Agent skill

Heat Metal

by Hmbown in Hmbown/Wizards-of-the-Ghosts

In D&D, Heat Metal makes a metal object painfully hot — the creature holding it must either endure the pain or drop it.

CC0-1.0Auto-check passedBackend & APIs

Install Heat Metal

skills CLI
$ npx skills add Hmbown/Wizards-of-the-Ghosts --skill heat-metal -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hmbown/Wizards-of-the-Ghosts heat-metal --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hmbown/Wizards-of-the-Ghosts.git skills-src && mkdir -p .claude/skills && cp -r skills-src/generated/openclaw/heat-metal .claude/skills/heat-metal && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
heat-metal
GitHub stars
110
Token cost
~633 tokens
SKILL.md length
268 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
CC0-1.0

At a glance

In D&D, Heat Metal makes a metal object painfully hot — the creature holding it must either endure the pain or drop it.

  • Works in 5 steps: Identify the tool, path, or behavior you… → Design the friction curve: what… → Implement the progressive friction:… → …
  • Tasks that involve Rate limiting
  • SKILL.md covers Overview, When To Use, Workflow and Deliverables, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Heat Metal is an agent skill from Hmbown/Wizards-of-the-Ghosts. In D&D, Heat Metal makes a metal object painfully hot — the creature holding it must either endure the pain or drop it. The real-world version is deliberate friction injection: making a deprecated API progressively slower, adding escalating CAPTCHAs to suspicious traffic, increasing the cost of a bad behavior path until the actor self-selects out. Heat Metal does not break the tool. It makes continuing to use it more painful than switching to the alternative. This is the spell behind deprecation-by-discomfort…

Its SKILL.md is about 630 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Rate limiting. The repository describes itself as: Unofficial Hermes Agent skill pack built from fantasy spell and skill names. The licence is CC0-1.0.

When your agent uses it

  • Tasks that involve Rate limiting

Example prompts

  • “/heat-metal”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Identify the tool, path, or behavior you want to discourage.
  2. Design the friction curve: what discomfort increases over time and at what rate.
  3. Implement the progressive friction: latency injection, CAPTCHA escalation, cost increases, warning banners.
  4. Monitor adoption of the preferred alternative to confirm the friction is driving the intended migration.
  5. Set a sunset date: Heat Metal should eventually end in either full migration or hard deprecation.

What it can do on your machine

Read from SKILL.md and the folder at commit 1f2e6a0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Heat Metal loads about 633 tokens when it runs. Until then it costs about 145 tokens; SKILL.md has 268 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~145
When it runs · the whole SKILL.md, loaded when a task matches
~633

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hmbown/Wizards-of-the-Ghosts at commit 1f2e6a0, republished under its CC0-1.0 licence (© Hmbown). 268 words, ~633 tokens.

Download SKILL.mdSave it as .claude/skills/heat-metal/SKILL.md (or your agent's skills folder).
name
heat-metal
description
In D&D, Heat Metal makes a metal object painfully hot — the creature holding it must either endure the pain or drop it. The real-world version is deliberate friction injection: making a deprecated API progressively slower, adding escalating CAPTCHAs to suspicious traffic, increasing the cost of a bad behavior path until the actor self-selects out. Heat Metal does not break the tool. It makes continuing to use it more painful than switching to the alternative. This is the spell behind deprecation-by-discomfort, progressive rate limiting, and sunset friction curves.
user-invocable
true

Heat Metal

Make a tool or process increasingly uncomfortable to use until it is abandoned.

Overview

Heat Metal is interpreted here as a hybrid spell with a prototype execution model.

Canonical source: Heat Metal (spell)

Provider target: OpenClaw

When To Use

  • You want to drive migration away from a deprecated tool, API, or workflow without hard-cutting access.
  • Suspicious or abusive behavior should be progressively penalized without outright blocking.
  • A gradual escalation of friction is more appropriate than an immediate ban or shutdown.

Workflow

  1. Identify the tool, path, or behavior you want to discourage.
  2. Design the friction curve: what discomfort increases over time and at what rate.
  3. Implement the progressive friction: latency injection, CAPTCHA escalation, cost increases, warning banners.
  4. Monitor adoption of the preferred alternative to confirm the friction is driving the intended migration.
  5. Set a sunset date: Heat Metal should eventually end in either full migration or hard deprecation.

Deliverables

  • A friction curve specification: what changes, how fast, and what the escalation stages are.
  • Migration metrics: how many users/systems have moved to the preferred alternative.
  • A sunset timeline with hard cutoff criteria.

Guardrails

  • Friction injection must be disclosed. Secretly making tools worse without explanation is a dark pattern.
  • Heat Metal targets behavior, not people. Progressive friction applied to specific users as punishment crosses into harassment.
  • Always provide a visible alternative. Making something painful to use without offering a better path is cruelty, not engineering.

Default Invocation

Use $heat-metal to design a progressive friction strategy that makes a deprecated tool, abusive pattern, or unwanted behavior increasingly uncomfortable until users migrate to the better alternative.

© Hmbown, CC0-1.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in generated/openclaw/heat-metal of Hmbown/Wizards-of-the-Ghosts.

Open the folder on GitHubat commit 1f2e6a0

Compare with similar skills

Heat Metal next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Heat Metal compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Heat Metal this skillHmbown/Wizards-of-the-Ghosts110—~633Automated safety check: PassCC0-1.0
Add Hosted Keysimstudioai/sim30k—~3.6kAutomated safety check: PassApache-2.0
Upstash Ratelimit TSupstash/ratelimit-js2k—~313Automated safety check: PassMIT
Repo2skillzhangyanxs/repo2skill246—~3.6kAutomated safety check: PassNone
Better Auth Security Best PracticesEpicenterHQ/epicenter4.8k—~896Automated safety check: PassCustom licence
Dload Fetch Toolphp-internal/dload105—~1.1kAutomated safety check: PassBSD-3-Clause

Similar skills

  • Add Hosted Key

    simstudioai/sim

    Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.

    30k GitHub stars~3.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Upstash Ratelimit TS

    upstash/ratelimit-js

    Official

    Lightweight guidance for using the Redis Rate Limit TypeScript SDK, including setup steps, basic usage, and pointers to advanced algorithm, features, pricing, and traffic‑protection docs.

    2k GitHub stars~313 tokensUpdated 16 days ago
    Backend & APIsAuto-check passed
  • Repo2skill

    zhangyanxs/repo2skill

    Convert GitHub/GitLab/Gitee repositories into comprehensive OpenCode Skills using embedded LLM calls with multiple mirrors and rate limit handling

    246 GitHub stars~3.6k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Dload Fetch Tool

    php-internal/dload

    Get a CLI tool — native binary or PHAR — from a GitHub release into a project folder with dload (vendor/bin/dload).

    105 GitHub stars~1.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • API Gateway

    itsmostafa/aws-agent-skills

    AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub stars~2.2k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed

More from Hmbown/Wizards-of-the-Ghosts

All 11 skills in this repo
  • Animate Objects

    Hmbown/Wizards-of-the-Ghosts

    This spell transforms inert → reactive. An agent skill from Hmbown/Wizards-of-the-Ghosts.

    110 GitHub stars~804 tokensUpdated 6 mo ago
    Auto-check passed
  • Dancing Lights

    Hmbown/Wizards-of-the-Ghosts

    Use this spell for lightweight indicators: status pips, progress markers, heartbeat widgets, and ambient observability that help humans orient quickly.

    110 GitHub stars~528 tokensUpdated 6 mo ago
    Auto-check passed
  • Detect Magic

    Hmbown/Wizards-of-the-Ghosts

    A skill your agent uses when you need a fast, structured scan for where the real magic is hiding in a repo, workflow, or system.

    110 GitHub stars~651 tokensUpdated 6 mo ago
    Auto-check passed
  • Dispel Magic

    Hmbown/Wizards-of-the-Ghosts

    Use this spell when you need to cleanly shut down, disable, or remove active AI tooling — the reverse of Detect Magic.

    110 GitHub stars~430 tokensUpdated 6 mo ago
    Auto-check passed
  • Foresight

    Hmbown/Wizards-of-the-Ghosts

    Foresight produces bounded forecasts with explicit uncertainty to guide decisions.

    110 GitHub stars~779 tokensUpdated 6 mo ago
    Auto-check passed
  • Glyph Of Warding

    Hmbown/Wizards-of-the-Ghosts

    A skill your agent uses when you need a watchful boundary around files, systems, metrics, queues, or workflows.

    110 GitHub stars~461 tokensUpdated 6 mo ago
    Auto-check passed

Categories

Questions about Heat Metal

What does Heat Metal do?

In D&D, Heat Metal makes a metal object painfully hot — the creature holding it must either endure the pain or drop it. Heat Metal is an agent skill from Hmbown/Wizards-of-the-Ghosts. In D&D, Heat Metal makes a metal object painfully hot — the creature holding it must either endure the pain or drop it.

When should I use Heat Metal?

Heat Metal fits situations like: tasks that involve Rate limiting.

How do I install Heat Metal in Claude Code?

Run `npx skills add Hmbown/Wizards-of-the-Ghosts --skill heat-metal -a claude-code`. Or copy the skill folder (generated/openclaw/heat-metal in Hmbown/Wizards-of-the-Ghosts) into .claude/skills/heat-metal in your project. Claude Code loads it when a task matches its description.

How do I install Heat Metal in Codex?

Run `npx skills add Hmbown/Wizards-of-the-Ghosts --skill heat-metal -a codex`. Or copy the skill folder (generated/openclaw/heat-metal in Hmbown/Wizards-of-the-Ghosts) into .agents/skills/heat-metal in your project. Codex loads it when a task matches its description.

Can I use Heat Metal in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hmbown/Wizards-of-the-Ghosts --skill heat-metal -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/heat-metal, .gemini/skills/heat-metal, .github/skills/heat-metal and .opencode/skills/heat-metal in your project.

What does Heat Metal need to run?

SKILL.md names no scripts, command-line tools or credentials: Heat Metal is instructions for the agent only.

Does Heat Metal access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Heat Metal safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Heat Metal use?

Heat Metal is published under the CC0-1.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Heat Metal use?

About 633 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Heat Metal?

Skills that share tags, products or a category with Heat Metal: Add Hosted Key (simstudioai/sim, 30k stars), Upstash Ratelimit TS (upstash/ratelimit-js, 2k stars), Repo2skill (zhangyanxs/repo2skill, 246 stars) and Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Heat Metal?

Hmbown (a GitHub user) maintains it in Hmbown/Wizards-of-the-Ghosts, which has 110 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on April 5, 2026.

Source: Hmbown/Wizards-of-the-Ghosts on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.