Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Raw

ASecurity

The speaker’s central claim is that coding agents will not produce major acceleration inside an unchanged SDLC: teams must move people from line-by-line implementation toward setting boundaries, supplying feedback, and running agent work as both engineering and research. This is an experienced practitioner’s view, not evidence that the model will work for every team. **For conventional software, autonomy needs deliberate control and feedback.** The speaker says a Cursor license alone did not ...

2 stars
0 votes
0 copies
0 views
Added 9/19/2026
ai-agentsgorailstestingapidatabasesecuritydocumentation

Works with

cursorcliapimcp

Security Analysis

A100/100

Scanned 9/19/2026

Install to Claude Code

$npx -y skills add welltraum/minto --skill raw --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Raw?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Raw
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/welltraum-raw-6addfcdc/badge)](https://www.skillsdirectory.com/skills/welltraum-raw-6addfcdc)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
12-talk-digest__codex__control.md
The speaker’s central claim is that coding agents will not produce major acceleration inside an unchanged SDLC: teams must move people from line-by-line implementation toward setting boundaries, supplying feedback, and running agent work as both engineering and research. This is an experienced practitioner’s view, not evidence that the model will work for every team.

**For conventional software, autonomy needs deliberate control and feedback.** The speaker says a Cursor license alone did not change behaviour: developers used defaults, needed three to six months to learn, and resisted abandoning familiar tools and practices. Their proposed response is to retain human control over accountable interfaces—contracts, APIs and databases—while agents generate and check the surrounding implementation. Feedback from tests, browser/server behaviour and users is presented as the mechanism that lets agents self-correct; they argue agent review should feed coding agents directly, rather than create another queue of comments for humans. [00:02–00:12]

**The process bottleneck shifts from coding to handoffs and broad ownership.** If each role works faster with an agent, the speaker argues that Agile handoffs become the limiting delay. They contrast a classical team that can spend a month without code with a “product engineer” who can ship a mobile app and website in days, while acknowledging such people are scarce. Their practical interim model is smaller, T-shaped teams covering more roles, backed by mandatory testing and feedback loops. [00:10–00:12]

**Agent systems require two disciplines, not a standard delivery team alone.** The talk divides the work into engineering—integrations, MCP, deployment and agent access rights—and research—datasets, benchmarks, metrics and evaluation methods. The speaker claims a team needs both capabilities, either in one unusually broad person or in complementary roles. They recommend framing an agent as business functions, with inputs, outputs, controls and integrations, using IDEF0 language; this reportedly helped teams start ambiguous work and cut an overgrown agent with roughly 100 tools down to its necessary functions. [00:14–00:20]

**Managing agents means managing experiments, not treating every failure as a Jira bug.** The speaker says agent errors should become evaluation data and hypotheses to test against agreed business metrics. In this model, a sprint contains experiments as well as features, and clients need visibility into what was tested and what failed. They cite the ML System Design Doc as a useful record of experiments and decisions, but note it requires disciplined documentation culture. [00:20–00:22]

**Services and governance must adapt to agents as a new actor.** The speaker argues existing services are designed for people, whereas agents need suitable entry points, permissions and security controls. They offer the example of a compromised shopping agent using a retailer’s MCP server, and raise recovery and protection questions without claiming answers. They also cite an incident in which an open-source assistant filled a disk and then deleted its own skills and memory during cleanup, supporting their warning that infrastructure guardrails remain necessary. [00:22–00:26]

For next week’s review, the most testable claims to bring are: where our human approvals must remain; whether our feedback signals are usable by agents; which handoffs persist after agent adoption; whether agent work has explicit evaluation and experiment loops; and whether our services, permissions and operational guardrails recognise agents as distinct actors.

Attribution

welltraumwelltraum
View sourceMore from welltraum →
SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

693161 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →