Agent skill

Host Capability Routing

by devcodex-labs in devcodex-labs/devcodex

宿主能力路由 Owner — 当已识别工作流意图后,需要在五个逻辑宿主、八个受支持 variant 上选择 direct / planfirst / autoauthorized,核验原始指令 authority,或判断 native lever 是否具备新鲜且安全的直接证据时使用。

AGPL-3.0Auto-check passed

Install Host Capability Routing

skills CLI
$ npx skills add devcodex-labs/devcodex --skill host-capability-routing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install devcodex-labs/devcodex host-capability-routing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/content/skills/host-capability-routing .claude/skills/host-capability-routing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
host-capability-routing
GitHub stars
439
Token cost
~1.9k tokens
SKILL.md length
657 words
Files
6
Skills in repo
70
Repo updated
First seen
Licence
AGPL-3.0

At a glance

宿主能力路由 Owner — 当已识别工作流意图后,需要在五个逻辑宿主、八个受支持 variant 上选择 direct / planfirst / autoauthorized,核验原始指令 authority,或判断 native lever 是否具备新鲜且安全的直接证据时使用。

  • Works in 3 steps: intent / routing 已给出最终 workflowIntent; → 任务需要判断 direct / plan_first /… → 当前消息、CP artifact 或 managed task source…
  • SKILL.md covers 定位, 触发边界, Owner 与非职责 and 输入, plus 10 more sections
  • Calls npm and node; needs CATALOG_DUPLICATE_KEY

What it does

Host Capability Routing is an agent skill from devcodex-labs/devcodex. 宿主能力路由 Owner — 当已识别工作流意图后,需要在五个逻辑宿主、八个受支持 variant 上选择 direct / planfirst / autoauthorized,核验原始指令 authority,或判断 native lever 是否具备新鲜且安全的直接证据时使用。

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `capability-intent-decision.v1.schema.json`, `host-lever-catalog.v1.json` and `host-lever-catalog.v1.schema.json`).

The repository describes itself as: Intent-driven AI coding workflow runtime for consistent context, skills, approvals, validation, and handoffs across six AI coding hosts. The licence is AGPL-3.0.

Example prompts

  • “/host-capability-routing”

Requirements

  • A credential in CATALOG_DUPLICATE_KEY

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. intent / routing 已给出最终 workflowIntent;
  2. 任务需要判断 direct / plan_first / auto_authorized,或需要解释当前宿主 variant 的能力上限;
  3. 当前消息、CP artifact 或 managed task source 可以形成 OriginalInstructionRefV1。

What it can do on your machine

Read from SKILL.md and the folder at commit 1dd4525. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CATALOG_DUPLICATE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Host Capability Routing loads about 1.9k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 657 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from devcodex-labs/devcodex at commit 1dd4525, republished under its AGPL-3.0 licence (© devcodex-labs). 657 words, ~1,927 tokens.

Download SKILL.mdSave it as .claude/skills/host-capability-routing/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
host-capability-routing
description
宿主能力路由 Owner — 当已识别工作流意图后,需要在五个逻辑宿主、八个受支持 variant 上选择 direct / plan_first / auto_authorized,核验原始指令 authority,或判断 native lever 是否具备新鲜且安全的直接证据时使用。

Host Capability Routing Skill

定位

本 Skill 是“工作流意图 → 宿主能力决策”的语义编排 Owner。它消费 intent / routing 已完成的工作流意图,输出 CapabilityIntentDecisionV1;它不重新分类工作流、不拥有 CP 状态机、不执行宿主命令,也不创建 Auto 授权。

能力面由中央决策 CSD-host-capability-routing 冻结为 rule-skill。本目录只保存领域契约、variant-aware catalog 和执行规则,不复制中央 CSD 的选择字段。

Phase 1 的唯一可执行路径是 portable-first:

  • direct:不额外进入宿主 native Plan;仍完整执行适用的安全不变量、CP、验证、报告和记忆。
  • plan_first:先形成 DevCodex 计划/CP 产物;不等于已经进入宿主 native Plan。
  • auto_authorized:只消费现有、可回读、仍有效的 Auto 授权证据;宿主 YOLO、permission mode 或“快一点”均不构成授权。

Native lever、MCP Tool/Resource、CLI 和 Hook 接线属于 Phase 2。Phase 1 可以读取 catalog 并解释上限,但不得声称已调用 native lever。

触发边界

在以下条件同时成立时使用:

  1. intent / routing 已给出最终 workflowIntent;
  2. 任务需要判断 direct / plan_first / auto_authorized,或需要解释当前宿主 variant 的能力上限;
  3. 当前消息、CP artifact 或 managed task source 可以形成 OriginalInstructionRefV1。

以下情况不触发或立即退化:

  • 普通闲聊且不进入 DevCodex 工作流;
  • 工作流意图尚未确定:先回 intent;
  • 原始指令 authority 缺失或跨轮仅剩 compat/none:停止当前 mutation,优先回绑任务事实并返回结构化意图重算;仍无法唯一化时才请求重述;
  • catalog 缺失、重复、过期、variant 未知或 matrix identity 不一致:使用 portable fallback,不猜 native;
  • Cursor、chatgpt-plain:标记 unsupported,使用手工全文/普通提示词路径。

Owner 与非职责

能力Owner本 Skill 行为
工作流意图intent / routing只消费,不覆盖
安全不变量instructions.md写入 appliedInvariantIds,不得降级
CP1→CP2→条件 CP3cp-gate保留并引用,不新增状态机
Auto authority当前 Auto 规则与确认回执只验证证据,不创建授权
宿主事实HostLeverCatalogV1 + HostAdapterCompatibilityMatrixV1精确查询、校验 freshness 和 fallback
原始指令 identity现有 host event / Governance Intake / CP / task source只形成 compact ref,不保存完整原文
完成态workflow completion / ECR不以本决策替代完成门禁
native invocationPhase 2 runtime ownerPhase 1 禁止执行

输入

最小输入:

  • instructionRef: OriginalInstructionRefV1
  • workflowIntent: dev | fix | analyze | audit | self-fix | other
  • 当前逻辑宿主和精确 hostSurfaceOrVariant
  • scope、风险、歧义和是否已有有效 Auto authority 的语义判断
  • HostLeverCatalogV1 及其对应 matrix identity

宿主 variant 必须来自当前 HostAdapterCompatibilityMatrixV1。不得新建平行 HOST_IDS 或把 Grok root、plain child、launcher 合并成一个能力声明。

输出

输出一份 CapabilityIntentDecisionV1:

  • 只引用 instructionRefId,不内嵌用户原文;
  • portable decision 固定为 direct / plan_first / auto_authorized;
  • appliedInvariantIds 列出本轮实际适用的不变量;
  • nativeEligibility 只记录精确 catalog key 和证据状态;
  • native 不可用时 fallback.applied=true、target=portable、retryable=false;
  • receipt 只保存 catalog identity,不复制完整 catalog row。

decisionId 是除展示字段 reason 和自身 decisionId 外的 decision core 的稳定 SHA-256。

决策顺序

  1. InstructionAuthorityGate:校验 OriginalInstructionRefV1。confirm、compact、resume 或宿主/session 变化后,优先回绑 digest-bound CP/task artifact。
  2. WorkflowIntentOwnerGate:确认工作流意图来自 intent / routing;本 Skill 不重算。
  3. PortableDecisionGate:
    • scope 清晰、低复杂度且无需额外计划时可选 direct;
    • scope 有歧义、复杂、跨模块、高风险或需要 CP3 时选 plan_first;
    • 只有 autoAuthorityRef 可回读且仍有效时才选 auto_authorized。
  4. InvariantProjectionGate:至少保留 S05;dev/fix/self-fix 还必须保留 CP1、CP2,需要 CP3 时追加 CP3。任何 portable 决策都不能绕过 S01~S07。
  5. ExactVariantCatalogGate:按 hostId + hostSurfaceOrVariant + capabilityFamilyId + leverVersion 唯一查询;0 行或多行均 fail closed。
  6. NativeEligibilityGate:证据、lease、permission、enter/approve/cancel/exit、显式 authority 和 Phase 2 runtime enablement 必须全部通过;否则 portable fallback。
  7. ReceiptGate:写入 bounded receipt;不得把 catalog row、原消息正文或宿主 UI 状态复制成第二事实源。

PortableDecisionGate

条件结果必要证据
scope 明确、风险低、无需额外计划directconfidence=high;适用 CP/安全锚点仍在
scope 歧义、复杂、多模块、高风险、控制面或 CP3plan_firstreasonCode 可复算;禁止 native 猜测
用户提供有效 Auto alias/自然语言授权auto_authorized非空 autoAuthorityRef;证据仍在当前 authority scope
confidence 低或信息不足plan_first 或请求澄清INTENT_CONFIDENCE_LOW

direct 不是“跳过 CP”,plan_first 不是“宿主 Plan 已进入”,auto_authorized 也不是“无需安全确认”。

OriginalInstructionRefGate

Authority 强度从高到低:

  1. digest-bound-cp-artifact 或 managed-task-source;
  2. 可回读 host-event 的 sha256/strong;
  3. governance-intake-anchor 的 fnv1a32-compat/compat;
  4. 当前轮 conversation-visible;
  5. unavailable。

规则:

  • 不持久化完整用户原文;controlledSummary 只是 ≤512 Unicode 字符的 projection。
  • projectionDigest 只证明受控摘要,不证明原始消息。
  • compat/none 不能单独授权跨轮 mutation。
  • source missing/mismatch/unverified 且没有强 CP/task authority 时,stopMutation=true,优先恢复强事实并重算结构化意图;仍无法唯一化时才请求重述。
  • 附件只保存宿主 locator 或内容 digest。
Show full SKILL.md (277 more words)Show less

Catalog 与 native truth ceiling

host-lever-catalog.v1.json 的主分母固定为当前 matrix 的 8 个 in-scope variant;Cursor 和 chatgpt-plain 在 unsupportedSurfaces 单列。

Evidence lease:

kindleasenative eligibility
repo-localsource-boundsource/matrix identity 变化即 stale
official-docsP30D只能证明文档声明,不能替代 direct replay
direct-host-replayP14D还需 permission/lifecycle/authority 全通过
unverifiedP0D永不满足

Phase 1 即使 evidence 为 fresh,也必须因 runtime 未接线而返回 NATIVE_NOT_PHASE1。宿主 UI、生成的 wrapper、plan 文件存在或 permission mode 均不等于 native 已应用。

FailureMatrix

reasonCode行为
INTENT_CONFIDENCE_LOWplan_first 或澄清;不调用 native
HOST_VARIANT_UNKNOWNportable fallback
CATALOG_DUPLICATE_KEY / CATALOG_UNAVAILABLE相关 family fail closed;维持当前工作流
CATALOG_SOURCE_STALE禁用 catalog native 判断并重新生成证据
NATIVE_EVIDENCE_STALE / NATIVE_EVIDENCE_UNVERIFIEDnative disabled
NATIVE_LIFECYCLE_INCOMPLETEnative disabled
NATIVE_PERMISSION_UNSAFEnative disabled
NATIVE_AUTHORITY_MISSING请求显式 authority;不自动调用
NATIVE_NOT_PHASE1正常 portable 路径
AUTO_AUTHORITY_MISSING不允许 auto_authorized
INSTRUCTION_SOURCE_MISSING停止自动 mutation,请求重述
INSTRUCTION_DIGEST_MISMATCH停止当前 mutation,恢复来源并重算结构化意图
INSTRUCTION_AUTHORITY_TOO_WEAK回绑强 CP/task authority
HOST_UNSUPPORTEDmanual/plain fallback
MCP_NOT_REQUIREDPhase 1 继续;不把 MCP 缺失当故障

MCP 边界

Phase 1 不读取或修改 MCP server inventory;MCP 不可用时 portable decision 必须无损。

只有以下条件全部成立,才可在新 CSD 和新 CP 中评估 Tool/Resource:

  1. 至少两个独立 runtime consumer 需要同一有界查询;
  2. 输入已由 Skill 归一化,不接收原始自然语言;
  3. 查询确定、只读、幂等且有 bounded receipt;
  4. 本地 catalog 仍是无损 fallback;
  5. runtime owner、协议、host matrix、迁移和回滚已冻结。

有界内容读取优先评估 Resource/Resource Template;只有参数化计算才评估 Tool。

验证

权威入口:

bash
npm run test:host-capability-routing
npm run test:capability-surface-decision
node scripts/validate.js

最小负向覆盖:

  • schema unknown field;
  • duplicate catalog key;
  • matrix/source identity stale;
  • 8/8 variant 和 2 unsupported coverage;
  • evidence expiry / P0D;
  • lifecycle incomplete;
  • permission unsafe;
  • explicit authority missing;
  • instruction strong/compat/none 与跨轮 mutation;
  • MCP absent;
  • unsupported surface;
  • native false claim=0。

消费者同步

当前消费者只保存 compact ref:

  • intent / routing:触发本 Skill,仍拥有 workflow intent;
  • cp-gate:核验 instruction authority,CP 状态机不变;
  • memory / summary / report / execution-contract:只引用 instructionRefId 与 projection,不复制原文;
  • prompts:使用相同 compact ref 字段;
  • package/portfolio/host projections:分发本 Skill、schemas、catalog;
  • README/website/Profile:说明 portable-first、native ceiling 和 MCP Phase 2 门槛。

Skill 缺失、未注册或 catalog 无效时,所有消费者必须回到既有 DevCodex 工作流,不得猜测 native。

演进与退役

  • 新增 variant、改变 portable decision enum、改变 Auto semantics、保存完整原文、接线 MCP/CLI/Hook/native lever,必须退回 CP2,并由 spec-governance 生成新鲜 CSD。
  • catalog writer 固定为 host-capability-routing/catalog-maintainer;运行消费者只读。
  • 若未来宿主提供统一、可验证且可回滚的 native contract,本 Skill 仍保留 portable fallback。
  • 若能力长期无真实消费者或被更强统一 owner 替代,应先撤消费者与 package entry,再按 S01 单独确认删除。

© devcodex-labs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files in content/skills/host-capability-routing of devcodex-labs/devcodex.

  • SKILL.md
  • capability-intent-decision.v1.schema.json
  • host-lever-catalog.v1.json
  • host-lever-catalog.v1.schema.json
  • intent.json
  • original-instruction-ref.v1.schema.json

Open the folder on GitHubat commit 1dd4525

Compare with similar skills

Host Capability Routing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Host Capability Routing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Host Capability Routing this skilldevcodex-labs/devcodex439—~1.9kAutomated safety check: PassAGPL-3.0
Product Capabilityaffaan-m/ECC274k2 repos~1.1kAutomated safety check: PassMIT
Direction Pickernexu-io/open-design100k—~472Automated safety check: WarnApache-2.0
Frontend Design Directionaffaan-m/ECC274k1 repos~1.1kAutomated safety check: PassMIT
Direction Attributethedaviddias/Front-End-Checklist74k—~534Automated safety check: PassMIT
Artifact Capabilitiesasgeirtj/system_prompts_leaks69k—~4.3kAutomated safety check: PassCC0-1.0

Similar skills

  • Product Capability

    affaan-m/ECC

    Translate PRD intent, roadmap asks, or product discussions into an implementation-ready capability plan that exposes constraints, invariants, interfaces, and unresolved decisions before…

    274k GitHub starsUsed in 2 repos~1.1k tokens
    Product & Project ManagementAuto-check passed
  • Direction Picker

    nexu-io/open-design

    Resolves the visual direction at the plan stage from the brief and design system, without asking the user.

    100k GitHub stars~472 tokensUpdated today
    Frontend & DesignAuto-check: warnings
  • Set an ECC-specific frontend design direction for production UI work.

    274k GitHub starsUsed in 1 repo~1.1k tokens
    Frontend & DesignAuto-check passed
  • Direction Attribute

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing templates, rendered HTML, or shared components related to Set text direction for RTL languages.

    74k GitHub stars~534 tokensUpdated yesterday
    Auto-check passed
  • Artifact Capabilities

    asgeirtj/system_prompts_leaks

    Runtime capabilities a published Artifact page can be granted — behavior static HTML cannot provide on its own, such as the page reading live or connected data, remembering what people do on it (a…

    69k GitHub stars~4.3k tokensUpdated yesterday
    Auto-check passed
  • Product Capability

    affaan-m/ECC

    将PRD意图、路线图需求或产品讨论转化为可实施的方案计划,在开始多服务工作之前暴露约束、不变性、接口和未解决的决策。当用户需要ECC原生的PRD到SRS通道,而不是模糊的规划文本时使用。

    274k GitHub stars~439 tokensUpdated 2 days ago
    Product & Project ManagementAuto-check passed

More from devcodex-labs/devcodex

All 70 skills in this repo
  • Accessibility I18n

    devcodex-labs/devcodex

    无障碍与国际化专家 Owner — 当任务涉及可访问性、键盘操作、焦点、屏幕阅读器、ARIA、语言地区、本地化、RTL、翻译资源、用户可见文案或多语言文档时使用;要求把包容性体验和本地化验证绑定到真实用户路径。

    439 GitHub stars~718 tokensUpdated 20 days ago
    Auto-check passed
  • AI Agent System Architecture

    devcodex-labs/devcodex

    AI Agent 系统架构专家 Owner — 当任务涉及 Agent 路由、工具调用、上下文管理、记忆、状态机、权限、人机协作、可观测性、回放验证或模型辅助治理时使用;要求把 Agent 行为设计成可解释、可恢复、可审计。

    439 GitHub stars~2.4k tokensUpdated 20 days ago
    Auto-check passed
  • API Contract Architecture

    devcodex-labs/devcodex

    API 契约架构专家 Owner — 当任务涉及 public API、HTTP/SDK/CLI 契约、版本兼容、错误模型、分页过滤、幂等、Schema、类型、迁移或消费者影响时使用;要求先冻结消费者契约,再设计实现与验证。

    439 GitHub stars~865 tokensUpdated 20 days ago
    Auto-check passed
  • Architecture Design

    devcodex-labs/devcodex

    架构设计文档编排 Owner — 当用户要求架构设计、系统设计、技术架构或可指导开发、Review 与任务拆分的完整方案时使用;要求从业务流程反推节点、状态、数据、一致性、异常补偿、ADR 与实施任务。

    439 GitHub stars~1.1k tokensUpdated 20 days ago
    Auto-check passed
  • Audit Common

    devcodex-labs/devcodex

    审查公共维度 G0~G5 + Profile Freshness Check — 所有 audit 子类型必先执行的基础维度层

    439 GitHub stars~4.1k tokensUpdated 20 days ago
    Auto-check passed
  • Audit Session

    devcodex-labs/devcodex

    审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复

    439 GitHub stars~1.8k tokensUpdated 20 days ago
    Auto-check passed

Questions about Host Capability Routing

What does Host Capability Routing do?

宿主能力路由 Owner — 当已识别工作流意图后,需要在五个逻辑宿主、八个受支持 variant 上选择 direct / planfirst / autoauthorized,核验原始指令 authority,或判断 native lever 是否具备新鲜且安全的直接证据时使用。. Host Capability Routing is an agent skill from devcodex-labs/devcodex.

How do I install Host Capability Routing in Claude Code?

Run `npx skills add devcodex-labs/devcodex --skill host-capability-routing -a claude-code`. Or copy the skill folder (content/skills/host-capability-routing in devcodex-labs/devcodex) into .claude/skills/host-capability-routing in your project. Claude Code loads it when a task matches its description.

How do I install Host Capability Routing in Codex?

Run `npx skills add devcodex-labs/devcodex --skill host-capability-routing -a codex`. Or copy the skill folder (content/skills/host-capability-routing in devcodex-labs/devcodex) into .agents/skills/host-capability-routing in your project. Codex loads it when a task matches its description.

Can I use Host Capability Routing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add devcodex-labs/devcodex --skill host-capability-routing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/host-capability-routing, .gemini/skills/host-capability-routing, .github/skills/host-capability-routing and .opencode/skills/host-capability-routing in your project.

What does Host Capability Routing need to run?

Going by SKILL.md and its folder, Host Capability Routing needs the command-line tools its instructions call (npm and node) and credentials named CATALOG_DUPLICATE_KEY. Our summary lists: A credential in CATALOG_DUPLICATE_KEY.

Does Host Capability Routing access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Host Capability Routing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Host Capability Routing use?

Host Capability Routing is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Host Capability Routing use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Host Capability Routing?

Skills that share tags, products or a category with Host Capability Routing: Product Capability (affaan-m/ECC, 274k stars), Direction Picker (nexu-io/open-design, 100k stars), Frontend Design Direction (affaan-m/ECC, 274k stars) and Direction Attribute (thedaviddias/Front-End-Checklist, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Host Capability Routing?

devcodex-labs (a GitHub organization) maintains it in devcodex-labs/devcodex, which has 439 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on September 17, 2026.

Source: devcodex-labs/devcodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.