Install
openclaw skills install @englandtong/agent-loop-engineeringRun isolated, low-context autonomous coding loops
openclaw skills install @englandtong/agent-loop-engineeringVersion: 2.2.0
Use this skill as the execution plane for authorized software work. Continue by default while useful progress remains inside scope. Make ordinary reversible project-local decisions, diagnose failures, repair them, and verify real behavior without asking the Owner to supervise each loop.
Respond in the user's language. Keep persistent state factual, compact, and free of hidden reasoning.
{baseDir}/references/en/.{baseDir}/SKILL.zh-CN.md and load only needed files from {baseDir}/references/zh-CN/.Execution requires:
Prefer Docs/ACTIVE_PACKET.md with contract_version: "2.0" and the 2.1 policy fields. If no packet exists, use cms-project-governance Legacy Bootstrap or run:
node {baseDir}/scripts/bootstrap-active-packet.mjs --workspace <project-path> --json
The bootstrap is read-only unless --write is supplied. Write only when its report is coherent and conflict-free. If current target, Work Order, decision, or authority is ambiguous, stop as Invalid State; do not guess.
Read {baseDir}/references/en/migration.md for legacy projects.
Treat user wording such as QC in a single-agent Controller-Developer-QC cycle as Stage Reviewer, not independent final QA.
Resolve the packet workspace and all candidate write paths to real paths. With write_scope: "." and outside_write_policy: Deny, do not create, modify, move, or delete anything outside the workspace, including through symlinks or junctions. Project rules may narrow this further.
Keep contract_version: "2.0" for compatibility. New packets add:
autonomy_mode: "Bounded"
acceptance_mode: "Layered"
delivery_class: "Runtime"
context_profile: "Compact"
write_scope: "."
outside_write_policy: "Deny"
authority_fingerprint: "sha256:..."
agent_strategy: "Isolated"
max_parallel_agents: 3
context_return_policy: "SummaryAndEvidence"
shared_authority_mode: "FingerprintAndExcerpt"
single_writer: true
Allowed delivery classes are Runtime, Contract, Governance, Artifact, and Mixed. A Contract or Governance delivery must not be reported as a working runtime feature. For Mixed, label each acceptance criterion with its class.
Layered means the same execution agent may perform stage review and repair, but new Standard and Full work must end at Ready for Independent Acceptance. Ready for Review remains a legacy-compatible input only. Only a different agent, task, or human reviewer using task-local evidence may set final QA acceptance.
Read {baseDir}/references/en/evidence-and-completion.md.
For autonomy_mode: Bounded, run this state machine:
Controller stage dispatch
-> Developer implementation and focused verification
-> Stage Reviewer checks criteria, diff, and raw evidence
-> pass: align and continue the next authorized stage
-> fail: Needs Fix on the same Packet and Work Order
-> Developer repair and re-verification
-> terminal stage: Ready for Independent Acceptance
Do not ask the Owner about ordinary reversible implementation choices. Choose the conservative project-consistent default and record material assumptions. Ask only when the decision changes target, Non-Goals, protected architecture/data, production behavior, cost, credentials, destructive effects, or acceptance authority.
After a failed check:
Stop after two consecutive attempts with the same failure signature and no new evidence, narrower scope, root cause, or passing behavior. Re-running the same command unchanged is not progress.
If the loop has not produced observable forward progress for three working sessions on the same Work Order, do not keep re-planning and do not restart the project. Cut the Work Order down to the smallest still-publishable increment, get it to Ready for Independent Acceptance, and hand the remainder back as a new proposal. Restarting a project to escape a stall is a failure mode, not a strategy; the usual cause is scope, not the codebase.
Keep wall-clock budgets out of deterministic code paths. In algorithms that must be reproducible (generators, solvers, seeded layouts, snapshot tests), bound work with deterministic counters such as MAX_TRIES, and keep any time budget in an outer wrapper only. Mixing BUDGET_MS into a deterministic path makes the same seed produce different results across runs and produces flaky evidence. If a first-run computation blocks the main thread or the first interaction, move it off the synchronous path before claiming the flow works.
Read {baseDir}/references/en/execution-loop.md.
Authorize at most ten stages:
| Size | Stage ceiling | Review horizon |
|---|---|---|
| Small | 30 minutes | 5 hours |
| Medium | 60 minutes | 10 hours |
| Large | 120 minutes | 20 hours |
A stage is an outcome checkpoint, not a document. Run a lightweight target-link check at every stage. Run formal alignment after stages 3, 6, and 10, and immediately when:
At stage 10, return Ready for Independent Acceptance, Needs Fix, Blocked, Invalid State, or a split/rebaseline recommendation. Never silently start another ten stages.
An acceptance criterion that requires someone to leave the keyboard — a real-device touch check, a print preview, a physical hardware step, a third party's sign-off, a paid account action — must not be written as a blocking precondition for the loop. Classify it as Deferred Owner Verification, deliver everything else to Ready for Independent Acceptance, and list the deferred item with its exact manual repro steps. A gate that the loop cannot execute by itself will otherwise freeze an otherwise-finished delivery; the common failure is a milestone sitting "almost accepted" for weeks on one manual check.
Never mark such a criterion verified because a similar automated check passed.
No evidence means no completion. A runtime claim normally requires:
Use the verification ladder:
Successful commands record command, exit code, concise result, timestamp, and evidence path. Failed commands retain the useful failure tail and raw-log path, not complete stdout in project state.
When evidence conflicts, keep the weaker result. Builds and unit tests do not overrule a broken user flow.
A stronger-sounding artifact never upgrades a weaker level of proof. Each row below is a claim-class error, not a wording preference:
| Do not report | As if it proved |
|---|---|
| source tests pass | the packaged, portable, or offline build works |
| build succeeds | a user flow is usable end to end |
| schema-valid JSON or a passing packet validator | the packet content is coherent or correct |
lint passes with a raised --max-warnings ceiling | code quality is acceptable (a raised ceiling is a disabled check) |
| a narrow unit test | a business or runtime flow works |
| a screenshot or a rendered page | interaction, touch, printing, or offline behavior works |
a health endpoint or a 200 response | the feature delivers user value |
| a security surface that was never assessed | Passed — write Not Assessed |
| one shard or subset of a suite | the authorized full-suite gate |
| a historical green record | the current state still passes |
When a check was not run, record not-executed. Never substitute a passing synonym.
context_profile: Compact reads by default:
Do not reread TARGET, ACCEPTANCE, or the Work Order when their recorded authority fingerprint is unchanged. Do not load historical Milestones, handoffs, QA files, or full logs unless diagnosing a named conflict.
Use soft context ceilings by size: Small 6 files / 30,000 characters, Medium 10 / 60,000, Large 16 / 100,000. Exceed only for named evidence, record why, and compact before continuing. These are context controls, not proof of completion.
Read {baseDir}/references/en/safety-and-context.md.
Delegate work to reduce retained context only when it is separable and expected to produce substantial reading or tool output. Keep small, tightly coupled work in the main loop. Give each worker a bounded task packet, disjoint write scope, authority fingerprint plus required excerpts, and a structured return capped to conclusions and evidence. Never send the full parent conversation.
Use one coordinating writer per Packet and normally no more than three active workers. Isolate log review, broad read-only discovery, noisy validation, and independent QA first. Parallel Developers require non-overlapping Work Orders and an authorized integration stage.
Read {baseDir}/references/en/isolated-delegation.md. For host-specific session, cache, attachment, compaction, and rewind controls, read {baseDir}/references/en/host-cost-controls.md only when that host is in use.
At loop end:
Docs/LOOP_RUNS.jsonl.New records use record_version: "2.1" and may include role, progress_delta, stage_review, failure_signature, and context_stats. Never copy the same status into several Markdown files. Prefer the packet and loop log over per-stage dispatch, handoff, or QA files.
Stop before:
Diagnostic sharding may narrow a long or timed-out suite, but it cannot replace an authorized full-suite gate unless Controller or Owner formally changes that gate.
For the concrete failure shapes behind these stops, read {baseDir}/references/en/anti-patterns.md.
An outer runner may repeat bounded loops only with a single-writer lock, fresh state, enforced budgets, and a stop on any terminal or invalid state. It must not invent scope, auto-answer Owner gates, accept governed work, or hide failures.
Give Stage Reviewer and independent QA raw criteria, diff, commands, and evidence. Do not give them the Developer's desired verdict as proof.
Read {baseDir}/references/en/automation-and-handoff.md.
Run compact validation without changing the project:
node {baseDir}/scripts/validate-loop-state.mjs --workspace <project-path> --summary --max-findings 20
Add --json for machine output or --strict-history only when old log migration itself is under review. Validator success proves state consistency, not product correctness.
Report only the current delta:
Execution state:
Stage and role:
Target link:
Progress delta:
Automatic verification:
Functional verification:
Stage review:
Risks or blockers:
Next action:
Independent QA needed:
Do not claim final acceptance unless the current acceptance authority permits it.