Notion To Blog
wasp-lang/wasp
Transfer a blog post from Notion to the Wasp blog. An agent skill from wasp-lang/wasp.
Pre-publish quality pass for Grab Engineering Blog posts in posts/.md.
$ npx skills add grab/engineering-blog --skill pre-publishing-blog-tone-checker -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install grab/engineering-blog pre-publishing-blog-tone-checker --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/grab/engineering-blog.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pre-publishing-blog-tone-checker .claude/skills/pre-publishing-blog-tone-checker && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pre-publishing-blog-tone-checker" agent skill from https://github.com/grab/engineering-blog/tree/master/skills/pre-publishing-blog-tone-checker into .claude/skills/pre-publishing-blog-tone-checker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pre-publishing-blog-tone-checker", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/grab/engineering-blog/tree/master/skills/pre-publishing-blog-tone-checkerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add grab/engineering-blog --skill pre-publishing-blog-tone-checker -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install grab/engineering-blog pre-publishing-blog-tone-checker --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grab/engineering-blog.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/pre-publishing-blog-tone-checker .agents/skills/pre-publishing-blog-tone-checker && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pre-publishing-blog-tone-checker" agent skill from https://github.com/grab/engineering-blog/tree/master/skills/pre-publishing-blog-tone-checker into .agents/skills/pre-publishing-blog-tone-checker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pre-publishing-blog-tone-checker", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add grab/engineering-blog --skill pre-publishing-blog-tone-checker -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install grab/engineering-blog pre-publishing-blog-tone-checker --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grab/engineering-blog.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/pre-publishing-blog-tone-checker .cursor/skills/pre-publishing-blog-tone-checker && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pre-publishing-blog-tone-checker" agent skill from https://github.com/grab/engineering-blog/tree/master/skills/pre-publishing-blog-tone-checker into .cursor/skills/pre-publishing-blog-tone-checker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pre-publishing-blog-tone-checker", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/grab/engineering-blog.git --path skills/pre-publishing-blog-tone-checker--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add grab/engineering-blog --skill pre-publishing-blog-tone-checker -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install grab/engineering-blog pre-publishing-blog-tone-checker --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grab/engineering-blog.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/pre-publishing-blog-tone-checker .gemini/skills/pre-publishing-blog-tone-checker && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pre-publishing-blog-tone-checker" agent skill from https://github.com/grab/engineering-blog/tree/master/skills/pre-publishing-blog-tone-checker into .gemini/skills/pre-publishing-blog-tone-checker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pre-publishing-blog-tone-checker", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install grab/engineering-blog pre-publishing-blog-tone-checkerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add grab/engineering-blog --skill pre-publishing-blog-tone-checker -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/grab/engineering-blog.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/pre-publishing-blog-tone-checker .github/skills/pre-publishing-blog-tone-checker && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pre-publishing-blog-tone-checker" agent skill from https://github.com/grab/engineering-blog/tree/master/skills/pre-publishing-blog-tone-checker into .github/skills/pre-publishing-blog-tone-checker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pre-publishing-blog-tone-checker", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add grab/engineering-blog --skill pre-publishing-blog-tone-checker -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install grab/engineering-blog pre-publishing-blog-tone-checker --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grab/engineering-blog.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/pre-publishing-blog-tone-checker .opencode/skills/pre-publishing-blog-tone-checker && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pre-publishing-blog-tone-checker" agent skill from https://github.com/grab/engineering-blog/tree/master/skills/pre-publishing-blog-tone-checker into .opencode/skills/pre-publishing-blog-tone-checker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pre-publishing-blog-tone-checker", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pre-publishing-blog-tone-checkerPre-publish quality pass for Grab Engineering Blog posts in posts/.md.
Pre Publishing Blog Tone Checker is an agent skill from grab/engineering-blog. Pre-publish quality pass for Grab Engineering Blog posts in posts/.md. Validates YAML front matter, ensures the canonical Join us footer, applies grammar/tone/spelling fixes via references/grammar-tone-writing-quality.md, then runs a PR/legal pre-flight for metrics, images, confidentiality, and reputational risk via references/pr-legal-pre-flight.md. Use when reviewing or editing a blog post before publish.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/grammar-tone-writing-quality.md`, `references/join-us-boilerplate.md` and `references/pr-legal-pre-flight.md`).
It sits in Writing & Content, covering Blog and article writing, Markdown and Project scaffolding. The repository describes itself as: 📝 We write about our technologies and the problems we handle at scale. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit fd83523. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pre Publishing Blog Tone Checker loads about 3k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 1,218 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from grab/engineering-blog at commit fd83523, republished under its MIT licence (© grab). 1,218 words, ~3,015 tokens.
.claude/skills/pre-publishing-blog-tone-checker/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Use this skill before publishing a Grab Engineering Blog post. It runs four passes on Markdown files in _posts/:
## Join us footer exists; add it if missing (references/join-us-boilerplate.md).references/grammar-tone-writing-quality.md.references/pr-legal-pre-flight.md; suggest fixes (do not apply redactions unless the user asks).Work one file at a time. Prefer small, safe edits. Preserve technical meaning. Summarize findings and ask whether to apply changes unless the user already asked you to edit.
| In scope | Out of scope |
|---|---|
_posts/*.md front matter validation | Broken link checking |
Body prose in _posts/*.md | Readability scores or lint tooling |
| PR/legal risk review of prose and images | Legal sign-off or formal approval |
Adding missing authors to _data/authors.yml | Renaming post files |
Adding the canonical ## Join us footer when missing | Rewriting code blocks, URLs, or quoted text without user approval |
Drafting missing excerpt or tags | Auto-redacting content without user confirmation |
| Suggesting safer wording for flagged metrics/names | Editing the Join us boilerplate text without an explicit PR/legal request |
_posts/*.md changes if they asked for a change-only pass.references/grammar-tone-writing-quality.md and edit the Markdown body (and metadata fields only where validation requires fixes). Do not edit the Join us boilerplate text.references/pr-legal-pre-flight.md and review the same file for images, tables, figures, metrics, internal names, quotes, and reputational risk. Produce suggested fixes using the reference report format. Do not apply PR/legal rewrites automatically unless the user explicitly requests it.Run these checks before any prose edits. Treat front matter as the YAML block between the opening and closing --- at the top of the file.
Every post must include all of these keys:
| Field | Required | Validation rules |
|---|---|---|
layout | Yes | Must be post. |
id | Yes | Must exactly match the filename without .md. Example: file 2026-06-19-palana-part-1-secure-platform-for-ai-agents.md → id: 2026-06-19-palana-part-1-secure-platform-for-ai-agents. |
title | Yes | Non-empty string in sentence case (see references/grammar-tone-writing-quality.md → Headings and titles). Use single quotes if the title contains a colon. |
date | Yes | Non-empty publish datetime, e.g. 2026-06-19 00:00:00. |
authors | Yes | YAML array of author handles, e.g. [kevin.littlejohn]. At least one author. |
categories | Yes | YAML array with at least one category, e.g. [Engineering]. |
tags | Yes | YAML array with at least 3 tags relevant to the post content. |
comments | Yes | Boolean: true or false. |
cover_photo | Yes | Site-root path to the banner image, e.g. /img/palana-part-1/banner-image.png. |
excerpt | Yes | Non-empty summary string. If missing or blank, draft one of 300 characters or fewer that summarizes the post. |
If any required key is missing, report it explicitly:
MISSING METADATA: <filename> is missing required field(s): <field1>, <field2>id vs filename.md from the filename and compare to id character for character.id to match the filename (do not rename the file).authorsauthors must exist as a key in _data/authors.yml.adrian.margin:
name: Adrian Margin
thumbnail: /img/authors/adrian-margin.pngfirstname.lastname).thumbnail file exists on disk (see Image file checks).categories_data/categories.yml (e.g. Engineering, Data Science, Design, Product, Security)._data/categories.yml, flag it and ask before adding.tagscover_photo/img/.img/ directory (see Image file checks).references/pr-legal-pre-flight.md).excerptResolve paths by stripping the leading / and checking under the repository root:
cover_photo: /img/palana-part-1/banner-image.png → img/palana-part-1/banner-image.pngthumbnail: /img/authors/adrian-margin.png → img/authors/adrian-margin.pngIf any referenced cover or author thumbnail file is missing, stop and report:
PLEASE INCLUDE IMAGE FILESList each missing path. Do not invent placeholder images.
---
layout: post
id: 2026-06-19-palana-part-1-secure-platform-for-ai-agents
title: 'Palana (Part 1): Why Grab built a secure platform for autonomous AI agents'
date: 2026-06-19 00:00:00
authors: [kevin.littlejohn]
categories: [Engineering]
tags: [Security, Artificial Intelligence, Kubernetes, DevSecOps, Platform, Engineering]
comments: true
cover_photo: /img/palana-part-1/banner-image.png
excerpt: "AI agents are becoming autonomous workloads with new security risks. Part 1 explains why Grab built Palana, a Kubernetes-native platform for running agents safely with isolation, controlled egress, and auditability."
---Run immediately after metadata validation. See references/join-us-boilerplate.md for the canonical copy.
## Join us heading (exact match).Report when the section was added or replaced:
JOIN US BOILERPLATE: missing — added | present — ok | present — replaced with canonical copyAfter metadata passes (or after reporting metadata gaps the user asked you to fix), edit the post body using references/grammar-tone-writing-quality.md.
title and all Markdown headings per references/grammar-tone-writing-quality.md → Headings and titles.Do not rewrite:
excerpt, wrong id, etc.).id / filename) unless correcting a metadata mismatch.Run after the grammar and tone pass on the same _posts/*.md file.
references/pr-legal-pre-flight.md in full.cover_photo, ![...](), and <img> tags — including alt text, captions, and surrounding prose.After all passes, report:
files checked: <list>
--- pass 1: metadata ---
metadata status: pass | fail
missing or invalid metadata: <list or "none">
image file errors: <list or "none">
authors added to _data/authors.yml: <list or "none">
excerpt drafted or revised: <yes/no>
tags added or revised: <yes/no>
--- pass 2: join us ---
join us boilerplate: missing — added | present — ok | present — replaced with canonical copy
--- pass 3: grammar and tone ---
grammar and mechanics fixes applied: <summary>
tone and style improvements applied: <summary>
UK/US spelling normalization applied: <yes/no and variant>
sentence case fixes (title/headings): <summary or "none">
--- pass 4: PR/legal ---
PR/LEGAL VERDICT: PASS | PASS WITH CHANGES | BLOCK
blockers: <count + details per pr-legal-pre-flight.md format>
recommended edits: <count + details>
clearance questions: <list or "none">
gate checklist: <from pr-legal-pre-flight.md>
--- overall ---
items intentionally left unchanged: <front matter (except metadata fixes), links, code, quoted text, PR/legal redactions pending user approval>
next step: <ask user to apply PR/legal fixes | ready for PR/legal submit | resolve blockers first>If metadata failed, list every missing or invalid field before prose and PR/legal findings.
© grab, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/pre-publishing-blog-tone-checker of grab/engineering-blog.
Open the folder on GitHubat commit fd83523
Pre Publishing Blog Tone Checker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pre Publishing Blog Tone Checker this skillgrab/engineering-blog | 138 | — | ~3k | Automated safety check: Pass | MIT | |
| Notion To Blogwasp-lang/wasp | 19k | — | ~922 | Automated safety check: Pass | MIT | |
| Post Writingbenjamincrozat/blog-v5 | 135 | — | ~2.3k | Automated safety check: Pass | None | |
| Reading Guidechingswy/Skill-Research-Figure | 179 | — | ~4.5k | Automated safety check: Pass | None | |
| Blog AnalyzeAgriciDaniel/claude-blog | 2.3k | 1 repos | ~3.5k | Automated safety check: Pass | MIT | |
| Blog WriteAgriciDaniel/claude-blog | 2.3k | 1 repos | ~5.6k | Automated safety check: Pass | MIT |
wasp-lang/wasp
Transfer a blog post from Notion to the Wasp blog. An agent skill from wasp-lang/wasp.
benjamincrozat/blog-v5
Draft and revise publication-ready Markdown blog posts with reader-first writing, current primary sources, tested examples, reproducible benchmarks for quantitative claims, visually inspected…
chingswy/Skill-Research-Figure
Structured learning navigator for blog posts and articles. An agent skill from chingswy/Skill-Research-Figure.
AgriciDaniel/claude-blog
Audit and score blog posts on a 5-category 100-point scoring system covering content quality, SEO optimization, E-E-A-T signals, technical elements, and AI citation readiness.
AgriciDaniel/claude-blog
Write new blog articles from scratch optimized for Google rankings and AI citations.
digoal/blog
Write Chinese "数据库筑基课" Markdown articles for database architects, DBAs, and application developers.
Categories
Pre-publish quality pass for Grab Engineering Blog posts in posts/.md. Pre Publishing Blog Tone Checker is an agent skill from grab/engineering-blog.md.
Pre Publishing Blog Tone Checker fits situations like: editing a blog post before publish; tasks that involve Blog and article writing; tasks that involve Markdown.
Run `npx skills add grab/engineering-blog --skill pre-publishing-blog-tone-checker -a claude-code`. Or copy the skill folder (skills/pre-publishing-blog-tone-checker in grab/engineering-blog) into .claude/skills/pre-publishing-blog-tone-checker in your project. Claude Code loads it when a task matches its description.
Run `npx skills add grab/engineering-blog --skill pre-publishing-blog-tone-checker -a codex`. Or copy the skill folder (skills/pre-publishing-blog-tone-checker in grab/engineering-blog) into .agents/skills/pre-publishing-blog-tone-checker in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grab/engineering-blog --skill pre-publishing-blog-tone-checker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pre-publishing-blog-tone-checker, .gemini/skills/pre-publishing-blog-tone-checker, .github/skills/pre-publishing-blog-tone-checker and .opencode/skills/pre-publishing-blog-tone-checker in your project.
SKILL.md names no scripts, command-line tools or credentials: Pre Publishing Blog Tone Checker is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Pre Publishing Blog Tone Checker is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Pre Publishing Blog Tone Checker: Notion To Blog (wasp-lang/wasp, 19k stars), Post Writing (benjamincrozat/blog-v5, 135 stars), Reading Guide (chingswy/Skill-Research-Figure, 179 stars) and Blog Analyze (AgriciDaniel/claude-blog, 2.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
grab (a GitHub organization) maintains it in grab/engineering-blog, which has 138 GitHub stars. The repository was last updated on October 8, 2026.
Source: grab/engineering-blog on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.