Agent skill

Endpoint Management

by cbrock84 in cbrock84/headcount

Manages laptops, desktops and mobile devices — enrollment, configuration, patching, software distribution, and lost or compromised devices.

MITAuto-check passed

Install Endpoint Management

skills CLI
$ npx skills add cbrock84/headcount --skill endpoint-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cbrock84/headcount endpoint-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cbrock84/headcount.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/it-operations/skills/endpoint-management .claude/skills/endpoint-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
endpoint-management
GitHub stars
2k
Token cost
~970 tokens
SKILL.md length
534 words
Files
2 (incl. references)
Skills in repo
178
Repo updated
First seen
Licence
MIT

At a glance

Manages laptops, desktops and mobile devices — enrollment, configuration, patching, software distribution, and lost or compromised devices.

  • SKILL.md covers Enrollment is the control point, A small number of standard…, Patch on a cadence with a… and Lost, stolen, or leaving, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Endpoint Management is an agent skill from cbrock84/headcount. Manages laptops, desktops and mobile devices — enrollment, configuration, patching, software distribution, and lost or compromised devices. Use this to set up device management, standardize builds, roll out software or an OS upgrade, handle a lost device, or bring an unmanaged fleet under control.

Its SKILL.md is about 970 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/sources.md`).

The repository describes itself as: An agent organization structured as a company — 15+ departments, 125+ skills, each independently installable, citing the standards and regulators that settle the question. Runs… The licence is MIT.

Example prompts

  • “Use the endpoint-management skill to manage laptops, desktops and mobile devices — enrollment, configuration, patching, software distribution, and…”
  • “/endpoint-management”

What it can do on your machine

Read from SKILL.md and the folder at commit 98d1c17. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Endpoint Management loads about 970 tokens when it runs, and up to ~1.5k if it reads all its reference files. Until then it costs about 80 tokens; SKILL.md has 534 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~970
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cbrock84/headcount at commit 98d1c17, republished under its MIT licence (© cbrock84). 534 words, ~970 tokens.

Download SKILL.mdSave it as .claude/skills/endpoint-management/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
endpoint-management
description
Manages laptops, desktops and mobile devices — enrollment, configuration, patching, software distribution, and lost or compromised devices. Use this to set up device management, standardize builds, roll out software or an OS upgrade, handle a lost device, or bring an unmanaged fleet under control.

Endpoint management

Endpoints are the most exposed and least controlled part of the estate: they leave the building, run arbitrary software, and are operated by people whose job is not IT.

Enrollment is the control point

A device that never enrolled is a device with no patching, no encryption guarantee, and no remote wipe. Enrollment must be a precondition of access to company data, not a request made afterwards.

Automate it from procurement so a device is enrolled before the user opens it. Manual enrollment as a post-delivery step is skipped exactly when the desk is busy.

Handle personal devices as a deliberate policy decision, not an accident. If personal devices reach company data, either manage the work container or restrict what they can reach — and be explicit with people about what the organization can and cannot see on their own hardware, because ambiguity there destroys trust quickly.

A small number of standard builds

Every additional build variant multiplies testing, support and failure modes. Converge on few, and handle exceptions by adding software to a standard build rather than by creating a new one.

Enforce the security baseline through configuration policy rather than instruction: disk encryption on, screen lock, firewall, up-to-date agents. Anything relying on a user to configure it is configured on some devices.

Patch on a cadence with a deadline

Endpoints patch worse than servers because they are off, asleep, or the user keeps deferring. Allow deferral with a hard deadline and force after it, and communicate the deadline in advance — an unexpected forced reboot during a customer call is what teaches people to avoid management.

Report coverage as a percentage of the fleet, and specifically chase the long tail. The devices that never appear in patch reports are usually the interesting ones: traveling users, spares, and the machine in a cupboard still holding a domain account.

Show full SKILL.md (225 more words)Show less

Lost, stolen, or leaving

Have the sequence ready in advance: lock, locate if possible, wipe, revoke credentials and sessions, and record what data was on it for legal-risk:privacy-and-data-protection to assess notification.

Encryption is what turns a lost laptop from an incident into paperwork. Verify enforcement continuously rather than trusting the policy is applied — the device where it silently failed is the one that gets left in a taxi.

Departures are coordinated with people:onboarding-and-offboarding, with asset return tracked against it-operations:it-asset-management.

Sources

references/sources.md in this skill lists the outside authorities that settle the questions here — what each one is authoritative for, and what you may do with it. Check them before answering on anything they cover, and cite what you used. Most are free to read and not free to reproduce; the use note on each is binding.

Tooling

Windows: Microsoft Intune, Configuration Manager, Ivanti, and similar. Apple: Jamf Pro, Kandji, Mosyle, and similar. Cross-platform: NinjaOne, Automox, Addigy, and similar.

Endpoint protection: Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, and similar.

Pick for your fleet's majority and accept a second tool for the minority. One tool that half-manages both platforms costs more than two that each work.

Never

  • Allow company data onto a device that never enrolled.
  • Rely on users to apply security configuration.
  • Allow indefinite patch deferral.
  • Assume encryption is on without verifying it per device.

© cbrock84, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/it-operations/skills/endpoint-management of cbrock84/headcount.

  • SKILL.md
  • references/sources.md

Open the folder on GitHubat commit 98d1c17

Compare with similar skills

Endpoint Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Endpoint Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Endpoint Management this skillcbrock84/headcount2k—~970Automated safety check: PassMIT
Mdm Device Managementsickn33/agentic-awesome-skills47k1 repos~3kAutomated safety check: NotesMIT
Implementing Patch Management For Ot Systemsmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Implementing Patch Management Workflowmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Managing Endpoint VersionsPostHog/posthog40k—~2.3kAutomated safety check: PassCustom licence
Agent Platform Endpoint Managementgoogle/skills21k—~1.6kAutomated safety check: PassApache-2.0

Similar skills

  • Mdm Device Management

    sickn33/agentic-awesome-skills

    Manage and secure company devices with MDM solutions. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 1 repo~3k tokens
    DevOps & CloudAuto-check: notes
  • Implementing Patch Management For Ot Systems

    mukul975/Anthropic-Cybersecurity-Skills

    Implements a structured patch management program for OT/ICS environments where IT-style patching can cause process disruption or safety hazards, covering vendor compatibility testing, risk-based…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Implementing Patch Management Workflow

    mukul975/Anthropic-Cybersecurity-Skills

    Patch management is the systematic process of identifying, testing, deploying, and verifying software updates to remediate vulnerabilities across an organization's IT infrastructure.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Official

    Work safely with endpoint versions — preview a draft in the playground, roll back to an older version, update settings on one version without bumping query history, deactivate a specific version.

    40k GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Manages Agent Platform serving endpoints. An agent skill from google/skills.

    21k GitHub stars~1.6k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Mdm Device Management

    BagelHole/DevOps-Security-Agent-Skills

    Manage and secure company devices with MDM solutions — enroll macOS, Windows, iOS, and Android devices, enforce security policies, and automate software deployment.

    1.1k GitHub stars~5.7k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check: notes

More from cbrock84/headcount

All 178 skills in this repo
  • Agent Hierarchy

    cbrock84/headcount

    Designs orchestrator-and-subagent hierarchies for a repository — splitting agents by exclusive write surface, pairing every producer with an independent auditor, and enforcing the split with a…

    2k GitHub stars~1.2k tokensUpdated 21 days ago
    Auto-check passed
  • Access And Identity

    cbrock84/headcount

    Designs and audits who can reach what — authentication, authorization models, privileged access, service credentials, and joiner-mover-leaver process.

    2k GitHub stars~1.1k tokensUpdated 21 days ago
    Auto-check passed
  • Account Based Marketing

    cbrock84/headcount

    Concentrates marketing and sales effort on a named set of accounts rather than on volume — qualifying whether the model fits your economics at all, building the account list and the buying group…

    2k GitHub stars~1.2k tokensUpdated 21 days ago
    Auto-check passed
  • Activation

    cbrock84/headcount

    Gets new users from signup to first real value — signup flow, onboarding, time-to-value, and the early experience that determines whether someone becomes a user or a lapsed account.

    2k GitHub stars~865 tokensUpdated 21 days ago
    Auto-check passed
  • AI ML Governance

    cbrock84/headcount

    Governs models and AI systems in production — intended use, evaluation, monitoring, human oversight, documentation, and the decision to deploy or retire.

    2k GitHub stars~1k tokensUpdated 21 days ago
    Auto-check passed
  • AI Research Analyst

    cbrock84/headcount

    Produces executive-level research — market sizing, competitor mapping, trend analysis, and strategic intelligence — grounded in cited sources with the confidence in each claim made explicit.

    2k GitHub stars~916 tokensUpdated 21 days ago
    Auto-check passed

Questions about Endpoint Management

What does Endpoint Management do?

Manages laptops, desktops and mobile devices — enrollment, configuration, patching, software distribution, and lost or compromised devices. Endpoint Management is an agent skill from cbrock84/headcount. Manages laptops, desktops and mobile devices — enrollment, configuration, patching, software distribution, and lost or compromised devices.

How do I install Endpoint Management in Claude Code?

Run `npx skills add cbrock84/headcount --skill endpoint-management -a claude-code`. Or copy the skill folder (plugins/it-operations/skills/endpoint-management in cbrock84/headcount) into .claude/skills/endpoint-management in your project. Claude Code loads it when a task matches its description.

How do I install Endpoint Management in Codex?

Run `npx skills add cbrock84/headcount --skill endpoint-management -a codex`. Or copy the skill folder (plugins/it-operations/skills/endpoint-management in cbrock84/headcount) into .agents/skills/endpoint-management in your project. Codex loads it when a task matches its description.

Can I use Endpoint Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cbrock84/headcount --skill endpoint-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/endpoint-management, .gemini/skills/endpoint-management, .github/skills/endpoint-management and .opencode/skills/endpoint-management in your project.

What does Endpoint Management need to run?

SKILL.md names no scripts, command-line tools or credentials: Endpoint Management is instructions for the agent only.

Does Endpoint Management access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Endpoint Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Endpoint Management use?

Endpoint Management is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Endpoint Management use?

About 970 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 536 tokens, read only when the agent opens those files.

What are the alternatives to Endpoint Management?

Skills that share tags, products or a category with Endpoint Management: Mdm Device Management (sickn33/agentic-awesome-skills, 47k stars), Implementing Patch Management For Ot Systems (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Patch Management Workflow (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Managing Endpoint Versions (PostHog/posthog, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Endpoint Management?

cbrock84 (a GitHub user) maintains it in cbrock84/headcount, which has 2,016 GitHub stars. The repository holds 178 skills in this directory. The repository was last updated on September 17, 2026.

Source: cbrock84/headcount on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.