Autonomous pipeline
Run the whole engineering lifecycle end-to-end from one request — spec → plan → build → simplify → test → review → performance → ship — as a single autonomous pass with ONE human approval (the plan) and hard-gated escalation for anything irreversible. It chains the auto-* phase skills, carries a durable pipeline checkpoint so a stop/crash resumes at the exact phase and task it left off, watches the signal between phases (a phase that misses its gate is recorded blocked and surfaces in the register — fail closed, no false-green downstream), and returns a verified findings register at the end. Autonomous: it AUTO-FIXES the confirmed findings in a bounded converge-loop (never asking permission to fix), returning only the residual it can't converge within budget or a fix needing an irreversible/ambiguous decision. This is the top-level "maximise autonomous agents" entry point. Composes every auto-* phase plus checkpoint-resume, budget-guard, watch-and-act, and adversarial-verify.From its SKILL.md
npx -y skills add ulpi-io/autonomous-engineering --skill autonomous-pipelineAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
30.4 KB, ~6.7k tokens by cl100k_base, as published. Nobody here has run it
Autonomous Pipeline
Overview
One request in, shipped-quality work out — by running the eight phases as one governed pass. The pipeline is not magic autonomy; it's disciplined autonomy: a single approval, fail-closed gates between phases, a durable checkpoint, a whole-run budget, and an honest findings register at the end. It removes the human stepping between phases, not the verification each phase enforces.
Phase order and gates
auto-spec → auto-plan →[APPROVAL]→ auto-build → auto-simplify → auto-test → auto-review → auto-performance → auto-ship
│ │ │ │ │ │ │ │
testable acyclic DAG all tasks behavior- green, verified measured, no gates green,
spec + self-reviewed integrated, preserving meaningful findings correctness rollback ready,
covers spec tests green cleanups coverage (no false +) regression human sign-off
Each arrow is a fail-closed gate: a phase that misses its bar is recorded blocked (never done) and its
items surface in the register so converged is false and a resume re-enters it — no phase hands a
false-green downstream. (The pass runs forward and collects findings rather than halting mid-run; the
register, not a mid-run stop, is what carries an unmet gate to the user.) The user may configure which
optional phases run (simplify/performance/go-live can be skipped);
build/test are not skippable. (This order follows spec→plan→build first; simplify runs against the
build's test safety net, test then hardens coverage.)
Runtime backends — canonical deterministic coordinator vs. legacy Workflow
The unattended stretch runs on ONE of two backends. They are NOT peers: one is the canonical runtime, the other a Claude-only compatibility shim.
- CANONICAL — the deterministic coordinator CLI (
scripts/pipeline.mjs). A zero-dependency Node program:node autonomous-pipeline/scripts/pipeline.mjs approve|start|resume|status|authorize. This is the runtime the Codex adapter launches and the one Claude should prefer for a real run. The decisive property: no model prompt owns Git, the checkpoint, the phase gates, or the convergence decision — the coordinator library (scripts/lib/) does, deterministically. Model agents (native or Codex) appear ONLY as sandboxed, capability-free per-task engineers; Git integration (git-integration.mjs,git-workspaces.mjs), the locked checkpoint store, the fail-closed phase engine, the budget ledger, the capability-gated authorization, and the convergence conjunction (pipeline-state.mjs) are all machinery, not prose an LLM can talk its way past. A BLOCKED required gate HARD-STOPS downstream execution here (fail-closed): the run returnsstatus:blocked/converged:falseand no later phase runs.capture-intake.mjs --config <config> --scope <draft>— separate pre-plan helper that creates the write-once authority. It is not a sixth run verb because it executes before spec/plan exist.approve --plan <canonical.json> --config <run-config.json>— validates the base is approval-ready, independently compares intake→plan, inits the durable run + immutable budget, enters thepreparedwindow, and mints the ONE-USE, intake/plan/config-hash-bound capability. This IS the recorded human approval. A human MUST sit betweenapprove(mint) andstart(consume) — the coordinator can never auto-chain the gate.start --run <id>— runs every preflight refusal (intake/plan/base/config drift, wrong target, dirty tree) and consumes the one-use approval BEFORE a single executor spawns, then drives build → post-build phases and publishes ONLY as a fast-forward after the explicit convergence conjunction + a durable finalizedone.resume --run <id>continues from durable state (never erasing spend, never re-consuming the approval);status --run <id>is a read-only snapshot;authorize --run <id> --action <ship|deploy|publish|remote-merge>halts a converged run and mints a fresh, action-scoped capability for one irreversible step (a plan approval never satisfies an action). Seereferences/cli-contract.md(grammar + exit codes),references/budget-contract.md(the immutable termination set), andreferences/authorization-contract.md(capability-gated approval + irreversible actions).
- LEGACY (Claude-only) —
references/pipeline-workflow.js. A compatibility backend invoked via the Claude CodeWorkflowtool. The Codex adapter cannot select it (a Workflow needs the Claude Code runtime). Because a Workflow cannot ask the user or hard-pause mid-run, it does ONE FORWARD PASS collecting findings rather than hard-stopping on a blocked gate — an honestly-different shape documented inreferences/pipeline-state.md. Prefer the canonical CLI; reach for the Workflow only on a Claude-only install where launching the CLI is not an option.
Phase 0: Intake — request, config, budget, mode
- Ultracode precheck (parallel-effort mode — WARN, never block; runs on new runs AND resumes).
Build → review → verify fan out across many CONCURRENT agents (the
Workflowbackend + the Phase 1 concurrency caps). That concurrency only materializes at the session's top runtime effort level,ultracode— a harness mode (ultrathink-style), NOT the staticeffort: highin this skill's frontmatter. Check it: Claude Code surfaces the state in your session context (a system-reminder noting ultracode on/off; theWorkflowtool being your standing default is the tell). If you cannot confirm it is on, tell the user in one line — "For the fastest run, enable ultracode, the max effort level for parallel work, so the build fans out across parallel agents:/effort ultracode, set the effort level to its max, or includeultracodein your request. Optional — without it the pipeline still completes with the SAME gates, checkpoints and findings register, just sequentially (slower)." Then proceed either way; never gate the run on this. - Detect new run vs resume (
$request= "resume" / a pipeline checkpoint id → resume; skip intake, load the checkpoint, continue at the recorded phase). - New run: capture the request; ask the FEW configuration questions (
AskUserQuestion): which optional phases to run (simplify, performance, go-live/ship-deploy), and any budget/scope steer. Keep it light. - Make the selected scope binding before spec — as an independent artifact, not a plan field alone.
Choose the run id/config first. Expand a named selection (for example,
Full MVP = PRD §13.1) into an intake draft{run, selection, selectedScope:[{id,title,source}]}. Then runnode <skill-dir>/scripts/capture-intake.mjs --config <absolute-run-config.json> --scope <absolute-intake-draft.json> --json. It atomically writes the canonical, write-once snapshot to<stateDir>/intake/<run>.json; an identical recapture is idempotent and any changed recapture is refused. Do this before auto-spec/auto-plan and pass that snapshot path/content to both. If the initial itemization itself must change, start a new run id (a later per-id reduction remains an acknowledgedscopeDrops[]record). The snapshot — not the spec or plan's copy — is the scope authority. - Codex delegation (D14 — offer ONLY if detected). Probe for a Codex integration (
command -v codex, or acodex-type subagent in your available agents). If — and only if — one is present, offer the user a choice to delegate any of three roles to Codex: build (the per-task engineer), review (the slice + dimension reviewers), verify (the adversarial finding-verifiers). Pass their choice asdelegate: { build|review|verify: 'native'|'codex' }. If Codex is NOT detected, do not mention it — every role runs native. (At run time, acodexrole with no integration DEGRADES to native and the degradation is recorded in the register — never a silent skip.) - Note which specialists are actually installed — the subagent types available to you and the domain
skills in your available-skills list.
auto-planroutes each task to the best fit BY DESCRIPTION (a Next.js task → whatever React/SSR specialist exists, whatever it's named), and you pass that installed set to the Workflow asavailableAgentsso a plan-assigned name that isn't present here degrades to a general engineer (recorded inmissingAgents) instead of hard-failing. Never route on a guessed name. - Verify a git work tree + working branch and declare the pipeline
budget-guardcontract. The canonical coordinator creates its checkpoint only at approval, after independently comparing plan to intake. The legacy backend creates its checkpoint after plan approval as described below.
Success criteria: run mode determined; write-once intake snapshot captured before spec; ultracode precheck surfaced (or confirmed on); phase config + budget set; git preflight passed.
Phase 1: Run the lifecycle (one approved pass)
The skill owns the human-facing front half (intake, spec, plan, and the single approval); a backend owns
the unattended stretch. Pick the backend by install: Codex (and any Claude run that prefers determinism)
uses the canonical CLI — after the approval is RECORDED (pipeline.mjs approve, which mints the one-use
capability), a human confirms and the run is launched with pipeline.mjs start --run <id>; Git,
checkpoints, gates and convergence are the coordinator's, never a prompt's (see Runtime backends
above). The steps below describe the legacy Claude Workflow path (references/pipeline-workflow.js),
which the Codex adapter cannot select:
- spec → plan run first, in-session, by FOLLOWING their contracts (they may ask questions, so they
stay outside the Workflow). Compose them by CONTRACT, not by a programmatic
Skill()call:auto-spec,auto-plan,auto-mapandauto-learnaredisable-model-invocationskills (expensive, explicit- invocation only), and the docs are explicit that dmi blocks programmatic invocation — so aSkill(auto-spec)from here would fail. Instead read the installed skill'sSKILL.md(find it under.claude/skills/,.agents/skills/, or the plugin root) and execute its phases directly; if it isn't installed, apply the methodology inline. Pass the independent intake snapshot path/content to both phases; auto-plan runs its validator with--intake <snapshot>. At the SINGLE approval gate, render SCOPE COVERAGE: N of M selected-scope items covered and list every uncovered id. A general plan approval never authorizes a drop: ask for and record a separate, unambiguous acknowledgement for each proposed drop id, update the plan, re-run its gate, and only then ask for the plan approval. - Create the checkpoint (
checkpoint-resume'sscripts/checkpoint.mjs init) — the Workflow sandbox has no filesystem access, so the skill creates the status file before launch. Pass--required-phases "build,test,review,auto_learn,auto_map" --require-validationso the store itself refuses a prematuredone. Pass--launch '{"scriptPath":"<pipeline-workflow.js>","args":{…the full launch args including intakePath and intakeScope…}}'so the exact relaunch recipe is persisted IN the status file — thenrun-status.mjs --resumecan reconstruct the resume with no session memory. - Launch
references/pipeline-workflow.jsvia the Workflow tool with full args:- required:
root,workingBranch,validate(the whole-workspace end-state gate),planPath(the approved DAG plan),intakePath(the write-once snapshot),intakeScope(its parsed complete object),approved: true,statusFile,checkpointCli(absolute path tocheckpoint-resume/scripts/checkpoint.mjs— the status-writer agents call it). - routing/quality:
availableAgents(the installed specialist set from Phase 0 — each task's plan-assigned agent/reviewer is honored when present, degrades to general when not, recorded inmissingAgents),allowGeneralFallback(default true — degrade a missing specialist rather than crash), andplanValidator(absolute path toauto-plan/scripts/validate-plan.mjs— the DETERMINISTIC DAG gate preflight runs; pass it so a cyclic/mis-ordered plan can't pass on model judgment. Without it, preflight falls back to an LLM plan check). - budget/config: the optional-phase
config({simplify, performance, shipPrep}),budgetFloor(default 60000 — stop-and-report at a phase boundary once the run dips below it), the concurrency caps (maxBuildParallel,maxParallel,maxFixper-task,maxFixRoundsfor the Phase-2 register converge-loop), anddelegate(D14 — the per-role Codex choice). It executes build → simplify → test → review → performance → ship-prep with fail-closed gates (a phase agent that died = a gate failure in the register; skipped ≠ clean), the DAG walk with worktree isolation and bounded fix loops (each engineer/reviewer routed to its task's specialist), and per-task checkpoint writes. It hard-throws withoutapproved: true— the human gate cannot be bypassed. Its return fieldworkflowConvergeddescribes only this ordinary pass; its finalconvergedremains false because the outer skill still owns whole-register remediation and the required closeout.
- required:
- AROUND the workflow (before launch / after it returns), use
watch-and-actto gate on external signals — e.g. CI green on the pushed branch before offering a fix round. (A Workflow cannot invoke skills mid-run.) - Any escalation (unfixable/ambiguous/irreversible) surfaces in the returned register and PAUSES the pipeline; on resolution, re-invoke — the checkpoint resumes at the exact phase/task.
Querying a run (any time, from any session): node <checkpoint-resume>/scripts/run-status.mjs
renders the newest run — phases, per-task progress, the open register, and the resume command — READ-
ONLY, so it's safe to run while the pipeline is in flight. --list shows all runs; --resume emits the
exact Workflow call to continue. This is how the user checks "where's my run at?" without touching it.
Native /goal framing (Claude Code): for a fully unattended run, set the session goal to the
pipeline's Output Contract before launching — /goal pins the done-condition ("selected scope is fully
covered; the whole actionable register is empty; every gate and final validation passed; durable
auto_learn and auto_map receipts are done") and the platform's independent verifier model
checks it, so the actor never grades itself. See converge-loop's
references/native-goal-loop.md for the full termination-set → /goal compilation.
See references/pipeline-state.md for the state machine, per-phase gate conditions, and the handoff
contract.
Success criteria: each ordinary phase reached its success bar before the next began; the checkpoint reflects progress; escalations reached the user, not a guessed-through continuation. This phase alone never claims final lifecycle convergence.
Phase 2: Fix to convergence (bounded auto-loop)
- Build ONE whole-run actionable register from every current source: build/blocked units, simplify,
test, review, performance, ship-prep, integration, final validation, and closeout. Severity never makes a
defect non-actionable. Exclude only a pure informational observation or a selected-scope drop the user
explicitly acknowledged for that id; a selected-scope item can never be relabeled info/deferred. Dedup,
then
adversarial-verifythe aggregate so only real items enter the fix loop. - "Fix all" means that complete actionable register, not the findings from one review pass or one file.
Run a BOUNDED fix converge-loop on it — do NOT ask permission: fix the findings
(slice-scoped, each staying inside its task's write scope), regression-test, re-review, and repeat until
the register clears. After every round, persist its resolutions/new findings and re-read the CURRENT
durable register before deciding whether it is dry; newly exposed regressions join the same loop. The
loop's termination set is explicit and declared up front (
converge-loop+budget-guard): a max round cap, the whole-run budget floor, and a no-progress/thrash stop. - STOP the loop and return the STILL-OPEN residual ONLY when a termination condition fires — budget/cap exhausted without convergence, no progress across a round, or a fix that needs an irreversible or ambiguous human decision (that one escalates and asks). Exhausted ≠ converged: report the residual as OPEN with the termination reason, never a fabricated green.
Success criteria: the complete current actionable register is driven to clean, OR the honestly-open residual is returned WITH the termination reason — and no permission question was asked about fixing confirmed findings.
Phase 2b: Close every run
- After EVERY run, including blocked, exhausted, and aborted runs, follow the
auto-learncontract by CONTRACT (it is a dmi skill: read its installedSKILL.mdand execute it; do not callSkill()). Harvest the checkpoint's aggregate register, blocked units, and degradations into verified, routed learnings. Recordauto_learnasrunning, thendoneonly after the contract actually succeeds; missing/dead/red recordsblockedand remains in the actionable register. - After every non-aborted run, follow
auto-maponly afterauto_learnis done. Refresh and verify the disclosure-tiered context map, then record the durableauto_mapreceipt. A blockedauto_learnleavesauto_mapunrun/upstream-blocked; neither receipt may be inferred from report prose. - Re-read the approved plan and durable checkpoint. Refuse final
doneunless every selected-scope id is task-mapped or separately acknowledged as dropped, the whole actionable register is empty, final validation is green, and both required closeout receipts aredone. Only then callcheckpoint.mjs finalize <file> done; otherwise finalizeneeds_attentionwith the exact residual.
Success criteria: closeout is attempted in order and durably receipted; a real run cannot report converged/done without both receipts. An aborted run still learns and reports that map was inapplicable, never that it ran.
Phase 3: Report
Read the pipeline checkpoint and report end-to-end (see Output Contract): what each phase produced, which gates ran vs. were skipped (by user config), what shipped, and the open register. Fail closed — a run with a dead gate, red end-state, uncovered scope, actionable register item, or missing closeout receipt is not "done".
Success criteria: an honest, phase-by-phase account; the durable checkpoint reflects the final state.
Common Rationalizations
| Rationalization | Reality |
|---|---|
| "It's autonomous, so just return the findings and let the user fix them." | Autonomous means it FIXES what it finds — it never asks permission to fix confirmed blockers. It auto-fixes to convergence. |
| "Fix all meant the 19 review findings; the other register can be follow-up." | Fix all means the entire current actionable register across every phase and severity. Only information or a separately approved scope drop is outside it. |
| "Auto-fix means loop until everything's perfect." | Auto-fix is BOUNDED: a max round cap + the run budget + a no-progress stop. It converges, or returns the open residual honestly. Unbounded looping is the multi-hour-grind failure mode; the termination set prevents it. |
| "Build came back with blocked tasks but let's just run review anyway." | A phase that didn't meet its bar hands a false-green downstream. Gates fail closed — pause or escalate. |
| "The user approved the plan, so I can deploy too." | Plan approval ≠ deploy approval. Irreversible steps in any phase still need explicit sign-off. |
| "Resume by re-running from spec, it's cleaner." | That redoes finished work and can diverge from what shipped. Resume from the checkpoint at the recorded phase. |
| "Report it as shipped — most of it worked." | Partial is not done. Report what shipped, which gates ran, and the open register honestly. |
| "Learn/map are useful follow-ups; the product is already done." | They are required closeout phases. Without both durable receipts the run is not converged/done. |
| "Skip the budget, the phases have their own." | The lifecycle is long; phase budgets don't bound the whole. Declare a pipeline budget too. |
Red Flags
- The auto-fix converge-loop running WITHOUT a declared termination set (max rounds + budget + no-progress) — it must be bounded, or it's the multi-hour-grind failure mode.
- Returning confirmed, mechanically-fixable blockers UNFIXED and asking the user whether to fix them — autonomous means fix them.
- Reporting a low-severity/non-review defect outside the fix loop, or deferring a selected-scope item.
- A downstream phase started while the upstream phase had unresolved blockers.
- A deploy/irreversible step taken on the strength of the plan approval alone.
- A resume that restarted from spec and redid integrated work.
- "Shipped" reported while a gate didn't run or the end-state validate is red.
converged:trueordonewith an uncovered selected-scope id or without bothauto_learnandauto_mapdurable receipts.- No pipeline-level budget declared for a full lifecycle run.
Guardrails
- One approval gate (the plan); every irreversible/ambiguous/unfixable situation still escalates.
- Auto-fix the confirmed register to convergence, BOUNDED by a termination set (max rounds + budget + no-progress); return only the residual it can't converge or a fix needing an irreversible/ambiguous decision — never ask permission to fix confirmed findings.
- Treat "fix all" as the current whole-run actionable register, re-read after each round; severity/source never exempts a defect, and selected scope cannot be deferred without its own user-approved drop.
- Phase gates fail closed; never pass a false-green downstream.
- Durable resume from the checkpoint; never restart from spec.
- Declare and enforce a pipeline-level budget.
- Report the honest end state, caveated by which phases were skipped.
- Refuse convergence on uncovered selected scope, any actionable register item, or a missing/blocked
auto_learn/auto_mapreceipt.
When To Load References
scripts/capture-intake.mjs— the deterministic Phase-0 write-once intake capture. Run it before loading auto-spec/auto-plan for a new pipeline run; never recreate the authority from the later plan.scripts/pipeline.mjs— the canonical deterministic coordinator CLI (the Codex runtime):approve|start|resume|status|authorize. Run it (after a recordedapprove) instead of the Workflow whenever determinism is wanted or Codex is the host; itsscripts/lib/modules own Git, the checkpoint, the gates, and convergence. Read the three contracts below to drive it safely.references/cli-contract.md— the CLI's five-verb grammar, flags, and pinned exit-code table (the human-readable spec;scripts/lib/cli-contract.mjsis the enforced one). Load before scripting the CLI.references/budget-contract.md— the immutable termination set (the whole-run budget/no-progress/ escalation bound the coordinator enforces). Load when setting or reasoning about a run's budget.references/authorization-contract.md— the capability-gated plan approval + irreversible-action model (approve/authorize). Load before wiring approval or any ship/deploy/publish/remote-merge step.references/pipeline-workflow.js— the LEGACY Claude-only Workflow backend for the unattended stretch (build → simplify → test → review → performance → ship-prep, forward-pass, checkpointed). The Codex adapter cannot select it. Launch via the Workflow tool with full args after the plan approval; edit + relaunch (same scriptPath) to iterate.references/pipeline-state.md— the phase state machine, per-phase gate conditions, the phase-to-phase handoff contract, the checkpoint v2 schema, and the canonical-hard-stop vs. legacy-forward-pass divergence. Load when wiring or resuming a run.- The phase skills —
auto-spec,auto-plan,auto-build,auto-simplify,auto-test,auto-review,auto-performance,auto-ship— each runs its own phase to its own bar. checkpoint-resume(skill) — the durable pipeline + per-phase state.budget-guard(skill) — the whole-run budget + escalation contract.watch-and-act(skill) — wait on CI/deploy signals between phases.adversarial-verify(skill) — verify the returned findings register.
Output Contract
Report:
- the run config — which phases ran vs. skipped; the working branch; the single approval recorded; the intake snapshot path/hash; and SCOPE COVERAGE: N of M with covered, explicitly dropped, and UNCOVERED ids
- per phase: outcome + gate status (met its bar / blocked / skipped); which specialists the build
actually routed to (
specialistsUsed) and any plan-assigned specialist that was absent here and so ran generic (missingAgents— surface it so the user can install the missing agent/skill) - ship-prep artifacts produced (changelog + PR body draft — OPENING the PR / deploying is the user's explicitly-gated step) and the end-state validate result (honest)
- the fix-loop outcome — sources/count of the whole actionable register, the count AUTO-FIXED to convergence, informational observations/explicit scope drops reported separately, and the STILL-OPEN residual (if any) with its termination reason (budget/cap exhausted, no-progress, or an escalated irreversible/ambiguous fix) — never an unfixed register presented as a menu of choices
- the pipeline checkpoint path (durable, resumable record) + the one-liner to query it any time
(
run-status.mjsfor a rendered view,run-status.mjs --resumefor the relaunch call) - closeout receipts —
auto_learnandauto_mapeach ran/done or the exact blocker; never report converged/done unless both are durablydone
What ships with it: 20 files
336.1 KB alongside SKILL.md, 16 of them executable
references/
- authorization-contract.md8.0 KB
- budget-contract.md6.7 KB
- cli-contract.md7.0 KB
- pipeline-state.md13.7 KB
- pipeline-workflow.jsruns47.3 KB
scripts/
- capture-intake.mjsruns3.1 KB
- lib/authorization.mjsruns25.7 KB
- lib/budget-ledger.mjsruns21.8 KB
- lib/build-engine.mjsruns19.0 KB
- lib/cli-contract.mjsruns10.9 KB
- lib/codex-executor.mjsruns9.6 KB
- lib/git-integration.mjsruns23.7 KB
- lib/git-workspaces.mjsruns13.0 KB
- lib/intake-scope.mjsruns10.7 KB
- lib/phase-engine.mjsruns20.5 KB
- lib/pipeline-engine.mjsruns42.6 KB
- lib/pipeline-state.mjsruns17.2 KB
- lib/process-runner.mjsruns8.2 KB
- lib/review-panel.mjsruns18.2 KB
- pipeline.mjsruns9.3 KB