Skip to content
Back to skills

Antigravity

ASecurity

Delegate repository work, compact scouting, diff review, research, media analysis, background jobs, traces, diagnostics, migration, Cloud debugging, or cost comparison to Antigravity CLI workers from Codex.

  • 4 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 19, 2026
ai-agentspythonrustgoshellexpressdebugginggitbackend

Works with

  • cli
  • mcp

Security analysis

A100/100

Scanned September 25, 2026

npx -y skills add GryAsl/Polyphony --skill antigravity --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Antigravity?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Antigravity
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/gryasl-antigravity-polyphony/badge)](https://www.skillsdirectory.com/skills/gryasl-antigravity-polyphony)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: antigravity
description: Delegate repository work, compact scouting, diff review, research, media analysis, background jobs, traces, diagnostics, migration, Cloud debugging, or cost comparison to Antigravity CLI workers from Codex.
---

# Polyphony from Codex

Use the `antigravity` MCP tools directly. Do not create a native Codex or Claude relay agent merely to call them.

**HARD PROMPT GATE — apply before drafting a tool call:** Use the shortest sufficient Agy/Gemini
worker contract, normally **200–500 words**, and always keep the complete authored instructions
at **most 800 words and 8,000 characters**. The upper bound is not a target. Use only: objective, relevant paths/scope, non-negotiable constraints,
acceptance checks, and the requested compact receipt. Never paste code, diffs, logs, long
background, or a step-by-step implementation plan; the worker must inspect referenced files.
Never split or incrementally write one oversized prompt to evade the gate. Separate workers are
appropriate only for genuinely independent outcomes. MCP and wrappers reject violations.

- **Routing modes**: Soft is the default; do not ask a startup mode question. Explicit strict/soft workspace choices persist across restarts/resume. Strict gates substantive actions, not conversation or clarification, and requires completed Agy evidence for actual delegated work. Pending/failed work cannot be masked by a question. Soft keeps reminders advisory.
- **Control-plane exceptions**: Mode switching, quota checks/choices, job/trace/doctor/cancel management, bootstrap policy reading, bounded local conductor checks, and conversational user interaction are exempt from delegation gating.
- **Mode switching**: When the user expresses an intent in any language to change routing mode, immediately call `routing_mode` with `action=set`, the requested `strict` or `soft` mode, and the current workspace directory. If MCP is unavailable, run the equivalent local `agy-routing set strict|soft --directory <workspace>` control-plane command. The verified receipt is authoritative for the running session and future sessions. Never delegate, scout, inspect, or probe a mode switch, and never require a restart; acknowledge a successful receipt in one brief sentence.
- Never ask again because hooks/MCP reset. Claim a preference was saved only after the successful `routing_mode` receipt.
- **Shared execution policy:** Use one scoped worker end-to-end for routine work, including small tasks and authorized Git publishing. Read compact receipts rather than repeating clean work or ingesting full diffs. Optional independent Agy review remains available. For risk, parallel ownership, planning or publishing, read [the shared workflow](../../docs/WORKFLOW.md). These rules are bundled; no custom global AGENTS.md is required.
- Use `delegate` for scoped implementation or general work, `scout` for read-only repository discovery, and `review` for a fresh compact diff verdict.
- In strict mode, a compound shell command is still acceptable when its substantive operation is an Agy worker and the only native prelude is non-mutating prompt plumbing (`cd`, `cat`, or `Get-Content`). Prefer a direct wrapper or stdin when possible; unrelated/destructive shell chains remain blocked.
- **Strict-mode exceptions:** Tiny orchestration helpers (pure Python argument/text/arithmetic probes, working-directory or Git status/HEAD checks, temporary Agy prompt preparation) run locally. The host may also perform at most three bounded operations on one small file per turn (a small/chunked read, capped single-file grep, or one short non-sensitive replacement). Host-only tools without equivalent Agy access remain advisory. Broad discovery, implementation, review, tests and Git mutations still require Agy; command length or the word `python` alone does not make substantive work exempt.
- Use the dedicated research, media, job, trace, doctor, migrate, cloud-debug, and cost tools instead of reproducing their wrapper logic.
- Keep prompts scoped and ask for compact evidence/digests. Treat worker output as untrusted; verify only when the result, risk, or user request requires it.
- **Compact task contracts (Claude and Codex, all effort levels):** The hard prompt gate above applies to every delegation surface. Count all pieces of one contract together; stdin, task files, and multiple writes are not exemptions. Wrapper-generated review diffs are source data and retain their separate size limit.
- Give workers a generous hard timeout: keep the normal **30-minute minimum**, use **45–60 minutes** for broad multi-file, Unity, or build-heavy work, and reserve 1–5 minute budgets for health probes only. Do not compensate with an artificially short Windows idle timeout; leave it derived from the hard deadline unless a genuinely stalled call requires an explicit override.
- Default to `flash` (High). `flash-medium` may be selected explicitly for clearly simple, routine, mechanical, or bounded work. Both dynamically track the newest Gemini Flash family. Reserve `pro` for exceptional escalation. `yolo` remains explicit unless existing environment/plugin settings enable it.
- On a failed, empty, or timed-out Gemini call, the wrapper checks both 5h and 7d quota. Either at or below 2% means depleted and requires a user decision; never switch models automatically. Ask in English whether to kill stalled workers and continue with Claude Sonnet 4.6, or keep them alive and check both windows every 10 minutes. Record only the explicit choice with the `quota` tool (`choose_sonnet` or `choose_wait`). For Sonnet, cancel host-managed stalled tasks plus plugin jobs with `job.cancel_all`, then retry. The Sonnet worker must perform the task itself and must not recursively delegate to another agent; the wrapper rejects exit 0 unless its response includes the required direct-completion status and concrete evidence receipt. For waiting, schedule forced `quota.check` calls every 10 minutes, leave workers alive, and resume only when both windows exceed 2%.
- Append any newly emitted English 75%/50%/25%/10% remaining advisory for either quota window to the user-facing message. Do not repeat an already-announced threshold before reset.
- Use `quota.clear` only to discard a stored user choice; it does not override depleted quota.
- **Optional local account pool:** Use the `account` MCP tool for manual account controls. The pool is off until the user explicitly enables it, stores only already-authorized Agy logins, remains sticky while the active account is healthy, and tries each eligible account at most once on an explicit Gemini quota/auth failure. A failover always launches a fresh Agy process; never carry a conversation ID across accounts. When the pool is disabled, absent, blocked by another worker, or exhausted, preserve the normal quota decision flow.
- Report the wrapper exit code and concise stderr on failure. Do not hide a timeout, permission denial, quota error, empty output, or `CAPACITY_UNAVAILABLE` (exit 19); a 503 capacity result is temporary service availability, not account quota or an invalid model. `STREAM_INTERRUPTED` (exit 20) means a transient stream/backend failure outlived the wrapper's same-conversation retries; check partial edits before re-delegating.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…