Agent skill

Migrate To Earl

by mathematic-inc in mathematic-inc/earl

Scans a codebase for raw API/CLI calls (curl, gh, stripe-cli, psql, grpcurl, etc.) and replaces them with Earl templates — one provider at a time.

Apache-2.0Auto-check passedBackend & APIs

Install Migrate To Earl

skills CLI
$ npx skills add mathematic-inc/earl --skill migrate-to-earl -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mathematic-inc/earl migrate-to-earl --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mathematic-inc/earl.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/development/migrate-to-earl .claude/skills/migrate-to-earl && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
migrate-to-earl
GitHub stars
113
Token cost
~1.9k tokens
SKILL.md length
849 words
Files
2 (incl. references)
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Scans a codebase for raw API/CLI calls (curl, gh, stripe-cli, psql, grpcurl, etc.) and replaces them with Earl templates — one provider at a time.

  • Works in 9 steps: Scan All Providers → Import Pre-built or Create Custom → Map Call Sites → …
  • Migrating a project from direct CLI tool usage to Earl
  • SKILL.md covers Scope Constraints (Read First), Phase 1: Scan All Providers, Phase 2: Import Pre-built or… and Phase 3: Map Call Sites, plus 7 more sections
  • Calls curl, jq and gh; reaches api.github.com; needs GITHUB_TOKEN

What it does

Migrate To Earl is an agent skill from mathematic-inc/earl. Scans a codebase for raw API/CLI calls (curl, gh, stripe-cli, psql, grpcurl, etc.) and replaces them with Earl templates — one provider at a time. Use when migrating a project from direct CLI tool usage to Earl, or when replacing raw HTTP calls with reviewed templates.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/cli-to-earl-mapping.md`).

It sits in Backend & APIs. It works with Stripe and PostgreSQL. The repository describes itself as: Secure CLI proxy for AI agents — HCL-defined operation templates with OS keychain secrets, MCP integration, and prompt injection protection. The licence is Apache-2.0.

When your agent uses it

  • Migrating a project from direct CLI tool usage to Earl
  • Replacing raw HTTP calls with reviewed templates

Example prompts

  • “Use the migrate-to-earl skill to scan a codebase for raw API/CLI calls (curl, gh, stripe-cli, psql, grpcurl, etc.) and replaces them with Earl…”
  • “/migrate-to-earl”

Requirements

  • Python 3
  • Node.js
  • A credential in GITHUB_TOKEN

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Scan All Providers
  2. Import Pre-built or Create Custom
  3. Map Call Sites
  4. Set Secrets
  5. Verify Earl Commands Work
  6. Checkpoint — Confirm Before Rewriting
  7. Replace Call Sites
  8. Final Validation
  9. Report

What it can do on your machine

Read from SKILL.md and the folder at commit c56a45f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq
    • gh
    • stripe

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Migrate To Earl loads about 1.9k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 71 tokens; SKILL.md has 849 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mathematic-inc/earl at commit c56a45f, republished under its Apache-2.0 licence (© mathematic-inc). 849 words, ~1,862 tokens.

Download SKILL.mdSave it as .claude/skills/migrate-to-earl/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
migrate-to-earl
description
Scans a codebase for raw API/CLI calls (curl, gh, stripe-cli, psql, grpcurl, etc.) and replaces them with Earl templates — one provider at a time. Use when migrating a project from direct CLI tool usage to Earl, or when replacing raw HTTP calls with reviewed templates.

Migrate to Earl

Converts existing raw CLI/API calls in a codebase to Earl templates. Works one provider at a time to keep changes reviewable and reversible.

Scope Constraints (Read First)

These rules prevent context window exhaustion and partial-migration messes:

  1. One provider per run. If multiple providers are found, ask which to migrate first.
  2. Cap at 10 call sites. If more than 10 are found, ask which 10 to prioritize. Flag the rest with # TODO: migrate to earl comments and note them in the final report.
  3. Commit checkpoint. Pause after template creation, before rewriting call sites. Let the user commit the template before the rewrite begins.
  4. Flag complex pipelines. Multi-pipe commands (curl | jq | xargs) are not rewritten. Add # TODO: migrate to earl (complex pipeline — review manually) and move on.

Phase 1: Scan All Providers

Read references/cli-to-earl-mapping.md (or fetch from https://raw.githubusercontent.com/mathematic-inc/earl/main/skills/development/migrate-to-earl/references/cli-to-earl-mapping.md) for the full list of patterns and files to scan.

Grep across all relevant files for every pattern in the mapping table. Even on repeated invocations, always do a full scan first.

Present a summary before asking the user to pick a provider:

"Found API/CLI calls to:

  • GitHub (12 sites in 4 files)
  • Stripe (8 sites in 2 files)
  • Slack (3 sites in 1 file)

Which provider would you like to migrate first?"

If only one provider is found, proceed with it directly.

Note the remaining providers in the report so the user knows what's left for follow-up runs.


Phase 2: Import Pre-built or Create Custom

Check if a pre-built template exists for the chosen provider (see references/cli-to-earl-mapping.md).

If pre-built exists:

Check earl templates list first — if the provider is already imported, skip the import command below and go directly to showing available commands.

bash
earl templates import https://raw.githubusercontent.com/mathematic-inc/earl/main/examples/<provider>.hcl
earl templates list

Show the user which commands are available in the imported template.

If no pre-built exists:

Invoke create-template for the provider. The create-template skill includes its own human review, validation, and secrets steps — do not duplicate those steps here.


Phase 3: Map Call Sites

For each found call site, determine the corresponding Earl command:

bash
earl templates list --json

Match each raw call to an Earl command:

  • curl -X GET https://api.github.com/repos/... → earl call github.get_repo
  • gh issue create ... → earl call github.create_issue
  • stripe customers list → earl call stripe.list_customers

For calls that don't map to any existing command, invoke create-template to add it.


Phase 4: Set Secrets

Skip this phase only if Phase 2 took the "no pre-built" path and invoked create-template directly (i.e., no bare earl templates import was run). In that case, create-template already ran secrets setup (its own Phase 7 and Phase 8) and confirmed secrets are set. Proceed to Phase 5.

Do NOT skip if Phase 2 ran a bare earl templates import — even if Phase 3 also invoked create-template for an unmapped command. The Phase 3 create-template only set secrets for the new command it created, not for the Phase 2 pre-built import. Phase 4 must still run for the pre-built provider's secrets.

Check annotations.secrets in the template file for required secret keys. For pre-built imports, read the imported file at ~/.config/earl/templates/<provider>.hcl (macOS/Linux) or %APPDATA%\earl\templates\<provider>.hcl (Windows) to find them.

Print the checklist of required secrets for the imported templates:

text
Before replacing call sites, set the required secrets in your terminal:

  earl secrets set <provider>.<key>

Tell me when you're done and I'll verify before we proceed.

On macOS: First run of earl secrets set may show a system keychain access dialog. Click "Always Allow" to avoid repeated prompts.

After the user confirms, verify:

bash
earl secrets list

Check that all required keys appear. Re-print missing ones if needed.


Show full SKILL.md (289 more words)Show less

Phase 5: Verify Earl Commands Work

Run a test call for each mapped command before touching any call sites:

bash
earl call --yes --json <provider>.<command> --<param> <representative_value>

Important: If a command has annotations.mode = "write", the test call will create/modify/ delete real data. If the template defines environments (check the environments block for valid names), use --env <name> to select a non-production environment for the test call. Otherwise, use read-only commands for verification where possible, or use a test/sandbox account. Warn the user before running any write-mode test calls.

If any call fails, resolve it (via troubleshoot-earl if needed) before proceeding.


Phase 6: Checkpoint — Confirm Before Rewriting

Show the user:

  1. The list of call sites that will be rewritten
  2. The Earl equivalents they'll be replaced with
  3. The call sites flagged for manual review (complex pipelines)

Ask explicitly:

"I'm about to rewrite these X call sites. This will modify your source files. Should I proceed? (You should commit your current changes first if you haven't.)"

Do not rewrite anything until the user approves.


Phase 7: Replace Call Sites

For each approved call site, rewrite to the Earl equivalent:

bash
# Before:
curl -H "Authorization: Bearer $GITHUB_TOKEN" https://api.github.com/repos/$OWNER/$REPO

# After:
earl call --yes --json github.get_repo --owner $OWNER --repo $REPO

For source files (Python, JavaScript, etc.): curl calls typically appear inside subprocess invocations — replace the subprocess call with the Earl equivalent for that language:

python
# Before (Python):
subprocess.run(["curl", "-H", f"Authorization: Bearer {token}", url])

# After (Python):
subprocess.run(["earl", "call", "--yes", "--json", "github.get_repo", "--owner", owner, "--repo", repo])
javascript
// Before (Node.js):
execSync(`curl -H "Authorization: Bearer ${token}" ${url}`);

// After (Node.js):
execSync(`earl call --yes --json github.get_repo --owner ${owner} --repo ${repo}`);

For flagged complex pipelines, add a comment but leave the original:

bash
# TODO: migrate to earl (complex pipeline — review manually)
curl ... | jq ... | xargs ...

Phase 8: Final Validation

bash
earl templates validate

Phase 9: Report

Summarize what was done:

  • Which provider was migrated
  • How many call sites were rewritten
  • Which were flagged for manual review
  • Which secrets were set
  • What providers remain for follow-up runs

Next Steps

  • To migrate another provider: invoke migrate-to-earl again
  • To create a template for an unmatched service: invoke create-template
  • To enforce Earl usage at the platform level: invoke secure-agent
  • If a migrated call fails: invoke troubleshoot-earl

© mathematic-inc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/development/migrate-to-earl of mathematic-inc/earl.

  • SKILL.md
  • references/cli-to-earl-mapping.md

Open the folder on GitHubat commit c56a45f

Compare with similar skills

Migrate To Earl next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Migrate To Earl compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Migrate To Earl this skillmathematic-inc/earl113—~1.9kAutomated safety check: PassApache-2.0
Stripe Projectsfossasia/eventyay1.7k5 repos~2kAutomated safety check: NotesApache-2.0
OneCLI Gatewaynanocoai/nanoclaw31k—~856Automated safety check: PassMIT
Adding Warehouse Person PropertiesPostHog/posthog40k—~2.9kAutomated safety check: PassCustom licence
Production Auditsickn33/agentic-awesome-skills47k1 repos~2.7kAutomated safety check: PassMIT
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC

Similar skills

  • Stripe Projects

    fossasia/eventyay

    A skill your agent uses when the user wants to provision infrastructure or third-party services using Stripe Projects.

    1.7k GitHub starsUsed in 5 repos~2k tokens
    Backend & APIsAuto-check: notes
  • OneCLI Gateway

    nanocoai/nanoclaw

    Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.

    31k GitHub stars~856 tokensUpdated today
    Backend & APIsAuto-check passed
  • Official

    Sync columns from a synced data warehouse table onto PostHog person or group properties, so warehouse data becomes usable anywhere person and group properties already work: feature flag targeting…

    40k GitHub stars~2.9k tokensUpdated today
    DatabasesAuto-check passed
  • Production Audit

    sickn33/agentic-awesome-skills

    Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health.

    47k GitHub starsUsed in 1 repo~2.7k tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed

More from mathematic-inc/earl

  • Create Template

    mathematic-inc/earl

    Creates a new Earl HCL template for a specific API, database, or shell command.

    113 GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed
  • Earl

    mathematic-inc/earl

    A skill your agent uses when you need to call an API, run a database query, or execute a shell command via Earl.

    113 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Secure Agent

    mathematic-inc/earl

    Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules.

    113 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed

Questions about Migrate To Earl

What does Migrate To Earl do?

Scans a codebase for raw API/CLI calls (curl, gh, stripe-cli, psql, grpcurl, etc.) and replaces them with Earl templates — one provider at a time. Migrate To Earl is an agent skill from mathematic-inc/earl.) and replaces them with Earl templates — one provider at a time.

When should I use Migrate To Earl?

Migrate To Earl fits situations like: migrating a project from direct CLI tool usage to Earl; replacing raw HTTP calls with reviewed templates.

How do I install Migrate To Earl in Claude Code?

Run `npx skills add mathematic-inc/earl --skill migrate-to-earl -a claude-code`. Or copy the skill folder (skills/development/migrate-to-earl in mathematic-inc/earl) into .claude/skills/migrate-to-earl in your project. Claude Code loads it when a task matches its description.

How do I install Migrate To Earl in Codex?

Run `npx skills add mathematic-inc/earl --skill migrate-to-earl -a codex`. Or copy the skill folder (skills/development/migrate-to-earl in mathematic-inc/earl) into .agents/skills/migrate-to-earl in your project. Codex loads it when a task matches its description.

Can I use Migrate To Earl in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mathematic-inc/earl --skill migrate-to-earl -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/migrate-to-earl, .gemini/skills/migrate-to-earl, .github/skills/migrate-to-earl and .opencode/skills/migrate-to-earl in your project.

What does Migrate To Earl need to run?

Going by SKILL.md and its folder, Migrate To Earl needs the command-line tools its instructions call (curl, jq, gh and stripe) and credentials named GITHUB_TOKEN. Our summary lists: Python 3; Node.js; A credential in GITHUB_TOKEN.

Does Migrate To Earl access the network?

SKILL.md names 1 domain. In commands or code: api.github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Migrate To Earl safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Migrate To Earl use?

Migrate To Earl is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Migrate To Earl use?

About 1.9k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Migrate To Earl?

Skills that share tags, products or a category with Migrate To Earl: Stripe Projects (fossasia/eventyay, 1.7k stars), OneCLI Gateway (nanocoai/nanoclaw, 31k stars), Adding Warehouse Person Properties (PostHog/posthog, 40k stars) and Production Audit (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Migrate To Earl?

mathematic-inc (a GitHub organization) maintains it in mathematic-inc/earl, which has 113 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 8, 2026.

Source: mathematic-inc/earl on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.