Agent skill

Nano Run

by garagon in garagon/nanostack

First-time setup and guided sprint. An agent skill from garagon/nanostack.

Apache-2.0Auto-check passedSecurity

Install Nano Run

skills CLI
$ npx skills add garagon/nanostack --skill nano-run -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install garagon/nanostack nano-run --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/garagon/nanostack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/start .claude/skills/nano-run && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nano-run
GitHub stars
207
Token cost
~3k tokens
SKILL.md length
1,218 words
Files
2 (incl. references)
Skills in repo
14
Repo updated
First seen
Licence
Apache-2.0

At a glance

First-time setup and guided sprint. An agent skill from garagon/nanostack.

  • Works in 4 steps: Detect state (read-only) → Configure → Write the setup record → …
  • Security work in your project
  • SKILL.md covers Telemetry preamble, Session state (read before…, Capability honesty (read… and Step 1: Detect state (read-only), plus 7 more sections
  • Calls jq and git

What it does

Nano Run is an agent skill from garagon/nanostack. First-time setup and guided sprint. Configures stack, permissions, and work preferences conversationally. Run once after installing nanostack. Triggers on /nano-run.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/onboarding-contract.md`).

It sits in Security. The repository describes itself as: A workflow harness that helps AI coding agents plan, review, test, and ship safer code. The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/nano-run”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Detect state (read-only)
  2. Configure
  3. Write the setup record
  4. One next action (end with this, not a menu)

What it can do on your machine

Read from SKILL.md and the folder at commit 0372aed. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nano Run loads about 3k tokens when it runs, and up to ~5k if it reads all its reference files. Until then it costs about 44 tokens; SKILL.md has 1,218 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from garagon/nanostack at commit 0372aed, republished under its Apache-2.0 licence (© garagon). 1,218 words, ~2,977 tokens.

Download SKILL.mdSave it as .claude/skills/nano-run/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
nano-run
description
First-time setup and guided sprint. Configures stack, permissions, and work preferences conversationally. Run once after installing nanostack. Triggers on /nano-run.
concurrency
exclusive
summary
Onboarding. Detects host, configures project, writes a setup record, and ends with one next action.
estimated_tokens
350

/nano-run — Get Started

You are a friendly onboarding guide. Your job is to configure nanostack for this user and help them run their first sprint. No jargon, no docs, just conversation.

The full per-skill contract lives at start/references/onboarding-contract.md. The setup-artifact JSON shape lives at reference/artifact-schema.md. Keep this skill aligned with both.

Telemetry preamble

Defensive telemetry init. No-op if telemetry is disabled via NANOSTACK_NO_TELEMETRY=1, ~/.nanostack/.telemetry-disabled, or if the helpers are removed.

bash
_P="$HOME/.claude/skills/nanostack/bin/lib/skill-preamble.sh"
[ -f "$_P" ] && . "$_P" nano-run
unset _P

Session state (read before anything else)

Read the v2 session fields per reference/session-state-contract.md. Onboarding is the first product surface; when uncertain, default to guided, not professional.

bash
SESSION=$NANOSTACK_STORE/session.json
[ -f "$SESSION" ] || SESSION="$HOME/.nanostack/session.json"

PROFILE=$(jq -r '.profile // (if (.capabilities // null) == null then "guided" else "professional" end)' "$SESSION" 2>/dev/null || echo "guided")
RUN_MODE=$(jq -r '.run_mode // "normal"' "$SESSION" 2>/dev/null || echo "normal")
AUTOPILOT=$(jq -r '.autopilot // false' "$SESSION" 2>/dev/null || echo "false")
PLAN_APPROVAL=$(jq -r '.plan_approval // (if .autopilot then "auto" else "manual" end)' "$SESSION" 2>/dev/null || echo "manual")
HOST=$(jq -r '.host // "unknown"' "$SESSION" 2>/dev/null || echo "unknown")

if [ "$RUN_MODE" = "report_only" ]; then
  REPORT_ONLY=1
else
  REPORT_ONLY=0
fi

How /nano-run uses each field:

FieldEffect
PROFILE=guidedPlain language. First screen avoids artifact, PR, CI, branch, diff, hook, phase, security audit, QA, scope drift. Output uses the four-block skeleton from reference/plain-language-contract.md.
PROFILE=professionalNames exact files, capability levels, commands, repair actions.
RUN_MODE=report_onlyDetect-and-report only. Do NOT run mutating setup scripts; do NOT write .nanostack/config.json / .nanostack/stack.json / .claude/settings.json; do NOT write the setup artifact.
AUTOPILOT=trueContinue to the recommended first run without pausing for approval, only after a complete brief gate (delegated to /think's Phase 6.6).
HOSTDrives capability honesty. Read adapters/<HOST>.json for the exact enforced / reported / instructions_only / unsupported levels. Never hardcode host promises.

If HOST=unknown, all capability fields read as unknown. Tell the user: "I can still guide the workflow, but I could not verify hard safety checks for this agent." Recommend /nano-doctor for a deeper check, and stay in Guided language unless the user explicitly chose Professional.

Capability honesty (read adapters, do not invent)

/nano-run reads host capabilities from disk. Do not synthesize promises from the host name.

bash
ADAPTER="$HOME/.claude/skills/nanostack/adapters/${HOST}.json"
if [ -f "$ADAPTER" ]; then
  BASH_GUARD=$(jq -r '.bash_guard // "unknown"' "$ADAPTER")
  WRITE_GUARD=$(jq -r '.write_guard // "unknown"' "$ADAPTER")
  PHASE_GATE=$(jq -r '.phase_gate // "unknown"' "$ADAPTER")
else
  BASH_GUARD=unknown
  WRITE_GUARD=unknown
  PHASE_GATE=unknown
fi

The contract document at start/references/onboarding-contract.md lists the four phrasings forbidden in any user-facing onboarding output, regardless of profile or host. The README's "What is enforced depends on your agent" section is the public statement of this rule; this skill must not contradict it.

Step 1: Detect state (read-only)

Inspect what is already on disk. This step never mutates and runs the same way under report-only.

  • Project root: git rev-parse --show-toplevel 2>/dev/null or current working directory.
  • Stack hints: package.json, go.mod, pyproject.toml, requirements.txt, Dockerfile.
  • Existing nanostack state: .nanostack/config.json, .nanostack/stack.json.
  • Existing host state: .claude/settings.json (presence of hooks, presence of broad permissions like Bash(rm:*) / Write(*) / Edit(*)).

Run the canonical config probe:

bash
~/.claude/skills/nanostack/bin/init-config.sh

Then probe the host config separately for legacy state. The legacy detector is read-only and emits structured JSON suitable for embedding into the setup artifact's summary.legacy field:

bash
LEGACY=$(~/.claude/skills/nanostack/bin/detect-legacy-setup.sh)
LEGACY_DETECTED=$(echo "$LEGACY" | jq -r '.detected')
MIGRATION_NEEDS_CONFIRMATION=$(echo "$LEGACY" | jq -r '.migration_requires_confirmation')

Decide the path:

DetectionPath
Config exists, hooks present, no broad permissions, .detected=falseConfigured. Ask what they want to do (Step 4).
.claude/settings.json is missing hooks or has Bash(rm:*) / Write(*) / Edit(*), .detected=trueLegacy install. See "Repair flow" below.
No configFirst-time setup. Continue to Step 2.

Repair flow (legacy detection)

When bin/detect-legacy-setup.sh reports .detected = true, do not silently mutate. The detector also tells you which hooks are missing and which broad permissions are present:

bash
echo "$LEGACY" | jq '{missing_hooks, broad_permissions, repair_available, migration_requires_confirmation}'

Show the user what you found in profile-appropriate language and ask once. The Guided "needs repair" output block in start/references/onboarding-contract.md is the canonical wording.

/nano-run may recommend:

bash
bin/init-project.sh --repair

Repair is additive: it adds missing hooks and creates a timestamped .bak of the existing settings, but does not remove any broad permission entries.

When migration_requires_confirmation is true, /nano-run must NOT silently run:

bash
bin/init-project.sh --migrate-permissions

That command removes Bash(rm:*) and similar broad rules. Only run it when the user explicitly approves the migration. The detector's JSON is embedded verbatim into the setup artifact's summary.legacy field so the choice (and the broad permissions still present) is auditable.

If the legacy state is unfixable from inside /nano-run (for example the user declines repair), write the setup artifact with summary.status = "needs_repair". The skill must not return "ready" while the host config is in a known-bad state.

Step 2: Configure

Skip this step entirely if REPORT_ONLY=1. Run only the read-only detection above and jump to the report-only output below.

Ask the user one question at a time in plain language. One decision per prompt; never dump all of them at once.

Question 1: "What type of projects do you build?"

  1. Web apps
  2. APIs and backend services
  3. CLI tools and scripts
  4. Mobile
  5. Not sure yet

Question 2: If a stack file was detected in Step 1, show what you found and ask if it is correct. If nothing was detected, set defaults based on Question 1.

Run the configuration:

bash
~/.claude/skills/nanostack/bin/init-stack.sh
~/.claude/skills/nanostack/bin/init-project.sh

Question 3: "How do you prefer to work?"

  1. Automatic. I describe what I want and the agent does everything.
  2. Step by step. I review each step before continuing.
  3. Let's try something simple first.

Save the preference in .nanostack/config.json under preferences.workflow_mode (autopilot or manual).

Show full SKILL.md (456 more words)Show less

Step 3: Write the setup record

After mutation succeeded (or after detect-only in report mode), call bin/save-setup-artifact.sh with the structured JSON payload. The writer validates required fields, enum values, and the report-only honesty invariant before anything reaches disk:

bash
~/.claude/skills/nanostack/bin/save-setup-artifact.sh "$SETUP_JSON"

It writes .nanostack/setup/<timestamp>.json and copies it to .nanostack/setup/latest.json (no symlinks, for portability). Schema is in reference/artifact-schema.md.

Required fields the writer rejects without:

  • summary.status (ready / needs_repair / report_only / partial / blocked)
  • summary.profile, .host, .run_mode, .project_mode
  • summary.capabilities (all three: bash_guard, write_guard, phase_gate)
  • summary.configuration (all four file states; use skipped_report_only under report mode)
  • summary.recommended_first_run.kind and .command
  • context_checkpoint.summary

The writer also enforces enums (bash_guard must be one of enforced / reported / instructions_only / unsupported / unknown) and the report-only honesty invariant (a report_only payload cannot claim configuration.<file> = "created" or "updated"; it must say skipped_report_only).

If a mutation step failed midway, write summary.status = "partial". Do not pretend setup completed.

Step 4: One next action (end with this, not a menu)

Pick exactly one next action based on state and end the conversation there.

StateNext action
PROFILE=guided and no project stack detectedTry examples/starter-todo first. Sandbox is the default for non-technical users so they do not risk a real product on the first run.
PROFILE=guided and project exists"Tell me the smallest change you want and start with /think."
PROFILE=professional and project exists/think "<change>" or /feature "<change>".
Setup needs repair"Let me update the safety checks and keep a backup."
RUN_MODE=report_only"Re-run /nano-run in normal mode when you want me to apply this."

When the user describes a change, hand off:

  • New project or big scope → use Skill tool: skill="think" with args "--autopilot".
  • Feature on existing project → use Skill tool: skill="feature".
  • Otherwise → use Skill tool: skill="think".

Output contracts (copy these shapes; do not invent your own)

The five canonical outputs live in start/references/onboarding-contract.md. Use them verbatim except for the variable parts (host name, file paths, recommended command). Each Guided output uses the four-block skeleton: Result, How to try, What was checked, What remains.

When PROFILE=guided, the Spanish four-block skeleton (Resultado, Como verlo, Que revise, Pendiente) applies on local mode and Spanish-speaking users.

Telemetry finalize

Before handing off to /think or returning control:

bash
_F="$HOME/.claude/skills/nanostack/bin/lib/skill-finalize.sh"
[ -f "$_F" ] && . "$_F" nano-run success
unset _F

Pass abort, error, or report_only instead of success if onboarding did not complete a normal run.

Rules

  • One question at a time. Never dump all questions at once.
  • Plain language. Never expose internal terms (SKILL.md, artifact, frontmatter, hook, phase) to a Guided user.
  • If the user seems confused, simplify further.
  • If the user already knows what they want ("just add dark mode"), skip to the sprint.
  • Auto-detect everything you can. Only ask what you cannot detect.
  • Read the host adapter. Do not invent capability claims.
  • In report_only, no mutation. No exception.
  • Legacy repair is explicit. No silent --migrate-permissions.
  • End with one next action. No menus.

© garagon, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in start of garagon/nanostack.

  • SKILL.md
  • references/onboarding-contract.md

Open the folder on GitHubat commit 0372aed

Compare with similar skills

Nano Run next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nano Run compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nano Run this skillgaragon/nanostack207—~3kAutomated safety check: PassApache-2.0
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed

More from garagon/nanostack

All 14 skills in this repo
  • Nano

    garagon/nanostack

    A skill your agent uses when starting non-trivial work (touching 3+ files, new features, refactors, bug investigations).

    207 GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Security

    garagon/nanostack

    Use before shipping to production. An agent skill from garagon/nanostack.

    207 GitHub stars~3.7k tokensUpdated 1 mo ago
    Auto-check: notes
  • Ship

    garagon/nanostack

    A skill your agent uses when code is ready to ship — creates PRs, merges, deploys, and verifies.

    207 GitHub stars~4.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Compound

    garagon/nanostack

    Document what you learned during this sprint. An agent skill from garagon/nanostack.

    207 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Conductor

    garagon/nanostack

    Orchestrate parallel agent sessions through a sprint. An agent skill from garagon/nanostack.

    207 GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Feature

    garagon/nanostack

    Add a feature to an existing project with a full sprint. An agent skill from garagon/nanostack.

    207 GitHub stars~1.4k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Nano Run

What does Nano Run do?

First-time setup and guided sprint. An agent skill from garagon/nanostack. Nano Run is an agent skill from garagon/nanostack. First-time setup and guided sprint.

When should I use Nano Run?

Nano Run fits situations like: security work in your project.

How do I install Nano Run in Claude Code?

Run `npx skills add garagon/nanostack --skill nano-run -a claude-code`. Or copy the skill folder (start in garagon/nanostack) into .claude/skills/nano-run in your project. Claude Code loads it when a task matches its description.

How do I install Nano Run in Codex?

Run `npx skills add garagon/nanostack --skill nano-run -a codex`. Or copy the skill folder (start in garagon/nanostack) into .agents/skills/nano-run in your project. Codex loads it when a task matches its description.

Can I use Nano Run in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add garagon/nanostack --skill nano-run -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nano-run, .gemini/skills/nano-run, .github/skills/nano-run and .opencode/skills/nano-run in your project.

What does Nano Run need to run?

Going by SKILL.md and its folder, Nano Run needs the command-line tools its instructions call (jq and git).

Does Nano Run access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Nano Run safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nano Run use?

Nano Run is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nano Run use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Nano Run?

Skills that share tags, products or a category with Nano Run: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars), Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars) and Security Alert Triage (elastic/agent-skills, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nano Run?

garagon (a GitHub user) maintains it in garagon/nanostack, which has 207 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 10, 2026.

Source: garagon/nanostack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.