Agent skill

Meticulous CLI Update

by FlintSH in FlintSH/Flare

Check whether the Meticulous CLI (@alwaysmeticulous/cli) and skills are installed and up to date, and install/update them if not.

MITAuto-check passedBackend & APIs

Install Meticulous CLI Update

skills CLI
$ npx skills add FlintSH/Flare --skill meticulous-cli-update -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install FlintSH/Flare meticulous-cli-update --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/FlintSH/Flare.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/meticulous-cli-update .claude/skills/meticulous-cli-update && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
meticulous-cli-update
GitHub stars
135
Token cost
~2.6k tokens
SKILL.md length
1,372 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Check whether the Meticulous CLI (@alwaysmeticulous/cli) and skills are installed and up to date, and install/update them if not.

  • Works in 5 steps: Check the installed version → Check the latest published version → Update the CLI if outdated → …
  • Backend & APIs work in your project
  • SKILL.md covers How to handle the…, Step 1 — Check the installed…, Step 2 — Check the latest… and Step 3 — Update the CLI if…, plus 2 more sections
  • Calls npm, npx and claude; needs METICULOUS_API_TOKEN

What it does

Meticulous CLI Update is an agent skill from FlintSH/Flare. Check whether the Meticulous CLI (@alwaysmeticulous/cli) and skills are installed and up to date, and install/update them if not. Invoked at the start of every other Meticulous skill, since the CLI and skills are under active development with frequent changes and improvements.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. It works with Model Context Protocol. The repository describes itself as: A modern, lightning-fast file sharing platform built for self-hosting. Created with support for ShareX, KDE Spectacle, Flameshot, and easy to set up. The licence is MIT.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “/meticulous-cli-update”

Requirements

  • Node.js
  • A credential in METICULOUS_API_TOKEN

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Check the installed version
  2. Check the latest published version
  3. Update the CLI if outdated
  4. Check authentication and project selection
  5. Update the installed Meticulous skills

What it can do on your machine

Read from SKILL.md and the folder at commit c910523. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • npx
    • claude
    • pnpm
    • yarn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, npx, pnpm and yarn, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • METICULOUS_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Meticulous CLI Update loads about 2.6k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 1,372 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from FlintSH/Flare at commit c910523, republished under its MIT licence (© FlintSH). 1,372 words, ~2,649 tokens.

Download SKILL.mdSave it as .claude/skills/meticulous-cli-update/SKILL.md (or your agent's skills folder).
name
meticulous-cli-update
description
Check whether the Meticulous CLI (@alwaysmeticulous/cli) and skills are installed and up to date, and install/update them if not. Invoked at the start of every other Meticulous skill, since the CLI and skills are under active development with frequent changes and improvements.
user-invocable
false

Install or update the Meticulous CLI

The @alwaysmeticulous/cli package is under active development and ships frequent changes and improvements. Other Meticulous skills assume the meticulous command is on PATH and up to date, so run this skill once at the start of any Meticulous workflow.

This only needs to run once per conversation. If you've already run it earlier in this conversation, skip it — there's no need to re-check the version or re-update on every Meticulous skill invocation.

Using the MCP server instead of the CLI? Steps 1-4 are about installing/updating the meticulous CLI binary and its own local auth — neither applies when calling tools on the hosted Meticulous MCP server, which is already on the latest version and authenticates via the MCP connection itself, not meticulous auth login. Skip straight to Step 5: the installed skills (this document set) are a separate thing from the CLI/MCP tool itself and still need to stay current either way, regardless of which one you're calling tools through.

Full setup instructions — installing the CLI, connecting the MCP server, and installing these skills — live at app.meticulous.ai/docs/agents/setup.

How to handle the install/update commands

This skill normally runs as a sub-step of another Meticulous skill. The install/update commands below (Steps 1, 3, and 5) are security-sensitive — they install packages and reach the network — so treat them as best-effort and non-blocking:

  • You generally can't tell in advance whether a command is whitelisted. If it's whitelisted it runs silently; if not, attempting it surfaces a permission prompt. Either outcome is fine — let that be how you find out.
  • If a command needs permission you don't have (a prompt appears, or the user declines it), treat that as the signal to recommend rather than force. Tell the user it's recommended to do XYZ — e.g. "It's recommended to update the Meticulous CLI by running npm install --global @alwaysmeticulous/cli@latest" — and move on. A declined prompt is not a failure; it just means "do it later."
  • If the user doesn't want to run it now, continue anyway. Do not stop the workflow; carry on with the remaining steps and then return to the calling skill. The only hard requirement is that the meticulous command exists at all (Step 1) — if it's genuinely not installed and the user declines to install it, no Meticulous skill can proceed, so stop there.

The read-only checks (meticulous --version, npm view …, meticulous auth whoami) are safe to run directly.

Step 1 — Check the installed version

bash
meticulous --version

If the command is not found, the CLI is not installed. Install it globally (best-effort, see the note above):

bash
npm install --global @alwaysmeticulous/cli@latest

If installing isn't whitelisted, recommend the user run that command themselves. Because no Meticulous skill can run without the CLI, this is the one case where you should stop and wait if the user declines — there's nothing to continue with. Once installed, re-run meticulous --version to confirm it's on PATH, and skip to Step 4.

Step 2 — Check the latest published version

bash
npm view @alwaysmeticulous/cli version

Step 3 — Update the CLI if outdated

If the installed version already matches the latest, skip to Step 4.

Otherwise, update according to how the CLI is installed (best-effort, see the note above — if updating isn't whitelisted, recommend the user run the appropriate command and continue regardless):

  • Globally installed (typical — which meticulous resolves to a path outside the current project):

    bash
    npm install --global @alwaysmeticulous/cli@latest
  • Locally installed in the project (@alwaysmeticulous/cli appears in the project's package.json and which meticulous resolves inside node_modules/.bin):

    bash
    npm install --save-dev @alwaysmeticulous/cli@latest
    # or, if the project uses pnpm:
    pnpm add --save-dev @alwaysmeticulous/cli@latest
    # or yarn:
    yarn add --dev @alwaysmeticulous/cli@latest

If the update ran, re-run meticulous --version and confirm it matches the latest before proceeding.

Step 4 — Check authentication and project selection

Verify the user is authenticated with Meticulous and has a project selected:

bash
meticulous auth whoami

Add --json if you'd rather branch on structured output — it prints authenticatedVia and selectedProject.

There are four outcomes:

(a) Signed in via OAuth, with a project selected
Authenticated via: OAuth
Logged in as: Jane Smith (jane@example.com)
Organizations: acme-corp (member)
Selected project: acme-corp/Web App

Nothing to do — continue to Step 5.

(b) Authenticated by an API token or injected credentials
Authenticated via: project API token (METICULOUS_API_TOKEN environment variable)
Pinned project: acme-corp/Web App

Also seen as project API token (~/.meticulous/config.json), test-run API token, or credentials injected at request time (agent platforms that attach a bearer credential to outbound requests to app.meticulous.ai). These credentials are scoped to a single project, which is already pinned, so there is nothing to select — do not run meticulous auth set-project: with an API token it errors out (the token is bound to one project), and with injected credentials there is likewise nothing to choose. Continue to Step 5.

Show full SKILL.md (686 more words)Show less
(c) "Not logged in"

The command exits with:

Not logged in. Run meticulous auth login, or set METICULOUS_API_TOKEN. In terminals without a browser, use meticulous auth login --non-interactive.

Sign-in is browser SSO, so a human always has to complete it in a browser; which login command to use depends on where you're running:

  • On the user's own machine (a browser there can reach this machine's localhost):

    bash
    meticulous auth login --non-interactive

    This prints a login URL and then waits on a local callback server, so run it in the background, then surface the printed URL to the user and ask them to open it and complete sign-in. Once they do, the command finishes and stores the token, and you can continue.

    Alternatively, ask the user to run meticulous auth login themselves — at their own terminal that opens the browser directly.

  • On a remote or sandboxed machine (cloud agent, SSH session, container) where a browser on another device can't reach this machine's localhost:

    bash
    meticulous auth login --device

    This uses the OAuth device flow: it prints a URL and a short code instead of waiting on a local callback. Run it in the background, then surface the URL and code to the user and ask them to open the URL on any device and enter the code. Once confirmed, the command finishes and stores the token.

Both forms skip the interactive project picker, so add --project "Organization/Project" when you already know which project to use — that logs in and pins the project in one step. Without --project, an account with access to several projects lands in case (d) below, so re-run meticulous auth whoami once login completes and handle whichever case it reports before continuing to Step 5.

In a CI-like environment with no human available at all, the alternative is an API token: set METICULOUS_API_TOKEN (or pass --apiToken) instead of logging in.

(d) Signed in via OAuth, but no default project

whoami succeeds and additionally logs (on stderr):

No default project set. Run meticulous auth set-project to choose one.

Project-scoped commands can't resolve a project in this state. It happens for accounts with access to several projects — including right after a --non-interactive or --device login, which skips the picker. List the options, then pin one:

bash
meticulous auth list-projects   # one "organization/project" slug per line
meticulous auth set-project --project "Organization/Project"

Ask the user which one to use unless it's unambiguous (e.g. only one project is listed, or the repo clearly corresponds to one of them). Alternatively, ask the user to run meticulous auth set-project themselves — without --project it shows an interactive picker.

The selection is saved to the account rather than the machine, so it also applies to the MCP server and to the user's other machines. meticulous auth get-project prints the currently resolved project on its own.

Step 5 — Update the installed Meticulous skills

The skills themselves are also under active development. How to update them depends on how they were installed (best-effort, see the note above):

  • Installed with npx skills — the default. Skill files live under .claude/skills/, .cursor/skills/, or the equivalent for the agent, alongside a skills-lock.json:

    bash
    # Install or update all skills, for the specified agents
    npx skills add alwaysmeticulous/skills --skill "*" --agent claude-code --agent codex --agent cursor -y

    Only run this once you've seen a skills-lock.json (or the skill files themselves) in the project, since it would otherwise install a second copy alongside a plugin install.

  • Installed as the Claude Code plugin — the skills show up namespaced as /meticulous:<skill-name>, and claude plugin list lists meticulous@meticulous. npx skills won't touch these; update the plugin instead:

    bash
    claude plugin update meticulous@meticulous

    Tell the user the update only takes effect after they restart Claude Code (they can also do this from the /plugin menu themselves). One exception: if claude plugin list reports the plugin's scope as managed, it's pinned by their organization's managed settings — don't try to update it, just mention it to the user.

  • Installed from the Cursor plugin marketplace — there's no command to run; recommend the user update it from Cursor's Customize → Plugins.

If the applicable command isn't whitelisted, recommend the user run it themselves. Either way — whether it ran, or the user declined — proceed with the calling skill.

© FlintSH, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/meticulous-cli-update of FlintSH/Flare.

Open the folder on GitHubat commit c910523

Compare with similar skills

Meticulous CLI Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Meticulous CLI Update compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Meticulous CLI Update this skillFlintSH/Flare135—~2.6kAutomated safety check: PassMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
OpenAPI to MCP Servermcp-use/mcp-use11k—~5.2kAutomated safety check: PassApache-2.0
Supabasecurvenote/curvenote1695 repos~2.2kAutomated safety check: PassCustom licence
AWS Serverless Edazxkane/aws-skills3674 repos~3.2kAutomated safety check: PassMIT
FoundatioFoundatioFx/Foundatio2.1k—~3.9kAutomated safety check: PassApache-2.0

Similar skills

  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • OpenAPI to MCP Server

    mcp-use/mcp-use

    Turns an OpenAPI or Swagger spec into an MCP server with the mcp-use TypeScript SDK, mapping each operation to a tool, wiring auth, testing and deploying.

    11k GitHub stars~5.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Supabase

    curvenote/curvenote

    A skill your agent uses when doing ANY task involving Supabase.

    169 GitHub starsUsed in 5 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • AWS Serverless Eda

    zxkane/aws-skills

    AWS serverless and event-driven architecture expert based on Well-Architected Framework.

    367 GitHub starsUsed in 4 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Foundatio

    FoundatioFx/Foundatio

    A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.

    2.1k GitHub stars~3.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Legba

    evilsocket/legba

    A skill your agent uses when the user wants to brute-force credentials, spray passwords, or enumerate services/subdomains against any network protocol (HTTP, SSH, FTP, SMB, RDP, databases, mail…

    1.9k GitHub stars~2.2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from FlintSH/Flare

All 10 skills in this repo
  • Meticulous CLI

    FlintSH/Flare

    Overview of the Meticulous CLI tool and its global options. An agent skill from FlintSH/Flare.

    135 GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed
  • Meticulous Fix

    FlintSH/Flare

    Fix the visual diffs that have been reviewed and rejected on a Meticulous test run, following their review comments if given.

    135 GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed
  • Increase coverage for a Meticulous project by tracing specific under-covered files back to a real UI action in the codebase, driving that action with a real recorded browser session, and validating…

    135 GitHub stars~7k tokensUpdated 2 days ago
    Auto-check passed
  • Iterative frontend development loop using Meticulous for per-step visual validation.

    135 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Meticulous Review

    FlintSH/Flare

    Analyze a completed Meticulous test run — compare the diffs against the PR description to see what's expected, then focus on finding and flagging potential regressions.

    135 GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed
  • Run a Meticulous session simulation against a live URL and analyze the visual output — either by inspecting screenshots directly (quick-check mode) or by comparing pixel and HTML diffs against a…

    135 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Meticulous CLI Update

What does Meticulous CLI Update do?

Check whether the Meticulous CLI (@alwaysmeticulous/cli) and skills are installed and up to date, and install/update them if not. Meticulous CLI Update is an agent skill from FlintSH/Flare. Check whether the Meticulous CLI (@alwaysmeticulous/cli) and skills are installed and up to date, and install/update them if not.

When should I use Meticulous CLI Update?

Meticulous CLI Update fits situations like: backend & APIs work in your project.

How do I install Meticulous CLI Update in Claude Code?

Run `npx skills add FlintSH/Flare --skill meticulous-cli-update -a claude-code`. Or copy the skill folder (.agents/skills/meticulous-cli-update in FlintSH/Flare) into .claude/skills/meticulous-cli-update in your project. Claude Code loads it when a task matches its description.

How do I install Meticulous CLI Update in Codex?

Run `npx skills add FlintSH/Flare --skill meticulous-cli-update -a codex`. Or copy the skill folder (.agents/skills/meticulous-cli-update in FlintSH/Flare) into .agents/skills/meticulous-cli-update in your project. Codex loads it when a task matches its description.

Can I use Meticulous CLI Update in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FlintSH/Flare --skill meticulous-cli-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/meticulous-cli-update, .gemini/skills/meticulous-cli-update, .github/skills/meticulous-cli-update and .opencode/skills/meticulous-cli-update in your project.

What does Meticulous CLI Update need to run?

Going by SKILL.md and its folder, Meticulous CLI Update needs the command-line tools its instructions call (npm, npx, claude, pnpm and yarn) and credentials named METICULOUS_API_TOKEN. Our summary lists: Node.js; A credential in METICULOUS_API_TOKEN.

Does Meticulous CLI Update access the network?

SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Meticulous CLI Update safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Meticulous CLI Update use?

Meticulous CLI Update is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Meticulous CLI Update use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Meticulous CLI Update?

Skills that share tags, products or a category with Meticulous CLI Update: Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), OpenAPI to MCP Server (mcp-use/mcp-use, 11k stars), Supabase (curvenote/curvenote, 169 stars) and AWS Serverless Eda (zxkane/aws-skills, 367 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Meticulous CLI Update?

FlintSH (a GitHub user) maintains it in FlintSH/Flare, which has 135 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 6, 2026.

Source: FlintSH/Flare on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.