Atlas / Skills / jeremylongshore / Managing Autonomous Development

Managing Autonomous DevelopmentBLOCK

skills/jeremylongshore/managing-autonomous-development

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
1.0.0
Hosts
3 documented
License
MIT
Stars
2,823
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This directory contains static assets used by this skill.

Purpose

Assets can include:

  • Configuration files (JSON, YAML)
  • Data files
  • Templates
  • Schemas
  • Test fixtures

Guidelines

  • Keep assets small and focused
  • Document asset purpose and format
  • Use standard file formats
  • Include schema validation where applicable

Common Asset Types

  • config.json - Configuration templates
  • schema.json - JSON schemas
  • template.yaml - YAML templates
  • test-data.json - Test fixtures
Read from source at commit 4f83675ca38aOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
openclawmentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: managing-autonomous-development
description: |
  Execute enables AI assistant to manage sugar's autonomous development workflows. it allows AI assistant to create tasks, view the status of the system, review pending tasks, and start autonomous execution mode. use this skill when the user asks to create a new develo... Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.
allowed-tools: Read, Write, Edit, Grep, Glob, Bash(cmd:*)
version: 1.0.0
author: Steven Leggett <[email protected]>
license: MIT
compatibility: Designed for Claude Code, also compatible with Codex and OpenClaw
tags: [devops, workflow, autonomous-development]
---
# Managing Autonomous Development

## Overview

Manage Sugar's autonomous development workflows: create development tasks, check system status, review pending work, and start autonomous execution mode. Sugar orchestrates AI-driven development by queuing tasks with type, priority, and execution parameters, then processing them sequentially or in parallel.

## Prerequisites

- Sugar plugin installed and configured in the project
- Sugar CLI available in the system PATH (`sugar --version`)
- Project repository initialized with Sugar configuration file
- Understanding of task types: `feature`, `bugfix`, `refactor`, `test`, `chore`
- Write access to the project codebase for autonomous execution

## Instructions

1. Check Sugar system status with `/sugar-status` to verify the daemon is running and view queue depth
2. Review pending tasks with `/sugar-review` to see queued work items, their priorities, and estimated complexity
3. Create new tasks with `/sugar-task <description> --type <type> --priority <1-5>` specifying the task description, type, and priority level
4. Validate Sugar configuration before starting autonomous mode: ensure test commands, lint rules, and commit settings are correct
5. Start autonomous execution in safe mode first: `/sugar-run --dry-run --once` to preview what Sugar would do without making changes
6. Monitor execution output for errors, test failures, or unexpected behavior during the dry run
7. Start full autonomous execution with `/sugar-run` when confident in the configuration
8. Review completed tasks and their outputs: check generated code, test results, and commit messages

## Output

- Task creation confirmations with task ID, type, priority, and queue position
- System status reports showing queue depth, active tasks, and execution history
- Task review summaries with descriptions, priorities, and estimated effort
- Execution logs showing task processing, code changes, test results, and commits
- Summary reports of completed autonomous development sessions

## Error Handling

| Error | Cause | Solution |
|-------|-------|---------|
| `Sugar daemon not running` | Sugar service not started or crashed | Start with `sugar start` or check logs for crash reason |
| `Task creation failed: invalid type` | Unsupported task type specified | Use valid types: `feature`, `bugfix`, `refactor`, `test`, `chore` |
| `Autonomous execution failed: tests failing` | Generated code does not pass project tests | Review the failing test output; fix the test or adjust the task description for clarity |
| `Configuration file not found` | Sugar config missing from project root | Initialize with `sugar init` to create the configuration file |
| `Priority out of range` | Priority value not between 1 and 5 | Use priority 1 (lowest) through 5 (highest/critical) |

## Examples

- "Create a new Sugar task: 'Add input validation to the user registration endpoint' with type feature and priority 3."
- "Check the current Sugar system status and list all pending tasks in the queue."
- "Start Sugar autonomous mode in dry-run to preview what changes it would make for the next queued task."

## Resources

- Sugar plugin documentation: https://github.com/roboticforce/sugar
- Task automation patterns:
- Autonomous development best practices: best-practices/
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

HIGHPrivilege escalation / persistence · review.unsafe_action · CWE-269, CWE-250
SKILL.md
Start full autonomous execution with `/sugar-run` when confident in the configuration
Why it matters. The skill directs the agent to start persistent, privileged code-modification and commit operations based solely on the agent's own confidence assessment rather than requiring explicit user approval for each execution.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__managing-autonomous-development.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f83675ca38aBLOCKD69first audit
06

Questions

What does the Managing Autonomous Development skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Managing Autonomous Development safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What can Managing Autonomous Development access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Managing Autonomous Development work with?

Its documentation mentions claude-code, codex and openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement