Agent skill

Kocoro

by Kocoro-lab in Kocoro-lab/Kocoro

Inspect AND manage Kocoro platform state — agents, skills, MCP servers, schedules, permissions, config, rules.

MITAuto-check: notesAgent Workflows

Install Kocoro

skills CLI
$ npx skills add Kocoro-lab/Kocoro --skill kocoro -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Kocoro-lab/Kocoro kocoro --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Kocoro-lab/Kocoro.git skills-src && mkdir -p .claude/skills && cp -r skills-src/internal/skills/bundled/skills/kocoro .claude/skills/kocoro && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kocoro
GitHub stars
414
Token cost
~2.5k tokens
SKILL.md length
1,028 words
Files
21 (incl. references)
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Inspect AND manage Kocoro platform state — agents, skills, MCP servers, schedules, permissions, config, rules.

  • Explicit operations on Kocoro-managed platform state under ~/.shannon/
  • SKILL.md covers Task-time capability gaps, Common Operations, Security and Style
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Including configured agents

What it does

Kocoro is an agent skill from Kocoro-lab/Kocoro. Inspect AND manage Kocoro platform state — agents, skills, MCP servers, schedules, permissions, config, rules. 中:列出/查看/查询/创建/修改/删除/配置/安装 agent/skill/MCP/计划/权限/规则。 日:一覧/表示/確認/検索/作成/更新/削除/設定/インストール エージェント/スキル/MCPサーバー/スケジュール/権限/ルール。 Use for explicit operations on Kocoro-managed platform state under ~/.shannon/, including configured agents, skills, MCP servers, schedules, permissions, rules, and config. Route only that platform-state portion through the daemon API; mixed requests may and should continue with file…

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 21 other files, including reference files (for example `references/agents.md`, `references/auth.md` and `references/calendar.md`).

It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: A Mac-native AI agent with memory, local computer access, browser control, IM channels, and MCP-native integrations. Built on Shannon. The licence is MIT.

When your agent uses it

  • Explicit operations on Kocoro-managed platform state under ~/.shannon/
  • Including configured agents

Example prompts

  • “/kocoro”

What it can do on your machine

Read from SKILL.md and the folder at commit 2d5a221. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kocoro loads about 2.5k tokens when it runs, and up to ~72k if it reads all its reference files. Until then it costs about 176 tokens; SKILL.md has 1,028 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~176
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~72k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:78
    ` (values go to OS keychain, NEVER edit `.env` or agent config for skill keys — see `references/skills.md`)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Kocoro-lab/Kocoro at commit 2d5a221, republished under its MIT licence (© Kocoro-lab). 1,028 words, ~2,521 tokens.

Download SKILL.mdSave it as .claude/skills/kocoro/SKILL.md (or your agent's skills folder). This skill also uses 20 other files; get the full folder from GitHub.
name
kocoro
description
Inspect AND manage Kocoro platform state — agents, skills, MCP servers, schedules, permissions, config, rules. 中:列出/查看/查询/创建/修改/删除/配置/安装 agent/skill/MCP/计划/权限/规则。 日:一覧/表示/確認/検索/作成/更新/削除/設定/インストール エージェント/スキル/MCPサーバー/スケジュール/権限/ルール。 Use for explicit operations on Kocoro-managed platform state under ~/.shannon/, including configured agents, skills, MCP servers, schedules, permissions, rules, and config. Route only that platform-state portion through the daemon API; mixed requests may and should continue with file, shell, web, and integration tools as appropriate. Do not use this platform-management skill merely to fill a task-time capability gap when discover_installable_skills is available.
hidden
true

Kocoro — Platform Configuration Assistant

You help users set up and manage their Kocoro platform.

Kocoro-managed platform operations go through the daemon HTTP API at http://localhost:7533. Use the http tool for those operations — with ONE exception: schedules use the native schedule_* tools (see "Create schedule" below). Never use bash/file_write/file_edit to manipulate Kocoro-managed state under ~/.shannon/ directly — the API handles validation, atomic writes, and audit logging that direct file access would bypass.

This routing rule is scoped. If a request also asks you to inspect a project file, run a command, search the web, or use an integration, use the corresponding tools for those parts. Activating this skill never means “HTTP only” for the whole run.

Task-time capability gaps

When discover_installable_skills is available and the current task needs a capability that is not in the visible installed skills, call it first. Do not guess a use_skill name, call /skills/downloadable or /skills/install/{name}, or ask for installation permission in text. If discovery returns a match, immediately call offer_skill_installation with the returned catalog IDs; that tool shows the localized Desktop card and stops the run so the user can choose.

The generic skill HTTP operations below are only for explicit platform administration, such as when the user asks to browse the catalog or directly install a named skill outside a capability-dependent task, and for consumers where the recommendation tools are not available. A user's consent reply to a task-time suggestion is not platform administration; use the card workflow.

Common Operations

Create an agent:

http POST http://localhost:7533/agents
body: {"display_name": "Agent Name", "prompt": "You are a ... assistant. You help users ..."}
# The slug is server-generated (agent-<6hex>) and returned in the response; clients send only display_name.

List agents: http GET http://localhost:7533/agents

Update agent prompt: http PUT http://localhost:7533/agents/{name} body: {"prompt": "..."}

Delete agent: http DELETE http://localhost:7533/agents/{name}?confirm=true (explain consequences first)

Agent config (model, tools): http PUT http://localhost:7533/agents/{name}/config body: {"agent": {"model": "..."}, "tools": {"allow": [...]}}

List globally installed skills: http GET http://localhost:7533/skills

List skills enabled for a named agent: http GET http://localhost:7533/agents/{name} and inspect skills

List bundled skills available to install (explicit administration): http GET http://localhost:7533/skills/downloadable

The runtime skill reminder contains only the skills enabled for the current agent. It is not a platform-wide installation inventory, and another agent can have a different enabled set. Always query GET /skills before answering which skills are installed globally.

Install a named skill directly (explicit administration only, outside a capability-dependent task): http POST http://localhost:7533/skills/install/{name}

Attach skill to agent: http PUT http://localhost:7533/agents/{name}/skills/{skill}

Set skill API keys: http PUT http://localhost:7533/skills/{slug}/secrets body: {"KEY_NAME": "value"} (values go to OS keychain, NEVER edit .env or agent config for skill keys — see references/skills.md)

Update settings: http PATCH http://localhost:7533/config body: {"agent": {"temperature": 0.7}}, then http POST http://localhost:7533/config/reload and verify with GET /config

Create rule: http PUT http://localhost:7533/rules/{name} body: {"content": "..."}

Schedules use the native schedule_* tools — NOT http. This is the one resource that must be created/updated/removed with the local tools (schedule_create, schedule_list, schedule_update, schedule_remove, schedule_show). They run through the same validated, audited ScheduleManager as the API, AND they capture the originating agent, channel, and conversation context — which is exactly what lets a schedule created from an IM channel (Slack/Lark/Feishu/…) proactively deliver its results back to that thread. A schedule created via raw http POST /schedules loses all of that: it runs as the default agent and never broadcasts, so the user never hears back.

  • Create: schedule_create { cron, prompt, description, [agent], [stateful], [broadcast] }
    • Pass stateful: true when the task must remember across runs (the prompt counts runs / "第几次", continues from last time, or tracks progress). Without it each run starts blank and such prompts break. Omit agent to schedule the current agent (don't pass agent: "" unless you really want the default agent).
  • List / Show / Update / Remove: schedule_list · schedule_show {id, …} · schedule_update {id, …} · schedule_remove {id, …}

Long markdown content — use body_from_file for raw-text endpoints. When uploading a long markdown file (instructions, rule body, etc.) to an endpoint that accepts raw text, send it with Content-Type: text/markdown and body_from_file. This avoids hand-escaping quotes / backslashes / newlines in inline JSON, which is the #1 source of 400 errors on these endpoints.

Show full SKILL.md (388 more words)Show less
http PUT http://localhost:7533/instructions
  headers: {"Content-Type": "text/markdown"}
  body_from_file: ~/source.md

Currently raw-text upload is supported on PUT /instructions only. For endpoints that still require a JSON wrapper (POST /agents prompt field, PUT /rules/{name} content field, etc.), inline body is the only option — keep those payloads short, or split a long prompt across an initial POST /agents (short prompt) followed by a separate PUT /agents/{name} to update the prompt later if the daemon grows raw-text support there.

For detailed docs on MCP servers, skill API keys, permissions, project init, or multi-step recipes, load the relevant reference: references/agents.md · references/skills.md · references/config.md · references/mcp.md · references/instructions.md · references/schedules.md · references/permissions.md · references/project-init.md · references/recipes.md · references/session-sync.md · references/memory.md · references/events.md · references/computer-use.md · references/queue.md · references/cancel.md · references/rewind.md · references/feishu.md

  • Session sync — default-on daily upload of local sessions to Shannon Cloud
  • Connect Feishu / Lark 飞书 连接 — auto-install a self-built Feishu/Lark bot from chat: drive the browser through the one-click app template, collect app_id/app_secret, POST /channels/feishu/app-installs (Cloud builds the larkws long connection), open user-info scope, publish
  • references/memory.md — memory feature config + diagnostics
  • references/events.md — /events SSE bus catalog (tool_status / usage / run_status / cloud_* / notification)
  • references/computer-use.md — internal Desktop control-plane, coordinate authority, and legacy-tool migration boundaries
  • references/queue.md — per-route mailbox: GET /queue, DELETE /queue/{id}, queue.* SSE events
  • references/cancel.md — extended POST /cancel with reason classification + optional last-user restore
  • references/rewind.md — POST /sessions/{id}/rewind slices history at a chosen user message

Security

NEVER modify these fields — the API rejects with 409. Do NOT add X-Confirm or any header to bypass: endpoint, api_key, permissions.denied_commands. Tell the user to edit ~/.shannon/config.yaml directly, then call POST /config/reload and verify the effective value with GET /config. MCP servers: shells (sh, bash, zsh), wrapper commands (env, nohup, sudo), and eval flags (-c, -e, --eval) are blocked. Use actual server binaries, not shell wrappers. publish_to_web extension allowlist (cloud.publish_allowed_extensions): additive only. Do not coach users to "just add .pem / .key / source code" to the allowlist to work around blocked uploads — the path/suffix denylist still applies and is intentionally not user-configurable. If a user wants to publish source code or configs, the right answer is "convert to .txt / .md first, after auditing for secrets". CONFIRM first: delete any resource, add MCP server, widen permissions, set daemon.auto_approve (disables approval prompts for all tool calls).

Style

  • Conversational. Propose names and solutions. Explain simply.
  • Complete every requested subtask; do not drop unrelated file, shell, web, or integration work from a mixed request.
  • After creating an agent, tell the user it's ready to use from the Kocoro Desktop sidebar.

© Kocoro-lab, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 20 other files (references) in internal/skills/bundled/skills/kocoro of Kocoro-lab/Kocoro.

  • SKILL.md
  • references/agents.md
  • references/auth.md
  • references/calendar.md
  • references/cancel.md
  • references/computer-use.md
  • references/config.md
  • references/desktop-rpc.md
  • references/events.md
  • references/feishu.md
  • references/instructions.md
  • references/mcp.md
  • references/memory.md
  • references/permissions.md
  • references/project-init.md
  • references/queue.md
  • references/recipes.md
  • references/rewind.md
  • references/schedules.md
  • references/session-sync.md
  • … and 1 more

Open the folder on GitHubat commit 2d5a221

Compare with similar skills

Kocoro next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kocoro compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kocoro this skillKocoro-lab/Kocoro414—~2.5kAutomated safety check: NotesMIT
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
Context Mode Output Sandboxmksglu/context-mode26k—~4.1kAutomated safety check: PassCustom licence

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Context Mode Output Sandbox

    mksglu/context-mode

    Routes large command, file, API and browser output through context-mode tools so only the needed result enters the agent's context, instead of dumping it via Bash.

    26k GitHub stars~4.1k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Migrates the compatible subset of settings and global file-based MCP servers from the Warp desktop app into Warp Agent CLI without exposing credentials or state.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    Agent WorkflowsAuto-check passed

More from Kocoro-lab/Kocoro

  • Claude API

    Kocoro-lab/Kocoro

    Build apps with the Claude API or Anthropic SDK. An agent skill from Kocoro-lab/Kocoro.

    414 GitHub starsUsed in 7 repos~4.5k tokens
    Auto-check passed
  • Kocoro Generative UI

    Kocoro-lab/Kocoro

    Generate interactive, inline HTML/SVG widgets (charts, diagrams, forms, dashboards, illustrations) that render in sandboxed iframes inside Kocoro Desktop chat.

    414 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check passed
  • PDF Reader

    Kocoro-lab/Kocoro

    Analyze PDF files attached by the user. An agent skill from Kocoro-lab/Kocoro.

    414 GitHub stars~482 tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Kocoro

What does Kocoro do?

Inspect AND manage Kocoro platform state — agents, skills, MCP servers, schedules, permissions, config, rules. Kocoro is an agent skill from Kocoro-lab/Kocoro. Inspect AND manage Kocoro platform state — agents, skills, MCP servers, schedules, permissions, config, rules.

When should I use Kocoro?

Kocoro fits situations like: explicit operations on Kocoro-managed platform state under ~/.shannon/; including configured agents.

How do I install Kocoro in Claude Code?

Run `npx skills add Kocoro-lab/Kocoro --skill kocoro -a claude-code`. Or copy the skill folder (internal/skills/bundled/skills/kocoro in Kocoro-lab/Kocoro) into .claude/skills/kocoro in your project. Claude Code loads it when a task matches its description.

How do I install Kocoro in Codex?

Run `npx skills add Kocoro-lab/Kocoro --skill kocoro -a codex`. Or copy the skill folder (internal/skills/bundled/skills/kocoro in Kocoro-lab/Kocoro) into .agents/skills/kocoro in your project. Codex loads it when a task matches its description.

Can I use Kocoro in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Kocoro-lab/Kocoro --skill kocoro -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kocoro, .gemini/skills/kocoro, .github/skills/kocoro and .opencode/skills/kocoro in your project.

What does Kocoro need to run?

SKILL.md names no scripts, command-line tools or credentials: Kocoro is instructions for the agent only.

Does Kocoro access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kocoro safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Kocoro use?

Kocoro is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kocoro use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 69k tokens, read only when the agent opens those files.

What are the alternatives to Kocoro?

Skills that share tags, products or a category with Kocoro: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Crush Configuration (charmbracelet/crush, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kocoro?

Kocoro-lab (a GitHub organization) maintains it in Kocoro-lab/Kocoro, which has 414 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 5, 2026.

Source: Kocoro-lab/Kocoro on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.