Agent skill

Serviceradar Bazel Guardrails

by carverauto in carverauto/serviceradar

Use before creating a worktree, script, or ad hoc orchestration, handling generated Bazel artifacts, changing native add-ons, or adding serviceradarcore tests.

Apache-2.0Auto-check passedAI & LLM Engineering

Install Serviceradar Bazel Guardrails

skills CLI
$ npx skills add carverauto/serviceradar --skill serviceradar-bazel-guardrails -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install carverauto/serviceradar serviceradar-bazel-guardrails --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/carverauto/serviceradar.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/serviceradar-bazel-guardrails .claude/skills/serviceradar-bazel-guardrails && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
serviceradar-bazel-guardrails
GitHub stars
921
Token cost
~1.3k tokens
SKILL.md length
667 words
Files
1
Skills in repo
18
Repo updated
First seen
Licence
Apache-2.0

At a glance

Use before creating a worktree, script, or ad hoc orchestration, handling generated Bazel artifacts, changing native add-ons, or adding serviceradarcore tests.

  • Tasks that involve Git worktrees
  • Calls bazel, git and make
  • Tasks that involve LLM guardrails

What it does

Serviceradar Bazel Guardrails is an agent skill from carverauto/serviceradar. Use before creating a worktree, script, or ad hoc orchestration, handling generated Bazel artifacts, changing native add-ons, or adding serviceradarcore tests.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering, covering Git worktrees and LLM guardrails. The repository describes itself as: Open-Source Network Management, Monitoring, ITOM, and Security Analytics. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Git worktrees
  • Tasks that involve LLM guardrails

Example prompts

  • “/serviceradar-bazel-guardrails”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 2563b3f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bazel
    • git
    • make
    • go
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Serviceradar Bazel Guardrails loads about 1.3k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 667 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from carverauto/serviceradar at commit 2563b3f, republished under its Apache-2.0 licence (© carverauto). 667 words, ~1,289 tokens.

Download SKILL.mdSave it as .claude/skills/serviceradar-bazel-guardrails/SKILL.md (or your agent's skills folder).
name
serviceradar-bazel-guardrails
description
Use before creating a worktree, script, or ad hoc orchestration, handling generated Bazel artifacts, changing native add-ons, or adding serviceradar_core tests.
user-invocable
false
metadata.internal
true

ServiceRadar Bazel Guardrails

  • After git worktree add (or any extra checkout), symlink the gitignored Bazel rc files before any bazel command. .bazelrc try-imports %workspace%/.bazelrc.remote and .bazelrc.local. Both are gitignored: they hold the BuildBuddy API key and the remote cache/executor overrides. git worktree add only checks out tracked files, so a new worktree has neither. Without them --config=remote / --config=ci cannot authenticate: Bazel prints PERMISSION_DENIED: Missing API key and never reaches RBE (local crawl or abort). bb view still works from the primary clone — that is not proof the worktree is wired for remote execution. From the checkout that already has the files:

    ln -sfn "$PRIMARY/.bazelrc.remote" "$WT/.bazelrc.remote"
    test -e "$PRIMARY/.bazelrc.local" && ln -sfn "$PRIMARY/.bazelrc.local" "$WT/.bazelrc.local"
    test -f "$WT/.bazelrc.remote"

    Same rule for /tmp/... trees, jj workspace add, and extra clones. Never commit those files.

  • Never read generated Bazel output. No cp out of bazel-out, no bazel info bazel-bin plus a path, no bazel cquery --output=files followed by reading the file. The output tree is a cache, not an interface: it can be wiped at any time, and its path encodes the configuration that produced it, so an artifact found under bazel-out/rbe_platform-opt/ is whatever happened to be built with that platform and compilation mode — the same command with a different -c or --config silently reads something else, or nothing.

    This tree hides the path deliberately: //.bazelrc sets --experimental_convenience_symlinks=clean, so there is no bazel-out symlink at the workspace root. A copy that appears to do nothing there is that guard working. Do not route around it by resolving an absolute path by hand.

    Express the need as a target instead: a filegroup consumed as a declared input, or write_source_files from aspect_bazel_lib to copy an artifact back into the tree. When a generated file must be committed — protoc output embedded with include_bytes! so cargo works without Bazel, generated bindings — the pattern is a committed copy, a diff_test that says when it is stale, and a write-back target that makes it current. See //config/manager_config/rust:update_embedded_instances, which copies from runfiles. If a write-back target is missing, add one rather than doing the copy by hand.

  • No shell scripts. Everything is a Bazel target. Do not add a script under scripts/, and do not extend an existing one. Build, test, provisioning, teardown, packaging and publishing are Bazel targets invoked with bazel build / bazel test / bazel run. A script is a build system with no dependency graph, no cache, no sandbox and no remote execution — every one of them is a hole in the graph that has to be re-run, re-debugged and re-documented by hand.

    The only permitted exception is a hard corner case that genuinely cannot be a Bazel action, and it must be justified in a comment at the top of the file. Today that means credential handling that must not become an action input: Docker/registry authentication and cosign/OpenBao signing setup, plus materializing rotating SRQL fixture credentials in the Bazel client's environment before database test actions start. "It was easier" is not a corner case.

    Corollaries:

    • Work an existing script does belongs in a target. //rust/integration-db already replaced scripts/{reset,drop,sweep-stale-core}-test-db.sh — those files are dead and should be deleted, not maintained.
    • A test needing a file gets it as a declared input (data/srcs), never from a script writing it to a runner temp dir and exporting a path. That pattern is what forces no-remote-exec and breaks RBE.
    • Ordering between targets is the caller's sequence of bazel invocations, not a script that wraps them.
Show full SKILL.md (110 more words)Show less

Two registration gates fail only under make test/BazelCI — never under mix test, go test, cargo test or a PR check — so a missing entry looks green all the way to trunk unless the no-mistakes pipeline catches it first:

  • Adding or changing a native add-on (addons/<name>/ + a Go/Rust binary) must be registered in four places, and any change to its source, config or BUILD.bazel requires bumping addons/<name>/addon.yaml version.
  • Adding an elixir/serviceradar_core test file requires a row in elixir/serviceradar_core/test/INTEGRATION_SOURCE_DISPOSITIONS.tsv. The no-mistakes test-registration gate (.no-mistakes.yaml) now runs this contract before push, so a missing row is caught there instead of only in BazelCI.

Both procedures, with their local verification commands, are in docs/agent-runbooks.md.

© carverauto, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/serviceradar-bazel-guardrails of carverauto/serviceradar.

Open the folder on GitHubat commit 2563b3f

Compare with similar skills

Serviceradar Bazel Guardrails next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Serviceradar Bazel Guardrails compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Serviceradar Bazel Guardrails this skillcarverauto/serviceradar921—~1.3kAutomated safety check: PassApache-2.0
Implementation Kickoffopenai/openai-guardrails-js105—~1kAutomated safety check: PassMIT
Aisafetyhotwuyoscar/AISafetyHot-Hub827—~1.4kAutomated safety check: PassCustom licence
ObliteratusRedWoodOG/Hermes-Desktop1775 repos~3.8kAutomated safety check: PassMIT
Lemonade Router Builderamd/skills408—~4kAutomated safety check: PassMIT
Explore Codelllllllama/RigorPilot-Skills4971 repos~648Automated safety check: PassMIT

Similar skills

  • Implementation Kickoff

    openai/openai-guardrails-js

    Official

    Start or resume a requested Guardrails implementation or PR takeover in the selected linked worktree with bounded scope and verification.

    105 GitHub stars~1k tokensUpdated 3 days ago
    AI & LLM EngineeringAuto-check passed
  • Aisafetyhot

    wuyoscar/AISafetyHot-Hub

    Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service.

    827 GitHub stars~1.4k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Obliteratus

    RedWoodOG/Hermes-Desktop

    Remove refusal behaviors from open-weight LLMs using OBLITERATUS — mechanistic interpretability techniques (diff-in-means, SVD, whitened SVD, LEACE, SAE decomposition, etc.) to excise guardrails…

    177 GitHub starsUsed in 5 repos~3.8k tokens
    AI & LLM EngineeringAuto-check passed
  • Turns a natural-language description of routing intent into a valid Lemonade collection.router policy JSON.

    408 GitHub stars~4k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Explore Code

    lllllllama/RigorPilot-Skills

    Rigor Improve implementation leaf skill for auditable candidate implementation in deep learning research repositories.

    497 GitHub starsUsed in 1 repo~648 tokens
    AI & LLM EngineeringAuto-check passed
  • Writing Eval Scenarios

    open-bias/open-bias

    Guide for writing eval conversation JSONs and running them through policy engines

    143 GitHub stars~1.5k tokensUpdated 4 days ago
    AI & LLM EngineeringAuto-check passed

More from carverauto/serviceradar

All 18 skills in this repo
  • Demo Cnpg Local Web Ng

    carverauto/serviceradar

    Run ServiceRadar web-ng locally against the live Kubernetes demo CNPG database for dashboard, SRQL, services, and UI testing.

    921 GitHub stars~672 tokensUpdated yesterday
    Auto-check passed
  • Web Ng Docker Loop

    carverauto/serviceradar

    Run ServiceRadar elixir/web-ng locally against the Docker Compose CNPG database with copied mTLS certs and Docker secrets, then verify dashboard UI changes with Playwright.

    921 GitHub stars~737 tokensUpdated yesterday
    Auto-check passed
  • Demo Local Rollout

    carverauto/serviceradar

    Build unpublished sha-... An agent skill from carverauto/serviceradar.

    921 GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • Demo Web Ng Fastpath

    carverauto/serviceradar

    Refresh the Kubernetes demo namespace with a web-ng-only change using the ServiceRadar fast path.

    921 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Fieldsurvey Local Web Ng

    carverauto/serviceradar

    Run ServiceRadar web-ng locally against the Kubernetes demo namespace FieldSurvey data, including CNPG NodePort access, NATS Object Store artifact access, authenticated browser checks, and…

    921 GitHub stars~785 tokensUpdated yesterday
    Auto-check passed
  • Release Cut And Demo Roll

    carverauto/serviceradar

    Cut a ServiceRadar release and roll the Kubernetes demo namespace to the resulting published semver image tag through the guarded ArgoCD release branch.

    921 GitHub stars~3.9k tokensUpdated yesterday
    Auto-check passed

Questions about Serviceradar Bazel Guardrails

What does Serviceradar Bazel Guardrails do?

Use before creating a worktree, script, or ad hoc orchestration, handling generated Bazel artifacts, changing native add-ons, or adding serviceradarcore tests. Serviceradar Bazel Guardrails is an agent skill from carverauto/serviceradar. Use before creating a worktree, script, or ad hoc orchestration, handling generated Bazel artifacts, changing native add-ons, or adding serviceradarcore tests.

When should I use Serviceradar Bazel Guardrails?

Serviceradar Bazel Guardrails fits situations like: tasks that involve Git worktrees; tasks that involve LLM guardrails.

How do I install Serviceradar Bazel Guardrails in Claude Code?

Run `npx skills add carverauto/serviceradar --skill serviceradar-bazel-guardrails -a claude-code`. Or copy the skill folder (.agents/skills/serviceradar-bazel-guardrails in carverauto/serviceradar) into .claude/skills/serviceradar-bazel-guardrails in your project. Claude Code loads it when a task matches its description.

How do I install Serviceradar Bazel Guardrails in Codex?

Run `npx skills add carverauto/serviceradar --skill serviceradar-bazel-guardrails -a codex`. Or copy the skill folder (.agents/skills/serviceradar-bazel-guardrails in carverauto/serviceradar) into .agents/skills/serviceradar-bazel-guardrails in your project. Codex loads it when a task matches its description.

Can I use Serviceradar Bazel Guardrails in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add carverauto/serviceradar --skill serviceradar-bazel-guardrails -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/serviceradar-bazel-guardrails, .gemini/skills/serviceradar-bazel-guardrails, .github/skills/serviceradar-bazel-guardrails and .opencode/skills/serviceradar-bazel-guardrails in your project.

What does Serviceradar Bazel Guardrails need to run?

Going by SKILL.md and its folder, Serviceradar Bazel Guardrails needs the command-line tools its instructions call (bazel, git, make, go and cargo). Our summary lists: Docker.

Does Serviceradar Bazel Guardrails access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Serviceradar Bazel Guardrails safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Serviceradar Bazel Guardrails use?

Serviceradar Bazel Guardrails is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Serviceradar Bazel Guardrails use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Serviceradar Bazel Guardrails?

Skills that share tags, products or a category with Serviceradar Bazel Guardrails: Implementation Kickoff (openai/openai-guardrails-js, 105 stars), Aisafetyhot (wuyoscar/AISafetyHot-Hub, 827 stars), Obliteratus (RedWoodOG/Hermes-Desktop, 177 stars) and Lemonade Router Builder (amd/skills, 408 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Serviceradar Bazel Guardrails?

carverauto (a GitHub organization) maintains it in carverauto/serviceradar, which has 921 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 10, 2026.

Source: carverauto/serviceradar on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.