Agent skill

Nanostack

by garagon in garagon/nanostack

A skill your agent uses when the user asks about available workflow skills, wants an overview of the engineering workflow, or references "nanostack".

Apache-2.0Auto-check passedSecurity

Install Nanostack

skills CLI
$ npx skills add garagon/nanostack --skill nanostack -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install garagon/nanostack nanostack --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nanostack
GitHub stars
207
Token cost
~2k tokens
SKILL.md length
912 words
Files
229
Skills in repo
14
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user asks about available workflow skills, wants an overview of the engineering workflow, or references "nanostack".

  • Works in 3 steps: Security has default precedence — unless… → Context determines final precedence —… → Conflicts are documented, not silenced —…
  • The user asks about available workflow skills
  • SKILL.md covers Available Skills, Workflow Order, Zen and Intensity Modes, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Nanostack is an agent skill from garagon/nanostack. Use when the user asks about available workflow skills, wants an overview of the engineering workflow, or references "nanostack". Also triggers on /nanostack.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 233 other files (for example `.claude-plugin/plugin.json`, `.cursor-plugin/plugin.json` and `.github/FUNDING.yml`).

It sits in Security. The repository describes itself as: A workflow harness that helps AI coding agents plan, review, test, and ship safer code. The licence is Apache-2.0.

When your agent uses it

  • The user asks about available workflow skills
  • Wants an overview of the engineering workflow
  • References nanostack

Example prompts

  • “nanostack”
  • “/nanostack”

Requirements

  • Python 3
  • Docker

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Security has default precedence — unless the risk is theoretical or internal-only
  2. Context determines final precedence — public-facing app vs internal tool vs startup vs compliance
  3. Conflicts are documented, not silenced — every resolution is recorded in the skill artifact

What it can do on your machine

Read from SKILL.md and the folder at commit 0372aed. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nanostack loads about 2k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 912 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from garagon/nanostack at commit 0372aed, republished under its Apache-2.0 licence (© garagon). 912 words, ~2,000 tokens.

Download SKILL.mdSave it as .claude/skills/nanostack/SKILL.md (or your agent's skills folder). This skill also uses 228 other files; get the full folder from GitHub.
name
nanostack
description
Use when the user asks about available workflow skills, wants an overview of the engineering workflow, or references "nanostack". Also triggers on /nanostack.

Nanostack — Engineering Workflow Skills

You have access to a set of composable engineering workflow skills. Each skill is a folder with supporting files — read them as needed for context.

Available Skills

SkillWhen to useModesKey files
/thinkBefore you build. Refines a rough idea through questions, explores alternatives, walks the design in sections.—think/references/forcing-questions.md, think/references/cognitive-patterns.md
/nanoBefore starting any non-trivial work. Produces a scoped, actionable plan.—plan/templates/plan-template.md
/reviewAfter code is written. Two-pass review + scope drift detection + conflict resolution.--quick --standard --thoroughreview/checklist.md, reference/conflict-precedents.md
/qaTo verify code works. Browser-based testing with Playwright, plus root-cause debugging.--quick --standard --thoroughqa/bin/screenshot.sh
/securityBefore shipping. OWASP Top 10 + STRIDE + variant analysis + conflict detection.--quick --standard --thoroughsecurity/references/owasp-checklist.md, security/templates/security-report.md
/shipTo create PRs, merge, deploy, and verify. Generates sprint journal on success.—ship/templates/pr-template.md
/guardWhen working near production, destructive operations, or sensitive systems.—guard/bin/check-dangerous.sh
/featureAdd a feature to an existing project. Skips /think, goes straight to plan → build → review → security → qa → ship.—feature/SKILL.md
/conductorOrchestrate parallel agent sessions through a sprint. Coordinate task claiming and artifact handoff.start claim complete statusconductor/bin/sprint.sh
/nano-runFirst-time setup. Configures stack, permissions, and preferences conversationally. Guides first sprint.—start/SKILL.md
/nano-helpQuick reference for all nanostack commands and how to use them.—help/SKILL.md

Workflow Order

The default workflow is: /think → /nano → build → /review → /security → /qa → /ship

With /conductor, review + security + qa run in parallel — they all depend on build, not on each other:

think → plan → build ─┬─ review  ─┐
                      ├─ qa       ├─ ship
                      └─ security ─┘

Activate /guard at any point when operating near production or sensitive systems.

Zen

Read ZEN.md for the full set of principles. When in doubt about a decision during any skill, consult it. The short version:

  • Question the requirement before writing the code.
  • Delete what shouldn't exist. Don't optimize what's left until you do.
  • Narrow the scope, not the ambition.
  • Fix it or ask. Never ignore it.
  • Security is not a tradeoff. It is a constraint.
  • The output should look better than what was asked for.

Intensity Modes

Skills /review, /security, and /qa support intensity modes:

ModeFlagWhenConfidence
Quick--quickTrivial changes (typos, config, docs)9/10 — only the obvious
Standard(default)Normal changes7/10 — anything reasonable
Thorough--thoroughCritical changes (auth, payments, infra)3/10 — flag everything suspicious

Skills auto-suggest a mode based on the diff, but the user always decides.

Artifact Persistence

Saving artifacts is not optional. Every skill must save its artifact after completing.

Skills automatically save their output to .nanostack/ after every run:

bash
.nanostack/<phase>/<timestamp>.json

This enables:

  • Scope drift detection — /review compares planned vs actual files
  • Conflict detection — /review and /security cross-reference each other's findings
  • Sprint journals — /ship generates a journal entry from all phase artifacts
  • Trend tracking — Are security findings decreasing over time?

Auto-saving is on by default. The user can disable it by setting auto_save: false in .nanostack/config.json.

Artifacts are validated before saving: save-artifact.sh rejects invalid JSON, missing required fields (phase, summary), and phase mismatches.

To discard artifacts from a bad session: bin/discard-sprint.sh (removes artifacts and journal entry for the current project and date).

Conflict Resolution

When skills produce contradictory guidance (e.g., /review says "more error detail" but /security says "minimize error exposure"), the conflict resolution framework applies:

  1. Security has default precedence — unless the risk is theoretical or internal-only
  2. Context determines final precedence — public-facing app vs internal tool vs startup vs compliance
  3. Conflicts are documented, not silenced — every resolution is recorded in the skill artifact

Read reference/conflict-precedents.md for known conflict patterns and pre-defined resolutions.

Show full SKILL.md (356 more words)Show less

Project Config

On first use in a project, run bin/init-config.sh --interactive to create .nanostack/config.json. This stores:

  • Installed agents — auto-detected (claude, codex, cursor, opencode, gemini)
  • Detected stack — node, go, python, docker
  • Preferences — default intensity mode, auto-save, conflict precedence

If config exists, read it at the start of any skill to adapt behavior:

bash
bin/init-config.sh  # outputs current config or {} if none

Skills use config for:

  • /review, /qa, /security: read preferences.default_intensity instead of always defaulting to standard
  • /security: read preferences.conflict_precedence to determine who wins in cross-skill conflicts
  • /security: read detected to skip irrelevant checks (don't scan for Python vulns in a Go project)

Per-skill configs (security/config.json, guard/config.json) store skill-specific settings and are read by that skill only.

Universal Rules

  • Read before acting. Every skill must read the relevant code/diff/config before producing output. Never analyze blind.
  • Boil the lake, not the ocean. When completeness costs minutes more than shortcuts, do the complete thing. When it costs days, don't.
  • Log failures, not just successes. When something goes wrong during a skill (script error, wrong approach, unexpected project behavior), capture it:
    bash
    ~/.claude/skills/nanostack/bin/capture-failure.sh <skill> "<what went wrong>" "<what was tried>" "<what fixed it>"
    Failures compound into knowledge. Next sprint, the same mistake is avoided. This does not require /compound or a successful ship — just log and move on.

Proactive Triggers

Suggest skills when context matches — don't wait for the user to remember:

TriggerSuggest
User says "what should I build" / unclear on direction/think
Task touches 3+ files or user says "how should I approach this"/nano
User says "done", "finished", "ready for review"/review
User says "does this work", "test this", bug report/qa
Pre-ship, user says "ready to deploy", or diff touches auth/env/infra/security
User says "create PR", "merge", "ship it"/ship
Destructive commands, production access, or sensitive operations detected/guard

Usage Rules

  • Start with /think for new products or when the "what" is unclear
  • Run /nano before building anything that touches more than 3 files
  • Run /review on your own code — the adversarial pass catches what you missed
  • /security is not optional before shipping to production
  • /guard is on-demand — activate it, don't leave it always on
  • Skills compose: /qa can invoke /security checks, /ship can invoke /review

© garagon, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 228 other files in the repository root of garagon/nanostack.

  • SKILL.md
  • .claude-plugin/plugin.json
  • .cursor-plugin/plugin.json
  • .github/CODEOWNERS
  • .github/FUNDING.yml
  • .github/ISSUE_TEMPLATE/bug_report.yml
  • .github/ISSUE_TEMPLATE/config.yml
  • .github/ISSUE_TEMPLATE/feature_request.yml
  • .github/pull_request_template.md
  • .github/workflows/e2e.yml
  • .github/workflows/lint.yml
  • .gitignore
  • AGENTS.md
  • CODE_OF_CONDUCT.md
  • CONTRIBUTING.md
  • EXTENDING.md
  • … and 213 more

Open the folder on GitHubat commit 0372aed

Compare with similar skills

Nanostack next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nanostack compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nanostack this skillgaragon/nanostack207—~2kAutomated safety check: PassApache-2.0
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from garagon/nanostack

All 14 skills in this repo
  • Nano

    garagon/nanostack

    A skill your agent uses when starting non-trivial work (touching 3+ files, new features, refactors, bug investigations).

    207 GitHub stars~3.3k tokensUpdated 29 days ago
    Auto-check passed
  • Nano Run

    garagon/nanostack

    First-time setup and guided sprint. An agent skill from garagon/nanostack.

    207 GitHub stars~3k tokensUpdated 29 days ago
    Auto-check passed
  • Security

    garagon/nanostack

    Use before shipping to production. An agent skill from garagon/nanostack.

    207 GitHub stars~3.7k tokensUpdated 29 days ago
    Auto-check: notes
  • Ship

    garagon/nanostack

    A skill your agent uses when code is ready to ship — creates PRs, merges, deploys, and verifies.

    207 GitHub stars~4.2k tokensUpdated 29 days ago
    Auto-check passed
  • Compound

    garagon/nanostack

    Document what you learned during this sprint. An agent skill from garagon/nanostack.

    207 GitHub stars~2.2k tokensUpdated 29 days ago
    Auto-check passed
  • Conductor

    garagon/nanostack

    Orchestrate parallel agent sessions through a sprint. An agent skill from garagon/nanostack.

    207 GitHub stars~2.6k tokensUpdated 29 days ago
    Auto-check passed

Categories

Questions about Nanostack

What does Nanostack do?

A skill your agent uses when the user asks about available workflow skills, wants an overview of the engineering workflow, or references "nanostack". Nanostack is an agent skill from garagon/nanostack. Use when the user asks about available workflow skills, wants an overview of the engineering workflow, or references "nanostack".

When should I use Nanostack?

Nanostack fits situations like: the user asks about available workflow skills; wants an overview of the engineering workflow; references nanostack.

How do I install Nanostack in Claude Code?

Run `npx skills add garagon/nanostack --skill nanostack -a claude-code`. Or copy the skill folder (the garagon/nanostack repository) into .claude/skills/nanostack in your project. Claude Code loads it when a task matches its description.

How do I install Nanostack in Codex?

Run `npx skills add garagon/nanostack --skill nanostack -a codex`. Or copy the skill folder (the garagon/nanostack repository) into .agents/skills/nanostack in your project. Codex loads it when a task matches its description.

Can I use Nanostack in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add garagon/nanostack --skill nanostack -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nanostack, .gemini/skills/nanostack, .github/skills/nanostack and .opencode/skills/nanostack in your project.

What does Nanostack need to run?

SKILL.md names no scripts, command-line tools or credentials: Nanostack is instructions for the agent only. Our summary lists: Python 3; Docker.

Does Nanostack access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nanostack safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nanostack use?

Nanostack is published under the Apache-2.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nanostack use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nanostack?

Skills that share tags, products or a category with Nanostack: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nanostack?

garagon (a GitHub user) maintains it in garagon/nanostack, which has 207 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 10, 2026.

Source: garagon/nanostack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.