Agent skill

Octo Shared

by Mininglamp-OSS in Mininglamp-OSS/octo-cli

Shared knowledge for using the octo CLI — authentication, unified gateway config, output envelopes, universal flags, error handling, and common patterns.

Apache-2.0Auto-check passedBackend & APIs

Install Octo Shared

skills CLI
$ npx skills add Mininglamp-OSS/octo-cli --skill octo-shared -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Mininglamp-OSS/octo-cli octo-shared --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Mininglamp-OSS/octo-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/octo-shared .claude/skills/octo-shared && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
octo-shared
GitHub stars
918
Token cost
~3.2k tokens
SKILL.md length
1,149 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

Shared knowledge for using the octo CLI — authentication, unified gateway config, output envelopes, universal flags, error handling, and common patterns.

  • Works in 8 steps: Authentication → Unified gateway configuration → Output: the JSON envelope → …
  • Backend & APIs work in your project
  • SKILL.md covers 1. Authentication, 2. Unified gateway configuration, 3. Output: the JSON envelope and 4. Universal flags, plus 4 more sections
  • Reaches im.deepminer.com.cn and im-test.deepminer.com.cn; needs OCTO_BOT_TOKEN and UK_TOKEN

What it does

Octo Shared is an agent skill from Mininglamp-OSS/octo-cli. Shared knowledge for using the octo CLI — authentication, unified gateway config, output envelopes, universal flags, error handling, and common patterns. Load before invoking any octo domain skill.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. It works with OpenAPI. The repository describes itself as: Metadata-driven CLI for AI Agent Bots — 48 operations across 7 domains, structured JSON envelope I/O, zero interactive prompts. The licence is Apache-2.0.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “/octo-shared”

Requirements

  • A credential in OCTO_BOT_TOKEN

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Authentication
  2. Unified gateway configuration
  3. Output: the JSON envelope
  4. Universal flags
  5. Error taxonomy and exit codes
  6. Input patterns
  7. Discovering the API
  8. Domain skills

What it can do on your machine

Read from SKILL.md and the folder at commit ff371c2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • im.deepminer.com.cn
    • im-test.deepminer.com.cn

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OCTO_BOT_TOKEN
    • UK_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Octo Shared loads about 3.2k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 1,149 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Mininglamp-OSS/octo-cli at commit ff371c2, republished under its Apache-2.0 licence (© Mininglamp-OSS). 1,149 words, ~3,218 tokens.

Download SKILL.mdSave it as .claude/skills/octo-shared/SKILL.md (or your agent's skills folder).
name
octo-shared
description
Shared knowledge for using the octo CLI — authentication, unified gateway config, output envelopes, universal flags, error handling, and common patterns. Load before invoking any octo domain skill.
version
0.5.0

octo-shared — CLI fundamentals for AI Agents

octo-cli is a thin REST client that exposes the Octo ecosystem (matters, messaging, groups, threads, files, bot, events, docs, html) as a single binary. Every service command is auto-generated from an embedded OpenAPI registry; output is a JSON envelope designed to be parsed by agents.

The matter domain is temporarily withheld while its backend API stabilizes — octo-cli matter ... is not registered and the octo-matter skill is not listed. Do not emit matter commands until it is re-enabled. The examples below use other domains.

Bots cannot delete documents, even documents they created or own/administer. Do not invoke docs delete, html rm, or equivalent raw api DELETE calls to delete a document. Ask a human with document admin permission to delete it in Octo instead. Do not switch credentials/routes or clear the document's contents as a workaround. This rule concerns whole documents, not normal editing or otherwise-permitted comment, version, asset, or sheet row/column removal.

1. Authentication

Bots authenticate with a bearer token. There is no interactive user login — but besides the two bot tokens (app_*, bf_*) there is a third kind, a user API key (uk_*), which carries a real person's identity and is used mainly for message search. Two ways to supply any of them:

Stored profile (recommended). A human (or provisioning step) logs the token in once; it is encrypted at rest under ~/.octo-cli, and the raw token never appears in any command line, shell history, or transcript afterward:

bash
# Operator setup (token read from a hidden prompt, or --with-token < file):
octo-cli auth login --bot-id cli_xxxxxxxx          # robot id you got when creating the bot
echo "$TOKEN" | octo-cli auth login --bot-id cli_xxxxxxxx --with-token   # non-interactive

# A user API key (uk_) is stored the same way — encrypted profile, bot_kind shows
# user_key. Use a friendly --profile name since it has no robot id:
echo "$UK_TOKEN" | octo-cli auth login --profile alice-search --with-token

Then, at runtime, select which bot to act as — the agent passes its own robot id, which it knows:

bash
octo-cli --bot-id cli_xxxxxxxx matter list         # or env OCTO_BOT_ID=cli_xxxxxxxx
octo-cli --profile myname matter list              # or by the friendly profile name

With exactly one stored profile, the selector is optional. With two or more, you must pass --bot-id or --profile — omitting it is a hard error (the CLI never guesses which identity to use).

Env token (fallback). When no profile is stored, the raw token is read from OCTO_BOT_TOKEN:

bash
export OCTO_BOT_TOKEN=app_xxxxxxxxxxxxxxxxxxxx      # App Bot (DM-only)
export OCTO_BOT_TOKEN=bf_xxxxxxxxxxxxxxxxxxxxx       # User Bot (full access)
export OCTO_BOT_TOKEN=uk_xxxxxxxxxxxxxxxxxxxxx       # User API key (real person; message search)

OCTO_BOT_ID is a selector (a robot id), not a secret; OCTO_BOT_TOKEN is the secret. If OCTO_BOT_ID names no stored profile the command fails — it never falls back to silently using OCTO_BOT_TOKEN under that id.

Token prefix determines capability — the CLI does NOT enforce this locally (the backend rejects unsupported operations with FORBIDDEN), with one exception: an app_* token running message search is rejected locally with a validation error before any request.

PrefixTypeDM msgGroup readGroup writeThreadVoiceSearch
app_*App Botyesyesnononono
bf_*User Botyesyesyesyesyesyes
uk_*User API key—————yes

uk_* carries a real person's identity and is meaningful mainly for message search (routed to /v1/user/*); for other domains use a bot token. bf_* can also search on behalf of a person with --on-behalf-of <uid>. identity.bot_kind reflects the kind: app_bot, user_bot, or user_key.

Outside OCTO_CREDENTIAL_MODE=task, inspect octo-cli auth status (or octo-cli config show) to confirm the active identity. Daemon task mode does not expose profile diagnostics; use the identity echoed by each success envelope and report authentication failures to the daemon instead (see §3).

2. Unified gateway configuration

All Octo domains use one gateway. Override it only for test or self-hosted deployments:

bash
# Production defaults to https://im.deepminer.com.cn. Override for test or
# self-hosted deployments:
export OCTO_API_BASE_URL=https://im-test.deepminer.com.cn

export OCTO_SPACE_ID=space_xxx                     # only for platform-scoped bots
export OCTO_FORMAT=json                            # default output format

Routing: all services go through OCTO_API_BASE_URL. The --service flag on octo-cli api is for documentation only — all traffic routes to the same gateway.

3. Output: the JSON envelope

Every successful invocation prints a single JSON object to stdout:

json
{
  "ok": true,
  "identity": { "type": "bot", "profile": "prod", "robot_id": "cli_xxx", "bot_kind": "app_bot", "source": "profile:prod" },
  "data": { ... or [...] },
  "_pagination": { "has_more": true, "next_cursor": "..." },
  "_rate_limit": { "remaining": 99, "reset": 1730000000 }
}

identity echoes the bot the command actually ran as — check it to catch acting as the wrong identity. It is always an object: a stored profile fills in profile / robot_id / source: "profile:<name>"; a raw OCTO_BOT_TOKEN yields { "type": "bot", "bot_kind": ..., "source": "env:OCTO_BOT_TOKEN" } (no profile/robot_id); a command that resolves no credential (e.g. version) yields the minimal { "type": "bot" }.

Every failure prints an error envelope to stderr and exits non-zero:

json
{
  "ok": false,
  "error": {
    "type": "validation",
    "code": "VALIDATION_ERROR",
    "message": "title is required",
    "hint": "check params with `octo-cli schema <op>`",
    "detail": { ...original backend payload... }
  }
}

Parse ok first. On failure, branch on error.type (a small fixed taxonomy) or error.code (a string, may come straight from the backend).

error.code: bot_delete_forbidden (error.type: permission, HTTP 403) is a terminal policy denial, not missing membership or a transient error. Do not retry, request a higher bot role, or change uid, owner, Space, credentials, or routes; ask a human document admin to perform the deletion. Do not claim success, even if the document was already deleted.

Backends differ in their raw error shape. The CLI normalizes both:

  • matters (structured): {error:{code, message, details}} → passes through into detail unchanged.
  • dmworkim (flat): {msg, status} → mapped to code/message via HTTP status.
Show full SKILL.md (418 more words)Show less

4. Universal flags

These flags work on every command (they are root-level persistent flags):

FlagPurpose
--formatjson (default) · table · csv · ndjson
--jq, -qApply a jq expression to the success envelope before formatting
--dry-runPrint the resolved request instead of sending it
--verboseLog request/response trace to stderr
--timeoutPer-request deadline, e.g. 30s, 2m
--no-retryDisable the default retry-on-transient policy
--spaceOverride OCTO_SPACE_ID for this invocation
--bot-idSelect/assert the stored credential by robot id (env OCTO_BOT_ID)
--profileSelect the stored credential by profile name

Paginated operations additionally expose:

FlagPurpose
--page-allWalk pages until has_more=false, emit one merged array
--page-limitHard cap on pages fetched with --page-all (default 10)

5. Error taxonomy and exit codes

error.typeExitTypical error.code
auth_error3UNAUTHORIZED, AUTH_UNAVAILABLE
validation2VALIDATION_ERROR, PAYLOAD_TOO_LARGE
config2missing env vars
permission1FORBIDDEN, SPACE_FORBIDDEN
rate_limited1RATE_LIMITED
network1NETWORK_ERROR, UPSTREAM_UNAVAILABLE
api_error1MATTER_NOT_FOUND, NOT_FOUND, INTERNAL_ERROR
internal1CLI-side bug

Agents should switch on error.code first (specific, deterministic), then error.type (broad), then exit_code (coarse).

The hint field is a one-line next action meant for an agent: follow it literally where it applies. E.g. MATTER_NOT_FOUND → "verify ID with octo-cli matters list".

6. Input patterns

Promoted flags vs --data

Simple top-level body fields auto-promote to typed flags (strings, integers, booleans, []string). For objects, arrays-of-objects, or when sending a large payload, use --data:

bash
octo-cli thread create group-abc --name "design review"
octo-cli message send --data '{"channel_id":"chat-1","channel_type":1,"payload":{"type":1,"content":"hi"}}'
octo-cli message send --data @body.json
octo-cli some-cmd --data @-            # read JSON from stdin

Explicit flags override fields set in --data. The --data escape hatch exists on every non-multipart command.

Piping with --jq
bash
octo-cli group list --jq '.data[].id' | xargs -I{} octo-cli group get {}
Paginating
bash
octo-cli docs search --keyword "spec" --page-all --page-limit 20

--page-all applies to any list operation that reports a cursor in _pagination. The merged output drops _pagination — you get a flat data array.

Dry-run for agent self-verification
bash
octo-cli message send --data '{"channel_id":"chat-1","channel_type":1,"payload":{"type":1,"content":"foo"}}' --dry-run

Prints the exact HTTP request body and URL, emits no side effect.

7. Discovering the API

The registry is embedded in the binary — no network needed:

bash
octo-cli schema --list                # all services + operation IDs
octo-cli schema --list message        # operations in one domain
octo-cli schema message.send          # full request/response schema
octo-cli config show                  # resolved config (token masked)
octo-cli auth status                  # active bot identity (whoami)
octo-cli auth list                    # stored profiles (no tokens)

When an operation isn't auto-registered yet or you need low-level control:

bash
octo-cli api GET  /api/v1/messages --params '{"chat_id":"chat-1"}'
octo-cli api POST /api/v1/messages --data @body.json

8. Domain skills

Once these fundamentals are understood, load the skill for the domain you need:

  • octo-matter — matters (todos/tasks), assignees, channels, timeline, AI extract — temporarily withheld (backend API stabilizing; not currently loadable)
  • octo-messaging — message send/edit/sync/read-receipt, groups, threads, events
  • octo-files — file upload/download, presigned credentials, bot housekeeping
  • octo-docs — docs domain (CRDT/Yjs): documents, spreadsheets, whiteboard scenes, members/sharing, comments, versions, attachments
  • octo-html — HTML docs domain (octo-doc, a DIFFERENT backend from octo-docs): self-contained interactive HTML documents, share codes, media assets, comments, agent element read/replace
  • octo-summary — create owner-only summaries from explicit sources, then discover, read, and cite summaries visible to the personal Agent's human owner — temporarily withheld (create backend at Mininglamp-OSS/octo-smart-summary#181 not yet merged/deployed/enabled; not currently loadable)

© Mininglamp-OSS, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/octo-shared of Mininglamp-OSS/octo-cli.

Open the folder on GitHubat commit ff371c2

Compare with similar skills

Octo Shared next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Octo Shared compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Octo Shared this skillMininglamp-OSS/octo-cli918—~3.2kAutomated safety check: PassApache-2.0
ToolJet Marketplace Plugin BuilderToolJet/ToolJet41k—~2.1kAutomated safety check: PassAGPL-3.0
Step Partsearthtojake/text-to-cad19k1 repos~1.5kAutomated safety check: PassMIT
OpenAPI to MCP Servermcp-use/mcp-use11k—~5.2kAutomated safety check: PassApache-2.0
Use Yaakmountain-loop/yaak19k—~1.9kAutomated safety check: PassMIT
API DesignerJeffallan/claude-skills12k1 repos~2kAutomated safety check: PassMIT

Similar skills

  • Turns an API description, such as an OpenAPI file or a Postman collection, into a connector plugin for ToolJet's marketplace and checks it with the repo's validator.

    41k GitHub stars~2.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Step Parts

    earthtojake/text-to-cad

    Find, evaluate, and download common purchasable CAD parts from step.parts, including named off-the-shelf actuators, servos, motors, electronics boards, connectors, screws, bolts, nuts, washers…

    19k GitHub starsUsed in 1 repo~1.5k tokens
    Backend & APIsAuto-check passed
  • OpenAPI to MCP Server

    mcp-use/mcp-use

    Turns an OpenAPI or Swagger spec into an MCP server with the mcp-use TypeScript SDK, mapping each operation to a tool, wiring auth, testing and deploying.

    11k GitHub stars~5.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Use Yaak

    mountain-loop/yaak

    A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

    19k GitHub stars~1.9k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 1 repo~2k tokens
    Backend & APIsAuto-check passed
  • Use whenever asked to add, create, or scaffold a CRUD endpoint, router, or entity in this repo's server (create/list/get/update/delete handlers, new…

    23k GitHub stars~461 tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from Mininglamp-OSS/octo-cli

All 11 skills in this repo
  • Octo Loop

    Mininglamp-OSS/octo-cli

    A skill your agent uses when operating the Octo Loop control plane through the octo-cli loop commands: reading or writing Fleet tasks, comments, metadata, projects, and labels; dispatching work to…

    918 GitHub stars~2.3k tokensUpdated 11 days ago
    Auto-check passed
  • Octo Summary

    Mininglamp-OSS/octo-cli

    Read, create, find, and cite Octo summaries through octo-cli.

    918 GitHub stars~1k tokensUpdated 11 days ago
    Auto-check passed
  • Octo Docs

    Mininglamp-OSS/octo-cli

    Docs domain — create and govern documents, read and incrementally edit a doc's live body, read and edit spreadsheets including structural row/column edits, find & replace, cells, layout, shared…

    918 GitHub stars~2k tokensUpdated 11 days ago
    Auto-check passed
  • Octo Drive

    Mininglamp-OSS/octo-cli

    Octo Drive — spaces, folders, file upload/download, online-document mounts, share links, invites, IM-attachment transfer.

    918 GitHub stars~4.4k tokensUpdated 11 days ago
    Auto-check passed
  • Octo Files

    Mininglamp-OSS/octo-cli

    File operations (upload/download, presigned S3 credentials) plus bot housekeeping (register, set-commands, user-info, space-members, typing, heartbeat).

    918 GitHub stars~1.6k tokensUpdated 11 days ago
    Auto-check passed
  • Octo HTML

    Mininglamp-OSS/octo-cli

    HTML docs domain (octo-doc) — create and govern self-contained interactive HTML documents, immutable versions, drafts, sharing, media, comments, and agent element edits.

    918 GitHub stars~4.2k tokensUpdated 11 days ago
    Auto-check passed

Works with

Categories

Questions about Octo Shared

What does Octo Shared do?

Shared knowledge for using the octo CLI — authentication, unified gateway config, output envelopes, universal flags, error handling, and common patterns. Octo Shared is an agent skill from Mininglamp-OSS/octo-cli. Shared knowledge for using the octo CLI — authentication, unified gateway config, output envelopes, universal flags, error handling, and common patterns.

When should I use Octo Shared?

Octo Shared fits situations like: backend & APIs work in your project.

How do I install Octo Shared in Claude Code?

Run `npx skills add Mininglamp-OSS/octo-cli --skill octo-shared -a claude-code`. Or copy the skill folder (skills/octo-shared in Mininglamp-OSS/octo-cli) into .claude/skills/octo-shared in your project. Claude Code loads it when a task matches its description.

How do I install Octo Shared in Codex?

Run `npx skills add Mininglamp-OSS/octo-cli --skill octo-shared -a codex`. Or copy the skill folder (skills/octo-shared in Mininglamp-OSS/octo-cli) into .agents/skills/octo-shared in your project. Codex loads it when a task matches its description.

Can I use Octo Shared in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Mininglamp-OSS/octo-cli --skill octo-shared -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/octo-shared, .gemini/skills/octo-shared, .github/skills/octo-shared and .opencode/skills/octo-shared in your project.

What does Octo Shared need to run?

Going by SKILL.md and its folder, Octo Shared needs credentials named OCTO_BOT_TOKEN and UK_TOKEN. Our summary lists: A credential in OCTO_BOT_TOKEN.

Does Octo Shared access the network?

SKILL.md names 2 domains. In commands or code: im.deepminer.com.cn and im-test.deepminer.com.cn; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Octo Shared safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Octo Shared use?

Octo Shared is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Octo Shared use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Octo Shared?

Skills that share tags, products or a category with Octo Shared: ToolJet Marketplace Plugin Builder (ToolJet/ToolJet, 41k stars), Step Parts (earthtojake/text-to-cad, 19k stars), OpenAPI to MCP Server (mcp-use/mcp-use, 11k stars) and Use Yaak (mountain-loop/yaak, 19k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Octo Shared?

Mininglamp-OSS (a GitHub organization) maintains it in Mininglamp-OSS/octo-cli, which has 918 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on September 28, 2026.

Source: Mininglamp-OSS/octo-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.