Let Fate Decide
Draws the 12 Houses of the Zodiac Tarot spread using cryptographic randomness to add 100+ bits of entropy to vague or underspecified planning. Interprets the spread to guide next steps. Use when feeling lucky, invoking heart-of-the-cards energy, or when prompts are ambiguous.
- Type
- Plugin
- Repository
- trailofbits/skills
- GitHub stars
- 7.3k
- License
- CC-BY-SA-4.0
- Repo last updated
- Sep 25, 2026
- Version
- 1.2.5
- Author
- Scott Arciszewski
What Let Fate Decide is
Let Fate Decide is a plugin published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Let Fate Decide adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Let Fate Decide
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills
- Install the plugin: claude plugin install let-fate-decide@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter trailofbits/skills (the owner/repo shorthand works for GitHub).
- Find Let Fate Decide in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/let-fate-decide/.claude-plugin/plugin.json, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.
A Claude Code skill that draws Tarot cards using secrets to inject entropy into vague or underspecified planning decisions.
What It Does
When a prompt is sufficiently ambiguous, or the user explicitly invokes fate, this skill shuffles a 22-card Major Arcana deck and a 56-card Minor Arcana deck independently using cryptographic randomness, then deals the 12 Houses of the Zodiac spread. Each house receives one Major Arcana card followed by two Minor Arcana cards, and all 36 cards may appear reversed. Claude then interprets the spread and uses the reading to inform its approach.
Triggers
- Vague or ambiguous prompts where multiple reasonable approaches exist
- "I'm feeling lucky", "let fate decide", "dealer's choice", "surprise me", "whatever you think", "YOLO"
- Casual delegation ("whatever", "up to you", "your call", "idk", "just do something", "wing it", "I trust you", "doesn't matter", "do what you want", "I don't care", "any approach works", "you pick")
- Yu-Gi-Oh references ("heart of the cards", "I believe in the heart of the cards", "you've activated my trap card", "it's time to duel")
- Shrug-like brevity -- very short prompts that fully delegate the decision
- About to arbitrarily pick between 2+ valid approaches (draw cards instead)
- "Try again" on a system with no actual changes (redraw)
How It Works
The spread is drawn by the draw agent (agents/draw.md), dispatched as let-fate-decide:draw.
- A Python script uses secrets.randbelow() to perform Fisher-Yates shuffles
- A Major Arcana deck and Minor Arcana deck are shuffled separately
- 12 houses are dealt, each with 1 Major Arcana and 2 Minor Arcana cards
- Each card has an independent 50% chance of being reversed
- Claude reads the house reference files and drawn cards' meaning files
- Claude interprets the spread
- The interpretation informs the planning direction
The default spread records a conservative unordered-card entropy budget exceeding 100 bits: roughly log2(C(22,12)) bits from Major Arcana selection, log2(C(56,24)) bits from Minor Arcana selection (assuming secrets.randbelow() is cryptographically secure), and 36 bits from independent card reversal choices. Exact values are computed at draw time and reported in the JSON output under entropy_bits. The actual ordered assignment of cards to houses contains more entropy.
In security, audit, and correctness workflows, this skill is only a discovery and hypothesis-generation aid. It can suggest where to look next, but evidence from review, testing, reproduction, or formal reasoning must decide whether a risk is real or resolved.
Reference Organization
Each zodiac house has its own markdown file under houses/. These files explain the house's technical meaning for building new projects, vulnerability discovery, correctness verification, and recurring workflows from the local security and engineering workflows this skill supports.
references/TECHNICAL_CONTEXT_LENSES.md distills those workflow themes into audit-stage, evidence-mode, domain, failure-class, and human/organizational lenses.
Each of the 78 Tarot cards has its own markdown file:
- cards/major/ - 22 Major Arcana (The Fool through The World)
- cards/wands/ - 14 Wands (Ace through King)
- cards/cups/ - 14 Cups (Ace through King)
- cards/swords/ - 14 Swords (Ace through King)
- cards/pentacles/ - 14 Pentacles (Ace through King)
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Let Fate Decide?
Let Fate Decide is a plugin for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Draws the 12 Houses of the Zodiac Tarot spread using cryptographic randomness to add 100+ bits of entropy to vague or underspecified planning. Interprets the spread to guide next steps. Use when feeling lucky, invoking heart-of-the-cards energy, or when prompts are ambiguous.
How do I install Let Fate Decide in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills Install the plugin: claude plugin install let-fate-decide@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Let Fate Decide in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter trailofbits/skills (the owner/repo shorthand works for GitHub). Find Let Fate Decide in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Let Fate Decide safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Devcontainer Setup Create pre-configured devcontainers with Claude Code and language-specific tooling Plugin · trailofbits/skills
- Exploitability Verifier Verifies whether a suspected vulnerability is actually exploitable by proving attacker control, mathematical bounds, and race condition feasibility. Spawned by fp-check during Phase 2 verification. Subagent · trailofbits/skills
- Firebase Apk Scanner Scan Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research only. Plugin · trailofbits/skills
- Fp Check Systematic false positive verification for security bug analysis with mandatory gate reviews Plugin · trailofbits/skills
- Modern Python Modern Python best practices. Use when creating new Python projects, and writing Python scripts, or migrating existing projects from legacy tools. Plugin · trailofbits/skills
- Insecure Defaults Detects insecure default configurations including hardcoded credentials, fallback secrets, weak authentication defaults, and dangerous values in production Plugin · trailofbits/skills
- Mutation Testing Configures mewt or muton campaigns, analyzes surviving mutants, and investigates bugs exposed by testing gaps. Use when setting up mutation testing, reviewing campaign results, identifying equivalent mutants, or finding bugs from surviving mutations. Plugin · trailofbits/skills
- Git Cleanup Safely analyzes and cleans up local git branches and worktrees by categorizing them as merged, squash-merged, superseded, or active work. Plugin · trailofbits/skills