Agent skill

Enterprise Boundary

by openchamber in openchamber/openchamber

A skill your agent uses when a change sends conversation content somewhere other than the session's OpenCode provider or this machine, opens a way into this machine (listening address, tunnel…

MITAuto-check passed

Install Enterprise Boundary

skills CLI
$ npx skills add openchamber/openchamber --skill enterprise-boundary -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openchamber/openchamber enterprise-boundary --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openchamber/openchamber.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/enterprise-boundary .claude/skills/enterprise-boundary && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
enterprise-boundary
GitHub stars
11k
Token cost
~1.7k tokens
SKILL.md length
924 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when a change sends conversation content somewhere other than the session's OpenCode provider or this machine, opens a way into this machine (listening address, tunnel…

  • Works in 4 steps: A key in policyFileSchema and its… → Validation in the consumer, with an… → Secrets kept on the server:… → …
  • A change sends conversation content somewhere other than the sessions OpenCode provider
  • SKILL.md covers Classify The Change, Enforce At The Boundary, Admin Knobs and Walk Every Surface, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Enterprise Boundary is an agent skill from openchamber/openchamber. Use when a change sends conversation content somewhere other than the session's OpenCode provider or this machine, opens a way into this machine (listening address, tunnel, relay, pairing, share link), adds a way to enter model providers, keys or endpoints, reports usage, or touches enterprise mode, the policy file or enterprise-mode.js.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Agentic Development Environment based on OpenCode AI agent. The licence is MIT.

When your agent uses it

  • A change sends conversation content somewhere other than the sessions OpenCode provider
  • Opens a way into this machine (listening address
  • Adds a way to enter model providers
  • Touches enterprise mode

Example prompts

  • “/enterprise-boundary”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. A key in policyFileSchema and its environment variable, resolved in readEnterprisePolicy by the source rule: when the file turns the mode…
  2. Validation in the consumer, with an invalid value treated as unset.
  3. Secrets kept on the server: publicEnterprisePolicy carries only what the UI must show.
  4. The matching enterprise-mode.d.ts entry and cases in enterprise-mode.test.js for file, environment, both, and a broken file.

What it can do on your machine

Read from SKILL.md and the folder at commit 74b79d4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Enterprise Boundary loads about 1.7k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 924 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openchamber/openchamber at commit 74b79d4, republished under its MIT licence (© openchamber). 924 words, ~1,662 tokens.

Download SKILL.mdSave it as .claude/skills/enterprise-boundary/SKILL.md (or your agent's skills folder).
name
enterprise-boundary
description
Use when a change sends conversation content somewhere other than the session's OpenCode provider or this machine, opens a way into this machine (listening address, tunnel, relay, pairing, share link), adds a way to enter model providers, keys or endpoints, reports usage, or touches enterprise mode, the policy file or `enterprise-mode.js`.

Enterprise Boundary

Enterprise mode is an administrator's promise: conversation content reaches only the model providers configured in OpenCode, and nothing opens this machine to others without the administrator's say. The user is not trusted to keep the promise; they may edit their environment, Settings, or install the npm server themselves. Every feature either keeps the promise by construction or answers to the mode.

The mechanism, its sources and the list of gated features live in the header of packages/web/server/lib/enterprise-mode.js; the admin-facing contract is the Enterprise mode section of packages/docs/content/docs/security.mdx. Read both before editing.

Classify The Change

Name each way the change can cross the boundary. The classification is complete when every data flow and every listener the change adds or alters sits in one class below or is shown to stay inside.

ClassWhat it isBehavior outside enterprise modeIn enterprise mode
EgressConversation content (messages, turn excerpts, file contents, model output, session names, speech) leaves for any destination other than the session's OpenCode provider or this machineOff until the user turns it onOff, unless the administrator pins an in-house destination or the destination is this machine
Metadata egressA message leaves without content (a push notification, a status ping)As designedContent stripped: generic text, no message text, no session name
ExposureAnother machine can reach this server or its data: a non-loopback listener, tunnel, relay, pairing candidate, share linkAs designed, behind UI authLoopback only, unless the administrator allows network access; relay only on a pinned self-hosted endpoint; public tunnels off
Provider entryThe app adds a model provider, key, endpoint or custom providerAs designedRefused; removing or switching existing accounts stays allowed. OpenCode's provider.use policy is the real lock
TelemetryUsage or install identifiers are reportedAs designedThe essential function stays (security update checks); usage and identifiers are dropped

Inside the boundary, with no gate: work that reaches only the session's provider through OpenCode, work that stays on this machine, and the small model on the user's own provider (never another connected one). A user-initiated action toward a service the user connected themselves (GitHub, Linear) sits outside the mode today; when such an action carries conversation content, raise it with the maintainer.

Whether a flow belongs to a class, and whether an in-house pin should exist, are product decisions. When either is unclear, ask before building.

Enforce At The Boundary

  • Server-side, at the point that performs the crossing. Read isEnterpriseMode() or readEnterprisePolicy() at use time, in the route, job or runtime that sends or listens. UI hiding is courtesy; the refusal lives where the request is served. Answer refusals with 403 and code: 'enterprise_mode' where the neighbouring routes do.
  • Every entry point. The web server serves web, desktop (in-process) and mobile; the CLI and --host reach the same main(); the Electron main process decides what to bind before the server starts; the VS Code extension host runs no OpenChamber server and bundles enterprise-mode.js for the parts it owns (packages/vscode/src/DOCUMENTATION.md). Write the surface list per ui-api-decoupling and give each runtime its enforcement or an explicit "does not exist here".
  • Fail closed. An unreadable policy keeps the mode on, pins nothing and allows nothing. A pinned value that fails validation counts as unset.
Show full SKILL.md (384 more words)Show less

Admin Knobs

When teams plausibly need the feature on their own infrastructure (Jev on an in-house endpoint, a self-hosted relay, network access inside a closed network), a pin beats a plain off. A new knob gets:

  1. A key in policyFileSchema and its environment variable, resolved in readEnterprisePolicy by the source rule: when the file turns the mode on, only the file decides and the environment adds nothing; otherwise the file value wins and the variable fills the gap.
  2. Validation in the consumer, with an invalid value treated as unset.
  3. Secrets kept on the server: publicEnterprisePolicy carries only what the UI must show.
  4. The matching enterprise-mode.d.ts entry and cases in enterprise-mode.test.js for file, environment, both, and a broken file.

Walk Every Surface

List every place a user meets the feature: Settings pages and their search entries (lib/settings/metadata.ts, search.ts), composer and pickers, menus, the command palette, notes that link to setup, onboarding. The walk is complete when each item has one of:

  • Disabled with the reason, in words the user understands, in every locale (locale-ui-patterns), read from useEnterpriseMode, useEnterprisePolicyStore or useJevBlockedByEnterprise.
  • Hidden, when the mode leaves nothing usable on a page (Routing without a pinned Jev, the tunnel page).
  • Unchanged, with the reason it stays inside the boundary.

A link that leads to a setup the mode forbids is a defect. Report every surface to the maintainer, including the ones left unchanged.

Record And Prove

  • Add the feature to the gated list in the enterprise-mode.js header, and to What changes in security.mdx for every locale under packages/docs/content/docs/.
  • Test the refusal with the mode on and the normal path with it off, at the enforcement point. Inject the policy through the options argument or set the variable inside the test; packages/web/vitest.config.ts clears the enterprise variables so a developer's shell cannot flip a suite.
  • A live check where the crossing is a process boundary: start the server with the mode on and the crossing requested (for example --lan), and watch it refuse; then allow it and watch it work.

Completion

Every crossing the change adds has a class, server-side enforcement on each runtime it exists on, a test with the mode on and off, a surface list with each surface's behavior, and updated docs. Open product questions are raised, never decided in the diff.

© openchamber, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/enterprise-boundary of openchamber/openchamber.

Open the folder on GitHubat commit 74b79d4

Compare with similar skills

Enterprise Boundary next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Enterprise Boundary compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Enterprise Boundary this skillopenchamber/openchamber11k—~1.7kAutomated safety check: PassMIT
Modeling Conversion MetricsPostHog/posthog40k—~1.4kAutomated safety check: PassCustom licence
Sendyc-software/qm15k—~1.5kAutomated safety check: PassMIT
Cost Conversationruvnet/ruflo74k—~407Automated safety check: NotesMIT
Conversation Memorydavila7/claude-code-templates32k4 repos~440Automated safety check: PassMIT
Conversation Archivegarrytan/gbrain31k—~5.6kAutomated safety check: PassMIT

Similar skills

  • Official

    Build reusable conversion models — funnel/step conversion rates, drop-off, and time-to-convert — on either PostHog data-warehouse views (HogQL) or an external dbt project.

    40k GitHub stars~1.4k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Send

    yc-software/qm

    Make a PR, wait for CI with bounded transport retries, independently review, and merge only when all gates pass.

    15k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Cost Conversation

    ruvnet/ruflo

    Per-conversation cost view — list every session in cost-tracking with started-at, message count, top model, and total cost

    74k GitHub stars~407 tokensUpdated today
    AI & LLM EngineeringAuto-check: notes
  • Conversation Memory

    davila7/claude-code-templates

    Persistent memory systems for LLM conversations including short-term, long-term, and entity-based memory Use when: conversation memory, remember, memory persistence, long-term memory, chat history.

    32k GitHub starsUsed in 4 repos~440 tokens
    Agent WorkflowsAuto-check passed
  • Conversation Archive

    garrytan/gbrain

    Import AI-assistant chat exports (ChatGPT, Claude, Perplexity) and agent session transcripts into the brain as one dated page per conversation under conversations/, validate each page against the…

    31k GitHub stars~5.6k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Landing Page Conversion Audit

    github/awesome-copilot

    Official

    Audit a landing page, sales page or checkout page for conversion leaks and return a fix list ordered by expected revenue impact.

    40k GitHub starsUsed in 1 repo~1.8k tokens
    Frontend & DesignAuto-check passed

More from openchamber/openchamber

All 21 skills in this repo
  • Theme System

    openchamber/openchamber

    A skill your agent uses when creating or modifying OpenChamber UI components, styling, colors, buttons, visual states, themes, or icons.

    11k GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • UI API Decoupling

    openchamber/openchamber

    A skill your agent uses when creating or modifying OpenChamber shared UI data access, OpenCode SDK calls, RuntimeAPIs, runtime fetch/auth/URLs, authenticated browser assets, bridges/proxies, runtime…

    11k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Drag To Reorder

    openchamber/openchamber

    A skill your agent uses when implementing or modifying OpenChamber sortable or drag-to-reorder behavior, especially @dnd-kit, touch/mobile interactions, variable-width items, or wrapping layouts.

    11k GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Locale UI Patterns

    openchamber/openchamber

    A skill your agent uses when creating or modifying OpenChamber UI text, labels, buttons, placeholders, aria labels, empty states, toasts, dialogs, settings copy, navigation labels, or any…

    11k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Performance Engineering

    openchamber/openchamber

    A skill your agent uses when implementing or reviewing code on interaction, render, event, polling, synchronization, list-processing, store-selector, cache, indexing, or high-volume data paths; when…

    11k GitHub stars~4.9k tokensUpdated yesterday
    Auto-check passed
  • Serve Sim

    openchamber/openchamber

    A skill your agent uses when working with the OpenChamber iOS Simulator app without opening Xcode - boot/install/launch the Capacitor iOS app, start a browser stream, tap/type/gesture/rotate…

    11k GitHub stars~619 tokensUpdated yesterday
    Auto-check passed

Questions about Enterprise Boundary

What does Enterprise Boundary do?

A skill your agent uses when a change sends conversation content somewhere other than the session's OpenCode provider or this machine, opens a way into this machine (listening address, tunnel…. Enterprise Boundary is an agent skill from openchamber/openchamber.js.

When should I use Enterprise Boundary?

Enterprise Boundary fits situations like: A change sends conversation content somewhere other than the sessions OpenCode provider; opens a way into this machine (listening address; adds a way to enter model providers; touches enterprise mode.

How do I install Enterprise Boundary in Claude Code?

Run `npx skills add openchamber/openchamber --skill enterprise-boundary -a claude-code`. Or copy the skill folder (.agents/skills/enterprise-boundary in openchamber/openchamber) into .claude/skills/enterprise-boundary in your project. Claude Code loads it when a task matches its description.

How do I install Enterprise Boundary in Codex?

Run `npx skills add openchamber/openchamber --skill enterprise-boundary -a codex`. Or copy the skill folder (.agents/skills/enterprise-boundary in openchamber/openchamber) into .agents/skills/enterprise-boundary in your project. Codex loads it when a task matches its description.

Can I use Enterprise Boundary in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openchamber/openchamber --skill enterprise-boundary -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/enterprise-boundary, .gemini/skills/enterprise-boundary, .github/skills/enterprise-boundary and .opencode/skills/enterprise-boundary in your project.

What does Enterprise Boundary need to run?

SKILL.md names no scripts, command-line tools or credentials: Enterprise Boundary is instructions for the agent only.

Does Enterprise Boundary access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Enterprise Boundary safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Enterprise Boundary use?

Enterprise Boundary is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Enterprise Boundary use?

About 1.7k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Enterprise Boundary?

Skills that share tags, products or a category with Enterprise Boundary: Modeling Conversion Metrics (PostHog/posthog, 40k stars), Send (yc-software/qm, 15k stars), Cost Conversation (ruvnet/ruflo, 74k stars) and Conversation Memory (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Enterprise Boundary?

openchamber (a GitHub organization) maintains it in openchamber/openchamber, which has 11,308 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 8, 2026.

Source: openchamber/openchamber on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.