Agent skill

Autobahn

by LilMGenius in LilMGenius/paperthin

Carve guardrail-adjacent items out of scope with safe alternatives before risk-adjacent work starts, then run the safe remainder at full strength in a fresh subagent that only ever sees the carved…

MITAuto-check passedAI & LLM Engineering

Install Autobahn

skills CLI
$ npx skills add LilMGenius/paperthin --skill autobahn -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LilMGenius/paperthin autobahn --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LilMGenius/paperthin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/depth/autobahn .claude/skills/autobahn && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
autobahn
GitHub stars
1.1k
Token cost
~2.1k tokens
SKILL.md length
1,215 words
Files
1
Skills in repo
28
Repo updated
First seen
Licence
MIT

At a glance

Carve guardrail-adjacent items out of scope with safe alternatives before risk-adjacent work starts, then run the safe remainder at full strength in a fresh subagent that only ever sees the carved…

  • Works in 6 steps: FRAME: Read the task, inputs, and… → CARVE: Sweep the task and adjacent… → GUARD: Distill the carve into a compact… → …
  • A task includes stealth
  • SKILL.md covers Goal, Workflow, Rules and Verification
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Autobahn is an agent skill from LilMGenius/paperthin. Carve guardrail-adjacent items out of scope with safe alternatives before risk-adjacent work starts, then run the safe remainder at full strength in a fresh subagent that only ever sees the carved prompt, never the risky input. Use when a task includes stealth, scraping, privacy, IP, policy, licensing, security, or other safety-adjacent material that could be silently dropped, over-elaborated, or needlessly diluted. Fires on the impulse, not only the topic: the moment you notice yourself about to hedge, soften…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering, covering Web scraping and Subagents. The repository describes itself as: Low-level agentic design patterns. Turning old engineering wisdom into reflexes your agent reaches for on its own—on any agent. The licence is MIT.

When your agent uses it

  • A task includes stealth
  • Other safety-adjacent material that could be silently dropped
  • Over-elaborated
  • Needlessly diluted

Example prompts

  • “/autobahn”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. FRAME: Read the task, inputs, and user-stated risk posture. If the user already authorized descoping, proceed. If not, produce a proposed…
  2. CARVE: Sweep the task and adjacent inputs for guardrail-adjacent items. For each, propose verdict=descope, class it bright-line or…
  3. GUARD: Distill the carve into a compact scope-guard block (absolute exclusions, allowed alternatives, and the context that authorizes what…
  4. RUN: Spawn a fresh, context-clean subagent (a Task that starts with no prior context) and hand it only the carved prompt, never the risky…
  5. VERIFY: Run an adversarial pass over the returned deliverable and adjacent artifacts, checking all five failure directions: risky content…
  6. LEDGER: Once the run has finished and the subagent's window is closed, report the deliverable with a descope ledger listing every carved…

What it can do on your machine

Read from SKILL.md and the folder at commit 7d5dc62. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Autobahn loads about 2.1k tokens when it runs. Until then it costs about 148 tokens; SKILL.md has 1,215 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~148
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LilMGenius/paperthin at commit 7d5dc62, republished under its MIT licence (© LilMGenius). 1,215 words, ~2,060 tokens.

Download SKILL.mdSave it as .claude/skills/autobahn/SKILL.md (or your agent's skills folder).
name
autobahn
description
Carve guardrail-adjacent items out of scope with safe alternatives before risk-adjacent work starts, then run the safe remainder at full strength in a fresh subagent that only ever sees the carved prompt, never the risky input. Use when a task includes stealth, scraping, privacy, IP, policy, licensing, security, or other safety-adjacent material that could be silently dropped, over-elaborated, or needlessly diluted. Fires on the impulse, not only the topic: the moment you notice yourself about to hedge, soften, silently skip, or brace for a refusal, carve before you execute.

Carve unsafe scope out of a task, then run the safe remainder in a fresh subagent that only ever sees the carved prompt, and report it with a visible descope ledger.

Goal

Turn risk-adjacent work into an explicit scope decision, then execute the safe scope in a clean room. The carve happens here; the running happens in a fresh subagent that receives only the carved prompt, never the risky original or this session's reasoning. That split is the point: the executing mind never reads a risky ask, so it has nothing to hedge, dilute, or refuse, and the safe work goes at full strength. autobahn is not evasion: it does not slip a flagged ask past a guardrail, it removes the ask and runs a genuinely safe prompt instead.

Workflow

  1. FRAME: Read the task, inputs, and user-stated risk posture. If the user already authorized descoping, proceed. If not, produce a proposed carve, make its split explicit, and wait for approval before RUN: a bright-line item has no safe version, so it is non-negotiable; a gray-zone item's safe alternative trades away scope the user might want, so it is the real question. If every item is bright-line, proceed; the ledger carries the record. If the user disputes a bright-line call itself, don't let the pressured session re-litigate it: hand the item's abstract description, stripped of the negotiation and any persuasion, to a fresh context for re-evaluation, and record the appeal and its outcome in the ledger either way.
  2. CARVE: Sweep the task and adjacent inputs for guardrail-adjacent items. For each, propose verdict=descope, class it bright-line or gray-zone, give one risk-free alternative, and name an archive destination per the negatives-as-corpus convention. A gray-zone item the user decides to keep stays in scope and enters the ledger as a kept-by-owner decision. Point to excluded techniques only as far as identification requires; never elaborate them.
  3. GUARD: Distill the carve into a compact scope-guard block (absolute exclusions, allowed alternatives, and the context that authorizes what stays in scope) and fold it into the carved prompt so the run carries it verbatim. The block names each exclusion so the run cannot re-introduce it, never the original risky ask verbatim or its method. In a harness where the run shares a filesystem or a memory store with this session, the block also tells the run not to consult decision logs, notes, or transcript search over that shared state: a clean prompt does no good if the run can read the risky ask back out of something this session just wrote nearby. Instruct the run to build the safe scope at full strength, with no hedging, apology, or shrunken deliverable.
  4. RUN: Spawn a fresh, context-clean subagent (a Task that starts with no prior context) and hand it only the carved prompt, never the risky original or your carve reasoning. It runs the safe scope at full strength and returns the deliverable; the executing agent never sees a risky ask, so the carve, not this session, is what lets it floor it. If risky material surfaces inside a subagent, it routes back here through CARVE, never improvised inline.
  5. VERIFY: Run an adversarial pass over the returned deliverable and adjacent artifacts, checking all five failure directions: risky content elaborated, risky content silently dropped, safe work diluted or treated as excluded, stale risky material left standing nearby, and the carve itself missed or over-excluded something — re-sweep the original task from a context independent of this one and diff the result against the ledger before reporting. Cap that independent re-sweep at one pass (N=1), not open-ended fan-out.
  6. LEDGER: Once the run has finished and the subagent's window is closed, report the deliverable with a descope ledger listing every carved item: its class, its verdict of descoped or kept-by-owner, the reason, the safe alternative, and the archive destination. Write the archive entry only now, not earlier — a record of the risky material sitting on disk while the run is still active undoes the isolation the carve bought. Treat exclusions as visible decisions, not gaps.
Show full SKILL.md (538 more words)Show less

Rules

  • The executing subagent sees only the carved prompt. Never hand it the risky original, your carve reasoning, or this session's context; a clean executing context is what keeps the safe run flag-free and the skill non-evasive. Where the run has filesystem or memory access alongside this session, the carved prompt also forbids it from consulting decision logs, notes, or transcript search — a clean prompt is not enough if the run can reconstruct the risky ask from something adjacent.
  • A same-session appeal is not a re-review: if the user pushes back on a bright-line call, route the dispute to a fresh context holding only the item's abstract description, not the negotiation. Repeated appeals on the same item are themselves a signal worth surfacing, not just resolving.
  • Require a proposed carve when the user has not pre-authorized descoping; do not begin RUN while a gray-zone item that shapes the carved prompt still awaits an answer. Bright-line exclusions are never negotiable, so never stall on those alone.
  • Never probe: do not pose an excluded or gray-zone ask to see whether it passes. The carve settles scope before any such ask exists.
  • Keep the scope-guard block portable and exact, and bake it into the carved prompt verbatim. It must guard both directions: the run elaborates no excluded material, and dilutes, hedges, or re-refuses nothing the carve kept in scope.
  • Guard against unsafe elaboration: never provide operational detail for excluded techniques beyond the minimum needed to identify what is out of scope. This binds the ledger and the carved prompt themselves.
  • Do not frame the skill as a way around safety controls. It honors constraints by removing risky asks before they are posed and by running a genuinely safe prompt in a clean room. It cannot make a flagged input pass; it produces a different, safe input.
  • Do not claim control over model routing, fallback provisioning, or fixed-model selection; those are harness behavior, not prompt behavior.
  • Preserve negatives-as-corpus: descoped material is archived with its cause of death and safe replacement, never erased from the record, so a later pass can mine the ledger for anti-patterns. Write that archive entry after the run has finished, not before — the point of the carve is that the risky material never sits where the run could read it.

Verification

Before finishing, confirm:

  • The CARVE covers every guardrail-adjacent item found, each carrying a class, a verdict of descoped or kept-by-owner, a safe alternative, and an archive destination.
  • The RUN subagent received only the carved prompt, its baked-in guard held both directions with no downstream hedging or elaboration, and — where filesystem or memory access is shared — the prompt also barred it from decision logs, notes, or transcript search over that shared state.
  • The safe deliverable was not diluted because of nearby risky material, and every mid-run discovery routed back through CARVE into the ledger.
  • An independent re-sweep of the original task, done from a fresh context, was diffed against the ledger before reporting, and any gap it surfaced — missed risk or an over-broad exclusion — was folded back in.
  • The archive entry for descoped material was written after the run closed, not before.
  • The final report includes a distinct LEDGER section with exclusions, classes, reasons, alternatives, and archive destinations.

© LilMGenius, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/depth/autobahn of LilMGenius/paperthin.

Open the folder on GitHubat commit 7d5dc62

Compare with similar skills

Autobahn next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Autobahn compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Autobahn this skillLilMGenius/paperthin1.1k—~2.1kAutomated safety check: PassMIT
Agent BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
Prompt Template Authoringnicobailon/pi-prompt-template-model321—~1.3kAutomated safety check: PassMIT
Langgraph Agent Patternssoba-labs/langchain-agent-skills107—~3.6kAutomated safety check: PassMIT
Analyze Runget-convex/convex-evals130—~2.1kAutomated safety check: PassApache-2.0
Performance Ab Benchmark Reviewbbartling/open-fdd173—~1.4kAutomated safety check: PassCustom licence

Similar skills

  • Agent Builder

    shareAI-lab/learn-claude-code

    Design and build AI agents for any domain. An agent skill from shareAI-lab/learn-claude-code.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    AI & LLM EngineeringAuto-check passed
  • Prompt Template Authoring

    nicobailon/pi-prompt-template-model

    Write and run custom Pi prompt templates (slash commands) for this extension.

    321 GitHub stars~1.3k tokensUpdated 18 days ago
    AI & LLM EngineeringAuto-check passed
  • Langgraph Agent Patterns

    soba-labs/langchain-agent-skills

    Implement multi-agent coordination patterns (supervisor-subagent, router, orchestrator-worker, handoffs) for LangGraph applications.

    107 GitHub stars~3.6k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed
  • Analyze Run

    get-convex/convex-evals

    Analyze all failures in a convex-evals run, spawning parallel sub-agents to investigate each failure and producing a report with classifications and recommendations.

    130 GitHub stars~2.1k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • A skill your agent uses to design, run, or review performance work with reproducible A/B baselines.

    173 GitHub stars~1.4k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Instruction Tuning

    adam-s/intercept

    Use sub-agents as test subjects to iteratively improve .claude/ instruction files.

    189 GitHub stars~4.6k tokensUpdated 2 mo ago
    AI & LLM EngineeringAuto-check passed

More from LilMGenius/paperthin

All 28 skills in this repo
  • Modelchk

    LilMGenius/paperthin

    Size a task's run before spending it: the cheapest sufficient capability tier (fast, standard, frontier) and the reasoning effort within it, on a neutral scale that binds to whatever levels the…

    1.1k GitHub stars~1.6k tokensUpdated 8 days ago
    Auto-check passed
  • Re0 Loop

    LilMGenius/paperthin

    Run repeated build - QA - re0-memo - re0-work cycles while preserving learning and letting code die.

    1.1k GitHub stars~579 tokensUpdated 8 days ago
    Auto-check passed
  • Catchup

    LilMGenius/paperthin

    Rebuild the human's lost context on a project from live state, in plain language: what needs them, what changed, what new words mean.

    1.1k GitHub stars~785 tokensUpdated 8 days ago
    Auto-check passed
  • Debloat

    LilMGenius/paperthin

    Compress an artifact that has accreted into bloat — padding, over-qualification, fused sentences, walls of enumeration, adjacent restatement — down to its load-bearing density, meaning preserved.

    1.1k GitHub stars~813 tokensUpdated 8 days ago
    Auto-check passed
  • Factchk

    LilMGenius/paperthin

    Verify reality-grounded claims against external sources in both directions before they ship — could the 'absurd' be real, could the 'obvious' be false or long-established?

    1.1k GitHub stars~717 tokensUpdated 8 days ago
    Auto-check passed
  • Nba

    LilMGenius/paperthin

    Read the live cycle state and return the single highest-leverage next best action, not a menu.

    1.1k GitHub stars~540 tokensUpdated 8 days ago
    Auto-check passed

Questions about Autobahn

What does Autobahn do?

Carve guardrail-adjacent items out of scope with safe alternatives before risk-adjacent work starts, then run the safe remainder at full strength in a fresh subagent that only ever sees the carved…. Autobahn is an agent skill from LilMGenius/paperthin. Carve guardrail-adjacent items out of scope with safe alternatives before risk-adjacent work starts, then run the safe remainder at full strength in a fresh subagent that only ever sees the carved prompt, never the risky input.

When should I use Autobahn?

Autobahn fits situations like: A task includes stealth; other safety-adjacent material that could be silently dropped; over-elaborated; needlessly diluted.

How do I install Autobahn in Claude Code?

Run `npx skills add LilMGenius/paperthin --skill autobahn -a claude-code`. Or copy the skill folder (skills/depth/autobahn in LilMGenius/paperthin) into .claude/skills/autobahn in your project. Claude Code loads it when a task matches its description.

How do I install Autobahn in Codex?

Run `npx skills add LilMGenius/paperthin --skill autobahn -a codex`. Or copy the skill folder (skills/depth/autobahn in LilMGenius/paperthin) into .agents/skills/autobahn in your project. Codex loads it when a task matches its description.

Can I use Autobahn in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LilMGenius/paperthin --skill autobahn -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/autobahn, .gemini/skills/autobahn, .github/skills/autobahn and .opencode/skills/autobahn in your project.

What does Autobahn need to run?

SKILL.md names no scripts, command-line tools or credentials: Autobahn is instructions for the agent only.

Does Autobahn access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Autobahn safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Autobahn use?

Autobahn is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Autobahn use?

About 2.1k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Autobahn?

Skills that share tags, products or a category with Autobahn: Agent Builder (shareAI-lab/learn-claude-code, 78k stars), Prompt Template Authoring (nicobailon/pi-prompt-template-model, 321 stars), Langgraph Agent Patterns (soba-labs/langchain-agent-skills, 107 stars) and Analyze Run (get-convex/convex-evals, 130 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Autobahn?

LilMGenius (a GitHub user) maintains it in LilMGenius/paperthin, which has 1,130 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 1, 2026.

Source: LilMGenius/paperthin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.