Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
cristoslc avatar

External Task Management

  • 1 installs
  • Updated April 18, 2026
  • cristoslc/tidegate

Enforce data-flow boundaries in AI agent deployments to prevent sensitive data exfiltration.

About

Tidegate is a reference architecture for preventing AI agent data leaks through taint-and-verify, VM boundaries, and egress allowlisting.

  • Taint-and-verify data flow model
  • gvproxy egress allowlist enforcement

External Task Management by the numbers

  • 1 all-time installs (skills.sh)
  • Ranked #1,834 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/cristoslc/tidegate --skill external-task-management

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs1
Last updatedApril 18, 2026
Repositorycristoslc/tidegate

What it does

Enforce data-flow boundaries in AI agent deployments to prevent sensitive data exfiltration.

Files

SKILL.mdMarkdownGitHub ↗

External Task Management

Prefer external task CLI tracking over built-in todo systems.

Default workflow (current default: bd)

1. Check for bd availability:

  • command -v bd

2. If missing, install bd:

  • macOS (Homebrew): brew install beads
  • Linux (Cargo): cargo install beads

3. Initialize and validate:

  • bd --help
  • bd ready

4. Track every meaningful work item with bd records.

Canonical task states

Use this logical mapping even if the CLI uses different labels:

  • todo: identified, not started
  • in_progress: actively being worked
  • blocked: cannot proceed due to dependency
  • done: completed and verified

Operating rules

1. Create/update external tasks at the start of work, after each major milestone, and before final response. 2. Keep task titles short and action-oriented. 3. Store handoff notes in the task entry rather than ephemeral chat context when possible. 4. Include references to related artifact IDs in task notes. Valid prefixes: VISION-NNN, EPIC-NNN, PRD-NNN, SPIKE-NNN, ADR-NNN.

Spec lineage tagging (bd-specific)

When creating bd tasks that implement a spec artifact:

  • Tag the origin spec with --external-ref <ID> (e.g., --external-ref PRD-003). This is immutable — it records which spec seeded the work.
  • Tag all tasks with spec:<ID> labels (e.g., --labels spec:PRD-003). These are mutable — add labels as cross-spec impact is discovered.
  • When a task affects multiple specs, add additional labels: bd label add <task-id> spec:PRD-007.
  • Use bd dep relate for bidirectional links between tasks in different plans.
  • Query all work for a spec with: bd list --label spec:PRD-003.

Observer pattern expectations

1. Maintain a compact current-status view that can be queried externally. 2. Ensure blockers are explicit and include required next action. 3. Use consistent tags/labels so supervisors can filter by stream, owner, or phase.

Failure and fallback

If bd cannot be installed or is unavailable in the environment: 1. Log the failure reason in your work notes. 2. Fall back to a neutral text task ledger (JSONL or Markdown checklist) in the working directory. 3. Continue the same canonical state model and keep updates externally visible. 4. Mark that this fallback should be replaced once a preferred CLI is selected by SPIKE-001.

Pending decision

The default CLI may change after SPIKE-001 External Task CLI Evaluation. Update this skill when the spike completes.

Related skills

Securityauditappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.