Update Provider Deps
mondoohq/mql
Upgrade an mql provider's vendored SDKs (all providers or a named subset), audit the new versions for breaking changes and fix call sites while keeping shipped MQL fields backwards-compatible, check…
Add or change a patch in packages/<pkg/patches/ to correct a distilled SDK's upstream spec — a missing error response or typed error (status, code, message, body or header matchers), a field that…
$ npx skills add alchemy-run/distilled --skill distilled-sdk-patch -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install alchemy-run/distilled distilled-sdk-patch --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/alchemy-run/distilled.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/distilled-sdk-patch .claude/skills/distilled-sdk-patch && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "distilled-sdk-patch" agent skill from https://github.com/alchemy-run/distilled/tree/main/.agents/skills/distilled-sdk-patch into .claude/skills/distilled-sdk-patch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "distilled-sdk-patch", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/alchemy-run/distilled/tree/main/.agents/skills/distilled-sdk-patchType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add alchemy-run/distilled --skill distilled-sdk-patch -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install alchemy-run/distilled distilled-sdk-patch --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alchemy-run/distilled.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/distilled-sdk-patch .agents/skills/distilled-sdk-patch && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "distilled-sdk-patch" agent skill from https://github.com/alchemy-run/distilled/tree/main/.agents/skills/distilled-sdk-patch into .agents/skills/distilled-sdk-patch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "distilled-sdk-patch", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alchemy-run/distilled --skill distilled-sdk-patch -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install alchemy-run/distilled distilled-sdk-patch --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alchemy-run/distilled.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/distilled-sdk-patch .cursor/skills/distilled-sdk-patch && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "distilled-sdk-patch" agent skill from https://github.com/alchemy-run/distilled/tree/main/.agents/skills/distilled-sdk-patch into .cursor/skills/distilled-sdk-patch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "distilled-sdk-patch", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/alchemy-run/distilled.git --path .agents/skills/distilled-sdk-patch--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add alchemy-run/distilled --skill distilled-sdk-patch -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install alchemy-run/distilled distilled-sdk-patch --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alchemy-run/distilled.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/distilled-sdk-patch .gemini/skills/distilled-sdk-patch && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "distilled-sdk-patch" agent skill from https://github.com/alchemy-run/distilled/tree/main/.agents/skills/distilled-sdk-patch into .gemini/skills/distilled-sdk-patch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "distilled-sdk-patch", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install alchemy-run/distilled distilled-sdk-patchInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add alchemy-run/distilled --skill distilled-sdk-patch -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/alchemy-run/distilled.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/distilled-sdk-patch .github/skills/distilled-sdk-patch && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "distilled-sdk-patch" agent skill from https://github.com/alchemy-run/distilled/tree/main/.agents/skills/distilled-sdk-patch into .github/skills/distilled-sdk-patch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "distilled-sdk-patch", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alchemy-run/distilled --skill distilled-sdk-patch -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install alchemy-run/distilled distilled-sdk-patch --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alchemy-run/distilled.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/distilled-sdk-patch .opencode/skills/distilled-sdk-patch && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "distilled-sdk-patch" agent skill from https://github.com/alchemy-run/distilled/tree/main/.agents/skills/distilled-sdk-patch into .opencode/skills/distilled-sdk-patch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "distilled-sdk-patch", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
distilled-sdk-patchAdd or change a patch in packages/<pkg/patches/ to correct a distilled SDK's upstream spec — a missing error response or typed error (status, code, message, body or header matchers), a field that…
Distilled SDK Patch is an agent skill from alchemy-run/distilled. Add or change a patch in packages/<pkg/patches/ to correct a distilled SDK's upstream spec — a missing error response or typed error (status, code, message, body or header matchers), a field that should be nullable or optional, a secret with no sensitive mark, a wrong response schema, or a shared model that needs splitting — then regenerate and read the generated diff to confirm it changes exactly what the patch says. Also for merging, slimming or rebasing an existing patch PR. Use for "patch <pkg", "type this…
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It works with Amazon Web Services and Cloudflare. The repository describes itself as: Effect-native SDKs for cloud providers. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 45d4da4. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Distilled SDK Patch loads about 2.6k tokens when it runs. Until then it costs about 182 tokens; SKILL.md has 1,241 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from alchemy-run/distilled at commit 45d4da4, republished under its Apache-2.0 licence (© alchemy-run). 1,241 words, ~2,554 tokens.
.claude/skills/distilled-sdk-patch/SKILL.md (or your agent's skills folder).A patch is a claim that the upstream description is wrong about the wire.
It lives in packages/<pkg>/patches/ and is committed together with the
src/services/ it produces. A package applies patches at one of two
stages, set by distilled.patches in its package.json (engine:
packages/core/src/codegen/patches.ts):
convert, so .generated-specs/
is the patched model and is committed with the patch."distilled": { "patches": "generate" }, e.g. azure):
patches/<model>/*.json are Smithy ops the generator applies to the
unpatched .generated-specs/<model>.json. Regenerating is enough to land
a fix, and the audit needs no spec mirror. Prefer this stage for a
package whose patches are all Smithy pointers.How convert applies patches (OpenAPI pointers before convert,
Smithy pointers after, stale pointers fail the run, operation names are
operationNames in convert and never a patch) is in the distilled-sdk
skill, step 5.
Write down the request and the response before writing a patch: status, headers, body, and which operation. A patch built from reading the spec alone guesses at the wire, and a wrong patch is worse than none — it gives callers a type they trust.
| Package shape | Where the patch goes |
|---|---|
One OpenAPI spec (planetscale, neon) | flat patches/<topic>.patch.json |
Several specs in one package (fly-io, gcp, axiom) | a subdirectory per spec — whichever one the package's convert.ts passes as its patches dir (patches/machines/, patches/aiplatform_v1/, patches/v1-edge-ingest/) |
Generate stage (azure) | patches/<model>/<topic>.json, Smithy pointers only — <model> is the .generated-specs/<model>.json it patches |
| Cloudflare | patches/<service>/<operation>.json; error shapes shared by a service go once in patches/<service>/_errors.json |
| AWS | patches/<sdkId>.json — a typed config for applyAwsSpecPatches (errors, syntheticErrors, errorCategories, enums, …), not RFC-6902. Follow the neighbours. |
Read the package's existing patches first and extend the file that already
covers the same kind of fix: one file for every omitted error status, one
per shape family for nullability. A new file is for a new kind of fix.
Files apply in name order with *.manual.json last; a numbered prefix
(neon's 001-…) is only needed when one file builds on another.
Every file has a description that says what the spec gets wrong, what the
wire does instead, and where that was observed (with a date for live
probes). It is the bug report sent upstream, and it must stay true as the
file changes.
Patch the spec (/paths, /components, /definitions) when the fix is
something the spec's own language can say — a response status, nullable,
a required list, x-sensitive, a schema. The next spec update audits
these naturally: when upstream publishes the same fix, the patch stops
changing the model and pnpm patches:audit flags it.
Patch the Smithy model (/shapes/<namespace>#<Shape>) for what the
spec cannot say — mostly typed errors with matchers. Smithy shape names are
derived by convert (inline schemas become names like
PaginatedDatabaseDataItem), so open .generated-specs/<model>.json and
copy the exact id rather than guessing it.
Schemas the spec inlines are separate copies. A fix on
/definitions/ServiceToken does not reach the inlined item schema of
PaginatedServiceToken; patch each copy (the generated diff in step 5
shows every shape a patch touched, so missing copies are visible).
Undocumented error status that maps to a standard class. OpenAPI
convert turns 400/403/404/409/422 responses into BadRequest,
Forbidden, NotFound, Conflict and UnprocessableEntity, and treats
401/429/500/503 as global. Add the response to the spec:
{ "op": "add",
"path": "/paths/~1databases~1{id}/delete/responses/422",
"value": { "description": "Unprocessable Entity" } }Error that needs its own class — the status is shared by several
failures, the status is not in the map above, or the API reports failure
inside a 2xx. Add an error shape with matchers and append it to the
operation's errors:
{ "op": "add",
"path": "/shapes/com.flyio.machines#NetworkNotFound",
"value": {
"type": "structure",
"members": { "message": { "target": "smithy.api#String" } },
"traits": {
"smithy.api#error": "client",
"com.distilled.openapi#errorMatchers": [
{ "status": 400, "message": { "includes": "network not found" } }
] } } },
{ "op": "add",
"path": "/shapes/com.flyio.machines#CreateAppIPAssignment/errors/-",
"value": { "target": "com.flyio.machines#NetworkNotFound" } }generate.ts passes as
errorMatchersTrait (com.distilled.openapi#errorMatchers for OpenAPI
packages; com.cloudflare.protocols#…, com.gcp.protocols#… elsewhere).
A generator that sets none ignores matchers — check before relying on
them.code, status, message (exact string, or
{ includes } / { matches }), body (JSON pointer → scalar or text
matcher, e.g. { "/success": false }), and headers (name →
text matcher). The most specific match across the operation's classes
wins, one point per field, so a message matcher beats a bare status
matcher on the same status. Match on the stable part of the response — a
numeric code or an error type — before free text.BadRequestError, ServerError, RetryableError,
…) comes from smithy.api#httpError and smithy.api#retryable
(errorCategories in packages/core/src/codegen/generator.ts), and
retry policies act on those categories. Set them deliberately: a client
error that arrives as a 5xx should not be retried as a server error.Field is null or missing on the wire. In the spec:
x-nullable: true (Swagger 2.0), nullable: true (OpenAPI 3.0), or null
in the type array (3.1). Being nullable and being required are
independent: a field that is always present but sometimes null keeps its
required entry; a field that is sometimes absent leaves the required
list (a replace of the whole list — say which fields left in the
description).
Secret without a sensitive mark. x-sensitive: true on the string
property. Convert already marks names matching its default patterns
(password, api_token, plain_text, …; isSensitiveProperty in
packages/core/src/codegen/openapi.ts), so check the generated type is not
already Redacted before adding one.
One operation returns more than the shared schema promises. Copy the
schema to a new name, change the copy, and re-point only that operation's
response — the PlanetScale password-with-secret patch gives create and
renew a plain_text that is never null while get and list keep the shared
nullable one. A response schema that is simply wrong gets its $ref
replaced.
pnpm generate <pkg>Always regenerate with pnpm generate <pkg>, even for one service. It
converts, generates and formats; a bare convert (with or without
--resource) leaves .generated-specs/ unformatted, and the diff then
shows every file as changed.
Do not add a per-package test for the patch. The generated diff in the next
step shows what the patch changes, and the behaviour it relies on (error
matchers, nullability, sensitive members) is tested once in
packages/core. When updating an existing patch PR that added one, delete
that test in the same update.
git diff origin/main -- packages/<pkg>/.generated-specs packages/<pkg>/src/servicesDiff against origin/main so a patch already committed on a PR branch
still shows up. Read the diff against the description:
Do not run pnpm patches:audit here. A patch is written to change the
model, and the diff above already shows whether it did. The audit rebuilds
the whole model once per patch file (minutes for cloudflare) and only
answers a question once the spec has moved underneath existing patches.
That is the distilled-sdk-update skill's job.
Then check the generated TypeScript reads the way a caller needs, run
pnpm exec tsc -b packages/<pkg> --noCheck false, and commit the patch
with the src/services/ it produced (and .generated-specs/ for a
convert-stage package), as
fix(<pkg>): … naming what callers gain ("type 422s observed on the live
API").
© alchemy-run, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/distilled-sdk-patch of alchemy-run/distilled.
Open the folder on GitHubat commit 45d4da4
Distilled SDK Patch next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Distilled SDK Patch this skillalchemy-run/distilled | 431 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| Update Provider Depsmondoohq/mql | 411 | — | ~4.5k | Automated safety check: Pass | Custom licence | |
| Deploy AstermemAsterove/AsterMem | 161 | — | ~3.2k | Automated safety check: Warn | AGPL-3.0 | |
| Cloudflare R2einverne/dotfiles | 121 | — | ~2.8k | Automated safety check: Pass | GPL-3.0 | |
| Implementing Cloud Waf Rulesmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Detecting SQL Injection Via Waf Logsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~564 | Automated safety check: Pass | Apache-2.0 |
mondoohq/mql
Upgrade an mql provider's vendored SDKs (all providers or a named subset), audit the new versions for breaking changes and fix call sites while keeping shipped MQL fields backwards-compatible, check…
Asterove/AsterMem
Guide the user through taking AsterMem live — on a cloud server, or on a machine they already own (home NAS, Raspberry Pi, this computer) exposed through Cloudflare Tunnel with no public IP.
einverne/dotfiles
Guide for implementing Cloudflare R2 - S3-compatible object storage with zero egress fees.
mukul975/Anthropic-Cybersecurity-Skills
Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive…
mukul975/Anthropic-Cybersecurity-Skills
Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns.
olorehq/olore
Local opennext documentation reference (latest). An agent skill from olorehq/olore.
alchemy-run/distilled
Move an existing distilled SDK to its mirror's latest spec, regenerate it, audit packages/<pkg/patches/ with pnpm patches:audit and delete or slim the patches the new spec has absorbed, then open…
alchemy-run/distilled
Build or update a distilled SDK for an API provider — sourcing its OpenAPI/Smithy/GraphQL/discovery description, adding the spec mirror that feeds it, generating packages/<provider, listing it on…
Works with
Add or change a patch in packages/<pkg/patches/ to correct a distilled SDK's upstream spec — a missing error response or typed error (status, code, message, body or header matchers), a field that…. Distilled SDK Patch is an agent skill from alchemy-run/distilled. Add or change a patch in packages/<pkg/patches/ to correct a distilled SDK's upstream spec — a missing error response or typed error (status, code, message, body or header matchers), a field that should be nullable or optional, a secret with no sensitive mark, a wrong response schema, or a shared model that needs splitting — then regenerate and read the generated diff to confirm it changes exactly what the patch says.
Distilled SDK Patch fits situations like: type this error; this field is null on the wire; mark X sensitive; any fix that would otherwise be an edit to generated code.
Run `npx skills add alchemy-run/distilled --skill distilled-sdk-patch -a claude-code`. Or copy the skill folder (.agents/skills/distilled-sdk-patch in alchemy-run/distilled) into .claude/skills/distilled-sdk-patch in your project. Claude Code loads it when a task matches its description.
Run `npx skills add alchemy-run/distilled --skill distilled-sdk-patch -a codex`. Or copy the skill folder (.agents/skills/distilled-sdk-patch in alchemy-run/distilled) into .agents/skills/distilled-sdk-patch in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alchemy-run/distilled --skill distilled-sdk-patch -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/distilled-sdk-patch, .gemini/skills/distilled-sdk-patch, .github/skills/distilled-sdk-patch and .opencode/skills/distilled-sdk-patch in your project.
Going by SKILL.md and its folder, Distilled SDK Patch needs the command-line tools its instructions call (pnpm and git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Distilled SDK Patch is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Distilled SDK Patch: Update Provider Deps (mondoohq/mql, 411 stars), Deploy Astermem (Asterove/AsterMem, 161 stars), Cloudflare R2 (einverne/dotfiles, 121 stars) and Implementing Cloud Waf Rules (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
alchemy-run (a GitHub organization) maintains it in alchemy-run/distilled, which has 431 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.
Source: alchemy-run/distilled on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.