Eight folders under skills/ get attached to bounded work instead of spawning permanent agents. The coordinator picks them, the console shows them, and the job packet records which ones ran.
cfops-safe-deploy
Tests, Wrangler dry-run, Git checkpoint, then an exact public version-marker gate. A successful upload alone is not accepted.
cfops-live-verify
Checks the changed route, redirect policy, expected text and phone interaction. A 200 serving the wrong app fails.
cfops-email-loopback
Sends a one-use challenge through the production sender, public MX, Email Routing and the inbound Worker; records confirmed, expired or failed.
cfops-context-handoff
Keeps the release commit, deployment receipt, verified facts and next safe action. Stale chatter expires.
cfops-security-review
Refute-first review that has to argue against its own finding before it files one.
cfops-private-mcp
Access to the private MCP surface under the operator's own OAuth grant.
cfops-google-research
Opens and traces primary sources rather than trusting search snippets.
cfops-claude-verifier
Optional independent second opinion when the operator has configured that provider. The user's key never enters the repo.
Every agent, every job, every lane runs the same five steps. It does not change for a cheaper model or a faster deadline.
Agents never hold the bootstrap token. They ask for a task token scoped to one zone with preset permissions that expires in an hour. There is deliberately no account-wide preset.
Read current state first — scan, resolve the zone, fetch what exists.
Show desired versus current as a before/after. Nothing has been written yet.
A human says yes. Mutating tools need apply: true; the CLI needs --apply.
Write only the approved change. An apply never deletes as a side effect.
Re-check the public result — status, redirect policy, expected marker — then record the hashes.