Agent skill

Miro

by HybridAIOne in HybridAIOne/hybridclaw

Discover Miro boards, read board items for planning and summaries, prepare guarded board writes, and run Enterprise board export workflows through SecretRef-backed API requests.

MITAuto-check passedBackend & APIs

Install Miro

skills CLI
$ npx skills add HybridAIOne/hybridclaw --skill miro -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HybridAIOne/hybridclaw miro --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HybridAIOne/hybridclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/miro .claude/skills/miro && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
miro
GitHub stars
159
Token cost
~3.5k tokens
SKILL.md length
942 words
Files
3
Skills in repo
72
Repo updated
First seen
Licence
MIT

At a glance

Discover Miro boards, read board items for planning and summaries, prepare guarded board writes, and run Enterprise board export workflows through SecretRef-backed API requests.

  • Works in 3 steps: Browser admin: open the active… → Browser /chat or TUI fallback → Local console fallback
  • Backend & APIs work in your project
  • SKILL.md covers Scope, Credential Rules, Default Workflow and Command Contract, plus 2 more sections
  • Runs JavaScript scripts from its folder; calls node; needs MIRO_ACCESS_TOKEN and MIRO_DISCOVERY_ACCESS_TOKEN

What it does

Miro is an agent skill from HybridAIOne/hybridclaw. Discover Miro boards, read board items for planning and summaries, prepare guarded board writes, and run Enterprise board export workflows through SecretRef-backed API requests.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files.

It sits in Backend & APIs. The repository describes itself as: Enterprise-ready self-hosted AI assistant runtime with sandboxed execution, secure credentials, approvals, and memory. The licence is MIT.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “/miro”

Requirements

  • A credential in MIRO_ACCESS_TOKEN
  • A credential in MIRO_DISCOVERY_ACCESS_TOKEN

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Browser admin: open the active HybridClaw admin URL ending in /admin/secrets and set the
  2. Browser /chat or TUI fallback
  3. Local console fallback

What it can do on your machine

Read from SKILL.md and the folder at commit 8162701. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developers.miro.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • MIRO_ACCESS_TOKEN
    • MIRO_DISCOVERY_ACCESS_TOKEN
    • MIRO_CLIENT_SECRET
    • MIRO_REFRESH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Miro loads about 3.5k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 942 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HybridAIOne/hybridclaw at commit 8162701, republished under its MIT licence (© HybridAIOne). 942 words, ~3,533 tokens.

Download SKILL.mdSave it as .claude/skills/miro/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
miro
description
Discover Miro boards, read board items for planning and summaries, prepare guarded board writes, and run Enterprise board export workflows through SecretRef-backed API requests.
user-invocable
true
requires.bins
node

Miro

Use this skill for Miro board work through the REST API: board discovery, metadata lookup, board item reads for summaries or planning, guarded creation and updates for common board items, and Enterprise board export jobs when the operator has Discovery access.

Scope

  • list accessible boards and fetch board metadata
  • read board items by type for audit-safe context capture and summaries
  • fetch specific sticky note, text, shape, connector, and frame items
  • create or update sticky notes, text items, shapes, connectors, and frames only after preview and explicit operator grant
  • create and inspect Enterprise board export jobs, including result/task lookup and export-link creation where the API supports it
  • download completed Enterprise export links into local workspace artifacts
  • classify missing credential, upstream auth/scope, rate-limit, and API errors
  • refuse deletes and permission/share changes in this v1 skill

Credential Rules

Store Miro tokens in HybridClaw runtime secrets. Never paste a raw Miro token into the prompt, a helper argument, a shell environment dump, or a log.

Recommended setup order:

  1. Browser admin: open the active HybridClaw admin URL ending in /admin/secrets and set the needed MIRO_* secrets.
  2. Browser /chat or TUI fallback: /secret set MIRO_ACCESS_TOKEN "<oauth-or-access-token>" plus any needed Discovery or OAuth client secrets.
  3. Local console fallback:
bash
hybridclaw secret set MIRO_ACCESS_TOKEN "<oauth-or-access-token>"
hybridclaw secret set MIRO_DISCOVERY_ACCESS_TOKEN "<enterprise-discovery-token>"
hybridclaw secret set MIRO_CLIENT_ID "<miro-client-id>"
hybridclaw secret set MIRO_CLIENT_SECRET "<miro-client-secret>"

Use MIRO_ACCESS_TOKEN for normal board APIs. Required Miro scopes depend on the operation:

  • board discovery and item reads: boards:read
  • sticky notes, text, shapes, connectors, and frames: boards:write

Use MIRO_DISCOVERY_ACCESS_TOKEN only for Enterprise board export APIs that require boards:export. Enterprise export requires a Miro Enterprise plan, Company Admin role, and enabled eDiscovery.

For Miro OAuth app authorization, use the helper to build the authorize URL, store the callback code as MIRO_OAUTH_CODE, and then exchange the code through the gateway. The exchange request uses <secret:MIRO_CLIENT_ID>, <secret:MIRO_CLIENT_SECRET>, and <secret:MIRO_OAUTH_CODE> placeholders and captures access_token into MIRO_ACCESS_TOKEN and refresh_token into MIRO_REFRESH_TOKEN with captureResponseFields.

Do not try to verify either secret with bash, environment inspection, or by asking the model whether a secret exists. The model cannot inspect the gateway secret store. If the operator says the secret was set, build the helper request and pass the httpRequest object to the built-in http_request tool. Only say a secret is missing if the gateway or helper error explicitly says MIRO_ACCESS_TOKEN or MIRO_DISCOVERY_ACCESS_TOKEN is missing, unavailable, not set, or unresolved.

Default Workflow

  1. Start with list-boards unless the board id is already known.
  2. Fetch board metadata with get-board before summarizing ownership, sharing, or last-modified context.
  3. Read board items with list-items, filtered by --type when the task is about a specific surface such as sticky notes, text, shapes, connectors, or frames.
  4. For large boards, page with the returned cursor and keep summaries bounded to relevant item types and regions named by the operator.
  5. For any board write, run approval-plan or --request first, show the preview, then wait for explicit approval.
  6. Pass --operator-grant approve-miro-board-write only after approval for the exact board id, operation, and payload.
  7. For Enterprise exports, use approval-plan export-create before creating an export job and approval-plan export-link before minting a download link. Pass --operator-grant approve-miro-export only after approval for the exact org id, board id or task id, and export format.
  8. After export-results returns an exportLink, use capture-export to save the ZIP/PDF/HTML/SVG export under .generated-miro and return the helper's artifacts[] output.
  9. Do not delete items, delete boards, or change board permissions through this skill.
Show full SKILL.md (383 more words)Show less

Command Contract

Run the colocated helper with Node:

bash
node skills/miro/miro.cjs --help

Plan a request without contacting Miro:

bash
node skills/miro/miro.cjs --format json plan "Summarize sticky notes on this Miro board"

Build the OAuth authorize URL:

bash
node skills/miro/miro.cjs --format json oauth authorize-url \
  --client-id "<miro-client-id>" \
  --redirect-uri "http://127.0.0.1:1455/oauth2/callback" \
  --scope boards:read \
  --scope boards:write

After the operator approves the URL and stores the callback code with hybridclaw secret set MIRO_OAUTH_CODE "<code>", exchange it without exposing the code or resulting tokens:

bash
node skills/miro/miro.cjs --format json http-request oauth-exchange-code \
  --redirect-uri "http://127.0.0.1:1455/oauth2/callback"

For expiring-token apps, refresh tokens through the same secret-capture path:

bash
node skills/miro/miro.cjs --format json http-request oauth-refresh-token

Build read requests:

bash
node skills/miro/miro.cjs --format json http-request list-boards \
  --query roadmap \
  --limit 20

node skills/miro/miro.cjs --format json http-request get-board \
  --board-id uXjVOD50NUI=

node skills/miro/miro.cjs --format json http-request list-items \
  --board-id uXjVOD50NUI= \
  --type sticky_note \
  --limit 50

node skills/miro/miro.cjs --format json http-request get-item \
  --board-id uXjVOD50NUI= \
  --type sticky_note \
  --item-id "3458764511234567890"

The helper prints { "command": "http-request", "httpRequest": { ... } }. Pass only the httpRequest value to the built-in http_request tool for live API calls. The helper sets bearerSecretName so the gateway injects the token server-side.

Preview and approve board writes:

bash
node skills/miro/miro.cjs --format json approval-plan create-sticky-note \
  --board-id uXjVOD50NUI= \
  --content "Decision: proceed with option B" \
  --x 0 \
  --y 0

node skills/miro/miro.cjs --format json http-request create-sticky-note \
  --board-id uXjVOD50NUI= \
  --content "Decision: proceed with option B" \
  --x 0 \
  --y 0 \
  --operator-grant approve-miro-board-write

Supported write operations:

  • create-sticky-note, update-sticky-note
  • create-text, update-text
  • create-shape, update-shape
  • create-connector, update-connector
  • create-frame, update-frame

Use structured flags for common payload fields: --content, --title, --shape, --x, --y, --width, --height, --parent-id, --style-json, --position-json, --geometry-json, and --data-json. For connector creation, provide --start-item-id and --end-item-id; optional --start-snap-to, --end-snap-to, --shape, --captions-json, and --style-json map to the Miro connector request body.

Use --payload-json only when the operator has supplied a known-good Miro REST payload shape that the structured flags cannot represent. Still run approval-plan first and keep the payload minimal.

Enterprise export workflow:

bash
node skills/miro/miro.cjs --format json approval-plan export-create \
  --org-id 3074457345821141000 \
  --board-id uXjVOD50NUI= \
  --request-id 92343229-c532-446d-b8cb-2f155bedb807 \
  --board-format PDF

node skills/miro/miro.cjs --format json http-request export-status \
  --org-id 3074457345821141000 \
  --job-id 92343229-c532-446d-b8cb-2f155bedb807

node skills/miro/miro.cjs --format json http-request export-results \
  --org-id 3074457345821141000 \
  --job-id 92343229-c532-446d-b8cb-2f155bedb807

node skills/miro/miro.cjs --format json capture-export \
  --export-url "https://..." \
  --filename "miro-board-export.zip"

Error Interpretation

  • Gateway errors saying MIRO_ACCESS_TOKEN is missing, not set, unavailable, or unresolved: ask the operator to set the runtime secret in the same HybridClaw runtime, then retry in a fresh agent runtime if the gateway was already running.
  • Gateway errors saying MIRO_DISCOVERY_ACCESS_TOKEN is missing: Enterprise export APIs cannot run until a Discovery token is stored.
  • Gateway errors saying MIRO_CLIENT_ID, MIRO_CLIENT_SECRET, MIRO_OAUTH_CODE, or MIRO_REFRESH_TOKEN is missing: the OAuth setup step has not stored the required secret in the active runtime.
  • Gateway errors saying the secret is blocked by policy: report a policy/runtime configuration problem; do not ask the operator to set the same secret again.
  • Miro 401 or 403 responses: the gateway injected a token, but Miro rejected it or the token lacks the needed board, organization, Enterprise, or OAuth scope.
  • Miro 429 responses: back off and preserve cursor/request-id values for idempotent retries.
  • Miro 5xx responses: report the upstream failure and retry only if the user asks and the operation is idempotent.

The helper can classify common failures offline:

bash
node skills/miro/miro.cjs --format json explain-error \
  --status 403 \
  --message "insufficient scope"

References

© HybridAIOne, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in skills/miro of HybridAIOne/hybridclaw.

  • SKILL.md
  • index.cjs
  • miro.cjs

Open the folder on GitHubat commit 8162701

Compare with similar skills

Miro next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Miro compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Miro this skillHybridAIOne/hybridclaw159—~3.5kAutomated safety check: PassMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api44k1 repos~717Automated safety check: PassLGPL-3.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Obsidian BasesAtmosphere/atmosphere3.8k22 repos~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    44k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Obsidian Bases

    Atmosphere/atmosphere

    Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.

    3.8k GitHub starsUsed in 22 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from HybridAIOne/hybridclaw

All 72 skills in this repo
  • Hermes3000 Writing

    HybridAIOne/hybridclaw

    Use Hermes3000 to plan, draft, revise, save, check consistency, and export long-form manuscripts through the Hermes3000 AI writing portal API.

    159 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Manim Video

    HybridAIOne/hybridclaw

    Plan, script, render, and stitch Manim Community Edition videos in Python.

    159 GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Skill Creator

    HybridAIOne/hybridclaw

    Create and update SKILL.md-based skills with strong trigger metadata, lean docs, and reliable init, validate, package, and publish workflows.

    159 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • XLSX

    HybridAIOne/hybridclaw

    Create, edit, inspect, and analyze .xlsx spreadsheets and Excel workbooks.

    159 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Excalidraw

    HybridAIOne/hybridclaw

    Create and revise editable .excalidraw diagrams as Excalidraw JSON for architecture diagrams, flowcharts, sequence diagrams, concept maps, and other hand-drawn explainers.

    159 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Google Ads

    HybridAIOne/hybridclaw

    Manage Google Ads accounts with safe GAQL reporting, campaign planning, guarded mutations, and gateway-proxied REST API calls.

    159 GitHub stars~4k tokensUpdated today
    Auto-check passed

Categories

Questions about Miro

What does Miro do?

Discover Miro boards, read board items for planning and summaries, prepare guarded board writes, and run Enterprise board export workflows through SecretRef-backed API requests. Miro is an agent skill from HybridAIOne/hybridclaw. Discover Miro boards, read board items for planning and summaries, prepare guarded board writes, and run Enterprise board export workflows through SecretRef-backed API requests.

When should I use Miro?

Miro fits situations like: backend & APIs work in your project.

How do I install Miro in Claude Code?

Run `npx skills add HybridAIOne/hybridclaw --skill miro -a claude-code`. Or copy the skill folder (skills/miro in HybridAIOne/hybridclaw) into .claude/skills/miro in your project. Claude Code loads it when a task matches its description.

How do I install Miro in Codex?

Run `npx skills add HybridAIOne/hybridclaw --skill miro -a codex`. Or copy the skill folder (skills/miro in HybridAIOne/hybridclaw) into .agents/skills/miro in your project. Codex loads it when a task matches its description.

Can I use Miro in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HybridAIOne/hybridclaw --skill miro -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/miro, .gemini/skills/miro, .github/skills/miro and .opencode/skills/miro in your project.

What does Miro need to run?

Going by SKILL.md and its folder, Miro needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node) and credentials named MIRO_ACCESS_TOKEN, MIRO_DISCOVERY_ACCESS_TOKEN, MIRO_CLIENT_SECRET and MIRO_REFRESH_TOKEN. Our summary lists: A credential in MIRO_ACCESS_TOKEN; A credential in MIRO_DISCOVERY_ACCESS_TOKEN.

Does Miro access the network?

SKILL.md names 1 domain. As links in the text: developers.miro.com. This is read from the text; nothing was executed.

Is Miro safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Miro use?

Miro is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Miro use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Miro?

Skills that share tags, products or a category with Miro: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 44k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Miro?

HybridAIOne (a GitHub organization) maintains it in HybridAIOne/hybridclaw, which has 159 GitHub stars. The repository holds 72 skills in this directory. The repository was last updated on October 9, 2026.

Source: HybridAIOne/hybridclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.