Repository navigation
Add Hivemind: Zero-Cost Multi-Agent Orchestration Skill - #1628
Hanishchow wants to merge 2 commits into
Conversation
18badcd to
d363ccf
Compare
Babysit review — needs path fixNice content, but the new files live at the repo root |
…ode dependency Addresses review feedback on anthropics#1628: - relocate hivemind/ -> skills/hivemind/ so the repo skill scanner picks it up - remove committed .runs/hive-smoke.jsonl runtime artifact; gitignore .runs/ - document the external opencode CLI dependency, free-model caveats, and setup steps - ship the slash commands and worker agent definitions the skill references - make the opencode binary resolver cross-platform instead of Windows-only
15829ee to
3b3fad9
Compare
Hivemind delegates grunt work to headless opencode workers (scout/coder/tester) while Claude Code stays the planner, reviewer, and merger. - skills/hivemind/SKILL.md documents the invocation contract, swarm flow, and fallbacks - scripts/ hold the single sanctioned worker entry point plus status/aggregate/bench tools - assets/ ship the slash commands and opencode agent definitions the skill references - prerequisites section documents the external opencode CLI + free-model dependency - runtime state (.runs/) is gitignored, not committed
98zc5g5jyw-arch
left a comment
There was a problem hiding this comment.
Review: Hivemind skill (#1628)
Thanks for the submission — the skill is well-structured, the scripts are defensive (argv-array spawning, --dir validation, timeouts, capped stderr, NDJSON parsing with fallbacks), and the "Golden Rule / fallback ladder / worktree isolation" protocol is genuinely good engineering. No credentials or secrets are hardcoded anywhere. Two blocking items below (both cheap to fix), then non-blocking notes.
Blocking
-
Missing
licensekey inSKILL.mdfrontmatter — the repo convention (seeskills/claude-api/SKILL.mdandskills/docx/SKILL.md) requires three keys:--- name: hivemind description: ... license: Complete terms in LICENSE.txt ---
The current frontmatter has only
nameanddescription. Please add thelicensekey. -
Missing
LICENSE.txt— every skill directory in this repo ships aLICENSE.txtwith complete terms (skill-creator,claude-api,docx, ...). The PR's 17 files contain no license file. Please addskills/hivemind/LICENSE.txtwith the appropriate terms for the skill content.
Non-blocking
-
descriptionlength/format — 390 chars, single line, valid YAML (under the ~1024-char limit, so it passes), but it is on the long side; consider tightening the first sentence to the core trigger ("Orchestrate free opencode workers from Claude Code…") and moving the longer trigger phrases later, matching the repo's "short single-paragraph description" convention. Not a blocker. -
Security hardening (suggestion) — in
scripts/oc-worker.mjs,ensureServer()runsspawn(\${quoted} serve --port ${PORT}`, { shell: true, ... }).PORTis derived from theHIVEMIND_SERVER_URLenv var, so a hostile value for that env var could inject shell syntax. Low severity (local env only), but consider spawning with an args array andshell: false, or validating thatPORTis numeric. The mainopencode run` invocation already uses an args array (no shell interpolation) — good. -
Third-party dependency note — this skill is an orchestration layer over the third-party
opencodeCLI and routes worker traffic to opencode's endpoints/free models. The SKILL.md discloses this clearly ("Do not delegate secrets or private code you would not send there") and caveats that free-tier pricing/availability is opencode's to change — thank you for that. Just flagging for maintainer awareness; acceptable as disclosed. -
No duplication — checked the existing skills in the repo; no agent-collaboration/orchestration skill exists, so this fills a genuine gap. Directory layout (
assets/agents/,assets/commands/,scripts/,scripts/bench/) is consistent with other script-heavy skills.
Summary
Great first contribution. Fix items 1 and 2 (add license key + LICENSE.txt), and this should be good to merge.
|
Thanks for the review — all three points are addressed, force-pushed as a single verified commit rebased on current
Two things I fixed while in there, since they'd have been the next round of review:
|
…v hardening - add skills/hivemind/LICENSE.txt (Apache 2.0) and the license key in SKILL.md frontmatter, matching every other skill directory in this repo - tighten the description from 390 to 300 chars, core trigger first - validate HIVEMIND_SERVER_URL and spawn opencode serve with an args array and shell:false, so no environment value is shell-interpolated; a malformed URL or out-of-range port now fails fast with one JSON line instead of a stack trace
|
Both blocking items are fixed, plus 3 and 4. Pushed as a follow-up verified commit. 1. name: hivemind
description: ...
license: Complete terms in LICENSE.txt2. 3.
4. Shell injection — you were right to flag it, and chasing it turned up a second, more likely bug. const child = spawn(bin, ["serve", "--port", PORT], { shell: false, detached: true, stdio: "ignore", windowsHide: true });That also removed the manual path-quoting the shell form needed. The second bug: a malformed The env var and its validation are now documented in SKILL.md next to the server-management paragraph. On 5 — noted, and I'd rather it stay flagged than buried. If the third-party dependency ever becomes disqualifying for this repo, tell me and I'll withdraw it without argument. |
98zc5g5jyw-arch
left a comment
There was a problem hiding this comment.
Re-review after b4f0c6f: all previously requested changes are addressed. 1) license key added to frontmatter, 2) LICENSE.txt shipped, 3) description tightened to 373 chars, 4) oc-worker.mjs now validates PORT via resolvePort() and spawns with shell:false args array. Looks good. LGTM.
Adds Hivemind, a skill that lets Claude Code delegate mechanical work to headless opencode workers running on free models, while Claude Code stays the only planner, reviewer, and merger.
Why
The expensive model's context is the scarce resource, not its intelligence. Hivemind moves grunt work — multi-lens review, research sweeps, bulk migrations, partitioned test runs — onto disposable workers, and every worker returns exactly one compact JSON line. Raw agent streams never enter the orchestrator's context, which is the whole point of the protocol.
What's in it
Three personas, each least-privilege: scout (read-only, no write/edit/bash), coder (writes, confined to one git worktree), tester (runs tests, never edits source). Writing workers never share a directory, and the orchestrator is the only merger.
Dependency disclosure
This is an orchestration layer over the third-party
opencodeCLI, and worker traffic goes to opencode's endpoints. SKILL.md opens with a Prerequisites section stating that plainly, including that the free tier belongs to opencode rather than Anthropic and that availability, rate limits, and pricing are theirs to change. It also warns against delegating secrets or private code. Flagging it here too rather than leaving it to be discovered in review.Canonical home
Maintained at https://github.com/Hanishchow/hivemind (Apache 2.0). This PR is a snapshot; fixes land there first and get ported here.
Contributor: @Hanishchow