Official agent skill

Let Fate Decide

by trailofbits in trailofbits/skills

Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

OfficialCC-BY-SA-4.0Auto-check: notesAgent Workflows

Install Let Fate Decide

skills CLI
$ npx skills add trailofbits/skills --skill let-fate-decide -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills let-fate-decide --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/let-fate-decide/skills/let-fate-decide .claude/skills/let-fate-decide && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
let-fate-decide
GitHub stars
7.4k
Token cost
~2.5k tokens
SKILL.md length
1,194 words
Files
105 (incl. scripts, references, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

  • Works in 6 steps: Run the drawing script → The script outputs JSON for the default… → Read each house file and each card's… → …
  • Breaking a tie between several reasonable implementation approaches
  • SKILL.md covers Quick Start, When to Use, When NOT to Use and Security and Correctness Use, plus 4 more sections
  • Calls uv

What it does

A bundled script, draw_cards.py, run with uv, draws the default spread of 12 houses, each with one Major Arcana and two Minor Arcana cards, and prints JSON with file paths for every house and card; a content flag includes the text inline. The agent reads those files, interprets the spread with an interpretation guide, optionally translates it through technical context lenses for audit, verification, domain, failure-class or stakeholder views, and applies the result to the task.

It is meant for vague or playful delegation such as let fate decide, whatever, idk or Yu-Gi-Oh references, for redraw requests, and for tie-breaking when the agent would otherwise pick between reasonable approaches arbitrarily. It is not used when instructions are clear, when one approach is obviously correct, when you ask for no tarot, or as the deciding authority for safety-critical work such as security, data integrity, production deployments or incident response.

When your agent uses it

  • Breaking a tie between several reasonable implementation approaches
  • Handling a vague request the user casually delegated
  • Drawing again when the user asks to try again with no system changes

Example prompts

  • “Let fate decide how we structure the settings page.”
  • “idk, whatever works for the caching approach; your call.”
  • “Draw again and see if the cards suggest a different path.”

Requirements

  • uv to run draw_cards.py
  • Pre-approved tools (allowed-tools): Bash, Read, Grep, Glob

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Run the drawing script
  2. The script outputs JSON for the default 12 Houses of the Zodiac spread
  3. Read each house file and each card's meaning file to understand the draw.
  4. Interpret the spread using the guide at {baseDir}/references/INTERPRETATION_GUIDE.md
  5. When the task belongs to a specialized technical workflow, use
  6. Apply the interpretation to the task at hand

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Let Fate Decide loads about 2.5k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 129 tokens; SKILL.md has 1,194 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Grep, Glob

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 1,194 words, ~2,495 tokens.

Download SKILL.mdSave it as .claude/skills/let-fate-decide/SKILL.md (or your agent's skills folder). This skill also uses 104 other files; get the full folder from GitHub.
name
let-fate-decide
description
Draws the 12 Houses of the Zodiac Tarot spread to inject entropy into planning when prompts are vague, ambiguous, or casually delegated. Interprets the spread to guide next steps. Use when the user says 'let fate decide', 'YOLO', 'whatever', 'idk', or other nonchalant phrases, makes Yu-Gi-Oh references, or when you are about to arbitrarily pick between multiple reasonable approaches. Prefer over asking clarifying questions when the user's tone is casual or playful rather than precision-seeking.
allowed-tools
Bash, Read, Grep, Glob

Let Fate Decide

When the path forward is unclear, let the cards speak.

Quick Start

  1. Run the drawing script:

    bash
    uv run --no-config {baseDir}/scripts/draw_cards.py
  2. The script outputs JSON for the default 12 Houses of the Zodiac spread: 12 houses, each with 1 Major Arcana card and 2 Minor Arcana cards. Each house and card includes a file path relative to {baseDir}/

  3. Read each house file and each card's meaning file to understand the draw. For faster reads, use --content to include house and card text directly in the JSON:

    bash
    uv run --no-config {baseDir}/scripts/draw_cards.py --content
  4. Interpret the spread using the guide at {baseDir}/references/INTERPRETATION_GUIDE.md

  5. When the task belongs to a specialized technical workflow, use {baseDir}/references/TECHNICAL_CONTEXT_LENSES.md to translate the reading into an audit, verification, domain, failure-class, or stakeholder lens

  6. Apply the interpretation to the task at hand

When to Use

  • Vague prompts: The user's request is ambiguous and multiple reasonable approaches exist
  • Explicit invocations: "I'm feeling lucky", "let fate decide", "dealer's choice", "surprise me", "whatever you think", "YOLO"
  • Casual delegation: "whatever", "up to you", "your call", "idk", "just do something", "wing it", "I trust you", "doesn't matter", "do what you want", "I don't care", "any approach works", "you pick"
  • Yu-Gi-Oh energy: "Heart of the cards", "I believe in the heart of the cards", "you've activated my trap card", "it's time to duel"
  • Shrug-like brevity: Very short prompts that fully delegate the decision without expressing a preference
  • Redraw requests: "Try again" or "draw again" when no actual system changes occurred (this means draw new cards, not re-run the same approach)
  • Tie-breaking: When you are about to arbitrarily pick between 2+ valid approaches, draw cards instead of silently choosing one

When NOT to Use

  • The user has given clear, specific instructions
  • The task has a single obvious correct approach
  • As the deciding authority for safety-critical work (security, data integrity, production deployments, release approval, incident response)
  • The user explicitly asks you NOT to use Tarot
  • The user's tone is precision-seeking rather than casual -- ask clarifying questions instead to gather actual requirements

Security and Correctness Use

This skill may be used inside a security, audit, or correctness pipeline as a creative lens for discovery: choosing which angle to inspect next, breaking analysis paralysis, generating hypotheses, or surfacing blind spots.

It is never sufficient by itself. In security and correctness contexts, the reading must be followed by ordinary engineering evidence: source review, tests, proofs, traces, reproduction steps, exploitability analysis, or other domain-appropriate verification. Do not treat a favorable card as permission to ship, suppress a finding, skip validation, or overrule a concrete risk.

How It Works

The Draw

The script uses secrets for cryptographic randomness:

  1. Builds separate Major Arcana (22 cards) and Minor Arcana (56 cards) decks
  2. Performs Fisher-Yates shuffles via secrets.randbelow() (no modulo bias)
  3. Deals the default 12 Houses of the Zodiac spread
  4. Each house receives 1 Major Arcana card followed by 2 Minor Arcana cards
  5. Each of the 36 cards independently has a 50% chance of being reversed

The default spread records a conservative unordered-card entropy budget exceeding 100 bits: roughly log2(C(22,12)) bits from Major Arcana selection, log2(C(56,24)) bits from Minor Arcana selection (assuming secrets.randbelow() is cryptographically secure), plus 36 reversal bits. The exact values are computed and reported in the JSON output under entropy_bits. The actual ordered assignment of cards to houses contains more entropy.

The Spread

The default spread is 12 Houses of the Zodiac:

HouseRepresentsQuestion It Answers
1SelfHow should this work begin?
2ResourcesWhat values, assets, or constraints matter?
3CommunicationWhat needs to be clarified or connected?
4FoundationsWhat context or dependency anchors the task?
5CreativityWhere should experimentation or delight shape the work?
6PracticeWhat quality, maintenance, or execution concern matters?
7PartnershipWho or what must this integrate with?
8TransformationWhat risk, shared state, or deep change is present?
9ExplorationWhat principle or broader strategy guides the path?
10CallingWhat delivery or long-term outcome is being served?
11CommunityWhat system, network, or shared aspiration is involved?
12The HiddenWhat blind spot, ending, or unconscious factor matters?

Within each house, the Major Arcana card sets the archetypal theme and the two Minor Arcana cards provide practical detail.

For compatibility with older workflows, draw_cards.py --legacy returns the previous 4-card hand, and draw_cards.py --legacy <count> returns a custom hand of 1-78 cards. A positional count without --legacy is rejected, because the new default spread has a fixed shape.

Show full SKILL.md (455 more words)Show less
Reference Files

Each house's meaning is in its own markdown file under {baseDir}/houses/. House files describe how the house applies across technical contexts including building new projects, vulnerability discovery, correctness verification, and common audit, verification, domain, failure-class, and stakeholder workflows.

Each card's meaning is in its own markdown file under {baseDir}/cards/:

  • cards/major/ - 22 Major Arcana (archetypal forces)
  • cards/wands/ - 14 Wands (creativity, action, will)
  • cards/cups/ - 14 Cups (emotion, intuition, relationships)
  • cards/swords/ - 14 Swords (intellect, conflict, truth)
  • cards/pentacles/ - 14 Pentacles (material, practical, craft)
Interpretation

After drawing, read each house file and each card file, then synthesize meaning. See {baseDir}/references/INTERPRETATION_GUIDE.md for the full interpretation workflow. For cross-domain translation, see {baseDir}/references/TECHNICAL_CONTEXT_LENSES.md.

Key rules:

  • Reversed cards invert or complicate the upright meaning
  • Major Arcana cards carry more weight than Minor Arcana
  • The spread tells a story across all 12 houses; don't interpret cards in isolation
  • Map abstract meanings to concrete technical decisions
  • In security, audit, and correctness work, use the reading to choose an investigation path, then require evidence before accepting or dismissing any risk
  • Never output interpretation as a text-only turn. Include the interpretation alongside your next tool call (the action that implements the chosen option). Prefer --content so all 36 card meanings and all 12 house meanings are available from the draw output.

Example Session (House-Level Fragment)

A real reading synthesizes all 12 houses; the fragment below shows only what one house contributes so the format is clear. Do not stop after one house in actual use.

User: "I dunno, just make it work somehow"

[Draw cards]
1st House (Self): The Magician (upright), Five of Swords (reversed),
                  Ten of Pentacles (upright)

House contribution: The starting stance is resourceful and tool-rich
(Magician), but the practical details warn against combative edge-case work
(Five of Swords reversed) while still favoring maintainable craft
(Ten of Pentacles). This is one input into the overall reading; combine with
the remaining 11 houses before deciding on an approach.

The named draw agent returns a more compact form for portent questions: 3 concise bullets covering the dominant theme, the main risk or blind spot, and the recommended next action.

Error Handling

If the drawing script fails:

  • Script crashes with traceback: Report the error to the user and skip the reading. Do not invent cards or simulate a draw — the whole point is real entropy.
  • Card file not found: Note the missing file, interpret the card from its name and suit alone, and continue with the reading.
  • Never fake entropy: If the script cannot run, do not simulate a draw using your own "randomness." Tell the user the draw failed.

Rationalizations to Reject

RationalizationWhy Wrong
"The cards said to, so I must"Cards inform direction, they don't override safety or correctness
"This reading justifies my pre-existing preference"Be honest if the reading challenges your instinct
"The reversed card means do nothing"Reversed means a different angle, not inaction
"Major Arcana overrides user requirements"User requirements always take priority over card readings
"I'll keep drawing until I get what I want"One draw per decision point; accept the reading
"The reading says the risk is fine"Cards can suggest what to inspect; only evidence can dismiss a security or correctness concern

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 104 other files (scripts, references, assets) in plugins/let-fate-decide/skills/let-fate-decide of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • cards/cups/ace-of-cups.md
  • cards/cups/eight-of-cups.md
  • cards/cups/five-of-cups.md
  • cards/cups/four-of-cups.md
  • cards/cups/king-of-cups.md
  • cards/cups/knight-of-cups.md
  • cards/cups/nine-of-cups.md
  • cards/cups/page-of-cups.md
  • cards/cups/queen-of-cups.md
  • cards/cups/seven-of-cups.md
  • cards/cups/six-of-cups.md
  • cards/cups/ten-of-cups.md
  • cards/cups/three-of-cups.md
  • cards/cups/two-of-cups.md
  • … and 88 more

Open the folder on GitHubat commit 82fe822

Compare with similar skills

Let Fate Decide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Let Fate Decide compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Let Fate Decide this skilltrailofbits/skills7.4k—~2.5kAutomated safety check: NotesCC-BY-SA-4.0
Brainstorming Before BuildingjnMetaCode/superpowers-zh8.3k—~1.8kAutomated safety check: PassMIT
LLM Councilgcpdev/llm-council-skill461—~1kAutomated safety check: NotesMIT
CE BrainstormEveryInc/compound-engineering-plugin25k—~1.9kAutomated safety check: PassMIT
Deep Discoveryforsonny/deep-discovery103—~1.7kAutomated safety check: PassMIT
Planmhmzdev/the-holy-quran-app889—~957Automated safety check: PassMIT

Similar skills

  • Brainstorming Before Building

    jnMetaCode/superpowers-zh

    Turns a rough idea into an approved design before any code is written, sorting the request into spike, bounded or architectural and enforcing an approval gate.

    8.3k GitHub stars~1.8k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • LLM Council

    gcpdev/llm-council-skill

    Multi-LLM collaborative brainstorming and planning. An agent skill from gcpdev/llm-council-skill.

    461 GitHub stars~1k tokensUpdated 9 mo ago
    Agent WorkflowsAuto-check: notes
  • CE Brainstorm

    EveryInc/compound-engineering-plugin

    Turns a vague or ambitious feature idea into a requirements-only plan through dialogue with you, sized to the work, before any code is written.

    25k GitHub stars~1.9k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Deep Discovery

    forsonny/deep-discovery

    Runs a 100-question self-interrogation of a design, plan, strategy or idea, each question building on the last, to expose weaknesses before you commit.

    103 GitHub stars~1.7k tokensUpdated 5 mo ago
    Agent WorkflowsAuto-check passed
  • Plan

    mhmzdev/the-holy-quran-app

    Turn an idea or brainstorm into an actionable execution plan for The Holy Qur'an app with phases, file changes, and machine-checkable success criteria.

    889 GitHub stars~957 tokensUpdated 29 days ago
    Agent WorkflowsAuto-check passed
  • Design Review

    xwtro0tk1t-cloud/harness

    Dispatch an independent challenger agent to adversarially review a spec or implementation plan against the actual codebase.

    265 GitHub stars~1.6k tokensUpdated 5 mo ago
    Agent WorkflowsAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated yesterday
    Auto-check: notes
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check: notes
  • Code Context Slicing

    trailofbits/skills

    Official

    Picks a small, graph-based slice of source with Trailmark and hands a focused code task to a smaller or local model without exposing the whole repository.

    7.4k GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Let Fate Decide

What does Let Fate Decide do?

Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step. py, run with uv, draws the default spread of 12 houses, each with one Major Arcana and two Minor Arcana cards, and prints JSON with file paths for every house and card; a content flag includes the text inline. The agent reads those files, interprets the spread with an interpretation guide, optionally translates it through technical context lenses for audit, verification, domain, failure-class or stakeholder views, and applies the result to the task.

When should I use Let Fate Decide?

Let Fate Decide fits situations like: breaking a tie between several reasonable implementation approaches; handling a vague request the user casually delegated; drawing again when the user asks to try again with no system changes.

How do I install Let Fate Decide in Claude Code?

Run `npx skills add trailofbits/skills --skill let-fate-decide -a claude-code`. Or copy the skill folder (plugins/let-fate-decide/skills/let-fate-decide in trailofbits/skills) into .claude/skills/let-fate-decide in your project. Claude Code loads it when a task matches its description.

How do I install Let Fate Decide in Codex?

Run `npx skills add trailofbits/skills --skill let-fate-decide -a codex`. Or copy the skill folder (plugins/let-fate-decide/skills/let-fate-decide in trailofbits/skills) into .agents/skills/let-fate-decide in your project. Codex loads it when a task matches its description.

Can I use Let Fate Decide in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill let-fate-decide -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/let-fate-decide, .gemini/skills/let-fate-decide, .github/skills/let-fate-decide and .opencode/skills/let-fate-decide in your project.

What does Let Fate Decide need to run?

Going by SKILL.md and its folder, Let Fate Decide needs the command-line tools its instructions call (uv). Our summary lists: uv to run draw_cards.py. Its frontmatter pre-approves these tools: Bash, Read, Grep, Glob.

Does Let Fate Decide access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Let Fate Decide safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Let Fate Decide use?

Let Fate Decide is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Let Fate Decide use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3k tokens, read only when the agent opens those files.

What are the alternatives to Let Fate Decide?

Skills that share tags, products or a category with Let Fate Decide: Brainstorming Before Building (jnMetaCode/superpowers-zh, 8.3k stars), LLM Council (gcpdev/llm-council-skill, 461 stars), CE Brainstorm (EveryInc/compound-engineering-plugin, 25k stars) and Deep Discovery (forsonny/deep-discovery, 103 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Let Fate Decide?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,440 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.