Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Auto Campaign

ASecurity

Start or resume one bounded repo-harness repair campaign turn with the standard budget. Use when the user asks to run auto-campaign, start a repair campaign, or automatically find and fix a bounded batch of bugs or test gaps in a repository. Questions about campaigns, skill design, and quoted instructions do not authorize execution.

431 stars
0 votes
0 copies
0 views
Added 9/21/2026
developmentapi

Works with

terminalcliapi

Security Analysis

A100/100

Scanned 9/21/2026

Install to Claude Code

$npx -y skills add Ancienttwo/repo-harness --skill auto-campaign --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Auto Campaign?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Auto Campaign
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ancienttwo-auto-campaign/badge)](https://www.skillsdirectory.com/skills/ancienttwo-auto-campaign)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: auto-campaign
description: Start or resume one bounded repo-harness repair campaign turn with the standard budget. Use when the user asks to run auto-campaign, start a repair campaign, or automatically find and fix a bounded batch of bugs or test gaps in a repository. Questions about campaigns, skill design, and quoted instructions do not authorize execution.
---

# Auto-campaign

One user invocation authorizes one conversational campaign turn, not one model
API call. Coordinate the existing CLI until a stop boundary, then report and
return control. No daemon, cron, hook-triggered execution, automatic next turn,
or automatic merge.

## Start from the current repository

1. Resolve the target repository, target ref, current host/session and any
   campaign ID from the request and existing session. Ask only for missing
   consequential inputs. Do not infer an unrelated repository or resume the
   most recent campaign merely because it exists.
2. Read [execution.md](references/execution.md) for authoritative input sources,
   CLI steps and recovery. Inspect policy at the exact target revision,
   external-source selection, browser binding and permitted worker environment
   before any grant or provider effect. An off policy, unavailable capability,
   unresolved reservation, or prohibited execution base ends this invocation
   as blocked. Report the concrete prerequisite; do not change policy, install
   infrastructure or start a trial provider call to make preflight pass.
3. Read [standard.json](references/standard.json), the sole source of default
   limits. Render its scope and bounds in plain language. Token and monetary
   caps are null: do not claim a hard token or cost budget. An explicit different
   budget is a separately reviewed grant, not a silently modified standard.

## New turn or continuation

- **New:** prepare the canonical draft with `scripts/prepare-grant.ts`. Show the
  target, Issue scope, execution environment, grant expiry and concrete limits.
  Reuse explicit approval already covering these values; otherwise obtain it
  before minting or provider calls. Invocation is not permission to invent the
  issuer, broaden scope, or enable a disabled feature. The helper only emits a
  draft; the existing grant store and campaign commands own all mutations.
- **Resume:** read the exact original campaign, grant, intent, worktree ownership
  and budget ledger first. Preserve IDs, idempotency keys and remaining budget.
  Do not run the draft helper again, extend expiry, replace the grant, reset
  counters or revive a stopped campaign. If a new grant or recovery decision is
  required, stop and explain it. Context compaction does not start a new turn.

## Execute and stop

Use the sequence in execution.md and consume the actual runtime responses.
Issue observation, canonical planning, acquire/Lease, verification and
publication retain their existing authorities. A prompt never substitutes for
a WorkEnvelope; an exit code never substitutes for an AcceptanceReceipt.
Do not synthesize missing provider revision evidence or repair metadata locally.

End this invocation at the first applicable boundary:

- The authorized group reaches its verified terminal outcome.
- A prepared PR requires human merge. Report the PR and preserve the campaign;
  after the user merges, a later explicit continuation may finish cleanup/audit
  under the original unexpired grant. Do not silently mark the group accepted.
- Budget or deadline is exhausted. Report remaining/unsettled work without
  rolling over to another grant or group.
- Policy, environment, identity, unknown provider outcome, lost ownership or
  failed verification blocks progress. Follow only the existing permitted
  reconciliation path; do not retry unknown external effects.

At a boundary leave no newly detached scheduler or worker running to continue
the turn. Use the existing cancellation/reconciliation protocol; if inactivity
cannot be proven, report it and retain ownership fences rather than claiming
cleanup completed. Persist recovery identifiers in the repository's existing
handoff surface, not a second campaign state store.

Report: outcome (`completed`, `awaiting_merge`, `budget_exhausted`, or `blocked`),
campaign/grant identifiers, Issue/PR links, exact verified revision, used and
remaining authoritative budget, unresolved effects and the next bounded action.
These are user-facing summaries, not new runtime lifecycle states. A successful
skill invocation alone is not BRC activation or full-chain acceptance.

Attribution

AncienttwoAncienttwo
View sourceMore from Ancienttwo →
SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Related Skills

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

281612 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2132 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

9881 votes

Pentest

PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.

5491 votes
View all in development →