Agent skill

Create Template

by mathematic-inc in mathematic-inc/earl

Creates a new Earl HCL template for a specific API, database, or shell command.

Apache-2.0Auto-check passedSecurity

Install Create Template

skills CLI
$ npx skills add mathematic-inc/earl --skill create-template -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mathematic-inc/earl create-template --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mathematic-inc/earl.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/development/create-template .claude/skills/create-template && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
create-template
GitHub stars
113
Token cost
~2.8k tokens
SKILL.md length
1,046 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Creates a new Earl HCL template for a specific API, database, or shell command.

  • Works in 8 steps: Discover Intent → Infer Protocol → Load Reference → …
  • Adding a new service to Earls template library
  • SKILL.md covers Process, Phase 1: Discover Intent, Phase 2: Infer Protocol and Phase 3: Load Reference, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Create Template is an agent skill from mathematic-inc/earl. Creates a new Earl HCL template for a specific API, database, or shell command. Use when adding a new service to Earl's template library, or when a pre-built template doesn't cover a needed command.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. It works with GitHub. The repository describes itself as: Secure CLI proxy for AI agents — HCL-defined operation templates with OS keychain secrets, MCP integration, and prompt injection protection. The licence is Apache-2.0.

When your agent uses it

  • Adding a new service to Earls template library
  • A pre-built template doesnt cover a needed command

Example prompts

  • “s template library, or when a pre-built template doesn”
  • “Use the create-template skill to create a new Earl HCL template for a specific API, database, or shell command”
  • “/create-template”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Discover Intent
  2. Infer Protocol
  3. Load Reference
  4. Draft Template
  5. Human Review (Required)
  6. Validate
  7. Set Secrets
  8. Verify

What it can do on your machine

Read from SKILL.md and the folder at commit c56a45f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and hcl).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • mathematic-inc.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Create Template loads about 2.8k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 1,046 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mathematic-inc/earl at commit c56a45f, republished under its Apache-2.0 licence (© mathematic-inc). 1,046 words, ~2,780 tokens.

Download SKILL.mdSave it as .claude/skills/create-template/SKILL.md (or your agent's skills folder).
name
create-template
description
Creates a new Earl HCL template for a specific API, database, or shell command. Use when adding a new service to Earl's template library, or when a pre-built template doesn't cover a needed command.

Create Template

Creates an Earl HCL template file for a specific service and protocol. Each template defines the commands, parameters, authentication, and protocol shape for one provider.

Process

  1. Discover — understand what service and command to build
  2. Infer protocol — map the user's description to one of Earl's 5 protocols
  3. Load reference — read the protocol reference for HCL shapes and patterns
  4. Write template — create the HCL file
  5. Review — show the user the complete template before running it
  6. Validate — run earl templates validate
  7. Secrets — print checklist for the human to set secrets
  8. Verify — run a test earl call

Phase 1: Discover Intent

If the request doesn't name a provider, command, and protocol, ask one question:

"What service do you want to call, and what should the command do? For example: 'Call the GitHub API to create an issue' or 'Query my PostgreSQL database for user records'."

Check for pre-built templates first

Earl ships with 26 ready-made provider templates. If the user names a known service, check whether it is already imported before offering to import it:

bash
earl templates list

Check the list carefully:

  • If the specific command needed is already present (e.g. github.create_issue appears in the list), skip the import and go directly to Phase 7 to set any missing secrets.
  • If the provider is imported but the specific command is not in the list (e.g. github commands appear but not github.create_issue), skip the import and proceed to custom template authoring (phases 2–6) to add the missing command to the existing file.
  • If the provider is not imported at all, offer to import the pre-built template:
bash
# Available: github, stripe, slack, notion, openai, anthropic, recall_ai, discord, gitlab, jira, linear,
#            pagerduty, twilio, sendgrid, cloudflare, vercel, render, shopify, hubspot,
#            mailchimp, datadog, sentry, airtable, auth0, supabase, resend
earl templates import https://raw.githubusercontent.com/mathematic-inc/earl/main/examples/<provider>.hcl

If a pre-built template was imported, skip to Phase 7: Set Secrets — phases 2–6 are not needed. Then continue to Phase 8 to verify the template works.

Only proceed to custom template authoring (phases 2–6) if no pre-built template covers the needed command.


Phase 2: Infer Protocol

Map the user's description to a protocol:

User mentionsProtocolReference file
REST, HTTP, API, endpoint, JSON API, webhookhttp../references/http-templates.md (raw)
GraphQL, query/mutation (in API context)graphql../references/graphql-templates.md (raw)
gRPC, protobuf, service meshgrpc../references/grpc-templates.md (raw)
shell, bash, CLI, script, command linebash../references/bash-templates.md (raw)
SQL, database, postgres, mysql, sqlitesql../references/sql-templates.md (raw)

If the answer is genuinely ambiguous, ask one follow-up question.

SSRF Warning

If the user mentions localhost, 127.0.0.1, 0.0.0.0, or any private IP range (10.x, 172.16-31.x, 192.168.x), warn immediately:

Earl blocks requests to private and loopback IP addresses (SSRF protection). This cannot be bypassed. Use a publicly accessible URL, or use the bash protocol to call local services.


Phase 3: Load Reference

Read the reference file for the chosen protocol before writing any HCL. The reference file contains the complete template shape, required fields, auth patterns, and known gotchas.

Critical rule for all protocols: HCL parses before Jinja renders. All {{ }} expressions must be inside valid HCL string values.

hcl
# WRONG — invalid HCL:
params = [{{ args.limit }}]

# CORRECT — Jinja expression inside a string, rendered to a number at call time:
params = ["{{ args.limit }}"]

Phase 4: Draft Template

Do NOT write the file to disk yet. Compose the template content in memory — it will be written to disk only after Phase 5 human review and approval.

Target path (determine now, write after approval):

  • Local (project-specific): ./templates/<provider>.hcl
  • Global (all projects): ~/.config/earl/templates/<provider>.hcl (macOS/Linux) or %APPDATA%\earl\templates\<provider>.hcl (Windows)

Default to local if the current directory is a project (contains .git/, package.json, Cargo.toml, or similar). Default to global otherwise.

Provider naming: lowercase letters and underscores only. No hyphens, dots, or uppercase. Examples: github, my_company_api, internal_db.

If the file already exists: Read it first. Add the new command block to the existing file rather than overwriting it.

Environments (optional): If the user needs staging/production separation, add an environments block at the provider level. Environment variables are available as vars.* in all template expressions. See the template schema docs for full syntax. Only add environments when the user explicitly needs them — most templates don't.

Template structure:

hcl
version = 1
provider = "<provider_name>"

command "<command_name>" {
  title       = "<Short title, shown in tool listings>"
  summary     = "<One-line summary>"
  description = <<-EOT
    <Full description of what this command does.>

    Parameters:
    - param_name: description

    ## Guidance for AI agents
    Use this command to <explain when to use it>.
    Example: `earl call --yes --json <provider>.<command> --param_name value`
  EOT

  annotations {
    mode    = "<read|write>"
    secrets = ["<provider>.<secret_key>"]
  }

  param "<param_name>" {
    type        = "<string|number|boolean>"
    description = "<What this parameter controls>"
    required    = <true|false>
    default     = "<default_value>"   # omit if required = true
  }

  operation {
    protocol = "<http|graphql|grpc|bash|sql>"
    # ... protocol-specific fields from the reference file
  }

  result {
    output = "{{ result }}"
  }
}

Required for every template:

  • annotations.mode: "read" if the command reads data, "write" if it creates/modifies/deletes
  • annotations.secrets: list all secret keys the template needs (format: "provider.key_name")
  • description must include a ## Guidance for AI agents section

Show full SKILL.md (380 more words)Show less

Phase 5: Human Review (Required)

Show the user the complete template content before writing the file:

"Here is the template I've drafted. Please review it before I write it to disk:

[show full template content]

Does this look correct? Should I write it and run earl templates validate?"

Do not write the file or proceed until the user explicitly approves. Once written to disk, the template is immediately callable — there is no staging step. Approval here is the only gate before it becomes live.


Phase 6: Validate

bash
earl templates validate

Fix any errors reported and re-validate. Common errors:

ErrorCauseFix
HCL parse error / unexpected tokenInvalid HCL syntaxCheck structure and quotes
template root must be an objectMissing version/provider fieldsAdd version = 1 and provider = "..."
undefined variable in Jinja{{ args.x }} doesn't match a param nameCheck param names match references
params = [{{ ... }}] syntax errorBare Jinja in HCL arrayWrap in string: ["{{ ... }}"]

Phase 7: Set Secrets

Check annotations.secrets in the template file for required secret keys. For pre-built imports, read the imported file at ~/.config/earl/templates/<provider>.hcl (macOS/Linux) or %APPDATA%\earl\templates\<provider>.hcl (Windows) to find them. Print a checklist:

text
Template ready. Set the required secrets in your terminal:

  earl secrets set <provider>.<key>

(Repeat for each secret listed above)

Tell me when you're done and I'll verify they're set.

On macOS: Warn the user that the first earl secrets set run may show a system dialog asking to allow Earl keychain access — click "Always Allow" to avoid repeated prompts.

After the user confirms, verify:

bash
earl secrets list

Check that all required keys appear. If any are missing, re-print just the missing ones.


Phase 8: Verify

Run a test call with representative parameters:

bash
earl call --yes --json <provider>.<command> --<param> <test_value>

Important: If annotations.mode = "write", the test call will create/modify/delete real data. If the template defines environments (check the environments block for valid names), use --env <name> to select a non-production environment for the test call. Otherwise, use a test or sandbox account, a safe test value (e.g. a dedicated test repo), or choose a read-only command for the initial verification. Warn the user before running write-mode test calls.

If the call fails:

  • HTTP 401/403 → secret not set or wrong key name
  • no such command → template not loaded, check earl templates list
  • Any other error → invoke troubleshoot-earl

Next Steps

  • To add another command to this template: invoke create-template again for the same provider
  • To replace existing CLI calls with Earl: invoke migrate-to-earl
  • To enforce Earl usage at the platform level: invoke secure-agent
  • If something isn't working: invoke troubleshoot-earl

© mathematic-inc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/development/create-template of mathematic-inc/earl.

Open the folder on GitHubat commit c56a45f

Compare with similar skills

Create Template next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Create Template compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Create Template this skillmathematic-inc/earl113—~2.8kAutomated safety check: PassApache-2.0
Security SecretsIgorWarzocha/Opencode-Workflows122—~1.2kAutomated safety check: NotesNone
Google Dorks Cataloguphiago/recon-skills1.3k—~1.1kAutomated safety check: NotesMIT
Agentic GitHub Actions Auditortrailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0
Snapshotboostsecurityio/poutine522—~214Automated safety check: PassApache-2.0
Implementing Sigstore For Software Signingmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: NotesApache-2.0

Similar skills

  • Security Secrets

    IgorWarzocha/Opencode-Workflows

    Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

    122 GitHub stars~1.2k tokensUpdated 8 mo ago
    SecurityAuto-check: notes
  • Google Dorks Catalog

    uphiago/recon-skills

    High-precision Google dorks for exposed configs, secrets, and credentials -- real-world validated

    1.3k GitHub stars~1.1k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.4k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • Snapshot

    boostsecurityio/poutine

    Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

    522 GitHub stars~214 tokensUpdated yesterday
    SecurityAuto-check passed
  • Implementing Sigstore For Software Signing

    mukul975/Anthropic-Cybersecurity-Skills

    Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Hunt Auth Bypass

    elementalsouls/Claude-BugHunter

    Hunting skill for auth bypass vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub stars~8.2k tokensUpdated yesterday
    SecurityAuto-check passed

More from mathematic-inc/earl

  • Migrate To Earl

    mathematic-inc/earl

    Scans a codebase for raw API/CLI calls (curl, gh, stripe-cli, psql, grpcurl, etc.) and replaces them with Earl templates — one provider at a time.

    113 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Earl

    mathematic-inc/earl

    A skill your agent uses when you need to call an API, run a database query, or execute a shell command via Earl.

    113 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Secure Agent

    mathematic-inc/earl

    Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules.

    113 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Create Template

What does Create Template do?

Creates a new Earl HCL template for a specific API, database, or shell command. Create Template is an agent skill from mathematic-inc/earl. Creates a new Earl HCL template for a specific API, database, or shell command.

When should I use Create Template?

Create Template fits situations like: adding a new service to Earls template library; A pre-built template doesnt cover a needed command.

How do I install Create Template in Claude Code?

Run `npx skills add mathematic-inc/earl --skill create-template -a claude-code`. Or copy the skill folder (skills/development/create-template in mathematic-inc/earl) into .claude/skills/create-template in your project. Claude Code loads it when a task matches its description.

How do I install Create Template in Codex?

Run `npx skills add mathematic-inc/earl --skill create-template -a codex`. Or copy the skill folder (skills/development/create-template in mathematic-inc/earl) into .agents/skills/create-template in your project. Codex loads it when a task matches its description.

Can I use Create Template in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mathematic-inc/earl --skill create-template -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/create-template, .gemini/skills/create-template, .github/skills/create-template and .opencode/skills/create-template in your project.

What does Create Template need to run?

SKILL.md names no scripts, command-line tools or credentials: Create Template is instructions for the agent only.

Does Create Template access the network?

SKILL.md names 1 domain. As links in the text: mathematic-inc.github.io. This is read from the text; nothing was executed.

Is Create Template safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Create Template use?

Create Template is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Create Template use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Create Template?

Skills that share tags, products or a category with Create Template: Security Secrets (IgorWarzocha/Opencode-Workflows, 122 stars), Google Dorks Catalog (uphiago/recon-skills, 1.3k stars), Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars) and Snapshot (boostsecurityio/poutine, 522 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Create Template?

mathematic-inc (a GitHub organization) maintains it in mathematic-inc/earl, which has 113 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 6, 2026.

Source: mathematic-inc/earl on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.