Operate a Flow Fleet
Read fleet, safety, artifacts, and collaboration before acting.
Route
Interpret only these routes:
<slugs>: launch one or more approved lowercase phase slugs.--status: invoke packagedfleet-dashboard.sh --once.--teardown <slug>: invoke packagedfleet-teardown.sh <slug>and preserve its branch and worktree.--teardown --all: enumerate validated.planning/flow/fleet/<slug>.jsonentries and invoke packaged teardown once per slug.
Pass --merge to teardown only when the user explicitly requests it. Never merge a non-DONE member or translate state into legacy paths.
Launch
Inspect repository status, confirm a named current branch, inspect
.planning/flow/config.json, and inspect the requested approvedspec.mdanddecisions.mdcontracts. Never read.env.fleet.Resolve scripts from this installed skill at
../../scripts/; call only packaged fleet and audit scripts for lifecycle operations.Before the first launch, display this exact autonomous command shape:
codex exec --dangerously-bypass-approvals-and-sandbox --ephemeral --cd <worktree> --output-schema <fleet-result-schema> --output-last-message <result-file> <autonomous-prompt>Require explicit acknowledgement of
--dangerously-bypass-approvals-and-sandbox. Do not persist a missing fleet block or launch a member before acknowledgement. Reject a configuredpermission_modeother thandanger-full-access.After acknowledgement, require the configuration root and any existing
.fleetvalue to be objects. Reject an existingpermission_modeunless it is exactlydanger-full-access; require the exact JSON booleanauto_simplify: falseand exact packaged Compose filename before launch.Merge the exact defaults from fleet into both absent and partial fleet blocks with
jq: set.fleet = ($fleet_defaults * (.fleet // {})). Write through a same-directory temporary file and atomically rename it only after validation. This defaults-first recursive merge fills missing known fields while every existing known or unknown field wins; never overwrite permission mode to dangerous.For multiple slugs, compare their specification and decision text for repeated repository paths. Emit an advisory overlap warning with the matching paths; let the human decide and never block automatically.
Invoke packaged
fleet-up.sh <slug>once per acknowledged slug. The script binds exact contract hashes and initiating branch/base identity, and rejects unsafe symlinked state paths. Stop launching further members after any failure and report the recovery state.
Report
Invoke the one-shot dashboard and report each slug, worktree, app/database ports, stage, status, branch, and concise message. Do not load or reproduce full fleet logs, prompts, or result payloads. When audit is enabled, record only the allowed semantic metadata described in audit.