agent-swarm — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited agent-swarm (Agent Skill) and scored it 87/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 3 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 3 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill requires Python 3.8+ and standard library only. No external packages needed.
To install this skill's dependencies:
pip-compile ./requirements.in
pip install -r ./requirements.txtSee ../../requirements.txt for the dependency lockfile (currently empty — standard library only).
Parallel or pipelined execution across multiple agents and worktrees. The orchestrator partitions work, dispatches to agents, and verifies/merges the results.
2.5. Interactively Determine CLI and Model (ask once during bootstrap): Before dispatching the swarm workers, you must ask the user:
agy, claude, copilot, gemini, llama).Gemini 3.5 Flash (Low) or gemini-3.5-flash for agy).swarm_run.py invocation with --engine and --model matching their choices, appending < /dev/null to prevent TTY input halts (SIGTTIN).Each worktree can be assigned to a different worker type based on task complexity:
| Worker | Cost | Best For |
|---|---|---|
| High-reasoning CLI (Opus, Ultra, GPT-5.3) | High | Complex logic, architecture |
| Fast CLI (Haiku, Flash 2.0) | Low | Tests, docs, routine tasks |
| Low-cost CLI (gpt-5-mini, gemini-3.5-flash) | Low | Standard low-cost reasoning tier |
| Free CLI: llama gemma-4-12b | $0 | Self-hosted local inference, zero-cost batch jobs |
| Deterministic Script | None | Formatting, linting, data transforms |
| Human | N/A | Judgment calls, creative decisions |
Cost Optimization Strategy: For bulk summarization or distillation jobs, use--engine llama(local Gemma 4) if you have local Metal/CUDA acceleration set up. It is the only truly zero-cost path. Cloud CLIs like--engine copilot(gpt-5-mini) or--engine agy(gemini-3.5-flash) are low-cost but paid (consuming AI Credits or per-token billing). Use--workers 2for cloud CLIs (rate-limit safe) and--workers 1for localllamato avoid context swapping on 16GB Macs.
The ./../scripts/swarm_run.py script is the universal engine for executing this pattern. It is driven by Job Files (.md with YAML frontmatter).
.swarm_state_<job>.json. Use --resume to skip already processed items.check_cmd in the job file to short-circuit work if a file is already processed (e.g. exists in cache).--engine [claude|gemini|copilot|agy] switches CLI backends at runtime.# Zero-cost Copilot batch (2 workers recommended to avoid rate limits)
source ~/.zshrc # NOTE: use source ~/.zshrc, NOT 'export COPILOT_GITHUB_TOKEN=$(gh auth token)'
# gh auth token generates a PAT without Copilot scope -> auth failures
python ./scripts/swarm_run.py \
--engine copilot \
--job ./resources/jobs/my_job.job.md \
--files-from checklist.md \
--resume --workers 2
# Gemini (free, higher parallelism)
python ./scripts/swarm_run.py \
--engine gemini \
--job ./resources/jobs/my_job.job.md \
--files-from checklist.md \
--resume --workers 5
# Claude (paid, highest quality)
python ./scripts/swarm_run.py \
--job ./resources/jobs/my_job.job.md \
[--dir some/dir] [--resume] [--dry-run]---
model: haiku # haiku -> auto-upgraded to gpt-5-mini (copilot) or gemini-3-pro-preview (gemini)
workers: 2 # keep to 2 for Copilot, up to 5-10 for Gemini/Claude
timeout: 120 # seconds per worker
ext: [".md"] # filters for --dir
# Shell template. {file} is shell-quoted automatically (handles apostrophes safely)
post_cmd: "python ./scripts/my_post_cmd.py --file {file} --summary {output}"
# Optional command to check if work is already done (exit 0 => skip)
check_cmd: "python ./scripts/check_cache.py --file {file}"
vars:
profile: project
---
Prompt for the agent goes here.
IMPORTANT for Copilot engine: The copilot CLI ignores stdin when -p is used.
Instead, the instruction is prepended to the file content automatically by ./scripts/swarm_run.py.
Do NOT use tool calls or filesystem access - rely only on the content provided via stdin.-p is present. ./scripts/swarm_run.py automatically prepends the prompt to the file content instead.source ~/.zshrc to load your token. gh auth token returns a PAT without Copilot permissions, causing auth failures under concurrency.--workers 2 maximum. Higher concurrency trips GitHub's anti-abuse systems and surfaces as authentication errors.fcntl.flock for atomic writes. See inject_summary.py.-p "prompt" flag normallyhaiku -> gemini-3-pro-previewIf a batch run is interrupted partway through and the output store (e.g. cache JSON) is partially corrupted, reconcile the checkpoint before resuming:
# Remove phantom "done" entries that aren't actually in the output store
completed = [f for f in st['completed'] if f in actual_output_keys]
st['failed'] = {}Then rerun with --resume.
{file} in post_cmd is shell-quoted automatically -- filenames with apostrophes are safetotal_tokens and duration_ms from worker agents to a centralized timing.json log immediately as subtasks complete, rather than waiting for the entire swarm batch to finish.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.