallel.
Expected outcome:
- Issue #60 started in its own worktree.
- Issue #61 was serialized because both classifications include the same file.
Security Audit
High RiskThe 81 static alerts are false positives caused by Markdown formatting, safe documentation references, or fixed workflow checks. Two semantic risks remain: unconfined implementer processes and unsafe shell interpolation of an untrusted issue title.
Confirmed security concerns (2)
Risk Factors
โ๏ธ External commands (50)
๐ Network access (1)
๐ Filesystem access (6)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/drix10-invoking-agents/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/drix10-invoking-agents?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/drix10-invoking-agents?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/drix10-invoking-agents/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/drix10-invoking-agents.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
drix10. (2026). invoking-agents security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/drix10-invoking-agents/audits/1BibTeX citation
@techreport{drix10-drix10-invoking-agents-2026,
author = {drix10},
title = {invoking-agents security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/drix10-invoking-agents/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "invoking-agents security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "drix10"
date-released: "2026-09-27"
url: "https://skillstore.io/skills/drix10-invoking-agents/audits/1"
identifiers:
- type: other
value: "skillstore:drix10-invoking-agents:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Deliver a GitHub Issue
Run one tracked issue through implementation, independent review, QA, and pull request creation.
Process a Local Work Item
Use acceptance criteria from local issue files when a GitHub issue is unavailable.
Enforce Review Separation
Keep implementation, review, and QA in separate processes with file-based evidence and bounded review rounds.
Try These Prompts
Implement issue #{issue_number} through the full agent-flow pipeline and open a pull request.Process the work item in {issue_file} as issue {issue_number}, then implement, review, test, and prepare a pull request.Resume issue #{issue_number} after this decision: {decision}. Preserve existing artifacts and continue from the recorded state.Classify issues {issue_numbers}, identify overlapping files, run independent worktrees in parallel, and serialize any conflicting changes.Best Practices
- Provide testable acceptance criteria before starting the pipeline.
- Use enforced containers or sandboxes for every agent that can edit or execute commands.
- Review escalation briefs and critical draft pull requests before continuing.
Avoid
- Do not combine implementer, reviewer, and QA responsibilities in one agent context.
- Do not bypass protected-path checks, review-round limits, or required human approval.
- Do not interpolate issue text directly into shell commands.