{"id":17105,"plugin_id":"plugins_6a6f9d4936ec81918b0a3b4997d36bd3","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:13:57.153Z","digest":"5ea5c5f101b29b228493ec0534bafe28364cf1e45bcc6ec53420d6179ab3a896","against":null,"payload":{"description":"Route one bounded planning checklist or single-file implementation proposal to an external model, quarantine and validate it outside the repository, and let Codex preview, download, adversarially review, approve for consideration, or reject it without automatic application. Use when the user asks for an Empire handoff, external-model implementation proposal, downloadable model artifact, project checklist, single-file frontend, partner plan, or worker file while Codex remains the only repository writer.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":227},{"relative_path":"scripts/empire_handoff.py","size_in_bytes":73034}],"name":"empire-handoff","skill_md_contents":"---\nname: empire-handoff\ndescription: Route one bounded planning checklist or single-file implementation proposal to an external model, quarantine and validate it outside the repository, and let Codex preview, download, adversarially review, approve for consideration, or reject it without automatic application. Use when the user asks for an Empire handoff, external-model implementation proposal, downloadable model artifact, project checklist, single-file frontend, partner plan, or worker file while Codex remains the only repository writer.\n---\n\n# Empire Handoff\n\nKeep Codex as the sole implementation authority. External `partner` and `worker` labels describe output type only; neither receives tools, filesystem access, approval authority, or repository-write access.\n\n## Resolve the runner\n\nResolve this skill directory as `EMPIRE_HANDOFF_ROOT`, then run:\n\n```bash\npython3 \"$EMPIRE_HANDOFF_ROOT/scripts/empire_handoff.py\" --help\n```\n\nUse `$empire-settings` when credentials or budgets need configuration. Never put credential values in chat or command arguments.\n\nThe CLI's default JSON remains the machine-readable source of truth. For direct\nhuman-readable output, add `--view compact` or `--view detailed` before or after\nthe lifecycle command. Present the returned result with status first, then\nidentity, cost, delivery, validation, and one safe next action. Never rerun a\npaid generation merely to change its presentation; format the existing result\ninstead.\n\n## Generate one handoff\n\nChoose only one supported pairing:\n\n- `partner` + `checklist` for specifications, plans, risk registers, test strategies, or adversarial thinking.\n- `worker` + `single-file` for exactly one textual source-file proposal.\n\nChecklist example:\n\n```bash\npython3 \"$EMPIRE_HANDOFF_ROOT/scripts/empire_handoff.py\" generate \\\n  --repo /absolute/path/to/repository \\\n  --task \"Turn the supplied project specification into an implementation checklist\" \\\n  --role partner \\\n  --format checklist \\\n  --suggested-path docs/implementation-checklist.md \\\n  --media-type text/markdown \\\n  --file PROJECT_SPEC.md \\\n  --mode balanced\n```\n\nSingle-file example:\n\n```bash\npython3 \"$EMPIRE_HANDOFF_ROOT/scripts/empire_handoff.py\" generate \\\n  --repo /absolute/path/to/repository \\\n  --task \"Propose one accessible responsive HTML5 landing page\" \\\n  --role worker \\\n  --format single-file \\\n  --suggested-path proposals/index.html \\\n  --media-type text/html \\\n  --file docs/frontend-spec.md \\\n  --mode balanced\n```\n\nSend only the minimum bounded evidence needed. Do not route secrets, credential files, unrelated repository content, or private material that is ineligible under the selected provider's data policy. Let catalog metadata, benchmark evidence, task fit, availability, and any configured accumulated project budget control selection. Use `--model provider/model` only when the user explicitly requests that canonical model. Do not add `--max-authorized-cost` unless the user explicitly requests a per-call dollar ceiling. Add `--require-zdr` only when the user explicitly requires Zero Data Retention; data-collecting providers remain denied by default.\n\nHandoff shares Review's invocation-time catalog policy. Exact-model cache misses and requests for the latest, newest, or currently available model force a live refresh before route selection. Use `--require-live-catalog` when a fresh authenticated OpenRouter scan must be explicit.\n\nHandoff results include the same measurement-only `context_preflight` contract\nas Review. Supply both `--codex-context-limit-tokens` and\n`--codex-context-used-tokens` only when the active host exposes them. Unknown\ncontext recommends artifact delivery because Handoff is already a persistent,\nquarantined workflow. `--response-class` records a recommendation but does not\nchange the provider request in this phase; `applied_to_dispatch: false` prevents\nthe receipt from implying enforcement.\n\n## Inspect and act\n\nTreat the generated artifact as quarantined source, not as an implementation.\n\n```bash\npython3 \"$EMPIRE_HANDOFF_ROOT/scripts/empire_handoff.py\" show HANDOFF_ID\npython3 \"$EMPIRE_HANDOFF_ROOT/scripts/empire_handoff.py\" continuation-plan HANDOFF_ID \\\n  --repo /absolute/path/to/repository \\\n  --task \"Finish only the missing risks and acceptance checks\" \\\n  --file PROJECT_SPEC.md \\\n  --completed-id scope \\\n  --completed-id implementation\npython3 \"$EMPIRE_HANDOFF_ROOT/scripts/empire_handoff.py\" adversarial-review HANDOFF_ID\npython3 \"$EMPIRE_HANDOFF_ROOT/scripts/empire_handoff.py\" approve HANDOFF_ID\npython3 \"$EMPIRE_HANDOFF_ROOT/scripts/empire_handoff.py\" reject HANDOFF_ID\npython3 \"$EMPIRE_HANDOFF_ROOT/scripts/empire_handoff.py\" download HANDOFF_ID \\\n  --repo /absolute/path/to/repository \\\n  --destination /path/outside/repository/proposal.html\n```\n\nRender `show` output as source text. Never execute generated HTML, JavaScript, or other executable content. A download destination must remain outside the active repository.\n\nIf generation returns `partial_recoverable` or `completed_degraded`, do not reject or rerun it. The assistant response was already saved to `research_artifact.content_path` before validation. Read it through repeated `show HANDOFF_ID --offset N --max-chars 12000` calls until `chunk.has_more` is false, synthesize the usable partial research, and clearly label incomplete sections. An in-band provider error with usable bytes is partial, never complete. Never start a paid retry or continuation automatically. Request explicit authorization and show incremental plus cumulative cost before a same-model continuation of only the missing work. A `failed_empty` result with observed cost must remain visible as `compensation_pending`; an unknown billing outcome must remain `pending_reconciliation`. Do not represent either as delivered or as zero cost.\n\nUse `continuation-plan` only for `partial_recoverable` handoffs. It is a\nnon-billable preflight: it revalidates the original project and evidence hash,\nhashes the missing-work request, records completed IDs, bounds the recovered\ntail used by a future continuation prompt, and reports the parent-based\nincremental and cumulative estimate. It never reserves budget or dispatches a\nprovider request. Treat `continuation_plan_blocked` as fail-closed. In\nparticular, a display provider name is not an exact OpenRouter provider slug;\nsame-provider continuation requires a proven slug plus a current pricing\nrefresh and explicit incremental and cumulative cost authorization. The paid\ncontinuation transport remains unavailable in this slice.\n\nA provider `content_filter` or `safety` terminal is\n`blocked_provider_safety`, even when readable bytes arrived or an in-band error\nis also present. Preserve those bytes privately but never preview, synthesize,\napprove, download, or export them through the ordinary handoff lifecycle.\n\nFor a paid `failed_empty` result, the review runtime automatically creates a\nlocal compensation record in state `needed`. Inspect or advance it through the\nreview CLI's `compensation list`, cross-project `compensation report`, and\n`compensation update` commands. New OpenRouter handoffs preserve the generation\nID in both the route receipt and local ledger so the empty delivery can be\nmatched to provider activity without relying only on timestamp/model/cost. A\nlocal record is not proof that a provider claim was submitted.\n\nFor adversarial review, create the separate review record, inspect the unchanged source through `show`, then have Codex independently report correctness, security, accessibility, assumptions, and missing-test findings. Do not mutate the original artifact while reviewing it.\n\n`approve` means approved for Codex consideration. It never means apply directly. After approval, Codex may revise, partially use, relocate, or reject the proposal; Codex must make repository edits itself and run appropriate validation before reporting completion.\n\n## Report provenance\n\nPresent:\n\n- Codex as lead and the selected external model as Partner or Worker.\n- End any handoff synthesis or conclusion with `synthesis_footnote.markdown`. It contains only the external model icon and base model name in one atomic SVG; never rebuild it from a standalone image and adjacent text.\n- A quiet footer after a horizontal rule using `response_footnote.markdown`; keep it on one physical line and use its text fallback when local images do not render. Each visible chip must be one transparent SVG image containing an internally aligned 14px logo and vector label; never place a standalone Markdown image beside separate Markdown text. Never emit raw HTML.\n- Requested, selected, and proven served model/provider identities.\n- `unavailable` whenever upstream metadata does not prove served identity.\n- Artificial Analysis as a chip only when matched benchmark evidence affected route selection. Keep Codex web-tool citations native beside their claims; include only provider-returned external URLs from `web_research.sources` in the Empire footer.\n- Route profile, benchmark availability, projected and observed cost, artifact hash, validation state, and warnings.\n- A clickable local file link only after a successful download.\n\nDo not expose the raw provider response, raw repository evidence, credentials, quarantine internals beyond the returned path, or unverified identity claims.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}