Agent skill

Agent Onboarding

by forefy in forefy/.context

Onboard yourself to a repo where several agents work in parallel, syncing through a shared TODO.md.

MITAuto-check passedSecurity

Install Agent Onboarding

skills CLI
$ npx skills add forefy/.context --skill agent-onboarding -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forefy/.context agent-onboarding --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/generic-utils/agent-onboarding .claude/skills/agent-onboarding && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agent-onboarding
GitHub stars
152
Token cost
~536 tokens
SKILL.md length
276 words
Files
1
Skills in repo
20
Repo updated
First seen
Licence
MIT

At a glance

Onboard yourself to a repo where several agents work in parallel, syncing through a shared TODO.md.

  • Joining the team on a shared codebase
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Agent Onboarding is an agent skill from forefy/.context. Onboard yourself to a repo where several agents work in parallel, syncing through a shared TODO.md. Use when joining the team on a shared codebase.

Its SKILL.md is about 540 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: AI Agent Skills, Goals and Dynamic Workflows for Security Auditing, Pentesting and Research. The licence is MIT.

When your agent uses it

  • Joining the team on a shared codebase

Example prompts

  • “/agent-onboarding”

What it can do on your machine

Read from SKILL.md and the folder at commit c8ff161. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Agent Onboarding loads about 536 tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 276 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~536

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from forefy/.context at commit c8ff161, republished under its MIT licence (© forefy). 276 words, ~536 tokens.

Download SKILL.mdSave it as .claude/skills/agent-onboarding/SKILL.md (or your agent's skills folder).
name
agent-onboarding
description
Onboard yourself to a repo where several agents work in parallel, syncing through a shared TODO.md. Use when joining the team on a shared codebase.
  • You are now a part of a working force and you should be aware of the codebase, whats happening here and what are the docs and maybe some of the Makefile for extra context.
  • If you had preexisting work assignments, give yourself an identity, like refractor-george or unit-testing-lary, otherwise ask the user why he brought you to name yourself based on your first task
  • Find the repo's TODO.md file where all the other team members are, if you are the first, setup what is needed to get this started for future agents including yourself
  • If there are existing TODO.md categories register yourself under one or more of them based on tasks at hand
  • Whenever you are in the decision making, check back to TODO.md to see you are complimentary, and not contradictory or duplicative, of another agent/team members work
  • TODO.md should be gitignored if not already
  • DON'T fill data outside what the user had, except for your name and tasks
  • DON'T give yourself unmeaningfull name like "copilot-hal", either understand by context or ask the user
  • If onboarded after some work, you have your context already so no need to go looking for it, and same for your identity
  • We want quick and effective context understanding and team registration
  • a copilot / claude code session can only have one identity at a time
  • Use the TODO.md to avoid conflicting in your actions with other members, and check back every time you are working on something to indicate to other agents not to conflict with you
  • If you are doing tasks under both categories just register yourself under both of them with the relevant tasks

The structure should be:

md
# TODO.md

## Some task category

### [refractor-george]

- [ ] Refractoring what the user asked regarding the x structure
  - [ ] Task you were given when interacting with the human
  - [ ] Another task
  - [ ] Task you just completed

## Another task category

[possibly other agents or team members]

© forefy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/generic-utils/agent-onboarding of forefy/.context.

Open the folder on GitHubat commit c8ff161

Compare with similar skills

Agent Onboarding next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agent Onboarding compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agent Onboarding this skillforefy/.context152—~536Automated safety check: PassMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~5.6kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4791 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~5.6k tokensUpdated yesterday
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    479 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from forefy/.context

All 20 skills in this repo
  • Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links.

    152 GitHub stars~951 tokensUpdated 2 days ago
    Auto-check passed
  • Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report.

    152 GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed
  • Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.

    152 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Audit Scope

    forefy/.context

    Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.

    152 GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed
  • External Enumeration

    forefy/.context

    Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.

    152 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    Auto-check passed

Categories

Questions about Agent Onboarding

What does Agent Onboarding do?

Onboard yourself to a repo where several agents work in parallel, syncing through a shared TODO.md. context.md.

When should I use Agent Onboarding?

Agent Onboarding fits situations like: joining the team on a shared codebase.

How do I install Agent Onboarding in Claude Code?

Run `npx skills add forefy/.context --skill agent-onboarding -a claude-code`. Or copy the skill folder (skills/generic-utils/agent-onboarding in forefy/.context) into .claude/skills/agent-onboarding in your project. Claude Code loads it when a task matches its description.

How do I install Agent Onboarding in Codex?

Run `npx skills add forefy/.context --skill agent-onboarding -a codex`. Or copy the skill folder (skills/generic-utils/agent-onboarding in forefy/.context) into .agents/skills/agent-onboarding in your project. Codex loads it when a task matches its description.

Can I use Agent Onboarding in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forefy/.context --skill agent-onboarding -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-onboarding, .gemini/skills/agent-onboarding, .github/skills/agent-onboarding and .opencode/skills/agent-onboarding in your project.

What does Agent Onboarding need to run?

SKILL.md names no scripts, command-line tools or credentials: Agent Onboarding is instructions for the agent only.

Does Agent Onboarding access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Agent Onboarding safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Agent Onboarding use?

Agent Onboarding is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agent Onboarding use?

About 536 tokens (SKILL.md is roughly 2.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Agent Onboarding?

Skills that share tags, products or a category with Agent Onboarding: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 479 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agent Onboarding?

forefy (a GitHub user) maintains it in forefy/.context, which has 152 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 4, 2026.

Source: forefy/.context on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.