Agent skill

Fugu

by aigorahub in aigorahub/elves

Run a bounded Sakana Fugu repository task or explicit review through codex-fugu.

MITAuto-check: notesAgent Workflows

Install Fugu

skills CLI
$ npx skills add aigorahub/elves --skill fugu -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aigorahub/elves fugu --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aigorahub/elves.git skills-src && mkdir -p .claude/skills && cp -r skills-src/aliases/claude/fugu .claude/skills/fugu && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fugu
GitHub stars
222
Token cost
~1.2k tokens
SKILL.md length
632 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Run a bounded Sakana Fugu repository task or explicit review through codex-fugu.

  • Works in 6 steps: Host-native first if rg/git/gh can… → Task mode: planning (default) vs review… → Profile: use plain fugu/high by default.… → …
  • The user types /fugu
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Asks to use Fugu

What it does

Fugu is an agent skill from aigorahub/elves. Run a bounded Sakana Fugu repository task or explicit review through codex-fugu. Use when the user types /fugu, asks to use Fugu, or asks for a Fugu review.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows. The repository describes itself as: Autonomous multi-batch development skill for Claude Code and Codex. They work while you sleep. The licence is MIT.

When your agent uses it

  • The user types /fugu
  • Asks to use Fugu
  • Asks for a Fugu review

Example prompts

  • “/fugu”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Host-native first if rg/git/gh can finish in under a minute.
  2. Task mode: planning (default) vs review when the user asked for a review or audit.
  3. Profile: use plain fugu/high by default. Use --deep only when regular Fugu needs xhigh effort. The host may select --cyber only for…
  4. Write: Fugu is read-only. The runner rejects --write.
  5. Context: the isolation snapshot is always on. Put goal, paths, done-when, and out-of-scope in the
  6. Capture: redirect to a log file (never | tail / | head). Chat cancel does not stop the

What it can do on your machine

Read from SKILL.md and the folder at commit fba17a3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fugu loads about 1.2k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 632 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:43
    admitted and copied; both `.env.*` and `*.env` names are excluded. Live writable-state limits

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aigorahub/elves at commit fba17a3, republished under its MIT licence (© aigorahub). 632 words, ~1,222 tokens.

Download SKILL.mdSave it as .claude/skills/fugu/SKILL.md (or your agent's skills folder).
name
fugu
description
Run a bounded Sakana Fugu repository task or explicit review through codex-fugu. Use when the user types /fugu, asks to use Fugu, or asks for a Fugu review.
disable-model-invocation
true
<!-- elves-managed-alias: claude-skill-alias v1 -->

Fugu Planning or Review

This is the Elves-managed Claude Code alias for /fugu [--deep|--ultra|--max] [--max-wait SECONDS] [--preflight] [--include PATH] <planning-task> and /fugu [--deep|--cyber|--ultra|--max] [--max-wait SECONDS] [--preflight] review <scope>.

Load the installed elves skill's Provider shortcut protocols and references/provider-shortcuts.md. Resolve scripts/run_fugu.sh from the active Elves skill root, keep the target repository as the working directory, pass through the validated mode/profile/context, and run it.

Host Fugu routing (required when the user omits a profile flag). Natural language "use Fugu" or plain /fugu <task> uses bare fugu/high by default. Before launch, state one short Fugu route: … line. Explicit user flags always win. Profile locks model + effort.

  1. Host-native first if rg/git/gh can finish in under a minute.
  2. Task mode: planning (default) vs review <scope> when the user asked for a review or audit.
  3. Profile: use plain fugu/high by default. Use --deep only when regular Fugu needs xhigh effort. The host may select --cyber only for explicit security review or threat-model intent after a successful Cyber call in the current session. Only a user-explicit --cyber request may establish that proof. Otherwise, use regular Fugu. The user must explicitly select --ultra or --max.
  4. Write: Fugu is read-only. The runner rejects --write.
  5. Context: the isolation snapshot is always on. Put goal, paths, done-when, and out-of-scope in the task string. Add exact --include PATH only for non-gitignored files; if any include, run --preflight first and launch only when admitted. No separate "minimal snapshot" product.
  6. Capture: redirect to a log file (never | tail / | head). Chat cancel does not stop the provider; wait up to the wall or kill the process group. On timeout/crash, harvest any Fugu partial salvage markers before relaunch. Verify findings host-native and clean up leftover process groups (see references/fugu-calling-guide.md).

Full decision table, route templates, wait/poll contract, and field notes: references/provider-shortcuts.md (Host routing when the user says "use Fugu") and references/fugu-calling-guide.md.

Plain /fugu <task> is a read-only planning task whose answer follows the request; /fugu review <scope> is the opinionated read-only review. Exact includes must be admitted and copied; both .env.* and *.env names are excluded. Live writable-state limits tolerate benign disappearing temporary subtrees and fail closed on other audit errors. macOS read-only cleanup remains best-effort and never claims recursive containment. The Linux lane omits procfs and exposes only a synthetic /proc/self/exe link to the qualified real Codex binary.

Show full SKILL.md (244 more words)Show less

The runner uses the official codex-fugu launcher with policy-admitted tracked and non-ignored untracked context, closed interactive input, and a hard wall-clock bound. It selects regular fugu/high when the host chooses plain, fugu/xhigh with --deep, fugu-cyber/xhigh with --cyber, fugu-ultra-v2.0/high with --ultra (then fugu-ultra, then fugu-ultra-v1.1), or fugu-ultra-v1.1/max with --max. Regular/deep sessions are ephemeral; Ultra uses exact-session staged synthesis, with its state confined to the disposable isolated lane, events carried by a bounded host-owned pipe, final output pinned to a no-follow descriptor, and a final descriptor-safe writable-state audit after each settled phase. Do not replace it with an improvised API request or remove its sandbox and timeout controls.

Read-only review snapshots omit oversized binary media instead of failing the whole review. Video, audio, presentation, archive, image, font, and 3D binaries above the per-file limit are left out and listed in the context manifest with path, byte size, and reason; the 16 MiB per-file limit is not raised. Source, prose instructions, executable agent configuration, and --include paths still fail closed and ask for a derived text, image, or transcript artifact.

Fugu is optional. On any non-zero exit the runner prints one directive line naming the reason. A quota, authentication, catalog, runner, timeout, or provider failure all mean the same thing. Select another available independent reviewer instead of stopping, record requested route, actual route, and fallback reason, and do not claim a review ran when it did not: python3 "$ELVES_SKILL_ROOT/scripts/cobbler_agents.py" review-route --host claude-code --requested fugu --unavailable fugu=<reason> --json.

© aigorahub, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in aliases/claude/fugu of aigorahub/elves.

Open the folder on GitHubat commit fba17a3

Compare with similar skills

Fugu next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fugu compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fugu this skillaigorahub/elves222—~1.2kAutomated safety check: NotesMIT
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
Hook Development for Claude Code Pluginsanthropics/claude-plugins-official38k10 repos~4.1kAutomated safety check: NotesApache-2.0
Using Superpowersfarm-fe/farm5.6k35 repos~1.4kAutomated safety check: PassMIT
Executing Plans Inlineobra/superpowers297k2 repos~5.1kAutomated safety check: PassMIT
Skill CreatorAzure/azqr79589 repos~8.2kAutomated safety check: PassApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • Hook Development for Claude Code Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.

    38k GitHub starsUsed in 10 repos~4.1k tokens
    Agent WorkflowsAuto-check: notes
  • Using Superpowers

    farm-fe/farm

    A skill your agent uses when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions

    5.6k GitHub starsUsed in 35 repos~1.4k tokens
    Agent WorkflowsAuto-check passed
  • Executing Plans Inline

    obra/superpowers

    Has the agent carry out an implementation plan itself, task by task in the current session, keeping a ledger, proving each step with a test and ending with one whole-branch review.

    297k GitHub starsUsed in 2 repos~5.1k tokens
    Agent WorkflowsAuto-check passed
  • Skill Creator

    Azure/azqr

    Official

    Create new skills, modify and improve existing skills, and measure skill performance.

    795 GitHub starsUsed in 89 repos~8.2k tokens
    Agent WorkflowsAuto-check passed
  • Claude Code Agent Development

    anthropics/claude-plugins-official

    Official

    Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.

    38k GitHub starsUsed in 7 repos~2.8k tokens
    Agent WorkflowsAuto-check passed

More from aigorahub/elves

All 14 skills in this repo
  • Elves

    aigorahub/elves

    Autonomous multi-batch development agent for long unattended runs, reviewed-PR landing, Cobbler-first orchestration, and optional Fugu, Manus, Grok, Devin, or Oh My Pi (omp) provider shortcuts.

    222 GitHub stars~16k tokensUpdated 3 days ago
    Auto-check: notes
  • Omp

    aigorahub/elves

    Bounded Oh My Pi (omp) provider shortcut via Elves. An agent skill from aigorahub/elves.

    222 GitHub stars~509 tokensUpdated 3 days ago
    Auto-check passed
  • Setup Cobbler

    aigorahub/elves

    Configure Cobbler model routes and external-agent preferences for this checkout.

    222 GitHub stars~537 tokensUpdated 3 days ago
    Auto-check passed
  • Elves Grok Bot

    aigorahub/elves

    Unattended-run kernel for Grok Bot non-git work. An agent skill from aigorahub/elves.

    222 GitHub stars~914 tokensUpdated 3 days ago
    Auto-check passed
  • Cobbler Mode

    aigorahub/elves

    Turn on Elves Cobbler Mode for the current Claude Code thread.

    222 GitHub stars~439 tokensUpdated 3 days ago
    Auto-check passed
  • Grok

    aigorahub/elves

    Run a bounded-permission headless Grok Build task. An agent skill from aigorahub/elves.

    222 GitHub stars~766 tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Fugu

What does Fugu do?

Run a bounded Sakana Fugu repository task or explicit review through codex-fugu. Fugu is an agent skill from aigorahub/elves. Run a bounded Sakana Fugu repository task or explicit review through codex-fugu.

When should I use Fugu?

Fugu fits situations like: the user types /fugu; asks to use Fugu; asks for a Fugu review.

How do I install Fugu in Claude Code?

Run `npx skills add aigorahub/elves --skill fugu -a claude-code`. Or copy the skill folder (aliases/claude/fugu in aigorahub/elves) into .claude/skills/fugu in your project. Claude Code loads it when a task matches its description.

How do I install Fugu in Codex?

Run `npx skills add aigorahub/elves --skill fugu -a codex`. Or copy the skill folder (aliases/claude/fugu in aigorahub/elves) into .agents/skills/fugu in your project. Codex loads it when a task matches its description.

Can I use Fugu in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aigorahub/elves --skill fugu -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fugu, .gemini/skills/fugu, .github/skills/fugu and .opencode/skills/fugu in your project.

What does Fugu need to run?

SKILL.md names no scripts, command-line tools or credentials: Fugu is instructions for the agent only. Our summary lists: Python 3.

Does Fugu access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Fugu safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Fugu use?

Fugu is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fugu use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fugu?

Skills that share tags, products or a category with Fugu: MCP Server Builder (anthropics/skills, 180k stars), Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 38k stars), Using Superpowers (farm-fe/farm, 5.6k stars) and Executing Plans Inline (obra/superpowers, 297k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fugu?

aigorahub (a GitHub organization) maintains it in aigorahub/elves, which has 222 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 6, 2026.

Source: aigorahub/elves on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.