Fla Ascend Performance
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
A skill your agent uses when the user asks about available workflow skills, wants an overview of the engineering workflow, or references "nanostack".
$ npx skills add garagon/nanostack --skill nanostack -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install garagon/nanostack nanostack --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nanostack" agent skill from https://github.com/garagon/nanostack/tree/main into .claude/skills/nanostack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nanostack", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add garagon/nanostack --skill nanostack -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install garagon/nanostack nanostack --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nanostack" agent skill from https://github.com/garagon/nanostack/tree/main into .agents/skills/nanostack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nanostack", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add garagon/nanostack --skill nanostack -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install garagon/nanostack nanostack --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nanostack" agent skill from https://github.com/garagon/nanostack/tree/main into .cursor/skills/nanostack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nanostack", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add garagon/nanostack --skill nanostack -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install garagon/nanostack nanostack --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nanostack" agent skill from https://github.com/garagon/nanostack/tree/main into .gemini/skills/nanostack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nanostack", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install garagon/nanostack nanostackInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add garagon/nanostack --skill nanostack -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nanostack" agent skill from https://github.com/garagon/nanostack/tree/main into .github/skills/nanostack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nanostack", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add garagon/nanostack --skill nanostack -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install garagon/nanostack nanostack --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nanostack" agent skill from https://github.com/garagon/nanostack/tree/main into .opencode/skills/nanostack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nanostack", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nanostackA skill your agent uses when the user asks about available workflow skills, wants an overview of the engineering workflow, or references "nanostack".
Nanostack is an agent skill from garagon/nanostack. Use when the user asks about available workflow skills, wants an overview of the engineering workflow, or references "nanostack". Also triggers on /nanostack.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 233 other files (for example `.claude-plugin/plugin.json`, `.cursor-plugin/plugin.json` and `.github/FUNDING.yml`).
It sits in Security. The repository describes itself as: A workflow harness that helps AI coding agents plan, review, test, and ship safer code. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 0372aed. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nanostack loads about 2k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 912 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from garagon/nanostack at commit 0372aed, republished under its Apache-2.0 licence (© garagon). 912 words, ~2,000 tokens.
.claude/skills/nanostack/SKILL.md (or your agent's skills folder). This skill also uses 228 other files; get the full folder from GitHub.You have access to a set of composable engineering workflow skills. Each skill is a folder with supporting files — read them as needed for context.
| Skill | When to use | Modes | Key files |
|---|---|---|---|
/think | Before you build. Refines a rough idea through questions, explores alternatives, walks the design in sections. | — | think/references/forcing-questions.md, think/references/cognitive-patterns.md |
/nano | Before starting any non-trivial work. Produces a scoped, actionable plan. | — | plan/templates/plan-template.md |
/review | After code is written. Two-pass review + scope drift detection + conflict resolution. | --quick --standard --thorough | review/checklist.md, reference/conflict-precedents.md |
/qa | To verify code works. Browser-based testing with Playwright, plus root-cause debugging. | --quick --standard --thorough | qa/bin/screenshot.sh |
/security | Before shipping. OWASP Top 10 + STRIDE + variant analysis + conflict detection. | --quick --standard --thorough | security/references/owasp-checklist.md, security/templates/security-report.md |
/ship | To create PRs, merge, deploy, and verify. Generates sprint journal on success. | — | ship/templates/pr-template.md |
/guard | When working near production, destructive operations, or sensitive systems. | — | guard/bin/check-dangerous.sh |
/feature | Add a feature to an existing project. Skips /think, goes straight to plan → build → review → security → qa → ship. | — | feature/SKILL.md |
/conductor | Orchestrate parallel agent sessions through a sprint. Coordinate task claiming and artifact handoff. | start claim complete status | conductor/bin/sprint.sh |
/nano-run | First-time setup. Configures stack, permissions, and preferences conversationally. Guides first sprint. | — | start/SKILL.md |
/nano-help | Quick reference for all nanostack commands and how to use them. | — | help/SKILL.md |
The default workflow is: /think → /nano → build → /review → /security → /qa → /ship
With /conductor, review + security + qa run in parallel — they all depend on build, not on each other:
think → plan → build ─┬─ review ─┐
├─ qa ├─ ship
└─ security ─┘Activate /guard at any point when operating near production or sensitive systems.
Read ZEN.md for the full set of principles. When in doubt about a decision during any skill, consult it. The short version:
Skills /review, /security, and /qa support intensity modes:
| Mode | Flag | When | Confidence |
|---|---|---|---|
| Quick | --quick | Trivial changes (typos, config, docs) | 9/10 — only the obvious |
| Standard | (default) | Normal changes | 7/10 — anything reasonable |
| Thorough | --thorough | Critical changes (auth, payments, infra) | 3/10 — flag everything suspicious |
Skills auto-suggest a mode based on the diff, but the user always decides.
Saving artifacts is not optional. Every skill must save its artifact after completing.
Skills automatically save their output to .nanostack/ after every run:
.nanostack/<phase>/<timestamp>.jsonThis enables:
/review compares planned vs actual files/review and /security cross-reference each other's findings/ship generates a journal entry from all phase artifactsAuto-saving is on by default. The user can disable it by setting auto_save: false in .nanostack/config.json.
Artifacts are validated before saving: save-artifact.sh rejects invalid JSON, missing required fields (phase, summary), and phase mismatches.
To discard artifacts from a bad session: bin/discard-sprint.sh (removes artifacts and journal entry for the current project and date).
When skills produce contradictory guidance (e.g., /review says "more error detail" but /security says "minimize error exposure"), the conflict resolution framework applies:
Read reference/conflict-precedents.md for known conflict patterns and pre-defined resolutions.
On first use in a project, run bin/init-config.sh --interactive to create .nanostack/config.json. This stores:
If config exists, read it at the start of any skill to adapt behavior:
bin/init-config.sh # outputs current config or {} if noneSkills use config for:
/review, /qa, /security: read preferences.default_intensity instead of always defaulting to standard/security: read preferences.conflict_precedence to determine who wins in cross-skill conflicts/security: read detected to skip irrelevant checks (don't scan for Python vulns in a Go project)Per-skill configs (security/config.json, guard/config.json) store skill-specific settings and are read by that skill only.
~/.claude/skills/nanostack/bin/capture-failure.sh <skill> "<what went wrong>" "<what was tried>" "<what fixed it>"Suggest skills when context matches — don't wait for the user to remember:
| Trigger | Suggest |
|---|---|
| User says "what should I build" / unclear on direction | /think |
| Task touches 3+ files or user says "how should I approach this" | /nano |
| User says "done", "finished", "ready for review" | /review |
| User says "does this work", "test this", bug report | /qa |
| Pre-ship, user says "ready to deploy", or diff touches auth/env/infra | /security |
| User says "create PR", "merge", "ship it" | /ship |
| Destructive commands, production access, or sensitive operations detected | /guard |
/think for new products or when the "what" is unclear/nano before building anything that touches more than 3 files/review on your own code — the adversarial pass catches what you missed/security is not optional before shipping to production/guard is on-demand — activate it, don't leave it always on/qa can invoke /security checks, /ship can invoke /review© garagon, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 228 other files in the repository root of garagon/nanostack.
Open the folder on GitHubat commit 0372aed
Nanostack next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nanostack this skillgaragon/nanostack | 207 | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Fla Ascend Performancefla-org/flash-linear-attention | 5.8k | — | ~6.3k | Automated safety check: Pass | MIT | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 481 | 1 repos | ~3.3k | Automated safety check: Pass | None | |
| Security Alert Triageelastic/agent-skills | 592 | 1 repos | ~3.5k | Automated safety check: Notes | Apache-2.0 |
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
SummerSec/ShiroAttack2
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…
garagon/nanostack
A skill your agent uses when starting non-trivial work (touching 3+ files, new features, refactors, bug investigations).
garagon/nanostack
First-time setup and guided sprint. An agent skill from garagon/nanostack.
garagon/nanostack
Use before shipping to production. An agent skill from garagon/nanostack.
garagon/nanostack
A skill your agent uses when code is ready to ship — creates PRs, merges, deploys, and verifies.
garagon/nanostack
Document what you learned during this sprint. An agent skill from garagon/nanostack.
garagon/nanostack
Orchestrate parallel agent sessions through a sprint. An agent skill from garagon/nanostack.
Categories
A skill your agent uses when the user asks about available workflow skills, wants an overview of the engineering workflow, or references "nanostack". Nanostack is an agent skill from garagon/nanostack. Use when the user asks about available workflow skills, wants an overview of the engineering workflow, or references "nanostack".
Nanostack fits situations like: the user asks about available workflow skills; wants an overview of the engineering workflow; references nanostack.
Run `npx skills add garagon/nanostack --skill nanostack -a claude-code`. Or copy the skill folder (the garagon/nanostack repository) into .claude/skills/nanostack in your project. Claude Code loads it when a task matches its description.
Run `npx skills add garagon/nanostack --skill nanostack -a codex`. Or copy the skill folder (the garagon/nanostack repository) into .agents/skills/nanostack in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add garagon/nanostack --skill nanostack -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nanostack, .gemini/skills/nanostack, .github/skills/nanostack and .opencode/skills/nanostack in your project.
SKILL.md names no scripts, command-line tools or credentials: Nanostack is instructions for the agent only. Our summary lists: Python 3; Docker.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Nanostack is published under the Apache-2.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Nanostack: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
garagon (a GitHub user) maintains it in garagon/nanostack, which has 207 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 10, 2026.
Source: garagon/nanostack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.