Agent skill

Maintain Skills

by heptameta in heptameta/heptabase-cli-skills

Maintain Agent Skills in a Heptabase repository across Claude Code, Codex, and Cursor.

MITAuto-check passedDevelopment

Install Maintain Skills

skills CLI
$ npx skills add heptameta/heptabase-cli-skills --skill maintain-skills -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install heptameta/heptabase-cli-skills maintain-skills --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/heptameta/heptabase-cli-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/maintain-skills .claude/skills/maintain-skills && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
maintain-skills
GitHub stars
155
Token cost
~1.5k tokens
SKILL.md length
701 words
Files
3 (incl. scripts)
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Maintain Agent Skills in a Heptabase repository across Claude Code, Codex, and Cursor.

  • Works in 4 steps: Run check-skills.mjs --changed to detect… → Search .claude/skills/ and relevant… → Resolve each conflict introduced or… → …
  • Auditing files under .claude/skills/
  • SKILL.md covers Use the canonical locations, Decide the invocation policy, Add Codex metadata by… and Prevent conflicting skills, plus 1 more section
  • Runs JavaScript scripts from its folder; calls node

What it does

Maintain Skills is an agent skill from heptameta/heptabase-cli-skills. Maintain Agent Skills in a Heptabase repository across Claude Code, Codex, and Cursor. Use when creating, editing, moving, removing, or auditing files under .claude/skills/.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `agents/openai.yaml`).

It sits in Development. The repository describes itself as: Agent skills for Heptabase CLI. The licence is MIT.

When your agent uses it

  • Auditing files under .claude/skills/

Example prompts

  • “/maintain-skills”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Run check-skills.mjs --changed to detect mechanical conflicts.
  2. Search .claude/skills/ and relevant AGENTS.md, CLAUDE.md, .claude/rules/, and .cursor/rules/ files for overlapping triggers or…
  3. Resolve each conflict introduced or affected by the change
  4. If the correct behavior is unclear, ask the user. Report unrelated pre-existing conflicts without expanding the task to fix them.

What it can do on your machine

Read from SKILL.md and the folder at commit b5fb23f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Maintain Skills loads about 1.5k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 701 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from heptameta/heptabase-cli-skills at commit b5fb23f, republished under its MIT licence (© heptameta). 701 words, ~1,480 tokens.

Download SKILL.mdSave it as .claude/skills/maintain-skills/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
maintain-skills
description
Maintain Agent Skills in a Heptabase repository across Claude Code, Codex, and Cursor. Use when creating, editing, moving, removing, or auditing files under .claude/skills/.
disable-model-invocation
false
metadata.internal
true

Maintain Skills

Apply only the Heptabase repository conventions below. Follow the active agent's normal skill-authoring guidance for general skill structure and writing quality.

Use the canonical locations

  • Treat .claude/skills/<skill-name>/ as the canonical source for team-owned repository skills.
  • Keep .agents/skills as a symlink to ../.claude/skills so Codex and other Agent Skills clients discover the same skills.
  • Do not copy team skills into .cursor/skills/ or .codex/skills/.
  • Use convert-cursor-to-claude-skill when converting rules, migrating commands, or fixing misplaced skill directories. This skill owns skill content and metadata, not path migration.

Decide the invocation policy

For every new skill, explicitly decide whether the model may invoke it automatically.

For an existing skill, preserve its current invocation policy unless the user asks to change it or the skill's intended behavior has materially changed.

The user's stated invocation choice always wins; you can suggest or ask but not override it. Do not override it with the defaults below.

<!-- prettier-ignore -->
Intended behaviorSKILL.mdagents/openai.yaml
The agent may load it when relevantOmit disable-model-invocation, or set it to falseOmit policy.allow_implicit_invocation, or set it to true
Only the user may start itSet disable-model-invocation: trueSet policy.allow_implicit_invocation: false

Because Codex allows implicit invocation by default, a human-invocation-only skill must include both settings and the complete UI metadata described below. An implicitly invocable skill may omit agents/openai.yaml unless it needs Codex UI metadata or dependencies.

When the user has not chosen:

  • Prefer model invocation for repository conventions, reference knowledge, and guidance that should apply whenever relevant.
  • Consider explicit-only invocation for named workflows whose timing the user is expected to control.
  • Do not infer explicit-only invocation only because a workflow uses tools, requires approval, or can cause side effects. Authorization is still checked when the action occurs.
  • If the correct invocation behavior is not easy to judge from the skill's purpose, ask the user before finalizing the skill.

Add Codex metadata by invocation mode

For a skill that the model may invoke automatically, agents/openai.yaml is optional. Add or update it only when it serves a Codex-specific purpose:

  • Improve a user-facing skill's name, description, default prompt, icon, or branding in Codex.
  • Declare tool dependencies for Codex.
  • Follow the user's request for Codex metadata.

Do not add the file only because a skill is new or being edited. Keep portable discovery in the SKILL.md name and description.

For a human-invocation-only skill, agents/openai.yaml and these fields are required:

  • interface.display_name
  • interface.short_description
  • interface.default_prompt
  • policy.allow_implicit_invocation: false

The skill selector is the primary entry point for a human-invocation-only skill, so its name, description, and starter prompt must be clear there.

When adding or editing the file:

  • Quote string values.
  • For implicitly invocable skills, keep interface fields optional.
  • When present or required, interface.short_description must contain 25 to 64 characters, and interface.default_prompt must mention $skill-name.
  • Include policy.allow_implicit_invocation when needed to keep Codex behavior aligned with disable-model-invocation.
  • Preserve unrelated interface, policy, and dependency fields.

Run the repository checker after creating or changing a skill:

bash
node .claude/skills/maintain-skills/scripts/check-skills.mjs --changed
Show full SKILL.md (219 more words)Show less

Prevent conflicting skills

Before finalizing a new or changed skill:

  1. Run check-skills.mjs --changed to detect mechanical conflicts.
  2. Search .claude/skills/ and relevant AGENTS.md, CLAUDE.md, .claude/rules/, and .cursor/rules/ files for overlapping triggers or instructions. Read possible overlaps; the checker cannot judge whether prose is consistent.
  3. Resolve each conflict introduced or affected by the change:
    • Frontmatter names must be unique within one repository. Separate repositories may reuse names.
    • For overlapping triggers, narrow the descriptions and state which skill owns each case.
    • For conflicting instructions, keep one source of truth or narrow the scopes so both can coexist.
    • Keep copies of the same team skill aligned across repositories.
  4. If the correct behavior is unclear, ask the user. Report unrelated pre-existing conflicts without expanding the task to fix them.

Validate the result

Run the checker from the repository root:

bash
node .claude/skills/maintain-skills/scripts/check-skills.mjs --changed

For a full repository audit:

bash
node .claude/skills/maintain-skills/scripts/check-skills.mjs

Standard checks require complete Codex UI metadata only for human-invocation-only skills.

For an optional audit that requires complete Codex UI metadata for every existing skill:

bash
node .claude/skills/maintain-skills/scripts/check-skills.mjs --strict-ui

When a task changes skills in more than one repository, run the checker separately in each affected repository.

Review the final diff and confirm that:

  • Only canonical .claude/skills/ files changed.
  • Invocation settings agree across SKILL.md and agents/openai.yaml.
  • No affected skills give conflicting instructions.
  • No unrelated skill or agent configuration was changed.

© heptameta, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in .claude/skills/maintain-skills of heptameta/heptabase-cli-skills.

  • SKILL.md
  • agents/openai.yaml
  • scripts/check-skills.mjs

Open the folder on GitHubat commit b5fb23f

Compare with similar skills

Maintain Skills next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Maintain Skills compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Maintain Skills this skillheptameta/heptabase-cli-skills155—~1.5kAutomated safety check: PassMIT
Vercel Composition Patternssupabase/supabase111k58 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 58 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from heptameta/heptabase-cli-skills

  • Release

    heptameta/heptabase-cli-skills

    Release a new version of heptabase-cli-skills, the public Agent Skills plugin package for the Heptabase CLI.

    155 GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed
  • Public Repo Guard

    heptameta/heptabase-cli-skills

    This repo (heptabase-cli-skills) is PUBLIC — everything committed is visible to the world and permanent in git history.

    155 GitHub stars~1.2k tokensUpdated 3 days ago
    Auto-check: warnings
  • Heptabase CLI

    heptameta/heptabase-cli-skills

    Use the local heptabase CLI whenever the user mentions Heptabase or shares an app.heptabase.com URL/deep link.

    155 GitHub stars~3.1k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Maintain Skills

What does Maintain Skills do?

Maintain Agent Skills in a Heptabase repository across Claude Code, Codex, and Cursor. Maintain Skills is an agent skill from heptameta/heptabase-cli-skills. Maintain Agent Skills in a Heptabase repository across Claude Code, Codex, and Cursor.

When should I use Maintain Skills?

Maintain Skills fits situations like: auditing files under .claude/skills/.

How do I install Maintain Skills in Claude Code?

Run `npx skills add heptameta/heptabase-cli-skills --skill maintain-skills -a claude-code`. Or copy the skill folder (.claude/skills/maintain-skills in heptameta/heptabase-cli-skills) into .claude/skills/maintain-skills in your project. Claude Code loads it when a task matches its description.

How do I install Maintain Skills in Codex?

Run `npx skills add heptameta/heptabase-cli-skills --skill maintain-skills -a codex`. Or copy the skill folder (.claude/skills/maintain-skills in heptameta/heptabase-cli-skills) into .agents/skills/maintain-skills in your project. Codex loads it when a task matches its description.

Can I use Maintain Skills in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add heptameta/heptabase-cli-skills --skill maintain-skills -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/maintain-skills, .gemini/skills/maintain-skills, .github/skills/maintain-skills and .opencode/skills/maintain-skills in your project.

What does Maintain Skills need to run?

Going by SKILL.md and its folder, Maintain Skills needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js.

Does Maintain Skills access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Maintain Skills safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Maintain Skills use?

Maintain Skills is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Maintain Skills use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Maintain Skills?

Skills that share tags, products or a category with Maintain Skills: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Maintain Skills?

heptameta (a GitHub organization) maintains it in heptameta/heptabase-cli-skills, which has 155 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 7, 2026.

Source: heptameta/heptabase-cli-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.