Delegate Through Flow
Read delegation, safety, and collaboration before acting.
Select
Accept auto or one explicit provider: codex, opencode, kimi, gemini, or kiro. For auto, select from the provider matrix in delegation, announce the provider, mode, and reason, and use read only for analysis-only work. Never add --dangerously-bypass-approvals-and-sandbox; standalone delegation does not inherit fleet authorization.
Run
Inspect repository status, resolve ../../scripts/run-agent.sh from this installed skill, check the selected binary, and determine its configured timeout_s without reading secret files.
Run the packaged preview and display both its exact expanded provider vector and confirmation token:
bash <packaged-run-agent.sh> --preview <provider> <read|write> <task>
Require explicit confirmation of that exact expanded vector. Treat the displayed token as bound to its provider, repository, mode, typed model, arguments, standardized prompt, and task; do not reuse it after any change.
Execute the identical packaged runner invocation without --preview, setting FLOW_DELEGATION_CONFIRM_TOKEN to the confirmed token. Execute only the packaged runner. Set the host execution timeout to at least timeout_s + 60 seconds so the runner can report its own timeout first.
Report the runner exit code and captured output path. Do not treat a delegated summary as proof of completion.
Review Independently
After every run, including failures, inspect Git status and the full unstaged and staged diff, inspect relevant untracked files, reconcile scope against the task, and run the relevant tests in the primary session. Return an independent APPROVED, CAVEATS, or REJECTED verdict with evidence and concerns.
1---2name: flow-delegate3description: Delegates a bounded repository task to an allowlisted external coding CLI through a guarded runner, with provider selection, timeout handling, and independent local review.4---56# Delegate Through Flow78Read [delegation](../../references/delegation.md), [safety](../../references/safety.md), and [collaboration](../../references/collaboration.md) before acting.910## Select1112Accept `auto` or one explicit provider: `codex`, `opencode`, `kimi`, `gemini`, or `kiro`. For `auto`, select from the provider matrix in [delegation](../../references/delegation.md), announce the provider, mode, and reason, and use `read` only for analysis-only work. Never add `--dangerously-bypass-approvals-and-sandbox`; standalone delegation does not inherit fleet authorization.1314## Run15161. Inspect repository status, resolve `../../scripts/run-agent.sh` from this installed skill, check the selected binary, and determine its configured `timeout_s` without reading secret files.172. Run the packaged preview and display both its exact expanded provider vector and confirmation token:1819 ```text20 bash <packaged-run-agent.sh> --preview <provider> <read|write> <task>21 ```22233. Require explicit confirmation of that exact expanded vector. Treat the displayed token as bound to its provider, repository, mode, typed model, arguments, standardized prompt, and task; do not reuse it after any change.244. Execute the identical packaged runner invocation without `--preview`, setting `FLOW_DELEGATION_CONFIRM_TOKEN` to the confirmed token. Execute only the packaged runner. Set the host execution timeout to at least `timeout_s + 60` seconds so the runner can report its own timeout first.255. Report the runner exit code and captured output path. Do not treat a delegated summary as proof of completion.2627## Review Independently2829After every run, including failures, inspect Git status and the full unstaged and staged diff, inspect relevant untracked files, reconcile scope against the task, and run the relevant tests in the primary session. Return an independent `APPROVED`, `CAVEATS`, or `REJECTED` verdict with evidence and concerns.