Agent skill

Openloomi Setup

by melandlabs in melandlabs/openloomi

Run OpenLoomi one-time setup — auto-chains install → set Codex provider → launch → wait API → mint guest session token → ready in one call.

Apache-2.0Auto-check passed

Install Openloomi Setup

skills CLI
$ npx skills add melandlabs/openloomi --skill openloomi-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install melandlabs/openloomi openloomi-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/melandlabs/openloomi.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/codex/skills/openloomi-setup .claude/skills/openloomi-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
openloomi-setup
GitHub stars
1k
Token cost
~5.1k tokens
SKILL.md length
1,996 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run OpenLoomi one-time setup — auto-chains install → set Codex provider → launch → wait API → mint guest session token → ready in one call.

  • Works in 5 steps: One-paragraph intro → Where things live (orientation) → The five-step first tour → …
  • SKILL.md covers Quick workflow, Flags, Live status and api_not_ready payload, plus 6 more sections
  • Calls node and curl

What it does

Openloomi Setup is an agent skill from melandlabs/openloomi. Run OpenLoomi one-time setup — auto-chains install → set Codex provider → launch → wait API → mint guest session token → ready in one call. Mirrors Claude's /openloomi:setup. Triggers: setup openloomi, install openloomi, install and run, 一键装好并跑起来, fix openloomi, finalize openloomi, installrequired, awaitinguseraction, sessioninitializationrequired, aiproviderrequired, installfailed, apinotready, what now, what next, first time, what can i do.

Its SKILL.md is about 5.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: OpenLoomi is an open-source AI coworker. It connects your work tools, understands what you’re working on, and tells you what needs your attention, why it matters, and what to do… The licence is Apache-2.0.

Example prompts

  • “/openloomi-setup”

Requirements

  • Pre-approved tools (allowed-tools): Bash(node $SKILL_DIR/../../scripts/loomi-bridge.mjs setup *)

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. One-paragraph intro
  2. Where things live (orientation)
  3. The five-step first tour
  4. Quick reference card
  5. Hand-off

What it can do on your machine

Read from SKILL.md and the folder at commit 2aca101. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(node $SKILL_DIR/../../scripts/loomi-bridge.mjs setup *)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Openloomi Setup loads about 5.1k tokens when it runs. Until then it costs about 119 tokens; SKILL.md has 1,996 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~119
When it runs · the whole SKILL.md, loaded when a task matches
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from melandlabs/openloomi at commit 2aca101, republished under its Apache-2.0 licence (© melandlabs). 1,996 words, ~5,110 tokens.

Download SKILL.mdSave it as .claude/skills/openloomi-setup/SKILL.md (or your agent's skills folder).
name
openloomi-setup
description
Run OpenLoomi one-time setup — auto-chains install → set Codex provider → launch → wait API → mint guest session token → ready in one call. Mirrors Claude's `/openloomi:setup`. Triggers: setup openloomi, install openloomi, install and run, 一键装好并跑起来, fix openloomi, finalize openloomi, install_required, awaiting_user_action, session_initialization_required, ai_provider_required, install_failed, api_not_ready, what now, what next, first time, what can i do.
allowed-tools
Bash(node $SKILL_DIR/../../scripts/loomi-bridge.mjs setup *)

OpenLoomi Setup (end-to-end wizard)

The bridge now exposes a single end-to-end wizard: setup --yes. One invocation walks the full Codex state machine:

install OpenLoomi.app from the official GitHub release
  → set OPENLOOMI_AGENT_PROVIDER=codex in the GUI launchd / environment.d
     (auto-restarts the desktop if it was already running)
  → launch the desktop app (`open -a <desktopMarker>` / platform equivalent)
  → wait for the local HTTP API to come up on http://localhost:3414
  → mint a guest bearer (one-tap sign-in) into ~/.openloomi/token
  → { ready: true }

Each transition is automatic. Do not ask the user to click anything in the GUI. The bridge only surfaces a stop condition when the next step truly requires human action — e.g. AI provider not configured, or the native Codex runtime isn't reachable.

This wizard is the Codex-side equivalent of Claude's /openloomi:setup. Both plugins speak the same bridge commands, the same flag names, and the same stop-condition vocabulary so an install step that works on one works on the other.

Quick workflow

  1. Make sure the Codex sandbox is set to a mode that allows the wizard to actually run. setup needs to write to /Applications (macOS) or ~/.config/environment.d/ (Linux), install/launch the desktop helper, and reach http://localhost:3414. workspace-write is the minimum that usually works; danger-full-access is the safe choice for the first run. If you do not have approval, ask the user before invoking the bridge.

  2. If the bridge returns setup: install_attempted (only happens on the very first invocation when --yes is required), this is informational — --yes is already passed through and the wizard proceeds.

  3. Run:

    bash
    node "$SKILL_DIR/../../scripts/loomi-bridge.mjs" setup --yes [--max-wait <ms>] [--api-timeout <ms>] [--install-timeout <ms>] [--launch-timeout <ms>] [--permission-timeout <ms>] [--bin-path <path>]
  4. Read the JSON. The bridge writes an audit trail of what it did into steps[]. Surface that to the user so they can see which transitions fired (status_check → install → runtime_env_write → quit_for_env_reload (only when needed) → launch → wait_api → guest_login).

  5. If setup: ready → done.

  6. If setup: awaiting_user_action → the chain hit a step that genuinely needs the user (e.g. nextAction: install_openloomi because --yes wasn't passed, nextAction: configure_ai_provider because no AI provider is configured, or nextAction: open_openloomi because the desktop process won't auto-launch). Explain what the user needs to do and stop — do not auto-retry.

  7. If setup: api_not_ready → show the bridge's hints[] and the pre-built resumeCommand. Re-running the wizard is always safe; the state machine is idempotent. Re-approval may be needed to leave the sandbox.

Flags

All flags are also accepted by the bridge directly. Names + defaults are identical to Claude's /openloomi:setup so the two plugins speak the same dial language.

FlagDefaultMeaning
--yesoffPre-approve install. Without it, the bridge stops at INSTALL_CONFIRMATION_REQUIRED because Codex can't presume consent. With it, the chain runs end-to-end.
--max-wait120000Global cap (ms) across the wait stages. Defaults to 120 s to absorb the first-run install + TCC prompts.
--api-timeout120000Per-stage budget for "waiting for local API". Independent of --max-wait.
--install-timeout300000Per-stage budget for "installing OpenLoomi". Covers download + copy on a 50 Mbps link.
--launch-timeout10000Per-stage budget for open -a <bundle> (and platform equivalents). Almost never actually hit; included for parity with the Claude side.
--permission-timeout60000Extra grace wait after --api-timeout when the desktop process is up but the API never woke up — only fires when the bridge can confirm the process is alive.
--bin-pathautoExplicit path to the OpenLoomi desktop bundle (e.g. /Applications/OpenLoomi.app). Mirrors Claude's flag and overrides the usual discovery order.

Live status

While the wizard is inside a long stage, the bridge writes a throttled 1 Hz line to stderr so the user can see progress:

  · installing OpenLoomi  (12s / max 5m) …
  · waiting for local API  (4s / max 2m) …
  · waiting on macOS permission prompt  (3s / max 1m) …

Stdout is reserved for the final JSON result — do not mix it.

api_not_ready payload

When --api-timeout (+ --permission-timeout grace) elapses, the wizard returns an actionable JSON payload you can use to drive chat-side guidance. The original setup: "api_not_ready" shape is preserved for backwards compatibility; new fields are added alongside it.

FieldTypeMeaning
okboolAlways false for this stop condition.
setupstringAlways "api_not_ready" here.
codestringStable machine code: "API_NOT_READY" or "PERMISSION_PROMPT_LIKELY" (when desktop process is up but API is not).
stagestringAlways "wait_api". Reserved for future per-stage error codes.
elapsedMsnumberWall-clock time since setup --yes started.
effectiveBudgetMsnumberTotal wait budget actually granted (api + permission grace).
canResumeboolAlways true. Re-running the wizard is the supported "keep waiting" action.
resumeCommandstringA pre-built command the user can paste — already uses a sensible raised --max-wait.
hintsstring[]1–3 hints, safe to print verbatim. Includes the macOS TCC prompt hint on Darwin.
overCapbooltrue if the elapsed time exceeded the global --max-wait cap (informational).
stepsStep[]The existing audit trail.
waitobjectThe raw waitForApi payload (code, elapsedMs, attempted, lastError, optional graceWait).
statusobjectThe latest setup-status snapshot.

Stop conditions and what they mean

setupWhen it fires
readyAll transitions completed. The desktop app is running, the API is reachable, the guest session token is minted, and the native Codex provider is the active agent. Surface mode, version, and executionProviderSource from status.
awaiting_user_actionA transition that needs the user ran without a programmatic path. Most commonly: nextAction: install_openloomi because --yes wasn't passed, nextAction: configure_ai_provider because no provider is configured, nextAction: open_openloomi because the desktop process didn't wake, or nextAction: inspect_codex_runtime because the native Codex agent is not active. Walk the user through what they need to do and stop.
install_attempted(Informational.) The first setup invocation in a fresh environment must install before it can confirm READY. --yes already authorised the install; treat this as a normal await.
install_failedThe platform install script exited non-zero (or hit --install-timeout). Show install.code / install.message.
runtime_env_failedThe set-codex-runtime-env step failed (rare; usually a TCC prompt on macOS, or a write-permission error on Linux). Follow runtimeEnv.message.
quit_for_env_reload_failedThe desktop app was running, the env var was written, but quitDesktopApp couldn't bring it down (TCC prompt blocking the kill). The only stop condition that truly needs the user to Quit+Reopen by hand. Surface quit.message.
launch_failedopen -a <desktopMarker> (or platform equivalent) returned a non-zero exit. On macOS this almost never happens for a signed .app; if it does, fall back to manual launch instructions.
api_not_readyThe desktop app was launched but the local HTTP API didn't respond within --api-timeout. The bridge only adds --permission-timeout grace when it can confirm the desktop process is alive. code distinguishes network/slow (API_NOT_READY) vs TCC prompt (PERMISSION_PROMPT_LIKELY); hints[] and resumeCommand are pre-built; canResume: true makes re-running the wizard the recommended action.
guest_login_failedAPI is up but the one-tap guest login was rejected by /api/auth/guest. Show session.code / session.error. The user can sign in via the GUI and re-run setup.
step_limit_reachedHit the internal step ceiling without reaching READY (default 8 transitions). Almost certainly a state-machine bug; show steps[].

The bridge's stdout output is authoritative. Never invoke the platform install script (setup.{macos,linux,windows}.*) directly — only the bridge may run it, and only after explicit user consent (which is what --yes records).

Codex provider wiring

Before any launch, the bridge writes OPENLOOMI_AGENT_PROVIDER=codex so the freshly-started desktop server picks up the Codex runtime. On macOS this is done via launchctl setenv plus a LaunchAgent so the variable survives reboot; on Linux the bridge edits ~/.config/environment.d/; on Windows the user must set the variable manually. codex-runtime-info always reports the current effective value.

Post-ready walkthrough

When setup: ready fires, the wizard is done. Print the canonical post-setup hand-off so the user knows what they just installed and what to try next. The bridge JSON above is for machines; this section is the human-facing surface and supersedes the earlier "do not improvise" rule with a richer, scripted intro + tour. Print all four parts on the very first setup: ready emission. On later re-runs you may abbreviate to the audit table plus "where to go next" line, but never skip the intro.

Show full SKILL.md (782 more words)Show less
1. One-paragraph intro

OpenLoomi is your open-source, local-first AI partner, built to protect your attention. It runs as a desktop app on your Mac, connects to the tools you authorise (Gmail, Slack, GitHub, Google Calendar, Notion, Linear, etc. via Composio, plus native bots for Telegram / WhatsApp / iMessage / Feishu / DingTalk / QQ / WeChat), watches the signals that come in, and surfaces daily decisions as cards on the desktop pet (Loomi the fox). You tap Approve and the action runs through the same connector — the result is written back into Memory so the next judgement is sharper. Nothing leaves your machine unless you opt in to a Connector.

2. Where things live (orientation)
SurfaceWhere
Desktop app/Applications/OpenLoomi.app
Local HTTP APIhttp://localhost:3414 (fallback 3515)
Guest bearer token~/.openloomi/token (base64-encoded JWT)
Codex runtime envOPENLOOMI_AGENT_PROVIDER=codex (LaunchAgent, survives reboot)
Memory files~/.openloomi/data/memory/{people,projects,notes,strategy,chats,channels}/
Knowledge BaseGET /api/rag/documents
Audit logGET /api/audit/...
Pet widgetWatcher polls ~/.openloomi/loop/decisions.json every 2s
3. The five-step first tour

After setup: ready, suggest this exact sequence. Each step is a single shell call plus a one-line description of what the user will see. Skip steps the user has already done — but always emit step 1 (health check) so the user knows what "still ready" looks like.

#WhatCommandWhat you'll see
1Health checknode "$PLUGIN/scripts/loomi-bridge.mjs" setup-statusSame audit table you just got. Confirms Codex runtime is still the active default agent.
2Pet reactsnode "$PLUGIN/scripts/loomi-bridge.mjs" pet happyLoomi the fox flips to the happy sprite. Try thinking, working, juggling to see the rest of the 9-state set.
3Connect a toolNative: node "$PLUGIN/skills/openloomi-connectors/scripts/openloomi-connectors.cjs" connect telegram or OAuth: composio link gmailA QR scan or browser OAuth opens; once you approve, the account shows in list-accounts.
4Run one Loop tickTOKEN=$(cat ~/.openloomi/token | base64 -d); curl -X POST http://localhost:3414/api/loop/tick -H "Authorization: Bearer $TOKEN"Loop pulls signals, classifies them, and enqueues decisions. Then GET /api/loop/decisions?status=pending to see the cards. Approve with POST /api/loop/action/schedule.
5Seed Memorynode "$PLUGIN/skills/openloomi-memory/scripts/openloomi-memory.cjs" add-memory "About me: ..." --file=tour/about-me.mdA tour-owned .md shows up in ~/.openloomi/data/memory/tour/. Future Loop ticks have grounding context without overwriting user memory.

Optional extensions after step 4 (skip if the user is new):

  • Custom Loop channel — register your own signal source (PUT /api/loop/channels with toolkit + toolSlug).
  • Classifier rule — deterministic overrides for known signal patterns (PUT /api/loop/classifier-rules).
  • Custom decision type — your own DecisionType icon + label (PUT /api/loop/types).

If the user asks for a hands-on walkthrough rather than just a recommendation, hand off to the openloomi-tour skill — it runs the same five steps with live probes and stops between each one for the user to react.

4. Quick reference card

End with this closed list so the user doesn't have to memorise URLs.

Want to…Run
See healthsetup-status
Flip the petpet <state>
Re-confirm Codex runtimecodex-runtime-info
List connectorsopenloomi-connectors list-accounts
Search memoryopenloomi-memory search-all "<query>"
Run a Loop tickPOST /api/loop/tick
See pending decisionsGET /api/loop/decisions?status=pending
Approve a decisionPOST /api/loop/action/schedule {decision_id, action:"run"}
Archive old dataarchive
5. Hand-off

Finish with: "Run openloomi-tour from this Codex session for a guided walkthrough, or pick a number above and I'll run that step for you."

After api_not_ready

When the wizard times out waiting for the API, the recommended chat-side flow is:

  1. Show the bridge's hints[] verbatim. Each is safe-to-print.
  2. If canResume: true (always the case for api_not_ready), suggest the user simply re-runs the wizard. The state machine is idempotent — already-completed steps (e.g. install, env write) will be skipped immediately, and the wizard will land back inside wait_api.
  3. If the user wants to raise the budget once, ship the pre-built resumeCommand (e.g. node <plugin>/scripts/loomi-bridge.mjs setup --yes --max-wait 180000) rather than asking them to invent the flag.

Follow-up commands

Follow-upBridge commandWhen to suggest
Status snapshotsetup-statusUser asks "is everything wired up?" — read-only snapshot.
Pet statepet happy / pet normal / etc.User asks about the Pet widget or wants to flip its state manually.
Code runtime envcodex-runtime-infoUser asks whether the desktop app is wired to Codex.
Install-onlyinstall-openloomi --confirmUser asks to install without launching (rare; mostly CI / VDI).

Sandbox notes

The setup wizard must be run outside the Codex sandbox (or with danger-full-access) — it needs to write to system application directories (/Applications on macOS, ~/.config/environment.d/ on Linux), launch a signed GUI helper, and reach the local HTTP API at http://localhost:3414. None of those survive read-only or default workspace-write mode in a fresh environment. If you are still inside a sandbox when the user asks for setup, request approval and re-run outside the sandbox before invoking the bridge. The bridge surfaces a sandbox-y reason in awaiting_user_action, launch_failed, or api_not_ready; the hints[] payload calls out the next concrete step (approve the request and retry).

© melandlabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/codex/skills/openloomi-setup of melandlabs/openloomi.

Open the folder on GitHubat commit 2aca101

Compare with similar skills

Openloomi Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Openloomi Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Openloomi Setup this skillmelandlabs/openloomi1k—~5.1kAutomated safety check: PassApache-2.0
Sbom Supply Chainsickn33/agentic-awesome-skills47k2 repos~3.4kAutomated safety check: PassMIT
Agent Supply Chaingithub/awesome-copilot40k1 repos~2.7kAutomated safety check: PassMIT
Supply Chain Securityzhaoxuya520/reverse-skill40k4 repos~953Automated safety check: WarnMIT
Canonical Chainthedaviddias/Front-End-Checklist74k—~417Automated safety check: PassMIT
Implementing Supply Chain Security With In Totomukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.0

Similar skills

  • Sbom Supply Chain

    sickn33/agentic-awesome-skills

    Generate, sign, and verify SBOMs and provenance attestations to secure the software supply chain.

    47k GitHub starsUsed in 2 repos~3.4k tokens
    SecurityAuto-check passed
  • Agent Supply Chain

    github/awesome-copilot

    Official

    Verify supply chain integrity for AI agent plugins, tools, and dependencies.

    40k GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Supply Chain Security

    zhaoxuya520/reverse-skill

    A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

    40k GitHub starsUsed in 4 repos~953 tokens
    SecurityAuto-check: warnings
  • Canonical Chain

    thedaviddias/Front-End-Checklist

    A skill your agent uses when auditing metadata, crawlability, structured data, or indexability related to Avoid redirect chains on canonical URLs.

    74k GitHub stars~417 tokensUpdated 2 days ago
    Marketing & SEOAuto-check passed
  • Implementing Supply Chain Security With In Toto

    mukul975/Anthropic-Cybersecurity-Skills

    Implements supply chain integrity verification for container builds with the in-toto framework: generating signing keys, defining a supply chain layout, recording pipeline steps as signed link…

    34k GitHub stars~2.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Supply Chain Guard

    davila7/claude-code-templates

    Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2…

    32k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from melandlabs/openloomi

All 23 skills in this repo
  • Openloomi Connectors

    melandlabs/openloomi

    openloomi Connectors tools - manage the native 7 messaging integrations and pair with the composio skill for the 1000+ apps OAuth layer (Slack, Discord, X, Gmail, Outlook, Google…

    1k GitHub stars~3.3k tokensUpdated 14 days ago
    Auto-check passed
  • Create Task

    melandlabs/openloomi

    Create an end-to-end Continual Learning Bench task. An agent skill from melandlabs/openloomi.

    1k GitHub stars~4.6k tokensUpdated 14 days ago
    Auto-check passed
  • Openloomi Memory

    melandlabs/openloomi

    openloomi Memory tools - search and manage the holistic context (people, projects, decisions, knowledge base, chat insights).

    1k GitHub stars~6k tokensUpdated 14 days ago
    Auto-check passed
  • Openloomi Setup

    melandlabs/openloomi

    OpenLoomi first-use setup and readiness guidance for skill-only agent runtimes.

    1k GitHub stars~420 tokensUpdated 14 days ago
    Auto-check passed
  • Find Skills

    melandlabs/openloomi

    Discover and install skills from the open agent skills ecosystem.

    1k GitHub stars~892 tokensUpdated 14 days ago
    Auto-check passed
  • Openloomi

    melandlabs/openloomi

    OpenLoomi runtime integration for Claude Code. An agent skill from melandlabs/openloomi.

    1k GitHub stars~1.4k tokensUpdated 14 days ago
    Auto-check passed

Questions about Openloomi Setup

What does Openloomi Setup do?

Run OpenLoomi one-time setup — auto-chains install → set Codex provider → launch → wait API → mint guest session token → ready in one call. Openloomi Setup is an agent skill from melandlabs/openloomi. Run OpenLoomi one-time setup — auto-chains install → set Codex provider → launch → wait API → mint guest session token → ready in one call.

How do I install Openloomi Setup in Claude Code?

Run `npx skills add melandlabs/openloomi --skill openloomi-setup -a claude-code`. Or copy the skill folder (plugins/codex/skills/openloomi-setup in melandlabs/openloomi) into .claude/skills/openloomi-setup in your project. Claude Code loads it when a task matches its description.

How do I install Openloomi Setup in Codex?

Run `npx skills add melandlabs/openloomi --skill openloomi-setup -a codex`. Or copy the skill folder (plugins/codex/skills/openloomi-setup in melandlabs/openloomi) into .agents/skills/openloomi-setup in your project. Codex loads it when a task matches its description.

Can I use Openloomi Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add melandlabs/openloomi --skill openloomi-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openloomi-setup, .gemini/skills/openloomi-setup, .github/skills/openloomi-setup and .opencode/skills/openloomi-setup in your project.

What does Openloomi Setup need to run?

Going by SKILL.md and its folder, Openloomi Setup needs the command-line tools its instructions call (node and curl). Its frontmatter pre-approves these tools: Bash(node $SKILL_DIR/../../scripts/loomi-bridge.mjs setup *).

Does Openloomi Setup access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Openloomi Setup safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Openloomi Setup use?

Openloomi Setup is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Openloomi Setup use?

About 5.1k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Openloomi Setup?

Skills that share tags, products or a category with Openloomi Setup: Sbom Supply Chain (sickn33/agentic-awesome-skills, 47k stars), Agent Supply Chain (github/awesome-copilot, 40k stars), Supply Chain Security (zhaoxuya520/reverse-skill, 40k stars) and Canonical Chain (thedaviddias/Front-End-Checklist, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Openloomi Setup?

melandlabs (a GitHub organization) maintains it in melandlabs/openloomi, which has 1,037 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 24, 2026.

Source: melandlabs/openloomi on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.