498 Orkas-AI

gate-control Skill

VideoStudio 审核授权与状态流转的规范策略。在 COMPOSE/AUTO/GENERATE/EDIT 中任何 Gate B/C/Preview/D 决策、门禁后修订、恢复审批或视觉 QA 结果耗尽之后使用;通过 `ovs gate transition` 将明确的用户授权和持久化的产物状态映射为唯一的下一步动作。门禁尚未建立时,不要用于日常规划或创作决策。

安装方式:把技能目录放入 ~/.claude/skills/(Claude Code)或在 claude.ai 设置中启用;也可复制右侧安装命令一键添加。

查看源码

技能指令原文(SKILL.md)

gate-control

This is the single authorization policy for every VideoStudio production line. Line skills own artifacts and production craft; they do not invent a second confirmation or recovery state machine.

Resolve the next operation from current facts—plan identity, artifact identity, narration materialization, paid-attempt facts, QA evidence, and explicit user authority—not from a monotonic stage rank. Preview/snapshot work may continue while required narration is missing; complete draft/final delivery may not. Stop the execution horizon at any operation whose returned evidence decides the next branch.

Gate-B identity is the normalized production-intent projection. Stable copy, timing, language, references, provider settings, and voice selection remain approval-bearing; execution-only fields such as produced paths/status and provider catalog display labels do not. Unknown plan fields remain signed so new semantics cannot bypass review.

Canonical review gates

The names below are internal protocol identifiers. In normal user-facing headings and decisions, use plain localized names instead:

| Internal identifier | English | Simplified Chinese |
| --- | --- | --- |
| Gate A | Direction confirmation | 制作方向确认 |
| Gate B | Production plan confirmation | 制作方案确认 |
| Gate C | Paid generation confirmation | 付费素材生成确认 |
| HTML Preview | Keyframe preview | 关键帧预览 |
| Gate D | Final video confirmation | 成片确认 |

Keep Gate A/B/C/D and HTML Preview for tool calls, stored state, and technical diagnostics only. Choose the production language from an explicit user request first, then the current UI/user language when known, otherwise English. Normalize Chinese to zh-CN, English to en, Japanese to ja, Portuguese to pt-BR, and unsupported languages to en; once submitted, keep that choice locked unless the user explicitly changes it.

Every gate shows the current artifact, a concise next-action/cost/QA note, one decision request, and then stops. A new turn, question, or unrelated message is not approval.

| Gate | Required artifact | Stable decision field | Approval authorizes |
| --- | --- | --- | --- |
| Gate B | canonical composition manifest or plan.json summary, including narration profile | gate_b_decision | production from that exact plan |
| Gate C | exact billable segment count and exact provider settings | gate_c_decision | those generation calls only |
| HTML Preview | current contact sheet | preview_decision | ovs draft for that preview |
| Gate D | draft video plus QA headline | gate_d_decision | high-quality finalization of that draft |

Decision values are approve and revise; keep free-text adjustments separate. Gate A locks the creative brief but does not authorize production, paid work, rendering, or final delivery.

Gate C is one batch-level decision. A pending or failed paid request is not reusable authority for another request: a user-requested retry needs a fresh Gate C and a new output path. Do not interleave per-shot confirmations.

Authority is not the same as recovery

  • A Preview/Gate D revise authorizes editing the displayed artifact within the requested scope and any required non-billable restart of its visual-QA cycle.
  • approve authorizes only the displayed artifact and next transition.
  • Technical QA exhaustion is not a second user decision and must never create a new recovery form.
  • Legacy visual_recovery_decision=new_visual_revision input remains consumable for old clients, but must not be emitted in a new task.
  • An error that says authorization is required does not itself prove recovery availability; query durable status first.
  • A malformed local payload, missing file, stale evidence, failed check, or write error is system work, not a creative decision. Repair it without creating a gate when approved intent is unchanged.

When production or rendering tools are explicitly unavailable, return a clearly unexecuted production package for an otherwise clear brief: assumptions, complete narration/script, timed storyboard, exact visible copy/captions, visual/audio and rights-safe asset plan, export target, preview checklist, and final playback/encoding QA. Do not claim files exist or withhold the package behind a direction form.

Required resolution

After a gate submission, a post-gate edit, a resumed turn with prior approval, or a visual-revision error:

  1. Identify the locked line: compose, auto, generate, or edit.
  2. Identify the reviewed artifact: composition for COMPOSE (and AUTO child compositions), otherwise production.
  3. Classify revision scope:
  • visual_only: HTML/CSS/SVG/layout/motion/palette/assets; no approved wording, timing, language, narration, delivery, source mapping, role, or provider-setting change.
  • gate_b_payload: approved copy/casing/punctuation, timing, language, narration, delivery, source mapping, semantic roles, or signed provider intent.
  • unknown: inspect the requested files before asking a technical question.
  1. Set recovery only from deterministic evidence: available, not_available, or unknown. This selects internal control flow, not a new form.
  2. Run ovs gate transition and obey next_action, form, allowed_ops, and prohibited_ops.

Always invoke the resolver through the public ovs gate transition command (or the equivalent gate_transition MCP tool). Never execute a resolver by referencing an installed skill or Marketplace path directly.
Pass only the decision field present in the current user submission. Never combine a current --decision with a cached --recovery-decision.

ovs gate transition \
  --line compose \
  --artifact composition \
  --gate gate_d \
  --decision revise \
  --scope visual_only \
  --recovery not_available

Pass --origin user|model|unknown for signed amendments, from the actual current user reply. Mixed user instructions plus additional model proposals use model. This pure resolver trusts caller-supplied facts; it does not verify chat history or record approvals. Optional evidence inputs are --error-code, --artifact-state, and --approval-status. --recovery-decision is backward-compatible input for an already-visible old form only. Use unknown when evidence is missing; never guess available.

Invariants

  • A Preview/Gate D visual_only revision with recovery not_available goes directly to a localized edit and deterministic QA. It emits no recovery question.
  • The same revision with recovery available still emits no form: make the localized edit, then use ovs check, ovs snapshot, and ovs draft. OVS automatically starts a fresh persisted repair cycle after the authored content signature changes.
  • A gate_b_payload revision originating from a model proposal creates exactly one Gate B amendment. A current user-specified change uses --origin user: apply and validate exactly that change without asking for the same instruction again. Its approved signature starts a fresh QA cycle, so recovery from the old signature is irrelevant and must not be combined into the form.
  • An unchanged artifact with recorded approval continues from that approval; never ask again merely because the task resumed.
  • A passing snapshot may create one Preview Gate. A passing draft may create one Gate D. No status check, advisory, retry, or bookkeeping step creates a user gate.
  • A content edit changes the draft signature and starts a fresh bounded repair cycle automatically. There is no public/manual reset operation; do not delete QA state by hand.
  • One user decision may produce at most one follow-up authorization request, and only for authority that decision did not already grant.
  • E_VISUAL_REVISION_EXPLICIT_AUTHORIZATION_REQUIRED never justifies a form. With recovery unknown, query status; with recovery available and no current revise decision, report the blocker and wait for the next real revision request.
  • After final-video approval, a local visual-only revision reuses the approved plan, assets, and narration. Edit only the affected scene, run ovs check and ovs snapshot, then encode the revised final; do not ask for production-plan confirmation again or repeat TTS/generation unless the requested scope changes signed content or provider intent.

Signed amendments

For a Gate B amendment, apply only the approved bounded patch, revalidate the changed plan/artifact, then continue through the real Preview/Gate D path. A current Gate B approval wins over cached approval for the old signature. Do not promise an immediate render when a newly materialized preview still needs review.

Status checks, plan bookkeeping, advisory QA, repair passes that remain, QA-cycle restart, and tool misuse errors never create a gate. Never emit visual_recovery_decision in new VideoStudio output.

Concrete review and recovery

A pending decision is not permission to ask it again. At a stop, show the complete current artifact once, invite the user's changes or go-ahead, then wait. A numbered choice or paraphrase of a displayed option is a decision; mixed approval plus edits means revise. Never use a new turn or a stale reply as approval.

Before COMPOSE plan confirmation, write only the canonical composition manifest and run free narration fit for its spoken windows. Script/shotlist files are legacy optional evidence, not a second required plan. Direction choice comes before authoring that manifest. For a fully specified one-shot deterministic edit, probe and execute the user's operation directly.

After two non-converging repair passes, show the current artifact, the visible unresolved problem and concrete directions for the user to choose. Do not silently create another repair cycle, delete QA state, or treat exhaustion as an unlimited retry. A real requested revision authorizes a bounded new attempt. Do not expose internal counters in ordinary user-facing text.

For AUTO, read assembled productions before preview or a child revision. For narration uncertainty, preserve the existing output, request identity and provider outcome. A failed or unknown billable request does not authorize another charge; present the concrete retry choice when new authorization is needed.