skill by
@amelnagdyDelegate a coding task to the Warp Agent CLI (`oz`) as a background implementer, then review its diff and land it yourself. Use this whenever the user wants to hand implementation work to Warp - phrasings like "have Warp implement X", "delegate this to the Warp CLI", "run it through Warp", "use oz to implement/fix/refactor" - or wants to run a queue of coding tasks through Warp while staying the reviewer. DO NOT USE for tasks small enough to do inline, when the user wants the code written directly without delegating, or for the interactive `warp` TUI (this skill drives the headless `oz agent run`, not the terminal app).
Permissions
Files
Delegate a coding task to the Warp Agent CLI (`oz`) as a background implementer, then review its diff and land it yourself. Use this whenever the user wants to hand implementation work to Warp - phrasings like "have Warp implement X", "delegate this to the Warp CLI", "run it through Warp", "use oz to implement/fix/refactor" - or wants to run a queue of coding tasks through Warp while staying the reviewer. DO NOT USE for tasks small enough to do inline, when the user wants the code written directly without delegating, or for the interactive `warp` TUI (this skill drives the headless `oz agent run`, not the terminal app).
Install
It’s free, and every skill you add syncs into every AI tool on your computer, instantly.
Version history
You are the orchestrator. Delegate a bounded coding task to a separate implementer - the Warp Agent CLI - then review what it produced and land it yourself. You write the brief and own the judgment; the implementer makes changes in its own conversation; you verify and commit.
The loop needs only a shell command and file access, so any comparable orchestrator can drive it.
oz, not warpWarp ships two different programs, and only one of them can be delegated to:
oz - the Warp Agent CLI. Headless and scriptable; oz agent run executes an agent against a
local directory. This is what the relay drives.warp - the interactive Warp TUI. It requires a terminal device, has no prompt or print flag
(its only options are --resume, --auto-approve, --api-key, and the provider-key commands),
and exits with Device not configured when stdin is a pipe. It cannot be relayed.If oz is missing but warp is installed, you have the TUI, not the CLI.
oz CLI is not installed or authenticated.oz agent run has no sandbox, no permission
mode, and no read-only run - see Autonomy and permissions.oz agent run uploads an end-of-run workspace snapshot
unless --no-snapshot is passed, and conversations live server-side.oz login, or set WARP_API_KEY for CI, a container, or any headless host.oz whoami can succeed while every dispatch fails with In order to use Warp's AI features, subscribe to a Warp plan, or bring your own inference. Warp records this internally as
QuotaLimit / "lack of AI quota", so it is a credit condition on the account rather than a
CLI-specific entitlement: oz runs the same agent harness as the Warp app and draws on the same
account, plan, and credits. Check that oz whoami names the account holding the plan - if it
does not, oz logout && oz login fixes it. Otherwise confirm the plan's AI credits are not
spent, or store your own provider key -
warp --set-provider-api-key <openai|anthropic|google|grok>, or /api-keys inside the TUI.
Bring-your-own-key needs no paid Warp plan.oz --version succeeds and oz whoami prints your user.--cd at, the target git repository.On macOS the CLI is distributed as a signed Developer ID binary; a first run may be held by Gatekeeper until it is approved.
Omit --model to use Warp's configured default. To pick another, choose an id from oz model list
and pass it verbatim. The relay accepts letters, digits, and . _ : / - only, so a value cannot be
mistaken for another oz flag.
Run these five steps per task. Steps 1, 4, and 5 require judgment; 2 and 3 are mechanical.
Warp sees only the text you send plus what it can inspect in the workspace - no chat history or
shared context. Include the goal, current state, what to change, what to leave untouched, the
project's actual gates, and a report contract. Tell it not to commit. Keep one task per brief.
The brief is delivered as the --prompt value on argv, so it is visible in the host process list -
keep secrets out of it and reference workspace files instead. See
references/writing-the-brief.md.
Use the bundled relay. It runs oz agent run --output-format ndjson, captures the event stream, and
writes result.json. (<skill-dir> is the installed folder containing this SKILL.md.)
node "<skill-dir>/scripts/relay.mjs" --brief brief.txt --cd /path/to/repo
# choose a model: add --model <id from oz model list>
# use an agent profile: add --profile <id>
# label the run: add --name <label>
# continue an existing conversation: add --conversation <id> (delta brief only)
# base the run on a Warp skill: add --skill <name|repo:name|org/repo:name>
# start MCP servers: add --mcp <path-or-inline-json> (repeatable)
# suppress the workspace snapshot upload: add --no-snapshot
# hard time limit (watchdog): add --timeout 2h (the 30m default suits short runs; implementation briefs routinely need 1-2h)
# see all options: node .../relay.mjs --help
The relay pins the workspace with both the child process's cwd and Warp's own --cwd. It writes
artifacts under the system temp dir by default and never commits. See
references/dispatch-and-poll.md.
The relay blocks until oz finishes. Run it with the orchestrator's background-command facility, or
background it in the shell and poll for result.json. A pre-run usage error exits 2 and writes no
result; a missing oz exits 127 and writes status: "warp_unavailable".
Trust process state and the working tree over a progress display. Completion means the process
exited and result.json exists. Warp's report is the finalMessage field in result.json (also
printed on stdout between the report markers); the raw event stream is always in events.jsonl.
Treat Warp's final message and gate claims as claims:
touchedFiles.Because there is no read-only mode to fall back on, the diff is the only record you get - and it records what git can see in the workspace afterward, not everything the run did. Dispatch from a clean tree so the two are as close as they can be. See references/review-and-land.md.
The implementer edits the working tree; the orchestrator commits. Commit only after the gates
pass and the diff holds. If rework is needed, send a delta brief with --conversation <id> using the
conversationId from result.json, then review again.
oz agent run has no sandbox, no permission mode, and no read-only mode. A headless run reads,
writes, edits, and executes commands with your own user permissions and never prompts. There is
nothing in the CLI to restrict that surface, so this relay ships no --read-only flag - offering one
would imply an enforcement that does not exist. The controls you actually have are:
--cd pins the workspace, and the relay passes it to Warp's own --cwd.
Treat this as aim, not a fence: on oz 0.2026.05.27 shell commands did run in the pinned
workspace, but the agent's file tool resolved bare relative paths against $HOME. Name absolute
paths in the brief - see references/writing-the-brief.md.touchedFiles is git status --porcelain taken after the run - post-run,
git-visible worktree state, not a log of what the agent did. It cannot show an ignored file, an
edit the run made and then reverted, or a write outside the repository (see item 1), and it
carries anything that was already dirty before dispatch. Dispatch from a clean tree so those are
the same set, and treat the diff as the best available record, not a complete one.--no-snapshot forwards Warp's flag so the end-of-run workspace snapshot is
not uploaded. Without it, the upload is Warp's default.--auto-approve belongs to the interactive warp TUI and has no bearing on oz agent run.
Delegation is something the human opts into. Once they have ("run this queue", "proceed"), committing verified, gate-passing work is the agreed contract. Two limits remain: surface, don't absorb (report Warp's design decisions, defensible-but-unasked turns, and non-blocking nitpicks) and stop for scope changes (if correct completion needs going beyond the brief, ask instead of expanding the mandate). See references/review-and-land.md.
result.json, polling, and failure recovery.In these kits
More from @amelnagdy
Works with
Claude, Codex, Cursor & more