AI Guides › Skills & Agents

The Skill That Should Never Auto-Trigger

By Nigel Guy · 2 min read

Auto-triggering feels like the whole point of a well-built skill — you shouldn't have to ask for the thing you always ask for. That instinct is right for almost everything, and dangerously wrong for the one category of skill where the entire value of a human noticing beforehand outweighs the convenience of not having to ask.

The rule: if a skill's action can't be undone, it doesn't get to auto-trigger, no matter how reliable it's been — reliability is a track record, not a substitute for the specific moment a human looks at this one before it happens.

The mechanism: the Irreversibility Test

Before letting any skill fire without a confirmation step, ask these in order:

  1. Can this action be undone, fully, by you, without help? Not "technically recoverable with enough effort" — undone cleanly, on your own, in a reasonable amount of time. If the honest answer is no, stop here: this skill needs a human checkpoint, full stop.
  2. Does it go somewhere external the moment it fires? An email sent, a message posted, a payment made, a public record changed — anything that leaves your control instantly is a stronger case for a checkpoint than something that stays in a system you can still edit.
  3. Is the cost of a false positive symmetric with the cost of a false negative? Some skills failing to fire when they should is mildly annoying; some skills firing when they shouldn't is a real problem. If those costs aren't roughly equal, the checkpoint should sit on the side with the bigger downside.
  4. Would you be comfortable explaining this specific action to whoever it affects, after the fact, with "the skill did it automatically" as the only explanation? If that sentence doesn't sit well, the skill shouldn't have fired without you.

Any "no" to the first question, or a genuinely uncomfortable answer to the last one, means: keep the trigger, but gate it behind an explicit confirmation. The skill can still do all the preparation automatically — draft it, queue it, get it ready — right up to the final, irreversible step.

What to skip

Skip treating a good track record as a reason to remove the checkpoint — the checkpoint isn't there because the skill is unreliable, it's there because irreversible actions deserve a human moment regardless of reliability. And skip building "smart" auto-trigger logic that tries to guess which specific instances are safe to skip the checkpoint on; that logic is itself a skill that can be wrong, on exactly the case where being wrong is expensive.

Guardrails

All 751 AI guides · JulieMango plans from £17/mo