Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Workspace Status

ASecurity

Read-only briefing and fresh-session recovery for a WORKSPACE: priorities, owners, current authority, delivery progress, blockers and next actions. Use for workspace-status or understanding a workspace. This skill never writes. NOT for creating records, scoping work, dispatching, syncing or native repository work.

13 stars
0 votes
0 copies
0 views
Added 10/6/2026
ai-agentsnodegitapi

Works with

terminalcliapi

Security Analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned 10/6/2026

$npx -y skills add EvolveHQ/docflow --skill workspace-status --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Workspace Status?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Workspace Status
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/evolvehq-workspace-status/badge)](https://www.skillsdirectory.com/skills/evolvehq-workspace-status)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: workspace-status
description: "Read-only briefing and fresh-session recovery for a WORKSPACE: priorities, owners, current authority, delivery progress, blockers and next actions. Use for workspace-status or understanding a workspace. This skill never writes. NOT for creating records, scoping work, dispatching, syncing or native repository work."
---

# workspace-status

Give a source-backed view of what matters and what can happen next.

## Operating contract

**Inputs:** canonical workspace root and optional focus/full record reference, actor/host and permitted reading scope.
**Effects:** read and report only; no canonical edit, claim, grant, index write, install or dispatch.
**Native claims / dependencies / resources:** observe their current native sources for relevant work; missing access means unknown rather than free ownership.
**Stopping point:** a dated orientation with source paths/revisions and explicit gaps.
**Receipt:** actual reads/checks and output, owner/branch/blocker/next action for focused work, latest grant applicability and observed native integration state.

## Resolve inputs and current authority

Reuse applicable choices already supplied, including host, actor, paths,
scope, depth and stopping point. Summarise the resolved choices; ask only
for a material missing or conflicting choice. A recorded preference alone
does not supply authority. Selection sets priority; accepted agreement,
role, profile, registry membership and a copied brief grant no execution.

Locate the installed sibling bootstrap skill (resolve symlinks first).
Its `templates/workspace-assets.json` lists the packaged asset locations:
`../../workspace` in a plugin or `../../docflow-workspace` in a detached
copy, relative to bootstrap. An explicit asset root is valid. Read that
root's `CONTRACT.md`, `schema.json` and `README.md`; all templates are
in bootstrap's `templates/`. If missing, report the exact missing asset
and stop dependent writes. Never assume a source checkout or install/fetch
dependencies implicitly. The external validator requires Node.js 22+.

Read the workspace entry point, registry and conventions, then the current
canonical records and declared native member instructions. Resolve canonical
home/full UUID and contained paths, including symlinks; a missing member
stays registered with diagnostics. Search only authorised roots. Copied
context and search indexes are discovery aids: read current authority,
claims and critical constraints directly.

Before each dependent action, recheck the actual operator mandate for actor,
scope, effects, conditions and stopping point. Initial authorised setup,
scoped reads and authorised canonical planning use that mandate; they do
not require or justify inventing a work record or execution grant.
For grant-bound native execution, additionally recheck the current grant:
actor, scope revision, delivery, action/effects, conditions, start, expiry,
revocation/suspension, exact grant revision and stopping point. Reuse an
existing compatible grant; request only missing or changed authority.
Check native ownership, dependencies and shared resources separately.
Reference-only members permit only scoped non-mutating actions. A denied
tool/action stops that action across alternate tools, routes and delegates.
Contact loss is not worker exit and never permits reassignment.

Validate with `node <assets>/validate.mjs <workspace> --at <current-UTC>`;
supply the actual UTC time and retain complete output/exit. Validation checks
record consistency, not permission, live ownership or proof of execution.
Unknown, stale, skipped, missing and failed evidence remain distinct.

## Procedure

1. Read README, AGENTS, registry and conventions; validate the workspace.
   If malformed, report diagnostics alongside readable unaffected records.
   Open the five canonical folders directly; INDEX is a dated derivative.
   An empty search result is not evidence of an empty queue or free claim.
2. Identify selected ideas, current accepted decisions and linked work.
   Keep agreement, priority, grants and delivery progress separate. Show
   superseded/rejected history without reviving it. A native member's
   legitimate Implemented state is not a workspace decision state.
3. For each relevant work record report full identity, priority, owner,
   blockers, dependencies, next_action and latest runs. Distinguish a
   grant-bound attempt from an imported/backfilled run: imported history is
   read-only and carries no workspace grant, so it never proves current
   authority. For native references
   read exact paths/revisions and current Status, branch and checks where
   authorised. Use the member's own discovery and queue conventions; do not
   create a competing queue or force a migration.
4. For a stopped/blocked item, name its existing owner, actual branch,
   blocker, last reconciled attempt and next step. Distinguish a stopped
   actor from an unknown/disconnected one. A terminal still existing does not
   prove its agent is active; silence does not prove exit. Report stale
   observations and ask for missing evidence only when needed for a next action.
5. Explain current authority without granting it. Read latest grant actor,
   scope/revision, expiry and revocation, native claims and resource
   reservations. Explicitly distinguish an executable assignment from a
   planned item without a grant; blocked dependencies remain visible.
6. A file in native plan/done on an unmerged branch is prepared completion.
   Only checked integration evidence under the member's actual completion
   event supports shipped status. One passed run or delivery does not close
   parent work. Completed work leaves the current agreement accepted.
7. Optionally identify already available relevant roles/profiles and sources
   through `<assets>/guides/recommendations.md`; distinguish reference,
   enable and use. Retain unchanged declined choices; add nothing when
   existing file tools suffice. Return a concise dated view and source links.

## Recovery and unknown outcomes

A fresh session repeats source reads, not the previous questionnaire.
Retain valid supplied focus and host choices; flag revisions that changed.
Do not refresh INDEX or repair malformed records during this read-only skill:
name the scoped workspace-sync action (record repair, delivery observations and
INDEX refresh) or workspace-scope action (record shaping) needed.
No run or canonical receipt is invented for read-only orientation.

<!-- docflow:closing-report -->
## Closing report

End every run, including blocked, failed and stopped runs, with a section
headed exactly **Status at a glance**, containing these three labels:

- **This run:** only actions actually attempted and their outcomes; quote each verify gate's exact output and exit code, including timeouts or interruptions.
- **Overall:** implemented, partially verified, verified, blocked, failed or unknown. A passing sub-step is not an overall pass; incomplete or missing evidence never becomes success.
- **Yet to do:** every remaining action, unresolved finding, verification, cleanup or required input. Write None only when the whole task is verifiably complete; never omit work because a budget ended.

Routine progress messages need no block. Keep final results brief and
distinguish work prepared on a PR from work confirmed shipped.
<!-- /docflow:closing-report -->

Attribution

EvolveHQEvolveHQ
View sourceSee grades on GitHubMore from EvolveHQ →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698431 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →