zcode-delegate
amelnagdy/delegate-skills
Delegate coding tasks to Z.AI ZCode CLI, review the diff, and land it yourself.
What is zcode-delegate?
This skill orchestrates a workflow where you hand off a bounded coding task to the Z.AI ZCode CLI as a background implementer, then review its output and commit it. Use it when the user explicitly asks to delegate work to ZCode (e.g., "have ZCode implement X", "run it through ZCode"), staying in control as the final reviewer and committer.
- Dispatches a coding task brief to the ZCode CLI and waits for completion
- Captures the diff and touched files from ZCode's implementation
- Reports a tri-state read-only violation check and CLI resolution details
- Provides a structured result.json with status, session ID, and artifacts for review
- Supports resuming prior sessions with delta briefs for iterative refinement
How to install zcode-delegate
npx skills add https://github.com/amelnagdy/delegate-skills --skill zcode-delegate- Z.AI ZCode desktop app installed (CLI ships inside the app, not on npm or PATH)
- Model provider configured in ~/.zcode/cli/config.json with a valid API key (separate from desktop app auth)
- Node 18+ and git installed
- Access to run shell commands and read files from the orchestrating agent
- Target code in a git repository
How to use zcode-delegate
- 1.Write a detailed brief describing the task goal, current state, changes needed, project gates, and report contract (see references/writing-the-brief.md)
- 2.Run the relay command: node <skill-dir>/scripts/relay.mjs --brief brief.txt --cd /path/to/repo
- 3.Wait for the relay to complete (it blocks until ZCode finishes; use run_in_background: true in Claude Code)
- 4.Review the result.json and diff: re-run project gates, check touchedFiles against the brief, verify no read-only violations
- 5.Commit the verified work yourself with a clear message; use --session <sessionId> for iterative refinement if needed
Use cases
- Delegate a feature implementation to ZCode while you review and verify the gates pass
- Hand off a refactoring task to ZCode and land the changes after confirming the diff matches the brief
- Run a queue of coding tasks through ZCode in background mode, reviewing each before committing
- Diagnose or review code in read-only mode without ZCode making edits
- Continue a prior ZCode session with additional instructions using the session ID
- Developers using Claude Code or other orchestrating agents with shell and file-read capability
- Teams wanting to offload implementation work while maintaining human review and commit control
- Users of Z.AI ZCode CLI who need headless delegation without desktop app interaction
zcode-delegate FAQ
No. The CLI keeps its own config at ~/.zcode/cli/config.json separate from the desktop app. You must configure a provider block and API key there, or set an environment variable like ZAI_API_KEY.
Do not use it for tasks small enough to code inline (delegation overhead is not worth it), when ZCode is not installed or has no model provider configured, or when you want to write the code yourself.
The relay takes a Git fingerprint before the run, executes ZCode in a temp directory (keeping your repo clean), and never commits. You review the diff and commit it yourself in step 5.
Yes, add --read-only to the relay command. ZCode will refuse edits and only produce a plan. Always verify touchedFiles is empty and check readOnlyViolation in the result.
Send a delta brief (only the new instructions) with --session <sessionId> from the prior result.json. The relay will continue that session with ZCode.
Full instructions (SKILL.md)
Source of truth, from amelnagdy/delegate-skills.
name: zcode-delegate
description: >-
Delegate a coding task to the Z.AI ZCode CLI as a background implementer, then review its diff and
land it yourself. Use this whenever the user wants to hand implementation work to ZCode — phrasings
like "have ZCode do X", "delegate this to ZCode", "run it through ZCode", or "use ZCode to
implement/fix/refactor" — or to run a queue of coding tasks through ZCode while staying the
reviewer. DO NOT USE for tasks small enough to do inline, or when the user wants the code written
directly without delegating.
license: MIT
compatibility: Requires the zcode CLI (Z.AI ZCode) with a configured model provider, Node 18+, and git. ZCode ships its CLI inside the desktop app rather than on PATH or npm — see Prerequisites. The orchestrating agent must be able to run shell commands and read files. Shell examples assume bash/zsh (macOS/Linux, or Git Bash/WSL on Windows).
metadata:
version: 0.5.0
ZCode Delegate
You are the orchestrator. This skill lets you hand a bounded coding task to a separate implementer — the Z.AI ZCode CLI — then review what it produced and land it yourself. You write the brief and own the judgment; ZCode does the typing; you verify and commit.
Nothing here is specific to one orchestrating agent. The loop needs only the ability to run a shell command and read a file. (It is designed for and run on Claude Code; treat other orchestrators as designed-for, not yet proven.)
When NOT to use this
- The task is small enough to just do inline — delegation overhead is not worth it.
- ZCode is not installed, or its CLI has no model provider configured.
- You want to write the code yourself, or you only need a review.
Prerequisites (check once)
- ZCode is installed. The CLI ships inside the desktop app — it is not on PATH and not on
npm. The relay resolves it in this order:
--zcode-path <file>orZCODE_CLIfirst, then PATH, then the installed app bundle. On Linux the app is an AppImage with no fixed install path, so the flag or the environment variable is required there — the relay guesses nothing. - A model provider is configured for the CLI, with a key it can actually reach. Being signed into the desktop app is not enough — see below.
- You are in (or will point
--cdat) the target git repository.
The relay records the CLI version and how it was resolved into result.json, so a surprising
install is visible after the fact.
Authenticating the headless CLI
Signing into the ZCode desktop app does not authenticate the CLI this relay drives. The CLI
keeps its own config at ~/.zcode/cli/config.json, separate from the desktop app's, and nothing
bridges the two. zcode login is the intended path, but where it fails with OAuth response is not valid JSON the way in is a Z.AI API key.
Two pieces are needed, and they are separate:
-
The provider block must exist in
~/.zcode/cli/config.json. It defines the provider, its endpoint and its models — the environment cannot supply this:{ "provider": { "zai": { "kind": "anthropic", "options": { "apiKeyRequired": true, "baseURL": "https://api.z.ai/api/anthropic" }, "models": { "glm-5.1": { "name": "GLM-5.1" } } } }, "model": { "main": "zai/glm-5.1" } } -
The key can live either in
provider.zai.options.apiKeyin that file, or in the environment as any one ofZAI_API_KEY,ZCODE_API_KEY, orANTHROPIC_API_KEY. Prefer the environment — it keeps the secret off disk.
If a run fails with Model provider is missing an API key: <provider>, the provider block resolved
but no key was found: set one of those variables and re-run.
Autonomy — read this before dispatching
ZCode's own term is mode. It has four values; only two are usable headlessly.
| mode | Behaviour |
|---|---|
yolo | Writes. ZCode's own default for --prompt, and this relay's write-capable default. |
plan | Refuses edits. What --read-only selects. |
build | Rejected by this relay. No permission client exists headlessly, so tools are blocked and the run exits 0 having done nothing. |
edit | Rejected for the same reason. |
Two limits stated plainly, because ZCode cannot enforce them:
planmode refused edits in testing, but the relay does not treat that as a guarantee. It takes a Git fingerprint before the run and reports a tri-statereadOnlyViolationafterwards. ConfirmtouchedFilescame back empty rather than assuming no edits.- ZCode has no
--allowed-tools. Only the--disallowed-toolsdenylist exists, and it is genuinely enforced. An explicit allowlisted tool surface is therefore impossible here — do not assume one.
The loop
Run these five steps per task. Steps 1, 4, and 5 are your judgment; 2 and 3 are mechanical.
1. Write the brief
ZCode sees only what you send — no repo memory, no chat history. Everything the task needs goes in the brief: the goal, the current state, what to change, what to leave untouched, the project's actual gate commands (discover them from the repo's CLAUDE.md/AGENTS.md/Makefile — do not assume), and a report contract. Tell ZCode it will not commit. One task per brief. The relay delivers the brief as an attached file, so the command line no longer bounds its length — the model's context window still does. Full guidance and a template: references/writing-the-brief.md.
2. Dispatch
node "<skill-dir>/scripts/relay.mjs" --brief brief.txt --cd /path/to/repo
# read-only (review/diagnosis, no edits): add --read-only
# continue a specific session: add --session <sess_...> (from result.json; send only the delta brief)
# continue the latest session for --cd: add --resume-last
# withhold tools (denylist): add --disallowed-tools "Write,Edit,Bash"
# point at the CLI explicitly: add --zcode-path /path/to/zcode.cjs
# hard time limit (watchdog): add --timeout 2h (default: off)
# see all options: node .../relay.mjs --help
(<skill-dir> is this skill's installed directory — the folder containing this SKILL.md.)
The relay writes its artifacts to a temp dir, so the repo under review stays clean. It never
commits — see step 5. Mechanics, flags, and the result.json shape:
references/dispatch-and-poll.md.
3. Wait for completion
The relay blocks until ZCode finishes, so back it with whatever your orchestrator offers:
- Claude Code: run the Bash call with
run_in_background: true; you are notified on completion. - Plain shell / other agents: foreground for short tasks, or background it and poll the result
file. The run is done when
result.jsonexists with astatus. A pre-run usage error exits 2 and writes no result file, so check the exit code too; a CLI that cannot be found exits 127 but does write aresult.jsonwith statuszcode_unavailable.
Do not trust progress trackers over reality: read the working tree, not a status line.
4. Review — do not trust the self-report
- Re-run the project's gates yourself. Never take "gates passed" on faith.
- Read the diff against the brief: did ZCode do what was asked, nothing more and nothing less?
touchedFilesis your starting point. - On a
--read-onlyrun, checkreadOnlyViolationand confirmtouchedFilesis empty. - Run the relevant guard skills on the diff if you have them installed.
Full checklist: references/review-and-land.md.
5. Land it
The orchestrator commits. Only after the gates pass and the diff holds:
- Commit the verified work yourself, with a clear message.
- If it needs changes, send a delta brief with
--session <sessionId>from the priorresult.json, and review again.
Read-only second opinions
The relay doubles as a way to get an adversarial second opinion with no write risk: dispatch
--read-only with a brief listing the agreed points, then each contested point with both positions,
and ask ZCode to defend or concede each. Because plan mode's guarantee is measured rather than
enforced here, verify touchedFiles came back empty instead of assuming no edits.
Authorization model
Delegation is something the human opts into. Once they have, committing verified, gate-passing work is the agreed contract. Two limits: surface, don't absorb (report ZCode's design decisions and defensible-but-unasked turns rather than silently keeping them) and stop for scope changes (if correct completion needs going beyond the brief, ask). The full treatment is in references/review-and-land.md.
References
- references/writing-the-brief.md — how to write a brief ZCode can execute blind: structure, the report contract, embedding the real gate commands.
- references/dispatch-and-poll.md —
relay.mjsflags, theresult.jsoncontract, how the CLI is resolved, backgrounding, and recovery. - references/review-and-land.md — the review checklist, the commit boundary, and the exact-session rework cycle.
- references/multi-task-queues.md — running a sequential queue: carrying constraints forward, progress tracking, and the end-of-run coherence check.
Related skills
More from amelnagdy/delegate-skills and the wider catalog.

agy-delegate
Delegate coding tasks to Google Antigravity CLI and review the diff before landing it.

aider-delegate
Delegate coding tasks to Aider as a background implementer, then review and land the diff yourself.

claude-delegate
Delegate coding tasks to a separate Claude Code session, review diffs, and land changes yourself.

cline-delegate
Delegate coding tasks to Cline CLI as a background implementer, then review and land the diff.

clean-code-guard
Review production code against Clean Code, SOLID, DRY, KISS, YAGNI, and LLM-specific failure modes before shipping.

docs-guard
Verify documentation accuracy against source code before publishing.