Managing Autonomous DevelopmentBLOCK
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This directory contains static assets used by this skill.
Purpose
Assets can include:
- Configuration files (JSON, YAML)
- Data files
- Templates
- Schemas
- Test fixtures
Guidelines
- Keep assets small and focused
- Document asset purpose and format
- Use standard file formats
- Include schema validation where applicable
Common Asset Types
- config.json - Configuration templates
- schema.json - JSON schemas
- template.yaml - YAML templates
- test-data.json - Test fixtures
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| codex | mentioned | |
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: managing-autonomous-development description: | Execute enables AI assistant to manage sugar's autonomous development workflows. it allows AI assistant to create tasks, view the status of the system, review pending tasks, and start autonomous execution mode. use this skill when the user asks to create a new develo... Use when appropriate context detected. Trigger with relevant phrases based on skill purpose. allowed-tools: Read, Write, Edit, Grep, Glob, Bash(cmd:*) version: 1.0.0 author: Steven Leggett <[email protected]> license: MIT compatibility: Designed for Claude Code, also compatible with Codex and OpenClaw tags: [devops, workflow, autonomous-development] --- # Managing Autonomous Development ## Overview Manage Sugar's autonomous development workflows: create development tasks, check system status, review pending work, and start autonomous execution mode. Sugar orchestrates AI-driven development by queuing tasks with type, priority, and execution parameters, then processing them sequentially or in parallel. ## Prerequisites - Sugar plugin installed and configured in the project - Sugar CLI available in the system PATH (`sugar --version`) - Project repository initialized with Sugar configuration file - Understanding of task types: `feature`, `bugfix`, `refactor`, `test`, `chore` - Write access to the project codebase for autonomous execution ## Instructions 1. Check Sugar system status with `/sugar-status` to verify the daemon is running and view queue depth 2. Review pending tasks with `/sugar-review` to see queued work items, their priorities, and estimated complexity 3. Create new tasks with `/sugar-task <description> --type <type> --priority <1-5>` specifying the task description, type, and priority level 4. Validate Sugar configuration before starting autonomous mode: ensure test commands, lint rules, and commit settings are correct 5. Start autonomous execution in safe mode first: `/sugar-run --dry-run --once` to preview what Sugar would do without making changes 6. Monitor execution output for errors, test failures, or unexpected behavior during the dry run 7. Start full autonomous execution with `/sugar-run` when confident in the configuration 8. Review completed tasks and their outputs: check generated code, test results, and commit messages ## Output - Task creation confirmations with task ID, type, priority, and queue position - System status reports showing queue depth, active tasks, and execution history - Task review summaries with descriptions, priorities, and estimated effort - Execution logs showing task processing, code changes, test results, and commits - Summary reports of completed autonomous development sessions ## Error Handling | Error | Cause | Solution | |-------|-------|---------| | `Sugar daemon not running` | Sugar service not started or crashed | Start with `sugar start` or check logs for crash reason | | `Task creation failed: invalid type` | Unsupported task type specified | Use valid types: `feature`, `bugfix`, `refactor`, `test`, `chore` | | `Autonomous execution failed: tests failing` | Generated code does not pass project tests | Review the failing test output; fix the test or adjust the task description for clarity | | `Configuration file not found` | Sugar config missing from project root | Initialize with `sugar init` to create the configuration file | | `Priority out of range` | Priority value not between 1 and 5 | Use priority 1 (lowest) through 5 (highest/critical) | ## Examples - "Create a new Sugar task: 'Add input validation to the user registration endpoint' with type feature and priority 3." - "Check the current Sugar system status and list all pending tasks in the queue." - "Start Sugar autonomous mode in dry-run to preview what changes it would make for the next queued task." ## Resources - Sugar plugin documentation: https://github.com/roboticforce/sugar - Task automation patterns: - Autonomous development best practices: best-practices/
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
Start full autonomous execution with `/sugar-run` when confident in the configuration
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__managing-autonomous-development.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | BLOCK | D | 69 | first audit |
Questions
What does the Managing Autonomous Development skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Managing Autonomous Development safe to install?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What can Managing Autonomous Development access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Managing Autonomous Development work with?
Its documentation mentions claude-code, codex and openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.