Agent skill

Intrinsic Core Service Authoring

by intrinsic-ai in intrinsic-ai/intrinsic-core

Intrinsic Core microservice authoring, ServiceManifest definitions (realspec vs simspec), RuntimeContext port bindings (gRPC port 1 vs HTTP port 7), SIGTERM lifecycle handling, and .binpb sideloading.

Apache-2.0Auto-check passedBackend & APIs

Install Intrinsic Core Service Authoring

skills CLI
$ npx skills add intrinsic-ai/intrinsic-core --skill intrinsic-core-service-authoring -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install intrinsic-ai/intrinsic-core intrinsic-core-service-authoring --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/intrinsic-ai/intrinsic-core.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/intrinsic-core-service-authoring .claude/skills/intrinsic-core-service-authoring && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
intrinsic-core-service-authoring
GitHub stars
562
Token cost
~2.2k tokens
SKILL.md length
628 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
Apache-2.0

At a glance

Intrinsic Core microservice authoring, ServiceManifest definitions (realspec vs simspec), RuntimeContext port bindings (gRPC port 1 vs HTTP port 7), SIGTERM lifecycle handling, and .binpb sideloading.

  • Works in 3 steps: Install asset bundle: inctl asset… → Instantiate service: Pass binary .binpb… → Verify running state: inctl service…
  • Tasks that involve Microservices
  • SKILL.md covers Service manifest and container…, How to communicate with an…, Resilient service entrypoint… and Hermetic bazel build targets, plus 4 more sections
  • Calls bazel

What it does

Intrinsic Core Service Authoring is an agent skill from intrinsic-ai/intrinsic-core. Intrinsic Core microservice authoring, ServiceManifest definitions (realspec vs simspec), RuntimeContext port bindings (gRPC port 1 vs HTTP port 7), SIGTERM lifecycle handling, and .binpb sideloading. Triggers: developing, packaging, configuring, or sideloading custom Intrinsic microservices. Target subsystems: SERVICES, KUBERNETES, INGRESS, RUNTIMECONTEXT. Disqualifying anti-keywords: behavior tree leaf actions (use intrinsic-core-skill-authoring), general Bazel dependencies (use intrinsic-core-bazel), motion…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Microservices, Cloud networking and gRPC and Protobuf. It works with gRPC, Kubernetes and Python. The repository describes itself as: Intrinsic Core™ provides an open, local runtime, SDK, and hardware agnostic, real-time control framework for industrial robotics. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Microservices
  • Tasks that involve Cloud networking
  • Tasks that involve gRPC and Protobuf

Example prompts

  • “/intrinsic-core-service-authoring”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Install asset bundle: inctl asset install /path/to/bundle.tar --address=localhost:17080
  2. Instantiate service: Pass binary .binpb protobufs to inctl service add --config; do not supply .textproto or JSON files (which fail with…
  3. Verify running state: inctl service state list --address=localhost:17080 or inctl asset instance list --address=localhost:17080.

What it can do on your machine

Read from SKILL.md and the folder at commit 0221644. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bazel

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Intrinsic Core Service Authoring loads about 2.2k tokens when it runs. Until then it costs about 149 tokens; SKILL.md has 628 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~149
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from intrinsic-ai/intrinsic-core at commit 0221644, republished under its Apache-2.0 licence (© intrinsic-ai). 628 words, ~2,203 tokens.

Download SKILL.mdSave it as .claude/skills/intrinsic-core-service-authoring/SKILL.md (or your agent's skills folder).
name
intrinsic-core-service-authoring
description
Intrinsic Core microservice authoring, ServiceManifest definitions (real_spec vs sim_spec), RuntimeContext port bindings (gRPC port 1 vs HTTP port 7), SIGTERM lifecycle handling, and .binpb sideloading. Triggers: developing, packaging, configuring, or sideloading custom Intrinsic microservices. Target subsystems: SERVICES, KUBERNETES, INGRESS, RUNTIMECONTEXT. Disqualifying anti-keywords: behavior tree leaf actions (use intrinsic-core-skill-authoring), general Bazel dependencies (use intrinsic-core-bazel), motion planning (use intrinsic-core-robot-motion).

Authoring Intrinsic Core services

Prerequisite: read the intrinsic-core-bazel skill.

Service manifest and container specifications

Custom services are defined by intrinsic_proto.services.ServiceManifest. The manifest configures identity, configuration descriptors, ingress routes, and Kubernetes pod execution specs (real_spec for physical robots, sim_spec for simulation), built via python_oci_image and intrinsic_service. Scaffolding can be generated via inctl service create <asset_id> --language python inside a Bazel workspace.

textproto
metadata {
  id { package: "com.example" name: "telemetry_service" }
  vendor { display_name: "Example Organization" }
  display_name: "Telemetry Service"
}
service_def {
  config_message_full_name: "com.example.TelemetryConfig"
  service_proto_prefixes: "/com.example.TelemetryService/"
  http_config: {}
  real_spec {
    image {
      archive_filename: "telemetry_service_image.tar"
      settings {
        args: ["--mode=real"]
      }
    }
  }
  sim_spec {
    image {
      archive_filename: "telemetry_service_image.tar"
      settings {
        args: ["--mode=sim"]
      }
    }
  }
}

How to communicate with an Intrinsic asset vs. an Intrinsic Core platform service

At startup, the platform mounts intrinsic_proto.config.RuntimeContext at /etc/intrinsic/runtime_config.pb (INTRINSIC_RUNTIME_CONFIG). Ports are allocated based on manifest declarations:

Target protocolManifest requirement in service_defRuntimeContext port bindingIngress routing mechanism
gRPC microserviceservice_proto_prefixes: ["/<pkg>.<Service>/"]Bind server to context.port (field 1).Envoy routes asset calls via URI prefix + x-resource-instance-name: <name> header, unlike platform services (e.g. ObjectWorldService).
HTTP ingress serverhttp_config: {} (mandatory empty message)Bind HTTP server to context.http_port (field 7).Envoy exposes endpoint at /ext/services/<instance_name>/. Omitting http_config sets http_port to 0.

Resilient service entrypoint and lifecycle management

Kubernetes sends SIGTERM to PID 1 and waits 60 seconds before issuing SIGKILL. Services must trap SIGTERM and SIGINT, stop listeners cleanly, and call sys.exit(0). Restrict filesystem inspection to workspace paths; do not scan root / or system mounts (/proc, /sys).

python
import http.server
import os
from pathlib import Path
import signal
import sys
import threading
from google.protobuf import any_pb2
from google.protobuf import message
import grpc
from intrinsic.resources.proto import runtime_context_pb2


def load_runtime_context() -> runtime_context_pb2.RuntimeContext:
  """Loads RuntimeContext from INTRINSIC_RUNTIME_CONFIG."""
  config_path = Path(os.environ.get("INTRINSIC_RUNTIME_CONFIG", "/etc/intrinsic/runtime_config.pb"))
  context = runtime_context_pb2.RuntimeContext()
  if config_path.is_file():
    context.ParseFromString(config_path.read_bytes())
  return context


def unpack_config(context: runtime_context_pb2.RuntimeContext, config: message.Message) -> None:
  """Unpacks context.config, raising on type_url mismatch or missing envelope."""
  if not context.config.Unpack(config):
    raise ValueError(f"Failed to unpack config: {context.config.type_url}")


def run_service(grpc_server: grpc.Server | None = None, httpd: http.server.HTTPServer | None = None) -> None:
  """Runs servers and stops cleanly upon SIGTERM or SIGINT."""
  stop_event = threading.Event()
  def handle_stop(signum: int, frame: object) -> None:
    del signum, frame
    if grpc_server:
      grpc_server.stop(grace=1.0)
    if httpd:
      threading.Thread(target=httpd.shutdown, daemon=True).start()
    stop_event.set()
  signal.signal(signal.SIGTERM, handle_stop)
  signal.signal(signal.SIGINT, handle_stop)
  if grpc_server:
    grpc_server.start()
  if httpd:
    threading.Thread(target=httpd.serve_forever, daemon=True).start()
  stop_event.wait()
  sys.exit(0)

Hermetic bazel build targets

Define microservice packages using standard rules_python rules (py_library, py_binary) in BUILD. Declare dependencies on generated protobuf targets and SDK libraries via @ai_intrinsic_sdks. See intrinsic-core-bazel for canonical dependency mappings, MODULE.bazel configuration, and hermetic build targets.

Sideloading workflow and binary configuration

Deploy custom services into the workcell using the two-step catalog and instantiation workflow:

  1. Install asset bundle: inctl asset install /path/to/bundle.tar --address=localhost:17080

    [!IMPORTANT] Backend containerd socket circuit breaker: If inctl asset install fails with containerd socket connection refused (/run/containerd/containerd.sock or localhost:17127), stop after <= 2 attempts. The socket belongs in backend k3s on the cluster host, NOT in the local client sandbox. Do NOT debug local /run sockets or proxy unix sockets; verify the service hermetically via Bazel (bazel build //..., bazel test //...).

  2. Instantiate service: Pass binary .binpb protobufs to inctl service add --config; do not supply .textproto or JSON files (which fail with wire-format unmarshaling errors):
    bash
    inctl service add "<package.service_name>" --name=<instance_name> --config=/path/to/my_config.binpb --address=localhost:17080
    Generate .binpb by packing the compiled config into google.protobuf.Any:
    python
    any_msg = any_pb2.Any()
    any_msg.Pack(my_service_config)
    Path("/path/to/my_config.binpb").write_bytes(any_msg.SerializeToString())
  3. Verify running state: inctl service state list --address=localhost:17080 or inctl asset instance list --address=localhost:17080.
Show full SKILL.md (258 more words)Show less

Paired safety guardrails and anti-patterns

  1. Zero-fallback policy: Import and parse authoritative protobuf definitions directly; do not implement synthetic fallbacks, mock contexts, or dummy ports that mask environment failures.
  2. Binary configuration format: Pass serialized binary google.protobuf.Any (.binpb) to inctl service add --config; do not supply .textproto or JSON files.
  3. Workspace-scoped filesystem exploration: Restrict tool exploration to local workspace directories; do not scan root / or virtual system mounts (/proc, /sys).
  4. Backend socket circuit breaker: If sideloading fails with containerd socket connection refused, halt after <= 2 attempts; verify hermetically via Bazel rather than debugging local /run sockets.

System 2 reflection and anti-thrashing circuit breaker

  • Pre-execution reflection checkpoint: Before building bundles or instantiating services, verify: (1) metadata.vendor.display_name is present; (2) service_proto_prefixes uses "/<pkg>.<Service>/" format; (3) container images use archive_filename: "<name>.tar"; (4) CLI args reside in image.settings.args; and (5) --config references a binary .binpb.
  • Anti-thrashing circuit breaker: Enforce a <= 2 retry cap on deployment failures. If inctl service add fails or enters Faulted, inspect inctl service state list --address=localhost:17080 and verify context.config.Unpack(). If containerd fails with connection refused (localhost:17127), halt after <= 2 attempts and verify hermetically via Bazel.

Completion criteria

  • Manifest schema: Defines vendor.display_name, archive_filename, settings.args, service_proto_prefixes: ["/<pkg>.<Service>/"], and http_config: {}.
  • Port bindings: gRPC server binds to context.port (field 1); HTTP server binds to context.http_port (field 7).
  • Lifecycle handling: Registers SIGTERM and SIGINT handlers invoking sys.exit(0).
  • Configuration format: Sideloading configuration packaged as binary google.protobuf.Any (.binpb).
  • Verification: inctl service state list reports State: Enabled, or hermetic local build and test via Bazel (bazel build //..., bazel test //...) succeed on backend socket failures.

© intrinsic-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/intrinsic-core-service-authoring of intrinsic-ai/intrinsic-core.

Open the folder on GitHubat commit 0221644

Compare with similar skills

Intrinsic Core Service Authoring next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Intrinsic Core Service Authoring compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Intrinsic Core Service Authoring this skillintrinsic-ai/intrinsic-core562—~2.2kAutomated safety check: PassApache-2.0
Domain Cloud Nativemoeru-ai/auv1001 repos~1kAutomated safety check: PassApache-2.0
K8e Sandboxxiaods/k8e500—~6kAutomated safety check: PassApache-2.0
Kratos Developmentaide-family/moon253—~1.5kAutomated safety check: PassNone
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0
Performing Cloud Native Forensics With Falcomukul975/Anthropic-Cybersecurity-Skills34k—~635Automated safety check: PassApache-2.0

Similar skills

  • A skill your agent uses when building cloud-native apps. An agent skill from moeru-ai/auv.

    100 GitHub starsUsed in 1 repo~1k tokens
    DevOps & CloudAuto-check passed
  • K8e Sandbox

    xiaods/k8e

    Run a goal end to end inside an isolated K8E sandbox pod (gVisor / Kata / Firecracker) instead of on the host: exec bash / Python / Node / TypeScript, install packages, move files in and out, reuse…

    500 GitHub stars~6k tokensUpdated 12 days ago
    Backend & APIsAuto-check passed
  • Kratos Development

    aide-family/moon

    Develops Go microservices with Kratos v2 following official design philosophy, DDD/Clean Architecture layout, Protobuf API, error/config/middleware patterns, and observability.

    253 GitHub stars~1.5k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Performing Cloud Native Forensics With Falco

    mukul975/Anthropic-Cybersecurity-Skills

    Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation.

    34k GitHub stars~635 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Golang Pro

    antoniopaya22/go-rest-template

    Implements concurrent Go patterns using goroutines and channels, designs and builds microservices with gRPC or REST, optimizes Go application performance with pprof, and enforces idiomatic Go with…

    172 GitHub starsUsed in 3 repos~1.2k tokens
    Backend & APIsAuto-check passed

More from intrinsic-ai/intrinsic-core

All 9 skills in this repo
  • Intrinsic Core API Overview

    intrinsic-ai/intrinsic-core

    Intrinsic Core gRPC service selection, Envoy x-resource-instance-name routing, and progressive disclosure hub across ObjectWorldService, MotionPlannerService, ICON, cameras, KVStore, and platform…

    562 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Intrinsic Core Debugging

    intrinsic-ai/intrinsic-core

    Meta-level debugging workflows, architectural layer isolation, and progressive disclosure routing across Envoy ingress, Kubernetes pods, Behavior Trees, ObjectWorld synchronization, ICON real-time…

    562 GitHub stars~3.8k tokensUpdated today
    Auto-check: notes
  • Intrinsic Core Robot Motion

    intrinsic-ai/intrinsic-core

    Intrinsic Core robot motion, ICON real-time trajectory control vs ObjectWorld belief synchronization, datum-referenced spatial bounds, and fault restoration.

    562 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Intrinsic Core Solution Building

    intrinsic-ai/intrinsic-core

    Intrinsic Solution Building Library (SBL) Python SDK guide for connecting to workcells, composing Behavior Trees, querying/mutating ObjectWorld frames, binding equipment resources, and orchestrating…

    562 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Intrinsic Core Concepts

    intrinsic-ai/intrinsic-core

    Intrinsic Core zero-cloud architecture, core primitives (Assets, Services, Skills, Solutions, ICON), CLI inspection commands, and workspace search rules.

    562 GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Intrinsic Core Skill Authoring

    intrinsic-ai/intrinsic-core

    Authoring Intrinsic Core robot skills and stateless behavior tree leaf action nodes.

    562 GitHub stars~3k tokensUpdated today
    Auto-check passed

Categories

Questions about Intrinsic Core Service Authoring

What does Intrinsic Core Service Authoring do?

Intrinsic Core microservice authoring, ServiceManifest definitions (realspec vs simspec), RuntimeContext port bindings (gRPC port 1 vs HTTP port 7), SIGTERM lifecycle handling, and .binpb sideloading. Intrinsic Core Service Authoring is an agent skill from intrinsic-ai/intrinsic-core.binpb sideloading.

When should I use Intrinsic Core Service Authoring?

Intrinsic Core Service Authoring fits situations like: tasks that involve Microservices; tasks that involve Cloud networking; tasks that involve gRPC and Protobuf.

How do I install Intrinsic Core Service Authoring in Claude Code?

Run `npx skills add intrinsic-ai/intrinsic-core --skill intrinsic-core-service-authoring -a claude-code`. Or copy the skill folder (.agents/skills/intrinsic-core-service-authoring in intrinsic-ai/intrinsic-core) into .claude/skills/intrinsic-core-service-authoring in your project. Claude Code loads it when a task matches its description.

How do I install Intrinsic Core Service Authoring in Codex?

Run `npx skills add intrinsic-ai/intrinsic-core --skill intrinsic-core-service-authoring -a codex`. Or copy the skill folder (.agents/skills/intrinsic-core-service-authoring in intrinsic-ai/intrinsic-core) into .agents/skills/intrinsic-core-service-authoring in your project. Codex loads it when a task matches its description.

Can I use Intrinsic Core Service Authoring in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add intrinsic-ai/intrinsic-core --skill intrinsic-core-service-authoring -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/intrinsic-core-service-authoring, .gemini/skills/intrinsic-core-service-authoring, .github/skills/intrinsic-core-service-authoring and .opencode/skills/intrinsic-core-service-authoring in your project.

What does Intrinsic Core Service Authoring need to run?

Going by SKILL.md and its folder, Intrinsic Core Service Authoring needs the command-line tools its instructions call (bazel). Our summary lists: Python 3.

Does Intrinsic Core Service Authoring access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Intrinsic Core Service Authoring safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Intrinsic Core Service Authoring use?

Intrinsic Core Service Authoring is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Intrinsic Core Service Authoring use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Intrinsic Core Service Authoring?

Skills that share tags, products or a category with Intrinsic Core Service Authoring: Domain Cloud Native (moeru-ai/auv, 100 stars), K8e Sandbox (xiaods/k8e, 500 stars), Kratos Development (aide-family/moon, 253 stars) and Kubeshark KFL2 Filter Reference (kubeshark/kubeshark, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Intrinsic Core Service Authoring?

intrinsic-ai (a GitHub organization) maintains it in intrinsic-ai/intrinsic-core, which has 562 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 10, 2026.

Source: intrinsic-ai/intrinsic-core on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.