Prime Agent
wcygan/dotfiles
A skill your agent uses when learning, configuring, or troubleshooting Prime Agent (PrimeIntellect-ai/prime-agent), including installation, providers, custom OpenAI-compatible models, local…
Bump or upgrade the pinned versions of Helmor's bundled agent CLIs, SDKs, and supporting binaries — Claude Code + claude-agent-sdk (lockstep), Codex, Cursor SDK, OpenCode, Kimi, Pi, and gh / glab /…
$ npx skills add dohooo/helmor --skill helmor-bump-vendors -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dohooo/helmor helmor-bump-vendors --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dohooo/helmor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/helmor-bump-vendors .claude/skills/helmor-bump-vendors && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "helmor-bump-vendors" agent skill from https://github.com/dohooo/helmor/tree/main/.agents/skills/helmor-bump-vendors into .claude/skills/helmor-bump-vendors/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "helmor-bump-vendors", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dohooo/helmor/tree/main/.agents/skills/helmor-bump-vendorsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dohooo/helmor --skill helmor-bump-vendors -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dohooo/helmor helmor-bump-vendors --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dohooo/helmor.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/helmor-bump-vendors .agents/skills/helmor-bump-vendors && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "helmor-bump-vendors" agent skill from https://github.com/dohooo/helmor/tree/main/.agents/skills/helmor-bump-vendors into .agents/skills/helmor-bump-vendors/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "helmor-bump-vendors", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dohooo/helmor --skill helmor-bump-vendors -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dohooo/helmor helmor-bump-vendors --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dohooo/helmor.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/helmor-bump-vendors .cursor/skills/helmor-bump-vendors && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "helmor-bump-vendors" agent skill from https://github.com/dohooo/helmor/tree/main/.agents/skills/helmor-bump-vendors into .cursor/skills/helmor-bump-vendors/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "helmor-bump-vendors", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dohooo/helmor.git --path .agents/skills/helmor-bump-vendors--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dohooo/helmor --skill helmor-bump-vendors -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dohooo/helmor helmor-bump-vendors --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dohooo/helmor.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/helmor-bump-vendors .gemini/skills/helmor-bump-vendors && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "helmor-bump-vendors" agent skill from https://github.com/dohooo/helmor/tree/main/.agents/skills/helmor-bump-vendors into .gemini/skills/helmor-bump-vendors/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "helmor-bump-vendors", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dohooo/helmor helmor-bump-vendorsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dohooo/helmor --skill helmor-bump-vendors -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dohooo/helmor.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/helmor-bump-vendors .github/skills/helmor-bump-vendors && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "helmor-bump-vendors" agent skill from https://github.com/dohooo/helmor/tree/main/.agents/skills/helmor-bump-vendors into .github/skills/helmor-bump-vendors/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "helmor-bump-vendors", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dohooo/helmor --skill helmor-bump-vendors -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dohooo/helmor helmor-bump-vendors --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dohooo/helmor.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/helmor-bump-vendors .opencode/skills/helmor-bump-vendors && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "helmor-bump-vendors" agent skill from https://github.com/dohooo/helmor/tree/main/.agents/skills/helmor-bump-vendors into .opencode/skills/helmor-bump-vendors/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "helmor-bump-vendors", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
helmor-bump-vendorsBump or upgrade the pinned versions of Helmor's bundled agent CLIs, SDKs, and supporting binaries — Claude Code + claude-agent-sdk (lockstep), Codex, Cursor SDK, OpenCode, Kimi, Pi, and gh / glab /…
Helmor Bump Vendors is an agent skill from dohooo/helmor. Bump or upgrade the pinned versions of Helmor's bundled agent CLIs, SDKs, and supporting binaries — Claude Code + claude-agent-sdk (lockstep), Codex, Cursor SDK, OpenCode, Kimi, Pi, and gh / glab / cloudflared / llama.cpp / Node. Encodes exactly which files to edit (sidecar/package.json, sidecar/scripts/vendor-platform.ts), how to source each version and compute its SHA256, the Claude SDK↔CLI lockstep rule, npm dist-tags caveats (latest vs next vs stable), the cross-arch (arm64+x64) SHA requirement, and the…
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/vendors.md` and `scripts/npm_vendor_sha.sh`).
It sits in Agent Workflows, covering LLM inference and serving. It works with npm, Claude Agent SDK, Kimi and llama.cpp. The repository describes itself as: Open-source local workbench for multi-agent software development. The licence is Apache-2.0.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit a76cda1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
buncargocodexFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
registry.npmjs.orgapi.github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Helmor Bump Vendors loads about 2.1k tokens when it runs, and up to ~4.5k if it reads all its reference files. Until then it costs about 191 tokens; SKILL.md has 883 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from dohooo/helmor at commit a76cda1, republished under its Apache-2.0 licence (© dohooo). 883 words, ~2,074 tokens.
.claude/skills/helmor-bump-vendors/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Standardized procedure for upgrading the third-party agent CLIs, SDKs, and helper binaries that Helmor pins and bundles. Goal: a correct, verified bump with no guesswork about where versions live, how to source each SHA256, or what to run before declaring it done.
Every bundled version is pinned in one (or both) of these files:
sidecar/package.json — npm dependencies. Covers SDKs (imported in TS) and the
npm-distributed CLIs whose native binary is staged from node_modules
(@anthropic-ai/claude-code, @openai/codex, opencode-ai).sidecar/scripts/vendor-platform.ts — version constants + per-version SHA256 tables
for every staged binary. Source of truth for what gets bundled into the release.sidecar/scripts/stage-vendor.ts — staging logic. Only edit it when a vendor's archive
layout changes (rare; see codex/cursor notes in references/vendors.md).| Class | Vendors | What to edit | SHA256? |
|---|---|---|---|
| A. npm SDK only | @anthropic-ai/claude-agent-sdk, @cursor/sdk, @opencode-ai/sdk, @earendil-works/pi-* | package.json line | No — plain npm dep |
| B. npm-distributed staged binary | claude-code, codex, opencode | package.json line + SHA256 table key in vendor-platform.ts | Yes — from npm tarball |
| C. GitHub-release staged binary | kimi, gh, glab, cloudflared, llama.cpp, node | <NAME>_VERSION const + SHA256 table in vendor-platform.ts (NOT in package.json) | Yes — source varies |
Per-vendor exact pin location, SHA256 source, and gotchas live in references/vendors.md —
read the relevant section before editing.
references/vendors.md for its class,
pin location, SHA source, and gotchas.bun -e 'console.log((await (await fetch("https://registry.npmjs.org/<pkg>")).json())["dist-tags"])'
Target latest (the stable channel). next is a prerelease — do not pin it unless the
user explicitly asks. claude-code also publishes a conservative stable tag that lags
(e.g. 2.1.179); Helmor tracks latest, not stable.https://api.github.com/repos/<owner>/<repo>/releases).package.json and/or the _VERSION const). Apply the Claude lockstep rule
and any per-vendor gotcha from the reference.cd sidecar && bun install — pulls the new versions. Sanity-check: resolved versions are
correct, any removed deps dropped from bun.lock, transitive deps you rely on are still present.scripts/npm_vendor_sha.sh for B; see the reference
for C. Both arm64 and x64 are mandatory (see Critical rules)./helmor-release skill to draft
the changeset (and an in-app announcement if the bump warrants one). Don't skip this — a vendor
bump is a user-visible change and needs a changeset. A routine bundled-agent refresh is typically
a patch changeset with no announcement; the body should name the user-visible change (which
agents moved to latest), not the internal cleanup (Pi removal, pin tidy-ups, doc fixes).@anthropic-ai/claude-agent-sdk@0.3.X and @anthropic-ai/claude-code@2.1.X
share patch X and ship together — always bump both to the same X. Verify: the SDK's
node_modules/@anthropic-ai/claude-agent-sdk/package.json carries claudeCodeVersion: "2.1.X".
Only claude-code (the staged binary) needs a SHA256 entry; the agent-sdk is a plain npm dep.arm64 and x64.
CI cross-builds the x86_64 bundle on an arm64 runner. On a native-arch host the build uses
node_modules directly and does not verify the SHA — so a wrong/missing x64 entry passes
locally but breaks CI. Always compute both from the tarballs.latest at bump time even if you "just looked" — a newer patch can
be promoted from next to latest within hours.codex-package.json descriptor; after a
bump, diff it — a layoutVersion change or new field means stage-vendor.ts needs review. See
references/vendors.md for codex, cursor (Node engines floor + phantom dep), and kimi (ACP
protocol version) specifics.cd sidecar && bun install # 1. installs targets; confirm versions + dropped deps in bun.lock
cd sidecar && bun run typecheck # 2. catches SDK API breaks (removed/renamed exports) — main breaking-change detector
cd sidecar && bun test # 3. sidecar unit tests
# 4. MANDATORY after ANY agent CLI/SDK bump — validates the stdout event-shape contract the Rust pipeline depends on:
cd src-tauri && cargo test --test pipeline_scenarios --test pipeline_fixtures --test pipeline_streams
cd sidecar && bun run build # 5. full staging + compile; a wrong SHA256 hard-fails here (downloads + verifies kimi / cross-arch)What each gate proves:
item/,turn/,thread/ methods; claude SDKMessage/stream blocks;
opencode message.part; kimi ACP session/update) and capture fresh fixtures if the shape moved.Before pinning, read the upstream changelog/release notes across the current→target window. Most agent-CLI patch bumps are additive; the risks that matter for Helmor are (a) SDK export/type changes (typecheck catches these) and (b) stdout event-shape changes (the Rust pipeline contract). Tag each notable change affects Helmor or no impact with reasoning, and surface it before bumping.
scripts/npm_vendor_sha.sh <claude-code|codex|opencode> <version> — downloads the darwin
arm64 + x64 npm tarballs and prints their SHA256, ready to paste into the vendor-platform.ts
table. (Class B only. Class A SDKs need no SHA; class C sources differ — see the reference.)references/vendors.md — exhaustive per-vendor map: integration mechanism, exact pin
location, SHA256 source/recipe, gotchas, and post-bump steps.© dohooo, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts, references) in .agents/skills/helmor-bump-vendors of dohooo/helmor.
Open the folder on GitHubat commit a76cda1
Helmor Bump Vendors next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Helmor Bump Vendors this skilldohooo/helmor | 1.3k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Prime Agentwcygan/dotfiles | 194 | — | ~1.8k | Automated safety check: Pass | None | |
| Agent SDK Version Bumppreset-io/agor | 1.4k | — | ~1.4k | Automated safety check: Pass | Custom licence | |
| Compact Memory Implementationsimbajigege/book2skills | 183 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Pi AgentK-Dense-AI/scientific-agent-skills | 48k | 1 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Agent BuilderMathews-Tom/armory | 329 | — | ~1.7k | Automated safety check: Pass | MIT |
wcygan/dotfiles
A skill your agent uses when learning, configuring, or troubleshooting Prime Agent (PrimeIntellect-ai/prime-agent), including installation, providers, custom OpenAI-compatible models, local…
preset-io/agor
Upgrades a pinned agent SDK in the agor project, such as the Claude, Codex or Gemini CLI one, and plans the release that carries it to packaged installs.
simbajigege/book2skills
A developer guide to adding compact memory to an agent: when to trigger compaction, how to fork a compactor sub-agent, what the summary holds, and how to restore it.
K-Dense-AI/scientific-agent-skills
Builds with and operates Pi, the minimal terminal coding harness.
Mathews-Tom/armory
Build AI agents and automate Claude Code programmatically via the Claude Agent SDK and headless CLI mode.
andrewyng/context-hub
Fetches current documentation for third-party APIs and SDKs with the chub CLI before the agent writes code against them, instead of relying on remembered API shapes.
dohooo/helmor
Use the Helmor CLI to remote-control Helmor from the terminal.
dohooo/helmor
Autonomous local-development debugging loop for Helmor bugs.
dohooo/helmor
Prepare Helmor releases by inspecting the current branch, drafting a concise user-facing Changesets entry first (bump + body — keep it as short as possible), creating any needed pending in-app…
dohooo/helmor
Operate, reproduce, and debug a running local Helmor desktop development build through the Tauri MCP bridge.
Categories
Bump or upgrade the pinned versions of Helmor's bundled agent CLIs, SDKs, and supporting binaries — Claude Code + claude-agent-sdk (lockstep), Codex, Cursor SDK, OpenCode, Kimi, Pi, and gh / glab /…. Helmor Bump Vendors is an agent skill from dohooo/helmor.cpp / Node.
Helmor Bump Vendors fits situations like: the user wants to upgrade / bump / update / refresh a bundled agent CLI; check whether a vendor is behind latest; run a dependency version sweep in the Helmor repo.
Run `npx skills add dohooo/helmor --skill helmor-bump-vendors -a claude-code`. Or copy the skill folder (.agents/skills/helmor-bump-vendors in dohooo/helmor) into .claude/skills/helmor-bump-vendors in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dohooo/helmor --skill helmor-bump-vendors -a codex`. Or copy the skill folder (.agents/skills/helmor-bump-vendors in dohooo/helmor) into .agents/skills/helmor-bump-vendors in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dohooo/helmor --skill helmor-bump-vendors -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/helmor-bump-vendors, .gemini/skills/helmor-bump-vendors, .github/skills/helmor-bump-vendors and .opencode/skills/helmor-bump-vendors in your project.
Going by SKILL.md and its folder, Helmor Bump Vendors needs a shell for the scripts in its folder and the command-line tools its instructions call (bun, cargo and codex). Our summary lists: A Bash shell.
SKILL.md names 2 domains. In commands or code: registry.npmjs.org and api.github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Helmor Bump Vendors is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Helmor Bump Vendors: Prime Agent (wcygan/dotfiles, 194 stars), Agent SDK Version Bump (preset-io/agor, 1.4k stars), Compact Memory Implementation (simbajigege/book2skills, 183 stars) and Pi Agent (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dohooo (a GitHub user) maintains it in dohooo/helmor, which has 1,309 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on August 22, 2026.
Source: dohooo/helmor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.