Agent skill

Healthmd CLI Operator

by CodyBontecou in CodyBontecou/health-md

Operate the standalone Health.md CLI against an open, paired iPhone.

AGPL-3.0Auto-check passed

Install Healthmd CLI Operator

skills CLI
$ npx skills add CodyBontecou/health-md --skill healthmd-cli-operator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CodyBontecou/health-md healthmd-cli-operator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CodyBontecou/health-md.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/healthmd-cli-operator .claude/skills/healthmd-cli-operator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
healthmd-cli-operator
GitHub stars
231
Token cost
~2.9k tokens
SKILL.md length
1,189 words
Files
2
Skills in repo
6
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Operate the standalone Health.md CLI against an open, paired iPhone.

  • Works in 3 steps: In foreground Health.md, open Sync →… → Keep Health.md foregrounded through… → If in-app scanning is unavailable, open…
  • The user asks to run pairing/status/export/extract/resume/cancel
  • SKILL.md covers Rules, Preflight, Live readiness and Waiting for an unavailable phone, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Healthmd CLI Operator is an agent skill from CodyBontecou/health-md. Operate the standalone Health.md CLI against an open, paired iPhone. Use when the user asks to run pairing/status/export/extract/resume/cancel, automate an Apple Health export, inspect CLI JSON, or troubleshoot Manual IP/Tailscale connectivity without the Health.md macOS app.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `evals/evals.json`). Compatibility notes: Requires the installed portable healthmd command on macOS, Linux, or Windows and a current Health.md iPhone app. Direct CLI Access is required for live…

It works with macOS. The repository describes itself as: Source code of Health.md. The licence is AGPL-3.0.

When your agent uses it

  • The user asks to run pairing/status/export/extract/resume/cancel
  • Automate an Apple Health export
  • Inspect CLI JSON
  • Troubleshoot Manual IP/Tailscale connectivity without the Health.md macOS app

Example prompts

  • “/healthmd-cli-operator”

Requirements

  • Compatibility (from SKILL.md): Requires the installed portable `healthmd` command on macOS, Linux, or Windows and a current Health.md iPhone app. Direct CLI Access is required for live commands. Generated-file destinations work on macOS/Linux in protocol v1; Windows supports raw and extract.

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. In foreground Health.md, open Sync → CLI, tap Scan Pairing QR under Direct CLI Access, and scan the displayed image. The in-app scan…
  2. Keep Health.md foregrounded through success.
  3. If in-app scanning is unavailable, open Sync → CLI, enable Direct CLI Access, select Manual IP, and enter the printed LAN/Tailscale…

What it can do on your machine

Read from SKILL.md and the folder at commit a5a2227. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the installed portable `healthmd` command on macOS, Linux, or Windows and a current Health.md iPhone app. Direct CLI Access is required for live commands. Generated-file destinations work on macOS/Linux in protocol v1; Windows supports raw and extract.

    From compatibility in the SKILL.md frontmatter.

Context cost

Healthmd CLI Operator loads about 2.9k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 1,189 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from CodyBontecou/health-md at commit a5a2227, republished under its AGPL-3.0 licence (© CodyBontecou). 1,189 words, ~2,916 tokens.

Download SKILL.mdSave it as .claude/skills/healthmd-cli-operator/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
healthmd-cli-operator
description
Operate the standalone Health.md CLI against an open, paired iPhone. Use when the user asks to run pairing/status/export/extract/resume/cancel, automate an Apple Health export, inspect CLI JSON, or troubleshoot Manual IP/Tailscale connectivity without the Health.md macOS app.
compatibility
Requires the installed portable `healthmd` command on macOS, Linux, or Windows and a current Health.md iPhone app. Direct CLI Access is required for live commands. Generated-file destinations work on macOS/Linux in protocol v1; Windows supports raw and extract.

Health.md CLI Operator

Use the installed standalone healthmd. Do not use the monorepo's apps/apple/scripts/healthmd; it runs the legacy Swift compatibility client. The Health.md macOS app is not required.

Rules

  • Direct Manual IP/Tailscale is the only portable transport. Never add --transport nearby.
  • On macOS/Linux use NO_COLOR=1 TERM=dumb, a hard timeout, and stdin from /dev/null. Give exports longer bounds than status.
  • Parse stdout JSON or the explicit output artifact. Add global --json whenever automation requires a structured result; interactive terminals otherwise render readable text. Pairing instructions and health-free progress may use stderr.
  • For an unfamiliar shape, run the incomplete command first: healthmd export, extract, resume, cancel, or a selected query returns local healthmd.cli_guidance/1 with requirements and request_sent: false; it does not contact iPhone.
  • Never infer execution success from exit status alone. A zero exit may be non-network guidance; require the expected result schema/status before reporting completion. Failures use healthmd.cli_error/1 with help_command and bounded next_actions.
  • Ask for physical iPhone actions when needed: open/unlock Health.md, scan a pairing QR with its in-app Direct CLI scanner (which connects automatically), enable Direct CLI Access, enter a fallback code, approve local-network access, or grant HealthKit read access.
  • Never print health values unless explicitly requested. Counts, dates, paths, statuses, and diagnostics are enough.
  • Never retry an unknown-outcome export blindly. Inspect its durable job first.
text
user/agent → standalone healthmd listener :17647
  ← authenticated encrypted LAN/Tailscale connection →
open paired iPhone → HealthKit → protected spool → output/destination

The Mac app, loopback port 17645, Mac destination bookmark, and Mac app connection state are irrelevant.

Preflight

bash
NO_COLOR=1 TERM=dumb timeout 15 healthmd --version </dev/null
NO_COLOR=1 TERM=dumb timeout 30 healthmd direct devices </dev/null

direct devices reads local trust without contacting iPhone. Pair if the intended iPhone is absent.

Pair
bash
NO_COLOR=1 TERM=dumb timeout 180 healthmd direct pair </dev/null

While it waits, tell the user to:

  1. In foreground Health.md, open Sync → CLI, tap Scan Pairing QR under Direct CLI Access, and scan the displayed image. The in-app scan starts pairing automatically; no second Pair tap is required. Do not open the QR as a custom URL.
  2. Keep Health.md foregrounded through success.
  3. If in-app scanning is unavailable, open Sync → CLI, enable Direct CLI Access, select Manual IP, and enter the printed LAN/Tailscale address, port, and shared 20-digit code. Use the six-digit Apple code only with a legacy iOS release.

Confirm stdout has healthmd.direct_pairing_result, status: success, and the intended device. After an unknown outcome, inspect healthmd direct devices rather than pairing again.

Pairing is normally one-time. Keep Direct CLI Access enabled and Health.md open for later commands. If several devices are trusted, add global --device DEVICE_UUID. If iPhone saved a non-default port, add global --port PORT to every network operation.

Live readiness

bash
NO_COLOR=1 TERM=dumb timeout 30 healthmd status </dev/null

Require:

  • the source reports connected and a platform of ios or android with readiness fields;
  • iphone.connected == true;
  • iphone.app_active == true for new work;
  • iphone.protected_data_available == true;
  • iphone.can_trigger_raw_exports == true for raw/extract;
  • iphone.can_trigger_exports == true for generated files;
  • no conflicting iphone.active_job_id.

Status reports no destination: direct file mode uses the command's explicit destination. wake_window reports the shared local wait policy plus this device's truthful wake enrollment: unavailable/wait_only without a stored wake credential (no push is sent), available/enrolled when the paired iPhone enrolled wake material. Published alpha.6 binaries are still wait-only; in subsequent official builds an enrolled locked-phone wait sends one best-effort APNs notification. Android remains wait-only until FCM ships. If status fails, report its JSON and ask for the minimum action. Never switch device, port, or transport silently.

Waiting for an unavailable phone

Query, export, extract, resume, and cancel wait up to 120 seconds by default. When health-free progress says the phone is unavailable, ask the user to unlock it and open Health.md; do not stop and re-run the command. Set --wake-timeout SECONDS when a different bounded window is needed, or --wake-timeout 0 for explicit fail-fast behavior. Set the shell's outer timeout longer than the wake window plus the command's operation timeout.

For MCP, configure HEALTHMD_WAKE_TIMEOUT; cancellation interrupts the wait immediately. Only tell the user to expect a notification when a post-alpha.6 build reports the selected iPhone as available/enrolled; delivery is best effort. Otherwise ask them to open Health.md while the P1 window waits. Wake expiry preserves direct_source_unavailable and adds wake_window_seconds. Neither expiry nor local cancellation is terminal phone-side job cancellation.

Strict raw

Prefer output files so health data does not enter logs:

bash
NO_COLOR=1 TERM=dumb timeout 300 \
  healthmd export --yesterday --raw --output yesterday.json </dev/null

NO_COLOR=1 TERM=dumb timeout 600 \
  healthmd export --last 7 --raw --output week.json </dev/null

NO_COLOR=1 TERM=dumb timeout 600 \
  healthmd export --from 2026-07-01 --to 2026-07-07 \
    --raw --output range.json </dev/null

Use --all only when explicitly requested, with a protected path and a large outer timeout. Afterward inspect only status, job ID, requested/retained days, capture summary, missing dates, schema versions, and counts. Never dump the corpus.

A strict partial result exits nonzero unless --allow-partial is explicit. Do not add that flag merely to make automation green.

Show full SKILL.md (463 more words)Show less

Canonical extraction

bash
NO_COLOR=1 TERM=dumb timeout 300 \
  healthmd extract --category Sleep --last 7 --output sleep.json </dev/null

NO_COLOR=1 TERM=dumb timeout 300 \
  healthmd extract --metric workouts --last 14 \
    --object records --detail lossless --output workout-records.json </dev/null

NO_COLOR=1 TERM=dumb timeout 300 \
  healthmd extract --category Sleep --last 7 \
    --format jsonl --output sleep.jsonl </dev/null

Validate the receipt, selected dates/source/detail, and day outcomes. JSONL file output creates OUTPUT.receipt.json. Omitted fields are not zero. Incomplete extraction withholds values unless --allow-partial is explicit.

Generated files

On macOS/Linux, use only an existing absolute destination chosen or approved by the user:

bash
mkdir -p "$HOME/Documents/HealthVault"
NO_COLOR=1 TERM=dumb timeout 300 \
  healthmd export --yesterday \
    --destination "$HOME/Documents/HealthVault" </dev/null

NO_COLOR=1 TERM=dumb timeout 600 \
  healthmd export --last 7 --category Sleep --detail summary \
    --destination "$HOME/Documents/HealthVault" </dev/null

Do not guess a path, use a relative path, or reuse a Mac app bookmark. --output is raw/extract; --destination is generated-file mode.

Default jobs preserve saved formats, subfolder, templates, filenames, write mode, and Daily Note behavior while suppressing roll-ups and summary-only mode. Use --use-iphone-settings only when the user explicitly wants all saved behavior. Generated-file mode works on macOS, Linux, and Windows after validating an existing native absolute non-symlink destination.

Durable jobs

After timeout, disconnect, direct_export_paused, or unknown final outcome:

bash
healthmd status --job JOB_UUID
healthmd resume JOB_UUID --timeout 300 --output recovered.json

status --job is local. Resume requires the same paired iPhone, device, port, and immutable request. Do not start a replacement job because the waiter stopped.

Cancel only on request:

bash
healthmd cancel JOB_UUID

direct_cancellation_pending is not terminal. Keep the same iPhone open and retry cancel until acknowledged. Ctrl-C does not cancel.

Report safely

Report only what CLI JSON, extraction receipt, or file receipt proves:

  • status and job ID;
  • requested/processed/retained days;
  • files written and explicit destination;
  • raw/extract schema and selection;
  • missing/partial diagnostics;
  • failure code and message.

Examples:

text
Health.md completed the direct export: 7/7 days, 14 files committed under /Users/.../HealthVault.
text
Health.md produced a complete strict raw result for yesterday: 1/1 day retained in yesterday.json.

Do not paste source records, routes, clinical content, measurements, or full raw output.

Troubleshooting order

  1. healthmd direct devices — local identity/trust.
  2. healthmd status --job JOB_UUID — durable state after a started command.
  3. healthmd status — live iPhone readiness.
  4. Verify Direct CLI Access, foreground/protected-data state, address/port, local-network permission, device selection, and LAN/Tailscale reachability.
  5. Resume the same durable job when appropriate.
ErrorAction
direct_not_pairedPair once; do not open the Mac app.
direct_device_selection_requiredAdd the intended --device.
direct_trust_invalidPreserve diagnostics; reset only with approval and forget on iPhone too.
direct_storage_unavailableRestore native credentials. On macOS authorize the installed signed binary in Keychain Access or explicitly remove stale Health.md direct trust on both sides and re-pair; the CLI does not wait on hidden authorization UI. On Linux unlock/configure Secret Service.
direct_iphone_unavailableCheck app foreground, access toggle, address/port, permission, and reachability.
direct_export_pausedInspect local job, reopen iPhone, and resume it.
direct_cancellation_pendingReopen iPhone and retry cancel.
invalid_direct_raw_responseDo not consume output; retain validation diagnostics.
invalid_direct_file_receiptDo not manually append/merge; inspect and resume if permitted.
job_expiredThe seven-day deadline elapsed; confirm before starting a new request.
transport_unsupportedUse Manual IP/LAN/Tailscale, not Nearby.
unknown_argument after passing --backendRemove it; the CLI is direct-only and has no backend option.

Privacy

  • Never log raw stdout or use health values as troubleshooting evidence.
  • Keep output and destination paths private and appropriately permissioned.
  • Do not alter generated files to repair interrupted overwrite/append/merge operations.
  • Do not claim fully unattended operation. Pairing and new work need a foreground iPhone; an active export gets only finite iOS background time.

© CodyBontecou, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/healthmd-cli-operator of CodyBontecou/health-md.

  • SKILL.md
  • evals/evals.json

Open the folder on GitHubat commit a5a2227

Compare with similar skills

Healthmd CLI Operator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Healthmd CLI Operator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Healthmd CLI Operator this skillCodyBontecou/health-md231—~2.9kAutomated safety check: PassAGPL-3.0
Site ArchitectureAvdLee/RocketSimApp80411 repos~3.3kAutomated safety check: PassCustom licence
Engine Whats Newflutter/flutter179k—~978Automated safety check: PassBSD-3-Clause
macOS Spm App PackagingDimillian/Skills4k5 repos~1.2kAutomated safety check: PassMIT
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT
Orca iOS Simulator Controlstablyai/orca88k1 repos~584Automated safety check: PassApache-2.0

Similar skills

  • Site Architecture

    AvdLee/RocketSimApp

    When the user wants to plan, map, or restructure their website's page hierarchy, navigation, URL structure, or internal linking.

    804 GitHub starsUsed in 11 repos~3.3k tokens
    Marketing & SEOAuto-check passed
  • Engine Whats New

    flutter/flutter

    Generates the "what's new" release summary and diff file for changes in the Flutter engine (//engine/src/flutter) between two releases (e.g., 3.47 vs 3.44).

    179k GitHub stars~978 tokensUpdated today
    MobileAuto-check passed
  • macOS Spm App Packaging

    Dimillian/Skills

    Scaffold, build, and package SwiftPM-based macOS apps without an Xcode project.

    4k GitHub starsUsed in 5 repos~1.2k tokens
    MobileAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • iOS Simulator control from inside Orca, with the live device view in Orca's emulator pane. Use when driving a booted Apple Simulator on macOS: taps, gestures…

    88k GitHub starsUsed in 1 repo~584 tokens
    MobileAuto-check passed
  • A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

    70k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed

More from CodyBontecou/health-md

  • Healthmd CLI

    CodyBontecou/health-md

    Safely install and use the Health.md CLI and MCP server to query user-authorized health data, chart typed metrics, inspect sleep and workouts, export scoped or complete public/authorized Apple…

    231 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Healthmd CLI

    CodyBontecou/health-md

    Install and operate the standalone Health.md CLI and portable healthmd-mcp server on macOS, Linux, or Windows.

    231 GitHub stars~3.9k tokensUpdated today
    Auto-check passed
  • Healthmd CLI

    CodyBontecou/health-md

    Safely install and use the Health.md CLI and MCP server to query user-authorized health data, chart typed metrics, inspect sleep and workouts, export scoped Apple Health or Health Connect data, and…

    231 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Healthmd CLI Development

    CodyBontecou/health-md

    Develop or debug the standalone Rust Health.md CLI, portable healthmd-mcp server, and iPhone direct service.

    231 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Healthmd CLI QA

    CodyBontecou/health-md

    Test the standalone Health.md CLI, portable healthmd-mcp server, and direct mobile paths.

    231 GitHub stars~4k tokensUpdated today
    Auto-check passed

Works with

Questions about Healthmd CLI Operator

What does Healthmd CLI Operator do?

Operate the standalone Health.md CLI against an open, paired iPhone. Healthmd CLI Operator is an agent skill from CodyBontecou/health-md.md CLI against an open, paired iPhone.

When should I use Healthmd CLI Operator?

Healthmd CLI Operator fits situations like: the user asks to run pairing/status/export/extract/resume/cancel; automate an Apple Health export; inspect CLI JSON; troubleshoot Manual IP/Tailscale connectivity without the Health.md macOS app.

How do I install Healthmd CLI Operator in Claude Code?

Run `npx skills add CodyBontecou/health-md --skill healthmd-cli-operator -a claude-code`. Or copy the skill folder (.agents/skills/healthmd-cli-operator in CodyBontecou/health-md) into .claude/skills/healthmd-cli-operator in your project. Claude Code loads it when a task matches its description.

How do I install Healthmd CLI Operator in Codex?

Run `npx skills add CodyBontecou/health-md --skill healthmd-cli-operator -a codex`. Or copy the skill folder (.agents/skills/healthmd-cli-operator in CodyBontecou/health-md) into .agents/skills/healthmd-cli-operator in your project. Codex loads it when a task matches its description.

Can I use Healthmd CLI Operator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CodyBontecou/health-md --skill healthmd-cli-operator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/healthmd-cli-operator, .gemini/skills/healthmd-cli-operator, .github/skills/healthmd-cli-operator and .opencode/skills/healthmd-cli-operator in your project.

What does Healthmd CLI Operator need to run?

SKILL.md names no scripts, command-line tools or credentials: Healthmd CLI Operator is instructions for the agent only. Compatibility (from SKILL.md): Requires the installed portable `healthmd` command on macOS, Linux, or Windows and a current Health.md iPhone app. Direct CLI Access is required for live commands. Generated-file destinations work on macOS/Linux in protocol v1; Windows supports raw and extract..

Does Healthmd CLI Operator access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Healthmd CLI Operator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Healthmd CLI Operator use?

Healthmd CLI Operator is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Healthmd CLI Operator use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Healthmd CLI Operator?

Skills that share tags, products or a category with Healthmd CLI Operator: Site Architecture (AvdLee/RocketSimApp, 804 stars), Engine Whats New (flutter/flutter, 179k stars), macOS Spm App Packaging (Dimillian/Skills, 4k stars) and Openclaw Live Updater (openclaw/openclaw, 392k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Healthmd CLI Operator?

CodyBontecou (a GitHub user) maintains it in CodyBontecou/health-md, which has 231 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 9, 2026.

Source: CodyBontecou/health-md on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.