Agent skill

Create Runfile

by danshapiro in danshapiro/kilroy

A skill your agent uses when authoring or repairing Kilroy run config YAML/JSON files, including DOT-to-provider backend alignment and runtime policy defaults.

MITAuto-check: notes

Install Create Runfile

skills CLI
$ npx skills add danshapiro/kilroy --skill create-runfile -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install danshapiro/kilroy create-runfile --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/danshapiro/kilroy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/create-runfile .claude/skills/create-runfile && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
create-runfile
GitHub stars
221
Token cost
~1.4k tokens
SKILL.md length
599 words
Files
2
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when authoring or repairing Kilroy run config YAML/JSON files, including DOT-to-provider backend alignment and runtime policy defaults.

  • Repairing Kilroy run config YAML/JSON files
  • SKILL.md covers Scope, Overview, Workflow and Non-Negotiable Guardrails, plus 1 more section
  • Needs GEMINI_API_KEY and API_KEY
  • Including DOT-to-provider backend alignment and runtime policy defaults

What it does

Create Runfile is an agent skill from danshapiro/kilroy. Use when authoring or repairing Kilroy run config YAML/JSON files, including DOT-to-provider backend alignment and runtime policy defaults.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `reference_run_template.yaml`).

The licence is MIT.

When your agent uses it

  • Repairing Kilroy run config YAML/JSON files
  • Including DOT-to-provider backend alignment and runtime policy defaults

Example prompts

  • “/create-runfile”

Requirements

  • A credential in GEMINI_API_KEY
  • A credential in API_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit b55fb0f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GEMINI_API_KEY
    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Create Runfile loads about 1.4k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 599 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:65
    - Store the actual secret values in a `.env` file at the repo root (gitignored). The engine loads `.env` at startup and
  • NoteMentions a .env fileSKILL.md:72
    GEMINI_API_KEY: ""   # value comes from .env / shell environment

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from danshapiro/kilroy at commit b55fb0f, republished under its MIT licence (© danshapiro). 599 words, ~1,369 tokens.

Download SKILL.mdSave it as .claude/skills/create-runfile/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
create-runfile
description
Use when authoring or repairing Kilroy run config YAML/JSON files, including DOT-to-provider backend alignment and runtime policy defaults.

Create Runfile

Scope

This skill owns run config authoring (run.yaml / run.json) for kilroy attractor run and resume.

In scope:

  • Building config structure (version: 1 schema).
  • Aligning provider backends with DOT model/provider usage.
  • Setting runtime, preflight, modeldb, git, and CXDB defaults.

Out of scope:

  • DOT graph authoring and routing design. Use create-dotfile for graph work.

Overview

Core principle:

  • Keep execution policy in run config, not in DOT topology.
  • Align run config with what the graph needs to execute now.
  • Favor explicit, deterministic defaults over implicit behavior.

Default run-config source:

  • skills/create-runfile/reference_run_template.yaml

Workflow

  1. Collect inputs.
  • Read the target DOT graph and detect provider usage (llm_provider attrs and model_stylesheet).
  • Capture user constraints for production/test mode and backend policy.
  1. Choose run mode explicitly.
  • Production mode: llm.cli_profile: real and no test-shim flags.
  • Test mode: llm.cli_profile: test_shim with shim-compatible provider config.
  1. Start from the template and fill required fields.
  • Required: version, repo.path, cxdb.binary_addr, cxdb.http_base_url, modeldb.openrouter_model_info_path.
  • Keep absolute paths for repo/modeldb/script entries.
  • Emit only fields supported by internal/attractor/engine/config.go.
  • Unknown keys are rejected at load time; do not emit unsupported keys.
  1. Align providers with DOT.
  • For every provider used by DOT, set llm.providers.<provider>.backend (api or cli).
  • Do not edit DOT to force backend execution strategy.

4.5 Resolve model names deterministically when catalogs are unavailable.

  • Model resolution order: user-specified model -> run snapshot/modeldb path -> internal/attractor/modeldb/pinned/openrouter_models.json -> internal/attractor/modeldb/manual_models.yaml -> skills/shared/model_fallbacks.yaml.
  • Use skills/shared/model_fallbacks.yaml only as backup; never let backup entries override explicit user model/provider choices.
  • Normalize known aliases through fallback mappings before emitting YAML (for example provider zai: glm-5.0 -> glm-5).
  1. Populate artifact_policy from skills/shared/profile_default_env.yaml.
  • The engine applies only env overrides declared explicitly in the run config.
  • Read skills/shared/profile_default_env.yaml for per-profile reference values.
  • Emit all required env vars for each profile used by the DOT graph.
  • Set artifact_policy.checkpoint.exclude_globs for checkpoint hygiene.
  • Do not use deprecated git.checkpoint_exclude_globs.

5.5 Declare secrets the project needs at build/test time.

  • If the project under construction needs API keys at test or build time (e.g. GEMINI_API_KEY for smoke tests that call a live LLM), declare them in artifact_policy.env.overrides so they pass through to the agent shell.
  • The agent shell deny-lists env vars whose names contain API_KEY, SECRET, TOKEN, PASSWORD, or CREDENTIAL by default. Vars declared in artifact_policy.env.overrides bypass this deny list because they represent explicit operator intent.
  • Store the actual secret values in a .env file at the repo root (gitignored). The engine loads .env at startup and declared override keys pick up the OS values automatically.
  • Use an empty string as the override value — the engine substitutes the real value from the environment at resolve time:
    yaml
    artifact_policy:
      env:
        overrides:
          generic:
            GEMINI_API_KEY: ""   # value comes from .env / shell environment
  • Never put actual secret values in the run config file.
Show full SKILL.md (169 more words)Show less
  1. Apply runtime defaults and safety guardrails.
  • Set git.run_branch_prefix, git.commit_per_node, and git.require_clean intentionally.
  • Keep runtime_policy explicit (stage_timeout_ms, stall_timeout_ms, retry cap).
  • Enable preflight.prompt_probes and use a non-aggressive timeout baseline for real-provider runs.
  1. Preserve local-run robustness.
  • In this repo, keep cxdb.autostart launcher wiring when generating local CXDB configs.
  • Keep artifact/checkpoint hygiene settings where relevant (for example managed tool-cache roots).
  1. Validate alignment before handoff.
  • Confirm every DOT provider has a run-config backend entry.
  • Confirm mode consistency (real vs test_shim) with intended command flags.
  • Confirm config has no unresolved placeholder paths.
  • If graph prompts consume scratch artifacts, require run-scoped paths (.ai/runs/$KILROY_RUN_ID/...); root .ai is not implicitly ingested.

Non-Negotiable Guardrails

  • Backend policy lives in run config; do not encode it in DOT structure.
  • Do not omit providers that are referenced by the graph.
  • Do not use fragile preflight probe timeouts for real-provider runs.
  • Do not emit local CXDB configs without cxdb.autostart wiring in this repository context.
  • Do not emit unsupported keys (for example: runtime_robustness, provider_capability_constraints).

References

  • docs/strongdm/attractor/attractor-spec.md
  • docs/strongdm/attractor/unified-llm-spec.md
  • README.md
  • skills/create-runfile/reference_run_template.yaml
  • skills/shared/profile_default_env.yaml
  • skills/shared/model_fallbacks.yaml

© danshapiro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/create-runfile of danshapiro/kilroy.

  • SKILL.md
  • reference_run_template.yaml

Open the folder on GitHubat commit b55fb0f

Compare with similar skills

Create Runfile next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Create Runfile compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Create Runfile this skilldanshapiro/kilroy221—~1.4kAutomated safety check: NotesMIT
Hermes Agent Skill AuthoringNousResearch/hermes-agent252k—~3.6kAutomated safety check: PassMIT
Configuring Oauth2 Authorization Flowmukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.0
Implementing GCP Binary Authorizationmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
Collectors Authoringnetdata/netdata81k—~1.9kAutomated safety check: PassGPL-3.0
Executing Nist Rmf Authorization To Operatemukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Hermes Agent Skill Authoring

    NousResearch/hermes-agent

    Author in-repo SKILL.md files: frontmatter and structure. An agent skill from NousResearch/hermes-agent.

    252k GitHub stars~3.6k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Configuring Oauth2 Authorization Flow

    mukul975/Anthropic-Cybersecurity-Skills

    Configures secure OAuth 2.0 authorization flows, including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant, covering flow selection, PKCE implementation, token…

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Implementing GCP Binary Authorization

    mukul975/Anthropic-Cybersecurity-Skills

    Implements GCP Binary Authorization end to end, including creating KMS-backed attestors, Container Analysis notes, deploy-time policies, and signing image attestations, so that only trusted…

    34k GitHub stars~2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Collectors Authoring

    netdata/netdata

    Author, modify, or review Netdata collectors across Go, IBM, C, Rust and external plugins.

    81k GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Executing Nist Rmf Authorization To Operate

    mukul975/Anthropic-Cybersecurity-Skills

    Drive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline (FIPS 200 / SP…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Author Byline

    thedaviddias/Front-End-Checklist

    A skill your agent uses when auditing metadata, crawlability, structured data, or indexability related to Display clear author bylines.

    74k GitHub stars~409 tokensUpdated yesterday
    Marketing & SEOAuto-check passed

More from danshapiro/kilroy

  • Build Dod

    danshapiro/kilroy

    A skill your agent uses when converting a spec, requirements document, or goal statement into a Definition of Done with acceptance criteria and integration test scenarios

    221 GitHub stars~2.5k tokensUpdated 5 mo ago
    Auto-check passed
  • Release Kilroy

    danshapiro/kilroy

    A skill your agent uses when preparing a Kilroy release — writing release notes, tagging, and publishing via goreleaser on GitHub.

    221 GitHub stars~2k tokensUpdated 5 mo ago
    Auto-check passed
  • Create Dotfile

    danshapiro/kilroy

    A skill your agent uses when authoring or repairing Kilroy Attractor DOT graphs from requirements, with template-first topology, routing guardrails, and validator-clean output.

    221 GitHub stars~6.4k tokensUpdated 5 mo ago
    Auto-check passed
  • Investigating Kilroy Runs

    danshapiro/kilroy

    To diagnose active, stuck, or failed Kilroy Attractor runs, inspect run artifacts (manifest.json, live.json, checkpoint.json, final.json, progress.ndjson), resolve run IDs/log roots, identify…

    221 GitHub stars~3.1k tokensUpdated 5 mo ago
    Auto-check passed
  • Starting A Project

    danshapiro/kilroy

    A skill your agent uses when bootstrapping a new project repository for Kilroy Attractor from a clean directory using existing spec, DoD, graph, and run config artifacts.

    221 GitHub stars~498 tokensUpdated 5 mo ago
    Auto-check passed
  • Using Kilroy

    danshapiro/kilroy

    Operate Kilroy Attractor pipelines end-to-end: ingest English requirements into DOT graphs, validate graph semantics, run and resume pipelines with run config files, configure provider backends…

    221 GitHub stars~4.3k tokensUpdated 5 mo ago
    Auto-check passed

Questions about Create Runfile

What does Create Runfile do?

A skill your agent uses when authoring or repairing Kilroy run config YAML/JSON files, including DOT-to-provider backend alignment and runtime policy defaults. Create Runfile is an agent skill from danshapiro/kilroy. Use when authoring or repairing Kilroy run config YAML/JSON files, including DOT-to-provider backend alignment and runtime policy defaults.

When should I use Create Runfile?

Create Runfile fits situations like: repairing Kilroy run config YAML/JSON files; including DOT-to-provider backend alignment and runtime policy defaults.

How do I install Create Runfile in Claude Code?

Run `npx skills add danshapiro/kilroy --skill create-runfile -a claude-code`. Or copy the skill folder (skills/create-runfile in danshapiro/kilroy) into .claude/skills/create-runfile in your project. Claude Code loads it when a task matches its description.

How do I install Create Runfile in Codex?

Run `npx skills add danshapiro/kilroy --skill create-runfile -a codex`. Or copy the skill folder (skills/create-runfile in danshapiro/kilroy) into .agents/skills/create-runfile in your project. Codex loads it when a task matches its description.

Can I use Create Runfile in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add danshapiro/kilroy --skill create-runfile -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/create-runfile, .gemini/skills/create-runfile, .github/skills/create-runfile and .opencode/skills/create-runfile in your project.

What does Create Runfile need to run?

Going by SKILL.md and its folder, Create Runfile needs credentials named GEMINI_API_KEY and API_KEY. Our summary lists: A credential in GEMINI_API_KEY; A credential in API_KEY.

Does Create Runfile access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Create Runfile safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Create Runfile use?

Create Runfile is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Create Runfile use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Create Runfile?

Skills that share tags, products or a category with Create Runfile: Hermes Agent Skill Authoring (NousResearch/hermes-agent, 252k stars), Configuring Oauth2 Authorization Flow (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing GCP Binary Authorization (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Collectors Authoring (netdata/netdata, 81k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Create Runfile?

danshapiro (a GitHub user) maintains it in danshapiro/kilroy, which has 221 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on April 27, 2026.

Source: danshapiro/kilroy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.