Agent skill

Apex Vendor Prompting

by jonathan-vella in jonathan-vella/apex

ANALYSIS SKILL — Manual-only audit of Anthropic Claude Opus 5.5 / Sonnet 5.5 and OpenAI GPT-6 / GPT-5.6 prompting guidance and APEX conventions.

MITAuto-check passedDevOps & Cloud

Install Apex Vendor Prompting

skills CLI
$ npx skills add jonathan-vella/apex --skill apex-vendor-prompting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jonathan-vella/apex apex-vendor-prompting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jonathan-vella/apex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/apex-vendor-prompting .claude/skills/apex-vendor-prompting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
apex-vendor-prompting
GitHub stars
217
Token cost
~2.7k tokens
SKILL.md length
992 words
Files
9 (incl. references, assets)
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

ANALYSIS SKILL — Manual-only audit of Anthropic Claude Opus 5.5 / Sonnet 5.5 and OpenAI GPT-6 / GPT-5.6 prompting guidance and APEX conventions.

  • Works in 6 steps: Read frontmatter of the target .agent.md… → Classify model family using the table… → Load the matching checklist from → …
  • : automatic authoring loads
  • SKILL.md covers When to Use This Skill, Decision Tree, Model-Family Detection and Reference Index, plus 4 more sections
  • Calls npm and node

What it does

Apex Vendor Prompting is an agent skill from jonathan-vella/apex. ANALYSIS SKILL — Manual-only audit of Anthropic Claude Opus 5.5 / Sonnet 5.5 and OpenAI GPT-6 / GPT-5.6 prompting guidance and APEX conventions. WHEN: explicitly invoked as /apex-vendor-prompting for a vendor-specific prompt audit. DO NOT USE FOR: automatic authoring loads, routine edits covered by instructions, generic Markdown style.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files and assets (for example `assets/audit-template.md`, `references/audit-procedure.md` and `references/checklists.md`).

It sits in DevOps & Cloud. It works with OpenAI. The repository describes itself as: APEX turns Azure platform engineering requirements into verified, deploy-ready IaC — powered by GitHub Copilot agents, real-time pricing, and built-in compliance. The licence is MIT.

When your agent uses it

  • : automatic authoring loads
  • Routine edits covered by instructions
  • Generic Markdown style

Example prompts

  • “/apex-vendor-prompting”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Read frontmatter of the target .agent.md / .prompt.md.
  2. Classify model family using the table above. Note the family's
  3. Load the matching checklist from
  4. Run the validator
  5. Manual pass: walk the checklist. Each Yes/No carries a rule ID
  6. Produce a report using

What it can do on your machine

Read from SKILL.md and the folder at commit d0d3f18. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • platform.claude.com
    • developers.openai.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Apex Vendor Prompting loads about 2.7k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 992 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jonathan-vella/apex at commit d0d3f18, republished under its MIT licence (© jonathan-vella). 992 words, ~2,744 tokens.

Download SKILL.mdSave it as .claude/skills/apex-vendor-prompting/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
apex-vendor-prompting
description
**ANALYSIS SKILL** — Manual-only audit of Anthropic Claude Opus 5.5 / Sonnet 5.5 and OpenAI GPT-6 / GPT-5.6 prompting guidance and APEX conventions. WHEN: explicitly invoked as /apex-vendor-prompting for a vendor-specific prompt audit. DO NOT USE FOR: automatic authoring loads, routine edits covered by instructions, generic Markdown style.
user-invocable
true
disable-model-invocation
true
argument-hint
agent or prompt path, model family and audit scope
license
MIT

Vendor Prompting Best Practices

Manual-only: use /apex-vendor-prompting explicitly for this audit workflow. Do not load this skill automatically or read its body to bypass the invocation flag. The thin authoring instructions and required vendor validators remain mandatory without this skill.

Audit-grade reference for the prompting patterns published by Anthropic (Claude Opus 5.5, Sonnet 5.5) and OpenAI (GPT-6, GPT-5.6), plus explicitly identified APEX conventions. Used to author and audit .agent.md and .prompt.md files in this repository.

The machine-readable source of truth is rules.json — every rule has an ID, source citation, severity, applies-to, and validator-check binding. The skill prose, the thin enforcement instruction vendor-prompting.instructions.md, and validate-agents.mjs all reference rule IDs from that file.


When to Use This Skill

  • Authoring a new .agent.md or .prompt.md and wanting the right vendor patterns up front.
  • Auditing an existing agent against vendor best practices (the audit procedure is in audit-procedure.md).
  • Investigating a finding from npm run lint:vendor-prompting — every finding includes a ruleId that maps to a rule in rules.json and back to a reference here.
  • Choosing the right model family for a new agent (decision rules in family-support.md).

Do NOT load this skill for routine edits where the format is already known. The thin instruction vendor-prompting.instructions.md auto-loads on *.agent.md / *.prompt.md edits and carries the hard-rule shortlist.

Decision Tree

text
I am editing or reviewing a *.agent.md / *.prompt.md ...
├── Which model is in the frontmatter?
│   ├── Claude Opus / Sonnet 5.5   → load references/claude-best-practices.md
│   ├── GPT-6 Sol / Luna (copilot) → load references/openai-prompting.md
│   ├── GPT-5.6 Terra (copilot)    → load references/openai-prompting.md
│   ├── MAI-Code-1.1-Flash         → reviewer-only; structural checks still run
│   └── Missing on prompt          → resolve custom-agent or picker inheritance
│
├── Is this a .prompt.md (single string model:) or .agent.md (array)?
│   ├── prompt → load references/checklists.md "prompt" column
│   └── agent  → load references/checklists.md "agent" column
│
└── Want the full audit procedure (5-15 min, produces written report)?
    → load references/audit-procedure.md and assets/audit-template.md

Model-Family Detection

classifyModel() lower-cases the model: value and matches it to a family (claude-opus-5.5 / claude-sonnet-5.5 / gpt-6-sol / gpt-6-luna / gpt-5.6-terra / mai-code / unknown). Retired labels classify as unknown. Validate every ordered fallback label and distinct family. Classification does not authorize a label: ordinary labels must exactly match the catalog. Only handoff overrides allow documented platform qualification.

Full match table, severity status per family (enforced / warn-only / reviewer-only / out-of-scope), and rule subsets per family live in references/family-support.md.

Reference Index

Load only the references your task needs. Most audits need 1-2.

ReferenceLoad when
claude-best-practices.mdAuthoring or auditing a Claude Opus 5.5 or Sonnet 5.5 agent
openai-prompting.mdAuthoring or auditing a GPT-6 Sol/Luna or GPT-5.6 Terra agent
cross-model-rules.mdHandoff design, prompt↔agent sync, language calibration
family-support.mdPicking a model family for a new agent
checklists.mdPerforming a manual pass-through audit
audit-procedure.mdExecuting the full 6-step audit

Rules

  • Source of truth is rules.json — every rule has an ID, severity, source citation, applies-to, and validator-check binding; this skill prose only references it.
  • Check every fallback without adding one; see Model-Family Detection.
  • Missing prompt models may be inherited; unknown explicit labels and unknown custom-agent targets fail validation.
  • Array agent models and string prompt models are APEX conventions, not YAML limitations. Parentheses are valid YAML scalar content.
  • Markdown outcome contracts for GPT are an APEX convention that mirrors the GPT-5.6 suggested prompt structure and extends it to GPT-6. Preserve exact catalog labels; unknown release/tier metadata stays unknown.
  • Claude main agents use the APEX Claude contract: one H1, a nonempty ## Role, and nonempty <scope_fencing>, <output_contract> and <stop_conditions> XML blocks.
  • Vendor autonomy advice does not remove APEX gates — approval gates, the security baseline and governance constraints stay required stops; consolidate their wording instead.
  • Leaf workers use role contracts, not mandatory personality or main-agent sections. Convert XML wrappers without deleting their safety or workflow content.
  • Do NOT load this skill for routine edits — the auto-loaded thin instruction vendor-prompting.instructions.md carries the hard-rule shortlist.
  • Run npm run lint:vendor-prompting before opening a PR; every finding includes a ruleId that maps to a rules.json entry.
  • Verdict thresholds — APPROVED if zero errors and ≤ 5 warns; otherwise NEEDS_REVISION with per-rule remediation
  • Out of scope: routine prompt edits where rules are already known, generic markdown style (see markdown.instructions.md)
Show full SKILL.md (413 more words)Show less

Steps

This is the canonical audit procedure (full version with templates lives in audit-procedure.md).

  1. Read frontmatter of the target .agent.md / .prompt.md. Capture name, model, user-invocable, agents, handoffs[].
  2. Classify model family using the table above. Note the family's status for every fallback from family-support.md.
  3. Load the matching checklist from checklists.md: pick the agent or prompt column, then the family-specific section.
  4. Run the validator: node tools/scripts/validate-agents.mjs --only=vendor-prompting --format=json and filter by file path. Capture rule IDs + severities.
  5. Manual pass: walk the checklist. Each Yes/No carries a rule ID and a verification hint (grep pattern, command, or visual cue).
  6. Produce a report using assets/audit-template.md. Combine automated findings (step 4) + manual findings (step 5). Verdict = APPROVED if zero errors and ≤ 5 warns; otherwise NEEDS_REVISION with per-rule remediation.

Source Citations

Every rule in rules.json cites the upstream source by source_id. All sources are live vendor docs fetched as Markdown (.md suffix):

  • Anthropic Claude prompting best practices — claude-prompting-best-practices.
  • Anthropic Prompting Claude Opus 5.5 — prompting-claude-opus-5-5: effort calibration, thinking-disabled migration, unattended runs, pasted text, progress updates.
  • Anthropic Prompting Claude Opus 5 — prompting-claude-opus-5: baseline the Opus 5.5 guide defers to — over-verification, task scope, subagent spawning, deliverable length.
  • OpenAI Using GPT-6 — latest-model/gpt-6-astra: family prompting best practices (written for Astra, starting point for Sol and Luna).
  • OpenAI Using GPT-5.6 — latest-model/gpt-5.6: Terra/Sol/Luna tiers, migration quickstart.
  • OpenAI Prompting guidance for GPT-5.6 — prompt-guidance-gpt-5p6: suggested prompt structure, autonomy boundaries, lean prompts.

OpenAI sources use model-pinned paths; latest-model without a model segment moves to the next generation silently. Hashes and fetch timestamps live in rules.json sources[].

Freshness

With explicit network authorization, run node tools/scripts/fetch-vendor-prompting-guides.mjs to refresh snapshots and emit a drift report. The fetch script (fetch-vendor-prompting-guides.mjs) fetches each vendor Markdown page anonymously. Snapshots are a gitignored local cache: when upstream is unavailable it falls back to a snapshot from an earlier successful run on the same machine. A clean checkout has no cache, so an offline refresh fails (exit 2) rather than falling back; rules.json hashes are the committed record.

Cached fallback preserves the last successful fetched_at and freshness date; attempted_at and the failure reason record the separate refresh attempt. Missing successful provenance remains unknown. An unchanged successful network response may advance freshness; cached reuse cannot establish upstream currency.

Review actual source diffs before updating normalized references and rule citations. There is no digest-generation step. Offline audits reuse cached sources without changing hashes, fetched timestamps, or claiming refreshed evidence. Source history does not establish model release, capabilities, cost tiers, or native harness behavior.

© jonathan-vella, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (references, assets) in .github/skills/apex-vendor-prompting of jonathan-vella/apex.

  • SKILL.md
  • assets/audit-template.md
  • references/audit-procedure.md
  • references/checklists.md
  • references/claude-best-practices.md
  • references/cross-model-rules.md
  • references/family-support.md
  • references/openai-prompting.md
  • rules.json

Open the folder on GitHubat commit d0d3f18

Compare with similar skills

Apex Vendor Prompting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Apex Vendor Prompting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Apex Vendor Prompting this skilljonathan-vella/apex217—~2.7kAutomated safety check: PassMIT
Caveman Gateway SetupJuliusBrussee/caveman111k1 repos~2.6kAutomated safety check: WarnApache-2.0
Azure Architecture Autopilotgithub/awesome-copilot40k1 repos~1.9kAutomated safety check: PassMIT
Youtubeeat-pray-ai/yutu699—~1.1kAutomated safety check: PassMIT
Local Stack RuntimeOpenHands/OpenHands91k—~375Automated safety check: PassMIT
Telemetry AnalyticsOpenHands/OpenHands91k—~305Automated safety check: PassMIT

Similar skills

  • Caveman Gateway Setup

    JuliusBrussee/caveman

    Routes every LLM call in a repository through the Caveman Cloud gateway in record mode, so requests and costs are measured without changing behavior.

    111k GitHub starsUsed in 1 repo~2.6k tokens
    DevOps & CloudAuto-check: warnings
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed
  • Youtube

    eat-pray-ai/yutu

    A skill your agent uses whenever the user mentions YouTube, video uploads, channel management, playlists, video SEO, or any YouTube Data API operation.

    699 GitHub stars~1.1k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Local Stack Runtime

    OpenHands/OpenHands

    This skill should be used when the user asks to "change the dev stack", "add a runtime service", "change the launcher", "update Docker", "bump Agent Server", "change ingress routing", or changes…

    91k GitHub stars~375 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Telemetry Analytics

    OpenHands/OpenHands

    This skill should be used when the user asks to "add tracking", "add a PostHog event", "change telemetry consent", "instrument onboarding", "debug analytics", or changes telemetry.ts…

    91k GitHub stars~305 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Capacity

    microsoft/GitHub-Copilot-for-Azure

    Official

    Discovers available Azure OpenAI model capacity across regions and projects.

    255 GitHub starsUsed in 1 repo~1.7k tokens
    DevOps & CloudAuto-check passed

More from jonathan-vella/apex

All 39 skills in this repo
  • Apex Azure Diagnostics

    jonathan-vella/apex

    WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis.

    217 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • ANALYSIS SKILL — Azure Policy discovery: effective assignments (incl.

    217 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Apex Context Management

    jonathan-vella/apex

    UTILITY SKILL — Two-mode context-window management. An agent skill from jonathan-vella/apex.

    217 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Apex Python Diagrams

    jonathan-vella/apex

    UTILITY SKILL — Python diagram generation for Azure architectures, WAF/cost/compliance charts, ERDs, swimlanes, timelines, and wireframes.

    217 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Apex Terraform Search Import

    jonathan-vella/apex

    WORKFLOW SKILL — Manual-only discovery and import of existing Azure resources into Terraform management.

    217 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Apex Agent Authoring

    jonathan-vella/apex

    WORKFLOW SKILL — Creates, restructures, and audits GitHub Copilot .agent.md and .prompt.md files with correct frontmatter, handoffs, model policy, context budgets, and validation.

    217 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Apex Vendor Prompting

What does Apex Vendor Prompting do?

ANALYSIS SKILL — Manual-only audit of Anthropic Claude Opus 5.5 / Sonnet 5.5 and OpenAI GPT-6 / GPT-5.6 prompting guidance and APEX conventions. Apex Vendor Prompting is an agent skill from jonathan-vella/apex.6 prompting guidance and APEX conventions.

When should I use Apex Vendor Prompting?

Apex Vendor Prompting fits situations like: : automatic authoring loads; routine edits covered by instructions; generic Markdown style.

How do I install Apex Vendor Prompting in Claude Code?

Run `npx skills add jonathan-vella/apex --skill apex-vendor-prompting -a claude-code`. Or copy the skill folder (.github/skills/apex-vendor-prompting in jonathan-vella/apex) into .claude/skills/apex-vendor-prompting in your project. Claude Code loads it when a task matches its description.

How do I install Apex Vendor Prompting in Codex?

Run `npx skills add jonathan-vella/apex --skill apex-vendor-prompting -a codex`. Or copy the skill folder (.github/skills/apex-vendor-prompting in jonathan-vella/apex) into .agents/skills/apex-vendor-prompting in your project. Codex loads it when a task matches its description.

Can I use Apex Vendor Prompting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jonathan-vella/apex --skill apex-vendor-prompting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/apex-vendor-prompting, .gemini/skills/apex-vendor-prompting, .github/skills/apex-vendor-prompting and .opencode/skills/apex-vendor-prompting in your project.

What does Apex Vendor Prompting need to run?

Going by SKILL.md and its folder, Apex Vendor Prompting needs the command-line tools its instructions call (npm and node).

Does Apex Vendor Prompting access the network?

SKILL.md names 2 domains. As links in the text: platform.claude.com and developers.openai.com. This is read from the text; nothing was executed.

Is Apex Vendor Prompting safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Apex Vendor Prompting use?

Apex Vendor Prompting is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Apex Vendor Prompting use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to Apex Vendor Prompting?

Skills that share tags, products or a category with Apex Vendor Prompting: Caveman Gateway Setup (JuliusBrussee/caveman, 111k stars), Azure Architecture Autopilot (github/awesome-copilot, 40k stars), Youtube (eat-pray-ai/yutu, 699 stars) and Local Stack Runtime (OpenHands/OpenHands, 91k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Apex Vendor Prompting?

jonathan-vella (a GitHub user) maintains it in jonathan-vella/apex, which has 217 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on October 10, 2026.

Source: jonathan-vella/apex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.