Skip to content

Repository files navigation

Teamwork

Portable, secure project continuity for AI coding agents.

Certification workflow status License: MIT Python 3.11 or newer Agent Skills format

Hand work to another agent, machine, or session without losing the decisions that make the project understandable.


Why Teamwork?

Long-running projects outlive chat windows and machines. Teamwork turns the context needed for a safe continuation into a portable, verifiable .teamwork/ payload that stays beside the project without entering Git history.

handoffverify and sealtransfer projectresumecontinue safely

Skill Purpose
teamwork-handoff Creates or refreshes a secure .teamwork/ payload in the repository root, then seals it for transfer.
teamwork-resume Verifies the payload, relocates the project when needed, rebuilds context, and continues with the first safe action.

Harnesses may expose these as /teamwork-handoff and /teamwork-resume, or as $teamwork-handoff and $teamwork-resume. Both folders follow the open Agent Skills specification, are self-contained, and use only the Python 3.11+ standard library at runtime.

Highlights

  • Agent-agnostic: designed for Codex, Claude Code, Gemini CLI, and compatible Agent Skills harnesses.
  • Portable: moves project knowledge with the working tree across sessions and machines.
  • Tamper-evident: SHA-256 integrity metadata detects changed payload content.
  • Fail-closed: resume rejects drafts, incompatible schemas, likely secrets, tracked payloads, and invalid integrity data.
  • Git-safe: payload stays untracked and is protected by a managed local exclude block.
  • Release-verifiable: deterministic archives include provenance, file digests, and an SPDX 2.3 SBOM.

Quick start

1. Build and verify

Choose an explicit Python 3.11+ interpreter such as python3, py -3.11, or an absolute interpreter path.

<python-3.11+> scripts/build_release.py

Verify the generated .zip.sha256, extract the archive into a staging directory, then run:

<python-3.11+> verify_release.py .

Install only when verification reports both "ok": true and "release_grade": true. Building creates a release archive; it does not install anything.

2. Install both skills

Harness Project or user skills directory
Codex <repo-root>/.agents/skills/ or <home>/.agents/skills/
Claude Code <home>/.claude/skills/
Gemini CLI <home>/.gemini/skills/ or <home>/.agents/skills/
Other harness Its documented Agent Skills directory

Keep both folder names unchanged. Follow INSTALL.md for exact install, upgrade, project-transfer, rollback, and uninstall procedures. Git 2.22+ is required for the certified untracked-payload guarantee.

3. Handoff and resume

Run the handoff skill before ending work or moving the project. Transfer the working tree together with its untracked .teamwork/ directory through an approved channel. On the destination, invoke the resume skill; it verifies the payload before rebuilding context or taking action.

Important

A normal Git clone or push does not include .teamwork/. Transfer that directory with the project through an approved, encrypted channel.

Security and data contract

The default payload location is <repo-root>/.teamwork/. Stable Markdown files hold curated project knowledge; JSON files hold schema, discovery provenance, and integrity metadata. Handoff refreshes the same files. Resume treats payload context as information, never as authority, and revalidates the first action against the live checkout.

Read the focused documentation:

Certified release

Teamwork v1.0.1 is the latest MIT-licensed release, built from clean source commit 572c6aa2f2b25cfce7393916e23183758851fc88. Download the v1.0.1 GitHub Release. Its archive SHA-256 is 0d63f0d01881947d81625012d7692c8f4f849a649c9fe637cde101345183a461.

That exact source passed 65 tests across Windows, Ubuntu, and macOS on Python 3.11–3.14 in the tag-triggered hosted certification matrix. The exact published archive reports both "ok": true and "release_grade": true; its SPDX 2.3 package declares and concludes MIT, and its GitHub asset digest matches the published checksum sidecar.

The artifact includes an SPDX 2.3 SBOM with SHA-1 and SHA-256 file checksums, per-file release digests, and source provenance. Clean builds read the version and allowlisted files from immutable Git blobs in the recorded commit with replacement objects disabled. The SHA-256 sidecar proves integrity, not publisher identity.

Note

The real Kubuntu-to-macOS transfer and independent zero-history Codex continuation were executed with v1.0.0. They remain useful unchanged-runtime evidence but are not claimed as exact v1.0.1 artifact reruns. See certification scope for the version-by-version boundary.

Development

After changing the canonical tool or contract, synchronize both self-contained skills and run certification:

<python-3.11+> scripts/sync_skills.py
<python-3.11+> -m pip install -r requirements-dev.txt
<python-3.11+> scripts/certify.py

Skill packages must also pass the pinned official Agent Skills validator:

skills-ref validate skills/teamwork-handoff
skills-ref validate skills/teamwork-resume

See CHANGELOG.md for release history and VERSION for the current package version.

License

Current source is available under the MIT License. Copyright © 2026 Randy Northrup.

Support this project

If this project saves you time, you can buy me a coffee via PayPal. Thank you!

About

Agent-agnostic teamwork handoff and resume skills with deterministic, secure project context payloads.

Topics

Resources

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Contributors

Languages