autopilot
Use when a human has an approved delivery plan and wants the full chain run under phase gates. Not for planning, open-ended debugging, or single-step execution: use work directly.
Install
npx skills add https://github.com/OutlineDriven/outline-driven-development/tree/main/.devin/skills/autopilot
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install outlinedriven-outline-driven-development@llmmart
git clone https://github.com/OutlineDriven/outline-driven-development.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole outlinedriven/outline-driven-development collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
Autopilot
Contract
| Field | Bound contract |
|---|---|
| Trigger | A human explicitly invokes /autopilot with a feature description and an approved execution plan. |
| Authority | Human-gated: previews the exact target and consequence before credentials, paid actions, data-at-rest changes, publication, deployment, remote bulk mutation, or irreversible deletion, continuing only when the invocation covers that consequence; every other write is reversible local, with version control as the rollback. Pass authorized push and PR targets to review-and-ship; do not publish directly. |
| Side effect | Delegates implementation, simplification, review, and finalization to their respective skills; local artifacts are written by work, commits and PR are created by review-and-ship. No mutation is performed by autopilot itself. |
| Done | Return DONE only after the requested close-out state is observed. Otherwise return BLOCKED with a resumable handoff. |
Inputs
Required: feature description, approved plan, repository, acceptance criteria, and close-out condition.
Optional: scope limits; assigned executor; target branch, remote, and PR destination; required checks; shipping instructions. Derive an omitted value only when repository evidence gives one safe, unique answer.
Procedure
- Parse the plan, scope, assignments, acceptance criteria, repository, required proof, shipping destination, and close-out condition. Reject contradictions and unavailable assigned executors. Done when: every required input is parsed and bound to a concrete value, contradictions are rejected with the conflicting pair named, and unavailable executors are reported; or the run stops on the first unresolvable input.
- Confirm that the human approved the plan. If not, stop before implementation and route to planning. Done when: an approval record is confirmed; the plan was approved through plan mode or an equivalent written approval; or the run stops and routes to planning with no delegation.
- Inspect enough repository evidence to bind the plan to exact artifacts, behavior, verification, and remote targets. Keep the campaign inside the approved scope. Done when: every plan step maps to a named repository artifact (file, directory, or remote target) and the scope boundary is stated with the artifacts inside it and the artifacts excluded from it.
- Preview each risky consequence. Stop when authority is absent or the target is ambiguous. Done when: every credential, paid, data-at-rest, publication, deployment, remote bulk, or irreversible consequence is previewed with its exact target, or the run stops naming the absent authority or ambiguous target.
- Delegate the bounded plan to
workin orchestrated mode. Include acceptance criteria, constraints, repository evidence, required verifier, and the required structured return.workowns implementation and local verification; autopilot does not reproduce those steps. Apply the gate state machine inreferences/pipeline-gates.md: a failing work verifier gets onestrike-the-rootpass and one recheck; a second failure halts the chain. Done when:workreturns a structured result with implementation summary and local verification passing, or the gate halts the chain with the verifier failure and diff recorded. - Delegate simplification to
simplifyon the completed diff. Gate:simplifyexits0,11, or12with behavior preserved. Halt on exit14(new bloat) or15(mixed-concern). Done when:simplifyreturns exit0,11, or12with behavior preserved confirmed by its output, or the chain halts on exit14or15with the exit code and cause recorded. - Delegate review to
reviewon the in-scope change. If critical or high findings remain, delegate onestrike-the-rootpass and re-review the changed files. Halt on residual critical or high findings. Done when:reviewreturns zero critical and zero high findings on the changed files, or the chain halts with the residual findings listed. - Delegate finalization to
review-and-ship. Pass the reviewed diff, explicit delegated shipping authority, branch, remote, PR destination, required checks, and shipping instructions. The finalizer owns checks, commits, publication classification, push, and PR creation or update; autopilot performs none of them. Done when:review-and-shipreturns its report with checks green and PR created or updated (full mode) or commits made and push skipped (local-only), or the finalizer returns blocked with its reason. - Observe authorized close-out. Route any supported in-scope fix back through
workin orchestrated mode, repeat affected gates, and invokereview-and-shipfor each authorized update. Do not merge, deploy, or publish elsewhere without matching authority. Done when: the close-out condition named in the inputs is observed in repository or remote state, or the run stops for absent authority. - Return the terminal classification and include the finalizer report. The gate and handoff formats in
references/pipeline-gates.mdare binding. Done when: the terminal result isDONEwith the finalizer report attached and close-out state quoted, orBLOCKEDwith the failed stage, reason, and next action named.
Failure and recovery
Stop on a missing approved plan, contradictory input, unavailable executor, ambiguous target, absent authority, failed gate, non-converging review, rejected remote mutation, or incomplete close-out. Preserve successful in-scope work and observed remote state. Recover only mutations made by this run, using reversible repository or hosting operations; never discard unrelated work.
Return BLOCKED with the failed stage, exact reason, autofix result, partial artifacts, remote mutations, proof state, recovery state, and the single concrete requirement to resume. Never claim rollback, publication, or close-out without observing it.
Output
Exactly one terminal result:
DONE: delivered behavior, changed artifacts, verification evidence, branch and PR, the completereview-and-shipreport, and observed close-out state.BLOCKED: failed stage, reason, partial result, remote state, proof and recovery status, and the next required action.
Files (outline-driven-development)
-
agents
-
openai.yaml 200 B
interface: display_name: "Autopilot" short_description: "Use when a human has an approved delivery plan and wants the full chain run under phase gates." policy: allow_implicit_invocation: false
-
-
references
-
pipeline-gates.md 5.8 KB
# Autopilot: pipeline gates and the autofix-then-halt state machine This file is the authoritative source for every phase gate, its autofix arm, and halt behavior. `SKILL.md` summarizes the process; this file defines the exact criteria and state machine. On any conflict, this file governs the mechanics and `~/.claude/claude/system-prompt-baseline.md` governs doctrine. ## The autofix-then-halt state machine One generic transition runs every phase. `P` is the current phase, `G(P)` its gate, `A(P)` its autofix arm (may be none). ``` RUN(P): invoke the phase's skill CHECK(P): evaluate G(P) pass -> ADVANCE fail, A(P) none -> HALT(P) fail, A(P) set -> AUTOFIX(P) [only if not already attempted this phase] AUTOFIX(P): invoke A(P) exactly ONCE; then RECHECK(P) RECHECK(P): evaluate G(P) pass -> ADVANCE fail -> HALT(P) [never a second AUTOFIX] ADVANCE: P := next phase in {1..6}, skipping phases disabled by local-only; goto RUN(P) HALT(P): stop the chain; collect residual findings from P; jump to Phase 6 (Report) with halt=P ``` Invariants the machine enforces: - **Once.** `AUTOFIX(P)` fires at most one time per phase. A failing `RECHECK` always routes to `HALT`, never back to `AUTOFIX`. Looping an arm to green hides a bad plan and compounds risk across a growing surface. - **No red advance.** `ADVANCE` is reachable only from a passing `CHECK`/`RECHECK`. A red gate never enters the next phase. - **Report is terminal and unconditional.** Both the success tail (after Phase 5/ADVANCE past the last enabled phase) and every `HALT(P)` route to Phase 6. ## Precondition: before Phase 1 The chain begins only when an approved plan exists: one the user approved through Claude Code's built-in plan mode (`ExitPlanMode`), or an equivalent written plan the user has approved. autopilot never produces it; "scope unknown" is not autofixable and has no arm. Fails → do not start; HALT before Phase 1 and hand off to upstream `askme` / `strategy`, where the user must supply an execution-ready task. ## Per-phase gate definitions Gate id equals phase number; there is one numbering system, not two. Phase 4 (`strike-the-root`) is G3's autofix arm and Phase 6 (Report) is terminal; both are gateless, so **there is no G4 and no G6**. The absence is the signal that those phases are not independently gated. | Gate | Phase / skill | Pass criteria (exact) | Autofix arm A(P) | On RECHECK still-fail | |------|---------------|-----------------------|------------------|-----------------------| | G1 | Phase 1 Execute / `work` (Orchestrated) | `work` runs in its Orchestrated caller mode, implementation and local verification only, returning a structured summary; the plan's steps are implemented and the repo-native verifier (build / type-check / test, as the repo defines) exits clean. It must not run simplify/review/PR/CI; autopilot owns those. | `strike-the-root` once, in findings/verifier-failure mode, on the failing verifier output | HALT → hand off the verifier failure and the diff so far | | G2 | Phase 2 Simplify / `simplify` | `simplify` exits `0`, `11` (empty diff), or `12` (false-positive-only); behavior preserved. | none distinct, `simplify` self-reverts a behavior regression (its exit `13`) internally | HALT on exit `14` (new bloat) or `15` (mixed-concern commit): these need a human re-plan | | G3 | Phase 3 Review / `review` (autofix = Phase 4 `strike-the-root`) | After at most one `strike-the-root` pass and a re-review of the changed files, no critical or high finding remains. | `strike-the-root` once on the review's critical/high findings, then re-review changed files only | HALT → hand off residual critical/high findings | | G5 | Phase 5 Finalize / `review-and-ship` | `review-and-ship` report returned: checks green and PR created/updated (full mode), or commits made and push skipped (local-only). The report carries review findings, check results, publication classification, and PR URL or local-only status. | none; a finalizer refusal (push refused, checks blocked) is a deliberate safety stop, not a defect to patch | HALT → hand off the finalizer's blocked report and the unpushed commits | Phase 4 (`strike-the-root`) and Phase 6 (Report) have no gate; Report always runs. ## Local-only detection Run `git remote`. Empty output → local-only; also forced by `mode:local`. Local-only effect: - **Phase 5 (G5)**: `review-and-ship` runs the local check suite, makes atomic commits, and skips push and PR creation. No remote is invented. The report states `mode: local-only` with the unpushed commit list. - Phase 6 (Report) still runs and the report states `mode: local-only` with the unpushed commit list. ## Halt handoff format On `HALT(P)`, Phase 6 emits a handoff so the next operator resumes without re-deriving state: ``` HALT at <Phase P — gate G?> reason: <one line — what the gate measured and why it stayed red> autofix tried: <A(P) name + outcome | none — not autofixable> residual: <the findings / verifier output / refusal that remain> state: <commits made (sha + subject), pushed? PR url?, working-tree dirty?> next: <the single action that unblocks — e.g. "return to plan mode for a narrower approved plan", "resolve test X", "authorize push to <branch>"> ``` ## Report format (success or halt) ``` autopilot report mode: <full | local-only> [+ headless] task: <one line> phases: 1 Execute ✓ 2 Simplify ✓ 3 Review ✓ 4 Strike-the-root <ran once | skipped, G3 clean> 5 Finalize <✓ | local-only> gates: <G1 G2 G3 G5 pass/fail, with the autofix arm noted where it fired> commits: <sha + subject per commit> remote: <pushed branch / PR url | local-only, not pushed> outcome: <shipped | HALT at Phase P — see handoff above> ```
-
-
SKILL.md 6.3 KB
--- name: autopilot description: 'Use when a human has an approved delivery plan and wants the full chain run under phase gates. Not for planning, open-ended debugging, or single-step execution: use work directly.' disable-model-invocation: true --- # Autopilot ## Contract | Field | Bound contract | |---|---| | Trigger | A human explicitly invokes `/autopilot` with a feature description and an approved execution plan. | | Authority | Human-gated: previews the exact target and consequence before credentials, paid actions, data-at-rest changes, publication, deployment, remote bulk mutation, or irreversible deletion, continuing only when the invocation covers that consequence; every other write is reversible local, with version control as the rollback. Pass authorized push and PR targets to `review-and-ship`; do not publish directly. | | Side effect | Delegates implementation, simplification, review, and finalization to their respective skills; local artifacts are written by `work`, commits and PR are created by `review-and-ship`. No mutation is performed by autopilot itself. | | Done | Return `DONE` only after the requested close-out state is observed. Otherwise return `BLOCKED` with a resumable handoff. | ## Inputs Required: feature description, approved plan, repository, acceptance criteria, and close-out condition. Optional: scope limits; assigned executor; target branch, remote, and PR destination; required checks; shipping instructions. Derive an omitted value only when repository evidence gives one safe, unique answer. ## Procedure 1. Parse the plan, scope, assignments, acceptance criteria, repository, required proof, shipping destination, and close-out condition. Reject contradictions and unavailable assigned executors. Done when: every required input is parsed and bound to a concrete value, contradictions are rejected with the conflicting pair named, and unavailable executors are reported; or the run stops on the first unresolvable input. 2. Confirm that the human approved the plan. If not, stop before implementation and route to planning. Done when: an approval record is confirmed; the plan was approved through plan mode or an equivalent written approval; or the run stops and routes to planning with no delegation. 3. Inspect enough repository evidence to bind the plan to exact artifacts, behavior, verification, and remote targets. Keep the campaign inside the approved scope. Done when: every plan step maps to a named repository artifact (file, directory, or remote target) and the scope boundary is stated with the artifacts inside it and the artifacts excluded from it. 4. Preview each risky consequence. Stop when authority is absent or the target is ambiguous. Done when: every credential, paid, data-at-rest, publication, deployment, remote bulk, or irreversible consequence is previewed with its exact target, or the run stops naming the absent authority or ambiguous target. 5. Delegate the bounded plan to `work` in orchestrated mode. Include acceptance criteria, constraints, repository evidence, required verifier, and the required structured return. `work` owns implementation and local verification; autopilot does not reproduce those steps. Apply the gate state machine in `references/pipeline-gates.md`: a failing work verifier gets one `strike-the-root` pass and one recheck; a second failure halts the chain. Done when: `work` returns a structured result with implementation summary and local verification passing, or the gate halts the chain with the verifier failure and diff recorded. 6. Delegate simplification to `simplify` on the completed diff. Gate: `simplify` exits `0`, `11`, or `12` with behavior preserved. Halt on exit `14` (new bloat) or `15` (mixed-concern). Done when: `simplify` returns exit `0`, `11`, or `12` with behavior preserved confirmed by its output, or the chain halts on exit `14` or `15` with the exit code and cause recorded. 7. Delegate review to `review` on the in-scope change. If critical or high findings remain, delegate one `strike-the-root` pass and re-review the changed files. Halt on residual critical or high findings. Done when: `review` returns zero critical and zero high findings on the changed files, or the chain halts with the residual findings listed. 8. Delegate finalization to `review-and-ship`. Pass the reviewed diff, explicit delegated shipping authority, branch, remote, PR destination, required checks, and shipping instructions. The finalizer owns checks, commits, publication classification, push, and PR creation or update; autopilot performs none of them. Done when: `review-and-ship` returns its report with checks green and PR created or updated (full mode) or commits made and push skipped (local-only), or the finalizer returns blocked with its reason. 9. Observe authorized close-out. Route any supported in-scope fix back through `work` in orchestrated mode, repeat affected gates, and invoke `review-and-ship` for each authorized update. Do not merge, deploy, or publish elsewhere without matching authority. Done when: the close-out condition named in the inputs is observed in repository or remote state, or the run stops for absent authority. 10. Return the terminal classification and include the finalizer report. The gate and handoff formats in `references/pipeline-gates.md` are binding. Done when: the terminal result is `DONE` with the finalizer report attached and close-out state quoted, or `BLOCKED` with the failed stage, reason, and next action named. ## Failure and recovery Stop on a missing approved plan, contradictory input, unavailable executor, ambiguous target, absent authority, failed gate, non-converging review, rejected remote mutation, or incomplete close-out. Preserve successful in-scope work and observed remote state. Recover only mutations made by this run, using reversible repository or hosting operations; never discard unrelated work. Return `BLOCKED` with the failed stage, exact reason, autofix result, partial artifacts, remote mutations, proof state, recovery state, and the single concrete requirement to resume. Never claim rollback, publication, or close-out without observing it. ## Output Exactly one terminal result: - `DONE`: delivered behavior, changed artifacts, verification evidence, branch and PR, the complete `review-and-ship` report, and observed close-out state. - `BLOCKED`: failed stage, reason, partial result, remote state, proof and recovery status, and the next required action.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.