Agent skill

Hep Upload

by agentlas-ai in agentlas-ai/Agentlas-OS

Publish an Agentlas package to Agent Cloud or the public Hub.

Apache-2.0Auto-check passedAgent Workflows

Install Hep Upload

skills CLI
$ npx skills add agentlas-ai/Agentlas-OS --skill hep-upload -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agentlas-ai/Agentlas-OS hep-upload --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agentlas-ai/Agentlas-OS.git skills-src && mkdir -p .claude/skills && cp -r skills-src/kimi/skills/hep-upload .claude/skills/hep-upload && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hep-upload
GitHub stars
1.6k
Token cost
~1.4k tokens
SKILL.md length
693 words
Files
1
Skills in repo
53
Repo updated
First seen
Licence
Apache-2.0

At a glance

Publish an Agentlas package to Agent Cloud or the public Hub.

  • Works in 3 steps: Ask the destination first → Resolve the runner → Preview or publish one immutable snapshot
  • Agent Workflows work in your project
  • SKILL.md covers Step 1 — Ask the destination…, Taking it back down, Step 2 — Resolve the runner and Step 3 — Preview or publish…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Hep Upload is an agent skill from agentlas-ai/Agentlas-OS. Publish an Agentlas package to Agent Cloud or the public Hub.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows. The repository describes itself as: Agent OS: keep specialist agents in a hub, spin up a temporary orchestrator per task. Local-first, works with any model. The licence is Apache-2.0.

When your agent uses it

  • Agent Workflows work in your project

Example prompts

  • “/hep-upload”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Ask the destination first
  2. Resolve the runner
  3. Preview or publish one immutable snapshot

What it can do on your machine

Read from SKILL.md and the folder at commit 6254906. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hep Upload loads about 1.4k tokens when it runs. Until then it costs about 18 tokens; SKILL.md has 693 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~18
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agentlas-ai/Agentlas-OS at commit 6254906, republished under its Apache-2.0 licence (© agentlas-ai). 693 words, ~1,430 tokens.

Download SKILL.mdSave it as .claude/skills/hep-upload/SKILL.md (or your agent's skills folder).
name
hep-upload
description
Publish an Agentlas package to Agent Cloud or the public Hub.

Update fallback: 자동 업데이트가 안 되면 hephaestus update를 한 번 실행하세요. 업데이트하지 않아도 현재 버전 명령은 그대로 동작합니다.

/hep-upload

Upload an Agentlas agent package. The argument is the exact text the user typed after /hep-upload — usually an agent folder, possibly empty.

Guardrails: do NOT diagnose command not found/PATH, do NOT edit ~/.zshrc, and do NOT create/commit/stash/push any git branch or claim you did. If the runner is missing, say so and stop — never fabricate an upload.

Step 1 — Ask the destination first

Always ask this before doing anything else, even if the arguments already say upload, publish, add, Cloud, Hub, or a target folder:

text
Cloud에 업로드할까요? 다른 사람들은 볼 수 없어요.
Upload to Cloud? Other people cannot see it.

Agentlas Hub에 업로드할까요? 다른 사람들이 빌려 쓸 수 있어요.
Upload to Agentlas Hub? Other people can borrow it.

Do not package, publish, register, add-source, reindex, or call any upload API until the user answers Cloud or Agentlas Hub. If the destination is answered but the target folder is ambiguous, ask for the exact agent folder before running anything.

Agentlas Hub publishing and calls are free. Do not ask for an upload price or pass the retired --rent-credits, --ingest-credits, or --fork-credits flags. The CLI refuses those flags. Ask what account, API key, or destination the user's host needs, and put those prerequisites in the package guide.

Taking it back down

Publishing is not one-way. If the user wants a published agent unlisted, call hephaestus.unpublish_agent with its slug — it returns what would happen and asks first, and only confirm: true acts. A hub-public package is soft-unpublished from Hub routing with its bytes retained for audit and recovery; an owner-private one has its stored bytes removed. Local installs are never touched. The same thing is on the web at agentlas.cloud/cargo.

Only your own agents. owner_only means it is not yours; repeat that rather than trying another route.

Step 2 — Resolve the runner

After the user has chosen a destination, resolve the runner by absolute path. Do not ask the user to open a separate terminal.

bash
RUNNER=""
for candidate in \
  "$HOME/.agentlas/runtime/current/bin/hephaestus" \
  "./bin/hephaestus"
do
  if [ -n "$candidate" ] && [ -x "$candidate" ]; then RUNNER="$candidate"; break; fi
done
if [ -z "$RUNNER" ]; then
  for cache in "$HOME/.claude/plugins/cache/agentlas-core-engine/hephaestus" \
               "${CODEX_HOME:-$HOME/.codex}/plugins/cache/agentlas-core-engine/hephaestus"; do
    newest="$(ls -d "$cache"/*/bin/hephaestus 2>/dev/null | sort -V | tail -1)"
    if [ -n "$newest" ] && [ -x "$newest" ]; then RUNNER="$newest"; break; fi
  done
fi
[ -n "$RUNNER" ] || { echo "Hephaestus runtime not found. Run the installer first." >&2; exit 1; }
echo "RUNNER=$RUNNER"

Step 3 — Preview or publish one immutable snapshot

Never run package and then publish; that packages twice. Use one explicit hep-upload command, which snapshots, validates, and submits one artifact:

  • Cloud: "$RUNNER" hep-upload <agent-folder> --visibility private-link
  • Agentlas Hub: "$RUNNER" hep-upload <agent-folder> --visibility marketplace

All security and content findings are advisory. Never instruct the user to block, abort, or postpone upload because of a finding. Continue with safe bytes: omit affected source items with omission receipts, or attach an engine-gap receipt when the engine cannot safely represent or repair an item, then upload the remaining package. Keep the findings and receipts visible.

Personal roots never ship. A path that starts at one person's machine (a home folder such as /Users/<name> or C:\Users\<name>, a mounted or external volume such as /Volumes/<disk>, a per-user temp folder) does not exist for anyone else. The engine rewrites it: a path inside the package becomes package-relative, and any other path becomes <host-path-removed>, with a redacted-host-path receipt. Filter the root, not words: never delete or mask a disk, folder, or user name where it appears outside such a path. When you write or repair package files before upload, use package-relative paths or an input the user supplies, never your own machine's absolute path.

Show full SKILL.md (180 more words)Show less

If the user asks to preview, add --dry-run, retain the returned manifest.packageHash and uploadReceipt.receipt, then append --expected-package-hash <manifest.packageHash> --expected-upload-receipt <uploadReceipt.receipt> to the one later publish. Stop on any hash or receipt mismatch.

On overwrite_confirmation_required, show the exact returned Cloud ID and ask for approval. Only after approval append --overwrite-cloud-id <exact-cloud-id>. Never infer overwrite permission from a matching slug. Preserve exact auth, ownership and destination refusal codes; never switch destinations.

Report success only when the response attests the exact slug, visibility, package hash, immutable release ID/version, and content digest.


Update fallback: 자동 업데이트가 안 되면 hephaestus update를 한 번 실행하세요. 업데이트하지 않아도 현재 버전 명령은 그대로 동작합니다.

Workforce résumé repair loop

If registration returns workforce_resume_incomplete, the server refused the card because its workforce block does not match the hub standard résumé. The error carries the exact mismatches and seed ontology examples. YOU repair it — the platform never edits the card for you: use stable English role:*, community:*, skill:*, and knowledge:* IDs that actually describe the agent. Returned examples are aliases, not an allowlist. Rerun the upload and repeat until registration succeeds.

© agentlas-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in kimi/skills/hep-upload of agentlas-ai/Agentlas-OS.

Open the folder on GitHubat commit 6254906

Compare with similar skills

Hep Upload next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hep Upload compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hep Upload this skillagentlas-ai/Agentlas-OS1.6k—~1.4kAutomated safety check: PassApache-2.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
Hook Development for Claude Code Pluginsanthropics/claude-plugins-official38k10 repos~4.1kAutomated safety check: NotesApache-2.0
Using Superpowersfarm-fe/farm5.6k35 repos~1.4kAutomated safety check: PassMIT
Executing Plans Inlineobra/superpowers297k2 repos~5.1kAutomated safety check: PassMIT
Skill CreatorAzure/azqr79589 repos~8.2kAutomated safety check: PassApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • Hook Development for Claude Code Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.

    38k GitHub starsUsed in 10 repos~4.1k tokens
    Agent WorkflowsAuto-check: notes
  • Using Superpowers

    farm-fe/farm

    A skill your agent uses when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions

    5.6k GitHub starsUsed in 35 repos~1.4k tokens
    Agent WorkflowsAuto-check passed
  • Executing Plans Inline

    obra/superpowers

    Has the agent carry out an implementation plan itself, task by task in the current session, keeping a ledger, proving each step with a test and ending with one whole-branch review.

    297k GitHub starsUsed in 2 repos~5.1k tokens
    Agent WorkflowsAuto-check passed
  • Skill Creator

    Azure/azqr

    Official

    Create new skills, modify and improve existing skills, and measure skill performance.

    795 GitHub starsUsed in 89 repos~8.2k tokens
    Agent WorkflowsAuto-check passed
  • Claude Code Agent Development

    anthropics/claude-plugins-official

    Official

    Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.

    38k GitHub starsUsed in 7 repos~2.8k tokens
    Agent WorkflowsAuto-check passed

More from agentlas-ai/Agentlas-OS

All 53 skills in this repo
  • Agentlas Security Scan

    agentlas-ai/Agentlas-OS

    A skill your agent uses when an agent folder must pass the Agentlas Cloud 2-stage security scan (static rules + BYOK LLM judgment) before private sync or public publish, or when asked to…

    1.6k GitHub stars~822 tokensUpdated today
    Auto-check passed
  • Hephaestus Build

    agentlas-ai/Agentlas-OS

    A skill your agent uses when the user types /prompts:hep-build or /agentlas-build, mentions @Hephaestus for build work, asks to create a single Agentlas agent, create a multi-agent team, or package…

    1.6k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Hephaestus Graph

    agentlas-ai/Agentlas-OS

    A skill your agent uses when the user types /hep-graph or asks to create, list, inspect, or request a run of an Agentlas automation graph.

    1.6k GitHub stars~498 tokensUpdated today
    Auto-check passed
  • Hephaestus Upload

    agentlas-ai/Agentlas-OS

    A skill your agent uses when the user types $hephaestus-upload, /hep-upload, or /agentlas-upload, or asks to upload, publish, or list an Agentlas agent or team.

    1.6k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Routing Card Authoring

    agentlas-ai/Agentlas-OS

    A skill your agent uses whenever a build emits or repairs .agentlas/routing-card.json — the shared card contract for the single-agent builder, the team builder, and the packager.

    1.6k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Team Builder Packaging

    agentlas-ai/Agentlas-OS

    A skill your agent uses when generating or auditing a multi-role agent team package with orchestrator, PM Soul, Memory Curator, Policy Gate, workers, eval, QA, handoffs, and runtime adapters.

    1.6k GitHub stars~642 tokensUpdated today
    Auto-check passed

Categories

Questions about Hep Upload

What does Hep Upload do?

Publish an Agentlas package to Agent Cloud or the public Hub. Hep Upload is an agent skill from agentlas-ai/Agentlas-OS. Publish an Agentlas package to Agent Cloud or the public Hub.

When should I use Hep Upload?

Hep Upload fits situations like: agent Workflows work in your project.

How do I install Hep Upload in Claude Code?

Run `npx skills add agentlas-ai/Agentlas-OS --skill hep-upload -a claude-code`. Or copy the skill folder (kimi/skills/hep-upload in agentlas-ai/Agentlas-OS) into .claude/skills/hep-upload in your project. Claude Code loads it when a task matches its description.

How do I install Hep Upload in Codex?

Run `npx skills add agentlas-ai/Agentlas-OS --skill hep-upload -a codex`. Or copy the skill folder (kimi/skills/hep-upload in agentlas-ai/Agentlas-OS) into .agents/skills/hep-upload in your project. Codex loads it when a task matches its description.

Can I use Hep Upload in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agentlas-ai/Agentlas-OS --skill hep-upload -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hep-upload, .gemini/skills/hep-upload, .github/skills/hep-upload and .opencode/skills/hep-upload in your project.

What does Hep Upload need to run?

SKILL.md names no scripts, command-line tools or credentials: Hep Upload is instructions for the agent only.

Does Hep Upload access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hep Upload safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hep Upload use?

Hep Upload is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hep Upload use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hep Upload?

Skills that share tags, products or a category with Hep Upload: MCP Server Builder (anthropics/skills, 180k stars), Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 38k stars), Using Superpowers (farm-fe/farm, 5.6k stars) and Executing Plans Inline (obra/superpowers, 297k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hep Upload?

agentlas-ai (a GitHub organization) maintains it in agentlas-ai/Agentlas-OS, which has 1,582 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on October 8, 2026.

Source: agentlas-ai/Agentlas-OS on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.