Agent Conductor
Agent Conductor
AGENTS.md 进,受治理的代理团队出。
Agent Conductor 是一个 MCP 服务器,它将编码代理生态系统已趋同的两大约定 ——
AGENTS.md 操作手册和 SKILL.md 技能 —— 从被动文档转变为主动编排层,
并以共识加固的决策引擎为高风险更改把关。
镜像: Cubiczan/agent-conductor · codeberg.org/cubiczan/agent-conductor · icohangar-ops/agent-conductor
许可证: MIT
状态: v0.1 — 可用的脚手架;参见路线图
问题
每一个严肃的代理工具 —— Claude Code、Cursor、Copilot、Codex、Gemini CLI ——
现在都会读取仓库根目录下的 AGENTS.md 和一批 SKILL.md 文件。
但这两大约定都是靠自觉的文本:
没有任何东西编译契约。不可协商的规则、层边界和验证清单以 markdown 形式存在,代理可能内化,也可能不内化。
没有任何东西把关决策。一个即将重写你评分模型的代理,与一个重命名变量的代理,以同样的信心推进。
没有任何东西验证清单是否执行。"交接前运行
npm test" 只是建议,不是门禁。
Conductor 让这些约定变得可执行 —— 无需任何代理工具做出更改。它以标准 MCP 服务器形式发布, 因此任何支持 MCP 的工具都能免费获得契约编译、技能发现和决策把关。
Related MCP server: @event4u/agent-config
工作原理
MCP client (Claude Code / Cursor / Copilot / ...)
│ stdio (JSON-RPC, MCP)
▼
┌────────────────────────────────────────────────┐
│ TypeScript front end (src/) │
│ contract/parser.ts AGENTS.md → contract │
│ skills/loader.ts SKILL.md discovery │
│ server.ts 7 MCP tools │
└────────────────┬───────────────────────────────┘
│ newline-delimited JSON, child stdio
▼
┌────────────────────────────────────────────────┐
│ Python decision engine (engine/) │
│ bridge.py → PyPI consensus-hardening-protocol│
│ R0 gates · foundation attacks · lifecycle │
└────────────────────────────────────────────────┘三大能力组:
契约 — 将
AGENTS.md编译为结构化的使命、不可协商规则、层级的做/不做边界、验证门禁、技能推荐和范围外清单。技能 — 跨项目和个人的范围发现
SKILL.md技能,采用渐进式披露:元数据约消耗 100 个 token,正文仅在需要时加载。决策 — 通过 Consensus Hardening Protocol 为工作把关:工作开始前的低成本 R0 合理性检查,以及高风险更改锁定前的对抗性基础攻击检查。
快速开始
npx -y @cubiczan/agent-conductor
pip install consensus-hardening-protocol # required for decision_* toolsnpm: @cubiczan/agent-conductor · PyPI: consensus-hardening-protocol
要求:Node 23+(原生运行 TypeScript)和 Python 3.10+,并安装已发布的 CHP 包。
git clone https://github.com/icohangar-ops/agent-conductor.git
cd agent-conductor
npm install
pip install -r engine/requirements.txt
npm test # TypeScript tests (parser, skills, live engine bridge)
npm run test:engine # Python bridge protocol tests
npm run build在 Claude Code 中注册:
claude mcp add agent-conductor -- node /path/to/agent-conductor/dist/index.js或在任何 MCP 客户端的 JSON 配置中:
{
"mcpServers": {
"agent-conductor": {
"command": "npx",
"args": ["-y", "@cubiczan/agent-conductor"]
}
}
}如果您的 Python 3 不在 python3 路径下,请设置 CONDUCTOR_PYTHON。
然后,在任何一个包含 AGENTS.md 的项目中:
"加载此项目的代理契约,列出其验证门禁,并对我即将进行的更改运行一次 decision_adversary 检查。"
工具参考
contract_load
将 AGENTS.md(或 CLAUDE.md)编译为结构化契约。接受文件路径或项目目录;默认为当前工作目录。
// input
{ "path": "examples/pipeline-pulse" }
// output (abridged — real output from the bundled example)
{
"source": "examples/pipeline-pulse/AGENTS.md",
"title": "AGENTS.md — Pipeline Pulse CRM",
"mission": "Pipeline Pulse CRM is a lightweight, local-first pipeline review dashboard...",
"rules": [
"Deterministic logic — same inputs → same scores, labels, and summaries...",
"Logic in crm.js — keep main.js thin (fetch, render, events).",
"... (6 total)"
],
"layers": [
{ "layer": "src/crm.js", "role": "Domain logic",
"do": "Deterministic scoring, filtering, summaries", "dont": "DOM manipulation" }
],
"gates": [
{ "name": "Code change checklist", "commands": ["npm test"], "notes": "" },
{ "name": "Before completion", "commands": [], "notes": "npm test — all green...\n..." }
],
"skills": [
{ "task": "CRM scoring / forecast changes", "skill": "obra/test-driven-development",
"url": "https://github.com/obra/superpowers/...", "why": "Tests-first changes to deterministic logic" }
],
"outOfScope": ["External CRM integrations (Salesforce, HubSpot, etc.)", "..."],
"sectionCount": 28
}解析器是无损的:它无法识别的小节会逐字保留,因此非传统 AGENTS.md 中的任何内容都不会被丢弃。
contract_verification
仅返回验证门禁 —— 即工作交接前必须通过的具名清单和 shell 命令。将其与代理的工作流配合使用:运行命令,确认成功,然后宣布完成。
skills_list
发现从项目根目录可见的 SKILL.md 技能。仅元数据。
// input
{ "projectRoot": "examples/pipeline-pulse" }
// output
{
"skills": [
{
"name": "pipeline-scoring",
"description": "Explain and modify scoreDealRisk weights in src/crm.js with matching test updates...",
"version": "0.1.0",
"scope": "project"
}
]
}搜索顺序(每个技能名称首次命中者优先):
优先级 | 路径 | 范围 |
1 |
| 项目 |
2 |
| 项目 |
3 |
| 项目 |
4 |
| 个人 |
5 |
| 个人 |
skill_load
加载指定技能的完整 SKILL.md 正文 —— 渐进式披露的按需部分。仅当任务与技能描述匹配时才调用它。
decision_gate
Consensus Hardening Protocol R0 门禁:成本最低、杠杆最高的检查,在开展工作之前运行。
// input
{ "solvable": true, "scoped": false, "valid": true, "worth_it": true }
// output
{ "verdict": "HALT", "results": { "Solvable": "PASS", "Scoped": "FATAL", "Valid": "PASS", "Worth_it": "PASS" } }任何 FATAL 答案都会中止:在把 token 浪费在一个未界定范围、未被理解或不值得解决的问题之前,停下来重新框定。
decision_adversary
针对高风险更改的一次性对抗性检查:CHP 攻击主张的基础,为其打分 0–100,并返回魔鬼代言人式的发现以及会话状态。
// input
{
"claim": "Change scoreDealRisk stale-activity weight from 20 to 30",
"context": "Tests updated; label distribution checked against fixture"
}
// output
{
"status": "EXPLORING", // or HALT / REFRAME_REQUIRED
"foundation_score": 77,
"findings": [
"Treat every financial number as unverified until tied to source data.",
"Require explicit flip criteria for any provisional recommendation."
],
"verification_failures": ["PENDING third-party validation"],
"report": "## TriangulationRunner Adversary Pass\n..."
}状态映射到 CHP 决策生命周期
(EXPLORING → PROVISIONAL_LOCK → LOCKED,带有 HALT 和
REFRAME_REQUIRED 出口):EXPLORING 表示主张在攻击中幸存,工作可以继续走向锁定;HALT/REFRAME_REQUIRED 表示基础失败。
engine_status
对 Python 引擎子进程进行健康检查。返回 { ok, engine: "chp", version }。
解析器识别的内容
contract_load 基于约定,而非基于模式。它提取现实世界中 AGENTS.md 文件实际使用的模式:
契约字段 | 来源约定 |
| 第一个 |
|
|
| 架构类标题下第一个包含 |
| 清单 / 验证 / 完成前标题下的 Shell 代码块 + 列表项 |
| 包含 |
| 范围外 / 非目标标题下的列表 |
| 所有内容,逐字保留 —— 无损回退 |
代码围栏内的标题会被忽略;表格容忍标题中的强调;提取的文本会去除 markdown 链接和强调。
编写技能
技能是包含带 YAML 前置元数据的 SKILL.md 的目录:
---
name: pipeline-scoring
description: Explain and modify scoreDealRisk weights in src/crm.js with matching test updates. Use when changing deal risk scoring, risk labels, or forecast thresholds.
version: 0.1.0
tools: [Read, Edit, Bash]
---
# Pipeline Scoring
Step-by-step instructions the agent follows when the task matches...质量标准(继承自 awesome-agent-skills 标准):带有可匹配关键词的第三人称描述,元数据约 100 个 token,正文不超过 500 行,无机器特定的绝对路径,仅声明技能所需的工具。
随附的示例 —— examples/pipeline-pulse —— 是一个完整的真实世界 AGENTS.md 外加一个项目范围的技能,也是测试套件所编译的内容。
项目结构
.
├── AGENTS.md # This repo's own contract (compiles with itself)
├── ARCHITECTURE.md # Design decisions and component detail
├── src/
│ ├── index.ts # stdio entrypoint
│ ├── server.ts # MCP server: 7 tools
│ ├── contract/ # AGENTS.md → AgentContract compiler
│ ├── skills/ # SKILL.md loader + registry
│ ├── engine/chpBridge.ts # Python engine client
│ └── utils/logger.ts # stderr-only logging (stdout is the transport)
├── engine/
│ ├── bridge.py # JSON-over-stdio router → PyPI `chp`
│ ├── requirements.txt # consensus-hardening-protocol pin
│ ├── NOTICE.md # attribution for the published engine
│ └── test_bridge.py # protocol tests
├── examples/pipeline-pulse/ # real AGENTS.md fixture + example skill
└── test/ # node:test suites (run the .ts directly)开发
pip install -r engine/requirements.txt
npm test # TypeScript tests — includes a live engine round-trip
npm run test:engine # Python-side protocol tests
npx tsc --noEmit # type check
npm run build # emit dist/
npm run dev # run the server from source (Node type stripping)内部规则(完整版位于本仓库自己的 AGENTS.md 中):
stdout 是神圣的 —— MCP 传输层独占它;桥接两侧的所有日志都输出到 stderr。
零新增 Node 运行时依赖 —— 仅
@modelcontextprotocol/sdk和zod;markdown/frontmatter 保持手写。CHP 是 PyPI 依赖。仅可擦除的 TypeScript —— 源码必须在 Node 的类型剥离下运行(无枚举、无参数属性)。
CHP 通过 PyPI —— 安装
consensus-hardening-protocol;不要在engine/下重新内置。协议修复属于上游。Python 3.10+ —— 已发布包的要求。
路线图
版本 | 主题 | 范围 |
v0.2 | 执行 | 将 |
v0.3 | 编排 | 通过 MCP 暴露 |
v0.4 | 注册表 | 从远程目录(awesome-agent-skills 格式)安装经过审查的技能,并附带来源审查提示 |
来源
Conductor 刻意复用经过验证的组件,而不是重写它们:
组件 | 来源 | 许可证 |
决策引擎(PyPI) | MIT | |
MCP 服务器 + 注册表形态 | MIT | |
技能质量标准 | — | |
示例夹具 | Pipeline Pulse CRM 操作手册 | fixture |
有关双语言设计,请参阅 engine/NOTICE.md 和 ARCHITECTURE.md。
Cubiczan stack
| 治理 | consensus-hardening-protocol · agent-conductor · compliance-as-code-agent · cleanmandate | | 平台 | cubiczan-mcp-server · operational-intelligence · software-factory |
Conductor 将 AGENTS.md + SKILL.md 编译为 MCP 工具,并通过 CHP 路由高风险决策——这与 Metabocommand 用于财务审批的锁模型相同。
许可证
MIT — 参见 LICENSE。内置的第三方组件保留其原始 MIT 许可证。
Available Tools
7 toolscontract_loadA
Compile an AGENTS.md operating manual into a structured agent contract: mission, non-negotiable rules, layer responsibilities, verification gates, recommended skills, and out-of-scope list. Pass a file path or a project directory (defaults to the current working directory).
| Name | Required | Description | Default |
|---|---|---|---|
| path | No | AGENTS.md path or project root |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full disclosure burden. It explicitly states the action (compile) and the output structure (mission, rules, etc.), implying a read-only operation without destructive effects. It does not detail error handling or side effects, but given the simple nature, the description adds sufficient context beyond the schema.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences: the first states the core purpose and output, the second gives parameter usage. It is front-loaded, free of fluff, and every sentence earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool has one parameter, no output schema, and no annotations. The description covers the trigger (AGENTS.md), the processing (compile), and the output outline (structured contract with listed sections). It could explicitly state the return format, but the listed components imply what the contract contains, making it sufficiently complete for a simple tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% (path described as 'AGENTS.md path or project root'). The description enriches this by clarifying that 'path' accepts a file or directory and defaults to the current working directory, providing practical usage details not present in the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb ('Compile') and resource ('AGENTS.md operating manual') to state exactly what the tool does: transforms a file into a structured agent contract with enumerated components (mission, rules, responsibilities, gates, skills, out-of-scope). This clearly distinguishes it from siblings like contract_verification or skills_list, which serve different purposes.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear invocation context: 'Pass a file path or a project directory (defaults to the current working directory).' This tells the agent how to supply input and what the default is, so it can decide when to call the tool. However, it does not explicitly mention alternatives or when not to use it, though the purpose is distinct enough to infer.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
contract_verificationA
Return the verification gates from a project's agent contract — the named checklists and shell commands that must pass before work is handed off. Run these and confirm success before declaring any task complete.
| Name | Required | Description | Default |
|---|---|---|---|
| path | No | AGENTS.md path or project root |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the burden of behavioral disclosure. It states the tool returns gates and instructs the agent to run them, which implies the agent needs to execute commands. However, it does not disclose whether the tool itself executes anything, whether there are side effects, or what happens if gates fail.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences and every clause adds value: what the tool returns, what those returns consist of, and when/how to use them. There is no filler or repetition.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple one-parameter read tool with no output schema, the description covers the return value, the usage timing, and the required action. It could be slightly richer about default path behavior or failure semantics, but it is arguably sufficient for an agent to select and invoke the tool correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, as the 'path' parameter is described as 'AGENTS.md path or project root'. The description adds no parameter details, but the schema already provides sufficient meaning, so the baseline of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb ('Return'), names the exact resource ('verification gates from a project's agent contract'), and elaborates what those gates are ('named checklists and shell commands'). This clearly distinguishes the tool from siblings like contract_load, which would handle contract loading, and decision_gate, which evaluates a decision.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives a clear usage context: run these gates and confirm success before declaring a task complete. It does not explicitly mention alternatives or exclusions, but the 'before work is handed off' phrase and sibling names make the appropriate use case evident.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
decision_adversaryA
Run a one-shot Consensus Hardening Protocol adversarial pass against a claim or proposed change: CHP attacks its foundations, scores them 0-100, and returns findings plus a session status (EXPLORING / HALT / REFRAME_REQUIRED). Use before locking any high-stakes decision.
| Name | Required | Description | Default |
|---|---|---|---|
| claim | Yes | The claim or decision to attack | |
| context | No | Supporting context for the claim | |
| high_stakes | No | Default true |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It usefully discloses one-shot behavior, the adversarial mechanism, and the statuses returned. However, it does not explain side effects, required permissions, or whether the pass modifies any state, which leaves some behavioral ambiguity.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences with no filler. The first sentence states the action and protocol; the second gives a crisp usage rule. Every phrase earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given there is no output schema, the description adequately outlines what is returned ('findings plus a session status') and lists the possible statuses. It could be slightly richer on the response shape or effect of high_stakes, but it is sufficient for a 3-parameter tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the baseline is 3. The description adds no extra parameter-level detail beyond the schema; it mentions 'claim or proposed change' and 'high-stakes decision' but does not elaborate on the context or high_stakes parameters.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb ('Run') and a concrete resource ('Consensus Hardening Protocol adversarial pass against a claim or proposed change'), and it names the core output (scores, findings, session status). This clearly distinguishes the tool from siblings like decision_gate or engine_status.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear usage context: 'Use before locking any high-stakes decision.' It does not explicitly mention when not to use it or name alternatives, but the guidance is specific enough to orient an agent.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
decision_gateA
Run the Consensus Hardening Protocol R0 gate on a proposed decision: is it solvable, scoped, valid, and worth making at all? Any FATAL answer returns HALT — stop and reframe before doing the work.
| Name | Required | Description | Default |
|---|---|---|---|
| valid | Yes | Is the current state accurately understood? | |
| scoped | Yes | Is the scope explicitly bounded? | |
| solvable | Yes | Can this problem actually be solved? | |
| worth_it | Yes | Do the stakes justify the work? |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must carry the full burden. It discloses the HALT behavior on FATAL answers, but does not explain what happens when all criteria pass, nor does it define 'FATAL' or the output format. This leaves significant behavioral ambiguity.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences, front-loads the purpose, and every clause earns its place. No redundancy or filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple gate with no output schema, the description could be more complete by stating the pass condition and output behavior. It implies all four must be true to proceed, but does not explicitly describe the success return value or the meaning of FATAL. Available structured data is minimal, so the description needs to do more.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema already describes all four boolean parameters clearly (100% coverage). The description repeats the names but adds no extra semantic detail beyond the schema. Baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb ('Run') and names a distinct resource ('Consensus Hardening Protocol R0 gate'), clearly listing the four evaluation criteria (solvable, scoped, valid, worth it). This distinguishes it from sibling tools like decision_adversary by framing it as a gate that halts work.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies when to use the tool ('on a proposed decision', 'before doing the work') and hints at the consequence of a FATAL result (stop and reframe). It does not explicitly compare to alternatives, but the timing guidance is clear enough.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
engine_statusA
Health/readiness probe for the CHP decision engine (Python subprocess). By default returns a cheap readiness snapshot (running, last exit code, restart-backoff state) WITHOUT spawning Python. Pass probe=true to also issue a live ping that warms/spawns the subprocess.
| Name | Required | Description | Default |
|---|---|---|---|
| probe | No | Issue a live ping (spawns the subprocess). Default false. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description discloses that the default mode does NOT spawn Python (a performance consideration), while probe=true will spawn/warm the subprocess. This is valuable behavioral context beyond what annotations would provide (none are provided). It clearly communicates the side effects of probe=true without any contradiction.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences, concise, and front-loaded with the core purpose. Every sentence adds value: the first defines the tool, the second explains the parameter distinction and behavioral implications. No wasted words.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity (one parameter, no output schema, no nested objects), the description is complete. It covers the default behavior, the alternative with probe=true, and the performance implication. There's no missing information that would prevent correct usage.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema already describes the 'probe' parameter with 100% coverage, so the baseline is 3. The description adds context that probe=true issues a live ping and spawns the subprocess, but this largely reinforces what the schema says. It doesn't add new syntax or format details beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool is a health/readiness probe for the CHP decision engine, distinguishing it from sibling tools that load contracts, list skills, or make decisions. It specifies the resource (CHP decision engine subprocess) and the action (health/readiness probe), making the purpose unmistakable.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explains the default behavior (cheap readiness snapshot without spawning Python) and when to use probe=true for a live ping. While it implies that probe=false is for quick checks and probe=true for when a live response is needed, it doesn't explicitly contrast with alternatives or state when not to use it.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
skill_loadA
Load the full SKILL.md body for a named skill — the on-demand half of progressive disclosure. Call only when the current task matches the skill's description.
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Skill name as returned by skills_list | |
| projectRoot | No | Project root (defaults to cwd) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations exist, so the description must carry the transparency burden. It communicates that this is an on-demand load operation and ties it to progressive disclosure, but it does not disclose return behavior, error/not-found handling, or explicit read-only guarantees.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short, purposeful sentences with no filler. The core action, context, and when-to-use guidance are all packed efficiently.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a two-parameter loader tool with no output schema, the description is adequate: it explains what is loaded, when to call it, and how it fits into the progressive disclosure flow. A small gap remains regarding what the response contains, but 'full SKILL.md body' conveys the essential outcome.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the schema already documents both parameters. The description adds minimal parameter-specific meaning beyond context ('named skill' and matching behavior), which aligns with the baseline for high coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states a specific action ('Load the full SKILL.md body') on a specific resource ('for a named skill'). It also distinguishes itself from siblings like skills_list by describing this as the on-demand half of progressive disclosure.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives a clear usage condition: 'Call only when the current task matches the skill's description.' It does not explicitly name alternatives such as skills_list for listing skills, but the progressive-disclosure context implies the distinction.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
skills_listA
Discover SKILL.md skills visible from a project root (project-scope .conductor/.claude/.cursor skill dirs, then personal ones). Returns metadata only (~100 tokens per skill); use skill_load for the full body.
| Name | Required | Description | Default |
|---|---|---|---|
| projectRoot | No | Project root (defaults to cwd) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description discloses that it returns only metadata (~100 tokens per skill) and covers scope resolution order, which is valuable behavioral context. However, no annotations are provided, and the description does not mention whether this performs a read-only operation, whether it follows symlinks, or how errors are handled if the project root is invalid. Still, for a listing tool, the scope and return-type disclosure is adequate.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences and front-loaded with the core purpose. It covers scope, return type, and the alternative tool in no more words than necessary. Every sentence earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple read-only discovery tool with one optional parameter and no output schema, the description is complete enough: it states scope, return size, and the next step (skill_load). The only minor gap is lack of detail about exact directory patterns, but that is not essential for an agent to select and invoke it correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
There is one parameter, projectRoot, with 100% schema description coverage ('Project root (defaults to cwd)'). The tool description adds the context that the root is used to discover relevant skill directories, but the schema already explains the parameter well. Baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's function: discover SKILL.md skills from a project root with specific scope details (project vs personal). It also distinguishes itself from the sibling tool skill_load by noting this returns metadata only, which helps the agent understand the difference between listing and loading.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly says when to use this tool: to discover skills visible from a project root, and explicitly tells the agent to use skill_load for the full body. This provides clear usage guidance and distinguishes it from the sibling skill_load without ambiguity.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
7 tool updates
v0.1.0- First observed
contract_load - First observed
contract_verification - First observed
decision_adversary - First observed
decision_gate - First observed
engine_status - First observed
skill_load - First observed
skills_list
TDQS
Scored across 7 tools
Each tool targets a distinct responsibility: contract compilation, verification gate retrieval, skill discovery, skill body loading, decision gating, adversarial review, and engine health. Even the two decision tools are clearly separated by depth: one is a lightweight pre-check, the other is a full adversarial pass.
The naming generally follows a resource_prefix_action pattern (contract_load, skills_list, decision_gate), but there are minor inconsistencies: contract_verification and engine_status are noun-phrase rather than verb-action, and skills_list/skill_load mix plural and singular forms. The pattern is still readable and predictable overall.
Seven tools is well-scoped for the server's purpose: two for contracts, two for skills, two for decision support, and one operational health probe. Each tool fills a distinct slot with no obvious bloat or redundancy.
The core workflows are covered: contracts can be loaded and verified, skills can be discovered and loaded, and decisions can be gated and adversarial-tested. Minor gaps exist, such as the lack of a tool to explicitly execute verification gates or persist/review decision outcomes, but agents can work around these with shell commands and existing server behavior.
Maintenance
Related MCP Connectors
Sovereign Agent OS — Persistent Memory, Governance & Compliance for AI Agents.
Multi-agent governance: task orchestration, compliance, decision validation, and ML predictions.
LLM Orchestration Agent 2
AI agent skills marketplace — token-efficient skill search & execution
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceEnables offline AI agent automation with embedded local LLM (Qwen 2.5), sandboxed file operations through AgentFS, and dynamic skill loading. Exposes capabilities via MCP with tri-state safety guards for private, air-gapped environments without network connectivity or API costs.-

@event4u/agent-configofficial
AlicenseAqualityAmaintenanceUniversal AI Agent OS — governed skills, rules, and commands for AI coding assistants (Claude Code, Augment, Cursor, Copilot, Windsurf). Read-only MCP bridge serves prompts and resources from a release-pinned content bundle.25863 npm11MIT- AlicenseNot gradedqualityCmaintenanceMulti-server MCP aggregator with 266 skills, an orchestration runtime, fleet/claims coordination, and hook-driven session governance for autonomous Claude/Cursor/Gemini agent runs.3MIT
- AlicenseNot gradedqualityDmaintenanceOrchestrates AI agents through structured markdown documents, enabling multi-agent workflows with automatic context injection and workflow management.14 npm5MIT