Mz Release Signoff
MaterializeInc/materialize
Verify a release candidate on the Grafana dashboards and sign off in release.
Help choose, configure, and test local agento11y guard packs for coding-agent tool calls.
$ npx skills add grafana/agento11y --skill setup-local-guards -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install grafana/agento11y setup-local-guards --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/grafana/agento11y.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/agento11y/internal/skills/content/setup-local-guards .claude/skills/setup-local-guards && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "setup-local-guards" agent skill from https://github.com/grafana/agento11y/tree/main/plugins/agento11y/internal/skills/content/setup-local-guards into .claude/skills/setup-local-guards/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "setup-local-guards", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/grafana/agento11y/tree/main/plugins/agento11y/internal/skills/content/setup-local-guardsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add grafana/agento11y --skill setup-local-guards -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install grafana/agento11y setup-local-guards --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/agento11y.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/agento11y/internal/skills/content/setup-local-guards .agents/skills/setup-local-guards && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "setup-local-guards" agent skill from https://github.com/grafana/agento11y/tree/main/plugins/agento11y/internal/skills/content/setup-local-guards into .agents/skills/setup-local-guards/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "setup-local-guards", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add grafana/agento11y --skill setup-local-guards -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install grafana/agento11y setup-local-guards --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/agento11y.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/agento11y/internal/skills/content/setup-local-guards .cursor/skills/setup-local-guards && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "setup-local-guards" agent skill from https://github.com/grafana/agento11y/tree/main/plugins/agento11y/internal/skills/content/setup-local-guards into .cursor/skills/setup-local-guards/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "setup-local-guards", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/grafana/agento11y.git --path plugins/agento11y/internal/skills/content/setup-local-guards--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add grafana/agento11y --skill setup-local-guards -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install grafana/agento11y setup-local-guards --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/agento11y.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/agento11y/internal/skills/content/setup-local-guards .gemini/skills/setup-local-guards && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "setup-local-guards" agent skill from https://github.com/grafana/agento11y/tree/main/plugins/agento11y/internal/skills/content/setup-local-guards into .gemini/skills/setup-local-guards/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "setup-local-guards", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install grafana/agento11y setup-local-guardsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add grafana/agento11y --skill setup-local-guards -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/grafana/agento11y.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/agento11y/internal/skills/content/setup-local-guards .github/skills/setup-local-guards && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "setup-local-guards" agent skill from https://github.com/grafana/agento11y/tree/main/plugins/agento11y/internal/skills/content/setup-local-guards into .github/skills/setup-local-guards/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "setup-local-guards", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add grafana/agento11y --skill setup-local-guards -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install grafana/agento11y setup-local-guards --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/agento11y.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/agento11y/internal/skills/content/setup-local-guards .opencode/skills/setup-local-guards && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "setup-local-guards" agent skill from https://github.com/grafana/agento11y/tree/main/plugins/agento11y/internal/skills/content/setup-local-guards into .opencode/skills/setup-local-guards/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "setup-local-guards", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
setup-local-guardsHelp choose, configure, and test local agento11y guard packs for coding-agent tool calls.
Setup Local Guards is an agent skill from grafana/agento11y, published by the product's own GitHub organization. Help choose, configure, and test local agento11y guard packs for coding-agent tool calls. Use when the user asks to enable safety packs, protect .env files, block dangerous commands, redact tool arguments, create custom local rules, or diagnose local guards. Covers local packs, not Grafana Cloud rule management or application SDK setup.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Monitoring and alerting. It works with Grafana. The repository describes itself as: Actually Useful Agent Observability. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9ab60bc. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Setup Local Guards loads about 2.6k tokens when it runs. Until then it costs about 89 tokens; SKILL.md has 1,396 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
ser asks to enable safety packs, protect .env files,- File safety matches `.env` and `.env.*`, including `.env.example`. It does not protect every secret file.agento11y guards test --json 'cat .env'Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from grafana/agento11y at commit 9ab60bc, republished under its Apache-2.0 licence (© grafana). 1,396 words, ~2,586 tokens.
.claude/skills/setup-local-guards/SKILL.md (or your agent's skills folder).Inspect the installed configuration, explain the relevant packs, ask for approval, then configure and test only the user's choices. For a question about existing behavior, stop after explaining it; do not change settings.
agento11y guards test.config.env; it can contain credentials.Run:
agento11y --version
agento11y guards test --help
agento11y local statusIf the binary or local guard commands are missing, explain what is missing.
Offer agento11y skills show setup-coding-agent for installation or host integration setup.
Do not assume an older binary includes this skill or every pack.
Local mode requires macOS or Linux.
Identify the target coding agent, its installed agento11y integration, and whether its sessions use the local daemon or go directly to Cloud.
Opening the local app does not route a running agent through it.
For Codex, ask the user to open /hooks and trust the agento11y hooks after installation.
Use the running app's Security > Guards to inspect the saved enablement, rules path, pack selections, and compilation errors.
If the app is stopped, ask before running agento11y local open to start it.
Use the displayed rules path rather than assuming ~/.config/agento11y/guards.toml.
Read an existing rules file before proposing edits; do not replace it with a template.
Use agento11y doctor --json if installation or routing needs further diagnosis.
Explain that doctor probes configured endpoints and obtain approval before those requests.
Use the installed app's pack descriptions and view previews to explain available packs. For blocked and allowed examples, refer to the local guard pack guide. The online guide can describe a different binary version; prefer the installed catalog and dry-run results when they differ. Do not require a network lookup to proceed with the installed catalog.
Before recommending Secret redaction, check whether the target host applies argument rewrites. Copilot CLI applies them; Copilot Chat in VS Code and unidentified Copilot surfaces drop them and run the original arguments. Do not present an offline redaction result as tool-argument protection on those surfaces.
Explain the trade-offs relevant to the user's request:
.env and .env.*, including .env.example. It does not protect every secret file.--force-with-lease; it does not block every history rewrite.State that text matching can miss indirect operations and can block harmless mentions. Unknown tools, unsupported hooks, and scripts that perform dangerous operations internally can escape these checks.
Explain any destination change before asking for approval.
Local mode stores full session content locally.
With Cloud forwarding, guard payloads can leave the machine even when generation capture is metadata_only.
Never enable forwarding just to make local guards work.
Ask which packs to enable or disable, then confirm the exact changes. Do not select every pack by default. Before changing packs in a hand-edited file, offer a backup: pack updates remove TOML comments and formatting.
Configure bundled packs in the app or custom rules in guards.toml.
Use Security > Guards to enable guards and toggle only the approved packs.
If you cannot operate the app, give the user those steps and wait for confirmation.
There is no agento11y guards enable or agento11y guards install command; do not invent one or reconstruct shipped pack regexes.
The switches save immediately: enablement goes in config.env, and pack rules go in the adjacent guards.toml.
Turning off the main switch removes all known pack rules when the file can be parsed.
Turning it back on does not restore the selection; custom rules remain.
Those custom rules still apply to requests from agents that have not picked up the disabled setting.
A broken file stays unchanged when the main switch is disabled.
Disabling a pack removes edits to that pack; re-enabling creates the shipped definition. Stop on save or compilation errors rather than claiming the pack is active.
For launcher-based sessions, use agento11y <agent> --local after approval, replacing <agent> with the target launcher name.
For hook-based setup, follow setup-coding-agent rather than guessing host configuration.
Restart the coding agent after changing enablement or destination, and inspect explicit environment overrides if saved settings do not take effect.
Pack-rule edits apply on the next daemon check without a daemon restart.
Custom rules are [[rules]] entries in guards.toml; preserve existing rules and pack definitions.
Refer to the custom-rule example for TOML syntax.
| Field | Meaning |
|---|---|
rule_id | Unique identifier shown in results. Keep custom IDs outside pack.*. |
enabled | Defaults to true; false disables the rule. Custom rules have no pack switch. |
phase | postflight checks tool calls before execution and is the default. |
priority | Lower values run first; defaults to 0. |
action_on_fail | deny blocks, warn continues, and allow ends local evaluation, skipping later rules. Defaults to deny. |
evaluators | Checks attached to the rule, each written as [[rules.evaluators]]. |
kind | regex runs locally. Cloud-only evaluator kinds do not. |
config.target | shell_command selects decoded arguments from recognized shell tools. |
config.reject | true fails on any pattern match; false (the default) fails when none match. |
config.patterns | Go regular expressions. Use TOML single-quoted strings to preserve backslashes. |
Use agento11y guards test '<command>' for a local dry run.
Choose dry runs for the selected packs, including a denied case and an allowed case.
If your own tool calls pass through guards, ask the user to run the complete dry-run commands directly in a terminal.
The outer tool call can match the dangerous text inside the quoted argument and be blocked before guards test starts.
Do not disable guards or disguise the command to get past that check.
A host-hook rejection is not a completed dry run.
Remind the user to run the full agento11y guards test command, never the inner command alone.
agento11y guards test 'git reset --hard'
agento11y guards test 'git push --force-with-lease'
agento11y guards test 'rm -rf /tmp/agento11y-guard-example'
agento11y guards test --json 'cat .env'With unmodified Git safety alone, the first command denies and the second allows.
Destructive commands denies the third; File safety denies the fourth.
Other rules can change those results.
Use --rules before the quoted command when testing an explicit file.
Use only synthetic, non-secret values for redaction tests.
The command executes none of the submitted text, contacts no endpoints, and changes no files.
It evaluates saved rules even when host guards are disabled.
Exit 0 means allow, 1 means deny, and 2 means an error, including compilation errors.
Read notices and errors: a missing default file or no enforceable rules can return allow.
--tool changes the synthetic tool name, not its {"command": ...} argument shape; it does not replay arbitrary file-tool calls.
For unexpected results, compare the rules path, enabled rules, tool name, and exact input before changing policy.
A malformed or unreadable file can leave no local rules enforcing.
AGENTO11Y_GUARDS_FAIL_OPEN=false does not make such a file fail closed.
Do not disable unrelated packs or broaden exceptions to make a test pass.
List the resolved file path, selected packs, changes made, dry-run results, and any remaining errors. Separate these conclusions:
If no live host check was observed, say that host enforcement remains unverified. Do not attempt a destructive live test to close that gap.
© grafana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/agento11y/internal/skills/content/setup-local-guards of grafana/agento11y.
Open the folder on GitHubat commit 9ab60bc
Setup Local Guards next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Setup Local Guards this skillgrafana/agento11y | 127 | — | ~2.6k | Automated safety check: Notes | Apache-2.0 | |
| Mz Release SignoffMaterializeInc/materialize | 6.4k | — | ~7.2k | Automated safety check: Pass | Custom licence | |
| Axiom Dashboard Builderopenclaw/clawhub | 9.5k | — | ~4.9k | Automated safety check: Pass | MIT | |
| Happy Infra Metrics and Grafanaslopus/happy | 24k | — | ~2k | Automated safety check: Notes | MIT | |
| Syncmetapawurb/hotpath-rs | 1.9k | — | ~1.2k | Automated safety check: Notes | MIT | |
| Optimize Slurm TopologyNVlabs/alpasim | 1.3k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 |
MaterializeInc/materialize
Verify a release candidate on the Grafana dashboards and sign off in release.
openclaw/clawhub
Designs and deploys Axiom dashboards through the API, choosing chart types and writing APL or metrics queries, with templates and migration notes for Splunk and Grafana.
slopus/happy
Queries live Prometheus metrics and manages Grafana dashboards as code for Happy's infrastructure, using the grafanactl CLI and the Grafana datasource proxy API.
pawurb/hotpath-rs
Sync changes from the hotpath, hotpath-macros and hotpath-drain crates to their meta counterparts (hotpath-meta, hotpath-macros-meta and hotpath-drain-meta).
NVlabs/alpasim
Optimize AlpaSim Slurm topology throughput using persistent local Prometheus/Grafana telemetry and run artifacts.
comet-ml/opik
Specifies how to instrument an opik-backend pipeline with per-stage OpenTelemetry metrics for throughput, latency, errors and queue delay by workspace.
grafana/agento11y
Optional credential-free Hermes integration checks using an explicit loopback model provider and local telemetry receivers.
grafana/agento11y
Run any Python LLM agent as an Agent Observability experiment using the public agento11y.experiments package: define a test suite, run an existing agent through typed trials, bind or record…
grafana/agento11y
Use early in an AI-agent project — before ship, before real traffic — to decide which evaluations to set up and to scaffold a starter experiment.
Works with
Categories
Help choose, configure, and test local agento11y guard packs for coding-agent tool calls. Setup Local Guards is an agent skill from grafana/agento11y, published by the product's own GitHub organization. Help choose, configure, and test local agento11y guard packs for coding-agent tool calls.
Setup Local Guards fits situations like: the user asks to enable safety packs; protect .env files; block dangerous commands; redact tool arguments.
Run `npx skills add grafana/agento11y --skill setup-local-guards -a claude-code`. Or copy the skill folder (plugins/agento11y/internal/skills/content/setup-local-guards in grafana/agento11y) into .claude/skills/setup-local-guards in your project. Claude Code loads it when a task matches its description.
Run `npx skills add grafana/agento11y --skill setup-local-guards -a codex`. Or copy the skill folder (plugins/agento11y/internal/skills/content/setup-local-guards in grafana/agento11y) into .agents/skills/setup-local-guards in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grafana/agento11y --skill setup-local-guards -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/setup-local-guards, .gemini/skills/setup-local-guards, .github/skills/setup-local-guards and .opencode/skills/setup-local-guards in your project.
SKILL.md names no scripts, command-line tools or credentials: Setup Local Guards is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Setup Local Guards is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Setup Local Guards: Mz Release Signoff (MaterializeInc/materialize, 6.4k stars), Axiom Dashboard Builder (openclaw/clawhub, 9.5k stars), Happy Infra Metrics and Grafana (slopus/happy, 24k stars) and Syncmeta (pawurb/hotpath-rs, 1.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
grafana (a GitHub organization, an official publisher) maintains it in grafana/agento11y, which has 127 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 8, 2026.
Source: grafana/agento11y on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.