Decide · ops SKILL.md
Draft-first Auto-review + takeover; Bots are not a security boundary
WhenUse when setting stop lines for send, pay, deploy, delete, and Auto-review rules.
StopAlways require approval for send/invite, publish, purchase, delete/overwrite, permission changes, production, legal terms. Never allow everything in the browser. Never paste passwords into chat.
Steps
- Put the stop in the request: Reconcile the campaign data and draft a recommended budget change. Do not change the campaign or message the agency. Ask for approval after showing the current value, proposed value, and expected impact.
- Always require approval for: send/invite, publish, purchase, delete/overwrite, permission changes, production, accepting legal terms.
- Settings → General → Auto-review. Narrow rules only. Require Approval always wins over Always Allow. Example: require approval before any external email; always allow git status in /workspace/reports. Never “allow everything in the browser.”
- Passwords/2FA/CAPTCHA/payment: Agent Computer → take control → finish the blocked step → continue. Masked secret request when offered. Never in chat.
- Local Mac/Windows execution is separate: Settings → General → Agent → Execution on Local Computer. Default Ask every time. Set Never allowed unless a Bot must touch local files. This does not restrict the cloud computer.
- Offboarding order: pause/delete routines → sign out of sites → uninstall connectors and revoke in the source → delete sensitive /workspace files → hide/delete Bots. Deleting a Bot does not wipe shared files or sessions.
LoadSettings → Auto-review. Takeover for 2FA/pay. Least privilege on plugins.
SourcexAI Grok Bot docs
--- name: Draft-first Auto-review + takeover; Bots are not a security boundary description: Use when setting stop lines for send, pay, deploy, delete, and Auto-review rules. --- # Draft-first Auto-review + takeover; Bots are not a security boundary When: Use when setting stop lines for send, pay, deploy, delete, and Auto-review rules. Stop: Always require approval for send/invite, publish, purchase, delete/overwrite, permission changes, production, legal terms. Never allow everything in the browser. Never paste passwords into chat. 1. Put the stop in the request: Reconcile the campaign data and draft a recommended budget change. Do not change the campaign or message the agency. Ask for approval after showing the current value, proposed value, and expected impact. 2. Always require approval for: send/invite, publish, purchase, delete/overwrite, permission changes, production, accepting legal terms. 3. Settings → General → Auto-review. Narrow rules only. Require Approval always wins over Always Allow. Example: require approval before any external email; always allow git status in /workspace/reports. Never “allow everything in the browser.” 4. Passwords/2FA/CAPTCHA/payment: Agent Computer → take control → finish the blocked step → continue. Masked secret request when offered. Never in chat. 5. Local Mac/Windows execution is separate: Settings → General → Agent → Execution on Local Computer. Default Ask every time. Set Never allowed unless a Bot must touch local files. This does not restrict the cloud computer. 6. Offboarding order: pause/delete routines → sign out of sites → uninstall connectors and revoke in the source → delete sensitive /workspace files → hide/delete Bots. Deleting a Bot does not wipe shared files or sessions. Load: Settings → Auto-review. Takeover for 2FA/pay. Least privilege on plugins.
