Agent skill

Kandev Protocol

by kdlbs in kdlbs/kandev

Follow the core Office agent protocol on wakeup, including parsing KANDEV context, checking blockers, commenting progress, updating status, and using the CLI safely.

AGPL-3.0Auto-check passedProductivity & Automation

Install Kandev Protocol

skills CLI
$ npx skills add kdlbs/kandev --skill kandev-protocol -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kdlbs/kandev kandev-protocol --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kdlbs/kandev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/apps/backend/internal/office/configloader/skills/kandev-protocol .claude/skills/kandev-protocol && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kandev-protocol
GitHub stars
909
Token cost
~2.1k tokens
SKILL.md length
830 words
Files
1
Skills in repo
45
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Follow the core Office agent protocol on wakeup, including parsing KANDEV context, checking blockers, commenting progress, updating status, and using the CLI safely.

  • Works in 8 steps: Read wake reason → Parse wake payload → Check blockers → …
  • Productivity & Automation work in your project
  • SKILL.md covers Environment Variables, Heartbeat Procedure, CLI Reference and Error Handling, plus 1 more section
  • Calls jq; needs KANDEV_API_KEY

What it does

Kandev Protocol is an agent skill from kdlbs/kandev. Follow the core Office agent protocol on wakeup, including parsing KANDEV context, checking blockers, commenting progress, updating status, and using the CLI safely.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation. The repository describes itself as: AI Kanban & Development Environment. Orchestrate multiple agents, review changes, open PRs. Multi-provider, self-hostable, no telemetry. The licence is AGPL-3.0.

When your agent uses it

  • Productivity & Automation work in your project

Example prompts

  • “/kandev-protocol”

Requirements

  • A credential in KANDEV_API_KEY

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Read wake reason
  2. Parse wake payload
  3. Check blockers
  4. Do the work
  5. Post progress comments
  6. Update task status
  7. Create subtasks (if needed)
  8. Exit

What it can do on your machine

Read from SKILL.md and the folder at commit b734113. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • KANDEV_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kandev Protocol loads about 2.1k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 830 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kdlbs/kandev at commit b734113, republished under its AGPL-3.0 licence (© kdlbs). 830 words, ~2,126 tokens.

Download SKILL.mdSave it as .claude/skills/kandev-protocol/SKILL.md (or your agent's skills folder).
name
kandev-protocol
description
Follow the core Office agent protocol on wakeup, including parsing KANDEV_* context, checking blockers, commenting progress, updating status, and using the CLI safely.
kandev.system
true
kandev.version
0.42.0
kandev.default_for_roles
ceo, worker, specialist, assistant, reviewer

Kandev Protocol

You are an agent managed by kandev. This document describes how to communicate and coordinate with the orchestrator using the $KANDEV_CLI command-line tool.

Environment Variables

These are injected into your session automatically. Do not hardcode them.

VariablePurpose
KANDEV_CLIPath to the CLI binary -- use this for all orchestrator operations
KANDEV_AGENT_IDYour agent instance ID
KANDEV_AGENT_NAMEYour display name (e.g. "CEO")
KANDEV_WORKSPACE_IDCurrent workspace scope
KANDEV_TASK_IDTask you are working on (if applicable)
KANDEV_RUN_IDCurrent run ID (included automatically by the CLI)
KANDEV_WAKE_REASONWhy you were woken (see wake reasons below)
KANDEV_WAKE_COMMENT_IDComment ID that triggered the wake (if applicable)
KANDEV_WAKE_PAYLOAD_JSONPre-computed task context -- parse this first
KANDEV_WAKE_PAYLOAD_PATHWorkspace-relative JSON file path when the payload is too large for inline env

Note: KANDEV_API_URL and KANDEV_API_KEY are also set but you do not need to use them directly. The CLI handles authentication and run-ID headers for you.

Heartbeat Procedure

When you wake up, follow these steps in order.

Step 1: Read wake reason

Check $KANDEV_WAKE_REASON. Possible values:

  • task_assigned -- a new task was assigned to you
  • task_comment -- someone commented on your task
  • task_children_completed -- all child tasks are done
  • approval_resolved -- an approval you requested was decided
  • heartbeat -- periodic check-in (CEO agents only)
Step 2: Parse wake payload

If $KANDEV_WAKE_PAYLOAD_JSON is set, parse it. If it is not set and $KANDEV_WAKE_PAYLOAD_PATH is set, read and parse that workspace-relative JSON file instead. The payload contains pre-computed context so you don't need to fetch it from the API (saves tokens):

json
{
  "task": {
    "id": "task-123",
    "identifier": "KAN-42",
    "title": "Add OAuth2 login",
    "description": "Implement OAuth2 login with Google provider...",
    "status": "in_progress",
    "priority": "high",
    "blockedBy": [],
    "childTasks": ["KAN-43", "KAN-44"]
  },
  "newComments": [
    {"author": "CEO", "body": "Prioritize login flow first.", "createdAt": "2026-04-27T10:00:00Z"}
  ],
  "commentWindow": {
    "total": 15,
    "included": 3,
    "fetchMore": false
  }
}

On fresh session: full task context. On resume: only new comments since last run. If commentWindow.fetchMore is true, fetch older comments from the API.

Step 3: Check blockers

If task.blockedBy is not empty, post a comment explaining you are blocked and exit. Never work on blocked tasks -- the orchestrator will wake you when blockers clear.

bash
$KANDEV_CLI kandev tasks message --prompt "Blocked by tasks: KAN-43, KAN-44. Waiting for resolution."
Step 4: Do the work

Based on your role and the task description, implement what is needed. Read your instruction files (HEARTBEAT.md, SOUL.md) for role-specific guidance.

Step 5: Post progress comments

Always post a comment before changing task status. This creates an audit trail and keeps other agents informed.

bash
$KANDEV_CLI kandev tasks message --prompt "Implemented OAuth2 login flow with Google provider. Tests pass."

For multiline comments, pipe via stdin:

bash
cat <<'EOF' | $KANDEV_CLI kandev tasks message --prompt -
Implementation summary:
- Added Google OAuth2 provider with PKCE flow
- Wrote integration tests covering token refresh
- Updated user model with provider_id column
EOF

tasks message uses the signed runtime scope. The server verifies that the task is writable by this run and derives the agent attribution from the run token. Do not use another comment command or supply author fields yourself.

Step 6: Update task status

Mark the task as done (or in_review if reviewers are assigned):

bash
$KANDEV_CLI kandev task update --status done

Use --status in_review instead of done when the task has reviewers. Use --status blocked if you discover a blocker during execution.

Step 7: Create subtasks (if needed)

If the task is too large, decompose it into subtasks:

bash
$KANDEV_CLI kandev task create --title "Implement Google OAuth provider" \
  --description "Add the provider flow, callback handling, and tests." \
  --parent "$KANDEV_TASK_ID" --assignee "worker-agent-id"

To find available agents for delegation:

bash
$KANDEV_CLI kandev agents list
Step 8: Exit

Your session will end after you finish. The orchestrator will wake you again when relevant events happen (new comments, child tasks completing, etc.).

CLI Reference

All commands use $KANDEV_CLI kandev <command>. Authentication, run-ID, and agent-ID headers are handled automatically from environment variables.

Show full SKILL.md (332 more words)Show less
task
task get [--id ID]                    Read task details (defaults to $KANDEV_TASK_ID)
task update [--id ID] --status S [--comment C]
                                      Update status with an optional status-change comment
task create --title T [--description D] Create a task or subtask
         [--parent ID] [--assignee A] [--project ID]

No other task creation options are supported by the Office runtime.

comment
text
tasks message [--id ID] --prompt P    Post an agent-authored comment
                                      Use --prompt - to read from stdin
agents
agents list [--role R] [--status S]   List agent instances in the workspace
memory

Persist information across sessions. Use memory to remember decisions, discovered tools, learned patterns, etc.

memory get [--layer L] [--key K]      Read memory entries
memory set --layer L --key K          Store a memory entry
           --content C
memory summary                        Get a summary of all memory entries

Layers: operating (how you work), knowledge (facts you learned).

checkout
checkout [--task ID]                  Atomically claim a task for this agent

Returns task details on success. Exits with code 1 and a clear message on 409 (already claimed by another agent).

Error Handling

All CLI commands follow these conventions:

  • Exit code 0: success. JSON result on stdout.
  • Exit code 1: error. JSON error on stderr: {"error": "message"}.
  • HTTP 409 on checkout: task already claimed. Do not retry.

Always check the exit code before parsing output:

bash
if output=$($KANDEV_CLI kandev task get 2>/dev/null); then
  echo "$output" | jq .title
else
  echo "Failed to fetch task" >&2
fi

Critical Rules

  1. Never retry a 409 Conflict. This means another agent has claimed the task. Post a comment and move on.

  2. Always post a comment before changing task status. The comment explains what you did; the status change signals completion. Never change status silently.

  3. Do not work on blocked tasks. If blockedBy is non-empty, post a comment and exit. The orchestrator will wake you when blockers resolve.

  4. If you cannot complete a task because a human decision is required (design choice, access credentials, ambiguous requirements), use the kandev-escalation skill to create a human task, cross-reference it, and mark your task blocked. The current CLI cannot create a blocker relationship, so recovery requires a normal human comment or task update. For all other cases (missing permissions, external dependency), post a comment explaining why and exit. Do not set the task to done if it is not actually done.

  5. Parse KANDEV_WAKE_PAYLOAD_JSON first. If it is absent, read KANDEV_WAKE_PAYLOAD_PATH. The payload contains pre-computed context. Only call the API for data not in the payload. This saves tokens.

  6. Keep comments concise but informative. Other agents and humans read them. Include what you did, what changed, and any decisions you made.

  7. Respect your role. CEO agents delegate, they do not implement. Worker agents implement, they do not delegate to peers. Reviewers review, they do not modify code.

© kdlbs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in apps/backend/internal/office/configloader/skills/kandev-protocol of kdlbs/kandev.

Open the folder on GitHubat commit b734113

Compare with similar skills

Kandev Protocol next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kandev Protocol compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kandev Protocol this skillkdlbs/kandev909—~2.1kAutomated safety check: PassAGPL-3.0
Agent Browserquran/quran.com-frontend-next1.9k42 repos~3.3kAutomated safety check: PassNone
Process Inboxtelegramdesktop/tdesktop33k2 repos~4.5kAutomated safety check: PassGPL-3.0
Perform Tasktelegramdesktop/tdesktop33k2 repos~3kAutomated safety check: PassGPL-3.0
Brave Searchbadlogic/pi-skills2.6k6 repos~592Automated safety check: PassMIT
Continuetelegramdesktop/tdesktop33k2 repos~9.4kAutomated safety check: PassGPL-3.0

Similar skills

  • Agent Browser

    quran/quran.com-frontend-next

    Automates browser interactions for web testing, form filling, screenshots, and data extraction.

    1.9k GitHub starsUsed in 42 repos~3.3k tokens
    Productivity & AutomationAuto-check passed
  • Process Inbox

    telegramdesktop/tdesktop

    Process the local ignored ai-tdesktop inbox into durable, independently testable Telegram Desktop task records while task execution worktrees remain active.

    33k GitHub starsUsed in 2 repos~4.5k tokens
    Productivity & AutomationAuto-check passed
  • Perform Task

    telegramdesktop/tdesktop

    Resolve, start or resume, implement, review, test, and publish exactly one existing ai-tdesktop task by short slug or full dated id, including rare blocked retries and split-required results.

    33k GitHub starsUsed in 2 repos~3k tokens
    Productivity & AutomationAuto-check passed
  • Brave Search

    badlogic/pi-skills

    Web search and content extraction via Brave Search API. An agent skill from badlogic/pi-skills.

    2.6k GitHub starsUsed in 6 repos~592 tokens
    Productivity & AutomationAuto-check passed
  • Continue

    telegramdesktop/tdesktop

    Continue autonomous Telegram Desktop development from the shared ai-tdesktop repository.

    33k GitHub starsUsed in 2 repos~9.4k tokens
    Productivity & AutomationAuto-check passed
  • Feishu Doc

    openclaw/openclaw

    Feishu document read/write workflows. An agent skill from openclaw/openclaw.

    392k GitHub stars~516 tokensUpdated today
    Productivity & AutomationAuto-check passed

More from kdlbs/kandev

All 45 skills in this repo
  • PR Walkthrough

    kdlbs/kandev

    Generate a single-file HTML walkthrough that explains a PR's purpose, user impact, interface changes, compatibility risks, and implementation.

    909 GitHub stars~6.2k tokensUpdated today
    Auto-check passed
  • Debug

    kdlbs/kandev

    Diagnose Kandev bugs, running-instance issues, UI/browser failures, and runtime behavior.

    909 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Improve Kandev's AI harness from session learnings or explicit requests.

    909 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Diagram Design

    kdlbs/kandev

    Create branded architecture, IT current-state, flowchart, sequence, state machine, ER/data model, timeline, swimlane, quadrant, radar/spider, polar chart (polar/radial lollipop), loop/flywheel…

    909 GitHub starsUsed in 1 repo~8k tokens
    Auto-check passed
  • TDD

    kdlbs/kandev

    Implement changes using Test-Driven Development (Red-Green-Refactor).

    909 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Verify

    kdlbs/kandev

    Run a broad local verification audit only when the user explicitly requests it or PR/CI remediation requires it.

    909 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Questions about Kandev Protocol

What does Kandev Protocol do?

Follow the core Office agent protocol on wakeup, including parsing KANDEV context, checking blockers, commenting progress, updating status, and using the CLI safely. Kandev Protocol is an agent skill from kdlbs/kandev. Follow the core Office agent protocol on wakeup, including parsing KANDEV context, checking blockers, commenting progress, updating status, and using the CLI safely.

When should I use Kandev Protocol?

Kandev Protocol fits situations like: productivity & Automation work in your project.

How do I install Kandev Protocol in Claude Code?

Run `npx skills add kdlbs/kandev --skill kandev-protocol -a claude-code`. Or copy the skill folder (apps/backend/internal/office/configloader/skills/kandev-protocol in kdlbs/kandev) into .claude/skills/kandev-protocol in your project. Claude Code loads it when a task matches its description.

How do I install Kandev Protocol in Codex?

Run `npx skills add kdlbs/kandev --skill kandev-protocol -a codex`. Or copy the skill folder (apps/backend/internal/office/configloader/skills/kandev-protocol in kdlbs/kandev) into .agents/skills/kandev-protocol in your project. Codex loads it when a task matches its description.

Can I use Kandev Protocol in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kdlbs/kandev --skill kandev-protocol -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kandev-protocol, .gemini/skills/kandev-protocol, .github/skills/kandev-protocol and .opencode/skills/kandev-protocol in your project.

What does Kandev Protocol need to run?

Going by SKILL.md and its folder, Kandev Protocol needs the command-line tools its instructions call (jq) and credentials named KANDEV_API_KEY. Our summary lists: A credential in KANDEV_API_KEY.

Does Kandev Protocol access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kandev Protocol safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kandev Protocol use?

Kandev Protocol is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kandev Protocol use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kandev Protocol?

Skills that share tags, products or a category with Kandev Protocol: Agent Browser (quran/quran.com-frontend-next, 1.9k stars), Process Inbox (telegramdesktop/tdesktop, 33k stars), Perform Task (telegramdesktop/tdesktop, 33k stars) and Brave Search (badlogic/pi-skills, 2.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kandev Protocol?

kdlbs (a GitHub organization) maintains it in kdlbs/kandev, which has 909 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on October 8, 2026.

Source: kdlbs/kandev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.