Agent skill

Claude Exec

by boshu2 in boshu2/agentops

Run one prompt through headless Claude with scoped permissions and a time bound.

Apache-2.0Auto-check passed

Install Claude Exec

skills CLI
$ npx skills add boshu2/agentops --skill claude-exec -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install boshu2/agentops claude-exec --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/boshu2/agentops.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/claude-exec .claude/skills/claude-exec && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
claude-exec
GitHub stars
447
Used in
1 other repo
Token cost
~1.1k tokens
SKILL.md length
378 words
Files
1
Skills in repo
31
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run one prompt through headless Claude with scoped permissions and a time bound.

  • Works in 5 steps: Inherited posture. A bare run loads the… → Renewed time. One bound, from the… → Exit 0 as proof. A denied call still… → …
  • Automating a claude -p call
  • SKILL.md covers Failure modes of a quick…, Run and Result
  • Calls claude

What it does

Claude Exec is an agent skill from boshu2/agentops. Run one prompt through headless Claude with scoped permissions and a time bound. Use when: scripting or automating a claude -p call, even a simple one.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: DevOps discipline for AI coding agents: shape the work, track it as a graph, and get each change judged by a context that didn't write it. The licence is Apache-2.0.

When your agent uses it

  • Automating a claude -p call
  • Even a simple one

Example prompts

  • “/claude-exec”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Inherited posture. A bare run loads the user's settings, hooks,
  2. Renewed time. One bound, from the caller's remaining time: a retry
  3. Exit 0 as proof. A denied call still exits 0 with is_error: false
  4. Silent fallback. With no claude, login or model, report and stop
  5. Self-review. Review runs as a separate session, never the author's.

What it can do on your machine

Read from SKILL.md and the folder at commit 3bdbfed. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • claude

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Claude Exec loads about 1.1k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 378 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from boshu2/agentops at commit 3bdbfed, republished under its Apache-2.0 licence (© boshu2). 378 words, ~1,111 tokens.

Download SKILL.mdSave it as .claude/skills/claude-exec/SKILL.md (or your agent's skills folder).
name
claude-exec
description
Run one prompt through headless Claude with scoped permissions and a time bound. Use when: scripting or automating a `claude -p` call, even a simple one.
skill_api_version
1
user-invocable
true
hexagonal_role
driving-adapter
practices
pragmatic-programmer, design-by-contract
consumes
claude-command-packet
produces
claude-run-output
context.window
inherit
metadata.tier
orchestration
metadata.capabilities
claude_exec
metadata.effects
run_claude_process, permission_tiered_workspace_effects

Claude Exec — one-shot runtime adapter

Run one caller-supplied prompt through Claude Code print mode and capture the result, only when the caller selects Claude: the native agent stays the default and batches belong to agent-native. Flags match claude --help for 2.1.282; recheck it on other versions.

Failure modes of a quick claude -p

  1. Inherited posture. A bare run loads the user's settings, hooks, plugins, MCP servers and CLAUDE.md; a settings bypassPermissions default held even under --safe-mode. Use the clean flags below and set --tools and --permission-mode to the task's effects.
  2. Renewed time. One bound, from the caller's remaining time: a retry spends it instead of renewing it. Make one attempt; any other is the caller's decision.
  3. Exit 0 as proof. A denied call still exits 0 with is_error: false and "done", and a bare file name once landed in the run's scratchpad, not $WORKDIR. Name targets by path, check effects there, and leave acceptance to a fresh validator.
  4. Silent fallback. With no claude, login or model, report and stop instead of switching runtimes or passing --fallback-model.
  5. Self-review. Review runs as a separate session, never the author's.
Show full SKILL.md (187 more words)Show less

Run

Redirect the prompt from a file, or pass it as the argument with </dev/null, because print mode reads stdin to EOF: a pipe left open hangs until the bound kills it. Stock macOS lacks timeout: use GNU timeout or Homebrew's gtimeout, and launch nothing without one.

bash
TO=$(command -v timeout || command -v gtimeout) || { echo "no timeout: not launching" >&2; exit 2; }
cd "$WORKDIR" || exit 2
# Read-only: review, research, questions.
"$TO" -k 10 "$SECS" claude -p --model "$MODEL" --output-format json \
  --setting-sources "" --strict-mcp-config --disable-slash-commands \
  --tools "Read,Grep,Glob" --permission-mode dontAsk \
  <"$PROMPT_FILE" >"$OUT" 2>"$ERR"; echo "exit=$?"
# Edit-capable: authorized file changes under $WORKDIR.
"$TO" -k 10 "$SECS" claude -p --model "$MODEL" --output-format json \
  --setting-sources "" --strict-mcp-config --disable-slash-commands \
  --tools "Read,Grep,Glob,Edit,Write" --permission-mode acceptEdits \
  <"$PROMPT_FILE" >"$OUT" 2>"$ERR"; echo "exit=$?"

Print mode never prompts: unapproved calls are denied and listed in permission_denials. Add Bash to --tools only for authorized commands named in --allowedTools, e.g. "Bash(go test *)"; with settings hooks dropped, that list is the guard. --max-budget-usd stops after the call that crosses it, and --help lists no turn cap, so bound a run by time and budget. --no-session-persistence keeps no transcript.

Result

JSON carries result, is_error, session_id, total_cost_usd, num_turns, permission_denials, and modelUsage keyed by the models billed; identity evidence needs stream-json --verbose per the model-dispatch recipe. Judge by exit status and is_error: an unknown model exited 1 with subtype: "success". Exit 1 also covers a spent budget or missing input; timeout gives 124, or 137 when KILL follows 10 seconds later. Keep at most the caller's byte cap (10 MiB default), mark a cut file truncated, return this, and stop:

text
command: <exact argv>    posture: <tools; permission mode; clean flags>
model: <requested> -> <modelUsage keys>    exit: <status | timeout at N s>
session_id: <id | none>    output: <path, bytes, truncated: yes|no>
permission_denials: <count and tools>

© boshu2, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/claude-exec of boshu2/agentops.

Open the folder on GitHubat commit 3bdbfed

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in boshu2/agentops, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Claude Exec next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Claude Exec compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Claude Exec this skillboshu2/agentops4471 repos~1.1kAutomated safety check: PassApache-2.0
Permission Managersickn33/agentic-awesome-skills47k1 repos~595Automated safety check: PassMIT
Performing OAuth Scope Minimization Reviewmukul975/Anthropic-Cybersecurity-Skills34k—~6.2kAutomated safety check: PassApache-2.0
Mem0 Memory Scopemem0ai/mem067k—~1.1kAutomated safety check: PassApache-2.0
Adding API ScopesPostHog/posthog40k—~2.1kAutomated safety check: PassCustom licence
Cognee Permissionstopoteretes/cognee32k—~3.6kAutomated safety check: PassApache-2.0

Similar skills

  • Permission Manager

    sickn33/agentic-awesome-skills

    Manage opencode permissions: review always-allow lists, suggest safe read-only commands, configure permission patterns

    47k GitHub starsUsed in 1 repo~595 tokens
    DevelopmentAuto-check passed
  • Performing OAuth Scope Minimization Review

    mukul975/Anthropic-Cybersecurity-Skills

    Performs OAuth 2.0 scope minimization review to identify over-permissioned third-party application integrations, excessive API scopes, unused token grants, and risky OAuth consent patterns across…

    34k GitHub stars~6.2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Shows or changes the default Mem0 memory scope, project, session or global, which decides where memories are saved and searched.

    67k GitHub stars~1.1k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Adding API Scopes

    PostHog/posthog

    Official

    Guidance for adding an API scope object to posthog/scopes.py and making it work for personal API keys, OAuth tokens and MCP clients.

    40k GitHub stars~2.1k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Cognee Permissions

    topoteretes/cognee

    A skill your agent uses when working with cognee's users, permissions, and multi-tenancy — creating users, tenants and roles, sharing datasets (read/write/delete/share grants), acting as a specific…

    32k GitHub stars~3.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Securing AWS Iam Permissions

    mukul975/Anthropic-Cybersecurity-Skills

    Hardens AWS IAM configurations to enforce least-privilege access, covering IAM policy scoping, permission boundaries, IAM Access Analyzer integration, and credential rotation strategies.

    34k GitHub stars~3.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from boshu2/agentops

All 31 skills in this repo
  • Agent Native

    boshu2/agentops

    Dispatch independent tasks to parallel workers or subagents without write collisions.

    447 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Council

    boshu2/agentops

    Compare independent opinions from several models or contexts without inflating agreement.

    447 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed
  • Craft Goal

    boshu2/agentops

    Draft or lint a bounded long-running goal prompt with a finish line and hard limits.

    447 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed
  • Doc

    boshu2/agentops

    Write or update READMEs, docs, repo instructions and handoff notes, checked against source.

    447 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Idea Genie

    boshu2/agentops

    Brainstorm evidence-backed options for what to build, or stress-test an idea.

    447 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Implement

    boshu2/agentops

    Change or repair code, config or services without weakening tests; report what ran and what did not.

    447 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Questions about Claude Exec

What does Claude Exec do?

Run one prompt through headless Claude with scoped permissions and a time bound. Claude Exec is an agent skill from boshu2/agentops. Run one prompt through headless Claude with scoped permissions and a time bound.

When should I use Claude Exec?

Claude Exec fits situations like: automating a claude -p call; even a simple one.

How do I install Claude Exec in Claude Code?

Run `npx skills add boshu2/agentops --skill claude-exec -a claude-code`. Or copy the skill folder (skills/claude-exec in boshu2/agentops) into .claude/skills/claude-exec in your project. Claude Code loads it when a task matches its description.

How do I install Claude Exec in Codex?

Run `npx skills add boshu2/agentops --skill claude-exec -a codex`. Or copy the skill folder (skills/claude-exec in boshu2/agentops) into .agents/skills/claude-exec in your project. Codex loads it when a task matches its description.

Can I use Claude Exec in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add boshu2/agentops --skill claude-exec -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/claude-exec, .gemini/skills/claude-exec, .github/skills/claude-exec and .opencode/skills/claude-exec in your project.

What does Claude Exec need to run?

Going by SKILL.md and its folder, Claude Exec needs the command-line tools its instructions call (claude).

Does Claude Exec access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Claude Exec safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Claude Exec use?

Claude Exec is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Claude Exec use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Claude Exec?

Skills that share tags, products or a category with Claude Exec: Permission Manager (sickn33/agentic-awesome-skills, 47k stars), Performing OAuth Scope Minimization Review (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Mem0 Memory Scope (mem0ai/mem0, 67k stars) and Adding API Scopes (PostHog/posthog, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Claude Exec?

boshu2 (a GitHub user) maintains it in boshu2/agentops, which has 447 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 7, 2026.

Source: boshu2/agentops on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.