AI Guides › Skills & Agents
The Skill That Should Never Auto-Trigger
By Nigel Guy · 2 min read
Auto-triggering feels like the whole point of a well-built skill — you
shouldn't have to ask for the thing you always ask for. That instinct is
right for almost everything, and dangerously wrong for the one category of
skill where the entire value of a human noticing beforehand outweighs the
convenience of not having to ask.
The rule: if a skill's action can't be undone, it doesn't get to
auto-trigger, no matter how reliable it's been — reliability is a track
record, not a substitute for the specific moment a human looks at this one
before it happens.
The mechanism: the Irreversibility Test
Before letting any skill fire without a confirmation step, ask these in
order:
- Can this action be undone, fully, by you, without help? Not
"technically recoverable with enough effort" — undone cleanly, on your
own, in a reasonable amount of time. If the honest answer is no, stop
here: this skill needs a human checkpoint, full stop.
- Does it go somewhere external the moment it fires? An email sent,
a message posted, a payment made, a public record changed — anything
that leaves your control instantly is a stronger case for a checkpoint
than something that stays in a system you can still edit.
- Is the cost of a false positive symmetric with the cost of a false
negative? Some skills failing to fire when they should is mildly
annoying; some skills firing when they shouldn't is a real problem. If
those costs aren't roughly equal, the checkpoint should sit on the side
with the bigger downside.
- Would you be comfortable explaining this specific action to whoever
it affects, after the fact, with "the skill did it automatically" as
the only explanation? If that sentence doesn't sit well, the skill
shouldn't have fired without you.
Any "no" to the first question, or a genuinely uncomfortable answer to the
last one, means: keep the trigger, but gate it behind an explicit
confirmation. The skill can still do all the preparation automatically —
draft it, queue it, get it ready — right up to the final, irreversible
step.
What to skip
Skip treating a good track record as a reason to remove the checkpoint —
the checkpoint isn't there because the skill is unreliable, it's there
because irreversible actions deserve a human moment regardless of
reliability. And skip building "smart" auto-trigger logic that tries to
guess which specific instances are safe to skip the checkpoint on; that
logic is itself a skill that can be wrong, on exactly the case where being
wrong is expensive.
Guardrails
- This isn't an argument against automation generally — it's specifically
about the irreversible step. Everything upstream of that step can and
should still be as automated as makes sense.
- "Irreversible" is sometimes a judgement call, not a fact. When in doubt
about whether an action counts, treat it as irreversible; the cost of an
unnecessary confirmation is far smaller than the cost of a wrong guess
here.
- A confirmation step only works if a human actually reads it before
approving. A rubber-stamped confirmation is a checkpoint in name only.
All 751 AI guides · JulieMango plans from £17/mo