Agent skill

Runtime Feature Flags

by kdlbs in kdlbs/kandev

Add, roll out, promote, graduate, or remove Kandev runtime feature flags and release toggles across the backend and frontend.

AGPL-3.0Auto-check passedProductivity & Automation

Install Runtime Feature Flags

skills CLI
$ npx skills add kdlbs/kandev --skill runtime-feature-flags -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kdlbs/kandev runtime-feature-flags --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kdlbs/kandev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/runtime-feature-flags .claude/skills/runtime-feature-flags && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
runtime-feature-flags
GitHub stars
909
Token cost
~1.5k tokens
SKILL.md length
709 words
Files
1
Skills in repo
45
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Add, roll out, promote, graduate, or remove Kandev runtime feature flags and release toggles across the backend and frontend.

  • Works in 6 steps: Profile default: add KANDEV_FEATURES_… → Backend config: add a bool field with… → Registry/config binding: add exactly one… → …
  • A task mentions a feature flag
  • SKILL.md covers Invariants, Add a flag, Roll out and promote and Graduate and remove the flag, plus 1 more section
  • Calls pnpm, go and make

What it does

Runtime Feature Flags is an agent skill from kdlbs/kandev. Add, roll out, promote, graduate, or remove Kandev runtime feature flags and release toggles across the backend and frontend. Use whenever a task mentions a feature flag, release toggle, staged rollout, kill switch, or graduating a flag.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation. The repository describes itself as: AI Kanban & Development Environment. Orchestrate multiple agents, review changes, open PRs. Multi-provider, self-hostable, no telemetry. The licence is AGPL-3.0.

When your agent uses it

  • A task mentions a feature flag
  • Graduating a flag

Example prompts

  • “/runtime-feature-flags”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Profile default: add KANDEV_FEATURES_ under features: in the
  2. Backend config: add a bool field with explicit mapstructure and
  3. Registry/config binding: add exactly one metadata registration to
  4. Backend gates: gate construction and every enabled-only entry path at the
  5. Frontend contract: add the all-off key to
  6. Tests: add enabled/disabled behavior tests for each changed backend path

What it can do on your machine

Read from SKILL.md and the folder at commit b734113. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • go
    • make
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Runtime Feature Flags loads about 1.5k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 709 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kdlbs/kandev at commit b734113, republished under its AGPL-3.0 licence (© kdlbs). 709 words, ~1,463 tokens.

Download SKILL.mdSave it as .claude/skills/runtime-feature-flags/SKILL.md (or your agent's skills folder).
name
runtime-feature-flags
description
Add, roll out, promote, graduate, or remove Kandev runtime feature flags and release toggles across the backend and frontend. Use whenever a task mentions a feature flag, release toggle, staged rollout, kill switch, or graduating a flag.

Runtime Feature Flags

Use this checklist for temporary release toggles and risky features. It is self-contained: do not depend on the agent having read an ADR or public docs. Read apps/backend/AGENTS.md and apps/web/AGENTS.md when the change touches those subtrees.

Invariants

  • The backend is authoritative. A disabled feature must not be reachable through HTTP, WebSocket, MCP, agent-tool, or background-job entry points.
  • A new release toggle is off in every shipped profile when it is merged. The disabled path preserves the existing behavior and fails closed before deriving data, writing state, dispatching work, or exposing a capability.
  • Effective values are ordered: explicit environment variable, SQLite override, then profile default. An explicit environment variable locks the admin UI.
  • Use one identity across layers: features.<camelCaseKey>, KANDEV_FEATURES_<UPPER_SNAKE_CASE>, a Go FeaturesConfig field, its JSON tag, and the matching frontend key. Never add a parallel flag map or switch.
  • Never reuse an identity recorded in the repository's append-only retired registry. Before relying on retirement, verify that retiredRuntimeFlagIdentities and its collision/completeness test exist; if they do not, add that runtimeflags infrastructure before removing a live flag.

Add a flag

Update these layers in the same change:

  1. Profile default: add KANDEV_FEATURES_<NAME> under features: in the root profiles.yaml; use prod: "false", dev: "false", and e2e: "false" for a release toggle unless the task explicitly documents a test-only exception.
  2. Backend config: add a bool field with explicit mapstructure and json tags to apps/backend/internal/common/config/config.go.
  3. Registry/config binding: add exactly one metadata registration to apps/backend/internal/runtimeflags/registry.go: key, env var, kind, label, description, stability, risk, and restart/mutability metadata. The registry definition is metadata-only; add the key/env constants and update OptionsFromConfig, ValuesFromConfig, and ApplyStatesToConfig in runtimeflags/config.go for typed config wiring.
  4. Backend gates: gate construction and every enabled-only entry path at the narrow composition boundary. Do not only hide the frontend; direct callers must receive the legacy behavior or a safe rejection.
  5. Frontend contract: add the all-off key to apps/web/lib/state/slices/features/types.ts. Use useFeature() for client surfaces and notFound() from the relevant server layout/page when a route subtree must be unavailable. SSR data must remain fail-closed.
  6. Tests: add enabled/disabled behavior tests for each changed backend path and frontend surface. Run the existing registry/profile/frontend contract tests; add focused tests for normalization, route visibility, and disabled side-effect prevention where applicable.

The completeness checks require exact equality between profile keys, typed backend fields/registrations, and frontend default keys. They do not discover semantic call sites, so trace the feature's HTTP, WebSocket, MCP, agent, worker, and startup paths manually.

Show full SKILL.md (299 more words)Show less

Roll out and promote

  1. Merge with all shipped profile defaults off.
  2. Enable one installation through Settings > System > Feature Toggles or an explicit environment variable, restart when metadata requires it, and test real workflows.
  3. When ready for everyone, change only the prod profile value to "true" for the next release. Retain the registry entry and backend/frontend gates as a kill switch so operators can still disable the feature.

Graduate and remove the flag

After the feature has proven itself as the default-on behavior, make the new behavior unconditional and remove the live flag end-to-end:

  • remove the profile entry and FeaturesConfig field;
  • remove the active registry registration;
  • remove backend conditionals and legacy branches;
  • remove the frontend default, useFeature() checks, and route gates;
  • remove flag-specific tests and documentation while keeping permanent behavior coverage.

Before removing the registration, verify the append-only retiredRuntimeFlagIdentities registry and its collision/completeness test exist, then append the exact key and environment variable in registry.go:

go
{key: "features.example", envVar: "KANDEV_FEATURES_EXAMPLE"},

Do not delete old runtime_flag_overrides rows as part of graduation. Unknown rows are intentionally inert, and the retired identity prevents stale operator state from reactivating a future feature. Never reuse either the key or env var.

Verification and handoff

Run the focused checks appropriate to the change:

  • In a fresh worktree, run pnpm install --frozen-lockfile from apps/ before any pnpm-based checks, tests, lint, or commits.
  • from apps/backend: go test ./internal/runtimeflags ./internal/common/config ./internal/profiles;
  • from the repository root: make -C apps/backend lint;
  • from apps: pnpm --filter @kandev/web test -- lib/state/slices/features/features-contract.test.ts;
  • from apps/web: pnpm run typecheck and pnpm run lint;
  • run affected E2E coverage when the gated surface is user-visible;
  • run git diff --check before handoff.

Report the flag key/env identity, profile defaults, every gated entry path, disabled/enabled test evidence, restart requirements, and whether the change is still a kill switch or has been fully graduated.

© kdlbs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/runtime-feature-flags of kdlbs/kandev.

Open the folder on GitHubat commit b734113

Compare with similar skills

Runtime Feature Flags next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Runtime Feature Flags compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Runtime Feature Flags this skillkdlbs/kandev909—~1.5kAutomated safety check: PassAGPL-3.0
Make Pages Interactiveparaschopra/make-pages-interactive481—~2kAutomated safety check: PassMIT
Agent Desktopsuperagent-ai/grok-cli3.5k—~720Automated safety check: PassMIT
Gauntletanomalyco/browser-control440—~1.1kAutomated safety check: PassMIT
Browsemr-daedalium/ostack-saas1141 repos~5.3kAutomated safety check: NotesMIT
Tabz BrowserGGPrompts/TabzChrome147—~730Automated safety check: PassMIT

Similar skills

  • Make Pages Interactive

    paraschopra/make-pages-interactive

    Turn a directory of static HTML pages into a live commenting surface.

    481 GitHub stars~2k tokensUpdated 3 mo ago
    Productivity & AutomationAuto-check passed
  • Agent Desktop

    superagent-ai/grok-cli

    Use the built-in Computer sub-agent with agent-desktop for macOS desktop automation.

    3.5k GitHub stars~720 tokensUpdated 3 mo ago
    Productivity & AutomationAuto-check passed
  • Gauntlet

    anomalyco/browser-control

    Run a real-world navigation and capability gauntlet on Browser Control across live websites, fix general DOM/ARIA/CDP root causes, benchmark speed and token efficiency, and finish with a mandatory…

    440 GitHub stars~1.1k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Browse

    mr-daedalium/ostack-saas

    Fast headless browser for QA testing and site dogfooding. An agent skill from mr-daedalium/ostack-saas.

    114 GitHub starsUsed in 1 repo~5.3k tokens
    Productivity & AutomationAuto-check: notes
  • Tabz Browser

    GGPrompts/TabzChrome

    Browser automation via 70 tabz MCP tools. An agent skill from GGPrompts/TabzChrome.

    147 GitHub stars~730 tokensUpdated 10 days ago
    Productivity & AutomationAuto-check passed
  • Preview Rostra

    dpc/rostra

    Use agent-browser to interact with Rostra's live development UI through accessibility snapshots, semantic controls, text entry, and screenshots.

    110 GitHub stars~2.3k tokensUpdated 14 days ago
    Productivity & AutomationAuto-check passed

More from kdlbs/kandev

All 45 skills in this repo
  • PR Walkthrough

    kdlbs/kandev

    Generate a single-file HTML walkthrough that explains a PR's purpose, user impact, interface changes, compatibility risks, and implementation.

    909 GitHub stars~6.2k tokensUpdated today
    Auto-check passed
  • Debug

    kdlbs/kandev

    Diagnose Kandev bugs, running-instance issues, UI/browser failures, and runtime behavior.

    909 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Improve Kandev's AI harness from session learnings or explicit requests.

    909 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Diagram Design

    kdlbs/kandev

    Create branded architecture, IT current-state, flowchart, sequence, state machine, ER/data model, timeline, swimlane, quadrant, radar/spider, polar chart (polar/radial lollipop), loop/flywheel…

    909 GitHub starsUsed in 1 repo~8k tokens
    Auto-check passed
  • TDD

    kdlbs/kandev

    Implement changes using Test-Driven Development (Red-Green-Refactor).

    909 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Verify

    kdlbs/kandev

    Run a broad local verification audit only when the user explicitly requests it or PR/CI remediation requires it.

    909 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Questions about Runtime Feature Flags

What does Runtime Feature Flags do?

Add, roll out, promote, graduate, or remove Kandev runtime feature flags and release toggles across the backend and frontend. Runtime Feature Flags is an agent skill from kdlbs/kandev. Add, roll out, promote, graduate, or remove Kandev runtime feature flags and release toggles across the backend and frontend.

When should I use Runtime Feature Flags?

Runtime Feature Flags fits situations like: A task mentions a feature flag; graduating a flag.

How do I install Runtime Feature Flags in Claude Code?

Run `npx skills add kdlbs/kandev --skill runtime-feature-flags -a claude-code`. Or copy the skill folder (.agents/skills/runtime-feature-flags in kdlbs/kandev) into .claude/skills/runtime-feature-flags in your project. Claude Code loads it when a task matches its description.

How do I install Runtime Feature Flags in Codex?

Run `npx skills add kdlbs/kandev --skill runtime-feature-flags -a codex`. Or copy the skill folder (.agents/skills/runtime-feature-flags in kdlbs/kandev) into .agents/skills/runtime-feature-flags in your project. Codex loads it when a task matches its description.

Can I use Runtime Feature Flags in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kdlbs/kandev --skill runtime-feature-flags -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/runtime-feature-flags, .gemini/skills/runtime-feature-flags, .github/skills/runtime-feature-flags and .opencode/skills/runtime-feature-flags in your project.

What does Runtime Feature Flags need to run?

Going by SKILL.md and its folder, Runtime Feature Flags needs the command-line tools its instructions call (pnpm, go, make and git).

Does Runtime Feature Flags access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Runtime Feature Flags safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Runtime Feature Flags use?

Runtime Feature Flags is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Runtime Feature Flags use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Runtime Feature Flags?

Skills that share tags, products or a category with Runtime Feature Flags: Make Pages Interactive (paraschopra/make-pages-interactive, 481 stars), Agent Desktop (superagent-ai/grok-cli, 3.5k stars), Gauntlet (anomalyco/browser-control, 440 stars) and Browse (mr-daedalium/ostack-saas, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Runtime Feature Flags?

kdlbs (a GitHub organization) maintains it in kdlbs/kandev, which has 909 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on October 8, 2026.

Source: kdlbs/kandev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.