Agent skill

Protected Files

by bradygaster in bradygaster/squad

Zero-dependency bootstrap files that must never import npm packages or SDK code

MITAuto-check passed

Install Protected Files

skills CLI
$ npx skills add bradygaster/squad --skill protected-files -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bradygaster/squad protected-files --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bradygaster/squad.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.copilot/skills/protected-files .claude/skills/protected-files && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
protected-files
GitHub stars
3.3k
Token cost
~712 tokens
SKILL.md length
315 words
Files
1
Skills in repo
31
Repo updated
First seen
Licence
MIT

At a glance

Zero-dependency bootstrap files that must never import npm packages or SDK code

  • Works in 3 steps: Add it to the Protected File List table… → Write a matching zero-dependency… → Add — zero dependencies marker in the…
  • SKILL.md covers Context, Protected File List, Rules and SDK/CLI Package Boundary, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Protected Files is an agent skill from bradygaster/squad. Zero-dependency bootstrap files that must never import npm packages or SDK code

Its SKILL.md is about 710 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with npm. The repository describes itself as: Squad: AI agent teams for any project. The licence is MIT.

Example prompts

  • “/protected-files”

Requirements

  • Node.js

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Add it to the Protected File List table above
  2. Write a matching zero-dependency regression test (see detect-squad-dir-zero-deps.test.ts for the pattern)
  3. Add — zero dependencies marker in the file header

What it can do on your machine

Read from SKILL.md and the folder at commit 1fd7e03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Protected Files loads about 712 tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 315 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~24
When it runs · the whole SKILL.md, loaded when a task matches
~712

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from bradygaster/squad at commit 1fd7e03, republished under its MIT licence (© bradygaster). 315 words, ~712 tokens.

Download SKILL.mdSave it as .claude/skills/protected-files/SKILL.md (or your agent's skills folder).
name
protected-files
description
Zero-dependency bootstrap files that must never import npm packages or SDK code
domain
dependency-safety
confidence
high
source
earned — CLI startup crashes when bootstrap files import SDK code

Context

The CLI (squad-cli) has bootstrap utilities that run before the Squad SDK is loaded. If these files import SDK code (e.g., FSStorageProvider, anything from squad-sdk), the CLI breaks at startup — no helpful error, just a crash.

This skill applies when:

  • Touching any file in packages/squad-cli/src/cli/core/
  • Running sweeping refactors (e.g., "convert all fs calls to StorageProvider")
  • Adding new bootstrap utilities

Protected File List

FilePurpose
packages/squad-cli/src/cli/core/detect-squad-dir.tsFinds .squad/ directory at startup — runs before SDK init
packages/squad-cli/src/cli/core/errors.tsError classes (SquadError, fatal()) — used by all CLI entry points
packages/squad-cli/src/cli/core/gh-cli.tsGitHub CLI wrapper — uses only node:child_process and node:util
packages/squad-cli/src/cli/core/output.tsColor/emoji console output — pure ANSI codes, zero imports
packages/squad-cli/src/cli/core/history-split.tsSeparates portable knowledge from project data — pure string logic

Rules

  • ❌ NEVER convert these files to use FSStorageProvider, StorageProvider, or any SDK abstraction
  • ❌ NEVER add import or require statements referencing packages outside node:* built-ins
  • ✅ ONLY use node:fs, node:path, node:child_process, node:util, and other Node.js built-in modules
  • ✅ DO check this list before sweeping refactors
  • ✅ LOOK for — zero dependencies markers in file headers as a signal

SDK/CLI Package Boundary

The packages/squad-cli/src/cli/core/ directory contains a mix of early-startup bootstrap utilities and later SDK-dependent modules. The protected list above is the authoritative set of zero-dependency bootstrap files. If you need to add SDK imports to another core/ file, verify it is not in the protected list and confirm the SDK is loaded at that point in the startup sequence.

Anti-Patterns

  • Converting all fs calls to StorageProvider without checking this list first
  • Adding import { X } from '@bradygaster/squad-sdk' to a bootstrap file
  • Assuming every file in core/ can safely import SDK code

Adding New Bootstrap Utilities

When adding a new file that runs before SDK init:

  1. Add it to the Protected File List table above
  2. Write a matching zero-dependency regression test (see detect-squad-dir-zero-deps.test.ts for the pattern)
  3. Add — zero dependencies marker in the file header

Regression tests guard these files, but prevention is better than detection.

© bradygaster, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .copilot/skills/protected-files of bradygaster/squad.

Open the folder on GitHubat commit 1fd7e03

Compare with similar skills

Protected Files next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Protected Files compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Protected Files this skillbradygaster/squad3.3k—~712Automated safety check: PassMIT
Defuddlekepano/obsidian-skills49k12 repos~208Automated safety check: PassMIT
Vercel Deploybytedance/deer-flow83k10 repos~797Automated safety check: PassMIT
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
Knap Markdown Templateskepano/obsidian-skills49k2 repos~986Automated safety check: PassMIT
Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop5.3k1 repos~2.2kAutomated safety check: PassMIT

Similar skills

  • Defuddle

    kepano/obsidian-skills

    Uses the Defuddle CLI to pull clean, readable Markdown, JSON or metadata from web pages, stripping navigation, ads and clutter to save tokens.

    49k GitHub starsUsed in 12 repos~208 tokens
    Knowledge ManagementAuto-check passed
  • Vercel Deploy

    bytedance/deer-flow

    Deploys a project to Vercel with one script and no login, then returns a live preview URL and a claim link for moving the deployment into your own Vercel account.

    83k GitHub starsUsed in 10 repos~797 tokens
    DevOps & CloudAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Knap Markdown Templates

    kepano/obsidian-skills

    Renders Markdown notes from Knap templates and JSON data on the command line, including notes built from Defuddle web page output.

    49k GitHub starsUsed in 2 repos~986 tokens
    Documents & OfficeAuto-check passed
  • Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.

    5.3k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed
  • Nx Run Tasks

    nomcopter/react-mosaic

    Helps with running tasks in an Nx workspace. An agent skill from nomcopter/react-mosaic.

    4.8k GitHub starsUsed in 8 repos~613 tokens
    DevelopmentAuto-check passed

More from bradygaster/squad

All 31 skills in this repo
  • Fact Checking

    bradygaster/squad

    Review and validate claims using counter-hypothesis testing.

    3.3k GitHub stars~503 tokensUpdated today
    Auto-check passed
  • Architectural Review

    bradygaster/squad

    How to review PRs for architectural quality — module boundaries, dependency direction, export surface, pattern consistency

    3.3k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Archival Integrity

    bradygaster/squad

    Preserve content when moving entries between tracked Squad state files

    3.3k GitHub stars~735 tokensUpdated today
    Auto-check passed
  • CI Validation Gates

    bradygaster/squad

    Defensive CI/CD patterns: semver validation, token checks, retry logic, and draft detection

    3.3k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • CLI Wiring

    bradygaster/squad

    Checklist and patterns for wiring new CLI commands into cli-entry.ts

    3.3k GitHub stars~501 tokensUpdated today
    Auto-check passed
  • Enables squad agents on different machines to share work via git-based task queuing

    3.3k GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Works with

Questions about Protected Files

What does Protected Files do?

Zero-dependency bootstrap files that must never import npm packages or SDK code. Protected Files is an agent skill from bradygaster/squad.

How do I install Protected Files in Claude Code?

Run `npx skills add bradygaster/squad --skill protected-files -a claude-code`. Or copy the skill folder (.copilot/skills/protected-files in bradygaster/squad) into .claude/skills/protected-files in your project. Claude Code loads it when a task matches its description.

How do I install Protected Files in Codex?

Run `npx skills add bradygaster/squad --skill protected-files -a codex`. Or copy the skill folder (.copilot/skills/protected-files in bradygaster/squad) into .agents/skills/protected-files in your project. Codex loads it when a task matches its description.

Can I use Protected Files in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bradygaster/squad --skill protected-files -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/protected-files, .gemini/skills/protected-files, .github/skills/protected-files and .opencode/skills/protected-files in your project.

What does Protected Files need to run?

SKILL.md names no scripts, command-line tools or credentials: Protected Files is instructions for the agent only. Our summary lists: Node.js.

Does Protected Files access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Protected Files safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Protected Files use?

Protected Files is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Protected Files use?

About 712 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Protected Files?

Skills that share tags, products or a category with Protected Files: Defuddle (kepano/obsidian-skills, 49k stars), Vercel Deploy (bytedance/deer-flow, 83k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars) and Knap Markdown Templates (kepano/obsidian-skills, 49k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Protected Files?

bradygaster (a GitHub user) maintains it in bradygaster/squad, which has 3,257 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 8, 2026.

Source: bradygaster/squad on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.