Skippy: reply like a person wherever he is tagged, see what he is sent, and do what he asks
he answers like a person wherever you tag him, sees what you send him, and actually does the thing instead of talking about it.
As of September 10, 08:02 PM
What the status words mean
proven · done, not independently checked · partly done · not started · blocked · parked24%blocked
38 steps: 4 proven · 13 partly done · 20 untouched · 1 blocked · 0 parked
agent runs · 14tokens used · 6.3Mreview notes · 4dollars charged · not recordedcounted over 4 of 4 run records
The plan as first written
Steps
| Id | Plain words | Percent | State | Proof | What is left |
|---|---|---|---|---|---|
| STEP 1 | Turn his program back on, and prove the cards, the playbooks and the approval queue answer. | 100% | proven | `node projects/ops/skippy-jobs/_test-mac-relay.mjs` AND the evidence folder holds three separate reads — one card, one playbook, one approval queue — each with the answer it returned | The step |
| STEP 2 | Register it so a restart brings it back without anyone being at the keyboard. | 100% | proven | `launchctl print gui/501/com.skippy.mac-server` AND an independent controlled stop with unattended return, monotonic elapsed time, and authenticated card, playbook and approval-queue reads after return. The existing `node projects/ops/skippy-jobs/_test-com-skippy-jobs-launchd-watch.mjs` is a separate jobs-runner baseline, not proof about the Mac server. | The step |
| STEP 3 | Watch a handed-off job get confirmed the way it already works today, then make the failed approval happen again on purpose right next to it. | 100% | proven | `node projects/ops/skippy-jobs/_test-approval-channel.mjs` AND one recorded run in which the frozen approval case is red while a confirmed hand-off passes beside it | The step |
| STEP 4 | Write down the single way Skippy asks for a yes — it turns up where his handed-off work turns up, Skippy restates exactly what he is about to do, and Nick approves, edits a detail or replies. | 0% | not started | `node projects/ops/skippy-jobs/_test-dispatch-lifecycle-guard.mjs` passes unchanged — which proves only that the existing hand-off life is undisturbed — AND the written contract in the evidence folder carries the restatement fields, the three replies, the only-a-confirmed-detail-matched-request-runs rule, the read-back into the same thread, and the named list of every approval surface it replaces. The command alone never closes this row | The step |
| STEP 5 | The request really appears in his feed with the details restated, and editing a detail or replying with a question really works. | 0% | not started | `node projects/ops/skippy-jobs/_test-approval-gate.mjs` with its three new cases AND the creative director's written wording-and-layout verdict on the restated item, per §2d | The step |
| STEP 6 | The agent that was waiting gets the answer, a broken return is loud, the repair goes live, and someone who did not build it runs the whole journey again. | 0% | not started | `node projects/ops/skippy-jobs/_test-signal-answer-from-approval.mjs` AND `node projects/ops/skippy-jobs/_test-approval-relay-drain.mjs` from a session that did not build the repair, AND the release identifier in the evidence folder as the machine wrote it | The step |
| STEP 7 | He approves one, edits one, and replies to one — from the same feed his handed-off work is in — and says in one sentence what he saw. | 0% | not started | `node projects/ops/skippy-jobs/_test-approval-cards-scheduled.mjs` AND `node projects/ops/skippy-jobs/_test-thread-reply-confirm.mjs` AND Nick's own sentence in the evidence folder beside the recorded timings for all three, AND the Mac mini's phone service (`com.skippy.mobile`) read back over ssh from the mini's own launchd list as loaded and answering, with the before and after readings both recorded | Waiting on Nick: three short things on his phone — approve one request, change a detail on a second and confirm the corrected version, and reply with a question to a third — plus one sentence on whether each arrived as a notification or only when he opened the app. Nothing else in this plan waits on this. |
| STEP 8 | The list of things Skippy may just do, and the wall he may never cross. | 0% | not started | `node projects/ops/skippy-jobs/_test-acting-guards.mjs` with a red case per channel AND the internal list present as machine-readable data in projects/ops/skippy-jobs/lib/standing-auth.json, resolved at send time rather than described in prose | The step |
| STEP 9 | He does the thing on Slack, WhatsApp and email, and the service itself says so. | 20% | partly done | `node projects/ops/skippy-jobs/_test-slack-send-gates.mjs` AND three provider read-backs in the evidence folder, one per channel, each carrying the provider's own identifier for the action and for the read-back | The step |
| STEP 10 | Prove the five daily checks — bills, birthdays, restocks, loose ends and stored-password use — still run, and ask the team that owns every repeating job to put them back on their clock. No second clock is built here. | 40% | partly done | `node projects/ops/skippy-jobs/_test-sweep-coverage-declared.mjs` AND the evidence folder holds all five checks run by hand with the date each last fired, plus the written request to that list's owner — and then EITHER the first card the pass produced OR the owner's refusal, quoted, with the step held open | The step |
| STEP 11 | Find out exactly what Slack sends when Nick posts a picture. | 0% | not started | `node projects/ops/skippy-jobs/_test-slack-inbound.mjs` unchanged as the control AND the captured upload event on disk in the evidence folder with the field that causes the drop named | The step |
| STEP 12 | Preserve a real person's picture through both Slack intake paths, including a picture without a caption. | 100% | proven | Both _test-slack-inbound.mjs and _test-slack-listen.mjs pass. With the scoped fix removed in an isolated temporary copy, the new attachment-preservation and captionless-upload cases fail; with it restored they pass. Existing non-human and unknown-owner rejection cases remain rejected. Evidence distinguishes history payloads measured live from reconstructed socket envelopes; a real socket event is not claimed if absent. | The step |
| STEP 13 | Download what he sent, with a size and type guard so a bad upload cannot fill a disk. | 0% | not started | `node projects/ops/skippy-jobs/_test-slack-file-kinds.mjs` with the over-size and wrong-type cases each refused naming which guard it hit, and an ordinary photograph passing | The step |
| STEP 14 | The picture reaches the model as a picture, not as a sentence about a picture. | 0% | not started | `node projects/personal/skippy-app/skippy-code/test-data-access.mjs` with the new picture cases AND an answer in the evidence folder naming something only that test picture contains | The step |
| STEP 15 | The other two doors, including "put these in the drive folder". | 0% | not started | `node projects/ops/skippy-jobs/_test-whatsapp-email-relay.mjs` with the new attachment cases on both channels AND the filing case recording the destination read back after the write | The step |
| STEP 16 | His real photo, answered correctly, judged by someone who did not build any of it. | 0% | not started | `node projects/ops/skippy-jobs/_test-slack-receive-coverage.mjs` AND the fresh grader's own written verdict in the evidence folder, one per channel Nick used, saying whether the answer names something only his picture contains, and naming what was not exercised | Waiting on Nick: one picture sent wherever is easiest, with a line saying it is a test. |
| STEP 17 | Read the download code end to end once, so an odd file breaks nothing. | 0% | not started | `node projects/ops/skippy-jobs/_test-slack-file-kinds.mjs` after any change a finding required AND every finding in the evidence folder carrying a written verdict, accepted ones included | The step |
| STEP 18 | The "what changed with this client" half of his business questions starts answering. | 40% | partly done | `node projects/personal/skippy-app/skippy-code/test-data-access.mjs` AND the run record naming, per question, which source answered and its read date | The step |
| STEP 19 | The hours that used to come back and stopped, come back again. | 70% | partly done | `node projects/ops/skippy-jobs/_test-payroll-hours-source-reachable.mjs` AND the hours question answered with a figure carrying its source and read date | The step |
| STEP 20 | Business questions stop being answered out of the household board, and "I don't know" carries its date. | 60% | partly done | `node projects/personal/skippy-app/skippy-code/_test-lookups-resolve.mjs` with the two new cases — the business question no longer resolving through the personal board, and the date asserted in the unavailable sentence | The step |
| STEP 21 | Read what the health team's own plan produced, write it down here with its date, and run none of it ourselves. | 0% | not started | `node projects/personal/skippy-app/skippy-code/_test-drift-guard.mjs` read as a READ-ONLY observation of the state that lane left AND the health lane's own written result quoted into the evidence folder with its date. This lane runs no health release and hands nothing over | The step |
| STEP 22 | Five short messages from him, each answered in the right place. | 30% | partly done | `node projects/ops/skippy-jobs/_test-slack-mention-scope.mjs` AND all ten identifiers — request and reply for each of the five — recorded in the evidence folder and re-opened at Slack on a second separate call, with the thread-context grade written per message | Waiting on Nick: five short Slack messages — three in one thread, one direct message, one in a private channel. |
| STEP 23 | The mailbox keeps being watched when nobody is looking, and a stall is visible. | 60% | partly done | `node projects/ops/skippy-jobs/_test-gmail-watcher-liveness.mjs` AND two consecutive unattended cycles recorded with their timestamps, plus the signal a stopped watcher produced | The step |
| STEP 24 | Skippy can read, search and tidy the inbox inside the scope Nick sets. | 10% | partly done | `node projects/ops/skippy-jobs/_test-gmail-watcher-gate.mjs` with the new scope cases AND one real inbox read recorded as counts only, never message bodies, plus a refusal naming the boundary it hit | The step |
| STEP 25 | He taps once and it goes: standing permission inside the company, one tap for anyone outside. | 10% | blocked | `node projects/ops/skippy-jobs/_test-raw-mail-send-blocked.mjs` unchanged AND one internal send read back at the mailbox on a second call, plus one external message sitting held with its tap outstanding on step 4's one path | Waiting on Nick: , per external message: one tap. He granted send permission on 2026-09-08 under that boundary; internal recipients stand, external is a tap each time. |
| STEP 26 | Bring the proper connection back, so "did he get it" has an answer. | 20% | partly done | `node projects/ops/skippy-jobs/_test-wa-send-gate-real.mjs` AND one send in the evidence folder with its real delivery receipt and the route it actually used | Waiting on Nick: a minute with his phone to re-pair. |
| STEP 27 | A picture in and a picture out, in his own chat. | 0% | not started | `node projects/ops/skippy-jobs/_test-wa-inbound-capture.mjs` with the new attachment cases AND one picture in and one picture out, each re-opened in the chat on a second call | The step |
| STEP 28 | He can put things in the calendar, not only read it. | 15% | partly done | `node projects/ops/skippy-jobs/_test-calendar-create-timezone-rollover.mjs` AND `node projects/ops/skippy-jobs/_test-calendar-push-honesty.mjs` AND the created, moved and cancelled event each read back on a second call in the evidence folder | The step |
| STEP 29 | Who gets paid, how much, on which rail, who approves, and what proof comes back — on paper first. | 20% | partly done | `node projects/ops/skippy-jobs/_test-approval-money-link.mjs` AND the written path in the evidence folder naming all three rails — Wise, Remitly and PayPal — with every approval point and every receipt written against each, and no rail described as "and similar" | The step |
| STEP 30 | The card he taps, and everything behind it, working with nothing real in it. | 0% | not started | `node projects/ops/skippy-jobs/_test-spend-card-survives-gate.mjs` AND one full end-to-end run on the placeholder recorded in the evidence folder with the card's four facts present, AND the creative director's written wording-and-layout verdict on the card, per §2d — no fidelity count, because no approved drawing contains this card | The step |
| STEP 31 | The whole thing tested hard, with an independent check that nothing left any account. | 0% | not started | `node projects/ops/skippy-jobs/_test-runner-money-and-destruction.mjs` AND the independent session's own written confirmation, read from the rails' own records rather than the test output, that no account moved in the test window | The step |
| STEP 32 | Enable the real payment instrument at the very end, after the tests pass, with protected details handled by the existing vault tools. | 0% | not started | Existing money-leak test plus protected instrument label, enforced activation prerequisites and independent refusal of unapproved execution; no values or real debit. | Waiting on Nick: approval of this specific activation. No instruction to type a secret into a nonexistent vault interface. Every actual debit still requires its own approval; an enrollment that itself charges money must name that charge before proceeding. |
| STEP 33 | The private message waiting for Skippy is read and answered by a real working session. | 60% | partly done | `node projects/personal/skippy-app/skippy-code/_test-relay-port-scope.mjs` AND both messages recorded read and acknowledged in the evidence folder, with the named session that read them | The step |
| STEP 34 | The few corrected sentences the documentation gate is holding go into their files. | 40% | partly done | `python3 projects/ops/agents/check_plan.py projects/ops/life-os/audits/TEAM-DATA-ACCESS/PLAN.md` AND each approved sentence readable in its destination file, with a diff proving no other line in those files changed | Waiting on Nick: approve the wording once. |
| STEP 35 | The careful security pass over everything this lane touched, at the end, as the rules require. | 0% | not started | `node projects/ops/skippy-jobs/_test-approval-gate-is-wired.mjs` AND a written verdict for EACH of the seven surfaces this step names — one per surface, present even when the verdict is "nothing found, and here is what was opened" — AND a verdict on every finding raised, the owner-shortcut finding included, with the coverage stated honestly as manual or automated | Waiting on Nick: , and only one thing: the §S click that starts the pass. **Nothing about a scan is asked of him.** The tier is settled — free only, on his own ruling of 2026-09-08 late evening ("why not do it free?"): the security review skill and its default scan, plus the local secrets scan. The paid deep-dive tier is not run, not costed and not raised. |
| STEP 36 | Two documents still describe a fault that was fixed on 4 September. | 0% | not started | `node projects/personal/skippy-app/alexa/test-console-receipt.mjs` AND a repository-wide search returning no line still saying the speaker answers with a placeholder or that Amazon's requests are refused as too large, AND a diff of the two named manuals showing only those lines changed | The step |
| STEP 37 | Stand next to a speaker, ask one question, write down what it said. | 0% | not started | `node projects/personal/skippy-app/alexa/test-adapter.mjs` AND Nick's own sentence in the evidence folder beside the route's own record of that request — the command alone never closes this row, because it passes with nobody having spoken | Waiting on Nick: thirty seconds at a speaker — "Alexa, open Skippy the Magnificent", then one question. |
| STEP 38 | Write down what actually happened, what is left, and what we got wrong — so the next lane does not pay for it twice. | 0% | not started | `python3 projects/ops/agents/check_plan.py --gate <a .md copy of this plan>` passes after the close-out is written AND this file carries a POSTMORTEM section and a NEXT list, AND the shared registry carries this lane's own new rows in the four-column format with the append shown by a diff | The step |
Done
4 of 38 steps proven
Left
34 of 38 steps not yet proven
Blocked on
- Nothing currently blocked.
Formal remaining plan
| # | Step | Needs Nick |
|---|---|---|
| 1 | Write down the single way Skippy asks for a yes — it turns up where his handed-off work turns up, Skippy restates exactly what he is about to do, and Nick approves, edits a detail or replies. | No |
| 2 | The request really appears in his feed with the details restated, and editing a detail or replying with a question really works. | No |
| 3 | The agent that was waiting gets the answer, a broken return is loud, the repair goes live, and someone who did not build it runs the whole journey again. | No |
| 4 | He approves one, edits one, and replies to one — from the same feed his handed-off work is in — and says in one sentence what he saw. | Yes |
| 5 | The list of things Skippy may just do, and the wall he may never cross. | No |
| 6 | He does the thing on Slack, WhatsApp and email, and the service itself says so. | No |
| 7 | Prove the five daily checks — bills, birthdays, restocks, loose ends and stored-password use — still run, and ask the team that owns every repeating job to put them back on their clock. No second clock is built here. | No |
| 8 | Find out exactly what Slack sends when Nick posts a picture. | No |
| 9 | Download what he sent, with a size and type guard so a bad upload cannot fill a disk. | No |
| 10 | The picture reaches the model as a picture, not as a sentence about a picture. | No |
| 11 | The other two doors, including "put these in the drive folder". | No |
| 12 | His real photo, answered correctly, judged by someone who did not build any of it. | Yes |
| 13 | Read the download code end to end once, so an odd file breaks nothing. | No |
| 14 | The "what changed with this client" half of his business questions starts answering. | No |
| 15 | The hours that used to come back and stopped, come back again. | No |
| 16 | Business questions stop being answered out of the household board, and "I don't know" carries its date. | No |
| 17 | Read what the health team's own plan produced, write it down here with its date, and run none of it ourselves. | No |
| 18 | Five short messages from him, each answered in the right place. | Yes |
| 19 | The mailbox keeps being watched when nobody is looking, and a stall is visible. | No |
| 20 | Skippy can read, search and tidy the inbox inside the scope Nick sets. | No |
| 21 | He taps once and it goes: standing permission inside the company, one tap for anyone outside. | Yes |
| 22 | Bring the proper connection back, so "did he get it" has an answer. | Yes |
| 23 | A picture in and a picture out, in his own chat. | No |
| 24 | He can put things in the calendar, not only read it. | No |
| 25 | Who gets paid, how much, on which rail, who approves, and what proof comes back — on paper first. | No |
| 26 | The card he taps, and everything behind it, working with nothing real in it. | No |
| 27 | The whole thing tested hard, with an independent check that nothing left any account. | No |
| 28 | Enable the real payment instrument at the very end, after the tests pass, with protected details handled by the existing vault tools. | Yes |
| 29 | The private message waiting for Skippy is read and answered by a real working session. | No |
| 30 | The few corrected sentences the documentation gate is holding go into their files. | Yes |
| 31 | The careful security pass over everything this lane touched, at the end, as the rules require. | Yes |
| 32 | Two documents still describe a fault that was fixed on 4 September. | No |
| 33 | Stand next to a speaker, ask one question, write down what it said. | Yes |
| 34 | Write down what actually happened, what is left, and what we got wrong — so the next lane does not pay for it twice. | No |
Decisions this lane is waiting on
- None.
blocked Blocked on the items listed above.