Use Yaak
mountain-loop/yaak
A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…
PowerX 底座 Capability 治理与发布准入规则。用于审计 REST/OpenAPI/gRPC/Gin 生成的能力候选、正式 platformcapabilities 目录、Capability Registry 登记、agentusable/permissioncode/risklevel 元数据、ignore…
$ npx skills add ArtisanCloud/PowerX --skill capability-governance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ArtisanCloud/PowerX capability-governance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ArtisanCloud/PowerX.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/governance/capability-governance .claude/skills/capability-governance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "capability-governance" agent skill from https://github.com/ArtisanCloud/PowerX/tree/release%2Fv1.0.0/.codex/skills/governance/capability-governance into .claude/skills/capability-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "capability-governance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ArtisanCloud/PowerX/tree/release%2Fv1.0.0/.codex/skills/governance/capability-governanceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ArtisanCloud/PowerX --skill capability-governance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ArtisanCloud/PowerX capability-governance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArtisanCloud/PowerX.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/governance/capability-governance .agents/skills/capability-governance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "capability-governance" agent skill from https://github.com/ArtisanCloud/PowerX/tree/release%2Fv1.0.0/.codex/skills/governance/capability-governance into .agents/skills/capability-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "capability-governance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ArtisanCloud/PowerX --skill capability-governance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ArtisanCloud/PowerX capability-governance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArtisanCloud/PowerX.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/governance/capability-governance .cursor/skills/capability-governance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "capability-governance" agent skill from https://github.com/ArtisanCloud/PowerX/tree/release%2Fv1.0.0/.codex/skills/governance/capability-governance into .cursor/skills/capability-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "capability-governance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ArtisanCloud/PowerX.git --path .codex/skills/governance/capability-governance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ArtisanCloud/PowerX --skill capability-governance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ArtisanCloud/PowerX capability-governance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArtisanCloud/PowerX.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/governance/capability-governance .gemini/skills/capability-governance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "capability-governance" agent skill from https://github.com/ArtisanCloud/PowerX/tree/release%2Fv1.0.0/.codex/skills/governance/capability-governance into .gemini/skills/capability-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "capability-governance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ArtisanCloud/PowerX capability-governanceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ArtisanCloud/PowerX --skill capability-governance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ArtisanCloud/PowerX.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/governance/capability-governance .github/skills/capability-governance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "capability-governance" agent skill from https://github.com/ArtisanCloud/PowerX/tree/release%2Fv1.0.0/.codex/skills/governance/capability-governance into .github/skills/capability-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "capability-governance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ArtisanCloud/PowerX --skill capability-governance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ArtisanCloud/PowerX capability-governance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArtisanCloud/PowerX.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/governance/capability-governance .opencode/skills/capability-governance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "capability-governance" agent skill from https://github.com/ArtisanCloud/PowerX/tree/release%2Fv1.0.0/.codex/skills/governance/capability-governance into .opencode/skills/capability-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "capability-governance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
capability-governancePowerX 底座 Capability 治理与发布准入规则。用于审计 REST/OpenAPI/gRPC/Gin 生成的能力候选、正式 platformcapabilities 目录、Capability Registry 登记、agentusable/permissioncode/risklevel 元数据、ignore…
Capability Governance is an agent skill from ArtisanCloud/PowerX. PowerX 底座 Capability 治理与发布准入规则。用于审计 REST/OpenAPI/gRPC/Gin 生成的能力候选、正式 platformcapabilities 目录、Capability Registry 登记、agentusable/permissioncode/risklevel 元数据、ignore 清单和缺失能力;当用户要求“重新识别能力”“能力是否能发布”“补齐能力登记”“检查 capability-gen/audit/check”“底座接口暴露给插件/agent”时使用。
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Backend & APIs, covering OpenAPI specifications and gRPC and Protobuf. It works with gRPC and OpenAPI. The repository describes itself as: PowerX是一款以企业微信为基础的微信私域运营开放平台,帮助企业实现引流获客、精细运营。 The licence is Apache-2.0.
9 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 3f7619d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
makegoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Capability Governance loads about 3k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 814 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ArtisanCloud/PowerX at commit 3f7619d, republished under its Apache-2.0 licence (© ArtisanCloud). 814 words, ~2,975 tokens.
.claude/skills/capability-governance/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.按统一规则判断 PowerX 底座能力候选是否可以进入 backend/config/platform_capabilities/*.yaml,并区分:
正式 YAML 不是文档。进入 backend/config/platform_capabilities 后会被 BaseCapabilitySeeder 写入 CapabilityRecord 并给 active tenants 建 registration,因此必须按运行时授权事实处理。
在对话里直接点名 skill。完整审计使用:
用 $capability-governance 做一次完整能力治理审计完整补齐使用:
用 $capability-governance 做一次完整能力治理补齐执行“完整能力治理补齐”时,不只解释结果,必须按下面顺序实际处理:
make capability-gen,确保 backend/config/platform_capabilities/generated.auto.yaml 被重新生成。generated.auto.yaml 是否作为正式 platform capability 文件存在,并包含所有生成能力的治理字段:permission_codeagent_usablerisk_levelactor_contextresource_scopests_direct 只能显式为 true,不得默认打开permission_code / agent_usable / risk_level。default_role_grants: [role_user],并确认未使用非法默认角色码。make capability-check。如果失败,先判断是:Group("") 丢父路径。category/reason 的 ignore,不允许静默忽略。make capability-gen 和 make capability-check,直到通过。make capability-seed,把正式 platform_capabilities/*.yaml 写入 capability_registry_records 并为 active tenants 补齐 registrations。也可以按问题缩小范围:
用 $capability-governance 检查 make capability-check 的失败原因
用 $capability-governance 判断这些候选能力哪些可以进 platform_capabilities
用 $capability-governance 分析 com.corex.customer.accounts.* 需要补哪些实现先读取这些位置,再给结论或改代码:
make_files/capability.mkmake_files/dev.mkbackend/cmd/capability_gen/main.gobackend/cmd/capability_audit/main.gobackend/config/platform_capabilities/*.yamlbackend/config/capability_audit_required.yamlbackend/internal/service/integration_gateway/base_capabilities.gobackend/internal/service/integration_gateway/platform_capability_config.gobackend/internal/http/auth_subject_validator.gobackend/internal/http/auth_subject_validator_test.go如果涉及 agent 能力授权,还要读取:
backend/internal/service/agent_authz/service.gobackend/internal/service/agent/agent_service.goweb-admin/app/pages/settings/ai/agents.vue从仓库根目录运行:
make capability-gen
make capability-audit
make capability-check
make capability-seed
CAPABILITY_AUDIT_FIX=1 make capability-audit解释命令结果时必须区分:
capability-gen:从 OpenAPI/gRPC/Gin 生成底座 raw 能力,默认写入 backend/config/platform_capabilities/generated.auto.yaml。该文件是正式登记的一部分,但生成能力默认必须是 agent_usable: false,不能当成手写业务聚合能力。capability-audit:检查正式目录、required 清单和路由覆盖。capability-check:先临时生成候选,再审计正式目录覆盖关系,适合判断“现有接口是否已被正式声明或明确忽略”。capability-seed:只同步正式 platform capability YAML 到运行库,不执行 migrate,不执行全量 seed。CAPABILITY_AUDIT_FIX=1:只生成草稿,不得直接把草稿视为可发布。当前 Make 约定:
make capability-gen 默认输出:backend/config/platform_capabilities/generated.auto.yamlmake capability-check 临时输出:tmp/capability-check/generated.platform-capabilities.yamlmake capability-check 通过时应输出类似:capability-audit: ok, declared=<正式能力数> referenced=<引用数> rest_routes=<REST覆盖数> candidates=<临时候选数> ignored_route_rules=<忽略规则数>如果 declared 只有几十个,而 candidates 有几百个,说明 raw 能力没有完整进入正式目录,不能视为完整。
能力进入正式 platform_capabilities 前必须满足:
capability_id 稳定且属于 com.corex.*。permission_code 明确,不能依赖不可读的粗粒度推导。agent_usable 明确设置。raw route 和后台管理能力默认应为 false。risk_level 明确设置。role_owner 和 role_admin;如需普通成员使用,descriptor 必须显式声明 default_role_grants: [role_user],不得靠手工补 iam_role_permission。module、categories、intents、tool_scopes 与业务语义一致。protocols 指向真实路径/RPC,路径参数风格要与项目规范一致。backend/config/platform_capabilities/generated.auto.yaml 是底座 raw 能力登记文件,必须被当作正式目录的一部分读取和审计,但它与手写聚合能力语义不同:
make capability-gen 生成,不手工大段编辑。permission_code、agent_usable、risk_level。agent_usable: false,避免 raw route 出现在智能体能力选购页面。actor_context 和 resource_scope。sts_direct: true。/admin、丢 /tenant、错误处理 Group(""),必须先修 generator,而不是手写补假能力。Capability 是业务授权单元,不是 URL。REST/OpenAPI/Admin/gRPC endpoint 只是 capability 的 protocol binding。
规则:
capability_id。/api/v1/admin/<resource> 与 /api/v1/<resource> 如果只是用户态后台入口和服务态开放入口的差异,应登记为同一个 capability 的不同 REST bindings。/api/v1/admin/scheduler/jobs、未来的 /api/v1/scheduler/jobs、powerx.scheduler.v1.SchedulerService 如果语义都是 Runtime Scheduler jobs,应优先归到 com.corex.scheduler.jobs;差异通过 binding metadata、service 层 actor/owner 校验和 tool_scope 表达。审计 capability 时必须先确认调用主体:
admin_user:PowerX Admin 或插件 Admin 页面,使用用户 JWT、tenant member、RBAC。典型路径 /api/v1/admin/*。service_actor:插件后端、agent、skill、系统集成,使用 STS/API Key/OAuth client。典型路径 /api/v1/tenant/invocations 或服务态开放 REST。web_user:租户侧 web 应用用户,使用用户 JWT 或业务 session。mini_app_user:小程序用户,使用小程序会话、用户 JWT 或 customer/user token。customer_actor:客户门户或外部客户身份,使用 customer token 或 customer-scoped OAuth/API Key。规则:
com.corex.customer.account.self_read,不能继承 com.corex.customer.accounts.admin_manage。actor_context。admin_manage、service_manage、self_read、self_update、owner_manage。插件 STS token 直接访问 PowerX Core HTTP 的允许集合按下面公式计算:
STS direct route policy =
static plugin runtime contracts
+ REST endpoints in formal platform_capabilities/*.yaml
- STS blocklist规则:
/tenant/invocations 和 /tenant/invocations/stream 是插件调用底座能力的推荐主路径。platform_capabilities/*.yaml 中的 REST protocol endpoints;generated.auto.yaml 当前也参与自动派生,但必须经过 blocklist。GET 就放开写操作。/api/v1/admin/* 是后台用户态 API 命名空间,不等于“禁止插件后台页面使用”。浏览器中的 PowerX Admin、插件 Admin 页面、以及任何携带用户 JWT 的后台请求,仍然按用户鉴权、租户成员、RBAC 和业务权限判断;STS direct route policy 不得影响用户态 JWT。uid/mid,不能代表登录用户通过 /api/v1/admin/* 绕过用户 RBAC。插件后端如果要代表当前用户调用底座后台 API,必须引入明确的 delegated/on-behalf-of 机制,不能复用普通 powerx:api STS token。/admin/*、/internal/*、/public/*、/auth/*、/setup/*、debug、migration、root、drain、bootstrap、mock、health、根级动态路径等非服务态开放入口。/admin/* 默认不允许服务态 STS direct call。只有确认为插件服务运行时合同的少量入口,才允许进入 static allow,并必须补用途说明和 auth_subject_validator 测试。make capability-check,再验证 STS direct policy。/api/v1/admin/* 改成 sts_direct: true。应保留 admin_user/user_jwt binding,并新增 service_actor/sts 的 core_internal binding 或服务态开放 REST,由 /tenant/invocations 在校验 Registry 与 tenant registration 后调 Core service。例如 com.corex.customer.accounts.admin_manage 使用 /api/v1/admin/customers/* 作为 payload endpoint 选择参数,但实际由 Core 内部 customer service 执行。满足发布准入,且插件/agent/skill 有复用价值的底座业务能力,例如 media、knowledge、workflow、scheduler、event fabric、agent runtime、AI 模型调用等。
优先使用手写业务聚合能力,而不是每个 raw route 一个 capability。聚合能力可以包含多个 REST/gRPC protocol binding。
后台治理、观测、诊断、插件运行时辅助接口,如果确实需要被租户或插件调用,可以登记,但必须:
agent_usable: false如果 raw route 已经被手写聚合能力覆盖,不要再发布重复 capability。应把 raw route 覆盖关系体现在聚合能力的 protocols 中,或在审计 ignore 中说明“covered_by: <capability_id>”。
以下类型不得进入租户能力注册目录:
/internal/** 或 /api/v1/internal/**/api/v1/admin/root/**_test.go 中的测试路由这些需要进入 capability_audit_ignore.yaml 时,每条必须有 category 和 reason,不能静默忽略。
这些类型即使被 OpenAPI/Gin/gRPC 生成器识别为候选,也不得通过服务态 STS direct 自动开放;如果确实属于插件服务运行时合同,应从 capability 发布判断中剥离,进入静态合同入口并单独测试。用户态后台页面访问 /api/v1/admin/* 不受这条 STS blocklist 影响,仍由用户 JWT 和 RBAC 判定。
如果只有 required_capabilities、插件调用方或文档提到某 capability,但底座没有真实 transport,不得补 YAML 伪造能力。必须先实现 API/service/repository/transport/权限/测试,然后再登记 capability。
典型判断:com.corex.customer.accounts.* 如果没有真实 customer admin HTTP/gRPC transport,就属于缺实现,不能仅靠 capability YAML 解决。
发现以下情况时先修工具,不要发布候选:
group := adminGroup.Group("") 后路由被生成到 /api/v1/catalog 而不是 /api/v1/admin/skills/catalog。_test.go 产生候选。/admin、/tenant、/internal 等实际前缀。permission_code、agent_usable、risk_level 缺省导致 UI 或授权过宽。修工具后重新运行 make capability-check,用新结果重新分类。
审计器必须强制:
permission_code。agent_usable。risk_level:low、medium、high、critical。actor_context 和 resource_scope。sts_direct: true 只能用于 actor_context: service_actor。sts_direct: true 不得指向 /api/v1/admin/*。generated.auto.yaml 也必须满足上述元数据规则。完整补齐后应能同时满足:
backend/config/platform_capabilities/generated.auto.yaml 中有 700+ raw 能力。make capability-check 通过。给用户结论时按这个顺序:
不要只回答“可以”或“不可以”。必须说明运行时影响和授权边界。
default_role_grants 只能使用 role_owner、role_admin、role_user、role_readonly、role_vendor;非法角色码必须 fail fast。完成治理或代码修改后至少运行:
make capability-check如果改了 Go 代码,按影响范围运行对应测试;如果新增/修改生成器或审计器,至少运行:
cd backend && go test ./cmd/capability_audit
cd backend && go test ./cmd/capability_gen如果改了 STS direct 规则或 platform capability REST endpoints,还要运行:
cd backend && go test ./internal/http如果对应包没有测试,也要明确说明无法运行或当前没有测试包。
© ArtisanCloud, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .codex/skills/governance/capability-governance of ArtisanCloud/PowerX.
Open the folder on GitHubat commit 3f7619d
Capability Governance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Capability Governance this skillArtisanCloud/PowerX | 379 | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Use Yaakmountain-loop/yaak | 19k | — | ~1.9k | Automated safety check: Pass | MIT | |
| SpikardGoldziher/spikard | 123 | — | ~799 | Automated safety check: Pass | MIT | |
| Release WorkflowGoldziher/spikard | 123 | — | ~909 | Automated safety check: Pass | MIT | |
| Dotnet APInovotnyllc/dotnet-artisan | 233 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Uxcholon-run/uxc | 115 | — | ~1.8k | Automated safety check: Pass | MIT |
mountain-loop/yaak
A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…
Goldziher/spikard
Scaffold Spikard projects and generate code from OpenAPI, AsyncAPI, OpenRPC, GraphQL, and Protobuf schemas using the Spikard CLI or its MCP server.
Goldziher/spikard
Release/publish the spikard Rust core crate and CLI end-to-end.
novotnyllc/dotnet-artisan
Builds ASP.NET Core APIs, EF Core data access, gRPC, SignalR, and backend services with middleware, security (OAuth, JWT, OWASP), resilience, messaging, OpenAPI, .NET Aspire, Semantic Kernel…
holon-run/uxc
Discover and call remote schema-exposed interfaces with UXC.
dotnet/skills
Guides creation and modification of ASP.NET Core Web API endpoints with correct HTTP semantics, OpenAPI metadata, and error handling.
ArtisanCloud/PowerX
PowerX API 命名与访问规范(/api/v1、/admin、/internal 边界). An agent skill from ArtisanCloud/PowerX.
ArtisanCloud/PowerX
PowerX CRUD 依赖注入规则(Deps 单入口、构造注入、跨传输复用). An agent skill from ArtisanCloud/PowerX.
ArtisanCloud/PowerX
PowerX CRUD gRPC 开发规范(proto、server、拦截器、错误映射). An agent skill from ArtisanCloud/PowerX.
ArtisanCloud/PowerX
PowerX HTTP Handler 规则(绑定校验、统一回包、无 DB IO). An agent skill from ArtisanCloud/PowerX.
ArtisanCloud/PowerX
PowerX CRUD HTTP 开发规范(管理端路由、绑定、错误桥接、多租户). An agent skill from ArtisanCloud/PowerX.
ArtisanCloud/PowerX
PowerX CRUD Model 规则(GORM 模型、多租户、索引、命名). An agent skill from ArtisanCloud/PowerX.
Categories
PowerX 底座 Capability 治理与发布准入规则。用于审计 REST/OpenAPI/gRPC/Gin 生成的能力候选、正式 platformcapabilities 目录、Capability Registry 登记、agentusable/permissioncode/risklevel 元数据、ignore…. Capability Governance is an agent skill from ArtisanCloud/PowerX.
Capability Governance fits situations like: tasks that involve OpenAPI specifications; tasks that involve gRPC and Protobuf.
Run `npx skills add ArtisanCloud/PowerX --skill capability-governance -a claude-code`. Or copy the skill folder (.codex/skills/governance/capability-governance in ArtisanCloud/PowerX) into .claude/skills/capability-governance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ArtisanCloud/PowerX --skill capability-governance -a codex`. Or copy the skill folder (.codex/skills/governance/capability-governance in ArtisanCloud/PowerX) into .agents/skills/capability-governance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArtisanCloud/PowerX --skill capability-governance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/capability-governance, .gemini/skills/capability-governance, .github/skills/capability-governance and .opencode/skills/capability-governance in your project.
Going by SKILL.md and its folder, Capability Governance needs the command-line tools its instructions call (make and go).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Capability Governance is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Capability Governance: Use Yaak (mountain-loop/yaak, 19k stars), Spikard (Goldziher/spikard, 123 stars), Release Workflow (Goldziher/spikard, 123 stars) and Dotnet API (novotnyllc/dotnet-artisan, 233 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ArtisanCloud (a GitHub organization) maintains it in ArtisanCloud/PowerX, which has 379 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 7, 2026.
Source: ArtisanCloud/PowerX on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.