Brainstorming Before Building
jnMetaCode/superpowers-zh
Turns a rough idea into an approved design before any code is written, sorting the request into spike, bounded or architectural and enforcing an approval gate.
Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.
$ npx skills add trailofbits/skills --skill let-fate-decide -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trailofbits/skills let-fate-decide --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/let-fate-decide/skills/let-fate-decide .claude/skills/let-fate-decide && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "let-fate-decide" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/let-fate-decide/skills/let-fate-decide into .claude/skills/let-fate-decide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "let-fate-decide", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trailofbits/skills/tree/main/plugins/let-fate-decide/skills/let-fate-decideType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trailofbits/skills --skill let-fate-decide -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trailofbits/skills let-fate-decide --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/let-fate-decide/skills/let-fate-decide .agents/skills/let-fate-decide && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "let-fate-decide" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/let-fate-decide/skills/let-fate-decide into .agents/skills/let-fate-decide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "let-fate-decide", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill let-fate-decide -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trailofbits/skills let-fate-decide --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/let-fate-decide/skills/let-fate-decide .cursor/skills/let-fate-decide && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "let-fate-decide" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/let-fate-decide/skills/let-fate-decide into .cursor/skills/let-fate-decide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "let-fate-decide", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trailofbits/skills.git --path plugins/let-fate-decide/skills/let-fate-decide--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trailofbits/skills --skill let-fate-decide -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trailofbits/skills let-fate-decide --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/let-fate-decide/skills/let-fate-decide .gemini/skills/let-fate-decide && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "let-fate-decide" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/let-fate-decide/skills/let-fate-decide into .gemini/skills/let-fate-decide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "let-fate-decide", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trailofbits/skills let-fate-decideInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trailofbits/skills --skill let-fate-decide -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/let-fate-decide/skills/let-fate-decide .github/skills/let-fate-decide && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "let-fate-decide" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/let-fate-decide/skills/let-fate-decide into .github/skills/let-fate-decide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "let-fate-decide", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill let-fate-decide -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trailofbits/skills let-fate-decide --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/let-fate-decide/skills/let-fate-decide .opencode/skills/let-fate-decide && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "let-fate-decide" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/let-fate-decide/skills/let-fate-decide into .opencode/skills/let-fate-decide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "let-fate-decide", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
let-fate-decideDraws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.
A bundled script, draw_cards.py, run with uv, draws the default spread of 12 houses, each with one Major Arcana and two Minor Arcana cards, and prints JSON with file paths for every house and card; a content flag includes the text inline. The agent reads those files, interprets the spread with an interpretation guide, optionally translates it through technical context lenses for audit, verification, domain, failure-class or stakeholder views, and applies the result to the task.
It is meant for vague or playful delegation such as let fate decide, whatever, idk or Yu-Gi-Oh references, for redraw requests, and for tie-breaking when the agent would otherwise pick between reasonable approaches arbitrarily. It is not used when instructions are clear, when one approach is obviously correct, when you ask for no tarot, or as the deciding authority for safety-critical work such as security, data integrity, production deployments or incident response.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadGrepGlobFrom allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
Shell commands in SKILL.md call:
uvFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Let Fate Decide loads about 2.5k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 129 tokens; SKILL.md has 1,194 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, Grep, GlobAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 1,194 words, ~2,495 tokens.
.claude/skills/let-fate-decide/SKILL.md (or your agent's skills folder). This skill also uses 104 other files; get the full folder from GitHub.When the path forward is unclear, let the cards speak.
Run the drawing script:
uv run --no-config {baseDir}/scripts/draw_cards.pyThe script outputs JSON for the default 12 Houses of the Zodiac spread:
12 houses, each with 1 Major Arcana card and 2 Minor Arcana cards. Each
house and card includes a file path relative to {baseDir}/
Read each house file and each card's meaning file to understand the draw.
For faster reads, use --content to include house and card text directly
in the JSON:
uv run --no-config {baseDir}/scripts/draw_cards.py --contentInterpret the spread using the guide at {baseDir}/references/INTERPRETATION_GUIDE.md
When the task belongs to a specialized technical workflow, use {baseDir}/references/TECHNICAL_CONTEXT_LENSES.md to translate the reading into an audit, verification, domain, failure-class, or stakeholder lens
Apply the interpretation to the task at hand
This skill may be used inside a security, audit, or correctness pipeline as a creative lens for discovery: choosing which angle to inspect next, breaking analysis paralysis, generating hypotheses, or surfacing blind spots.
It is never sufficient by itself. In security and correctness contexts, the reading must be followed by ordinary engineering evidence: source review, tests, proofs, traces, reproduction steps, exploitability analysis, or other domain-appropriate verification. Do not treat a favorable card as permission to ship, suppress a finding, skip validation, or overrule a concrete risk.
The script uses secrets for cryptographic randomness:
secrets.randbelow() (no modulo bias)The default spread records a conservative unordered-card entropy budget
exceeding 100 bits: roughly log2(C(22,12)) bits from Major Arcana selection,
log2(C(56,24)) bits from Minor Arcana selection (assuming
secrets.randbelow() is cryptographically secure), plus 36 reversal bits. The
exact values are computed and reported in the JSON output under entropy_bits.
The actual ordered assignment of cards to houses contains more entropy.
The default spread is 12 Houses of the Zodiac:
| House | Represents | Question It Answers |
|---|---|---|
| 1 | Self | How should this work begin? |
| 2 | Resources | What values, assets, or constraints matter? |
| 3 | Communication | What needs to be clarified or connected? |
| 4 | Foundations | What context or dependency anchors the task? |
| 5 | Creativity | Where should experimentation or delight shape the work? |
| 6 | Practice | What quality, maintenance, or execution concern matters? |
| 7 | Partnership | Who or what must this integrate with? |
| 8 | Transformation | What risk, shared state, or deep change is present? |
| 9 | Exploration | What principle or broader strategy guides the path? |
| 10 | Calling | What delivery or long-term outcome is being served? |
| 11 | Community | What system, network, or shared aspiration is involved? |
| 12 | The Hidden | What blind spot, ending, or unconscious factor matters? |
Within each house, the Major Arcana card sets the archetypal theme and the two Minor Arcana cards provide practical detail.
For compatibility with older workflows, draw_cards.py --legacy returns the
previous 4-card hand, and draw_cards.py --legacy <count> returns a custom
hand of 1-78 cards. A positional count without --legacy is rejected, because
the new default spread has a fixed shape.
Each house's meaning is in its own markdown file under {baseDir}/houses/.
House files describe how the house applies across technical contexts including
building new projects, vulnerability discovery, correctness verification, and
common audit, verification, domain, failure-class, and stakeholder workflows.
Each card's meaning is in its own markdown file under {baseDir}/cards/:
cards/major/ - 22 Major Arcana (archetypal forces)cards/wands/ - 14 Wands (creativity, action, will)cards/cups/ - 14 Cups (emotion, intuition, relationships)cards/swords/ - 14 Swords (intellect, conflict, truth)cards/pentacles/ - 14 Pentacles (material, practical, craft)After drawing, read each house file and each card file, then synthesize meaning. See {baseDir}/references/INTERPRETATION_GUIDE.md for the full interpretation workflow. For cross-domain translation, see {baseDir}/references/TECHNICAL_CONTEXT_LENSES.md.
Key rules:
--content so all 36 card
meanings and all 12 house meanings are available from the draw output.A real reading synthesizes all 12 houses; the fragment below shows only what one house contributes so the format is clear. Do not stop after one house in actual use.
User: "I dunno, just make it work somehow"
[Draw cards]
1st House (Self): The Magician (upright), Five of Swords (reversed),
Ten of Pentacles (upright)
House contribution: The starting stance is resourceful and tool-rich
(Magician), but the practical details warn against combative edge-case work
(Five of Swords reversed) while still favoring maintainable craft
(Ten of Pentacles). This is one input into the overall reading; combine with
the remaining 11 houses before deciding on an approach.The named draw agent returns a more compact form for portent questions:
3 concise bullets covering the dominant theme, the main risk or blind spot,
and the recommended next action.
If the drawing script fails:
| Rationalization | Why Wrong |
|---|---|
| "The cards said to, so I must" | Cards inform direction, they don't override safety or correctness |
| "This reading justifies my pre-existing preference" | Be honest if the reading challenges your instinct |
| "The reversed card means do nothing" | Reversed means a different angle, not inaction |
| "Major Arcana overrides user requirements" | User requirements always take priority over card readings |
| "I'll keep drawing until I get what I want" | One draw per decision point; accept the reading |
| "The reading says the risk is fine" | Cards can suggest what to inspect; only evidence can dismiss a security or correctness concern |
© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 104 other files (scripts, references, assets) in plugins/let-fate-decide/skills/let-fate-decide of trailofbits/skills.
Open the folder on GitHubat commit 82fe822
Let Fate Decide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Let Fate Decide this skilltrailofbits/skills | 7.4k | — | ~2.5k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Brainstorming Before BuildingjnMetaCode/superpowers-zh | 8.3k | — | ~1.8k | Automated safety check: Pass | MIT | |
| LLM Councilgcpdev/llm-council-skill | 461 | — | ~1k | Automated safety check: Notes | MIT | |
| CE BrainstormEveryInc/compound-engineering-plugin | 25k | — | ~1.9k | Automated safety check: Pass | MIT | |
| Deep Discoveryforsonny/deep-discovery | 103 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Planmhmzdev/the-holy-quran-app | 889 | — | ~957 | Automated safety check: Pass | MIT |
jnMetaCode/superpowers-zh
Turns a rough idea into an approved design before any code is written, sorting the request into spike, bounded or architectural and enforcing an approval gate.
gcpdev/llm-council-skill
Multi-LLM collaborative brainstorming and planning. An agent skill from gcpdev/llm-council-skill.
EveryInc/compound-engineering-plugin
Turns a vague or ambitious feature idea into a requirements-only plan through dialogue with you, sized to the work, before any code is written.
forsonny/deep-discovery
Runs a 100-question self-interrogation of a design, plan, strategy or idea, each question building on the last, to expose weaknesses before you commit.
mhmzdev/the-holy-quran-app
Turn an idea or brainstorm into an actionable execution plan for The Holy Qur'an app with phases, file changes, and machine-checkable success criteria.
xwtro0tk1t-cloud/harness
Dispatch an independent challenger agent to adversarially review a spec or implementation plan against the actual codebase.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
trailofbits/skills
Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.
trailofbits/skills
Picks a small, graph-based slice of source with Trailmark and hands a focused code task to a smaller or local model without exposing the whole repository.
Categories
Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step. py, run with uv, draws the default spread of 12 houses, each with one Major Arcana and two Minor Arcana cards, and prints JSON with file paths for every house and card; a content flag includes the text inline. The agent reads those files, interprets the spread with an interpretation guide, optionally translates it through technical context lenses for audit, verification, domain, failure-class or stakeholder views, and applies the result to the task.
Let Fate Decide fits situations like: breaking a tie between several reasonable implementation approaches; handling a vague request the user casually delegated; drawing again when the user asks to try again with no system changes.
Run `npx skills add trailofbits/skills --skill let-fate-decide -a claude-code`. Or copy the skill folder (plugins/let-fate-decide/skills/let-fate-decide in trailofbits/skills) into .claude/skills/let-fate-decide in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trailofbits/skills --skill let-fate-decide -a codex`. Or copy the skill folder (plugins/let-fate-decide/skills/let-fate-decide in trailofbits/skills) into .agents/skills/let-fate-decide in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill let-fate-decide -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/let-fate-decide, .gemini/skills/let-fate-decide, .github/skills/let-fate-decide and .opencode/skills/let-fate-decide in your project.
Going by SKILL.md and its folder, Let Fate Decide needs the command-line tools its instructions call (uv). Our summary lists: uv to run draw_cards.py. Its frontmatter pre-approves these tools: Bash, Read, Grep, Glob.
SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Let Fate Decide is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Let Fate Decide: Brainstorming Before Building (jnMetaCode/superpowers-zh, 8.3k stars), LLM Council (gcpdev/llm-council-skill, 461 stars), CE Brainstorm (EveryInc/compound-engineering-plugin, 25k stars) and Deep Discovery (forsonny/deep-discovery, 103 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,440 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.
Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.