The PR merged.
The website didn't change.

malohacoast.com rebuild · 5 Oct 2026

What actually happened
  • An agent rebuilt the page and opened a PR. It was merged.
  • The live site still served the old consulting page.
  • The host, Cloudflare Pages, had no Git source connected. Merging deployed nothing.

Nobody lied. The agent checked the wrong thing.

A first-principles guide

pstack,
from the problem up

Lauren Tan's open-source skills for rigorous agent work, explained through one real project.

Use arrow keys to move. Press F for fullscreen.

The problem pstack solves
Agents are fast at producing work.
They're unreliable at knowing when it's done.
"throughput without quality is not a goal i aspire to."Lauren Tan, pstack README
Why it compounds
"Verification is the slowest step in most agent work, because it's the step that usually waits on a human."pstack guide, "Verify the result and open a PR"

Add more agents without fixing this, and you just get more unchecked work to review.

First principles

What a good engineer brings that an agent doesn't

01

A way of working

How this team debugs, designs, and ships.

02

A checkable "done"

Something that can pass or fail, not a feeling.

03

Memory of misses

Last month's mistake changes this month's habit.

A fresh agent chat starts with none of these. They have to be written down.

So what is pstack?
"I've taken all the failure modes I've observed and turned them into skills."Lauren Tan, How I Use Cursor
Cursor pluginPlain markdown filesMIT licensed/add-plugin pstack
Building block 1

A skill is a markdown file the agent reads

---
name: figure-it-out
description: "Design an auditable playbook when
  no narrower one fits ..."
disable-model-invocation: true
---

A name, a "when to use" line, then instructions in prose. That flag means it runs only when you type it.

Our site: no skill told the agent how this host deploys.

Building block 2

Principles: 24 short rules with names

Prove It WorksSubtract Before You AddFix Root CausesEncode Lessons in StructureNever Block on the Human

The name is a steering handle. On our site, one line would have redirected the agent:

apply prove it works. open the live site.

The guide's own example: "apply prove it works. run the real import flow and show me the written records."

Building block 3

Playbooks: 23 recipes for recurring tasks

bug fixfeaturerefactoringperfprototypevisual parityshippingautonomous runand more
bug fix: "reproduce a defect, root-cause it, and fix with runtime evidence."pstack README, playbook table

Our site: no stock playbook fit a redesign-and-deploy job.

The router

/poteto-mode ties it together

1Read your request
›
2Match a playbook
›
3Copy its steps into a todo list
›
4Call skills as steps fire

A skipped step stays in the list as skip: <reason>, so you can see what it chose not to do.

Our site: with a "verify live" step, skipping it would have shown up in plain sight.

When no playbook fits

/figure-it-out designs one first

A
Frame
Done as a falsifiable predicate
B
Design
Small units, riskiest first, checks before work
C
Loop
Hypothesis, smallest change, measure, keep or revert
D
Trail
Log every decision with evidence
E
Verify
Check the whole on the real product

"The deliverable before any code is the workflow itself." · figure-it-out SKILL.md

Back to our site · Phase A

Done, written so it can fail

On live malohacoast.com and www, within about 10 seconds:

  1. A visitor can name the three products
  2. Each product row has intentional media
  3. The page no longer reads as a plain text list
  4. Media stays small, and reduced motion gets a still
  5. Hire link and contact email work
  6. Zero client traces in frames, filenames, alt text, or copy
The principle doing the work

Prove it works on the real artifact

"It compiles" is not evidence. Neither is "it merged."

VERIFIEDNOT VERIFIEDINCONCLUSIVE

"Inconclusive is not a pass. Don't hide a negative." · figure-it-out SKILL.md

Our first "live verified" was one text check. It never tested the predicate clause by clause.

Leave a trail

show-me-your-work: one row per decision

decisionwhyevidenceresult
took screenshots of the old version before changing anythingso we can compare old against newscripts/snapshot.sh, baseline/saved 120 reference screenshots

Example row from the skill file. "The trail plus the diff is what lets the human come back and trust the work."

Learn from the miss

/reflect turns a run into skill edits

3 REVIEWERSJudgment, Tooling, Divergent read the transcript
›
SYNTHESIZERSorts into Accepted, Rejected, Backlog
›
YOUApprove which edits apply

"Skill changes affect every future agent in the org. Do not auto-apply." · reflect SKILL.md

What reflect found for us
  • Our playbook said "done is merged." When done is a live site, merged is a middle step.
  • Onboarding asked for repo and host. It never asked how the host deploys.
  • "Live verified" was a single lucky check, not the predicate.

Divergent reviewer findings, malohacoast.com session, 5 Oct 2026. Proposals, pending approval.

Close the loop

Encode the lesson in structure, not more text

"Textual instructions are easy to miss."Encode Lessons in Structure, principle skill

For us: done now means live, verified clause by clause, on every hostname. It's in the predicate, so the next run can't skip it.

Trade-off

Rigor costs tokens

"pstack spends extra tokens on subagents and review panels. That's the price of the rigor."pstack guide, "Set up pstack"

Her advice: save /poteto-mode for work that needs rigor. A small, obvious edit doesn't.

When not to use it
  • A small, obvious edit.
  • No checkable finish line. "A duration is not a finish condition."
  • A loop you haven't earned trust in. It "only makes unchecked work faster."
  • You want different habits. It's one engineer's style; /automate-me drafts your own.

Quotes from the pstack guide, "Run work while you sleep" and "Recipes and pitfalls".

Our honest caveat
  • We ran it outside its usual setup. /setup-pstack was never run.
  • pstack didn't know our host deployed by hand. Nothing does until you ask.
  • The checks got good only once we wrote "live" into done.

"Rigor is gates and artifacts, not 'try harder'."

The PR merged. The website didn't change.

Now done means a visitor on the live site sees it, in ten seconds, on both hostnames.

"if you want to go fast, go deep first."

Lauren Tan, pstack README

Sources
  1. pstack README, v0.15.15 · github.com/cursor/plugins/tree/main/pstack
  2. figure-it-out, reflect, show-me-your-work SKILL.md · .../pstack/skills
  3. Principles: prove-it-works, encode-lessons-in-structure · same folder
  4. The pstack guide: Set up pstack, Verify the result and open a PR, Run work while you sleep, Steer with principle names, Recipes and pitfalls · .../pstack/docs/guide
  5. Lauren Tan, "How I Use Cursor", X article · x.com/poteto/status/2058975157503570132

The malohacoast.com story comes from our own project notes (FIO2-FRAME.md, REFLECT-DIGEST.md, REFLECT-REVIEWERS.md), not from Lauren's sources. Sources read 6 Oct 2026.

Full story·
← → navigate · F fullscreen · N notes