Agent skill

Init Script Contract

by Archive228 in Archive228/loopkit

Author idempotent init.sh under 120s plus sibling test.sh, stop.sh, reset.sh, serve.sh with fixed names the harness relies on.

MITAuto-check passed

Install Init Script Contract

skills CLI
$ npx skills add Archive228/loopkit --skill init-script-contract -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Archive228/loopkit init-script-contract --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Archive228/loopkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/init-script-contract .claude/skills/init-script-contract && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
init-script-contract
GitHub stars
756
Token cost
~1.2k tokens
SKILL.md length
648 words
Files
1
Skills in repo
43
Repo updated
First seen
Licence
MIT

At a glance

Author idempotent init.sh under 120s plus sibling test.sh, stop.sh, reset.sh, serve.sh with fixed names the harness relies on.

  • Works in 8 steps: Pick the stack the spec implies. Do not… → Write init.sh to run end-to-end from an… → Time it. Run time ./init.sh on a clean… → …
  • SKILL.md covers When to apply, The five scripts, Procedure and Anti-patterns, plus 3 more sections
  • Calls npm, git and yarn

What it does

Init Script Contract is an agent skill from Archive228/loopkit. Author idempotent init.sh under 120s plus sibling test.sh, stop.sh, reset.sh, serve.sh with fixed names the harness relies on.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: 33 battle-tested skills + minimal .claude harness for any coding agent (Claude Code, Cursor, Codex, Gemini CLI). The licence is MIT.

Example prompts

  • “/init-script-contract”

Requirements

  • Node.js
  • Docker

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Pick the stack the spec implies. Do not scaffold Docker, CI, or lint configs the spec does not require.
  2. Write init.sh to run end-to-end from an empty clone. Pin every dependency (lockfile, ==, Pipfile.lock). Answer every prompt…
  3. Time it. Run time ./init.sh on a clean clone. If it exceeds 120s, split — move one-time setup into init.sh and server launch into…
  4. Make it idempotent. Run ./init.sh twice back-to-back. If the second run errors or duplicates state, guard each step with existence checks…
  5. Write stop.sh to kill by PID file or port, not by process name grep. Grep kills sibling agents on shared sandboxes.
  6. Write test.sh with a single end-to-end smoke test that proves init.sh produced a serving app. No feature tests — those belong to future…
  7. Write reset.sh to drop and recreate the DB, clear caches, wipe /tmp artifacts. Never touch tracked files.
  8. Verify from empty state. git clean -fdx && ./init.sh && ./test.sh && ./stop.sh. Every script exits 0.

What it can do on your machine

Read from SKILL.md and the folder at commit 5ae033e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • git
    • yarn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, git and yarn, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Init Script Contract loads about 1.2k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 648 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Archive228/loopkit at commit 5ae033e, republished under its MIT licence (© Archive228). 648 words, ~1,224 tokens.

Download SKILL.mdSave it as .claude/skills/init-script-contract/SKILL.md (or your agent's skills folder).
name
init-script-contract
description
Author idempotent init.sh under 120s plus sibling test.sh, stop.sh, reset.sh, serve.sh with fixed names the harness relies on.
when_to_use
scaffolding a new project the initializer agent will hand to future sessions, setup takes over 120s and needs splitting into init plus serve, every coding…

Init Script Contract

Every coding session in a multi-session project starts by bringing the dev server up. If the entry point is named differently each time, or takes four minutes, or prompts for input, you burn tokens and wall-clock on every single session. The fix is a fixed set of script names at the project root with a hard contract. The initializer agent writes them once; every downstream session relies on them.

The names are load-bearing — [[shift-notes]] and [[broken-window-check]] both refer to them by name. Do not invent your own.

When to apply

  • You are the initializer agent scaffolding a fresh project.
  • You just discovered setup exceeds 120s and need to split cleanly.
  • You are auditing an existing project whose sessions keep re-discovering how to launch the app.

The five scripts

ScriptContract
init.shClean clone → dev server up on localhost. Idempotent. Under 120s. Zero prompts.
serve.shStart the dev server only. Written when init.sh cannot fit under 120s.
test.shRun the full test suite. Exit non-zero on any failure.
stop.shCleanly kill the dev server. Sessions run this before exiting.
reset.shWipe local DB and ephemeral state. Leave code untouched. Used by [[broken-window-check]].

Procedure

  1. Pick the stack the spec implies. Do not scaffold Docker, CI, or lint configs the spec does not require.
  2. Write init.sh to run end-to-end from an empty clone. Pin every dependency (lockfile, ==, Pipfile.lock). Answer every prompt non-interactively (-y, --yes, DEBIAN_FRONTEND=noninteractive).
  3. Time it. Run time ./init.sh on a clean clone. If it exceeds 120s, split — move one-time setup into init.sh and server launch into serve.sh. Have init.sh call serve.sh at the end so single-command startup still works.
  4. Make it idempotent. Run ./init.sh twice back-to-back. If the second run errors or duplicates state, guard each step with existence checks (if [ ! -d node_modules ], createdb --if-not-exists, etc.).
  5. Write stop.sh to kill by PID file or port, not by process name grep. Grep kills sibling agents on shared sandboxes.
  6. Write test.sh with a single end-to-end smoke test that proves init.sh produced a serving app. No feature tests — those belong to future sessions.
  7. Write reset.sh to drop and recreate the DB, clear caches, wipe /tmp artifacts. Never touch tracked files.
  8. Verify from empty state. git clean -fdx && ./init.sh && ./test.sh && ./stop.sh. Every script exits 0.
Show full SKILL.md (267 more words)Show less

Anti-patterns

  • Naming it bootstrap.sh, setup.sh, dev.sh. Downstream sessions grep for the fixed names. A cute alias silently disables the harness.
  • Interactive prompts. yarn install asking about peer deps, createdb asking for a password, npm audit waiting for input. Every prompt is a stall the session cannot answer.
  • Unpinned deps. npm install foo without a lockfile means the next session gets a different transitive graph. See the Feb 2026 incident where an agent ran npm update --save and broke twelve sessions.
  • Killing the server with pkill node. Kills every node process in the sandbox. Use a PID file written by serve.sh.
  • Letting init.sh create files outside the project directory. Sandbox will reject it and the failure mode is opaque.
  • Skipping reset.sh because "the DB is fine". [[broken-window-check]] needs it to isolate a bad commit from stale state.

Red flags

  • init.sh prints "Press Y to continue" anywhere in its output.
  • Timing varies wildly run-to-run — some dep is fetched from the network on the hot path.
  • Running init.sh twice leaves migrations doubled or ports bound.
  • stop.sh exits 0 but lsof -i :3000 still shows the server.

When NOT to apply

Single-session scripts and one-shot demos. The contract exists to amortize setup cost across many sessions; a one-off run does not need it.

  • [[shift-notes]] — the notes downstream sessions read after init.sh succeeds.
  • [[broken-window-check]] — runs init.sh then reset.sh when reverting a bad feature.
  • [[single-feature-per-session]] — the discipline this contract enables by keeping session startup cheap.

Inspiration: Prithvi's March 2026 planner/generator/evaluator write-up, where the fixed harness entry points let the evaluator persona re-verify any generator session from scratch without re-learning the launch procedure.

© Archive228, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/init-script-contract of Archive228/loopkit.

Open the folder on GitHubat commit 5ae033e

Compare with similar skills

Init Script Contract next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Init Script Contract compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Init Script Contract this skillArchive228/loopkit756—~1.2kAutomated safety check: PassMIT
Initasgeirtj/system_prompts_leaks69k—~5.5kAutomated safety check: PassCC0-1.0
Initasgeirtj/system_prompts_leaks69k—~602Automated safety check: PassCC0-1.0
Hermes Agent Skill AuthoringNousResearch/hermes-agent252k—~3.6kAutomated safety check: PassMIT
Configuring Oauth2 Authorization Flowmukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.0
Authoring Skillsvercel/next.js143k—~1kAutomated safety check: PassMIT

Similar skills

  • Init

    asgeirtj/system_prompts_leaks

    Initialize new CLAUDE.md file(s) and optional skills/hooks with codebase documentation

    69k GitHub stars~5.5k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Init

    asgeirtj/system_prompts_leaks

    Initialize a new CLAUDE.md file with codebase documentation. An agent skill from asgeirtj/system_prompts_leaks.

    69k GitHub stars~602 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Hermes Agent Skill Authoring

    NousResearch/hermes-agent

    Author in-repo SKILL.md files: frontmatter and structure. An agent skill from NousResearch/hermes-agent.

    252k GitHub stars~3.6k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Configuring Oauth2 Authorization Flow

    mukul975/Anthropic-Cybersecurity-Skills

    Configures secure OAuth 2.0 authorization flows, including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant, covering flow selection, PKCE implementation, token…

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Authoring Skills

    vercel/next.js

    Official

    How to create and maintain agent skills in .agents/skills/. An agent skill from vercel/next.js.

    143k GitHub stars~1k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Abp Authorization

    abpframework/abp

    ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.

    14k GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed

More from Archive228/loopkit

All 43 skills in this repo
  • Hitl Escalate

    Archive228/loopkit

    Escalate blocked runs to a human via configured channel or fallback to BLOCKED.md and exit the loop.

    756 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Structured Output

    Archive228/loopkit

    Get JSON out of the model reliably. An agent skill from Archive228/loopkit.

    756 GitHub stars~830 tokensUpdated 2 mo ago
    Auto-check passed
  • Using Loopkit

    Archive228/loopkit

    A skill your agent uses when starting any conversation in a loopkit-enabled project - establishes how to find and use loopkit's 49 skills, requiring skill invocation before ANY response including…

    756 GitHub stars~1.4k tokensUpdated 2 mo ago
    Auto-check passed
  • Active Memory Reminder

    Archive228/loopkit

    Before compaction Loopkit extracts decisions into claude-decisions.json (machine-readable).

    756 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Eval Harness

    Archive228/loopkit

    Build a repeatable eval loop that grades agent output with an LLM judge, so prompt/skill changes get scored against a baseline instead of eyeballed.

    756 GitHub stars~876 tokensUpdated 2 mo ago
    Auto-check passed
  • Feature List JSON

    Archive228/loopkit

    Enumerate every end-to-end feature as strict JSON entries with passes:false, editable-passes-only discipline, and priority order.

    756 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Init Script Contract

What does Init Script Contract do?

Author idempotent init.sh under 120s plus sibling test.sh, stop.sh, reset.sh, serve.sh with fixed names the harness relies on. Init Script Contract is an agent skill from Archive228/loopkit.sh with fixed names the harness relies on.

How do I install Init Script Contract in Claude Code?

Run `npx skills add Archive228/loopkit --skill init-script-contract -a claude-code`. Or copy the skill folder (skills/init-script-contract in Archive228/loopkit) into .claude/skills/init-script-contract in your project. Claude Code loads it when a task matches its description.

How do I install Init Script Contract in Codex?

Run `npx skills add Archive228/loopkit --skill init-script-contract -a codex`. Or copy the skill folder (skills/init-script-contract in Archive228/loopkit) into .agents/skills/init-script-contract in your project. Codex loads it when a task matches its description.

Can I use Init Script Contract in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Archive228/loopkit --skill init-script-contract -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/init-script-contract, .gemini/skills/init-script-contract, .github/skills/init-script-contract and .opencode/skills/init-script-contract in your project.

What does Init Script Contract need to run?

Going by SKILL.md and its folder, Init Script Contract needs the command-line tools its instructions call (npm, git and yarn). Our summary lists: Node.js; Docker.

Does Init Script Contract access the network?

SKILL.md contains no URLs. Its commands use npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Init Script Contract safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Init Script Contract use?

Init Script Contract is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Init Script Contract use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Init Script Contract?

Skills that share tags, products or a category with Init Script Contract: Init (asgeirtj/system_prompts_leaks, 69k stars), Init (asgeirtj/system_prompts_leaks, 69k stars), Hermes Agent Skill Authoring (NousResearch/hermes-agent, 252k stars) and Configuring Oauth2 Authorization Flow (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Init Script Contract?

Archive228 (a GitHub user) maintains it in Archive228/loopkit, which has 756 GitHub stars. The repository holds 43 skills in this directory. The repository was last updated on July 14, 2026.

Source: Archive228/loopkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.