Agent skill

Os Step By Step

by kharmanskyi in kharmanskyi/open-steps

ALWAYS invoke this skill when you need the user to act - run a command, paste a secret, click, approve - and whenever they ask how to do something or say they do not know what to do: "step by step"…

MITAuto-check passedWriting & Content

Install Os Step By Step

skills CLI
$ npx skills add kharmanskyi/open-steps --skill os-step-by-step -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kharmanskyi/open-steps os-step-by-step --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kharmanskyi/open-steps.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/os-step-by-step .claude/skills/os-step-by-step && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
os-step-by-step
GitHub stars
1.3k
Token cost
~1.9k tokens
SKILL.md length
949 words
Files
2 (incl. references)
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

ALWAYS invoke this skill when you need the user to act - run a command, paste a secret, click, approve - and whenever they ask how to do something or say they do not know what to do: "step by step"…

  • Works in 4 steps: Try it. A real 403 is a finding; "I… → Find another route. Another tool, a… → Shrink the ask. Obtain what you can… → …
  • Writing & Content work in your project
  • SKILL.md covers Language, When to use, Step 0 - earn the right to ask and The shape, plus 5 more sections
  • Calls ssh

What it does

Os Step By Step is an agent skill from kharmanskyi/open-steps. ALWAYS invoke this skill when you need the user to act - run a command, paste a secret, click, approve - and whenever they ask how to do something or say they do not know what to do: "step by step", "walk me through it", "what do I do", "what should I do", "I don't understand what to do", "explain what I need to do", in any language. Picking which task comes next is os-whats-next; this skill is for doing the thing in front of you. First earn the ask: try it yourself, find another route, shrink it to the part only…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/01-paste-a-secret.md`).

It sits in Writing & Content. The repository describes itself as: Plain-language agent skills for Claude Code, Codex, Cursor and Gemini CLI: honest session reports, straight verdicts, steps you can follow. MIT. The licence is MIT.

When your agent uses it

  • Writing & Content work in your project

Example prompts

  • “step by step”
  • “walk me through it”
  • “what do I do”
  • “/os-step-by-step”

Requirements

  • Pre-approved tools (allowed-tools): Read(~/.claude/open-steps/**)

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Try it. A real 403 is a finding; "I probably lack permission" is a guess.
  2. Find another route. Another tool, a value already on the host, a file
  3. Shrink the ask. Obtain what you can yourself; hand over only the
  4. Check you are not asking twice - search the session and the reports

What it can do on your machine

Read from SKILL.md and the folder at commit 4fa744b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read(~/.claude/open-steps/**)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • ssh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use ssh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Os Step By Step loads about 1.9k tokens when it runs, and up to ~2.9k if it reads all its reference files. Until then it costs about 191 tokens; SKILL.md has 949 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~191
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kharmanskyi/open-steps at commit 4fa744b, republished under its MIT licence (© kharmanskyi). 949 words, ~1,885 tokens.

Download SKILL.mdSave it as .claude/skills/os-step-by-step/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
os-step-by-step
description
ALWAYS invoke this skill when you need the user to act - run a command, paste a secret, click, approve - and whenever they ask how to do something or say they do not know what to do: "step by step", "walk me through it", "what do I do", "what should I do", "I don't understand what to do", "explain what I need to do", in any language. Picking which task comes next is os-whats-next; this skill is for doing the thing in front of you. First earn the ask: try it yourself, find another route, shrink it to the part only they can do. Then one action per step, commands labelled by what they touch, no jargon. Commands are single lines that prompt for any value - typing hidden for secrets - and confirm in plain words. Afterwards verify their step.
allowed-tools
Read(~/.claude/open-steps/**)

os-step-by-step

The user is not stuck because the task is hard - they cannot tell what they are being asked to do. This skill turns "I need something from you" into an instruction a person who does not read code can follow without a follow-up question. os-done-or-not reports that something is needed; this one says exactly how.

Language

Write in the language the user speaks in this session, detected from the conversation. Commands, file names and identifiers stay English.

When to use

Triggers live in the description above - any moment you need the user's hands, or they ask what to do.

Step 0 - earn the right to ask

Every ask costs the user a context switch. Prove it is necessary; stop at the first item that clears the block:

  1. Try it. A real 403 is a finding; "I probably lack permission" is a guess.
  2. Find another route. Another tool, a value already on the host, a file you can read.
  3. Shrink the ask. Obtain what you can yourself; hand over only the irreducible part.
  4. Check you are not asking twice - search the session and the reports folder first.

Three walls where asking IS the correct move, never to be worked around: pulling a secret into your own context, loosening a guard that is there on purpose, doing what the user said only they do.

The shape

Always this order - the ask first, never after the diagnosis.

**What I need from you: <one sentence, plain words>.**

Why you and not me: <one or two sentences. A real reason, in human terms.>

**Step 1. <action in three to six words>**
<What to do. One action only.>

**Step 2. <action>**
<...>

**How you'll know it worked.**
<What the user will see. What to do if they see something else.>

**What happens next, on my side.**
<One line: what you do once they are done, and what you will say.>

After they act - verify, do not trust

"Done" is a claim. Run the one quickest check that would fail if the step had not worked - the file exists with the right owner, the service answers, the value works once. Never print a secret to confirm it: confirm its effect. If the check fails, give only the corrected step - never the whole list again. Verified versus assumed is exactly what os-done-or-not needs for "yes" versus "not checked".

Secrets and dangerous steps

A secret never goes through the chat - it would stay in the history and the logs. The command below puts it where it belongs directly; say who deletes it and when. A hard-to-undo step - live users, money, deletion - gets its own warning line before the command.

Writing a secret to a remote host - one line: it prompts, hides the typing, refuses a truncated paste, confirms by size:

bash
printf 'Paste the connection string, then press Enter: '; IFS= read -rs V; echo; if [ ${#V} -lt 20 ]; then echo "Only ${#V} characters - that looks truncated, nothing was saved."; else printf '%s' "$V" | ssh root@HOST 'umask 077 && cat > /path/to/secret' && ssh root@HOST 'echo "Saved, $(wc -c < /path/to/secret) bytes"'; fi; unset V

Typed by hand rather than pasted - ask twice; a typo in a hidden field is otherwise undetectable:

bash
printf 'Enter the token: '; IFS= read -rs A; echo; printf 'Enter it again: '; IFS= read -rs B; echo; if [ "$A" != "$B" ]; then echo "The two entries differ - nothing saved, run it again."; else printf '%s' "$A" | (umask 077; cat > /path/to/secret) && echo "Saved, $(wc -c < /path/to/secret) bytes"; fi; unset A B

These templates are for bash and zsh and have not been run on Windows. There, ask the user to open a separate Git Bash window just for this command, and to leave the agent running where it is. Never write an unchecked PowerShell one.

Two properties the templates cannot keep for you, both measured:

  • printf …; IFS= read -rs VAR - never read -rsp. In zsh -p means "read from a coprocess": the variable comes back empty with no error and the secret file is written blank. macOS defaults to zsh.
  • The value never appears in the command itself - only piped from the variable; anything in the arguments lands in shell history and the process list.

The rest the templates already embody - one single line, umask 077 before writing, refuse short input, confirm by byte count never by content, unset at the end. Adapt the prompt, the threshold and the path; keep every property.

The same pattern serves any value the user must supply by hand - a public key, a domain, an address, an id. Prompt for it the same way; keep the typing visible when the value is not secret (drop -s), skip the length gate when short is valid - and always end with a plain-words confirmation of what just happened, so pressing Enter never feels like dropping a coin into a well.

Show full SKILL.md (324 more words)Show less

Choices, not instructions

A decision gets no steps. Use your tool's question picker where it has one (in Claude Code, AskUserQuestion), with the pack's contract: plain question, why it matters, what changes later, easy to undo, two to four options, the recommended one first and marked. Where there is no picker, write the same question and options as plain text, the recommended one first and marked.

Hard rules

  1. The ask goes first. What you tried and what failed is your problem - one line at the end, or nothing.
  2. One action per step. Two commands is two steps.
  3. Label every command with what it touches - the test server, the live server, their own machine. Look-alike steps on different targets: say what happens if they are swapped.
  4. A command is self-contained. One line the user pastes and runs; if it needs a value, it asks for it. Never make the user feed input by redirection, a heredoc or Ctrl-D.
  5. No jargon inside a step. Avoid terms instead of explaining them: write what the person sees and clicks. One unavoidable term may stay - without a lecture.
  6. Always give a way to check. A step the user cannot verify is a step they will redo out of doubt.
  7. Never mix your work with theirs. Two lists with plain headings; a buried "this one's on you" is not an instruction.
  8. Never compress a multi-step sequence - here brevity causes misreads. Blocks of two to three sentences; longer gets skimmed, and a skimmed step is a missed step.

Known gotchas

  • A heading is not a summary: "one command per host" above two commands reads as one command. Count out loud.
  • A dropped step is "skip step 3" - never a silent renumber.
  • If you can verify it yourself, verify it yourself; do not ask for confirmation you do not need.
  • "Say done" needs a subject - the user may have three of your requests open.

© kharmanskyi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/os-step-by-step of kharmanskyi/open-steps.

  • SKILL.md
  • references/01-paste-a-secret.md

Open the folder on GitHubat commit 4fa744b

Compare with similar skills

Os Step By Step next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Os Step By Step compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Os Step By Step this skillkharmanskyi/open-steps1.3k—~1.9kAutomated safety check: PassMIT
Socialcoreyhaines31/marketingskills54k4 repos~4.5kAutomated safety check: PassMIT
HumanizerAzure-Samples/interview-coach-agent-framework17237 repos~5.8kAutomated safety check: PassMIT
Avoid AI Writingconorbronsdon/avoid-ai-writing4.9k3 repos~8.1kAutomated safety check: PassMIT
JavaScript Concept Fact Checkerleonardomso/33-js-concepts67k1 repos~5kAutomated safety check: PassMIT
User-Facing Text Cleanupguillaumemeyer/watermarks-remover24k—~3.5kAutomated safety check: PassMIT

Similar skills

  • Social

    coreyhaines31/marketingskills

    When the user wants help creating, scheduling, or optimizing social media content for LinkedIn, Twitter/X, Instagram, TikTok, or Facebook, or wants to do social listening and engagement triage.

    54k GitHub starsUsed in 4 repos~4.5k tokens
    Writing & ContentAuto-check passed
  • Humanizer

    Azure-Samples/interview-coach-agent-framework

    Official

    Remove signs of AI-generated writing from text. An agent skill from Azure-Samples/interview-coach-agent-framework.

    172 GitHub starsUsed in 37 repos~5.8k tokens
    Writing & ContentAuto-check passed
  • Avoid AI Writing

    conorbronsdon/avoid-ai-writing

    Audit and rewrite content to remove AI writing patterns ("AI-isms").

    4.9k GitHub starsUsed in 3 repos~8.1k tokens
    Writing & ContentAuto-check passed
  • JavaScript Concept Fact Checker

    leonardomso/33-js-concepts

    Verifies the technical accuracy of JavaScript concept pages by checking code examples, MDN and ECMAScript claims and external links through a five-phase method.

    67k GitHub starsUsed in 1 repo~5k tokens
    Writing & ContentAuto-check passed
  • User-Facing Text Cleanup

    guillaumemeyer/watermarks-remover

    Audits prose for invisible Unicode characters and rewrites it while keeping facts, citations, code and required disclosures unchanged and the writer's voice intact.

    24k GitHub stars~3.5k tokensUpdated yesterday
    Writing & ContentAuto-check passed
  • Install Anti Slop

    trycompai/crm

    Install and configure the anti-slop Oxlint plugin in a local TypeScript or JavaScript repository.

    11k GitHub starsUsed in 1 repo~881 tokens
    Writing & ContentAuto-check passed

More from kharmanskyi/open-steps

  • Os Big Picture

    kharmanskyi/open-steps

    ALWAYS invoke this skill when the user asks where the project as a whole stands - "where are we", "what's the big picture", "what have we built", "what is in this project", "map the project", "what…

    1.3k GitHub stars~1.9k tokensUpdated 4 days ago
    Auto-check passed
  • Os Ask Simple

    kharmanskyi/open-steps

    ALWAYS invoke this skill before asking the user any technical question or offering options, and whenever they ask to be asked in plain words - "ask simple", "ask me simply", "ask me in plain words"…

    1.3k GitHub stars~1.4k tokensUpdated 4 days ago
    Auto-check passed
  • Os Check Work

    kharmanskyi/open-steps

    ALWAYS invoke this skill when the user asks about work done outside this session - "check work", "check the others", "check other sessions" - or to accept one: "the session is done, check it", "can…

    1.3k GitHub stars~1.9k tokensUpdated 4 days ago
    Auto-check passed
  • Os Whats Next

    kharmanskyi/open-steps

    ALWAYS invoke this skill when the user asks what to do next, what is left, or what is blocked - "what's next", "what now", "what should we work on", "anything I can do" - in any language.

    1.3k GitHub stars~1.9k tokensUpdated 4 days ago
    Auto-check passed
  • Os Done Or Not

    kharmanskyi/open-steps

    ALWAYS invoke this skill when work wraps up or the user asks how it went - "done or not", "are we done", "what happened", "report", "what's the status of this ticket" - in any language, and when a…

    1.3k GitHub stars~1.8k tokensUpdated 4 days ago
    Auto-check passed
  • Os Say Simple

    kharmanskyi/open-steps

    ALWAYS invoke this skill when the user asks for simpler or shorter about something said or written - "say it simply", "what does this mean", "I don't understand your answer", "too long", "wait…

    1.3k GitHub stars~1.3k tokensUpdated 4 days ago
    Auto-check passed

Questions about Os Step By Step

What does Os Step By Step do?

ALWAYS invoke this skill when you need the user to act - run a command, paste a secret, click, approve - and whenever they ask how to do something or say they do not know what to do: "step by step"…. Os Step By Step is an agent skill from kharmanskyi/open-steps. ALWAYS invoke this skill when you need the user to act - run a command, paste a secret, click, approve - and whenever they ask how to do something or say they do not know what to do: "step by step", "walk me through it", "what do I do", "what should I do", "I don't understand what to do", "explain what I need to do", in any language.

When should I use Os Step By Step?

Os Step By Step fits situations like: writing & Content work in your project.

How do I install Os Step By Step in Claude Code?

Run `npx skills add kharmanskyi/open-steps --skill os-step-by-step -a claude-code`. Or copy the skill folder (skills/os-step-by-step in kharmanskyi/open-steps) into .claude/skills/os-step-by-step in your project. Claude Code loads it when a task matches its description.

How do I install Os Step By Step in Codex?

Run `npx skills add kharmanskyi/open-steps --skill os-step-by-step -a codex`. Or copy the skill folder (skills/os-step-by-step in kharmanskyi/open-steps) into .agents/skills/os-step-by-step in your project. Codex loads it when a task matches its description.

Can I use Os Step By Step in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kharmanskyi/open-steps --skill os-step-by-step -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/os-step-by-step, .gemini/skills/os-step-by-step, .github/skills/os-step-by-step and .opencode/skills/os-step-by-step in your project.

What does Os Step By Step need to run?

Going by SKILL.md and its folder, Os Step By Step needs the command-line tools its instructions call (ssh). Its frontmatter pre-approves these tools: Read(~/.claude/open-steps/**).

Does Os Step By Step access the network?

SKILL.md contains no URLs. Its commands use ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Os Step By Step safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Os Step By Step use?

Os Step By Step is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Os Step By Step use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.

What are the alternatives to Os Step By Step?

Skills that share tags, products or a category with Os Step By Step: Social (coreyhaines31/marketingskills, 54k stars), Humanizer (Azure-Samples/interview-coach-agent-framework, 172 stars), Avoid AI Writing (conorbronsdon/avoid-ai-writing, 4.9k stars) and JavaScript Concept Fact Checker (leonardomso/33-js-concepts, 67k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Os Step By Step?

kharmanskyi (a GitHub user) maintains it in kharmanskyi/open-steps, which has 1,272 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 5, 2026.

Source: kharmanskyi/open-steps on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.