Agent skill

Agent First App

by awebai in awebai/aweb

A skill your agent uses when building an app where AI agents are the users: agent-first product design, BYOT/AWID team-certificate auth instead of accounts, no-signup services, team-scoped data, and…

MITAuto-check passed

Install Agent First App

skills CLI
$ npx skills add awebai/aweb --skill agent-first-app -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install awebai/aweb agent-first-app --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/awebai/aweb.git skills-src && mkdir -p .claude/skills && cp -r skills-src/naapp/folio/skills/agent-first-app .claude/skills/agent-first-app && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agent-first-app
GitHub stars
115
Token cost
~744 tokens
SKILL.md length
398 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when building an app where AI agents are the users: agent-first product design, BYOT/AWID team-certificate auth instead of accounts, no-signup services, team-scoped data, and…

  • Building an app where AI agents are the users: agent-first product design
  • SKILL.md covers The inversion, in three lines, What you do not build, Agent-first surface checklist and Process: SOT first, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • BYOT/AWID team-certificate auth instead of accounts

What it does

Agent First App is an agent skill from awebai/aweb. Use when building an app where AI agents are the users: agent-first product design, BYOT/AWID team-certificate auth instead of accounts, no-signup services, team-scoped data, and server-plus-recipes application surfaces.

Its SKILL.md is about 740 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Communication for AI agents: stable identity, durable mail and chat, and wake-up events across sessions, runtimes, machines, and organizations. MIT, self-hostable. The licence is MIT.

When your agent uses it

  • Building an app where AI agents are the users: agent-first product design
  • BYOT/AWID team-certificate auth instead of accounts
  • No-signup services
  • Team-scoped data

Example prompts

  • “/agent-first-app”

What it can do on your machine

Read from SKILL.md and the folder at commit a6ca92a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Agent First App loads about 744 tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 398 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~744

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from awebai/aweb at commit a6ca92a, republished under its MIT licence (© awebai). 398 words, ~744 tokens.

Download SKILL.mdSave it as .claude/skills/agent-first-app/SKILL.md (or your agent's skills folder).
name
agent-first-app
description
Use when building an app where AI agents are the users: agent-first product design, BYOT/AWID team-certificate auth instead of accounts, no-signup services, team-scoped data, and server-plus-recipes application surfaces.

Build an agent-first app

Load this before turning "build an app for agents", "build a BYOT app", or "make an app for agent teams" into code. Its job is to stop the classic mistake: building auth the old way.

The inversion, in three lines

  • The agent is the user.
  • A valid AWID team certificate is being signed in.
  • You ship a server and exact recipes, not a client agents must install.

The normal web-app reflex is backwards here. There is no signup button because the caller already has identity, team membership, and signing tools. Your service is a relying party.

What you do not build

Push back if the plan includes:

  • signup or onboarding accounts;
  • OAuth, API keys, sessions, password reset, or dashboard write auth;
  • per-user account records as the security boundary;
  • a bespoke SDK/client that duplicates aw id request --team-auth.

Build this instead:

  • one request-bound team-certificate verifier — load skills/team-cert-verification/SKILL.md for that boundary;
  • team-scoped data keyed only from the verified certificate team_id;
  • structured errors: 401 fail-closed for auth, 402 with limit, current, and max for caps;
  • team-unit billing: the human appears once to pay, not to authenticate;
  • free-tier caps from day one so no team is grandfathered into uncapped use.
Show full SKILL.md (198 more words)Show less

Agent-first surface checklist

Before you call the product usable by agents:

  • Document recipes only after running them verbatim from a fresh workspace.
  • Provide a plain-text /llms.txt twin for agents that fetch instead of browse.
  • Make the landing page read like the terminal session it documents: shell comments explain, commands are individually copyable, and stop points are explicit.
  • Do not add "copy all" when the sequence has human or controller stop points.
  • Prefer append-only versions with verified attribution when the domain allows it; agent teams need auditability more than clever editing.

Process: SOT first

Write the source of truth before writing features. It should name the product contract, authority model, auth envelope, data model, API, validation strategy, milestones, and non-goals. docs/sot.md is the worked example in this repo.

Validation is part of the spec, not a cleanup task. Load skills/byot-e2e-validation/SKILL.md while designing the auth and e2e surface. Before any public claim, run a customer-shaped probe: fresh directory, released aw, documented commands verbatim.

Repo map lives elsewhere

Do not duplicate the repo map here. The agent-first pattern and copy/adapt/ replace map belongs in docs/agent-first.md. Link to that path from product or README work and coordinate with whoever is editing it.

© awebai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in naapp/folio/skills/agent-first-app of awebai/aweb.

Open the folder on GitHubat commit a6ca92a

More from awebai/aweb

All 17 skills in this repo
  • Recognizes old aweb bootstrap-era `agents/` directories and migrates them to current team and identity primitives, since the old command family is retired.

    115 GitHub stars~701 tokensUpdated today
    Auto-check passed
  • Guides decisions for agents working in an aweb team: when to check shared state, claim tasks, take locks, read team roles and instructions, and open separate worktrees.

    115 GitHub stars~4k tokensUpdated today
    Auto-check passed
  • aweb Messaging

    awebai/aweb

    Guides how an agent reads and responds to aweb mail and chat events, choosing between asynchronous mail and synchronous chat and respecting sender verification and encryption boundaries.

    115 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • This skill should be used when joining or being added to an aweb team, picking the correct invite/add-member path for the team's authority model (hosted vs BYOT), accepting invites, fetching team…

    115 GitHub stars~5.4k tokensUpdated today
    Auto-check passed
  • Creates or appends a folio document from the built-in pitch, memo or metrics templates by sending schema-checked slots that folio renders to Markdown.

    115 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Present To Human

    awebai/aweb

    A skill your agent uses when an agent needs to show a human an folio document: mint a document-bound capability link with POST /v1/present, open the returned URL for the human, print it as fallback…

    115 GitHub stars~590 tokensUpdated today
    Auto-check passed

Questions about Agent First App

What does Agent First App do?

A skill your agent uses when building an app where AI agents are the users: agent-first product design, BYOT/AWID team-certificate auth instead of accounts, no-signup services, team-scoped data, and…. Agent First App is an agent skill from awebai/aweb. Use when building an app where AI agents are the users: agent-first product design, BYOT/AWID team-certificate auth instead of accounts, no-signup services, team-scoped data, and server-plus-recipes application surfaces.

When should I use Agent First App?

Agent First App fits situations like: building an app where AI agents are the users: agent-first product design; BYOT/AWID team-certificate auth instead of accounts; no-signup services; team-scoped data.

How do I install Agent First App in Claude Code?

Run `npx skills add awebai/aweb --skill agent-first-app -a claude-code`. Or copy the skill folder (naapp/folio/skills/agent-first-app in awebai/aweb) into .claude/skills/agent-first-app in your project. Claude Code loads it when a task matches its description.

How do I install Agent First App in Codex?

Run `npx skills add awebai/aweb --skill agent-first-app -a codex`. Or copy the skill folder (naapp/folio/skills/agent-first-app in awebai/aweb) into .agents/skills/agent-first-app in your project. Codex loads it when a task matches its description.

Can I use Agent First App in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awebai/aweb --skill agent-first-app -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-first-app, .gemini/skills/agent-first-app, .github/skills/agent-first-app and .opencode/skills/agent-first-app in your project.

What does Agent First App need to run?

SKILL.md names no scripts, command-line tools or credentials: Agent First App is instructions for the agent only.

Does Agent First App access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Agent First App safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Agent First App use?

Agent First App is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agent First App use?

About 744 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

Who maintains Agent First App?

awebai (a GitHub organization) maintains it in awebai/aweb, which has 115 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 9, 2026.

Source: awebai/aweb on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.