Catalog
JuliusBrussee/caveman-manage

JuliusBrussee

caveman-manage

Inspect Caveman Cloud's experiment lifecycle and block unsafe execution. Use when asked to start, approve, cancel, promote or roll back a Caveman experiment.

NewUpdated Sep 9, 2026

Manage eval-gated experiments

Treat every lifecycle change as a production control action. Read current state and results, then report one supported recommendation or block. Current agent MCP is intentionally read-only: control-api does not yet enforce a complete lifecycle transition table and evidence gate atomically.

Non-negotiable gates

  1. A request to review, inspect, explain, or recommend authorizes reads only.
  2. Never approve an experiment whose results are pending, whose required guardrails are absent, or whose evidence reports a breach.
  3. Never convert experiment lift into verified_savings. Only active real traffic plus provider-causal, provider-complete ledger evidence can do that.
  4. Never supply an organization id. Project and tenant scope come from the logged-in Caveman identity and server RBAC.
  5. Never execute a lifecycle mutation, even after user approval. Exact <action>:<experiment_id> strings are agent-generatable and are not proof of human intent.
  6. Unknown states and server errors fail closed. Report exact cave_snake_code.

Step 1 — Load project and experiment

Prefer MCP:

caveman_context {}
caveman_experiment_get {"action":"get","experiment_id":"<id>"}
caveman_experiment_get {"action":"results","experiment_id":"<id>"}

Use {"action":"list"} when the user has not named an id.

CLI fallback:

caveman cloud experiments list
caveman cloud experiments show <id>
caveman cloud experiments results <id>

Stop if login, project, experiment, or results are unavailable.

Step 2 — Evaluate evidence

Report:

  • current lifecycle state and safety class;
  • control and candidate sample sizes;
  • quality or eval result;
  • latency, error, cost, retry, drop, and escalation guardrails when present;
  • evidence cost;
  • rollback or hold reason;
  • whether result is pending, failed, promotable, or active.

Absence is not a pass. If a required field is absent, state evidence incomplete and do not propose approval.

Step 3 — Propose one action

Allowed actions:

  • start — only from a startable draft or queued state with configured graders;
  • approve — only with complete passing evidence and a safety class the current role may approve;
  • cancel — stop a non-active experiment the user no longer wants;
  • rollback — revert an active or harmful change through the server's linked policy path. Current deployments may reject this honestly with cave_not_implemented; never describe that response as a rollback.

Show recommendation and id:

Proposed action: approve experiment 7f...
Reason: candidate passed quality and every configured guardrail.
Execution: blocked until server-authoritative lifecycle and evidence gates ship.

Do not treat earlier generic statements such as "manage it" or "do what is best" as mutation approval.

Step 4 — Block unsafe execution

Do not emit or run an executable lifecycle command. Explain that current server does not yet enforce every evidence/state transition atomically. CLI and MCP agent surfaces therefore expose experiment reads only.

Step 5 — Re-read after external operator action

If operator says they executed command, read detail and results again. Report server-observed post-state, audit or result response, and any policy-delivery status returned. Never infer success from operator intent alone.

Use this close:

Action: <action> <experiment-id>
Before: <state>
Server response: <status and cave_snake_code if any>
After: <re-read state>
Basis: experiment evidence only. Verified savings unchanged unless the signed
ledger independently records active, provider-causal real-traffic savings.
Files1
1 files · 1.4 KB

Select a file to preview

Overall Score

88/100

Grade

A

Excellent

Grades are signals, not a certification. Always review a skill yourself before use.

Safety

92

Quality

87

Clarity

86

Completeness

82

Summary

This skill guides agents in safely managing Caveman Cloud experiment lifecycles by reading state and results, then proposing actions without executing mutations. It enforces strict non-negotiable gates: reads-only for reviews, blocking approval of pending/unsafe experiments, refusing to convert lift into savings without provider-causal evidence, and explicitly preventing execution of lifecycle commands to preserve human intent verification.

Detected Capabilities

read experiment metadata and results via MCPread experiment lifecycle stateCLI fallback for experiment inspectionpropose lifecycle actions without executingparse and evaluate evidence completenessreport server error codes and policy status

Trigger Keywords

Phrases that agents use to match this skill to user intent.

review experiment evidencecaveman experiment approvalinspect experiment resultsblock unsafe experimentsrecommend rollback

Risk Signals

INFO

Skill explicitly prohibits execution of lifecycle mutations

Step 4 — Block unsafe execution
INFO

Server RBAC enforced; organization ID never supplied by agent

Non-negotiable gate #4
INFO

Failed closed on unknown states and server errors with exact error codes reported

Non-negotiable gate #6
INFO

Requires evidence completeness verification before approval recommendations

Step 2 — Evaluate evidence

Use Cases

  • Review experiment state and evidence before approval decisions
  • Inspect pending experiment results and guardrail status
  • Recommend safe rollback or cancellation of experiments
  • Audit evidence completeness against Caveman safety gates
  • Block unsafe experiment mutations and report server status

Quality Notes

  • Clear non-negotiable gates establish hard boundaries: reads-only authorization model prevents accidental mutations
  • Structured 5-step process (load, evaluate, propose, block, re-read) is methodical and auditable
  • Evidence evaluation criteria explicitly stated (sample sizes, guardrails, result status) — agent knows what complete evidence looks like
  • Fallback CLI instructions provided but secondary to read-only MCP preference
  • Human intent verification is explicitly protected: agent-generatable action strings are rejected as proof of intent
  • Edge cases well-addressed: pending results, missing guardrails, server errors, and post-action re-reads
  • Proper close template (Before/After/Basis) ensures verifiable audit trail
  • License file is present but not integral to skill content — no security issues there
Model: claude-haiku-4-5-20251001Analyzed: Sep 9, 2026

Reviews

Add this skill to your library to leave a review.

No reviews yet

Be the first to share your experience.

Version History

  1. v2.0

    Contract changed: description

    ✦ AINarrowed activation criteria: removes eval-gated lifecycle mention, evidence-first instruction, and gate/transition clarity from description.

    triggering2026-09-09

    LATEST
  2. v1.0

    2026-08-17

    View This VersionInitial version

Use JuliusBrussee/caveman-manage in your dev environment

Command Palette

Search for a command to run...