Agent skill

Control API

by PersonalJarvis in PersonalJarvis/PersonalJarvis

Change Jarvis's own configuration through the local Control API instead of clicking the desktop UI or driving Computer-Use.

Apache-2.0Auto-check passedProductivity & Automation

Install Control API

skills CLI
$ npx skills add PersonalJarvis/PersonalJarvis --skill control-api -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PersonalJarvis/PersonalJarvis control-api --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PersonalJarvis/PersonalJarvis.git skills-src && mkdir -p .claude/skills && cp -r skills-src/jarvis/skills/builtin/control-api .claude/skills/control-api && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
control-api
GitHub stars
141
Token cost
~1.3k tokens
SKILL.md length
349 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
Apache-2.0

At a glance

Change Jarvis's own configuration through the local Control API instead of clicking the desktop UI or driving Computer-Use.

  • Works in 5 steps: Get the key and base URL → Discover what you can change → Read and write config → …
  • Tasks that involve Text to speech and voice
  • SKILL.md covers 1. Get the key and base URL, 2. Discover what you can change, 3. Read and write config and 4. Convenience: switch language, plus 2 more sections
  • Calls curl; needs JARVIS_KEY

What it does

Control API is an agent skill from PersonalJarvis/PersonalJarvis. Change Jarvis's own configuration through the local Control API instead of clicking the desktop UI or driving Computer-Use. Lets a local coding agent (Codex CLI, Claude Code) read and change settings, switch brain/STT/TTS providers, switch the reply language, and rotate API keys — all over HTTP on the loopback interface.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation, covering Text to speech and voice and Desktop control. The repository describes itself as: Your AI assistant, built for the agentic era. Open source and local: talk to it, and it runs your agents, your coding CLIs, your browser and your apps. Windows, macOS, Linux. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Text to speech and voice
  • Tasks that involve Desktop control

Example prompts

  • “/control-api”

Requirements

  • A credential in JARVIS_KEY

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Get the key and base URL
  2. Discover what you can change
  3. Read and write config
  4. Convenience: switch language
  5. Providers and secrets

What it can do on your machine

Read from SKILL.md and the folder at commit d3c7b70. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JARVIS_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Control API loads about 1.3k tokens when it runs. Until then it costs about 84 tokens; SKILL.md has 349 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PersonalJarvis/PersonalJarvis at commit d3c7b70, republished under its Apache-2.0 licence (© PersonalJarvis). 349 words, ~1,333 tokens.

Download SKILL.mdSave it as .claude/skills/control-api/SKILL.md (or your agent's skills folder).
name
control-api
description
Change Jarvis's own configuration through the local Control API instead of clicking the desktop UI or driving Computer-Use. Lets a local coding agent (Codex CLI, Claude Code) read and change settings, switch brain/STT/TTS providers, switch the reply language, and rotate API keys — all over HTTP on the loopback interface.
schema_version
1
version
1.0.0
when_to_use
Use when a coding agent must change a Jarvis setting on this machine — switch a provider, change the reply language, adjust TTS speed, or rotate an API key…
category
meta
tags
self-config, control-api, agent, settings
author
builtin
license
Apache-2.0
risk_policy.default_tier
ask

Jarvis Control API

Jarvis exposes a local HTTP API at /api/control/* so an agent can do anything the user can do in the desktop app — without Computer-Use. This skill is the recipe a coding agent (Codex CLI, Claude Code) follows when the user asks it to change a Jarvis setting on this machine.

1. Get the key and base URL

Every install generates its own per-user key (prefix jctl_).

  • Base URL: http://127.0.0.1:<port> where <port> is [ui].admin_api_port in jarvis.toml (the same port the desktop app/browser UI uses).
  • Key: copy it from the desktop app → Settings → Jarvis API, or read it on the loopback interface:
bash
curl -s http://127.0.0.1:<port>/api/control/api-key
# => {"key":"jctl_...","masked":"jctl_…1234"}

Send the key as a Bearer header on every other call:

Authorization: Bearer jctl_...

Verify it works:

bash
curl -s -H "Authorization: Bearer $JARVIS_KEY" \
  http://127.0.0.1:<port>/api/control/auth/probe        # => {"ok":true}

2. Discover what you can change

bash
curl -s -H "Authorization: Bearer $JARVIS_KEY" \
  http://127.0.0.1:<port>/api/control/allowlist

Returns every mutable setting with its path, risk_tier (safe/ask), needs_restart, and a description. Validate a path against this before you write — a path that is not listed (or is a protected secret) is refused.

3. Read and write config

bash
# read
curl -s -H "Authorization: Bearer $JARVIS_KEY" \
  "http://127.0.0.1:<port>/api/control/config?path=brain.reply_language"

# write
curl -s -X PUT -H "Authorization: Bearer $JARVIS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"path":"brain.reply_language","value":"en","reason":"user asked"}' \
  http://127.0.0.1:<port>/api/control/config

The response envelope: {ok, applied, needs_confirmation, pending_id, requires_restart, backup_path, risk_tier, ...}.

  • safe settings (e.g. brain.reply_language, tts.speed, ui.theme) apply immediately: applied=true. Language hot-reloads into the next turn — no restart.
  • ask settings (e.g. brain.primary, tts.provider) return needs_confirmation=true and a pending_id. Confirm it:
bash
curl -s -X POST -H "Authorization: Bearer $JARVIS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"pending_id":"<id>"}' \
  http://127.0.0.1:<port>/api/control/config/confirm
# or .../config/reject to cancel

requires_restart=true means the change is persisted but only takes effect after the user restarts Jarvis (e.g. STT provider) — say so honestly.

4. Convenience: switch language

There are TWO language settings: ui.language (the INTERFACE the user sees — every label/button) and brain.reply_language (what Jarvis SPEAKS/writes; auto mirrors the user's input). When the user says "change the/your language to X", switch BOTH — the /language verb does that for a concrete code:

bash
curl -s -X PUT -H "Authorization: Bearer $JARVIS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"reply_language":"en"}' \
  http://127.0.0.1:<port>/api/control/language        # auto | de | en | es
# concrete code (de/en/es) -> sets reply_language AND ui.language; the open UI
# switches live. "auto" -> reply only.

Or set just one explicitly via /config (ui.language = en/de/es, brain.reply_language = auto/de/en/es).

5. Providers and secrets

bash
# snapshot of all providers + settings
curl -s -H "Authorization: Bearer $JARVIS_KEY" \
  http://127.0.0.1:<port>/api/control/providers

# switch a tier (brain | tts | stt | subagent)
curl -s -X PUT -H "Authorization: Bearer $JARVIS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"provider":"gemini"}' \
  http://127.0.0.1:<port>/api/control/providers/brain

# list secret slots (masked) / set / delete a provider key
curl -s -H "Authorization: Bearer $JARVIS_KEY" \
  http://127.0.0.1:<port>/api/control/secrets
curl -s -X PUT -H "Authorization: Bearer $JARVIS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"value":"sk-..."}' \
  http://127.0.0.1:<port>/api/control/secrets/openai_api_key

Rules

  • Local only. The API binds loopback on desktop; the Bearer key is the boundary. Never paste the key into chat, logs, commits, or a remote service.
  • Only paths in /api/control/allowlist are writable. Secrets are write/rotate only — they are never returned in clear by the config endpoints.
  • Prefer this API over Computer-Use or editing jarvis.toml by hand: it is atomic (backup + validate + rollback) and audited.

© PersonalJarvis, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in jarvis/skills/builtin/control-api of PersonalJarvis/PersonalJarvis.

Open the folder on GitHubat commit d3c7b70

Compare with similar skills

Control API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Control API compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Control API this skillPersonalJarvis/PersonalJarvis141—~1.3kAutomated safety check: PassApache-2.0
Computer Usekatipally/openlive336—~1.4kAutomated safety check: PassApache-2.0
Vision SkillsAnionex/agent-vision-toolkit1.2k1 repos~4kAutomated safety check: PassMIT
Mac Computer UseTo3akaRin/mac-computer-use1.1k1 repos~495Automated safety check: PassMIT
AgentCall Join Meetingpattern-ai-labs/agentcall1651 repos~25kAutomated safety check: PassMIT
Crabbox Appsopenclaw/openclaw392k—~1.5kAutomated safety check: PassMIT

Similar skills

  • Computer Use

    katipally/openlive

    Use before operating an app on the user's computer, such as clicking, filling a field, reading a window or moving through a website in their browser.

    336 GitHub stars~1.4k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Vision Skills

    Anionex/agent-vision-toolkit

    Local vision CLIs: glance (describe/ask/OCR an image), ground (locate a target, pixel box), detect (element inventory), trace (image to SVG geometry), crop (cut a pixel box to a file), and…

    1.2k GitHub starsUsed in 1 repo~4k tokens
    Productivity & AutomationAuto-check passed
  • Mac Computer Use

    To3akaRin/mac-computer-use

    操作 macOS 桌面应用,探测窗口和自动化接口、截图、读取或修改辅助功能元素、执行鼠标键盘动作,以及通过 CDP 操作内嵌 Chromium 页面。适用于桌面应用自动化与界面验收;普通网页任务优先使用已有浏览器工具。

    1.1k GitHub starsUsed in 1 repo~495 tokens
    Productivity & AutomationAuto-check passed
  • AgentCall Join Meeting

    pattern-ai-labs/agentcall

    Joins Google Meet, Teams or Zoom video calls as an AI bot with voice and visual presence through the AgentCall service, in audio, text-to-speech or webpage modes.

    165 GitHub starsUsed in 1 repo~25k tokens
    Productivity & AutomationAuto-check passed
  • Crabbox Apps

    openclaw/openclaw

    A skill your agent uses when asked to open, run, test, or show an app in Crabbox, including native desktops, web previews, and computer use on a temporary machine.

    392k GitHub stars~1.5k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Agent Management

    autonomous-ai/Physical-AI-Operating-System

    Legacy Autonomous Buddy control for explicitly requested Buddy coding sessions.

    381 GitHub stars~1.7k tokensUpdated today
    Productivity & AutomationAuto-check passed

More from PersonalJarvis/PersonalJarvis

All 12 skills in this repo
  • Skill Creator

    PersonalJarvis/PersonalJarvis

    Creates a new Jarvis skill from the user's description — the assistant writes the whole skill (name, trigger phrase, schedule, steps, spoken answer format) and files it as a draft.

    141 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Jarvis Doc Author

    PersonalJarvis/PersonalJarvis

    Authoritative skill for writing internal Personal-Jarvis docs under docs/ and sibling directories.

    141 GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Drive Jarvis CLI

    PersonalJarvis/PersonalJarvis

    A skill your agent uses when you (a Claude Code / Codex session, or any terminal agent) need to control a running Personal Jarvis instance — switch the brain provider, dispatch or inspect missions…

    141 GitHub stars~945 tokensUpdated today
    Auto-check passed
  • Generate CLI Command

    PersonalJarvis/PersonalJarvis

    Use after building a feature that adds or changes a REST route in jarvis/ui/web/routes.py, as the "definition of done" before committing.

    141 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Phase6 Adr Update

    PersonalJarvis/PersonalJarvis

    A skill your agent uses when a Phase-6 architecture decision needs to be amended or a new Phase-6 ADR needs to be written (e.g.

    141 GitHub stars~893 tokensUpdated today
    Auto-check passed
  • Phase6 Smoke Test

    PersonalJarvis/PersonalJarvis

    A skill your agent uses to run a quick end-to-end smoke test against the Phase-6 Mission-Manager + Critic-Loop.

    141 GitHub stars~725 tokensUpdated today
    Auto-check passed

Questions about Control API

What does Control API do?

Change Jarvis's own configuration through the local Control API instead of clicking the desktop UI or driving Computer-Use. Control API is an agent skill from PersonalJarvis/PersonalJarvis. Change Jarvis's own configuration through the local Control API instead of clicking the desktop UI or driving Computer-Use.

When should I use Control API?

Control API fits situations like: tasks that involve Text to speech and voice; tasks that involve Desktop control.

How do I install Control API in Claude Code?

Run `npx skills add PersonalJarvis/PersonalJarvis --skill control-api -a claude-code`. Or copy the skill folder (jarvis/skills/builtin/control-api in PersonalJarvis/PersonalJarvis) into .claude/skills/control-api in your project. Claude Code loads it when a task matches its description.

How do I install Control API in Codex?

Run `npx skills add PersonalJarvis/PersonalJarvis --skill control-api -a codex`. Or copy the skill folder (jarvis/skills/builtin/control-api in PersonalJarvis/PersonalJarvis) into .agents/skills/control-api in your project. Codex loads it when a task matches its description.

Can I use Control API in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PersonalJarvis/PersonalJarvis --skill control-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/control-api, .gemini/skills/control-api, .github/skills/control-api and .opencode/skills/control-api in your project.

What does Control API need to run?

Going by SKILL.md and its folder, Control API needs the command-line tools its instructions call (curl) and credentials named JARVIS_KEY. Our summary lists: A credential in JARVIS_KEY.

Does Control API access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Control API safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Control API use?

Control API is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Control API use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Control API?

Skills that share tags, products or a category with Control API: Computer Use (katipally/openlive, 336 stars), Vision Skills (Anionex/agent-vision-toolkit, 1.2k stars), Mac Computer Use (To3akaRin/mac-computer-use, 1.1k stars) and AgentCall Join Meeting (pattern-ai-labs/agentcall, 165 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Control API?

PersonalJarvis (a GitHub organization) maintains it in PersonalJarvis/PersonalJarvis, which has 141 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 8, 2026.

Source: PersonalJarvis/PersonalJarvis on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.