Slow, exhaustive planning sessions: question the user one decision at a time until requirements are fully confirmed, then optionally chain into research scouts, a readiness audit, an architecture draft, and a staged roadmap. Trigger on "help me plan", "let's design", "I want to build", "deep planner", or /plan. Built-in plan mode is the lightweight alternative; this is the opt-in careful path.
Answer a how-to / syntax / config / factual question from a SOURCE the user points at (a docs URL, or a local file/directory of docs), not from memory, and cite the exact location so they can read around it. Trigger on a doc link or local path plus a question, or tool/software syntax where a stale answer would be wrong (NWChem, Slurm, a library's API). For community sentiment use recent-research; for a literature survey use deep-research.
Audit a repo's docs against its code and bring them back in sync: inventory all docs, fan out doc-auditor sub-agents to verify every concrete claim, report drift with proving paths, then fix and rebuild on your call. Trigger on "check the docs", "are my docs current", "audit the documentation", "docs drift", or a pre-release doc pass. NOT for answering questions from docs (doc-grounded) or prose quality (writing reviewers).
Pressure-test a real decision through five advisor lenses, anonymous peer review, and a single synthesized verdict (Karpathy's LLM Council on sub-agents). Trigger on 'council this', 'run the council', 'pressure-test this', 'stress-test this', 'debate this', or a genuine 'should I X or Y' with real stakes and options. Not for factual lookups, yes/no questions, or creation tasks. Claude Code only.
Scanner-grounded security audit, distinct from the built-in /security-review: runs the right scanners (semgrep, osv-scanner, trivy, gitleaks, bandit), queries live CVEs via MCP, walks a 24-category threat-model checklist, and produces a triaged report. Trigger on "deep security review", "full security audit", "check for CVEs", "scan my dependencies", or proactively after changes touching auth, crypto, deserialization, or dependency upgrades. Routine file/network I/O does NOT trigger; offer it in a sentence instead.
Macro-first pipeline for multi-page documents where structure matters as much as prose (proposals, papers, grants, reports): intake -> outline contract -> draft -> developmental, structural, specificity, voice, and persona reviews -> human-writer copy pass. Trigger on "deep writing pass", "this reads like AI even with no AI tells", or any long-form piece for a specialist audience. Under ~1 page use human-writer; for critique only, editor.
Use any time you generate or rewrite prose for the user — emails, documents, posts, proposals, any written content — so it reads like a sharp human wrote it: direct, specific, no AI tells. Also trigger on "make this sound less like AI", "rewrite this", "tighten this", or "clean this up" said of prose. NOT for code: "clean this up" pointed at code means refactoring, not writing. For critique without rewriting, use editor.
In-depth, tool-grounded code review, distinct from the built-in /code-review. Default scope is the WHOLE codebase (runs linters/tests, reads architecture, checks for AI slop, renders a Continue/Refactor/Rebuild verdict); scopes down to a deep change review only when the user names a PR, commit, or diff. Trigger on "deep code review", "review this codebase", "is this good code", "audit this project". For "is this exploitable?" use security-review-deep.