Skip to content

Skills an agent cannot start: review every command for agent invocation (disable-model-invocation) #41

Description

@timofriedlberlin

Problem

Five skills in the marketplace set disable-model-invocation: true, so an agent can never start them.
The Skill tool refuses with "cannot be used with Skill tool due to disable-model-invocation", and it adds
"Do not replicate this skill's workflow by other means":

plugin (0.14.17) skill
aep decompose, drive, review-plan, wave
worktree cleanup

(aep:drive and aep:wave in 0.14.16 carry the flag too.)

In practice the operator asks an agent in words to do exactly what the skill does, for example "merge
all worktrees, then /worktree:cleanup". The agent cannot load the skill. It cannot follow the skill's
steps by hand either, because the refusal tells it not to. So it has to stop and ask the operator to type
the command, in the middle of work the operator already asked for. That is a hard stop in a headless or
orchestrated run, and friction everywhere else.

The safety the flag is meant to give is already built into the skills' own steps. worktree:cleanup, for
example, says to dry-run and apply only exact ids the operator approved. Those steps hold just as well
when an agent runs them.

Request

  1. Review every command and skill in the marketplace for agent invocability. The working assumption:
    everything a plugin provides is eventually run by an agent.
  2. Drop disable-model-invocation wherever the skill's own steps already gate the risky part: an
    explicit dry-run, then an operator-approved list, or a proposal the operator approves before anything
    is written.
  3. Where a gate is really needed, put it inside the skill, for example "ask the operator to approve
    the table before --apply". Do not put it in the invocation. Then an agent can start the skill, prepare
    the evidence, and stop only at the decision.
  4. Keep an operator-only skill only where there is a reason, and state that reason in its
    description. The refusal text should then say what the agent may do instead.
  5. Add an eval that starts each skill from an agent turn ("the operator asked for X") and checks that
    it either runs or stops at an explicit, documented approval gate, never at the invocation.

Activity

  1. added a commit that references this issue on Oct 7, 2026
  2. b10x-bot commented on Oct 7, 2026

    @b10x-bot
    Contributor

    Shipped in 0.21.2 through #69.

    request done
    1. review every command and skill the five commands were the only skills with the flag; none keeps it
    2. drop the flag where the skill gates the risk aep:wave, aep:drive, aep:decompose, aep:review-plan and worktree:cleanup drop disable-model-invocation and the Codex allow_implicit_invocation: false
    3. the gate lives inside the skill aep:wave stops at its stage-1 proposal. worktree:cleanup applies only after a dry-run; the operator request (the command, or in words) authorizes the apply, and without one it stops after the dry-run
    4. operator-only only with a reason R3 and agentplugins-check: both flags plus an Operator-only: sentence in the description, or neither
    5. an eval per command evals/command-{wave,drive,decompose,review-plan,cleanup}-agent-turn: an agent turn must start the command and reach its work or its documented stop, never a refusal at invocation
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions