Agent skill

Auto

by guardana in guardana/guardana

Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions.

Apache-2.0Auto-check passedSecurity

Install Auto

skills CLI
$ npx skills add guardana/guardana --skill auto -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install guardana/guardana auto --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/guardana/guardana.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/auto .claude/skills/auto && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auto
GitHub stars
129
Token cost
~792 tokens
SKILL.md length
441 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
Apache-2.0

At a glance

Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions.

  • Works in 6 steps: Check it is still true. Reproduce the… → Decide instead of asking. For every open… → Checkpoint. After each lane: tick it,… → …
  • The user hands over a task and wants it finished unattended (zrób to do końca
  • SKILL.md covers Hard lines — stop and report… and Report
  • Calls git

What it does

Auto is an agent skill from guardana/guardana. Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions. Use when the user hands over a task and wants it finished unattended ("zrób to do końca", "/auto …"). Stops only at the hard lines listed inside.

Its SKILL.md is about 790 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Prompt injection and agent security. It works with Git. The repository describes itself as: Open-source AI security verification for model artifacts, live endpoints, MCP servers, and recorded agent traces. Reproducible evidence for release decisions. The licence is Apache-2.0.

When your agent uses it

  • The user hands over a task and wants it finished unattended (zrób to do końca
  • Tasks that involve Prompt injection and agent security

Example prompts

  • “zrób to do końca”
  • “/auto …”
  • “/auto”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Check it is still true. Reproduce the bug / confirm the feature is missing / confirm the
  2. Decide instead of asking. For every open question take the most REVERSIBLE option, and
  3. Checkpoint. After each lane: tick it, update the Handoff section (done / next / how to
  4. Review loop, bounded. /review → fix findings → gate → re-review ONLY the fixes. At most
  5. Commit, do not push (explicit paths, one commit per logical change, no attribution, the
  6. Retro, one minute. If a missing rule or skill line cost you a detour, add that ONE line to

What it can do on your machine

Read from SKILL.md and the folder at commit ae7ee8b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auto loads about 792 tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 441 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~792

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from guardana/guardana at commit ae7ee8b, republished under its Apache-2.0 licence (© guardana). 441 words, ~792 tokens.

Download SKILL.mdSave it as .claude/skills/auto/SKILL.md (or your agent's skills folder).
name
auto
description
Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions. Use when the user hands over a task and wants it finished unattended ("zrób to do końca", "/auto …"). Stops only at the hard lines listed inside.
argument-hint
[task description | path to a work file]
disable-model-invocation
true

Auto — finish it without asking

Task: $ARGUMENTS

Run work → plan → build → gate → review → fix → gate → commit, in one go.

  1. Check it is still true. Reproduce the bug / confirm the feature is missing / confirm the dead code is still there. Other sessions work in this repo: look at git log -15, git status and docs/work/ first. Nothing to do → say so and stop cleanly. A work file already covers it → continue THAT file from its Handoff section; never start a duplicate.
  2. Decide instead of asking. For every open question take the most REVERSIBLE option, and record it under "Decisions" in the work file as decided alone: … — reverse by … so the user can overrule it afterwards. Only a question on the hard-lines list below stops the run.
  3. Checkpoint. After each lane: tick it, update the Handoff section (done / next / how to verify), run the scoped verification. Every third lane run the full gate. If context gets long, the work file alone must let a fresh session continue.
  4. Review loop, bounded. /review → fix findings → gate → re-review ONLY the fixes. At most three rounds; what is still open after that goes into the report, not into a fourth round.
  5. Commit, do not push (explicit paths, one commit per logical change, no attribution, the five documentation places answered). The push — a site deploy — stays with the user unless they said "and push" in the task; a tag never happens here.
  6. Retro, one minute. If a missing rule or skill line cost you a detour, add that ONE line to the right .claude/rules/ file or skill now.
Show full SKILL.md (174 more words)Show less

Hard lines — stop and report instead of crossing

  • git push, a version tag, scripts/release.py, a GitHub release, force operations, history rewrites;
  • any command that contacts a live endpoint or MCP server, or spends money on a provider — probe, monitor, calibrate with a judge, target inspect against a real URL;
  • renaming or dropping a protected contract (CLAUDE.md lists them): a schema_version, an exit code, a rule id, an entry-point group, a CLI flag, the collector envelope, the Action inputs;
  • making a check return clean to get green — the verdict is inconclusive or a finding, or the task stops here;
  • reader-facing wording with no text-broker engine available;
  • deleting a user-facing page, a design document or a fixture;
  • a gate red for a reason that is not yours and that you cannot fix inside the task.

Report

What was asked → what is now true; commits; the gate's verdict lines; review rounds and what stayed open; decisions made alone (each reversible how); what was NOT verified; the next step that needs the user (usually: push, or a release).

© guardana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/auto of guardana/guardana.

Open the folder on GitHubat commit ae7ee8b

Compare with similar skills

Auto next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auto compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auto this skillguardana/guardana129—~792Automated safety check: PassApache-2.0
Sillytavern API ReferenceLiarMTTT/TavernWeave150—~2.4kAutomated safety check: PassCustom licence
Remediating With AWS Security Agentaws/agent-toolkit-for-aws2.8k—~2.9kAutomated safety check: PassApache-2.0
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
Careful Mode Command Guardrailsgarrytan/gstack136k—~931Automated safety check: NotesMIT
Plugin Scanneriflytek/skillhub5.2k2 repos~1.1kAutomated safety check: NotesApache-2.0

Similar skills

  • Sillytavern API Reference

    LiarMTTT/TavernWeave

    Verify exact SillyTavern, Tavern Helper / JS-Slash-Runner, STScript, macro, prompt-injection, worldbook, EJS, MVU, and runtime-library capabilities before implementing or reviewing rolecard…

    150 GitHub stars~2.4k tokensUpdated 4 days ago
    Agent WorkflowsAuto-check passed
  • Remediating With AWS Security Agent

    aws/agent-toolkit-for-aws

    Official

    Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation.

    2.8k GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • Checks each shell command for destructive patterns such as recursive deletes, force pushes and dropped tables, and asks before letting them run.

    136k GitHub stars~931 tokensUpdated today
    SecurityAuto-check: notes
  • Plugin Scanner

    iflytek/skillhub

    Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

    5.2k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes
  • Agent Security Audit

    OWASP/secure-agent-playbook

    Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails.

    187 GitHub stars~542 tokensUpdated 13 days ago
    SecurityAuto-check passed

More from guardana/guardana

All 16 skills in this repo
  • Content Model

    guardana/guardana

    Route wording work to GPT (codex CLI) or Gemini (agy CLI) instead of writing it with Claude — landing-page copy, a readability rewrite of a README or docs page, attack and judge prompts for a rule…

    129 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Ship

    guardana/guardana

    Commit and push a finished change the way this repo requires — explicit paths, one commit per logical change, no attribution, the five documentation places answered, the site checks before a push (a…

    129 GitHub stars~836 tokensUpdated yesterday
    Auto-check: notes
  • Add A Rule

    guardana/guardana

    Add security coverage to Guardana the way this repository requires — as a rule, evaluator or target, never by patching the engine — with the fixtures, the framework mapping and the documentation…

    129 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Docs

    guardana/guardana

    Documentation work in this repo — the five places a user-visible change must answer, the page conventions the site build enforces, the tests that pin prose to the registry, and a simplification pass…

    129 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • False Green Audit

    guardana/guardana

    Hunt for the failure this project exists to prevent — code that compiles, types, tests green, and quietly reports "all clear" about something it never examined.

    129 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Gate

    guardana/guardana

    Run this project's verification — the full local CI mirror (ruff, mypy, import contract, pytest with PostgreSQL, coverage floors, dogfood, generated docs and site, the isolated example suites, the…

    129 GitHub stars~776 tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Auto

What does Auto do?

Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions. Auto is an agent skill from guardana/guardana. Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions.

When should I use Auto?

Auto fits situations like: the user hands over a task and wants it finished unattended (zrób to do końca; tasks that involve Prompt injection and agent security.

How do I install Auto in Claude Code?

Run `npx skills add guardana/guardana --skill auto -a claude-code`. Or copy the skill folder (.claude/skills/auto in guardana/guardana) into .claude/skills/auto in your project. Claude Code loads it when a task matches its description.

How do I install Auto in Codex?

Run `npx skills add guardana/guardana --skill auto -a codex`. Or copy the skill folder (.claude/skills/auto in guardana/guardana) into .agents/skills/auto in your project. Codex loads it when a task matches its description.

Can I use Auto in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add guardana/guardana --skill auto -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auto, .gemini/skills/auto, .github/skills/auto and .opencode/skills/auto in your project.

What does Auto need to run?

Going by SKILL.md and its folder, Auto needs the command-line tools its instructions call (git).

Does Auto access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Auto safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Auto use?

Auto is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auto use?

About 792 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Auto?

Skills that share tags, products or a category with Auto: Sillytavern API Reference (LiarMTTT/TavernWeave, 150 stars), Remediating With AWS Security Agent (aws/agent-toolkit-for-aws, 2.8k stars), Forensify (alexgreensh/repo-forensics, 188 stars) and Careful Mode Command Guardrails (garrytan/gstack, 136k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auto?

guardana (a GitHub organization) maintains it in guardana/guardana, which has 129 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 7, 2026.

Source: guardana/guardana on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.