Agent Lightning
microsoft/agent-lightning
Provides the action space, tradeoffs, and evaluation context for improving an editable AI agent against a benchmark while preserving its deployment contract.
A skill your agent uses when working near production, sensitive systems, or destructive operations.
$ npx skills add garagon/nanostack --skill guard -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install garagon/nanostack guard --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/garagon/nanostack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/guard .claude/skills/guard && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "guard" agent skill from https://github.com/garagon/nanostack/tree/main/guard into .claude/skills/guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guard", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/garagon/nanostack/tree/main/guardType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add garagon/nanostack --skill guard -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install garagon/nanostack guard --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garagon/nanostack.git skills-src && mkdir -p .agents/skills && cp -r skills-src/guard .agents/skills/guard && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "guard" agent skill from https://github.com/garagon/nanostack/tree/main/guard into .agents/skills/guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guard", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add garagon/nanostack --skill guard -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install garagon/nanostack guard --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garagon/nanostack.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/guard .cursor/skills/guard && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "guard" agent skill from https://github.com/garagon/nanostack/tree/main/guard into .cursor/skills/guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guard", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/garagon/nanostack.git --path guard--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add garagon/nanostack --skill guard -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install garagon/nanostack guard --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garagon/nanostack.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/guard .gemini/skills/guard && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "guard" agent skill from https://github.com/garagon/nanostack/tree/main/guard into .gemini/skills/guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guard", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install garagon/nanostack guardInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add garagon/nanostack --skill guard -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/garagon/nanostack.git skills-src && mkdir -p .github/skills && cp -r skills-src/guard .github/skills/guard && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "guard" agent skill from https://github.com/garagon/nanostack/tree/main/guard into .github/skills/guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guard", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add garagon/nanostack --skill guard -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install garagon/nanostack guard --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garagon/nanostack.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/guard .opencode/skills/guard && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "guard" agent skill from https://github.com/garagon/nanostack/tree/main/guard into .opencode/skills/guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guard", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
guardA skill your agent uses when working near production, sensitive systems, or destructive operations.
Guard is an agent skill from garagon/nanostack. Use when working near production, sensitive systems, or destructive operations. Activates on-demand safety hooks that block dangerous commands. Supports modes — careful (warn), freeze (guided, keeps writes within scope), unfreeze (remove restrictions). Triggers on /guard, /careful, /freeze, /unfreeze.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `agents/openai.yaml`, `bin/budget-gate.sh` and `bin/check-dangerous.sh`).
It sits in DevOps & Cloud. The repository describes itself as: A workflow harness that helps AI coding agents plan, review, test, and ship safer code. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 0372aed. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (Shell), which the agent can run.
Shell commands in SKILL.md call:
gitdockerkubectlpythonnodeshjqFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, docker and kubectl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Guard loads about 2k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 917 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- Writing to production configs or `.env` filesed against known-bad patterns (e.g. `cat .env`, `find . -delete`).Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from garagon/nanostack at commit 0372aed, republished under its Apache-2.0 licence (© garagon). 917 words, ~2,012 tokens.
.claude/skills/guard/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.You have activated safety guardrails. These protect against accidental destructive operations during this session.
Defensive telemetry init. No-op if telemetry is disabled via NANOSTACK_NO_TELEMETRY=1, ~/.nanostack/.telemetry-disabled, or if the helpers are removed.
_P="$HOME/.claude/skills/nanostack/bin/lib/skill-preamble.sh"
[ -f "$_P" ] && . "$_P" guard
unset _PThe user may activate a specific mode. If no mode is specified, default to careful.
What it does: Warns before any potentially destructive operation but does not block.
When you detect a destructive operation, pause and present:
⚠️ GUARD: Potentially destructive operation detected
Operation: {{what you're about to do}}
Impact: {{what could go wrong}}
Reversible: {{yes/no — if yes, how}}
Proceed? [y/n]Use AskUserQuestion to get explicit confirmation before proceeding.
Destructive operations include:
rm -rf, rm -r on directoriesgit reset --hard, git push --force, git branch -DDROP TABLE, DELETE FROM without WHERE, TRUNCATEkubectl delete, docker rm, docker system prune.env filesguard/bin/check-dangerous.sh script flagsWhat it does: Asks the agent to keep its file writes (Edit, Write) within a
chosen scope for the rest of the session. This is a guided instruction the agent
follows, not a hook-enforced block: unlike the secret and system-path denylist
in check-write.sh, the Write/Edit hook does not currently reject an
out-of-scope write. Treat freeze as agent-level discipline, not a wall.
When the user says /freeze or /guard freeze:
guard/config.json// guard/config.json
{
"mode": "freeze",
"allowed_paths": [
"src/feature/**",
"tests/feature/**"
],
"frozen_at": "2025-01-01T00:00:00Z"
}When you are about to write outside the frozen scope, decline and say so (the hook does not stop the write for you, so this is on the agent to honor):
🔒 GUARD FREEZE: declining write outside the frozen scope
File: {{path}}
Reason: not in the allowed scope
Allowed: {{list of allowed paths}}
To unfreeze: /unfreezeWhat it does: Removes freeze restrictions.
When the user says /unfreeze or /guard unfreeze:
🔓 GUARD: Freeze lifted. Returning to careful mode.guard/bin/check-dangerous.sh runs every Bash call through a layered check pipeline. The order is deliberate: block rules run first so commands whose binary is on the allowlist (cat, find, head, tail) still get matched against known-bad patterns (e.g. cat .env, find . -delete).
Block rules (run first, no exceptions). Matched against the full command string. The current rule counts are loaded from guard/rules.json; this doc does not hand-maintain them.
Allowlist. Commands like git status, ls, jq short-circuit when no block rule matched.
Phase-aware concurrency. When a session is active and the current phase declares concurrency: read (built-in or custom), write commands are blocked with category concurrency-safety. The active phase's SKILL.md is resolved through bin/lib/phases.sh so custom phases get the same protection as built-in ones. Detection covers more than the obvious utilities: output redirection to anything except /dev/*, in-place editors (sed -i, perl -i), tee/truncate/patch/install, inline interpreter code (python -c, node -e, sh -c, whose quoted body is invisible to pattern checks), and git worktree mutations (stash, restore, checkout, merge, rebase, apply, clean). Quoted segments are stripped first so a read like awk '$3 > 5' file is never mistaken for redirection. The regression lock is ci/e2e-read-phase-writes.sh.
In-project fast-path. Operations that only touch files inside the current git repo pass through. Reviewable via version control. Runs after the concurrency check so an in-project touch ./foo cannot bypass a read-phase block.
Sprint phase gate. Blocks git commit / git push until the required-before-ship ancestors of the active phase_graph have completed. The built-in sprint defaults to review + security + qa; custom graphs gate on their own ancestor list.
Budget gate. Blocks all commands when the configured budget is exceeded. A small set of safe reads (git status, git diff, ls, cat) stay runnable so you can inspect and save work behind the wall. This gate is a cost cap, not a sandbox: it does not defend against a repository whose own git config runs helper programs (diff.external, textconv, core.fsmonitor, filters, hooks), since those run on any git command regardless of the gate. Command-line vectors that turn a read into command execution (-c, --ext-diff, --output, --exec-path=) are rejected from the read exemption.
Warn rules. Final pass: matched commands are allowed but flagged in the output so the user is reminded what they're doing.
When a command is blocked, guard suggests a safer alternative instead of just failing:
BLOCKED [G-007] Force push overwrites remote history
Category: history-destruction
Command: git push --force origin main
Safer alternative: git push --force-with-lease (safer, fails if remote changed)Rules live in guard/rules.json. Each rule has an ID, regex pattern, category, description, and (for block rules) a safer alternative. The shipped categories include mass-deletion, history-destruction, database-destruction, infra-destruction, production-access, remote-code-execution, security-degradation, and safety-bypass. Run jq '[.tiers.block.rules[].id] | length' guard/rules.json (or the equivalent for warn rules) to inspect the live counts; the CI lint job derives them from this file.
Users can add custom rules by editing guard/rules.json.
Before returning control:
_F="$HOME/.claude/skills/nanostack/bin/lib/skill-finalize.sh"
[ -f "$_F" ] && . "$_F" guard success
unset _FPass abort or error instead of success if guard did not complete normally.
/guard and lasts until the session ends. It does not persist across sessions. This is intentional — always-on guardrails train people to ignore them.rm on a single test file is not dangerous. rm -rf / is. The script is calibrated for genuinely destructive patterns.© garagon, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files in guard of garagon/nanostack.
Open the folder on GitHubat commit 0372aed
Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Guard this skillgaragon/nanostack | 207 | — | ~2k | Automated safety check: Notes | Apache-2.0 | |
| Agent Lightningmicrosoft/agent-lightning | 19k | — | ~1.7k | Automated safety check: Pass | MIT | |
| Caveman Gateway SetupJuliusBrussee/caveman | 110k | 1 repos | ~2.6k | Automated safety check: Warn | Apache-2.0 | |
| SageMaker Production Defaultshuggingface/skills | 11k | 1 repos | ~6.9k | Automated safety check: Pass | Apache-2.0 | |
| Megatron-LM Base Image BumpNVIDIA/Megatron-LM | 18k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Opik Local Dev Environmentcomet-ml/opik | 22k | — | ~734 | Automated safety check: Pass | Apache-2.0 |
microsoft/agent-lightning
Provides the action space, tradeoffs, and evaluation context for improving an editable AI agent against a benchmark while preserving its deployment contract.
JuliusBrussee/caveman
Routes every LLM call in a repository through the Caveman Cloud gateway in record mode, so requests and costs are measured without changing behavior.
huggingface/skills
Deploys SageMaker endpoints with autoscaling, CloudWatch alarms and tags on by default, using scripts for real-time, scale-to-zero and async setups.
NVIDIA/Megatron-LM
Moves Megatron-LM CI to a newer NVIDIA PyTorch base image, updating both the GitHub and GitLab pins together and handling the CI follow-up.
comet-ml/opik
Starts, rebuilds, and troubleshoots the Opik local dev stack, including an optional Comet Platform integration mode for the Opik team.
vivekchand/clawmetry
Give the human an off switch and a cost meter for the coding agents on this machine, using ClawMetry.
garagon/nanostack
A skill your agent uses when starting non-trivial work (touching 3+ files, new features, refactors, bug investigations).
garagon/nanostack
First-time setup and guided sprint. An agent skill from garagon/nanostack.
garagon/nanostack
Use before shipping to production. An agent skill from garagon/nanostack.
garagon/nanostack
A skill your agent uses when code is ready to ship — creates PRs, merges, deploys, and verifies.
garagon/nanostack
Document what you learned during this sprint. An agent skill from garagon/nanostack.
garagon/nanostack
Orchestrate parallel agent sessions through a sprint. An agent skill from garagon/nanostack.
Categories
A skill your agent uses when working near production, sensitive systems, or destructive operations. Guard is an agent skill from garagon/nanostack. Use when working near production, sensitive systems, or destructive operations.
Guard fits situations like: working near production; sensitive systems; destructive operations.
Run `npx skills add garagon/nanostack --skill guard -a claude-code`. Or copy the skill folder (guard in garagon/nanostack) into .claude/skills/guard in your project. Claude Code loads it when a task matches its description.
Run `npx skills add garagon/nanostack --skill guard -a codex`. Or copy the skill folder (guard in garagon/nanostack) into .agents/skills/guard in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add garagon/nanostack --skill guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/guard, .gemini/skills/guard, .github/skills/guard and .opencode/skills/guard in your project.
Going by SKILL.md and its folder, Guard needs a shell for the scripts in its folder and the command-line tools its instructions call (git, docker, kubectl, python, node and sh). Our summary lists: Python 3; A Bash shell; Docker.
SKILL.md contains no URLs. Its commands use git and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Guard is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Guard: Agent Lightning (microsoft/agent-lightning, 19k stars), Caveman Gateway Setup (JuliusBrussee/caveman, 110k stars), SageMaker Production Defaults (huggingface/skills, 11k stars) and Megatron-LM Base Image Bump (NVIDIA/Megatron-LM, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
garagon (a GitHub user) maintains it in garagon/nanostack, which has 207 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 10, 2026.
Source: garagon/nanostack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.