Imported from xennon101/ai-capability-framework (
agent-skills/skills/aicf-action-lifecycle/SKILL.md). Install upstream withnpx skills add xennon101/ai-capability-framework --skill aicf-action-lifecycle. Copyright stays with the author (MIT).
AICF Action Lifecycle
Purpose
Guide implementation or review of side-effect workflows so prepare, approval, commit, verify, idempotency, and audit paths stay host-controlled and fail closed.
Use this skill when
- Adding or auditing prepare, approval, commit, verify, audit, or idempotency behavior.
- Linking prepare capabilities to host-controlled commit capabilities.
- Testing state transitions for side-effecting capabilities.
Do not use this skill when
- Creating read-only capability manifests.
- Exposing commit tools to models.
- Building production approval UI or durable storage unless explicitly requested.
Inputs to inspect first
- Capability lifecycle metadata, linked prepare/commit IDs, runtime action manager, stores, audit sink, handlers, and tests.
- References: state machine, approval patterns, idempotency and audit, and verification patterns.
Workflow
- Identify side effects: create, update, delete, send, money movement, permission changes, external workflows, or irreversible effects.
- Keep the model-exposed operation read or prepare by default.
- Link prepare to the allowed commit capability explicitly.
- Wire prepared action, approval, idempotency, audit, and verification paths.
- Enforce valid transitions: proposed, prepared, approval required, approved, rejected, committed, failed, expired, cancelled.
- Prevent duplicate commits with scoped idempotency.
- Mark failed commit attempts as failed and preserve audit evidence.
- Add tests for every valid and invalid transition.
Use action handler template, prepared action record, and approval record as safe examples.
Required outputs
- Lifecycle implementation or audit notes with linked prepare/commit behavior.
- Tests for success, approval, rejection, expiry, duplicate commit, invalid transition, and handler failure.
- Safe audit/idempotency summary.
Validation
- Run runtime lifecycle tests and package checks used by the repository.
- Confirm commit uses stored prepared action args.
- Confirm terminal states cannot return to pending or approved.
Hard rules
- Commit must not be executable through model-originated tool calls.
- Commit must require the correct stored prepared action and approval when policy requires it.
- Invalid output, thrown handler, or failed commit must move the action to failed.
- Do not store private raw data in audit records.
Handoff format
Report lifecycle states changed, handlers wired, idempotency scope, audit evidence, tests run, and remaining approval/storage obligations.
