Agent skill

Distilled SDK Patch

by alchemy-run in alchemy-run/distilled

Add or change a patch in packages/<pkg/patches/ to correct a distilled SDK's upstream spec — a missing error response or typed error (status, code, message, body or header matchers), a field that…

Apache-2.0Auto-check passed

Install Distilled SDK Patch

skills CLI
$ npx skills add alchemy-run/distilled --skill distilled-sdk-patch -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alchemy-run/distilled distilled-sdk-patch --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alchemy-run/distilled.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/distilled-sdk-patch .claude/skills/distilled-sdk-patch && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
distilled-sdk-patch
GitHub stars
431
Token cost
~2.6k tokens
SKILL.md length
1,241 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
Apache-2.0

At a glance

Add or change a patch in packages/<pkg/patches/ to correct a distilled SDK's upstream spec — a missing error response or typed error (status, code, message, body or header matchers), a field that…

  • Works in 5 steps: have evidence → pick the file → pick the pointer → …
  • Type this error
  • SKILL.md covers Step 1 — have evidence, Step 2 — pick the file, Step 3 — pick the pointer and Recipes, plus 2 more sections
  • Calls pnpm and git

What it does

Distilled SDK Patch is an agent skill from alchemy-run/distilled. Add or change a patch in packages/<pkg/patches/ to correct a distilled SDK's upstream spec — a missing error response or typed error (status, code, message, body or header matchers), a field that should be nullable or optional, a secret with no sensitive mark, a wrong response schema, or a shared model that needs splitting — then regenerate and read the generated diff to confirm it changes exactly what the patch says. Also for merging, slimming or rebasing an existing patch PR. Use for "patch <pkg", "type this…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Amazon Web Services and Cloudflare. The repository describes itself as: Effect-native SDKs for cloud providers. The licence is Apache-2.0.

When your agent uses it

  • Type this error
  • This field is null on the wire
  • Mark X sensitive
  • Any fix that would otherwise be an edit to generated code

Example prompts

  • “patch <pkg”
  • “type this error”
  • “this field is null on the wire”
  • “/distilled-sdk-patch”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. have evidence
  2. pick the file
  3. pick the pointer
  4. regenerate
  5. check the change

What it can do on your machine

Read from SKILL.md and the folder at commit 45d4da4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Distilled SDK Patch loads about 2.6k tokens when it runs. Until then it costs about 182 tokens; SKILL.md has 1,241 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~182
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alchemy-run/distilled at commit 45d4da4, republished under its Apache-2.0 licence (© alchemy-run). 1,241 words, ~2,554 tokens.

Download SKILL.mdSave it as .claude/skills/distilled-sdk-patch/SKILL.md (or your agent's skills folder).
name
distilled-sdk-patch
description
Add or change a patch in packages/<pkg>/patches/ to correct a distilled SDK's upstream spec — a missing error response or typed error (status, code, message, body or header matchers), a field that should be nullable or optional, a secret with no sensitive mark, a wrong response schema, or a shared model that needs splitting — then regenerate and read the generated diff to confirm it changes exactly what the patch says. Also for merging, slimming or rebasing an existing patch PR. Use for "patch <pkg>", "type this error", "this field is null on the wire", "mark X sensitive", or any fix that would otherwise be an edit to generated code. Moving to a newer spec and pruning patches is distilled-sdk-update.

Patching a distilled SDK

A patch is a claim that the upstream description is wrong about the wire. It lives in packages/<pkg>/patches/ and is committed together with the src/services/ it produces. A package applies patches at one of two stages, set by distilled.patches in its package.json (engine: packages/core/src/codegen/patches.ts):

  • convert (the default): applied by convert, so .generated-specs/ is the patched model and is committed with the patch.
  • generate ("distilled": { "patches": "generate" }, e.g. azure): patches/<model>/*.json are Smithy ops the generator applies to the unpatched .generated-specs/<model>.json. Regenerating is enough to land a fix, and the audit needs no spec mirror. Prefer this stage for a package whose patches are all Smithy pointers.

How convert applies patches (OpenAPI pointers before convert, Smithy pointers after, stale pointers fail the run, operation names are operationNames in convert and never a patch) is in the distilled-sdk skill, step 5.

Step 1 — have evidence

Write down the request and the response before writing a patch: status, headers, body, and which operation. A patch built from reading the spec alone guesses at the wire, and a wrong patch is worse than none — it gives callers a type they trust.

  • A live call is best. Create throwaway resources, trigger the case, tear them down, and never print credentials.
  • An upstream error catalogue, a provider SDK's source, or an issue where someone pasted the response are acceptable; name the source in the description.
  • A probe that never reached the code path proves nothing: a 401 or a 404 on a dummy slug says nothing about what a real request returns.

Step 2 — pick the file

Package shapeWhere the patch goes
One OpenAPI spec (planetscale, neon)flat patches/<topic>.patch.json
Several specs in one package (fly-io, gcp, axiom)a subdirectory per spec — whichever one the package's convert.ts passes as its patches dir (patches/machines/, patches/aiplatform_v1/, patches/v1-edge-ingest/)
Generate stage (azure)patches/<model>/<topic>.json, Smithy pointers only — <model> is the .generated-specs/<model>.json it patches
Cloudflarepatches/<service>/<operation>.json; error shapes shared by a service go once in patches/<service>/_errors.json
AWSpatches/<sdkId>.json — a typed config for applyAwsSpecPatches (errors, syntheticErrors, errorCategories, enums, …), not RFC-6902. Follow the neighbours.

Read the package's existing patches first and extend the file that already covers the same kind of fix: one file for every omitted error status, one per shape family for nullability. A new file is for a new kind of fix. Files apply in name order with *.manual.json last; a numbered prefix (neon's 001-…) is only needed when one file builds on another.

Every file has a description that says what the spec gets wrong, what the wire does instead, and where that was observed (with a date for live probes). It is the bug report sent upstream, and it must stay true as the file changes.

Step 3 — pick the pointer

Patch the spec (/paths, /components, /definitions) when the fix is something the spec's own language can say — a response status, nullable, a required list, x-sensitive, a schema. The next spec update audits these naturally: when upstream publishes the same fix, the patch stops changing the model and pnpm patches:audit flags it.

Patch the Smithy model (/shapes/<namespace>#<Shape>) for what the spec cannot say — mostly typed errors with matchers. Smithy shape names are derived by convert (inline schemas become names like PaginatedDatabaseDataItem), so open .generated-specs/<model>.json and copy the exact id rather than guessing it.

Schemas the spec inlines are separate copies. A fix on /definitions/ServiceToken does not reach the inlined item schema of PaginatedServiceToken; patch each copy (the generated diff in step 5 shows every shape a patch touched, so missing copies are visible).

Show full SKILL.md (654 more words)Show less

Recipes

Undocumented error status that maps to a standard class. OpenAPI convert turns 400/403/404/409/422 responses into BadRequest, Forbidden, NotFound, Conflict and UnprocessableEntity, and treats 401/429/500/503 as global. Add the response to the spec:

json
{ "op": "add",
  "path": "/paths/~1databases~1{id}/delete/responses/422",
  "value": { "description": "Unprocessable Entity" } }

Error that needs its own class — the status is shared by several failures, the status is not in the map above, or the API reports failure inside a 2xx. Add an error shape with matchers and append it to the operation's errors:

json
{ "op": "add",
  "path": "/shapes/com.flyio.machines#NetworkNotFound",
  "value": {
    "type": "structure",
    "members": { "message": { "target": "smithy.api#String" } },
    "traits": {
      "smithy.api#error": "client",
      "com.distilled.openapi#errorMatchers": [
        { "status": 400, "message": { "includes": "network not found" } }
      ] } } },
{ "op": "add",
  "path": "/shapes/com.flyio.machines#CreateAppIPAssignment/errors/-",
  "value": { "target": "com.flyio.machines#NetworkNotFound" } }
  • The trait id is whatever the package's generate.ts passes as errorMatchersTrait (com.distilled.openapi#errorMatchers for OpenAPI packages; com.cloudflare.protocols#…, com.gcp.protocols#… elsewhere). A generator that sets none ignores matchers — check before relying on them.
  • A matcher's fields all have to match; separate matchers on one class are alternatives. Fields are code, status, message (exact string, or { includes } / { matches }), body (JSON pointer → scalar or text matcher, e.g. { "/success": false }), and headers (name → text matcher). The most specific match across the operation's classes wins, one point per field, so a message matcher beats a bare status matcher on the same status. Match on the stable part of the response — a numeric code or an error type — before free text.
  • The error's category (BadRequestError, ServerError, RetryableError, …) comes from smithy.api#httpError and smithy.api#retryable (errorCategories in packages/core/src/codegen/generator.ts), and retry policies act on those categories. Set them deliberately: a client error that arrives as a 5xx should not be retried as a server error.

Field is null or missing on the wire. In the spec: x-nullable: true (Swagger 2.0), nullable: true (OpenAPI 3.0), or null in the type array (3.1). Being nullable and being required are independent: a field that is always present but sometimes null keeps its required entry; a field that is sometimes absent leaves the required list (a replace of the whole list — say which fields left in the description).

Secret without a sensitive mark. x-sensitive: true on the string property. Convert already marks names matching its default patterns (password, api_token, plain_text, …; isSensitiveProperty in packages/core/src/codegen/openapi.ts), so check the generated type is not already Redacted before adding one.

One operation returns more than the shared schema promises. Copy the schema to a new name, change the copy, and re-point only that operation's response — the PlanetScale password-with-secret patch gives create and renew a plain_text that is never null while get and list keep the shared nullable one. A response schema that is simply wrong gets its $ref replaced.

Step 4 — regenerate

sh
pnpm generate <pkg>

Always regenerate with pnpm generate <pkg>, even for one service. It converts, generates and formats; a bare convert (with or without --resource) leaves .generated-specs/ unformatted, and the diff then shows every file as changed.

Do not add a per-package test for the patch. The generated diff in the next step shows what the patch changes, and the behaviour it relies on (error matchers, nullability, sensitive members) is tested once in packages/core. When updating an existing patch PR that added one, delete that test in the same update.

Step 5 — check the change

sh
git diff origin/main -- packages/<pkg>/.generated-specs packages/<pkg>/src/services

Diff against origin/main so a patch already committed on a PR branch still shows up. Read the diff against the description:

  • exactly the shapes and members meant changed — done.
  • nothing changed — the spec already says this (drop the patch), or the pointer landed somewhere convert does not read.
  • more changed than intended — the patch reaches further than meant (a shared shape, say); narrow it.

Do not run pnpm patches:audit here. A patch is written to change the model, and the diff above already shows whether it did. The audit rebuilds the whole model once per patch file (minutes for cloudflare) and only answers a question once the spec has moved underneath existing patches. That is the distilled-sdk-update skill's job.

Then check the generated TypeScript reads the way a caller needs, run pnpm exec tsc -b packages/<pkg> --noCheck false, and commit the patch with the src/services/ it produced (and .generated-specs/ for a convert-stage package), as fix(<pkg>): … naming what callers gain ("type 422s observed on the live API").

© alchemy-run, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/distilled-sdk-patch of alchemy-run/distilled.

Open the folder on GitHubat commit 45d4da4

Compare with similar skills

Distilled SDK Patch next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Distilled SDK Patch compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Distilled SDK Patch this skillalchemy-run/distilled431—~2.6kAutomated safety check: PassApache-2.0
Update Provider Depsmondoohq/mql411—~4.5kAutomated safety check: PassCustom licence
Deploy AstermemAsterove/AsterMem161—~3.2kAutomated safety check: WarnAGPL-3.0
Cloudflare R2einverne/dotfiles121—~2.8kAutomated safety check: PassGPL-3.0
Implementing Cloud Waf Rulesmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Detecting SQL Injection Via Waf Logsmukul975/Anthropic-Cybersecurity-Skills34k—~564Automated safety check: PassApache-2.0

Similar skills

  • Upgrade an mql provider's vendored SDKs (all providers or a named subset), audit the new versions for breaking changes and fix call sites while keeping shipped MQL fields backwards-compatible, check…

    411 GitHub stars~4.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Deploy Astermem

    Asterove/AsterMem

    Guide the user through taking AsterMem live — on a cloud server, or on a machine they already own (home NAS, Raspberry Pi, this computer) exposed through Cloudflare Tunnel with no public IP.

    161 GitHub stars~3.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: warnings
  • Cloudflare R2

    einverne/dotfiles

    Guide for implementing Cloudflare R2 - S3-compatible object storage with zero egress fees.

    121 GitHub stars~2.8k tokensUpdated 28 days ago
    Backend & APIsAuto-check passed
  • Implementing Cloud Waf Rules

    mukul975/Anthropic-Cybersecurity-Skills

    Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting SQL Injection Via Waf Logs

    mukul975/Anthropic-Cybersecurity-Skills

    Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns.

    34k GitHub stars~564 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Local opennext documentation reference (latest). An agent skill from olorehq/olore.

    103 GitHub stars~825 tokensUpdated today
    Backend & APIsAuto-check passed

More from alchemy-run/distilled

  • Distilled SDK Update

    alchemy-run/distilled

    Move an existing distilled SDK to its mirror's latest spec, regenerate it, audit packages/<pkg/patches/ with pnpm patches:audit and delete or slim the patches the new spec has absorbed, then open…

    431 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Distilled SDK

    alchemy-run/distilled

    Build or update a distilled SDK for an API provider — sourcing its OpenAPI/Smithy/GraphQL/discovery description, adding the spec mirror that feeds it, generating packages/<provider, listing it on…

    431 GitHub stars~6k tokensUpdated today
    Auto-check passed

Questions about Distilled SDK Patch

What does Distilled SDK Patch do?

Add or change a patch in packages/<pkg/patches/ to correct a distilled SDK's upstream spec — a missing error response or typed error (status, code, message, body or header matchers), a field that…. Distilled SDK Patch is an agent skill from alchemy-run/distilled. Add or change a patch in packages/<pkg/patches/ to correct a distilled SDK's upstream spec — a missing error response or typed error (status, code, message, body or header matchers), a field that should be nullable or optional, a secret with no sensitive mark, a wrong response schema, or a shared model that needs splitting — then regenerate and read the generated diff to confirm it changes exactly what the patch says.

When should I use Distilled SDK Patch?

Distilled SDK Patch fits situations like: type this error; this field is null on the wire; mark X sensitive; any fix that would otherwise be an edit to generated code.

How do I install Distilled SDK Patch in Claude Code?

Run `npx skills add alchemy-run/distilled --skill distilled-sdk-patch -a claude-code`. Or copy the skill folder (.agents/skills/distilled-sdk-patch in alchemy-run/distilled) into .claude/skills/distilled-sdk-patch in your project. Claude Code loads it when a task matches its description.

How do I install Distilled SDK Patch in Codex?

Run `npx skills add alchemy-run/distilled --skill distilled-sdk-patch -a codex`. Or copy the skill folder (.agents/skills/distilled-sdk-patch in alchemy-run/distilled) into .agents/skills/distilled-sdk-patch in your project. Codex loads it when a task matches its description.

Can I use Distilled SDK Patch in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alchemy-run/distilled --skill distilled-sdk-patch -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/distilled-sdk-patch, .gemini/skills/distilled-sdk-patch, .github/skills/distilled-sdk-patch and .opencode/skills/distilled-sdk-patch in your project.

What does Distilled SDK Patch need to run?

Going by SKILL.md and its folder, Distilled SDK Patch needs the command-line tools its instructions call (pnpm and git).

Does Distilled SDK Patch access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Distilled SDK Patch safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Distilled SDK Patch use?

Distilled SDK Patch is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Distilled SDK Patch use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Distilled SDK Patch?

Skills that share tags, products or a category with Distilled SDK Patch: Update Provider Deps (mondoohq/mql, 411 stars), Deploy Astermem (Asterove/AsterMem, 161 stars), Cloudflare R2 (einverne/dotfiles, 121 stars) and Implementing Cloud Waf Rules (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Distilled SDK Patch?

alchemy-run (a GitHub organization) maintains it in alchemy-run/distilled, which has 431 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.

Source: alchemy-run/distilled on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.