mattlane66/planning-skills-for-agents-and-humans
Planning workflows with evidence-gated research, fluid collaborative shaping, explicit promotion gates, breadboarding, bounded implementation handoffs, and reflection.
Changelog
Unreleased
v1.5.1 — Explicit execution-appetite authority — 2026-09-29
Fixed
- Require explicit human acceptance of every run-level execution appetite before implementation can begin; agents may propose the appetite but cannot approve or silently enlarge their own bet.
- Make that acceptance machine-verifiable in the orchestration/integrity contracts and context packet, with regression coverage for the build gate.
- Document how the portable execution-appetite method compiles into runtime-specific controls, using current Claude Messages API, Agent SDK, and Managed Agents mechanisms only as non-canonical examples.
v1.5.0 — Inference appetite and bounded agent execution — 2026-09-29
Fixed
-
Complete the execution-appetite orchestration contract by defining its hard-gate semantics, updating contract tests, and bundling the referenced guide in the Claude plugin.
-
Refresh transitive npm locks for newly disclosed
undici,fast-uri, andip-addressadvisories, including moving the existingfast-urioverride to patched3.1.8, before publishing v1.5.0. -
Preserve product-repository
AGENTS.mdreferences in the Claude plugin, rewrite nested support paths, and check all bundled Markdown links. -
Surface default hook reminders as runtime-visible JSON and recognize absolute planning/documentation paths without false build reminders.
-
Make Lead User validation read-only, support completed empty evidence passes and explicit brief-field provenance, and require canonical Phase H delivery in all modes.
-
Bind Evidence Freeze to content, reject overlapping independent lineages and selected concepts with failed requirement fit, and redact escaped withheld URLs.
-
Run assurance validation from integrity-checked host code; supply explicit trusted synthetic human decisions and retain failed artifacts with bounded subprocesses.
-
Correct MCP routing at exclusion, realized-fit, and negated-scope boundaries; serve bounded, skill-local support resources through MCP.
-
Reconcile artifact authority against the orchestration manifest, bring examples and stable IDs up to the skill contracts, and complete the Gemini/Claude command surfaces.
-
Reject untrusted Host headers on the loopback viewer, align the site's Node floor with its dependencies, test that floor in CI, and separate major dependency updates.
Added
-
Add a future-proof Agent Execution Appetite model that keeps human attention and useful-by time primary while treating tokens, spend, turns, and compute as replaceable runtime guardrails.
-
Extend context packets and orchestration with run-level
Worth / Needed by / Protect / Cut first / Stop whenboundaries so agents work to outcomes rather than exhaustion. -
Extend canonical agent run logs with actual human cost, runtime evidence, figuring-it-out versus executing-down effort, shaping signals, and explicit continue/reshape/new-bet decisions.
-
Add stable criterion lineage from evidence-backed R candidates through Working/Accepted authority, selected mechanisms, implementation context, and realized-fit assessment.
-
Add inverse requirement coverage and selected-design requirement realization maps so every Accepted R can be traced to the concrete behavior that claims to embody it.
-
Separate implementation verification from realized fit, with outcome-evidence-only realized-fit statuses and regression cases for supported, unassessed, and contradicted criteria.
-
Add an explicit
x / y / f()routing diagnostic so current-situation, desired-outcome, and solution uncertainty lead to different next moves. -
Add semantic public-web need–solution mining as a complementary discovery lane while keeping popularity/interest metrics as discovery signals only.
-
Add independent discovery-branch coverage checks for pivotal needs and an optional enabler/discontinuity scan for high-altitude opportunity work.
-
Add explicit need transferability assessment as the sixth Concept Generation Gate check.
-
Add layer-preserving rejection records so technical/economic/safety objections to a mechanism or implementation part do not silently invalidate the need, principle, or requirement.
-
Make the discovery-signal/decision-evidence boundary explicit across the Lead User protocol, prompts, state contract, portable workflow, and validator.
v1.4.0 — Lead User research and assurance — 2026-08-31
Added
- Added deterministic Lead User next-phase routing, a
/lead-userstart/resume controller, and focused Phase A–H wrappers for Claude Code and Gemini CLI. - Added an explicit research-to-frame handoff template and human acceptance gate.
- Added a complete synthetic Lead User v1.7 reference study with qualified, derivative, contradictory, concept-shaping, operational-action, and privacy-safe drill-down state.
- Added a blind real-runtime assurance harness that scores generated study artifacts independently of adapter self-report, plus a manual GitHub Actions workflow.
Improved
- Integrated Lead User Research into the planning router, orchestration contract, cross-platform invocation guidance, and optional upstream planning flow without making research a mandatory predecessor to framing.
- Made source content explicitly
UNTRUSTED_DATA, persisted instruction-risk handling, and added a malicious-source regression fixture. - Strengthened structural validation for source, evidence, trends, lineage, findings, concept gates, sufficiency dimensions, decision status, completion, and cross-format privacy/state markers, including a deterministic brief-to-state fingerprint.
- Replaced narrative action strings with evidence-oriented A## execution contracts and made the Decision Brief action-first, evidence-linked, and privacy-safe by default.
- Made Lead User assurance cover every authoritative registry, explicit synthetic-fixture isolation, falsification/observability ledgers, pyramiding, lineage conflicts, transitive concept/ACT evidence, shaping-frame output, and human selection provenance.
Fixed
- Ignored repository-local Python virtual environments during Markdown link checks and version-control discovery so third-party package documentation cannot create false failures.
- Made Node health stages stop immediately on install, build, test, or audit failure so a later successful command cannot mask an earlier verification failure.
- Prevented empty negative interpretations and completed insufficiency repairs from looping forever by persisting explicit interpretation and repair transitions.
- Refused non-empty initializer targets, required adversarial and discovery registries, required evidence bases, and rejected unsafe outward URLs and Markdown injection.
- Made private-identity detection token-aware, prevented derivative lineage from also counting as independent, and enforced evidence-backed trend/LU paths at decision gates.
- Rewrote every Lead User support path in the generated Claude plugin to a resolvable bundle-local path and added bundle regression checks.
- Rendered accepted shaping frames, real candidate/selected mechanism states, human selection provenance, rotated parts, and prominent synthetic-fixture warnings.
v1.3.1 — Routing safety and reproducible releases — 2026-08-11
Fixed
- Made MCP workflow recommendations honor explicit skill exclusions, negated prerequisite states, and clearly labeled untrusted quoted material.
- Required an accepted breadboard before recommending Statechart and added regression coverage for routing, prompt-injection, and source-trust boundaries.
- Derived the MCP server version from its package manifest so runtime metadata cannot drift from coordinated plugin versions.
- Defined
active_scopeas the canonical machine-readable alias for either one selected slice or one selected Dumplink task group.
Added
- Added deterministic release tooling for all Claude upload ZIPs, the Claude Code plugin bundle, and a
SHA256SUMSmanifest. - Added success-gated automatic version tagging after Repo health passes on
main; existing tags are never moved or recreated. - Added CodeQL analysis, weekly Dependabot updates, Python dependency auditing, and an opt-in blind real-runtime behavior-evaluation workflow.
- Added contribution, security, conduct, issue, and pull-request guidance plus Dumplink source attribution.
Security
- Separated trusted routing instructions from untrusted transcripts, issue bodies, web content, pasted files, quoted text, and tool output across canonical and packaged skill surfaces.
- Pinned every GitHub Action to a full commit SHA, applied least-privilege workflow permissions, disabled persisted checkout credentials, and added bounded workflow timeouts and concurrency.
- Documented that non-loopback visualizer hosting has no authentication and is appropriate only on trusted networks.
Changed
- Hardened tag releases to require exact stable SemVer, coordinated versions, an exact changelog section, ancestry on
main, a passing full health suite, and prebuilt checksummed assets before publication. - Isolated npm verification in a task-scoped cache so health checks do not depend on a writable user-level npm cache.
- Updated the MCP SDK and
tsxwithin their existing major-version compatibility boundaries.
v1.3.0 — Fluid shaping, Wayfinding, and verifiable breadboards — 2026-08-11
Improved
- Made collaborative shaping fluid by default: teams can start R-first, S-first, evidence-first, or uncertainty-first and move among requirements, shapes, fit checks, focused spikes, sketches, and candidate breadboards while material remains Working.
- Reframed human gates as promotion/commitment gates rather than navigation locks; Accepted requirements and Appetite still constrain selection, candidate evidence still requires reconciliation, and selected behavior/scope still gate implementation.
- Added explicit
collaborativeandgatedorchestration profiles so interactive human shaping can stay flexible while automation and policy-controlled workflows retain deterministic prerequisites. - Allowed collaborative candidate-shape breadboarding to use Working requirements or Unset/Working Appetite while keeping final fit/Appetite claims provisional and build scope forbidden.
- Updated Claude Code, Codex, Gemini CLI, Claude Design, MCP integration guidance, runtime adapters, README/start-here/workflow docs, quality rubric, eval corpora, and health checks to describe the same profile behavior.
- Declared the MIT license in every canonical skill and split breadboarding's detailed notation and slicing material into an on-demand reference.
- Separated portable Agent Skills metadata from Claude Code, Codex, Gemini CLI, Claude Design, and MCP adapter behavior.
- Made Claude human-gate aliases manual-only, hid alias-backed generated skills from duplicate slash-menu discovery, and added operational metadata to direct-only Claude skills.
- Added native Gemini skill installation guidance, Codex skill-only boundary checks, Claude Design example packaging, and shared activation fixtures across all skills.
- Replaced ad hoc frontmatter parsing with YAML validation and added runtime adapter regression tests.
- Added CI validation for every generated Claude upload package, including ZIP roots, metadata, cross-skill references, and required local resources.
- Clarified when Claude Design should invoke a skill directly and when repository-aware work must return to Claude Code.
- Made custom package-output cleanup non-recursive and fail closed around protected paths, unrelated content, directories, and symlinks.
- Expanded repository health checks to run packager tests and dependency audits.
- Unified root, Claude upload, and MCP skill descriptions behind
skill-metadata.json, with parity and boundary regression checks.
Added
- Added
/spikefocused shaping wrappers for Claude Code and Gemini CLI; spikes can originate from R, S, fit, sketches, candidate breadboards, or implementation reality and return explicit R/S/fit/Appetite implications without deciding the product direction. - Added Gemini
/shapeand/breadboardwrappers for parity with the collaborative Claude shaping surface. - Added a solution-first shaping walkthrough showing rough Shape A → Working R → Working fit → spike/candidate breadboard → Accepted judging inputs → explicit human selection → selected-design reconciliation.
- Added workflow and activation eval cases for S-first shaping, Working fit checks, provisional candidate breadboarding, focused spikes, gated-profile prerequisites, and hard selection gates.
- Added the
wayfindingskill and/wayfindwrappers for coordinating dependent planning decisions across sessions without creating a second source of product truth. - Added portable local-Markdown and optional issue-tracker adapters, Wayfinding map and ticket templates, MCP routing, and cross-runtime activation coverage.
- Added a Claude and Claude Design workflow that separates canonical skills from Claude Code command wrappers.
- Added uploadable Claude skill ZIP generation with optimized trigger metadata and bundled supporting resources.
- Added positive, automatic-selection, near-neighbor, negative-trigger, command-wrapper, and cross-surface fallback tests for Claude skill invocation.
- Added packager safety tests and regression coverage for hidden support files and malformed visualizer paths.
Fixed
- Removed the implicit requirement that ordinary interactive shaping must proceed through criteria → Appetite → shapes before useful solution exploration can occur, while preserving the same strict selection and build gates.
- Preserved dot-prefixed support-file references in generated Claude skill packages and made piped CI failures propagate correctly.
- Reconciled frame, appetite, shape-selection, kickoff-authority, context-feeding, and breadboard-reflection rules across canonical artifacts and adapters.
- Removed task grouping and slicing from shaping, separated descriptive and normative breadboarding, and made Dumplink ingest one selected project, create its vertical task-group slices, then stop for human plan approval and active-group selection.
- Upgraded repository-health Actions to their Node 24-based major versions and added manual workflow dispatch for explicit CI verification.
- Removed moderate-or-higher MCP dependency vulnerabilities and made the visualizer return a bounded
400response for malformed encoded paths.
v1.2.0 - Planning gates, visual reconciliation, and live planning views
Added
- Added the
sketch-reconciliationskill and/reconcile-sketchwrappers for Claude Code and Gemini CLI. - Added a durable sketch-reconciliation template with observation, mapping, delta, decision, fit-impact, and ripple sections.
- Added a local Mermaid viewer that watches one or more planning Markdown files and hot-reloads every diagram in the browser.
- Added exact MCP routing for
R x A,A x R, spike, shape-update, sketch-reconciliation, slicing, slice-planning, and execution-verification shorthand. - Added an explicit appetite gate plus
/appetitewrappers for Claude Code and Gemini CLI.
Improved
- Extended the tool-neutral orchestration contract with an explicit visual-reconciliation gate.
- Added regression coverage for the conversational prompts used in an end-to-end shaping session.
- Extended repository health checks to validate the new skill, command surfaces, visualizer package, and viewer documentation.
- Made the generated Claude bundle self-contained for skill, agent-instruction, template, documentation, orchestration, and hook references.
- Synchronized context-packet requirements and cross-platform installation guidance for product-repository use.
v1.1.0 — Release integrity
Fixed
- Added the MIT license text referenced by the plugin manifests.
- Established root skill folders as the canonical source and synchronized all packaged
skills/copies. - Added byte-for-byte packaged-skill parity checks.
- Fixed broken artifact references in
.agent-orchestration.yaml. - Aligned drift-check authority order with Dumplink task-group precedence.
- Unified Claude, Codex, and MCP package versions.
Improved
- Added the optional Statechart skill across packaged skills, templates, commands, MCP routing, documentation, examples, and health checks.
- Reworked the README around a 10-minute entry path and the Frame → Shape → Breadboard core workflow.
- Updated Claude, Codex, Gemini, MCP, and invocation documentation to cover the complete skill set.
- Made the generated Claude bundle self-contained, removed duplicate command/skill names, and updated command permissions to current Claude tool names.
- Made MCP artifact tools read canonical template files instead of hard-coded duplicates.
- Made MCP skill and template exposure track the canonical inventory and orchestration manifest.
- Replaced the MCP workflow recommender's default Dumplink step with prerequisite-aware routing.
- Added reproducible MCP installs, compilation tests, recommendation tests, and package locking.
- Made lifecycle hooks executable and non-blocking by default, with explicit strict mode for blocking behavior.
- Strengthened repository health checks for manifests, references, generated bundles, docs, and MCP verification.
- Clarified that
evals/contains structural contract fixtures, not behavioral model benchmarks.
v0.1.0 — Initial public release
Initial reusable release of Planning Skills for Agents and Humans.
Included
- Framing, shaping, breadboarding, kickoff, context-feeding, and reflection skills.
- Root canonical skill folders and packaged plugin copies.
- Tool-neutral
AGENTS.mdinstructions and Claude, Codex, Gemini, and MCP adapters. - A small grocery-list walkthrough and canvas-export guidance.