Agent skill

Installing CLI Tools

by CodeAlive-AI in CodeAlive-AI/ai-driven-development

Install, upgrade, configure, and verify developer CLI tools safely.

MITAuto-check: notes

Install Installing CLI Tools

skills CLI
$ npx skills add CodeAlive-AI/ai-driven-development --skill installing-cli-tools -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CodeAlive-AI/ai-driven-development installing-cli-tools --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CodeAlive-AI/ai-driven-development.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/installing-cli-tools .claude/skills/installing-cli-tools && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
installing-cli-tools
GitHub stars
155
Token cost
~1.5k tokens
SKILL.md length
803 words
Files
2
Skills in repo
22
Repo updated
First seen
Licence
MIT

At a glance

Install, upgrade, configure, and verify developer CLI tools safely.

  • Works in 9 steps: Identify the exact CLI, target… → Check current state with narrow commands… → Research current official installation… → …
  • A user asks to install a new CLI
  • SKILL.md covers Overview, Workflow, Secret Handling and Installation Checks, plus 3 more sections
  • Calls brew, npm and python3

What it does

Installing CLI Tools is an agent skill from CodeAlive-AI/ai-driven-development. Install, upgrade, configure, and verify developer CLI tools safely. Use when a user asks to install a new CLI, command-line app, SDK tool, package-manager binary, GitHub release binary, language runtime tool, or AI/vendor CLI; configure shell PATH/completions; run first login; set API keys, tokens, or env variables for a CLI; migrate an existing CLI install; or troubleshoot a CLI installation while avoiding secret leakage.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It works with GitHub. The repository describes itself as: Practices, protocols, and skills for AI-driven software development. Skills and safety hooks for Claude Code, Codex, OpenCode, Cursor, Antigravity, and any agent supporting the… The licence is MIT.

When your agent uses it

  • A user asks to install a new CLI
  • Command-line app
  • Package-manager binary
  • GitHub release binary

Example prompts

  • “/installing-cli-tools”

Requirements

  • Python 3

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Identify the exact CLI, target OS/architecture, intended use, and whether authentication is required.
  2. Check current state with narrow commands such as command -v tool, tool --version, package-manager queries, and existing config file paths…
  3. Research current official installation docs before acting unless the user supplied an exact trusted source. Prefer official docs, package…
  4. Choose the least surprising install method
  5. Install to a user-writable, reversible location when possible. Avoid sudo unless the install path truly requires it and the user has agreed.
  6. Wire PATH/completions only as narrowly as needed. Never edit shell startup files to add secrets.
  7. Configure authentication through a safe channel.
  8. Verify with tool --version, tool doctor or equivalent, and a non-destructive authenticated command if relevant.
  9. Report what changed, where files were placed, how to undo it, and whether any restart/new shell is needed.

What it can do on your machine

Read from SKILL.md and the folder at commit 25b7b1d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • brew
    • npm
    • python3
    • uv
    • cargo
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Installing CLI Tools loads about 1.5k tokens when it runs. Until then it costs about 112 tokens; SKILL.md has 803 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:29
    or search for existing secret values in `.env`, shell rc files, keychains, SSH keys, cloud credential files, or password

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from CodeAlive-AI/ai-driven-development at commit 25b7b1d, republished under its MIT licence (© CodeAlive-AI). 803 words, ~1,510 tokens.

Download SKILL.mdSave it as .claude/skills/installing-cli-tools/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
installing-cli-tools
description
Install, upgrade, configure, and verify developer CLI tools safely. Use when a user asks to install a new CLI, command-line app, SDK tool, package-manager binary, GitHub release binary, language runtime tool, or AI/vendor CLI; configure shell PATH/completions; run first login; set API keys, tokens, or env variables for a CLI; migrate an existing CLI install; or troubleshoot a CLI installation while avoiding secret leakage.

Installing CLI Tools

Overview

Use this skill to take a CLI from "not installed" to "usable and verified" without exposing credentials in chat, logs, shell history, or repo files. Treat installation and secret setup as separate phases.

Workflow

  1. Identify the exact CLI, target OS/architecture, intended use, and whether authentication is required.
  2. Check current state with narrow commands such as command -v tool, tool --version, package-manager queries, and existing config file paths only when needed.
  3. Research current official installation docs before acting unless the user supplied an exact trusted source. Prefer official docs, package registry pages, signed release notes, or the upstream GitHub release.
  4. Choose the least surprising install method:
    • Existing project manager (brew, npm, pipx, uv tool, cargo install, go install) when official and maintained.
    • Vendor installer only when it is the official path and its behavior is understood.
    • Manual binary install only after verifying architecture, checksum/signature when available, permissions, and destination.
  5. Install to a user-writable, reversible location when possible. Avoid sudo unless the install path truly requires it and the user has agreed.
  6. Wire PATH/completions only as narrowly as needed. Never edit shell startup files to add secrets.
  7. Configure authentication through a safe channel.
  8. Verify with tool --version, tool doctor or equivalent, and a non-destructive authenticated command if relevant.
  9. Report what changed, where files were placed, how to undo it, and whether any restart/new shell is needed.

Secret Handling

Never read, print, summarize, grep, or search for existing secret values in .env, shell rc files, keychains, SSH keys, cloud credential files, or password-manager vaults. Do not run broad commands like env, printenv, or recursive token searches.

For new credentials, use the safest supported option in this order:

  1. Browser/device OAuth or official tool auth login.
  2. The platform's secure setup flow or connector for that provider.
  3. OS credential store, such as macOS Keychain, through commands that accept the secret via stdin or hidden prompt.
  4. Tool-specific config command that prompts interactively and does not echo the input.
  5. A local secrets manager such as op, bw, pass, gopass, or direnv with a secret backend, if the user already uses it.
  6. A plaintext env file only when the user explicitly asks for it or the CLI has no safer option; write placeholders by default and set mode 0600.

Do not put secret values in command arguments, chat messages, shell history, logs, generated docs, git commits, package manager config, MCP config, or shell startup files. If a command needs a value, prefer an interactive prompt, stdin, or a temporary file with 0600 permissions that is removed immediately after use.

Before accepting a credential from the user, state the destination and persistence model in one sentence, for example: "This will store the token in macOS Keychain under service example-cli; I will not print it back." If the current environment cannot safely accept hidden input, stop and ask the user to run the official login command locally.

Show full SKILL.md (308 more words)Show less

Installation Checks

Use precise commands and avoid noisy discovery. Good checks:

sh
command -v example
example --version
brew list --versions example
npm view example-cli version
python3 -m pipx list

For GitHub release binaries, verify the asset matches OS and CPU architecture. Use shasum -a 256 when upstream publishes checksums. Prefer signed or notarized macOS artifacts when available.

For installer scripts fetched over the network, do not pipe directly into a shell unless the user explicitly requests that official install style. Prefer downloading to a temporary file, reading the script enough to understand what it changes, then running it.

Shell Integration

Modify shell files only for PATH, completions, aliases requested by the user, or non-secret configuration. Before editing, identify the active shell and target file. Keep edits idempotent and bounded by clear comments when adding a block.

Do not add API keys, tokens, passwords, or provider credentials to .zshrc, .bashrc, .profile, .config/fish/config.fish, or project shell hooks. For env variables that point to non-secret paths or feature flags, explain why they are safe.

Verification

Verify both installation and authentication without destructive actions:

  • Installation: tool --version, tool help, or package-manager metadata.
  • PATH: open a fresh shell or source only the changed file when safe.
  • Auth: tool auth status, whoami, account show, or a read-only API call.
  • Failure: capture exact non-secret error text and classify whether the issue is PATH, missing dependency, architecture, permissions, network, or authentication.

If verification requires a paid operation, mutation, or secret display command, do not run it. Use the vendor's status command or ask the user for permission to run a specific safe alternative.

Rollback

Track install actions as you go. When finishing, include the uninstall command or manual rollback path:

  • Package manager uninstall command.
  • Files, symlinks, launch agents, or completions created.
  • Shell file block added.
  • Credential entry name only, never the value.

For failed installs, clean temporary files and partial symlinks when that is clearly safe. Ask before deleting user-owned config, caches, or credentials.

© CodeAlive-AI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/installing-cli-tools of CodeAlive-AI/ai-driven-development.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 25b7b1d

Compare with similar skills

Installing CLI Tools next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Installing CLI Tools compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Installing CLI Tools this skillCodeAlive-AI/ai-driven-development155—~1.5kAutomated safety check: NotesMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Diagnosing Superpowers Sessionsobra/superpowers296k3 repos~1.7kAutomated safety check: PassMIT
GitHub Deep Researchbytedance/deer-flow83k5 repos~1.3kAutomated safety check: PassMIT
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Investigates a session where Superpowers went wrong, reads the transcripts on disk and produces an evidence-cited report, optionally prepared as a bug report for the maintainers.

    296k GitHub starsUsed in 3 repos~1.7k tokens
    Agent WorkflowsAuto-check passed
  • GitHub Deep Research

    bytedance/deer-flow

    Researches a GitHub repository over four rounds using the GitHub API and web search, then writes a structured markdown report with timeline, metrics and Mermaid diagrams.

    83k GitHub starsUsed in 5 repos~1.3k tokens
    Research & ScienceAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed

More from CodeAlive-AI/ai-driven-development

All 22 skills in this repo
  • Investigating Repository History

    CodeAlive-AI/ai-driven-development

    Investigate GitHub repository history before risky code changes using git blame/log, GitHub PRs, review comments, squash/rebase/cherry-pick/rename heuristics, and cited evidence.

    155 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Plugins Management

    CodeAlive-AI/ai-driven-development

    Create, publish, delete, and submit plugins for coding agents (Claude Code, OpenCode, Devin CLI/Desktop).

    155 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check: notes
  • Semantic Scholar Deep

    CodeAlive-AI/ai-driven-development

    Deep research over the Semantic Scholar Graph API. An agent skill from CodeAlive-AI/ai-driven-development.

    155 GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Windows QA Engineer

    CodeAlive-AI/ai-driven-development

    A skill your agent uses when testing Windows 11 desktop apps (WinForms/WPF/UWP) via UFO UIA/Win32 automation MCP.

    155 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Agentic Readiness

    CodeAlive-AI/ai-driven-development

    Audit and improve repositories for reliable agentic work across Codex and Codex App, Claude Code, and OpenCode.

    155 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Hooks Management

    CodeAlive-AI/ai-driven-development

    Manage hooks and automation for coding agents (Claude Code, Codex CLI, OpenCode, Devin CLI/Desktop).

    155 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check: notes

Works with

Questions about Installing CLI Tools

What does Installing CLI Tools do?

Install, upgrade, configure, and verify developer CLI tools safely. Installing CLI Tools is an agent skill from CodeAlive-AI/ai-driven-development. Install, upgrade, configure, and verify developer CLI tools safely.

When should I use Installing CLI Tools?

Installing CLI Tools fits situations like: A user asks to install a new CLI; command-line app; package-manager binary; GitHub release binary.

How do I install Installing CLI Tools in Claude Code?

Run `npx skills add CodeAlive-AI/ai-driven-development --skill installing-cli-tools -a claude-code`. Or copy the skill folder (skills/installing-cli-tools in CodeAlive-AI/ai-driven-development) into .claude/skills/installing-cli-tools in your project. Claude Code loads it when a task matches its description.

How do I install Installing CLI Tools in Codex?

Run `npx skills add CodeAlive-AI/ai-driven-development --skill installing-cli-tools -a codex`. Or copy the skill folder (skills/installing-cli-tools in CodeAlive-AI/ai-driven-development) into .agents/skills/installing-cli-tools in your project. Codex loads it when a task matches its description.

Can I use Installing CLI Tools in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CodeAlive-AI/ai-driven-development --skill installing-cli-tools -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/installing-cli-tools, .gemini/skills/installing-cli-tools, .github/skills/installing-cli-tools and .opencode/skills/installing-cli-tools in your project.

What does Installing CLI Tools need to run?

Going by SKILL.md and its folder, Installing CLI Tools needs the command-line tools its instructions call (brew, npm, python3, uv, cargo and go). Our summary lists: Python 3.

Does Installing CLI Tools access the network?

SKILL.md contains no URLs. Its commands use npm and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Installing CLI Tools safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Installing CLI Tools use?

Installing CLI Tools is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Installing CLI Tools use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Installing CLI Tools?

Skills that share tags, products or a category with Installing CLI Tools: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Diagnosing Superpowers Sessions (obra/superpowers, 296k stars), GitHub Deep Research (bytedance/deer-flow, 83k stars) and Greploop (onyx-dot-app/onyx, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Installing CLI Tools?

CodeAlive-AI (a GitHub organization) maintains it in CodeAlive-AI/ai-driven-development, which has 155 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 6, 2026.

Source: CodeAlive-AI/ai-driven-development on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.