Agent skill

Notes

by arandu-io in arandu-io/arandu

Work with the Note module of this Arandu application. An agent skill from arandu-io/arandu.

MITAuto-check passed

Install Notes

skills CLI
$ npx skills add arandu-io/arandu --skill notes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install arandu-io/arandu notes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/arandu-io/arandu.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/notes .claude/skills/notes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
notes
GitHub stars
281
Token cost
~1.1k tokens
SKILL.md length
522 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Work with the Note module of this Arandu application. An agent skill from arandu-io/arandu.

  • The request mentions notes
  • SKILL.md covers What it is made of, Its fields, Reaching a record and A request, end to end, plus 2 more sections
  • Calls go
  • A notes route is involved

What it does

Notes is an agent skill from arandu-io/arandu. Work with the Note module of this Arandu application. Use when the request mentions notes, when a notes route is involved, or when reading or changing note records. Covers what the module exposes, which roles may take which action, and the rule that the Service authorizes before it reaches the Hesape Model.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: The Arandu project skeleton, which aru new clones. The licence is MIT.

When your agent uses it

  • The request mentions notes
  • A notes route is involved
  • Changing note records

Example prompts

  • “/notes”

What it can do on your machine

Read from SKILL.md and the folder at commit 38c9b70. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Notes loads about 1.1k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 522 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from arandu-io/arandu at commit 38c9b70, republished under its MIT licence (© arandu-io). 522 words, ~1,122 tokens.

Download SKILL.mdSave it as .claude/skills/notes/SKILL.md (or your agent's skills folder).
name
notes
description
Work with the Note module of this Arandu application. Use when the request mentions notes, when a notes route is involved, or when reading or changing note records. Covers what the module exposes, which roles may take which action, and the rule that the Service authorizes before it reaches the Hesape Model.
license
MIT

Example resource. Remove with the list under "The example resource" in README.md.

The Note module

Generated from a specification. If it needs to change, change the specification and generate again rather than editing the files by hand -- what falls outside what the specification can say goes between the // arandu:begin custom and // arandu:end custom markers, which survive regeneration.

What it is made of

filewhat it holds
app/Models/Note.gothe entity and its table, with custom blocks for settings and local scopes
app/Models/NoteQuery.goNotes, the typed query and the collection, written by aru model:build and never by hand
app/Policies/NotePolicy.gowho may do what, and the only thing that issues a Grant
app/Services/NoteService.gothe domain and the only consumer of the Model entry point
app/Http/Controllers/NoteController.gothe actions the routes dispatch to
app/Http/Requests/NoteRequest.gothe input contract of create and update, with its form tags. Authorization stays in the Policy
resources/views, under the resourcethe four screens, which share one row struct
tests/Unit/Note_test.gothat reads authorize before the Model is queried

Its fields

fieldtype
titlestring
bodytext
pinnedbool

Every query uses the Model's tenant_id scope. Builder terminals take the Grant, and its tenant never comes from a path segment, a body, a query or a header.

Reaching a record

There is one way, and the compiler is what says so.

go
g, err := security.Authorize(ctx, policy, subject, action, models.Note{})
if err != nil {
    return err
}
record, err := models.Notes(db).FindOrFail(ctx, g, id)

Every terminal of NoteQuery takes security.Grant, and nothing outside the security package can build one. The Service owns the database handle, authorizes first, and then spends that Grant on the Model. A Controller has neither dependency and cannot grow a second persistence path.

Reads are not exempt. List, FindOrFail, a report and an export all require a Grant.

Show full SKILL.md (246 more words)Show less

A request, end to end

go
var in requests.NoteRequest
if err := ctx.Bind(&in); err != nil {
    return err
}
who, _ := ctx.User()
created, err := c.svc.Create(ctx.Ctx(), who, in)
if err != nil {
    return err
}
return ctx.RedirectRoute("notes.show", created.ID)
  • Who is asking is ctx.User(), which the sign-in guard on the routes puts on the request. There is no session lookup in the controller.
  • The input is ctx.Bind into NoteRequest: only the fields with a form tag are read, trimmed and converted. A new field is one line there, one in the model and one in the service's fill.
  • An error is returned, never mapped. The router answers it: validation.Errors goes back to the form with the messages and what was typed, a missing row is 404, a refusal is 403, and an error with an HTTPStatus() int method is that status.
  • A screen's page is view.New(ctx, title): the title, what a rejected form left in the flash, and the CSRF token the middleware issued. The controller takes the service and nothing else.
  • The listing is the Model's SimplePaginate, newest first, and the key is one the Model generates on insert.

What the policy allows

The generated policy denied every action; this example opened it, inside the custom block of app/Policies/NotePolicy.go:

actionwho
note.list, note.view, note.createanybody signed in to the tenant
note.update, note.deletethe note's author, user_id, and nobody else

The author is set by NoteService.Create from ctx.User(), never from the form. A note of another tenant is not found at all (404), because every read is scoped by the Grant's tenant; another member's note is found and refused (403). tests/Feature/Notes_test.go proves each of those.

Before calling a change finished

sh
export GOWORK=off
aru view:build && go build ./... && go vet ./... && go test -race ./... && aru doctor

© arandu-io, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/notes of arandu-io/arandu.

Open the folder on GitHubat commit 38c9b70

Compare with similar skills

Notes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Notes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Notes this skillarandu-io/arandu281—~1.1kAutomated safety check: PassMIT
Meeting Notes And Actionscomposio-community/awesome-codex-skills17k—~357Automated safety check: PassNone
Es Modulesthedaviddias/Front-End-Checklist74k—~482Automated safety check: PassMIT
Meeting Notesholaboss-ai/holaOS11k—~548Automated safety check: PassCustom licence
Note Takinginkeep/open-knowledge4.4k—~485Automated safety check: PassGPL-3.0
Release Notes One Pagernexu-io/open-design100k—~920Automated safety check: PassApache-2.0

Similar skills

  • Meeting Notes And Actions

    composio-community/awesome-codex-skills

    Turn meeting transcripts or rough notes into crisp summaries with decisions, risks, and owner-tagged action items; use for Zoom/Meet/Teams transcripts, call notes, or long meeting chats to generate…

    17k GitHub stars~357 tokensUpdated 2 mo ago
    Productivity & AutomationAuto-check passed
  • Es Modules

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing scripts, client components, bundles, or runtime behavior related to Use ES modules (import/export).

    74k GitHub stars~482 tokensUpdated yesterday
    Auto-check passed
  • Meeting Notes

    holaboss-ai/holaOS

    Turn raw notes or a transcript into a clean summary with decisions and action items.

    11k GitHub stars~548 tokensUpdated 1 mo ago
    Productivity & AutomationAuto-check passed
  • Note Taking

    inkeep/open-knowledge

    How to work in a Plain Notes project (the plain-notes starter pack): a flat notes/ folder plus a daily/ journal.

    4.4k GitHub stars~485 tokensUpdated today
    Knowledge ManagementAuto-check passed
  • Release Notes One Pager

    nexu-io/open-design

    Release notes one-page HTML with highlights, Added, Fixed, Breaking changes, Known issues, and Upgrade note.

    100k GitHub stars~920 tokensUpdated today
    DevelopmentAuto-check passed
  • Apple Notes Search

    sickn33/agentic-awesome-skills

    Semantic + keyword search and connection-discovery across the user's own Apple Notes via the apple-notes MCP server.

    47k GitHub starsUsed in 1 repo~2k tokens
    Agent WorkflowsAuto-check passed

More from arandu-io/arandu

  • Arandu Doctor Findings

    arandu-io/arandu

    Explains what each aru doctor architecture-check finding means in the Arandu Go framework, why it is never suppressed, and how to fix the line it points to.

    281 GitHub stars~1.2k tokensUpdated 3 days ago
    Auto-check passed
  • Decides whether a feature belongs in the application or in one of five shared Arandu modules before adding permissions, wallets, tags, Markdown rendering or API docs.

    281 GitHub stars~1.8k tokensUpdated 3 days ago
    Auto-check passed
  • Arandu Module Generator

    arandu-io/arandu

    Adds a new entity, resource or CRUD module to an Arandu Go application by writing a YAML specification instead of hand-writing the Go code.

    281 GitHub stars~2.4k tokensUpdated 3 days ago
    Auto-check passed
  • Arandu Policy and Grants

    arandu-io/arandu

    Explains authorization in an Arandu Go application: write a Policy, get a security.Grant through security.Authorize, re-authorize each row, and keep tenant isolation.

    281 GitHub stars~1.4k tokensUpdated 3 days ago
    Auto-check passed
  • Arandu View Templates

    arandu-io/arandu

    Writes and changes pages, layouts, forms and HTMX fragments in an Arandu Go app using its .kyse.go templates, escaping rules and Content-Security-Policy limits.

    281 GitHub stars~1.5k tokensUpdated 3 days ago
    Auto-check passed

Questions about Notes

What does Notes do?

Work with the Note module of this Arandu application. An agent skill from arandu-io/arandu. Notes is an agent skill from arandu-io/arandu. Work with the Note module of this Arandu application.

When should I use Notes?

Notes fits situations like: the request mentions notes; A notes route is involved; changing note records.

How do I install Notes in Claude Code?

Run `npx skills add arandu-io/arandu --skill notes -a claude-code`. Or copy the skill folder (.agents/skills/notes in arandu-io/arandu) into .claude/skills/notes in your project. Claude Code loads it when a task matches its description.

How do I install Notes in Codex?

Run `npx skills add arandu-io/arandu --skill notes -a codex`. Or copy the skill folder (.agents/skills/notes in arandu-io/arandu) into .agents/skills/notes in your project. Codex loads it when a task matches its description.

Can I use Notes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add arandu-io/arandu --skill notes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/notes, .gemini/skills/notes, .github/skills/notes and .opencode/skills/notes in your project.

What does Notes need to run?

Going by SKILL.md and its folder, Notes needs the command-line tools its instructions call (go).

Does Notes access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Notes safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Notes use?

Notes is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Notes use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Notes?

Skills that share tags, products or a category with Notes: Meeting Notes And Actions (composio-community/awesome-codex-skills, 17k stars), Es Modules (thedaviddias/Front-End-Checklist, 74k stars), Meeting Notes (holaboss-ai/holaOS, 11k stars) and Note Taking (inkeep/open-knowledge, 4.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Notes?

arandu-io (a GitHub organization) maintains it in arandu-io/arandu, which has 281 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 4, 2026.

Source: arandu-io/arandu on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.