Agent skill

Restic

by magnus919 in magnus919/agent-skills

Install, configure, operate, secure, automate, tune, troubleshoot, and recover restic backups across local, SFTP, S3-compatible, cloud, and REST backends.

MITAuto-check passedDevOps & Cloud

Install Restic

skills CLI
$ npx skills add magnus919/agent-skills --skill restic -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install magnus919/agent-skills restic --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/restic .claude/skills/restic && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
restic
GitHub stars
115
Token cost
~1.8k tokens
SKILL.md length
696 words
Files
21 (incl. scripts, references)
Skills in repo
131
Repo updated
First seen
Licence
MIT

At a glance

Install, configure, operate, secure, automate, tune, troubleshoot, and recover restic backups across local, SFTP, S3-compatible, cloud, and REST backends.

  • Works in 5 steps: Discover before changing anything:… → Keep repository passwords and backend… → Before any mutation, confirm target… → …
  • Managing a restic repository
  • SKILL.md covers Operating contract, First read-only discovery, When not to use and Choose the path, plus 4 more sections
  • Runs Shell scripts from its folder

What it does

Restic is an agent skill from magnus919/agent-skills. Install, configure, operate, secure, automate, tune, troubleshoot, and recover restic backups across local, SFTP, S3-compatible, cloud, and REST backends. Use when creating or managing a restic repository, designing backup or retention policy, validating restores, handling repository health or locks, moving repositories, or building safe scheduled backup jobs. Do not use for a generic file-copy task that does not need encrypted, deduplicated snapshots.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 24 other files, including scripts and reference files (for example `README.md`, `evals/evals.json` and `references/backup-design-and-automation.md`). Compatibility notes: Requires the restic CLI. Live operations also require a reachable repository and its credentials; backend-specific tools or credentials may be required.

It sits in DevOps & Cloud, covering Backup and disaster recovery and File uploads and storage. The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.

When your agent uses it

  • Managing a restic repository
  • Designing backup
  • Retention policy
  • Validating restores

Example prompts

  • “/restic”

Requirements

  • A Bash shell
  • Compatibility (from SKILL.md): Requires the restic CLI. Live operations also require a reachable repository and its credentials; backend-specific tools or credentials may be required.

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Discover before changing anything: restic version, backend type, repository format, source paths, credentials mechanism, schedule…
  2. Keep repository passwords and backend credentials out of command history, logs, templates, and chat. Prefer a root/user-readable password…
  3. Before any mutation, confirm target repository, source scope, exclusions, retention groups, schedule, maintenance window, and…
  4. Back up with stable host and tag conventions. Inspect the resulting snapshot, then test a restore into an empty, separate target. A…
  5. Treat forget, prune, key remove, rebuild-index, repair, migrate, and backend lifecycle rules as consequential operations. Preview where…

What it can do on your machine

Read from SKILL.md and the folder at commit 22b4723. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Shell, from the files we listed), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the restic CLI. Live operations also require a reachable repository and its credentials; backend-specific tools or credentials may be required.

    From compatibility in the SKILL.md frontmatter.

Context cost

Restic loads about 1.8k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 696 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from magnus919/agent-skills at commit 22b4723, republished under its MIT licence (© magnus919). 696 words, ~1,832 tokens.

Download SKILL.mdSave it as .claude/skills/restic/SKILL.md (or your agent's skills folder). This skill also uses 20 other files; get the full folder from GitHub.
name
restic
description
Install, configure, operate, secure, automate, tune, troubleshoot, and recover restic backups across local, SFTP, S3-compatible, cloud, and REST backends. Use when creating or managing a restic repository, designing backup or retention policy, validating restores, handling repository health or locks, moving repositories, or building safe scheduled backup jobs. Do not use for a generic file-copy task that does not need encrypted, deduplicated snapshots.
compatibility
Requires the restic CLI. Live operations also require a reachable repository and its credentials; backend-specific tools or credentials may be required.
license
MIT
metadata.source
https://restic.readthedocs.io/en/stable/
metadata.research_checked
2026-07-15

Restic

Restic is a backup CLI, not a daemon. Treat a scheduled job or service manager as the execution layer. Every usable backup design proves four things: the source was captured, the repository is readable, retention is intentional, and a restore works in a separate target.

Operating contract

  1. Discover before changing anything: restic version, backend type, repository format, source paths, credentials mechanism, schedule, retention policy, and recovery objective.
  2. Keep repository passwords and backend credentials out of command history, logs, templates, and chat. Prefer a root/user-readable password file or a secret manager command over inline values.
  3. Before any mutation, confirm target repository, source scope, exclusions, retention groups, schedule, maintenance window, and rollback/recovery path. Read-only discovery may proceed without confirmation.
  4. Back up with stable host and tag conventions. Inspect the resulting snapshot, then test a restore into an empty, separate target. A successful backup exit code is not recovery evidence.
  5. Treat forget, prune, key remove, rebuild-index, repair, migrate, and backend lifecycle rules as consequential operations. Preview where possible and keep a known-good recovery path.

First read-only discovery

sh
scripts/restic-preflight.sh
restic version
restic snapshots --json
restic stats --mode raw-data

Set repository location and password source through the environment or command flags before commands that open a repository. Do not export a literal password into a shared shell history. See repository and backend setup.

When not to use

Do not load this for a one-time unencrypted file copy, a database backup format that restic cannot create, or provider-specific object-storage administration without a restic repository. Use the relevant application backup procedure for consistency, then use this skill to protect its resulting artifacts.

Choose the path

NeedRead first
Install or choose a supported binaryfoundations and installation
Initialize a repository or select local, SFTP, object storage, REST, or rclone backendrepository and backends
Design sources, excludes, tags, schedules, or service-manager automationbackup design and automation
Write unattended jobs, handle exit codes, parse JSON, or reason about locksscripting and command contract
Define retention, run maintenance, verify integrity, or conduct a restore drillretention, integrity, and recovery
Threat-model secrets, access, ransomware, or credentialssecurity and threat model
Reduce runtime, control bandwidth/cache, or collect useful evidenceperformance and observability
Diagnose failure, locks, corruption, backend errors, or copy/migration worktroubleshooting and migration
Check source scope, version currency, or a backend claimsource index
Show full SKILL.md (317 more words)Show less

Safe workflow

Generated data: Before embedding a database export in a backup job, read the scripting and command contract. --stdin-from-command runs exactly one producer command after --; an outer shell pipe is not part of that producer. For compression or transformation, pass a tested wrapper program as the producer, or use backup --stdin only with pipefail and explicit failure handling.

sh
# 1. Read-only preflight. It never prints secret values.
scripts/restic-preflight.sh

# 2. Initialize only after confirming the intended empty target.
restic init --repo /path/to/repository --password-file /secure/path/restic-password

# 3. Create a tagged snapshot, then inspect it.
restic --repo /path/to/repository --password-file /secure/path/restic-password \
  backup /data --tag production --tag files
restic --repo /path/to/repository --password-file /secure/path/restic-password snapshots

# 4. Restore to an empty, separate directory and inspect the result.
restic --repo /path/to/repository --password-file /secure/path/restic-password \
  restore latest --target /var/tmp/restic-restore-test

Use templates/backup-policy.env.example to document non-secret policy and templates/restore-drill.md to record an evidence-backed recovery test. For Linux scheduling, adapt templates/systemd/restic-backup.service and templates/systemd/restic-backup.timer; keep secret paths and source paths local, not committed.

Scripts

  • scripts/restic-preflight.sh — read-only local configuration and CLI checks; it redacts values and never opens a repository.
  • scripts/restic-verify.sh — bounded repository verification: metadata check by default, optional sampled or full data reads. It does not alter retention or prune data.
  • scripts/test-restic-preflight.sh — deterministic shell test using a fake restic executable.
  • scripts/test-restic-verify.sh — deterministic shell test for bounded check-command construction.

Run scripts from the skill root. They require Bash and restic; restic-verify.sh also requires an already configured repository and password mechanism.

Hard boundaries

  • Never run prune in the same unattended window as the only backup job unless its duration and lock impact are understood.
  • Never equate forget with reclaimed storage. forget removes snapshot references; prune later removes unreferenced data.
  • Never restore over a production source path as a first recovery step. Restore elsewhere, validate, then perform a deliberate cutover.
  • Never use unlock merely because a backup is blocked. First establish whether another restic process is active and whether the lock is stale.
  • Never assume provider immutability, retention, permissions, or object-lock semantics from a generic S3 URL. Verify the specific backend's policy and restore it in a drill.

Exit criteria

The requested operation is complete only when its relevant boundary is evidenced: installation reports the expected binary; a backup has a listed snapshot; maintenance has a post-operation check; and recovery has a restore into a separate target plus an inspection of the restored data.

© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 20 other files (scripts, references) in restic of magnus919/agent-skills.

  • SKILL.md
  • README.md
  • evals/evals.json
  • references/backup-design-and-automation.md
  • references/foundations-and-installation.md
  • references/performance-and-observability.md
  • references/repository-and-backends.md
  • references/retention-integrity-and-recovery.md
  • references/scripting-and-command-contract.md
  • references/security-and-threat-model.md
  • references/source-index.md
  • references/troubleshooting-and-migration.md
  • scripts/restic-preflight.sh
  • scripts/restic-verify.sh
  • scripts/test-restic-preflight.sh
  • scripts/test-restic-verify.sh
  • templates/backup-policy.env.example
  • … and 4 more

Open the folder on GitHubat commit 22b4723

Compare with similar skills

Restic next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Restic compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Restic this skillmagnus919/agent-skills115—~1.8kAutomated safety check: PassMIT
Storage S3 Resiliency Expertiseaws/tools-for-devops-agent103—~2.8kAutomated safety check: PassApache-2.0
Implementing Immutable Backup With Resticmukul975/Anthropic-Cybersecurity-Skills34k—~1kAutomated safety check: PassApache-2.0
Database Backupssickn33/agentic-awesome-skills47k2 repos~3.1kAutomated safety check: NotesMIT
Storage Fsx Windows Sla Optimizeraws/tools-for-devops-agent103—~3.4kAutomated safety check: PassApache-2.0
Kopiur Designhome-operations/kopiur115—~2.4kAutomated safety check: PassAGPL-3.0

Similar skills

  • Storage S3 Resiliency Expertise

    aws/tools-for-devops-agent

    Official

    S3 resiliency, security, and data protection review. An agent skill from aws/tools-for-devops-agent.

    103 GitHub stars~2.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Implementing Immutable Backup With Restic

    mukul975/Anthropic-Cybersecurity-Skills

    Implements ransomware-resistant backups using restic with S3-compatible Object Lock (AWS S3, MinIO, Backblaze B2), automating backup creation, integrity checks via restic check --read-data…

    34k GitHub stars~1k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Database Backups

    sickn33/agentic-awesome-skills

    Implement database backup strategies. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3.1k tokens
    DatabasesAuto-check: notes
  • Storage Fsx Windows Sla Optimizer

    aws/tools-for-devops-agent

    Official

    Read-only SLA-readiness, availability, and cost review of Amazon FSx for Windows File Server.

    103 GitHub stars~3.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Kopiur Design

    home-operations/kopiur

    Design norms and locked decisions for the Kopiur Kopia-native Kubernetes backup operator (Rust/kube-rs).

    115 GitHub stars~2.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Mongodb Backups

    TheDecipherist/claude-code-mastery-project-starter-kit

    Production MongoDB backup and restore practices that the documentation gets wrong.

    338 GitHub stars~1.3k tokensUpdated 3 mo ago
    DatabasesAuto-check passed

More from magnus919/agent-skills

All 131 skills in this repo
  • Artifact Pyramids

    magnus919/agent-skills

    Organize durable agent research outputs as summaries, analysis, and evidence dossiers.

    115 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Ascii City Engine

    magnus919/agent-skills

    Build portable, first-person colored ASCII city engines and small GIS-derived city packs.

    115 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Color Management

    magnus919/agent-skills

    Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.

    115 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Data Scientist

    magnus919/agent-skills

    A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…

    115 GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Docker Compose

    magnus919/agent-skills

    Use Docker Compose to define, run, debug, and harden multi-container applications.

    115 GitHub stars~2k tokensUpdated today
    Auto-check: notes
  • Fpga Development

    magnus919/agent-skills

    Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.

    115 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Questions about Restic

What does Restic do?

Install, configure, operate, secure, automate, tune, troubleshoot, and recover restic backups across local, SFTP, S3-compatible, cloud, and REST backends. Restic is an agent skill from magnus919/agent-skills. Install, configure, operate, secure, automate, tune, troubleshoot, and recover restic backups across local, SFTP, S3-compatible, cloud, and REST backends.

When should I use Restic?

Restic fits situations like: managing a restic repository; designing backup; retention policy; validating restores.

How do I install Restic in Claude Code?

Run `npx skills add magnus919/agent-skills --skill restic -a claude-code`. Or copy the skill folder (restic in magnus919/agent-skills) into .claude/skills/restic in your project. Claude Code loads it when a task matches its description.

How do I install Restic in Codex?

Run `npx skills add magnus919/agent-skills --skill restic -a codex`. Or copy the skill folder (restic in magnus919/agent-skills) into .agents/skills/restic in your project. Codex loads it when a task matches its description.

Can I use Restic in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill restic -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/restic, .gemini/skills/restic, .github/skills/restic and .opencode/skills/restic in your project.

What does Restic need to run?

Going by SKILL.md and its folder, Restic needs a shell for the scripts in its folder. Our summary lists: A Bash shell. Compatibility (from SKILL.md): Requires the restic CLI. Live operations also require a reachable repository and its credentials; backend-specific tools or credentials may be required..

Does Restic access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Restic safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Restic use?

Restic is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Restic use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to Restic?

Skills that share tags, products or a category with Restic: Storage S3 Resiliency Expertise (aws/tools-for-devops-agent, 103 stars), Implementing Immutable Backup With Restic (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Database Backups (sickn33/agentic-awesome-skills, 47k stars) and Storage Fsx Windows Sla Optimizer (aws/tools-for-devops-agent, 103 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Restic?

magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 115 GitHub stars. The repository holds 131 skills in this directory. The repository was last updated on October 10, 2026.

Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.