Agent skill

C0 Config

by Consensys in Consensys/c0

A skill your agent uses when changing c0 deployment configuration, runtime-editable global settings, auth providers, AI providers, MCP Context Forge, discovered registries, secret references, or…

LGPL-3.0Auto-check: notesDevOps & Cloud

Install C0 Config

skills CLI
$ npx skills add Consensys/c0 --skill c0-config -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Consensys/c0 c0-config --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Consensys/c0.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/c0-config .claude/skills/c0-config && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
c0-config
GitHub stars
105
Token cost
~2.1k tokens
SKILL.md length
1,016 words
Files
2
Skills in repo
11
Repo updated
First seen
Licence
LGPL-3.0

At a glance

A skill your agent uses when changing c0 deployment configuration, runtime-editable global settings, auth providers, AI providers, MCP Context Forge, discovered registries, secret references, or…

  • Works in 3 steps: An explicit domain in the selected stage… → If the domain is omitted, read its… → If neither exists, use the domain's…
  • Changing c0 deployment configuration
  • SKILL.md covers Canonical Deployment…, Cloudflare Binding Boundary, Secrets and Deployment and Runtime…, plus 4 more sections
  • Needs C0_LITELLM_API_KEY

What it does

C0 Config is an agent skill from Consensys/c0. Use when changing c0 deployment configuration, runtime-editable global settings, auth providers, AI providers, MCP Context Forge, discovered registries, secret references, or open-source deployment configuration.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in DevOps & Cloud, covering Deployment. It works with Model Context Protocol. The repository describes itself as: c0 is an open-source AI platform built for organizational work, tools, and context. A single deployment to Cloudflare to get started. The licence is LGPL-3.0.

When your agent uses it

  • Changing c0 deployment configuration
  • Runtime-editable global settings
  • MCP Context Forge
  • Discovered registries

Example prompts

  • “/c0-config”

Requirements

  • A credential in C0_LITELLM_API_KEY

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. An explicit domain in the selected stage config is deployment-managed and locked in Admin.
  2. If the domain is omitted, read its editable value from C0_CONFIG KV.
  3. If neither exists, use the domain's documented default or unconfigured state.

What it can do on your machine

Read from SKILL.md and the folder at commit e7a1810. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are jsonc).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • C0_LITELLM_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

C0 Config loads about 2.1k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 1,016 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:15
    ` tracked. Ignore secret-bearing `config/.env` and `config/.*.vars` files while tracking their example templates.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Consensys/c0 at commit e7a1810, republished under its LGPL-3.0 licence (© Consensys). 1,016 words, ~2,066 tokens.

Download SKILL.mdSave it as .claude/skills/c0-config/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
c0-config
description
Use when changing c0 deployment configuration, runtime-editable global settings, auth providers, AI providers, MCP Context Forge, discovered registries, secret references, or open-source deployment configuration.

c0 Config

Use this skill whenever work changes c0 configuration or the boundary between deployment-managed and runtime-managed state.

Canonical Deployment Configuration

The selected config/<stage>.config.jsonc file is the only source of truth for non-secret operator configuration. Keep configuration readable, reviewable, and shareable there rather than encoding objects in environment variables.

  • Keep complete, independent config/dev.config.jsonc, config/test.config.jsonc, config/pre.config.jsonc, and config/prod.config.jsonc files in the repository's config/ directory. Do not add cross-file inheritance, partial overrides, or profile merging.
  • Keep the stage JSONC files, config/example.config.jsonc, and config/c0.config.schema.json tracked. Ignore secret-bearing config/.env and config/.*.vars files while tracking their example templates.
  • Map preview stages such as pre-123 to config/pre.config.jsonc. Other supported stages map directly to config/<stage>.config.jsonc.
  • Fail before creating Alchemy resources when the selected file does not exist or fails schema validation.
  • Parse and schema-decode only the selected file once at the Alchemy deployment boundary.
  • Use that same resolved object for infrastructure decisions and Worker bindings so build-time and runtime configuration cannot drift structurally.
  • Keep schemaVersion explicit and regenerate config/c0.config.schema.json when the schema changes.
  • Point every stage file at the generated config/c0.config.schema.json. Run nub run config:check after editing any stage file or its schema. Run nub run config:schema intentionally when the generated schema needs to change.
  • Define the external JSON contract with Effect Schema and generate the editor schema from that same contract. Schema.Struct is appropriate for plain JSON DTOs; use Schema.Class only when configuration values need class identity, constructors, methods, or branding.

Do not parse stage JSONC in a Worker or web request. Do not add a serialized JSON environment variable or a duplicate defaults layer.

Cloudflare Binding Boundary

Alchemy compiles the resolved config into bounded bindings:

  • Pass cohesive, small server domains as native Cloudflare JSON bindings, such as C0_CONFIG_AUTH or C0_CONFIG_MCPCF.
  • Pass browser-safe values as explicit VITE_* scalars. Never expose a secret or the full server configuration to the browser.
  • Do not pass the entire configuration as one large binding. Cloudflare applies binding-count and per-binding size limits.
  • Keep deployment-time binding budget checks close to the infrastructure code.
  • Derive Worker env types from the Alchemy resources. Do not hand-write or cast a parallel env contract when resource inference is available.

Native JSON bindings arrive as objects. Runtime code should schema-decode them as objects and must not accept legacy JSON strings as a hidden fallback.

Secrets

Secret values never belong in a stage config file. Reference them explicitly at the field that consumes them:

jsonc
{
  "apiKey": {
    "env": "C0_LITELLM_API_KEY"
  }
}
  • Secret reference names must be explicit, stable uppercase environment binding names.
  • Do not derive secret names from JSON paths or KV keys.
  • Only secrets explicitly marked with "generateIfMissing": true may be generated by Alchemy.
  • Generated secrets must use stable Alchemy logical ids so they persist in Alchemy state across deployments.
  • A referenced active secret must resolve or deployment must fail closed. Do not silently fall back to a KV secret when the JSONC field explicitly names a missing deployment secret.
  • Disabled integrations and providers should not require their otherwise-unused secrets.
  • config/.dev.vars, config/.test.vars, config/.pre.vars, and config/.prod.vars contain secrets and deployment credentials only, never non-secret configuration objects.
  • Use nub run config:write-stage-vars -- <stage> <path> to reconcile a stage file with the active secret references before syncing or deploying it.
  • Never print secret values during validation or handoff. Names-only inspection is safe.

Deployment and Runtime Precedence

For a domain that supports Admin editing, use this precedence:

  1. An explicit domain in the selected stage config is deployment-managed and locked in Admin.
  2. If the domain is omitted, read its editable value from C0_CONFIG KV.
  3. If neither exists, use the domain's documented default or unconfigured state.

The lock message must identify the active stage config location, for example config/prod.config.jsonc:aiProviders.litellm, and explain that the field must be removed from deployment configuration and redeployed before Admin can edit it.

Do not add long-lived compatibility fallbacks for old env names. Migrate callers and delete the obsolete path.

Authentication is deployment-managed because it defines which providers may establish identity. Provider kind does not grant authority: provider capabilities independently control sign-in, user provisioning, and explicit account linking. Keep implicit account linking disabled and keep provider secrets as explicit secret references.

Show full SKILL.md (339 more words)Show less

Runtime-Owned State

Use C0_CONFIG KV for runtime-editable settings and externally discovered registries. Keep stable string keys and JSON values.

Runtime-editable setup values:

  • config/ai-providers/litellm
  • secrets/ai-providers/litellm/api-key
  • config/mcpcf
  • secrets/mcpcf/admin-api-token

Runtime-discovered registry data:

  • registry/ai-providers/litellm/models
  • registry/mcpcf/server-index
  • registry/mcpcf/servers/{serverId}
  • registry/ai-search/sources/{sourceId}

Do not put discovered catalogs or runtime-created sources in JSONC, infrastructure bindings, .vars files, GitHub variables, or stage metadata. Refresh and edit them through the owning runtime/admin workflow. Sensitive KV values must use the app-level encrypted-value envelope.

Exports from Admin should distinguish these boundaries:

  • Export deployment-managed setup as a JSONC fragment plus separate secret assignments.
  • Export runtime registry data as portable runtime data, not as environment overrides.
  • Never export discovered registries into GitHub secrets.

Configuration Digest

Compute the deployment digest from canonicalized resolved configuration and expose it for health diagnostics, support, and cache invalidation. The digest is observability metadata, not a startup equality gate: Alchemy already uses one resolved object for infrastructure and runtime bindings.

Storage Boundaries

  • Use D1 for c0-owned relational state with a schema we control, especially user-owned rows and reporting tables.
  • Keep user_mcpcf_server_configs in D1 because it is user-related relational state.
  • Use USER_WORKFLOW_KV for user-namespaced workflow kv-put and kv-get storage.
  • Keep REPOS_CACHE for repo/workflow-builder internal caches.
  • Keep WORKFLOW_SESSION_RESPONSE_CACHE for workflow session-node response caching.
  • Do not add hidden D1/KV fallback paths. When state moves, provide an explicit migration and make the new source authoritative.

Change Checklist

When adding or moving a configuration field:

  1. Classify it as public build-time, server deployment-time, secret, runtime-editable, or runtime-discovered.
  2. Add it to the shared Effect schema and every complete stage file where it applies.
  3. Add an explicit secret reference only if the value is secret.
  4. Compile it through the existing Alchemy resolver into the narrowest appropriate binding.
  5. Update runtime precedence, Admin lock state, and export behavior where the domain is runtime-editable.
  6. Regenerate the JSON schema and Alchemy-derived env types when their sources change.
  7. Update stage secret generation/sync workflows if a new active secret name is introduced.
  8. Validate with nub run config:check, focused tests, and the repository-required typecheck, lint, and format commands.

© Consensys, LGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/c0-config of Consensys/c0.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit e7a1810

Compare with similar skills

C0 Config next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

C0 Config compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
C0 Config this skillConsensys/c0105—~2.1kAutomated safety check: NotesLGPL-3.0
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template786—~5.9kAutomated safety check: NotesMIT
Deploy Observabilityaliyun/alibabacloud-observability-mcp-server166—~2.6kAutomated safety check: NotesNone
Release Allpaperboytm/spool592—~1.1kAutomated safety check: PassCustom licence
Deploynoskillish/bankmcp277—~744Automated safety check: PassMIT

Similar skills

  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Prepare Cloudflare Production Deployment

    LubomirGeorgiev/cloudflare-workers-nextjs-saas-template

    Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.

    786 GitHub stars~5.9k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Deploy Observability

    aliyun/alibabacloud-observability-mcp-server

    Deploy, start, and update the Alibaba Cloud Observability MCP Server (阿里云可观测 MCP Server).

    166 GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Release All

    paperboytm/spool

    Publish the complete Spool CLI release train: synchronized versions, npm packages, the GitHub release, and the matching production web deployment.

    592 GitHub stars~1.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Deploy

    noskillish/bankmcp

    Deploy BankMCP™ to a small server so it works in claude.ai and on the phone: Railway or Fly.io, volume, domain, setup page, connector.

    277 GitHub stars~744 tokensUpdated 11 days ago
    DevOps & CloudAuto-check passed
  • Hcls Deploy Agent

    aws-samples/amazon-bedrock-agents-healthcare-lifesciences

    Official

    A skill your agent uses when a developer wants to deploy an HCLS agent to Amazon Bedrock AgentCore, configure Gateway tools as MCP endpoints, set up authentication with Cognito, configure memory, or…

    274 GitHub stars~813 tokensUpdated 8 days ago
    DevOps & CloudAuto-check passed

More from Consensys/c0

All 11 skills in this repo
  • Debug deployed Cloudflare Workers using the cfobservability MCP, Wrangler, D1/R2 state, repo evidence, and safe live reproduction.

    105 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Deslop Typescript

    Consensys/c0

    Run a final de-slopping pass on nearly finished JavaScript or TypeScript work before commit or PR.

    105 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed
  • A skill your agent uses when adding, changing, or reviewing Workflow Nodes in the c0 agent repo, including shared node catalog metadata, Workflow Node options and ports, runtime node Adapters…

    105 GitHub stars~943 tokensUpdated 1 mo ago
    Auto-check passed
  • Guidance for safely changing the c0 Workflow runtime ABI, manifest ABI, runtime kernels, manifest migrations, workflow artifact compatibility, and audit/backfill tooling.

    105 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Agent Eval Loop

    Consensys/c0

    Run and improve the c0 agent evaluation loop using the local and remote Cloudflare MCP harness, versioned history notes, and current Cloudflare product updates.

    105 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Alchemy Env Types

    Consensys/c0

    Derive Cloudflare worker env types from Alchemy resource Env types instead of hand-writing env shapes.

    105 GitHub stars~707 tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about C0 Config

What does C0 Config do?

A skill your agent uses when changing c0 deployment configuration, runtime-editable global settings, auth providers, AI providers, MCP Context Forge, discovered registries, secret references, or…. C0 Config is an agent skill from Consensys/c0. Use when changing c0 deployment configuration, runtime-editable global settings, auth providers, AI providers, MCP Context Forge, discovered registries, secret references, or open-source deployment configuration.

When should I use C0 Config?

C0 Config fits situations like: changing c0 deployment configuration; runtime-editable global settings; MCP Context Forge; discovered registries.

How do I install C0 Config in Claude Code?

Run `npx skills add Consensys/c0 --skill c0-config -a claude-code`. Or copy the skill folder (.agents/skills/c0-config in Consensys/c0) into .claude/skills/c0-config in your project. Claude Code loads it when a task matches its description.

How do I install C0 Config in Codex?

Run `npx skills add Consensys/c0 --skill c0-config -a codex`. Or copy the skill folder (.agents/skills/c0-config in Consensys/c0) into .agents/skills/c0-config in your project. Codex loads it when a task matches its description.

Can I use C0 Config in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Consensys/c0 --skill c0-config -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/c0-config, .gemini/skills/c0-config, .github/skills/c0-config and .opencode/skills/c0-config in your project.

What does C0 Config need to run?

Going by SKILL.md and its folder, C0 Config needs credentials named C0_LITELLM_API_KEY. Our summary lists: A credential in C0_LITELLM_API_KEY.

Does C0 Config access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is C0 Config safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does C0 Config use?

C0 Config is published under the LGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does C0 Config use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to C0 Config?

Skills that share tags, products or a category with C0 Config: AWS Cdk Development (zxkane/aws-skills, 367 stars), Prepare Cloudflare Production Deployment (LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, 786 stars), Deploy Observability (aliyun/alibabacloud-observability-mcp-server, 166 stars) and Release All (paperboytm/spool, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains C0 Config?

Consensys (a GitHub organization) maintains it in Consensys/c0, which has 105 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on August 18, 2026.

Source: Consensys/c0 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.