Vercel Composition Patterns
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
How Nostr works in this repository: the three NIP lanes under nips/, the wire protocol (NIP-01), relay authentication (NIP-42), payload encryption (NIP-44), the Block agent NIPs the relay serves…
$ npx skills add OpenAgentsInc/openagents --skill nostr -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install OpenAgentsInc/openagents nostr --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/OpenAgentsInc/openagents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/nostr .claude/skills/nostr && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nostr" agent skill from https://github.com/OpenAgentsInc/openagents/tree/main/.agents/skills/nostr into .claude/skills/nostr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nostr", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/OpenAgentsInc/openagents/tree/main/.agents/skills/nostrType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add OpenAgentsInc/openagents --skill nostr -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install OpenAgentsInc/openagents nostr --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OpenAgentsInc/openagents.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/nostr .agents/skills/nostr && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nostr" agent skill from https://github.com/OpenAgentsInc/openagents/tree/main/.agents/skills/nostr into .agents/skills/nostr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nostr", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OpenAgentsInc/openagents --skill nostr -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install OpenAgentsInc/openagents nostr --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OpenAgentsInc/openagents.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/nostr .cursor/skills/nostr && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nostr" agent skill from https://github.com/OpenAgentsInc/openagents/tree/main/.agents/skills/nostr into .cursor/skills/nostr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nostr", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/OpenAgentsInc/openagents.git --path .agents/skills/nostr--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add OpenAgentsInc/openagents --skill nostr -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install OpenAgentsInc/openagents nostr --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OpenAgentsInc/openagents.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/nostr .gemini/skills/nostr && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nostr" agent skill from https://github.com/OpenAgentsInc/openagents/tree/main/.agents/skills/nostr into .gemini/skills/nostr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nostr", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install OpenAgentsInc/openagents nostrInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add OpenAgentsInc/openagents --skill nostr -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/OpenAgentsInc/openagents.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/nostr .github/skills/nostr && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nostr" agent skill from https://github.com/OpenAgentsInc/openagents/tree/main/.agents/skills/nostr into .github/skills/nostr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nostr", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OpenAgentsInc/openagents --skill nostr -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install OpenAgentsInc/openagents nostr --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OpenAgentsInc/openagents.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/nostr .opencode/skills/nostr && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nostr" agent skill from https://github.com/OpenAgentsInc/openagents/tree/main/.agents/skills/nostr into .opencode/skills/nostr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nostr", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nostrHow Nostr works in this repository: the three NIP lanes under nips/, the wire protocol (NIP-01), relay authentication (NIP-42), payload encryption (NIP-44), the Block agent NIPs the relay serves…
Nostr is an agent skill from OpenAgentsInc/openagents. How Nostr works in this repository: the three NIP lanes under nips/, the wire protocol (NIP-01), relay authentication (NIP-42), payload encryption (NIP-44), the Block agent NIPs the relay serves, and the OpenAgents NIPs (NIP-CJ jobs, NIP-CAP capabilities, NIP-PRG programs) that carry a Coder turn to a worker. Read it before touching crates/nostr, crates/nostr-relay, crates/coder/src/relay.rs, coder-worker, or any file under nips/, and before debugging a relay handoff.
Its SKILL.md is about 6.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ad29644. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CODER_SECRET_KEYCODER_WORKER_SECRETCODER_DOOR_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nostr loads about 6.2k tokens when it runs. Until then it costs about 123 tokens; SKILL.md has 3,032 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from OpenAgentsInc/openagents at commit ad29644, republished under its Apache-2.0 licence (© OpenAgentsInc). 3,032 words, ~6,158 tokens.
.claude/skills/nostr/SKILL.md (or your agent's skills folder).Use this skill when you change or debug anything that touches a relay:
the protocol crates, the relay binary, the Coder relay door, the worker,
or a specification under nips/. The specifications are the source of
truth; this skill tells you where they are and how the pieces fit, so you
don't rediscover the flow from code.
| Lane | Path | Source of truth | Synced |
|---|---|---|---|
| Official NIPs | nips/official/ | nostr-protocol/nips | yes, ./scripts/sync-nips.sh |
| Block (Buzz) extension NIPs | nips/block/ | block/buzz | yes |
| OpenAgents NIPs | nips/openagents/ | this repository | no — the files here are authoritative |
nips/manifest.json pins the upstream commit of each synced lane. A sync
never changes the implementation without review and a fixture update.
nips/README.md states the mandate: every pinned spec that applies to a
relay is an implementation target for crates/nostr and
crates/nostr-relay, optional features stay fail-closed and out of NIP-11
until they run, and client-only NIPs are implemented as fixture-backed
clients rather than pretended.
Read the September 26 upstream review and implementation coverage before assuming complete support. Source inventory checks now track the current pins separately from behavioral evidence. PMA 30179 is rejected, client-authored 39007 is refused, and app data and private artifacts have explicit visibility. RS has an opt-in atomic HTTP snapshot. The PL executor is off by default and needs a credential-holding push gateway; no real device delivery is recorded. Client helpers do not imply complete AP, FI, CW-thread, or RS merge integration.
Read the spec before the code. The files you need most often:
nips/official/01.md — the protocol: events, kinds, filters, and the
client-relay messages.nips/official/42.md — client authentication to a relay.nips/official/44.md — encrypted payloads.nips/official/11.md — the relay information document.nips/official/40.md — the expiration tag.nips/official/19.md — npub and nsec encoding.nips/block/README.md — a per-spec summary of all 17 Block NIPs.nips/openagents/NIP-CJ.md — Coder jobs, the protocol between coder
and coder-worker.nips/openagents/NIP-DEC.md — decisions: typed questions with structured
(EntryType) instructions and criteria, carried by the CJ decision family.nips/openagents/NIP-CAP.md — capability manifests and presence.nips/openagents/NIP-PRG.md — programs.nips/openagents/NIP-EXT.md — extension releases, discovery, revocation,
foreign-format import, and compatible host component-set assessments.nips/openagents/NIP-REG.md — curated plugin registries, exact publisher
release pins, per-registry trust, and signed Nostr and GitHub/HTTPS sources.nips/openagents/NIP-RUN.md — encrypted durable journals and recovery.nips/openagents/NIP-CTX.md — task frames, evidence views, and expansion.nips/openagents/NIP-POL.md — instructions, approvals, disclosure, routing
records, and governed activation of learned private preferences.nips/openagents/NIP-COORD.md — task claims, fencing, and background findings.nips/openagents/NIP-EVAL.md — attributable workload evaluation and promotion evidence.nips/openagents/NIP-OPT.md — semantic AI contracts, immutable implementations,
bounded studies, actual candidate execution, and optimization evidence.nips/openagents/NIP-XP.md — quests, referee awards of accepted outcomes,
revocations, and per-reader XP ledgers; crates/nostr (xp) checks them.nips/openagents/NIP-KB.md — shared knowledge entries, heads, withdrawals,
and evidence; crates/nostr (kb) checks them.nips/openagents/NIP-CTRL.md — task-scoped client pairing, observation,
steering, and cancellation; no approval or wallet authority from pairing.nips/openagents/NIP-MKT.md — negotiated offerings, bilateral orders,
private records, and separately admitted fixed-price Lightning settlement.nips/openagents/NIP-LAB.md — bounded agent labor, exact execution linkage,
deliverables, independent checks, rework, disputes, acceptance, and rights.nips/openagents/NIP-X402.md — Designed Lightning-paid operations before
execution, standard x402 HTTP/MCP bindings, and an opt-in native Nostr profile.nips/openagents/NIP-SESS.md — engine sessions, actual adapter support,
queues, turn control, pending interactions, and retained native history.nips/openagents/NIP-WS.md — workspace/resource identity, conditional edits,
checkpoints, and bounded projection snapshots, deltas, and cuts.nips/openagents/NIP-WORK.md — tracked objectives, planning relationships,
accountable ownership, delegation, exact revisions, and work disposition.nips/openagents/NIP-AUTO.md — durable schedules, source watches, bounded
goal continuations, occurrence identity, and restart-safe accounting.nips/openagents/NIP-ENV.md — execution environment leases, actual
materialization, attachment, cleanup, and uncertain resource accounting.nips/openagents/NIP-LIVE.md — admitted media/capture, participants and
recipients, input and speaking floors, evidence, and scoped device input.nips/openagents/NIP-REACH.md — private host directory, bounded presence,
reachability, and authenticated direct channels. Placement grants no rights.nips/openagents/NIP-HOST.md — host-wide device enrollment and scoped
grants; access rights do not supply POL approval or spending authority.nips/openagents/NIP-TERM.md — host-owned interactive terminals, bounded
output replay, explicit gaps, and current access checks.nips/openagents/NIP-SOV.md — Designed successor to historical SA: durable
identity, supported custody, bounded AUTO lifecycle, POL guardians, treasury
policy, and retained recovery evidence. It allocates no new event kinds.nips/openagents/NIP-MV.md — Verse world presence, entity state, and
gestures; independent of the shared agent-artifact contracts.docs/optimization/README.md — DSPy/GEPA concepts, Gym evaluation, host
boundaries, and a consolidated unfiled integration backlog.nips/openagents/contracts.md — pinned identities, schemas, locks, evidence,
context, effects, outcomes, and private artifact envelopes for the v1 contracts.docs/coder/design/typesafe-agent-protocol-addendum.md — what belongs in
Nostr and what hosts/clients must implement; complete source-proposal coverage.docs/protocol/implementation-plan.md — implementation across all lanes.docs/agents/README.md and docs/agents/roadmap.md — general agent
infrastructure, Coder's domain boundary, and remaining non-code contracts.docs/protocol/block-nips.md — what the relay does with each Block NIP,
including what it deliberately doesn't advertise.The OpenAgents lane contains 30 NIPs plus the shared contracts. X402, SESS, WS,
WORK, AUTO, ENV, LIVE, and SOV are Designed drafts, as are POL's learned
preference lifecycle and EXT's import/component-set assessment additions.
REG is a Designed profile using inert EXT catalogs and existing release/head
kinds; no registry client is implemented. These profiles allocate no new event
kinds: private artifacts use 3188, remote host operations use admitted CAP/CJ
profiles, and effects leave RUN evidence.
Keeping an encrypted envelope does not implement the contract inside it.
SOV does not restore the legacy 392xx allocations or imply working key
custody, guardians, or payments. REACH has a narrower coder-reach
implementation; consult its role limits before treating reachability as
availability or controller-transfer authority.
ATIF is a Designed draft that does allocate kinds: public trajectory
declarations 3198 and chunks 3199; private trajectories ride 3188. It
replaces historical 39230/39231; no component publishes trajectories yet.
MKT/LAB has a bounded free-order host in crates/coder-labor, with retained relay
and process fixtures. Paid settlement, independently operated service delivery,
and broader market roles remain unfinished. CTRL has a bounded local-owner bridge in crates/coder-control; read
docs/coder/runtime/nostr-task-control.md for its rights, expiry, exact retry,
and disclosure limits. It does not complete mobile control or a cross-device
product. Check the glossary
for the narrower implemented and partial roles.
Read the x402 integration assessment
before adding a payment adapter. NIP-X402 preserves upstream http:1 and
mcp:1; nostr:openagents:1 is an opt-in OpenAgents extension that requires
explicit facilitator support. It pays before execution; MKT/LAB pays after
acceptance. NWC is wallet transport, not purchase authority. Zap invoices hash
the zap request, while x402 invoices hash the bound operation; do not reuse
one invoice as both. L402/LSAT is a distinct macaroon-based protocol. These
paths have no operational OpenAgents wallet or settlement adapter. Pure
validation components do not consume proofs or authorize spending.
Read the teardown integration plan and file-by-file archive coverage when carrying historical ideas forward. The archive supplies design evidence; its old TypeScript, hosting, and product decisions are not current instructions. A tracked work item, session, run, environment, view, and commercial order have separate identities. Assignment does not dispatch; completion does not accept labor; acceptance does not pay; a live view does not grant mutation. Hosts must enforce these boundaries before advertising the corresponding role.
An event is a signed JSON object: id (SHA-256 of the serialized
fields), pubkey (the author's x-only secp256k1 key, hex), created_at
(unix seconds), kind, tags (arrays of strings; the first element is
the tag name), content, and sig (Schnorr). The id and sig are what
make an event evidence: a relay can relabel or drop an event, but it can't
forge one.
Kind ranges decide how a relay stores an event:
| Range | Class | Relay behavior |
|---|---|---|
| everything not listed below | regular | stored, all kept |
0, 3, 10000–19999 | replaceable | latest per pubkey+kind kept |
20000–29999 | ephemeral | fanned out to open subscriptions, never stored |
30000–39999 | addressable | latest per pubkey+kind+d tag kept |
crates/nostr implements this as EventClass::from_kind in
domain/replacement.rs. Every NIP-CJ
job kind is ephemeral; NIP-CAP and NIP-PRG discovery kinds are addressable.
NIP-EXT and NIP-RUN add regular immutable records with separate addressable
heads. A discovery head is never an execution version pin.
Messages, client to relay:
["EVENT", <event>] — publish.["REQ", <sub_id>, <filter>, ...] — subscribe; the relay sends stored
matches, then EOSE, then live matches until CLOSE.["CLOSE", <sub_id>] — end a subscription.["AUTH", <event>] — answer a NIP-42 challenge.Relay to client:
["EVENT", <sub_id>, <event>] — a match.["OK", <event_id>, true|false, <message>] — the verdict on an
EVENT or AUTH. A false message starts with a machine-readable
prefix: duplicate:, pow:, blocked:, rate-limited:, invalid:,
restricted:, mute:, auth-required:, or error:.["EOSE", <sub_id>] — end of stored events; what follows is live.["CLOSED", <sub_id>, <message>] — the relay ended the subscription,
with the same prefixes.["NOTICE", <message>] — human-readable.["AUTH", <challenge>] — a NIP-42 challenge.Filters select on ids, authors, kinds, #<single-letter-tag>,
since, until, and limit. Only single-letter tags are indexed, which
is why NIP-CJ routes on e and p.
A relay may send ["AUTH", <challenge>] at any time; this relay sends
one on connect whenever NOSTR_RELAY_URL is set. The client answers with
a kind-22242 event carrying ["relay", <url>] and
["challenge", <challenge>] tags, created_at within ten minutes of
now, and the relay replies ["OK", <auth_event_id>, true, ""]. Kind
22242 is never stored or broadcast.
An unauthenticated client isn't refused by default. Only what the relay gates needs auth:
NOSTR_RELAY_AUTH_REQUIRED=true — the relay answers
auth-required: on EVENT and CLOSED ... auth-required: on REQ.1059, engrams 30174, turn
metrics 44200, and others listed in
event_visible_to_reader in crates/nostr-relay/src/gateway/subscription.rs).
A subscription's read_pubkeys is the set of keys the connection has
authenticated as.- tag), closed-membership relays, and every
relay command in docs/protocol/block-nips.md.The Coder client and worker always authenticate when challenged — the
npub is the account — and both refuse a connection whose challenge
gets no OK. NIP-AA lets an agent key satisfy AUTH with an owner
attestation (nips/block/NIP-OA.md) instead of its own membership.
NIP-44 version 2 encrypts a payload under a conversation key derived
from the sender's secret and the recipient's public key (ECDH, then HKDF),
so either party can decrypt and nobody else can. It hides the content and
pads its length; it does not hide the tags, so kind, e, and p stay
visible to the relay as routing metadata. Gift wraps (NIP-59) and every
NIP-CJ payload use it. The implementation is crates/nostr's nip44
module.
nips/openagents/NIP-CJ.md is the contract between coder (the
customer) and coder-worker (the fulfiller). The relay is transport
only: it holds no job state and sees only ciphertext.
| Kind | Name | Direction | Payload type |
|---|---|---|---|
25900 | job request | terminal → worker | task, transcript, instructions, client, v |
27000 | job feedback | worker → terminal | judgment, partial (with seq under v: 1), status |
26900 | job result | worker → terminal | result with text, optional usage and model |
The flow, in the order the sockets speak it:
{"kinds": [25900], "#p": [<worker pubkey>]}.25900 request
p-tagged to the worker with NIP-44 content encrypted to the
worker's key, subscribes {"kinds": [26900, 27000], "#e": [<request id>]},
and only then publishes the request. Subscribing first closes the
race where fast feedback would be missed.e-tagged to the request and p-tagged
to the customer, encrypted to the customer's key.26900 or 27000, the signer is the configured
worker, an e tag names this request, and a p tag names this
terminal. The subscription label is a routing hint, never identity.status: error. The terminal
then sends CLOSE for the job's subscription and keeps the socket
for the next turn. A relay CLOSED on that subscription ends the job
as a relay error with the relay's reason. A socket that broke, or a
wait that ran out with a subscription that might still deliver, is
dropped, and the next turn opens a fresh one. A turn holds the socket
for its duration, so a caller that cancels the turn drops the socket
with it; the relay frees the subscription when the connection ends.The conversation specification uses integer v1 with sequenced partials. Decision and execution bodies use their named v1 schemas. Validate each family against its own complete contract; do not infer support from a version alone.
Deadlines and failure words, on the terminal side
(crates/coder/src/relay.rs): if nothing bound to the request arrives
within the contact deadline, the turn fails with cause worker_absent
("no worker answered"). If a worker was heard but no result arrives
within the answer deadline, the cause names the worker as silent. A
relay OK … false on the request fails the turn with the relay's reason.
Opening a socket, handshake and AUTH together, is bounded by
CONNECT_TIMEOUT. A worker that fails upstream and publishes nothing
looks identical to an absent worker from the terminal — check the
worker's stderr before blaming the relay.
A worker whose door is a local executor (CODER_EXECUTOR) publishes one
encrypted kind-27000 feedback event,
{"type": "status", "status": "processing"}, as soon as it admits a
delegation and before the executor starts. The terminal counts any
well-formed kind-27000 status of queued, processing, or error as
contact, so its 30-second contact deadline ends at admission rather than
at the executor's answer.
Environment, terminal side: CODER_WORKER (worker npub or hex pubkey)
and CODER_RELAY (ws:// or wss:// URL). The identity is
CODER_SECRET_KEY or CODER_NSEC, or, when neither is set, the key at
~/.openagents/nostr-secret, created on first use with mode 0600. Only
a missing file is a first use: an unreadable one is an error, so a
permissions accident cannot silently mint a new npub. Creation is
exclusive and atomic, and concurrent first runs agree on one key. A
fresh keypair is a valid anonymous account; never print, log, or commit
the secret.
Environment, worker side (crates/coder/src/bin/coder-worker.rs):
CODER_WORKER_SECRET (64 hex or nsec), CODER_RELAY, and the door:
CODER_DOOR_KEY with CODER_DOOR_URL and CODER_WORKER_MODEL for an
Open Responses door, or CODER_EXECUTOR=<capability slug> for a local
approved executor such as devin-local (see
docs/coder/guides/worker-executor.md). Setting both is refused. The
worker prints its pubkey on start; that value is what the terminal's
CODER_WORKER names. --once answers one job and exits; --decline <CODE> refuses every job with a typed status error, for measuring the
refusal path. CODER_WORKER_ALLOW (comma-separated npub or hex keys)
limits which customers the worker answers; anyone else gets a typed
not_admitted status, never silence. Unset admits everyone, which is
right only on a local relay. CODER_WORKER_JOBS bounds how many jobs
the worker runs at once; unset, an executor door runs as many as its
manifest's concurrent_max and a model door runs four. A request past
the bound is refused before anything runs, with a typed busy status,
and the refusal releases the slot. The worker's key and the terminal's
key must differ.
docs/coder/measurements/relay-transport.md is the measured proof that both ends
meet, with per-transport latency and refusal causes.
CAP describes portable interfaces, host bindings, presence, and operator preferences. Reading a manifest is inert; probes and invocations have separate admission. PRG defines typed workflows, seven step kinds, bounded composition, and the Wasm packet ABI. EXT distributes immutable components and RUN records durable execution.
OPT separates semantic AI signatures from their concrete implementations. Programs can invoke a supported pinned implementation through the same host boundary. Compiler, optimizer, evaluator, and inference capabilities remain distinct. EVAL supplies workload evidence and scoped promotion; neither a score nor a package signature grants execution.
Follow the normative NIPs for exact fields and validation. Implement only supported roles and advertise them after conformance. Artifact identity, actual materialization, protected evaluation, and operator adoption are separate checks. Local operation need not publish an event for every action.
crates/nostr-relay)One binary, one Postgres database. Configuration is environment only;
deploy/nostr-relay.env.example and docs/deployment/configuration.md
list every variable. The ones you need for a local run:
DATABASE_URL=postgres://<user>:<password>@127.0.0.1:5432/<db>
NOSTR_RELAY_BIND_ADDR=127.0.0.1
NOSTR_RELAY_PORT=7447
NOSTR_RELAY_URL=ws://127.0.0.1:7447 # enables the NIP-42 challenge
NOSTR_RELAY_MEDIA_ROOT=$HOME/relay-media # optional; absolute path
NOSTR_RELAY_AUTH_REQUIRED=false # true to gate EVENT and REQ
NOSTR_RELAY_LOG_LEVEL=infoMigrations run on first boot and the start fails closed if the ledger
disagrees with the database. GET /health and a NIP-11 request
(Accept: application/nostr+json on /) confirm it's up.
docs/deployment/runbook-local-dev.md walks the same steps with a
disposable Postgres cluster and the nak client.
Live fan-out is in gateway/subscription.rs: a published event is
indexed by id, author, kind, and each single-letter tag; a subscription
is matched against its filters, then checked with
event_visible_to_reader for the private kinds; a subscription still
loading history buffers live matches until EOSE. Ephemeral events are
deduplicated by id over a short window and never reach storage.
The Block NIPs the relay serves, and how, are in
docs/protocol/block-nips.md. The relay-signed kinds (39005, 39006, 39007,
30622) are refused from clients with restricted:.
When coder -p reports worker_absent:
worker <pubkey>, relay <url>, door …, and waiting for jobs.
CODER_WORKER must equal that printed pubkey.nak req or a scripted WebSocket client) and run
the turn again. Seeing the kind-25900 event there proves the relay
and the terminal; not seeing it means the request was refused (read
the OK) or the terminal's CODER_RELAY points elsewhere.job <id> failed: …. A worker whose
door fails upstream publishes nothing, and the terminal can't tell
that from silence.NOSTR_RELAY_LOG_LEVEL=debug. It then logs one
line per admitted ephemeral event: kind, ID, author, e and p
tags, and the content's byte length, never the content. A 25900
with no 26900 tagged e to it is a job the worker never answered.
Ephemeral kinds are not stored, so the database holds nothing to
query afterwards; the log is the only relay-side record.crates/nostr has no storage, no network, and
no third-party Nostr crate.nsec, or door key.
Test fixtures use throwaway keys generated in the test.e,
and p — before the payload is read.nips/openagents/ or a synced upstream
commit), then validators and fixtures, then the applicable host, client, or
relay role. A client-only or encrypted host contract does not become relay
behavior merely because its envelope passes validation.© OpenAgentsInc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/nostr of OpenAgentsInc/openagents.
Open the folder on GitHubat commit ad29644
Nostr next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nostr this skillOpenAgentsInc/openagents | 455 | — | ~6.2k | Automated safety check: Pass | Apache-2.0 | |
| Vercel Composition Patternssupabase/supabase | 111k | 59 repos | ~726 | Automated safety check: Pass | MIT | |
| Finishing a Development Branchobra/superpowers | 296k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Typescript Advanced Typesrolling-scopes/rsschool-app | 10k | 25 repos | ~4.2k | Automated safety check: Pass | MPL-2.0 | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT |
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
rolling-scopes/rsschool-app
Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
onyx-dot-app/onyx
Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.
OpenAgentsInc/openagents
Build AI-powered software with TypeSafe: small units of AI intelligence you can use like programming primitives.
OpenAgentsInc/openagents
Call the OpenAgents decision API: authenticate with an oak bearer key, post state + typed questions to POST /v1/systemone, read Noul, Choice, and Score answers with their probabilities, and handle…
OpenAgentsInc/openagents
Apply the Google Developer Documentation Style Guide to user-facing docs, READMEs, AGENTS.md, and commit messages.
OpenAgentsInc/openagents
Authenticate to and call the OpenAgents decision API — typed decisions, batch classification, durable jobs, and the bundled documentation — through the oak CLI, the oak-mcp server, or raw HTTP.
Categories
How Nostr works in this repository: the three NIP lanes under nips/, the wire protocol (NIP-01), relay authentication (NIP-42), payload encryption (NIP-44), the Block agent NIPs the relay serves…. Nostr is an agent skill from OpenAgentsInc/openagents. How Nostr works in this repository: the three NIP lanes under nips/, the wire protocol (NIP-01), relay authentication (NIP-42), payload encryption (NIP-44), the Block agent NIPs the relay serves, and the OpenAgents NIPs (NIP-CJ jobs, NIP-CAP capabilities, NIP-PRG programs) that carry a Coder turn to a worker.
Nostr fits situations like: development work in your project.
Run `npx skills add OpenAgentsInc/openagents --skill nostr -a claude-code`. Or copy the skill folder (.agents/skills/nostr in OpenAgentsInc/openagents) into .claude/skills/nostr in your project. Claude Code loads it when a task matches its description.
Run `npx skills add OpenAgentsInc/openagents --skill nostr -a codex`. Or copy the skill folder (.agents/skills/nostr in OpenAgentsInc/openagents) into .agents/skills/nostr in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OpenAgentsInc/openagents --skill nostr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nostr, .gemini/skills/nostr, .github/skills/nostr and .opencode/skills/nostr in your project.
Going by SKILL.md and its folder, Nostr needs credentials named CODER_SECRET_KEY, CODER_WORKER_SECRET and CODER_DOOR_KEY.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Nostr is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.2k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Nostr: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
OpenAgentsInc (a GitHub organization) maintains it in OpenAgentsInc/openagents, which has 455 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 8, 2026.
Source: OpenAgentsInc/openagents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.