Domain Cloud Native
moeru-ai/auv
A skill your agent uses when building cloud-native apps. An agent skill from moeru-ai/auv.
Intrinsic Core microservice authoring, ServiceManifest definitions (realspec vs simspec), RuntimeContext port bindings (gRPC port 1 vs HTTP port 7), SIGTERM lifecycle handling, and .binpb sideloading.
$ npx skills add intrinsic-ai/intrinsic-core --skill intrinsic-core-service-authoring -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install intrinsic-ai/intrinsic-core intrinsic-core-service-authoring --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/intrinsic-ai/intrinsic-core.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/intrinsic-core-service-authoring .claude/skills/intrinsic-core-service-authoring && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "intrinsic-core-service-authoring" agent skill from https://github.com/intrinsic-ai/intrinsic-core/tree/main/.agents/skills/intrinsic-core-service-authoring into .claude/skills/intrinsic-core-service-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "intrinsic-core-service-authoring", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/intrinsic-ai/intrinsic-core/tree/main/.agents/skills/intrinsic-core-service-authoringType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add intrinsic-ai/intrinsic-core --skill intrinsic-core-service-authoring -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install intrinsic-ai/intrinsic-core intrinsic-core-service-authoring --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/intrinsic-ai/intrinsic-core.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/intrinsic-core-service-authoring .agents/skills/intrinsic-core-service-authoring && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "intrinsic-core-service-authoring" agent skill from https://github.com/intrinsic-ai/intrinsic-core/tree/main/.agents/skills/intrinsic-core-service-authoring into .agents/skills/intrinsic-core-service-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "intrinsic-core-service-authoring", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add intrinsic-ai/intrinsic-core --skill intrinsic-core-service-authoring -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install intrinsic-ai/intrinsic-core intrinsic-core-service-authoring --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/intrinsic-ai/intrinsic-core.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/intrinsic-core-service-authoring .cursor/skills/intrinsic-core-service-authoring && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "intrinsic-core-service-authoring" agent skill from https://github.com/intrinsic-ai/intrinsic-core/tree/main/.agents/skills/intrinsic-core-service-authoring into .cursor/skills/intrinsic-core-service-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "intrinsic-core-service-authoring", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/intrinsic-ai/intrinsic-core.git --path .agents/skills/intrinsic-core-service-authoring--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add intrinsic-ai/intrinsic-core --skill intrinsic-core-service-authoring -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install intrinsic-ai/intrinsic-core intrinsic-core-service-authoring --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/intrinsic-ai/intrinsic-core.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/intrinsic-core-service-authoring .gemini/skills/intrinsic-core-service-authoring && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "intrinsic-core-service-authoring" agent skill from https://github.com/intrinsic-ai/intrinsic-core/tree/main/.agents/skills/intrinsic-core-service-authoring into .gemini/skills/intrinsic-core-service-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "intrinsic-core-service-authoring", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install intrinsic-ai/intrinsic-core intrinsic-core-service-authoringInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add intrinsic-ai/intrinsic-core --skill intrinsic-core-service-authoring -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/intrinsic-ai/intrinsic-core.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/intrinsic-core-service-authoring .github/skills/intrinsic-core-service-authoring && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "intrinsic-core-service-authoring" agent skill from https://github.com/intrinsic-ai/intrinsic-core/tree/main/.agents/skills/intrinsic-core-service-authoring into .github/skills/intrinsic-core-service-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "intrinsic-core-service-authoring", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add intrinsic-ai/intrinsic-core --skill intrinsic-core-service-authoring -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install intrinsic-ai/intrinsic-core intrinsic-core-service-authoring --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/intrinsic-ai/intrinsic-core.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/intrinsic-core-service-authoring .opencode/skills/intrinsic-core-service-authoring && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "intrinsic-core-service-authoring" agent skill from https://github.com/intrinsic-ai/intrinsic-core/tree/main/.agents/skills/intrinsic-core-service-authoring into .opencode/skills/intrinsic-core-service-authoring/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "intrinsic-core-service-authoring", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
intrinsic-core-service-authoringIntrinsic Core microservice authoring, ServiceManifest definitions (realspec vs simspec), RuntimeContext port bindings (gRPC port 1 vs HTTP port 7), SIGTERM lifecycle handling, and .binpb sideloading.
Intrinsic Core Service Authoring is an agent skill from intrinsic-ai/intrinsic-core. Intrinsic Core microservice authoring, ServiceManifest definitions (realspec vs simspec), RuntimeContext port bindings (gRPC port 1 vs HTTP port 7), SIGTERM lifecycle handling, and .binpb sideloading. Triggers: developing, packaging, configuring, or sideloading custom Intrinsic microservices. Target subsystems: SERVICES, KUBERNETES, INGRESS, RUNTIMECONTEXT. Disqualifying anti-keywords: behavior tree leaf actions (use intrinsic-core-skill-authoring), general Bazel dependencies (use intrinsic-core-bazel), motion…
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Microservices, Cloud networking and gRPC and Protobuf. It works with gRPC, Kubernetes and Python. The repository describes itself as: Intrinsic Core™ provides an open, local runtime, SDK, and hardware agnostic, real-time control framework for industrial robotics. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 0221644. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bazelFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Intrinsic Core Service Authoring loads about 2.2k tokens when it runs. Until then it costs about 149 tokens; SKILL.md has 628 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from intrinsic-ai/intrinsic-core at commit 0221644, republished under its Apache-2.0 licence (© intrinsic-ai). 628 words, ~2,203 tokens.
.claude/skills/intrinsic-core-service-authoring/SKILL.md (or your agent's skills folder).Prerequisite: read the intrinsic-core-bazel skill.
Custom services are defined by intrinsic_proto.services.ServiceManifest. The manifest configures identity, configuration descriptors, ingress routes, and Kubernetes pod execution specs (real_spec for physical robots, sim_spec for simulation), built via python_oci_image and intrinsic_service. Scaffolding can be generated via inctl service create <asset_id> --language python inside a Bazel workspace.
metadata {
id { package: "com.example" name: "telemetry_service" }
vendor { display_name: "Example Organization" }
display_name: "Telemetry Service"
}
service_def {
config_message_full_name: "com.example.TelemetryConfig"
service_proto_prefixes: "/com.example.TelemetryService/"
http_config: {}
real_spec {
image {
archive_filename: "telemetry_service_image.tar"
settings {
args: ["--mode=real"]
}
}
}
sim_spec {
image {
archive_filename: "telemetry_service_image.tar"
settings {
args: ["--mode=sim"]
}
}
}
}At startup, the platform mounts intrinsic_proto.config.RuntimeContext at /etc/intrinsic/runtime_config.pb (INTRINSIC_RUNTIME_CONFIG). Ports are allocated based on manifest declarations:
| Target protocol | Manifest requirement in service_def | RuntimeContext port binding | Ingress routing mechanism |
|---|---|---|---|
| gRPC microservice | service_proto_prefixes: ["/<pkg>.<Service>/"] | Bind server to context.port (field 1). | Envoy routes asset calls via URI prefix + x-resource-instance-name: <name> header, unlike platform services (e.g. ObjectWorldService). |
| HTTP ingress server | http_config: {} (mandatory empty message) | Bind HTTP server to context.http_port (field 7). | Envoy exposes endpoint at /ext/services/<instance_name>/. Omitting http_config sets http_port to 0. |
Kubernetes sends SIGTERM to PID 1 and waits 60 seconds before issuing SIGKILL. Services must trap SIGTERM and SIGINT, stop listeners cleanly, and call sys.exit(0). Restrict filesystem inspection to workspace paths; do not scan root / or system mounts (/proc, /sys).
import http.server
import os
from pathlib import Path
import signal
import sys
import threading
from google.protobuf import any_pb2
from google.protobuf import message
import grpc
from intrinsic.resources.proto import runtime_context_pb2
def load_runtime_context() -> runtime_context_pb2.RuntimeContext:
"""Loads RuntimeContext from INTRINSIC_RUNTIME_CONFIG."""
config_path = Path(os.environ.get("INTRINSIC_RUNTIME_CONFIG", "/etc/intrinsic/runtime_config.pb"))
context = runtime_context_pb2.RuntimeContext()
if config_path.is_file():
context.ParseFromString(config_path.read_bytes())
return context
def unpack_config(context: runtime_context_pb2.RuntimeContext, config: message.Message) -> None:
"""Unpacks context.config, raising on type_url mismatch or missing envelope."""
if not context.config.Unpack(config):
raise ValueError(f"Failed to unpack config: {context.config.type_url}")
def run_service(grpc_server: grpc.Server | None = None, httpd: http.server.HTTPServer | None = None) -> None:
"""Runs servers and stops cleanly upon SIGTERM or SIGINT."""
stop_event = threading.Event()
def handle_stop(signum: int, frame: object) -> None:
del signum, frame
if grpc_server:
grpc_server.stop(grace=1.0)
if httpd:
threading.Thread(target=httpd.shutdown, daemon=True).start()
stop_event.set()
signal.signal(signal.SIGTERM, handle_stop)
signal.signal(signal.SIGINT, handle_stop)
if grpc_server:
grpc_server.start()
if httpd:
threading.Thread(target=httpd.serve_forever, daemon=True).start()
stop_event.wait()
sys.exit(0)bazel build targetsDefine microservice packages using standard rules_python rules (py_library, py_binary) in BUILD. Declare dependencies on generated protobuf targets and SDK libraries via @ai_intrinsic_sdks. See intrinsic-core-bazel for canonical dependency mappings, MODULE.bazel configuration, and hermetic build targets.
Deploy custom services into the workcell using the two-step catalog and instantiation workflow:
inctl asset install /path/to/bundle.tar --address=localhost:17080[!IMPORTANT] Backend containerd socket circuit breaker: If
inctl asset installfails with containerd socket connection refused (/run/containerd/containerd.sockorlocalhost:17127), stop after <= 2 attempts. The socket belongs in backendk3son the cluster host, NOT in the local client sandbox. Do NOT debug local/runsockets or proxy unix sockets; verify the service hermetically via Bazel (bazel build //...,bazel test //...).
.binpb protobufs to inctl service add --config; do not supply .textproto or JSON files (which fail with wire-format unmarshaling errors):inctl service add "<package.service_name>" --name=<instance_name> --config=/path/to/my_config.binpb --address=localhost:17080.binpb by packing the compiled config into google.protobuf.Any:any_msg = any_pb2.Any()
any_msg.Pack(my_service_config)
Path("/path/to/my_config.binpb").write_bytes(any_msg.SerializeToString())inctl service state list --address=localhost:17080 or inctl asset instance list --address=localhost:17080.google.protobuf.Any (.binpb) to inctl service add --config; do not supply .textproto or JSON files./ or virtual system mounts (/proc, /sys)./run sockets.metadata.vendor.display_name is present; (2) service_proto_prefixes uses "/<pkg>.<Service>/" format; (3) container images use archive_filename: "<name>.tar"; (4) CLI args reside in image.settings.args; and (5) --config references a binary .binpb.inctl service add fails or enters Faulted, inspect inctl service state list --address=localhost:17080 and verify context.config.Unpack(). If containerd fails with connection refused (localhost:17127), halt after <= 2 attempts and verify hermetically via Bazel.vendor.display_name, archive_filename, settings.args, service_proto_prefixes: ["/<pkg>.<Service>/"], and http_config: {}.context.port (field 1); HTTP server binds to context.http_port (field 7).SIGTERM and SIGINT handlers invoking sys.exit(0).google.protobuf.Any (.binpb).inctl service state list reports State: Enabled, or hermetic local build and test via Bazel (bazel build //..., bazel test //...) succeed on backend socket failures.© intrinsic-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/intrinsic-core-service-authoring of intrinsic-ai/intrinsic-core.
Open the folder on GitHubat commit 0221644
Intrinsic Core Service Authoring next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Intrinsic Core Service Authoring this skillintrinsic-ai/intrinsic-core | 562 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Domain Cloud Nativemoeru-ai/auv | 100 | 1 repos | ~1k | Automated safety check: Pass | Apache-2.0 | |
| K8e Sandboxxiaods/k8e | 500 | — | ~6k | Automated safety check: Pass | Apache-2.0 | |
| Kratos Developmentaide-family/moon | 253 | — | ~1.5k | Automated safety check: Pass | None | |
| Kubeshark KFL2 Filter Referencekubeshark/kubeshark | 12k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| Performing Cloud Native Forensics With Falcomukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~635 | Automated safety check: Pass | Apache-2.0 |
moeru-ai/auv
A skill your agent uses when building cloud-native apps. An agent skill from moeru-ai/auv.
xiaods/k8e
Run a goal end to end inside an isolated K8E sandbox pod (gVisor / Kata / Firecracker) instead of on the host: exec bash / Python / Node / TypeScript, install packages, move files in and out, reuse…
aide-family/moon
Develops Go microservices with Kratos v2 following official design philosophy, DDD/Clean Architecture layout, Protobuf API, error/config/middleware patterns, and observability.
kubeshark/kubeshark
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
mukul975/Anthropic-Cybersecurity-Skills
Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation.
antoniopaya22/go-rest-template
Implements concurrent Go patterns using goroutines and channels, designs and builds microservices with gRPC or REST, optimizes Go application performance with pprof, and enforces idiomatic Go with…
intrinsic-ai/intrinsic-core
Intrinsic Core gRPC service selection, Envoy x-resource-instance-name routing, and progressive disclosure hub across ObjectWorldService, MotionPlannerService, ICON, cameras, KVStore, and platform…
intrinsic-ai/intrinsic-core
Meta-level debugging workflows, architectural layer isolation, and progressive disclosure routing across Envoy ingress, Kubernetes pods, Behavior Trees, ObjectWorld synchronization, ICON real-time…
intrinsic-ai/intrinsic-core
Intrinsic Core robot motion, ICON real-time trajectory control vs ObjectWorld belief synchronization, datum-referenced spatial bounds, and fault restoration.
intrinsic-ai/intrinsic-core
Intrinsic Solution Building Library (SBL) Python SDK guide for connecting to workcells, composing Behavior Trees, querying/mutating ObjectWorld frames, binding equipment resources, and orchestrating…
intrinsic-ai/intrinsic-core
Intrinsic Core zero-cloud architecture, core primitives (Assets, Services, Skills, Solutions, ICON), CLI inspection commands, and workspace search rules.
intrinsic-ai/intrinsic-core
Authoring Intrinsic Core robot skills and stateless behavior tree leaf action nodes.
Works with
Categories
Intrinsic Core microservice authoring, ServiceManifest definitions (realspec vs simspec), RuntimeContext port bindings (gRPC port 1 vs HTTP port 7), SIGTERM lifecycle handling, and .binpb sideloading. Intrinsic Core Service Authoring is an agent skill from intrinsic-ai/intrinsic-core.binpb sideloading.
Intrinsic Core Service Authoring fits situations like: tasks that involve Microservices; tasks that involve Cloud networking; tasks that involve gRPC and Protobuf.
Run `npx skills add intrinsic-ai/intrinsic-core --skill intrinsic-core-service-authoring -a claude-code`. Or copy the skill folder (.agents/skills/intrinsic-core-service-authoring in intrinsic-ai/intrinsic-core) into .claude/skills/intrinsic-core-service-authoring in your project. Claude Code loads it when a task matches its description.
Run `npx skills add intrinsic-ai/intrinsic-core --skill intrinsic-core-service-authoring -a codex`. Or copy the skill folder (.agents/skills/intrinsic-core-service-authoring in intrinsic-ai/intrinsic-core) into .agents/skills/intrinsic-core-service-authoring in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add intrinsic-ai/intrinsic-core --skill intrinsic-core-service-authoring -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/intrinsic-core-service-authoring, .gemini/skills/intrinsic-core-service-authoring, .github/skills/intrinsic-core-service-authoring and .opencode/skills/intrinsic-core-service-authoring in your project.
Going by SKILL.md and its folder, Intrinsic Core Service Authoring needs the command-line tools its instructions call (bazel). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Intrinsic Core Service Authoring is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Intrinsic Core Service Authoring: Domain Cloud Native (moeru-ai/auv, 100 stars), K8e Sandbox (xiaods/k8e, 500 stars), Kratos Development (aide-family/moon, 253 stars) and Kubeshark KFL2 Filter Reference (kubeshark/kubeshark, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
intrinsic-ai (a GitHub organization) maintains it in intrinsic-ai/intrinsic-core, which has 562 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 10, 2026.
Source: intrinsic-ai/intrinsic-core on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.