Agent skill

Stack

by guardana in guardana/guardana

Run and inspect the local pieces of Guardana — the throwaway PostgreSQL for the collector, the collector itself, a fake OpenAI-compatible endpoint to probe, the documentation site served locally…

Apache-2.0Auto-check passedDevOps & Cloud

Install Stack

skills CLI
$ npx skills add guardana/guardana --skill stack -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install guardana/guardana stack --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/guardana/guardana.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/stack .claude/skills/stack && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
stack
GitHub stars
152
Token cost
~568 tokens
SKILL.md length
219 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run and inspect the local pieces of Guardana — the throwaway PostgreSQL for the collector, the collector itself, a fake OpenAI-compatible endpoint to probe, the documentation site served locally…

  • Try a command for real
  • Calls uv, docker and python3
  • Reproduce a collector
  • Before a browser check

What it does

Stack is an agent skill from guardana/guardana. Run and inspect the local pieces of Guardana — the throwaway PostgreSQL for the collector, the collector itself, a fake OpenAI-compatible endpoint to probe, the documentation site served locally, the two container images. Use to try a command for real, to reproduce a collector or probe problem, or before a browser check.

Its SKILL.md is about 570 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers, Static sites and blogs and Prompt injection and agent security. It works with PostgreSQL, OpenAI, Docker and Python. The repository describes itself as: Open-source AI security verification for model artifacts, live endpoints, MCP servers, and recorded agent traces. Reproducible evidence for release decisions. The licence is Apache-2.0.

When your agent uses it

  • Try a command for real
  • Reproduce a collector
  • Before a browser check

Example prompts

  • “/stack”

Requirements

  • Python 3
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit dd3920e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • docker
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Stack loads about 568 tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 219 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~568

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from guardana/guardana at commit dd3920e, republished under its Apache-2.0 licence (© guardana). 219 words, ~568 tokens.

Download SKILL.mdSave it as .claude/skills/stack/SKILL.md (or your agent's skills folder).
name
stack
description
Run and inspect the local pieces of Guardana — the throwaway PostgreSQL for the collector, the collector itself, a fake OpenAI-compatible endpoint to probe, the documentation site served locally, the two container images. Use to try a command for real, to reproduce a collector or probe problem, or before a browser check.
argument-hint
[postgres | collector | endpoint | site | images]

Local stack

Requested: $ARGUMENTS (nothing = postgres).

whatcommandnotes
postgresdocker compose -f deploy/docker-compose.dev.yml up -d --waitport 55439 on purpose; databases guardana_test (the suite) and guardana (local use). Tests read GUARDANA_TEST_DATABASE_URL=postgresql://guardana:guardana@127.0.0.1:55439/guardana_test; GUARDANA_REQUIRE_POSTGRES=1 turns the skip into a failure, as CI does.
collectorexport GUARDANA_DATABASE_URL=postgresql://guardana:guardana@127.0.0.1:55439/guardana then uv run guardana-collector migrate and uv run guardana-collector servemigrations never run on container start; docs/usage-collector.md has the token and environment model. The engine reaches it only through --reporter server://….
endpointa fake OpenAI-compatible server is a few lines of http.server answering /v1/chat/completions; guardana.core.testing has scripted transports for in-process useuv run guardana probe --url http://127.0.0.1:<port>/v1 --model fake … then read the JSON it wrote. plan probe never contacts the endpoint. Never point probe, monitor or calibrate at a paid provider without the user saying so and a budget.
siteuv run python scripts/build_site.py && python3 -m http.server -d site 8099exactly what Cloudflare serves; site-check for what to look at.
imagesuv run --no-project python scripts/image_smoke.py (--no-build reuses images)builds guardana-cli:smoke and guardana-collector:smoke and runs them; needs docker.
depsuv sync (all five packages plus dev and docs groups)uv sync --locked is what CI runs.

Nothing here contacts a network host other than what you started; the product's rule is that traffic goes only to destinations the run names (principle 3 in CLAUDE.md).

© guardana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/stack of guardana/guardana.

Open the folder on GitHubat commit dd3920e

Compare with similar skills

Stack next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Stack compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Stack this skillguardana/guardana152—~568Automated safety check: PassApache-2.0
Code PatternsAedelon/claude-code-blueprint120—~1.2kAutomated safety check: PassCustom licence
Deploying Go SDK Bundlesastronomer/agents450—~1.8kAutomated safety check: NotesApache-2.0
Dockeravibebuilder/claude-prime120—~1kAutomated safety check: NotesMIT
Deploymentericrisco/rsc-harness156—~4.2kAutomated safety check: NotesMIT
Cognee Docker Setuptopoteretes/cognee32k1 repos~901Automated safety check: NotesApache-2.0

Similar skills

  • Code Patterns

    Aedelon/claude-code-blueprint

    Reference patterns for REST APIs, pytest/vitest testing, Docker multi-stage builds, GitHub Actions CI/CD, PostgreSQL, TypeScript generics, Python async, and React Server Components.

    120 GitHub stars~1.2k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed
  • Deploying Go SDK Bundles

    astronomer/agents

    Builds, packs, and deploys compiled Airflow Go SDK bundles so the ExecutableCoordinator can run them.

    450 GitHub stars~1.8k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Docker

    avibebuilder/claude-prime

    ALWAYS activate when the user's query involves Docker in any way — even if it also matches other skills.

    120 GitHub stars~1k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check: notes
  • Deployment

    ericrisco/rsc-harness

    A skill your agent uses when taking an app from source to live: choosing the deploy target from requirements (Hetzner+Coolify vs Vercel vs a third), then wiring container → CI → registry → host with…

    156 GitHub stars~4.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Cognee Docker Setup

    topoteretes/cognee

    Runs the Cognee AI memory platform in Docker, from a one-file prebuilt image to a full compose stack with UI, MCP server, Postgres and Neo4j.

    32k GitHub starsUsed in 1 repo~901 tokens
    DevOps & CloudAuto-check: notes
  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes

More from guardana/guardana

All 16 skills in this repo
  • Content Model

    guardana/guardana

    Route wording work to GPT (codex CLI) or Gemini (agy CLI) instead of writing it with Claude — landing-page copy, a readability rewrite of a README or docs page, attack and judge prompts for a rule…

    152 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Ship

    guardana/guardana

    Commit and push a finished change the way this repo requires — explicit paths, one commit per logical change, no attribution, the five documentation places answered, the site checks before a push (a…

    152 GitHub stars~836 tokensUpdated yesterday
    Auto-check: notes
  • Add A Rule

    guardana/guardana

    Add security coverage to Guardana the way this repository requires — as a rule, evaluator or target, never by patching the engine — with the fixtures, the framework mapping and the documentation…

    152 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Auto

    guardana/guardana

    Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions.

    152 GitHub stars~792 tokensUpdated yesterday
    Auto-check passed
  • Docs

    guardana/guardana

    Documentation work in this repo — the five places a user-visible change must answer, the page conventions the site build enforces, the tests that pin prose to the registry, and a simplification pass…

    152 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • False Green Audit

    guardana/guardana

    Hunt for the failure this project exists to prevent — code that compiles, types, tests green, and quietly reports "all clear" about something it never examined.

    152 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed

Questions about Stack

What does Stack do?

Run and inspect the local pieces of Guardana — the throwaway PostgreSQL for the collector, the collector itself, a fake OpenAI-compatible endpoint to probe, the documentation site served locally…. Stack is an agent skill from guardana/guardana. Run and inspect the local pieces of Guardana — the throwaway PostgreSQL for the collector, the collector itself, a fake OpenAI-compatible endpoint to probe, the documentation site served locally, the two container images.

When should I use Stack?

Stack fits situations like: try a command for real; reproduce a collector; before a browser check.

How do I install Stack in Claude Code?

Run `npx skills add guardana/guardana --skill stack -a claude-code`. Or copy the skill folder (.claude/skills/stack in guardana/guardana) into .claude/skills/stack in your project. Claude Code loads it when a task matches its description.

How do I install Stack in Codex?

Run `npx skills add guardana/guardana --skill stack -a codex`. Or copy the skill folder (.claude/skills/stack in guardana/guardana) into .agents/skills/stack in your project. Codex loads it when a task matches its description.

Can I use Stack in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add guardana/guardana --skill stack -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/stack, .gemini/skills/stack, .github/skills/stack and .opencode/skills/stack in your project.

What does Stack need to run?

Going by SKILL.md and its folder, Stack needs the command-line tools its instructions call (uv, docker and python3). Our summary lists: Python 3; Docker.

Does Stack access the network?

SKILL.md contains no URLs. Its commands use uv and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Stack safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Stack use?

Stack is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Stack use?

About 568 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Stack?

Skills that share tags, products or a category with Stack: Code Patterns (Aedelon/claude-code-blueprint, 120 stars), Deploying Go SDK Bundles (astronomer/agents, 450 stars), Docker (avibebuilder/claude-prime, 120 stars) and Deployment (ericrisco/rsc-harness, 156 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Stack?

guardana (a GitHub organization) maintains it in guardana/guardana, which has 152 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 6, 2026.

Source: guardana/guardana on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.