Swap Control Center
SkillAI & modelsSelect verified controller and worker routes with independent provider, model, reasoning effort, and transport choices, then bind a compatible relay mode for work initiated from Cursor, Codex, Claude, OpenCode, Grok, Kimi, or another capable host. Use when the user wants the active host to relay bounded work to a different controller, choose subagent models separately, optionally set up and test an approved CLI or bridge, or transfer controller ownership once without changing host permissions or creating multiple controllers.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Swap Control Center skill
What this skill tells your AI
The instructions your AI receives, as published by giang6283623/minimal-vibe-coding-kit in .agents/skills/swap-control-center/SKILL.md and read by ahel’s review.
Use this skill as the dynamic-provider preset for
agent-control-center. Keep one orchestration engine and exactly one active
controller.
Procedure
- Read Agent Control Center and its four references. If the core skill is incomplete, stop and report the missing resource.
- Freeze the objective, host, topology, scope, authorization, budget, and acceptance contract before route selection.
- Build the live route inventory first. Classify every application, CLI, SDK, API, MCP bridge, and manual route independently. Never infer a ready route from a provider name or an application login.
- Follow
provider-selection.md.
In the active parent conversation, use the host's exposed structured
question tool, including
AskUserQuestionorrequest_user_inputwhen that exact tool is available. Otherwise ask one concise plain-text question at a time. Resolve controller and worker routes independently from current verified capabilities. Derivemanual-handofffrom a manual controller transport; otherwise select a compatible automatic or sequential relay mode. Never infer worker assignments from the selected controller. - If the chosen route needs setup, present the exact official source, version, install or configuration action, authentication step, expected billing or data boundary, rollback, and bounded smoke test. Obtain explicit user approval before each state-changing action or paid request. Rebuild the inventory after setup.
- Bind the selected controller provider to
controller=<provider-id>, bind the separately selected worker defaults or per-role routes, and run the Agent Control Center host-mediated loop. The host parent remains the user-facing relay and dispatch authority. The selected controller owns decomposition, work-order decisions, receipt review, and final acceptance. Topology skills execute controller-issued orders and do not create a second plan or controller. Forprovider=codexandtransport=codex-cli, use the bundled stateful bridge in../agent-control-center/references/codex-cli-bridge.md. Do not improvise a one-shot command. Other external providers require an equivalent verified preflight, start, reply, cancel, and close adapter before automatic use. - If the user requests a later role swap, use the one-transfer contract in
controller-modes.md. Pause dispatch, settle outstanding work, obtain any required approval, invalidate unused old orders, and resume with one new controller. Never run co-controllers or recursive controller delegation. - Report the active host, controller provider, transport, requested and attested model settings, setup or smoke-test evidence, worker routes, transfer history, validation, fallback, and residual risk.
Read examples.md when a host needs a concrete Cursor, CLI, or unavailable-route interaction pattern.
Codex selection
Codex is a normal fixed-provider choice in this skill. When the user selects
Codex, set controller=codex and follow the Codex route order and Cursor
app-only safeguards in controller-modes.md. Require a verified Codex route and
ask before any fallback to another controller. Do not require Cursor CLI or
Cursor SDK merely because Cursor is the active host.
When Cursor hosts a Codex controller with Cursor workers, send the task envelope through the stateful bridge first. Codex returns bounded work orders, Cursor dispatches only the approved Cursor worker routes, Cursor returns proof receipts to the same Codex session, and Codex decides. Do not launch Codex analysis lanes unless the user independently selected a ready Codex worker route.
Before the first Codex controller request, use bridge preflight output to ask
for the model and reasoning effort through the active parent's exact structured
question tool, including AskUserTool when that tool is available. Preserve an
explicit user choice. Do not offer values absent from the bridge preflight
catalog.
Cursor-hosted Codex executable priority
When Cursor hosts provider=codex with transport=codex-cli, let the stateful
bridge select and verify the executable in this order:
MVCK_CODEX_BIN, when the operator set one absolute executable path. This explicit route must pass preflight or stop without automatic fallback.- The
openai.chatgptextension path registered for the currentcodex_vscodeCursor host. - Other bounded, non-obsolete
openai.chatgptextension candidates that have matching local registry or manifest structure for the current platform. - The first executable
codexentry onPATH.
Cursor environment, registry, and extension manifest values are untrusted local routing evidence, not cryptographic publisher or model attestation. Every automatic candidate must pass executable identity, CLI capability, login, and exact full CLI-to-cache version checks before selection. Never equate a prerelease version with its base release.
Bind preflight, catalog selection, start, reply, idle cancel, close, state, and public receipts to the same route-binding digest and executable SHA-256. Start a new bridge-owned child process from that executable. Never enumerate, attach to, signal, resume, or reuse the Cursor extension's app-server process or session.
Cursor Codex recovery
When this route fails preflight, start, or reply, read
codex-extension-recovery.md. Run the
non-mutating checks first and present the bridge's recoveryPlan as a proposal,
not as authority. Before every fix, state the exact action, target, state
change, quota or billing impact, risk, rollback, and verification, then wait for
explicit approval in the parent conversation.
Keep approvals single-use and action-specific. A cache refresh does not approve
login, install, update, state close, model selection, or a live controller
start. Never manually edit models_cache.json, normalize a prerelease version,
repair an open session in place, or reuse a route-binding receipt after the
executable, cache, login, or host route changes.
Fail-closed rules
- Never choose a provider, model, effort, or route from documentation alone.
- Never install a CLI, start login, enable billing, edit user configuration, or send a paid test request without explicit approval.
- Never use a repository config file for personal provider credentials or a personal controller bridge.
- Never assign the controller provider as a worker merely because it is the controller. Require an independent verified worker selection.
- Never treat a command name as provider identity. Verify the binary's own
version or authenticated metadata because aliases such as
agentcan collide. - Never claim that an external controller directly controls the host UI or native agents. Plain MCP, CLI, SDK, and manual transports are request-response routes.
- Use
requested-not-attestedwhenever the effective model or reasoning effort cannot be authenticated through the host boundary.
Report
Lead with the accepted task outcome or the exact missing capability. Then use the Agent Control Center output contract. Report relay mode, controller route, worker routes, and every user-approved setup action or controller transfer.
Signals
- GitHub stars
- 27
- Forks
- 3
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
swap-control-center- Source
- github.com/giang6283623/minimal-vibe-coding-kit