Agent skill

Work

by guardana in guardana/guardana

Entry point for any development task in this repo — feature, bugfix, refactor, cleanup, a new command, target or evaluator, a collector change.

Apache-2.0Auto-check passedSecurity

Install Work

skills CLI
$ npx skills add guardana/guardana --skill work -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install guardana/guardana work --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/guardana/guardana.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/work .claude/skills/work && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
work
GitHub stars
152
Token cost
~1k tokens
SKILL.md length
568 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
Apache-2.0

At a glance

Entry point for any development task in this repo — feature, bugfix, refactor, cleanup, a new command, target or evaluator, a collector change.

  • Works in 4 steps: Check it is still true, and that nobody… → Size it (say the size out loud, one line) → Spend tokens where they buy quality → …
  • Tasks that involve Refactoring
  • SKILL.md covers 0. Check it is still true, and…, 1. Size it (say the size out…, 2. Spend tokens where they buy… and 3. Always true
  • Calls git

What it does

Work is an agent skill from guardana/guardana. Entry point for any development task in this repo — feature, bugfix, refactor, cleanup, a new command, target or evaluator, a collector change. Sizes the task, picks the lightest lifecycle that is still safe, and says which model tier does which part. Use at the start of a task, or to resume one from docs/work/.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Refactoring and Prompt injection and agent security. The repository describes itself as: Open-source AI security verification for model artifacts, live endpoints, MCP servers, and recorded agent traces. Reproducible evidence for release decisions. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Refactoring
  • Tasks that involve Prompt injection and agent security

Example prompts

  • “/work”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Check it is still true, and that nobody holds it
  2. Size it (say the size out loud, one line)
  3. Spend tokens where they buy quality
  4. Always true

What it can do on your machine

Read from SKILL.md and the folder at commit dd3920e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Work loads about 1k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 568 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from guardana/guardana at commit dd3920e, republished under its Apache-2.0 licence (© guardana). 568 words, ~1,036 tokens.

Download SKILL.mdSave it as .claude/skills/work/SKILL.md (or your agent's skills folder).
name
work
description
Entry point for any development task in this repo — feature, bugfix, refactor, cleanup, a new command, target or evaluator, a collector change. Sizes the task, picks the lightest lifecycle that is still safe, and says which model tier does which part. Use at the start of a task, or to resume one from docs/work/.
argument-hint
[task description | path to a work file]

Work — the lifecycle

Task: $ARGUMENTS

In-flight work files: !ls docs/work/*.md 2>/dev/null | grep -v -E 'README|BACKLOG|TEMPLATE' || echo none

0. Check it is still true, and that nobody holds it

Several sessions work in this repo. Before anything else: reproduce the bug or confirm the gap (git log -15 --oneline, git status --short, the list above). Already fixed → say so and stop. A work file already covers it → continue THAT file from its Handoff section, never a duplicate. Uncommitted changes that are not yours stay untouched and unstaged.

1. Size it (say the size out loud, one line)

sizeit is this whenlifecycle
S≤ 2 files, no schema / exit code / CLI flag / extension-contract change, the fix is obviousdo it → /gate → /ship
Mone package, several files, or any change a saved run, a report or a finding could show/plan → build it yourself (or one coder) → /gate → /review → /ship
Lcrosses packages, adds a command / target / evaluator / schema / migration, touches the collector envelope or the extension contract/plan with lanes → /build (parallel coders) → /gate → /review → /ship in ordered commits → close

When unsure between two sizes, take the smaller and escalate the moment a second package shows up. Specialised entries: new coverage is add-a-rule (a rule, evaluator or target — never the engine); a roadmap question is /research; a documentation-only task is /docs; a symptom is /debug first; "nothing changes for users" is /refactor; closing a milestone is release. /auto <task> runs the whole chain unattended, deciding reversibly instead of asking, and stops only at its hard lines (push, tags, paid probes, protected contracts).

Show full SKILL.md (306 more words)Show less

2. Spend tokens where they buy quality

part of the jobwhowhy
find code, a rule, a test; read a log; summarise outputscout (Haiku)the answer matters, not the pages
run the gate, a suite, a --check scriptrunner (Haiku)thousands of lines stay out of context
design, hard or cross-cutting code, integrationmain sessionneeds the whole picture
one well-briefed lane of code + testscoder (Opus, high)code is where quality is non-negotiable
pre-ship reviewreviewer (Opus, high)fresh context finds what the author cannot
a deliberate hunt for a false greenfalse-green-hunter (Opus, high)the defect class this project exists to prevent
reader-facing wording, or a verdict about ittext-broker → GPT / Geminisee content-model; never written by Claude
the landing page or docs site in a browserbrowser (Sonnet)snapshots are huge

Rules of thumb: never spawn an agent for something one Grep answers; give every agent the exact files, the question and the shape of the answer; two agents may run in parallel only when their file sets are disjoint; an agent's report is evidence to check, not a fact; agents do not spawn agents. Never pick a Fable/Mythos model for an agent, a script or a config.

3. Always true

  • Work files live in docs/work/ and hold ONLY work in flight. Shipping deletes the file; what must outlive it moves to its home (a docs/ page, a design document, a .claude/rules/ line, docs/maintainers/lessons.md). Open leftovers go to docs/work/BACKLOG.md.
  • A task is done when the gate is green with the verdict lines read, the change is reviewed (M/L), the five documentation places are answered, it is committed — and, if it changes what a command writes, the documented command was run against a real or faked target and its artifact read.
  • "Not measured" is never "passed". Say what you did not verify.

© guardana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/work of guardana/guardana.

Open the folder on GitHubat commit dd3920e

Compare with similar skills

Work next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Work compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Work this skillguardana/guardana152—~1kAutomated safety check: PassApache-2.0
Architectural Analysispedronauck/skills6331 repos~524Automated safety check: PassNone
Forensifyalexgreensh/repo-forensics187—~2.5kAutomated safety check: NotesCustom licence
Skylos Securityduriantaco/skylos843—~545Automated safety check: PassApache-2.0
Agentic GitHub Actions Auditortrailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0
Plugin Scanneriflytek/skillhub5.2k2 repos~1.1kAutomated safety check: NotesApache-2.0

Similar skills

  • Architectural Analysis

    pedronauck/skills

    Audit architecture, dead code, duplication, type confusion, and code smells across a codebase.

    633 GitHub starsUsed in 1 repo~524 tokens
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    187 GitHub stars~2.5k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • Skylos Security

    duriantaco/skylos

    Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.

    843 GitHub stars~545 tokensUpdated yesterday
    SecurityAuto-check passed
  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.4k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • Plugin Scanner

    iflytek/skillhub

    Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

    5.2k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes
  • Security Guide

    jnMetaCode/shellward

    OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation

    140 GitHub stars~644 tokensUpdated 9 days ago
    SecurityAuto-check: warnings

More from guardana/guardana

All 16 skills in this repo
  • Content Model

    guardana/guardana

    Route wording work to GPT (codex CLI) or Gemini (agy CLI) instead of writing it with Claude — landing-page copy, a readability rewrite of a README or docs page, attack and judge prompts for a rule…

    152 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Ship

    guardana/guardana

    Commit and push a finished change the way this repo requires — explicit paths, one commit per logical change, no attribution, the five documentation places answered, the site checks before a push (a…

    152 GitHub stars~836 tokensUpdated yesterday
    Auto-check: notes
  • Add A Rule

    guardana/guardana

    Add security coverage to Guardana the way this repository requires — as a rule, evaluator or target, never by patching the engine — with the fixtures, the framework mapping and the documentation…

    152 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Auto

    guardana/guardana

    Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions.

    152 GitHub stars~792 tokensUpdated yesterday
    Auto-check passed
  • Docs

    guardana/guardana

    Documentation work in this repo — the five places a user-visible change must answer, the page conventions the site build enforces, the tests that pin prose to the registry, and a simplification pass…

    152 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • False Green Audit

    guardana/guardana

    Hunt for the failure this project exists to prevent — code that compiles, types, tests green, and quietly reports "all clear" about something it never examined.

    152 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed

Questions about Work

What does Work do?

Entry point for any development task in this repo — feature, bugfix, refactor, cleanup, a new command, target or evaluator, a collector change. Work is an agent skill from guardana/guardana. Entry point for any development task in this repo — feature, bugfix, refactor, cleanup, a new command, target or evaluator, a collector change.

When should I use Work?

Work fits situations like: tasks that involve Refactoring; tasks that involve Prompt injection and agent security.

How do I install Work in Claude Code?

Run `npx skills add guardana/guardana --skill work -a claude-code`. Or copy the skill folder (.claude/skills/work in guardana/guardana) into .claude/skills/work in your project. Claude Code loads it when a task matches its description.

How do I install Work in Codex?

Run `npx skills add guardana/guardana --skill work -a codex`. Or copy the skill folder (.claude/skills/work in guardana/guardana) into .agents/skills/work in your project. Codex loads it when a task matches its description.

Can I use Work in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add guardana/guardana --skill work -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/work, .gemini/skills/work, .github/skills/work and .opencode/skills/work in your project.

What does Work need to run?

Going by SKILL.md and its folder, Work needs the command-line tools its instructions call (git).

Does Work access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Work safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Work use?

Work is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Work use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Work?

Skills that share tags, products or a category with Work: Architectural Analysis (pedronauck/skills, 633 stars), Forensify (alexgreensh/repo-forensics, 187 stars), Skylos Security (duriantaco/skylos, 843 stars) and Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Work?

guardana (a GitHub organization) maintains it in guardana/guardana, which has 152 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 6, 2026.

Source: guardana/guardana on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.