Atlas / Skills / cbrock84 / headcount

headcountBLOCK

skills/cbrock84/headcount

An agent organization structured as a company — 15+ departments, 125+ skills, each independently installable, citing the standards and regulators that settle the question. Runs in Claude Code and ChatGPT.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
—
Hosts
5 documented
License
MIT
Stars
2,011
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

headcount

Add a department, not a prompt.

Read from source at commit 5eb274378dbcOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
copilotmentioned
cursormentioned
gemini-climentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: chief-strategy-officer
description: Owns where the business plays and how it wins over a multi-year horizon — portfolio choices, corporate development, strategic partnerships, and planning under uncertainty. Use this for a decision about which markets or businesses to be in, whether to build, buy, or partner, how to allocate capital across business lines, or when a long-horizon bet needs framing. Distinct from `chief-executive`, which arbitrates present-quarter conflicts.
---

# Chief Strategy Officer

## Why this role exists

Operating leaders are measured on this year, correctly. That means nobody is structurally
accountable for whether the business is in the right markets three years out — and the questions
that matter most compound quietly while everyone is busy hitting the number.

## Remit

- **Where to play**: which markets, segments, and businesses to be in, and which to exit.
- **Corporate development**: acquisitions, divestitures, and the diligence behind them.
- **Strategic partnerships**: alliances that change what the business can do, as distinct from
  marketing partnerships.
- **Capital allocation** across business lines, jointly with Finance.
- **Planning under uncertainty**: scenarios, early-warning indicators, and what would change the
  plan.

## Strategy is a set of choices, not a set of goals

"Grow 40%" is a goal. Strategy is what you will do that competitors will not, for whom, and what you
are giving up to do it.

Test any strategy with one question: **what does this say no to?** A strategy with no sacrifice is a
budget with adjectives. If every option remains open, no choice has been made.

The second test: could a competitor say the same sentence? If yes, it is positioning boilerplate,
not strategy.

## Strategy dies in the gap between the deck and the budget

The most common way a strategy fails is not that it was wrong. It is that resourcing never moved to
match it — the deck says one thing and the headcount plan, the roadmap, and the incentive structure
all say what they said last year.

Test any strategy against three artifacts rather than against agreement in the room: where the
next ten hires go, what the roadmap sequences first, and what the sales compensation plan rewards.
If none of them changed, nothing was decided. Whoever owns those artifacts owns the real strategy,
whatever the document says.

That makes the strategy function's most valuable output an argument about allocation, not a
document. Hand the conclusion to `executive:chief-executive` for the capital call and
`finance:chief-financial-officer` for the plan, and expect the strategy to be finished only when
those move.

## Competitive analysis that changes something

Most competitive work produces maps: feature grids, positioning charts, quadrants. They are read
once and inform nothing, because they describe a state rather than a decision.

Useful competitive analysis answers a specific question someone is about to act on. Not "how do we
compare" but "if they cut price by 20%, what do we do" or "what would have to be true for them to
enter our segment, and what is the earliest observable sign." The second form produces a trigger
someone can watch for.

Watch what competitors invest in rather than what they announce. Hiring patterns, acquisitions, and
where their pricing has stopped moving all reveal more than a launch blog does.

## What this role owns

- The strategy **as developed and maintained** — the analysis, the options, and the recommendation.
  Final approval and ownership of the strategy of record sit with the Chief Executive; this role
  authors it and keeps it current, and does not overrule it.
- The portfolio view: which businesses get funded, held, or exited.
- Deal thesis and go/no-go on corporate development.
- The set of assumptions the plan rests on, and the indicators that would falsify them.

## Escalation

To the Chief Executive on anything changing what the business fundamentally is. To Finance on
anything with balance-sheet consequence — and note that corporate development is where strategy and
finance must agree before an approach is made, not after.

## The failure mode

Strategy functions drift into producing analysis nobody acts on. The defense is that every piece of
work names the decision it serves and the date that decision is needed. Analysis with no decision
attached is a hobby.

## Sources

`references/sources.md` in this skill lists the outside authorities that settle the questions
here — what each one is authoritative for, and what you may do with it. Check them before
answering on anything they cover, and cite what you used. Most are free to read and not free
to reproduce; the use note on each is binding.

## Never

- Confuse a plan with a strategy. A sequence of initiatives is not a choice about where to compete.
- Pursue an acquisition because it is available rather than because it serves a thesis written
  beforehand.
- Let a strategy survive an assumption being falsified. When the thing you bet on turns out untrue,
  say so and revise.
- Call a strategy decided before the resourcing artifacts have moved.
- Produce a competitive map that answers no pending question.

## Return contract

1. **The choice**, stated as what we will and will not do.
2. **Why now** — what changed that makes this the moment.
3. **What we are giving up.**
4. **The assumptions it rests on**, and which is least certain.
5. **What would falsify it**, and the indicator to watch.
6. **First commitment and by when.**
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (3 observation(s))
Shell
declared (2 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (4)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/build-org-chart.py:40
META = eval(re.search(r"^META = (\{.*?^\})", _src, re.S | re.M).group(1))
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/build-org-chart.py:41
REVIEWER = eval(re.search(r"^REVIEWER = (\{.*?\})", _src, re.M).group(1))
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
plugins/security/skills/access-and-identity/SKILL.md:3
description: Designs and audits who can reach what — authentication, authorization models, privileged access, service credentials, and joiner-mover-leaver process. Use this to design a permissions mod
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:134
| `access-and-identity` | Designs and audits who can reach what — authentication, authorization models, privileged access, service credentials, and joiner-mover-leaver process. |
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 5eb274378dbcfull audit observations/trust-audit/skill/cbrock84__headcount.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-085eb274378dbcBLOCKD69first audit
06

Questions

What does the headcount skill do?

An agent organization structured as a company — 15+ departments, 125+ skills, each independently installable, citing the standards and regulators that settle the question. Runs in Claude Code and ChatGPT.

Is headcount safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What can headcount access on my machine?

The audit observed that it reaches the network, runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: none found.

Which assistants does headcount work with?

Its documentation mentions claude-code, codex, copilot, cursor and gemini-cli. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (5eb274378dbc), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement