Agent skill

Openart

by AI45Lab in AI45Lab/OpenART

Guide an OpenART agent or contributor through planning, running, extending, and debugging the framework.

AGPL-3.0Auto-check: notesSecurity

Install Openart

skills CLI
$ npx skills add AI45Lab/OpenART --skill openart -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install AI45Lab/OpenART openart --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/AI45Lab/OpenART.git skills-src && mkdir -p .claude/skills && cp -r skills-src/OpenART/skills/openart .claude/skills/openart && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
openart
GitHub stars
231
Token cost
~918 tokens
SKILL.md length
390 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Guide an OpenART agent or contributor through planning, running, extending, and debugging the framework.

  • Works in 6 steps: Confirm the repository root and inspect… → Read the route-specific document and… → Prefer the smallest config-driven… → …
  • Tasks that involve Prompt injection and agent security
  • SKILL.md covers Route the request, Standard workflow, Planner and corpus guidance and Tool and target boundary, plus 1 more section
  • Calls python and git; needs OPENART_PLANNER_API_KEY

What it does

Openart is an agent skill from AI45Lab/OpenART. Guide an OpenART agent or contributor through planning, running, extending, and debugging the framework.

Its SKILL.md is about 920 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Prompt injection and agent security, Red teaming and adversary simulation and Debugging. It works with Docker and Python. The repository describes itself as: OpenART is an open-source framework designed to evaluate the safety and robustness of autonomous AI agents in dynamic, long-horizon, and stateful environments. It stress-tests… The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve Prompt injection and agent security
  • Tasks that involve Red teaming and adversary simulation
  • Tasks that involve Debugging

Example prompts

  • “/openart”

Requirements

  • Python 3
  • Docker
  • A credential in OPENART_PLANNER_API_KEY

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Confirm the repository root and inspect git status before editing.
  2. Read the route-specific document and inspect existing configs/artifacts.
  3. Prefer the smallest config-driven change; avoid duplicating taxonomy or
  4. Run a local or single-scenario smoke check before a batch or Docker launch.
  5. Validate the generated task, scenario, tool selection, and safety contract.
  6. Preserve the output directory, validation report, and failure artifacts.

What it can do on your machine

Read from SKILL.md and the folder at commit 1f7e138. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENART_PLANNER_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Openart loads about 918 tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 390 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~918

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:42
    dentials, endpoint, and model belong in `.env` or the shell through

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from AI45Lab/OpenART at commit 1f7e138, republished under its AGPL-3.0 licence (© AI45Lab). 390 words, ~918 tokens.

Download SKILL.mdSave it as .claude/skills/openart/SKILL.md (or your agent's skills folder).
name
openart
description
Guide an OpenART agent or contributor through planning, running, extending, and debugging the framework.
metadata.scope
operator
metadata.version
1.0.0
metadata.audiences
agent, human

OpenART guide

Use this skill when a request concerns the OpenART benchmark, planner, scenario generation, managed tools, target/attacker runs, evaluation, or framework development. This is the single operator entry point; do not create separate skills for each workflow. It is guidance for work on OpenART, not a target-visible skill, attacker payload, or authorization to run commands.

Route the request

IntentRead firstTypical entry point
Understand the frameworkdocs/00_overview.mdInspect the relevant component and task bundle
Generate a task from a scenariodocs/12_planner_design_implementation_usage.mdpython -m framework.planner.cli ...
Expand or inspect scenario seedsframework/planner/scenarios.pypython scripts/planner.py scenarios ...
Run or compare evaluationsdocs/09_evaluation_and_outputs.mdpython -m framework.cli run ...
Add or select a managed tooldocs/07_capabilities_tools_mcp.mdInspect ../openart-tools/ and tool_use_graph.json
Extend the frameworkdocs/10_extension_guides.mdPrefer a config-driven change
Diagnose a failuredocs/11_debugging_and_testing.mdInspect logs, prepared artifacts, and focused tests

Standard workflow

  1. Confirm the repository root and inspect git status before editing.
  2. Read the route-specific document and inspect existing configs/artifacts.
  3. Prefer the smallest config-driven change; avoid duplicating taxonomy or command behavior in this skill.
  4. Run a local or single-scenario smoke check before a batch or Docker launch.
  5. Validate the generated task, scenario, tool selection, and safety contract.
  6. Preserve the output directory, validation report, and failure artifacts.
Show full SKILL.md (184 more words)Show less

Planner and corpus guidance

Planner credentials, endpoint, and model belong in .env or the shell through OPENART_PLANNER_API_KEY, OPENART_PLANNER_BASE_URL, and OPENART_PLANNER_MODEL. Use the approved model configured by the repository (for example glm-5.3-flash) rather than hard-coding a model in generated tasks or this skill. Keep the planner tool store explicit with --tool-store and keep output directories separate for independent runs.

For scenario or corpus changes, preserve the repository's scenario schema and coverage metadata. Do not silently overwrite an existing corpus; use a new output directory or an explicit, reviewed continuation plan.

Tool and target boundary

Managed tool guides under ../openart-tools/ describe capabilities available to a runtime agent. Target-native skills and attacker output are controlled by task configuration and vector_permissions. Never copy this operator guide into a target workspace, tool_guide.md, or an attacker-controlled surface.

Safety and authorization

This skill explains what to inspect and which existing entry point to use. It does not authorize Docker launches, external service calls, large paid planner batches, destructive cleanup, repository resets, or pushes. Ask for explicit confirmation before those actions. Keep secrets out of Markdown, logs, task bundles, and committed configuration.

© AI45Lab, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in OpenART/skills/openart of AI45Lab/OpenART.

Open the folder on GitHubat commit 1f7e138

Compare with similar skills

Openart next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Openart compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Openart this skillAI45Lab/OpenART231—~918Automated safety check: NotesAGPL-3.0
Console AgentLeoYeAI/openclaw-master-skills2.2k—~4.1kAutomated safety check: PassMIT
Debugguardana/guardana129—~933Automated safety check: PassApache-2.0
Burla Parallel Dev ClustersBurla-Cloud/burla263—~1.6kAutomated safety check: PassCustom licence
Zizkadb Dev SetupZIZKA-AI-SL/ZizkaDB123—~535Automated safety check: NotesCustom licence
Awf Debug Toolsgithub/gh-aw-firewall148—~2.6kAutomated safety check: NotesMIT

Similar skills

  • Console Agent

    LeoYeAI/openclaw-master-skills

    Build AI agents with console.agent() - the jQuery of AI Agents.

    2.2k GitHub stars~4.1k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Debug

    guardana/guardana

    Systematic diagnosis of a red test, a rule that fires or stays silent wrongly, a scan or probe whose artifact looks wrong, a collector error, a red CI run or a gate that is green for the wrong reason.

    129 GitHub stars~933 tokensUpdated yesterday
    SecurityAuto-check passed
  • Sets up an isolated Burla dev cluster per git worktree so several agents can work in parallel, and explains when to use local-dev or remote-dev.

    263 GitHub stars~1.6k tokensUpdated 16 days ago
    DevelopmentAuto-check passed
  • Zizkadb Dev Setup

    ZIZKA-AI-SL/ZizkaDB

    Set up and start the local ZizkaDB development stack. An agent skill from ZIZKA-AI-SL/ZizkaDB.

    123 GitHub stars~535 tokensUpdated 2 days ago
    DevelopmentAuto-check: notes
  • Awf Debug Tools

    github/gh-aw-firewall

    Official

    Practical Python scripts for debugging awf - parse logs, diagnose issues, inspect containers, test domains

    148 GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check: notes
  • Burla Internals Deep Dive

    Burla-Cloud/burla

    Reference for Burla internals: how a remote_parallel_map job flows between services, how clusters and nodes are managed, and where the head keeps its state.

    263 GitHub stars~2.4k tokensUpdated 16 days ago
    DevelopmentAuto-check passed

Works with

Questions about Openart

What does Openart do?

Guide an OpenART agent or contributor through planning, running, extending, and debugging the framework. Openart is an agent skill from AI45Lab/OpenART. Guide an OpenART agent or contributor through planning, running, extending, and debugging the framework.

When should I use Openart?

Openart fits situations like: tasks that involve Prompt injection and agent security; tasks that involve Red teaming and adversary simulation; tasks that involve Debugging.

How do I install Openart in Claude Code?

Run `npx skills add AI45Lab/OpenART --skill openart -a claude-code`. Or copy the skill folder (OpenART/skills/openart in AI45Lab/OpenART) into .claude/skills/openart in your project. Claude Code loads it when a task matches its description.

How do I install Openart in Codex?

Run `npx skills add AI45Lab/OpenART --skill openart -a codex`. Or copy the skill folder (OpenART/skills/openart in AI45Lab/OpenART) into .agents/skills/openart in your project. Codex loads it when a task matches its description.

Can I use Openart in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AI45Lab/OpenART --skill openart -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openart, .gemini/skills/openart, .github/skills/openart and .opencode/skills/openart in your project.

What does Openart need to run?

Going by SKILL.md and its folder, Openart needs the command-line tools its instructions call (python and git) and credentials named OPENART_PLANNER_API_KEY. Our summary lists: Python 3; Docker; A credential in OPENART_PLANNER_API_KEY.

Does Openart access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Openart safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Openart use?

Openart is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Openart use?

About 918 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Openart?

Skills that share tags, products or a category with Openart: Console Agent (LeoYeAI/openclaw-master-skills, 2.2k stars), Debug (guardana/guardana, 129 stars), Burla Parallel Dev Clusters (Burla-Cloud/burla, 263 stars) and Zizkadb Dev Setup (ZIZKA-AI-SL/ZizkaDB, 123 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Openart?

AI45Lab (a GitHub organization) maintains it in AI45Lab/OpenART, which has 231 GitHub stars. The repository was last updated on October 3, 2026.

Source: AI45Lab/OpenART on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.