execute-task
The execution loop. Three sources converge:
- Plan (HOW) —
docs/superpowers/plans/*.md produced by GENERATE
- TaskMaster (WHAT) —
.taskmaster/tasks/tasks.json with
dependencies and complexity scores
- CDD (PROOF) — acceptance cards per task, evidence-gated
execute-task is the single skill that runs the full build from "tasks are
ready" to SHIP_CHECK_OK. It is autonomous — no AskUserQuestion inside the
loop. Any gap that would require user input is surfaced through the recon
escalation ladder (step 11) or the inbox (steps 4 and 8), never via a modal
prompt.
Entry
This skill is invoked either:
- Directly by the user once HANDOFF has completed and a task-execution
mode (A/B/C) has been dispatched, or
- By the
prd-taskmaster orchestrator when current_phase is EXECUTE.
On entry, confirm that:
.atlas-ai/state/pipeline.json exists and records phase: EXECUTE
.taskmaster/tasks/tasks.json exists with at least one ready task
.atlas-ai/customizations/system-prompt-template.md is present (may be
empty — absence is a setup bug, empty is fine)
If any of the above are missing, report the gap and halt. Do NOT attempt to
bootstrap the missing artifact from inside this loop — that is the
orchestrator's job.
Cycle (per iteration)
Each pass through this cycle moves exactly one TaskMaster task from pending
to done. Do the 13 steps in order. Do not skip.
Task-start SHA — at the very beginning of each iteration (before step 2),
capture the current git HEAD:
task_start_sha=$(git rev-parse HEAD)
Record $task_start_sha in the execute-log row for this iteration. It is the
oracle of truth for every reachability sweep in step 9b below: "what modules
did THIS task add?" is diff $task_start_sha..HEAD. The oracle flow already
issues per-task start commits; this surfaces the same value in the loop prose.
Heartbeat check: verify the execute-task heartbeat timer is running.
If missing, register one via CronCreate("execute-task-heartbeat", "* * * * *", "echo heartbeat").
Abort the iteration if the timer cannot be created — a missing heartbeat
means a missing stuck-session detector, and that is load-bearing.
Inbox reconciliation: read .atlas-ai/state/pipeline.json,
.taskmaster/tasks/tasks.json, and the current TodoWrite list.
Diff them. If the three are stale by more than 5 tasks (i.e. TodoWrite
says 10 done but tasks.json says 3 done), report the diff and halt — do
not paper over bookkeeping drift by silently reconciling.
Pick next task: run backend op next with the plugin's project-root
pointer. Use exactly this invocation:
python3 script.py next-task
Parse the JSON result.
- If no ready tasks and all tasks are
done, run .atlas-ai/ship-check.py,
emit SHIP_CHECK_OK on success, exit the loop.
- If no ready tasks but pending tasks exist, the dependency graph is
deadlocked — report and halt.
Load plan step: search for the matching task ID in this priority
order, halting only after all three fail:
docs/superpowers/plans/*.md (the superpowers GENERATE default output)
.taskmaster/docs/plan.md (the prd-taskmaster HANDOFF default output,
whose path is also recorded in
pipeline.json:phase_evidence.HANDOFF.plan_file_path)
- Any custom path declared in
pipeline.json:phase_evidence.HANDOFF.plan_file_path (in case
a future handoff variant writes elsewhere)
If none of the three contains the matching task ID, the task was
invented downstream of the plan — mark the task blocked, inbox the
parent orchestrator with message_type="blocker", and continue to the
next iteration.
(Codified 2026-06-04 — yesterday's ai-human-tasker run had its plan at
.taskmaster/docs/plan.md only, while this step previously read
docs/superpowers/plans/*.md exclusively. The controller silently
improvised; a cold-start successor would have hit the blocked path on
every task.)
Generate CDD card: convert the task's subtasks field into a
testing_plan. Each subtask becomes a verifiable check with a concrete
evidence path (file, command output, or test name). Write the card to
.atlas-ai/cdd/task-<id>.json. A task without subtasks is treated as a
single RED card.
Set in-progress: run backend op set-status from the current project
root:
python3 script.py set-status --id <N> --status in-progress
This flip is
observable by watchers and anchors the iteration in TaskMaster itself.
Dispatch implementer subagent — NEVER in-session. The controller
must:
- Provide the FULL task text to the subagent. Never tell the subagent to
"read tasks.json" — per spec §12, the controller serialises the task
into the dispatch prompt.
- Inject the plugin customisation block at
.atlas-ai/customizations/system-prompt-template.md
into the subagent's system prompt. If the file is empty, inject nothing
and continue.
- Tier the model by TaskMaster complexity score:
1-4 fast — use the fast tier (Haiku-class)
5-7 standard — use the standard tier (Sonnet-class)
8-10 capable — use the capable tier (Opus-class)
- Wait for the subagent to return a terminal status:
DONE,
DONE_WITH_CONCERNS, NEEDS_CONTEXT, or BLOCKED.
Rationale: complexity-tiered dispatch keeps the dollars-per-task curve
sensible. A complexity-2 boilerplate task does not need Opus; a
complexity-9 architectural task should not be given to Haiku.
Route by status: the subagent's return status drives the next move.
- DONE — proceed to the spec gate, then the quality gate. If both
pass, advance to step 9.
- DONE_WITH_CONCERNS — the subagent completed but flagged concerns.
Address each concern before advancing; re-dispatch if needed.
- NEEDS_CONTEXT — the subagent requested more context. Provide the
requested context and re-dispatch. Retry cap at 2 — if the subagent
still returns NEEDS_CONTEXT after two re-dispatches, escalate via the
recon ladder (step 11).
- BLOCKED — the subagent cannot proceed. Try one model-tier upgrade
first (e.g. standard -> capable). If still blocked, break the task
into smaller subtasks via backend op
expand
(python3 script.py expand --id <N>). If still
blocked, set status=blocked, inbox parent, halt this iteration.
Do NOT invent new status values. The four above are the only terminal
returns. Any other string from the subagent is a protocol violation and
should be logged + treated as BLOCKED.
Triple verification — the plugin's core quality gate, per spec §11.4.
Three independent checks must agree.
Hard exit-code gate (MANDATORY — bypasses agreement count). Before
invoking the three checkers, run .atlas-ai/ship-check.py --dry-run. If
it reports any non-zero Exit status N in evidence files, the task
FAILS regardless of how the agent narratives read. SHIP_CHECK_FAIL is
NOT a warning. Narrative claiming the exit code is "expected" or
"infrastructure noise" does NOT override this gate — write a separate
task-fix-N to address the underlying failure instead. There is NO
override path; Gate 5 is unfakable. (Codified 2026-06-04 after T12
in ai-human-tasker was marked DONE while pnpm test exited 1 with 11
failing tests.)
9b. Reachability sweep (MANDATORY for wired/live tasks). After the
hard exit-code gate passes, run the reachability sweep for this task:
python3 script.py reachability-sweep \
--task <task_id> \
--start-commit <task_start_sha>
This command:
- Inspects every source module added between
$task_start_sha and HEAD.
- Computes a per-task verdict:
WIRED, EXEMPT, ORPHAN, or ERROR.
- Writes the verdict dict into the task's CDD card
.atlas-ai/cdd/task-<id>.json under the "reachability" key (atomic,
additive — existing card keys are preserved).
The sweep exit code encodes the verdict:
exit 0 → WIRED or EXEMPT (pass; proceed to the three checkers).
exit 1 → ORPHAN or ERROR (see step 10 for the auto-downgrade path).
For spike/domain-model tasks the sweep returns EXEMPT automatically (no
importer search is performed for those tiers).
Why sweep before the triple check? A green test on a module
imported by nothing is not "done" — it is scaffolded. The triple check
can pass for an ORPHAN module (all tests pass; doubt and validate agree).
The reachability gate closes that gap: done means the module is
reachable from real production callsites, not just reachable from tests.
Wire it or it ships as scaffold.
The three checks (run only if the hard gate AND the reachability sweep both pass):
- Plugin-native check: evidence file count vs declared subtask count
(from the CDD card in step 5). Missing evidence = fail.
/doubt skill — adversarial doubt sweep on the claimed completion.
/validate skill — deterministic validation pass (lint / tests / exit
codes).
- External
Opus subagent sanity pass — asks a fresh subagent "would
you merge this?" with the task spec + diff + evidence.
3+ agree pass -> task passes. Disagreement -> halt this iteration,
surface to inbox.
Mark done + propagate state — branch on the sweep verdict from step 9b:
WIRED or EXEMPT (sweep exit 0) → proceed normally:
a. Run backend op set-status for the parent task. Because the sweep
already wrote the reachability block into the CDD card, the
set-status CLI auto-reads it — no --reachability flag needed:
python3 script.py set-status --id <N> --status done
If you want to be explicit (e.g. for logging), you may pass:
--reachability WIRED or --reachability EXEMPT.
b. Subtask writeback: for each subtask S in task.subtasks whose
evidence file (per the CDD card from step 5) exists, run
python3 script.py set-status --id <N>.<S> --status done. Subtasks left
pending while the parent is done are a data-integrity violation
that breaks any tool computing progress from subtask state.
(Codified 2026-06-04 — yesterday's run left all 39 subtasks
pending despite 13/13 parent tasks done.)
c. Update .atlas-ai/state/pipeline.json per-task: call
mcp__plugin_prd_go__update_pipeline_task_status(task_id=<N>, status="done") if the MCP tool is available. If not, fall back to
atomic read-modify-write using the pattern in
mcp-server/pipeline.py:locked_update() — read, append <N> to
phase_evidence.EXECUTE.tasks_completed, write to temp, rename.
Never leave pipeline.json and tasks.json mutually inconsistent.
(Codified 2026-06-04 — yesterday's run promised this write in
SKILL.md but never executed it. pipeline.json froze at HANDOFF
transition through all 85 minutes of execution.)
ORPHAN or ERROR (sweep exit 1) → auto-downgrade to scaffold:
Do NOT mark the task done. Instead:
python3 script.py set-status --id <N> --status scaffold
Then:
- Log to
execute-log.jsonl: "reachability_verdict": "ORPHAN" (or
"ERROR"), "auto_downgraded": true, and a plain-English note of
which modules are unwired (from the sweep's modules list in the
CDD card).
- Do NOT halt the loop — continue to the next task (step 1).
An ORPHAN module is scaffolded work, not blocked work. The ship
gate (Gate 6, RA3) will report it honestly as
scaffold, not done.
- If you need to wire the module, create a follow-up task
(
title: "Wire <module> into <entrypoint>") and append it via
python3 script.py expand --id <N> or the MCP equivalent.
Throughline: a green test on a module imported by nothing is not
done — wire it or it ships as scaffold. The auto-downgrade ensures
the task graph stays honest: Gate 6 will block the ship until every
wired/live task's reachability block reads WIRED or EXEMPT. If all
wired/live tasks auto-downgraded to scaffold, the ship check will
block at Gate 2 ("not every task is done") and the developer must
choose: wire the modules, re-tier them (spike/domain-model), or mark
them explicitly exempt (reachableVia: cli:...). There is no silent
path to SHIP_CHECK_OK with an unwired module at a wired/live tier.
Check stepback triggers: if 15 minutes have passed with no task
moving to done, OR 5 consecutive iterations have failed on the same
task class, the recon escalation ladder is MANDATORY. Climb the ladder
in this exact order, not out of order:
/stepback -> /research-before-coding -> /question -> pivot
/stepback — reassess the architectural assumption. Was the plan
wrong?
/research-before-coding — feed the blocker into the Perplexity +
Context7 + GitHub pipeline for fresh external context.
/question — batch-research the unresolved unknowns in parallel.
pivot — the plan step itself is unsound; kick the task back to the
plan author (inbox parent with message_type="plan_pivot_requested").
The ladder is append-only — if /stepback surfaces a fix, apply it and
return to step 3. Only climb if the prior rung did not yield progress.
Render progress — show the execute progress panel: MCP
render_status(phase="EXECUTE") → print its rendered field; CLI
python3 script.py status --phase EXECUTE. Then emit the atlas-gamify
one-line score (tasks done / tasks total, complexity-weighted). This is the
human-visible progress signal and also feeds the dogfood debrief.
Loop: back to step 1 until SHIP_CHECK_OK or a halt condition fires.
Termination
The termination sequence is strict — three steps, in order, no shortcuts:
- Run
.atlas-ai/ship-check.py. If it does NOT exit 0, halt. Do NOT
emit any completion signal. Investigate the gate failure, fix, retry.
- MANDATORY: invoke
Skill(skill: "sync") to refresh the memory
bank (session-context/CLAUDE-*.md, MEMORY.md, capability inventory).
This MUST happen BEFORE the SHIP_CHECK_OK token is printed.
Orchestrators tail-watch the token; if the memory bank is stale when
they react, successor sessions inherit a wrong picture of the world.
(Codified 2026-06-04 — yesterday's ai-human-tasker run shipped 15.6k
LOC while session-context/CLAUDE-activeContext.md still said
"Scaffold complete. No application code yet".)
- Print
SHIP_CHECK_OK to stdout. This is the ONLY place in your
output where the token may appear — emit it nowhere else, to avoid
false-positive matches by log-watchers.
The ship-check script is deterministic. Its gates are documented at the
top of ${CLAUDE_PLUGIN_ROOT}/skel/ship-check.py (copied to .atlas-ai/ship-check.py at setup):
- Gate 1:
pipeline.json current_phase == "EXECUTE"
- Gate 2: every
master.tasks[].status == "done"
- Gate 3: every task has a CDD card (
task-<id>.json or combined variant)
- Gate 4: plan file exists at
.taskmaster/docs/plan.md OR docs/superpowers/plans/*.md
- Gate 5 (HARD): no non-zero
Exit status N line in any evidence file
Gate 5 is the convergent must-do from the 2026-06-04 audit — a "PASS"
label on a non-zero-exit test is structurally impossible after this
script runs. There is no override path for Gate 5; it is the unfakable
oracle.
Do not emit SHIP_CHECK_OK on a mere "DONE" keyword in a subagent reply.
Do not emit on "all tasks marked done" without the explicit ship-check.
Do not emit before /sync has been called.
Red flags
These are the most common pressure points where the loop silently degrades
from "verified" to "performative". If you catch yourself thinking any of
them, stop and repair the gap.
- "Close enough, mark it done" -> NO. Evidence OR nothing.
- "Let me skip the doubt step this time" -> NO. Triple verification is non-negotiable.
- "I'll retry with same model+prompt" (BLOCKED) -> NO. Escalate.
- "The task says done, don't check evidence files" -> NO. Task status must reflect evidence.
Observability
Every iteration appends a structured row to
.atlas-ai/state/execute-log.jsonl. Field types are strict — text
narrative in a typed field is a logging bug, not compliance. The schema:
iteration (integer, or "FINAL" for the terminal marker)
timestamp (ISO 8601 string)
task_id (string)
complexity (integer or human label)
tier (string: "fast" | "standard" | "capable")
subagent_status (string: "DONE" | "DONE_WITH_CONCERNS" | "NEEDS_CONTEXT" | "BLOCKED")
retry_count (integer)
triple_verify (string: "PASS" / "FAIL" plus free-text rationale)
stepback_triggered (boolean, REQUIRED — true iff /stepback was
invoked this iteration). Putting narrative-text in this field is a
violation; use stepback_narrative instead.
stepback_narrative (string, nullable — explanation when
stepback_triggered: true; null otherwise)
ladder_rung (string, nullable — which rung was reached if escalated)
gamify (string — atlas-gamify one-line score)
The stepback fields were split (2026-06-04) after a FINAL iteration entry
wrote a paragraph of narrative into the boolean stepback field and was
treated as compliance with the stepback_mandatory rule. Boolean trigger
- nullable narrative is the correct schema.
This log is the dogfood artifact — debrief tools consume it, the
orchestrator greps it, and future runs read it for retrospective analysis.
Composition
- Orchestrator handoff: this skill is invoked post-HANDOFF. It does
not call
/handoff — that direction is one-way.
- Plan editing: if the plan is unsound, the ladder escalates to
pivot, which inboxes the plan author. This skill does not mutate the
plan in place.
- Ship-check:
.atlas-ai/ship-check.py is the terminal gate. This
skill calls it; it does not reimplement the checks.
Non-exits
This skill uses no explicit process termination. A halt condition reports
the reason in the structured log and returns control to the caller (the
user or the orchestrator). Never kill the shell — the caller owns the
session lifecycle.
1---2name: execute-task3description: Execute the next TaskMaster task using the implementation plan with CDD verification. Picks the next ready task, matches it to the plan step, implements via a dispatched subagent, verifies subtasks with evidence, marks the task done, and loops until every task is complete. Wraps the TaskMaster next -> in-progress -> done lifecycle with CDD GREEN / RED / BLUE verification and the plugin's triple-verification rule. Autonomous by design — no user prompts inside the loop.4---56# execute-task78The execution loop. Three sources converge:910- **Plan** (HOW) — `docs/superpowers/plans/*.md` produced by GENERATE11- **TaskMaster** (WHAT) — `.taskmaster/tasks/tasks.json` with12 dependencies and complexity scores13- **CDD** (PROOF) — acceptance cards per task, evidence-gated1415execute-task is the single skill that runs the full build from "tasks are16ready" to SHIP_CHECK_OK. It is autonomous — no AskUserQuestion inside the17loop. Any gap that would require user input is surfaced through the recon18escalation ladder (step 11) or the inbox (steps 4 and 8), never via a modal19prompt.2021## Entry2223This skill is invoked either:24251. Directly by the user once HANDOFF has completed and a task-execution26 mode (A/B/C) has been dispatched, **or**272. By the `prd-taskmaster` orchestrator when `current_phase` is `EXECUTE`.2829On entry, confirm that:3031- `.atlas-ai/state/pipeline.json` exists and records `phase: EXECUTE`32- `.taskmaster/tasks/tasks.json` exists with at least one ready task33- `.atlas-ai/customizations/system-prompt-template.md` is present (may be34 empty — absence is a setup bug, empty is fine)3536If any of the above are missing, report the gap and halt. Do NOT attempt to37bootstrap the missing artifact from inside this loop — that is the38orchestrator's job.3940## Cycle (per iteration)4142Each pass through this cycle moves exactly one TaskMaster task from `pending`43to `done`. Do the 13 steps in order. Do not skip.4445> **Task-start SHA** — at the very beginning of each iteration (before step 2),46> capture the current git HEAD:47>48> ```bash49> task_start_sha=$(git rev-parse HEAD)50> ```51>52> Record `$task_start_sha` in the execute-log row for this iteration. It is the53> oracle of truth for every reachability sweep in step 9b below: "what modules54> did THIS task add?" is `diff $task_start_sha..HEAD`. The oracle flow already55> issues per-task start commits; this surfaces the same value in the loop prose.56571. **Heartbeat check**: verify the execute-task heartbeat timer is running.58 If missing, register one via `CronCreate("execute-task-heartbeat", "* * * * *", "echo heartbeat")`.59 Abort the iteration if the timer cannot be created — a missing heartbeat60 means a missing stuck-session detector, and that is load-bearing.61622. **Inbox reconciliation**: read `.atlas-ai/state/pipeline.json`,63 `.taskmaster/tasks/tasks.json`, and the current TodoWrite list.64 Diff them. If the three are stale by more than 5 tasks (i.e. TodoWrite65 says 10 done but tasks.json says 3 done), report the diff and halt — do66 not paper over bookkeeping drift by silently reconciling.67683. **Pick next task**: run backend op `next` with the plugin's project-root69 pointer. Use exactly this invocation:7071 ```bash72 python3 script.py next-task73 ```7475 Parse the JSON result.76 - If no ready tasks and all tasks are `done`, run `.atlas-ai/ship-check.py`,77 emit SHIP_CHECK_OK on success, exit the loop.78 - If no ready tasks but pending tasks exist, the dependency graph is79 deadlocked — report and halt.80814. **Load plan step**: search for the matching task ID in this priority82 order, halting only after all three fail:8384 1. `docs/superpowers/plans/*.md` (the superpowers GENERATE default output)85 2. `.taskmaster/docs/plan.md` (the prd-taskmaster HANDOFF default output,86 whose path is also recorded in87 `pipeline.json:phase_evidence.HANDOFF.plan_file_path`)88 3. Any custom path declared in89 `pipeline.json:phase_evidence.HANDOFF.plan_file_path` (in case90 a future handoff variant writes elsewhere)9192 If none of the three contains the matching task ID, the task was93 invented downstream of the plan — mark the task `blocked`, inbox the94 parent orchestrator with `message_type="blocker"`, and continue to the95 next iteration.9697 (Codified 2026-06-04 — yesterday's ai-human-tasker run had its plan at98 `.taskmaster/docs/plan.md` only, while this step previously read99 `docs/superpowers/plans/*.md` exclusively. The controller silently100 improvised; a cold-start successor would have hit the `blocked` path on101 every task.)1021035. **Generate CDD card**: convert the task's `subtasks` field into a104 `testing_plan`. Each subtask becomes a verifiable check with a concrete105 evidence path (file, command output, or test name). Write the card to106 `.atlas-ai/cdd/task-<id>.json`. A task without subtasks is treated as a107 single RED card.1081096. **Set in-progress**: run backend op `set-status` from the current project110 root:111112 ```bash113 python3 script.py set-status --id <N> --status in-progress114 ```115116 This flip is117 observable by watchers and anchors the iteration in TaskMaster itself.1181197. **Dispatch implementer subagent** — NEVER in-session. The controller120 must:121122 - Provide the FULL task text to the subagent. Never tell the subagent to123 "read tasks.json" — per spec §12, the controller serialises the task124 into the dispatch prompt.125 - Inject the plugin customisation block at `.atlas-ai/customizations/system-prompt-template.md`126 into the subagent's system prompt. If the file is empty, inject nothing127 and continue.128 - Tier the model by TaskMaster complexity score:129 - `1-4 fast` — use the fast tier (Haiku-class)130 - `5-7 standard` — use the standard tier (Sonnet-class)131 - `8-10 capable` — use the capable tier (Opus-class)132 - Wait for the subagent to return a terminal status: `DONE`,133 `DONE_WITH_CONCERNS`, `NEEDS_CONTEXT`, or `BLOCKED`.134135 Rationale: complexity-tiered dispatch keeps the dollars-per-task curve136 sensible. A complexity-2 boilerplate task does not need Opus; a137 complexity-9 architectural task should not be given to Haiku.1381398. **Route by status**: the subagent's return status drives the next move.140141 - **DONE** — proceed to the spec gate, then the quality gate. If both142 pass, advance to step 9.143 - **DONE_WITH_CONCERNS** — the subagent completed but flagged concerns.144 Address each concern before advancing; re-dispatch if needed.145 - **NEEDS_CONTEXT** — the subagent requested more context. Provide the146 requested context and re-dispatch. Retry cap at 2 — if the subagent147 still returns NEEDS_CONTEXT after two re-dispatches, escalate via the148 recon ladder (step 11).149 - **BLOCKED** — the subagent cannot proceed. Try one model-tier upgrade150 first (e.g. standard -> capable). If still blocked, break the task151 into smaller subtasks via backend op `expand`152 (`python3 script.py expand --id <N>`). If still153 blocked, set status=blocked, inbox parent, halt this iteration.154155 Do NOT invent new status values. The four above are the only terminal156 returns. Any other string from the subagent is a protocol violation and157 should be logged + treated as BLOCKED.1581599. **Triple verification** — the plugin's core quality gate, per spec §11.4.160 Three independent checks must agree.161162 **Hard exit-code gate (MANDATORY — bypasses agreement count).** Before163 invoking the three checkers, run `.atlas-ai/ship-check.py --dry-run`. If164 it reports any non-zero `Exit status N` in evidence files, the task165 FAILS regardless of how the agent narratives read. SHIP_CHECK_FAIL is166 NOT a warning. Narrative claiming the exit code is "expected" or167 "infrastructure noise" does NOT override this gate — write a separate168 `task-fix-N` to address the underlying failure instead. There is NO169 override path; Gate 5 is unfakable. (Codified 2026-06-04 after T12170 in ai-human-tasker was marked DONE while `pnpm test` exited 1 with 11171 failing tests.)172173 **9b. Reachability sweep (MANDATORY for wired/live tasks).** After the174 hard exit-code gate passes, run the reachability sweep for this task:175176 ```bash177 python3 script.py reachability-sweep \178 --task <task_id> \179 --start-commit <task_start_sha>180 ```181182 This command:183 - Inspects every source module added between `$task_start_sha` and `HEAD`.184 - Computes a per-task verdict: `WIRED`, `EXEMPT`, `ORPHAN`, or `ERROR`.185 - **Writes the verdict dict** into the task's CDD card186 `.atlas-ai/cdd/task-<id>.json` under the `"reachability"` key (atomic,187 additive — existing card keys are preserved).188189 The sweep exit code encodes the verdict:190 - `exit 0` → WIRED or EXEMPT (pass; proceed to the three checkers).191 - `exit 1` → ORPHAN or ERROR (see step 10 for the auto-downgrade path).192193 For spike/domain-model tasks the sweep returns EXEMPT automatically (no194 importer search is performed for those tiers).195196 > **Why sweep before the triple check?** A green test on a module197 > imported by nothing is not "done" — it is scaffolded. The triple check198 > can pass for an ORPHAN module (all tests pass; doubt and validate agree).199 > The reachability gate closes that gap: `done` means the module is200 > reachable from real production callsites, not just reachable from tests.201 > Wire it or it ships as scaffold.202203 The three checks (run only if the hard gate AND the reachability sweep both pass):204205 - Plugin-native check: evidence file count vs declared subtask count206 (from the CDD card in step 5). Missing evidence = fail.207 - `/doubt` skill — adversarial doubt sweep on the claimed completion.208 - `/validate` skill — deterministic validation pass (lint / tests / exit209 codes).210 - External `Opus subagent` sanity pass — asks a fresh subagent "would211 you merge this?" with the task spec + diff + evidence.212213 3+ agree pass -> task passes. Disagreement -> halt this iteration,214 surface to inbox.21521610. **Mark done + propagate state** — branch on the sweep verdict from step 9b:217218 **WIRED or EXEMPT** (sweep exit 0) → proceed normally:219220 a. Run backend op `set-status` for the parent task. Because the sweep221 already wrote the `reachability` block into the CDD card, the222 `set-status` CLI auto-reads it — no `--reachability` flag needed:223224 ```bash225 python3 script.py set-status --id <N> --status done226 ```227228 If you want to be explicit (e.g. for logging), you may pass:229 `--reachability WIRED` or `--reachability EXEMPT`.230231 b. **Subtask writeback**: for each subtask `S` in `task.subtasks` whose232 evidence file (per the CDD card from step 5) exists, run233 `python3 script.py set-status --id <N>.<S> --status done`. Subtasks left234 `pending` while the parent is `done` are a data-integrity violation235 that breaks any tool computing progress from subtask state.236 (Codified 2026-06-04 — yesterday's run left all 39 subtasks237 `pending` despite 13/13 parent tasks `done`.)238239 c. Update `.atlas-ai/state/pipeline.json` per-task: call240 `mcp__plugin_prd_go__update_pipeline_task_status(task_id=<N>,241 status="done")` if the MCP tool is available. If not, fall back to242 atomic read-modify-write using the pattern in243 `mcp-server/pipeline.py:locked_update()` — read, append `<N>` to244 `phase_evidence.EXECUTE.tasks_completed`, write to temp, rename.245 Never leave pipeline.json and tasks.json mutually inconsistent.246 (Codified 2026-06-04 — yesterday's run promised this write in247 SKILL.md but never executed it. pipeline.json froze at HANDOFF248 transition through all 85 minutes of execution.)249250 **ORPHAN or ERROR** (sweep exit 1) → **auto-downgrade to scaffold**:251252 Do NOT mark the task `done`. Instead:253254 ```bash255 python3 script.py set-status --id <N> --status scaffold256 ```257258 Then:259 - Log to `execute-log.jsonl`: `"reachability_verdict": "ORPHAN"` (or260 `"ERROR"`), `"auto_downgraded": true`, and a plain-English note of261 which modules are unwired (from the sweep's `modules` list in the262 CDD card).263 - **Do NOT halt the loop** — continue to the next task (step 1).264 An ORPHAN module is scaffolded work, not blocked work. The ship265 gate (Gate 6, RA3) will report it honestly as `scaffold`, not `done`.266 - If you need to wire the module, create a follow-up task267 (`title: "Wire <module> into <entrypoint>"`) and append it via268 `python3 script.py expand --id <N>` or the MCP equivalent.269270 > **Throughline:** a green test on a module imported by nothing is not271 > done — wire it or it ships as scaffold. The auto-downgrade ensures272 > the task graph stays honest: Gate 6 will block the ship until every273 > wired/live task's reachability block reads WIRED or EXEMPT. If all274 > wired/live tasks auto-downgraded to scaffold, the ship check will275 > block at Gate 2 ("not every task is done") and the developer must276 > choose: wire the modules, re-tier them (spike/domain-model), or mark277 > them explicitly exempt (`reachableVia: cli:...`). There is no silent278 > path to SHIP_CHECK_OK with an unwired module at a wired/live tier.27928011. **Check stepback triggers**: if 15 minutes have passed with no task281 moving to done, OR 5 consecutive iterations have failed on the same282 task class, the recon escalation ladder is MANDATORY. Climb the ladder283 in this exact order, not out of order:284285 `/stepback` -> `/research-before-coding` -> `/question` -> `pivot`286287 - `/stepback` — reassess the architectural assumption. Was the plan288 wrong?289 - `/research-before-coding` — feed the blocker into the Perplexity +290 Context7 + GitHub pipeline for fresh external context.291 - `/question` — batch-research the unresolved unknowns in parallel.292 - `pivot` — the plan step itself is unsound; kick the task back to the293 plan author (inbox parent with `message_type="plan_pivot_requested"`).294295 The ladder is append-only — if `/stepback` surfaces a fix, apply it and296 return to step 3. Only climb if the prior rung did not yield progress.29729812. **Render progress** — show the execute progress panel: MCP299 `render_status(phase="EXECUTE")` → print its `rendered` field; CLI300 `python3 script.py status --phase EXECUTE`. Then emit the atlas-gamify301 one-line score (tasks done / tasks total, complexity-weighted). This is the302 human-visible progress signal and also feeds the dogfood debrief.30330413. **Loop**: back to step 1 until SHIP_CHECK_OK or a halt condition fires.305306## Termination307308The termination sequence is strict — three steps, in order, no shortcuts:3093101. Run `.atlas-ai/ship-check.py`. If it does NOT exit 0, halt. Do NOT311 emit any completion signal. Investigate the gate failure, fix, retry.3122. **MANDATORY**: invoke `Skill(skill: "sync")` to refresh the memory313 bank (session-context/CLAUDE-*.md, MEMORY.md, capability inventory).314 This MUST happen BEFORE the SHIP_CHECK_OK token is printed.315 Orchestrators tail-watch the token; if the memory bank is stale when316 they react, successor sessions inherit a wrong picture of the world.317 (Codified 2026-06-04 — yesterday's ai-human-tasker run shipped 15.6k318 LOC while `session-context/CLAUDE-activeContext.md` still said319 "Scaffold complete. No application code yet".)3203. Print `SHIP_CHECK_OK` to stdout. This is the ONLY place in your321 output where the token may appear — emit it nowhere else, to avoid322 false-positive matches by log-watchers.323324The ship-check script is deterministic. Its gates are documented at the325top of `${CLAUDE_PLUGIN_ROOT}/skel/ship-check.py` (copied to `.atlas-ai/ship-check.py` at setup):326327- Gate 1: `pipeline.json current_phase == "EXECUTE"`328- Gate 2: every `master.tasks[].status == "done"`329- Gate 3: every task has a CDD card (`task-<id>.json` or combined variant)330- Gate 4: plan file exists at `.taskmaster/docs/plan.md` OR `docs/superpowers/plans/*.md`331- Gate 5 (HARD): no non-zero `Exit status N` line in any evidence file332333Gate 5 is the convergent must-do from the 2026-06-04 audit — a "PASS"334label on a non-zero-exit test is structurally impossible after this335script runs. There is no override path for Gate 5; it is the unfakable336oracle.337338Do not emit SHIP_CHECK_OK on a mere "DONE" keyword in a subagent reply.339Do not emit on "all tasks marked done" without the explicit ship-check.340Do not emit before `/sync` has been called.341342## Red flags343344These are the most common pressure points where the loop silently degrades345from "verified" to "performative". If you catch yourself thinking any of346them, stop and repair the gap.347348- "Close enough, mark it done" -> NO. Evidence OR nothing.349- "Let me skip the doubt step this time" -> NO. Triple verification is non-negotiable.350- "I'll retry with same model+prompt" (BLOCKED) -> NO. Escalate.351- "The task says done, don't check evidence files" -> NO. Task status must reflect evidence.352353## Observability354355Every iteration appends a structured row to356`.atlas-ai/state/execute-log.jsonl`. Field types are strict — text357narrative in a typed field is a logging bug, not compliance. The schema:358359- `iteration` (integer, or `"FINAL"` for the terminal marker)360- `timestamp` (ISO 8601 string)361- `task_id` (string)362- `complexity` (integer or human label)363- `tier` (string: `"fast"` | `"standard"` | `"capable"`)364- `subagent_status` (string: `"DONE"` | `"DONE_WITH_CONCERNS"` | `"NEEDS_CONTEXT"` | `"BLOCKED"`)365- `retry_count` (integer)366- `triple_verify` (string: `"PASS"` / `"FAIL"` plus free-text rationale)367- `stepback_triggered` (boolean, REQUIRED — true iff `/stepback` was368 invoked this iteration). Putting narrative-text in this field is a369 violation; use `stepback_narrative` instead.370- `stepback_narrative` (string, nullable — explanation when371 `stepback_triggered: true`; `null` otherwise)372- `ladder_rung` (string, nullable — which rung was reached if escalated)373- `gamify` (string — atlas-gamify one-line score)374375The stepback fields were split (2026-06-04) after a FINAL iteration entry376wrote a paragraph of narrative into the boolean `stepback` field and was377treated as compliance with the `stepback_mandatory` rule. Boolean trigger378+ nullable narrative is the correct schema.379380This log is the dogfood artifact — debrief tools consume it, the381orchestrator greps it, and future runs read it for retrospective analysis.382383## Composition384385- **Orchestrator handoff**: this skill is invoked post-HANDOFF. It does386 not call `/handoff` — that direction is one-way.387- **Plan editing**: if the plan is unsound, the ladder escalates to388 `pivot`, which inboxes the plan author. This skill does not mutate the389 plan in place.390- **Ship-check**: `.atlas-ai/ship-check.py` is the terminal gate. This391 skill calls it; it does not reimplement the checks.392393## Non-exits394395This skill uses no explicit process termination. A halt condition reports396the reason in the structured log and returns control to the caller (the397user or the orchestrator). Never kill the shell — the caller owns the398session lifecycle.