Agent skill

Agent Canvas Environment

by OpenHands in OpenHands/extensions

Work effectively inside a local Agent Canvas environment, including local agent-server auth, frontend/backend port discovery, safe workspace hygiene, and delegating work to a new local conversation…

MITAuto-check passedFrontend & Design

Install Agent Canvas Environment

skills CLI
$ npx skills add OpenHands/extensions --skill agent-canvas-environment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OpenHands/extensions agent-canvas-environment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OpenHands/extensions.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agent-canvas-environment .claude/skills/agent-canvas-environment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agent-canvas-environment
GitHub stars
158
Token cost
~2.5k tokens
SKILL.md length
615 words
Files
5
Skills in repo
78
Repo updated
First seen
Licence
MIT

At a glance

Work effectively inside a local Agent Canvas environment, including local agent-server auth, frontend/backend port discovery, safe workspace hygiene, and delegating work to a new local conversation…

  • Works in 2 steps: agent_profile_id (simplest, but no… → Encrypted agent_settings (full tools,…
  • Frontend & Design work in your project
  • SKILL.md covers Core rules, Find the session key, Delegate to a local conversation and Monitor a delegated conversation, plus 1 more section
  • Calls curl, jq and git; needs SESSION_API_KEY and LOCAL_BACKEND_API_KEY

What it does

Agent Canvas Environment is an agent skill from OpenHands/extensions. Work effectively inside a local Agent Canvas environment, including local agent-server auth, frontend/backend port discovery, safe workspace hygiene, and delegating work to a new local conversation through POST /api/conversations.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `.plugin/plugin.json` and `README.md`).

It sits in Frontend & Design. The repository describes itself as: Public registry for OpenHands extensions. The licence is MIT.

When your agent uses it

  • Frontend & Design work in your project

Example prompts

  • “/agent-canvas-environment”

Requirements

  • A credential in SESSION_API_KEY
  • A credential in LOCAL_BACKEND_API_KEY

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. agent_profile_id (simplest, but no tools) — send only agent_profile_id: "" (from GET /api/agent-profiles → the profile whose id equals…
  2. Encrypted agent_settings (full tools, preserves context) — start from the encrypted /api/settings agent_settings payload, drop…

What it can do on your machine

Read from SKILL.md and the folder at commit d008b81. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SESSION_API_KEY
    • LOCAL_BACKEND_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Agent Canvas Environment loads about 2.5k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 615 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from OpenHands/extensions at commit d008b81, republished under its MIT licence (© OpenHands). 615 words, ~2,486 tokens.

Download SKILL.mdSave it as .claude/skills/agent-canvas-environment/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
agent-canvas-environment
description
Work effectively inside a local Agent Canvas environment, including local agent-server auth, frontend/backend port discovery, safe workspace hygiene, and delegating work to a new local conversation through POST /api/conversations.
triggers
agent canvas, agent-canvas, local conversation, delegate local conversation, session api key, X-Session-API-Key, localhost:8001

Agent Canvas Environment

Use this skill when running inside or alongside a local Agent Canvas stack, especially when the user asks to inspect the local backend, create or monitor local conversations, or delegate work to another local conversation.

Core rules

  • Treat the local Agent Canvas backend as an agent-server API, usually http://localhost:8001.
  • Treat the local UI as a separate frontend, usually http://localhost:8000.
  • Do not print session API keys. Pass them directly in X-Session-API-Key.
  • Trust any runtime-services block or explicit user-provided host over default ports.
  • Before mutating a repository, check git status -sb. If a worktree has unrelated changes, use a separate worktree or clone.
  • When delegating, write a self-contained prompt. The new conversation does not inherit the current chat context.

Find the session key

Use the first available value, without echoing it:

bash
KEY="${SESSION_API_KEY:-${OH_SESSION_API_KEYS_0:-${LOCAL_BACKEND_API_KEY:-}}}"
if [ -z "$KEY" ] && [ -f "$HOME/.openhands/agent-canvas/api-key.txt" ]; then
  KEY="$(tr -d '\n' < "$HOME/.openhands/agent-canvas/api-key.txt")"
fi
test -n "$KEY" || { echo "No Agent Canvas session API key found" >&2; exit 1; }

Validate backend access:

bash
curl -sS -o /tmp/agent-canvas-conversations.json -w '%{http_code}\n' \
  -H "X-Session-API-Key: $KEY" \
  http://localhost:8001/api/conversations/search

HTTP 200 means the backend and key work.

Delegate to a local conversation

Use POST /api/conversations with:

  • the encrypted agent_settings from GET /api/settings (with X-Expose-Secrets: encrypted), which carries the real Fernet-encrypted llm.api_key, the existing agent_context, and the agent kind — so you never handle plaintext credentials and you don't drop the caller's skill/context config
  • secrets_encrypted: true so the agent-server decrypts that api_key server-side
  • the exec tool set merged into agent_settings.tools (and task_tool_set when you enable sub-agents)
  • tool_module_qualnames for any non-SDK tools (e.g. canvas_ui)
  • agent_context.load_public_skills/load_user_skills/load_project_skills set to true if the delegated agent should inherit bundled/user/project skills
  • a fresh absolute workspace directory
  • initial_message.run: true
  • worktree: false when the workspace is already isolated
Credential handling — important

GET /api/settings (default) masks every credential — llm.api_key comes back as the literal string "**********". If you forward that verbatim, the new conversation authenticates with the placeholder and fails immediately with LLMAuthenticationError (You must provide an API key).

The supported way to obtain forwardable credentials is the X-Expose-Secrets: encrypted request header. With it, /api/settings returns the real llm.api_key as a Fernet-encrypted token (starts with gAAAAA) intended to be sent back to the server with secrets_encrypted: true; the agent-server's decrypt_incoming_llm_secrets decrypts it server-side. Do not read ~/.openhands/profiles/*.json directly — that is brittle (the caller may not share the backend's home directory, active_profile may be null, the profile store may live elsewhere).

Two working approaches:

  1. agent_profile_id (simplest, but no tools) — send only agent_profile_id: "<uuid>" (from GET /api/agent-profiles → the profile whose id equals active_agent_profile_id from /api/settings). The server resolves the LLM key + agent kind from the profile. Mutually exclusive with agent/agent_settings, and the openhands agent-profile schema forbids tools/include_default_tools, so the conversation gets zero exec tools this way. Use only when the task needs no tools.

  2. Encrypted agent_settings (full tools, preserves context) — start from the encrypted /api/settings agent_settings payload, drop schema_version and mcp_config (to avoid MCP-connection failures at creation time), merge in the exec tool set and load_*_skills flags, and send with secrets_encrypted: true. This is the pattern for real delegated work.

Show full SKILL.md (151 more words)Show less

Template (full tools, preserves context):

bash
set -euo pipefail

BASE="${AGENT_CANVAS_BACKEND:-http://localhost:8001}"
KEY="${SESSION_API_KEY:-${OH_SESSION_API_KEYS_0:-${LOCAL_BACKEND_API_KEY:-}}}"
if [ -z "$KEY" ] && [ -f "$HOME/.openhands/agent-canvas/api-key.txt" ]; then
  KEY="$(tr -d '\n' < "$HOME/.openhands/agent-canvas/api-key.txt")"
fi
test -n "$KEY" || { echo "No Agent Canvas session API key found" >&2; exit 1; }

WORKDIR="${WORKDIR:-$HOME/workspace/delegated/$(date +%Y%m%d-%H%M%S)}"
mkdir -p "$WORKDIR"

# Fetch the agent_settings with ENCRYPTED secrets exposed. This returns the
# real llm.api_key as a Fernet token (gAAAAA...) plus the existing
# agent_context/agent kind, so we preserve the caller's config and never
# handle plaintext credentials.
SETTINGS_JSON="$(curl -sS -H "X-Session-API-Key: $KEY" -H "X-Expose-Secrets: encrypted" "$BASE/api/settings")"

PROMPT='Write a complete, task-specific prompt here. Include repo, branch, constraints, validation, and expected report.'

PAYLOAD="$(jq -n --argjson settings "$SETTINGS_JSON" --arg prompt "$PROMPT" --arg workdir "$WORKDIR" '
  # Start from the encrypted agent_settings so llm.api_key (Fernet token),
  # agent_kind, and agent_context are preserved. Drop schema_version and
  # mcp_config (MCP servers can fail to connect at creation time; the profile
  # can be re-resolved later if needed).
  def base_agent_settings:
    ($settings.agent_settings // {})
    | del(.schema_version)
    | del(.mcp_config);

  # Merge the exec tool set into the existing tools list. Include task_tool_set
  # when sub-agents are enabled — enable_sub_agents alone does not expose the
  # delegation tool; Agent Canvas adds task_tool_set for that.
  def with_tools:
    .tools = ((.tools // []) + [
      {name: "terminal", params: {}},
      {name: "file_editor", params: {}},
      {name: "task_tracker", params: {}},
      {name: "browser_tool_set", params: {}},
      {name: "canvas_ui", params: {}}
    ] + (if .enable_sub_agents then [{name: "task_tool_set", params: {}}] else [] end)
    | unique_by(.name));

  # Preserve the existing agent_context and enable skill loading for the
  # delegated agent (defaults are false, so set these explicitly).
  def with_skill_loading:
    .agent_context = ((.agent_context // {}) + {
      load_public_skills: true,
      load_user_skills: true,
      load_project_skills: true
    });

  ($settings.conversation_settings // {}) as $conv |
  {
    secrets_encrypted: true,
    agent_settings: (base_agent_settings | with_tools | with_skill_loading),
    tool_module_qualnames: { canvas_ui: "canvas_ui_tool" },
    workspace: {kind: "LocalWorkspace", working_dir: $workdir},
    confirmation_policy: {kind: "NeverConfirm"},
    # Delegated tasks usually need more than the SDK default of 80 iterations;
    # default to the caller's conversation_settings value (1000 in Agent Canvas)
    # so long-running tasks aren't cut off prematurely. Override per-task if needed.
    max_iterations: (($conv.max_iterations // 1000) | if . == null then 1000 else . end),
    stuck_detection: true,
    autotitle: true,
    worktree: false,
    initial_message: {
      role: "user",
      content: [{type: "text", text: $prompt}],
      run: true
    }
  }
')"

curl -sS -X POST "$BASE/api/conversations" \
  -H "Content-Type: application/json" \
  -H "X-Session-API-Key: $KEY" \
  --data-binary "$PAYLOAD" | jq '{id, title, execution_status, workspace}'

Verify the new conversation actually has tools and is running (not errored):

bash
CID="<conversation_id>"
curl -sS -H "X-Session-API-Key: $KEY" "$BASE/api/conversations/$CID" \
  | jq '{execution_status, tools: [.agent.tools[]?.name]}'
curl -sS -H "X-Session-API-Key: $KEY" "$BASE/api/conversations/$CID/events/search?limit=20" \
  | jq '[.events[]? | select(.kind=="ConversationErrorEvent") | .code] // []'

execution_status should be running/idle/finished (not error), tools should list the exec tools, and there should be no ConversationErrorEvent.

If MCP servers configured in the profile are unreachable, conversation creation can fail with MCP Connection Failure; the template drops mcp_config from the forwarded agent_settings to avoid that.

Report both links:

  • UI: http://localhost:8000/conversations/<conversation_id>
  • API: http://localhost:8001/api/conversations/<conversation_id>

Monitor a delegated conversation

bash
CID="<conversation_id>"
curl -sS -H "X-Session-API-Key: $KEY" "$BASE/api/conversations/$CID" \
  | jq '{id, title, execution_status, updated_at, workspace, agent_kind: .agent.kind, current_model_id, current_model_name}'

curl -sS -H "X-Session-API-Key: $KEY" "$BASE/api/conversations/$CID/events/search?limit=20" \
  | jq '.events // .items // .'

Terminal statuses commonly include idle, running, finished, error, stuck, and stopped.

Prompt checklist for delegation

Include:

  • repository owner/name and local path if relevant
  • branch, PR, issue, or Linear ticket identifiers
  • current status and known blockers
  • exact files or subsystems in scope
  • dirty-worktree warnings and paths not to touch
  • whether to push, open a PR, or only report
  • checks/tests to run
  • expected final report format

Do not rely on the new conversation knowing anything from the current thread.

© OpenHands, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in skills/agent-canvas-environment of OpenHands/extensions.

  • SKILL.md
  • .claude-plugin
  • .codex-plugin
  • .plugin/plugin.json
  • README.md

Open the folder on GitHubat commit d008b81

Compare with similar skills

Agent Canvas Environment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agent Canvas Environment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agent Canvas Environment this skillOpenHands/extensions158—~2.5kAutomated safety check: PassMIT
Web Artifacts Builderanthropics/skills180k41 repos~769Automated safety check: PassApache-2.0
React Doctormakeplane/plane61k12 repos~657Automated safety check: PassAGPL-3.0
Impeccablebestofjs/bestofjs3.1k27 repos~2.6kAutomated safety check: PassMIT
Figma Design System Builderwarpdotdev/warp65k2 repos~4.4kAutomated safety check: PassAGPL-3.0
Web Interface Guidelines Reviewervercel-labs/openreview1.7k98 repos~308Automated safety check: PassNone

Similar skills

  • Web Artifacts Builder

    anthropics/skills

    Official

    Builds multi-component claude.ai HTML artifacts as a small React, TypeScript and Tailwind project, then bundles it into one shareable HTML file.

    180k GitHub starsUsed in 41 repos~769 tokens
    Frontend & DesignAuto-check passed
  • React Doctor

    makeplane/plane

    Scans React code for lint, accessibility, bundle size and architecture issues, reports a health score and checks that changes do not lower it.

    61k GitHub starsUsed in 12 repos~657 tokens
    Frontend & DesignAuto-check passed
  • Impeccable

    bestofjs/bestofjs

    A skill your agent uses when the user wants to design, redesign, shape, critique, audit, polish, clarify, distill, harden, optimize, adapt, animate, colorize, extract, or otherwise improve a…

    3.1k GitHub starsUsed in 27 repos~2.6k tokens
    Frontend & DesignAuto-check passed
  • Builds or updates a design system in Figma from a codebase in ordered phases: discovery, variables and tokens, components, theming and documentation, with checkpoints.

    65k GitHub starsUsed in 2 repos~4.4k tokens
    Frontend & DesignAuto-check passed
  • Web Interface Guidelines Reviewer

    vercel-labs/openreview

    Official

    Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my…

    1.7k GitHub starsUsed in 98 repos~308 tokens
    Frontend & DesignAuto-check passed
  • Tailwindcss Development

    anonaddy/anonaddy

    Always invoke when the user's message includes 'tailwind' in any form.

    4.9k GitHub starsUsed in 10 repos~865 tokens
    Frontend & DesignAuto-check passed

More from OpenHands/extensions

All 78 skills in this repo
  • GitHub

    OpenHands/extensions

    Interact with GitHub repositories, pull requests, issues, and workflows using the GITHUBTOKEN environment variable and GitHub CLI.

    158 GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • Agent Readiness Report

    OpenHands/extensions

    Evaluate how well a codebase supports autonomous AI-assisted development.

    158 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Discord

    OpenHands/extensions

    Build and automate Discord integrations (bots, webhooks, slash commands, and REST API workflows).

    158 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • GitHub Issue To PR

    OpenHands/extensions

    Create an automation that implements GitHub issues when a configurable trigger label is applied.

    158 GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • GitHub Repo Monitor

    OpenHands/extensions

    This skill should be used when the user asks to "monitor a GitHub repository", "watch GitHub for issues or PRs", "respond to @OpenHands mentions on GitHub", "set up an OpenHands GitHub integration"…

    158 GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • GitLab Issue To Mr

    OpenHands/extensions

    Create an automation that implements GitLab issues when a configurable trigger label is applied.

    158 GitHub stars~4.9k tokensUpdated today
    Auto-check passed

Questions about Agent Canvas Environment

What does Agent Canvas Environment do?

Work effectively inside a local Agent Canvas environment, including local agent-server auth, frontend/backend port discovery, safe workspace hygiene, and delegating work to a new local conversation…. Agent Canvas Environment is an agent skill from OpenHands/extensions. Work effectively inside a local Agent Canvas environment, including local agent-server auth, frontend/backend port discovery, safe workspace hygiene, and delegating work to a new local conversation through POST /api/conversations.

When should I use Agent Canvas Environment?

Agent Canvas Environment fits situations like: frontend & Design work in your project.

How do I install Agent Canvas Environment in Claude Code?

Run `npx skills add OpenHands/extensions --skill agent-canvas-environment -a claude-code`. Or copy the skill folder (skills/agent-canvas-environment in OpenHands/extensions) into .claude/skills/agent-canvas-environment in your project. Claude Code loads it when a task matches its description.

How do I install Agent Canvas Environment in Codex?

Run `npx skills add OpenHands/extensions --skill agent-canvas-environment -a codex`. Or copy the skill folder (skills/agent-canvas-environment in OpenHands/extensions) into .agents/skills/agent-canvas-environment in your project. Codex loads it when a task matches its description.

Can I use Agent Canvas Environment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OpenHands/extensions --skill agent-canvas-environment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-canvas-environment, .gemini/skills/agent-canvas-environment, .github/skills/agent-canvas-environment and .opencode/skills/agent-canvas-environment in your project.

What does Agent Canvas Environment need to run?

Going by SKILL.md and its folder, Agent Canvas Environment needs the command-line tools its instructions call (curl, jq and git) and credentials named SESSION_API_KEY and LOCAL_BACKEND_API_KEY. Our summary lists: A credential in SESSION_API_KEY; A credential in LOCAL_BACKEND_API_KEY.

Does Agent Canvas Environment access the network?

SKILL.md contains no URLs. Its commands use curl and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Agent Canvas Environment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Agent Canvas Environment use?

Agent Canvas Environment is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agent Canvas Environment use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Agent Canvas Environment?

Skills that share tags, products or a category with Agent Canvas Environment: Web Artifacts Builder (anthropics/skills, 180k stars), React Doctor (makeplane/plane, 61k stars), Impeccable (bestofjs/bestofjs, 3.1k stars) and Figma Design System Builder (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agent Canvas Environment?

OpenHands (a GitHub organization) maintains it in OpenHands/extensions, which has 158 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.

Source: OpenHands/extensions on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.