Agent skill

Hephaestus Upload

by agentlas-ai in agentlas-ai/Agentlas-OS

A skill your agent uses when the user types $hephaestus-upload, /hep-upload, or /agentlas-upload, or asks to upload, publish, or list an Agentlas agent or team.

Apache-2.0Auto-check passedAgent Workflows

Install Hephaestus Upload

skills CLI
$ npx skills add agentlas-ai/Agentlas-OS --skill hephaestus-upload -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agentlas-ai/Agentlas-OS hephaestus-upload --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agentlas-ai/Agentlas-OS.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hephaestus-upload .claude/skills/hephaestus-upload && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hephaestus-upload
GitHub stars
1.6k
Token cost
~1.3k tokens
SKILL.md length
660 words
Files
1
Skills in repo
53
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user types $hephaestus-upload, /hep-upload, or /agentlas-upload, or asks to upload, publish, or list an Agentlas agent or team.

  • Works in 7 steps: Ask the destination first — always → Public Hub publishing is free → Resolve the runner in this host → …
  • The user types $hephaestus-upload
  • SKILL.md covers 1. Ask the destination first —…, 2. Public Hub publishing is free, 3. Resolve the runner in this… and 4. Use one immutable upload gate, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Hephaestus Upload is an agent skill from agentlas-ai/Agentlas-OS. Use when the user types $hephaestus-upload, /hep-upload, or /agentlas-upload, or asks to upload, publish, or list an Agentlas agent or team. Ask Cloud (private) vs Agentlas Hub (public) FIRST, then publish through the bundled Hephaestus gate.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows. The repository describes itself as: Agent OS: keep specialist agents in a hub, spin up a temporary orchestrator per task. Local-first, works with any model. The licence is Apache-2.0.

When your agent uses it

  • The user types $hephaestus-upload
  • /agentlas-upload
  • List an Agentlas agent

Example prompts

  • “/hephaestus-upload”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Ask the destination first — always
  2. Public Hub publishing is free
  3. Resolve the runner in this host
  4. Use one immutable upload gate
  5. Publish once, optionally pinned to the preview
  6. Workforce résumé repair loop
  7. Report honestly

What it can do on your machine

Read from SKILL.md and the folder at commit 6254906. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hephaestus Upload loads about 1.3k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 660 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agentlas-ai/Agentlas-OS at commit 6254906, republished under its Apache-2.0 licence (© agentlas-ai). 660 words, ~1,335 tokens.

Download SKILL.mdSave it as .claude/skills/hephaestus-upload/SKILL.md (or your agent's skills folder).
name
hephaestus-upload
description
Use when the user types $hephaestus-upload, /hep-upload, or /agentlas-upload, or asks to upload, publish, or list an Agentlas agent or team. Ask Cloud (private) vs Agentlas Hub (public) FIRST, then publish through the bundled Hephaestus gate.

Hephaestus Upload (Cloud or Agentlas Hub)

Publish a finished Agentlas package. This is a WRITE surface: a Hub upload is public and other people can borrow it, so the destination question comes before any packaging or API call.

Upload is deliberately NOT folded into /hep-network. Network staffs a roster (a read), upload publishes an artifact (a write that is hard to take back); merging them would let "find me an agent" end in an accidental publish.

1. Ask the destination first — always

Ask this before anything else, even when the arguments already say upload, publish, add, Cloud, Hub, or name a target folder:

text
Cloud에 업로드할까요? 다른 사람들은 볼 수 없어요.
Upload to Cloud? Other people cannot see it.

Agentlas Hub에 업로드할까요? 다른 사람들이 빌려 쓸 수 있어요.
Upload to Agentlas Hub? Other people can borrow it.

Do not package, publish, register, add-source, reindex, or call any upload API until the user answers Cloud or Agentlas Hub. If the destination is answered but the target folder is ambiguous, ask for the exact agent folder before running anything.

2. Public Hub publishing is free

The public Hub is an agent community. Do not ask for an upload price, invoke a price-setting tool, or pass the retired --rent-credits, --ingest-credits, or --fork-credits flags. The CLI rejects those legacy flags. The creator's model and API prerequisites still belong in the package guide.

3. Resolve the runner in this host

Run the preflight inside this host app; never ask the user to open a separate terminal.

bash
RUNNER=""
for candidate in "$HOME/.agentlas/runtime/current/bin/hephaestus" "./bin/hephaestus"; do
  [ -x "$candidate" ] && RUNNER="$candidate" && break
done
[ -n "$RUNNER" ] || { echo "Hephaestus runtime not found. Run the installer first." >&2; exit 1; }

4. Use one immutable upload gate

Do not run package and then publish: that packages twice and the second artifact may differ from the one reviewed. The upload gate copies the selected folder into a private, link-free snapshot, repairs and validates that snapshot once, and either dry-runs or submits those exact bytes.

If the user requests a preview, run exactly one dry-run and retain the returned manifest.packageHash and uploadReceipt.receipt:

  • Cloud: "$RUNNER" hep-upload <agent-folder> --visibility private-link --dry-run
  • Agentlas Hub: "$RUNNER" hep-upload <agent-folder> --visibility marketplace --dry-run

All security and content findings are advisory. Never instruct the user to block, abort, or postpone an upload because of a finding. Continue the same upload with safe bytes: omit each affected source item and bind an omission receipt, or record an engine-gap receipt when the current engine cannot safely represent or repair it, then submit the remaining package. Keep every finding and omission visible in the result. The gate also repairs what it can derive from the package — including the entity type: a card that claims agent while the package ships a multi-node roster is corrected to team, so the release is executed as the team it actually is.

Show full SKILL.md (249 more words)Show less

5. Publish once, optionally pinned to the preview

  • Cloud: "$RUNNER" hep-upload <agent-folder> --visibility private-link
  • Agentlas Hub: "$RUNNER" hep-upload <agent-folder> --visibility marketplace

After a dry-run, append both --expected-package-hash <manifest.packageHash> and --expected-upload-receipt <uploadReceipt.receipt> to the one publish command. The receipt binds the exact hash, visibility, slug, and destination. Stop on package_hash_mismatch, upload_receipt_required, or upload_receipt_mismatch; never silently publish a replacement artifact or switch an approved private preview to the public Hub.

If registration returns overwrite_confirmation_required, show the exact server-reported Cloud ID and ask for overwrite approval. Only after approval, rerun the same pinned command with --overwrite-cloud-id <exact-cloud-id>. Never infer overwrite permission from a matching slug.

Surface authentication and entitlement codes exactly (sign_in_required, auth_unavailable, owner_only). Do not replace a failed Hub destination with Cloud or vice versa.

6. Workforce résumé repair loop

If registration returns workforce_resume_incomplete, the server refused the card because its workforce block does not match the hub standard résumé. The error carries the exact mismatches and seed ontology examples. YOU repair it — the platform never edits the card for you: use stable English role:*, community:*, skill:*, and knowledge:* IDs that actually describe the agent. The returned examples are aliases, not an allowlist. Rerun the upload and repeat until registration succeeds.

7. Report honestly

Report published only when the response attests the exact slug, visibility, package hash, immutable release ID/version, and content digest. Say which destination it went to. Otherwise report the last true state and the server's exact refusal code. Do not relabel an advisory finding as an upload block.

© agentlas-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hephaestus-upload of agentlas-ai/Agentlas-OS.

Open the folder on GitHubat commit 6254906

Compare with similar skills

Hephaestus Upload next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hephaestus Upload compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hephaestus Upload this skillagentlas-ai/Agentlas-OS1.6k—~1.3kAutomated safety check: PassApache-2.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
Hook Development for Claude Code Pluginsanthropics/claude-plugins-official38k10 repos~4.1kAutomated safety check: NotesApache-2.0
Using Superpowersfarm-fe/farm5.6k35 repos~1.4kAutomated safety check: PassMIT
Executing Plans Inlineobra/superpowers297k2 repos~5.1kAutomated safety check: PassMIT
Skill CreatorAzure/azqr79589 repos~8.2kAutomated safety check: PassApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • Hook Development for Claude Code Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.

    38k GitHub starsUsed in 10 repos~4.1k tokens
    Agent WorkflowsAuto-check: notes
  • Using Superpowers

    farm-fe/farm

    A skill your agent uses when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions

    5.6k GitHub starsUsed in 35 repos~1.4k tokens
    Agent WorkflowsAuto-check passed
  • Executing Plans Inline

    obra/superpowers

    Has the agent carry out an implementation plan itself, task by task in the current session, keeping a ledger, proving each step with a test and ending with one whole-branch review.

    297k GitHub starsUsed in 2 repos~5.1k tokens
    Agent WorkflowsAuto-check passed
  • Skill Creator

    Azure/azqr

    Official

    Create new skills, modify and improve existing skills, and measure skill performance.

    795 GitHub starsUsed in 89 repos~8.2k tokens
    Agent WorkflowsAuto-check passed
  • Claude Code Agent Development

    anthropics/claude-plugins-official

    Official

    Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.

    38k GitHub starsUsed in 7 repos~2.8k tokens
    Agent WorkflowsAuto-check passed

More from agentlas-ai/Agentlas-OS

All 53 skills in this repo
  • Agentlas Security Scan

    agentlas-ai/Agentlas-OS

    A skill your agent uses when an agent folder must pass the Agentlas Cloud 2-stage security scan (static rules + BYOK LLM judgment) before private sync or public publish, or when asked to…

    1.6k GitHub stars~822 tokensUpdated yesterday
    Auto-check passed
  • Hephaestus Build

    agentlas-ai/Agentlas-OS

    A skill your agent uses when the user types /prompts:hep-build or /agentlas-build, mentions @Hephaestus for build work, asks to create a single Agentlas agent, create a multi-agent team, or package…

    1.6k GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Hephaestus Graph

    agentlas-ai/Agentlas-OS

    A skill your agent uses when the user types /hep-graph or asks to create, list, inspect, or request a run of an Agentlas automation graph.

    1.6k GitHub stars~498 tokensUpdated yesterday
    Auto-check passed
  • Routing Card Authoring

    agentlas-ai/Agentlas-OS

    A skill your agent uses whenever a build emits or repairs .agentlas/routing-card.json — the shared card contract for the single-agent builder, the team builder, and the packager.

    1.6k GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Team Builder Packaging

    agentlas-ai/Agentlas-OS

    A skill your agent uses when generating or auditing a multi-role agent team package with orchestrator, PM Soul, Memory Curator, Policy Gate, workers, eval, QA, handoffs, and runtime adapters.

    1.6k GitHub stars~642 tokensUpdated yesterday
    Auto-check passed
  • Hephaestus Network

    agentlas-ai/Agentlas-OS

    A skill your agent uses when the user types $hephaestus-network, /hep-network, or /agentlas-network, mentions @Hephaestus, or asks Agentlas to staff a durable goal from registered Local, owner…

    1.6k GitHub stars~5.8k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Hephaestus Upload

What does Hephaestus Upload do?

A skill your agent uses when the user types $hephaestus-upload, /hep-upload, or /agentlas-upload, or asks to upload, publish, or list an Agentlas agent or team. Hephaestus Upload is an agent skill from agentlas-ai/Agentlas-OS. Use when the user types $hephaestus-upload, /hep-upload, or /agentlas-upload, or asks to upload, publish, or list an Agentlas agent or team.

When should I use Hephaestus Upload?

Hephaestus Upload fits situations like: the user types $hephaestus-upload; /agentlas-upload; list an Agentlas agent.

How do I install Hephaestus Upload in Claude Code?

Run `npx skills add agentlas-ai/Agentlas-OS --skill hephaestus-upload -a claude-code`. Or copy the skill folder (skills/hephaestus-upload in agentlas-ai/Agentlas-OS) into .claude/skills/hephaestus-upload in your project. Claude Code loads it when a task matches its description.

How do I install Hephaestus Upload in Codex?

Run `npx skills add agentlas-ai/Agentlas-OS --skill hephaestus-upload -a codex`. Or copy the skill folder (skills/hephaestus-upload in agentlas-ai/Agentlas-OS) into .agents/skills/hephaestus-upload in your project. Codex loads it when a task matches its description.

Can I use Hephaestus Upload in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agentlas-ai/Agentlas-OS --skill hephaestus-upload -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hephaestus-upload, .gemini/skills/hephaestus-upload, .github/skills/hephaestus-upload and .opencode/skills/hephaestus-upload in your project.

What does Hephaestus Upload need to run?

SKILL.md names no scripts, command-line tools or credentials: Hephaestus Upload is instructions for the agent only.

Does Hephaestus Upload access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hephaestus Upload safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hephaestus Upload use?

Hephaestus Upload is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hephaestus Upload use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hephaestus Upload?

Skills that share tags, products or a category with Hephaestus Upload: MCP Server Builder (anthropics/skills, 180k stars), Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 38k stars), Using Superpowers (farm-fe/farm, 5.6k stars) and Executing Plans Inline (obra/superpowers, 297k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hephaestus Upload?

agentlas-ai (a GitHub organization) maintains it in agentlas-ai/Agentlas-OS, which has 1,582 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on October 8, 2026.

Source: agentlas-ai/Agentlas-OS on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.