Agent skill

Run Workflow

by oocx in oocx/tfplan2md

Drive a work item through the workflow in auto mode - resolve the next stage, run it, advance state, and stop only at gates.

MITAuto-check passedDevOps & Cloud

Install Run Workflow

skills CLI
$ npx skills add oocx/tfplan2md --skill run-workflow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install oocx/tfplan2md run-workflow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/oocx/tfplan2md.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/run-workflow .claude/skills/run-workflow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
run-workflow
GitHub stars
174
Token cost
~1.4k tokens
SKILL.md length
725 words
Files
1
Skills in repo
28
Repo updated
First seen
Licence
MIT

At a glance

Drive a work item through the workflow in auto mode - resolve the next stage, run it, advance state, and stop only at gates.

  • DevOps & Cloud work in your project
  • SKILL.md covers The loop, Running a stage, Starting a new work item and Gates, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Run Workflow is an agent skill from oocx/tfplan2md. Drive a work item through the workflow in auto mode - resolve the next stage, run it, advance state, and stop only at gates.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. The repository describes itself as: Convert terraform plans (json) into human readable markdown for easier review of changes in pull requests. The licence is MIT.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/run-workflow”

What it can do on your machine

Read from SKILL.md and the folder at commit 3fa4b5a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Run Workflow loads about 1.4k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 725 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from oocx/tfplan2md at commit 3fa4b5a, republished under its MIT licence (© oocx). 725 words, ~1,356 tokens.

Download SKILL.mdSave it as .claude/skills/run-workflow/SKILL.md (or your agent's skills folder).
name
run-workflow
description
Drive a work item through the workflow in auto mode - resolve the next stage, run it, advance state, and stop only at gates.

Run Workflow

The driver. Runs a work item from its current stage to completion, stopping only at the three gates. Read docs/workflow.md for the stages and gate rules, and the agent-runtime skill for how roles operate.

The loop

bash
scripts/workflow-next.sh          # what runs next, and with which model
# ... run that stage; the role appends its own work-protocol entry ...
scripts/workflow-next.sh          # repeat

You do not call wp-append.sh --role. The role that ran the stage appends its own entry before returning, and that append is what advances the stage. A second append from the driver would advance past whichever role is now current, silently skipping it. wp-append.sh refuses a --role that does not match the current stage, so a duplicate call fails loudly rather than corrupting the run — but the rule is that completion has exactly one owner.

The driver does use wp-append.sh for --gate and --rework, which are its own decisions rather than a role's.

workflow-next.sh derives everything from the branch name and state.json. Note that it is not purely a query: it advances past a skipped UAT stage and records that UAT is required, so calling it is part of driving the run rather than inspecting it. Use scripts/workflow-gate.sh status when you only want to look. It costs almost nothing and needs no memory of previous turns, so a session that compacted or died resumes by calling it again.

Exit codes: 0 a stage is ready, 2 blocked at a gate.

Running a stage

Spawn the role as a subagent with the model workflow-next.sh reports — that isolation is why this workflow is affordable. Give it:

Act as the <Role> role. Read .agents/roles/<stage>.md and the agent-runtime skill, then do your stage for the work item in <work-item-dir>.

Do not paste the role file into the prompt; the subagent reads it. Do not add your own instructions about how to do the role's job — if they were needed, they belong in the role file.

One exception: the code-reviewer stage runs in Codex, not as a subagent:

bash
scripts/codex-review.sh <work-item-dir>

Its exit code decides what happens next, and it advances the stage itself:

ExitMeaningWhat you do
0APPROVEDContinue the loop
1REWORKContinue the loop — it has already routed back to the Developer
2codex unavailable or failed twiceSpawn the Code Reviewer subagent instead, and pass --problems "reviewer: claude-fallback" on its work-protocol entry so the retrospective can see the review was single-family

Exit 2 is not a rework signal. Treating it as one sends the Developer back for a review that never happened.

Show full SKILL.md (327 more words)Show less

Starting a new work item

The entry role creates the branch, the folder, work-protocol.md and state.json:

RequestEntry roleBranch
New featureRequirements Engineerfeature/NNN-<slug>
BugIssue Analystfix/NNN-<slug>
Workflow changeWorkflow Engineerworkflow/NNN-<slug>
Website changeWeb Designerwebsite/NNN-<slug>

Reserve NNN with the next-issue-number skill. Do not ask which role to start with — determine it from the request and delegate; the entry role asks the clarifying questions, because that is its job and not yours.

Gates

When workflow-next.sh exits 2, stop and put the question to the Maintainer, along with any open_questions accumulated since the last gate. Then record the answer:

bash
scripts/wp-append.sh --gate spec --decision approved

arch is only pending when the Architect wrote contested into it. uat is skipped automatically when the diff does not touch user-visible output — the driver reports the skip and moves on.

Rework

The code reviewer routes its own rework. codex-review.sh calls --rework itself before exiting 1, so do not call it again — a second call counts the same rejection twice and can block the run after two failed reviews instead of three.

For a UAT failure, use the gate; for a build failure, call rework yourself:

bash
scripts/wp-append.sh --gate uat --decision rejected      # UAT failed
scripts/wp-append.sh --rework release-manager --reason "PR validation failed"

Both route back to the Developer and increment attempts, which escalates the model one tier. Escalating forever is not a strategy: after three attempts at the same stage, stop and involve the Maintainer. Repeated failure at one stage is usually a specification problem wearing an implementation costume.

Before release

bash
scripts/workflow-gate.sh all

Non-zero means a required role never logged its work, and the release does not proceed.

What not to do

  • Do not do a role's work yourself. If the Developer's stage is next, spawn the Developer — writing the code yourself defeats the isolation the workflow is built on.
  • Do not skip a stage because it seems unnecessary. The work-protocol gate will refuse the release, and you will have lost the intervening work.
  • Do not block on a question away from a gate. Record it with an assumption (wp-append.sh --question ... --assumed ...) and continue.

© oocx, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/run-workflow of oocx/tfplan2md.

Open the folder on GitHubat commit 3fa4b5a

Compare with similar skills

Run Workflow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Run Workflow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Run Workflow this skilloocx/tfplan2md174—~1.4kAutomated safety check: PassMIT
Monitor CInrwl/nx29k5 repos~4.7kAutomated safety check: PassMIT
Repo Hygiene Scan and FixQwenLM/qwen-code28k—~1.7kAutomated safety check: PassApache-2.0
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
Bash Defensive Patternspromovaweb/setupvibe10113 repos~572Automated safety check: PassGPL-3.0
Author Migrationnrwl/nx29k—~12kAutomated safety check: NotesMIT

Similar skills

  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 5 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.

    28k GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Bash Defensive Patterns

    promovaweb/setupvibe

    Master defensive Bash programming techniques for production-grade scripts.

    101 GitHub starsUsed in 13 repos~572 tokens
    DevOps & CloudAuto-check passed
  • Author or scope a first-party Nx migration. An agent skill from nrwl/nx.

    29k GitHub stars~12k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.

    5.1k GitHub stars~1.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from oocx/tfplan2md

All 28 skills in this repo
  • Create Agent Skill

    oocx/tfplan2md

    Create a new Agent Skill following project standards and templates.

    174 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Detect and analyze edge crossings and overlaps in SVG workflow diagrams using geometric intersection algorithms and visual analysis.

    174 GitHub stars~4.3k tokensUpdated yesterday
    Auto-check passed
  • Generate PNG screenshots for release notes using the repository's HtmlRenderer and ScreenshotGenerator tools.

    174 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Git Rebase Main

    oocx/tfplan2md

    Safely rebase the current feature branch on top of the latest origin/main.

    174 GitHub stars~456 tokensUpdated yesterday
    Auto-check passed
  • Next Issue Number

    oocx/tfplan2md

    Determine the next available issue number across all change types (feature, fix, workflow, website) by checking both local docs and remote branches, then reserve it by pushing an empty branch.

    174 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Run Uat

    oocx/tfplan2md

    Run User Acceptance Testing by creating a PR with rendered markdown on GitHub or Azure DevOps.

    174 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Questions about Run Workflow

What does Run Workflow do?

Drive a work item through the workflow in auto mode - resolve the next stage, run it, advance state, and stop only at gates. Run Workflow is an agent skill from oocx/tfplan2md. Drive a work item through the workflow in auto mode - resolve the next stage, run it, advance state, and stop only at gates.

When should I use Run Workflow?

Run Workflow fits situations like: devOps & Cloud work in your project.

How do I install Run Workflow in Claude Code?

Run `npx skills add oocx/tfplan2md --skill run-workflow -a claude-code`. Or copy the skill folder (.agents/skills/run-workflow in oocx/tfplan2md) into .claude/skills/run-workflow in your project. Claude Code loads it when a task matches its description.

How do I install Run Workflow in Codex?

Run `npx skills add oocx/tfplan2md --skill run-workflow -a codex`. Or copy the skill folder (.agents/skills/run-workflow in oocx/tfplan2md) into .agents/skills/run-workflow in your project. Codex loads it when a task matches its description.

Can I use Run Workflow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add oocx/tfplan2md --skill run-workflow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/run-workflow, .gemini/skills/run-workflow, .github/skills/run-workflow and .opencode/skills/run-workflow in your project.

What does Run Workflow need to run?

SKILL.md names no scripts, command-line tools or credentials: Run Workflow is instructions for the agent only.

Does Run Workflow access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Run Workflow safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Run Workflow use?

Run Workflow is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Run Workflow use?

About 1.4k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Run Workflow?

Skills that share tags, products or a category with Run Workflow: Monitor CI (nrwl/nx, 29k stars), Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars) and Bash Defensive Patterns (promovaweb/setupvibe, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Run Workflow?

oocx (a GitHub user) maintains it in oocx/tfplan2md, which has 174 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 6, 2026.

Source: oocx/tfplan2md on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.